<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>VMware Security &amp; Compliance Blog</title>
	
	<link>http://blogs.vmware.com/security</link>
	<description />
	<lastBuildDate>Thu, 09 May 2013 20:38:41 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.4.1</generator>
		<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/VmwareSecurityComplianceBlog" /><feedburner:info uri="vmwaresecuritycomplianceblog" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><feedburner:browserFriendly></feedburner:browserFriendly><item>
		<title>vSphere 5.1 Hardening Guide goes mobile!</title>
		<link>http://blogs.vmware.com/security/2013/04/vsphere-5-1-hardening-guide-goes-mobile.html</link>
		<comments>http://blogs.vmware.com/security/2013/04/vsphere-5-1-hardening-guide-goes-mobile.html#comments</comments>
		<pubDate>Tue, 30 Apr 2013 20:05:41 +0000</pubDate>
		<dc:creator>Mike Foley</dc:creator>
				<category><![CDATA[Web/Tech]]></category>
		<category><![CDATA[Weblogs]]></category>

		<guid isPermaLink="false">http://blogs.vmware.com/security/?p=739</guid>
		<description><![CDATA[Hi, It has been a couple of weeks since the release of the vSphere 5.1 Hardening Guide. Right around that time there was a call for updated content for the VMware Mobile Knowledge Portal app Well, I really wanted to &#8230; <a href="http://blogs.vmware.com/security/2013/04/vsphere-5-1-hardening-guide-goes-mobile.html">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Hi,</p>
<p>It has been a couple of weeks since the release of the <a href="https://blogs.vmware.com/security/2013/04/vsphere-5-1-hardening-guide-official-release.html" target="_blank">vSphere 5.1 Hardening Guide</a>. Right around that time there was a call for updated content for the <a href="http://www.vmwaremkp.com/" target="_blank">VMware Mobile Knowledge Portal app</a> Well, I really wanted to see the updated Hardening Guide available on that  platform. That presented a challenge. For most customers, the format of releasing it as an Excel spreadsheet meets their need but have you looked at a spreadsheet on an iPad? Not a pretty sight.</p>
<p><span id="more-739"></span></p>
<p>So, using Microsoft Word&#8217;s Mail Merge capability I whipped up a proof of concept and showed it to a couple of folks. When your boss says &#8220;That&#8217;s awesome!&#8221; you know you&#8217;re on the right track. After some updating, we came out with a decent template and I&#8217;m happy to say that it looks great on my old iPad.</p>
<p>Here&#8217;s some examples:</p>
<p>First, a picture of the Mobile Knowledge Portal app itself. You can see a list of all the Hardening Guide content.</p>
<p><a href="http://blogs.vmware.com/security/files/2013/04/IMG_0051.png"><img class="alignnone size-medium wp-image-740" title="Portal App" src="http://blogs.vmware.com/security/files/2013/04/IMG_0051-300x225.png" alt="VMware Mobile Knowledge Portal App" width="300" height="225" /></a></p>
<p>Now the Introduction Page that explains what the Hardening Guide contains</p>
<p><a href="http://blogs.vmware.com/security/files/2013/04/IMG_0052.png"><img class="alignnone size-medium wp-image-741" title="Hardening Guide Intro Page" src="http://blogs.vmware.com/security/files/2013/04/IMG_0052-300x225.png" alt="" width="300" height="225" /></a></p>
<p>Finally, here&#8217;s an example of Hardening Guide data reformatted for a tablet. This is useful for browsing through all the guidelines.</p>
<p><a href="http://blogs.vmware.com/security/files/2013/04/IMG_0053.png"><img class="alignnone size-medium wp-image-742" title="ESXi-Config-NTP guideline" src="http://blogs.vmware.com/security/files/2013/04/IMG_0053-300x225.png" alt="ESXi-Config-NTP guideline" width="300" height="225" /></a></p>
<p>If you don&#8217;t have the VMKP, get it now for iPad and Android! Here&#8217;s some more info about the app and where to get it.</p>
<p>Get it for iPad on <a href="https://itunes.apple.com/WebObjects/MZStore.woa/wa/viewSoftware?id=566387182&amp;mt=8" target="_blank">iTunes</a><br />
Get it for Android tablets at <a href="https://play.google.com/store/apps/details?id=com.vmware.marketing.mobileknowledgeportal" target="_blank">Google Play</a></p>
<p>The VMKP is designed to provide a simple way for VMware customers to view technical collateral around the Datacenter &amp; Cloud Infrastructure and Infrastructure &amp; Operations Management products.<br />
VMKP 2.0 adds the following enhancements over the original version<br />
- Android and iPad support<br />
- Ability to rate collateral<br />
- Ability to provide feedback to VMware on pieces of collateral<br />
- Integration with Facebook and Twitter to let others know what you have been reading on the VMKP<br />
- Mechanism to request additional collateral items</p>
<p>&nbsp;</p>
<p>I hope you find this useful. If you have feedback, please send it on!</p>
<p>Thanks,</p>
<p>mike</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.vmware.com/security/2013/04/vsphere-5-1-hardening-guide-goes-mobile.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>VMware Common Criteria Update – April 2013</title>
		<link>http://blogs.vmware.com/security/2013/04/vmware-common-criteria-update-april-2013.html</link>
		<comments>http://blogs.vmware.com/security/2013/04/vmware-common-criteria-update-april-2013.html#comments</comments>
		<pubDate>Tue, 23 Apr 2013 16:36:59 +0000</pubDate>
		<dc:creator>Charu Chaubal</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[certification]]></category>
		<category><![CDATA[common criteria]]></category>
		<category><![CDATA[EAL2]]></category>
		<category><![CDATA[EAL4+]]></category>
		<category><![CDATA[vsphere]]></category>

		<guid isPermaLink="false">http://blogs.vmware.com/security/?p=729</guid>
		<description><![CDATA[The following is an article from Eric Betts, who manages VMware&#8217;s Common Criteria certification program. Feed back to VMware’s announcement of vSphere 5.1 achieving “In-Evaluation” has been overwhelmingly successful.  However, it also caused quite a flurry of questions regarding the &#8230; <a href="http://blogs.vmware.com/security/2013/04/vmware-common-criteria-update-april-2013.html">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><em>The following is an article from Eric Betts, who manages VMware&#8217;s Common Criteria certification program.</em></p>
<p>Feed back to VMware’s announcement of vSphere 5.1 achieving “In-Evaluation” has been overwhelmingly successful.  However, it also caused quite a flurry of questions regarding the change in EAL level from EAL4+ to EAL2+ and questions on EAL4 vs. EAL2.  This blog posting will help with clarifying VMware’s position and overview of reform changes in-progress with Common Criteria.</p>
<p>Information Technology (IT) customers often leverage third party validations, such as Common Criteria, for assurance of IT product features &amp; implementation and compliance with a known standard.  Common Criteria is a methodology framework for the evaluation of IT products, mutually recognized by 26 member nations (up to EAL4) and is an ISO standard (ISO-15408).   These factors, among many others, have contributed to the success, acceptance and often the requirement for Common Criteria certifications for Government and Defense related procurement sales.  However, as with any technology, process or standard, they must evolve and adapt to address current technologies and industry trends to remain relevant.   Common Criteria is evolving to address such needs.</p>
<p>The National Information Assurance Partnership (NIAP) in cooperation with other countries has initiated a series of changes for reform.  Changes include enlisting the help of industry through technical communities for development of new Protection Profiles (PP), improving consistency, speed and efficiency of evaluations.  As part of the reform, requirements for specific EAL levels will be replaced with “Approved Protection Profiles” and products will be listed as “PP Compliant”.  These products which implement the functionality described in the protection profile will then be evaluated in a consistent manner and against the same security threats which have been observed by the larger security community.  In the event that there is no protection profile in place at the time of entering the evaluation evaluations will be accepted up to a maximum evaluation level of EAL2 which is roughly consistent with the level of detail in the current protection profiles.</p>
<p>Security claims for prior Common Criteria evaluations were driven by vendor developed Security Targets and optional Protection Profiles.  While this provided vendors with greater flexibility, it also enabled opportunity for inconsistent evaluations.  Going forward products will be required to conform to a set of security claims from a mandatory protection profile.  This baseline will improve consistency across evaluations, testing laboratories and international schemes.</p>
<p>The Common Criteria certification of vSphere 5.1 @ EAL2+ demonstrates VMware’s continued commitment to evolving standards, validation of the latest VMware platform and providing assurance to our customers.</p>
<p>The National Information Assurance Partnership (NIAP) developed a FAQ which provides in-depth details on the Common Criteria reform titled “<em><a href="http://www.niap-ccevs.org/NIAP_Evolution/faqs/niap_evolution/FAQs28Mar_v6.pdf">Frequently Asked Questions for NIAP/CCEVS and the Use of Common Criteria in the US (28 March 2012)</a>”</em></p>
<p>The FAQ below is based on specific questions and discussions at VMware:</p>
<p>Q: Why is vSphere being certified at EAL2?</p>
<p>A: As stated in the NIAP FAQ, the ability to certify at EAL4 was sunset as part of the Common Criteria reform.  When vSphere started the certification process, EAL2 was the target level for commercial software.</p>
<p>Q: You just stated that Common Criteria evaluations at EAL4 are no longer possible, I searched and discovered VMware vCNS 5.1.2 on the “In-Evaluation” list at EAL4?  What gives??</p>
<p>A: Correct.  Short answer is timing and timelines.  vCNS entered into evaluation when while EAL4’s were still being accepted.  However, when vSphere entered into evaluation, certifications at EAL4 were no longer being accepted.</p>
<p>Q: Does certifying at EAL2+ mean that vSphere 5.1 is less secure?</p>
<p>A: No, absolutely not!  The certification process by which vSphere 5.1 is being evaluated  is changing.  vSphere 5.1 remains the trusted center piece of the industry-leading virtualization platform for building flexible cloud infrastructures with performance and reliability to run the most demanding enterprise applications.</p>
<p>Q: Why didn’t vSphere 5.1 conform to a mandatory Protection Profile?</p>
<p>A: When vSphere 5.1 entered into evaluation a protection profile for virtualization was not available.  vSphere 5.1 will be a Security Target based evaluation.  The vSphere 5.1 Security Target contains a full comprehensive set of security claims where applicable, portions were leveraged from existing protection profiles like General Purpose Operating System (GPOS).</p>
<p>Also see NIAP FAQ questions #14 &amp; #16.</p>
<p>VMware was an active participant in the Tech Community that developed the foundation content for the Virtualization Protection Profile.  The Protection Profile for Virtualization is currently under development and the estimated completion date is Q3/2013.</p>
<p>See complete NAIP PP lists:</p>
<p>-       Completed:    <a href="http://www.niap-ccevs.org/pp/">http://www.niap-ccevs.org/pp/</a></p>
<p>-       In draft:          <a href="http://www.niap-ccevs.org/pp/draft_pps/">http://www.niap-ccevs.org/pp/draft_pps/</a></p>
<p>Q: Why is vSphere 5.1 being certified through Canada and not the US?</p>
<p>A: Common Criteria certifications up to EAL4+ are mutually recognized by all member nations.  All schemes are governed and accredited by identical standards, so location isn’t important.  The decision to certify though Canada was a decision based on several business factors.</p>
<p>Also see the Common Criteria Recognition Agreement “<a href="http://www.commoncriteriaportal.org/vision.cfm">Vision Statement</a>”.</p>
<p>Q: Why are some products still being certified at EAL4 through other schemes?</p>
<p>A: While the US, Canada and most other schemes are in lock-step agreement with proposed timelines and processes for reform, some schemes decided to postpone new NIAP direction and continue to perform evaluations at EAL4 for specific country requirements.</p>
<p>Join the conversation:</p>
<p>VMware community discussion: “<a href="http://communities.vmware.com/message/2224868#2224868">VMware Common Criteria Security Certification Update</a>”</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.vmware.com/security/2013/04/vmware-common-criteria-update-april-2013.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>VMware CP&amp;C releases VMware vSphere 5.1 Hardening Guide Compliance toolkit in VCM!</title>
		<link>http://blogs.vmware.com/security/2013/04/vmware-cpc-releases-vmware-vsphere-5-1-hardening-guide-compliance-toolkit-in-vcm.html</link>
		<comments>http://blogs.vmware.com/security/2013/04/vmware-cpc-releases-vmware-vsphere-5-1-hardening-guide-compliance-toolkit-in-vcm.html#comments</comments>
		<pubDate>Tue, 16 Apr 2013 03:35:41 +0000</pubDate>
		<dc:creator>Pravin Goyal</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Center for Policy and Compliance]]></category>
		<category><![CDATA[VCM Content]]></category>
		<category><![CDATA[vSphere 5.1]]></category>
		<category><![CDATA[vSphere Hardening]]></category>

		<guid isPermaLink="false">http://blogs.vmware.com/security/?p=677</guid>
		<description><![CDATA[The VMware Center for Policy &#38; Compliance (CP&#38;C) is pleased to announce, the most awaited and anticipated content of the year, the release of VMware vSphere 5.1 Hardening Guide Compliance toolkit in VMware vCenter Configuration Manager (VCM), a key component in &#8230; <a href="http://blogs.vmware.com/security/2013/04/vmware-cpc-releases-vmware-vsphere-5-1-hardening-guide-compliance-toolkit-in-vcm.html">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><a href="http://blogs.vmware.com/security/files/2013/04/CPC-Logo.png"><img class="alignleft size-full wp-image-721" title="CPC Logo" src="http://blogs.vmware.com/security/files/2013/04/CPC-Logo.png" alt="" width="76" height="125" /></a>The VMware Center for Policy &amp; Compliance (CP&amp;C) is pleased to announce, the most awaited and anticipated content of the year, the release of <a title="VMware vSphere 5.1 Hardening Guide" href="http://blogs.vmware.com/vsphere/2013/04/vsphere-5-1-hardening-guide-official-release.html" target="_blank">VMware vSphere 5.1 Hardening Guide </a>Compliance toolkit in VMware vCenter Configuration Manager (<a title="VMware vCenter Configuration Manager" href="http://www.vmware.com/products/configuration-manager/overview.html" target="_blank">VCM</a>), a key component in the VMware vCenter Operations Suite. (vC Ops). As a critical component of the vC Ops suite, VCM is the FIRST product in the market today to have the official GA version of the vSphere 5.1 Hardening Guidelines.</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>The package comes in 4 versions:</p>
<blockquote>
<ul>
<li><span style="color: #0000ff;">Full – Has all recommendations present in the hardening guide</span></li>
<li><span style="color: #0000ff;">Profile 1 – Has only Profile 1 recommendations</span></li>
<li><span style="color: #0000ff;">Profile 2 – Has only Profile 2 recommendations</span></li>
<li><span style="color: #0000ff;">Profile 3 – Has only Profile 3 recommendations</span></li>
</ul>
</blockquote>
<p><span id="more-677"></span>Pick the packages based on the profile you are wanting to adhere to! You can download the packages using VCM Content Wizard and begin to use it.</p>
<p><strong>Compliance Rule Groups and Templates for vSphere 5.1 Hardening Guide:</strong></p>
<dl id="attachment_691" class="wp-caption alignleft" style="width: 1289px;">
<dt class="wp-caption-dt"><a href="http://blogs.vmware.com/security/files/2013/04/VHG_51_Rule-Groups-and-Templates_2.png"><img class="size-full wp-image-691" title="vSphere 5.1 Hardening Guide Rule Groups and Templates - 1" src="http://blogs.vmware.com/security/files/2013/04/VHG_51_Rule-Groups-and-Templates_2.png" alt="vSphere 5.1 Hardening Guide Rule Groups and Templates - 1" width="1279" height="613" /></a></dt>
<dd class="wp-caption-dd">vSphere 5.1 Hardening Guide Rule Groups and Templates &#8211; 1</dd>
</dl>
<div id="attachment_709" class="wp-caption alignleft" style="width: 1288px"><a href="http://blogs.vmware.com/security/files/2013/04/VHG_51_Rule-Groups-and-Templates_21.png"><img class=" wp-image-709 " title="vSphere 5.1 Hardening Guide Rule Groups and Templates - 2" src="http://blogs.vmware.com/security/files/2013/04/VHG_51_Rule-Groups-and-Templates_21.png" alt="vSphere 5.1 Hardening Guide Rule Groups and Templates - 2" width="1278" height="599" /></a><p class="wp-caption-text">vSphere 5.1 Hardening Guide Rule Groups and Templates &#8211; 2</p></div>
<p> <strong>One-Click Collection Filter Set to collect all data needed for Compliance assessment</strong>:</p>
<div id="attachment_710" class="wp-caption alignleft" style="width: 1124px"><a href="http://blogs.vmware.com/security/files/2013/04/VHG_51_Collection-Filters1.png"><img class="size-full wp-image-710" title="vSphere 5.1 Hardening Guide Collection Filter Set" src="http://blogs.vmware.com/security/files/2013/04/VHG_51_Collection-Filters1.png" alt="vSphere 5.1 Hardening Guide Collection Filter Set" width="1114" height="579" /></a><p class="wp-caption-text">vSphere 5.1 Hardening Guide Collection Filter Set</p></div>
<p>&nbsp;</p>
<p><strong>Track your compliance posture using these great dashboards</strong>:</p>
<div id="attachment_688" class="wp-caption alignleft" style="width: 1022px"><a href="http://blogs.vmware.com/security/files/2013/04/VHG_51_Dashboard_1.png"><img class="size-full wp-image-688" title="vSphere 5.1 Hardening Dashboard - 1" src="http://blogs.vmware.com/security/files/2013/04/VHG_51_Dashboard_1.png" alt="vSphere 5.1 Hardening Dashboard - 1" width="1012" height="716" /></a><p class="wp-caption-text">vSphere 5.1 Hardening Dashboard &#8211; 1</p></div>
<p><strong>You can also break down the compliance results by data type and vCenter Server to see where most of your infractions are coming from:</strong>:</p>
<div id="attachment_689" class="wp-caption alignnone" style="width: 1030px"><a href="http://blogs.vmware.com/security/files/2013/04/VHG_51_Dashboard_2.png"><img class=" wp-image-689" title="vSphere 5.1 Hardening Guide Dashboard - 2" src="http://blogs.vmware.com/security/files/2013/04/VHG_51_Dashboard_2.png" alt="vSphere 5.1 Hardening Guide Dashboard - 2" width="1020" height="727" /></a><p class="wp-caption-text">vSphere 5.1 Hardening Guide Dashboard &#8211; 2</p></div>
<p><strong><strong>From there, you can see the individual rules behind the content that is surfaced in our dashboards:</strong></strong></p>
<div id="attachment_692" class="wp-caption alignleft" style="width: 1277px"><a href="http://blogs.vmware.com/security/files/2013/04/VHG_51_Template-Results.png"><img class="size-full wp-image-692" title="vSphere 5.1 Hardening - Compliance Assessment Detailed Results" src="http://blogs.vmware.com/security/files/2013/04/VHG_51_Template-Results.png" alt="vSphere 5.1 Hardening - Compliance Assessment Detailed Results" width="1267" height="631" /></a><p class="wp-caption-text">vSphere 5.1 Hardening &#8211; Compliance Assessment Detailed Results</p></div>
<p> <br />
Keep in mind that VCM manages not only virtual environments, but covers physical as well. It is the market leader in Configuration Audit, Change Detection, Patch Management and COMPLIANCE content. Yes! That is right, we can also remediate non compliant results with a right click in both the virtual and physical world!</p>
<p>Start Green Stay Green!</p>
<p>Thanks and regards,<br />
<strong>Pravin Goyal</strong><br />
<strong><small>RHCE | HP-UX CSA | VCP | MBA | CISSP | GISP | CCSK | CloudU | CompTIA CE | ITIL-F | ITSM-F</small></strong></p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.vmware.com/security/2013/04/vmware-cpc-releases-vmware-vsphere-5-1-hardening-guide-compliance-toolkit-in-vcm.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>vSphere 5.1 Hardening Guide – Official Release</title>
		<link>http://blogs.vmware.com/security/2013/04/vsphere-5-1-hardening-guide-official-release.html</link>
		<comments>http://blogs.vmware.com/security/2013/04/vsphere-5-1-hardening-guide-official-release.html#comments</comments>
		<pubDate>Mon, 15 Apr 2013 20:26:06 +0000</pubDate>
		<dc:creator>Mike Foley</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blogs.vmware.com/security/?p=715</guid>
		<description><![CDATA[Hi, I&#8217;m pleased to announce to availability of the official release of the vSphere 5.1 Hardening Guide. The guide is being released as an Excel spreadsheet only. This guide follows the same format as the 5.0 guide. All reference and &#8230; <a href="http://blogs.vmware.com/security/2013/04/vsphere-5-1-hardening-guide-official-release.html">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Hi,</p>
<p>I&#8217;m pleased to announce to availability of the official release of the vSphere 5.1 Hardening Guide. The guide is being released as an Excel spreadsheet only. This guide follows the same format as the 5.0 guide.</p>
<p>All reference and documentation URL&#8217;s and code samples have been updated for 5.1. The guide is available <a href="http://communities.vmware.com/docs/DOC-22981">here</a></p>
<p>The permanent home will be here soon: http://vmware.com/go/securityguides</p>
<p>Also available is a separate document containing the Change Log for the guide. The Change Log is available <a href="http://communities.vmware.com/docs/DOC-22981">here</a></p>
<p>Thanks to everyone who contributed feedback on the Public Drafts and also the team at VMware for their outstanding work in making this guide possible.</p>
<p>mike</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.vmware.com/security/2013/04/vsphere-5-1-hardening-guide-official-release.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>vSphere 5.1 Hardening Guide Release Candidate now available</title>
		<link>http://blogs.vmware.com/security/2013/03/vsphere-5-1-hardening-guide-release-candidate-now-available.html</link>
		<comments>http://blogs.vmware.com/security/2013/03/vsphere-5-1-hardening-guide-release-candidate-now-available.html#comments</comments>
		<pubDate>Thu, 28 Mar 2013 13:41:01 +0000</pubDate>
		<dc:creator>Mike Foley</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[vSphere 5.1]]></category>
		<category><![CDATA[vSphere Hardening]]></category>

		<guid isPermaLink="false">http://blogs.vmware.com/security/?p=674</guid>
		<description><![CDATA[I would like to announce the release of the Rev B/Release Candidate for the vSphere 5.1 Security Hardening Guide.  This guide should be functionally complete and has been posted for your review and your feedback. We’d love to hear your &#8230; <a href="http://blogs.vmware.com/security/2013/03/vsphere-5-1-hardening-guide-release-candidate-now-available.html">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>I would like to announce the release of the Rev B/Release Candidate for the vSphere 5.1 Security Hardening Guide.  This guide should be functionally complete and has been posted for your review and your feedback.</p>
<p>We’d love to hear your feedback, good and bad, on the contents of the guide. I would encourage you to post your reply in the <a href="http://communities.vmware.com/community/vmtn/server/security" target="_blank">Security and Compliance Communities forum </a>but if you have more sensitive concerns, send it to me at mfoley@vmware.com. The intent is to publish the final GA copy in <strong>two weeks</strong> with any changes/updates incorporated so get your inputs in as soon as possible!</p>
<p>The <a href="http://communities.vmware.com/docs/DOC-22783" target="_blank">vSphere 5.1 Security Hardening Guide</a> has been posted to the VMware Communities in the “<a href="http://communities.vmware.com/community/vmtn/general/security" target="_self">Security and Compliance</a>” area, in the Documents tab. A separate Change Log document has also been published with the RC Guide.</p>
<p>Thanks to everyone who provided feedback on the Rev A Draft, and also to the team at VMware who contributed to this guide in many significant ways.</p>
<p>Thanks,<br />
mike foley</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.vmware.com/security/2013/03/vsphere-5-1-hardening-guide-release-candidate-now-available.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>CIS and DISA CP&amp;C toolkit update</title>
		<link>http://blogs.vmware.com/security/2013/02/cis-and-disa-cpc-toolkit-update.html</link>
		<comments>http://blogs.vmware.com/security/2013/02/cis-and-disa-cpc-toolkit-update.html#comments</comments>
		<pubDate>Thu, 21 Feb 2013 02:16:27 +0000</pubDate>
		<dc:creator>Pravin Goyal</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Center for Policy and Compliance]]></category>
		<category><![CDATA[CIS]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[DISA]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[VCM Content]]></category>

		<guid isPermaLink="false">http://blogs.vmware.com/security/?p=635</guid>
		<description><![CDATA[Hi All, The VMware Center for Policy &#38; Compliance (CP&#38;C) is pleased to announce the availability of latest Center for Internet Security (CIS) and Defense Information Security Agency (DISA) Compliance toolkit packages for VMware vCenter Configuration Manager (VCM). The highlights &#8230; <a href="http://blogs.vmware.com/security/2013/02/cis-and-disa-cpc-toolkit-update.html">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Hi All,</p>
<p>The VMware Center for Policy &amp; Compliance (CP&amp;C) is pleased to announce the availability of latest Center for Internet Security (<a title="CIS" href="https://cisecurity.org/" target="_blank">CIS</a>) and Defense Information Security Agency (<a title="DISA STIGs" href="http://iase.disa.mil/stigs/" target="_blank">DISA</a>) Compliance toolkit packages for VMware vCenter Configuration Manager (<a title="VCM" href="http://www.vmware.com/products/configuration-manager/overview.html" target="_blank">VCM</a>).</p>
<blockquote><p>The highlights of this release are as below:</p>
<ol>
<li>CIS has new content for
<ul>
<li>AIX 5.3-6.1 and</li>
<li>RHEL 6</li>
</ul>
</li>
<li>DISA has new content for
<ul>
<li>HP-UX 11.23 and 11.31</li>
<li>Solaris 10</li>
<li>AIX 6.1 and</li>
<li>RHEL 5</li>
</ul>
</li>
</ol>
</blockquote>
<p><span id="more-635"></span>Apart from the new ones, the older ones are also packaged together respectively. You can download the packages using CCW tool and begin to use it.</p>
<p>Below are some snapshots to give you a quick feel of the update:</p>
<p><small><strong>CIS Rule Groups and Templates</strong></small><br />
<a href="http://blogs.vmware.com/security/files/2013/02/CIS_Rule_Groups_and_Templates1.png"><img class="alignnone size-full wp-image-654" title="CIS_Rule_Groups_and_Templates" src="http://blogs.vmware.com/security/files/2013/02/CIS_Rule_Groups_and_Templates1.png" alt="" width="591" height="484" /></a></p>
<p><small><strong>DISA Rule Groups and Templates</strong></small><br />
<a href="http://blogs.vmware.com/security/files/2013/02/DISA_Rule_Groups_and_Templates2.png"><img class="alignnone size-full wp-image-655" title="DISA_Rule_Groups_and_Templates" src="http://blogs.vmware.com/security/files/2013/02/DISA_Rule_Groups_and_Templates2.png" alt="" width="611" height="509" /></a></p>
<p><small><strong>Dashboard View 1</strong></small><br />
<a href="http://blogs.vmware.com/security/files/2013/02/Dashboard-11.png"><img class="alignnone size-full wp-image-658" title="Dashboard 1" src="http://blogs.vmware.com/security/files/2013/02/Dashboard-11.png" alt="" width="944" height="714" /></a></p>
<p><small><strong>Dashboard View 2</strong></small><br />
<a href="http://blogs.vmware.com/security/files/2013/02/Dashboard-23.png"><img class="alignnone size-full wp-image-659" title="Dashboard 2" src="http://blogs.vmware.com/security/files/2013/02/Dashboard-23.png" alt="" width="681" height="596" /></a></p>
<p><small><strong>Detailed Compliance Assessment Results</strong></small><br />
<a href="http://blogs.vmware.com/security/files/2013/02/Template-Results.png"><img class="alignnone size-large wp-image-651" title="Template Results" src="http://blogs.vmware.com/security/files/2013/02/Template-Results-1024x507.png" alt="" width="584" height="289" /></a></p>
<p><strong>Stay tuned, DISA <a title="Compliance Checkers" href="https://my.vmware.com/web/vmware/evalcenter?p=compliance-chk&amp;lp=default" target="_blank">Compliance Checker </a>for Windows and Linux is coming soon!</strong></p>
<p>Thanks and regards,<br />
<strong>Pravin Goyal</strong><br />
<small><strong>RHCE | HP-UX CSA | VCP | MBA | CISSP | GISP | CCSK | CloudU | CompTIA CE | ITIL-F | ITSM-F</strong></small></p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.vmware.com/security/2013/02/cis-and-disa-cpc-toolkit-update.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Patch Tuesday Overview – February 2013</title>
		<link>http://blogs.vmware.com/security/2013/02/patch-tuesday-overview-february-2013.html</link>
		<comments>http://blogs.vmware.com/security/2013/02/patch-tuesday-overview-february-2013.html#comments</comments>
		<pubDate>Fri, 15 Feb 2013 19:23:48 +0000</pubDate>
		<dc:creator>Aravind Kolipakkam</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Patch]]></category>
		<category><![CDATA[Patch Management]]></category>
		<category><![CDATA[Patch Tuesday]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[VCM Content]]></category>
		<category><![CDATA[VMware CP&C]]></category>

		<guid isPermaLink="false">http://blogs.vmware.com/security/?p=600</guid>
		<description><![CDATA[For this month&#8217;s Patch Tuesday Microsoft released 12 bulletins of which five were rated as Critical and seven as Important updates, addressing a total of 57 vulnerabilities across Internet Explorer, .NET Framework, Office, Windows and Exchange Server. For those who &#8230; <a href="http://blogs.vmware.com/security/2013/02/patch-tuesday-overview-february-2013.html">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>For this month&#8217;s Patch Tuesday Microsoft released 12 bulletins of which five were rated as Critical and seven as Important updates, addressing a total of 57 vulnerabilities across Internet Explorer, .NET Framework, Office, Windows and Exchange Server.</p>
<p>For those who need to prioritize deployments, there are 3 security bulletins that will need to be addressed right away.</p>
<p><a href="http://technet.microsoft.com/en-us/security/bulletin/ms13-009"><strong>MS13-009</strong></a> addresses 13 issues across all supported versions of Internet Explorer and <a href="http://technet.microsoft.com/en-us/security/bulletin/ms13-010"><strong>MS13-010</strong></a> addresses issues in the Vector Markup Language (VML) which is used by all versions of Internet Explorer. Both of these issues could allow Remote Code Execution if a user viewed a specially crafted webpage using Internet Explorer.</p>
<p><a href="http://technet.microsoft.com/en-us/security/bulletin/ms13-020"><strong>MS13-020</strong></a> affecting Windows XP resolves an issue in Microsoft Windows Object Linking and Embedding (OLE) Automation which could allow Remote Code Execution if a user opens a malicious RTF file with an embedded ActiveX control in either Word or WordPad.</p>
<p>In addition to the above mentioned bulletins, for the second time in less than a week, both Microsoft and Adobe released Critical-class bulletins (<a href="http://support.microsoft.com/kb/2805940"><strong>KB2805940</strong></a> and <a href="http://www.adobe.com/support/security/bulletins/apsb13-05.html"><strong>APSB13-05</strong></a>) to update Flash Players. These updates address at least 16 distinct vulnerabilities including buffer overflow and use-after-free vulnerabilities that could lead to Code Execution.</p>
<p>All the above mentioned bulletins are now available for deployment via <a href="http://www.vmware.com/products/configuration-manager/overview.html"><strong>VMware vCenter Configuration Manager</strong></a> (VCM).</p>
<p>Aravind Kolipakkam<br />
Sr. Member of Technical Staff, VMware Center for Policy &amp; Compliance</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.vmware.com/security/2013/02/patch-tuesday-overview-february-2013.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>VMware CP&amp;C releases VMware vSphere 5.0 Hardening Guide Dec 2012 (v1.2) Compliance toolkit in VCM!</title>
		<link>http://blogs.vmware.com/security/2013/02/vmware-cpc-releases-vmware-vsphere-5-0-hardening-guide-dec-2012-v1-2-compliance-toolkit-in-vcm.html</link>
		<comments>http://blogs.vmware.com/security/2013/02/vmware-cpc-releases-vmware-vsphere-5-0-hardening-guide-dec-2012-v1-2-compliance-toolkit-in-vcm.html#comments</comments>
		<pubDate>Fri, 15 Feb 2013 01:41:17 +0000</pubDate>
		<dc:creator>Pravin Goyal</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[VCM Content]]></category>
		<category><![CDATA[virtualization security]]></category>
		<category><![CDATA[vSphere 5.0 Hardening Guidelines]]></category>

		<guid isPermaLink="false">http://blogs.vmware.com/security/?p=551</guid>
		<description><![CDATA[The VMware Center for Policy &#38; Compliance (CP&#38;C) is pleased to announce the release of VMware vSphere 5.0 Hardening Guide Dec 2012 (v1.2) Compliance toolkit in VMware vCenter Configuration Manager (VCM), a key component in the VMware vCenter Operations Suite. &#8230; <a href="http://blogs.vmware.com/security/2013/02/vmware-cpc-releases-vmware-vsphere-5-0-hardening-guide-dec-2012-v1-2-compliance-toolkit-in-vcm.html">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>The VMware Center for Policy &amp; Compliance (CP&amp;C) is pleased to announce the release of <a title="VMware vSphere 5.0 Hardening Guide v1.2" href="https://www.vmware.com/files/xls/security/HardeningGuide-vSphere50-v1.2.xlsx" target="_blank">VMware vSphere 5.0 Hardening Guide Dec 2012 (v1.2)</a> Compliance toolkit in VMware vCenter Configuration Manager (<a title="VMware vCenter Configuration Manager" href="http://www.vmware.com/products/configuration-manager/overview.html" target="_blank">VCM</a>), a key component in the VMware vCenter Operations Suite. (vC Ops).</p>
<p>The highlights of this release are as below:</p>
<ol>
<li>Package aligned with the latest version of VMware vSphere 5.0 Hardening Guide i.e. v1.2 released in Dec 2012</li>
<li>The package now comes in 4 versions:</li>
</ol>
<blockquote>
<ul>
<li>Full &#8211; Has all recommendations present in the hardening guide</li>
<li>Profile 1 &#8211; Has only Profile 1 recommendations</li>
<li>Profile 2 &#8211; Has only Profile 2 recommendations</li>
<li>Profile 3 &#8211; Has only Profile 3 recommendations</li>
</ul>
</blockquote>
<p><span id="more-551"></span>Now pick the packages based on the profile you are wanting to adhere to!</p>
<p>You can download the packages using vCM Content Wizard and begin to use it.</p>
<p><strong>With the updated vSphere 5.0 hardening content in vCM, our customers will be able to get great dashboard to track their Compliance posture:</strong></p>
<p><strong><a href="http://blogs.vmware.com/security/files/2013/02/Dashboard4.png"><img class="aligncenter size-medium wp-image-574" title="Dashboard" src="http://blogs.vmware.com/security/files/2013/02/Dashboard4-300x193.png" alt="" width="300" height="193" /></a></strong></p>
<p><strong>You can also break down the compliance results by data type to see where most of your infractions are coming from:</strong></p>
<p><strong><a href="http://blogs.vmware.com/security/files/2013/02/Data-Class3.png"><img class="aligncenter size-medium wp-image-575" title="Data Class" src="http://blogs.vmware.com/security/files/2013/02/Data-Class3-300x218.png" alt="" width="300" height="218" /></a></strong></p>
<p><strong><strong><a href="http://blogs.vmware.com/security/files/2013/02/By-Source1.png"><img class="aligncenter size-medium wp-image-578" title="By Source" src="http://blogs.vmware.com/security/files/2013/02/By-Source1-300x70.png" alt="" width="300" height="70" /></a></strong></strong></p>
<p><strong><strong>From there, you can see the individual rules behind the content that is surfaced in our dashboards. </strong></strong><strong></strong> <a href="http://blogs.vmware.com/security/files/2013/02/Rules.png"><img class="aligncenter size-medium wp-image-579" title="Rules" src="http://blogs.vmware.com/security/files/2013/02/Rules-300x115.png" alt="" width="300" height="115" /></a></p>
<p><strong>In this release we provided 20 Rule groups, 8 templates and 15 collection filters.</strong></p>
<p><a href="http://blogs.vmware.com/security/files/2013/02/Rule-Groups.png"><img class="aligncenter size-medium wp-image-582" title="Rule Groups" src="http://blogs.vmware.com/security/files/2013/02/Rule-Groups-215x300.png" alt="" width="215" height="300" /></a> <a href="http://blogs.vmware.com/security/files/2013/02/Templates.png"><img class="aligncenter size-medium wp-image-583" title="Templates" src="http://blogs.vmware.com/security/files/2013/02/Templates-300x267.png" alt="" width="300" height="267" /></a></p>
<p><a href="http://blogs.vmware.com/security/files/2013/02/Collection-Filters.png"><img class="aligncenter size-medium wp-image-584" title="Collection Filters" src="http://blogs.vmware.com/security/files/2013/02/Collection-Filters-300x124.png" alt="" width="300" height="124" /></a></p>
<p><a href="http://blogs.vmware.com/security/files/2013/02/Sample-Rules.png"><img class="aligncenter size-medium wp-image-585" title="Sample Rules" src="http://blogs.vmware.com/security/files/2013/02/Sample-Rules-300x120.png" alt="" width="300" height="120" /></a></p>
<p>Keep in mind that vCM manages not only virtual environments, but covers physical as well. It is the market leader in Configuration Audit, Change Detection, Patch Management and COMPLIANCE content. Yes! That is right, we can also remediate non compliant results with a right click in both the virtual and physical world!</p>
<p>Also, don&#8217;t forget about the <a href="https://my.vmware.com/web/vmware/evalcenter?p=compliance-chk&amp;lp=default" target="_blank">VMware CP&amp;C FREE compliance checkers</a>!</p>
<p>Thanks and regards,<br />
<strong>Pravin Goyal</strong><br />
<strong><small>RHCE | HP-UX CSA | VCP | MBA | CISSP | GISP | CCSK | CloudU | CompTIA CE | ITIL-F | ITSM-F</small></strong></p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.vmware.com/security/2013/02/vmware-cpc-releases-vmware-vsphere-5-0-hardening-guide-dec-2012-v1-2-compliance-toolkit-in-vcm.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>vSphere 5.1 Hardening Guide **DRAFT** now available</title>
		<link>http://blogs.vmware.com/security/2013/02/vsphere-5-1-hardening-guide-draft-now-available.html</link>
		<comments>http://blogs.vmware.com/security/2013/02/vsphere-5-1-hardening-guide-draft-now-available.html#comments</comments>
		<pubDate>Mon, 11 Feb 2013 22:02:28 +0000</pubDate>
		<dc:creator>Mike Foley</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blogs.vmware.com/security/?p=540</guid>
		<description><![CDATA[Hello? Is this thing on? A brief intro for those that don&#8217;t know me and my new role. My name is Mike Foley. I&#8217;m a Sr. Technical Marketing Manager, working for Charu Chaubal in VMware&#8217;s Technical Marketing group. My primary &#8230; <a href="http://blogs.vmware.com/security/2013/02/vsphere-5-1-hardening-guide-draft-now-available.html">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Hello? Is this thing on?</p>
<p>A brief intro for those that don&#8217;t know me and my new role. My name is Mike Foley. I&#8217;m a Sr. Technical Marketing Manager, working for Charu Chaubal in VMware&#8217;s Technical Marketing group. My primary role is that of technical marketing support for security of the core vSphere platform. I come from RSA, where I was their virtualization evangelist/go-to guy for many years. My personal blog is at <a href="http://yelof.com" target="_blank">http://yelof.com</a> and I&#8217;m on Twitter as <a href="http://www.twitter.com/mikefoley" target="_blank">@mikefoley</a>.</p>
<p>I would like to announce the **draft** release of the vSphere 5.1 Security Hardening Guide.  This initial draft release has taken the 5.0 guide and updated it for 5.1. What it does NOT contain at this time is a complete review of functionality around the new 5.1 SSO capabilities. We are working on those parts and hope to have an updated draft very soon.</p>
<p>We&#8217;d love to hear your feedback, good and bad, on the contents of the guide. I would encourage you to post your reply in the <a href="http://communities.vmware.com/community/vmtn/server/security" target="_blank">Security and Compliance Communities forum </a>but if you have more sensitive concerns, send it to me at mfoley@vmware.com.</p>
<p>The <a href="http://communities.vmware.com/docs/DOC-21732">vSphere 5.1 Security Hardening Guide</a> has been posted to the VMware Communities in the &#8220;<a href="http://communities.vmware.com/community/vmtn/general/security" target="_self">Security and Compliance</a>” area, in the Documents tab.  Thanks to everyone who provided feedback on the Public Draft, and also to the team at VMware who contributed to this guide in many significant ways.</p>
<p>Thanks,<br />
mike foley</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.vmware.com/security/2013/02/vsphere-5-1-hardening-guide-draft-now-available.html/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>A New Year and New VMware vShield Protection: Symantec Endpoint Protection</title>
		<link>http://blogs.vmware.com/security/2013/01/a-new-year-and-new-vmware-vshield-protection-symantec-endpoint-protection.html</link>
		<comments>http://blogs.vmware.com/security/2013/01/a-new-year-and-new-vmware-vshield-protection-symantec-endpoint-protection.html#comments</comments>
		<pubDate>Thu, 10 Jan 2013 18:08:24 +0000</pubDate>
		<dc:creator>Rob Randell</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blogs.vmware.com/security/?p=530</guid>
		<description><![CDATA[Written by Jeremiah Cornelius - Security Architect &#8211; VMware Global Strategic Alliances VMware vShield Endpoint enables Symantec Endpoint Protection 12 &#8211; offloading anti-virus and anti-malware agent processing to a dedicated secure virtual appliance &#8211; streamlining deployment and monitoring for your VMware &#8230; <a href="http://blogs.vmware.com/security/2013/01/a-new-year-and-new-vmware-vshield-protection-symantec-endpoint-protection.html">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Written by Jeremiah Cornelius - Security Architect &#8211; VMware Global Strategic Alliances</p>
<p><em>VMware vShield Endpoint enables Symantec Endpoint Protection 12 &#8211; offloading anti-virus and anti-malware agent processing to a dedicated secure virtual appliance &#8211; streamlining deployment and monitoring for your VMware environment.<strong></strong></em></p>
<p>One year ago, there was really only a single option available if a VMware customer wished to use the <a href="http://www.vmware.com/products/datacenter-virtualization/vsphere/endpoint.html">vShield Endpoint</a> introspection possible on vSphere to protect servers or virtual desktops.  As 2013 begins, the number of partner solutions has grown to a half-dozen and continues to grow. It’s probably an understatement to call the latest of these, “much anticipated”.  The introduction I’m referring to is Symantec’s <a href="http://www.symantec.com/endpoint-protection?inid=us_ghp_hero1_sep-vmware">Endpoint Protection 12.1.2</a>. With the mid-December availability of Symantec’s entry to the field of virtual guest protection, we welcome a new year.</p>
<p>Symantec has been working with the VMware vCloud Security team for several years. Now, I’m glad to see that our shared customers can begin to enjoy the rewards of our strategic alliance.</p>
<p>“We collaborated closely with Symantec so that VMware vShield Endpoint and Symantec Endpoint Protection 12 will work together… our customers need the right security solutions to embrace virtualizing business critical applications and to accelerate cloud adoption.”</p>
<p><strong>Parag Pate</strong>l, vice president, VMware</p>
<p>Symantec support for VMware vSphere and View deployments delivers the opportunity for a unified solution across your entire infrastructure. Managing operations of both physical and virtual endpoints through single, uniform policies and management, <a href="http://kb.vmware.com/selfservice/microsites/search.do?cmd=displayKC&amp;docType=kc&amp;externalId=2039762&amp;sliceId=1&amp;docTypeID=DT_KB_1_1&amp;dialogID=522362062&amp;stateId=1%200%20522360587">Symantec Endpoint Protection coupled with vShield Endpoint</a> – can now improve virtualization consolidation ratios, and prevent anti-virus storms in the software-defined data center, along with the traditional protection, already relied upon. I’m also glad that the new Symantec Endpoint Protection release continues offering improvement in the detection engine and behavior-based blocking of “zero day” attacks. Technologies like Insight and SONAR allow reduction of anti-virus scans and maximum performance. Effort has been also made to simplify your deployment and updating while improving the quality of reporting.</p>
<p>The additional benefit I’d like to share with customers for coupling Symantec’s protections with vShield Endpoint is the additional layer for defense in depth &#8211; agent-less and directly from the VMware Cloud infrastructure, without further guest configuration. This improves your overall security posture and compliance for the growing number of virtual machines deployed in testing, development, and private cloud deployments.</p>
<p>We also made it easier to <a href="http://kb.vmware.com/kb/2036875">acquire the vShield Endpoint</a> part of this. Recognizing the value of ensuring security and compliance audit requirements for the expanding roles of virtualization and private clouds, VMware customers with valid Support and Subscription (SnS) contracts for vSphere Essentials Plus or higher editions are now entitled to vShield Endpoint functionality at no extra cost. This means that vShield Endpoint is now licensed with vSphere, and better positioned to deliver you these benefits with Symantec Endpoint Protection today.</p>
<p>Symantec has additional security solutions that work with VMware vShield and vCloud Networking and Security to create a broad set of solutions for VMware customers, to provide:</p>
<ul>
<li><span style="text-decoration: underline;">Optimized Endpoint Protection for High-density Virtual Environments</span></li>
<li><span style="text-decoration: underline;">Orchestrated Data Loss Prevention</span></li>
<li><span style="text-decoration: underline;">Compliance Across Converged Infrastructure</span></li>
<li><span style="text-decoration: underline;">Protection for Virtual Data Centers Against Advanced Threats</span></li>
<li><span style="text-decoration: underline;">Integrated Threat Intelligence</span></li>
</ul>
<p>There’s more details and information on these protections, including whitepapers and solutions briefs at – <a href="https://solutionexchange.vmware.com/store/search?utf8=%E2%9C%93&amp;search%5Bq%5D=symantec">VMware Solutions Exchange</a> and <a href="http://www.symantec.com/partners/programs/globalstrategic/gsp.jsp?id=vmware">Symantec Partner: VMware</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.vmware.com/security/2013/01/a-new-year-and-new-vmware-vshield-protection-symantec-endpoint-protection.html/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss><!-- Dynamic page generated in 0.187 seconds. --><!-- Cached page generated by WP-Super-Cache on 2013-05-09 13:38:59 -->
