
Head of Production Management
The objective for the previous Part 1 and Part 2 were to provide an introduction what we mean by relying on a Secure Core architecture for a TRUE KVM system by introducing 7 hypothesis for evaluating solutions.
These are
In Part 1 and 2, we addressed the first 3 and in this Part 3, we are going to continue to evaluate the next 2 hypothesis relevant for a secure operation of KVM systems.
Addressing Hypothesis 4 and 5
Whether you are entrusted with the well-being of the population of your country or the seamless operation of the production plant, it is wise to carefully assess your needs in terms of network security and the operational implications. ISO27000 attempts to provide a step by step process to help IT teams managing the mission critical infrastructure of a company. It is also expected that ISO27000 will become for critical infrastructure what ISO9000 was for the commercial businesses.
“The world is being divided into those who know they are being hacked and those who don´t. However, everybody is subject to being hacked.” Once you acknowledge this inescapable truth I learnt during the presentation of a datacenter manager several years ago, you know you have to take the necessary precautions to shield your system against hacking exploiting unidentified operating system loopholes sold on the darknet.
As mentioned above, take a step back and look at the security challenge holistically. Saving cost becomes irrelevant in the situation of a catastrophic failure. The guiding principle should be the definition of adequate protection first and then going into the details. Many penetrations occur based on human error and ill-guided attempts of users to take workflow shortcuts to save time. The following diagram is terribly complicated, I agree. But it offers a checklist and a framework to assess risks and implement measures to mitigate them. It is not only applicable to KVM infrastructure but serves as a blueprint for all operational networks connected to the internet. Many technical conclusions render separated cable networks and infrastructure components as the only viable solution to effectively protect assets and the integrity of the operation or mission.
Network protection is not only a technical effort. It involves regulation, procedures, training and an increased awareness of everyone in the company or operation for potential intrusion opportunities. It permeates all areas and levels and requires that everyone participates actively in the protection and enforcement of security.
If you would like to discuss TRUE KVM with me in more detail, please leave a comment, send me a message or contact our technical support or sales teams at an IHSE office near you. We are here to help you get the most out of your KVM system.
Yours
Mark Hempel