Virtualisation provides significant cost savings
by sharing storage space and central processing
unit (CPU) capacity. As with any technology,
though, virtual IT systems are not risk-proof.
A proper risk mitigation strategy needs to be
developed and followed if organisations are to
harness the benefits of virtualisation technology.
Information security auditors have an important
role to play in auditing the risks of virtual IT
systems. This article discusses virtual IT systems
and the inherent risks that need to be audited for
proper risk mitigation and provides guidelines for
security audits of virtual IT systems that can be
referenced during information security audits and
the application of security to virtual IT systems.