ISACA Harrisburg Chapter - ISACA - Information Systems Audit & Control Association ISACA Harrisburg Chapter - ISACA - Information Systems Audit & Control Association
Main Menu
Home
About ISACA
Vision Statement
Chapter Awards
Membership
Certification
Career Opportunities
Bylaws
Policies
Chapter Board
Library Materials
Links
Send us an e-mail
Training Summary
2008-2009
2007-2008
2006-2007
2005-2006
ISACA Links
ISACA International
Global Knowledge Network (K-NET)
ISACA International Member Benefits
Join ISACA
ISACA Bookstore
ISACA Career Centre
New CRISC Certification
ISACA Harrisburg Event Anncouncements
 
September Program, Please Join Us for this Event
 
Audit and Security of Virtual Machines
Date: September 21, 2010
Presenter: John Tannahill, CA, CISM, CGEIT
CPEs: 8
Location: Homewood Suites Harrisburg East
3990 TecPort Drive
Harrisburg, PA 17111
Member Cost: $250*
Non-Member Cost: $350*
Registration: 7:45 - 8:00
Presentation: 8:00 - 4:30
Continental Breakfast & Lunch Provided Register by Friday September 17, 2010

About the Presenter - John G. Tannahill, CA, CISM, CGEIT

John Tannahill is an independent Information Security and Audit Services Consultant. John's current consulting work areas are focused on information security in large information systems environments and networks. Particular areas of technical security expertise include: Windows 2003/2008; Unix (including Solaris, AIX & Linux); Oracle, Microsoft SQL Server, DB2 & Network and Internet security.

John is a frequent speaker in Canada, USA and Europe on the subject of Information Security.


Seminar Highlights

This seminar will focus on the audit and security issues related to the use of Virtual Machine environments.

  • Detailed discussion of VMware Virtual Machine architecture and security components (VMware vSphere)
  • Detailed discussion of VMware ESX Server & VMware vCenter security and control features

Agenda - What You Will Learn.

1. VM Concepts

  • Virtual Machine Concepts
  • Hypervisors
  • VMware ESX Server Overview
  • VMware vCenter and Virtual Center Overview
  • Security Architecture and Design Issues
  • Audit & Control Objectives
  • Threats & Vulnerabilities
  • VMware vSphere4

2. VMware ESX Server Audit

  • Audit Objectives and Checklists for the ESX Server and vCenter Environments
  • Security Configuration Standards
  • Configuration and Patch Management
  • Security Management
  • Service Console Security Configuration
  • Host Level Management Security
  • User Account Controls (e.g. ssh; sudo)
  • Controlling Administrator Access
  • Directory & File Permissions
  • Logging & Monitoring
  • VM Files and Settings
  • Guest VM Configuration
  • Guest to Host Isolation Controls
  • Network and Firewall Security

3. VMware vCenter Audit

  • Architecture & Design
  • Auditing Management Server Configuration and Components
  • Inventory Control Areas
  • Virtual Center Users
  • Controls over Administrative Users (Data Center Administrator, VM Administrator etc.)
  • Roles (e.g. System and Sample Roles) and Objects
  • Permissions and Permission Privileges Group Management
  • Security Monitoring

4. Cloud Computing

  • Concepts Overview
  • Security and Control Issues

5. Security and Audit Tools & Techniques

  • Audit Tools & Scripts

Note: session will include discussion of other VM Technologies in the Concepts session, including:

  • Microsoft Hyper-V
  • Citrix XEN Server
  • Solaris Containers
  • Linux VM
  • Microsoft Virtual Server & PC
  • VirtualBox
  • VMware ESXi server; Player; Workstation
  • VMware vSphere4

*No shows will be billed
Upcoming Events
 
Audit and Security of Virtual Machines
September 21, 2010
Homewood Suites Harrisburg East
John Tannahill, CA, CISM, CGEIT
Members: $250Non: $350
CPE's: 8More Info
Previous Events
 
Data Loss Prevention
 
Integrating COBIT into your IT Audit Process and Organization
 
Safeguarding Citizen Data
 
Auditing UNIX
 
Philadelphia ISACA Chapter 2010 Spring 5-Day Training Conference
 
Topic: Fraud
 
Annual Meeting
 
 
Monthly Online Learning Opportunities: ISACA e-Symposium - Click Here

ISACA-Harrisburg P. O. Box 482, Camp Hill, PA 17001
 
The Harrisburg Chapter is a not-for-profit organization dedicated to supporting information systems audit, control, and security practitioners through a commitment to education, certification, and professional standards. The Harrisburg Chapter is a not-for-profit organization dedicated to supporting information systems audit, control, and security practitioners through a commitment to education, certification, and professional standards. Our chapter is part of a worldwide association of more than 26,000 professionals in more than 100 countries.

As it is one of the objectives of the ISACA to be a forum for the free expression and interchange of ideas, statements of position or expression of opinion appearing herein are those of the authors, and not by fact of publication those of the Harrisburg Chapter. Likewise, the publication of any advertisement is not to be construed as an endorsement of the product or service being offered unless it is specifically stated in the advertisement.