SHARE
Facebook X Pinterest WhatsApp

Can Virtualization Help (or Hurt) Compliance?

Virtualization is seen as a major cost saver, yet does it make compliance (generally seen as a major headache) still harder? Can a virtualized environment be compatible with regulatory compliance? It’s question rarely raised, but one that’s important to address because non-compliance can be serious — not to mention costly. In October last year the […]

Written By
thumbnail Paul Rubens
Paul Rubens
Jun 23, 2011
Datamation content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Virtualization is seen as a major cost saver, yet does it make compliance (generally seen as a major headache) still harder?

Can a virtualized environment be compatible with regulatory compliance? It’s question rarely raised, but one that’s important to address because non-compliance can be serious — not to mention costly.

In October last year the PCI Security Standards Council (PCI SSC) published the PCI Data Security Standard (PCI DSS) v2.0, and for the first time it was explicitly stated that you could use virtualization technologies and be PCI-DSS compliant. Before that it was up to the auditor to decide if server virtualization — or any other form of virtualization for that matter — was acceptable at all, and conservative ones could simply rule it out.

But saying you can use virtualization really opens a can of worms. A recent Ponemon Institute study found that PCI-DSS is widely regarded as a higher priority than all other regulations including HIPAA, the EU Privacy Directive, Sarbanes-Oxley and United States state laws for data breach, as well as the most difficult set of regulations to comply with. Given how hard it is to be in compliance with PCI-DSS at the best of times, what chance do organizations really have of getting auditors to sign them off as being compliant with a virtualized infrastructure?

The good news is that help is at hand in the form of 39 pages of PCI DSS Virtualization Guidelines, published earlier this month by the Virtualization Special Interest Group of the PCI SSC.

Read the rest about compliance and virtualization at ServerWatch.

  SEE ALL
DATA CENTER ARTICLES
 
thumbnail Paul Rubens

Paul Rubens is a technology journalist based in England and is a Datamtion and eSecurity Planet contributor.

Recommended for you...

4 Data Virtualization Benefits: Redefining Data Accessibility
Anina Ot
Apr 25, 2024
What Is Data Analysis? Ultimate Guide (+ Real-World Examples)
Kaye Timonera
Feb 19, 2024
What Is Qualitative Data? Characteristics & Examples
Kaye Timonera
Jan 23, 2024
What Is Quantitative Data? Characteristics & Examples
Kaye Timonera
Jan 12, 2024
Datamation Logo

Datamation is the leading industry resource for B2B data professionals and technology buyers. Datamation's focus is on providing insight into the latest trends and innovation in AI, data security, big data, and more, along with in-depth product recommendations and comparisons. More than 1.7M users gain insight and guidance from Datamation every year.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.