Skip to main content
Guidance

Secure design principles

Guides for the design of cyber secure systems

Page 8 of 17

Virtualisation security design principles

These principles focus on virtualisation technologies which may be used in the cloud, on servers deployed on-premise, or on end user devices.

The principles are a subset of the Cyber security design principles, extending them to help you think through the security considerations when designing systems that use virtualisation.





  • 1. Establish the context Before you start designing your virtualised system, you should first understand what business operations it will support, the risks it will face and the impact of its compromise.
  • 2. Make compromise difficult Design with security in mind at each layer of the virtualised system.
  • 3. Make disruption difficult

    Virtualisation has a number of features which can be used to help avoid disruption and improve availability. However, if a system is not designed correctly, virtualisation can become a single point of failure and reduce resilience.

  • 4. Make compromise detection easier The design should include the ability to detect attacks and compromises. This will enable you to respond promptly to both attempted and successful compromises, introducing additional security controls where necessary as part of the ongoing lifecycle of your system.
  • 5. Reduce the impact of compromise Features such as replication, snapshots, and high availability can be used to speed system recovery, giving virtual systems an edge over traditional infrastructure. When designing a system, you should take advantage of these strengths wherever possible.

Reviewed

Version

1.0