April | 2021

A secure VDI environment demands periodic risk assessment, maintaining the controls, and a strong action plan to mitigate the impact of identified risks. 
How to Keep Your Virtual Desktop Environment Secure
How to Keep Your Virtual Desktop Environment Secure
How to Keep Your Virtual Desktop Environment Secure

Focus Area

NIST 800-53 Control Family

Key Risk

Key Controls

Process

Configuration Management

Misconfiguration resulting in inadequate capacity causing availability issues

Configuration management policy and procedures,  access control, configuration change control

Technology

Configuration Management

Misconfigured systems could be exploited by malicious players to cause security breaches

Baseline configuration and configuration change control

People

Awareness and Training

Standards not followed hence allowed insecure application to get provisioned

Security awareness and training, policy and procedures

Process

Maintenance

Missing some servers on manual check of server reboot will impact business

System maintenance policy and procedures

Asset

Asset Criticality Rating

Threat

Vulnerability

Control

Business Impact

Likelihood

Risk Rating

Risk

Risk Recommendation

VWS

High

Hacker introducing malware

Insecure system configurations

Standard image guidelines with hardening

High

Medium

High

Security breach resulting in unavailability of systems

Baseline configuration and configuration change control

VWS

High

System failure

Mis-provisioned VMs to critical user

Training for administrators

High

Medium

High

Critical user has incorrect VMs resulting in business impact

Security awareness and training, policy and procedures

About the Author