More and more legal regulations require the implementation of “state of the art” cybersecurity. These include the NIS 2 regulation that recently came into force, the GDPR, and the requirements of DIN ISO 27001. This also includes smaller companies and more industries.
With end-to-end encryption of all VMware VMs, testing steps are no longer required and process descriptions in the context of protection profiles and risk analyses can be significantly reduced.
Protection of critical data
With the encryption service, all sensitive data on the VMware VM are protected:
- Database, file system and source code repository are automatically encrypted.
- Locally stored access data (e.g., for database access, SSH keys, etc.) are protected.
- Log files (e.g., from applications) and personal data for system logins, transactions, and IP addresses are encrypted at all times.
vSAN-Protection & TPM
Besides encrypting VMs, VMware also offers the option of protecting so-called vSANs (virtual Storage Attached Network) with the same method. Additionally, applications and operating systems for which TPMs (Trusted Platform Module) are required (e.g., Microsoft Windows 11) can be virtualized without any problems with this method.
Encryption of data in any operating mode
During storage, operation, and access, data on the VMs remain encrypted. This provides comprehensive security and saves additional costs for encryption.
- Security at rest
When the storage medium on which the encrypted VM is located is accessed, the data cannot be read. This explicitly also applies to databases running on the VM. Expensive database encryption is no longer necessary. - Security at work
Protection is also provided while the VM is running. - Security in transit
During transfer from the storage location to the hypervisor / ESXi host, the VM’s data is also protected.
Highly secure key storage
The Key Encryption Key (KEK) is stored externally in a KMS for each VM and protected via FIPS-certified Hardware Security Modules. This logically separates the storage locations of the VM and the key.