It covers hypervisors, host systems, guest operating systems, virtual networks and storage, images, snapshots, migration, device passthrough, and management interfaces. Its central concern is preserving isolation and controlled resource sharing among workloads and between guests and the host.
The hypervisor mediates processor, memory, device, storage, and network access, making its management plane highly privileged. An organization may operate these layers or inherit host and hypervisor controls from a provider; each guest still needs customer-managed controls. Inventories must include powered-off machines, templates, snapshots containing secrets, cloned identities, and migrated workloads.
Key points
Management planeSeparate and strongly authenticate administration, apply least privilege, protect automation and images, restrict exposed interfaces, monitor important changes, and maintain tested recovery.
Isolation and resourcesMinimize device and host access, control virtual networks, validate passthrough and shared services, and prevent one workload from exhausting resources needed by others.
LifecycleHarden hosts and guests, maintain supported software, govern templates, snapshots, clones, migration, backup, and disposal, and preserve unique identities and current controls after restoration.
Important limitationA virtual machine is not a physical security boundary. Hypervisor, firmware, management-plane, or host compromise can affect many guests, while vulnerable guest software and unsafe virtual networking remain risks. Snapshots and rapid cloning can reproduce outdated software, credentials, identifiers, and misconfigurations.