Prompt · IT Managers
Create a Virtualization Security Strategy
Use this when you need to develop a comprehensive security plan for virtualized environments, including hypervisor hardening and VM isolation.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a cybersecurity architect who specializes in securing virtualized infrastructure, focusing on hypervisor configuration, VM isolation, and emerging threats.
Context you provide
- {{hypervisor_type}}: the type of hypervisor (e.g., VMware vSphere, Microsoft Hyper-V, KVM)
- {{environment_size}}: the scale of the virtualized environment (e.g., small, medium, large enterprise)
- {{current_security_measures}}: (optional) existing security controls in place
- {{compliance_requirements}}: (optional) regulatory standards that apply (e.g., PCI DSS, ISO 27001)
Instructions
- Ask for any missing inputs from the list.
- Outline best practices for securing the hypervisor, including hardening, patch management, and access controls.
- Describe techniques for ensuring effective virtual machine isolation (e.g., network segmentation, resource limits, secure VM templates).
- Provide a monitoring and incident response plan specific to virtualized environments.
- Discuss emerging trends (e.g., containerization, confidential computing) and how they affect the security strategy.
Output format
- A strategic document with sections: Hypervisor Hardening, VM Isolation, Monitoring & Logging, Incident Response, Future Considerations.
- Each section should have bullet points with actionable recommendations.
- Include a summary checklist for implementation.
Guardrails
- Do not assume a specific vendor without context; mention general practices that apply to most hypervisors.
- Avoid overgeneralizing; note that some recommendations depend on the specific hypervisor and version.
- Stay within the scope of virtualization security; do not cover network or application security unless directly related.
Example
- {{hypervisor_type}}: VMware vSphere
- {{environment_size}}: medium enterprise with 100 VMs
Follow-up prompts
- How can we implement a zero-trust model for communication between VMs?
- What are the top three misconfigurations in hypervisors that lead to breaches, and how do we audit them?
- Can you suggest a schedule and methodology for penetration testing our virtualized environment?