7.1. Standards7.1.1. Jericho Forum7.1.2. The Distributed Management Task Force (DMTF)7.1.2.1. The DMTF Open Virtualization Format (OVF)7.1.2.2. The DMTF Open Cloud Standards Incubator7.1.3. The International Organization for Standardization (ISO)7.1.3.1. ISO 270017.1.3.2. ISO 270027.1.3.3. ISO 270037.1.3.4. ISO 270047.1.3.5. ISO 270057.1.3.6. ISO 270067.1.3.7. International Organization for Standardization/International Electrotechnical Commission ISO/IEC 29361, ISO/IEC 29362, and ISO/IEC 29363 Standards7.1.3.8. Distributed Application Platforms and Services7.1.4. The European Telecommunications Standards Institute (ETSI)7.1.5. The Organization for the Advancement of Structured Information Standards (OASIS)7.1.6. Storage Networking Industry Association (SNIA)7.1.7. Open Grid Forum (OGF)7.1.8. The Open Web Application Security Project (OWASP)7.1.8.1. OWASP Top Ten Project7.1.8.2. OWASP Development Guide7.1.8.3. OWASP Code Review Guide7.1.8.4. OWASP Testing Guide7.2. Incident Response7.2.1. NIST Special Publication 800-617.2.1.1. Preparation7.2.1.2. Detection and Analysis7.2.1.3. Containment, Eradication, and Recovery7.2.1.4. Post-Incident Activity7.2.1.5. NIST Incident-Handling Summary7.2.2. Internet Engineering Task Force Incident-Handling Guidelines7.2.3. Layered Security and IDS7.2.3.1. Intrusion Detection7.2.3.1.1. Network-Based ID7.2.3.1.2. Host-Based ID7.2.3.1.3. Signature-Based ID7.2.3.1.4. Statistical Anomaly-Based ID7.2.3.2. IDS Issues7.2.4. Computer Security and Incident Response Teams7.2.4.1. CERT/CC7.2.4.2. FedCIRC7.2.4.3. Forum of Incident Response and Security Teams7.2.5. Security Incident Notification Process7.2.6. Automated Notice and Recovery Mechanisms7.3. Encryption and Key Management7.3.1. VM Architecture7.3.2. Key Protection Countermeasures7.3.3. Hardware Protection7.3.4. Software-Based Protection7.3.5. Data Deduplication7.3.5.1. Hashing7.4. Retirement7.4.1. VM Life Cycle7.4.1.1. Overwriting7.4.1.2. Degaussing7.4.1.3. Destruction7.4.1.4. Record Retention7.4.1.5. Data Remanence7.4.1.6. Due Care and Due Diligence7.4.1.7. Documentation Control7.5. Summary7.6. Notes