Page 901 - (ISC)² CISSP Certified Information Systems Security Professional Official Study Guide
P. 901
The term virtual desktop refers to at least three different types of
technology:
A remote access tool that grants the user access to a distant
computer system by allowing remote viewing and control of the
distant desktop’s display, keyboard, mouse, and so on.
An extension of the virtual application concept encapsulating
multiple applications and some form of “desktop” or shell for
portability or cross-OS operation. This technology offers some of
the features/benefits/applications of one platform to users of
another without the need for multiple computers, dual-booting, or
virtualizing an entire OS platform.
An extended or expanded desktop larger than the display being
used allows the user to employ multiple application layouts,
switching between them using keystrokes or mouse movements.
See Chapter 8, “Principles of Security Models, Design, and
Capabilities,” and Chapter 9, “Security Vulnerabilities, Threats, and
Countermeasures,” for more information on virtualization as part of
security architecture and design.
Virtual Networking
The concept of OS virtualization has given rise to other virtualization
topics, such as virtualized networks. A virtualized network or network
virtualization is the combination of hardware and software
networking components into a single integrated entity. The resulting
system allows for software control over all network functions:
management, traffic shaping, address assignment, and so on. A single
management console or interface can be used to oversee every aspect
of the network, a task requiring physical presence at each hardware
component in the past. Virtualized networks have become a popular
means of infrastructure deployment and management by corporations
worldwide. They allow organizations to implement or adapt other
interesting network solutions, including software-defined networks,
virtual SANs, guest operating systems, and port isolation.
Software-defined networking (SDN) is a unique approach to network

