Bringing a virtualization platform into production is one of the highest-risk changes in a data centre. A disciplined set of pre-checks (before go-live) and post-checks (after the hypervisor cluster is up) protects availability, security and service quality — and keeps the rollout aligned with the standards auditors expect. This guide summarises the checks Skyline Cloud applies on every virtualization go-live, mapped to the relevant ISO and industry standards.
Why pre- and post-checks matter
A virtualization layer concentrates many workloads onto shared compute, storage and network. A single missed dependency — an unverified power feed, a non-redundant uplink, an unset HA policy — can take down dozens of services at once. Structured checks turn a risky cut-over into a repeatable, auditable procedure with a clear go/no-go decision and sign-off.
Reference standards
| Standard | Relevance |
|---|---|
| ISO/IEC 27001 / 27017 / 27018 | Information & cloud security, physical access, logging |
| ISO 22301 / ISO/IEC 27031 | Business continuity, high availability, backup and DR (RPO/RTO) |
| ISO/IEC 20000-1 | IT service management — change, configuration, monitoring |
| ANSI/TIA-942 · ISO/IEC 22237 | Data centre facility, power, cooling and redundancy |
| ISO 50001 · ASHRAE TC 9.9 | Energy management and thermal envelope |
| ISO 9001 | Documented procedure, records and sign-off |
Pre-virtualization checks (before go-live)
Complete and sign off these before any production workload is migrated.
- Facility & environmental (TIA-942 / ISO 22237): dual (A/B) power feeds verified; UPS autonomy ≥ design runtime and generator auto-start tested; cooling with N+1 and temperature/humidity within the ASHRAE A1 envelope (18–27 °C); fire suppression and leak detection active.
- Physical security (ISO 27001 A.7): badge/biometric access control, CCTV with ≥ 90-day retention, a current visitor log, and locked racks.
- Network: redundant uplinks verified; firmware at baseline; out-of-band management segmented; firewall default-deny; VLAN/IP plan applied; DNS and NTP reachable.
- Storage: SAN/NAS healthy; multipathing configured; ≥ 20% capacity headroom; redundancy verified and an IOPS/latency baseline captured.
- Compute / hosts: firmware at baseline; hardware virtualization (VT-x/AMD-V, IOMMU) enabled; hardware health green; NTP accurate; an identical "golden" host build across the cluster.
- Security & compliance (ISO 27001 / 27017): CIS hardening applied; patched to baseline; least-privilege admin accounts; MFA enforced; audit logging shipped to a SIEM.
- Backup & DR (ISO 22301 / 27031): backup target reachable; DR replication tested; RPO and RTO documented; restore procedure ready.
- Change & documentation (ISO/IEC 20000): change approved at the CAB; rollback plan and runbook prepared; CMDB updated; maintenance window communicated.
Post-virtualization checks (platform live)
Complete these once the hypervisor/cluster is up, before the platform is released to production.
- Hypervisor & cluster: all hosts joined with no alarms; consistent versions; shared datastores mounted everywhere; CPU-compatibility (EVC) configured.
- High availability & live migration (ISO 22301): HA enabled and a host-failover test passed; admission control set (N+1); load balancing working; live migration verified.
- Virtual machines: clean boot with current guest tools and time sync; no orphaned or inaccessible VMs; reservations per service tier; no contention (CPU-ready < 5%, no ballooning/swap).
- Virtual networking: redundant uplinks and NIC teaming verified; VLANs reachable with no packet loss; management, migration and storage traffic separated.
- Storage (runtime): datastores healthy with no all-paths-down events; multipath optimised and latency under 20 ms; capacity and latency alerts set.
- Security hardening (ISO 27001 / 27017): management interfaces isolated, lockdown mode on, valid TLS certificates, RBAC applied, audit logs shipping to the SIEM.
- Monitoring & alerting (ISO 20000): agents reporting for every host and VM; thresholds and escalation configured; NOC dashboards live; a performance baseline recorded.
- Backup & DR verification (ISO 22301): first full backup completed and a test restore validated; replication healthy and RPO met; snapshot/retention policy applied.
- Performance & acceptance (ISO 9001): benchmark meets baseline; service smoke tests pass; user acceptance obtained; go-live sign-off recorded and documentation archived.
Governance and sign-off
Record each check with a pass/fail result, the responsible engineer and the date, and require sign-off from the infrastructure lead before production release. Keep the completed checklist as an audit record — it is evidence for ISO 27001, 20000 and 22301 surveillance audits.
Download the printable checklist (PDF)
Take the whole checklist into your change window. The branded, print-ready PDF includes the pre-go-live checks, the post-virtualization checks, an ISO / TIA-942 reference table and an acceptance & sign-off sheet — three pages you can fill in and keep as an audit record.
Download the Skyline checklist (PDF)
How Skyline Cloud helps
Skyline Cloud designs, builds and operates virtualization and private-cloud platforms across Saudi Arabia and the GCC to these standards — with documented go-live procedures, monitoring, backup/DR and 24/7 support. Talk to our team about a resilient, audit-ready virtualization platform.

Comments
0 total · 0 threads