Sunday, March 20, 2016

Lesson 5 - DISA

Technically these posts are supposed to be about new things but I thought I'd do this mainly because not everyone in the class has the, um, pleasure, of working with an organization such as DISA (Defense Information Systems Agency).   They hold the keys to the kingdom so to speak.  Every attached system must adhere to their standards or have a waiver which explains exactly what can't be done and why.

DISA's Information Assurance Support Environment webpage is where all the baselines are kept.  It's unclassified and open to the public (most of it anyway, anything that says PKI is protected and you must have a DoD account to access).

Here is the Risk Management Framework for DoD Information Technology.  It's a wonderful read.  The one that I've been spending most of my time with lately is the DoD Cloud Computing Security stuff.

If you are a SA (System Admin) or do any hands on work, you'll love the STIGs (Security Technical Implementation Guides).  These are the guidelines every machine and application must adhere to and are tested against.

No comments:

Post a Comment