Showing posts with label DoD. Show all posts
Showing posts with label DoD. Show all posts

Monday, February 20, 2012

Life Update

I know I haven't posted in a while.....

Firstly, I've been getting upset frustrated with DoD auditing in support of DIACAP, or whatever it is going to be called in the future.  After doing this auditing for close to four years, I see numerous problems with no clear-cut solution.  But, that is a post for another day.  I'll still post DoD IA posts, but expect to see more incident response / digital forensics posts.

While I started my post-college career in software development, specifically COBOL, I figured it was time to learn a scripting language.  Currently, I write many of my auditing tools using vbscript, however, it is not portable across multiple platforms.  After thinking about it for a while, I've decided to teach myself Python; so there could be some Python posts in the future.  Many of the open source DFIR tools that I've seen/used are either written in either Perl or Python, so it's high-time I learned one of those languages.

Finally, if there are (larger than normal) gaps in posting, it is because I am studying for my SANS GCIH re-certification.  Without realizing it, I took my GCFA class outside of the window where I could have used it for my GCIH re-certification credits.  Fortunately, I really like the material in the GCIH, and I put much of it into practice.  It's been fun to read the updated manuals and go through the DVD with new and updated software.

Saturday, January 14, 2012

Command Cyber Readiness Inspection

In the coming weeks I will be traveling to a base in order to help them prepare for a Command Cyber Readiness Inspection.  I have never participated in one of these, typically I am auditing a system for certification efforts.

As far as I understand, DISA picks the unit/system that is undergoing the inspection.  There are a series of checklists that they will use and that must be completely filled out.  It also appears that they will Retina scan the entire system.  In addition to helping the unit prepare by running a "pre-audit" we will be ensuring that documentation is complete and up-to-date.  Our only "true" deliverable will be a POAM so that the unit knows what they need to fix or update before the actual inspection takes place.

I would be interested in hearing more about the mechanics of a CCRI; who gets selected, why, etc.

Tuesday, July 19, 2011

DISA may have been hacked

Here's the link.

Keep your eyes on the news for more to the story.

Friday, December 31, 2010

IPv6 deployment guides have been released by NIST

I really wasn't planning on posting anything until the new year, but this story in the SANS NewsBites prompted me to post this up.  NIST has posted a final version of its "Guidelines for the Secure Deployment of IPv6."

This has ramifications in a bunch of checklists that DoD auditors will be looking at.  From experience though, I know of many checks in the Application Security and Development checklist where this will have impact.  Specifically, you can look at: V-16781, V-6164, V-6165, V-19706, V-19707, V-19708, V-19709, V-16829, and mentioned in V-16822 and V-16836.

Thursday, January 7, 2010

DISA SRR tools need CAC in order to get them

I know that DISA periodically makes part of their site unavailable while they make changes to their regulations (checklists, STIGS, etc.) So, for the past couple of days I've been waiting for the new checklists to be posted so as to prepare for a new trip. Yesterday, a bunch of the checklists updated: MS SQL Server has been split into SQL Server 2000 and 2005. The Oracle checklists have been split up by Oracle version. I notice that three of the Windows checklists have been updated: Windows 2000, 2003, and 2008. Curiously, there is not a checklist posted for Windows XP or Vista. I supposed they are forth-coming.

However, I was highly surprised to see that the SRR scripts have been moved to a site that requires CAC authentication. And at this, I have to wonder why. In my opinion, the scripts do a great job of testing configurations against what the DoD expects items under their purview to be configured. Was that such a bad thing that everyone had access to the tools? It only makes the community safer. I'm hoping this is a temporary measure, and that all will return to normal as I would hate to see valuable tools be available only to a select few.