The UNIX and Linux Forums  
Hello and Welcome from United States to the UNIX and Linux Forums! Thank You for Visiting and Joining Our Global Community.

Go Back   The UNIX and Linux Forums > Special Forums > Security > IT Security RSS
.
google unix.com



More UNIX and Linux Forum Topics You Might Find Helpful
Thread Thread Starter Forum Replies Last Post
Consensus Audit Guidelines - What is the consensus? iBot IT Security RSS 0 03-03-2009 06:50 PM
Unix Shell Scripting Guidelines acheepi Shell Programming and Scripting 2 01-17-2006 02:30 PM
Guidelines for Posting Here Neo What's on Your Mind? 0 03-04-2005 04:01 PM
Guidelines For Posting Here Neo Forum Support Area for Unregistered Users & Account Problems 0 01-14-2005 05:13 PM

Reply
English Japanese Spanish French German Portuguese Italian Dutch Swedish Russian Norwegian Hungarian Hebrew Danish Powered by Powered by Google
 
LinkBack Thread Tools Search this Thread Rate Thread Display Modes
  #1 (permalink)  
Old 07-08-2009
iBot's Avatar
iBot iBot is offline
Forum Robot Girl
  
 

Join Date: Sep 2000
Posts: 22,144
Some Background Notes on the Common Audit Guidelines (CAG)

Here's some background on the CAG (Common Audit Guidelines).  The Red Teams have consistently proved that poor configuration and patching practices have made it easy for them to defeat network defenses.  This determination lead to the Air Force approaching Microsoft and insisting that new desktop software application come with a standard secure configuration.  This was the genesis of what is now known as the Federal Desktop Core Configuration (FDCC.) FDCC uses Red Team knowledge about attacker techniques to protect systems and network vulnerabilities used by attackers to break into systems.  This in turn, has led to the Twenty Critical Security Controls (the “CAG” not to be confused with the older abbreviation for Carrier, Air Group used by the Navy.)  In the IA context, CAG is the follow-on to the FDCC.  It extends the mandate that “offense must teach defense” to identify all 20 critical controls that ensure systems are protected against most known attack vectors and that the systems are configured adequately so that attack software that does get through can be found and eliminated quickly.  The demonstrated collateral benefits of these efforts include saving costs in terms of configuration management and patching plus reducing help desk calls.




More...
Reply

Bookmarks

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT -4. The time now is 04:29 AM.


Powered by: vBulletin, Copyright ©2000 - 2006, Jelsoft Enterprises Limited. Language Translations Powered by .
vBCredits v1.4 Copyright ©2007 - 2008, PixelFX Studios
The UNIX and Linux Forums Content Copyright ©1993-2009. All Rights Reserved.Ad Management by RedTyger

Content Relevant URLs by vBSEO 3.2.0