![]() |
Hello and Welcome from United States to the UNIX and Linux Forums! Thank You for Visiting and Joining Our Global Community.
|
|
google unix.com
|
|||||||
| Forums | Register | Forum Rules | Links | Albums | FAQ | Members List | Calendar | Search | Today's Posts | Mark Forums Read |
More UNIX and Linux Forum Topics You Might Find Helpful
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Some Background Notes on the Common Audit Guidelines (CAG) | iBot | IT Security RSS | 0 | 07-08-2009 04:15 PM |
| Consensus Audit Guidelines - What is the consensus? | iBot | IT Security RSS | 0 | 03-03-2009 06:50 PM |
| Transfer Learning From Multiple Source Domains via Consensus Regularization | iBot | UNIX and Linux RSS News | 0 | 09-22-2008 03:20 AM |
| Guidelines for Posting Here | Neo | What's on Your Mind? | 0 | 03-04-2005 04:01 PM |
| Guidelines For Posting Here | Neo | Forum Support Area for Unregistered Users & Account Problems | 0 | 01-14-2005 05:13 PM |
![]() |
|
|
LinkBack | Thread Tools | Search this Thread | Rate Thread | Display Modes |
|
|
|
|||||
|
Some Background Notes on the Consensus Audit Guidelines (CAG)
Here's some background on the CAG (Consensus Audit Guidelines). The Red Teams have consistently proved that poor configuration and patching practices have made it easy for them to defeat network defenses. This determination lead to the Air Force approaching Microsoft and insisting that new desktop software application come with a standard secure configuration. This was the genesis of what is now known as the Federal Desktop Core Configuration (FDCC.) FDCC uses Red Team knowledge about attacker techniques to protect systems and network vulnerabilities used by attackers to break into systems. This in turn, has led to the Twenty Critical Security Controls (the “CAG” not to be confused with the older abbreviation for Carrier, Air Group used by the Navy.) In the IA context, CAG is the follow-on to the FDCC. It extends the mandate that “offense must teach defense” to identify all 20 critical controls that ensure systems are protected against most known attack vectors and that the systems are configured adequately so that attack software that does get through can be found and eliminated quickly. The demonstrated collateral benefits of these efforts include saving costs in terms of configuration management and patching plus reducing help desk calls.
More... |
![]() |
| Bookmarks |
| Thread Tools | Search this Thread |
| Display Modes | Rate This Thread |
|
|