Classic, love the integration one.......
Sent from my iPhone using Tapatalk
Sent from my iPhone using Tapatalk
This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.
Show posts MenuQuote from: Otanx on August 07, 2015, 10:49:17 AM
Are you guys not doing the new RMF (Risk Management Framework) stuff yet, or just nobody willing to accept risk in your AO? If you are not familiar with it basically RMF says you don't need to meet every single requirement, but you need to identify what you can't meet, identify mitigation, and residual risk, and then get it signed off by someone in the cyber group depending on the level of risk left. So for something like RANCID you can't do two factor, but you mitigate the risk by limiting logins for that account only to the RANCID server, limiting commands it can run to only what is required, and finally by using a complex password 32 characters long with a 8/8/8/8 mix of upper/lower/numbers/symbols that is changed every X days. Then someone in the chain gets to sign off that the operational gains outweigh the risk.
-Otanx