4 ms·
I have some experience here, not with the NSA though. BYOD is forbidden, and checked when you enter the building. There is only wired hardware - and wireless is
by FourthProtocol 5y ago
I have some experience here, not with the NSA though. BYOD is forbidden, and checked when you enter the building. There is only wired hardware - and wireless is, well, jammed. Any software introduced into such networks is vetted before introduction/deployment. It takes time. 3rd party apps don't auto update - Microsoft for example provide updates that can be vetted before being allowed onto the network.
And this is only some bleedingly obvious stuff...
The document does not describe SECRET or TOP SECRET environments. Not even RESTRICTED. R, S and TS policies are themselves marked with protective markings, which this PDF lacks.
Governments have a lower level of protection called PROTECTED or similar that is closer to what the document describes, but even that would be protectively marked...
Looks to me like NSA is sharing some of their lesser sensitive stuff to possibly help their vendors, businesses partners and public at large. Kind of like "we recommend Joe Public do it like so..."
- aborsy 5y agoAre there guidelines on how to secure S and TS environments?
- FourthProtocol 5y agoYes. I assume you're asking if they're publicly available, which is a no. Is not an easy world to penetrate, for good reason.
- faeyanpiraat 5y agoYour website has great structure to communicate your values effectively; it must’ve helped you land some great opportunities.
- FourthProtocol 5y agoThank you. The only value I set out with when building the more recent version of the site was to share what I know. Too many people learn a thing and keep it to themselves.
- greggsy 5y agoThere’s heaps of content in the NIST 800- series, which is all available online
- greggsy 5y agoIt’s covered in the NIST 800 series, which is available online
- mike_d 5y agoTo clarify a bit, you are talking about classifed network design. That isn't what this document is about. The author of this document, Information Assurance Directorate (www.iad.gov) is focused on helping domestic government, their contractors, and private industry secure networks and devices against intrusion from hostile actors.
- FourthProtocol 5y agoI'm talking about op-sec. Network design is but a single aspect of that, and often doesn't feature at all. I mean this more in the sense described by Wikipedia¹, and not the likes of SecurityStudio²/Fortinet³ (first two search results). ¹ https://en.wikipedia.org/wiki/Operations_security https://en.wikipedia.org/wiki/Operations_security ² https://securitystudio.com/operational-security/ https://securitystudio.com/operational-security/ ³ https://www.fortinet.com/resources/cyberglossary/operational-security https://www.fortinet.com/resources/cyberglossary/operational...
- greggsy 5y agoI’m not sure how that’s relevant?
- FourthProtocol 5y agoIt's relevant because your GP asked specifically whether I was talking about network design.
- znpy 5y ago> and wireless is, well, jammed Uhm... wouldnt this, like, kill people with a pacemaker ? I was always told that jammers are dangerous for people with a pacemaker.
- dijit 5y agoThe way it's usually implemented is two sides of a wall have a mesh in them, similar to chicken wire. Jams all signals, doesn't require a beacon to be constantly transmitting.
- alufers 5y agoSo it's a faraday cage?
- dijit 5y agoYes, but part of the infrastructure of the building.
- rzzzt 5y agoI'd assumed "jamming" is when something actively disrupts communication, not passively prohibits the signal from reaching its intended recipient, which sounds more like "shielding". (Maybe this is unnecessary nitpicking, and everyone else understands that it was informal; English is not my first language.)
- InCityDreams 5y agoNative English speaker: you're correct (ie, i agree with you).
- greggsy 5y agoThe point of the document is for industry and public consumption, not spooks. The GCHQ, ACSC and other agencies release similar publications.