01.03.2019 Views

CDM-CYBER-DEFENSE-eMAGAZINE-March-2019

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

ConfigOS supports over 6,000 standard STIG controls in a wide range of tested content.<br />

However, the software is also designed to allow users to tailor controls to respond to an<br />

application’s requirements.<br />

“We could enforce the STIGs to the letter, but that doesn’t work if it means the application will not<br />

run,” explains Hajost. “So ConfigOS creates an operational policy that is as close to the published<br />

STIGs as possible, but still allows the application to function as designed,” explains Hajost.<br />

The signature containers can then be transported across large and small networks, classified<br />

environments, labs, disconnected networks, and tactical environments with connected and<br />

disconnected endpoints. No other changes are required to the network, security and no software<br />

is installed on any endpoints.<br />

To date, ConfigOS has been licensed by just about every branch of the Department of Defense,<br />

as well as parts of DHS, HHS, and Department of Energy. The product is also used by large<br />

defense contractors and in programs for all branches of the military.<br />

Hajost adds that automation is even more important given that STIG compliance is an ongoing<br />

process with new security updates introduced periodically<br />

The STIGs, for example, are updated every 90 days to account for newly discovered<br />

vulnerabilities as well as changes and updates to by the vendors supplying the major operating<br />

environment components.<br />

With ConfigOS that means that within two business days after DISA publishes a new version of<br />

the STIGs, new tested production content is made available to customers.<br />

“When it is a manual task, security updates to existing applications and operating systems are<br />

typically delayed by months,” says Hajost.<br />

The software can also speed implementation of new network applications, servers and appliances<br />

by evaluating and hardening each prior to installation.<br />

Hajost estimates automating the process reduces initial hardening time by 90%, while reducing<br />

system security policy maintenance expenses by about 70%.<br />

Given the potential cost savings of automating STIG policy compliance exceeds hundreds of<br />

millions of dollars annually, IT personnel struggling to secure government networks manually may<br />

find this one task they are happy to automate.<br />

About the Author<br />

Jeff Elliott is a Torrance, Calif.-based technical writer. He has researched and<br />

written about industrial technologies and issues for the past 20 years.<br />

For more information about ConfigOS from SteelCloud call (703) 674-5500; or<br />

visit www.steelcloud.com.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!