Author Topic: Swiss cheese more secure than US Army computer system  (Read 756 times)

vaskidmark

  • National Anthem Snob
  • friends
  • Senior Member
  • ***
  • Posts: 12,799
  • WTF?
Swiss cheese more secure than US Army computer system
« on: October 27, 2015, 10:57:12 AM »
http://borepatch.blogspot.com/2015/10/us-army-computer-systems-have-more.html

Quote
    The US Army has gaping holes in its information security infrastructure and operates an environment of vulnerability reporting fear, according to current and former members of the department's cyber wing.

    Captain Michael Weigand and Captain Rock Stevens make the comments in an academic piece on the Cyber Defense Review http://www.cyberdefensereview.org/2015/10/23/avrp/ , a joint project between the Army Cyber Institute and the US Marine Corps Forces Cyberspace Command.

    In it they say most of the Army's systems are underpinned by information technology but are exposed by an absence of centralised patch management and full bug remediation oversight, along with a "ban" on penetration testing.

I am certainly going to sleep sound knowing this.

stay safe.
If cowardly and dishonorable men sometimes shoot unarmed men with army pistols or guns, the evil must be prevented by the penitentiary and gallows, and not by a general deprivation of a constitutional privilege.

Hey you kids!! Get off my lawn!!!

They keep making this eternal vigilance thing harder and harder.  Protecting the 2nd amendment is like playing PACMAN - there's no pause button so you can go to the bathroom.

mtnbkr

  • friend
  • Senior Member
  • ***
  • Posts: 15,388
Re: Swiss cheese more secure than US Army computer system
« Reply #1 on: October 27, 2015, 01:22:37 PM »
Not really any different than most large organization, public and private.

Chris

Ben

  • Administrator
  • Senior Member
  • *****
  • Posts: 46,162
  • I'm an Extremist!
Re: Swiss cheese more secure than US Army computer system
« Reply #2 on: October 27, 2015, 02:16:49 PM »
Not really any different than most large organization, public and private.

Chris

Other than the "no pen testing" thing,  at least for .gov.  if anything,  we used to spend almost too much time in pen test prep mode. Seems strange of all the gov,  these guys would blow it off.
"I'm a foolish old man that has been drawn into a wild goose chase by a harpy in trousers and a nincompoop."

Firethorn

  • friend
  • Senior Member
  • ***
  • Posts: 5,789
  • Where'd my explosive space modulator go?
Re: Swiss cheese more secure than US Army computer system
« Reply #3 on: October 27, 2015, 02:39:02 PM »
As an example, the USAF has dedicated penetration testing teams.

So I'm not sure that the "ban on penetration testing" is accurate.  A ban on outside test groups, maybe.

mtnbkr

  • friend
  • Senior Member
  • ***
  • Posts: 15,388
Re: Swiss cheese more secure than US Army computer system
« Reply #4 on: October 27, 2015, 02:53:00 PM »
So I'm not sure that the "ban on penetration testing" is accurate.  A ban on outside test groups, maybe.

Probably non-authorized pen testing, aka hacking.

Chris

MillCreek

  • Skippy The Wonder Dog
  • friend
  • Senior Member
  • ***
  • Posts: 20,011
  • APS Risk Manager
Re: Swiss cheese more secure than US Army computer system
« Reply #5 on: October 27, 2015, 03:14:03 PM »
As an example, the USAF has dedicated penetration testing teams.



That's what she said.  Ahem. Phrasing. Inappropes.
_____________
Regards,
MillCreek
Snohomish County, WA  USA


Quote from: Angel Eyes on August 09, 2018, 01:56:15 AM
You are one lousy risk manager.

MechAg94

  • friend
  • Senior Member
  • ***
  • Posts: 33,807
Re: Swiss cheese more secure than US Army computer system
« Reply #6 on: October 27, 2015, 03:43:51 PM »
Maybe the actual pen test teams are still trying to solve the Fountain/ball point question.
“It is much more important to kill bad bills than to pass good ones.”  ― Calvin Coolidge

dogmush

  • friend
  • Senior Member
  • ***
  • Posts: 13,952
Re: Swiss cheese more secure than US Army computer system
« Reply #7 on: October 27, 2015, 06:20:58 PM »
At least we don't store classified data on General's private servers.

We're not the worst!  Yea!
« Last Edit: October 28, 2015, 08:54:37 PM by dogmush »

Fitz

  • Face-melter
  • friend
  • Senior Member
  • ***
  • Posts: 6,254
  • Floyd Rose is my homeboy
    • My Book
Re: Swiss cheese more secure than US Army computer system
« Reply #8 on: October 28, 2015, 08:08:31 PM »
not at all surprising to me
Fitz

---------------
I have reached a conclusion regarding every member of this forum.
I no longer respect any of you. I hope the following offends you as much as this thread has offended me:
You are all awful people. I mean this *expletive deleted*ing seriously.

-MicroBalrog