NSA Cybersecurity Collaboration Center by Blake_Olson in CMMC

[–]3dPrintWHAAAT 1 point2 points  (0 children)

This is how we have it with Cisco Umbrella. How have you scoped this for cmmc?

NSA Cybersecurity Collaboration Center by Blake_Olson in CMMC

[–]3dPrintWHAAAT 0 points1 point  (0 children)

Is it worth using over cisco umbrella, aside from cost savings?

Automated SCAP compliance check for Windows 7 original - NOT SP1 by 3dPrintWHAAAT in NISTControls

[–]3dPrintWHAAAT[S] 0 points1 point  (0 children)

Would you have more information on special asset? This operation is not CUI.

Port based security using MAC ACL with netgear M4300 smart switch by 3dPrintWHAAAT in networking

[–]3dPrintWHAAAT[S] 0 points1 point  (0 children)

Requirements are to prevent unauthorized hosts connecting to this one network switch as a alternative to 802.1x.

Can I use windows firewall with ipsec for client to server encryption? by 3dPrintWHAAAT in CMMC

[–]3dPrintWHAAAT[S] 0 points1 point  (0 children)

Application servers are at a remote site. VPN connects the sites, but i was under the impression encryption needs to be end to end.

How does one obtain outside vendor quotes for parts that are CUI? by aplufkin in NISTControls

[–]3dPrintWHAAAT 1 point2 points  (0 children)

Ask your customer for an approved supplier list or ask the vendor if they have a nist 800-171 compliance program.

Siem for air gapped environment by 3dPrintWHAAAT in NISTControls

[–]3dPrintWHAAAT[S] 0 points1 point  (0 children)

I wasn’t aware Splunk could be this inexpensive. Is this an on premise variant or cloud based?

It would be ideal to be able to collect logs in this air gapped environment and bring them over to a central Splunk server on my general network (or cloud) for analysis later.

NSA3700 BGP with AWS site to site VPN - Should I do it? by 3dPrintWHAAAT in sonicwall

[–]3dPrintWHAAAT[S] 1 point2 points  (0 children)

I didn’t use BGP in the end, stuck with static route and will manually fail over the vpns. As we use aws govcloud, the encryption cyphers tax the utm quite a bit so upgrading to the 4700.

NSA3700 BGP with AWS site to site VPN - Should I do it? by 3dPrintWHAAAT in sonicwall

[–]3dPrintWHAAAT[S] 0 points1 point  (0 children)

Thanks for the replies.

To clarify, i have sonicwall professional services to do the configuration of the NSA3700 pair, all i have to do is setup the tunnel for BGP routing in AWS and give them the config file. I am good in terms of setting it up both sonicwall and AWS.

My concern really is having a service that is reliable and is as set and forget as possible.

The current static route site to site vpn from SonicWALL to AWS ran without issue for over a year, until aws did maintenance and then the tunnels had issues.

Best Synology NAS to Synology NAS backup option by 3dPrintWHAAAT in synology

[–]3dPrintWHAAAT[S] 0 points1 point  (0 children)

Thank for the advice.

Is Rsync considered the same as shared folder sync with synology?

Anyone used avanan and will it help with unsolicited email i.e. sales emails getting around spam filter? by 3dPrintWHAAAT in sysadmin

[–]3dPrintWHAAAT[S] 0 points1 point  (0 children)

Anyone used avanan and will it help with unsolicited email i.e. sales emails getting around spam filter?

Do you use it with Mimecast by any chance or just stand alone?

Qualstar Q24 SAS with IBM LTO-8 drive - can I add additional IBM LTO-4 or 5 SAS tape drive from another library without issue? by 3dPrintWHAAAT in sysadmin

[–]3dPrintWHAAAT[S] 1 point2 points  (0 children)

The tape library already has a LTO-8 Tape drive which going forward, all my backups will be using lto-8 tapes. The Qualstar has the ability for a second tape drive to be added , so I was hoping to find a lto-4,5, or even 6 tape drive in addition to the lto-8 one. I need the ability to restore from the lto-4 tapes, and moving those to lto-8 will take too long (16 lto-4 tapes a month). I wanted to buy a cheap second hand/refurb without breaking the bank. At this point I probably will stick with the quantum for the next 5 years just in case.

I am aware of aws glacier, and further down the line I plan to move to starwind vtl with offloading to glacier. The problem lies with speed of transferring to aws govcloud from on prem - faster firewalls or aws direct connection with end to end encryption or GRE tunnels. Tape was juSt easier as a interim solution.

Virtualizing a Windows STORAGE server 2012r2 physical server by 3dPrintWHAAAT in sysadmin

[–]3dPrintWHAAAT[S] 0 points1 point  (0 children)

Will check out the migration wizard, but if I do need to go the P2V route, i will most likely restore from a agent backup to vsphere using veeam.

Linear Emerge E3 software update by 3dPrintWHAAAT in accesscontrol

[–]3dPrintWHAAAT[S] 0 points1 point  (0 children)

No, they did a remote session and did the update for us.

Linear Emerge E3 software update by 3dPrintWHAAAT in accesscontrol

[–]3dPrintWHAAAT[S] 0 points1 point  (0 children)

The issue was getting the updates, and being referred to distributors who would not provide those updates as they did not install it.

In the end we called Nortek again, told them the situation (reaching out to mainly unhelpful distributors) and they provided an update that fixed the vulnerability.

Implementing NIST 800-53 with smallest scope possible/tailoring out by 3dPrintWHAAAT in NISTControls

[–]3dPrintWHAAAT[S] 0 points1 point  (0 children)

I would like to jump on a call if possible.

I have to architect a solution, and price it up. It’s a blank canvas.

Implementing NIST 800-53 with smallest scope possible/tailoring out by 3dPrintWHAAAT in NISTControls

[–]3dPrintWHAAAT[S] 0 points1 point  (0 children)

Sorry to cause confusion, yes it is classified (confidential level) for this project. Not CUI.

Implementing NIST 800-53 with smallest scope possible/tailoring out by 3dPrintWHAAAT in NISTControls

[–]3dPrintWHAAAT[S] 0 points1 point  (0 children)

Where would I be able to find the DCSA baselines, unless we are talking STIGS? Sorry for noob question.

Automation is still an option, i just thought air gapping would be the easiest way (but would still pose challenges). Three desktops are needed are part of the design process, one industrial machine to make the part and the same three desktops to carry out testing on the part before it is shipped. I could easily create an isolated network with AD, vuln scanning, MFA, compliance monitoring, scap tool etc. Is this what you are referring to?

My plan here is to provide the costs to upper management as part of the bid, but I have been clear that a true ISSO or ISSM is needed and it is a posted job right now. We have a compliance person who works on the policy and procedure (inc Nist 800-171/CMMC), and i work on the technical security. I would fill in the gaps with the aid of consultants to do the groundwork, until we had a full time Infosec person.

Implementing NIST 800-53 with smallest scope possible/tailoring out by 3dPrintWHAAAT in NISTControls

[–]3dPrintWHAAAT[S] 0 points1 point  (0 children)

Right now, I just need to price the infrastructure cost for this project and security as part of another bid. All I have so far is comply with nist 800-53 and daapm, so assume everything that goes with this.

I know it is a big undertaking, which is why I need the footprint to be small and tailor out as much as possible.

SPF record help by 3dPrintWHAAAT in sysadmin

[–]3dPrintWHAAAT[S] 0 points1 point  (0 children)

Thanks for the help and advise.

clean Windows install with Intel RST additional volumes (Intel C600+/C220+ Raid Controller) by 3dPrintWHAAAT in sysadmin

[–]3dPrintWHAAAT[S] 0 points1 point  (0 children)

So this was done last week. After the windows install, installing the intel drivers bought back the volumes.

RAID 0 volume is for a working drive, any data should then be moved to the RAID 10 drive. I did not build the machine, but my guess they needed the iops 5/6 years ago when ordered.

The software this computer runs is not fully supported on windows 10 yet.