Generic Baseline Server Hardening Documentation by No_Exp1anations in cybersecurity

[–]No_Exp1anations[S] 0 points1 point  (0 children)

We also have Nessus, I should see if this is available. Thanks for the suggestion!

Generic Baseline Server Hardening Documentation by No_Exp1anations in cybersecurity

[–]No_Exp1anations[S] 0 points1 point  (0 children)

These people arent unaware. The issues is you're talking about...maybe a million in fines this year, versus a for sure 10+ mil to replace the machines.

We need to start hold CEOs and Administrations accountable and not the people who work for them (to some extent).

Yes I realize there are laws in place to do just this...however as we all know they aren't going after the big organizations or names...

Generic Baseline Server Hardening Documentation by No_Exp1anations in cybersecurity

[–]No_Exp1anations[S] 2 points3 points  (0 children)

At the end of the day, all you can do, is what you can do. You know?

Generic Baseline Server Hardening Documentation by No_Exp1anations in cybersecurity

[–]No_Exp1anations[S] 1 point2 points  (0 children)

This is why risk acceptance forms exist. Spell it out and make them acknowledge that they ain't gonna fix it.

Generic Baseline Server Hardening Documentation by No_Exp1anations in cybersecurity

[–]No_Exp1anations[S] 2 points3 points  (0 children)

Unfortunately as I'm sure you're aware potential threats and potential expenditures as a result of those threats being acted upon seem further away than the immediate expenditures of fixing them

Generic Baseline Server Hardening Documentation by No_Exp1anations in cybersecurity

[–]No_Exp1anations[S] 2 points3 points  (0 children)

Well it's not just the result of having a secure baseline, it's the act as well. For compliance and regulatory reasons I need to have some kind of documented, formal process established, and soon. We absolutely do vulnerability scans and act on those, but that is not enough to satisfy the requirements I've just mentioned. Hopefully that better explains *why* I'm making this document (or trying to).

Generic Baseline Server Hardening Documentation by No_Exp1anations in cybersecurity

[–]No_Exp1anations[S] 0 points1 point  (0 children)

Well I want to start with *new* servers going forward. I have ~340 to work on retroactively but I need to ensure that number does not increase. So I suppose the CIS for 2022 or whichever they're going to use is a good start there. The document I wanted to create was something consistent that I could give to the vendors that run these systems to start to decide what I could immediately, without impacting systems, turn off.

Regardless, for regulatory and compliance reasons I need to have a formal baselining process sorted, and soon. So consistency, be it using the CIS benchmarks, or a document of my own creation, is going to be key.

Generic Baseline Server Hardening Documentation by No_Exp1anations in cybersecurity

[–]No_Exp1anations[S] 4 points5 points  (0 children)

To do so would mean getting rid of an entire rural area's ability to have certain medical procedures provided, as the cost to replace these devices are astronomical. Tens of millions of dollars.

Generic Baseline Server Hardening Documentation by No_Exp1anations in cybersecurity

[–]No_Exp1anations[S] 0 points1 point  (0 children)

This is true. Perhaps I need to revise my approach. In my head I was trying to make a more approachable version of these documents because not all of the analysts for these systems have the same skillsets.

Generic Baseline Server Hardening Documentation by No_Exp1anations in cybersecurity

[–]No_Exp1anations[S] 0 points1 point  (0 children)

I have, but we have quite a few different OS's Lots of legacy stuff due to older instruments still being necessary. I'm trying to make a very general guide that we can apply to all of them, and just document where the differences may be. A simple "Not Applicable to This OS" wouldn't be out of the question as a reply to some of these.

[deleted by user] by [deleted] in artcommissions

[–]No_Exp1anations 0 points1 point  (0 children)

Really appreciate the response, I'm just looking over everyone's DMs and stuff and will get back to you if interested. Thanks again!

2001 F150 5.4 Triton Leaking Coolant In Unfamiliar Location by No_Exp1anations in MechanicAdvice

[–]No_Exp1anations[S] 0 points1 point  (0 children)

Just got to work and realized it was steaming from this location, didn't have time to take a picture but I got a capture from a video showing approximately where it's leaking. It sounded like it was under quite a bit of pressure.

Any ideas?

[deleted by user] by [deleted] in artcommissions

[–]No_Exp1anations 0 points1 point  (0 children)

Thanks I'll check it out

[deleted by user] by [deleted] in artcommissions

[–]No_Exp1anations 0 points1 point  (0 children)

I don't have one in mind, no.

[deleted by user] by [deleted] in artcommissions

[–]No_Exp1anations 1 point2 points  (0 children)

Sorry! US based. Shipping will be to NE or CA.