DoctorMac
DoctorMac

Matt Carson on Lesson Learned from a DIBCAC assessment.

|
Embed
Progress spinner
DoctorMac
DoctorMac

Charles River Analytics first had an onprem solution after a self-assessment they decided to go to a cloud solution

|
Embed
Progress spinner
DoctorMac
DoctorMac

They had large holes in their policies and procedures.

|
Embed
Progress spinner
In reply to
DoctorMac
DoctorMac

They ended up with 300 different pieces of evidence in their assessment

|
Embed
Progress spinner
DoctorMac
DoctorMac

Doing a good data flow diagream allow you to accurately scope your environment

|
Embed
Progress spinner
DoctorMac
DoctorMac

Know your FIPS settings. DIBCAC wanted to FIPS all the things if it had FIPS mode...I disagree with that conclusion but you gotta do what they say you gotta do.

|
Embed
Progress spinner
DoctorMac
DoctorMac

You need to know the in and outs of your system to defend implementations. DIBCAC comes in with speficic bias,. They had some devices too old to MFA. Worked with DIBCAC and created a VLAN so those machines are behind the box with MFA.

|
Embed
Progress spinner
DoctorMac
DoctorMac

Nobody is told why they make the DIBCAC list. Plan on a week of shutting down and doing nothing but the assessment.

|
Embed
Progress spinner