GSA / GSA/modernization

Comment from email: FW: Concerning Cybersecurity RFC (Part 2)

Open
#32 0 comments 0 reactions 0 assignees View on GitHub
Public comment
Dominant language
CSS
Stars
59
Forks
8
PR merge metrics
No merged PRs in 30d

Description

Update Concerning Strengthening Cybersecurity of Federal Networks & Critical Infrastructure RFC ( part 6):

Here are some thing missed from my previous Friday contact:

Switch Types: I recommend HP Over Cisco

A. Government leans toward Cisco. Cisco has deteriorated since the late 1990s.

1. Low end cisco units do not handle necessary functions to properly monitor from within.

2. Cisco requires dedicated technical ability and professional training.

3. Small networks don't have the financial or technical resources for such.

4. Cisco Documentation is written by Intellectual Idiots, scattered, hard to find and hard to understand.

B. HP is a better switch

1. HP Procurve model 2920 are small network units that support large network function.

2. A technical Person is easily self trained.

3. Small Networks do have the financial and technical resources to keep HP switches secure.

4. HP Documentation is easy to find and understandable.

5. Encrypt all functional data (Add this)

A. Use Encryption Methods (on or off the network)":

1. HTTPS

2. FTPS

3. SNMPv3

4. Any other Future Encryption Technology

Here is a bit more that can be done that I do not think is Commercially available but you have the resources to create it:

OTHER SECURITY MEASURES :

A. When using a UTM like Sophos

1. Connect UTM Logs combined with Server Logs

2. A way to feed all those text logs into a database

a. Set up to be always on and searched to Date Time to the second.

b. This would speed up the steps needed to prevent or stop breaches

c. Stored up to 5 years (depending on space availability)

d. When Breached or attempted intrusions happen patterns may be able to be established. Everything has a pattern!

B. Network Security Training

1. Most network breaches come the web browsing or email

a. Regular Network User Security & Awareness Training is critical.

b. Hacking methods are dynamic, constantly changing. Network Users need regular updates.

C. Better Methods of Login using combinations of biometrics, card swipes, and pass phrases can be developed

Network Security Is A Continuous Process - Never Finished

Regards,

David Pinkston

Manager

San Joaquin Refinery Co., Inc.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.