Re: [Fed-Talk] What happened with SCAP-on-Apple?
Re: [Fed-Talk] What happened with SCAP-on-Apple?
- Subject: Re: [Fed-Talk] What happened with SCAP-on-Apple?
- From: "Colvin, Ron (GSFC-700.0)[VALADOR INC]" <email@hidden>
- Date: Mon, 10 Feb 2014 22:56:09 +0000
- Thread-topic: [Fed-Talk] What happened with SCAP-on-Apple?
For those on the list using CIS or looking for security guidance rather than compliance the Benchmark for 10.8 was released last week. We are hoping to get 10.9 out in a couple months, depending on how many changes there are from 10.8.
On Feb 10, 2014, at 5:40 PM, "John Oliver" < email@hidden> wrote:
It looks like that project is languishing. This makes me sad.
I attended (virtually) the OSD Apple Engineering Coalition kickoff last week, and, coincidentally, just found out about and volunteered for a working group to address enterprise management of Macs at SSC. One of the
obvious issues we have with Macs on a government network is STIGs, the rapid release and die-off schedule for OSX, and the three years it takes DISA to release a STIG (BTW: I believe we can expect a STIG for Mountain Lion maybe in a month or so?)
Red Hat addressed this issue with their own open source
SCAP Security Guide project. That's the official upstream for STIGs for Red Hat now, and they can get it done in about a year. Something like this would be a tremendous resource for Apple and for those of us who use Apple products.
I hope we can light a fire and help SCAP-on-Apple to succeed!
Anyone who's interested in DoDAEC – I can forward on some info to anyone with a CAC who works on a DoD program. They created a trifold but it weighs in at 12MB so I won't be attaching it :-)
--
John Oliver | SAIC
Defense & Maritime Solutions
Surveillance and Reconnaissance Solutions Division
SPAWAR Systems Center Pacific | Code 53223
Sr. Systems Administrator
Bldg 600 | Room 428N
Office: (619) 553-9567
email@hidden
email@hidden
DCO:
email@hidden
_______________________________________________
Do not post admin requests to the list. They will be ignored.
Fed-talk mailing list (email@hidden)
Help/Unsubscribe/Update your Subscription:
This email sent to email@hidden
|
_______________________________________________
Do not post admin requests to the list. They will be ignored.
Fed-talk mailing list (email@hidden)
Help/Unsubscribe/Update your Subscription:
This email sent to email@hidden