View Single Post
      05-11-2021, 11:13 AM   #37
zx10guy
Brigadier General
5150
Rep
3,241
Posts

Drives: 2013 135i
Join Date: Feb 2014
Location: DC

iTrader: (0)

And why I've been harping on having stated regulations which put in place financial penalties and in the case of gross negligence, jail time. None of these behaviors will change unless organizations and individuals get hit where they do care which is losing money or losing their time sitting in a cell.

The examples of the errant USB device being plugged into an air gapped computer is one example. But many people don't focus on other vectors such as the firmware that's installed in many of the subcomponents of devices. This brings up supply chain security. Many Federal agencies require TAA certified products. Some require BAA. But these come at an additional cost. Some OEMs go one step further to offer up secure supply chain services. Again at an additional cost. Then there's the software. The Solarwinds hack shows how things can go terribly wrong with a trusted software company. Even at the basics such as firmware updates. How many IT staffers spend the time to ensure the firmware is pristine by doing hash comparisons with the OEM's official hash?
__________________
Quote:
Originally Posted by Lups View Post
We might not be in an agreement on Trump, but I'll be the first penis chaser here to say I'll rather take it up in the ass than to argue with you on this.
Appreciate 2
vreihen1615339.00