This Blog has Moved!

This blog is moving to


Thank you for visiting! Content will remain here for archival purposes.
Showing posts with label DISA. Show all posts
Showing posts with label DISA. Show all posts

DISA Gold Disk FOIA Request Denied

Sad news. DISA has denied my request for the source code to the Gold Disk.

While there were multiple justifications in the letter, the primary justification was that the source code includes licensed proprietary technology, which DISA does not have legal ability to release.

This is unfortunate, but within the law. Since incomplete source code would be useless, I have decided not to file an appeal.

DISA Gold Disk FOIA Request Sent

UPDATE: My FOIA request was denied, and these tools will remain lost forever.  Details here.

I have sent a FOIA request to DISA for public release of the DISA FSO Gold Disk.  It is my hope that this request will be rather painless, and that DISA will release all requested materials.

If/when DISA does release the requested materials, I will establish an open source project on either SourceForge or Google Code for continued development of the Gold Disk.

My letter is below. I should receive a response within 30 days.

Hello,
I am writing to you to request public release of the following:
DISA FSO Gold Disk binaries
DISA FSO Gold Disk source code
DISA FSO Gold Disk developer documentation
DISA FSO Gold Disk user/administrator manuals

Per http://iase.disa.mil/stigs/index.html
"The DISA FSO Windows Gold disk tool provides an automated mechanism for compliance reporting and remediation to the Windows STIGs. The FSO Windows Gold Disks are an unlicensed tool developed by the FSO, the use of this tool is completely at the user's own risk. Currently, the Gold Disk supports Windows XP, Windows Vista, Windows 2003, Windows 2008 R1. There are no plans to develop Gold Disks for future technologies or products, FSO will utilize the SCAP standards for compliance reporting for Windows 7."

Since the tool is unlicensed and developed by FSO, that puts the tool in Public Domain. Furthermore, the DISA FSO Gold Disk is no longer supported for use within DoD, and development has ceased, meaning the tool is no longer in use within the DoD.

This tool could be of great use to the private sector, and would help increase the security of our nation.

I understand that the DISA Gold Disk does contain IAVM information which is still FOUO. As such, I am agreeable to this information being sanitized prior to public disclosure.

Since this is a FOIA request for public interest, I would like to request that any fees be waived.

I look forward to your response.

Thanks,
Ken Buckler
Caffeine Security

CASP now DoD 8570 Approved - Free Practice Exams to Help Study!

According to DISA the CompTIA Advanced Security Practitioner (CASP) is now 8570 approved.  http://iase.disa.mil/eta/iawip/content_pages/iabaseline.html

This is great news for those looking for a more affordable alternative to CISSP for IAT level III and IAM level II compliance.

As one of the first recipients of the CASP I am absolutely thrilled by this and feel DISA has chosen the correct categorization for this certification.  It's a very tough certification - and requires the person taking the certification to have hands-on experience with multiple security and networking technologies.

If you're looking to take the CASP I would recommend taking practice exams for the CompTIA Security+, CISSP, and Cisco CCNP.  You can access all of these practice exams for free at my Career Tools blog.

Reaching out to the @EFF for assistance with DISA Gold Disk and UNIX SRR FOIA Request

Due to DISA's resistance for my request for a public copy of the DISA Gold Disk and UNIX SRR security evaluation tools I have reached out to the Electronic Frontiers Foundation for assistance with filing a Freedom of Information Act request.

I have already been informed by the DISA Office of General Counsel that this is a technical issue not a legal issue.

I hope that with their help I can acquire the following for DISA Gold Disk and UNIX SRR:
  • User Documentation
  • Binary Executables
  • Source Code
  • Developer Documentation
  • All other related documents
Stay tuned!

DISA Gold Disk and SRR - The Lost Security Tools

UPDATE: My FOIA request was denied, and these tools will remain lost forever.  Details here.


Today I sent an email to DISA requesting a public copy of the Gold Disk and SRR tools.

For those unfamiliar with the tools, they used to be available from http://iase.disa.mil/stigs/index.html

However, the tools are now PKI protected and no longer accessible to the public.

According the DISA's web site these tools are unlicensed...putting them in the public domain.  Here is a description of both tools directly from DISA's website:

Security Readiness Review (SRRs) Scripts test products for STIG compliance. SRR Scripts are available for some operating systems and databases that have STIGs. The SRR scripts are unlicensed tools developed by the FSO and the use of these tools on products is completely at the user's own risk.

The DISA FSO Windows Gold disk tool provides an automated mechanism for compliance reporting and remediation to the Windows STIGs. The FSO Windows Gold Disks are an unlicensed tool developed by the FSO, the use of this tool is completely at the user's own risk. Currently, the Gold Disk supports Windows XP, Windows Vista, Windows 2003, Windows 2008 R1. There are no plans to develop Gold Disks for future technologies or products, FSO will utilize the SCAP standards for compliance reporting for Windows 7.
Hopefully they will provide the tools without any issue.  If not, my next step will be a FOIA request.  It is my hope that should they provide the tools, that someone may continue working on them for private sector use.

In the meantime...SCAP versions of all STIGs (DISA security guides) are publicly available:
http://iase.disa.mil/stigs/dod_purpose-tool/index.html