zlacker

[parent] [thread] 1 comments
1. server+(OP)[view] [source] 2022-01-27 17:58:23
The memo does say each agency needs to pick one system that is not internet accessible and make it accessible in the next year. The way I read this memo is pushing that VPNs don't add much in the way of security (if you follow the rest of the memo) and should be removed.
replies(1): >>tptace+pf
2. tptace+pf[view] [source] 2022-01-27 19:07:20
>>server+(OP)
The other way to read that part of the memo is that the exercise of exposing an application on the public Internet is a forcing function that will require agencies to build application security skills necessary whether or not they use VPNs. Note that the memo demands agencies find a single FISMA-Moderate service to expose.
[go to top]