spk-logo-white-text-short2
0%
1-888-310-4540 (main) / 1-888-707-6150 (support) info@spkaa.com
Select Page

How to Conduct System Hardening Using the Defense Information Systems Agency’s (DISA) “Gold Disk”

Written by SPK Blog Post
Published on December 6, 2011

Holes in your IT infrastructure can make for some awkward situations. Whether you’re dealing with sensitive customer information, upcoming product designs, or simply just don’t want people messing with your stuff, maintaining system integrity can be difficult. Symantec is great, but what do you do when the integrity of your system directly relates to national security? Where do you turn when the boss says you gotta keep those centrifuges spinning or heads will roll?

The DoD has developed a process, called DIACAP, for certifying that an Information System (IS) is compliant with DoD security standards. DIACAP stands for DoD Information Assurance Certification and Accreditation Process and you can find additional information about it here and here.

The DISA (an agency within the DoD) has developed a tool, called “Gold Disk”, to help identify and mitigate security holes according to DIACAP standards. It scans your machine and produces a detailed outline of all the Category 1, 2, and 3 vulnerabilities it finds, depending on the applicable Mission Assurance Level. It even goes as far as to suggest the appropriate means of resolving the issue, point out relevant Microsoft Security Bulletins, and offer to fix things for you.

Keep reading for my step-by-step walk-through on how to use DISA’s “Gold Disk”, a handy tool!

David Hubbell
SPK Software Engineer

Latest White Papers

A Checklist for Reducing Time to Market in Engineering

A Checklist for Reducing Time to Market in Engineering

Product teams all have the same goal: produce high-quality products and reduce time to market. Achieving these goals simultaneously can be difficult, but your team doesn’t have to sacrifice one for the other. Learn how in this eBook.What You Will Learn In this eBook,...

Related Resources

Avoiding Audit Failures with End-to-End Digital Traceability

Avoiding Audit Failures with End-to-End Digital Traceability

Key Takeaways Audit failures often stem from incomplete records, disconnected systems, weak controls, and manual processes. Continuous traceability helps teams capture compliance evidence as part of everyday engineering work. Connecting ALM and PLM creates clearer...

Continuous Compliance for Automotive Software Updates

Continuous Compliance for Automotive Software Updates

Key Takeaways Automotive compliance must be continuous. Regulations such as UNECE R155 and R156 require teams to manage cybersecurity risks and software updates throughout the vehicle lifecycle, not just at audit time. Disconnected tools make compliance difficult....

Renewing Microsoft 365 Soon? You May Be Overpaying 

Renewing Microsoft 365 Soon? You May Be Overpaying 

Key Takeaways Microsoft 365 Business Basic, Standard, and Premium now support up to 100 GB primary mailboxes, removing one reason some organizations previously needed higher-cost licensing. Office 365 E3 users may be candidates for Business Premium, particularly if...