spk-logo-tm-2023
0%
1-888-310-4540 (main) / 1-888-707-6150 (support) info@spkaa.com
Select Page

How to Conduct System Hardening Using the Defense Information Systems Agency’s (DISA) “Gold Disk”

windchill features best plm software
Written by SPK Blog Post
Published on December 6, 2011

Holes in your IT infrastructure can make for some awkward situations. Whether you’re dealing with sensitive customer information, upcoming product designs, or simply just don’t want people messing with your stuff, maintaining system integrity can be difficult. Symantec is great, but what do you do when the integrity of your system directly relates to national security? Where do you turn when the boss says you gotta keep those centrifuges spinning or heads will roll?

The DoD has developed a process, called DIACAP, for certifying that an Information System (IS) is compliant with DoD security standards. DIACAP stands for DoD Information Assurance Certification and Accreditation Process and you can find additional information about it here and here.

The DISA (an agency within the DoD) has developed a tool, called “Gold Disk”, to help identify and mitigate security holes according to DIACAP standards. It scans your machine and produces a detailed outline of all the Category 1, 2, and 3 vulnerabilities it finds, depending on the applicable Mission Assurance Level. It even goes as far as to suggest the appropriate means of resolving the issue, point out relevant Microsoft Security Bulletins, and offer to fix things for you.

Keep reading for my step-by-step walk-through on how to use DISA’s “Gold Disk”, a handy tool!

David Hubbell
SPK Software Engineer

Latest White Papers

The Safe AI Governance Playbook

The Safe AI Governance Playbook

When it comes to AI, balancing safety and security with innovation is vital for peak efficiency. This eBook explores how to achieve success with AI governance.What You Will Learn In this eBook, you will discover: Why AI governance matters The role of AI governance...

Related Resources

The Hidden Cost of Disconnecting Requirements from Development

The Hidden Cost of Disconnecting Requirements from Development

Complex product development involves multi-disciplinary teams, with systems engineers or requirements analysts producing the requirements, and other disciplines creating designs and tests based on those requirements. Serious problems can arise if all teams do not have...

Achieving Regulatory Compliance through Connected ALM and PLM Systems

Achieving Regulatory Compliance through Connected ALM and PLM Systems

Compliance is not always about having the right documentation.  In regulated industries, compliance is about proving that requirements are defined, changes are controlled, risks are addressed, tests are completed, and approvals are captured in a traceable, audit-ready...

Meet the Experts: Ginna Kang

Meet the Experts: Ginna Kang

Ginna Khang is an Applications Engineer focused on research and development (R&D).  She started at SPK and Associates in 2022 as an intern while she attended UC Santa Cruz.  After graduating in 2024, she was brought on full-time.  Here is more about Ginna in her...