spk-logo-tm-2023
0%
1-888-310-4540 (main) / 1-888-707-6150 (support) info@spkaa.com
Select Page

How to Conduct System Hardening Using the Defense Information Systems Agency’s (DISA) “Gold Disk”

windchill features best plm software
Written by SPK Blog Post
Published on December 6, 2011

Holes in your IT infrastructure can make for some awkward situations. Whether you’re dealing with sensitive customer information, upcoming product designs, or simply just don’t want people messing with your stuff, maintaining system integrity can be difficult. Symantec is great, but what do you do when the integrity of your system directly relates to national security? Where do you turn when the boss says you gotta keep those centrifuges spinning or heads will roll?

The DoD has developed a process, called DIACAP, for certifying that an Information System (IS) is compliant with DoD security standards. DIACAP stands for DoD Information Assurance Certification and Accreditation Process and you can find additional information about it here and here.

The DISA (an agency within the DoD) has developed a tool, called “Gold Disk”, to help identify and mitigate security holes according to DIACAP standards. It scans your machine and produces a detailed outline of all the Category 1, 2, and 3 vulnerabilities it finds, depending on the applicable Mission Assurance Level. It even goes as far as to suggest the appropriate means of resolving the issue, point out relevant Microsoft Security Bulletins, and offer to fix things for you.

Keep reading for my step-by-step walk-through on how to use DISA’s “Gold Disk”, a handy tool!

David Hubbell
SPK Software Engineer

Latest White Papers

SOLIDWORKS vs. Creo: A Comparison

SOLIDWORKS vs. Creo: A Comparison

Solidworks and Creo are both popular 3D CAD solutions, and for good reason. They both offer a wide range of capabilities, but which system works best for your team?What You Will Learn In this comparison of Solidworks and Creo, you will discover the differences between...

Related Resources

The Future of Government Work is Here

The Future of Government Work is Here

Are you ready to secure your mission, empower all teams, and serve every citizen? The future of government work is here, and it's called the Atlassian Government Cloud.What You Will Learn Legacy systems cannot compete with the capabilities of the cloud. In this eBook,...

Modern Test Management for Regulated Industry Software Teams

Modern Test Management for Regulated Industry Software Teams

Introduction to Appsvio Hello everyone, and welcome to this SPK and Associates video entitled Modern Test Management for Regulated Industry Software Teams. I’m Michael Roberts, Vice President of Sales and Marketing for SPK and Associates. Today we’re going to talk...

Is GitHub Costing More Than It Should?

Is GitHub Costing More Than It Should?

CI/CD is an important aspect of software engineering that directly impacts engineering velocity, release confidence, and total cost of ownership.  So, with the upcoming 2026 pricing changes to GitHub Actions, many teams are asking a fair question: Are we paying the...