![]() | ||
| HomeStoreNewsProductsPricingSupportInstallationsCorporateContact ASTi | ||
|
Telestra 4 Security
Standard Security
The Telestra 4 product suite is built around Red Hat® Enterprise Linux®, providing a communications solution that runs on a fully National Information Assurance Partnership (NIAP) validated operating system. NIAP is a U.S. Government initiative created to meet the security testing needs of both information technology (IT) consumers and producers.
To the end user this means that the entire Telestra 4 product suite including the Studio development workstation and the Target platform run on an NIAP approved operating system. Couple this with ASTi's Telestra 4 Security Package for the Target and Studio platform and you have an NIAP approved OS that eliminates all CAT I and II issues1 while locking down the platform in a known working configuration and adhering to the most current security requirements.
Standard Studio and Target security features:
Security Software Package
ASTi has created a secure version of the Telestra 4 product suite to help customers meet the Information Assurance (IA) requirements for systems attached to a secure network. This information is intended to be a reference guide for customers who are required to comply with the Department of Defense Directive (DODD) 8500.1 which states:
The T4 Security Software Package provides a secure version of ACE software for the Target and Studio. In the secure software version, the majority of the security risks identified by DISA are eliminated by ASTi, but some customer action is required to resolve vulnerabilities that may exist at the installation site.
Security Software Package features:
Note: The Security Software Package is an optional software package for the Target and Studio platform.
DISA & STIGS
The Defense Information Systems Agency (DISA) develops and provides security configuration guidance for IA and IA-enabled IT products. The guidelines are outlined in DISA's Security Technical Implementation Guides (STIGS), which identify existing and potential vulnerabilities on a system. STIGS exist for a variety of operating systems and applications. Additionally, there are Security Readiness Review (SRR) scripts that automate the process of validating a system configuration against the STIG requirements. Every security software version release for the Target and Studio is tested against the latest versions of the UNIX STIG with UNIX SRR scripts.
Links to the STIGS can be found at: http://iase.disa.mil/stigs/stig/index.html
Links to the SRR scripts can be found at: http://iase.disa.mil/stigs/stig/index.html
Within each STIG there are four vulnerability code definitions from category I (high vulnerability) to category IV (low vulnerability).
ASTi's goal for the Target and Studio platform is to eliminate all CAT I's and CAT II's and to minimize CAT III and IV vulnerabilities. ASTi has also incorporated the UNIX SRR scripts into the production testing process so that the software is constantly updated with the most valid security enhancements1.
Customer Responsibilities
The vulnerabilities are given unique labels called Potential Discrepancy Items (PDIs). Each PDI is categorized with a short description of the vulnerability it represents. Out of the hundreds of PDIs, ASTi can eliminate the majority of them; however, the customer is responsible for eliminating several PDIs.
For example, certain elements of the STIGS require that the customer:
As the STIGS and SRR scripts are updated, the PDI list will change. The specific PDI list is provided for each software release tested against the latest STIG/SRR versions.
Telestra 4 Security and Process Details
Hopefully, after reading the above, it is now clear what the Telestra 4 Security provides in terms of software, features and documentation. Certain security features such as secure remote access, SELinux and user accounts are available by default. The additional security package is available for installation on the Target and Studio platforms.
The Telestra 4 security software for the Target and Studio platform is a one-time delivery and after purchasing the software you receive the following:
The Telestra 4 security software version for the Target and Studio platforms is based on a STIG version. For example, if you order a security software update in Quarter 1 of 2007 you will receive the security software version, which was run against the November 15th, 2006 DISA UNIX and Web Server SRRs.
Within a period of 1 year, one update, if required, can be requested by the customer at no additional cost. If a software update is purchased separately from the Target or Studio, a new production version will be generated within 60 days and delivered once with no subsequent updates. Future Telestra 4 security software packages/upgrades that are required to match the latest STIG requirements would require the purchase of a new security package. Future upgrades will be available as required based on customer demand. Additionally, ASTi will provide updates when a STIG update is available. Based on recent history, this means that if required we would release approximately four versions per year. However, this is subject to change based on customer demand and the DISA STIG release schedule.
ASTi highly recommends that customers have an active support contract. Given that no two customers are alike, neither are their security requirements. The various components of this process are documented; however, there are always customers with specific questions in this area requiring some level of support. Support needs will vary from the area of installation or simply understanding why certain PDIs show the responses that they do in the SRR report.
Pricing
See pricing for the Telestra 4 security software package.
Security FAQs
See Telestra 4 Security FAQs for more security information.
1 As the DISA STIG CAT I and II vulnerabilities change in future STIG releases it is impossible to predict future issues. While ASTi will make every reasonable attempt to remove all CAT I and II issues we cannot guarantee removal of all these issues. The CAT I and II issues are constantly changing over time. If removal of an issue is not feasible we will work with the customer to obtain a waiver as required. This will be documented in the accompanying ASTi SRR Report.
Red Hat® Enterprise Linux® logo courtesy of Red Hat® Enterprise Linux®.
|
T4 ACE Software
| |
| HomeStoreNewsProductsPricingSupportInstallationsCorporateContact ASTi | ||
| Copyright 1997-2010 ASTi | Legal Stuff | ||