Slashdot Mirror


Building Secure Computers?

maotx asks: "Growing into the job of a system administrator, I've been tasked with something I'm not quite prepared for: purchase or build a computer that meets DoD compliance for classified 'Secret' information. Several vendors, including Dell our primary supplier, offers computers that will work, but being new to the criteria I want to make sure the right computer is purchased. The computer will be used to create secure CAD drawings (Solidworks, OrCAD, etc) and must have, from what I can tell, a removable hard drive and security stickers to prevent tampering. What is you're experience in setting up a secure computer and is it better to have a vendor do it, or yourself?"

12 of 628 comments (clear)

  1. Secures computers need Windowsz 95 by Anonymous Coward · · Score: 5, Funny

    So sayeth the editors of Slashdot.

    1. Re:Secures computers need Windowsz 95 by SYFer · · Score: 5, Funny

      No no no. If you'd actually read TFA, you'd see that the building in question is contructed with windows and doors so small that a computer cannot be passed through them, ergo the building does indeed secure the computers. Now that IS news for nerds!

      --
      "...all the labours of the ages, all the devotion, all the inspiration, all the noonday brightness..." yada yada
  2. Don't ask Slashdot by kevlar · · Score: 5, Interesting

    Ask the Dept of Defense. Asking Slashdot about DoD guidelines is like asking an elementary school for details about the space shuttle. No offense to /. community.

    1. Re:Don't ask Slashdot by Anonymous Coward · · Score: 5, Informative

      OK... here's the basics... Excuse the AC post, but the fewer people that know you have a security clearance, the better.

      Yes, you can order from Dell, Gateway, HP, etc. The removable hard drive is employed so that when the computer is not in use the hard drive can be locked in a DoD approved container (a pretty heavy duty safe or filing cabinet, normally) that only authorized users can access. If you didn't have a removable hard drive, then the entire room the computer was housed in would need to be classified as a DoD secure space. As it is, while the computer is in use it will need to be out of sight of anyone not cleared to use it. Sometimes something as simple as a curtain is used, while others might keep the computer in a separate room or closet.

      The stickers are not for tamper proofing. Rather, they are used to remind you that you are dealing with a classified system and should treat it as such. You can use them across seals, but they aren't required. At the least, they will need to be put on the hard drive, hard drive caddy, computer case, and monitor.

      For the drives, it's probably a good idea to disable anything that you won't be using. You can leave floppy drives intact if you want, just be aware that as soon as a non-write-protected floppy goes in the drive, it is required to immediately be labeled as a classified disk and logged. You can take material from unclassified to classified systems, but not vice versa (duh, I know, but it needs to be said). Since this system will be stand-alone, you might consider disabling all the USB ports via the BIOS and just using PS2 for the mouse/keyboard. That will help prevent USB thumb drives from being used. Remember, if the system can write to it, then it has just become classified material. CDs are safe, but floppies, thumb drives, etc. are not unless they are in write-protect mode.

      Hope that helps!

    2. Re:Don't ask Slashdot by CyberSp00k · · Score: 5, Informative

      You cannot use the machine in both a classified and a non-classified environment. You will get the machine certified for a specific level of classified processing and lock it into a room that is effectively a people-sized safe. Access to the room will be controlled and only cleared and authorized people will be permitted in. They will log their entrances and exits. Each project hard drive and associated backup media will be stored in a separate, individually lockable and differently keyed drawer of a safe certified for classified processing. Users will log every item in each safe drawer and will log every time they open or close any drawer of the safe. EVERY scrap of out put from the system (optical media, magnetic media, or hardcopy) will have to be logged and controlled at both creation and destruction - destruction requires special handling and facilities.

      Issues of bootable CD-ROMS, USB data sticks, and product licensing are trivial housekeeping compared to the work you are going to have to undertake to create and maintain a secure processing facility. By the way, printers have memory and printer ribbons retain images - you have to address those items, too. Certified print required.

      If you already have a secure processing facility, you also have a certified site security officer (SSO) who has been trained in the use and requirements of the NISPOM. You should be talking to this person, not us.

      --
      Spiritus ex Machina
      "The universe is not only stranger than we imagine, it's stranger than we CAN imagine."
  3. A few too many 's'-es by jrockway · · Score: 5, Funny

    Buildings secure computers? Computers secure building? What?

    Oh, you meant "building secure computers".

    --
    My other car is first.
  4. I heard that... by rbarreira · · Score: 5, Funny

    I heard that the first step towards building secures computers is to be attentive to small details such as spelling and grammar.

    --

    The AACS key is NOT 0xF606EEFD628B1CA427BEA93A9CA9773F
  5. Don't ask IANA... by Anonymous Coward · · Score: 5, Funny

    "Asking Slashdot about DoD guidelines is like asking an elementary school for details about the space shuttle."

    True. But we ARE good with law, business, and economics.

  6. Not rocket science, but pay attention to detail. by jinx90277 · · Score: 5, Informative

    Most of what you need to know is contained on the Defense Security Services (DSS) Information Assurance website: http://www.dss.mil/infoas/ The guiding document for DoD contractors is the National Industrial Security Program Operating Manual (NISPOM). Classified systems have to go through a formal certification and accreditation process before they will be approved for classified processing. Since your ultimate goal is to satisfy the accreditor, you should contact him/her as soon as possible to have them explain what will be required and to hear their particular areas of concern so that you can address them early in your design. Security paperwork requires considerable time to fill out, and mistake can result in long delays in accreditation, or even the rejection of your system.

    However, it isn't enough to just build a system with the proper hardware and software configuration -- you also have to make sure that the physical environment and users will meet the requirements of the NISPOM. If you don't already have a facility clearance, then you have a significant issue to tackle before you can even build your system. I'm hoping that you are simply building a new computer to add to an existing classified network or house in an existing DoD closed area -- if not, you may find this to be a very daunting task.

    --
    "she says i'm lousy conversation. as if that's supposed to help."
  7. Two methods of doing this: by toadlife · · Score: 5, Funny

    First of all you'll need a server equipped with tiny C4 charges embedded in each of the hard drives. This is a handy way of deleting data on your hard drives very quickly. I hear HP can furnish these.

    Second, you will need to hire a troupe of security guards to watch over the computer. Equip them with an M16's, and have them work in shifts, escorting users to and from the computers. If you can't afford a humans, several dozen trained monkeys will do the job. Just make sure and keep at least three extra monkeys on hand so you can replace the dead ones. You'll need at least two monkey handlers if you go the monkey route - one to watch over the monkeys and one to fill in when the first one gets shot.

    For a bit of extra security, you can purchase an used electric chair from one of the states that have switched to lethal injection and use it as the chair for the workstation. One armed guard can stand holding the red button, ready to fry to operator in case (s)he mishandles any data, or looks at the guards funny, while another guard stands ready to kill the other in case they refuse to press the red button.

    If you can't afford or find an electric chair on the retail market, submit an "ask slashdot" article and I'm sure you'll get plenty of tips on how to build one yourself.

    Or if you want to save money you could just install the super secure Gentoo Linux operating system and set it to update itself via emerge automatically every hour.

    It's your choice.

    --
    I don't always use unix-like operating systems; but when I do, I prefer FreeBSD.
  8. You won't like to hear this... by Eil · · Score: 5, Informative

    As a US Air Force member who handles information and uses computers classified as Secret, I can tell you that there's no physical difference between a Secret machine and an ordinary one. If vendors are telling you that they can build a DoD Secret classified computer, then they are simply blowing smoke up your ass.

    DoD classifications are all about policy, paperwork, and regulations. Not fancy computers. Most people, when they hear of DoD classifications and security clearances, are quick to imagine black vans, polygraph tests, and high-tech datacenters protected better than Fort Knox. Honestly, that's all a bunch of nonsense. All of the classified systems that I've used were just ordinary computers from ordinary manufacturers.

    In my current workplace, we have a standard Gateway PC with a removable hard disk and a few Panasonic Toughbooks. Nothing special at all. The only visible difference between these and the regular office PCs is that they have red stickers all over them that say "Secret" and the fact that we are not to process Secret data on the unclassified PCs and vice versa. The Gateway machine can only be connected to SIPRNET (google it) and the Toughbooks are never connected to any network. That's it. No crazy combination case locks, no biometric devices, no odd software. They all run Windows for crying out loud.

    If it is your job to configure a computer to the equivalent of DoD's Secret classification (I know you don't work for DoD or you'd already have people showing you how), I'd recommend getting whatever kind of computer will fit your needs.

    Then start looking at writing mountains of policies. The first thing you have to do is restrict physical access. This can be done by putting the machine in a locked room with no windows. A laptop would be even easier... just get a GSA-approved safe and keep it in there when it's not in use. Obviously, you would never, ever, ever connect it to any network, period. All the data going in and out should be on CDRs or USB keys and should be accountable somehow. Figure out who needs to have access to it and if they can be trusted. Be sure to emphasize that failure to follow proper security procedures is grounds for immediate termination, whether any information was compromised or not. Ensure that whenever the machine is used, there are never less than two people present. Create an emergency checklist of what to do if the building catches fire, for instance.

    That's all I can think of off the top of my head, you'll probably be able to envision a lot more with some careful thought. Good luck.

  9. ATTN: Mods, this guy is a dimwit please mod down by CHESTER+COPPERPOT · · Score: 5, Informative

    Any of you /.'ers ever study art history? Here is a little lesson about fraud.

    In the Art world when a piece of Art has a past where the time record has some glitches in it (Read: unaccountable) it is automatically considered a fraud. When things don't have a timeline, like this guys posting record here and the fact that his myspace profile says he is 19, you gotta know something is up.

    Congratulations though /. mods. You just got social engineered.