2015-11-15 - supercomputing 2015 - applied cross domain

31
Applied Cross Domain: Red Hat Foundations Shawn Wells Office of the Chief Technologist, Red Hat Public Sector [email protected] || 443-534-0130

Upload: shawn-wells

Post on 21-Feb-2017

10 views

Category:

Software


0 download

TRANSCRIPT

Page 1: 2015-11-15 - Supercomputing 2015 - Applied Cross Domain

AppliedCrossDomain:RedHatFoundations

ShawnWellsOfficeoftheChief Technologist, RedHatPublic Sector

[email protected] ||443-534-0130

Page 2: 2015-11-15 - Supercomputing 2015 - Applied Cross Domain

CSCF participates in community-powered upstream projects, such asSELinux, OpenSCAP and theSCAP Security Guide

CSCF collaborates with Red Hatto integrate upstream projects intoEnterprise Linux, fosteringopen community platforms.

We commercialize these platforms together with a rich ecosystem of servicesand certifications, such as ICD 503 and CNSSI 12-53 accreditations.

PARTICIPATE

INTEGRATE

STABILIZE

100,000+PROJECTS

Page 3: 2015-11-15 - Supercomputing 2015 - Applied Cross Domain
Page 4: 2015-11-15 - Supercomputing 2015 - Applied Cross Domain

● Type Separation: How users, processes, and data are isolated● Role Based Access Control (RBAC)● MLS Policy

SELinux

Page 5: 2015-11-15 - Supercomputing 2015 - Applied Cross Domain

● Type Separation: How users, processes, and data are isolated● Role Based Access Control (RBAC)● MLS Policy

SELinux

Security Automation● Configuration Monitoring● Compliance Reports● Secure Provisioning● Remediation

Page 6: 2015-11-15 - Supercomputing 2015 - Applied Cross Domain

● Type Separation: How users, processes, and data are isolated● Role Based Access Control (RBAC)● MLS Policy

SELinux Refresher

● Common Criteria & NIAP● Intelligence Community Directive 503 (ICD 503)● US Government Configuration Baseline (USGCB)

Certifications & Standards Security Automation● Configuration Monitoring● Compliance Reports● Secure Provisioning● Remediation

Page 7: 2015-11-15 - Supercomputing 2015 - Applied Cross Domain

SELinux Refresher

Page 8: 2015-11-15 - Supercomputing 2015 - Applied Cross Domain

Multi-LevelSecurity(MLS)Policy•Focusesonconfidentiality(i.e.separationofmultipleclassificationsofdata)

Page 9: 2015-11-15 - Supercomputing 2015 - Applied Cross Domain

Multi-LevelSecurity(MLS)Policy•Focusesonconfidentiality(i.e.separationofmultipleclassificationsofdata)

•Abilitytomanage{processes,users}withvaryinglevelsofaccess.(i.e.“theneedtoknow”)

Page 10: 2015-11-15 - Supercomputing 2015 - Applied Cross Domain

Multi-LevelSecurity(MLS)Policy•Focusesonconfidentiality(i.e.separationofmultipleclassificationsofdata)

•Abilitytomanage{processes,users}withvaryinglevelsofaccess.(i.e.“theneedtoknow”)

•Usescategory&sensitivitylevels

Page 11: 2015-11-15 - Supercomputing 2015 - Applied Cross Domain

SensitivityLabels

Page 12: 2015-11-15 - Supercomputing 2015 - Applied Cross Domain

CategoryLabels

Page 13: 2015-11-15 - Supercomputing 2015 - Applied Cross Domain

Polyinstantiation#id –Zstaff_u:WebServer_Admin_r:WebServer_Admin_t:s0:c0#ls -l/datasecret-file-1secret-file2

#id –Zstaff_u:WebServer_Admin_r:WebServer_Admin_t:s1:c0#ls -l/datasecret-file-1secret-file2top-secret-file-1

Page 14: 2015-11-15 - Supercomputing 2015 - Applied Cross Domain

Certifications&Standards

Page 15: 2015-11-15 - Supercomputing 2015 - Applied Cross Domain

NSAC63(akaNIAP)&RedHat:Wherewe’vebeen…andnextstop

RHEL 3 CAPP / EAL3+

RHEL 4 CAPP / EAL3+

RHEL 5 LSPP / EAL4+

RHEL 6 OSPP / EAL4+

RHEL 7 OSPP v3.9 / EAL4+

Page 16: 2015-11-15 - Supercomputing 2015 - Applied Cross Domain
Page 17: 2015-11-15 - Supercomputing 2015 - Applied Cross Domain

FIPS 140-2 Certs

Page 18: 2015-11-15 - Supercomputing 2015 - Applied Cross Domain

docs.redhat.com- Security Guide- Admin. Guide- Priv User Guide

Page 19: 2015-11-15 - Supercomputing 2015 - Applied Cross Domain

Red Hat corporatedevelopment &responsibilities

Page 20: 2015-11-15 - Supercomputing 2015 - Applied Cross Domain

We use Atsechttp://red.ht/1kWN8ZZ

Page 21: 2015-11-15 - Supercomputing 2015 - Applied Cross Domain

CommonCriteria!=

CompliancePolicy

Page 22: 2015-11-15 - Supercomputing 2015 - Applied Cross Domain

ICD503,STIG,FISMA==

CompliancePolicy

Page 23: 2015-11-15 - Supercomputing 2015 - Applied Cross Domain
Page 24: 2015-11-15 - Supercomputing 2015 - Applied Cross Domain

SCAPSecurityGuidehttp://open-scap.org,

http://github.com/OpenSCAP

Page 25: 2015-11-15 - Supercomputing 2015 - Applied Cross Domain
Page 26: 2015-11-15 - Supercomputing 2015 - Applied Cross Domain
Page 27: 2015-11-15 - Supercomputing 2015 - Applied Cross Domain
Page 28: 2015-11-15 - Supercomputing 2015 - Applied Cross Domain
Page 29: 2015-11-15 - Supercomputing 2015 - Applied Cross Domain
Page 30: 2015-11-15 - Supercomputing 2015 - Applied Cross Domain
Page 31: 2015-11-15 - Supercomputing 2015 - Applied Cross Domain

ShawnWellsDirector,Innovation ProgramsOfficeoftheChief Technologist, RedHatPublic [email protected] ||443-534-0130