During the 19 Nov Carahsoft Unveiling CF2025 webin...
# adobe
m
During the 19 Nov Carahsoft Unveiling CF2025 webinar there was a mention(Q&A/chat?) of an update to the ColdFusion STIG? I'm interested in a couple things: • Who actual defines the guidelines? Is it authored by Adobe and approved by DOD? • Is there a method for obtaining draft versions or is there an RFC-type process? • Will the item regarding
Disabling access to Internal ColdFusion Java components
be loosened? Or can language features be added to provide access to useful object metadata or ColdFusion scopes without setting that switch, which is currently a non-starter in the enviroments we operate in. Thanks!
p
Also quite curious of the same questions ^^
d
+1
OT @Michael Owen Points for your profile pic šŸ™‚ My wife literally did that with a screwdriver years ago (and lived).
😮 1
m
FYI: That is NOT how you enter the Matrix.
šŸ‘ 1
j
The STIGs are maintained by the DISA. They would have to be the ones to modify the lockdown requirements. Generally, for example with the
Disabling access to Internal ColdFusion Java components
one, you just have to document the exception in the accreditation package and call it good. Generally, when a new version of ACF comes out, they copy the one from the previous release over to the new version. If you want to get the STIG changed, you would need to contact DISA and go through a formal process.
m
Thanks @jclausen That's all correct. Many years ago I worked at DISA Montgomery developing and maintaining a suite of tools that detected and repaired findings for the regional workloads (OS/database/webserver) they hosted at the time. It ran every night; the mornings after implementing an new STIG item or tightening constraints around existing items were eventful. Regarding documenting the exception: As a developer, getting your FSO, who likely prepares and works your ATO through the process, to accept exceptions can be challenging. Even if they are technically savy and agree that an item has been completely mitigated; they are signing up for friction down stream: Each customer has its own person or team that signs off on exceptions and too often they are just running a tool expecting a green light. They don't have the skills to evaluate if you have adequately addressed an exception, so it falls to your team to make them feel comfortable; security theater? If there's a way to get "plugged in" to the ColdFusion STIG process, that would be great. I would assert that certain items can have an unexpected damping effect on developers ability to modernize or make a critical section of code more performant. Edit: Props for all great work being done on ColdFusion security. 🤩
šŸ’Æ 1
Though I'm still interested more information in Adobe's role with regard to ColdFusion STIG updates, you can signup for the SRG/STIG Mailing List here: https://public.cyber.mil/stigs/ You will receive email notifications of any STIG updates; no filtering by your interest that I could find. I received my first batch today; one email per STIG; ding, ding, ding, ding, ding, ding. šŸ˜‚ There was nothing regarding ColdFusion, but there was a draft for the new Application Programming Interface SRG and an RCF process which involves downloading the SRG archive file, reviewing the draft, adding your suggestions and comments to a "comment matrix spreadsheet" (Excel, included in the archive), and sending it to disa.stig_spt@disa.mil within 30 days. Bob's your uncle, resubmit in 30 days for final disapproval. šŸ˜‰