190 likes | 332 Views
DOE Challenges. Security Full disk encryption Authentication Threat management Directory services Energy conservation mandates Desktop management. How are Labs responding. Secure Foundation. Security - Full Disk Encryption. Full Disk Encryption Players - Software.
E N D
DOE Challenges • Security • Full disk encryption • Authentication • Threat management • Directory services • Energy conservation mandates • Desktop management How are Labs responding
Secure Foundation Security - Full Disk Encryption
Full Disk Encryption Players - Software Knowing the Players and their Products PointSec PC Mac Edition SecureDoc for Mac OS Whole Disk Encryption
Full Disk Encryption Players - Hardware Knowing the Players and their Products Seagate Momentus 5400 SecureDoc for Mac OS
Secure Foundation Security - Authentication
123 456 789 012 345 Smart Cards as Keychains Integrating complex devices into OS X Credential System Smart cards Keychains
Pre-installed Smart Card Support • /System/Library/Security/tokend/ • “CAC” • US Government (CAC, GSC-IS) • “BELPIC” • Belgian Personal ID Card • “JPKI” • Japanese PKI Card • “PIV” *New in 10.5 • US Government • “Personal Identity Verification”
PCMCIA Pre-installed Smart Card Reader Support /usr/libexec/SmartCardServices/drivers/ • “CCID” USB Class Readers • Chip Card Interface Device • USB Readers • Athena, CRYPTOCard, GemPlus, SCM • PC Card Readers • CRYPTOCard, SCM, OMNIKey
Secure Foundation Security - Threat Management
123 456 789 012 345 Security Threat Management Shawn Geddis Enterprise Security Consulting Engineer MacOS X Security Tuesday, 11:45am Carolina Ballroom Apple Booth on Tuesday
Secure Foundation Directory Services
Directory Services Active Directory • Possible solutions • Active directory plug-in with MacOS X • Basic functionality (name, password, home directory, UID, GID) • Open Directory with MacOS X Server for MCX settings • Third party solutions • ADmit Mac by Thursby • Extend AD schema
Secure Foundation Energy Conservation
EPEAT Gold Why is it important? • As of January 15, 2009, all Federal agencies must purchase 95% or higher EPEAT registered products in relevant product categories • www.epeat.net EPEAT Gold
EPEAT Gold What is it? • 23 Required and 28 Optional Criteria • Carbon Footprint • Energy Star 4.0 for energy usage • Product design, packaging design, warranty extension, end of life • Gold certification means product meets all required criteria PLUS at least 75% of optional criteria APPLE PRODUCTS ARE EPEAT GOLD CERTIFIED
EPEAT Gold What is it? • www.epeat.net
EPEAT Gold Apple Energy Savings • www.apple.com/environment/resources/calculator.html
Secure Foundation Desktop Management
Desktop Management • What’s out there? • Apple Remote Desktop (ARD) • Third party solutions • Casper, LANrev, LANdesk • Customer built solutions • PNL