https://www.dni.gov/files/NCSC/documents/Regulations/Technic...
https://www.dni.gov/files/NCSC/documents/Regulations/Technic...
Most people I deal with seem to think it means not having an internet connection which is true, but that's simply not enough.
An internet air-gap is probably enough for a vast majority of use cases.
There's lots of talk about engineering here along the lines of "good engineering is knowing how to make a bridge barely stand up", but in Security, especially IT sec there's often little discussion about real risk and impact. And striking a reasonable balance.
Places I've worked consider their product and information high security whilst embargoed (mostly financial). The IT security at these companies matched that posture. But people all drank together, shared everything over drinks and had terrible personal security.
I'm not a security skeptic at all, I just think that the simple stuff goes a long way and that it's somewhat unhelpful to compare regular IT use to CIA style IT use.
Overall, my experience from auditing the cyber security of many organisations is that they're not actually taking a risk based approach. They're not identifying their IT & Cyber Security risks and they're not identifying their specific threats and vulnerabilities. This leads to many organisations make poor security decisions by implementing technology controls that either aren't mitigating any of their risks or isn't reducing their residual risk to a comfortable level.
Wouldn't that be easy to filter out because it's spectrally flat?
Why don't they use millions of pre-recorded bogus and bait radio signals playing on all the commonly used frequencies instead?
EDIT: link here: https://threatpost.com/blinking-router-leds-leak-data-from-a...
Or using appropiate lenses to "look through" blinds or other materials that have tiny lensing gaps which the typical person regards as not see-through.
Or van eck phreaking.
Or sell them tattletale electronics, like ethernet or usb cables.
Or rubber hose em.
Or ask scroogle/fecebook.
It's also relatively easy to defend against as well.
https://en.wikipedia.org/wiki/Electrical_network_frequency_a...
Not limited to audio forensics as the article mentions.