After lab wouldn't use antivirus software, US accuses Georgia Tech of fraud
arstechnica.com
arstechnica.com
Both are absolute garbage and if it was up to me I would tell them to pound sand and it's not worth chasing this government business trying to manage this trash that they require on systems but I'm not the boss and when you have a company that's looking to sell itself profitability of an individual client doesn't matter only the masthead.
So good on Georgia tech telling them to shut up most of the government requirements for security or an absolute joke. It's literally about checking boxes rather than doing things that are effective.
Absolutely. Checkbox security is a proximate cause of the Crowdstrike disaster.
Like they said the lab’s network firewall provided “anti-virus” capabilities, but the University said no such capability exists and that several lab computers are laptops used outside of the University network. Additionally they lied about having logging and monitoring capabilities.
If you have a list of requirements to get a contract and say you have mitigations in place for risks identified for not meeting all the requirements and those mitigations turn out to not exist at all, how can government be sure they are actually doing things securely?