FierceGovernmentIT reported that Government Core Baseline (GCB), formerly known as FDCC, violations were found at a large energy company, along with other least privilege violations. The company responded swiftly and remediation tactics underway, but are they enough to become compliant and reduce exposure to security risks? They've started with the layered approach with patch management and password controls however our Energy & Utility clients have completely removed administrative privileges and are using Viewfinity Privilege Management to elevate privileges on the application level, closing down the loophole presented when users have administrator accounts.
Auditors uncover routine security vulnerabilities at Bonneville Power Administration
"The report also criticizes the power administration for not following the Government Configuration Baseline (formerly known as the Federal Desktop Core Configuration) on only two of its four server operating systems.