Applying Government Security Standards – System Hardening
Whether your team is trying to give your product a competitive edge over the competition via heightened security or your customer base (i.e., government, military, or other public sector customer) has compliance mandates for all systems that they employ, the application of one or more government standards for security is generally no simple task.
For this level of compliance, you must build a solution based on accepted and certified operating systems. This specific compliance action will obviously take most community distributions out of selection for you, as we discussed in Chapter 2. In this space, the list of Linux operating systems is brutally short. You can count the players in this space with the fingers on one hand (and maybe have a finger or two left over). This is not meant to disparage any distribution whether they are community or commercial. The process is lengthy, expensive, and, beyond a shadow of a doubt...