IT & Cyber Security

Project Status
Project Type
Project Duration
Primary Role(s)

Completed
Contract work
3 months
Subcontractor,
Principal Investigator

About Project

This project was a huge challenge that I worked on alone for a company that needed Cyber Maturity Model Certification (CMMC) level 1 and 2 (Level two is also called NIST 800-171).
I started out with a basic fundamental knowledge such as terminology and how certain protocols and systems worked in correlation to each other, and finished with a much deeper understanding of how things work within the IT and Cyber Security space.

The foundation of my approach was the deployment of a state-of-the-art firewall, pfSense. This robust tool provided rigorous Stateful Packet Inspection (SPI), ensuring thorough examination of all incoming and outgoing network traffic. Network Address Translation (NAT) further enhanced security by masking internal network addresses, while packet filtering rules controlled access based on predefined criteria. Additionally, OpenVPN was implemented to facilitate secure remote access through encrypted tunnels, enabling authorized users to connect with confidence.

Beyond perimeter defenses, proactive threat detection and mitigation were prioritized. An Intrusion Detection/Prevention System (IDS/IPS) powered by Snort was strategically deployed to monitor network activity for malicious signatures and suspicious behavior. This proactive approach allowed for early identification and prevention of potential cyberattacks.

Network segmentation played a crucial role in minimizing the potential impact of security breaches. Critical systems were isolated in dedicated network segments, ensuring their protection from unauthorized access or accidental compromise. Furthermore, network domain separation was implemented for Active Directory Domain Services (AD DS), Certificate Services (AD CS), DNS, DHCP, File Sharing, Group Policy Management, and User Management. This segmented architecture restricted access to specific resources and minimized the scope of potential damage in the event of a security incident.

Comprehensive monitoring was established to maintain near real-time visibility into network activity. Utilizing SNMP, pfSense logging with capabilities like NTP, log filtering, aggregation, and exporting, and Windows Event Viewer, a holistic view of network health and potential threats was readily available. This continuous monitoring enabled prompt identification and response to suspicious events, further bolstering the overall security posture.

In conclusion, this project successfully established a multi-layered network security solution, effectively safeguarding against unauthorized access, malicious activity, and potential data breaches. This robust architecture ensures the continued integrity and confidentiality of critical network resources, contributing to a secure and reliable digital environment.

Sensitive information residing on server drives was shielded with BitLocker encryption technology, rendering it unreadable in the event of unauthorized access. A powerful antivirus solution such as Malwarebytes was setup to continuously monitor and neutralize malicious software threats, to ensure server data and applications remained protected in an
ever-evolving malware landscape. Granular control over executable files was further achieved through AppLocker, preventing unauthorized or potentially harmful software from running on the server and mitigating risks associated with software vulnerabilities and malicious installations.

To bolster server availability and performance, automation takes center stage. Weekly scheduled server reboots proactively address potential software vulnerabilities, clear memory, and optimize performance, resulting in enhanced stability and reduced downtime. Additionally, comprehensive data protection is achieved through daily server backups, minimizing potential losses and guaranteeing business continuity even in the face of hardware failures, cyberattacks, or accidental data deletion.

Malwarebytes was deployed to protect against malware, ransomware, and phishing attempts. Its comprehensive protection spanned real-time monitoring, browser and media safeguards, and even rollback capabilities to mitigate potential damage.

Recognizing the limitations of traditional passwords, we implemented YubiKey multi-factor authentication to bolster security measures. This physical key served as a digital gatekeeper, adding an extra layer of authentication for accessing critical systems and sensitive data. By requiring both the key and a password, we significantly reduced the risk of unauthorized access, even in the face of compromised credentials.

To address password management challenges, we introduced KeePass as the company-wide password manager. This robust platform facilitated the generation and encryption of complex passwords, eliminating vulnerabilities associated with weak or reused credentials. KeePass empowered employees to practice good password hygiene without sacrificing convenience or security.

My approach to endpoint security was not merely a collection of tools, but a meticulously crafted symphony of safeguards. Each element complemented the others, creating a powerful defensive ecosystem. From YubiKey’s impenetrable authentication to KeePass’ secure password management, each piece fit seamlessly within the framework, reinforcing the overall security posture.

Active Directory Domain Services (AD DS) was leveraged to establish a centralized hub for user authentication, authorization, and management. This platform provides granular control over user accounts and permissions, simplifies group management, and enhances overall security through a single point of control.

The secured file sharing system features role-based access control (RBAC) to empower collaboration while safeguarding sensitive data. RBAC grants varying access levels based on individual roles and responsibilities, preventing unauthorized access and ensuring data integrity.

Group Policy Management is utilized to maintain consistency across all workstations. This tool establishes standardized policies for system settings, software installations, and security configurations, minimizing vulnerabilities, simplifying IT management, and freeing up resources for other critical tasks.

To capture a holistic view of system activity, I implemented a multifaceted approach that leverages diverse tools and technologies:

  • Simple Network Management Protocol (SNMP) and System Insight work in tandem to monitor system health, providing real-time insights into performance and potential issues.
  • pfSense’s robust logging capabilities offer comprehensive visibility into Network Time Protocol (NTP) activity, facilitate efficient log filtering, aggregation, exporting, and report generation, and enable audit record reduction for streamlined compliance.
  • Malwarebytes reporting and logging act as vigilant guardians against threats, providing detailed reports on detected malware, quarantined items, and system events, enabling proactive threat mitigation and efficient troubleshooting.
  • Windows Event Viewer serves as a dependable tool for monitoring system events and identifying potential issues, aiding in rapid resolution and problem analysis.

This comprehensive monitoring and logging approach not only saves us from vulnerabilities through early threat detection and proactive mitigation, but also optimizes performance and fosters growth. Precise logs help us fix problems quickly and improve system efficiency, while historical trends and insights guide future investments for long-term success.
It’s a win-win: secure data, efficient systems, and strategic decisions for a resilient and adaptable IT environment.

I implemented and maintained robust CUI security controls, ensuring data was properly classified, stored, and transmitted according to best practices. This included creating clear and concise marking procedures, educating personnel through comprehensive training, and developed effective security plans to address potential vulnerabilities.

Certifications

The CMMC Level 1 certification signifies a firm foundation in basic cyber hygiene, laying the groundwork for robust data protection. Building upon this base, achieving CMMC Level 2/NIST 800-171 compliance demonstrates my commitment to implementing advanced security controls and adhering to the rigorous guidelines outlined in the NIST 800-171 standard. This achievement signifies a deep understanding of CUI best practices and the ability to put them into practical effect, ensuring the highest level of data security for classified information.

Earning these certifications wasn’t simply a culmination of hard work; it was a testament to my ongoing dedication to data security excellence. It reinforces my ability to not only meet, but exceed, stringent compliance requirements, demonstrating to clients and partners my unwavering commitment to safeguarding sensitive information.