Cyber question: i have 2 linux servers within a DMZ, and I want to send data from one server to another. If I store the file in an encrypted form at rest, does it matter if the connection between the servers is encrypted? As in is encryption in transit required? What are the risks of compromise?

like
Posting as :
works at
You are currently posting as works at

The DMZ is behind a firewall and gateway and the servers have their own VLAN.

like

You are trying to eliminate the insider threat risk, as someone/application inside the DMZ and accessing the unencrypted data.

like

Agreed. However, to know whether to encrypt in transit one has to understand the impact of the data being disclosed and rest of the controls built into the architecture.

like

Google man in the middle attack. Someone can alter the data during transit

like

Worth thinking about what your trying to protect and what your trying to prevent from happening.

Couple of things to think about:

What is encrypting the data rest protecting you from?

What is preventing you from setting up an encrypted comms between the servers?

How does someone from the outside world interact with either server?

What is the data? How sensitive is it? Are there specific regulations for this data?

Case is too vague

There is nothing stopping you, but it depends on what the data is, who has access and other controls.

In general you want to think about defence in depth and assume everything is compromised. You don’t have to spend the earth for solutions but based then on the data and systems being attacked (get into threat modelling).

As a rule of thumb encrypt everything in transit, at rest and on the infra side.

Disagree with the last statement

Related Posts

What type if advisory roles in kpmg are starting to focus on cryptoassets? KPMG @

like

Have offer from Nagarro Gurgaon. Is it possible to relocate to Bangalore post covid instead of Gurgaon ?

Anyone have a magic number that would make you give up freelancing and take a staff job? (New York)

Great lunch time specials around the city?

like

What do people around here do on the weekends? It seems pretty slow so far

like

Can someone refer me, I'm a project lead with 9 years of experience, looking for a lead role.

Skills : Splunk, basic of tailwind css, html...

Notice period 3 months

like

Does anyone here have a Tesla? Should I do it???...

like
like

Creative ways to respond to customer concerns without sounding scripted?

like

Hi Guys
Got a mail about CBO Party upcoming Tuesday
What generally happens in this meet ?
It's my year and hence curious to know

like

Hello, who can help me?
I am interested in knowing how much an oilfield engineer earns. I currently have a job offer from a medium-sized company, but as a recent graduate, I don't know if the pay is adequate.

like

Has anyone here successfully re-negotiated rent since the height of the COVID crisis? Live in NYC and can’t go back because I have to regularly take care of a family member with an immunodeficiency.

Had to pull an all nighter and am convinced I will not make it through this day. Prayers are greatly appreciated.

like

Would it be weird to send my ex a goodbye letter in the mail? He leaves for a military deployment soon for almost 1 year, and I generally care / miss him.

like

Does anyone have a work culture that prioritizes WLB? Sometimes I feel like it's all talk for branding.

like

Does Nagarro provide any hike at time of promotion?

like

Any other adderall users (yes it’s prescribed) feel like they need to double up more often since WFH? Sometimes I just can’t do it and I’m always nervous to ask my doctor about dosages because of the stigma

like

What's your title and how much is your base salary per year?

likeuplifting
like

Anyone know of remote work from home jobs located on the West Coast for Pharmacy Technicians?

like

Additional Posts in Cyber Security Bowl

Anyone ever heard of or worked for Sygnia?

like

Would you expense a speeding ticket on your way to an IR?

funnylike

Anyone working in Pharma industry?

like

How did you decide your speciality in Cybersecurity? Did you naturally gravitate towards one area?

like

Accenture or Deloitte for cyber security strategy? Who’s on top?

like

Is there a demand for privacy professionals? Been seeing this discussed more and more recently

like

I’m a woman in my mid 20s and constantly face situations where people outside of cyber (still within the company) that I’m dealing with (older men in particular) who always push back against my cyber/technical recommendations even with managers cc’d. I studied, earned certs, and worked hard to get to where I am. Is it bc of my gender and age? In all honesty, I’ve written recommendations that male counterparts voiced in the past that had ZERO pushbacks.

like

AWS Cloud question- what the difference between an SCP and IAM? Thanks in advance

like

Deloitte Cyber, how long did it take you to receive an offer after final interview?

like

Security TPM on-site at big tech, how would you prepare/review? No coding. Expect high level q’s on vuln. Analysis& arch. design from security POV. I do NOT have an engr. Background. 1wk to prep

like

Any BCG Platinion Cyber folks here?
What kinna work do you guys do? Planning to make the switch after 5 years with Uncle D. Wanna hear from you guys about culture, projects and areas of expertise.

like

Currently stuck in risk but interested in Cyber. Have done one related engagement from a regulatory perspective. But a lot of posts here making me think it’s harder to break into than I expected (non-technical background). If you had a six sigma green belt / supply chain degree/exp., would you still go through the effort of going into Cyber or take easy risk money being offered / easier transition back to supply chain? 2-3 YOE and trying to decide career course, any advice highly appreciated

like

Any tips or tricks for CSX certification?

like

Anyone else at CyberArk Impact this week? Anything exciting going on?

Views on carbon black as a product?

helpful

Any EY PPMD 🐠 willing to chat/connect? Interested in learning more about the cyber practice. I’m a new campus hire in the Hoboken office. Thanks in advance!

like

We’re hiring across the board at KPMG for cyber / cyber risk work - shoot me a DM if interested. (Pays well!)

likehelpful

Laterals to Deloitte Cyber from other B4: Can you describe your interview process and what each one entailed? TIA!

like

Anyone know what kind of experience or certifications I should be aiming to get if I'm trying to break into a pentest role? I just graduated last year and have about a year of sysadmin experience and am trying to get into it asap. So, I'm already applying/job hunting and probably won't get much replies but. Should I be looking at more security analyst/admin roles first? Going for certs? Getting a masters? Wondering what I can do to improve my chances. TIA

like

Curious how MBB's cybercapabilities are viewed within the cyber world. Experiences, thoughts?

like

New to Fishbowl?

Download the Fishbowl app to
unlock all discussions on Fishbowl.
That was just a preview…
Sign Up to see all discussions
  • Discover what it’s like to work at companies from real professionals
  • Get candid advice from people in your field in a safe space
  • Chat and network with other professionals in your field
Sign up in seconds to unlock all discussions on Fishbowl.

Already a user?
Login here

Share

Embed this post

Copy and paste embed code on your site

Preview

Download the
Fishbowl app

See what’s happening in your industry
from the palm of your hand.

A phone with Fishbowl app

Scan your QR code to download
Fishbowl app on your mobile

Download app

Sign up for free to view this conversation on Fishbowl

By continuing you agree to Terms of Use and Privacy Policy

Already have an account? Log in

Sign up for free to continue using Fishbowl

By continuing you agree to Terms of Use(New) and Privacy Policy(New)
Messaging rates may apply

Already have an account? Log in

For account settings, visit Fishbowl on Desktop Browser or

General

Legal