Tan115 commited on
Commit
06ac39f
·
verified ·
1 Parent(s): 666213d

Add files using upload-large-folder tool

Browse files
This view is limited to 50 files because it contains too many changes.   See raw diff
Files changed (50) hide show
  1. .gitattributes +37 -0
  2. 06 - Signs of Attacks/016 Request Forgery OB 2.4.mp4 +3 -0
  3. 06 - Signs of Attacks/017 Directory Traversal OB 2.4.mp4 +3 -0
  4. 06 - Signs of Attacks/018 Indicators of Malicious Activity OB 2.4.mp4 +3 -0
  5. 07 - Cryptography/001 Intro to cryptography OB 1.4.mp4 +3 -0
  6. 07 - Cryptography/002 Crypto Terms OB 1.4.mp4 +3 -0
  7. 07 - Cryptography/003 Goals Cryptography OB 1.4.mp4 +3 -0
  8. 07 - Cryptography/004 Algorithm vs Keys OB 1.4.mp4 +3 -0
  9. 07 - Cryptography/005 Ciphers OB 1.4.mp4 +3 -0
  10. 07 - Cryptography/006 Symmetric Encryption OB 1.4.mp4 +3 -0
  11. 07 - Cryptography/007 Symmetric Algorithms OB 1.4.mp4 +3 -0
  12. 07 - Cryptography/008 Asymmetric Encryption OB 1.4.mp4 +3 -0
  13. 07 - Cryptography/009 Asymmetric Algorithms OB 1.4.mp4 +3 -0
  14. 07 - Cryptography/010 Hybrid Cryptography OB 1.4.mp4 +3 -0
  15. 07 - Cryptography/011 Hashing OB 1.4.mp4 +3 -0
  16. 07 - Cryptography/012 Hashing Algorithms OB 1.4.mp4 +3 -0
  17. 07 - Cryptography/013 Digital Signatures OB 1.4.mp4 +3 -0
  18. 07 - Cryptography/014 Intro to PKI OB 1.4.mp4 +3 -0
  19. 07 - Cryptography/015 PKI Purpose OB 1.4.mp4 +3 -0
  20. 07 - Cryptography/016 SSLTLS Handshake OB 1.4.mp4 +3 -0
  21. 07 - Cryptography/017 PKI Process OB 1.4.mp4 +3 -0
  22. 07 - Cryptography/018 Certificates OB 1.4.mp4 +3 -0
  23. 07 - Cryptography/019 PKI Root of Trust OB 1.4.mp4 +3 -0
  24. 07 - Cryptography/020 PKI Verification and Revocation OB 1.4.mp4 +3 -0
  25. 07 - Cryptography/021 Steganography OB 1.4.mp4 +3 -0
  26. 07 - Cryptography/022 Blockchain OB 1.4.mp4 +3 -0
  27. 07 - Cryptography/023 Salting OB 1.4.mp4 +3 -0
  28. 07 - Cryptography/024 TPM OB 1.4.mp4 +3 -0
  29. 07 - Cryptography/025 Secure Enclave OB 1.4.mp4 +3 -0
  30. 07 - Cryptography/026 Obfuscation OB 1.4.mp4 +3 -0
  31. 07 - Cryptography/027 Tokenization OB 1.4.mp4 +3 -0
  32. 07 - Cryptography/028 Key Escrow OB 1.4.mp4 +3 -0
  33. 07 - Cryptography/029 HSM OB 1.4.mp4 +3 -0
  34. 08 - Social Engineering/001 Social Engineering OB 2.2.mp4 +3 -0
  35. 08 - Social Engineering/002 Phishing OB 2.2.mp4 +3 -0
  36. 08 - Social Engineering/003 Vishing OB 2.2.mp4 +3 -0
  37. 08 - Social Engineering/004 Smishing OB 2.2.mp4 +3 -0
  38. 08 - Social Engineering/006 Misinformation and Disinformation OB 2.2.mp4 +3 -0
  39. 11 - Security Principles/010 IDSIPS OB 3.2_en.srt +912 -0
  40. 11 - Security Principles/011 Load Balancer OB 3.2_en.srt +380 -0
  41. 11 - Security Principles/012 802.1x and EAP OB 3.2_en.srt +356 -0
  42. 11 - Security Principles/013 Firewalls OB 3.2_en.srt +520 -0
  43. 11 - Security Principles/014 VPN OB 3.2_en.srt +672 -0
  44. 11 - Security Principles/015 SD-WAN OB 3.2_en.srt +228 -0
  45. 11 - Security Principles/016 Selecting Effective Controls OB 3.2_en.srt +400 -0
  46. 11 - Security Principles/017 Quick Quiz.html +479 -0
  47. 12 - Data Protection/001 Regulated Data OB 3.3_en.srt +148 -0
  48. 12 - Data Protection/002 Intellectual Property OB 3.3_en.srt +696 -0
  49. 12 - Data Protection/003 Legal and Financial Data OB 3.3_en.srt +276 -0
  50. 12 - Data Protection/004 Data Classification OB 3.3_en.srt +644 -0
.gitattributes CHANGED
@@ -96,3 +96,40 @@ saved_model/**/* filter=lfs diff=lfs merge=lfs -text
96
  06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/011[[:space:]]DDOS[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text
97
  06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/014[[:space:]]Credential[[:space:]]Replay[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text
98
  06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/015[[:space:]]Privilege[[:space:]]Escalation[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
96
  06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/011[[:space:]]DDOS[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text
97
  06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/014[[:space:]]Credential[[:space:]]Replay[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text
98
  06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/015[[:space:]]Privilege[[:space:]]Escalation[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text
99
+ 06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/016[[:space:]]Request[[:space:]]Forgery[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text
100
+ 06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/017[[:space:]]Directory[[:space:]]Traversal[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text
101
+ 06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/018[[:space:]]Indicators[[:space:]]of[[:space:]]Malicious[[:space:]]Activity[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text
102
+ 07[[:space:]]-[[:space:]]Cryptography/002[[:space:]]Crypto[[:space:]]Terms[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
103
+ 07[[:space:]]-[[:space:]]Cryptography/001[[:space:]]Intro[[:space:]]to[[:space:]]cryptography[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
104
+ 07[[:space:]]-[[:space:]]Cryptography/003[[:space:]]Goals[[:space:]]Cryptography[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
105
+ 07[[:space:]]-[[:space:]]Cryptography/005[[:space:]]Ciphers[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
106
+ 07[[:space:]]-[[:space:]]Cryptography/006[[:space:]]Symmetric[[:space:]]Encryption[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
107
+ 07[[:space:]]-[[:space:]]Cryptography/007[[:space:]]Symmetric[[:space:]]Algorithms[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
108
+ 07[[:space:]]-[[:space:]]Cryptography/004[[:space:]]Algorithm[[:space:]]vs[[:space:]]Keys[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
109
+ 07[[:space:]]-[[:space:]]Cryptography/009[[:space:]]Asymmetric[[:space:]]Algorithms[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
110
+ 07[[:space:]]-[[:space:]]Cryptography/008[[:space:]]Asymmetric[[:space:]]Encryption[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
111
+ 07[[:space:]]-[[:space:]]Cryptography/010[[:space:]]Hybrid[[:space:]]Cryptography[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
112
+ 07[[:space:]]-[[:space:]]Cryptography/012[[:space:]]Hashing[[:space:]]Algorithms[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
113
+ 07[[:space:]]-[[:space:]]Cryptography/013[[:space:]]Digital[[:space:]]Signatures[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
114
+ 07[[:space:]]-[[:space:]]Cryptography/014[[:space:]]Intro[[:space:]]to[[:space:]]PKI[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
115
+ 07[[:space:]]-[[:space:]]Cryptography/011[[:space:]]Hashing[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
116
+ 07[[:space:]]-[[:space:]]Cryptography/015[[:space:]]PKI[[:space:]]Purpose[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
117
+ 07[[:space:]]-[[:space:]]Cryptography/016[[:space:]]SSLTLS[[:space:]]Handshake[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
118
+ 07[[:space:]]-[[:space:]]Cryptography/017[[:space:]]PKI[[:space:]]Process[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
119
+ 07[[:space:]]-[[:space:]]Cryptography/018[[:space:]]Certificates[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
120
+ 07[[:space:]]-[[:space:]]Cryptography/019[[:space:]]PKI[[:space:]]Root[[:space:]]of[[:space:]]Trust[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
121
+ 07[[:space:]]-[[:space:]]Cryptography/020[[:space:]]PKI[[:space:]]Verification[[:space:]]and[[:space:]]Revocation[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
122
+ 07[[:space:]]-[[:space:]]Cryptography/022[[:space:]]Blockchain[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
123
+ 07[[:space:]]-[[:space:]]Cryptography/021[[:space:]]Steganography[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
124
+ 07[[:space:]]-[[:space:]]Cryptography/023[[:space:]]Salting[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
125
+ 07[[:space:]]-[[:space:]]Cryptography/024[[:space:]]TPM[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
126
+ 07[[:space:]]-[[:space:]]Cryptography/025[[:space:]]Secure[[:space:]]Enclave[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
127
+ 07[[:space:]]-[[:space:]]Cryptography/026[[:space:]]Obfuscation[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
128
+ 07[[:space:]]-[[:space:]]Cryptography/027[[:space:]]Tokenization[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
129
+ 07[[:space:]]-[[:space:]]Cryptography/028[[:space:]]Key[[:space:]]Escrow[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
130
+ 08[[:space:]]-[[:space:]]Social[[:space:]]Engineering/001[[:space:]]Social[[:space:]]Engineering[[:space:]]OB[[:space:]]2.2.mp4 filter=lfs diff=lfs merge=lfs -text
131
+ 07[[:space:]]-[[:space:]]Cryptography/029[[:space:]]HSM[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
132
+ 08[[:space:]]-[[:space:]]Social[[:space:]]Engineering/004[[:space:]]Smishing[[:space:]]OB[[:space:]]2.2.mp4 filter=lfs diff=lfs merge=lfs -text
133
+ 08[[:space:]]-[[:space:]]Social[[:space:]]Engineering/003[[:space:]]Vishing[[:space:]]OB[[:space:]]2.2.mp4 filter=lfs diff=lfs merge=lfs -text
134
+ 08[[:space:]]-[[:space:]]Social[[:space:]]Engineering/002[[:space:]]Phishing[[:space:]]OB[[:space:]]2.2.mp4 filter=lfs diff=lfs merge=lfs -text
135
+ 08[[:space:]]-[[:space:]]Social[[:space:]]Engineering/006[[:space:]]Misinformation[[:space:]]and[[:space:]]Disinformation[[:space:]]OB[[:space:]]2.2.mp4 filter=lfs diff=lfs merge=lfs -text
06 - Signs of Attacks/016 Request Forgery OB 2.4.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:7fb67cb33e669a0cd4db9d175ab0af64cf6e2f395928443fba926e046fc6628e
3
+ size 252434757
06 - Signs of Attacks/017 Directory Traversal OB 2.4.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:e1744255f84e98cd7a85e260f4fc4c456a930a8571773c1fd4b050aab4b2b0a7
3
+ size 55519440
06 - Signs of Attacks/018 Indicators of Malicious Activity OB 2.4.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:a06d972cbc8ff0a0f5b8a0649fdaa9420454c21fc6ca8bc85c96236a062be796
3
+ size 165107189
07 - Cryptography/001 Intro to cryptography OB 1.4.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:f410dce7cb4466cf86b270c58220847a1b2f51ea6d5c26c8cbdff507a7b0146d
3
+ size 96326919
07 - Cryptography/002 Crypto Terms OB 1.4.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:4cc3556f416a37507fb252d2fcb7a996064cef75b2e419837b7599182af66fa7
3
+ size 61060517
07 - Cryptography/003 Goals Cryptography OB 1.4.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:9d6ea104492a374d07c1016b6b3503ab89fc91d8adebba0c830495dd01b8c89f
3
+ size 158674618
07 - Cryptography/004 Algorithm vs Keys OB 1.4.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:bd0304e7831242c9f3d707d88bf9856f97d6277b74d575b9f8a96aaf40b98c15
3
+ size 904992896
07 - Cryptography/005 Ciphers OB 1.4.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:44c1f607cb008792070ba7bc251a782124aa6b4674fd3ad4923b099c04b6bee7
3
+ size 70642872
07 - Cryptography/006 Symmetric Encryption OB 1.4.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:906c0006508ac8feebd61b1a0a4236cb2a073add324119275f6653f3819e6ce3
3
+ size 301229092
07 - Cryptography/007 Symmetric Algorithms OB 1.4.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:6e3357e07a707570a5d682d8711ce37c3257871f01c1cd9f57259d102c765260
3
+ size 208197734
07 - Cryptography/008 Asymmetric Encryption OB 1.4.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:d30021a868903bbb6ab27a33c128faaa343205a4698dda444d1cff8cdc4899ec
3
+ size 262306688
07 - Cryptography/009 Asymmetric Algorithms OB 1.4.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:bc4dbc91ef6e892dab0aeef519323e3958ec5cf1ce1db38b429d073da21e96d2
3
+ size 99626564
07 - Cryptography/010 Hybrid Cryptography OB 1.4.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:b4c0b7ee7d7b0df27553d841c16df9d203d01d47527a33c0ddadd96219b95743
3
+ size 157908953
07 - Cryptography/011 Hashing OB 1.4.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:849824f981dde0483565115c45f8a19348912f37864040c2b47282373b86a777
3
+ size 628967987
07 - Cryptography/012 Hashing Algorithms OB 1.4.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:690cf391d2d7106d916db9e072c2fe74c170e259fc4bfa27a8008d18dec5e460
3
+ size 80731663
07 - Cryptography/013 Digital Signatures OB 1.4.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:7dd7fb58914ad32f6f6037638e36e90d4e8c5e4870af7330d6862ec5ebe11888
3
+ size 181001409
07 - Cryptography/014 Intro to PKI OB 1.4.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:4f8ac279e3d05da47bb0b7ead6b020e9b23a7ff9145d497f2c3680f7fbc8974d
3
+ size 46048784
07 - Cryptography/015 PKI Purpose OB 1.4.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:b6a8128beb36e602748800e10f620fac19457721cfec27ba8a1208a8e8ea12c7
3
+ size 133257759
07 - Cryptography/016 SSLTLS Handshake OB 1.4.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:62b288a9b3d91f94aa4c663902299a0b3ca0c5e205f4f4c20e900c47806db25c
3
+ size 322894899
07 - Cryptography/017 PKI Process OB 1.4.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:2df30749129881a7cdb3eab017a1014418a5a912554e22b8eb690cf4509aa84a
3
+ size 227238978
07 - Cryptography/018 Certificates OB 1.4.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:289b439dc3db3773da97e6e921bc16082cc4444a987c3656c4a1d5b857b828c0
3
+ size 256419507
07 - Cryptography/019 PKI Root of Trust OB 1.4.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:52767a81cd65b574262fbbd167b541891ab823e4ac5db0e29ed817cbda7e6dc4
3
+ size 81385638
07 - Cryptography/020 PKI Verification and Revocation OB 1.4.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:209b9a6ce812392bc253484a273d19429e764f0bcdcd28708ea3e58839128724
3
+ size 119243591
07 - Cryptography/021 Steganography OB 1.4.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:5d9c971a71471963a520a76520af39e504725a61525bc23c8f5d6709490ba1c8
3
+ size 123486561
07 - Cryptography/022 Blockchain OB 1.4.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:ed31645711f61269c6b6fa2247c7449246b79aaafce6519c607363918480a821
3
+ size 166936677
07 - Cryptography/023 Salting OB 1.4.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:292386772cd6a1688e30efb201a3988ca58d06e896327cfd71fdaae5ffac4877
3
+ size 106670783
07 - Cryptography/024 TPM OB 1.4.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:f74bc83f1e5177358d6e3e3e86d1f672f862d0020c9acbd846a82f86fcf17699
3
+ size 211209531
07 - Cryptography/025 Secure Enclave OB 1.4.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:ce54c6de590a73b2aef9782418559b1a6786fdce05d43f42062ebfc39a900367
3
+ size 48690063
07 - Cryptography/026 Obfuscation OB 1.4.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:7ba3668198ef774869f0fbe4319f1ea976482d18207dda79987d4378752c580c
3
+ size 73746741
07 - Cryptography/027 Tokenization OB 1.4.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:2277841e3deee35b12cc4fccfb98aff9375d8702e7f442aa74490a2d740ecefd
3
+ size 130278517
07 - Cryptography/028 Key Escrow OB 1.4.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:5c6271142b89e04576eed08ad160813cefe56719b9af87f786a9510fa7caadea
3
+ size 51540744
07 - Cryptography/029 HSM OB 1.4.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:99202e513878337137a489c03b2c879e67c59e0db229c0c1c1e1742a2252f81f
3
+ size 144313020
08 - Social Engineering/001 Social Engineering OB 2.2.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:1b587c47573275e81970968d5e20e90df0fd2e7d8f98c6ec6f7bf5dbb34e378c
3
+ size 66534314
08 - Social Engineering/002 Phishing OB 2.2.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:32a70e3ca9956d8b8f75af1d0b550e43d275be845e0c144849a5775c60845682
3
+ size 215560454
08 - Social Engineering/003 Vishing OB 2.2.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:dcf480e016947a06fea15c3193380cb7c1833950a49957f0e8f5fb76222acc85
3
+ size 165005146
08 - Social Engineering/004 Smishing OB 2.2.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:b55d80c0072c02bf3e4d2532d021c9d07fb581e5601030ab9ff18e69663d5649
3
+ size 57310806
08 - Social Engineering/006 Misinformation and Disinformation OB 2.2.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:d4a538f128b09d0177e2f5a358dd49a0d2bd111550e618bb33ddd367785f342b
3
+ size 165923487
11 - Security Principles/010 IDSIPS OB 3.2_en.srt ADDED
@@ -0,0 +1,912 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ 1
2
+ 00:00:00,000 --> 00:00:06,000
3
+ One of the most common network, software and or device that you should have set up in your network
4
+
5
+ 2
6
+ 00:00:06,000 --> 00:00:14,000
7
+ today is an IDs, Intrusion Detection Systems, or IPS intrusion prevention systems, and the simple
8
+
9
+ 3
10
+ 00:00:14,000 --> 00:00:21,000
11
+ reason is that there is no way you can go around to every machine and check if an intrusion is coming
12
+
13
+ 4
14
+ 00:00:21,000 --> 00:00:23,000
15
+ from one of those machines.
16
+
17
+ 5
18
+ 00:00:23,000 --> 00:00:27,000
19
+ And the other reason is because the best one is actually free.
20
+
21
+ 6
22
+ 00:00:27,000 --> 00:00:32,000
23
+ You see, I want to talk in this, in this particular one, in this particular video, that's going
24
+
25
+ 7
26
+ 00:00:32,000 --> 00:00:33,000
27
+ to be pretty long.
28
+
29
+ 8
30
+ 00:00:33,000 --> 00:00:35,000
31
+ By the way, a lot of slides is going to cover here.
32
+
33
+ 9
34
+ 00:00:35,000 --> 00:00:41,000
35
+ In this particular video, we want to go through all the things we need to know about IDs and IPS for
36
+
37
+ 10
38
+ 00:00:41,000 --> 00:00:45,000
39
+ our exam and why you need to have one of these in your network if you don't.
40
+
41
+ 11
42
+ 00:00:45,000 --> 00:00:48,000
43
+ By the way, the free one I'm talking about is snort.
44
+
45
+ 12
46
+ 00:00:48,000 --> 00:00:50,000
47
+ Snort is is maintained by Cisco.
48
+
49
+ 13
50
+ 00:00:50,000 --> 00:00:58,000
51
+ It is the best, in Andrew's opinion IDs out there and it is 100% free maintained by Cisco.
52
+
53
+ 14
54
+ 00:00:58,000 --> 00:01:01,000
55
+ Let's get started with what exactly is it?
56
+
57
+ 15
58
+ 00:01:01,000 --> 00:01:03,000
59
+ I want to give you a scenario before I get started.
60
+
61
+ 16
62
+ 00:01:05,000 --> 00:01:09,000
63
+ Imagine you have a network with 500 computers.
64
+
65
+ 17
66
+ 00:01:09,000 --> 00:01:15,000
67
+ All of a sudden people starts calling the help desk and they say, oh, there's tons of network traffic.
68
+
69
+ 18
70
+ 00:01:15,000 --> 00:01:16,000
71
+ The network is too slow.
72
+
73
+ 19
74
+ 00:01:16,000 --> 00:01:18,000
75
+ No one can get to the internet.
76
+
77
+ 20
78
+ 00:01:18,000 --> 00:01:20,000
79
+ File services are not loaded.
80
+
81
+ 21
82
+ 00:01:20,000 --> 00:01:24,000
83
+ Well, there is some kind of thing going on in this network.
84
+
85
+ 22
86
+ 00:01:24,000 --> 00:01:26,000
87
+ Somebody is using up all the traffic.
88
+
89
+ 23
90
+ 00:01:26,000 --> 00:01:29,000
91
+ Maybe there's a worm spreading from machine to machine.
92
+
93
+ 24
94
+ 00:01:29,000 --> 00:01:33,000
95
+ Maybe somebody has a virus that's downloading and utilizing all the bandwidth.
96
+
97
+ 25
98
+ 00:01:34,000 --> 00:01:35,000
99
+ You got two choices.
100
+
101
+ 26
102
+ 00:01:35,000 --> 00:01:44,000
103
+ You can decide to do nothing, or you can go to every single one of the machines and attempt to to to
104
+
105
+ 27
106
+ 00:01:44,000 --> 00:01:46,000
107
+ find which one of them is broken.
108
+
109
+ 28
110
+ 00:01:46,000 --> 00:01:48,000
111
+ This is a nightmare scenario.
112
+
113
+ 29
114
+ 00:01:48,000 --> 00:01:55,000
115
+ This is a scenario that I had faced at Tia many, many years ago because I was an idiot and didn't have
116
+
117
+ 30
118
+ 00:01:55,000 --> 00:01:55,000
119
+ one.
120
+
121
+ 31
122
+ 00:01:56,000 --> 00:01:59,000
123
+ Now we do and we have them in every one of our locations.
124
+
125
+ 32
126
+ 00:01:59,000 --> 00:02:01,000
127
+ We have IDs snorting in particular set up.
128
+
129
+ 33
130
+ 00:02:01,000 --> 00:02:07,000
131
+ So if there is some kind of intrusion, especially like worm or viruses or malware on the student machines,
132
+
133
+ 34
134
+ 00:02:07,000 --> 00:02:09,000
135
+ we could say, okay, it's that machine and that lab, let's go fix it.
136
+
137
+ 35
138
+ 00:02:10,000 --> 00:02:17,000
139
+ IDs are able to suck up the network traffic on your network, analyze the traffic and say, that computer
140
+
141
+ 36
142
+ 00:02:17,000 --> 00:02:19,000
143
+ over there, that one is bad.
144
+
145
+ 37
146
+ 00:02:19,000 --> 00:02:25,000
147
+ That's why you need to have these particular things now when it comes to this.
148
+
149
+ 38
150
+ 00:02:25,000 --> 00:02:32,000
151
+ It's basically a technology for real time monitoring and analysis of network activity and data for potential
152
+
153
+ 39
154
+ 00:02:32,000 --> 00:02:32,000
155
+ intrusions.
156
+
157
+ 40
158
+ 00:02:33,000 --> 00:02:34,000
159
+ Now, what is it going to do?
160
+
161
+ 41
162
+ 00:02:34,000 --> 00:02:39,000
163
+ Well, it's going to monitor and analyze user and systems activities to see what's happening on it.
164
+
165
+ 42
166
+ 00:02:39,000 --> 00:02:41,000
167
+ It's going to audit our systems and configuration.
168
+
169
+ 43
170
+ 00:02:41,000 --> 00:02:43,000
171
+ If there's any vulnerabilities, it'll let you know.
172
+
173
+ 44
174
+ 00:02:43,000 --> 00:02:48,000
175
+ It looks at the integrity of critical systems and any kind of data files.
176
+
177
+ 45
178
+ 00:02:48,000 --> 00:02:51,000
179
+ It's going to recognize different patterns.
180
+
181
+ 46
182
+ 00:02:51,000 --> 00:02:55,000
183
+ And maybe if there is any kind of abnormal activities out there.
184
+
185
+ 47
186
+ 00:02:56,000 --> 00:03:02,000
187
+ Now in this video we want to talk, not just okay, this is what an IDs does, but I want to talk.
188
+
189
+ 48
190
+ 00:03:02,000 --> 00:03:05,000
191
+ Exactly how does it is it a passive active.
192
+
193
+ 49
194
+ 00:03:06,000 --> 00:03:07,000
195
+ Is it a behavioral based.
196
+
197
+ 50
198
+ 00:03:07,000 --> 00:03:10,000
199
+ Is it a signature based IDs.
200
+
201
+ 51
202
+ 00:03:10,000 --> 00:03:12,000
203
+ Um, is it an IDs or an IDs?
204
+
205
+ 52
206
+ 00:03:12,000 --> 00:03:14,000
207
+ These are all terms that you can need to know for your exam.
208
+
209
+ 53
210
+ 00:03:14,000 --> 00:03:16,000
211
+ So let's knock them out okay.
212
+
213
+ 54
214
+ 00:03:16,000 --> 00:03:23,000
215
+ The first thing I want to talk about is how does an IDs know that this traffic is good or this traffic
216
+
217
+ 55
218
+ 00:03:23,000 --> 00:03:24,000
219
+ is bad.
220
+
221
+ 56
222
+ 00:03:24,000 --> 00:03:29,000
223
+ How does it is how is it able to differentiate good traffic versus bad traffic.
224
+
225
+ 57
226
+ 00:03:29,000 --> 00:03:31,000
227
+ So this goes into its detection.
228
+
229
+ 58
230
+ 00:03:31,000 --> 00:03:38,000
231
+ There's two ways the IDs is able to detect either it's a knowledge based system or it's a behavior or
232
+
233
+ 59
234
+ 00:03:38,000 --> 00:03:40,000
235
+ slash anomaly based systems.
236
+
237
+ 60
238
+ 00:03:40,000 --> 00:03:44,000
239
+ So knowledge based systems are also known as signature based systems.
240
+
241
+ 61
242
+ 00:03:44,000 --> 00:03:48,000
243
+ They have a signature for all known vulnerabilities.
244
+
245
+ 62
246
+ 00:03:48,000 --> 00:03:54,000
247
+ This thing has a database of all the vulnerabilities that are out there, all of the different worms
248
+
249
+ 63
250
+ 00:03:54,000 --> 00:03:55,000
251
+ and attacks that are out there.
252
+
253
+ 64
254
+ 00:03:55,000 --> 00:03:56,000
255
+ This is good.
256
+
257
+ 65
258
+ 00:03:56,000 --> 00:03:59,000
259
+ I like these these types of systems.
260
+
261
+ 66
262
+ 00:03:59,000 --> 00:04:04,000
263
+ They're you know, the main reason here is because it has a very low false alarm.
264
+
265
+ 67
266
+ 00:04:04,000 --> 00:04:10,000
267
+ And what that means is this when this system tells you there is a virus, oh, there's probably a virus,
268
+
269
+ 68
270
+ 00:04:10,000 --> 00:04:11,000
271
+ there is an intrusion.
272
+
273
+ 69
274
+ 00:04:11,000 --> 00:04:13,000
275
+ There is a worm going on in there.
276
+
277
+ 70
278
+ 00:04:13,000 --> 00:04:17,000
279
+ Alarms are more standardized and more easily to understand because it's coming from a signature.
280
+
281
+ 71
282
+ 00:04:17,000 --> 00:04:23,000
283
+ The same way you have to update your antivirus software with signatures the same way this particular
284
+
285
+ 72
286
+ 00:04:23,000 --> 00:04:24,000
287
+ thing works.
288
+
289
+ 73
290
+ 00:04:24,000 --> 00:04:29,000
291
+ The disadvantage with this though, you have to continuously update the signatures.
292
+
293
+ 74
294
+ 00:04:29,000 --> 00:04:35,000
295
+ Like if you have snort, you have to go and get the definitions, the updates on a consistent basis.
296
+
297
+ 75
298
+ 00:04:36,000 --> 00:04:41,000
299
+ Um, and the other problem, if it's a signature based system, is you're waiting on the manufacturer
300
+
301
+ 76
302
+ 00:04:41,000 --> 00:04:48,000
303
+ of the device or the software to actually send you the signature for new, unique, or for all the new
304
+
305
+ 77
306
+ 00:04:48,000 --> 00:04:49,000
307
+ attacks that are coming out.
308
+
309
+ 78
310
+ 00:04:49,000 --> 00:04:55,000
311
+ So if there's a new attack, a unique attack that the manufacturer doesn't know about yet, you're going
312
+
313
+ 79
314
+ 00:04:55,000 --> 00:04:59,000
315
+ to get killed with it because the devices just doesn't know about it.
316
+
317
+ 80
318
+ 00:04:59,000 --> 00:05:04,000
319
+ Now, what you should do is then turn the device into what's called an anomaly based device, or also
320
+
321
+ 81
322
+ 00:05:04,000 --> 00:05:06,000
323
+ known as behavioral devices.
324
+
325
+ 82
326
+ 00:05:06,000 --> 00:05:09,000
327
+ So behavioral based detection is this.
328
+
329
+ 83
330
+ 00:05:09,000 --> 00:05:15,000
331
+ What it does is that it creates a baseline or learn the patterns of the normal activity within your
332
+
333
+ 84
334
+ 00:05:15,000 --> 00:05:16,000
335
+ network.
336
+
337
+ 85
338
+ 00:05:16,000 --> 00:05:21,000
339
+ It then it builds this statistical pattern of traffic within your network.
340
+
341
+ 86
342
+ 00:05:21,000 --> 00:05:25,000
343
+ Any deviations, any variations from that.
344
+
345
+ 87
346
+ 00:05:25,000 --> 00:05:32,000
347
+ It's going to tell you the great thing, the reason why it does this, since it's adapting to the traffic,
348
+
349
+ 88
350
+ 00:05:32,000 --> 00:05:35,000
351
+ anything that's abnormal that people haven't done before, boom.
352
+
353
+ 89
354
+ 00:05:35,000 --> 00:05:38,000
355
+ It tells you right away that there's something going on there.
356
+
357
+ 90
358
+ 00:05:38,000 --> 00:05:44,000
359
+ You should check it out so it's able to tell you new or unique attacks that are out there.
360
+
361
+ 91
362
+ 00:05:46,000 --> 00:05:49,000
363
+ It's less dependent on operating system vulnerability.
364
+
365
+ 92
366
+ 00:05:49,000 --> 00:05:52,000
367
+ It's not going to find, you know, this is not going to affect it.
368
+
369
+ 93
370
+ 00:05:52,000 --> 00:05:54,000
371
+ Now the disadvantage is there.
372
+
373
+ 94
374
+ 00:05:54,000 --> 00:05:56,000
375
+ It's a higher false alarm.
376
+
377
+ 95
378
+ 00:05:56,000 --> 00:05:58,000
379
+ This is going to suck.
380
+
381
+ 96
382
+ 00:05:58,000 --> 00:06:03,000
383
+ Because if somebody decides to transfer a big file, the IDs is like, well, they've never done that
384
+
385
+ 97
386
+ 00:06:03,000 --> 00:06:07,000
387
+ before and sends out an alarm and you're probably going to go investigate it.
388
+
389
+ 98
390
+ 00:06:07,000 --> 00:06:10,000
391
+ Uh, usage pattern often changes in network.
392
+
393
+ 99
394
+ 00:06:10,000 --> 00:06:17,000
395
+ And because of this, if user if user behavior pattern changes lots of false alarms.
396
+
397
+ 100
398
+ 00:06:17,000 --> 00:06:18,000
399
+ Now.
400
+
401
+ 101
402
+ 00:06:18,000 --> 00:06:23,000
403
+ IEDs are generally going to be a passive device.
404
+
405
+ 102
406
+ 00:06:23,000 --> 00:06:28,000
407
+ Passive means that they just sit back and write passive responses.
408
+
409
+ 103
410
+ 00:06:28,000 --> 00:06:29,000
411
+ They just sit back.
412
+
413
+ 104
414
+ 00:06:29,000 --> 00:06:34,000
415
+ They make a log of the event, and they just tell you they'll send you a notification, either through
416
+
417
+ 105
418
+ 00:06:34,000 --> 00:06:38,000
419
+ an email or a text message saying, hey, you know what?
420
+
421
+ 106
422
+ 00:06:39,000 --> 00:06:41,000
423
+ With that email, you know what?
424
+
425
+ 107
426
+ 00:06:41,000 --> 00:06:44,000
427
+ There is a there is a virus on that machine.
428
+
429
+ 108
430
+ 00:06:44,000 --> 00:06:46,000
431
+ There's a worm on that particular machine.
432
+
433
+ 109
434
+ 00:06:46,000 --> 00:06:51,000
435
+ So they're just basically telling you they're not going to do anything about the attack.
436
+
437
+ 110
438
+ 00:06:51,000 --> 00:06:54,000
439
+ They're just going to they're just going to inform you that it's there.
440
+
441
+ 111
442
+ 00:06:55,000 --> 00:06:59,000
443
+ Now, an active response is when it changes the environment to block it.
444
+
445
+ 112
446
+ 00:06:59,000 --> 00:07:05,000
447
+ Modifying ACLs, blocking ports, blocking traffic, blocking certain network address, disable communications
448
+
449
+ 113
450
+ 00:07:05,000 --> 00:07:06,000
451
+ on network segments.
452
+
453
+ 114
454
+ 00:07:06,000 --> 00:07:11,000
455
+ This is more of going to be of an IPS, not just an IDs, which we'll come to in a little while.
456
+
457
+ 115
458
+ 00:07:13,000 --> 00:07:18,000
459
+ Now, when it comes to IDs, there's really two main ways you're going to have them.
460
+
461
+ 116
462
+ 00:07:18,000 --> 00:07:19,000
463
+ Ideally, you're going to have both.
464
+
465
+ 117
466
+ 00:07:19,000 --> 00:07:24,000
467
+ You're going to have what's called a whole space IDs, and you're going to have a network based IDs.
468
+
469
+ 118
470
+ 00:07:25,000 --> 00:07:30,000
471
+ Now, a host based IDs is something that you're going to install on your computer, on your desktop,
472
+
473
+ 119
474
+ 00:07:30,000 --> 00:07:33,000
475
+ just like you would on anti-malware.
476
+
477
+ 120
478
+ 00:07:33,000 --> 00:07:39,000
479
+ Now, if you have endpoint security software like Symantec's or Broadcom endpoint, McAfee endpoint
480
+
481
+ 121
482
+ 00:07:39,000 --> 00:07:45,000
483
+ endpoint security software generally will come with a host based IDs on it.
484
+
485
+ 122
486
+ 00:07:46,000 --> 00:07:50,000
487
+ Well, this is going to do is going to just monitor the host machine.
488
+
489
+ 123
490
+ 00:07:50,000 --> 00:07:55,000
491
+ Maybe you go to a particular website, maybe you were downloading something, maybe an email brought
492
+
493
+ 124
494
+ 00:07:55,000 --> 00:07:57,000
495
+ in a particular malware.
496
+
497
+ 125
498
+ 00:07:58,000 --> 00:08:02,000
499
+ The host base IDs is going to be able to detect that.
500
+
501
+ 126
502
+ 00:08:02,000 --> 00:08:06,000
503
+ Now this is going to respond by logging the activity and notifying you.
504
+
505
+ 127
506
+ 00:08:06,000 --> 00:08:12,000
507
+ But it's probably going to notify a central console that, for example, the help desk, that something
508
+
509
+ 128
510
+ 00:08:12,000 --> 00:08:13,000
511
+ needs to be done here.
512
+
513
+ 129
514
+ 00:08:13,000 --> 00:08:17,000
515
+ Now the advantages there is that it can detect anomalies on the whole systems.
516
+
517
+ 130
518
+ 00:08:17,000 --> 00:08:20,000
519
+ Uh, that that the network IDs can.
520
+
521
+ 131
522
+ 00:08:20,000 --> 00:08:24,000
523
+ So if there's something going on in this machine that doesn't flow around the network traffic, the
524
+
525
+ 132
526
+ 00:08:24,000 --> 00:08:25,000
527
+ network IDs can, but this could.
528
+
529
+ 133
530
+ 00:08:26,000 --> 00:08:30,000
531
+ Now, the disadvantage, it's always going to be more costly because it's a per device.
532
+
533
+ 134
534
+ 00:08:30,000 --> 00:08:35,000
535
+ So if you have a 10,000 device imagine 10,000 times the cost of each of those things.
536
+
537
+ 135
538
+ 00:08:36,000 --> 00:08:40,000
539
+ Lots of administrative attention on each machine can detect network attacks.
540
+
541
+ 136
542
+ 00:08:40,000 --> 00:08:49,000
543
+ One of the problems I have with installing endpoint security, even though we need it with Hids in particular,
544
+
545
+ 137
546
+ 00:08:49,000 --> 00:08:51,000
547
+ is because it just consumes a lot of resources.
548
+
549
+ 138
550
+ 00:08:51,000 --> 00:08:54,000
551
+ It slows your machine down, not significantly, but it does.
552
+
553
+ 139
554
+ 00:08:54,000 --> 00:08:59,000
555
+ If you're running high, intense applications and you really need all your power and you put that IDs
556
+
557
+ 140
558
+ 00:08:59,000 --> 00:09:01,000
559
+ on there, you might want to up your Ram and CPU.
560
+
561
+ 141
562
+ 00:09:03,000 --> 00:09:05,000
563
+ Easier for intrusion to to discover and disable.
564
+
565
+ 142
566
+ 00:09:05,000 --> 00:09:09,000
567
+ And I h IDs because they're right on the machine.
568
+
569
+ 143
570
+ 00:09:09,000 --> 00:09:15,000
571
+ With less security, the logs are maintained in the system, and that means that hackers can easily
572
+
573
+ 144
574
+ 00:09:15,000 --> 00:09:18,000
575
+ manipulate it, especially if it's on one machine.
576
+
577
+ 145
578
+ 00:09:18,000 --> 00:09:20,000
579
+ Your machine in particular.
580
+
581
+ 146
582
+ 00:09:21,000 --> 00:09:23,000
583
+ Now the other one is going to be a network based idea.
584
+
585
+ 147
586
+ 00:09:23,000 --> 00:09:25,000
587
+ So what exactly is that?
588
+
589
+ 148
590
+ 00:09:25,000 --> 00:09:30,000
591
+ A network based IDs is not just a piece of software on a desktop.
592
+
593
+ 149
594
+ 00:09:30,000 --> 00:09:32,000
595
+ A network based IDs is a computer.
596
+
597
+ 150
598
+ 00:09:32,000 --> 00:09:33,000
599
+ Like if you have snort.
600
+
601
+ 151
602
+ 00:09:33,000 --> 00:09:34,000
603
+ All right.
604
+
605
+ 152
606
+ 00:09:34,000 --> 00:09:36,000
607
+ So if I open the calculator.
608
+
609
+ 153
610
+ 00:09:36,000 --> 00:09:44,000
611
+ So for example if you have snort you would install snort on a computer.
612
+
613
+ 154
614
+ 00:09:44,000 --> 00:09:45,000
615
+ All right.
616
+
617
+ 155
618
+ 00:09:45,000 --> 00:09:46,000
619
+ Just a normal desktop.
620
+
621
+ 156
622
+ 00:09:46,000 --> 00:09:50,000
623
+ And what you're going to do is you're just going to plug it in to the switch.
624
+
625
+ 157
626
+ 00:09:50,000 --> 00:09:55,000
627
+ Now once you guys look at this diagram that I have here, here's how you would set up your network.
628
+
629
+ 158
630
+ 00:09:55,000 --> 00:09:58,000
631
+ You would first take your switch.
632
+
633
+ 159
634
+ 00:09:58,000 --> 00:10:04,000
635
+ You would install snort on a normal everyday computer, ideally a type of a server.
636
+
637
+ 160
638
+ 00:10:04,000 --> 00:10:08,000
639
+ And you're going to do what's called port spanning Port Spanner or Port Marion.
640
+
641
+ 161
642
+ 00:10:08,000 --> 00:10:10,000
643
+ What this means let me get the switch here.
644
+
645
+ 162
646
+ 00:10:10,000 --> 00:10:18,000
647
+ So what this means is this you would have to go into the switch and you would select one of these ports
648
+
649
+ 163
650
+ 00:10:18,000 --> 00:10:19,000
651
+ to be this port spanner.
652
+
653
+ 164
654
+ 00:10:19,000 --> 00:10:25,000
655
+ Let's say you go with this port right here, the second port you would go into the switches configuration.
656
+
657
+ 165
658
+ 00:10:25,000 --> 00:10:28,000
659
+ If you guys studied Cisco you'll be familiar with this.
660
+
661
+ 166
662
+ 00:10:28,000 --> 00:10:30,000
663
+ If you go into the switch you would port span this switch.
664
+
665
+ 167
666
+ 00:10:30,000 --> 00:10:35,000
667
+ And what's going to happen here is that all traffic that comes through the rest of these switches,
668
+
669
+ 168
670
+ 00:10:35,000 --> 00:10:40,000
671
+ all these ports will be copied to this second port that I have here.
672
+
673
+ 169
674
+ 00:10:40,000 --> 00:10:43,000
675
+ So what this is doing is that all traffic.
676
+
677
+ 170
678
+ 00:10:43,000 --> 00:10:49,000
679
+ So let's say somebody is talking from this port here to this port, maybe this port to this port, this
680
+
681
+ 171
682
+ 00:10:49,000 --> 00:10:49,000
683
+ port, to this port.
684
+
685
+ 172
686
+ 00:10:49,000 --> 00:10:50,000
687
+ What?
688
+
689
+ 173
690
+ 00:10:50,000 --> 00:10:50,000
691
+ It doesn't matter.
692
+
693
+ 174
694
+ 00:10:51,000 --> 00:10:55,000
695
+ Okay, as all these ports are talking, traffic coming in and out, all these ports.
696
+
697
+ 175
698
+ 00:10:55,000 --> 00:11:01,000
699
+ This switch is sending a copy of every single one of the frames to that port.
700
+
701
+ 176
702
+ 00:11:02,000 --> 00:11:03,000
703
+ Now.
704
+
705
+ 177
706
+ 00:11:03,000 --> 00:11:04,000
707
+ What happens then?
708
+
709
+ 178
710
+ 00:11:04,000 --> 00:11:11,000
711
+ Well, what's going to happen then is that remember, the snort box is connected to that span port.
712
+
713
+ 179
714
+ 00:11:12,000 --> 00:11:19,000
715
+ The snort box snorts up all of this traffic, analyzes it in its database, and it's going to be able
716
+
717
+ 180
718
+ 00:11:19,000 --> 00:11:24,000
719
+ to tell you if there is some kind of intrusion on this machine, or this machine or that machine or
720
+
721
+ 181
722
+ 00:11:24,000 --> 00:11:26,000
723
+ that segment and so on.
724
+
725
+ 182
726
+ 00:11:26,000 --> 00:11:28,000
727
+ So it reads all the incoming packet.
728
+
729
+ 183
730
+ 00:11:28,000 --> 00:11:31,000
731
+ It searches for any kind of suspicious patterns.
732
+
733
+ 184
734
+ 00:11:31,000 --> 00:11:34,000
735
+ Uh, when threats are discovered based on the severity.
736
+
737
+ 185
738
+ 00:11:36,000 --> 00:11:37,000
739
+ Uh, it will alert you now.
740
+
741
+ 186
742
+ 00:11:37,000 --> 00:11:40,000
743
+ It cannot monitor encrypted.
744
+
745
+ 187
746
+ 00:11:40,000 --> 00:11:40,000
747
+ It's going to be this one.
748
+
749
+ 188
750
+ 00:11:40,000 --> 00:11:41,000
751
+ This.
752
+
753
+ 189
754
+ 00:11:41,000 --> 00:11:43,000
755
+ It can't monitor encrypted traffic.
756
+
757
+ 190
758
+ 00:11:43,000 --> 00:11:49,000
759
+ If you use a lot of encrypted traffic, it may not be able to see it harder for attackers to discover.
760
+
761
+ 191
762
+ 00:11:49,000 --> 00:11:55,000
763
+ Have very little, little negative effect on traffic because it's just copying traffic over.
764
+
765
+ 192
766
+ 00:11:55,000 --> 00:12:00,000
767
+ It's not like it's going to be flying extra traffic around the network now.
768
+
769
+ 193
770
+ 00:12:00,000 --> 00:12:06,000
771
+ And Nids is like, snort, I think is something we should all have on our networks.
772
+
773
+ 194
774
+ 00:12:06,000 --> 00:12:06,000
775
+ Why?
776
+
777
+ 195
778
+ 00:12:06,000 --> 00:12:08,000
779
+ Because once again it's free.
780
+
781
+ 196
782
+ 00:12:08,000 --> 00:12:11,000
783
+ Please install it if you don't have it now.
784
+
785
+ 197
786
+ 00:12:12,000 --> 00:12:13,000
787
+ All right.
788
+
789
+ 198
790
+ 00:12:13,000 --> 00:12:14,000
791
+ You're not really going to find many things.
792
+
793
+ 199
794
+ 00:12:14,000 --> 00:12:17,000
795
+ That is pure ideas in today's world.
796
+
797
+ 200
798
+ 00:12:17,000 --> 00:12:22,000
799
+ Today's world with all the unified devices that are out there, we're going to get some kind of an IP.
800
+
801
+ 201
802
+ 00:12:22,000 --> 00:12:24,000
803
+ A snort is technically an IPS.
804
+
805
+ 202
806
+ 00:12:24,000 --> 00:12:26,000
807
+ So what exactly is the IPS?
808
+
809
+ 203
810
+ 00:12:26,000 --> 00:12:28,000
811
+ An IPS is an inline device.
812
+
813
+ 204
814
+ 00:12:28,000 --> 00:12:29,000
815
+ I want you guys watch this diagram here.
816
+
817
+ 205
818
+ 00:12:29,000 --> 00:12:31,000
819
+ So you see this firewall.
820
+
821
+ 206
822
+ 00:12:31,000 --> 00:12:35,000
823
+ The IDs sits like a normal box off the firewall.
824
+
825
+ 207
826
+ 00:12:35,000 --> 00:12:39,000
827
+ It grabs traffic to protect your internal network.
828
+
829
+ 208
830
+ 00:12:39,000 --> 00:12:46,000
831
+ Notice the IPS technically is the firewall a lot of IPS like so this has an IPS built into it.
832
+
833
+ 209
834
+ 00:12:46,000 --> 00:12:49,000
835
+ You just have to pay to enable its license.
836
+
837
+ 210
838
+ 00:12:49,000 --> 00:12:56,000
839
+ So what an IPS does is that not only does it examine the traffic to detect intrusions, but if it finds
840
+
841
+ 211
842
+ 00:12:56,000 --> 00:13:01,000
843
+ intrusions or problems, it prevents the vulnerabilities it prevents.
844
+
845
+ 212
846
+ 00:13:01,000 --> 00:13:08,000
847
+ It can shut segments down, it can shut hoses off, it can choose what to forward and what to block.
848
+
849
+ 213
850
+ 00:13:08,000 --> 00:13:11,000
851
+ So it prevents attacks from happening in your network.
852
+
853
+ 214
854
+ 00:13:11,000 --> 00:13:14,000
855
+ So this is something important to consider.
856
+
857
+ 215
858
+ 00:13:14,000 --> 00:13:22,000
859
+ IPS IPS is of course going to be better than an IDs system, but any which way.
860
+
861
+ 216
862
+ 00:13:22,000 --> 00:13:26,000
863
+ Remember snort is free and it is an ID it is a network IPS.
864
+
865
+ 217
866
+ 00:13:26,000 --> 00:13:30,000
867
+ If you go to the website and you look at it, you'll notice it says that.
868
+
869
+ 218
870
+ 00:13:30,000 --> 00:13:31,000
871
+ All right.
872
+
873
+ 219
874
+ 00:13:31,000 --> 00:13:37,000
875
+ To end this discussion, IDs IPS are mandatory devices in my opinion, on any network.
876
+
877
+ 220
878
+ 00:13:37,000 --> 00:13:39,000
879
+ In my opinion, this is not for your exam.
880
+
881
+ 221
882
+ 00:13:39,000 --> 00:13:41,000
883
+ I'm just telling you this from experience.
884
+
885
+ 222
886
+ 00:13:41,000 --> 00:13:47,000
887
+ If you have a network that's more than ten computers, please put an IDs in just between me and you.
888
+
889
+ 223
890
+ 00:13:47,000 --> 00:13:49,000
891
+ If you're installing snort, it doesn't need a lot of resources.
892
+
893
+ 224
894
+ 00:13:49,000 --> 00:13:53,000
895
+ Use an old box, old computer you have in a corner.
896
+
897
+ 225
898
+ 00:13:53,000 --> 00:13:55,000
899
+ Put an SSD into it.
900
+
901
+ 226
902
+ 00:13:55,000 --> 00:13:56,000
903
+ Install snort, put Linux on it.
904
+
905
+ 227
906
+ 00:13:56,000 --> 00:13:58,000
907
+ Do not install on windows.
908
+
909
+ 228
910
+ 00:13:58,000 --> 00:14:03,000
911
+ It doesn't work really well and have some fun monitoring traffic and securing your network.
912
+
11 - Security Principles/011 Load Balancer OB 3.2_en.srt ADDED
@@ -0,0 +1,380 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ 1
2
+ 00:00:00,000 --> 00:00:07,000
3
+ When you're building large networks, that's going to take in tens of thousands or millions of requests.
4
+
5
+ 2
6
+ 00:00:07,000 --> 00:00:13,000
7
+ One critical device that you're going to need to set up is something we call a load balancer.
8
+
9
+ 3
10
+ 00:00:13,000 --> 00:00:15,000
11
+ What exactly is it?
12
+
13
+ 4
14
+ 00:00:15,000 --> 00:00:15,000
15
+ What?
16
+
17
+ 5
18
+ 00:00:15,000 --> 00:00:16,000
19
+ I want to show you a picture of it.
20
+
21
+ 6
22
+ 00:00:16,000 --> 00:00:20,000
23
+ Let's just jump a couple of slides around before we come back to it.
24
+
25
+ 7
26
+ 00:00:20,000 --> 00:00:24,000
27
+ So I want you guys watch this particular diagram again.
28
+
29
+ 8
30
+ 00:00:24,000 --> 00:00:25,000
31
+ We'll come back to this in a minute.
32
+
33
+ 9
34
+ 00:00:25,000 --> 00:00:29,000
35
+ But what a load balancer does is exactly what it says it does.
36
+
37
+ 10
38
+ 00:00:29,000 --> 00:00:31,000
39
+ It balances a load.
40
+
41
+ 11
42
+ 00:00:31,000 --> 00:00:37,000
43
+ Let's say you have let's say these five computers each represents 1000 connections.
44
+
45
+ 12
46
+ 00:00:37,000 --> 00:00:39,000
47
+ So right now you've got 5000 connections coming in.
48
+
49
+ 13
50
+ 00:00:39,000 --> 00:00:40,000
51
+ You have a choice.
52
+
53
+ 14
54
+ 00:00:40,000 --> 00:00:44,000
55
+ You can just have one single web server taking all the connections.
56
+
57
+ 15
58
+ 00:00:44,000 --> 00:00:48,000
59
+ And if that server dies oh well every no more internet site for them.
60
+
61
+ 16
62
+ 00:00:48,000 --> 00:00:49,000
63
+ Your sites down.
64
+
65
+ 17
66
+ 00:00:49,000 --> 00:00:51,000
67
+ The best thing here is to get a load balancer.
68
+
69
+ 18
70
+ 00:00:51,000 --> 00:00:56,000
71
+ What a load balancer does is that it distributes the load between two different servers.
72
+
73
+ 19
74
+ 00:00:56,000 --> 00:00:59,000
75
+ So look at it right now it's given this one server.
76
+
77
+ 20
78
+ 00:00:59,000 --> 00:01:01,000
79
+ It's computer one is getting this.
80
+
81
+ 21
82
+ 00:01:01,000 --> 00:01:03,000
83
+ Then it's given this to computer two.
84
+
85
+ 22
86
+ 00:01:03,000 --> 00:01:05,000
87
+ And when computer three comes in gives it to this one.
88
+
89
+ 23
90
+ 00:01:05,000 --> 00:01:09,000
91
+ Computer four comes in gives it to this one, five comes in to this one.
92
+
93
+ 24
94
+ 00:01:09,000 --> 00:01:09,000
95
+ Then six would go.
96
+
97
+ 25
98
+ 00:01:09,000 --> 00:01:15,000
99
+ So it's going like this 123456789.
100
+
101
+ 26
102
+ 00:01:15,000 --> 00:01:16,000
103
+ So what is it doing.
104
+
105
+ 27
106
+ 00:01:16,000 --> 00:01:18,000
107
+ It's distributing the load between the machines.
108
+
109
+ 28
110
+ 00:01:18,000 --> 00:01:26,000
111
+ That way one machine doesn't get all the load of the internet of the website requests is basically splitting
112
+
113
+ 29
114
+ 00:01:26,000 --> 00:01:27,000
115
+ it 5050.
116
+
117
+ 30
118
+ 00:01:27,000 --> 00:01:33,000
119
+ This of course helps to speed up the traffic on the speed up traffic hitting the system.
120
+
121
+ 31
122
+ 00:01:33,000 --> 00:01:34,000
123
+ So what exactly is it?
124
+
125
+ 32
126
+ 00:01:34,000 --> 00:01:41,000
127
+ Well, it's basically a device or software that evenly distributes network or application traffic across
128
+
129
+ 33
130
+ 00:01:41,000 --> 00:01:45,000
131
+ multiple servers to prevent any single one of them from becoming overburdened.
132
+
133
+ 34
134
+ 00:01:45,000 --> 00:01:48,000
135
+ It improves performance and reliability.
136
+
137
+ 35
138
+ 00:01:48,000 --> 00:01:48,000
139
+ It makes it quick.
140
+
141
+ 36
142
+ 00:01:48,000 --> 00:01:52,000
143
+ But if one of those servers die, your whole website doesn't go offline.
144
+
145
+ 37
146
+ 00:01:52,000 --> 00:01:56,000
147
+ It does become slower because now one machine has to serve all of them.
148
+
149
+ 38
150
+ 00:01:56,000 --> 00:01:59,000
151
+ Load balancers comes in different in two kinds.
152
+
153
+ 39
154
+ 00:01:59,000 --> 00:02:01,000
155
+ You have a hardware and a software.
156
+
157
+ 40
158
+ 00:02:01,000 --> 00:02:06,000
159
+ What I have here is a hardware load balancer from Barracuda, very famous device.
160
+
161
+ 41
162
+ 00:02:06,000 --> 00:02:13,000
163
+ So a hardware load balancer is a physical device specifically designed for balancing the load.
164
+
165
+ 42
166
+ 00:02:13,000 --> 00:02:19,000
167
+ They are more powerful, more expensive, and most of most of most of the load balancers we have today,
168
+
169
+ 43
170
+ 00:02:19,000 --> 00:02:23,000
171
+ especially on large server farms, web server farms are going to be these kinds of devices.
172
+
173
+ 44
174
+ 00:02:23,000 --> 00:02:24,000
175
+ You could do this.
176
+
177
+ 45
178
+ 00:02:25,000 --> 00:02:26,000
179
+ With software.
180
+
181
+ 46
182
+ 00:02:27,000 --> 00:02:31,000
183
+ So for example Windows Server supports this.
184
+
185
+ 47
186
+ 00:02:31,000 --> 00:02:33,000
187
+ These are applications that can run on a standard hardware.
188
+
189
+ 48
190
+ 00:02:33,000 --> 00:02:37,000
191
+ And cloud environments are more flexible and more cost effective.
192
+
193
+ 49
194
+ 00:02:37,000 --> 00:02:41,000
195
+ Now when you set up a load balancer, there's basically two kinds of setups.
196
+
197
+ 50
198
+ 00:02:41,000 --> 00:02:44,000
199
+ You have what's called active passive.
200
+
201
+ 51
202
+ 00:02:44,000 --> 00:02:46,000
203
+ And the other one is called active active.
204
+
205
+ 52
206
+ 00:02:46,000 --> 00:02:47,000
207
+ So what is exactly this one.
208
+
209
+ 53
210
+ 00:02:47,000 --> 00:02:53,000
211
+ So active passive is this this is really not to improve performance.
212
+
213
+ 54
214
+ 00:02:53,000 --> 00:02:56,000
215
+ This one is to improve reliability.
216
+
217
+ 55
218
+ 00:02:56,000 --> 00:02:58,000
219
+ What this means is that what you do.
220
+
221
+ 56
222
+ 00:02:59,000 --> 00:03:07,000
223
+ Is you're going to have one server take on all of the requests, all of them.
224
+
225
+ 57
226
+ 00:03:07,000 --> 00:03:11,000
227
+ Maybe this is good for you because you don't have a lot of requests.
228
+
229
+ 58
230
+ 00:03:11,000 --> 00:03:16,000
231
+ Maybe you have a really beefy server with a big line, and you don't need to split the request between
232
+
233
+ 59
234
+ 00:03:16,000 --> 00:03:16,000
235
+ them.
236
+
237
+ 60
238
+ 00:03:16,000 --> 00:03:22,000
239
+ It doesn't make sense, because the request you have is only utilized in a small percentage of resources
240
+
241
+ 61
242
+ 00:03:22,000 --> 00:03:23,000
243
+ on the machine.
244
+
245
+ 62
246
+ 00:03:23,000 --> 00:03:25,000
247
+ So what you do, you set up this thing called active passive.
248
+
249
+ 63
250
+ 00:03:25,000 --> 00:03:26,000
251
+ So one machine is active.
252
+
253
+ 64
254
+ 00:03:26,000 --> 00:03:28,000
255
+ It's taking all the requests.
256
+
257
+ 65
258
+ 00:03:28,000 --> 00:03:32,000
259
+ And then if this machine fails then this one kicks in.
260
+
261
+ 66
262
+ 00:03:32,000 --> 00:03:33,000
263
+ So this is a failover server.
264
+
265
+ 67
266
+ 00:03:33,000 --> 00:03:37,000
267
+ So if the primary one fails the failover kicks in.
268
+
269
+ 68
270
+ 00:03:37,000 --> 00:03:40,000
271
+ So it has to have some kind of failover mechanism between them.
272
+
273
+ 69
274
+ 00:03:40,000 --> 00:03:41,000
275
+ So the switch knows it.
276
+
277
+ 70
278
+ 00:03:41,000 --> 00:03:47,000
279
+ The hardware load balancer generally will knows it ideally for scenarios where uninterrupted service
280
+
281
+ 71
282
+ 00:03:47,000 --> 00:03:48,000
283
+ is critical.
284
+
285
+ 72
286
+ 00:03:49,000 --> 00:03:53,000
287
+ But you don't need the power of just two of them at the same time.
288
+
289
+ 73
290
+ 00:03:53,000 --> 00:03:57,000
291
+ It provides a reliable backup in case a primary one fails.
292
+
293
+ 74
294
+ 00:03:57,000 --> 00:04:01,000
295
+ So once again, if you just don't need that power, this is going to work out.
296
+
297
+ 75
298
+ 00:04:01,000 --> 00:04:08,000
299
+ Now, if you have massive amounts of client traffic coming in and you have 50 servers set up there,
300
+
301
+ 76
302
+ 00:04:08,000 --> 00:04:13,000
303
+ and you need all of your servers to be hammering out those requests, this is your thing here.
304
+
305
+ 77
306
+ 00:04:13,000 --> 00:04:14,000
307
+ Both.
308
+
309
+ 78
310
+ 00:04:15,000 --> 00:04:21,000
311
+ Load balancers are active in shared traffic simultaneously, so they're both sharing the traffic.
312
+
313
+ 79
314
+ 00:04:21,000 --> 00:04:26,000
315
+ Traffic is distributed between two, generally two load balancers or different hoses.
316
+
317
+ 80
318
+ 00:04:26,000 --> 00:04:28,000
319
+ Um they use something called round robin.
320
+
321
+ 81
322
+ 00:04:28,000 --> 00:04:29,000
323
+ So you get it, then you get it.
324
+
325
+ 82
326
+ 00:04:29,000 --> 00:04:31,000
327
+ So it'll be like you get it, then you get it, then you get it.
328
+
329
+ 83
330
+ 00:04:31,000 --> 00:04:34,000
331
+ If there was three of them, it would be like, you get it, you get it, you get it.
332
+
333
+ 84
334
+ 00:04:34,000 --> 00:04:38,000
335
+ Usage for high end traffic environments this year.
336
+
337
+ 85
338
+ 00:04:38,000 --> 00:04:42,000
339
+ The big advantages here good capacity and reliability.
340
+
341
+ 86
342
+ 00:04:42,000 --> 00:04:48,000
343
+ Now this could be done with multiple load balancers or it could be done with a single load balancer.
344
+
345
+ 87
346
+ 00:04:48,000 --> 00:04:51,000
347
+ Although if you have multiple load balancers because if this device fails you're in trouble.
348
+
349
+ 88
350
+ 00:04:51,000 --> 00:04:56,000
351
+ So you could have multiple load balancers uh, different forms.
352
+
353
+ 89
354
+ 00:04:56,000 --> 00:04:59,000
355
+ Maybe each load balancer has ten machines.
356
+
357
+ 90
358
+ 00:04:59,000 --> 00:05:02,000
359
+ There are different ways to set this up for your exam.
360
+
361
+ 91
362
+ 00:05:02,000 --> 00:05:04,000
363
+ Just understand what a load balancer is.
364
+
365
+ 92
366
+ 00:05:04,000 --> 00:05:05,000
367
+ It is what it says it is.
368
+
369
+ 93
370
+ 00:05:05,000 --> 00:05:07,000
371
+ It distributes loads between machines.
372
+
373
+ 94
374
+ 00:05:07,000 --> 00:05:14,000
375
+ Key reason for that is going to be because we want to not just distribute the traffic, but we want
376
+
377
+ 95
378
+ 00:05:14,000 --> 00:05:20,000
379
+ the reliability in case one of those machines fail, it doesn't bring down the entire network.
380
+
11 - Security Principles/012 802.1x and EAP OB 3.2_en.srt ADDED
@@ -0,0 +1,356 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ 1
2
+ 00:00:00,000 --> 00:00:00,000
3
+ All right.
4
+
5
+ 2
6
+ 00:00:00,000 --> 00:00:02,000
7
+ Take a look at the switch that I have here.
8
+
9
+ 3
10
+ 00:00:02,000 --> 00:00:03,000
11
+ So we got this switch.
12
+
13
+ 4
14
+ 00:00:03,000 --> 00:00:07,000
15
+ We plug you're going to plug your computer into my switch.
16
+
17
+ 5
18
+ 00:00:07,000 --> 00:00:10,000
19
+ And you're going to be able to gain access to the network.
20
+
21
+ 6
22
+ 00:00:10,000 --> 00:00:17,000
23
+ Or are you one of the just having a switch lying around is one of the worst things you can ever do.
24
+
25
+ 7
26
+ 00:00:17,000 --> 00:00:23,000
27
+ If you're right now, if your switch is set up to the point where anyone can just walk in, plug a computer
28
+
29
+ 8
30
+ 00:00:23,000 --> 00:00:28,000
31
+ into it, and gain full network access without any form of authentication.
32
+
33
+ 9
34
+ 00:00:28,000 --> 00:00:29,000
35
+ That is bad news.
36
+
37
+ 10
38
+ 00:00:29,000 --> 00:00:36,000
39
+ So what we want to do is we want to be able we put this down before it kills me here.
40
+
41
+ 11
42
+ 00:00:36,000 --> 00:00:41,000
43
+ We want to be able to do what is called port security.
44
+
45
+ 12
46
+ 00:00:41,000 --> 00:00:43,000
47
+ But what exactly is that?
48
+
49
+ 13
50
+ 00:00:43,000 --> 00:00:48,000
51
+ So port security is used to secure network ports on computers and network devices, and particularly
52
+
53
+ 14
54
+ 00:00:48,000 --> 00:00:55,000
55
+ switches guarding against on authorized access and insurance, secure communication.
56
+
57
+ 15
58
+ 00:00:55,000 --> 00:00:57,000
59
+ This is more than likely going to be secured.
60
+
61
+ 16
62
+ 00:00:57,000 --> 00:01:03,000
63
+ Network switch ports now generally, port security can also mean things like filtering ports through
64
+
65
+ 17
66
+ 00:01:03,000 --> 00:01:04,000
67
+ TCP and UDP.
68
+
69
+ 18
70
+ 00:01:04,000 --> 00:01:05,000
71
+ This is going to be done with like firewalls.
72
+
73
+ 19
74
+ 00:01:06,000 --> 00:01:10,000
75
+ It's meant to stop unauthorized access to your network.
76
+
77
+ 20
78
+ 00:01:10,000 --> 00:01:15,000
79
+ But in this particular video, what I want to talk about is not just filtering traffic through ports.
80
+
81
+ 21
82
+ 00:01:15,000 --> 00:01:17,000
83
+ This is going to be done generally through a firewall.
84
+
85
+ 22
86
+ 00:01:17,000 --> 00:01:21,000
87
+ I want to talk about the physical port security, like on this switch.
88
+
89
+ 23
90
+ 00:01:21,000 --> 00:01:28,000
91
+ And in particular there's two terms that we want to be familiar with something called 821 X and EAP
92
+
93
+ 24
94
+ 00:01:28,000 --> 00:01:31,000
95
+ or Extensible Authentication Protocol.
96
+
97
+ 25
98
+ 00:01:31,000 --> 00:01:32,000
99
+ Let me explain what this is to you.
100
+
101
+ 26
102
+ 00:01:32,000 --> 00:01:36,000
103
+ So 821 x you have to come into the switch and enable these things.
104
+
105
+ 27
106
+ 00:01:36,000 --> 00:01:40,000
107
+ You you configure the ports on the switch and you enable this.
108
+
109
+ 28
110
+ 00:01:40,000 --> 00:01:42,000
111
+ This is an IEEE standard.
112
+
113
+ 29
114
+ 00:01:43,000 --> 00:01:44,000
115
+ For port.
116
+
117
+ 30
118
+ 00:01:44,000 --> 00:01:46,000
119
+ Port based access control.
120
+
121
+ 31
122
+ 00:01:46,000 --> 00:01:50,000
123
+ It's used to authenticate device that are attempting to connect to your LAN.
124
+
125
+ 32
126
+ 00:01:50,000 --> 00:01:53,000
127
+ And you can also do this for your wireless connection.
128
+
129
+ 33
130
+ 00:01:53,000 --> 00:01:59,000
131
+ Also not just for your wired switch, but you can also enable it on your wireless.
132
+
133
+ 34
134
+ 00:01:59,000 --> 00:02:00,000
135
+ Here's how it works.
136
+
137
+ 35
138
+ 00:02:00,000 --> 00:02:06,000
139
+ When a device attempts to connect to a network that's that has 801 enabled, the authenticator blocks
140
+
141
+ 36
142
+ 00:02:06,000 --> 00:02:11,000
143
+ all traffic except the 8021, and the client is authenticated.
144
+
145
+ 37
146
+ 00:02:11,000 --> 00:02:12,000
147
+ Now I want to show you guys something.
148
+
149
+ 38
150
+ 00:02:12,000 --> 00:02:14,000
151
+ I have a diagram of this from Wikipedia.
152
+
153
+ 39
154
+ 00:02:15,000 --> 00:02:21,000
155
+ So when you want to connect to a network, notice the switch that is going to be utilizing.
156
+
157
+ 40
158
+ 00:02:22,000 --> 00:02:24,000
159
+ That's going to be utilizing 801 x.
160
+
161
+ 41
162
+ 00:02:24,000 --> 00:02:31,000
163
+ So what you do is you configure the switch to say if the computer does not authenticate and go through
164
+
165
+ 42
166
+ 00:02:31,000 --> 00:02:34,000
167
+ 8 to 1 x, we're not going to allow you access in.
168
+
169
+ 43
170
+ 00:02:34,000 --> 00:02:37,000
171
+ So it only accepts that kind of access.
172
+
173
+ 44
174
+ 00:02:37,000 --> 00:02:38,000
175
+ So here's how it works.
176
+
177
+ 45
178
+ 00:02:39,000 --> 00:02:40,000
179
+ The supplicant is you.
180
+
181
+ 46
182
+ 00:02:40,000 --> 00:02:41,000
183
+ That's the user.
184
+
185
+ 47
186
+ 00:02:41,000 --> 00:02:44,000
187
+ You connect to the switch and you're trying to gain access to the network.
188
+
189
+ 48
190
+ 00:02:44,000 --> 00:02:51,000
191
+ But before the switch can grant you access to the LAN resources, what you have to do, you have to
192
+
193
+ 49
194
+ 00:02:51,000 --> 00:02:55,000
195
+ send a request to the authenticator to switch.
196
+
197
+ 50
198
+ 00:02:55,000 --> 00:03:00,000
199
+ The authenticator then sends that request to an authentication server.
200
+
201
+ 51
202
+ 00:03:00,000 --> 00:03:04,000
203
+ That authentication server is going to authenticate you username password.
204
+
205
+ 52
206
+ 00:03:04,000 --> 00:03:08,000
207
+ It can do a variety of different things certificate based authentication.
208
+
209
+ 53
210
+ 00:03:08,000 --> 00:03:10,000
211
+ So there's many different ways it can do this.
212
+
213
+ 54
214
+ 00:03:10,000 --> 00:03:16,000
215
+ You can use a Radius server something we'll cover in another class in another video when the when the
216
+
217
+ 55
218
+ 00:03:16,000 --> 00:03:23,000
219
+ authentication server said it's okay, then the authenticator tells you and then you can access resources.
220
+
221
+ 56
222
+ 00:03:24,000 --> 00:03:29,000
223
+ Now the supplicant I just mentioned to you, you send the credential to the authenticator, which forwards
224
+
225
+ 57
226
+ 00:03:29,000 --> 00:03:30,000
227
+ them to the authentication server.
228
+
229
+ 58
230
+ 00:03:30,000 --> 00:03:34,000
231
+ And the authentication server is something that's going to run like a Radius server.
232
+
233
+ 59
234
+ 00:03:34,000 --> 00:03:39,000
235
+ If the server approves it, it gives you access and then you can access the network.
236
+
237
+ 60
238
+ 00:03:39,000 --> 00:03:42,000
239
+ Now you notice I have these things called EAP here.
240
+
241
+ 61
242
+ 00:03:42,000 --> 00:03:46,000
243
+ See that EAP stands for Extensible Authentication Protocol.
244
+
245
+ 62
246
+ 00:03:46,000 --> 00:03:50,000
247
+ You are authenticating to a particular device.
248
+
249
+ 63
250
+ 00:03:50,000 --> 00:03:53,000
251
+ This here is this is the protocol that's going to allow that.
252
+
253
+ 64
254
+ 00:03:54,000 --> 00:03:56,000
255
+ It's a framework frequently used in network access.
256
+
257
+ 65
258
+ 00:03:57,000 --> 00:03:58,000
259
+ All right.
260
+
261
+ 66
262
+ 00:03:58,000 --> 00:04:02,000
263
+ It's designed to support multiple authentication passwords, tokens, certificates.
264
+
265
+ 67
266
+ 00:04:02,000 --> 00:04:07,000
267
+ So if you want to authenticate to my network and you plug a computer into my switch.
268
+
269
+ 68
270
+ 00:04:08,000 --> 00:04:11,000
271
+ You're going to have to provide either some kind of certificate.
272
+
273
+ 69
274
+ 00:04:11,000 --> 00:04:13,000
275
+ You can use tokens.
276
+
277
+ 70
278
+ 00:04:14,000 --> 00:04:15,000
279
+ Uh, certificates is a good one.
280
+
281
+ 71
282
+ 00:04:15,000 --> 00:04:16,000
283
+ I like that one.
284
+
285
+ 72
286
+ 00:04:17,000 --> 00:04:19,000
287
+ The worst, of course, is passwords.
288
+
289
+ 73
290
+ 00:04:19,000 --> 00:04:21,000
291
+ This thing is widely used.
292
+
293
+ 74
294
+ 00:04:21,000 --> 00:04:25,000
295
+ It's mostly it was widely used in PGP or point to point connections.
296
+
297
+ 75
298
+ 00:04:26,000 --> 00:04:26,000
299
+ Um.
300
+
301
+ 76
302
+ 00:04:27,000 --> 00:04:34,000
303
+ But it's a lot of time now using 821 X, and it's used generally in conjunction with a Radius server
304
+
305
+ 77
306
+ 00:04:34,000 --> 00:04:35,000
307
+ to centralize authentication.
308
+
309
+ 78
310
+ 00:04:35,000 --> 00:04:40,000
311
+ That way you can have tons of switches all foward to a single.
312
+
313
+ 79
314
+ 00:04:41,000 --> 00:04:44,000
315
+ Authentication server like a radius.
316
+
317
+ 80
318
+ 00:04:45,000 --> 00:04:47,000
319
+ Why would you want this?
320
+
321
+ 81
322
+ 00:04:47,000 --> 00:04:47,000
323
+ Right?
324
+
325
+ 82
326
+ 00:04:47,000 --> 00:04:48,000
327
+ You think about this.
328
+
329
+ 83
330
+ 00:04:49,000 --> 00:04:53,000
331
+ One of the worst things that can happen to somebody walking into a network and just plug a computer
332
+
333
+ 84
334
+ 00:04:53,000 --> 00:04:57,000
335
+ into your to plug a computer into your network, gain all your network access.
336
+
337
+ 85
338
+ 00:04:57,000 --> 00:04:59,000
339
+ That would severely suck.
340
+
341
+ 86
342
+ 00:04:59,000 --> 00:05:01,000
343
+ The best thing to do is to have this on your network.
344
+
345
+ 87
346
+ 00:05:01,000 --> 00:05:07,000
347
+ Now, it's not difficult to set up, but it is more setup that needs to get done.
348
+
349
+ 88
350
+ 00:05:07,000 --> 00:05:12,000
351
+ That way, when somebody plugs a computer into your network, you're 100% sure this person actually
352
+
353
+ 89
354
+ 00:05:12,000 --> 00:05:14,000
355
+ belongs in the network.
356
+
11 - Security Principles/013 Firewalls OB 3.2_en.srt ADDED
@@ -0,0 +1,520 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ 1
2
+ 00:00:00,000 --> 00:00:04,000
3
+ In this course, I discussed a lot of different ways to secure a network.
4
+
5
+ 2
6
+ 00:00:04,000 --> 00:00:11,000
7
+ But when it comes to network security, Network Security 101 is a firewall.
8
+
9
+ 3
10
+ 00:00:11,000 --> 00:00:17,000
11
+ And in this video we're going to talk about firewalls in particularly like this little firewall that
12
+
13
+ 4
14
+ 00:00:17,000 --> 00:00:19,000
15
+ I have right here.
16
+
17
+ 5
18
+ 00:00:19,000 --> 00:00:19,000
19
+ All right.
20
+
21
+ 6
22
+ 00:00:19,000 --> 00:00:20,000
23
+ That one has two USBs.
24
+
25
+ 7
26
+ 00:00:20,000 --> 00:00:21,000
27
+ This one doesn't.
28
+
29
+ 8
30
+ 00:00:21,000 --> 00:00:23,000
31
+ All right let's get started with different kinds of firewall.
32
+
33
+ 9
34
+ 00:00:23,000 --> 00:00:26,000
35
+ And I'm going to explain to you that this is an next generation firewall.
36
+
37
+ 10
38
+ 00:00:26,000 --> 00:00:28,000
39
+ And what makes this one unique.
40
+
41
+ 11
42
+ 00:00:28,000 --> 00:00:29,000
43
+ Let's get started.
44
+
45
+ 12
46
+ 00:00:30,000 --> 00:00:36,000
47
+ When it comes to basic network security, one of the most basic things you've got to have on a computer
48
+
49
+ 13
50
+ 00:00:37,000 --> 00:00:38,000
51
+ or on a network is a firewall.
52
+
53
+ 14
54
+ 00:00:38,000 --> 00:00:44,000
55
+ Now firewalls comes in to basically going to come in two main designs.
56
+
57
+ 15
58
+ 00:00:44,000 --> 00:00:48,000
59
+ You have, uh, host based firewalls and network firewalls.
60
+
61
+ 16
62
+ 00:00:48,000 --> 00:00:49,000
63
+ This is a network firewall.
64
+
65
+ 17
66
+ 00:00:49,000 --> 00:00:55,000
67
+ You have a host based firewall that's installed on your physical box, like on your your desktop, like
68
+
69
+ 18
70
+ 00:00:55,000 --> 00:00:56,000
71
+ Windows Firewall.
72
+
73
+ 19
74
+ 00:00:56,000 --> 00:00:59,000
75
+ Now, what exactly is it?
76
+
77
+ 20
78
+ 00:00:59,000 --> 00:01:02,000
79
+ Well, a network security system, it's basically a network.
80
+
81
+ 21
82
+ 00:01:02,000 --> 00:01:05,000
83
+ The monitors and controls incoming and outgoing network traffic.
84
+
85
+ 22
86
+ 00:01:05,000 --> 00:01:10,000
87
+ Whether that's coming into your host or coming into your network, typically establishes a barrier between
88
+
89
+ 23
90
+ 00:01:10,000 --> 00:01:14,000
91
+ a trusted, secure internal network and an outside external network.
92
+
93
+ 24
94
+ 00:01:14,000 --> 00:01:19,000
95
+ So if it's a network, if it's a network based firewall, they're talking about this one here has a
96
+
97
+ 25
98
+ 00:01:19,000 --> 00:01:20,000
99
+ Wang port.
100
+
101
+ 26
102
+ 00:01:22,000 --> 00:01:27,000
103
+ Anything connected here would be considered on the public side, and anything connected here, the land
104
+
105
+ 27
106
+ 00:01:27,000 --> 00:01:29,000
107
+ port would be considered good traffic.
108
+
109
+ 28
110
+ 00:01:29,000 --> 00:01:32,000
111
+ Now it's implemented in hardware and software.
112
+
113
+ 29
114
+ 00:01:32,000 --> 00:01:35,000
115
+ So obviously this is an appliance that we would have.
116
+
117
+ 30
118
+ 00:01:35,000 --> 00:01:41,000
119
+ Of course you would have software firewalls like something uh, that you would install like like Windows
120
+
121
+ 31
122
+ 00:01:41,000 --> 00:01:41,000
123
+ Firewall.
124
+
125
+ 32
126
+ 00:01:41,000 --> 00:01:42,000
127
+ That's a good example.
128
+
129
+ 33
130
+ 00:01:42,000 --> 00:01:46,000
131
+ But you can also have like Symantec's or Broadcom endpoint, McAfee endpoint.
132
+
133
+ 34
134
+ 00:01:46,000 --> 00:01:49,000
135
+ These will generally come with software based firewalls.
136
+
137
+ 35
138
+ 00:01:49,000 --> 00:01:54,000
139
+ They're going to enforce a security policy like allow or disallow these kinds of traffic.
140
+
141
+ 36
142
+ 00:01:54,000 --> 00:01:58,000
143
+ They control the flow of traffic does not differentiate data versus command.
144
+
145
+ 37
146
+ 00:01:58,000 --> 00:02:02,000
147
+ It just doesn't know whether something is a command or a particular data.
148
+
149
+ 38
150
+ 00:02:02,000 --> 00:02:06,000
151
+ So it might be difficult to detect that controls the flow of traffic.
152
+
153
+ 39
154
+ 00:02:06,000 --> 00:02:10,000
155
+ Um, controls the flow of traffic between hosts and network.
156
+
157
+ 40
158
+ 00:02:10,000 --> 00:02:16,000
159
+ Now, there are different kinds of firewalls that we want to be familiar with for our exam.
160
+
161
+ 41
162
+ 00:02:16,000 --> 00:02:23,000
163
+ The first kind of firewall that came out when I was a little boy was packet filtering firewalls.
164
+
165
+ 42
166
+ 00:02:23,000 --> 00:02:26,000
167
+ And these things are not firewalls, they were just routers.
168
+
169
+ 43
170
+ 00:02:26,000 --> 00:02:32,000
171
+ When an access control list, they were subject to many kinds of attacks and they do not exist today.
172
+
173
+ 44
174
+ 00:02:33,000 --> 00:02:37,000
175
+ Today we're all stateful packet inspection.
176
+
177
+ 45
178
+ 00:02:37,000 --> 00:02:38,000
179
+ This was known as stateless.
180
+
181
+ 46
182
+ 00:02:38,000 --> 00:02:43,000
183
+ The reason for this is because this type of firewall didn't know traffic that left.
184
+
185
+ 47
186
+ 00:02:43,000 --> 00:02:46,000
187
+ So it was subject to something called source routing.
188
+
189
+ 48
190
+ 00:02:46,000 --> 00:02:49,000
191
+ Once again, this thing doesn't really exist.
192
+
193
+ 49
194
+ 00:02:49,000 --> 00:02:54,000
195
+ All firewalls today and all the firewalls that I'm going to be talking about, such as web application
196
+
197
+ 50
198
+ 00:02:54,000 --> 00:03:04,000
199
+ firewalls, utms, and next gen firewalls are all based on stateful packet inspection or Spice or stateful
200
+
201
+ 51
202
+ 00:03:04,000 --> 00:03:05,000
203
+ inspection firewalls.
204
+
205
+ 52
206
+ 00:03:05,000 --> 00:03:08,000
207
+ This is the most they're more advanced than packet filtering.
208
+
209
+ 53
210
+ 00:03:08,000 --> 00:03:09,000
211
+ They keep a track.
212
+
213
+ 54
214
+ 00:03:09,000 --> 00:03:12,000
215
+ They have a state table of who left and who's coming back in.
216
+
217
+ 55
218
+ 00:03:12,000 --> 00:03:19,000
219
+ They're incredibly popular on all firewall technology, including what I have here is based on it now.
220
+
221
+ 56
222
+ 00:03:20,000 --> 00:03:26,000
223
+ One kind of firewall that is popular if you're hosting web servers is going to be something called a
224
+
225
+ 57
226
+ 00:03:26,000 --> 00:03:29,000
227
+ WAF or a web application firewall.
228
+
229
+ 58
230
+ 00:03:29,000 --> 00:03:34,000
231
+ The design to protect web applications by filtering and monitoring web traffic.
232
+
233
+ 59
234
+ 00:03:34,000 --> 00:03:39,000
235
+ Let me show you guys a particular diagram from a very famous company called Akamai.
236
+
237
+ 60
238
+ 00:03:39,000 --> 00:03:42,000
239
+ So imagine you have a web for a web server farm.
240
+
241
+ 61
242
+ 00:03:42,000 --> 00:03:43,000
243
+ All right.
244
+
245
+ 62
246
+ 00:03:43,000 --> 00:03:44,000
247
+ All these are all your web servers.
248
+
249
+ 63
250
+ 00:03:44,000 --> 00:03:51,000
251
+ You have all kinds of end users coming through the internet to get to your web server.
252
+
253
+ 64
254
+ 00:03:51,000 --> 00:03:59,000
255
+ You put the web application firewall between you and the public, any kind of negative traffic that
256
+
257
+ 65
258
+ 00:03:59,000 --> 00:04:06,000
259
+ is attempting to hit your web servers, things such as SQL injection, cross site scripting, session
260
+
261
+ 66
262
+ 00:04:06,000 --> 00:04:11,000
263
+ hijacking, anything that's negative that's going to attempt to hit your.
264
+
265
+ 67
266
+ 00:04:12,000 --> 00:04:14,000
267
+ Hit your, uh, your web server.
268
+
269
+ 68
270
+ 00:04:14,000 --> 00:04:16,000
271
+ This thing is going to stop.
272
+
273
+ 69
274
+ 00:04:16,000 --> 00:04:20,000
275
+ So this is really important if you're running web applications.
276
+
277
+ 70
278
+ 00:04:21,000 --> 00:04:23,000
279
+ Uh, they operate at the application layer.
280
+
281
+ 71
282
+ 00:04:23,000 --> 00:04:24,000
283
+ The rules are customized.
284
+
285
+ 72
286
+ 00:04:24,000 --> 00:04:26,000
287
+ They're generally could be a hardware or software.
288
+
289
+ 73
290
+ 00:04:26,000 --> 00:04:31,000
291
+ But a lot of times now, being that a lot of people have all their web servers are in the cloud, they're
292
+
293
+ 74
294
+ 00:04:31,000 --> 00:04:33,000
295
+ probably going to be part of a cloud service.
296
+
297
+ 75
298
+ 00:04:34,000 --> 00:04:38,000
299
+ Now, the other two confuses a lot of folks.
300
+
301
+ 76
302
+ 00:04:38,000 --> 00:04:41,000
303
+ And I'll tell you the difference between them, because as I go through them, they're going to sound
304
+
305
+ 77
306
+ 00:04:41,000 --> 00:04:42,000
307
+ alike.
308
+
309
+ 78
310
+ 00:04:42,000 --> 00:04:50,000
311
+ Unified threat management systems are this this, by the way, is is this one this is an NDF w.
312
+
313
+ 79
314
+ 00:04:51,000 --> 00:04:55,000
315
+ So if you go to Sonicwall and you look up Sonicwall firewalls, you'll see this this big across the
316
+
317
+ 80
318
+ 00:04:55,000 --> 00:04:58,000
319
+ top next generation firewalls.
320
+
321
+ 81
322
+ 00:04:58,000 --> 00:04:59,000
323
+ But what exactly is this one now?
324
+
325
+ 82
326
+ 00:04:59,000 --> 00:05:00,000
327
+ Utms.
328
+
329
+ 83
330
+ 00:05:00,000 --> 00:05:07,000
331
+ This is a great this is a big comprehensive solution that includes things like antivirus, anti-spyware,
332
+
333
+ 84
334
+ 00:05:07,000 --> 00:05:11,000
335
+ firewalls, intrusion detections, preventions, and content filtering.
336
+
337
+ 85
338
+ 00:05:12,000 --> 00:05:13,000
339
+ They're easy to use.
340
+
341
+ 86
342
+ 00:05:13,000 --> 00:05:14,000
343
+ They're very.
344
+
345
+ 87
346
+ 00:05:14,000 --> 00:05:20,000
347
+ They come pre-built with many policies ideal for small to mid sized business.
348
+
349
+ 88
350
+ 00:05:20,000 --> 00:05:22,000
351
+ Now it's going to sound the same.
352
+
353
+ 89
354
+ 00:05:22,000 --> 00:05:24,000
355
+ Okay, I'm just giving you a heads up now.
356
+
357
+ 90
358
+ 00:05:24,000 --> 00:05:28,000
359
+ Far more advanced than traditional firewalls include functionalities.
360
+
361
+ 91
362
+ 00:05:28,000 --> 00:05:29,000
363
+ Deep packet inspection.
364
+
365
+ 92
366
+ 00:05:29,000 --> 00:05:36,000
367
+ They include intrusion prevention systems application awareness deep packet inspection.
368
+
369
+ 93
370
+ 00:05:36,000 --> 00:05:39,000
371
+ They can actually see within the packet good threat intelligence.
372
+
373
+ 94
374
+ 00:05:39,000 --> 00:05:44,000
375
+ They will also come with antivirus, anti-spyware firewall, intrusion detection, prevention system
376
+
377
+ 95
378
+ 00:05:44,000 --> 00:05:46,000
379
+ and content filtering.
380
+
381
+ 96
382
+ 00:05:46,000 --> 00:05:50,000
383
+ These two things sound very much alike.
384
+
385
+ 97
386
+ 00:05:50,000 --> 00:05:55,000
387
+ Now, if you are a small business and you just want something to take out the box and you just plug
388
+
389
+ 98
390
+ 00:05:55,000 --> 00:05:58,000
391
+ it in and it comes with a great set of policies.
392
+
393
+ 99
394
+ 00:05:58,000 --> 00:06:01,000
395
+ UTM is easy to manage and it comes with most policies.
396
+
397
+ 100
398
+ 00:06:01,000 --> 00:06:07,000
399
+ If you're looking for something more customizable to best match your business needs, then you get the
400
+
401
+ 101
402
+ 00:06:07,000 --> 00:06:08,000
403
+ Ngfw.
404
+
405
+ 102
406
+ 00:06:08,000 --> 00:06:11,000
407
+ These particular are the engine firewalls.
408
+
409
+ 103
410
+ 00:06:11,000 --> 00:06:18,000
411
+ The engine firewalls are much more customizable, more robust than the Utms.
412
+
413
+ 104
414
+ 00:06:19,000 --> 00:06:20,000
415
+ Okay, so keep that in mind.
416
+
417
+ 105
418
+ 00:06:20,000 --> 00:06:22,000
419
+ The difference is customization.
420
+
421
+ 106
422
+ 00:06:22,000 --> 00:06:26,000
423
+ One is just really more customization than others.
424
+
425
+ 107
426
+ 00:06:26,000 --> 00:06:27,000
427
+ Okay.
428
+
429
+ 108
430
+ 00:06:27,000 --> 00:06:29,000
431
+ Great discussion on firewalls.
432
+
433
+ 109
434
+ 00:06:29,000 --> 00:06:36,000
435
+ Now I'm not sure if you guys remember the OSI model from previous classes, but one of the things that
436
+
437
+ 110
438
+ 00:06:36,000 --> 00:06:42,000
439
+ we should be familiar with is where firewalls operate layer four and layer seven.
440
+
441
+ 111
442
+ 00:06:42,000 --> 00:06:49,000
443
+ So layer four firewalls focus on data transport because they operate at the transport layer, the control
444
+
445
+ 112
446
+ 00:06:49,000 --> 00:06:50,000
447
+ traffic based on TCP, UDP.
448
+
449
+ 113
450
+ 00:06:51,000 --> 00:06:54,000
451
+ You got to remember something at the basic level.
452
+
453
+ 114
454
+ 00:06:54,000 --> 00:06:56,000
455
+ All firewalls do one thing.
456
+
457
+ 115
458
+ 00:06:56,000 --> 00:07:03,000
459
+ They block ports at the most conceptual level of firewall should block ports and ports operate at layer
460
+
461
+ 116
462
+ 00:07:03,000 --> 00:07:06,000
463
+ four, your transport layer, not your network layer.
464
+
465
+ 117
466
+ 00:07:06,000 --> 00:07:08,000
467
+ That's going to be IP.
468
+
469
+ 118
470
+ 00:07:09,000 --> 00:07:16,000
471
+ Now, if the firewall can read into the application and stop certain traffic based on things like a
472
+
473
+ 119
474
+ 00:07:16,000 --> 00:07:22,000
475
+ URL, this is going to be a layer four firewall inspects the content of the traffic there, make more
476
+
477
+ 120
478
+ 00:07:22,000 --> 00:07:26,000
479
+ informed pretty much decisions, so keep that in mind.
480
+
481
+ 121
482
+ 00:07:26,000 --> 00:07:28,000
483
+ Now application.
484
+
485
+ 122
486
+ 00:07:28,000 --> 00:07:34,000
487
+ Anytime you hear the terms application firewall that is considered application firewall is considered
488
+
489
+ 123
490
+ 00:07:34,000 --> 00:07:35,000
491
+ a layer seven.
492
+
493
+ 124
494
+ 00:07:35,000 --> 00:07:37,000
495
+ Because remember layer seven is application.
496
+
497
+ 125
498
+ 00:07:37,000 --> 00:07:41,000
499
+ But generally if the exam doesn't specify anything it says what layer is a firewall.
500
+
501
+ 126
502
+ 00:07:41,000 --> 00:07:42,000
503
+ It's layer four.
504
+
505
+ 127
506
+ 00:07:42,000 --> 00:07:46,000
507
+ Unless they say something like web application firewall.
508
+
509
+ 128
510
+ 00:07:46,000 --> 00:07:51,000
511
+ Uh, by the way, proxy servers are also a type of a firewall.
512
+
513
+ 129
514
+ 00:07:51,000 --> 00:07:54,000
515
+ And that's a proxy server is a layer seven device.
516
+
517
+ 130
518
+ 00:07:54,000 --> 00:07:58,000
519
+ So keep that in mind in case you got a question about that on your test.
520
+
11 - Security Principles/014 VPN OB 3.2_en.srt ADDED
@@ -0,0 +1,672 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ 1
2
+ 00:00:00,000 --> 00:00:03,000
3
+ One very popular thing to do today is to work from home.
4
+
5
+ 2
6
+ 00:00:03,000 --> 00:00:07,000
7
+ Maybe you're doing that right now, or maybe you're looking for a job to work from home.
8
+
9
+ 3
10
+ 00:00:07,000 --> 00:00:14,000
11
+ The technology that allows work from home, that allows you to connect to a corporate network and utilize
12
+
13
+ 4
14
+ 00:00:14,000 --> 00:00:19,000
15
+ all the corporate network resources, is called a VPN.
16
+
17
+ 5
18
+ 00:00:19,000 --> 00:00:20,000
19
+ So what exactly is that?
20
+
21
+ 6
22
+ 00:00:21,000 --> 00:00:23,000
23
+ Well, here's what it is.
24
+
25
+ 7
26
+ 00:00:23,000 --> 00:00:28,000
27
+ A VPN is a technology that creates an encrypted connection over a less secure network.
28
+
29
+ 8
30
+ 00:00:28,000 --> 00:00:34,000
31
+ It builds on top of an existing physical network, provides a connection mechanism between you and that
32
+
33
+ 9
34
+ 00:00:34,000 --> 00:00:38,000
35
+ corporate network, generally across a public network such as the internet.
36
+
37
+ 10
38
+ 00:00:38,000 --> 00:00:41,000
39
+ It allows secure connection between endpoints.
40
+
41
+ 11
42
+ 00:00:41,000 --> 00:00:48,000
43
+ Basically, it's going to allow employees to securely access corporate intranet or internal resources
44
+
45
+ 12
46
+ 00:00:48,000 --> 00:00:50,000
47
+ can securely connect.
48
+
49
+ 13
50
+ 00:00:50,000 --> 00:00:53,000
51
+ It can even connect global offices together.
52
+
53
+ 14
54
+ 00:00:53,000 --> 00:00:56,000
55
+ And it provides a connection over the public internet.
56
+
57
+ 15
58
+ 00:00:56,000 --> 00:00:58,000
59
+ Now let me give you some good examples of this.
60
+
61
+ 16
62
+ 00:00:58,000 --> 00:01:01,000
63
+ So I use VPNs quite often.
64
+
65
+ 17
66
+ 00:01:01,000 --> 00:01:03,000
67
+ In fact, I work from home quite a lot.
68
+
69
+ 18
70
+ 00:01:03,000 --> 00:01:07,000
71
+ When I'm at home, I want to be able to access the server at work.
72
+
73
+ 19
74
+ 00:01:07,000 --> 00:01:11,000
75
+ That server at work has a database with all the students and the information for the school.
76
+
77
+ 20
78
+ 00:01:11,000 --> 00:01:16,000
79
+ It has a file server for different documents that I need access to so I could stay home.
80
+
81
+ 21
82
+ 00:01:16,000 --> 00:01:20,000
83
+ I connect to my workplace VPN and then it's like I'm sitting there.
84
+
85
+ 22
86
+ 00:01:20,000 --> 00:01:27,000
87
+ I have access to every single thing in the actual network to have a bunch of locations.
88
+
89
+ 23
90
+ 00:01:27,000 --> 00:01:30,000
91
+ For example, we have a location in Long Island, New York and Manhattan.
92
+
93
+ 24
94
+ 00:01:31,000 --> 00:01:33,000
95
+ In New York City, Midtown Manhattan.
96
+
97
+ 25
98
+ 00:01:33,000 --> 00:01:40,000
99
+ We connect these two locations with a VPN, so folks in Manhattan can share data with folks in Long
100
+
101
+ 26
102
+ 00:01:40,000 --> 00:01:41,000
103
+ Island.
104
+
105
+ 27
106
+ 00:01:41,000 --> 00:01:43,000
107
+ So VPNs are pretty robust.
108
+
109
+ 28
110
+ 00:01:43,000 --> 00:01:49,000
111
+ You can use it as a user access VPN, like I'm using it to connect to my workplace, or you can use
112
+
113
+ 29
114
+ 00:01:49,000 --> 00:01:51,000
115
+ it to connect different sites together.
116
+
117
+ 30
118
+ 00:01:51,000 --> 00:01:52,000
119
+ Now.
120
+
121
+ 31
122
+ 00:01:54,000 --> 00:01:55,000
123
+ Take a look at this here.
124
+
125
+ 32
126
+ 00:01:55,000 --> 00:01:58,000
127
+ This here is called a site to site VPN.
128
+
129
+ 33
130
+ 00:01:58,000 --> 00:01:59,000
131
+ This is like site one.
132
+
133
+ 34
134
+ 00:01:59,000 --> 00:02:02,000
135
+ Could be like our new Manhattan site.
136
+
137
+ 35
138
+ 00:02:02,000 --> 00:02:05,000
139
+ Site two could be like our Long Island site.
140
+
141
+ 36
142
+ 00:02:05,000 --> 00:02:09,000
143
+ And notice it's going across the internet utilizing VPN devices.
144
+
145
+ 37
146
+ 00:02:09,000 --> 00:02:11,000
147
+ What would you say would do that?
148
+
149
+ 38
150
+ 00:02:11,000 --> 00:02:14,000
151
+ This is what we use to do our VPN.
152
+
153
+ 39
154
+ 00:02:14,000 --> 00:02:16,000
155
+ Our Sonicwall is our VPN buddy.
156
+
157
+ 40
158
+ 00:02:16,000 --> 00:02:21,000
159
+ We set up the VPN on this device, and I'm going to go through some of the technology that this thing
160
+
161
+ 41
162
+ 00:02:21,000 --> 00:02:22,000
163
+ uses.
164
+
165
+ 42
166
+ 00:02:22,000 --> 00:02:29,000
167
+ This thing uses IPsec is what it utilizes to create a tunnel between the two endpoints.
168
+
169
+ 43
170
+ 00:02:29,000 --> 00:02:32,000
171
+ And we'll describe what that is coming up in a few minutes.
172
+
173
+ 44
174
+ 00:02:32,000 --> 00:02:33,000
175
+ So.
176
+
177
+ 45
178
+ 00:02:33,000 --> 00:02:37,000
179
+ This type of VPN is a virtual point to point connection.
180
+
181
+ 46
182
+ 00:02:38,000 --> 00:02:45,000
183
+ All right through and it encapsulate the data, virtual encapsulation of the data to the untrusted internet.
184
+
185
+ 47
186
+ 00:02:45,000 --> 00:02:47,000
187
+ So it's all encrypted.
188
+
189
+ 48
190
+ 00:02:47,000 --> 00:02:48,000
191
+ How does it do it?
192
+
193
+ 49
194
+ 00:02:48,000 --> 00:02:50,000
195
+ Well, it does it by tunnelling.
196
+
197
+ 50
198
+ 00:02:51,000 --> 00:02:51,000
199
+ All right.
200
+
201
+ 51
202
+ 00:02:51,000 --> 00:02:56,000
203
+ Tunneling means that it encapsulate all the packets inside of something else.
204
+
205
+ 52
206
+ 00:02:57,000 --> 00:03:00,000
207
+ When it comes to tunneling, they're basically two tunnels.
208
+
209
+ 53
210
+ 00:03:00,000 --> 00:03:06,000
211
+ VPNs utilizes in today's world to transport confidential companies data.
212
+
213
+ 54
214
+ 00:03:06,000 --> 00:03:13,000
215
+ We're going to utilize either a TLS tunnel or we're going to be using L2, TCP with IPsec tunnels.
216
+
217
+ 55
218
+ 00:03:13,000 --> 00:03:14,000
219
+ All right.
220
+
221
+ 56
222
+ 00:03:14,000 --> 00:03:17,000
223
+ Those are going to be the two tunnels that we're going to be needing to know.
224
+
225
+ 57
226
+ 00:03:19,000 --> 00:03:26,000
227
+ So the first thing I want to show you is what's called an LL2MLS tunnel or SSL tunnels.
228
+
229
+ 58
230
+ 00:03:26,000 --> 00:03:33,000
231
+ These are tunnels or tunnels that are set up utilizing TLS, SSL, the operator layer four of the OSI
232
+
233
+ 59
234
+ 00:03:33,000 --> 00:03:34,000
235
+ model.
236
+
237
+ 60
238
+ 00:03:34,000 --> 00:03:40,000
239
+ Now, if you remember from cryptography or if you haven't watched that section yet, go through it.
240
+
241
+ 61
242
+ 00:03:40,000 --> 00:03:43,000
243
+ In cryptography, I go through the whole SSL handshake with you.
244
+
245
+ 62
246
+ 00:03:43,000 --> 00:03:44,000
247
+ It's very secure.
248
+
249
+ 63
250
+ 00:03:44,000 --> 00:03:47,000
251
+ We are using SSL all the time.
252
+
253
+ 64
254
+ 00:03:47,000 --> 00:03:50,000
255
+ Every website you go to is protected with SSL.
256
+
257
+ 65
258
+ 00:03:50,000 --> 00:03:56,000
259
+ What we're doing is we're encapsulating the VPN traffic or tunneling it into an SSL.
260
+
261
+ 66
262
+ 00:03:56,000 --> 00:03:59,000
263
+ Now we're going to use this for encryption.
264
+
265
+ 67
266
+ 00:03:59,000 --> 00:04:01,000
267
+ No need to open any additional ports.
268
+
269
+ 68
270
+ 00:04:01,000 --> 00:04:05,000
271
+ Mostly use on user access VPN.
272
+
273
+ 69
274
+ 00:04:05,000 --> 00:04:06,000
275
+ Now what does that mean.
276
+
277
+ 70
278
+ 00:04:06,000 --> 00:04:11,000
279
+ These are going to be VPNs that you use to access a corporate network, not necessarily between site
280
+
281
+ 71
282
+ 00:04:11,000 --> 00:04:19,000
283
+ to site, like my Manhattan location to our Long Island location, maybe just a website or access to
284
+
285
+ 72
286
+ 00:04:19,000 --> 00:04:26,000
287
+ a client that needs access to a client that needs to be installed, something like OpenVPN we also use
288
+
289
+ 73
290
+ 00:04:26,000 --> 00:04:29,000
291
+ as a client, but things like Sonicwall.
292
+
293
+ 74
294
+ 00:04:30,000 --> 00:04:32,000
295
+ Has SSL based VPNs.
296
+
297
+ 75
298
+ 00:04:32,000 --> 00:04:35,000
299
+ And with that, I'm going to show you guys what that looks like.
300
+
301
+ 76
302
+ 00:04:35,000 --> 00:04:39,000
303
+ There's a link there that you guys can try that I have already opened for you.
304
+
305
+ 77
306
+ 00:04:39,000 --> 00:04:41,000
307
+ So when you went to that link.
308
+
309
+ 78
310
+ 00:04:42,000 --> 00:04:43,000
311
+ Uh, I want to show you.
312
+
313
+ 79
314
+ 00:04:43,000 --> 00:04:44,000
315
+ Oh, here we go.
316
+
317
+ 80
318
+ 00:04:44,000 --> 00:04:46,000
319
+ So when you guys went to that link.
320
+
321
+ 81
322
+ 00:04:48,000 --> 00:04:50,000
323
+ This is a demo of their SSL based VPN.
324
+
325
+ 82
326
+ 00:04:50,000 --> 00:04:55,000
327
+ So you would just view the demo and it's going to log you into the VPN.
328
+
329
+ 83
330
+ 00:04:55,000 --> 00:04:58,000
331
+ So this is actually what what it looks like.
332
+
333
+ 84
334
+ 00:04:58,000 --> 00:05:00,000
335
+ It doesn't want to work here for us.
336
+
337
+ 85
338
+ 00:05:00,000 --> 00:05:03,000
339
+ Hopefully this works for us.
340
+
341
+ 86
342
+ 00:05:04,000 --> 00:05:06,000
343
+ All right demo let's log in.
344
+
345
+ 87
346
+ 00:05:06,000 --> 00:05:07,000
347
+ You just demo.
348
+
349
+ 88
350
+ 00:05:07,000 --> 00:05:08,000
351
+ And the password is like password.
352
+
353
+ 89
354
+ 00:05:08,000 --> 00:05:10,000
355
+ It puts it there for you.
356
+
357
+ 90
358
+ 00:05:10,000 --> 00:05:11,000
359
+ So this is a VPN.
360
+
361
+ 91
362
+ 00:05:11,000 --> 00:05:13,000
363
+ This is an SSL based VPN.
364
+
365
+ 92
366
+ 00:05:13,000 --> 00:05:18,000
367
+ And basically I have access to things like a file share on their network.
368
+
369
+ 93
370
+ 00:05:18,000 --> 00:05:21,000
371
+ And I can go in and I can access particular files.
372
+
373
+ 94
374
+ 00:05:21,000 --> 00:05:25,000
375
+ As you can see, uh, I can go in and, um.
376
+
377
+ 95
378
+ 00:05:26,000 --> 00:05:27,000
379
+ What else more we have here.
380
+
381
+ 96
382
+ 00:05:27,000 --> 00:05:30,000
383
+ RDP to a particular computer.
384
+
385
+ 97
386
+ 00:05:30,000 --> 00:05:33,000
387
+ Let's say we know what is going to log me into one of their systems.
388
+
389
+ 98
390
+ 00:05:33,000 --> 00:05:37,000
391
+ So now look, I'm logging in to a system on their network.
392
+
393
+ 99
394
+ 00:05:38,000 --> 00:05:40,000
395
+ This is all done through the web browser, right?
396
+
397
+ 100
398
+ 00:05:40,000 --> 00:05:42,000
399
+ This is all done.
400
+
401
+ 101
402
+ 00:05:42,000 --> 00:05:43,000
403
+ This is a computer.
404
+
405
+ 102
406
+ 00:05:43,000 --> 00:05:43,000
407
+ It's already logged in.
408
+
409
+ 103
410
+ 00:05:43,000 --> 00:05:45,000
411
+ Is this that screen?
412
+
413
+ 104
414
+ 00:05:45,000 --> 00:05:45,000
415
+ See?
416
+
417
+ 105
418
+ 00:05:46,000 --> 00:05:50,000
419
+ Yeah, it's a really old system that Sonic was given the demo on old server here.
420
+
421
+ 106
422
+ 00:05:50,000 --> 00:05:52,000
423
+ So let me close this out.
424
+
425
+ 107
426
+ 00:05:53,000 --> 00:05:55,000
427
+ So you can access Outlook Web access.
428
+
429
+ 108
430
+ 00:05:55,000 --> 00:05:58,000
431
+ So it's just a demo that you can set up.
432
+
433
+ 109
434
+ 00:05:58,000 --> 00:06:00,000
435
+ Now this is great.
436
+
437
+ 110
438
+ 00:06:00,000 --> 00:06:05,000
439
+ If you set up a VPN like this, there's really nothing for no one to install.
440
+
441
+ 111
442
+ 00:06:05,000 --> 00:06:11,000
443
+ It's heavily secured because it runs on TLS, which is pretty much the standards of all internet security.
444
+
445
+ 112
446
+ 00:06:11,000 --> 00:06:17,000
447
+ Now let's talk of another kind of implementation we can implement.
448
+
449
+ 113
450
+ 00:06:17,000 --> 00:06:20,000
451
+ And that's going to be what's called L2 Tpns.
452
+
453
+ 114
454
+ 00:06:20,000 --> 00:06:25,000
455
+ L2 Tpns are layer two tunneling protocol.
456
+
457
+ 115
458
+ 00:06:25,000 --> 00:06:32,000
459
+ These are kind of VPNs that were basically a hybrid of what was called L2 f and an older one called
460
+
461
+ 116
462
+ 00:06:32,000 --> 00:06:32,000
463
+ PCP.
464
+
465
+ 117
466
+ 00:06:33,000 --> 00:06:34,000
467
+ It's basically a point to point tunnel.
468
+
469
+ 118
470
+ 00:06:34,000 --> 00:06:40,000
471
+ And it utilizes something called IPsec in order to encrypt your data, which we'll talk about in a minute.
472
+
473
+ 119
474
+ 00:06:40,000 --> 00:06:47,000
475
+ It supports all types of radius are used on like windows boxes or Texas for, uh, Cisco boxes.
476
+
477
+ 120
478
+ 00:06:47,000 --> 00:06:51,000
479
+ Now, IPsec is something you want to be familiar with for your exam.
480
+
481
+ 121
482
+ 00:06:51,000 --> 00:06:58,000
483
+ Instead of using something such as TLS to secure your VPN, you can use IPsec.
484
+
485
+ 122
486
+ 00:06:58,000 --> 00:07:01,000
487
+ IPsec is a standalone VPN protocol.
488
+
489
+ 123
490
+ 00:07:01,000 --> 00:07:09,000
491
+ It's the main security anytime you set up L2tpv3, L2, TCP based VPNs, which you could do on my Sonicwall,
492
+
493
+ 124
494
+ 00:07:09,000 --> 00:07:11,000
495
+ you're going to use IPsec.
496
+
497
+ 125
498
+ 00:07:11,000 --> 00:07:16,000
499
+ IPsec comes in a variety of different components that you want to be familiar with for your exam.
500
+
501
+ 126
502
+ 00:07:16,000 --> 00:07:18,000
503
+ If you're asking, what the hell is all this?
504
+
505
+ 127
506
+ 00:07:18,000 --> 00:07:26,000
507
+ Well, when you set it up on the firewall on your VPN devices, particularly things like VPN concentrators,
508
+
509
+ 128
510
+ 00:07:26,000 --> 00:07:32,000
511
+ when you set these things up, like on a VPN concentrator, especially IPsec, you have to determine,
512
+
513
+ 129
514
+ 00:07:32,000 --> 00:07:35,000
515
+ do you want to set it up with RH or ESP?
516
+
517
+ 130
518
+ 00:07:35,000 --> 00:07:40,000
519
+ Ideally, you'll do both RH if you configure this, provides authentication.
520
+
521
+ 131
522
+ 00:07:41,000 --> 00:07:44,000
523
+ Integrity and non-repudiation of the data.
524
+
525
+ 132
526
+ 00:07:44,000 --> 00:07:48,000
527
+ That's important because you don't want anybody to log in authentication.
528
+
529
+ 133
530
+ 00:07:48,000 --> 00:07:52,000
531
+ You want to check if the data was modified and you want to be verified where the data is coming from.
532
+
533
+ 134
534
+ 00:07:53,000 --> 00:07:57,000
535
+ E does not support, uh, encryption of the data.
536
+
537
+ 135
538
+ 00:07:57,000 --> 00:08:02,000
539
+ It doesn't support confidentiality of data that's going to be encapsulating security payload.
540
+
541
+ 136
542
+ 00:08:02,000 --> 00:08:03,000
543
+ So make sure you enable both boxes.
544
+
545
+ 137
546
+ 00:08:03,000 --> 00:08:06,000
547
+ In fact, when you set up a VPN, these two are enabled by default.
548
+
549
+ 138
550
+ 00:08:06,000 --> 00:08:16,000
551
+ Now also when you set up these kinds of firewalls, uh, VPNs, especially in IPsec, it runs in two
552
+
553
+ 139
554
+ 00:08:16,000 --> 00:08:19,000
555
+ modes tunnel mode and transport mode.
556
+
557
+ 140
558
+ 00:08:19,000 --> 00:08:20,000
559
+ In tunnel mode.
560
+
561
+ 141
562
+ 00:08:20,000 --> 00:08:25,000
563
+ What's happening here is that it's it's protecting the IP header.
564
+
565
+ 142
566
+ 00:08:25,000 --> 00:08:29,000
567
+ Notice this green box right here the IP header I could just highlight it.
568
+
569
+ 143
570
+ 00:08:29,000 --> 00:08:34,000
571
+ It protects the IP header and trailer and the payload being the data.
572
+
573
+ 144
574
+ 00:08:35,000 --> 00:08:43,000
575
+ It encapsulates everything an IP header includes, like the source IP and destination IP in transport
576
+
577
+ 145
578
+ 00:08:43,000 --> 00:08:45,000
579
+ mode is just the payload that's being detected.
580
+
581
+ 146
582
+ 00:08:45,000 --> 00:08:47,000
583
+ The final destination is visible.
584
+
585
+ 147
586
+ 00:08:47,000 --> 00:08:55,000
587
+ So if you're going across a network where you control all the routers so it can encrypt and decrypt
588
+
589
+ 148
590
+ 00:08:55,000 --> 00:08:59,000
591
+ the packet at every one of the routers, then it's okay to use tunnel mode.
592
+
593
+ 149
594
+ 00:08:59,000 --> 00:09:03,000
595
+ But if it has to go across a network that you can't control, you're probably going to set it up in
596
+
597
+ 150
598
+ 00:09:03,000 --> 00:09:05,000
599
+ transport mode.
600
+
601
+ 151
602
+ 00:09:05,000 --> 00:09:06,000
603
+ Now.
604
+
605
+ 152
606
+ 00:09:07,000 --> 00:09:10,000
607
+ When it comes to setting up a VPN.
608
+
609
+ 153
610
+ 00:09:10,000 --> 00:09:12,000
611
+ In today's world.
612
+
613
+ 154
614
+ 00:09:12,000 --> 00:09:18,000
615
+ As of right now, as I speak to you, more and more VPNs are being deployed with TLS setup, and the
616
+
617
+ 155
618
+ 00:09:18,000 --> 00:09:23,000
619
+ reason for that is because TLS doesn't require you to open a bunch of ports.
620
+
621
+ 156
622
+ 00:09:23,000 --> 00:09:29,000
623
+ Like if you want to set up an L2, TCP based VPN, it's much easier to configure and more familiar to
624
+
625
+ 157
626
+ 00:09:29,000 --> 00:09:30,000
627
+ users.
628
+
629
+ 158
630
+ 00:09:30,000 --> 00:09:35,000
631
+ And just like you saw with the Sonicwall, you could pretty much run it off of your browser versus L2.
632
+
633
+ 159
634
+ 00:09:35,000 --> 00:09:40,000
635
+ TCP based VPNs almost always have to have you install a client on the machine.
636
+
637
+ 160
638
+ 00:09:40,000 --> 00:09:43,000
639
+ That client needs to be configured.
640
+
641
+ 161
642
+ 00:09:43,000 --> 00:09:49,000
643
+ Different types of L2, TCP, or VPN keys needs to be set up on the machine, so it's much more of an
644
+
645
+ 162
646
+ 00:09:49,000 --> 00:09:54,000
647
+ administrative work if you control the machines like the clients, like the clients that people are
648
+
649
+ 163
650
+ 00:09:54,000 --> 00:09:57,000
651
+ using at home is owned by the company.
652
+
653
+ 164
654
+ 00:09:57,000 --> 00:09:59,000
655
+ The company sets it up and they can't do anything on that machine.
656
+
657
+ 165
658
+ 00:09:59,000 --> 00:10:00,000
659
+ But companies work.
660
+
661
+ 166
662
+ 00:10:00,000 --> 00:10:03,000
663
+ Then it's probably okay to use an L2, TCP based VPN.
664
+
665
+ 167
666
+ 00:10:03,000 --> 00:10:10,000
667
+ If not, if people are working from home and they're utilizing their own machine, the best thing to
668
+
669
+ 168
670
+ 00:10:10,000 --> 00:10:14,000
671
+ do is use a TLS or SSL VPN.
672
+
11 - Security Principles/015 SD-WAN OB 3.2_en.srt ADDED
@@ -0,0 +1,228 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ 1
2
+ 00:00:00,000 --> 00:00:04,000
3
+ In today's world, networking is becoming crazy complex.
4
+
5
+ 2
6
+ 00:00:04,000 --> 00:00:10,000
7
+ You see, back in the days when you worked in a large network, you had generally one data center that
8
+
9
+ 3
10
+ 00:00:10,000 --> 00:00:14,000
11
+ the company controlled and all the other branch offices would connect to it.
12
+
13
+ 4
14
+ 00:00:15,000 --> 00:00:18,000
15
+ But today it's a lot complex.
16
+
17
+ 5
18
+ 00:00:18,000 --> 00:00:19,000
19
+ And I want to show you a diagram.
20
+
21
+ 6
22
+ 00:00:20,000 --> 00:00:25,000
23
+ Now I want you guys to forget all the connection into the cloud for now.
24
+
25
+ 7
26
+ 00:00:25,000 --> 00:00:30,000
27
+ I want you guys just to look at this thing here with just where it says data center.
28
+
29
+ 8
30
+ 00:00:30,000 --> 00:00:36,000
31
+ Back in the days when we had set up networks, what we would do is we would just have every branch would
32
+
33
+ 9
34
+ 00:00:36,000 --> 00:00:43,000
35
+ connect to the data center, like this branch here would connect to the data center, this branch data
36
+
37
+ 10
38
+ 00:00:43,000 --> 00:00:45,000
39
+ center, this branch data center, this branch, this branch, this branch.
40
+
41
+ 11
42
+ 00:00:46,000 --> 00:00:48,000
43
+ And everything was like a centralized thing.
44
+
45
+ 12
46
+ 00:00:49,000 --> 00:00:52,000
47
+ But now it's all over the place.
48
+
49
+ 13
50
+ 00:00:52,000 --> 00:01:00,000
51
+ Right now the applications are in the cloud all over, split across different cloud based systems.
52
+
53
+ 14
54
+ 00:01:00,000 --> 00:01:06,000
55
+ The applications are stored partially in the data center and partially in the cloud.
56
+
57
+ 15
58
+ 00:01:06,000 --> 00:01:08,000
59
+ Now branch offices are going to the cloud.
60
+
61
+ 16
62
+ 00:01:08,000 --> 00:01:10,000
63
+ They're also going to the data center.
64
+
65
+ 17
66
+ 00:01:10,000 --> 00:01:12,000
67
+ Some of the app is in the cloud.
68
+
69
+ 18
70
+ 00:01:12,000 --> 00:01:14,000
71
+ Some of it is in the data center.
72
+
73
+ 19
74
+ 00:01:14,000 --> 00:01:17,000
75
+ Some of the policies in the data center, some of the policy in the cloud.
76
+
77
+ 20
78
+ 00:01:17,000 --> 00:01:20,000
79
+ This can get complex very fast, very quick.
80
+
81
+ 21
82
+ 00:01:20,000 --> 00:01:22,000
83
+ So there's a couple of things here.
84
+
85
+ 22
86
+ 00:01:23,000 --> 00:01:26,000
87
+ Let's talk about software defined networking.
88
+
89
+ 23
90
+ 00:01:26,000 --> 00:01:35,000
91
+ Software defined networking is basically to simplify a branch office networking and get optimal application
92
+
93
+ 24
94
+ 00:01:35,000 --> 00:01:36,000
95
+ performance.
96
+
97
+ 25
98
+ 00:01:36,000 --> 00:01:42,000
99
+ It provides a centralized control function to securely and intelligently intelligently transfer network
100
+
101
+ 26
102
+ 00:01:42,000 --> 00:01:43,000
103
+ traffic.
104
+
105
+ 27
106
+ 00:01:43,000 --> 00:01:46,000
107
+ What I need you guys to know for your exam is this.
108
+
109
+ 28
110
+ 00:01:46,000 --> 00:01:52,000
111
+ This thing overlays your network and what it does is that it's going to allow for efficient network,
112
+
113
+ 29
114
+ 00:01:52,000 --> 00:02:01,000
115
+ um, traffic that allows applications to be used correctly and efficiently, making data routing more
116
+
117
+ 30
118
+ 00:02:01,000 --> 00:02:02,000
119
+ efficient.
120
+
121
+ 31
122
+ 00:02:02,000 --> 00:02:06,000
123
+ You see, if we don't have this, the data routing would be all over the.
124
+
125
+ 32
126
+ 00:02:06,000 --> 00:02:10,000
127
+ They would have to go and pull some of the data from the cloud and pull it, some of it from the data
128
+
129
+ 33
130
+ 00:02:10,000 --> 00:02:10,000
131
+ center.
132
+
133
+ 34
134
+ 00:02:11,000 --> 00:02:17,000
135
+ Another thing you want to have in here when you set this up is sassy SASE.
136
+
137
+ 35
138
+ 00:02:17,000 --> 00:02:20,000
139
+ It stands for Secure Access Service Edge.
140
+
141
+ 36
142
+ 00:02:20,000 --> 00:02:22,000
143
+ This is a cloud native network and architect.
144
+
145
+ 37
146
+ 00:02:22,000 --> 00:02:26,000
147
+ It combines network security functions with Wan capability.
148
+
149
+ 38
150
+ 00:02:26,000 --> 00:02:31,000
151
+ It merges the SD SD-Wan capabilities with security services.
152
+
153
+ 39
154
+ 00:02:31,000 --> 00:02:32,000
155
+ What is it doing?
156
+
157
+ 40
158
+ 00:02:32,000 --> 00:02:38,000
159
+ Well, this is going to allow those tunnels that you see between those connections to become encrypted,
160
+
161
+ 41
162
+ 00:02:38,000 --> 00:02:41,000
163
+ to connect them to cloud based services, to make them more efficient.
164
+
165
+ 42
166
+ 00:02:41,000 --> 00:02:44,000
167
+ So let's go back here and talk more about this.
168
+
169
+ 43
170
+ 00:02:45,000 --> 00:02:47,000
171
+ So when you set up things like SD-Wan.
172
+
173
+ 44
174
+ 00:02:47,000 --> 00:02:53,000
175
+ SD-Wan is going to allow you to efficiently utilize all types of network connections.
176
+
177
+ 45
178
+ 00:02:55,000 --> 00:02:57,000
179
+ All types of multiple connections.
180
+
181
+ 46
182
+ 00:02:57,000 --> 00:03:02,000
183
+ So imagine you're sitting in this branch office and you need to access some of the applications in the
184
+
185
+ 47
186
+ 00:03:02,000 --> 00:03:04,000
187
+ cloud, some of it in the data center.
188
+
189
+ 48
190
+ 00:03:04,000 --> 00:03:06,000
191
+ Applications can even be split apart.
192
+
193
+ 49
194
+ 00:03:06,000 --> 00:03:10,000
195
+ Now you have SD-Wan, comes in, sets up a variety.
196
+
197
+ 50
198
+ 00:03:10,000 --> 00:03:16,000
199
+ It's it's a type of software defined networking or Sdn that allows it.
200
+
201
+ 51
202
+ 00:03:16,000 --> 00:03:21,000
203
+ It's basically a higher controller level that sits over all these connections and determines the best,
204
+
205
+ 52
206
+ 00:03:21,000 --> 00:03:25,000
207
+ most efficient and secure path to get through the data.
208
+
209
+ 53
210
+ 00:03:25,000 --> 00:03:27,000
211
+ If you're wondering, why do we do all this?
212
+
213
+ 54
214
+ 00:03:27,000 --> 00:03:34,000
215
+ Well, imagine right now how complex networking is without getting too technical and in depth into it,
216
+
217
+ 55
218
+ 00:03:34,000 --> 00:03:36,000
219
+ because you don't need it basically for your exam.
220
+
221
+ 56
222
+ 00:03:36,000 --> 00:03:38,000
223
+ What this really is going to allow you to do?
224
+
225
+ 57
226
+ 00:03:39,000 --> 00:03:44,000
227
+ All the apps the company is using is is going to make it faster and more secure to use.
228
+
11 - Security Principles/016 Selecting Effective Controls OB 3.2_en.srt ADDED
@@ -0,0 +1,400 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ 1
2
+ 00:00:00,000 --> 00:00:07,000
3
+ So far we have seen quite a lot of different security security network appliances that we can implement.
4
+
5
+ 2
6
+ 00:00:07,000 --> 00:00:13,000
7
+ But there's a couple of things that we got to think about selecting the effective controls, selecting
8
+
9
+ 3
10
+ 00:00:13,000 --> 00:00:21,000
11
+ the right amount of security to apply to a network, selecting the right device that we have to put
12
+
13
+ 4
14
+ 00:00:21,000 --> 00:00:28,000
15
+ in our network, selecting the right configuration that we put onto these devices.
16
+
17
+ 5
18
+ 00:00:28,000 --> 00:00:31,000
19
+ So in this video we want to talk about selecting effective controls.
20
+
21
+ 6
22
+ 00:00:31,000 --> 00:00:36,000
23
+ What is the process of identifying and implementing the right security measure for your organization.
24
+
25
+ 7
26
+ 00:00:37,000 --> 00:00:40,000
27
+ Now this is going to get very complex.
28
+
29
+ 8
30
+ 00:00:40,000 --> 00:00:43,000
31
+ Every single organization is built differently.
32
+
33
+ 9
34
+ 00:00:43,000 --> 00:00:45,000
35
+ Every organization has assets of different value.
36
+
37
+ 10
38
+ 00:00:45,000 --> 00:00:48,000
39
+ Every organization values assets differently.
40
+
41
+ 11
42
+ 00:00:48,000 --> 00:00:53,000
43
+ Some organization doesn't have much value on their data on their.
44
+
45
+ 12
46
+ 00:00:53,000 --> 00:00:54,000
47
+ Because you know why?
48
+
49
+ 13
50
+ 00:00:54,000 --> 00:00:56,000
51
+ Well, maybe some of the employee data.
52
+
53
+ 14
54
+ 00:00:56,000 --> 00:01:00,000
55
+ But the company's main data don't really put a value on because it's all public knowledge.
56
+
57
+ 15
58
+ 00:01:00,000 --> 00:01:01,000
59
+ Think of like a.
60
+
61
+ 16
62
+ 00:01:02,000 --> 00:01:03,000
63
+ Like something on.
64
+
65
+ 17
66
+ 00:01:03,000 --> 00:01:04,000
67
+ If you're managing Wikipedia.
68
+
69
+ 18
70
+ 00:01:04,000 --> 00:01:08,000
71
+ All the data that Wikipedia have, it's pretty much public data.
72
+
73
+ 19
74
+ 00:01:08,000 --> 00:01:13,000
75
+ The only thing that's private is their credit card information that they collect and the employee resources.
76
+
77
+ 20
78
+ 00:01:13,000 --> 00:01:16,000
79
+ But if you work for the military, it's vastly different.
80
+
81
+ 21
82
+ 00:01:16,000 --> 00:01:23,000
83
+ Everything there, most of it, especially like in the NSA, it's all private or top secret information
84
+
85
+ 22
86
+ 00:01:23,000 --> 00:01:24,000
87
+ versus Wikipedia.
88
+
89
+ 23
90
+ 00:01:24,000 --> 00:01:31,000
91
+ 90% of what they collect is public data, vast differences between organization and what they value,
92
+
93
+ 24
94
+ 00:01:31,000 --> 00:01:33,000
95
+ vast differences on how they value it.
96
+
97
+ 25
98
+ 00:01:33,000 --> 00:01:38,000
99
+ So when you select security controls, these are things you have to consider.
100
+
101
+ 26
102
+ 00:01:38,000 --> 00:01:42,000
103
+ And that starts with a risk assessment starts with a thorough risk assessment.
104
+
105
+ 27
106
+ 00:01:42,000 --> 00:01:49,000
107
+ What exactly identify what exact risks do you guys face and how do you want to mitigate those potential
108
+
109
+ 28
110
+ 00:01:49,000 --> 00:01:50,000
111
+ threats?
112
+
113
+ 29
114
+ 00:01:51,000 --> 00:01:54,000
115
+ I mentioned at the beginning of this course Layered Defense.
116
+
117
+ 30
118
+ 00:01:55,000 --> 00:01:57,000
119
+ You have to implement a variety of different controls.
120
+
121
+ 31
122
+ 00:01:57,000 --> 00:01:59,000
123
+ No single point.
124
+
125
+ 32
126
+ 00:02:00,000 --> 00:02:00,000
127
+ All right.
128
+
129
+ 33
130
+ 00:02:00,000 --> 00:02:01,000
131
+ No single.
132
+
133
+ 34
134
+ 00:02:01,000 --> 00:02:02,000
135
+ Everything needs layered.
136
+
137
+ 35
138
+ 00:02:02,000 --> 00:02:03,000
139
+ Layered approach.
140
+
141
+ 36
142
+ 00:02:03,000 --> 00:02:07,000
143
+ And what you should be consideration is what are the different layers.
144
+
145
+ 37
146
+ 00:02:07,000 --> 00:02:08,000
147
+ How are you going to layer them?
148
+
149
+ 38
150
+ 00:02:08,000 --> 00:02:13,000
151
+ You may have cameras in different locations and maybe you need security guard and cameras.
152
+
153
+ 39
154
+ 00:02:13,000 --> 00:02:19,000
155
+ Maybe you you have particularly, uh, doors that are built a certain way and you don't have security
156
+
157
+ 40
158
+ 00:02:19,000 --> 00:02:21,000
159
+ guards, things to consider.
160
+
161
+ 41
162
+ 00:02:21,000 --> 00:02:28,000
163
+ But if there's one thing I know, but living long enough in this world, a lot of times the consideration
164
+
165
+ 42
166
+ 00:02:28,000 --> 00:02:31,000
167
+ may come to selecting the right controls for your business.
168
+
169
+ 43
170
+ 00:02:31,000 --> 00:02:36,000
171
+ Unfortunately, almost always comes back to money.
172
+
173
+ 44
174
+ 00:02:37,000 --> 00:02:38,000
175
+ Evaluating the course.
176
+
177
+ 45
178
+ 00:02:38,000 --> 00:02:42,000
179
+ What is the cost of implementing a control against the potential risk benefit that is given?
180
+
181
+ 46
182
+ 00:02:43,000 --> 00:02:48,000
183
+ If there's one thing we're going to talk about when we get to a risk assessment is can't spend $10,
184
+
185
+ 47
186
+ 00:02:48,000 --> 00:02:51,000
187
+ protecting $5 doesn't make sense.
188
+
189
+ 48
190
+ 00:02:51,000 --> 00:02:58,000
191
+ A lot of times, the control that we select, the kind of firewall that we implement, the kind of IDs
192
+
193
+ 49
194
+ 00:02:58,000 --> 00:03:06,000
195
+ that we put into place, um, whether we have a load balancer, the type of VPN we set up, a lot of
196
+
197
+ 50
198
+ 00:03:06,000 --> 00:03:08,000
199
+ these things are going to be determined basically.
200
+
201
+ 51
202
+ 00:03:08,000 --> 00:03:09,000
203
+ And do you have the budget for it?
204
+
205
+ 52
206
+ 00:03:09,000 --> 00:03:10,000
207
+ Yeah.
208
+
209
+ 53
210
+ 00:03:10,000 --> 00:03:16,000
211
+ We all want the latest and greatest engine firewall, but we can't afford it because it's super expensive.
212
+
213
+ 54
214
+ 00:03:16,000 --> 00:03:19,000
215
+ So you have to be able to understand that cost is a big thing.
216
+
217
+ 55
218
+ 00:03:19,000 --> 00:03:24,000
219
+ Another thing that you have to really keep in consideration is regulation.
220
+
221
+ 56
222
+ 00:03:24,000 --> 00:03:30,000
223
+ Certain regulations will make it mandatory for you to encrypt and store certain data in a certain way.
224
+
225
+ 57
226
+ 00:03:30,000 --> 00:03:35,000
227
+ For example, in HIPAA regulation, you're going to have to secure a certain medical records.
228
+
229
+ 58
230
+ 00:03:35,000 --> 00:03:37,000
231
+ If you follow PCI compliance.
232
+
233
+ 59
234
+ 00:03:37,000 --> 00:03:41,000
235
+ This is a kind of a standard that you're going to have to encrypt credit card information.
236
+
237
+ 60
238
+ 00:03:41,000 --> 00:03:47,000
239
+ So the controls you select their technical stability, assessing the technical capability of feasibilities
240
+
241
+ 61
242
+ 00:03:47,000 --> 00:03:47,000
243
+ controls.
244
+
245
+ 62
246
+ 00:03:47,000 --> 00:03:49,000
247
+ Can you even implement it?
248
+
249
+ 63
250
+ 00:03:49,000 --> 00:03:55,000
251
+ Does your environment even support a particular control that you want to implement every time you implement
252
+
253
+ 64
254
+ 00:03:55,000 --> 00:03:59,000
255
+ a particular risk, maybe a new kind of firewall or a load balancer or something?
256
+
257
+ 65
258
+ 00:04:00,000 --> 00:04:07,000
259
+ You know it identifies more risk into the organization's control, should be directly relevant for the
260
+
261
+ 66
262
+ 00:04:07,000 --> 00:04:09,000
263
+ risk that they're implementing does.
264
+
265
+ 67
266
+ 00:04:10,000 --> 00:04:16,000
267
+ And the other thing is that if you implement this control, does it result in reducing a particular
268
+
269
+ 68
270
+ 00:04:16,000 --> 00:04:18,000
271
+ risk, the risk of hackers breaking in?
272
+
273
+ 69
274
+ 00:04:18,000 --> 00:04:19,000
275
+ So you put a firewall in place.
276
+
277
+ 70
278
+ 00:04:19,000 --> 00:04:21,000
279
+ Does the firewall address that?
280
+
281
+ 71
282
+ 00:04:22,000 --> 00:04:27,000
283
+ The risk of a worm spreading around inside of a network.
284
+
285
+ 72
286
+ 00:04:27,000 --> 00:04:28,000
287
+ Does the firewall address that?
288
+
289
+ 73
290
+ 00:04:28,000 --> 00:04:32,000
291
+ Well, network firewalls generally is not going to stop a worm from spreading around inside of the network
292
+
293
+ 74
294
+ 00:04:32,000 --> 00:04:33,000
295
+ if it's already there.
296
+
297
+ 75
298
+ 00:04:33,000 --> 00:04:35,000
299
+ Host based firewalls does.
300
+
301
+ 76
302
+ 00:04:35,000 --> 00:04:42,000
303
+ So you have to make sure that the what you're implementing addresses that risk stability and adaptability.
304
+
305
+ 77
306
+ 00:04:42,000 --> 00:04:44,000
307
+ Controls should be able to scale with the company.
308
+
309
+ 78
310
+ 00:04:44,000 --> 00:04:52,000
311
+ Don't buy a particular appliance, and it's only good for 100 users in the company right now is at 80,
312
+
313
+ 79
314
+ 00:04:52,000 --> 00:04:53,000
315
+ and it's going to go to 200in a few months.
316
+
317
+ 80
318
+ 00:04:53,000 --> 00:04:54,000
319
+ That's not scalable.
320
+
321
+ 81
322
+ 00:04:55,000 --> 00:05:01,000
323
+ Always evaluate regular monitor, review and update these types of controls for effectiveness is going
324
+
325
+ 82
326
+ 00:05:01,000 --> 00:05:02,000
327
+ to be important.
328
+
329
+ 83
330
+ 00:05:02,000 --> 00:05:04,000
331
+ Monitor your environment.
332
+
333
+ 84
334
+ 00:05:05,000 --> 00:05:15,000
335
+ If there's one thing we know in it that sometimes I can't stand is the constant nonstop change of technology,
336
+
337
+ 85
338
+ 00:05:15,000 --> 00:05:21,000
339
+ such as different kinds of software, hardware, different kinds of attacks that comes out, pushes
340
+
341
+ 86
342
+ 00:05:21,000 --> 00:05:26,000
343
+ us to consistently modify and change the technology that we work in.
344
+
345
+ 87
346
+ 00:05:27,000 --> 00:05:28,000
347
+ Our environments will change.
348
+
349
+ 88
350
+ 00:05:28,000 --> 00:05:35,000
351
+ Whatever it secure environment that you're working in right now will not will cease to exist and completely
352
+
353
+ 89
354
+ 00:05:35,000 --> 00:05:38,000
355
+ do a major change.
356
+
357
+ 90
358
+ 00:05:39,000 --> 00:05:45,000
359
+ I guarantee you, within the next 5 to 8 years on on a general rotation, every 5 to 8 years, the whole
360
+
361
+ 91
362
+ 00:05:45,000 --> 00:05:46,000
363
+ thing will change.
364
+
365
+ 92
366
+ 00:05:46,000 --> 00:05:51,000
367
+ All technology changes, all the operating systems will change, all the devices will change.
368
+
369
+ 93
370
+ 00:05:51,000 --> 00:05:55,000
371
+ For example, Sonicwall is not going to allow us to keep using this particular device because they're
372
+
373
+ 94
374
+ 00:05:55,000 --> 00:05:56,000
375
+ going to say it's outdated.
376
+
377
+ 95
378
+ 00:05:56,000 --> 00:05:57,000
379
+ We'll have to get a new one.
380
+
381
+ 96
382
+ 00:05:58,000 --> 00:06:04,000
383
+ So the and a consistent changes is the control effective new attacks will come out.
384
+
385
+ 97
386
+ 00:06:04,000 --> 00:06:05,000
387
+ And then what are you going to do.
388
+
389
+ 98
390
+ 00:06:05,000 --> 00:06:09,000
391
+ You're going to have to update your devices, update your software.
392
+
393
+ 99
394
+ 00:06:09,000 --> 00:06:13,000
395
+ If there's one thing that's a constant when it managing security.
396
+
397
+ 100
398
+ 00:06:13,000 --> 00:06:19,000
399
+ One thing that's that's a constant when managing security uh, is change.
400
+
11 - Security Principles/017 Quick Quiz.html ADDED
@@ -0,0 +1,479 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ <!DOCTYPE html>
2
+ <html lang="en">
3
+ <head>
4
+ <meta charset="UTF-8" />
5
+ <meta http-equiv="X-UA-Compatible" content="IE=edge" />
6
+ <meta name="viewport" content="width=device-width, initial-scale=1.0" />
7
+ <title>Quiz</title>
8
+ <style>
9
+ * {
10
+ font-family: system-ui, -apple-system, BlinkMacSystemFont, "Segoe UI", Roboto, Oxygen, Ubuntu, Cantarell,
11
+ "Open Sans", "Helvetica Neue", sans-serif;
12
+ margin: 0;
13
+ padding: 0;
14
+ box-sizing: border-box;
15
+ font-size: 16px;
16
+ }
17
+
18
+ main {
19
+ padding-top: 48px;
20
+ }
21
+
22
+ :root {
23
+ --large-device-width: 850px;
24
+ --primary-color: #0f172a;
25
+ --secondary-color: #020617;
26
+ --primary-text-color: #c7d1dd;
27
+ --secondary-text-color: #061602;
28
+ --success-background: hsl(159, 82%, 24%);
29
+ --success-foreground: hsl(164, 86%, 16%);
30
+ --success: hsl(160, 84%, 39%);
31
+ --danger: #ef4444;
32
+ --warning: #f59e0b;
33
+ --info-background: hsl(218, 81%, 8%);
34
+ --info-foreground: hsl(217, 91%, 85%);
35
+ --border-color: #d1d7dc;
36
+ --check-box-size: 20px;
37
+ /* control the size */
38
+ --check-box-color: var(--info-foreground);
39
+ /* the active color */
40
+ }
41
+
42
+ body {
43
+ position: relative;
44
+ background-color: #020617;
45
+ color: var(--primary-text-color);
46
+ }
47
+
48
+ #score-stats-container {
49
+ position: fixed;
50
+ z-index: 10;
51
+ top: 0;
52
+ height: 40px;
53
+ width: 100%;
54
+ background-color: var(--info-background);
55
+
56
+ padding: 0px 16px;
57
+ color: var(--info-foreground);
58
+ font-weight: 600;
59
+ display: flex;
60
+ align-items: center;
61
+ justify-content: space-between;
62
+ }
63
+
64
+ #quiz-container {
65
+ border-radius: 8px;
66
+ display: flex;
67
+ gap: 16px;
68
+ flex-direction: column;
69
+ }
70
+
71
+ input[type="radio"] {
72
+ height: var(--check-box-size);
73
+ aspect-ratio: 1;
74
+ border: calc(var(--check-box-size) / 8) solid #939393;
75
+ padding: calc(var(--check-box-size) / 8);
76
+ background: radial-gradient(farthest-side, var(--check-box-color) 94%, #0000) 50%/0 0 no-repeat
77
+ content-box;
78
+ border-radius: 50%;
79
+ outline-offset: calc(var(--check-box-size) / 10);
80
+ -webkit-appearance: none;
81
+ -moz-appearance: none;
82
+ appearance: none;
83
+ cursor: pointer;
84
+ font-size: inherit;
85
+ transition: 0.3s;
86
+ }
87
+
88
+ input[type="radio"]:checked {
89
+ border-color: var(--check-box-color);
90
+ background-size: 100% 100%;
91
+ }
92
+
93
+ input[type="radio"]:disabled {
94
+ background: linear-gradient(#939393 0 0) 50%/100% 20% no-repeat content-box;
95
+ opacity: 0.5;
96
+ cursor: not-allowed;
97
+ }
98
+
99
+ label {
100
+ display: inline-flex;
101
+ align-items: center;
102
+ gap: 10px;
103
+ cursor: pointer;
104
+ padding: 4px 6px;
105
+ border-radius: 4px;
106
+ }
107
+
108
+ @media (max-width: 767px) {
109
+ input[type="radio"],
110
+ label {
111
+ cursor: default;
112
+ }
113
+
114
+ #quiz-container {
115
+ margin-left: 8px;
116
+ margin-right: 8px;
117
+ }
118
+ }
119
+
120
+ /* PC (Desktop devices) */
121
+ @media (min-width: 768px) {
122
+ body {
123
+ display: flex;
124
+ justify-content: center;
125
+ }
126
+
127
+ main {
128
+ max-width: var(--large-device-width);
129
+ }
130
+
131
+ #score-stats-container {
132
+ max-width: var(--large-device-width);
133
+ }
134
+
135
+ dialog {
136
+ max-width: var(--large-device-width);
137
+ }
138
+ }
139
+
140
+ @media print {
141
+ input[type="radio"] {
142
+ background: none !important;
143
+ border-color: #939393 !important;
144
+ }
145
+
146
+ input[type="radio"]:checked {
147
+ border-color: #939393 !important;
148
+ }
149
+ }
150
+
151
+ .question-lable {
152
+ display: flex;
153
+ align-items: center;
154
+ gap: 8px;
155
+ }
156
+
157
+ button {
158
+ -webkit-tap-highlight-color: transparent;
159
+ -webkit-touch-callout: none;
160
+ -webkit-user-select: none;
161
+ user-select: none;
162
+ outline: none;
163
+ position: relative;
164
+ overflow: hidden;
165
+ cursor: pointer;
166
+ }
167
+
168
+ .button {
169
+ background-color: var(--success-background);
170
+ border: none;
171
+ color: #f4f5f7;
172
+ opacity: 0.8;
173
+ font-size: 18px;
174
+ flex-grow: 1;
175
+ padding: 8px 16px;
176
+ border-radius: 8px;
177
+ }
178
+
179
+ .button:hover {
180
+ opacity: 1;
181
+ }
182
+
183
+ .explanation-btn {
184
+ border: none;
185
+ color: var(--success);
186
+ background-color: transparent;
187
+ }
188
+
189
+ #submit-button:active::after {
190
+ background-color: #ef4444;
191
+ }
192
+
193
+ .single-question-container {
194
+ background-color: var(--primary-color);
195
+ display: flex;
196
+ flex-direction: column;
197
+ gap: 8px;
198
+ padding: 16px;
199
+ border-radius: 8px;
200
+ }
201
+
202
+ #modal-content {
203
+ padding: 16px;
204
+ line-height: 24px;
205
+ }
206
+
207
+ dialog::backdrop {
208
+ background: rgba(0, 0, 0, 0.5);
209
+ }
210
+
211
+ dialog {
212
+ position: fixed;
213
+ border: 1px solid var(--border-color);
214
+ background-color: var(--primary-color);
215
+ color: rgb(240, 241, 248);
216
+ padding: 16px;
217
+ border-radius: 8px;
218
+ width: 80vw;
219
+ max-height: 80vh;
220
+ overflow: auto;
221
+ top: 50%;
222
+ left: 50%;
223
+ -webkit-transform: translateX(-50%) translateY(-50%);
224
+ -moz-transform: translateX(-50%) translateY(-50%);
225
+ -ms-transform: translateX(-50%) translateY(-50%);
226
+ transform: translateX(-50%) translateY(-50%);
227
+ }
228
+
229
+ #close-modal-btn {
230
+ position: absolute;
231
+ top: 4px;
232
+ right: 4px;
233
+ padding: 2px 8px;
234
+ border-radius: 2px;
235
+ border: none;
236
+ background-color: var(--danger);
237
+ }
238
+
239
+ .correct-answer label {
240
+ border: 2px solid var(--success);
241
+ width: 100%;
242
+ }
243
+
244
+ .incorrect-answer label {
245
+ border: 2px solid var(--danger);
246
+ width: 100%;
247
+ }
248
+
249
+ .options-container {
250
+ display: flex;
251
+ flex-direction: column;
252
+ gap: 4px;
253
+ }
254
+
255
+ #quiz-meta-container {
256
+ border-radius: 8px;
257
+ background-color: var(--primary-color);
258
+ margin-bottom: 12px;
259
+ padding: 8px;
260
+ }
261
+
262
+ #quiz-title {
263
+ text-align: center;
264
+ font-size: 24px;
265
+ margin-bottom: 8px;
266
+ }
267
+
268
+ #quiz-description {
269
+ line-height: 1.5;
270
+ padding: 2px 6px;
271
+ }
272
+ </style>
273
+ </head>
274
+
275
+ <body onload="main()">
276
+ <main>
277
+ <section id="quiz-meta-container">
278
+ <h1 id="quiz-title"></h1>
279
+ <p id="quiz-description"></p>
280
+ </section>
281
+ <section id="score-stats-container">
282
+ <div id="score-card">
283
+ Score: <span id="current-score">999</span> of
284
+ <span id="pass-percent">999%</span>
285
+ </div>
286
+ <div>Correct: <span id="correct-answers">999</span></div>
287
+ <div>Incorrect: <span id="wrong-answers">999</span></div>
288
+ </section>
289
+
290
+ <section id="quiz-container"></section>
291
+
292
+ <dialog id="modal" class="modal-container">
293
+ <div id="modal-content">
294
+ <p id="modal-text"></p>
295
+ </div>
296
+ </dialog>
297
+ </main>
298
+
299
+ <script>
300
+ const quizData = {"quiz_id": 6180138, "quiz_description": null, "quiz_title": "Quick Quiz", "pass_percent": null, "questions": [{"_class": "assessment", "id": 74728886, "assessment_type": "multiple-choice", "prompt": {"question": "<p>An organization decides to implement a system that segregates its network into different segments based on the function and security level. What is this an example of?</p>", "relatedLectureIds": "", "feedbacks": ["", "This scenario exemplifies the implementation of Security zones. By segregating the network into different segments based on function and security level, the organization can apply appropriate security measures for each zone, thereby enhancing overall security and managing risks more effectively. This differs from Device placement, which is about the strategic positioning of physical devices, and Attack surface, which refers to the total number of points where an unauthorized user can try to enter data or extract data.", "", ""], "answers": ["<p>Device placement</p>", "<p>Security zones</p>", "<p>Attack surface</p>", "<p>Connectivity</p>"]}, "correct_response": ["b"], "section": "", "question_plain": "An organization decides to implement a system that segregates its network into different segments based on the function and security level. What is this an example of?", "related_lectures": []}, {"_class": "assessment", "id": 74728890, "assessment_type": "multiple-choice", "prompt": {"question": "<p>A company's network automatically shuts down its connection when a system failure is detected to prevent potential security breaches. What type of failure mode does this represent?</p>", "relatedLectureIds": "", "feedbacks": ["", "This scenario represents a Fail-closed failure mode. In a fail-closed setup, when a system failure is detected, the network automatically shuts down its connection, which prevents potential security breaches during the downtime. This contrasts with Fail-open, where the system remains operational even after detecting a failure, potentially exposing it to security risks.", "", ""], "answers": ["<p>Fail-open</p>", "<p>Fail-closed</p>", "<p>Active device attribute</p>", "<p>Inline device placement</p>"]}, "correct_response": ["b"], "section": "", "question_plain": "A company's network automatically shuts down its connection when a system failure is detected to prevent potential security breaches. What type of failure mode does this represent?", "related_lectures": []}, {"_class": "assessment", "id": 74728896, "assessment_type": "multiple-choice", "prompt": {"question": "<p>A company uses a technology that inspects incoming and outgoing network traffic and blocks potential threats based on a set of security rules. What is this technology?</p>", "relatedLectureIds": "", "feedbacks": ["", "This scenario describes an Intrusion Prevention System (IPS). An IPS monitors network traffic to detect and prevent identified threats, acting based on predefined security rules. This is distinct from a Proxy server, which acts as an intermediary for requests from clients, a Load balancer, which distributes network traffic across multiple servers, and a Jump server, used as a secure and controlled entry point to a remote network.", "", ""], "answers": ["<p>Proxy server</p>", "<p>Intrusion Prevention System (IPS)</p>", "<p>Load balancer</p>", "<p>Jump server</p>"]}, "correct_response": ["b"], "section": "", "question_plain": "A company uses a technology that inspects incoming and outgoing network traffic and blocks potential threats based on a set of security rules. What is this technology?", "related_lectures": []}, {"_class": "assessment", "id": 74728898, "assessment_type": "multiple-choice", "prompt": {"question": "<p>A large corporation employs a solution that allows its employees to securely access the company's internal network from remote locations. What does this represent?</p>", "relatedLectureIds": "", "feedbacks": ["", "", "This scenario represents the use of a Virtual Private Network (VPN). A VPN allows secure access to a private network over the internet, enabling employees to access internal network resources remotely while maintaining data security and privacy. This is different from general Remote access, which can include non-VPN methods, Tunneling, which is a broader concept often part of VPN technology, and SD-WAN, which is a more specific approach to managing wide-area networks.", ""], "answers": ["<p>Remote access</p>", "<p>Tunneling</p>", "<p>Virtual Private Network (VPN)</p>", "<p>Software-defined wide area network (SD-WAN)</p>"]}, "correct_response": ["c"], "section": "", "question_plain": "A large corporation employs a solution that allows its employees to securely access the company's internal network from remote locations. What does this represent?", "related_lectures": []}, {"_class": "assessment", "id": 74728906, "assessment_type": "multiple-choice", "prompt": {"question": "<p>To enhance network security, a company implements a switch that requires devices to be authenticated before they can access the network. What technology is being used?</p>", "relatedLectureIds": "", "feedbacks": ["This scenario describes the use of Port security with 802.1X. The 802.1X standard is used to control network access, requiring devices to be authenticated before they can access the network. This helps in preventing unauthorized devices from connecting to the network. EAP is a protocol used in network access authentication, but 802.1X specifically refers to the port-based network access control.", "", "", ""], "answers": ["<p>Port security with 802.1X</p>", "<p>EAP (Extensible Authentication Protocol)</p>", "<p>Firewall</p>", "<p>Jump server</p>"]}, "correct_response": ["a"], "section": "", "question_plain": "To enhance network security, a company implements a switch that requires devices to be authenticated before they can access the network. What technology is being used?", "related_lectures": []}]};
301
+ let correct = new Set();
302
+ let incorrect = new Set();
303
+ let totalNumberOfQuestions = 0;
304
+ const quizTitle = quizData.quiz_title;
305
+ const quizDescription = quizData.quiz_description;
306
+ const questionData = quizData.questions;
307
+ const passPercent = quizData.pass_percent;
308
+ const modalTextElement = document.getElementById("modal-text");
309
+ const quizContainerElement = document.getElementById("quiz-container");
310
+
311
+ const dialog = document.querySelector("dialog");
312
+ const showButton = document.getElementById("view-explanatin");
313
+ const closeButton = document.getElementById("close-modal-btn");
314
+ const quizTitleElement = document.getElementById("quiz-title");
315
+ const quizDescriptionElement = document.getElementById("quiz-description");
316
+
317
+ function main() {
318
+ // update quiz meta data
319
+ document.title = quizTitle;
320
+ quizTitleElement.innerHTML = quizTitle;
321
+ quizDescriptionElement.innerHTML = quizDescription;
322
+
323
+ const passPercentElement = document.getElementById("pass-percent");
324
+ passPercentElement.innerHTML = passPercent + "%";
325
+ totalNumberOfQuestions = questionData.length;
326
+ // shuffle the questionData to randomize the order of the questions
327
+ for (let i = questionData.length - 1; i > 0; i--) {
328
+ const j = Math.floor(Math.random() * (i + 1));
329
+ [questionData[i], questionData[j]] = [questionData[j], questionData[i]];
330
+ }
331
+
332
+ let formattedQuestions = questionData.map(formatSingleQuestionData);
333
+ updateScore();
334
+ // display the formattedQuestions
335
+ formattedQuestions.forEach((question, idx) => {
336
+ renderSingleQuestion(question, idx + 1);
337
+ });
338
+ }
339
+
340
+ /**
341
+ * Formats the question data from the given QuizData object.
342
+ *
343
+ * @param {Object} singleQuizData - The singleQuizData object containing prompt and correct_response.
344
+ * @return {Object} The formatted question object with the following properties:
345
+ * - id: The ID of the question.
346
+ * - question: The text of the question.
347
+ * - answers: The array of answer options.
348
+ * - correctAnswer: The text of the correct answer.
349
+ * - explanation: The explanation of the correct answer.
350
+ */
351
+ function formatSingleQuestionData(singleQuizData = null) {
352
+ const { prompt, correct_response, id } = singleQuizData;
353
+ const questionText = prompt.question;
354
+ const answers = prompt.answers;
355
+ const correctAnswer = correct_response[0];
356
+ const correctAnswerText = answers[correctAnswer.toLowerCase().charCodeAt(0) - 97];
357
+ const questionObj = {
358
+ id: id,
359
+ question: questionText,
360
+ answers: answers,
361
+ correctAnswer: correctAnswerText,
362
+ explanation: prompt?.explanation || "",
363
+ };
364
+ return questionObj;
365
+ }
366
+
367
+ /**
368
+ * Renders a single question with its options and submit button.
369
+ *
370
+ * @param {Object} singleQuestionData - The data of the question to render.
371
+ * @param {number} rootIndex - The index of the question in the quiz.
372
+ * @return {void} return nothing.
373
+ */
374
+
375
+ const renderSingleQuestion = (singleQuestionData = {}, rootIndex = 1) => {
376
+ const { id, explanation, answers, correctAnswer, question } = singleQuestionData;
377
+ // shuffle the answers to randomize the order of the answers
378
+ for (let i = answers.length - 1; i > 0; i--) {
379
+ const j = Math.floor(Math.random() * (i + 1));
380
+ [answers[i], answers[j]] = [answers[j], answers[i]];
381
+ }
382
+ const optionsHTML = answers
383
+ .map((option, index) => {
384
+ const optionId = `${id}_${index}`;
385
+
386
+ return `
387
+ <div class="question-lable">
388
+ <input type="radio" id="${optionId}" name="${"answer"}" value="${option}" />
389
+ <label for="${optionId}">${option}</label>
390
+ </div>
391
+ `;
392
+ })
393
+
394
+ .join("");
395
+
396
+ const container = document.createElement("div");
397
+ container.innerHTML = `
398
+ <form data-correct-answer="${correctAnswer}" data-question-id="${id}" class="single-question-container" onsubmit="submitButtonListener(event)">
399
+ <div style="display: flex;justify-content: space-between;">
400
+ <p style="font-weight: 600">Question ${rootIndex}:</p>
401
+ <button type="button" onclick="renderExplanation(event)" id="${`explanation-${id}`}" data-explanation="${explanation}" class="explanation-btn">View Explanation</button>
402
+ </div>
403
+ <p style="margin-bottom: 8px;line-height: 1.5">${question}</p>
404
+ <div class="options-container">
405
+ ${optionsHTML}
406
+ </div>
407
+ <div style="display: flex; gap: 8px;">
408
+ <button type="submit" id="submit-button" class="button">Submit</button>
409
+ </div>
410
+ </form>
411
+ `;
412
+ quizContainerElement.appendChild(container);
413
+ };
414
+
415
+ /**
416
+ * Updates the score on the page based on the number of correct and incorrect answers.
417
+ *
418
+ * @return {void} This function does not return a value.
419
+ */
420
+ function updateScore() {
421
+ const currentParcentageElement = document.getElementById("current-score");
422
+ const correctAnswerElement = document.getElementById("correct-answers");
423
+ const wrongAnswerElement = document.getElementById("wrong-answers");
424
+ correctAnswerElement.innerHTML = correct.size;
425
+ wrongAnswerElement.innerHTML = incorrect.size;
426
+ const score = Number((correct.size / totalNumberOfQuestions) * 100).toFixed(2);
427
+ currentParcentageElement.innerHTML = score;
428
+ }
429
+
430
+ /**
431
+ * Handles the event when the submit button is clicked.
432
+ *
433
+ * @param {Event} e - The event object.
434
+ * @return {void} This function does not return anything.
435
+ */
436
+ const submitButtonListener = (e) => {
437
+ e.preventDefault();
438
+ const formData = new FormData(e.target);
439
+ const form = e.target;
440
+ const selectedOption = e.target.querySelector('input[type="radio"]:checked');
441
+ if (!selectedOption) {
442
+ alert("Please select an answer!");
443
+ return;
444
+ }
445
+
446
+ let isCorrect = false;
447
+ const { answer: userAnswer } = Object.fromEntries(formData.entries());
448
+ const correctAnswer = e.target.dataset.correctAnswer;
449
+ const questionId = e.target.dataset.questionId;
450
+ if (userAnswer == correctAnswer) {
451
+ correct.add(questionId);
452
+ incorrect.delete(questionId);
453
+ isCorrect = true;
454
+ } else {
455
+ incorrect.add(e.target.dataset.questionId);
456
+ correct.delete(questionId);
457
+ }
458
+ updateScore();
459
+
460
+ const resultClass = isCorrect ? "correct-answer" : "incorrect-answer";
461
+
462
+ form.querySelectorAll(".question-lable").forEach((label) => {
463
+ label.classList.remove("correct-answer", "incorrect-answer");
464
+ });
465
+ selectedOption.closest(".question-lable").classList.add(resultClass);
466
+ };
467
+
468
+ function renderExplanation(ev) {
469
+ modalTextElement.innerHTML = ev.target.dataset?.explanation || "no explanation found";
470
+ dialog.showModal();
471
+ dialog.addEventListener("click", (event) => {
472
+ if (event.target === dialog) {
473
+ dialog.close();
474
+ }
475
+ });
476
+ }
477
+ </script>
478
+ </body>
479
+ </html>
12 - Data Protection/001 Regulated Data OB 3.3_en.srt ADDED
@@ -0,0 +1,148 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ 1
2
+ 00:00:00,000 --> 00:00:07,000
3
+ Most organizations nowadays will follow some kind of regulations pertaining to the data that it collects.
4
+
5
+ 2
6
+ 00:00:07,000 --> 00:00:12,000
7
+ In today's world, especially in the United States, we have tons of laws that we have to follow, whether
8
+
9
+ 3
10
+ 00:00:12,000 --> 00:00:18,000
11
+ it's collecting medical information and having to follow HIPAA compliance, collecting credit card information,
12
+
13
+ 4
14
+ 00:00:18,000 --> 00:00:22,000
15
+ and following things such as PCI standards now.
16
+
17
+ 5
18
+ 00:00:23,000 --> 00:00:26,000
19
+ What happens is this is known as regulated data.
20
+
21
+ 6
22
+ 00:00:26,000 --> 00:00:32,000
23
+ This includes data that's subject to all kinds of regulatory requirements, different kind of laws and
24
+
25
+ 7
26
+ 00:00:32,000 --> 00:00:34,000
27
+ regulations, personal data.
28
+
29
+ 8
30
+ 00:00:34,000 --> 00:00:41,000
31
+ So if you work in places, if you collect personal data and your organization does business or is located
32
+
33
+ 9
34
+ 00:00:41,000 --> 00:00:43,000
35
+ in Europe, you'll have to follow GDPR.
36
+
37
+ 10
38
+ 00:00:44,000 --> 00:00:45,000
39
+ Uh, in the United States.
40
+
41
+ 11
42
+ 00:00:45,000 --> 00:00:51,000
43
+ Here we have things like HIPAA compliance where health health information and then financial data,
44
+
45
+ 12
46
+ 00:00:52,000 --> 00:00:55,000
47
+ uh, for PCI compliance is going to be like credit card information.
48
+
49
+ 13
50
+ 00:00:55,000 --> 00:01:01,000
51
+ Now, all of these laws here, uh, that are covered, we're going to be covering some of these laws
52
+
53
+ 14
54
+ 00:01:01,000 --> 00:01:03,000
55
+ a little bit later in this course.
56
+
57
+ 15
58
+ 00:01:03,000 --> 00:01:04,000
59
+ So hold on to that.
60
+
61
+ 16
62
+ 00:01:04,000 --> 00:01:09,000
63
+ But for now we want to talk about how just that data is regulated.
64
+
65
+ 17
66
+ 00:01:09,000 --> 00:01:14,000
67
+ Don't think that by collecting people's information, especially people's name, address, social security
68
+
69
+ 18
70
+ 00:01:14,000 --> 00:01:20,000
71
+ number, health care information, like diseases, they may have, medications, they may be taken credit
72
+
73
+ 19
74
+ 00:01:20,000 --> 00:01:21,000
75
+ card information.
76
+
77
+ 20
78
+ 00:01:21,000 --> 00:01:24,000
79
+ This is all data that's going to be regulated.
80
+
81
+ 21
82
+ 00:01:24,000 --> 00:01:32,000
83
+ In fact things that GDPR, the general data protection, this uh, things like GDPR, this is a this
84
+
85
+ 22
86
+ 00:01:32,000 --> 00:01:36,000
87
+ is a this is basically a law that protects Europeans.
88
+
89
+ 23
90
+ 00:01:36,000 --> 00:01:36,000
91
+ Okay.
92
+
93
+ 24
94
+ 00:01:36,000 --> 00:01:38,000
95
+ Or the European Union citizens data.
96
+
97
+ 25
98
+ 00:01:38,000 --> 00:01:41,000
99
+ Things like browsing information is what this collects.
100
+
101
+ 26
102
+ 00:01:41,000 --> 00:01:48,000
103
+ So when you start collecting data on your users, you have to keep in mind that a lot of the data will
104
+
105
+ 27
106
+ 00:01:48,000 --> 00:01:54,000
107
+ be subject to certain laws and regulations within the country that you're collecting that data from.
108
+
109
+ 28
110
+ 00:01:54,000 --> 00:01:59,000
111
+ Compliance with these legal and regulatory standards are critical.
112
+
113
+ 29
114
+ 00:01:59,000 --> 00:02:05,000
115
+ First of all, it will be against the law if you don't, and it's probably going to be mandatory.
116
+
117
+ 30
118
+ 00:02:05,000 --> 00:02:12,000
119
+ This involves good security measurements, access control, and of course ensuring the privacy or confidentiality
120
+
121
+ 31
122
+ 00:02:12,000 --> 00:02:15,000
123
+ and integrity of the data.
124
+
125
+ 32
126
+ 00:02:15,000 --> 00:02:22,000
127
+ So don't think that you can just set up a business or don't think most companies can just go and set
128
+
129
+ 33
130
+ 00:02:22,000 --> 00:02:28,000
131
+ up businesses, start collecting information and not worry about the laws that they should be following.
132
+
133
+ 34
134
+ 00:02:28,000 --> 00:02:35,000
135
+ So make sure as a security professional, you are aware of what local laws within your country that
136
+
137
+ 35
138
+ 00:02:35,000 --> 00:02:38,000
139
+ you should be following when it comes to data compliance.
140
+
141
+ 36
142
+ 00:02:38,000 --> 00:02:43,000
143
+ And also if you're collecting data from overseas or you're doing business overseas from your country,
144
+
145
+ 37
146
+ 00:02:43,000 --> 00:02:46,000
147
+ what laws you should be following there also.
148
+
12 - Data Protection/002 Intellectual Property OB 3.3_en.srt ADDED
@@ -0,0 +1,696 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ 1
2
+ 00:00:00,000 --> 00:00:08,000
3
+ People and organizations in today's world create specific things such as invention, expression, such
4
+
5
+ 2
6
+ 00:00:08,000 --> 00:00:12,000
7
+ as art, or expressions like write in a book.
8
+
9
+ 3
10
+ 00:00:12,000 --> 00:00:16,000
11
+ These things that they create is valuable to them and is worth money to them.
12
+
13
+ 4
14
+ 00:00:17,000 --> 00:00:23,000
15
+ In fact, I am an author and I wrote one of the world's best selling project management book, the PMP
16
+
17
+ 5
18
+ 00:00:23,000 --> 00:00:25,000
19
+ Exam Prep Simplified.
20
+
21
+ 6
22
+ 00:00:25,000 --> 00:00:29,000
23
+ Now, this particular book is an expression of me.
24
+
25
+ 7
26
+ 00:00:29,000 --> 00:00:31,000
27
+ This particular book does bring me in an income.
28
+
29
+ 8
30
+ 00:00:31,000 --> 00:00:36,000
31
+ And for anybody to steal my particular work would result in damages to me.
32
+
33
+ 9
34
+ 00:00:36,000 --> 00:00:41,000
35
+ You see, organizations also have this problem, especially with people that create inventions.
36
+
37
+ 10
38
+ 00:00:41,000 --> 00:00:45,000
39
+ If you make a unique invention that only you.
40
+
41
+ 11
42
+ 00:00:46,000 --> 00:00:48,000
43
+ Uh, should be using in order to profit from that invention.
44
+
45
+ 12
46
+ 00:00:48,000 --> 00:00:50,000
47
+ Because that is your idea.
48
+
49
+ 13
50
+ 00:00:50,000 --> 00:00:52,000
51
+ You need to protect your invention.
52
+
53
+ 14
54
+ 00:00:52,000 --> 00:00:54,000
55
+ I need to protect my expression.
56
+
57
+ 15
58
+ 00:00:54,000 --> 00:00:57,000
59
+ You see, this is called intellectual property.
60
+
61
+ 16
62
+ 00:00:58,000 --> 00:00:59,000
63
+ This is the creation.
64
+
65
+ 17
66
+ 00:00:59,000 --> 00:01:01,000
67
+ This is creations of the mind.
68
+
69
+ 18
70
+ 00:01:01,000 --> 00:01:09,000
71
+ Like inventions, literacy work, artistic work, design symbols and names that is used in commerce.
72
+
73
+ 19
74
+ 00:01:09,000 --> 00:01:16,000
75
+ Now, in this video, I want to go through the different ways we can that we can use to protect our
76
+
77
+ 20
78
+ 00:01:16,000 --> 00:01:17,000
79
+ intellectual property.
80
+
81
+ 21
82
+ 00:01:17,000 --> 00:01:17,000
83
+ Our.
84
+
85
+ 22
86
+ 00:01:17,000 --> 00:01:21,000
87
+ The organization thinks that copyrights and patents and trademarks.
88
+
89
+ 23
90
+ 00:01:21,000 --> 00:01:23,000
91
+ That's what we're cover in this video.
92
+
93
+ 24
94
+ 00:01:23,000 --> 00:01:29,000
95
+ IP theft can result in significant economic loss and competitive disadvantage.
96
+
97
+ 25
98
+ 00:01:29,000 --> 00:01:34,000
99
+ Now, if this is something that I have personal experience with because I have personally experienced
100
+
101
+ 26
102
+ 00:01:34,000 --> 00:01:41,000
103
+ this, my study guide or my book was published on Amazon, and Amazon has exclusive rights as the only
104
+
105
+ 27
106
+ 00:01:41,000 --> 00:01:43,000
107
+ distributor of the book.
108
+
109
+ 28
110
+ 00:01:44,000 --> 00:01:46,000
111
+ After a couple of years and it was doing well.
112
+
113
+ 29
114
+ 00:01:46,000 --> 00:01:50,000
115
+ All of a sudden we started having a seller that started to sell my book.
116
+
117
+ 30
118
+ 00:01:50,000 --> 00:01:51,000
119
+ They were buying.
120
+
121
+ 31
122
+ 00:01:51,000 --> 00:01:55,000
123
+ They were printing the book themselves and selling it on Amazon.
124
+
125
+ 32
126
+ 00:01:55,000 --> 00:01:59,000
127
+ They were priced at Amazon, so people were buying their book and we didn't realize it for a while.
128
+
129
+ 33
130
+ 00:01:59,000 --> 00:02:03,000
131
+ So we actually lost a significant amount of money due to IP theft.
132
+
133
+ 34
134
+ 00:02:03,000 --> 00:02:05,000
135
+ This book is copyrighted.
136
+
137
+ 35
138
+ 00:02:05,000 --> 00:02:11,000
139
+ Protection includes rights management, strict access control, even watermarking to trace and identify
140
+
141
+ 36
142
+ 00:02:11,000 --> 00:02:13,000
143
+ unauthorized copies.
144
+
145
+ 37
146
+ 00:02:13,000 --> 00:02:15,000
147
+ Now, the book does have a unique mark that we know.
148
+
149
+ 38
150
+ 00:02:15,000 --> 00:02:17,000
151
+ If you copy it, we'll know.
152
+
153
+ 39
154
+ 00:02:17,000 --> 00:02:22,000
155
+ So how does organizations protect their intellectual property?
156
+
157
+ 40
158
+ 00:02:22,000 --> 00:02:27,000
159
+ Well, let's go through some of the most common ways that you're going to need to know for your exam.
160
+
161
+ 41
162
+ 00:02:27,000 --> 00:02:30,000
163
+ The first one here I have is copyrights.
164
+
165
+ 42
166
+ 00:02:30,000 --> 00:02:37,000
167
+ So copyrights are laws that protects against unauthorized duplication of an original creative work.
168
+
169
+ 43
170
+ 00:02:37,000 --> 00:02:41,000
171
+ Now when people think of okay, what can I copyright?
172
+
173
+ 44
174
+ 00:02:41,000 --> 00:02:49,000
175
+ Well, these are some of the things here that you can copyright, literacy work, musical work, uh,
176
+
177
+ 45
178
+ 00:02:49,000 --> 00:02:56,000
179
+ all kinds of pictorial work like pictures, motion pictures, sound recordings, architectural work,
180
+
181
+ 46
182
+ 00:02:56,000 --> 00:02:59,000
183
+ all of these are copyrightable.
184
+
185
+ 47
186
+ 00:02:59,000 --> 00:03:03,000
187
+ Now I want to before I get into this, I want to make something clear.
188
+
189
+ 48
190
+ 00:03:03,000 --> 00:03:09,000
191
+ The moment work is created, it is copyrighted.
192
+
193
+ 49
194
+ 00:03:10,000 --> 00:03:11,000
195
+ There's two kinds of copyrights.
196
+
197
+ 50
198
+ 00:03:11,000 --> 00:03:13,000
199
+ In the United States.
200
+
201
+ 51
202
+ 00:03:13,000 --> 00:03:17,000
203
+ There is a regular copyright, and then there's a registered copyright.
204
+
205
+ 52
206
+ 00:03:18,000 --> 00:03:25,000
207
+ The moment you have an idea of an expression of some kind and you draw it on a piece of paper, or you
208
+
209
+ 53
210
+ 00:03:25,000 --> 00:03:29,000
211
+ write it down on a piece of paper, it is automatically copyrighted.
212
+
213
+ 54
214
+ 00:03:29,000 --> 00:03:32,000
215
+ You do not need to register it.
216
+
217
+ 55
218
+ 00:03:33,000 --> 00:03:40,000
219
+ Now, if you feel that this work will be public, will be on the public shelves, such as a book on
220
+
221
+ 56
222
+ 00:03:40,000 --> 00:03:45,000
223
+ Amazon, or you're going to be selling this picture online, or it's going to be like a motion picture
224
+
225
+ 57
226
+ 00:03:45,000 --> 00:03:49,000
227
+ where everybody's going to be seeing it, or it's going to be some kind of play or something like that,
228
+
229
+ 58
230
+ 00:03:50,000 --> 00:03:52,000
231
+ then it's best to get it registered.
232
+
233
+ 59
234
+ 00:03:52,000 --> 00:03:58,000
235
+ A registered copyright is when you go to your copyright office, like we do here in the United States,
236
+
237
+ 60
238
+ 00:03:58,000 --> 00:04:01,000
239
+ and we submit the work to the Copyright Office.
240
+
241
+ 61
242
+ 00:04:01,000 --> 00:04:02,000
243
+ And we claim that that is our work.
244
+
245
+ 62
246
+ 00:04:02,000 --> 00:04:09,000
247
+ The Copyright Office then puts a stamp on it that says, as of this day, Bob says this is his work.
248
+
249
+ 63
250
+ 00:04:09,000 --> 00:04:14,000
251
+ They actually don't check to see if anybody else owns it, but they're just saying that that it is there.
252
+
253
+ 64
254
+ 00:04:15,000 --> 00:04:16,000
255
+ Now, why do we want to register?
256
+
257
+ 65
258
+ 00:04:16,000 --> 00:04:18,000
259
+ What's the benefit of registration?
260
+
261
+ 66
262
+ 00:04:18,000 --> 00:04:23,000
263
+ When you register a copyright, it's the only time you can actually bring lawsuits against people.
264
+
265
+ 67
266
+ 00:04:23,000 --> 00:04:24,000
267
+ So if anybody.
268
+
269
+ 68
270
+ 00:04:24,000 --> 00:04:30,000
271
+ So let's say you wrote something down on a copyright and somebody else stole your idea and you're sure
272
+
273
+ 69
274
+ 00:04:30,000 --> 00:04:32,000
275
+ of it, you can't sue them yet.
276
+
277
+ 70
278
+ 00:04:32,000 --> 00:04:33,000
279
+ You have to go and register it.
280
+
281
+ 71
282
+ 00:04:33,000 --> 00:04:34,000
283
+ Then you can sue them.
284
+
285
+ 72
286
+ 00:04:34,000 --> 00:04:35,000
287
+ So it's best to do it right away.
288
+
289
+ 73
290
+ 00:04:36,000 --> 00:04:42,000
291
+ Uh, also, you're entitled to all kinds of different damages in case somebody steals your copyright.
292
+
293
+ 74
294
+ 00:04:42,000 --> 00:04:43,000
295
+ This is not a law course.
296
+
297
+ 75
298
+ 00:04:43,000 --> 00:04:48,000
299
+ I'm not going to get into the specifics, but if you do have work that are made, publish, go and register
300
+
301
+ 76
302
+ 00:04:48,000 --> 00:04:48,000
303
+ it.
304
+
305
+ 77
306
+ 00:04:48,000 --> 00:04:49,000
307
+ Registry.
308
+
309
+ 78
310
+ 00:04:50,000 --> 00:04:51,000
311
+ Registering a copyright.
312
+
313
+ 79
314
+ 00:04:51,000 --> 00:04:53,000
315
+ It's actually something that is very easy.
316
+
317
+ 80
318
+ 00:04:53,000 --> 00:04:54,000
319
+ I did it myself online.
320
+
321
+ 81
322
+ 00:04:54,000 --> 00:04:55,000
323
+ It takes about ten minutes.
324
+
325
+ 82
326
+ 00:04:55,000 --> 00:04:57,000
327
+ Do not pay companies to do it.
328
+
329
+ 83
330
+ 00:04:57,000 --> 00:05:01,000
331
+ And I think I paid about $40 to register the book, so keep that in mind.
332
+
333
+ 84
334
+ 00:05:01,000 --> 00:05:03,000
335
+ It's not difficult.
336
+
337
+ 85
338
+ 00:05:03,000 --> 00:05:05,000
339
+ Now remember remember what I'm talking about.
340
+
341
+ 86
342
+ 00:05:05,000 --> 00:05:09,000
343
+ Copyrights does not have to be registered to have the protection.
344
+
345
+ 87
346
+ 00:05:09,000 --> 00:05:12,000
347
+ The protection we're talking about is right here.
348
+
349
+ 88
350
+ 00:05:12,000 --> 00:05:16,000
351
+ So remember a copyright is an expression of idea or resources.
352
+
353
+ 89
354
+ 00:05:16,000 --> 00:05:22,000
355
+ Authors can control how whoever owns the copyright controls how the work is distributed, reproduced
356
+
357
+ 90
358
+ 00:05:22,000 --> 00:05:23,000
359
+ and used now.
360
+
361
+ 91
362
+ 00:05:24,000 --> 00:05:28,000
363
+ Copyrights are valid for very long periods of time.
364
+
365
+ 92
366
+ 00:05:28,000 --> 00:05:36,000
367
+ It's valid generally for 70 years after the death of the last remaining author, unless it's work for
368
+
369
+ 93
370
+ 00:05:36,000 --> 00:05:36,000
371
+ hire.
372
+
373
+ 94
374
+ 00:05:36,000 --> 00:05:44,000
375
+ So work for hire is this work for hire is when somebody hires you to create work for an organization.
376
+
377
+ 95
378
+ 00:05:44,000 --> 00:05:48,000
379
+ So if you go to a company and you wrote procedures and policies, that's called work for hire, work
380
+
381
+ 96
382
+ 00:05:48,000 --> 00:05:49,000
383
+ for hire.
384
+
385
+ 97
386
+ 00:05:49,000 --> 00:05:56,000
387
+ An anonymous works are protected for 95 years from the date of the first publication of 120 days from
388
+
389
+ 98
390
+ 00:05:56,000 --> 00:05:58,000
391
+ the date of creation, which one ever is shortest?
392
+
393
+ 99
394
+ 00:05:58,000 --> 00:06:03,000
395
+ If it was published dated, it's 95 years or it's 120 years.
396
+
397
+ 100
398
+ 00:06:04,000 --> 00:06:09,000
399
+ So let's say you're a bad person and you want to steal my book, right?
400
+
401
+ 101
402
+ 00:06:09,000 --> 00:06:10,000
403
+ My PMP study guide.
404
+
405
+ 102
406
+ 00:06:10,000 --> 00:06:17,000
407
+ Well, if you want to steal it well or use it, I'm going to sue you because I have the legal copyright.
408
+
409
+ 103
410
+ 00:06:17,000 --> 00:06:22,000
411
+ But if you want to wait for the copyright to expire to republish the work, you have to wait.
412
+
413
+ 104
414
+ 00:06:22,000 --> 00:06:26,000
415
+ You have to wait for me to die and then you have to wait 70 years.
416
+
417
+ 105
418
+ 00:06:27,000 --> 00:06:31,000
419
+ Penalties can penalties is going to be up to $1.1 million in damages.
420
+
421
+ 106
422
+ 00:06:31,000 --> 00:06:31,000
423
+ Now.
424
+
425
+ 107
426
+ 00:06:31,000 --> 00:06:34,000
427
+ This number can change depending on when you're watching this video.
428
+
429
+ 108
430
+ 00:06:34,000 --> 00:06:36,000
431
+ Ten years in prison now.
432
+
433
+ 109
434
+ 00:06:37,000 --> 00:06:41,000
435
+ This is copyright and these are things that are copyrightable that I have here.
436
+
437
+ 110
438
+ 00:06:41,000 --> 00:06:47,000
439
+ Now, the other thing here that we can use to protect our IP is going to be trademarks.
440
+
441
+ 111
442
+ 00:06:47,000 --> 00:06:55,000
443
+ Trademarks protect words, names, symbols, sounds, shapes, colors, musical tones or a combination.
444
+
445
+ 112
446
+ 00:06:56,000 --> 00:07:01,000
447
+ Uh, they protect someone from stealing another person's quote unquote look and feel.
448
+
449
+ 113
450
+ 00:07:01,000 --> 00:07:04,000
451
+ The primary purpose is to avoid confusion in the marketplace.
452
+
453
+ 114
454
+ 00:07:04,000 --> 00:07:06,000
455
+ This protects intellectual property.
456
+
457
+ 115
458
+ 00:07:06,000 --> 00:07:12,000
459
+ The good thing with trademarks is that they're valid, unlike a copyright, which generally, when I
460
+
461
+ 116
462
+ 00:07:12,000 --> 00:07:16,000
463
+ die, it's 70 years technically trademarks, you can keep renewing it over and over.
464
+
465
+ 117
466
+ 00:07:16,000 --> 00:07:18,000
467
+ They're valid for ten years with unlimited renewal.
468
+
469
+ 118
470
+ 00:07:19,000 --> 00:07:19,000
471
+ Um.
472
+
473
+ 119
474
+ 00:07:20,000 --> 00:07:22,000
475
+ On unlimited.
476
+
477
+ 120
478
+ 00:07:22,000 --> 00:07:27,000
479
+ You can renew an unlimited number of times, so you can keep renewing that over and over and over.
480
+
481
+ 121
482
+ 00:07:27,000 --> 00:07:29,000
483
+ Now, what are things that are going to be trademarked?
484
+
485
+ 122
486
+ 00:07:29,000 --> 00:07:32,000
487
+ Lots of things that are trademark are generally things like symbols.
488
+
489
+ 123
490
+ 00:07:32,000 --> 00:07:37,000
491
+ The Technical Institute of America, if you look at our name and symbols, those are all trademarks.
492
+
493
+ 124
494
+ 00:07:37,000 --> 00:07:41,000
495
+ We own the trademark to the Technical Institute of America.
496
+
497
+ 125
498
+ 00:07:41,000 --> 00:07:44,000
499
+ The the the actual company's name.
500
+
501
+ 126
502
+ 00:07:44,000 --> 00:07:48,000
503
+ The Technical Institute of America is a trademark name.
504
+
505
+ 127
506
+ 00:07:48,000 --> 00:07:52,000
507
+ The symbol of itself, the shield that we use is also trademarked.
508
+
509
+ 128
510
+ 00:07:52,000 --> 00:07:56,000
511
+ This helps to ensure that we protect our brand.
512
+
513
+ 129
514
+ 00:07:56,000 --> 00:08:01,000
515
+ Many, many companies are trademarking their content, their brands, their logo.
516
+
517
+ 130
518
+ 00:08:01,000 --> 00:08:04,000
519
+ How do you know when you see a particular logo?
520
+
521
+ 131
522
+ 00:08:04,000 --> 00:08:07,000
523
+ You might see a little circle that says TM on it.
524
+
525
+ 132
526
+ 00:08:07,000 --> 00:08:10,000
527
+ If you see a little circle with a C with a circle, that's a copyright.
528
+
529
+ 133
530
+ 00:08:11,000 --> 00:08:13,000
531
+ Now the other one here you have is patents.
532
+
533
+ 134
534
+ 00:08:13,000 --> 00:08:15,000
535
+ If you have an invention.
536
+
537
+ 135
538
+ 00:08:16,000 --> 00:08:21,000
539
+ Unique invention that you have invented to help the world progress.
540
+
541
+ 136
542
+ 00:08:21,000 --> 00:08:25,000
543
+ You're going to get exclusive use of your invention if you patent your invention.
544
+
545
+ 137
546
+ 00:08:25,000 --> 00:08:31,000
547
+ So patent protects the right of inventors and their inventions, protection of those who have legal
548
+
549
+ 138
550
+ 00:08:31,000 --> 00:08:32,000
551
+ ownership of the patent.
552
+
553
+ 139
554
+ 00:08:33,000 --> 00:08:37,000
555
+ The invention, must be new, must be useful, and must not be obvious.
556
+
557
+ 140
558
+ 00:08:37,000 --> 00:08:42,000
559
+ The owner has exclusive control of the invention for 20 years.
560
+
561
+ 141
562
+ 00:08:42,000 --> 00:08:47,000
563
+ After that it goes to the public domain and anyone can produce your work.
564
+
565
+ 142
566
+ 00:08:47,000 --> 00:08:52,000
567
+ This is why when organizations like drug companies first make a drug that they've spent billions of
568
+
569
+ 143
570
+ 00:08:52,000 --> 00:08:58,000
571
+ dollars producing, they have about 20 years because they have patent that formula for that drug to
572
+
573
+ 144
574
+ 00:08:58,000 --> 00:09:02,000
575
+ sell it as much as they want so they can recuperate their costs.
576
+
577
+ 145
578
+ 00:09:02,000 --> 00:09:06,000
579
+ And after that it becomes a generic medication, and then anyone can take the formula.
580
+
581
+ 146
582
+ 00:09:08,000 --> 00:09:16,000
583
+ Another thing that you want to protect is the secret recipe to the McDonald's Big Mac sauce, or the
584
+
585
+ 147
586
+ 00:09:16,000 --> 00:09:20,000
587
+ secret recipe to KFC's fried chicken.
588
+
589
+ 148
590
+ 00:09:21,000 --> 00:09:22,000
591
+ It's coming up to lunch time.
592
+
593
+ 149
594
+ 00:09:22,000 --> 00:09:26,000
595
+ It's actually around 11:00 in the morning, so I'm thinking about I could use a Big Mac right now.
596
+
597
+ 150
598
+ 00:09:27,000 --> 00:09:36,000
599
+ Organizations have top secret information that they use in order for the survivability of that company.
600
+
601
+ 151
602
+ 00:09:36,000 --> 00:09:38,000
603
+ These are called trade secrets.
604
+
605
+ 152
606
+ 00:09:38,000 --> 00:09:45,000
607
+ It's any form of information, device, method, process, or formula such as that Big Mac sauce that,
608
+
609
+ 153
610
+ 00:09:45,000 --> 00:09:49,000
611
+ if disclosed, will cause significant damage to the organization.
612
+
613
+ 154
614
+ 00:09:50,000 --> 00:09:53,000
615
+ Now resources generally is going to provide.
616
+
617
+ 155
618
+ 00:09:53,000 --> 00:09:59,000
619
+ Must be of competitive value, must be protected from unauthorized use, is proprietary to the company
620
+
621
+ 156
622
+ 00:09:59,000 --> 00:10:01,000
623
+ essential for them to survive.
624
+
625
+ 157
626
+ 00:10:01,000 --> 00:10:11,000
627
+ Now there is really nothing to register like we do with copyrights or patents or, uh, or trademarks.
628
+
629
+ 158
630
+ 00:10:11,000 --> 00:10:13,000
631
+ Trade secrets just has to be protected.
632
+
633
+ 159
634
+ 00:10:14,000 --> 00:10:18,000
635
+ There is a law in the United States you don't need to know this one for your exam.
636
+
637
+ 160
638
+ 00:10:18,000 --> 00:10:19,000
639
+ I just put it there.
640
+
641
+ 161
642
+ 00:10:19,000 --> 00:10:25,000
643
+ For your knowledge, the Espionage Act of 1996 is a law that specifies that if anyone ever steals a
644
+
645
+ 162
646
+ 00:10:25,000 --> 00:10:31,000
647
+ trade secrets and discloses that they can be fined, as you can see here, potential jail time.
648
+
649
+ 163
650
+ 00:10:32,000 --> 00:10:38,000
651
+ So the way to protect trade secrets as a security professional is just do your normal security things,
652
+
653
+ 164
654
+ 00:10:38,000 --> 00:10:45,000
655
+ encrypt it, put good windows permission or file permission like access control firewalls, IDs systems
656
+
657
+ 165
658
+ 00:10:45,000 --> 00:10:49,000
659
+ may be used potential air gapped systems to store this kind of information.
660
+
661
+ 166
662
+ 00:10:49,000 --> 00:10:53,000
663
+ Whoever gets the information should be signing a non-disclosure agreement.
664
+
665
+ 167
666
+ 00:10:53,000 --> 00:10:56,000
667
+ This prohibits them from sharing this information.
668
+
669
+ 168
670
+ 00:10:56,000 --> 00:11:04,000
671
+ And if they do share it, they could, uh, be subject to potential fines or the company can sue them
672
+
673
+ 169
674
+ 00:11:04,000 --> 00:11:05,000
675
+ for the loss of income and so on.
676
+
677
+ 170
678
+ 00:11:07,000 --> 00:11:07,000
679
+ Okay.
680
+
681
+ 171
682
+ 00:11:07,000 --> 00:11:11,000
683
+ These are some ways that we're going to protect our intellectual property.
684
+
685
+ 172
686
+ 00:11:11,000 --> 00:11:16,000
687
+ Keep in mind, intellectual property is how lots of organizations survives in today's day and time.
688
+
689
+ 173
690
+ 00:11:16,000 --> 00:11:21,000
691
+ And a lot of these IPS is essential for the survival of the business.
692
+
693
+ 174
694
+ 00:11:21,000 --> 00:11:25,000
695
+ So as an IT professional, make sure you protect them.
696
+
12 - Data Protection/003 Legal and Financial Data OB 3.3_en.srt ADDED
@@ -0,0 +1,276 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ 1
2
+ 00:00:00,000 --> 00:00:05,000
3
+ As you collect information, you're going to be collecting different kinds of information in particularly,
4
+
5
+ 2
6
+ 00:00:05,000 --> 00:00:11,000
7
+ some of the data that we collect on a network may be considered, uh, legal information.
8
+
9
+ 3
10
+ 00:00:11,000 --> 00:00:14,000
11
+ While some of the information we collect may be financial information.
12
+
13
+ 4
14
+ 00:00:14,000 --> 00:00:20,000
15
+ And then some of this information we collect is easily readable by us.
16
+
17
+ 5
18
+ 00:00:20,000 --> 00:00:24,000
19
+ And versus some of it is not and can only be read by a computer.
20
+
21
+ 6
22
+ 00:00:24,000 --> 00:00:26,000
23
+ So let's talk about the first one I have here.
24
+
25
+ 7
26
+ 00:00:26,000 --> 00:00:28,000
27
+ Legal information.
28
+
29
+ 8
30
+ 00:00:28,000 --> 00:00:35,000
31
+ A lot of times some of the data that we collect on clients, or that we create ourselves internally
32
+
33
+ 9
34
+ 00:00:35,000 --> 00:00:39,000
35
+ could fall into the to to the realm of legal information.
36
+
37
+ 10
38
+ 00:00:39,000 --> 00:00:44,000
39
+ Legal information are things that deals with legal matters, including case files, legal advice and
40
+
41
+ 11
42
+ 00:00:44,000 --> 00:00:46,000
43
+ other sensitive legal documents.
44
+
45
+ 12
46
+ 00:00:47,000 --> 00:00:52,000
47
+ A breach of these type, a breach of this kind of information, or the release of this kind of information,
48
+
49
+ 13
50
+ 00:00:52,000 --> 00:00:57,000
51
+ especially if the company is in some kind of a lawsuit, could result in attorney client privileges
52
+
53
+ 14
54
+ 00:00:57,000 --> 00:00:59,000
55
+ being compromised.
56
+
57
+ 15
58
+ 00:00:59,000 --> 00:01:00,000
59
+ Uh, case integrity.
60
+
61
+ 16
62
+ 00:01:00,000 --> 00:01:04,000
63
+ So ensuring the confidentiality encryption of this kind of information is critical.
64
+
65
+ 17
66
+ 00:01:04,000 --> 00:01:05,000
67
+ Let me give you an example.
68
+
69
+ 18
70
+ 00:01:06,000 --> 00:01:13,000
71
+ Let's say the organization, uh, has gotten sued by another company because that company is claiming
72
+
73
+ 19
74
+ 00:01:13,000 --> 00:01:16,000
75
+ that it stole its IP topic.
76
+
77
+ 20
78
+ 00:01:16,000 --> 00:01:19,000
79
+ We just covered it, stole its design.
80
+
81
+ 21
82
+ 00:01:19,000 --> 00:01:26,000
83
+ But your organization has proof that it didn't stole the design, and it actually created the actual
84
+
85
+ 22
86
+ 00:01:26,000 --> 00:01:28,000
87
+ product itself from scratch.
88
+
89
+ 23
90
+ 00:01:28,000 --> 00:01:36,000
91
+ The documents that proves that we created the design ourselves now falls into a legal into a legal case,
92
+
93
+ 24
94
+ 00:01:36,000 --> 00:01:39,000
95
+ or now it becomes legal information.
96
+
97
+ 25
98
+ 00:01:39,000 --> 00:01:42,000
99
+ This means that it's going to have to be presented in a court of law.
100
+
101
+ 26
102
+ 00:01:42,000 --> 00:01:47,000
103
+ As an IT professional, you're going to have to make sure that you protect the integrity, make sure
104
+
105
+ 27
106
+ 00:01:47,000 --> 00:01:52,000
107
+ that it never gets modified, because you're going to use this as proof in the case you have to encrypt
108
+
109
+ 28
110
+ 00:01:52,000 --> 00:01:57,000
111
+ it so it doesn't get leaked out, or the other sides don't get to see it because they have an assumption
112
+
113
+ 29
114
+ 00:01:57,000 --> 00:01:58,000
115
+ that may not be true.
116
+
117
+ 30
118
+ 00:01:58,000 --> 00:02:01,000
119
+ Another thing is financial information.
120
+
121
+ 31
122
+ 00:02:01,000 --> 00:02:07,000
123
+ It is super easy to get in trouble with the law nowadays, because you're collecting financial information
124
+
125
+ 32
126
+ 00:02:07,000 --> 00:02:09,000
127
+ and may not even be realized in it.
128
+
129
+ 33
130
+ 00:02:09,000 --> 00:02:11,000
131
+ How important it is.
132
+
133
+ 34
134
+ 00:02:12,000 --> 00:02:17,000
135
+ This is going to be things, transactions, financial records, credit card information, and other
136
+
137
+ 35
138
+ 00:02:17,000 --> 00:02:19,000
139
+ monetary data that you're collecting from your customers.
140
+
141
+ 36
142
+ 00:02:19,000 --> 00:02:25,000
143
+ Right now, most organizations that sells products online will collect some kind of payment information.
144
+
145
+ 37
146
+ 00:02:26,000 --> 00:02:30,000
147
+ Now, financial data is always going to be the target for these.
148
+
149
+ 38
150
+ 00:02:30,000 --> 00:02:35,000
151
+ I don't want to say always, 90% of the time is going to be the target for these hackers that comes
152
+
153
+ 39
154
+ 00:02:35,000 --> 00:02:37,000
155
+ in, breaks into your company.
156
+
157
+ 40
158
+ 00:02:37,000 --> 00:02:40,000
159
+ What they're looking for are those credit card information.
160
+
161
+ 41
162
+ 00:02:40,000 --> 00:02:45,000
163
+ We're going to have to do things like encrypted, encrypt the processing and make sure that if there
164
+
165
+ 42
166
+ 00:02:45,000 --> 00:02:50,000
167
+ is standards like PCI compliance, PCI means payment card industry.
168
+
169
+ 43
170
+ 00:02:52,000 --> 00:02:54,000
171
+ DSS data security standard.
172
+
173
+ 44
174
+ 00:02:54,000 --> 00:03:01,000
175
+ It's basically a standard that organizations have to follow to secure credit card information or financial
176
+
177
+ 45
178
+ 00:03:01,000 --> 00:03:02,000
179
+ information.
180
+
181
+ 46
182
+ 00:03:02,000 --> 00:03:06,000
183
+ Now, the other thing here that we're going to be talking about is what's called readable data.
184
+
185
+ 47
186
+ 00:03:06,000 --> 00:03:08,000
187
+ Readable data falls into two kinds.
188
+
189
+ 48
190
+ 00:03:08,000 --> 00:03:14,000
191
+ Human readable, US readable and non-human readable things that we can interpret and see on a network,
192
+
193
+ 49
194
+ 00:03:14,000 --> 00:03:18,000
195
+ such as text, documents, images, printable information.
196
+
197
+ 50
198
+ 00:03:18,000 --> 00:03:24,000
199
+ And then non readable is going to be non human readable things that only the computer can read.
200
+
201
+ 51
202
+ 00:03:24,000 --> 00:03:27,000
203
+ Think of things like machine code.
204
+
205
+ 52
206
+ 00:03:27,000 --> 00:03:30,000
207
+ No one can read machine code ones and zeros.
208
+
209
+ 53
210
+ 00:03:30,000 --> 00:03:34,000
211
+ Certain kind of log files, encrypted data that only computers can decrypt.
212
+
213
+ 54
214
+ 00:03:35,000 --> 00:03:38,000
215
+ Both of these will require protection.
216
+
217
+ 55
218
+ 00:03:38,000 --> 00:03:39,000
219
+ Okay.
220
+
221
+ 56
222
+ 00:03:39,000 --> 00:03:41,000
223
+ Both of these will require protection.
224
+
225
+ 57
226
+ 00:03:41,000 --> 00:03:45,000
227
+ That only that only that organization or whoever needs to see it.
228
+
229
+ 58
230
+ 00:03:45,000 --> 00:03:53,000
231
+ This is going to be things such as encryption, firewalls, intrusion detection systems, access controls
232
+
233
+ 59
234
+ 00:03:53,000 --> 00:03:54,000
235
+ and so on.
236
+
237
+ 60
238
+ 00:03:54,000 --> 00:03:57,000
239
+ All the protection mechanisms that we have spoken about.
240
+
241
+ 61
242
+ 00:03:57,000 --> 00:04:02,000
243
+ So human readable is, is very likely to get stolen.
244
+
245
+ 62
246
+ 00:04:02,000 --> 00:04:06,000
247
+ Because that's what if they break into the company, that's what they're going to be coming after.
248
+
249
+ 63
250
+ 00:04:06,000 --> 00:04:13,000
251
+ Cybercriminals could be attacking non human readable for decryption or misuse of that data.
252
+
253
+ 64
254
+ 00:04:14,000 --> 00:04:16,000
255
+ Data protection is super important.
256
+
257
+ 65
258
+ 00:04:16,000 --> 00:04:18,000
259
+ If the company is in some kind of a lawsuit.
260
+
261
+ 66
262
+ 00:04:18,000 --> 00:04:23,000
263
+ You've got to remember as a security person to protect that data, because that data could be the one
264
+
265
+ 67
266
+ 00:04:23,000 --> 00:04:26,000
267
+ that proves that the company did nothing wrong.
268
+
269
+ 68
270
+ 00:04:26,000 --> 00:04:29,000
271
+ And you will be collecting tons of financial information.
272
+
273
+ 69
274
+ 00:04:29,000 --> 00:04:34,000
275
+ So you want to make sure you protect both of them to keep your company secure.
276
+
12 - Data Protection/004 Data Classification OB 3.3_en.srt ADDED
@@ -0,0 +1,644 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ 1
2
+ 00:00:00,000 --> 00:00:05,000
3
+ Organizations today store a lot of information or particularly a lot of data.
4
+
5
+ 2
6
+ 00:00:05,000 --> 00:00:10,000
7
+ We have tons and tons of data, and the longer that company stays in business, the more data you're
8
+
9
+ 3
10
+ 00:00:10,000 --> 00:00:11,000
11
+ going to get.
12
+
13
+ 4
14
+ 00:00:11,000 --> 00:00:18,000
15
+ Now the question comes down to does all of that data have the same value?
16
+
17
+ 5
18
+ 00:00:18,000 --> 00:00:24,000
19
+ Do we apply the same set of controls to all of all the data?
20
+
21
+ 6
22
+ 00:00:24,000 --> 00:00:25,000
23
+ The answer is no.
24
+
25
+ 7
26
+ 00:00:25,000 --> 00:00:27,000
27
+ Different data sets have different value.
28
+
29
+ 8
30
+ 00:00:27,000 --> 00:00:31,000
31
+ For example, what's on a company's website is public information.
32
+
33
+ 9
34
+ 00:00:31,000 --> 00:00:35,000
35
+ That particular data, if it's lost, doesn't cost much harm to the business.
36
+
37
+ 10
38
+ 00:00:35,000 --> 00:00:40,000
39
+ But if the company uses a very particular manufacturing method or formula to produce a product, if
40
+
41
+ 11
42
+ 00:00:40,000 --> 00:00:45,000
43
+ that's lost, that's going to cause the company significant financial harm.
44
+
45
+ 12
46
+ 00:00:45,000 --> 00:00:49,000
47
+ We don't protect data, all the data with the same set of controls.
48
+
49
+ 13
50
+ 00:00:49,000 --> 00:00:58,000
51
+ We don't have unlimited resources to buy things like IDs systems, IPS, endpoint protection, firewall
52
+
53
+ 14
54
+ 00:00:58,000 --> 00:01:01,000
55
+ encryption, redundant systems, cloud storages, and so on and so on.
56
+
57
+ 15
58
+ 00:01:01,000 --> 00:01:04,000
59
+ All the different security controls you can think about.
60
+
61
+ 16
62
+ 00:01:04,000 --> 00:01:10,000
63
+ We don't have unlimited amount of money and people to buy, configure, setup and maintain all those
64
+
65
+ 17
66
+ 00:01:10,000 --> 00:01:11,000
67
+ controls.
68
+
69
+ 18
70
+ 00:01:11,000 --> 00:01:14,000
71
+ So what we have is we have a limited set of controls.
72
+
73
+ 19
74
+ 00:01:14,000 --> 00:01:15,000
75
+ We have a ton of data.
76
+
77
+ 20
78
+ 00:01:15,000 --> 00:01:22,000
79
+ So we have to take the limited resources and allocate it to ensure the right data gets the right protection.
80
+
81
+ 21
82
+ 00:01:22,000 --> 00:01:25,000
83
+ Or in other words, the right data gets the right control.
84
+
85
+ 22
86
+ 00:01:25,000 --> 00:01:27,000
87
+ The question is how do we determine that?
88
+
89
+ 23
90
+ 00:01:27,000 --> 00:01:29,000
91
+ How do we determine.
92
+
93
+ 24
94
+ 00:01:29,000 --> 00:01:32,000
95
+ Well, you're going to get those controls and you're going to get those controls.
96
+
97
+ 25
98
+ 00:01:32,000 --> 00:01:36,000
99
+ You're going to have a ton of controls and you're not going to have any control.
100
+
101
+ 26
102
+ 00:01:36,000 --> 00:01:39,000
103
+ The answer is data classification.
104
+
105
+ 27
106
+ 00:01:39,000 --> 00:01:42,000
107
+ And this starts this discussion on this topic.
108
+
109
+ 28
110
+ 00:01:43,000 --> 00:01:44,000
111
+ Now.
112
+
113
+ 29
114
+ 00:01:44,000 --> 00:01:48,000
115
+ Data classification affects all aspects of A of the data.
116
+
117
+ 30
118
+ 00:01:48,000 --> 00:01:50,000
119
+ When should a data.
120
+
121
+ 31
122
+ 00:01:50,000 --> 00:01:52,000
123
+ When should the data be backed up?
124
+
125
+ 32
126
+ 00:01:52,000 --> 00:01:53,000
127
+ Depends on a classification.
128
+
129
+ 33
130
+ 00:01:53,000 --> 00:01:54,000
131
+ Where should it be stored?
132
+
133
+ 34
134
+ 00:01:54,000 --> 00:01:56,000
135
+ Depends on this classification.
136
+
137
+ 35
138
+ 00:01:56,000 --> 00:02:00,000
139
+ Who should have access to it depends on its classification.
140
+
141
+ 36
142
+ 00:02:00,000 --> 00:02:02,000
143
+ How should it be processed?
144
+
145
+ 37
146
+ 00:02:02,000 --> 00:02:03,000
147
+ Depends on its classification.
148
+
149
+ 38
150
+ 00:02:03,000 --> 00:02:05,000
151
+ What type of machine should it be stored on?
152
+
153
+ 39
154
+ 00:02:05,000 --> 00:02:07,000
155
+ Depends on its classification.
156
+
157
+ 40
158
+ 00:02:07,000 --> 00:02:08,000
159
+ You get the point.
160
+
161
+ 41
162
+ 00:02:08,000 --> 00:02:12,000
163
+ Every single aspect of the data.
164
+
165
+ 42
166
+ 00:02:13,000 --> 00:02:18,000
167
+ Is going to be, or what happens to it is going to be dependent on that classification.
168
+
169
+ 43
170
+ 00:02:18,000 --> 00:02:24,000
171
+ So data classification helps in determining the level of security controls and handling protocols that
172
+
173
+ 44
174
+ 00:02:24,000 --> 00:02:26,000
175
+ should be applied to various kinds of data.
176
+
177
+ 45
178
+ 00:02:27,000 --> 00:02:34,000
179
+ Data classification helps with the creation, usage and determination and destruction of the data.
180
+
181
+ 46
182
+ 00:02:34,000 --> 00:02:39,000
183
+ For example public information information that's on your public website.
184
+
185
+ 47
186
+ 00:02:39,000 --> 00:02:44,000
187
+ When the when that server that was just storing public data, whenever you're ready to throw that server
188
+
189
+ 48
190
+ 00:02:44,000 --> 00:02:48,000
191
+ out or destroy the server, just put it in a garbage.
192
+
193
+ 49
194
+ 00:02:48,000 --> 00:02:49,000
195
+ Nothing else to do.
196
+
197
+ 50
198
+ 00:02:49,000 --> 00:02:53,000
199
+ Take out the hard drive and dump it in the bin because everything on the drive is public.
200
+
201
+ 51
202
+ 00:02:53,000 --> 00:02:59,000
203
+ But if that if that server was storing top secret data, you would want to degauss and shred the hard
204
+
205
+ 52
206
+ 00:02:59,000 --> 00:03:00,000
207
+ drive.
208
+
209
+ 53
210
+ 00:03:00,000 --> 00:03:06,000
211
+ So it has a different procedure to destroy the data depending on its classification.
212
+
213
+ 54
214
+ 00:03:07,000 --> 00:03:12,000
215
+ Now for your exam, the data owner determines the classification.
216
+
217
+ 55
218
+ 00:03:12,000 --> 00:03:15,000
219
+ You have to remember that who determines classification?
220
+
221
+ 56
222
+ 00:03:15,000 --> 00:03:17,000
223
+ The data owner does that.
224
+
225
+ 57
226
+ 00:03:17,000 --> 00:03:21,000
227
+ They will determine how critical it is, how sensitive it is.
228
+
229
+ 58
230
+ 00:03:21,000 --> 00:03:23,000
231
+ They're going to determine its value.
232
+
233
+ 59
234
+ 00:03:23,000 --> 00:03:24,000
235
+ They need to know.
236
+
237
+ 60
238
+ 00:03:24,000 --> 00:03:26,000
239
+ Don't forget the data owner determines Bob has access.
240
+
241
+ 61
242
+ 00:03:26,000 --> 00:03:28,000
243
+ Mary doesn't, or vice versa.
244
+
245
+ 62
246
+ 00:03:28,000 --> 00:03:32,000
247
+ They determine how to declassify it if it needs to be or destroy it.
248
+
249
+ 63
250
+ 00:03:32,000 --> 00:03:38,000
251
+ The whole objective of data classification, like I mentioned earlier, is to get the right controls
252
+
253
+ 64
254
+ 00:03:38,000 --> 00:03:43,000
255
+ to the right data owner will define the retention requirements.
256
+
257
+ 65
258
+ 00:03:43,000 --> 00:03:46,000
259
+ Data classifications will also define how long you keep it.
260
+
261
+ 66
262
+ 00:03:47,000 --> 00:03:54,000
263
+ Basically, the whole point of this entire topic is to the optimization of resources and keeping our
264
+
265
+ 67
266
+ 00:03:54,000 --> 00:03:55,000
267
+ data secure.
268
+
269
+ 68
270
+ 00:03:55,000 --> 00:03:56,000
271
+ Now.
272
+
273
+ 69
274
+ 00:03:57,000 --> 00:03:59,000
275
+ There's a couple of things here I want to mention.
276
+
277
+ 70
278
+ 00:04:00,000 --> 00:04:05,000
279
+ When it comes to classification, you have to think of the entire CIA.
280
+
281
+ 71
282
+ 00:04:05,000 --> 00:04:10,000
283
+ How sensitive it is, how critical it is sensitivity and critical, and how critical it is generally
284
+
285
+ 72
286
+ 00:04:10,000 --> 00:04:12,000
287
+ relate back to confidentiality.
288
+
289
+ 73
290
+ 00:04:12,000 --> 00:04:19,000
291
+ So you want to keep in mind these particular things when you're thinking about, for example, top secret
292
+
293
+ 74
294
+ 00:04:19,000 --> 00:04:26,000
295
+ data, secret data, public data, unclassified data, you have to think about these particular things.
296
+
297
+ 75
298
+ 00:04:26,000 --> 00:04:34,000
299
+ For example, in the military, they they prioritize our emphasized confidentiality.
300
+
301
+ 76
302
+ 00:04:34,000 --> 00:04:39,000
303
+ Fully emphasizing confidentiality may give up, for example, availability.
304
+
305
+ 77
306
+ 00:04:41,000 --> 00:04:47,000
307
+ A machine that is super secure, that no one can go in and just tamper with the machine and steal its
308
+
309
+ 78
310
+ 00:04:47,000 --> 00:04:47,000
311
+ data.
312
+
313
+ 79
314
+ 00:04:47,000 --> 00:04:52,000
315
+ A machine that's turned off and unplugged airgap the machine.
316
+
317
+ 80
318
+ 00:04:52,000 --> 00:04:56,000
319
+ Well, if it's air gapped, then only two people can get access to it and they have to put the machine
320
+
321
+ 81
322
+ 00:04:56,000 --> 00:04:57,000
323
+ on because it's not turned on.
324
+
325
+ 82
326
+ 00:04:58,000 --> 00:05:02,000
327
+ The problem with this is that, yes, good confidentiality, but it's not available to anyone except
328
+
329
+ 83
330
+ 00:05:02,000 --> 00:05:03,000
331
+ a few people.
332
+
333
+ 84
334
+ 00:05:03,000 --> 00:05:10,000
335
+ Low availability in private industries, though, we're going to emphasize the full CIA.
336
+
337
+ 85
338
+ 00:05:10,000 --> 00:05:12,000
339
+ We're going to want to push the full thing.
340
+
341
+ 86
342
+ 00:05:12,000 --> 00:05:16,000
343
+ We're going to try to get CIA for most of our data, not all of it.
344
+
345
+ 87
346
+ 00:05:16,000 --> 00:05:19,000
347
+ Keep your classification scheme simple.
348
+
349
+ 88
350
+ 00:05:19,000 --> 00:05:24,000
351
+ I'm going to talk about a different classification scheme that we can use, the different terms you
352
+
353
+ 89
354
+ 00:05:24,000 --> 00:05:25,000
355
+ can use in a minute.
356
+
357
+ 90
358
+ 00:05:25,000 --> 00:05:28,000
359
+ Here's an example though of a classification scheme.
360
+
361
+ 91
362
+ 00:05:28,000 --> 00:05:31,000
363
+ So for example this is just an example.
364
+
365
+ 92
366
+ 00:05:31,000 --> 00:05:34,000
367
+ Like in the military when we're talking protection of data.
368
+
369
+ 93
370
+ 00:05:34,000 --> 00:05:39,000
371
+ Look at how the different classification will determine what type of controls.
372
+
373
+ 94
374
+ 00:05:40,000 --> 00:05:41,000
375
+ If you have data.
376
+
377
+ 95
378
+ 00:05:42,000 --> 00:05:46,000
379
+ Particularly something like on paper, if it's top secret, put it in a vault.
380
+
381
+ 96
382
+ 00:05:46,000 --> 00:05:49,000
383
+ If it's secret, a safe would be okay.
384
+
385
+ 97
386
+ 00:05:49,000 --> 00:05:53,000
387
+ Confidential, maybe a filing cabinet with a metal bar and a lock.
388
+
389
+ 98
390
+ 00:05:53,000 --> 00:05:54,000
391
+ And on classified.
392
+
393
+ 99
394
+ 00:05:54,000 --> 00:05:54,000
395
+ No protection.
396
+
397
+ 100
398
+ 00:05:54,000 --> 00:05:55,000
399
+ Leave it on the desk.
400
+
401
+ 101
402
+ 00:05:55,000 --> 00:06:00,000
403
+ Notice the different classification results in different controls.
404
+
405
+ 102
406
+ 00:06:01,000 --> 00:06:08,000
407
+ Now, the question that a lot of people ask me is, Andrew, what are the different classification schemes
408
+
409
+ 103
410
+ 00:06:08,000 --> 00:06:09,000
411
+ that we can use?
412
+
413
+ 104
414
+ 00:06:09,000 --> 00:06:18,000
415
+ There is no official definition of any potential or any classification scheme that is out there.
416
+
417
+ 105
418
+ 00:06:18,000 --> 00:06:25,000
419
+ Many books that we read, CISSP books, Security+ books, even the books on Ec-council.
420
+
421
+ 106
422
+ 00:06:25,000 --> 00:06:31,000
423
+ They're going to vary in the definitions because there's no definition and the exam will never ask you,
424
+
425
+ 107
426
+ 00:06:31,000 --> 00:06:34,000
427
+ is this secret, top secret or confidential?
428
+
429
+ 108
430
+ 00:06:34,000 --> 00:06:35,000
431
+ They'll never do that.
432
+
433
+ 109
434
+ 00:06:35,000 --> 00:06:38,000
435
+ Just understand what data classification is.
436
+
437
+ 110
438
+ 00:06:38,000 --> 00:06:42,000
439
+ I want to show you an example of what you could use though.
440
+
441
+ 111
442
+ 00:06:43,000 --> 00:06:46,000
443
+ Uh, this is a classification scheme that you could use.
444
+
445
+ 112
446
+ 00:06:46,000 --> 00:06:50,000
447
+ And I want to show you how different schemes mean different things.
448
+
449
+ 113
450
+ 00:06:50,000 --> 00:06:52,000
451
+ So let's take a look here.
452
+
453
+ 114
454
+ 00:06:52,000 --> 00:06:54,000
455
+ So here's a data classification scheme.
456
+
457
+ 115
458
+ 00:06:54,000 --> 00:06:57,000
459
+ So on this one we have four classes 0 to 3.
460
+
461
+ 116
462
+ 00:06:58,000 --> 00:07:01,000
463
+ And on the bottom of the triangle let's go with non-government.
464
+
465
+ 117
466
+ 00:07:01,000 --> 00:07:03,000
467
+ First let's see a private organization.
468
+
469
+ 118
470
+ 00:07:03,000 --> 00:07:05,000
471
+ Class zero is no damage.
472
+
473
+ 119
474
+ 00:07:05,000 --> 00:07:09,000
475
+ Any data that's classified as public has no damage.
476
+
477
+ 120
478
+ 00:07:09,000 --> 00:07:11,000
479
+ If it's released to the public no damage.
480
+
481
+ 121
482
+ 00:07:11,000 --> 00:07:12,000
483
+ All right.
484
+
485
+ 122
486
+ 00:07:12,000 --> 00:07:19,000
487
+ Maybe like upcoming projects, the company is doing class one sensitive does cause damage to the business.
488
+
489
+ 123
490
+ 00:07:19,000 --> 00:07:23,000
491
+ Things like the company's financial, like its profit and loss statement.
492
+
493
+ 124
494
+ 00:07:23,000 --> 00:07:25,000
495
+ Serious damage like a class two.
496
+
497
+ 125
498
+ 00:07:25,000 --> 00:07:27,000
499
+ This one is private.
500
+
501
+ 126
502
+ 00:07:27,000 --> 00:07:30,000
503
+ This would be like releasing air information about the company's employees.
504
+
505
+ 127
506
+ 00:07:30,000 --> 00:07:33,000
507
+ And then of course, grave damage to that business.
508
+
509
+ 128
510
+ 00:07:33,000 --> 00:07:36,000
511
+ Confidential or proprietary data like trade secrets.
512
+
513
+ 129
514
+ 00:07:36,000 --> 00:07:41,000
515
+ If you are the federal government, here's a classification that you can use.
516
+
517
+ 130
518
+ 00:07:41,000 --> 00:07:43,000
519
+ Top secret wartime information.
520
+
521
+ 131
522
+ 00:07:43,000 --> 00:07:44,000
523
+ This is released.
524
+
525
+ 132
526
+ 00:07:44,000 --> 00:07:48,000
527
+ Grave damage to national security troop deployment information.
528
+
529
+ 133
530
+ 00:07:48,000 --> 00:07:51,000
531
+ This would be serious damage to national security.
532
+
533
+ 134
534
+ 00:07:51,000 --> 00:07:56,000
535
+ Confidential is like trade secrets or health care information of government workers that are non classified
536
+
537
+ 135
538
+ 00:07:56,000 --> 00:07:58,000
539
+ is going to be their version of public.
540
+
541
+ 136
542
+ 00:07:58,000 --> 00:08:01,000
543
+ Now this is just an example.
544
+
545
+ 137
546
+ 00:08:01,000 --> 00:08:02,000
547
+ Okay.
548
+
549
+ 138
550
+ 00:08:02,000 --> 00:08:04,000
551
+ This is just an example.
552
+
553
+ 139
554
+ 00:08:04,000 --> 00:08:05,000
555
+ All right.
556
+
557
+ 140
558
+ 00:08:05,000 --> 00:08:10,000
559
+ Here at TI we only use three levels of data classification I know companies that only use two.
560
+
561
+ 141
562
+ 00:08:10,000 --> 00:08:12,000
563
+ You don't have to use them all.
564
+
565
+ 142
566
+ 00:08:12,000 --> 00:08:18,000
567
+ But when it comes to data classification, here are some different, uh, terms that you can use.
568
+
569
+ 143
570
+ 00:08:18,000 --> 00:08:20,000
571
+ Sensitive confidential.
572
+
573
+ 144
574
+ 00:08:20,000 --> 00:08:21,000
575
+ Public I think has a universal meaning.
576
+
577
+ 145
578
+ 00:08:21,000 --> 00:08:23,000
579
+ Anyone can access it.
580
+
581
+ 146
582
+ 00:08:23,000 --> 00:08:25,000
583
+ But for example, what are some companies may call it private.
584
+
585
+ 147
586
+ 00:08:25,000 --> 00:08:32,000
587
+ Some may call it confidential, what some call sensitive, some may call restricted, what some call
588
+
589
+ 148
590
+ 00:08:32,000 --> 00:08:34,000
591
+ confidential, some may call it critical.
592
+
593
+ 149
594
+ 00:08:34,000 --> 00:08:39,000
595
+ And then of course, the military will add things like secret and top secret on top of this.
596
+
597
+ 150
598
+ 00:08:39,000 --> 00:08:41,000
599
+ Or maybe a line in here with these.
600
+
601
+ 151
602
+ 00:08:41,000 --> 00:08:45,000
603
+ There really isn't a full definition.
604
+
605
+ 152
606
+ 00:08:46,000 --> 00:08:50,000
607
+ Now when it comes to your exam and data classification, remember something.
608
+
609
+ 153
610
+ 00:08:50,000 --> 00:08:52,000
611
+ Data classification is a big terme.
612
+
613
+ 154
614
+ 00:08:52,000 --> 00:09:00,000
615
+ Data classification is the umbrella terms that affects all controls of the data.
616
+
617
+ 155
618
+ 00:09:01,000 --> 00:09:04,000
619
+ Like I mentioned earlier in the beginning, let's do a quick recap.
620
+
621
+ 156
622
+ 00:09:04,000 --> 00:09:11,000
623
+ Data classification affects everything about the data, determines what controls is applied to what
624
+
625
+ 157
626
+ 00:09:11,000 --> 00:09:15,000
627
+ data, determines who should have access to it, or you can't access this because you're not in the
628
+
629
+ 158
630
+ 00:09:15,000 --> 00:09:18,000
631
+ top secret clearance, or you can't access this because you don't.
632
+
633
+ 159
634
+ 00:09:18,000 --> 00:09:20,000
635
+ You can't access confidential data.
636
+
637
+ 160
638
+ 00:09:20,000 --> 00:09:23,000
639
+ You can access public data, things like that.
640
+
641
+ 161
642
+ 00:09:23,000 --> 00:09:26,000
643
+ Keep this in mind when answering your exam questions.
644
+