diff --git a/.gitattributes b/.gitattributes index 8272af31b311785108f0a0d047f4ca74fb3d1e6a..4cf99daff613be2e80703175abf0bd9c6c09859f 100644 --- a/.gitattributes +++ b/.gitattributes @@ -96,3 +96,40 @@ saved_model/**/* filter=lfs diff=lfs merge=lfs -text 06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/011[[:space:]]DDOS[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text 06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/014[[:space:]]Credential[[:space:]]Replay[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text 06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/015[[:space:]]Privilege[[:space:]]Escalation[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text +06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/016[[:space:]]Request[[:space:]]Forgery[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text +06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/017[[:space:]]Directory[[:space:]]Traversal[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text +06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/018[[:space:]]Indicators[[:space:]]of[[:space:]]Malicious[[:space:]]Activity[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text +07[[:space:]]-[[:space:]]Cryptography/002[[:space:]]Crypto[[:space:]]Terms[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text +07[[:space:]]-[[:space:]]Cryptography/001[[:space:]]Intro[[:space:]]to[[:space:]]cryptography[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text +07[[:space:]]-[[:space:]]Cryptography/003[[:space:]]Goals[[:space:]]Cryptography[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text +07[[:space:]]-[[:space:]]Cryptography/005[[:space:]]Ciphers[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text +07[[:space:]]-[[:space:]]Cryptography/006[[:space:]]Symmetric[[:space:]]Encryption[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text +07[[:space:]]-[[:space:]]Cryptography/007[[:space:]]Symmetric[[:space:]]Algorithms[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text +07[[:space:]]-[[:space:]]Cryptography/004[[:space:]]Algorithm[[:space:]]vs[[:space:]]Keys[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text +07[[:space:]]-[[:space:]]Cryptography/009[[:space:]]Asymmetric[[:space:]]Algorithms[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text +07[[:space:]]-[[:space:]]Cryptography/008[[:space:]]Asymmetric[[:space:]]Encryption[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text +07[[:space:]]-[[:space:]]Cryptography/010[[:space:]]Hybrid[[:space:]]Cryptography[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text +07[[:space:]]-[[:space:]]Cryptography/012[[:space:]]Hashing[[:space:]]Algorithms[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text +07[[:space:]]-[[:space:]]Cryptography/013[[:space:]]Digital[[:space:]]Signatures[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text +07[[:space:]]-[[:space:]]Cryptography/014[[:space:]]Intro[[:space:]]to[[:space:]]PKI[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text +07[[:space:]]-[[:space:]]Cryptography/011[[:space:]]Hashing[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text +07[[:space:]]-[[:space:]]Cryptography/015[[:space:]]PKI[[:space:]]Purpose[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text +07[[:space:]]-[[:space:]]Cryptography/016[[:space:]]SSLTLS[[:space:]]Handshake[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text +07[[:space:]]-[[:space:]]Cryptography/017[[:space:]]PKI[[:space:]]Process[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text +07[[:space:]]-[[:space:]]Cryptography/018[[:space:]]Certificates[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text +07[[:space:]]-[[:space:]]Cryptography/019[[:space:]]PKI[[:space:]]Root[[:space:]]of[[:space:]]Trust[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text +07[[:space:]]-[[:space:]]Cryptography/020[[:space:]]PKI[[:space:]]Verification[[:space:]]and[[:space:]]Revocation[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text +07[[:space:]]-[[:space:]]Cryptography/022[[:space:]]Blockchain[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text +07[[:space:]]-[[:space:]]Cryptography/021[[:space:]]Steganography[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text +07[[:space:]]-[[:space:]]Cryptography/023[[:space:]]Salting[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text +07[[:space:]]-[[:space:]]Cryptography/024[[:space:]]TPM[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text +07[[:space:]]-[[:space:]]Cryptography/025[[:space:]]Secure[[:space:]]Enclave[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text +07[[:space:]]-[[:space:]]Cryptography/026[[:space:]]Obfuscation[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text +07[[:space:]]-[[:space:]]Cryptography/027[[:space:]]Tokenization[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text +07[[:space:]]-[[:space:]]Cryptography/028[[:space:]]Key[[:space:]]Escrow[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text +08[[:space:]]-[[:space:]]Social[[:space:]]Engineering/001[[:space:]]Social[[:space:]]Engineering[[:space:]]OB[[:space:]]2.2.mp4 filter=lfs diff=lfs merge=lfs -text +07[[:space:]]-[[:space:]]Cryptography/029[[:space:]]HSM[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text +08[[:space:]]-[[:space:]]Social[[:space:]]Engineering/004[[:space:]]Smishing[[:space:]]OB[[:space:]]2.2.mp4 filter=lfs diff=lfs merge=lfs -text +08[[:space:]]-[[:space:]]Social[[:space:]]Engineering/003[[:space:]]Vishing[[:space:]]OB[[:space:]]2.2.mp4 filter=lfs diff=lfs merge=lfs -text +08[[:space:]]-[[:space:]]Social[[:space:]]Engineering/002[[:space:]]Phishing[[:space:]]OB[[:space:]]2.2.mp4 filter=lfs diff=lfs merge=lfs -text +08[[:space:]]-[[:space:]]Social[[:space:]]Engineering/006[[:space:]]Misinformation[[:space:]]and[[:space:]]Disinformation[[:space:]]OB[[:space:]]2.2.mp4 filter=lfs diff=lfs merge=lfs -text diff --git a/06 - Signs of Attacks/016 Request Forgery OB 2.4.mp4 b/06 - Signs of Attacks/016 Request Forgery OB 2.4.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..6bc883fa67ccd74b2103a94f84fe23707c0d0e3d --- /dev/null +++ b/06 - Signs of Attacks/016 Request Forgery OB 2.4.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:7fb67cb33e669a0cd4db9d175ab0af64cf6e2f395928443fba926e046fc6628e +size 252434757 diff --git a/06 - Signs of Attacks/017 Directory Traversal OB 2.4.mp4 b/06 - Signs of Attacks/017 Directory Traversal OB 2.4.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..73d2fe3d7425557296fe28f57864096cb008982a --- /dev/null +++ b/06 - Signs of Attacks/017 Directory Traversal OB 2.4.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:e1744255f84e98cd7a85e260f4fc4c456a930a8571773c1fd4b050aab4b2b0a7 +size 55519440 diff --git a/06 - Signs of Attacks/018 Indicators of Malicious Activity OB 2.4.mp4 b/06 - Signs of Attacks/018 Indicators of Malicious Activity OB 2.4.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..4ebbd5da6cd81232538390718b857ea1badff160 --- /dev/null +++ b/06 - Signs of Attacks/018 Indicators of Malicious Activity OB 2.4.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:a06d972cbc8ff0a0f5b8a0649fdaa9420454c21fc6ca8bc85c96236a062be796 +size 165107189 diff --git a/07 - Cryptography/001 Intro to cryptography OB 1.4.mp4 b/07 - Cryptography/001 Intro to cryptography OB 1.4.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..84f5c7c07f2298234b47ea845ec2c6c80d92b3cd --- /dev/null +++ b/07 - Cryptography/001 Intro to cryptography OB 1.4.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:f410dce7cb4466cf86b270c58220847a1b2f51ea6d5c26c8cbdff507a7b0146d +size 96326919 diff --git a/07 - Cryptography/002 Crypto Terms OB 1.4.mp4 b/07 - Cryptography/002 Crypto Terms OB 1.4.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..9b7995f85f0a6a1773d2149e616e382489566c05 --- /dev/null +++ b/07 - Cryptography/002 Crypto Terms OB 1.4.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:4cc3556f416a37507fb252d2fcb7a996064cef75b2e419837b7599182af66fa7 +size 61060517 diff --git a/07 - Cryptography/003 Goals Cryptography OB 1.4.mp4 b/07 - Cryptography/003 Goals Cryptography OB 1.4.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..23bd9405737a2dd111daed928189152b29378764 --- /dev/null +++ b/07 - Cryptography/003 Goals Cryptography OB 1.4.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:9d6ea104492a374d07c1016b6b3503ab89fc91d8adebba0c830495dd01b8c89f +size 158674618 diff --git a/07 - Cryptography/004 Algorithm vs Keys OB 1.4.mp4 b/07 - Cryptography/004 Algorithm vs Keys OB 1.4.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..71d7b2fa99ecc00b14be2922bdfec808f1639cfc --- /dev/null +++ b/07 - Cryptography/004 Algorithm vs Keys OB 1.4.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:bd0304e7831242c9f3d707d88bf9856f97d6277b74d575b9f8a96aaf40b98c15 +size 904992896 diff --git a/07 - Cryptography/005 Ciphers OB 1.4.mp4 b/07 - Cryptography/005 Ciphers OB 1.4.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..d7293a4c6858390d6ac9c3c76ac3e872d964aaf2 --- /dev/null +++ b/07 - Cryptography/005 Ciphers OB 1.4.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:44c1f607cb008792070ba7bc251a782124aa6b4674fd3ad4923b099c04b6bee7 +size 70642872 diff --git a/07 - Cryptography/006 Symmetric Encryption OB 1.4.mp4 b/07 - Cryptography/006 Symmetric Encryption OB 1.4.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..0a333fe7207f85a91a6d90054dbf7329ef1e1fc3 --- /dev/null +++ b/07 - Cryptography/006 Symmetric Encryption OB 1.4.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:906c0006508ac8feebd61b1a0a4236cb2a073add324119275f6653f3819e6ce3 +size 301229092 diff --git a/07 - Cryptography/007 Symmetric Algorithms OB 1.4.mp4 b/07 - Cryptography/007 Symmetric Algorithms OB 1.4.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..21a61a72dfe9fd6f6af0f449ed600e8d206759fe --- /dev/null +++ b/07 - Cryptography/007 Symmetric Algorithms OB 1.4.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:6e3357e07a707570a5d682d8711ce37c3257871f01c1cd9f57259d102c765260 +size 208197734 diff --git a/07 - Cryptography/008 Asymmetric Encryption OB 1.4.mp4 b/07 - Cryptography/008 Asymmetric Encryption OB 1.4.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..7ccb1a2b7c8ab75630d0da85f832414f4c37659c --- /dev/null +++ b/07 - Cryptography/008 Asymmetric Encryption OB 1.4.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:d30021a868903bbb6ab27a33c128faaa343205a4698dda444d1cff8cdc4899ec +size 262306688 diff --git a/07 - Cryptography/009 Asymmetric Algorithms OB 1.4.mp4 b/07 - Cryptography/009 Asymmetric Algorithms OB 1.4.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..e16683a95acbd55791a6bec428889a221dade8a9 --- /dev/null +++ b/07 - Cryptography/009 Asymmetric Algorithms OB 1.4.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:bc4dbc91ef6e892dab0aeef519323e3958ec5cf1ce1db38b429d073da21e96d2 +size 99626564 diff --git a/07 - Cryptography/010 Hybrid Cryptography OB 1.4.mp4 b/07 - Cryptography/010 Hybrid Cryptography OB 1.4.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..174f7ec50ea6126c895c07f478266a0e13358fac --- /dev/null +++ b/07 - Cryptography/010 Hybrid Cryptography OB 1.4.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:b4c0b7ee7d7b0df27553d841c16df9d203d01d47527a33c0ddadd96219b95743 +size 157908953 diff --git a/07 - Cryptography/011 Hashing OB 1.4.mp4 b/07 - Cryptography/011 Hashing OB 1.4.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..bdfef8f2f2fee27ab0099e5c33e5b5ab392448f5 --- /dev/null +++ b/07 - Cryptography/011 Hashing OB 1.4.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:849824f981dde0483565115c45f8a19348912f37864040c2b47282373b86a777 +size 628967987 diff --git a/07 - Cryptography/012 Hashing Algorithms OB 1.4.mp4 b/07 - Cryptography/012 Hashing Algorithms OB 1.4.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..584140d50d0bf34f9b6c9f27fb4175d7b9d217e3 --- /dev/null +++ b/07 - Cryptography/012 Hashing Algorithms OB 1.4.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:690cf391d2d7106d916db9e072c2fe74c170e259fc4bfa27a8008d18dec5e460 +size 80731663 diff --git a/07 - Cryptography/013 Digital Signatures OB 1.4.mp4 b/07 - Cryptography/013 Digital Signatures OB 1.4.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..daa26ea153f1dfd36b3f130f2185c2df18ce4c2b --- /dev/null +++ b/07 - Cryptography/013 Digital Signatures OB 1.4.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:7dd7fb58914ad32f6f6037638e36e90d4e8c5e4870af7330d6862ec5ebe11888 +size 181001409 diff --git a/07 - Cryptography/014 Intro to PKI OB 1.4.mp4 b/07 - Cryptography/014 Intro to PKI OB 1.4.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..b16f59e3a06f23e004b144467b773b27de1d8bf3 --- /dev/null +++ b/07 - Cryptography/014 Intro to PKI OB 1.4.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:4f8ac279e3d05da47bb0b7ead6b020e9b23a7ff9145d497f2c3680f7fbc8974d +size 46048784 diff --git a/07 - Cryptography/015 PKI Purpose OB 1.4.mp4 b/07 - Cryptography/015 PKI Purpose OB 1.4.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..e31b6b11e16c5ce0445daf2b36728f4b60a22f22 --- /dev/null +++ b/07 - Cryptography/015 PKI Purpose OB 1.4.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:b6a8128beb36e602748800e10f620fac19457721cfec27ba8a1208a8e8ea12c7 +size 133257759 diff --git a/07 - Cryptography/016 SSLTLS Handshake OB 1.4.mp4 b/07 - Cryptography/016 SSLTLS Handshake OB 1.4.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..80b7145b5d72a6bbca9f8ea741944b53fd6aa06b --- /dev/null +++ b/07 - Cryptography/016 SSLTLS Handshake OB 1.4.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:62b288a9b3d91f94aa4c663902299a0b3ca0c5e205f4f4c20e900c47806db25c +size 322894899 diff --git a/07 - Cryptography/017 PKI Process OB 1.4.mp4 b/07 - Cryptography/017 PKI Process OB 1.4.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..88428e48ad93ba4e57a1de42126ed40c611d04f2 --- /dev/null +++ b/07 - Cryptography/017 PKI Process OB 1.4.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:2df30749129881a7cdb3eab017a1014418a5a912554e22b8eb690cf4509aa84a +size 227238978 diff --git a/07 - Cryptography/018 Certificates OB 1.4.mp4 b/07 - Cryptography/018 Certificates OB 1.4.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..9fa513c5ad20466fa9f3172e94a3b4493577f70e --- /dev/null +++ b/07 - Cryptography/018 Certificates OB 1.4.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:289b439dc3db3773da97e6e921bc16082cc4444a987c3656c4a1d5b857b828c0 +size 256419507 diff --git a/07 - Cryptography/019 PKI Root of Trust OB 1.4.mp4 b/07 - Cryptography/019 PKI Root of Trust OB 1.4.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..8d49ecb60dbefd707ae17d29d1550294d94b6a6d --- /dev/null +++ b/07 - Cryptography/019 PKI Root of Trust OB 1.4.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:52767a81cd65b574262fbbd167b541891ab823e4ac5db0e29ed817cbda7e6dc4 +size 81385638 diff --git a/07 - Cryptography/020 PKI Verification and Revocation OB 1.4.mp4 b/07 - Cryptography/020 PKI Verification and Revocation OB 1.4.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..f5d588bc36c2989eb849cb1588952c7bdde0dcf1 --- /dev/null +++ b/07 - Cryptography/020 PKI Verification and Revocation OB 1.4.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:209b9a6ce812392bc253484a273d19429e764f0bcdcd28708ea3e58839128724 +size 119243591 diff --git a/07 - Cryptography/021 Steganography OB 1.4.mp4 b/07 - Cryptography/021 Steganography OB 1.4.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..ca2c1619e074b474c81e618454aab0d8a3c73f8d --- /dev/null +++ b/07 - Cryptography/021 Steganography OB 1.4.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:5d9c971a71471963a520a76520af39e504725a61525bc23c8f5d6709490ba1c8 +size 123486561 diff --git a/07 - Cryptography/022 Blockchain OB 1.4.mp4 b/07 - Cryptography/022 Blockchain OB 1.4.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..49af1c5d0719105e6c9cc244bc524c1f07763c02 --- /dev/null +++ b/07 - Cryptography/022 Blockchain OB 1.4.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:ed31645711f61269c6b6fa2247c7449246b79aaafce6519c607363918480a821 +size 166936677 diff --git a/07 - Cryptography/023 Salting OB 1.4.mp4 b/07 - Cryptography/023 Salting OB 1.4.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..42978eac196d129ed2889b9107f679e2e1f77ff5 --- /dev/null +++ b/07 - Cryptography/023 Salting OB 1.4.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:292386772cd6a1688e30efb201a3988ca58d06e896327cfd71fdaae5ffac4877 +size 106670783 diff --git a/07 - Cryptography/024 TPM OB 1.4.mp4 b/07 - Cryptography/024 TPM OB 1.4.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..00cc5442b594deb729babc59e1557d4aac84f2d4 --- /dev/null +++ b/07 - Cryptography/024 TPM OB 1.4.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:f74bc83f1e5177358d6e3e3e86d1f672f862d0020c9acbd846a82f86fcf17699 +size 211209531 diff --git a/07 - Cryptography/025 Secure Enclave OB 1.4.mp4 b/07 - Cryptography/025 Secure Enclave OB 1.4.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..5e347e22a9f90befce210c8ff67b7d72f62284a8 --- /dev/null +++ b/07 - Cryptography/025 Secure Enclave OB 1.4.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:ce54c6de590a73b2aef9782418559b1a6786fdce05d43f42062ebfc39a900367 +size 48690063 diff --git a/07 - Cryptography/026 Obfuscation OB 1.4.mp4 b/07 - Cryptography/026 Obfuscation OB 1.4.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..e7dcb7d16bfb783f39adc4e20c0350bd0a07dd9c --- /dev/null +++ b/07 - Cryptography/026 Obfuscation OB 1.4.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:7ba3668198ef774869f0fbe4319f1ea976482d18207dda79987d4378752c580c +size 73746741 diff --git a/07 - Cryptography/027 Tokenization OB 1.4.mp4 b/07 - Cryptography/027 Tokenization OB 1.4.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..d2ce2f1b55582e64ee2fabf78b2a4e02402db56b --- /dev/null +++ b/07 - Cryptography/027 Tokenization OB 1.4.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:2277841e3deee35b12cc4fccfb98aff9375d8702e7f442aa74490a2d740ecefd +size 130278517 diff --git a/07 - Cryptography/028 Key Escrow OB 1.4.mp4 b/07 - Cryptography/028 Key Escrow OB 1.4.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..183214c80f92a13504135813d222239fd688b449 --- /dev/null +++ b/07 - Cryptography/028 Key Escrow OB 1.4.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:5c6271142b89e04576eed08ad160813cefe56719b9af87f786a9510fa7caadea +size 51540744 diff --git a/07 - Cryptography/029 HSM OB 1.4.mp4 b/07 - Cryptography/029 HSM OB 1.4.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..458a808324c7fadf66223451feadcd34cdcd88da --- /dev/null +++ b/07 - Cryptography/029 HSM OB 1.4.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:99202e513878337137a489c03b2c879e67c59e0db229c0c1c1e1742a2252f81f +size 144313020 diff --git a/08 - Social Engineering/001 Social Engineering OB 2.2.mp4 b/08 - Social Engineering/001 Social Engineering OB 2.2.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..2cdbc16ab4e4d540b055b5bd02107a5ee1b82fba --- /dev/null +++ b/08 - Social Engineering/001 Social Engineering OB 2.2.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:1b587c47573275e81970968d5e20e90df0fd2e7d8f98c6ec6f7bf5dbb34e378c +size 66534314 diff --git a/08 - Social Engineering/002 Phishing OB 2.2.mp4 b/08 - Social Engineering/002 Phishing OB 2.2.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..b2243c9cefd0308f773a91019672513e84786958 --- /dev/null +++ b/08 - Social Engineering/002 Phishing OB 2.2.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:32a70e3ca9956d8b8f75af1d0b550e43d275be845e0c144849a5775c60845682 +size 215560454 diff --git a/08 - Social Engineering/003 Vishing OB 2.2.mp4 b/08 - Social Engineering/003 Vishing OB 2.2.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..80805336a2369e0eac97664d1ad9a9bf2519b991 --- /dev/null +++ b/08 - Social Engineering/003 Vishing OB 2.2.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:dcf480e016947a06fea15c3193380cb7c1833950a49957f0e8f5fb76222acc85 +size 165005146 diff --git a/08 - Social Engineering/004 Smishing OB 2.2.mp4 b/08 - Social Engineering/004 Smishing OB 2.2.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..0ad242020291489d83ab02953ed6d75f34ab1d69 --- /dev/null +++ b/08 - Social Engineering/004 Smishing OB 2.2.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:b55d80c0072c02bf3e4d2532d021c9d07fb581e5601030ab9ff18e69663d5649 +size 57310806 diff --git a/08 - Social Engineering/006 Misinformation and Disinformation OB 2.2.mp4 b/08 - Social Engineering/006 Misinformation and Disinformation OB 2.2.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..5cf0878e74138f7e046654c3a817d191ee7b23f6 --- /dev/null +++ b/08 - Social Engineering/006 Misinformation and Disinformation OB 2.2.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:d4a538f128b09d0177e2f5a358dd49a0d2bd111550e618bb33ddd367785f342b +size 165923487 diff --git a/11 - Security Principles/010 IDSIPS OB 3.2_en.srt b/11 - Security Principles/010 IDSIPS OB 3.2_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..49111dd8e44ef4ce0756eb6b74cc09054618780f --- /dev/null +++ b/11 - Security Principles/010 IDSIPS OB 3.2_en.srt @@ -0,0 +1,912 @@ +1 +00:00:00,000 --> 00:00:06,000 +One of the most common network, software and or device that you should have set up in your network + +2 +00:00:06,000 --> 00:00:14,000 +today is an IDs, Intrusion Detection Systems, or IPS intrusion prevention systems, and the simple + +3 +00:00:14,000 --> 00:00:21,000 +reason is that there is no way you can go around to every machine and check if an intrusion is coming + +4 +00:00:21,000 --> 00:00:23,000 +from one of those machines. + +5 +00:00:23,000 --> 00:00:27,000 +And the other reason is because the best one is actually free. + +6 +00:00:27,000 --> 00:00:32,000 +You see, I want to talk in this, in this particular one, in this particular video, that's going + +7 +00:00:32,000 --> 00:00:33,000 +to be pretty long. + +8 +00:00:33,000 --> 00:00:35,000 +By the way, a lot of slides is going to cover here. + +9 +00:00:35,000 --> 00:00:41,000 +In this particular video, we want to go through all the things we need to know about IDs and IPS for + +10 +00:00:41,000 --> 00:00:45,000 +our exam and why you need to have one of these in your network if you don't. + +11 +00:00:45,000 --> 00:00:48,000 +By the way, the free one I'm talking about is snort. + +12 +00:00:48,000 --> 00:00:50,000 +Snort is is maintained by Cisco. + +13 +00:00:50,000 --> 00:00:58,000 +It is the best, in Andrew's opinion IDs out there and it is 100% free maintained by Cisco. + +14 +00:00:58,000 --> 00:01:01,000 +Let's get started with what exactly is it? + +15 +00:01:01,000 --> 00:01:03,000 +I want to give you a scenario before I get started. + +16 +00:01:05,000 --> 00:01:09,000 +Imagine you have a network with 500 computers. + +17 +00:01:09,000 --> 00:01:15,000 +All of a sudden people starts calling the help desk and they say, oh, there's tons of network traffic. + +18 +00:01:15,000 --> 00:01:16,000 +The network is too slow. + +19 +00:01:16,000 --> 00:01:18,000 +No one can get to the internet. + +20 +00:01:18,000 --> 00:01:20,000 +File services are not loaded. + +21 +00:01:20,000 --> 00:01:24,000 +Well, there is some kind of thing going on in this network. + +22 +00:01:24,000 --> 00:01:26,000 +Somebody is using up all the traffic. + +23 +00:01:26,000 --> 00:01:29,000 +Maybe there's a worm spreading from machine to machine. + +24 +00:01:29,000 --> 00:01:33,000 +Maybe somebody has a virus that's downloading and utilizing all the bandwidth. + +25 +00:01:34,000 --> 00:01:35,000 +You got two choices. + +26 +00:01:35,000 --> 00:01:44,000 +You can decide to do nothing, or you can go to every single one of the machines and attempt to to to + +27 +00:01:44,000 --> 00:01:46,000 +find which one of them is broken. + +28 +00:01:46,000 --> 00:01:48,000 +This is a nightmare scenario. + +29 +00:01:48,000 --> 00:01:55,000 +This is a scenario that I had faced at Tia many, many years ago because I was an idiot and didn't have + +30 +00:01:55,000 --> 00:01:55,000 +one. + +31 +00:01:56,000 --> 00:01:59,000 +Now we do and we have them in every one of our locations. + +32 +00:01:59,000 --> 00:02:01,000 +We have IDs snorting in particular set up. + +33 +00:02:01,000 --> 00:02:07,000 +So if there is some kind of intrusion, especially like worm or viruses or malware on the student machines, + +34 +00:02:07,000 --> 00:02:09,000 +we could say, okay, it's that machine and that lab, let's go fix it. + +35 +00:02:10,000 --> 00:02:17,000 +IDs are able to suck up the network traffic on your network, analyze the traffic and say, that computer + +36 +00:02:17,000 --> 00:02:19,000 +over there, that one is bad. + +37 +00:02:19,000 --> 00:02:25,000 +That's why you need to have these particular things now when it comes to this. + +38 +00:02:25,000 --> 00:02:32,000 +It's basically a technology for real time monitoring and analysis of network activity and data for potential + +39 +00:02:32,000 --> 00:02:32,000 +intrusions. + +40 +00:02:33,000 --> 00:02:34,000 +Now, what is it going to do? + +41 +00:02:34,000 --> 00:02:39,000 +Well, it's going to monitor and analyze user and systems activities to see what's happening on it. + +42 +00:02:39,000 --> 00:02:41,000 +It's going to audit our systems and configuration. + +43 +00:02:41,000 --> 00:02:43,000 +If there's any vulnerabilities, it'll let you know. + +44 +00:02:43,000 --> 00:02:48,000 +It looks at the integrity of critical systems and any kind of data files. + +45 +00:02:48,000 --> 00:02:51,000 +It's going to recognize different patterns. + +46 +00:02:51,000 --> 00:02:55,000 +And maybe if there is any kind of abnormal activities out there. + +47 +00:02:56,000 --> 00:03:02,000 +Now in this video we want to talk, not just okay, this is what an IDs does, but I want to talk. + +48 +00:03:02,000 --> 00:03:05,000 +Exactly how does it is it a passive active. + +49 +00:03:06,000 --> 00:03:07,000 +Is it a behavioral based. + +50 +00:03:07,000 --> 00:03:10,000 +Is it a signature based IDs. + +51 +00:03:10,000 --> 00:03:12,000 +Um, is it an IDs or an IDs? + +52 +00:03:12,000 --> 00:03:14,000 +These are all terms that you can need to know for your exam. + +53 +00:03:14,000 --> 00:03:16,000 +So let's knock them out okay. + +54 +00:03:16,000 --> 00:03:23,000 +The first thing I want to talk about is how does an IDs know that this traffic is good or this traffic + +55 +00:03:23,000 --> 00:03:24,000 +is bad. + +56 +00:03:24,000 --> 00:03:29,000 +How does it is how is it able to differentiate good traffic versus bad traffic. + +57 +00:03:29,000 --> 00:03:31,000 +So this goes into its detection. + +58 +00:03:31,000 --> 00:03:38,000 +There's two ways the IDs is able to detect either it's a knowledge based system or it's a behavior or + +59 +00:03:38,000 --> 00:03:40,000 +slash anomaly based systems. + +60 +00:03:40,000 --> 00:03:44,000 +So knowledge based systems are also known as signature based systems. + +61 +00:03:44,000 --> 00:03:48,000 +They have a signature for all known vulnerabilities. + +62 +00:03:48,000 --> 00:03:54,000 +This thing has a database of all the vulnerabilities that are out there, all of the different worms + +63 +00:03:54,000 --> 00:03:55,000 +and attacks that are out there. + +64 +00:03:55,000 --> 00:03:56,000 +This is good. + +65 +00:03:56,000 --> 00:03:59,000 +I like these these types of systems. + +66 +00:03:59,000 --> 00:04:04,000 +They're you know, the main reason here is because it has a very low false alarm. + +67 +00:04:04,000 --> 00:04:10,000 +And what that means is this when this system tells you there is a virus, oh, there's probably a virus, + +68 +00:04:10,000 --> 00:04:11,000 +there is an intrusion. + +69 +00:04:11,000 --> 00:04:13,000 +There is a worm going on in there. + +70 +00:04:13,000 --> 00:04:17,000 +Alarms are more standardized and more easily to understand because it's coming from a signature. + +71 +00:04:17,000 --> 00:04:23,000 +The same way you have to update your antivirus software with signatures the same way this particular + +72 +00:04:23,000 --> 00:04:24,000 +thing works. + +73 +00:04:24,000 --> 00:04:29,000 +The disadvantage with this though, you have to continuously update the signatures. + +74 +00:04:29,000 --> 00:04:35,000 +Like if you have snort, you have to go and get the definitions, the updates on a consistent basis. + +75 +00:04:36,000 --> 00:04:41,000 +Um, and the other problem, if it's a signature based system, is you're waiting on the manufacturer + +76 +00:04:41,000 --> 00:04:48,000 +of the device or the software to actually send you the signature for new, unique, or for all the new + +77 +00:04:48,000 --> 00:04:49,000 +attacks that are coming out. + +78 +00:04:49,000 --> 00:04:55,000 +So if there's a new attack, a unique attack that the manufacturer doesn't know about yet, you're going + +79 +00:04:55,000 --> 00:04:59,000 +to get killed with it because the devices just doesn't know about it. + +80 +00:04:59,000 --> 00:05:04,000 +Now, what you should do is then turn the device into what's called an anomaly based device, or also + +81 +00:05:04,000 --> 00:05:06,000 +known as behavioral devices. + +82 +00:05:06,000 --> 00:05:09,000 +So behavioral based detection is this. + +83 +00:05:09,000 --> 00:05:15,000 +What it does is that it creates a baseline or learn the patterns of the normal activity within your + +84 +00:05:15,000 --> 00:05:16,000 +network. + +85 +00:05:16,000 --> 00:05:21,000 +It then it builds this statistical pattern of traffic within your network. + +86 +00:05:21,000 --> 00:05:25,000 +Any deviations, any variations from that. + +87 +00:05:25,000 --> 00:05:32,000 +It's going to tell you the great thing, the reason why it does this, since it's adapting to the traffic, + +88 +00:05:32,000 --> 00:05:35,000 +anything that's abnormal that people haven't done before, boom. + +89 +00:05:35,000 --> 00:05:38,000 +It tells you right away that there's something going on there. + +90 +00:05:38,000 --> 00:05:44,000 +You should check it out so it's able to tell you new or unique attacks that are out there. + +91 +00:05:46,000 --> 00:05:49,000 +It's less dependent on operating system vulnerability. + +92 +00:05:49,000 --> 00:05:52,000 +It's not going to find, you know, this is not going to affect it. + +93 +00:05:52,000 --> 00:05:54,000 +Now the disadvantage is there. + +94 +00:05:54,000 --> 00:05:56,000 +It's a higher false alarm. + +95 +00:05:56,000 --> 00:05:58,000 +This is going to suck. + +96 +00:05:58,000 --> 00:06:03,000 +Because if somebody decides to transfer a big file, the IDs is like, well, they've never done that + +97 +00:06:03,000 --> 00:06:07,000 +before and sends out an alarm and you're probably going to go investigate it. + +98 +00:06:07,000 --> 00:06:10,000 +Uh, usage pattern often changes in network. + +99 +00:06:10,000 --> 00:06:17,000 +And because of this, if user if user behavior pattern changes lots of false alarms. + +100 +00:06:17,000 --> 00:06:18,000 +Now. + +101 +00:06:18,000 --> 00:06:23,000 +IEDs are generally going to be a passive device. + +102 +00:06:23,000 --> 00:06:28,000 +Passive means that they just sit back and write passive responses. + +103 +00:06:28,000 --> 00:06:29,000 +They just sit back. + +104 +00:06:29,000 --> 00:06:34,000 +They make a log of the event, and they just tell you they'll send you a notification, either through + +105 +00:06:34,000 --> 00:06:38,000 +an email or a text message saying, hey, you know what? + +106 +00:06:39,000 --> 00:06:41,000 +With that email, you know what? + +107 +00:06:41,000 --> 00:06:44,000 +There is a there is a virus on that machine. + +108 +00:06:44,000 --> 00:06:46,000 +There's a worm on that particular machine. + +109 +00:06:46,000 --> 00:06:51,000 +So they're just basically telling you they're not going to do anything about the attack. + +110 +00:06:51,000 --> 00:06:54,000 +They're just going to they're just going to inform you that it's there. + +111 +00:06:55,000 --> 00:06:59,000 +Now, an active response is when it changes the environment to block it. + +112 +00:06:59,000 --> 00:07:05,000 +Modifying ACLs, blocking ports, blocking traffic, blocking certain network address, disable communications + +113 +00:07:05,000 --> 00:07:06,000 +on network segments. + +114 +00:07:06,000 --> 00:07:11,000 +This is more of going to be of an IPS, not just an IDs, which we'll come to in a little while. + +115 +00:07:13,000 --> 00:07:18,000 +Now, when it comes to IDs, there's really two main ways you're going to have them. + +116 +00:07:18,000 --> 00:07:19,000 +Ideally, you're going to have both. + +117 +00:07:19,000 --> 00:07:24,000 +You're going to have what's called a whole space IDs, and you're going to have a network based IDs. + +118 +00:07:25,000 --> 00:07:30,000 +Now, a host based IDs is something that you're going to install on your computer, on your desktop, + +119 +00:07:30,000 --> 00:07:33,000 +just like you would on anti-malware. + +120 +00:07:33,000 --> 00:07:39,000 +Now, if you have endpoint security software like Symantec's or Broadcom endpoint, McAfee endpoint + +121 +00:07:39,000 --> 00:07:45,000 +endpoint security software generally will come with a host based IDs on it. + +122 +00:07:46,000 --> 00:07:50,000 +Well, this is going to do is going to just monitor the host machine. + +123 +00:07:50,000 --> 00:07:55,000 +Maybe you go to a particular website, maybe you were downloading something, maybe an email brought + +124 +00:07:55,000 --> 00:07:57,000 +in a particular malware. + +125 +00:07:58,000 --> 00:08:02,000 +The host base IDs is going to be able to detect that. + +126 +00:08:02,000 --> 00:08:06,000 +Now this is going to respond by logging the activity and notifying you. + +127 +00:08:06,000 --> 00:08:12,000 +But it's probably going to notify a central console that, for example, the help desk, that something + +128 +00:08:12,000 --> 00:08:13,000 +needs to be done here. + +129 +00:08:13,000 --> 00:08:17,000 +Now the advantages there is that it can detect anomalies on the whole systems. + +130 +00:08:17,000 --> 00:08:20,000 +Uh, that that the network IDs can. + +131 +00:08:20,000 --> 00:08:24,000 +So if there's something going on in this machine that doesn't flow around the network traffic, the + +132 +00:08:24,000 --> 00:08:25,000 +network IDs can, but this could. + +133 +00:08:26,000 --> 00:08:30,000 +Now, the disadvantage, it's always going to be more costly because it's a per device. + +134 +00:08:30,000 --> 00:08:35,000 +So if you have a 10,000 device imagine 10,000 times the cost of each of those things. + +135 +00:08:36,000 --> 00:08:40,000 +Lots of administrative attention on each machine can detect network attacks. + +136 +00:08:40,000 --> 00:08:49,000 +One of the problems I have with installing endpoint security, even though we need it with Hids in particular, + +137 +00:08:49,000 --> 00:08:51,000 +is because it just consumes a lot of resources. + +138 +00:08:51,000 --> 00:08:54,000 +It slows your machine down, not significantly, but it does. + +139 +00:08:54,000 --> 00:08:59,000 +If you're running high, intense applications and you really need all your power and you put that IDs + +140 +00:08:59,000 --> 00:09:01,000 +on there, you might want to up your Ram and CPU. + +141 +00:09:03,000 --> 00:09:05,000 +Easier for intrusion to to discover and disable. + +142 +00:09:05,000 --> 00:09:09,000 +And I h IDs because they're right on the machine. + +143 +00:09:09,000 --> 00:09:15,000 +With less security, the logs are maintained in the system, and that means that hackers can easily + +144 +00:09:15,000 --> 00:09:18,000 +manipulate it, especially if it's on one machine. + +145 +00:09:18,000 --> 00:09:20,000 +Your machine in particular. + +146 +00:09:21,000 --> 00:09:23,000 +Now the other one is going to be a network based idea. + +147 +00:09:23,000 --> 00:09:25,000 +So what exactly is that? + +148 +00:09:25,000 --> 00:09:30,000 +A network based IDs is not just a piece of software on a desktop. + +149 +00:09:30,000 --> 00:09:32,000 +A network based IDs is a computer. + +150 +00:09:32,000 --> 00:09:33,000 +Like if you have snort. + +151 +00:09:33,000 --> 00:09:34,000 +All right. + +152 +00:09:34,000 --> 00:09:36,000 +So if I open the calculator. + +153 +00:09:36,000 --> 00:09:44,000 +So for example if you have snort you would install snort on a computer. + +154 +00:09:44,000 --> 00:09:45,000 +All right. + +155 +00:09:45,000 --> 00:09:46,000 +Just a normal desktop. + +156 +00:09:46,000 --> 00:09:50,000 +And what you're going to do is you're just going to plug it in to the switch. + +157 +00:09:50,000 --> 00:09:55,000 +Now once you guys look at this diagram that I have here, here's how you would set up your network. + +158 +00:09:55,000 --> 00:09:58,000 +You would first take your switch. + +159 +00:09:58,000 --> 00:10:04,000 +You would install snort on a normal everyday computer, ideally a type of a server. + +160 +00:10:04,000 --> 00:10:08,000 +And you're going to do what's called port spanning Port Spanner or Port Marion. + +161 +00:10:08,000 --> 00:10:10,000 +What this means let me get the switch here. + +162 +00:10:10,000 --> 00:10:18,000 +So what this means is this you would have to go into the switch and you would select one of these ports + +163 +00:10:18,000 --> 00:10:19,000 +to be this port spanner. + +164 +00:10:19,000 --> 00:10:25,000 +Let's say you go with this port right here, the second port you would go into the switches configuration. + +165 +00:10:25,000 --> 00:10:28,000 +If you guys studied Cisco you'll be familiar with this. + +166 +00:10:28,000 --> 00:10:30,000 +If you go into the switch you would port span this switch. + +167 +00:10:30,000 --> 00:10:35,000 +And what's going to happen here is that all traffic that comes through the rest of these switches, + +168 +00:10:35,000 --> 00:10:40,000 +all these ports will be copied to this second port that I have here. + +169 +00:10:40,000 --> 00:10:43,000 +So what this is doing is that all traffic. + +170 +00:10:43,000 --> 00:10:49,000 +So let's say somebody is talking from this port here to this port, maybe this port to this port, this + +171 +00:10:49,000 --> 00:10:49,000 +port, to this port. + +172 +00:10:49,000 --> 00:10:50,000 +What? + +173 +00:10:50,000 --> 00:10:50,000 +It doesn't matter. + +174 +00:10:51,000 --> 00:10:55,000 +Okay, as all these ports are talking, traffic coming in and out, all these ports. + +175 +00:10:55,000 --> 00:11:01,000 +This switch is sending a copy of every single one of the frames to that port. + +176 +00:11:02,000 --> 00:11:03,000 +Now. + +177 +00:11:03,000 --> 00:11:04,000 +What happens then? + +178 +00:11:04,000 --> 00:11:11,000 +Well, what's going to happen then is that remember, the snort box is connected to that span port. + +179 +00:11:12,000 --> 00:11:19,000 +The snort box snorts up all of this traffic, analyzes it in its database, and it's going to be able + +180 +00:11:19,000 --> 00:11:24,000 +to tell you if there is some kind of intrusion on this machine, or this machine or that machine or + +181 +00:11:24,000 --> 00:11:26,000 +that segment and so on. + +182 +00:11:26,000 --> 00:11:28,000 +So it reads all the incoming packet. + +183 +00:11:28,000 --> 00:11:31,000 +It searches for any kind of suspicious patterns. + +184 +00:11:31,000 --> 00:11:34,000 +Uh, when threats are discovered based on the severity. + +185 +00:11:36,000 --> 00:11:37,000 +Uh, it will alert you now. + +186 +00:11:37,000 --> 00:11:40,000 +It cannot monitor encrypted. + +187 +00:11:40,000 --> 00:11:40,000 +It's going to be this one. + +188 +00:11:40,000 --> 00:11:41,000 +This. + +189 +00:11:41,000 --> 00:11:43,000 +It can't monitor encrypted traffic. + +190 +00:11:43,000 --> 00:11:49,000 +If you use a lot of encrypted traffic, it may not be able to see it harder for attackers to discover. + +191 +00:11:49,000 --> 00:11:55,000 +Have very little, little negative effect on traffic because it's just copying traffic over. + +192 +00:11:55,000 --> 00:12:00,000 +It's not like it's going to be flying extra traffic around the network now. + +193 +00:12:00,000 --> 00:12:06,000 +And Nids is like, snort, I think is something we should all have on our networks. + +194 +00:12:06,000 --> 00:12:06,000 +Why? + +195 +00:12:06,000 --> 00:12:08,000 +Because once again it's free. + +196 +00:12:08,000 --> 00:12:11,000 +Please install it if you don't have it now. + +197 +00:12:12,000 --> 00:12:13,000 +All right. + +198 +00:12:13,000 --> 00:12:14,000 +You're not really going to find many things. + +199 +00:12:14,000 --> 00:12:17,000 +That is pure ideas in today's world. + +200 +00:12:17,000 --> 00:12:22,000 +Today's world with all the unified devices that are out there, we're going to get some kind of an IP. + +201 +00:12:22,000 --> 00:12:24,000 +A snort is technically an IPS. + +202 +00:12:24,000 --> 00:12:26,000 +So what exactly is the IPS? + +203 +00:12:26,000 --> 00:12:28,000 +An IPS is an inline device. + +204 +00:12:28,000 --> 00:12:29,000 +I want you guys watch this diagram here. + +205 +00:12:29,000 --> 00:12:31,000 +So you see this firewall. + +206 +00:12:31,000 --> 00:12:35,000 +The IDs sits like a normal box off the firewall. + +207 +00:12:35,000 --> 00:12:39,000 +It grabs traffic to protect your internal network. + +208 +00:12:39,000 --> 00:12:46,000 +Notice the IPS technically is the firewall a lot of IPS like so this has an IPS built into it. + +209 +00:12:46,000 --> 00:12:49,000 +You just have to pay to enable its license. + +210 +00:12:49,000 --> 00:12:56,000 +So what an IPS does is that not only does it examine the traffic to detect intrusions, but if it finds + +211 +00:12:56,000 --> 00:13:01,000 +intrusions or problems, it prevents the vulnerabilities it prevents. + +212 +00:13:01,000 --> 00:13:08,000 +It can shut segments down, it can shut hoses off, it can choose what to forward and what to block. + +213 +00:13:08,000 --> 00:13:11,000 +So it prevents attacks from happening in your network. + +214 +00:13:11,000 --> 00:13:14,000 +So this is something important to consider. + +215 +00:13:14,000 --> 00:13:22,000 +IPS IPS is of course going to be better than an IDs system, but any which way. + +216 +00:13:22,000 --> 00:13:26,000 +Remember snort is free and it is an ID it is a network IPS. + +217 +00:13:26,000 --> 00:13:30,000 +If you go to the website and you look at it, you'll notice it says that. + +218 +00:13:30,000 --> 00:13:31,000 +All right. + +219 +00:13:31,000 --> 00:13:37,000 +To end this discussion, IDs IPS are mandatory devices in my opinion, on any network. + +220 +00:13:37,000 --> 00:13:39,000 +In my opinion, this is not for your exam. + +221 +00:13:39,000 --> 00:13:41,000 +I'm just telling you this from experience. + +222 +00:13:41,000 --> 00:13:47,000 +If you have a network that's more than ten computers, please put an IDs in just between me and you. + +223 +00:13:47,000 --> 00:13:49,000 +If you're installing snort, it doesn't need a lot of resources. + +224 +00:13:49,000 --> 00:13:53,000 +Use an old box, old computer you have in a corner. + +225 +00:13:53,000 --> 00:13:55,000 +Put an SSD into it. + +226 +00:13:55,000 --> 00:13:56,000 +Install snort, put Linux on it. + +227 +00:13:56,000 --> 00:13:58,000 +Do not install on windows. + +228 +00:13:58,000 --> 00:14:03,000 +It doesn't work really well and have some fun monitoring traffic and securing your network. + diff --git a/11 - Security Principles/011 Load Balancer OB 3.2_en.srt b/11 - Security Principles/011 Load Balancer OB 3.2_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..e715b591f59a3f59cfc343e1db9c19a9d62e0abc --- /dev/null +++ b/11 - Security Principles/011 Load Balancer OB 3.2_en.srt @@ -0,0 +1,380 @@ +1 +00:00:00,000 --> 00:00:07,000 +When you're building large networks, that's going to take in tens of thousands or millions of requests. + +2 +00:00:07,000 --> 00:00:13,000 +One critical device that you're going to need to set up is something we call a load balancer. + +3 +00:00:13,000 --> 00:00:15,000 +What exactly is it? + +4 +00:00:15,000 --> 00:00:15,000 +What? + +5 +00:00:15,000 --> 00:00:16,000 +I want to show you a picture of it. + +6 +00:00:16,000 --> 00:00:20,000 +Let's just jump a couple of slides around before we come back to it. + +7 +00:00:20,000 --> 00:00:24,000 +So I want you guys watch this particular diagram again. + +8 +00:00:24,000 --> 00:00:25,000 +We'll come back to this in a minute. + +9 +00:00:25,000 --> 00:00:29,000 +But what a load balancer does is exactly what it says it does. + +10 +00:00:29,000 --> 00:00:31,000 +It balances a load. + +11 +00:00:31,000 --> 00:00:37,000 +Let's say you have let's say these five computers each represents 1000 connections. + +12 +00:00:37,000 --> 00:00:39,000 +So right now you've got 5000 connections coming in. + +13 +00:00:39,000 --> 00:00:40,000 +You have a choice. + +14 +00:00:40,000 --> 00:00:44,000 +You can just have one single web server taking all the connections. + +15 +00:00:44,000 --> 00:00:48,000 +And if that server dies oh well every no more internet site for them. + +16 +00:00:48,000 --> 00:00:49,000 +Your sites down. + +17 +00:00:49,000 --> 00:00:51,000 +The best thing here is to get a load balancer. + +18 +00:00:51,000 --> 00:00:56,000 +What a load balancer does is that it distributes the load between two different servers. + +19 +00:00:56,000 --> 00:00:59,000 +So look at it right now it's given this one server. + +20 +00:00:59,000 --> 00:01:01,000 +It's computer one is getting this. + +21 +00:01:01,000 --> 00:01:03,000 +Then it's given this to computer two. + +22 +00:01:03,000 --> 00:01:05,000 +And when computer three comes in gives it to this one. + +23 +00:01:05,000 --> 00:01:09,000 +Computer four comes in gives it to this one, five comes in to this one. + +24 +00:01:09,000 --> 00:01:09,000 +Then six would go. + +25 +00:01:09,000 --> 00:01:15,000 +So it's going like this 123456789. + +26 +00:01:15,000 --> 00:01:16,000 +So what is it doing. + +27 +00:01:16,000 --> 00:01:18,000 +It's distributing the load between the machines. + +28 +00:01:18,000 --> 00:01:26,000 +That way one machine doesn't get all the load of the internet of the website requests is basically splitting + +29 +00:01:26,000 --> 00:01:27,000 +it 5050. + +30 +00:01:27,000 --> 00:01:33,000 +This of course helps to speed up the traffic on the speed up traffic hitting the system. + +31 +00:01:33,000 --> 00:01:34,000 +So what exactly is it? + +32 +00:01:34,000 --> 00:01:41,000 +Well, it's basically a device or software that evenly distributes network or application traffic across + +33 +00:01:41,000 --> 00:01:45,000 +multiple servers to prevent any single one of them from becoming overburdened. + +34 +00:01:45,000 --> 00:01:48,000 +It improves performance and reliability. + +35 +00:01:48,000 --> 00:01:48,000 +It makes it quick. + +36 +00:01:48,000 --> 00:01:52,000 +But if one of those servers die, your whole website doesn't go offline. + +37 +00:01:52,000 --> 00:01:56,000 +It does become slower because now one machine has to serve all of them. + +38 +00:01:56,000 --> 00:01:59,000 +Load balancers comes in different in two kinds. + +39 +00:01:59,000 --> 00:02:01,000 +You have a hardware and a software. + +40 +00:02:01,000 --> 00:02:06,000 +What I have here is a hardware load balancer from Barracuda, very famous device. + +41 +00:02:06,000 --> 00:02:13,000 +So a hardware load balancer is a physical device specifically designed for balancing the load. + +42 +00:02:13,000 --> 00:02:19,000 +They are more powerful, more expensive, and most of most of most of the load balancers we have today, + +43 +00:02:19,000 --> 00:02:23,000 +especially on large server farms, web server farms are going to be these kinds of devices. + +44 +00:02:23,000 --> 00:02:24,000 +You could do this. + +45 +00:02:25,000 --> 00:02:26,000 +With software. + +46 +00:02:27,000 --> 00:02:31,000 +So for example Windows Server supports this. + +47 +00:02:31,000 --> 00:02:33,000 +These are applications that can run on a standard hardware. + +48 +00:02:33,000 --> 00:02:37,000 +And cloud environments are more flexible and more cost effective. + +49 +00:02:37,000 --> 00:02:41,000 +Now when you set up a load balancer, there's basically two kinds of setups. + +50 +00:02:41,000 --> 00:02:44,000 +You have what's called active passive. + +51 +00:02:44,000 --> 00:02:46,000 +And the other one is called active active. + +52 +00:02:46,000 --> 00:02:47,000 +So what is exactly this one. + +53 +00:02:47,000 --> 00:02:53,000 +So active passive is this this is really not to improve performance. + +54 +00:02:53,000 --> 00:02:56,000 +This one is to improve reliability. + +55 +00:02:56,000 --> 00:02:58,000 +What this means is that what you do. + +56 +00:02:59,000 --> 00:03:07,000 +Is you're going to have one server take on all of the requests, all of them. + +57 +00:03:07,000 --> 00:03:11,000 +Maybe this is good for you because you don't have a lot of requests. + +58 +00:03:11,000 --> 00:03:16,000 +Maybe you have a really beefy server with a big line, and you don't need to split the request between + +59 +00:03:16,000 --> 00:03:16,000 +them. + +60 +00:03:16,000 --> 00:03:22,000 +It doesn't make sense, because the request you have is only utilized in a small percentage of resources + +61 +00:03:22,000 --> 00:03:23,000 +on the machine. + +62 +00:03:23,000 --> 00:03:25,000 +So what you do, you set up this thing called active passive. + +63 +00:03:25,000 --> 00:03:26,000 +So one machine is active. + +64 +00:03:26,000 --> 00:03:28,000 +It's taking all the requests. + +65 +00:03:28,000 --> 00:03:32,000 +And then if this machine fails then this one kicks in. + +66 +00:03:32,000 --> 00:03:33,000 +So this is a failover server. + +67 +00:03:33,000 --> 00:03:37,000 +So if the primary one fails the failover kicks in. + +68 +00:03:37,000 --> 00:03:40,000 +So it has to have some kind of failover mechanism between them. + +69 +00:03:40,000 --> 00:03:41,000 +So the switch knows it. + +70 +00:03:41,000 --> 00:03:47,000 +The hardware load balancer generally will knows it ideally for scenarios where uninterrupted service + +71 +00:03:47,000 --> 00:03:48,000 +is critical. + +72 +00:03:49,000 --> 00:03:53,000 +But you don't need the power of just two of them at the same time. + +73 +00:03:53,000 --> 00:03:57,000 +It provides a reliable backup in case a primary one fails. + +74 +00:03:57,000 --> 00:04:01,000 +So once again, if you just don't need that power, this is going to work out. + +75 +00:04:01,000 --> 00:04:08,000 +Now, if you have massive amounts of client traffic coming in and you have 50 servers set up there, + +76 +00:04:08,000 --> 00:04:13,000 +and you need all of your servers to be hammering out those requests, this is your thing here. + +77 +00:04:13,000 --> 00:04:14,000 +Both. + +78 +00:04:15,000 --> 00:04:21,000 +Load balancers are active in shared traffic simultaneously, so they're both sharing the traffic. + +79 +00:04:21,000 --> 00:04:26,000 +Traffic is distributed between two, generally two load balancers or different hoses. + +80 +00:04:26,000 --> 00:04:28,000 +Um they use something called round robin. + +81 +00:04:28,000 --> 00:04:29,000 +So you get it, then you get it. + +82 +00:04:29,000 --> 00:04:31,000 +So it'll be like you get it, then you get it, then you get it. + +83 +00:04:31,000 --> 00:04:34,000 +If there was three of them, it would be like, you get it, you get it, you get it. + +84 +00:04:34,000 --> 00:04:38,000 +Usage for high end traffic environments this year. + +85 +00:04:38,000 --> 00:04:42,000 +The big advantages here good capacity and reliability. + +86 +00:04:42,000 --> 00:04:48,000 +Now this could be done with multiple load balancers or it could be done with a single load balancer. + +87 +00:04:48,000 --> 00:04:51,000 +Although if you have multiple load balancers because if this device fails you're in trouble. + +88 +00:04:51,000 --> 00:04:56,000 +So you could have multiple load balancers uh, different forms. + +89 +00:04:56,000 --> 00:04:59,000 +Maybe each load balancer has ten machines. + +90 +00:04:59,000 --> 00:05:02,000 +There are different ways to set this up for your exam. + +91 +00:05:02,000 --> 00:05:04,000 +Just understand what a load balancer is. + +92 +00:05:04,000 --> 00:05:05,000 +It is what it says it is. + +93 +00:05:05,000 --> 00:05:07,000 +It distributes loads between machines. + +94 +00:05:07,000 --> 00:05:14,000 +Key reason for that is going to be because we want to not just distribute the traffic, but we want + +95 +00:05:14,000 --> 00:05:20,000 +the reliability in case one of those machines fail, it doesn't bring down the entire network. + diff --git a/11 - Security Principles/012 802.1x and EAP OB 3.2_en.srt b/11 - Security Principles/012 802.1x and EAP OB 3.2_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..5b538bc496ce708541d93e3968d1483918f8350a --- /dev/null +++ b/11 - Security Principles/012 802.1x and EAP OB 3.2_en.srt @@ -0,0 +1,356 @@ +1 +00:00:00,000 --> 00:00:00,000 +All right. + +2 +00:00:00,000 --> 00:00:02,000 +Take a look at the switch that I have here. + +3 +00:00:02,000 --> 00:00:03,000 +So we got this switch. + +4 +00:00:03,000 --> 00:00:07,000 +We plug you're going to plug your computer into my switch. + +5 +00:00:07,000 --> 00:00:10,000 +And you're going to be able to gain access to the network. + +6 +00:00:10,000 --> 00:00:17,000 +Or are you one of the just having a switch lying around is one of the worst things you can ever do. + +7 +00:00:17,000 --> 00:00:23,000 +If you're right now, if your switch is set up to the point where anyone can just walk in, plug a computer + +8 +00:00:23,000 --> 00:00:28,000 +into it, and gain full network access without any form of authentication. + +9 +00:00:28,000 --> 00:00:29,000 +That is bad news. + +10 +00:00:29,000 --> 00:00:36,000 +So what we want to do is we want to be able we put this down before it kills me here. + +11 +00:00:36,000 --> 00:00:41,000 +We want to be able to do what is called port security. + +12 +00:00:41,000 --> 00:00:43,000 +But what exactly is that? + +13 +00:00:43,000 --> 00:00:48,000 +So port security is used to secure network ports on computers and network devices, and particularly + +14 +00:00:48,000 --> 00:00:55,000 +switches guarding against on authorized access and insurance, secure communication. + +15 +00:00:55,000 --> 00:00:57,000 +This is more than likely going to be secured. + +16 +00:00:57,000 --> 00:01:03,000 +Network switch ports now generally, port security can also mean things like filtering ports through + +17 +00:01:03,000 --> 00:01:04,000 +TCP and UDP. + +18 +00:01:04,000 --> 00:01:05,000 +This is going to be done with like firewalls. + +19 +00:01:06,000 --> 00:01:10,000 +It's meant to stop unauthorized access to your network. + +20 +00:01:10,000 --> 00:01:15,000 +But in this particular video, what I want to talk about is not just filtering traffic through ports. + +21 +00:01:15,000 --> 00:01:17,000 +This is going to be done generally through a firewall. + +22 +00:01:17,000 --> 00:01:21,000 +I want to talk about the physical port security, like on this switch. + +23 +00:01:21,000 --> 00:01:28,000 +And in particular there's two terms that we want to be familiar with something called 821 X and EAP + +24 +00:01:28,000 --> 00:01:31,000 +or Extensible Authentication Protocol. + +25 +00:01:31,000 --> 00:01:32,000 +Let me explain what this is to you. + +26 +00:01:32,000 --> 00:01:36,000 +So 821 x you have to come into the switch and enable these things. + +27 +00:01:36,000 --> 00:01:40,000 +You you configure the ports on the switch and you enable this. + +28 +00:01:40,000 --> 00:01:42,000 +This is an IEEE standard. + +29 +00:01:43,000 --> 00:01:44,000 +For port. + +30 +00:01:44,000 --> 00:01:46,000 +Port based access control. + +31 +00:01:46,000 --> 00:01:50,000 +It's used to authenticate device that are attempting to connect to your LAN. + +32 +00:01:50,000 --> 00:01:53,000 +And you can also do this for your wireless connection. + +33 +00:01:53,000 --> 00:01:59,000 +Also not just for your wired switch, but you can also enable it on your wireless. + +34 +00:01:59,000 --> 00:02:00,000 +Here's how it works. + +35 +00:02:00,000 --> 00:02:06,000 +When a device attempts to connect to a network that's that has 801 enabled, the authenticator blocks + +36 +00:02:06,000 --> 00:02:11,000 +all traffic except the 8021, and the client is authenticated. + +37 +00:02:11,000 --> 00:02:12,000 +Now I want to show you guys something. + +38 +00:02:12,000 --> 00:02:14,000 +I have a diagram of this from Wikipedia. + +39 +00:02:15,000 --> 00:02:21,000 +So when you want to connect to a network, notice the switch that is going to be utilizing. + +40 +00:02:22,000 --> 00:02:24,000 +That's going to be utilizing 801 x. + +41 +00:02:24,000 --> 00:02:31,000 +So what you do is you configure the switch to say if the computer does not authenticate and go through + +42 +00:02:31,000 --> 00:02:34,000 +8 to 1 x, we're not going to allow you access in. + +43 +00:02:34,000 --> 00:02:37,000 +So it only accepts that kind of access. + +44 +00:02:37,000 --> 00:02:38,000 +So here's how it works. + +45 +00:02:39,000 --> 00:02:40,000 +The supplicant is you. + +46 +00:02:40,000 --> 00:02:41,000 +That's the user. + +47 +00:02:41,000 --> 00:02:44,000 +You connect to the switch and you're trying to gain access to the network. + +48 +00:02:44,000 --> 00:02:51,000 +But before the switch can grant you access to the LAN resources, what you have to do, you have to + +49 +00:02:51,000 --> 00:02:55,000 +send a request to the authenticator to switch. + +50 +00:02:55,000 --> 00:03:00,000 +The authenticator then sends that request to an authentication server. + +51 +00:03:00,000 --> 00:03:04,000 +That authentication server is going to authenticate you username password. + +52 +00:03:04,000 --> 00:03:08,000 +It can do a variety of different things certificate based authentication. + +53 +00:03:08,000 --> 00:03:10,000 +So there's many different ways it can do this. + +54 +00:03:10,000 --> 00:03:16,000 +You can use a Radius server something we'll cover in another class in another video when the when the + +55 +00:03:16,000 --> 00:03:23,000 +authentication server said it's okay, then the authenticator tells you and then you can access resources. + +56 +00:03:24,000 --> 00:03:29,000 +Now the supplicant I just mentioned to you, you send the credential to the authenticator, which forwards + +57 +00:03:29,000 --> 00:03:30,000 +them to the authentication server. + +58 +00:03:30,000 --> 00:03:34,000 +And the authentication server is something that's going to run like a Radius server. + +59 +00:03:34,000 --> 00:03:39,000 +If the server approves it, it gives you access and then you can access the network. + +60 +00:03:39,000 --> 00:03:42,000 +Now you notice I have these things called EAP here. + +61 +00:03:42,000 --> 00:03:46,000 +See that EAP stands for Extensible Authentication Protocol. + +62 +00:03:46,000 --> 00:03:50,000 +You are authenticating to a particular device. + +63 +00:03:50,000 --> 00:03:53,000 +This here is this is the protocol that's going to allow that. + +64 +00:03:54,000 --> 00:03:56,000 +It's a framework frequently used in network access. + +65 +00:03:57,000 --> 00:03:58,000 +All right. + +66 +00:03:58,000 --> 00:04:02,000 +It's designed to support multiple authentication passwords, tokens, certificates. + +67 +00:04:02,000 --> 00:04:07,000 +So if you want to authenticate to my network and you plug a computer into my switch. + +68 +00:04:08,000 --> 00:04:11,000 +You're going to have to provide either some kind of certificate. + +69 +00:04:11,000 --> 00:04:13,000 +You can use tokens. + +70 +00:04:14,000 --> 00:04:15,000 +Uh, certificates is a good one. + +71 +00:04:15,000 --> 00:04:16,000 +I like that one. + +72 +00:04:17,000 --> 00:04:19,000 +The worst, of course, is passwords. + +73 +00:04:19,000 --> 00:04:21,000 +This thing is widely used. + +74 +00:04:21,000 --> 00:04:25,000 +It's mostly it was widely used in PGP or point to point connections. + +75 +00:04:26,000 --> 00:04:26,000 +Um. + +76 +00:04:27,000 --> 00:04:34,000 +But it's a lot of time now using 821 X, and it's used generally in conjunction with a Radius server + +77 +00:04:34,000 --> 00:04:35,000 +to centralize authentication. + +78 +00:04:35,000 --> 00:04:40,000 +That way you can have tons of switches all foward to a single. + +79 +00:04:41,000 --> 00:04:44,000 +Authentication server like a radius. + +80 +00:04:45,000 --> 00:04:47,000 +Why would you want this? + +81 +00:04:47,000 --> 00:04:47,000 +Right? + +82 +00:04:47,000 --> 00:04:48,000 +You think about this. + +83 +00:04:49,000 --> 00:04:53,000 +One of the worst things that can happen to somebody walking into a network and just plug a computer + +84 +00:04:53,000 --> 00:04:57,000 +into your to plug a computer into your network, gain all your network access. + +85 +00:04:57,000 --> 00:04:59,000 +That would severely suck. + +86 +00:04:59,000 --> 00:05:01,000 +The best thing to do is to have this on your network. + +87 +00:05:01,000 --> 00:05:07,000 +Now, it's not difficult to set up, but it is more setup that needs to get done. + +88 +00:05:07,000 --> 00:05:12,000 +That way, when somebody plugs a computer into your network, you're 100% sure this person actually + +89 +00:05:12,000 --> 00:05:14,000 +belongs in the network. + diff --git a/11 - Security Principles/013 Firewalls OB 3.2_en.srt b/11 - Security Principles/013 Firewalls OB 3.2_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..fe305010615fa92e09f5779ffb91cc9a00efb41b --- /dev/null +++ b/11 - Security Principles/013 Firewalls OB 3.2_en.srt @@ -0,0 +1,520 @@ +1 +00:00:00,000 --> 00:00:04,000 +In this course, I discussed a lot of different ways to secure a network. + +2 +00:00:04,000 --> 00:00:11,000 +But when it comes to network security, Network Security 101 is a firewall. + +3 +00:00:11,000 --> 00:00:17,000 +And in this video we're going to talk about firewalls in particularly like this little firewall that + +4 +00:00:17,000 --> 00:00:19,000 +I have right here. + +5 +00:00:19,000 --> 00:00:19,000 +All right. + +6 +00:00:19,000 --> 00:00:20,000 +That one has two USBs. + +7 +00:00:20,000 --> 00:00:21,000 +This one doesn't. + +8 +00:00:21,000 --> 00:00:23,000 +All right let's get started with different kinds of firewall. + +9 +00:00:23,000 --> 00:00:26,000 +And I'm going to explain to you that this is an next generation firewall. + +10 +00:00:26,000 --> 00:00:28,000 +And what makes this one unique. + +11 +00:00:28,000 --> 00:00:29,000 +Let's get started. + +12 +00:00:30,000 --> 00:00:36,000 +When it comes to basic network security, one of the most basic things you've got to have on a computer + +13 +00:00:37,000 --> 00:00:38,000 +or on a network is a firewall. + +14 +00:00:38,000 --> 00:00:44,000 +Now firewalls comes in to basically going to come in two main designs. + +15 +00:00:44,000 --> 00:00:48,000 +You have, uh, host based firewalls and network firewalls. + +16 +00:00:48,000 --> 00:00:49,000 +This is a network firewall. + +17 +00:00:49,000 --> 00:00:55,000 +You have a host based firewall that's installed on your physical box, like on your your desktop, like + +18 +00:00:55,000 --> 00:00:56,000 +Windows Firewall. + +19 +00:00:56,000 --> 00:00:59,000 +Now, what exactly is it? + +20 +00:00:59,000 --> 00:01:02,000 +Well, a network security system, it's basically a network. + +21 +00:01:02,000 --> 00:01:05,000 +The monitors and controls incoming and outgoing network traffic. + +22 +00:01:05,000 --> 00:01:10,000 +Whether that's coming into your host or coming into your network, typically establishes a barrier between + +23 +00:01:10,000 --> 00:01:14,000 +a trusted, secure internal network and an outside external network. + +24 +00:01:14,000 --> 00:01:19,000 +So if it's a network, if it's a network based firewall, they're talking about this one here has a + +25 +00:01:19,000 --> 00:01:20,000 +Wang port. + +26 +00:01:22,000 --> 00:01:27,000 +Anything connected here would be considered on the public side, and anything connected here, the land + +27 +00:01:27,000 --> 00:01:29,000 +port would be considered good traffic. + +28 +00:01:29,000 --> 00:01:32,000 +Now it's implemented in hardware and software. + +29 +00:01:32,000 --> 00:01:35,000 +So obviously this is an appliance that we would have. + +30 +00:01:35,000 --> 00:01:41,000 +Of course you would have software firewalls like something uh, that you would install like like Windows + +31 +00:01:41,000 --> 00:01:41,000 +Firewall. + +32 +00:01:41,000 --> 00:01:42,000 +That's a good example. + +33 +00:01:42,000 --> 00:01:46,000 +But you can also have like Symantec's or Broadcom endpoint, McAfee endpoint. + +34 +00:01:46,000 --> 00:01:49,000 +These will generally come with software based firewalls. + +35 +00:01:49,000 --> 00:01:54,000 +They're going to enforce a security policy like allow or disallow these kinds of traffic. + +36 +00:01:54,000 --> 00:01:58,000 +They control the flow of traffic does not differentiate data versus command. + +37 +00:01:58,000 --> 00:02:02,000 +It just doesn't know whether something is a command or a particular data. + +38 +00:02:02,000 --> 00:02:06,000 +So it might be difficult to detect that controls the flow of traffic. + +39 +00:02:06,000 --> 00:02:10,000 +Um, controls the flow of traffic between hosts and network. + +40 +00:02:10,000 --> 00:02:16,000 +Now, there are different kinds of firewalls that we want to be familiar with for our exam. + +41 +00:02:16,000 --> 00:02:23,000 +The first kind of firewall that came out when I was a little boy was packet filtering firewalls. + +42 +00:02:23,000 --> 00:02:26,000 +And these things are not firewalls, they were just routers. + +43 +00:02:26,000 --> 00:02:32,000 +When an access control list, they were subject to many kinds of attacks and they do not exist today. + +44 +00:02:33,000 --> 00:02:37,000 +Today we're all stateful packet inspection. + +45 +00:02:37,000 --> 00:02:38,000 +This was known as stateless. + +46 +00:02:38,000 --> 00:02:43,000 +The reason for this is because this type of firewall didn't know traffic that left. + +47 +00:02:43,000 --> 00:02:46,000 +So it was subject to something called source routing. + +48 +00:02:46,000 --> 00:02:49,000 +Once again, this thing doesn't really exist. + +49 +00:02:49,000 --> 00:02:54,000 +All firewalls today and all the firewalls that I'm going to be talking about, such as web application + +50 +00:02:54,000 --> 00:03:04,000 +firewalls, utms, and next gen firewalls are all based on stateful packet inspection or Spice or stateful + +51 +00:03:04,000 --> 00:03:05,000 +inspection firewalls. + +52 +00:03:05,000 --> 00:03:08,000 +This is the most they're more advanced than packet filtering. + +53 +00:03:08,000 --> 00:03:09,000 +They keep a track. + +54 +00:03:09,000 --> 00:03:12,000 +They have a state table of who left and who's coming back in. + +55 +00:03:12,000 --> 00:03:19,000 +They're incredibly popular on all firewall technology, including what I have here is based on it now. + +56 +00:03:20,000 --> 00:03:26,000 +One kind of firewall that is popular if you're hosting web servers is going to be something called a + +57 +00:03:26,000 --> 00:03:29,000 +WAF or a web application firewall. + +58 +00:03:29,000 --> 00:03:34,000 +The design to protect web applications by filtering and monitoring web traffic. + +59 +00:03:34,000 --> 00:03:39,000 +Let me show you guys a particular diagram from a very famous company called Akamai. + +60 +00:03:39,000 --> 00:03:42,000 +So imagine you have a web for a web server farm. + +61 +00:03:42,000 --> 00:03:43,000 +All right. + +62 +00:03:43,000 --> 00:03:44,000 +All these are all your web servers. + +63 +00:03:44,000 --> 00:03:51,000 +You have all kinds of end users coming through the internet to get to your web server. + +64 +00:03:51,000 --> 00:03:59,000 +You put the web application firewall between you and the public, any kind of negative traffic that + +65 +00:03:59,000 --> 00:04:06,000 +is attempting to hit your web servers, things such as SQL injection, cross site scripting, session + +66 +00:04:06,000 --> 00:04:11,000 +hijacking, anything that's negative that's going to attempt to hit your. + +67 +00:04:12,000 --> 00:04:14,000 +Hit your, uh, your web server. + +68 +00:04:14,000 --> 00:04:16,000 +This thing is going to stop. + +69 +00:04:16,000 --> 00:04:20,000 +So this is really important if you're running web applications. + +70 +00:04:21,000 --> 00:04:23,000 +Uh, they operate at the application layer. + +71 +00:04:23,000 --> 00:04:24,000 +The rules are customized. + +72 +00:04:24,000 --> 00:04:26,000 +They're generally could be a hardware or software. + +73 +00:04:26,000 --> 00:04:31,000 +But a lot of times now, being that a lot of people have all their web servers are in the cloud, they're + +74 +00:04:31,000 --> 00:04:33,000 +probably going to be part of a cloud service. + +75 +00:04:34,000 --> 00:04:38,000 +Now, the other two confuses a lot of folks. + +76 +00:04:38,000 --> 00:04:41,000 +And I'll tell you the difference between them, because as I go through them, they're going to sound + +77 +00:04:41,000 --> 00:04:42,000 +alike. + +78 +00:04:42,000 --> 00:04:50,000 +Unified threat management systems are this this, by the way, is is this one this is an NDF w. + +79 +00:04:51,000 --> 00:04:55,000 +So if you go to Sonicwall and you look up Sonicwall firewalls, you'll see this this big across the + +80 +00:04:55,000 --> 00:04:58,000 +top next generation firewalls. + +81 +00:04:58,000 --> 00:04:59,000 +But what exactly is this one now? + +82 +00:04:59,000 --> 00:05:00,000 +Utms. + +83 +00:05:00,000 --> 00:05:07,000 +This is a great this is a big comprehensive solution that includes things like antivirus, anti-spyware, + +84 +00:05:07,000 --> 00:05:11,000 +firewalls, intrusion detections, preventions, and content filtering. + +85 +00:05:12,000 --> 00:05:13,000 +They're easy to use. + +86 +00:05:13,000 --> 00:05:14,000 +They're very. + +87 +00:05:14,000 --> 00:05:20,000 +They come pre-built with many policies ideal for small to mid sized business. + +88 +00:05:20,000 --> 00:05:22,000 +Now it's going to sound the same. + +89 +00:05:22,000 --> 00:05:24,000 +Okay, I'm just giving you a heads up now. + +90 +00:05:24,000 --> 00:05:28,000 +Far more advanced than traditional firewalls include functionalities. + +91 +00:05:28,000 --> 00:05:29,000 +Deep packet inspection. + +92 +00:05:29,000 --> 00:05:36,000 +They include intrusion prevention systems application awareness deep packet inspection. + +93 +00:05:36,000 --> 00:05:39,000 +They can actually see within the packet good threat intelligence. + +94 +00:05:39,000 --> 00:05:44,000 +They will also come with antivirus, anti-spyware firewall, intrusion detection, prevention system + +95 +00:05:44,000 --> 00:05:46,000 +and content filtering. + +96 +00:05:46,000 --> 00:05:50,000 +These two things sound very much alike. + +97 +00:05:50,000 --> 00:05:55,000 +Now, if you are a small business and you just want something to take out the box and you just plug + +98 +00:05:55,000 --> 00:05:58,000 +it in and it comes with a great set of policies. + +99 +00:05:58,000 --> 00:06:01,000 +UTM is easy to manage and it comes with most policies. + +100 +00:06:01,000 --> 00:06:07,000 +If you're looking for something more customizable to best match your business needs, then you get the + +101 +00:06:07,000 --> 00:06:08,000 +Ngfw. + +102 +00:06:08,000 --> 00:06:11,000 +These particular are the engine firewalls. + +103 +00:06:11,000 --> 00:06:18,000 +The engine firewalls are much more customizable, more robust than the Utms. + +104 +00:06:19,000 --> 00:06:20,000 +Okay, so keep that in mind. + +105 +00:06:20,000 --> 00:06:22,000 +The difference is customization. + +106 +00:06:22,000 --> 00:06:26,000 +One is just really more customization than others. + +107 +00:06:26,000 --> 00:06:27,000 +Okay. + +108 +00:06:27,000 --> 00:06:29,000 +Great discussion on firewalls. + +109 +00:06:29,000 --> 00:06:36,000 +Now I'm not sure if you guys remember the OSI model from previous classes, but one of the things that + +110 +00:06:36,000 --> 00:06:42,000 +we should be familiar with is where firewalls operate layer four and layer seven. + +111 +00:06:42,000 --> 00:06:49,000 +So layer four firewalls focus on data transport because they operate at the transport layer, the control + +112 +00:06:49,000 --> 00:06:50,000 +traffic based on TCP, UDP. + +113 +00:06:51,000 --> 00:06:54,000 +You got to remember something at the basic level. + +114 +00:06:54,000 --> 00:06:56,000 +All firewalls do one thing. + +115 +00:06:56,000 --> 00:07:03,000 +They block ports at the most conceptual level of firewall should block ports and ports operate at layer + +116 +00:07:03,000 --> 00:07:06,000 +four, your transport layer, not your network layer. + +117 +00:07:06,000 --> 00:07:08,000 +That's going to be IP. + +118 +00:07:09,000 --> 00:07:16,000 +Now, if the firewall can read into the application and stop certain traffic based on things like a + +119 +00:07:16,000 --> 00:07:22,000 +URL, this is going to be a layer four firewall inspects the content of the traffic there, make more + +120 +00:07:22,000 --> 00:07:26,000 +informed pretty much decisions, so keep that in mind. + +121 +00:07:26,000 --> 00:07:28,000 +Now application. + +122 +00:07:28,000 --> 00:07:34,000 +Anytime you hear the terms application firewall that is considered application firewall is considered + +123 +00:07:34,000 --> 00:07:35,000 +a layer seven. + +124 +00:07:35,000 --> 00:07:37,000 +Because remember layer seven is application. + +125 +00:07:37,000 --> 00:07:41,000 +But generally if the exam doesn't specify anything it says what layer is a firewall. + +126 +00:07:41,000 --> 00:07:42,000 +It's layer four. + +127 +00:07:42,000 --> 00:07:46,000 +Unless they say something like web application firewall. + +128 +00:07:46,000 --> 00:07:51,000 +Uh, by the way, proxy servers are also a type of a firewall. + +129 +00:07:51,000 --> 00:07:54,000 +And that's a proxy server is a layer seven device. + +130 +00:07:54,000 --> 00:07:58,000 +So keep that in mind in case you got a question about that on your test. + diff --git a/11 - Security Principles/014 VPN OB 3.2_en.srt b/11 - Security Principles/014 VPN OB 3.2_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..a83190783617ae7e4df75a2d666f016076af1a19 --- /dev/null +++ b/11 - Security Principles/014 VPN OB 3.2_en.srt @@ -0,0 +1,672 @@ +1 +00:00:00,000 --> 00:00:03,000 +One very popular thing to do today is to work from home. + +2 +00:00:03,000 --> 00:00:07,000 +Maybe you're doing that right now, or maybe you're looking for a job to work from home. + +3 +00:00:07,000 --> 00:00:14,000 +The technology that allows work from home, that allows you to connect to a corporate network and utilize + +4 +00:00:14,000 --> 00:00:19,000 +all the corporate network resources, is called a VPN. + +5 +00:00:19,000 --> 00:00:20,000 +So what exactly is that? + +6 +00:00:21,000 --> 00:00:23,000 +Well, here's what it is. + +7 +00:00:23,000 --> 00:00:28,000 +A VPN is a technology that creates an encrypted connection over a less secure network. + +8 +00:00:28,000 --> 00:00:34,000 +It builds on top of an existing physical network, provides a connection mechanism between you and that + +9 +00:00:34,000 --> 00:00:38,000 +corporate network, generally across a public network such as the internet. + +10 +00:00:38,000 --> 00:00:41,000 +It allows secure connection between endpoints. + +11 +00:00:41,000 --> 00:00:48,000 +Basically, it's going to allow employees to securely access corporate intranet or internal resources + +12 +00:00:48,000 --> 00:00:50,000 +can securely connect. + +13 +00:00:50,000 --> 00:00:53,000 +It can even connect global offices together. + +14 +00:00:53,000 --> 00:00:56,000 +And it provides a connection over the public internet. + +15 +00:00:56,000 --> 00:00:58,000 +Now let me give you some good examples of this. + +16 +00:00:58,000 --> 00:01:01,000 +So I use VPNs quite often. + +17 +00:01:01,000 --> 00:01:03,000 +In fact, I work from home quite a lot. + +18 +00:01:03,000 --> 00:01:07,000 +When I'm at home, I want to be able to access the server at work. + +19 +00:01:07,000 --> 00:01:11,000 +That server at work has a database with all the students and the information for the school. + +20 +00:01:11,000 --> 00:01:16,000 +It has a file server for different documents that I need access to so I could stay home. + +21 +00:01:16,000 --> 00:01:20,000 +I connect to my workplace VPN and then it's like I'm sitting there. + +22 +00:01:20,000 --> 00:01:27,000 +I have access to every single thing in the actual network to have a bunch of locations. + +23 +00:01:27,000 --> 00:01:30,000 +For example, we have a location in Long Island, New York and Manhattan. + +24 +00:01:31,000 --> 00:01:33,000 +In New York City, Midtown Manhattan. + +25 +00:01:33,000 --> 00:01:40,000 +We connect these two locations with a VPN, so folks in Manhattan can share data with folks in Long + +26 +00:01:40,000 --> 00:01:41,000 +Island. + +27 +00:01:41,000 --> 00:01:43,000 +So VPNs are pretty robust. + +28 +00:01:43,000 --> 00:01:49,000 +You can use it as a user access VPN, like I'm using it to connect to my workplace, or you can use + +29 +00:01:49,000 --> 00:01:51,000 +it to connect different sites together. + +30 +00:01:51,000 --> 00:01:52,000 +Now. + +31 +00:01:54,000 --> 00:01:55,000 +Take a look at this here. + +32 +00:01:55,000 --> 00:01:58,000 +This here is called a site to site VPN. + +33 +00:01:58,000 --> 00:01:59,000 +This is like site one. + +34 +00:01:59,000 --> 00:02:02,000 +Could be like our new Manhattan site. + +35 +00:02:02,000 --> 00:02:05,000 +Site two could be like our Long Island site. + +36 +00:02:05,000 --> 00:02:09,000 +And notice it's going across the internet utilizing VPN devices. + +37 +00:02:09,000 --> 00:02:11,000 +What would you say would do that? + +38 +00:02:11,000 --> 00:02:14,000 +This is what we use to do our VPN. + +39 +00:02:14,000 --> 00:02:16,000 +Our Sonicwall is our VPN buddy. + +40 +00:02:16,000 --> 00:02:21,000 +We set up the VPN on this device, and I'm going to go through some of the technology that this thing + +41 +00:02:21,000 --> 00:02:22,000 +uses. + +42 +00:02:22,000 --> 00:02:29,000 +This thing uses IPsec is what it utilizes to create a tunnel between the two endpoints. + +43 +00:02:29,000 --> 00:02:32,000 +And we'll describe what that is coming up in a few minutes. + +44 +00:02:32,000 --> 00:02:33,000 +So. + +45 +00:02:33,000 --> 00:02:37,000 +This type of VPN is a virtual point to point connection. + +46 +00:02:38,000 --> 00:02:45,000 +All right through and it encapsulate the data, virtual encapsulation of the data to the untrusted internet. + +47 +00:02:45,000 --> 00:02:47,000 +So it's all encrypted. + +48 +00:02:47,000 --> 00:02:48,000 +How does it do it? + +49 +00:02:48,000 --> 00:02:50,000 +Well, it does it by tunnelling. + +50 +00:02:51,000 --> 00:02:51,000 +All right. + +51 +00:02:51,000 --> 00:02:56,000 +Tunneling means that it encapsulate all the packets inside of something else. + +52 +00:02:57,000 --> 00:03:00,000 +When it comes to tunneling, they're basically two tunnels. + +53 +00:03:00,000 --> 00:03:06,000 +VPNs utilizes in today's world to transport confidential companies data. + +54 +00:03:06,000 --> 00:03:13,000 +We're going to utilize either a TLS tunnel or we're going to be using L2, TCP with IPsec tunnels. + +55 +00:03:13,000 --> 00:03:14,000 +All right. + +56 +00:03:14,000 --> 00:03:17,000 +Those are going to be the two tunnels that we're going to be needing to know. + +57 +00:03:19,000 --> 00:03:26,000 +So the first thing I want to show you is what's called an LL2MLS tunnel or SSL tunnels. + +58 +00:03:26,000 --> 00:03:33,000 +These are tunnels or tunnels that are set up utilizing TLS, SSL, the operator layer four of the OSI + +59 +00:03:33,000 --> 00:03:34,000 +model. + +60 +00:03:34,000 --> 00:03:40,000 +Now, if you remember from cryptography or if you haven't watched that section yet, go through it. + +61 +00:03:40,000 --> 00:03:43,000 +In cryptography, I go through the whole SSL handshake with you. + +62 +00:03:43,000 --> 00:03:44,000 +It's very secure. + +63 +00:03:44,000 --> 00:03:47,000 +We are using SSL all the time. + +64 +00:03:47,000 --> 00:03:50,000 +Every website you go to is protected with SSL. + +65 +00:03:50,000 --> 00:03:56,000 +What we're doing is we're encapsulating the VPN traffic or tunneling it into an SSL. + +66 +00:03:56,000 --> 00:03:59,000 +Now we're going to use this for encryption. + +67 +00:03:59,000 --> 00:04:01,000 +No need to open any additional ports. + +68 +00:04:01,000 --> 00:04:05,000 +Mostly use on user access VPN. + +69 +00:04:05,000 --> 00:04:06,000 +Now what does that mean. + +70 +00:04:06,000 --> 00:04:11,000 +These are going to be VPNs that you use to access a corporate network, not necessarily between site + +71 +00:04:11,000 --> 00:04:19,000 +to site, like my Manhattan location to our Long Island location, maybe just a website or access to + +72 +00:04:19,000 --> 00:04:26,000 +a client that needs access to a client that needs to be installed, something like OpenVPN we also use + +73 +00:04:26,000 --> 00:04:29,000 +as a client, but things like Sonicwall. + +74 +00:04:30,000 --> 00:04:32,000 +Has SSL based VPNs. + +75 +00:04:32,000 --> 00:04:35,000 +And with that, I'm going to show you guys what that looks like. + +76 +00:04:35,000 --> 00:04:39,000 +There's a link there that you guys can try that I have already opened for you. + +77 +00:04:39,000 --> 00:04:41,000 +So when you went to that link. + +78 +00:04:42,000 --> 00:04:43,000 +Uh, I want to show you. + +79 +00:04:43,000 --> 00:04:44,000 +Oh, here we go. + +80 +00:04:44,000 --> 00:04:46,000 +So when you guys went to that link. + +81 +00:04:48,000 --> 00:04:50,000 +This is a demo of their SSL based VPN. + +82 +00:04:50,000 --> 00:04:55,000 +So you would just view the demo and it's going to log you into the VPN. + +83 +00:04:55,000 --> 00:04:58,000 +So this is actually what what it looks like. + +84 +00:04:58,000 --> 00:05:00,000 +It doesn't want to work here for us. + +85 +00:05:00,000 --> 00:05:03,000 +Hopefully this works for us. + +86 +00:05:04,000 --> 00:05:06,000 +All right demo let's log in. + +87 +00:05:06,000 --> 00:05:07,000 +You just demo. + +88 +00:05:07,000 --> 00:05:08,000 +And the password is like password. + +89 +00:05:08,000 --> 00:05:10,000 +It puts it there for you. + +90 +00:05:10,000 --> 00:05:11,000 +So this is a VPN. + +91 +00:05:11,000 --> 00:05:13,000 +This is an SSL based VPN. + +92 +00:05:13,000 --> 00:05:18,000 +And basically I have access to things like a file share on their network. + +93 +00:05:18,000 --> 00:05:21,000 +And I can go in and I can access particular files. + +94 +00:05:21,000 --> 00:05:25,000 +As you can see, uh, I can go in and, um. + +95 +00:05:26,000 --> 00:05:27,000 +What else more we have here. + +96 +00:05:27,000 --> 00:05:30,000 +RDP to a particular computer. + +97 +00:05:30,000 --> 00:05:33,000 +Let's say we know what is going to log me into one of their systems. + +98 +00:05:33,000 --> 00:05:37,000 +So now look, I'm logging in to a system on their network. + +99 +00:05:38,000 --> 00:05:40,000 +This is all done through the web browser, right? + +100 +00:05:40,000 --> 00:05:42,000 +This is all done. + +101 +00:05:42,000 --> 00:05:43,000 +This is a computer. + +102 +00:05:43,000 --> 00:05:43,000 +It's already logged in. + +103 +00:05:43,000 --> 00:05:45,000 +Is this that screen? + +104 +00:05:45,000 --> 00:05:45,000 +See? + +105 +00:05:46,000 --> 00:05:50,000 +Yeah, it's a really old system that Sonic was given the demo on old server here. + +106 +00:05:50,000 --> 00:05:52,000 +So let me close this out. + +107 +00:05:53,000 --> 00:05:55,000 +So you can access Outlook Web access. + +108 +00:05:55,000 --> 00:05:58,000 +So it's just a demo that you can set up. + +109 +00:05:58,000 --> 00:06:00,000 +Now this is great. + +110 +00:06:00,000 --> 00:06:05,000 +If you set up a VPN like this, there's really nothing for no one to install. + +111 +00:06:05,000 --> 00:06:11,000 +It's heavily secured because it runs on TLS, which is pretty much the standards of all internet security. + +112 +00:06:11,000 --> 00:06:17,000 +Now let's talk of another kind of implementation we can implement. + +113 +00:06:17,000 --> 00:06:20,000 +And that's going to be what's called L2 Tpns. + +114 +00:06:20,000 --> 00:06:25,000 +L2 Tpns are layer two tunneling protocol. + +115 +00:06:25,000 --> 00:06:32,000 +These are kind of VPNs that were basically a hybrid of what was called L2 f and an older one called + +116 +00:06:32,000 --> 00:06:32,000 +PCP. + +117 +00:06:33,000 --> 00:06:34,000 +It's basically a point to point tunnel. + +118 +00:06:34,000 --> 00:06:40,000 +And it utilizes something called IPsec in order to encrypt your data, which we'll talk about in a minute. + +119 +00:06:40,000 --> 00:06:47,000 +It supports all types of radius are used on like windows boxes or Texas for, uh, Cisco boxes. + +120 +00:06:47,000 --> 00:06:51,000 +Now, IPsec is something you want to be familiar with for your exam. + +121 +00:06:51,000 --> 00:06:58,000 +Instead of using something such as TLS to secure your VPN, you can use IPsec. + +122 +00:06:58,000 --> 00:07:01,000 +IPsec is a standalone VPN protocol. + +123 +00:07:01,000 --> 00:07:09,000 +It's the main security anytime you set up L2tpv3, L2, TCP based VPNs, which you could do on my Sonicwall, + +124 +00:07:09,000 --> 00:07:11,000 +you're going to use IPsec. + +125 +00:07:11,000 --> 00:07:16,000 +IPsec comes in a variety of different components that you want to be familiar with for your exam. + +126 +00:07:16,000 --> 00:07:18,000 +If you're asking, what the hell is all this? + +127 +00:07:18,000 --> 00:07:26,000 +Well, when you set it up on the firewall on your VPN devices, particularly things like VPN concentrators, + +128 +00:07:26,000 --> 00:07:32,000 +when you set these things up, like on a VPN concentrator, especially IPsec, you have to determine, + +129 +00:07:32,000 --> 00:07:35,000 +do you want to set it up with RH or ESP? + +130 +00:07:35,000 --> 00:07:40,000 +Ideally, you'll do both RH if you configure this, provides authentication. + +131 +00:07:41,000 --> 00:07:44,000 +Integrity and non-repudiation of the data. + +132 +00:07:44,000 --> 00:07:48,000 +That's important because you don't want anybody to log in authentication. + +133 +00:07:48,000 --> 00:07:52,000 +You want to check if the data was modified and you want to be verified where the data is coming from. + +134 +00:07:53,000 --> 00:07:57,000 +E does not support, uh, encryption of the data. + +135 +00:07:57,000 --> 00:08:02,000 +It doesn't support confidentiality of data that's going to be encapsulating security payload. + +136 +00:08:02,000 --> 00:08:03,000 +So make sure you enable both boxes. + +137 +00:08:03,000 --> 00:08:06,000 +In fact, when you set up a VPN, these two are enabled by default. + +138 +00:08:06,000 --> 00:08:16,000 +Now also when you set up these kinds of firewalls, uh, VPNs, especially in IPsec, it runs in two + +139 +00:08:16,000 --> 00:08:19,000 +modes tunnel mode and transport mode. + +140 +00:08:19,000 --> 00:08:20,000 +In tunnel mode. + +141 +00:08:20,000 --> 00:08:25,000 +What's happening here is that it's it's protecting the IP header. + +142 +00:08:25,000 --> 00:08:29,000 +Notice this green box right here the IP header I could just highlight it. + +143 +00:08:29,000 --> 00:08:34,000 +It protects the IP header and trailer and the payload being the data. + +144 +00:08:35,000 --> 00:08:43,000 +It encapsulates everything an IP header includes, like the source IP and destination IP in transport + +145 +00:08:43,000 --> 00:08:45,000 +mode is just the payload that's being detected. + +146 +00:08:45,000 --> 00:08:47,000 +The final destination is visible. + +147 +00:08:47,000 --> 00:08:55,000 +So if you're going across a network where you control all the routers so it can encrypt and decrypt + +148 +00:08:55,000 --> 00:08:59,000 +the packet at every one of the routers, then it's okay to use tunnel mode. + +149 +00:08:59,000 --> 00:09:03,000 +But if it has to go across a network that you can't control, you're probably going to set it up in + +150 +00:09:03,000 --> 00:09:05,000 +transport mode. + +151 +00:09:05,000 --> 00:09:06,000 +Now. + +152 +00:09:07,000 --> 00:09:10,000 +When it comes to setting up a VPN. + +153 +00:09:10,000 --> 00:09:12,000 +In today's world. + +154 +00:09:12,000 --> 00:09:18,000 +As of right now, as I speak to you, more and more VPNs are being deployed with TLS setup, and the + +155 +00:09:18,000 --> 00:09:23,000 +reason for that is because TLS doesn't require you to open a bunch of ports. + +156 +00:09:23,000 --> 00:09:29,000 +Like if you want to set up an L2, TCP based VPN, it's much easier to configure and more familiar to + +157 +00:09:29,000 --> 00:09:30,000 +users. + +158 +00:09:30,000 --> 00:09:35,000 +And just like you saw with the Sonicwall, you could pretty much run it off of your browser versus L2. + +159 +00:09:35,000 --> 00:09:40,000 +TCP based VPNs almost always have to have you install a client on the machine. + +160 +00:09:40,000 --> 00:09:43,000 +That client needs to be configured. + +161 +00:09:43,000 --> 00:09:49,000 +Different types of L2, TCP, or VPN keys needs to be set up on the machine, so it's much more of an + +162 +00:09:49,000 --> 00:09:54,000 +administrative work if you control the machines like the clients, like the clients that people are + +163 +00:09:54,000 --> 00:09:57,000 +using at home is owned by the company. + +164 +00:09:57,000 --> 00:09:59,000 +The company sets it up and they can't do anything on that machine. + +165 +00:09:59,000 --> 00:10:00,000 +But companies work. + +166 +00:10:00,000 --> 00:10:03,000 +Then it's probably okay to use an L2, TCP based VPN. + +167 +00:10:03,000 --> 00:10:10,000 +If not, if people are working from home and they're utilizing their own machine, the best thing to + +168 +00:10:10,000 --> 00:10:14,000 +do is use a TLS or SSL VPN. + diff --git a/11 - Security Principles/015 SD-WAN OB 3.2_en.srt b/11 - Security Principles/015 SD-WAN OB 3.2_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..af1577e1af867dc53cefcc03414aa2d7121ece1f --- /dev/null +++ b/11 - Security Principles/015 SD-WAN OB 3.2_en.srt @@ -0,0 +1,228 @@ +1 +00:00:00,000 --> 00:00:04,000 +In today's world, networking is becoming crazy complex. + +2 +00:00:04,000 --> 00:00:10,000 +You see, back in the days when you worked in a large network, you had generally one data center that + +3 +00:00:10,000 --> 00:00:14,000 +the company controlled and all the other branch offices would connect to it. + +4 +00:00:15,000 --> 00:00:18,000 +But today it's a lot complex. + +5 +00:00:18,000 --> 00:00:19,000 +And I want to show you a diagram. + +6 +00:00:20,000 --> 00:00:25,000 +Now I want you guys to forget all the connection into the cloud for now. + +7 +00:00:25,000 --> 00:00:30,000 +I want you guys just to look at this thing here with just where it says data center. + +8 +00:00:30,000 --> 00:00:36,000 +Back in the days when we had set up networks, what we would do is we would just have every branch would + +9 +00:00:36,000 --> 00:00:43,000 +connect to the data center, like this branch here would connect to the data center, this branch data + +10 +00:00:43,000 --> 00:00:45,000 +center, this branch data center, this branch, this branch, this branch. + +11 +00:00:46,000 --> 00:00:48,000 +And everything was like a centralized thing. + +12 +00:00:49,000 --> 00:00:52,000 +But now it's all over the place. + +13 +00:00:52,000 --> 00:01:00,000 +Right now the applications are in the cloud all over, split across different cloud based systems. + +14 +00:01:00,000 --> 00:01:06,000 +The applications are stored partially in the data center and partially in the cloud. + +15 +00:01:06,000 --> 00:01:08,000 +Now branch offices are going to the cloud. + +16 +00:01:08,000 --> 00:01:10,000 +They're also going to the data center. + +17 +00:01:10,000 --> 00:01:12,000 +Some of the app is in the cloud. + +18 +00:01:12,000 --> 00:01:14,000 +Some of it is in the data center. + +19 +00:01:14,000 --> 00:01:17,000 +Some of the policies in the data center, some of the policy in the cloud. + +20 +00:01:17,000 --> 00:01:20,000 +This can get complex very fast, very quick. + +21 +00:01:20,000 --> 00:01:22,000 +So there's a couple of things here. + +22 +00:01:23,000 --> 00:01:26,000 +Let's talk about software defined networking. + +23 +00:01:26,000 --> 00:01:35,000 +Software defined networking is basically to simplify a branch office networking and get optimal application + +24 +00:01:35,000 --> 00:01:36,000 +performance. + +25 +00:01:36,000 --> 00:01:42,000 +It provides a centralized control function to securely and intelligently intelligently transfer network + +26 +00:01:42,000 --> 00:01:43,000 +traffic. + +27 +00:01:43,000 --> 00:01:46,000 +What I need you guys to know for your exam is this. + +28 +00:01:46,000 --> 00:01:52,000 +This thing overlays your network and what it does is that it's going to allow for efficient network, + +29 +00:01:52,000 --> 00:02:01,000 +um, traffic that allows applications to be used correctly and efficiently, making data routing more + +30 +00:02:01,000 --> 00:02:02,000 +efficient. + +31 +00:02:02,000 --> 00:02:06,000 +You see, if we don't have this, the data routing would be all over the. + +32 +00:02:06,000 --> 00:02:10,000 +They would have to go and pull some of the data from the cloud and pull it, some of it from the data + +33 +00:02:10,000 --> 00:02:10,000 +center. + +34 +00:02:11,000 --> 00:02:17,000 +Another thing you want to have in here when you set this up is sassy SASE. + +35 +00:02:17,000 --> 00:02:20,000 +It stands for Secure Access Service Edge. + +36 +00:02:20,000 --> 00:02:22,000 +This is a cloud native network and architect. + +37 +00:02:22,000 --> 00:02:26,000 +It combines network security functions with Wan capability. + +38 +00:02:26,000 --> 00:02:31,000 +It merges the SD SD-Wan capabilities with security services. + +39 +00:02:31,000 --> 00:02:32,000 +What is it doing? + +40 +00:02:32,000 --> 00:02:38,000 +Well, this is going to allow those tunnels that you see between those connections to become encrypted, + +41 +00:02:38,000 --> 00:02:41,000 +to connect them to cloud based services, to make them more efficient. + +42 +00:02:41,000 --> 00:02:44,000 +So let's go back here and talk more about this. + +43 +00:02:45,000 --> 00:02:47,000 +So when you set up things like SD-Wan. + +44 +00:02:47,000 --> 00:02:53,000 +SD-Wan is going to allow you to efficiently utilize all types of network connections. + +45 +00:02:55,000 --> 00:02:57,000 +All types of multiple connections. + +46 +00:02:57,000 --> 00:03:02,000 +So imagine you're sitting in this branch office and you need to access some of the applications in the + +47 +00:03:02,000 --> 00:03:04,000 +cloud, some of it in the data center. + +48 +00:03:04,000 --> 00:03:06,000 +Applications can even be split apart. + +49 +00:03:06,000 --> 00:03:10,000 +Now you have SD-Wan, comes in, sets up a variety. + +50 +00:03:10,000 --> 00:03:16,000 +It's it's a type of software defined networking or Sdn that allows it. + +51 +00:03:16,000 --> 00:03:21,000 +It's basically a higher controller level that sits over all these connections and determines the best, + +52 +00:03:21,000 --> 00:03:25,000 +most efficient and secure path to get through the data. + +53 +00:03:25,000 --> 00:03:27,000 +If you're wondering, why do we do all this? + +54 +00:03:27,000 --> 00:03:34,000 +Well, imagine right now how complex networking is without getting too technical and in depth into it, + +55 +00:03:34,000 --> 00:03:36,000 +because you don't need it basically for your exam. + +56 +00:03:36,000 --> 00:03:38,000 +What this really is going to allow you to do? + +57 +00:03:39,000 --> 00:03:44,000 +All the apps the company is using is is going to make it faster and more secure to use. + diff --git a/11 - Security Principles/016 Selecting Effective Controls OB 3.2_en.srt b/11 - Security Principles/016 Selecting Effective Controls OB 3.2_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..2ac01090d2db1f0521d544b542768b2e6a20ffe9 --- /dev/null +++ b/11 - Security Principles/016 Selecting Effective Controls OB 3.2_en.srt @@ -0,0 +1,400 @@ +1 +00:00:00,000 --> 00:00:07,000 +So far we have seen quite a lot of different security security network appliances that we can implement. + +2 +00:00:07,000 --> 00:00:13,000 +But there's a couple of things that we got to think about selecting the effective controls, selecting + +3 +00:00:13,000 --> 00:00:21,000 +the right amount of security to apply to a network, selecting the right device that we have to put + +4 +00:00:21,000 --> 00:00:28,000 +in our network, selecting the right configuration that we put onto these devices. + +5 +00:00:28,000 --> 00:00:31,000 +So in this video we want to talk about selecting effective controls. + +6 +00:00:31,000 --> 00:00:36,000 +What is the process of identifying and implementing the right security measure for your organization. + +7 +00:00:37,000 --> 00:00:40,000 +Now this is going to get very complex. + +8 +00:00:40,000 --> 00:00:43,000 +Every single organization is built differently. + +9 +00:00:43,000 --> 00:00:45,000 +Every organization has assets of different value. + +10 +00:00:45,000 --> 00:00:48,000 +Every organization values assets differently. + +11 +00:00:48,000 --> 00:00:53,000 +Some organization doesn't have much value on their data on their. + +12 +00:00:53,000 --> 00:00:54,000 +Because you know why? + +13 +00:00:54,000 --> 00:00:56,000 +Well, maybe some of the employee data. + +14 +00:00:56,000 --> 00:01:00,000 +But the company's main data don't really put a value on because it's all public knowledge. + +15 +00:01:00,000 --> 00:01:01,000 +Think of like a. + +16 +00:01:02,000 --> 00:01:03,000 +Like something on. + +17 +00:01:03,000 --> 00:01:04,000 +If you're managing Wikipedia. + +18 +00:01:04,000 --> 00:01:08,000 +All the data that Wikipedia have, it's pretty much public data. + +19 +00:01:08,000 --> 00:01:13,000 +The only thing that's private is their credit card information that they collect and the employee resources. + +20 +00:01:13,000 --> 00:01:16,000 +But if you work for the military, it's vastly different. + +21 +00:01:16,000 --> 00:01:23,000 +Everything there, most of it, especially like in the NSA, it's all private or top secret information + +22 +00:01:23,000 --> 00:01:24,000 +versus Wikipedia. + +23 +00:01:24,000 --> 00:01:31,000 +90% of what they collect is public data, vast differences between organization and what they value, + +24 +00:01:31,000 --> 00:01:33,000 +vast differences on how they value it. + +25 +00:01:33,000 --> 00:01:38,000 +So when you select security controls, these are things you have to consider. + +26 +00:01:38,000 --> 00:01:42,000 +And that starts with a risk assessment starts with a thorough risk assessment. + +27 +00:01:42,000 --> 00:01:49,000 +What exactly identify what exact risks do you guys face and how do you want to mitigate those potential + +28 +00:01:49,000 --> 00:01:50,000 +threats? + +29 +00:01:51,000 --> 00:01:54,000 +I mentioned at the beginning of this course Layered Defense. + +30 +00:01:55,000 --> 00:01:57,000 +You have to implement a variety of different controls. + +31 +00:01:57,000 --> 00:01:59,000 +No single point. + +32 +00:02:00,000 --> 00:02:00,000 +All right. + +33 +00:02:00,000 --> 00:02:01,000 +No single. + +34 +00:02:01,000 --> 00:02:02,000 +Everything needs layered. + +35 +00:02:02,000 --> 00:02:03,000 +Layered approach. + +36 +00:02:03,000 --> 00:02:07,000 +And what you should be consideration is what are the different layers. + +37 +00:02:07,000 --> 00:02:08,000 +How are you going to layer them? + +38 +00:02:08,000 --> 00:02:13,000 +You may have cameras in different locations and maybe you need security guard and cameras. + +39 +00:02:13,000 --> 00:02:19,000 +Maybe you you have particularly, uh, doors that are built a certain way and you don't have security + +40 +00:02:19,000 --> 00:02:21,000 +guards, things to consider. + +41 +00:02:21,000 --> 00:02:28,000 +But if there's one thing I know, but living long enough in this world, a lot of times the consideration + +42 +00:02:28,000 --> 00:02:31,000 +may come to selecting the right controls for your business. + +43 +00:02:31,000 --> 00:02:36,000 +Unfortunately, almost always comes back to money. + +44 +00:02:37,000 --> 00:02:38,000 +Evaluating the course. + +45 +00:02:38,000 --> 00:02:42,000 +What is the cost of implementing a control against the potential risk benefit that is given? + +46 +00:02:43,000 --> 00:02:48,000 +If there's one thing we're going to talk about when we get to a risk assessment is can't spend $10, + +47 +00:02:48,000 --> 00:02:51,000 +protecting $5 doesn't make sense. + +48 +00:02:51,000 --> 00:02:58,000 +A lot of times, the control that we select, the kind of firewall that we implement, the kind of IDs + +49 +00:02:58,000 --> 00:03:06,000 +that we put into place, um, whether we have a load balancer, the type of VPN we set up, a lot of + +50 +00:03:06,000 --> 00:03:08,000 +these things are going to be determined basically. + +51 +00:03:08,000 --> 00:03:09,000 +And do you have the budget for it? + +52 +00:03:09,000 --> 00:03:10,000 +Yeah. + +53 +00:03:10,000 --> 00:03:16,000 +We all want the latest and greatest engine firewall, but we can't afford it because it's super expensive. + +54 +00:03:16,000 --> 00:03:19,000 +So you have to be able to understand that cost is a big thing. + +55 +00:03:19,000 --> 00:03:24,000 +Another thing that you have to really keep in consideration is regulation. + +56 +00:03:24,000 --> 00:03:30,000 +Certain regulations will make it mandatory for you to encrypt and store certain data in a certain way. + +57 +00:03:30,000 --> 00:03:35,000 +For example, in HIPAA regulation, you're going to have to secure a certain medical records. + +58 +00:03:35,000 --> 00:03:37,000 +If you follow PCI compliance. + +59 +00:03:37,000 --> 00:03:41,000 +This is a kind of a standard that you're going to have to encrypt credit card information. + +60 +00:03:41,000 --> 00:03:47,000 +So the controls you select their technical stability, assessing the technical capability of feasibilities + +61 +00:03:47,000 --> 00:03:47,000 +controls. + +62 +00:03:47,000 --> 00:03:49,000 +Can you even implement it? + +63 +00:03:49,000 --> 00:03:55,000 +Does your environment even support a particular control that you want to implement every time you implement + +64 +00:03:55,000 --> 00:03:59,000 +a particular risk, maybe a new kind of firewall or a load balancer or something? + +65 +00:04:00,000 --> 00:04:07,000 +You know it identifies more risk into the organization's control, should be directly relevant for the + +66 +00:04:07,000 --> 00:04:09,000 +risk that they're implementing does. + +67 +00:04:10,000 --> 00:04:16,000 +And the other thing is that if you implement this control, does it result in reducing a particular + +68 +00:04:16,000 --> 00:04:18,000 +risk, the risk of hackers breaking in? + +69 +00:04:18,000 --> 00:04:19,000 +So you put a firewall in place. + +70 +00:04:19,000 --> 00:04:21,000 +Does the firewall address that? + +71 +00:04:22,000 --> 00:04:27,000 +The risk of a worm spreading around inside of a network. + +72 +00:04:27,000 --> 00:04:28,000 +Does the firewall address that? + +73 +00:04:28,000 --> 00:04:32,000 +Well, network firewalls generally is not going to stop a worm from spreading around inside of the network + +74 +00:04:32,000 --> 00:04:33,000 +if it's already there. + +75 +00:04:33,000 --> 00:04:35,000 +Host based firewalls does. + +76 +00:04:35,000 --> 00:04:42,000 +So you have to make sure that the what you're implementing addresses that risk stability and adaptability. + +77 +00:04:42,000 --> 00:04:44,000 +Controls should be able to scale with the company. + +78 +00:04:44,000 --> 00:04:52,000 +Don't buy a particular appliance, and it's only good for 100 users in the company right now is at 80, + +79 +00:04:52,000 --> 00:04:53,000 +and it's going to go to 200in a few months. + +80 +00:04:53,000 --> 00:04:54,000 +That's not scalable. + +81 +00:04:55,000 --> 00:05:01,000 +Always evaluate regular monitor, review and update these types of controls for effectiveness is going + +82 +00:05:01,000 --> 00:05:02,000 +to be important. + +83 +00:05:02,000 --> 00:05:04,000 +Monitor your environment. + +84 +00:05:05,000 --> 00:05:15,000 +If there's one thing we know in it that sometimes I can't stand is the constant nonstop change of technology, + +85 +00:05:15,000 --> 00:05:21,000 +such as different kinds of software, hardware, different kinds of attacks that comes out, pushes + +86 +00:05:21,000 --> 00:05:26,000 +us to consistently modify and change the technology that we work in. + +87 +00:05:27,000 --> 00:05:28,000 +Our environments will change. + +88 +00:05:28,000 --> 00:05:35,000 +Whatever it secure environment that you're working in right now will not will cease to exist and completely + +89 +00:05:35,000 --> 00:05:38,000 +do a major change. + +90 +00:05:39,000 --> 00:05:45,000 +I guarantee you, within the next 5 to 8 years on on a general rotation, every 5 to 8 years, the whole + +91 +00:05:45,000 --> 00:05:46,000 +thing will change. + +92 +00:05:46,000 --> 00:05:51,000 +All technology changes, all the operating systems will change, all the devices will change. + +93 +00:05:51,000 --> 00:05:55,000 +For example, Sonicwall is not going to allow us to keep using this particular device because they're + +94 +00:05:55,000 --> 00:05:56,000 +going to say it's outdated. + +95 +00:05:56,000 --> 00:05:57,000 +We'll have to get a new one. + +96 +00:05:58,000 --> 00:06:04,000 +So the and a consistent changes is the control effective new attacks will come out. + +97 +00:06:04,000 --> 00:06:05,000 +And then what are you going to do. + +98 +00:06:05,000 --> 00:06:09,000 +You're going to have to update your devices, update your software. + +99 +00:06:09,000 --> 00:06:13,000 +If there's one thing that's a constant when it managing security. + +100 +00:06:13,000 --> 00:06:19,000 +One thing that's that's a constant when managing security uh, is change. + diff --git a/11 - Security Principles/017 Quick Quiz.html b/11 - Security Principles/017 Quick Quiz.html new file mode 100644 index 0000000000000000000000000000000000000000..3d98d1bdfb03561bac229c500139a327759ee18c --- /dev/null +++ b/11 - Security Principles/017 Quick Quiz.html @@ -0,0 +1,479 @@ + + + + + + + Quiz + + + + +
+
+

+

+
+
+
+ Score: 999 of + 999% +
+
Correct: 999
+
Incorrect: 999
+
+ +
+ + + + +
+ + + + diff --git a/12 - Data Protection/001 Regulated Data OB 3.3_en.srt b/12 - Data Protection/001 Regulated Data OB 3.3_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..20eb27da53adbba68f26007dd1133de1ee3de11c --- /dev/null +++ b/12 - Data Protection/001 Regulated Data OB 3.3_en.srt @@ -0,0 +1,148 @@ +1 +00:00:00,000 --> 00:00:07,000 +Most organizations nowadays will follow some kind of regulations pertaining to the data that it collects. + +2 +00:00:07,000 --> 00:00:12,000 +In today's world, especially in the United States, we have tons of laws that we have to follow, whether + +3 +00:00:12,000 --> 00:00:18,000 +it's collecting medical information and having to follow HIPAA compliance, collecting credit card information, + +4 +00:00:18,000 --> 00:00:22,000 +and following things such as PCI standards now. + +5 +00:00:23,000 --> 00:00:26,000 +What happens is this is known as regulated data. + +6 +00:00:26,000 --> 00:00:32,000 +This includes data that's subject to all kinds of regulatory requirements, different kind of laws and + +7 +00:00:32,000 --> 00:00:34,000 +regulations, personal data. + +8 +00:00:34,000 --> 00:00:41,000 +So if you work in places, if you collect personal data and your organization does business or is located + +9 +00:00:41,000 --> 00:00:43,000 +in Europe, you'll have to follow GDPR. + +10 +00:00:44,000 --> 00:00:45,000 +Uh, in the United States. + +11 +00:00:45,000 --> 00:00:51,000 +Here we have things like HIPAA compliance where health health information and then financial data, + +12 +00:00:52,000 --> 00:00:55,000 +uh, for PCI compliance is going to be like credit card information. + +13 +00:00:55,000 --> 00:01:01,000 +Now, all of these laws here, uh, that are covered, we're going to be covering some of these laws + +14 +00:01:01,000 --> 00:01:03,000 +a little bit later in this course. + +15 +00:01:03,000 --> 00:01:04,000 +So hold on to that. + +16 +00:01:04,000 --> 00:01:09,000 +But for now we want to talk about how just that data is regulated. + +17 +00:01:09,000 --> 00:01:14,000 +Don't think that by collecting people's information, especially people's name, address, social security + +18 +00:01:14,000 --> 00:01:20,000 +number, health care information, like diseases, they may have, medications, they may be taken credit + +19 +00:01:20,000 --> 00:01:21,000 +card information. + +20 +00:01:21,000 --> 00:01:24,000 +This is all data that's going to be regulated. + +21 +00:01:24,000 --> 00:01:32,000 +In fact things that GDPR, the general data protection, this uh, things like GDPR, this is a this + +22 +00:01:32,000 --> 00:01:36,000 +is a this is basically a law that protects Europeans. + +23 +00:01:36,000 --> 00:01:36,000 +Okay. + +24 +00:01:36,000 --> 00:01:38,000 +Or the European Union citizens data. + +25 +00:01:38,000 --> 00:01:41,000 +Things like browsing information is what this collects. + +26 +00:01:41,000 --> 00:01:48,000 +So when you start collecting data on your users, you have to keep in mind that a lot of the data will + +27 +00:01:48,000 --> 00:01:54,000 +be subject to certain laws and regulations within the country that you're collecting that data from. + +28 +00:01:54,000 --> 00:01:59,000 +Compliance with these legal and regulatory standards are critical. + +29 +00:01:59,000 --> 00:02:05,000 +First of all, it will be against the law if you don't, and it's probably going to be mandatory. + +30 +00:02:05,000 --> 00:02:12,000 +This involves good security measurements, access control, and of course ensuring the privacy or confidentiality + +31 +00:02:12,000 --> 00:02:15,000 +and integrity of the data. + +32 +00:02:15,000 --> 00:02:22,000 +So don't think that you can just set up a business or don't think most companies can just go and set + +33 +00:02:22,000 --> 00:02:28,000 +up businesses, start collecting information and not worry about the laws that they should be following. + +34 +00:02:28,000 --> 00:02:35,000 +So make sure as a security professional, you are aware of what local laws within your country that + +35 +00:02:35,000 --> 00:02:38,000 +you should be following when it comes to data compliance. + +36 +00:02:38,000 --> 00:02:43,000 +And also if you're collecting data from overseas or you're doing business overseas from your country, + +37 +00:02:43,000 --> 00:02:46,000 +what laws you should be following there also. + diff --git a/12 - Data Protection/002 Intellectual Property OB 3.3_en.srt b/12 - Data Protection/002 Intellectual Property OB 3.3_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..13435af1412ec450b970fb60acf2e12e3fadcb58 --- /dev/null +++ b/12 - Data Protection/002 Intellectual Property OB 3.3_en.srt @@ -0,0 +1,696 @@ +1 +00:00:00,000 --> 00:00:08,000 +People and organizations in today's world create specific things such as invention, expression, such + +2 +00:00:08,000 --> 00:00:12,000 +as art, or expressions like write in a book. + +3 +00:00:12,000 --> 00:00:16,000 +These things that they create is valuable to them and is worth money to them. + +4 +00:00:17,000 --> 00:00:23,000 +In fact, I am an author and I wrote one of the world's best selling project management book, the PMP + +5 +00:00:23,000 --> 00:00:25,000 +Exam Prep Simplified. + +6 +00:00:25,000 --> 00:00:29,000 +Now, this particular book is an expression of me. + +7 +00:00:29,000 --> 00:00:31,000 +This particular book does bring me in an income. + +8 +00:00:31,000 --> 00:00:36,000 +And for anybody to steal my particular work would result in damages to me. + +9 +00:00:36,000 --> 00:00:41,000 +You see, organizations also have this problem, especially with people that create inventions. + +10 +00:00:41,000 --> 00:00:45,000 +If you make a unique invention that only you. + +11 +00:00:46,000 --> 00:00:48,000 +Uh, should be using in order to profit from that invention. + +12 +00:00:48,000 --> 00:00:50,000 +Because that is your idea. + +13 +00:00:50,000 --> 00:00:52,000 +You need to protect your invention. + +14 +00:00:52,000 --> 00:00:54,000 +I need to protect my expression. + +15 +00:00:54,000 --> 00:00:57,000 +You see, this is called intellectual property. + +16 +00:00:58,000 --> 00:00:59,000 +This is the creation. + +17 +00:00:59,000 --> 00:01:01,000 +This is creations of the mind. + +18 +00:01:01,000 --> 00:01:09,000 +Like inventions, literacy work, artistic work, design symbols and names that is used in commerce. + +19 +00:01:09,000 --> 00:01:16,000 +Now, in this video, I want to go through the different ways we can that we can use to protect our + +20 +00:01:16,000 --> 00:01:17,000 +intellectual property. + +21 +00:01:17,000 --> 00:01:17,000 +Our. + +22 +00:01:17,000 --> 00:01:21,000 +The organization thinks that copyrights and patents and trademarks. + +23 +00:01:21,000 --> 00:01:23,000 +That's what we're cover in this video. + +24 +00:01:23,000 --> 00:01:29,000 +IP theft can result in significant economic loss and competitive disadvantage. + +25 +00:01:29,000 --> 00:01:34,000 +Now, if this is something that I have personal experience with because I have personally experienced + +26 +00:01:34,000 --> 00:01:41,000 +this, my study guide or my book was published on Amazon, and Amazon has exclusive rights as the only + +27 +00:01:41,000 --> 00:01:43,000 +distributor of the book. + +28 +00:01:44,000 --> 00:01:46,000 +After a couple of years and it was doing well. + +29 +00:01:46,000 --> 00:01:50,000 +All of a sudden we started having a seller that started to sell my book. + +30 +00:01:50,000 --> 00:01:51,000 +They were buying. + +31 +00:01:51,000 --> 00:01:55,000 +They were printing the book themselves and selling it on Amazon. + +32 +00:01:55,000 --> 00:01:59,000 +They were priced at Amazon, so people were buying their book and we didn't realize it for a while. + +33 +00:01:59,000 --> 00:02:03,000 +So we actually lost a significant amount of money due to IP theft. + +34 +00:02:03,000 --> 00:02:05,000 +This book is copyrighted. + +35 +00:02:05,000 --> 00:02:11,000 +Protection includes rights management, strict access control, even watermarking to trace and identify + +36 +00:02:11,000 --> 00:02:13,000 +unauthorized copies. + +37 +00:02:13,000 --> 00:02:15,000 +Now, the book does have a unique mark that we know. + +38 +00:02:15,000 --> 00:02:17,000 +If you copy it, we'll know. + +39 +00:02:17,000 --> 00:02:22,000 +So how does organizations protect their intellectual property? + +40 +00:02:22,000 --> 00:02:27,000 +Well, let's go through some of the most common ways that you're going to need to know for your exam. + +41 +00:02:27,000 --> 00:02:30,000 +The first one here I have is copyrights. + +42 +00:02:30,000 --> 00:02:37,000 +So copyrights are laws that protects against unauthorized duplication of an original creative work. + +43 +00:02:37,000 --> 00:02:41,000 +Now when people think of okay, what can I copyright? + +44 +00:02:41,000 --> 00:02:49,000 +Well, these are some of the things here that you can copyright, literacy work, musical work, uh, + +45 +00:02:49,000 --> 00:02:56,000 +all kinds of pictorial work like pictures, motion pictures, sound recordings, architectural work, + +46 +00:02:56,000 --> 00:02:59,000 +all of these are copyrightable. + +47 +00:02:59,000 --> 00:03:03,000 +Now I want to before I get into this, I want to make something clear. + +48 +00:03:03,000 --> 00:03:09,000 +The moment work is created, it is copyrighted. + +49 +00:03:10,000 --> 00:03:11,000 +There's two kinds of copyrights. + +50 +00:03:11,000 --> 00:03:13,000 +In the United States. + +51 +00:03:13,000 --> 00:03:17,000 +There is a regular copyright, and then there's a registered copyright. + +52 +00:03:18,000 --> 00:03:25,000 +The moment you have an idea of an expression of some kind and you draw it on a piece of paper, or you + +53 +00:03:25,000 --> 00:03:29,000 +write it down on a piece of paper, it is automatically copyrighted. + +54 +00:03:29,000 --> 00:03:32,000 +You do not need to register it. + +55 +00:03:33,000 --> 00:03:40,000 +Now, if you feel that this work will be public, will be on the public shelves, such as a book on + +56 +00:03:40,000 --> 00:03:45,000 +Amazon, or you're going to be selling this picture online, or it's going to be like a motion picture + +57 +00:03:45,000 --> 00:03:49,000 +where everybody's going to be seeing it, or it's going to be some kind of play or something like that, + +58 +00:03:50,000 --> 00:03:52,000 +then it's best to get it registered. + +59 +00:03:52,000 --> 00:03:58,000 +A registered copyright is when you go to your copyright office, like we do here in the United States, + +60 +00:03:58,000 --> 00:04:01,000 +and we submit the work to the Copyright Office. + +61 +00:04:01,000 --> 00:04:02,000 +And we claim that that is our work. + +62 +00:04:02,000 --> 00:04:09,000 +The Copyright Office then puts a stamp on it that says, as of this day, Bob says this is his work. + +63 +00:04:09,000 --> 00:04:14,000 +They actually don't check to see if anybody else owns it, but they're just saying that that it is there. + +64 +00:04:15,000 --> 00:04:16,000 +Now, why do we want to register? + +65 +00:04:16,000 --> 00:04:18,000 +What's the benefit of registration? + +66 +00:04:18,000 --> 00:04:23,000 +When you register a copyright, it's the only time you can actually bring lawsuits against people. + +67 +00:04:23,000 --> 00:04:24,000 +So if anybody. + +68 +00:04:24,000 --> 00:04:30,000 +So let's say you wrote something down on a copyright and somebody else stole your idea and you're sure + +69 +00:04:30,000 --> 00:04:32,000 +of it, you can't sue them yet. + +70 +00:04:32,000 --> 00:04:33,000 +You have to go and register it. + +71 +00:04:33,000 --> 00:04:34,000 +Then you can sue them. + +72 +00:04:34,000 --> 00:04:35,000 +So it's best to do it right away. + +73 +00:04:36,000 --> 00:04:42,000 +Uh, also, you're entitled to all kinds of different damages in case somebody steals your copyright. + +74 +00:04:42,000 --> 00:04:43,000 +This is not a law course. + +75 +00:04:43,000 --> 00:04:48,000 +I'm not going to get into the specifics, but if you do have work that are made, publish, go and register + +76 +00:04:48,000 --> 00:04:48,000 +it. + +77 +00:04:48,000 --> 00:04:49,000 +Registry. + +78 +00:04:50,000 --> 00:04:51,000 +Registering a copyright. + +79 +00:04:51,000 --> 00:04:53,000 +It's actually something that is very easy. + +80 +00:04:53,000 --> 00:04:54,000 +I did it myself online. + +81 +00:04:54,000 --> 00:04:55,000 +It takes about ten minutes. + +82 +00:04:55,000 --> 00:04:57,000 +Do not pay companies to do it. + +83 +00:04:57,000 --> 00:05:01,000 +And I think I paid about $40 to register the book, so keep that in mind. + +84 +00:05:01,000 --> 00:05:03,000 +It's not difficult. + +85 +00:05:03,000 --> 00:05:05,000 +Now remember remember what I'm talking about. + +86 +00:05:05,000 --> 00:05:09,000 +Copyrights does not have to be registered to have the protection. + +87 +00:05:09,000 --> 00:05:12,000 +The protection we're talking about is right here. + +88 +00:05:12,000 --> 00:05:16,000 +So remember a copyright is an expression of idea or resources. + +89 +00:05:16,000 --> 00:05:22,000 +Authors can control how whoever owns the copyright controls how the work is distributed, reproduced + +90 +00:05:22,000 --> 00:05:23,000 +and used now. + +91 +00:05:24,000 --> 00:05:28,000 +Copyrights are valid for very long periods of time. + +92 +00:05:28,000 --> 00:05:36,000 +It's valid generally for 70 years after the death of the last remaining author, unless it's work for + +93 +00:05:36,000 --> 00:05:36,000 +hire. + +94 +00:05:36,000 --> 00:05:44,000 +So work for hire is this work for hire is when somebody hires you to create work for an organization. + +95 +00:05:44,000 --> 00:05:48,000 +So if you go to a company and you wrote procedures and policies, that's called work for hire, work + +96 +00:05:48,000 --> 00:05:49,000 +for hire. + +97 +00:05:49,000 --> 00:05:56,000 +An anonymous works are protected for 95 years from the date of the first publication of 120 days from + +98 +00:05:56,000 --> 00:05:58,000 +the date of creation, which one ever is shortest? + +99 +00:05:58,000 --> 00:06:03,000 +If it was published dated, it's 95 years or it's 120 years. + +100 +00:06:04,000 --> 00:06:09,000 +So let's say you're a bad person and you want to steal my book, right? + +101 +00:06:09,000 --> 00:06:10,000 +My PMP study guide. + +102 +00:06:10,000 --> 00:06:17,000 +Well, if you want to steal it well or use it, I'm going to sue you because I have the legal copyright. + +103 +00:06:17,000 --> 00:06:22,000 +But if you want to wait for the copyright to expire to republish the work, you have to wait. + +104 +00:06:22,000 --> 00:06:26,000 +You have to wait for me to die and then you have to wait 70 years. + +105 +00:06:27,000 --> 00:06:31,000 +Penalties can penalties is going to be up to $1.1 million in damages. + +106 +00:06:31,000 --> 00:06:31,000 +Now. + +107 +00:06:31,000 --> 00:06:34,000 +This number can change depending on when you're watching this video. + +108 +00:06:34,000 --> 00:06:36,000 +Ten years in prison now. + +109 +00:06:37,000 --> 00:06:41,000 +This is copyright and these are things that are copyrightable that I have here. + +110 +00:06:41,000 --> 00:06:47,000 +Now, the other thing here that we can use to protect our IP is going to be trademarks. + +111 +00:06:47,000 --> 00:06:55,000 +Trademarks protect words, names, symbols, sounds, shapes, colors, musical tones or a combination. + +112 +00:06:56,000 --> 00:07:01,000 +Uh, they protect someone from stealing another person's quote unquote look and feel. + +113 +00:07:01,000 --> 00:07:04,000 +The primary purpose is to avoid confusion in the marketplace. + +114 +00:07:04,000 --> 00:07:06,000 +This protects intellectual property. + +115 +00:07:06,000 --> 00:07:12,000 +The good thing with trademarks is that they're valid, unlike a copyright, which generally, when I + +116 +00:07:12,000 --> 00:07:16,000 +die, it's 70 years technically trademarks, you can keep renewing it over and over. + +117 +00:07:16,000 --> 00:07:18,000 +They're valid for ten years with unlimited renewal. + +118 +00:07:19,000 --> 00:07:19,000 +Um. + +119 +00:07:20,000 --> 00:07:22,000 +On unlimited. + +120 +00:07:22,000 --> 00:07:27,000 +You can renew an unlimited number of times, so you can keep renewing that over and over and over. + +121 +00:07:27,000 --> 00:07:29,000 +Now, what are things that are going to be trademarked? + +122 +00:07:29,000 --> 00:07:32,000 +Lots of things that are trademark are generally things like symbols. + +123 +00:07:32,000 --> 00:07:37,000 +The Technical Institute of America, if you look at our name and symbols, those are all trademarks. + +124 +00:07:37,000 --> 00:07:41,000 +We own the trademark to the Technical Institute of America. + +125 +00:07:41,000 --> 00:07:44,000 +The the the actual company's name. + +126 +00:07:44,000 --> 00:07:48,000 +The Technical Institute of America is a trademark name. + +127 +00:07:48,000 --> 00:07:52,000 +The symbol of itself, the shield that we use is also trademarked. + +128 +00:07:52,000 --> 00:07:56,000 +This helps to ensure that we protect our brand. + +129 +00:07:56,000 --> 00:08:01,000 +Many, many companies are trademarking their content, their brands, their logo. + +130 +00:08:01,000 --> 00:08:04,000 +How do you know when you see a particular logo? + +131 +00:08:04,000 --> 00:08:07,000 +You might see a little circle that says TM on it. + +132 +00:08:07,000 --> 00:08:10,000 +If you see a little circle with a C with a circle, that's a copyright. + +133 +00:08:11,000 --> 00:08:13,000 +Now the other one here you have is patents. + +134 +00:08:13,000 --> 00:08:15,000 +If you have an invention. + +135 +00:08:16,000 --> 00:08:21,000 +Unique invention that you have invented to help the world progress. + +136 +00:08:21,000 --> 00:08:25,000 +You're going to get exclusive use of your invention if you patent your invention. + +137 +00:08:25,000 --> 00:08:31,000 +So patent protects the right of inventors and their inventions, protection of those who have legal + +138 +00:08:31,000 --> 00:08:32,000 +ownership of the patent. + +139 +00:08:33,000 --> 00:08:37,000 +The invention, must be new, must be useful, and must not be obvious. + +140 +00:08:37,000 --> 00:08:42,000 +The owner has exclusive control of the invention for 20 years. + +141 +00:08:42,000 --> 00:08:47,000 +After that it goes to the public domain and anyone can produce your work. + +142 +00:08:47,000 --> 00:08:52,000 +This is why when organizations like drug companies first make a drug that they've spent billions of + +143 +00:08:52,000 --> 00:08:58,000 +dollars producing, they have about 20 years because they have patent that formula for that drug to + +144 +00:08:58,000 --> 00:09:02,000 +sell it as much as they want so they can recuperate their costs. + +145 +00:09:02,000 --> 00:09:06,000 +And after that it becomes a generic medication, and then anyone can take the formula. + +146 +00:09:08,000 --> 00:09:16,000 +Another thing that you want to protect is the secret recipe to the McDonald's Big Mac sauce, or the + +147 +00:09:16,000 --> 00:09:20,000 +secret recipe to KFC's fried chicken. + +148 +00:09:21,000 --> 00:09:22,000 +It's coming up to lunch time. + +149 +00:09:22,000 --> 00:09:26,000 +It's actually around 11:00 in the morning, so I'm thinking about I could use a Big Mac right now. + +150 +00:09:27,000 --> 00:09:36,000 +Organizations have top secret information that they use in order for the survivability of that company. + +151 +00:09:36,000 --> 00:09:38,000 +These are called trade secrets. + +152 +00:09:38,000 --> 00:09:45,000 +It's any form of information, device, method, process, or formula such as that Big Mac sauce that, + +153 +00:09:45,000 --> 00:09:49,000 +if disclosed, will cause significant damage to the organization. + +154 +00:09:50,000 --> 00:09:53,000 +Now resources generally is going to provide. + +155 +00:09:53,000 --> 00:09:59,000 +Must be of competitive value, must be protected from unauthorized use, is proprietary to the company + +156 +00:09:59,000 --> 00:10:01,000 +essential for them to survive. + +157 +00:10:01,000 --> 00:10:11,000 +Now there is really nothing to register like we do with copyrights or patents or, uh, or trademarks. + +158 +00:10:11,000 --> 00:10:13,000 +Trade secrets just has to be protected. + +159 +00:10:14,000 --> 00:10:18,000 +There is a law in the United States you don't need to know this one for your exam. + +160 +00:10:18,000 --> 00:10:19,000 +I just put it there. + +161 +00:10:19,000 --> 00:10:25,000 +For your knowledge, the Espionage Act of 1996 is a law that specifies that if anyone ever steals a + +162 +00:10:25,000 --> 00:10:31,000 +trade secrets and discloses that they can be fined, as you can see here, potential jail time. + +163 +00:10:32,000 --> 00:10:38,000 +So the way to protect trade secrets as a security professional is just do your normal security things, + +164 +00:10:38,000 --> 00:10:45,000 +encrypt it, put good windows permission or file permission like access control firewalls, IDs systems + +165 +00:10:45,000 --> 00:10:49,000 +may be used potential air gapped systems to store this kind of information. + +166 +00:10:49,000 --> 00:10:53,000 +Whoever gets the information should be signing a non-disclosure agreement. + +167 +00:10:53,000 --> 00:10:56,000 +This prohibits them from sharing this information. + +168 +00:10:56,000 --> 00:11:04,000 +And if they do share it, they could, uh, be subject to potential fines or the company can sue them + +169 +00:11:04,000 --> 00:11:05,000 +for the loss of income and so on. + +170 +00:11:07,000 --> 00:11:07,000 +Okay. + +171 +00:11:07,000 --> 00:11:11,000 +These are some ways that we're going to protect our intellectual property. + +172 +00:11:11,000 --> 00:11:16,000 +Keep in mind, intellectual property is how lots of organizations survives in today's day and time. + +173 +00:11:16,000 --> 00:11:21,000 +And a lot of these IPS is essential for the survival of the business. + +174 +00:11:21,000 --> 00:11:25,000 +So as an IT professional, make sure you protect them. + diff --git a/12 - Data Protection/003 Legal and Financial Data OB 3.3_en.srt b/12 - Data Protection/003 Legal and Financial Data OB 3.3_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..d991fa23b18ce2d90d017b3f7e26c2032c07eaf2 --- /dev/null +++ b/12 - Data Protection/003 Legal and Financial Data OB 3.3_en.srt @@ -0,0 +1,276 @@ +1 +00:00:00,000 --> 00:00:05,000 +As you collect information, you're going to be collecting different kinds of information in particularly, + +2 +00:00:05,000 --> 00:00:11,000 +some of the data that we collect on a network may be considered, uh, legal information. + +3 +00:00:11,000 --> 00:00:14,000 +While some of the information we collect may be financial information. + +4 +00:00:14,000 --> 00:00:20,000 +And then some of this information we collect is easily readable by us. + +5 +00:00:20,000 --> 00:00:24,000 +And versus some of it is not and can only be read by a computer. + +6 +00:00:24,000 --> 00:00:26,000 +So let's talk about the first one I have here. + +7 +00:00:26,000 --> 00:00:28,000 +Legal information. + +8 +00:00:28,000 --> 00:00:35,000 +A lot of times some of the data that we collect on clients, or that we create ourselves internally + +9 +00:00:35,000 --> 00:00:39,000 +could fall into the to to the realm of legal information. + +10 +00:00:39,000 --> 00:00:44,000 +Legal information are things that deals with legal matters, including case files, legal advice and + +11 +00:00:44,000 --> 00:00:46,000 +other sensitive legal documents. + +12 +00:00:47,000 --> 00:00:52,000 +A breach of these type, a breach of this kind of information, or the release of this kind of information, + +13 +00:00:52,000 --> 00:00:57,000 +especially if the company is in some kind of a lawsuit, could result in attorney client privileges + +14 +00:00:57,000 --> 00:00:59,000 +being compromised. + +15 +00:00:59,000 --> 00:01:00,000 +Uh, case integrity. + +16 +00:01:00,000 --> 00:01:04,000 +So ensuring the confidentiality encryption of this kind of information is critical. + +17 +00:01:04,000 --> 00:01:05,000 +Let me give you an example. + +18 +00:01:06,000 --> 00:01:13,000 +Let's say the organization, uh, has gotten sued by another company because that company is claiming + +19 +00:01:13,000 --> 00:01:16,000 +that it stole its IP topic. + +20 +00:01:16,000 --> 00:01:19,000 +We just covered it, stole its design. + +21 +00:01:19,000 --> 00:01:26,000 +But your organization has proof that it didn't stole the design, and it actually created the actual + +22 +00:01:26,000 --> 00:01:28,000 +product itself from scratch. + +23 +00:01:28,000 --> 00:01:36,000 +The documents that proves that we created the design ourselves now falls into a legal into a legal case, + +24 +00:01:36,000 --> 00:01:39,000 +or now it becomes legal information. + +25 +00:01:39,000 --> 00:01:42,000 +This means that it's going to have to be presented in a court of law. + +26 +00:01:42,000 --> 00:01:47,000 +As an IT professional, you're going to have to make sure that you protect the integrity, make sure + +27 +00:01:47,000 --> 00:01:52,000 +that it never gets modified, because you're going to use this as proof in the case you have to encrypt + +28 +00:01:52,000 --> 00:01:57,000 +it so it doesn't get leaked out, or the other sides don't get to see it because they have an assumption + +29 +00:01:57,000 --> 00:01:58,000 +that may not be true. + +30 +00:01:58,000 --> 00:02:01,000 +Another thing is financial information. + +31 +00:02:01,000 --> 00:02:07,000 +It is super easy to get in trouble with the law nowadays, because you're collecting financial information + +32 +00:02:07,000 --> 00:02:09,000 +and may not even be realized in it. + +33 +00:02:09,000 --> 00:02:11,000 +How important it is. + +34 +00:02:12,000 --> 00:02:17,000 +This is going to be things, transactions, financial records, credit card information, and other + +35 +00:02:17,000 --> 00:02:19,000 +monetary data that you're collecting from your customers. + +36 +00:02:19,000 --> 00:02:25,000 +Right now, most organizations that sells products online will collect some kind of payment information. + +37 +00:02:26,000 --> 00:02:30,000 +Now, financial data is always going to be the target for these. + +38 +00:02:30,000 --> 00:02:35,000 +I don't want to say always, 90% of the time is going to be the target for these hackers that comes + +39 +00:02:35,000 --> 00:02:37,000 +in, breaks into your company. + +40 +00:02:37,000 --> 00:02:40,000 +What they're looking for are those credit card information. + +41 +00:02:40,000 --> 00:02:45,000 +We're going to have to do things like encrypted, encrypt the processing and make sure that if there + +42 +00:02:45,000 --> 00:02:50,000 +is standards like PCI compliance, PCI means payment card industry. + +43 +00:02:52,000 --> 00:02:54,000 +DSS data security standard. + +44 +00:02:54,000 --> 00:03:01,000 +It's basically a standard that organizations have to follow to secure credit card information or financial + +45 +00:03:01,000 --> 00:03:02,000 +information. + +46 +00:03:02,000 --> 00:03:06,000 +Now, the other thing here that we're going to be talking about is what's called readable data. + +47 +00:03:06,000 --> 00:03:08,000 +Readable data falls into two kinds. + +48 +00:03:08,000 --> 00:03:14,000 +Human readable, US readable and non-human readable things that we can interpret and see on a network, + +49 +00:03:14,000 --> 00:03:18,000 +such as text, documents, images, printable information. + +50 +00:03:18,000 --> 00:03:24,000 +And then non readable is going to be non human readable things that only the computer can read. + +51 +00:03:24,000 --> 00:03:27,000 +Think of things like machine code. + +52 +00:03:27,000 --> 00:03:30,000 +No one can read machine code ones and zeros. + +53 +00:03:30,000 --> 00:03:34,000 +Certain kind of log files, encrypted data that only computers can decrypt. + +54 +00:03:35,000 --> 00:03:38,000 +Both of these will require protection. + +55 +00:03:38,000 --> 00:03:39,000 +Okay. + +56 +00:03:39,000 --> 00:03:41,000 +Both of these will require protection. + +57 +00:03:41,000 --> 00:03:45,000 +That only that only that organization or whoever needs to see it. + +58 +00:03:45,000 --> 00:03:53,000 +This is going to be things such as encryption, firewalls, intrusion detection systems, access controls + +59 +00:03:53,000 --> 00:03:54,000 +and so on. + +60 +00:03:54,000 --> 00:03:57,000 +All the protection mechanisms that we have spoken about. + +61 +00:03:57,000 --> 00:04:02,000 +So human readable is, is very likely to get stolen. + +62 +00:04:02,000 --> 00:04:06,000 +Because that's what if they break into the company, that's what they're going to be coming after. + +63 +00:04:06,000 --> 00:04:13,000 +Cybercriminals could be attacking non human readable for decryption or misuse of that data. + +64 +00:04:14,000 --> 00:04:16,000 +Data protection is super important. + +65 +00:04:16,000 --> 00:04:18,000 +If the company is in some kind of a lawsuit. + +66 +00:04:18,000 --> 00:04:23,000 +You've got to remember as a security person to protect that data, because that data could be the one + +67 +00:04:23,000 --> 00:04:26,000 +that proves that the company did nothing wrong. + +68 +00:04:26,000 --> 00:04:29,000 +And you will be collecting tons of financial information. + +69 +00:04:29,000 --> 00:04:34,000 +So you want to make sure you protect both of them to keep your company secure. + diff --git a/12 - Data Protection/004 Data Classification OB 3.3_en.srt b/12 - Data Protection/004 Data Classification OB 3.3_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..456cc25dc307dbf8b9d1239404e8f3d76c606036 --- /dev/null +++ b/12 - Data Protection/004 Data Classification OB 3.3_en.srt @@ -0,0 +1,644 @@ +1 +00:00:00,000 --> 00:00:05,000 +Organizations today store a lot of information or particularly a lot of data. + +2 +00:00:05,000 --> 00:00:10,000 +We have tons and tons of data, and the longer that company stays in business, the more data you're + +3 +00:00:10,000 --> 00:00:11,000 +going to get. + +4 +00:00:11,000 --> 00:00:18,000 +Now the question comes down to does all of that data have the same value? + +5 +00:00:18,000 --> 00:00:24,000 +Do we apply the same set of controls to all of all the data? + +6 +00:00:24,000 --> 00:00:25,000 +The answer is no. + +7 +00:00:25,000 --> 00:00:27,000 +Different data sets have different value. + +8 +00:00:27,000 --> 00:00:31,000 +For example, what's on a company's website is public information. + +9 +00:00:31,000 --> 00:00:35,000 +That particular data, if it's lost, doesn't cost much harm to the business. + +10 +00:00:35,000 --> 00:00:40,000 +But if the company uses a very particular manufacturing method or formula to produce a product, if + +11 +00:00:40,000 --> 00:00:45,000 +that's lost, that's going to cause the company significant financial harm. + +12 +00:00:45,000 --> 00:00:49,000 +We don't protect data, all the data with the same set of controls. + +13 +00:00:49,000 --> 00:00:58,000 +We don't have unlimited resources to buy things like IDs systems, IPS, endpoint protection, firewall + +14 +00:00:58,000 --> 00:01:01,000 +encryption, redundant systems, cloud storages, and so on and so on. + +15 +00:01:01,000 --> 00:01:04,000 +All the different security controls you can think about. + +16 +00:01:04,000 --> 00:01:10,000 +We don't have unlimited amount of money and people to buy, configure, setup and maintain all those + +17 +00:01:10,000 --> 00:01:11,000 +controls. + +18 +00:01:11,000 --> 00:01:14,000 +So what we have is we have a limited set of controls. + +19 +00:01:14,000 --> 00:01:15,000 +We have a ton of data. + +20 +00:01:15,000 --> 00:01:22,000 +So we have to take the limited resources and allocate it to ensure the right data gets the right protection. + +21 +00:01:22,000 --> 00:01:25,000 +Or in other words, the right data gets the right control. + +22 +00:01:25,000 --> 00:01:27,000 +The question is how do we determine that? + +23 +00:01:27,000 --> 00:01:29,000 +How do we determine. + +24 +00:01:29,000 --> 00:01:32,000 +Well, you're going to get those controls and you're going to get those controls. + +25 +00:01:32,000 --> 00:01:36,000 +You're going to have a ton of controls and you're not going to have any control. + +26 +00:01:36,000 --> 00:01:39,000 +The answer is data classification. + +27 +00:01:39,000 --> 00:01:42,000 +And this starts this discussion on this topic. + +28 +00:01:43,000 --> 00:01:44,000 +Now. + +29 +00:01:44,000 --> 00:01:48,000 +Data classification affects all aspects of A of the data. + +30 +00:01:48,000 --> 00:01:50,000 +When should a data. + +31 +00:01:50,000 --> 00:01:52,000 +When should the data be backed up? + +32 +00:01:52,000 --> 00:01:53,000 +Depends on a classification. + +33 +00:01:53,000 --> 00:01:54,000 +Where should it be stored? + +34 +00:01:54,000 --> 00:01:56,000 +Depends on this classification. + +35 +00:01:56,000 --> 00:02:00,000 +Who should have access to it depends on its classification. + +36 +00:02:00,000 --> 00:02:02,000 +How should it be processed? + +37 +00:02:02,000 --> 00:02:03,000 +Depends on its classification. + +38 +00:02:03,000 --> 00:02:05,000 +What type of machine should it be stored on? + +39 +00:02:05,000 --> 00:02:07,000 +Depends on its classification. + +40 +00:02:07,000 --> 00:02:08,000 +You get the point. + +41 +00:02:08,000 --> 00:02:12,000 +Every single aspect of the data. + +42 +00:02:13,000 --> 00:02:18,000 +Is going to be, or what happens to it is going to be dependent on that classification. + +43 +00:02:18,000 --> 00:02:24,000 +So data classification helps in determining the level of security controls and handling protocols that + +44 +00:02:24,000 --> 00:02:26,000 +should be applied to various kinds of data. + +45 +00:02:27,000 --> 00:02:34,000 +Data classification helps with the creation, usage and determination and destruction of the data. + +46 +00:02:34,000 --> 00:02:39,000 +For example public information information that's on your public website. + +47 +00:02:39,000 --> 00:02:44,000 +When the when that server that was just storing public data, whenever you're ready to throw that server + +48 +00:02:44,000 --> 00:02:48,000 +out or destroy the server, just put it in a garbage. + +49 +00:02:48,000 --> 00:02:49,000 +Nothing else to do. + +50 +00:02:49,000 --> 00:02:53,000 +Take out the hard drive and dump it in the bin because everything on the drive is public. + +51 +00:02:53,000 --> 00:02:59,000 +But if that if that server was storing top secret data, you would want to degauss and shred the hard + +52 +00:02:59,000 --> 00:03:00,000 +drive. + +53 +00:03:00,000 --> 00:03:06,000 +So it has a different procedure to destroy the data depending on its classification. + +54 +00:03:07,000 --> 00:03:12,000 +Now for your exam, the data owner determines the classification. + +55 +00:03:12,000 --> 00:03:15,000 +You have to remember that who determines classification? + +56 +00:03:15,000 --> 00:03:17,000 +The data owner does that. + +57 +00:03:17,000 --> 00:03:21,000 +They will determine how critical it is, how sensitive it is. + +58 +00:03:21,000 --> 00:03:23,000 +They're going to determine its value. + +59 +00:03:23,000 --> 00:03:24,000 +They need to know. + +60 +00:03:24,000 --> 00:03:26,000 +Don't forget the data owner determines Bob has access. + +61 +00:03:26,000 --> 00:03:28,000 +Mary doesn't, or vice versa. + +62 +00:03:28,000 --> 00:03:32,000 +They determine how to declassify it if it needs to be or destroy it. + +63 +00:03:32,000 --> 00:03:38,000 +The whole objective of data classification, like I mentioned earlier, is to get the right controls + +64 +00:03:38,000 --> 00:03:43,000 +to the right data owner will define the retention requirements. + +65 +00:03:43,000 --> 00:03:46,000 +Data classifications will also define how long you keep it. + +66 +00:03:47,000 --> 00:03:54,000 +Basically, the whole point of this entire topic is to the optimization of resources and keeping our + +67 +00:03:54,000 --> 00:03:55,000 +data secure. + +68 +00:03:55,000 --> 00:03:56,000 +Now. + +69 +00:03:57,000 --> 00:03:59,000 +There's a couple of things here I want to mention. + +70 +00:04:00,000 --> 00:04:05,000 +When it comes to classification, you have to think of the entire CIA. + +71 +00:04:05,000 --> 00:04:10,000 +How sensitive it is, how critical it is sensitivity and critical, and how critical it is generally + +72 +00:04:10,000 --> 00:04:12,000 +relate back to confidentiality. + +73 +00:04:12,000 --> 00:04:19,000 +So you want to keep in mind these particular things when you're thinking about, for example, top secret + +74 +00:04:19,000 --> 00:04:26,000 +data, secret data, public data, unclassified data, you have to think about these particular things. + +75 +00:04:26,000 --> 00:04:34,000 +For example, in the military, they they prioritize our emphasized confidentiality. + +76 +00:04:34,000 --> 00:04:39,000 +Fully emphasizing confidentiality may give up, for example, availability. + +77 +00:04:41,000 --> 00:04:47,000 +A machine that is super secure, that no one can go in and just tamper with the machine and steal its + +78 +00:04:47,000 --> 00:04:47,000 +data. + +79 +00:04:47,000 --> 00:04:52,000 +A machine that's turned off and unplugged airgap the machine. + +80 +00:04:52,000 --> 00:04:56,000 +Well, if it's air gapped, then only two people can get access to it and they have to put the machine + +81 +00:04:56,000 --> 00:04:57,000 +on because it's not turned on. + +82 +00:04:58,000 --> 00:05:02,000 +The problem with this is that, yes, good confidentiality, but it's not available to anyone except + +83 +00:05:02,000 --> 00:05:03,000 +a few people. + +84 +00:05:03,000 --> 00:05:10,000 +Low availability in private industries, though, we're going to emphasize the full CIA. + +85 +00:05:10,000 --> 00:05:12,000 +We're going to want to push the full thing. + +86 +00:05:12,000 --> 00:05:16,000 +We're going to try to get CIA for most of our data, not all of it. + +87 +00:05:16,000 --> 00:05:19,000 +Keep your classification scheme simple. + +88 +00:05:19,000 --> 00:05:24,000 +I'm going to talk about a different classification scheme that we can use, the different terms you + +89 +00:05:24,000 --> 00:05:25,000 +can use in a minute. + +90 +00:05:25,000 --> 00:05:28,000 +Here's an example though of a classification scheme. + +91 +00:05:28,000 --> 00:05:31,000 +So for example this is just an example. + +92 +00:05:31,000 --> 00:05:34,000 +Like in the military when we're talking protection of data. + +93 +00:05:34,000 --> 00:05:39,000 +Look at how the different classification will determine what type of controls. + +94 +00:05:40,000 --> 00:05:41,000 +If you have data. + +95 +00:05:42,000 --> 00:05:46,000 +Particularly something like on paper, if it's top secret, put it in a vault. + +96 +00:05:46,000 --> 00:05:49,000 +If it's secret, a safe would be okay. + +97 +00:05:49,000 --> 00:05:53,000 +Confidential, maybe a filing cabinet with a metal bar and a lock. + +98 +00:05:53,000 --> 00:05:54,000 +And on classified. + +99 +00:05:54,000 --> 00:05:54,000 +No protection. + +100 +00:05:54,000 --> 00:05:55,000 +Leave it on the desk. + +101 +00:05:55,000 --> 00:06:00,000 +Notice the different classification results in different controls. + +102 +00:06:01,000 --> 00:06:08,000 +Now, the question that a lot of people ask me is, Andrew, what are the different classification schemes + +103 +00:06:08,000 --> 00:06:09,000 +that we can use? + +104 +00:06:09,000 --> 00:06:18,000 +There is no official definition of any potential or any classification scheme that is out there. + +105 +00:06:18,000 --> 00:06:25,000 +Many books that we read, CISSP books, Security+ books, even the books on Ec-council. + +106 +00:06:25,000 --> 00:06:31,000 +They're going to vary in the definitions because there's no definition and the exam will never ask you, + +107 +00:06:31,000 --> 00:06:34,000 +is this secret, top secret or confidential? + +108 +00:06:34,000 --> 00:06:35,000 +They'll never do that. + +109 +00:06:35,000 --> 00:06:38,000 +Just understand what data classification is. + +110 +00:06:38,000 --> 00:06:42,000 +I want to show you an example of what you could use though. + +111 +00:06:43,000 --> 00:06:46,000 +Uh, this is a classification scheme that you could use. + +112 +00:06:46,000 --> 00:06:50,000 +And I want to show you how different schemes mean different things. + +113 +00:06:50,000 --> 00:06:52,000 +So let's take a look here. + +114 +00:06:52,000 --> 00:06:54,000 +So here's a data classification scheme. + +115 +00:06:54,000 --> 00:06:57,000 +So on this one we have four classes 0 to 3. + +116 +00:06:58,000 --> 00:07:01,000 +And on the bottom of the triangle let's go with non-government. + +117 +00:07:01,000 --> 00:07:03,000 +First let's see a private organization. + +118 +00:07:03,000 --> 00:07:05,000 +Class zero is no damage. + +119 +00:07:05,000 --> 00:07:09,000 +Any data that's classified as public has no damage. + +120 +00:07:09,000 --> 00:07:11,000 +If it's released to the public no damage. + +121 +00:07:11,000 --> 00:07:12,000 +All right. + +122 +00:07:12,000 --> 00:07:19,000 +Maybe like upcoming projects, the company is doing class one sensitive does cause damage to the business. + +123 +00:07:19,000 --> 00:07:23,000 +Things like the company's financial, like its profit and loss statement. + +124 +00:07:23,000 --> 00:07:25,000 +Serious damage like a class two. + +125 +00:07:25,000 --> 00:07:27,000 +This one is private. + +126 +00:07:27,000 --> 00:07:30,000 +This would be like releasing air information about the company's employees. + +127 +00:07:30,000 --> 00:07:33,000 +And then of course, grave damage to that business. + +128 +00:07:33,000 --> 00:07:36,000 +Confidential or proprietary data like trade secrets. + +129 +00:07:36,000 --> 00:07:41,000 +If you are the federal government, here's a classification that you can use. + +130 +00:07:41,000 --> 00:07:43,000 +Top secret wartime information. + +131 +00:07:43,000 --> 00:07:44,000 +This is released. + +132 +00:07:44,000 --> 00:07:48,000 +Grave damage to national security troop deployment information. + +133 +00:07:48,000 --> 00:07:51,000 +This would be serious damage to national security. + +134 +00:07:51,000 --> 00:07:56,000 +Confidential is like trade secrets or health care information of government workers that are non classified + +135 +00:07:56,000 --> 00:07:58,000 +is going to be their version of public. + +136 +00:07:58,000 --> 00:08:01,000 +Now this is just an example. + +137 +00:08:01,000 --> 00:08:02,000 +Okay. + +138 +00:08:02,000 --> 00:08:04,000 +This is just an example. + +139 +00:08:04,000 --> 00:08:05,000 +All right. + +140 +00:08:05,000 --> 00:08:10,000 +Here at TI we only use three levels of data classification I know companies that only use two. + +141 +00:08:10,000 --> 00:08:12,000 +You don't have to use them all. + +142 +00:08:12,000 --> 00:08:18,000 +But when it comes to data classification, here are some different, uh, terms that you can use. + +143 +00:08:18,000 --> 00:08:20,000 +Sensitive confidential. + +144 +00:08:20,000 --> 00:08:21,000 +Public I think has a universal meaning. + +145 +00:08:21,000 --> 00:08:23,000 +Anyone can access it. + +146 +00:08:23,000 --> 00:08:25,000 +But for example, what are some companies may call it private. + +147 +00:08:25,000 --> 00:08:32,000 +Some may call it confidential, what some call sensitive, some may call restricted, what some call + +148 +00:08:32,000 --> 00:08:34,000 +confidential, some may call it critical. + +149 +00:08:34,000 --> 00:08:39,000 +And then of course, the military will add things like secret and top secret on top of this. + +150 +00:08:39,000 --> 00:08:41,000 +Or maybe a line in here with these. + +151 +00:08:41,000 --> 00:08:45,000 +There really isn't a full definition. + +152 +00:08:46,000 --> 00:08:50,000 +Now when it comes to your exam and data classification, remember something. + +153 +00:08:50,000 --> 00:08:52,000 +Data classification is a big terme. + +154 +00:08:52,000 --> 00:09:00,000 +Data classification is the umbrella terms that affects all controls of the data. + +155 +00:09:01,000 --> 00:09:04,000 +Like I mentioned earlier in the beginning, let's do a quick recap. + +156 +00:09:04,000 --> 00:09:11,000 +Data classification affects everything about the data, determines what controls is applied to what + +157 +00:09:11,000 --> 00:09:15,000 +data, determines who should have access to it, or you can't access this because you're not in the + +158 +00:09:15,000 --> 00:09:18,000 +top secret clearance, or you can't access this because you don't. + +159 +00:09:18,000 --> 00:09:20,000 +You can't access confidential data. + +160 +00:09:20,000 --> 00:09:23,000 +You can access public data, things like that. + +161 +00:09:23,000 --> 00:09:26,000 +Keep this in mind when answering your exam questions. + diff --git a/12 - Data Protection/005 Geolocation and Sovereignty OB 3.3_en.srt b/12 - Data Protection/005 Geolocation and Sovereignty OB 3.3_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..48c7a17efbea31aa0e90190d0a8340b83344db88 --- /dev/null +++ b/12 - Data Protection/005 Geolocation and Sovereignty OB 3.3_en.srt @@ -0,0 +1,144 @@ +1 +00:00:00,000 --> 00:00:04,000 +Organizations today collect data from multiple parts of the world. + +2 +00:00:04,000 --> 00:00:08,000 +You see, most organizations do business internationally. + +3 +00:00:08,000 --> 00:00:13,000 +For example, if you have an e-commerce site, you may have people purchasing products on your e-commerce + +4 +00:00:13,000 --> 00:00:18,000 +site that is located in Europe, Asia, United States, and the rest of the world. + +5 +00:00:18,000 --> 00:00:26,000 +So what happens is this is this is important to know because the geographic location of the data matters. + +6 +00:00:26,000 --> 00:00:31,000 +Depending on where that data is collected, it's subject to different regulatory compliance. + +7 +00:00:31,000 --> 00:00:33,000 +That's that's going to be important. + +8 +00:00:33,000 --> 00:00:39,000 +For example, collecting data from EU citizens results in you following GDPR. + +9 +00:00:39,000 --> 00:00:44,000 +Now also the other things to think about is the latency and performance of the data. + +10 +00:00:44,000 --> 00:00:49,000 +If you're capturing or getting data from around the world and your servers are in the United States, + +11 +00:00:49,000 --> 00:00:53,000 +that could be a problem as the performance of the data look at the risk management. + +12 +00:00:54,000 --> 00:00:57,000 +With collecting data from around the world. + +13 +00:00:57,000 --> 00:01:03,000 +Does your organization have the legal department and the resources it takes to comply with legal laws + +14 +00:01:03,000 --> 00:01:04,000 +around the world? + +15 +00:01:04,000 --> 00:01:08,000 +This brings me to this topic of data sovereignty. + +16 +00:01:08,000 --> 00:01:14,000 +Now, data sovereignty is basically a legal concept that data is subject to the laws and governance + +17 +00:01:14,000 --> 00:01:19,000 +structure of the country in which it is collected, stored and processed. + +18 +00:01:19,000 --> 00:01:24,000 +This is important if you collect data from folks within the United States. + +19 +00:01:24,000 --> 00:01:29,000 +Your servers are here, your processes and data processing the data here. + +20 +00:01:30,000 --> 00:01:32,000 +But maybe your company is international. + +21 +00:01:32,000 --> 00:01:35,000 +You should still be following the United States data. + +22 +00:01:36,000 --> 00:01:39,000 +Now this is really important, especially when it comes to storing data. + +23 +00:01:39,000 --> 00:01:45,000 +Not because you decide to take data and store it somewhere else that doesn't have a lot of laws means + +24 +00:01:45,000 --> 00:01:49,000 +that you don't have to follow the law where you actually collected the data from. + +25 +00:01:49,000 --> 00:01:55,000 +Organizations must ensure that their data handling and storage comply with laws of those countries from + +26 +00:01:55,000 --> 00:01:56,000 +where we collected it. + +27 +00:01:56,000 --> 00:02:01,000 +For example, you collect EU citizens data, but you're storing that data in South Asia, which doesn't + +28 +00:02:01,000 --> 00:02:04,000 +have a ton of privacy laws. + +29 +00:02:04,000 --> 00:02:10,000 +You you're still under the jurisdiction of GDPR, doesn't matter where you're storing that particular + +30 +00:02:10,000 --> 00:02:11,000 +data. + +31 +00:02:11,000 --> 00:02:14,000 +This is particularly important for multinational companies. + +32 +00:02:14,000 --> 00:02:20,000 +You see, multinational companies are going to be collecting data from folks all around the world. + +33 +00:02:20,000 --> 00:02:26,000 +And what becomes cumbersome to deal with is all the different regulations that different countries may + +34 +00:02:26,000 --> 00:02:26,000 +have. + +35 +00:02:26,000 --> 00:02:32,000 +And then you now have to comply with all of those country requirements in order to keep the data secure, + +36 +00:02:32,000 --> 00:02:40,000 +but just not to keep it secure, to actually be doing the right thing and be doing it legally. + diff --git a/12 - Data Protection/006 Methods to Secure Data OB 3.3_en.srt b/12 - Data Protection/006 Methods to Secure Data OB 3.3_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..1ecd8ef8c4da5ecac347876aa9923910f62ea059 --- /dev/null +++ b/12 - Data Protection/006 Methods to Secure Data OB 3.3_en.srt @@ -0,0 +1,524 @@ +1 +00:00:00,000 --> 00:00:04,000 +In this video, I'm going to give you some ways that you should be secure in your data. + +2 +00:00:04,000 --> 00:00:09,000 +Now, this video acts more as a summary of the things that are most of the things that I've already + +3 +00:00:09,000 --> 00:00:11,000 +covered so far in this course. + +4 +00:00:11,000 --> 00:00:18,000 +So since this topic is all about data, let's take a look at some of the things that we should be doing + +5 +00:00:18,000 --> 00:00:20,000 +when it comes to securing our data. + +6 +00:00:20,000 --> 00:00:23,000 +Now, once again, I've gone through almost all of these things. + +7 +00:00:23,000 --> 00:00:28,000 +For example, in cryptography, we talked we talked about obfuscation and tokenization. + +8 +00:00:28,000 --> 00:00:35,000 +I'm going to give you also hashing will give you guys a quick, just a quick review of these particular + +9 +00:00:35,000 --> 00:00:36,000 +ways to secure data. + +10 +00:00:36,000 --> 00:00:42,000 +If you want more explanation on those topics, remember to revert back to those particular sections. + +11 +00:00:43,000 --> 00:00:48,000 +The first thing we'll start out with is the geographic restrictions of data. + +12 +00:00:48,000 --> 00:00:53,000 +This involves restricting the physical access where data could be stored and accessible. + +13 +00:00:53,000 --> 00:00:59,000 +By this, we spoke about when we talked about data sovereignty, where we collect that data, where + +14 +00:00:59,000 --> 00:01:07,000 +we're storing that data more than likely will determine the actual laws and regulations that applies + +15 +00:01:07,000 --> 00:01:08,000 +to the data. + +16 +00:01:08,000 --> 00:01:11,000 +You have to be sure that data is only stored, processed in certain locations. + +17 +00:01:11,000 --> 00:01:17,000 +You can't take data and store them in a location that is against the laws of that particular country. + +18 +00:01:17,000 --> 00:01:21,000 +Certain countries have laws that says the data can't be stored outside the country. + +19 +00:01:21,000 --> 00:01:26,000 +So if you decide if you determine that you're going to take this data and move it out of the country, + +20 +00:01:26,000 --> 00:01:29,000 +you're breaking the laws of that particular country. + +21 +00:01:29,000 --> 00:01:31,000 +This would be a type of a geographic restriction. + +22 +00:01:32,000 --> 00:01:33,000 +So by process. + +23 +00:01:34,000 --> 00:01:39,000 +Let's go through this by ensuring data is only processed, stored and processed in certain locations. + +24 +00:01:39,000 --> 00:01:44,000 +Organizations can more easily comply with this kind of regulation. + +25 +00:01:44,000 --> 00:01:46,000 +The next thing here is encryption. + +26 +00:01:46,000 --> 00:01:49,000 +The entire cryptographic section of this course reviews this. + +27 +00:01:49,000 --> 00:01:54,000 +Remember what encryption is converting data into a coded format which we call ciphertext. + +28 +00:01:54,000 --> 00:01:58,000 +That is unreasonable, that is unreadable without a specific key. + +29 +00:01:58,000 --> 00:02:02,000 +So you need that key to decrypt the data to get the plain text. + +30 +00:02:03,000 --> 00:02:05,000 +You can also you can also encrypt them using passwords. + +31 +00:02:05,000 --> 00:02:09,000 +Now this is fundamentally how we're going to protect data. + +32 +00:02:09,000 --> 00:02:14,000 +When most people think of think of encryption they think in confidentiality. + +33 +00:02:14,000 --> 00:02:18,000 +Remember encryption protects data at rest and data in transit. + +34 +00:02:19,000 --> 00:02:21,000 +Remember it really doesn't affect data in use. + +35 +00:02:21,000 --> 00:02:25,000 +Remember, data at rest is going to be things like hard drive based encryption versus data. + +36 +00:02:25,000 --> 00:02:29,000 +And use is going to be things like SSL, TLS encryption. + +37 +00:02:29,000 --> 00:02:34,000 +Now, anytime you encrypt data, you have to use a decryption key to decrypt that data. + +38 +00:02:34,000 --> 00:02:40,000 +99% of the time when people are thinking data security, they're thinking encryption. + +39 +00:02:41,000 --> 00:02:48,000 +Uh, also in the world of cryptography, in the cryptography section, we spoke about hashing. + +40 +00:02:48,000 --> 00:02:50,000 +Remember what hashing does? + +41 +00:02:50,000 --> 00:02:59,000 +Hashing transforms a string of characters into a into usually shorter fixed length value or basically + +42 +00:02:59,000 --> 00:03:00,000 +hashes itself. + +43 +00:03:00,000 --> 00:03:02,000 +These strings are hashes. + +44 +00:03:02,000 --> 00:03:08,000 +Now, what hashing does is that it basically encrypts something, produces a cryptographic hash, or + +45 +00:03:08,000 --> 00:03:11,000 +it hashes text of any length to produce a cryptographic hash. + +46 +00:03:11,000 --> 00:03:17,000 +These cryptographic hashes are known as one way, which means that you cannot take the hash and turn + +47 +00:03:17,000 --> 00:03:17,000 +it back. + +48 +00:03:18,000 --> 00:03:21,000 +Now it is common for us to do this in password. + +49 +00:03:21,000 --> 00:03:23,000 +This is what passwords Paul. + +50 +00:03:23,000 --> 00:03:25,000 +Passwords are hash. + +51 +00:03:25,000 --> 00:03:27,000 +So unlike encryption hashing is a one way function. + +52 +00:03:27,000 --> 00:03:31,000 +You cannot take the hash and go back to the actual data. + +53 +00:03:31,000 --> 00:03:32,000 +Why do we do this? + +54 +00:03:32,000 --> 00:03:36,000 +Hashing produces integrity of the information. + +55 +00:03:36,000 --> 00:03:44,000 +Remember that for your exam, once again there is a full 20 or 30 minute video on hashing in the cryptography + +56 +00:03:44,000 --> 00:03:45,000 +section. + +57 +00:03:45,000 --> 00:03:48,000 +The other thing that we have is what's called data masking. + +58 +00:03:48,000 --> 00:03:49,000 +All right. + +59 +00:03:49,000 --> 00:03:55,000 +Data masking is basically protecting the data from you not being able to see it. + +60 +00:03:55,000 --> 00:03:56,000 +But the data is still there. + +61 +00:03:56,000 --> 00:03:58,000 +They do this a lot in databases. + +62 +00:03:58,000 --> 00:04:00,000 +And you guys see this quite often. + +63 +00:04:00,000 --> 00:04:04,000 +Like when you're typing in a password on a computer, it doesn't actually show the password. + +64 +00:04:04,000 --> 00:04:09,000 +It shows you x, x, x or it may show you asterisks instead. + +65 +00:04:09,000 --> 00:04:10,000 +That's a form of data masking. + +66 +00:04:10,000 --> 00:04:17,000 +This is to protect sensitive data while still allowing users to work with the realistic format of the + +67 +00:04:17,000 --> 00:04:18,000 +actual data. + +68 +00:04:19,000 --> 00:04:21,000 +The other one here is tokenization. + +69 +00:04:21,000 --> 00:04:26,000 +Now we also have a whole video on this in the cryptography section. + +70 +00:04:26,000 --> 00:04:28,000 +So what is tokenization? + +71 +00:04:28,000 --> 00:04:34,000 +Well, tokenization is when we replace sensitive data with non-sensitive substitutes called tokens. + +72 +00:04:34,000 --> 00:04:41,000 +The token can represent a set of data organizations or systems and software will use that token as it + +73 +00:04:41,000 --> 00:04:44,000 +would use the actual sensitive data. + +74 +00:04:44,000 --> 00:04:48,000 +Only the token server will know that this token represents this data. + +75 +00:04:48,000 --> 00:04:54,000 +For example, you can go to a token server, give it your credit card number, your actual credit card + +76 +00:04:54,000 --> 00:04:54,000 +number. + +77 +00:04:54,000 --> 00:04:55,000 +It'll give you a token. + +78 +00:04:55,000 --> 00:05:01,000 +You can then use that token to purchase stuff all over the internet like you would on PayPal. + +79 +00:05:01,000 --> 00:05:07,000 +And then what would happen is no one would be able to take that token and decrypt it back to your credit + +80 +00:05:07,000 --> 00:05:07,000 +card. + +81 +00:05:08,000 --> 00:05:13,000 +They would have to hack the token server because the token server knows this token represents this credit + +82 +00:05:13,000 --> 00:05:13,000 +card. + +83 +00:05:13,000 --> 00:05:17,000 +So these tokens can be used in a system without ever showing your sensitive data. + +84 +00:05:17,000 --> 00:05:21,000 +So you're basically given all the vendors your token, but you're not actually giving them your credit + +85 +00:05:21,000 --> 00:05:23,000 +card information. + +86 +00:05:24,000 --> 00:05:25,000 +Obfuscation. + +87 +00:05:25,000 --> 00:05:29,000 +This is also not a topic we covered in cryptography. + +88 +00:05:29,000 --> 00:05:33,000 +This involves making data more ambiguous or unclear. + +89 +00:05:33,000 --> 00:05:38,000 +We obfuscate many things, whether in the obfuscation video. + +90 +00:05:38,000 --> 00:05:42,000 +I showed you guys how I obfuscated source code in an application. + +91 +00:05:42,000 --> 00:05:46,000 +We did that with JavaScript, and now it can be done using a variety of means, whether it's mixing + +92 +00:05:46,000 --> 00:05:49,000 +mixing data with other non-sensitive data. + +93 +00:05:49,000 --> 00:05:51,000 +Change in file name. + +94 +00:05:51,000 --> 00:05:56,000 +Basically, this makes it unclear obscure the meaning of actual data. + +95 +00:05:56,000 --> 00:05:58,000 +Now we do this a lot. + +96 +00:05:58,000 --> 00:05:59,000 +Obfuscation. + +97 +00:05:59,000 --> 00:06:00,000 +We do this a lot in source codes. + +98 +00:06:00,000 --> 00:06:04,000 +This protects the source code from easily being exploited. + +99 +00:06:04,000 --> 00:06:06,000 +Segmentation. + +100 +00:06:06,000 --> 00:06:14,000 +This area we covered in the network security segmentation is when you break your network in different + +101 +00:06:14,000 --> 00:06:20,000 +parts, especially like logical segmentations where we would do it utilizing things like VLANs. + +102 +00:06:20,000 --> 00:06:27,000 +So this divides the network into smaller segments, uh, to control access and reduce the risk of widespread + +103 +00:06:27,000 --> 00:06:28,000 +network breaches. + +104 +00:06:28,000 --> 00:06:34,000 +For example, if you break your network into ten different segments, maybe you have one for finance, + +105 +00:06:34,000 --> 00:06:40,000 +one for account and one for sales, marketing, management, research and development, inventory tracking, + +106 +00:06:40,000 --> 00:06:41,000 +and so on. + +107 +00:06:41,000 --> 00:06:46,000 +If one segment like sales get a particular virus, that virus is not going to go and infect other segments + +108 +00:06:46,000 --> 00:06:49,000 +because it blocks the flow of traffic. + +109 +00:06:49,000 --> 00:06:56,000 +This reduces cyber attacks or cyber breaches to one particular segment, so you can limit access to + +110 +00:06:56,000 --> 00:06:57,000 +sensitive data. + +111 +00:06:57,000 --> 00:07:03,000 +That's one of its main other points, because if you think about this, people in the sales don't need + +112 +00:07:03,000 --> 00:07:04,000 +access to accounting information. + +113 +00:07:04,000 --> 00:07:09,000 +If you segment it, people in sales can only see sales things. + +114 +00:07:11,000 --> 00:07:13,000 +Permission restrictions. + +115 +00:07:13,000 --> 00:07:15,000 +This is going to be like file permissions. + +116 +00:07:15,000 --> 00:07:16,000 +In this particular one. + +117 +00:07:16,000 --> 00:07:24,000 +You're going to set up an enforced policies that control who has access to what data and what are they + +118 +00:07:24,000 --> 00:07:24,000 +allowed to do with it. + +119 +00:07:24,000 --> 00:07:28,000 +So you could say someone can read this, they can write to it, but they can't. + +120 +00:07:28,000 --> 00:07:30,000 +They can't actually delete it. + +121 +00:07:30,000 --> 00:07:32,000 +They can't change permission to it. + +122 +00:07:32,000 --> 00:07:33,000 +So we're going to set permissions. + +123 +00:07:33,000 --> 00:07:34,000 +Now. + +124 +00:07:34,000 --> 00:07:40,000 +Permission restrictions is one of the most common and basic things we should be doing when we manage + +125 +00:07:40,000 --> 00:07:41,000 +security. + +126 +00:07:42,000 --> 00:07:42,000 +All right. + +127 +00:07:42,000 --> 00:07:44,000 +These were some basic things. + +128 +00:07:44,000 --> 00:07:46,000 +And once again we went over quite a lot of these. + +129 +00:07:46,000 --> 00:07:48,000 +And these here were some great reviews. + +130 +00:07:48,000 --> 00:07:51,000 +This is just a great review or list of things. + +131 +00:07:51,000 --> 00:07:56,000 +If you forgot, these are list of things that you can do to protect your data. + diff --git a/12 - Data Protection/007 Quick Quiz.html b/12 - Data Protection/007 Quick Quiz.html new file mode 100644 index 0000000000000000000000000000000000000000..d80b5290a80ebd039723665fb95a7dfbf7833dc1 --- /dev/null +++ b/12 - Data Protection/007 Quick Quiz.html @@ -0,0 +1,479 @@ + + + + + + + Quiz + + + + +
+
+

+

+
+
+
+ Score: 999 of + 999% +
+
Correct: 999
+
Incorrect: 999
+
+ +
+ + + + +
+ + + + diff --git a/13 - Common Security Techniques/001 Secure Baselines OB 4.1_en.srt b/13 - Common Security Techniques/001 Secure Baselines OB 4.1_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..7ddebf84ea4ce25978f524b78dcd3726bf1bb8c8 --- /dev/null +++ b/13 - Common Security Techniques/001 Secure Baselines OB 4.1_en.srt @@ -0,0 +1,568 @@ +1 +00:00:00,000 --> 00:00:07,000 +I remember working in organizations where every single workstation had different configurations. + +2 +00:00:07,000 --> 00:00:14,000 +There was no standardized base of configurations that was out there, and the organization had a lot + +3 +00:00:14,000 --> 00:00:20,000 +of trouble fixing things, because every time they would go to a machine, it would be configured different + +4 +00:00:20,000 --> 00:00:21,000 +than another machine. + +5 +00:00:21,000 --> 00:00:24,000 +This resulted in massive security holes. + +6 +00:00:24,000 --> 00:00:29,000 +Since there was no standardized configurations for all computers across the network, we weren't too + +7 +00:00:29,000 --> 00:00:31,000 +sure what machine was really secure. + +8 +00:00:31,000 --> 00:00:37,000 +With the right software and the right configs versus other machines just didn't have any. + +9 +00:00:37,000 --> 00:00:42,000 +And anytime new machines were brought in, there wasn't like a standard procedure of how to configure + +10 +00:00:42,000 --> 00:00:45,000 +this machine to make it secure to join the network. + +11 +00:00:45,000 --> 00:00:48,000 +You see what this organization lacked. + +12 +00:00:48,000 --> 00:00:51,000 +And this happens a lot in small businesses, by the way. + +13 +00:00:51,000 --> 00:00:58,000 +But this organization lack is what's called a baseline or what's known as baseline configs. + +14 +00:00:58,000 --> 00:01:01,000 +So in this topic let's talk about secure baselines. + +15 +00:01:01,000 --> 00:01:03,000 +So what exactly is this. + +16 +00:01:03,000 --> 00:01:10,000 +Well this refers to a set of security standards and configurations that an organization establishes + +17 +00:01:10,000 --> 00:01:12,000 +to protect its systems and its data. + +18 +00:01:12,000 --> 00:01:14,000 +Here's the perfect world. + +19 +00:01:15,000 --> 00:01:22,000 +In the perfect world, every single organization is going to have a standard set of configurations that + +20 +00:01:22,000 --> 00:01:26,000 +it applies to all the computers in its network. + +21 +00:01:26,000 --> 00:01:31,000 +Every time a computer is brought in, uh, it's probably wiped out. + +22 +00:01:31,000 --> 00:01:36,000 +It's given a standard installation of maybe windows with a standard set of configurations, security + +23 +00:01:36,000 --> 00:01:40,000 +software and functionality software like Microsoft Office. + +24 +00:01:40,000 --> 00:01:42,000 +Everything is configured in this way. + +25 +00:01:42,000 --> 00:01:43,000 +It's joined to the domain. + +26 +00:01:43,000 --> 00:01:49,000 +It has this level of, um, this level of patching applied to it and so on. + +27 +00:01:49,000 --> 00:01:50,000 +This is good. + +28 +00:01:50,000 --> 00:01:57,000 +Every machine has the same configuration in terms of security configurations of software and so on. + +29 +00:01:57,000 --> 00:02:00,000 +This helps for you to predict if anything can go wrong. + +30 +00:02:00,000 --> 00:02:02,000 +No more ad hoc. + +31 +00:02:02,000 --> 00:02:04,000 +This is what a baseline is. + +32 +00:02:04,000 --> 00:02:09,000 +They're developed based on industry best practices, regulatory requirements especially. + +33 +00:02:09,000 --> 00:02:15,000 +So let's say the this the computer would be in the financial department. + +34 +00:02:15,000 --> 00:02:21,000 +The financial department due to the type of data may follow, certain kinds of encryption or certain + +35 +00:02:21,000 --> 00:02:27,000 +kinds of configuration to match certain regulatory laws, or it may have organization specific needs. + +36 +00:02:27,000 --> 00:02:34,000 +Now, if this sounds good to you and you want to have a standardized configuration to all machines in + +37 +00:02:34,000 --> 00:02:38,000 +your organization, now remember the standardized configurations could be customized. + +38 +00:02:38,000 --> 00:02:44,000 +You can have a standard config for sales, standard config for finance, for management, and so on + +39 +00:02:44,000 --> 00:02:47,000 +as long as you have a good standardization going on. + +40 +00:02:47,000 --> 00:02:50,000 +If this sounds good, well here are the steps to doing it. + +41 +00:02:50,000 --> 00:02:54,000 +Let's go take a look at how the how to build a good secure baseline. + +42 +00:02:54,000 --> 00:02:59,000 +So the first step is going to be to establish then deploy then maintain. + +43 +00:02:59,000 --> 00:03:02,000 +The first step in doing a secure baseline is establish. + +44 +00:03:03,000 --> 00:03:08,000 +The first thing you have to do is you have to do what's called assessment and analysis. + +45 +00:03:09,000 --> 00:03:13,000 +What you're doing is you're going to assess the current security posture, like what's happening in + +46 +00:03:13,000 --> 00:03:14,000 +the in the company right here. + +47 +00:03:14,000 --> 00:03:16,000 +Where are we right now? + +48 +00:03:16,000 --> 00:03:22,000 +You know, before you embark on a trip to our journey to standardize your baseline, ask yourself, + +49 +00:03:22,000 --> 00:03:23,000 +where are we right now? + +50 +00:03:23,000 --> 00:03:24,000 +What's happening? + +51 +00:03:24,000 --> 00:03:29,000 +Then the next thing we want to do is we want to understand the needs of the business. + +52 +00:03:29,000 --> 00:03:31,000 +What type of threats and vulnerabilities do we have? + +53 +00:03:31,000 --> 00:03:33,000 +What type of threats do we face? + +54 +00:03:33,000 --> 00:03:38,000 +What kind of, for example, regulations do we face? + +55 +00:03:38,000 --> 00:03:41,000 +Then you want to start to define those standards. + +56 +00:03:41,000 --> 00:03:44,000 +Once you know, hey, this is what these are the threats. + +57 +00:03:44,000 --> 00:03:45,000 +These are the vulnerabilities. + +58 +00:03:45,000 --> 00:03:47,000 +These are the laws. + +59 +00:03:47,000 --> 00:03:50,000 +The next thing we're going to do is now we have to go out. + +60 +00:03:50,000 --> 00:03:54,000 +We have to start to define those configurations and controls. + +61 +00:03:54,000 --> 00:04:01,000 +You can go to companies like NIST or I should say government agencies like NIST, ISO and other kinds + +62 +00:04:01,000 --> 00:04:04,000 +of big name businesses out there. + +63 +00:04:04,000 --> 00:04:11,000 +Microsoft has standard baseline configs, two that you can now use in order to start to build your configuration. + +64 +00:04:11,000 --> 00:04:15,000 +Now, you might want to include all kinds of regulatory requirements. + +65 +00:04:15,000 --> 00:04:17,000 +The next thing you want to do is to document this. + +66 +00:04:17,000 --> 00:04:21,000 +The establish baseline configs and standards are documented. + +67 +00:04:21,000 --> 00:04:25,000 +And this is going to serve as a reference for implementing and maintaining your baseline. + +68 +00:04:25,000 --> 00:04:28,000 +Now before I move on, I want to give you an example. + +69 +00:04:29,000 --> 00:04:30,000 +Right. + +70 +00:04:30,000 --> 00:04:32,000 +I want to give you guys an example of all of these particular things here. + +71 +00:04:32,000 --> 00:04:38,000 +Now a baseline I'm going to give you an example of a baseline configuration that we have at Tia. + +72 +00:04:38,000 --> 00:04:40,000 +For student machines. + +73 +00:04:40,000 --> 00:04:47,000 +The baseline configure a secure baseline configuration is every time we buy a computer we do not buy + +74 +00:04:47,000 --> 00:04:48,000 +pre pre-built. + +75 +00:04:48,000 --> 00:04:49,000 +We build our own. + +76 +00:04:49,000 --> 00:04:54,000 +So every time a machine is comes off the assembly line, it's always a desktop. + +77 +00:04:54,000 --> 00:05:01,000 +The first thing we do is the machine has to have the latest installation of its firmware. + +78 +00:05:01,000 --> 00:05:03,000 +So we make sure firmwares are updated. + +79 +00:05:03,000 --> 00:05:08,000 +Windows is installed and fully patched at to that particular time. + +80 +00:05:08,000 --> 00:05:11,000 +We then install Microsoft Office. + +81 +00:05:11,000 --> 00:05:16,000 +We then do a variety of configurations to the group policy on the machine. + +82 +00:05:16,000 --> 00:05:21,000 +Since we run a decentralized network, we don't have a domain controller for our student workstations + +83 +00:05:21,000 --> 00:05:22,000 +because we change them up a lot. + +84 +00:05:22,000 --> 00:05:29,000 +Student accounts are created as standard account passwords are implemented, certain programs are blocked. + +85 +00:05:29,000 --> 00:05:32,000 +Things such as access to the control panel is wiped out. + +86 +00:05:32,000 --> 00:05:34,000 +So we have a certain set. + +87 +00:05:34,000 --> 00:05:41,000 +These are all configurations that has to get done before the machine can go on to the network and people + +88 +00:05:41,000 --> 00:05:43,000 +to start using it now. + +89 +00:05:44,000 --> 00:05:50,000 +Now that we have documented and this is all we want done, we get to deploy this configuration. + +90 +00:05:50,000 --> 00:05:57,000 +So implementation the secure baselines are implemented across the entire entire network. + +91 +00:05:57,000 --> 00:05:59,000 +This includes servers workstations. + +92 +00:05:59,000 --> 00:06:05,000 +Now I want to point out that secure baselines just doesn't only apply to workstations, they apply to + +93 +00:06:05,000 --> 00:06:05,000 +servers. + +94 +00:06:05,000 --> 00:06:09,000 +They're going to apply to routers, switches, firewalls and so on. + +95 +00:06:09,000 --> 00:06:14,000 +The best way to push this out is with image and software. + +96 +00:06:14,000 --> 00:06:21,000 +Image and software helps to automate the deployment of these configurations. + +97 +00:06:21,000 --> 00:06:22,000 +So what is an image. + +98 +00:06:22,000 --> 00:06:23,000 +So here's what we do. + +99 +00:06:23,000 --> 00:06:29,000 +The easiest way for us to ensure that all these machines have a standard set of configuration is we + +100 +00:06:29,000 --> 00:06:30,000 +take one machine. + +101 +00:06:30,000 --> 00:06:36,000 +We build this machine absolutely perfect with the right windows installation configurations of the group + +102 +00:06:36,000 --> 00:06:42,000 +policies, file permission, user accounts, installed software patches, and so on. + +103 +00:06:43,000 --> 00:06:45,000 +We then image that machine. + +104 +00:06:45,000 --> 00:06:49,000 +We pull out an image and then we apply that image to the other computers. + +105 +00:06:49,000 --> 00:06:51,000 +Now this can be done manually. + +106 +00:06:51,000 --> 00:06:52,000 +You know there's a variety. + +107 +00:06:52,000 --> 00:06:54,000 +You know we used to use a software. + +108 +00:06:54,000 --> 00:06:56,000 +It was really good called Clone Deploy. + +109 +00:06:56,000 --> 00:06:58,000 +There was tons of Imogen back in the days. + +110 +00:06:58,000 --> 00:07:00,000 +I'm not sure if this one still exists. + +111 +00:07:00,000 --> 00:07:03,000 +Very famous was Norton, Ghost or Enterprise goals. + +112 +00:07:03,000 --> 00:07:06,000 +Those are amazing software that you can just push images out. + +113 +00:07:06,000 --> 00:07:08,000 +Helps to automate it. + +114 +00:07:08,000 --> 00:07:09,000 +When it's done. + +115 +00:07:09,000 --> 00:07:14,000 +You want to verify and make sure that after the deployment the configurations are there. + +116 +00:07:14,000 --> 00:07:15,000 +Compliance check. + +117 +00:07:15,000 --> 00:07:18,000 +Make sure that they are configured to the standard. + +118 +00:07:18,000 --> 00:07:21,000 +Go through the machines and verify whatever you had set up. + +119 +00:07:21,000 --> 00:07:24,000 +Whatever your company wanted is actually there. + +120 +00:07:24,000 --> 00:07:26,000 +Now comes maintenance. + +121 +00:07:28,000 --> 00:07:31,000 +This is the hard part, trust me. + +122 +00:07:31,000 --> 00:07:36,000 +You see, when the machine goes into production, people start installing things. + +123 +00:07:36,000 --> 00:07:39,000 +People start requesting changes. + +124 +00:07:39,000 --> 00:07:44,000 +The machine may lose some of its patches or not get updated to the current patches. + +125 +00:07:44,000 --> 00:07:49,000 +So you have to make sure that you continuously monitor. + +126 +00:07:49,000 --> 00:07:51,000 +You have to audit machines. + +127 +00:07:51,000 --> 00:07:55,000 +So continuously monitoring is to ensure the system remains in compliance. + +128 +00:07:55,000 --> 00:07:58,000 +No one is changing those configurations. + +129 +00:07:58,000 --> 00:07:59,000 +Audit them. + +130 +00:07:59,000 --> 00:08:01,000 +Audit them means to literally go and check them. + +131 +00:08:01,000 --> 00:08:08,000 +Take a couple of machines and couple departments at random and see, well, are they actually still + +132 +00:08:08,000 --> 00:08:11,000 +in or still on the baseline? + +133 +00:08:12,000 --> 00:08:17,000 +You want to make sure that you continuously update and patch machines. + +134 +00:08:17,000 --> 00:08:22,000 +I have never seen a baseline that didn't have updated patches, and then ongoing training and awareness + +135 +00:08:22,000 --> 00:08:24,000 +let people know that there is a baseline. + +136 +00:08:24,000 --> 00:08:27,000 +We do have a program for this and all texts coming in. + +137 +00:08:27,000 --> 00:08:29,000 +All users are aware of your baseline. + +138 +00:08:31,000 --> 00:08:36,000 +Do not manage your workstations, your computers, your server or your network. + +139 +00:08:36,000 --> 00:08:37,000 +AD hoc. + +140 +00:08:38,000 --> 00:08:43,000 +Every machine, especially when they're bound to departments, should have a standard set of configurations, + +141 +00:08:43,000 --> 00:08:47,000 +and those standard set of configurations help you to keep your network secure. + +142 +00:08:47,000 --> 00:08:53,000 +And this is one of the reasons I should say the main reasons that we should be using baselines. + diff --git a/13 - Common Security Techniques/002 Hardening Devices OB 4.1_en.srt b/13 - Common Security Techniques/002 Hardening Devices OB 4.1_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..abddda0949a5b7b2e1450cf48ebadb2a9104a214 --- /dev/null +++ b/13 - Common Security Techniques/002 Hardening Devices OB 4.1_en.srt @@ -0,0 +1,1088 @@ +1 +00:00:00,000 --> 00:00:06,000 +On your network, you're going to have a wide variety of devices from mobile devices, routers, IoT + +2 +00:00:06,000 --> 00:00:08,000 +devices, and everything else in between. + +3 +00:00:08,000 --> 00:00:15,000 +In this video, I want to do a quick review of how to secure a wide variety of devices on your network. + +4 +00:00:15,000 --> 00:00:16,000 +So let's knock this out. + +5 +00:00:16,000 --> 00:00:19,000 +Now this is more like a review video. + +6 +00:00:19,000 --> 00:00:20,000 +That's something you should be learning new. + +7 +00:00:20,000 --> 00:00:22,000 +As I've covered most of these things. + +8 +00:00:22,000 --> 00:00:24,000 +The team here is called Harden. + +9 +00:00:24,000 --> 00:00:24,000 +It. + +10 +00:00:24,000 --> 00:00:26,000 +Harden makes things more secure. + +11 +00:00:26,000 --> 00:00:27,000 +Harden against what. + +12 +00:00:28,000 --> 00:00:29,000 +Harden against cyber attacks. + +13 +00:00:29,000 --> 00:00:31,000 +That's what this is. + +14 +00:00:31,000 --> 00:00:37,000 +So it refers to the process of strengthening various hardware components to make them more secure. + +15 +00:00:37,000 --> 00:00:41,000 +This is going to involve implementing different types of security measures and different configurations + +16 +00:00:41,000 --> 00:00:43,000 +to these devices. + +17 +00:00:43,000 --> 00:00:45,000 +So let's get started. + +18 +00:00:45,000 --> 00:00:46,000 +And all of these different things. + +19 +00:00:46,000 --> 00:00:52,000 +Number one we're going to talk about what I consider device that most people spend most of their time + +20 +00:00:52,000 --> 00:00:53,000 +on. + +21 +00:00:53,000 --> 00:00:56,000 +This one little thing, our mobile devices. + +22 +00:00:56,000 --> 00:01:03,000 +Now when it comes to mobile devices such as my phone now this video is not about functionality. + +23 +00:01:03,000 --> 00:01:03,000 +All right? + +24 +00:01:03,000 --> 00:01:06,000 +This video is just about how do we secure these devices. + +25 +00:01:06,000 --> 00:01:08,000 +So the first thing we want to do is strong authentication. + +26 +00:01:08,000 --> 00:01:10,000 +You guys should have a strong Pin. + +27 +00:01:10,000 --> 00:01:12,000 +You should have dual authentication. + +28 +00:01:12,000 --> 00:01:15,000 +You can put pins and biometrics. + +29 +00:01:15,000 --> 00:01:17,000 +The data on these devices are encrypted. + +30 +00:01:17,000 --> 00:01:18,000 +And that's good. + +31 +00:01:18,000 --> 00:01:23,000 +If not you want to make sure that encryption is is enabled. + +32 +00:01:23,000 --> 00:01:25,000 +Installation of security software. + +33 +00:01:25,000 --> 00:01:30,000 +It boggles my mind that many devices, many people don't have antivirus software installed on their + +34 +00:01:30,000 --> 00:01:31,000 +devices. + +35 +00:01:31,000 --> 00:01:36,000 +You want to be able to control app permissions, and a lot of mobile devices does allow you to control + +36 +00:01:36,000 --> 00:01:37,000 +that. + +37 +00:01:37,000 --> 00:01:39,000 +Certain apps cannot access certain data. + +38 +00:01:39,000 --> 00:01:44,000 +Anytime you install an app, and the app asks you to access to certain data, such as your phone book + +39 +00:01:44,000 --> 00:01:46,000 +or your geolocation. + +40 +00:01:46,000 --> 00:01:49,000 +Unless you really need that app, it's probably not a good idea. + +41 +00:01:49,000 --> 00:01:55,000 +The more app that has access you have granted access to your private information is, the bigger the + +42 +00:01:55,000 --> 00:01:56,000 +attack surface. + +43 +00:01:56,000 --> 00:02:02,000 +Because if one of those apps ever get a vulnerability, your data is history, regularly updated. + +44 +00:02:03,000 --> 00:02:06,000 +Samsung pushes updates and a consistent basis. + +45 +00:02:06,000 --> 00:02:12,000 +Maybe on a weekly basis you should be updating apps and your operating system as much as possible. + +46 +00:02:12,000 --> 00:02:15,000 +It also included you secure Wi-Fi. + +47 +00:02:15,000 --> 00:02:17,000 +Don't join public Wi-Fi. + +48 +00:02:17,000 --> 00:02:19,000 +Public Wi-Fi are bad news. + +49 +00:02:19,000 --> 00:02:22,000 +You don't know who's on there or where it's coming from. + +50 +00:02:22,000 --> 00:02:27,000 +The best thing to do is always try to use your phone internet connection to your ISP and if you do need + +51 +00:02:27,000 --> 00:02:28,000 +a Wi-Fi. + +52 +00:02:29,000 --> 00:02:34,000 +If you do need some kind of Wi-Fi connection, like on your laptop, you can always do internet connection + +53 +00:02:34,000 --> 00:02:36,000 +sharing from your phone, but never use public Wi-Fi. + +54 +00:02:36,000 --> 00:02:38,000 +I try to stay off of public Wi-Fi. + +55 +00:02:38,000 --> 00:02:45,000 +Use secure Wi-Fi, and if you ever connect to a public Wi-Fi, you need to get to your corporate network. + +56 +00:02:45,000 --> 00:02:48,000 +Make sure to use a VPN for another layer of encryption. + +57 +00:02:49,000 --> 00:02:50,000 +Okay, moving on here. + +58 +00:02:50,000 --> 00:02:50,000 +Workstation. + +59 +00:02:50,000 --> 00:02:52,000 +This is what you're going to have at work. + +60 +00:02:52,000 --> 00:02:54,000 +Like that picture shows you. + +61 +00:02:54,000 --> 00:02:57,000 +So when it comes to workstations, what are we going to do? + +62 +00:02:57,000 --> 00:03:04,000 +Well, good endpoint security software should give you things like antivirus, anti-malware, firewalls + +63 +00:03:04,000 --> 00:03:06,000 +are going to be some of the most common things. + +64 +00:03:06,000 --> 00:03:11,000 +You want to make sure that you're always patching all the time. + +65 +00:03:11,000 --> 00:03:12,000 +I like automatic updates. + +66 +00:03:12,000 --> 00:03:15,000 +I understand that certain organizations like to test updates. + +67 +00:03:15,000 --> 00:03:18,000 +That's fine, but roll out those updates as soon as you could. + +68 +00:03:18,000 --> 00:03:20,000 +Good access controls, for example. + +69 +00:03:20,000 --> 00:03:23,000 +File permissions is going to be important. + +70 +00:03:23,000 --> 00:03:25,000 +Remember the principles of least privileges and so on. + +71 +00:03:25,000 --> 00:03:30,000 +Users shouldn't have admin privileges on the boxes, and something that a lot of people don't think + +72 +00:03:30,000 --> 00:03:34,000 +about when it comes to workstations is the actual physical security. + +73 +00:03:34,000 --> 00:03:37,000 +You know, here's something in organizations. + +74 +00:03:37,000 --> 00:03:43,000 +Sometimes organizations will the cases are actually padlocked. + +75 +00:03:43,000 --> 00:03:46,000 +You can't get into the case to take out the hard drive. + +76 +00:03:46,000 --> 00:03:50,000 +Malicious employees, when they want to steal data, copies all the data to the hard drive. + +77 +00:03:51,000 --> 00:03:55,000 +It opens the case, takes the hard drive out, put in their pocket and walk out the organization and + +78 +00:03:55,000 --> 00:03:57,000 +your data is leaving with them. + +79 +00:03:57,000 --> 00:03:59,000 +So you may. + +80 +00:03:59,000 --> 00:04:04,000 +Or maybe you should physically protect the workstations on those desks. + +81 +00:04:04,000 --> 00:04:08,000 +Of course, you want to also have things like the TPM chip. + +82 +00:04:08,000 --> 00:04:16,000 +TPM chips enables BitLocker encryption or hard disk hard drive based encryptions on those machines. + +83 +00:04:16,000 --> 00:04:18,000 +The next thing you have is switches. + +84 +00:04:18,000 --> 00:04:19,000 +All right. + +85 +00:04:19,000 --> 00:04:24,000 +So if you remember we talked about securing these giant switches. + +86 +00:04:24,000 --> 00:04:28,000 +And this is a 24 port Cisco switch that I have here. + +87 +00:04:28,000 --> 00:04:32,000 +We want to be able to secure these kinds of devices. + +88 +00:04:32,000 --> 00:04:33,000 +Now how do we harden switches. + +89 +00:04:34,000 --> 00:04:39,000 +Switches especially managed switches comes with a lot of services that you may not need. + +90 +00:04:39,000 --> 00:04:41,000 +Make sure to shut them off. + +91 +00:04:41,000 --> 00:04:48,000 +In short that the management, the secure management and the login to its interfaces can only be done + +92 +00:04:48,000 --> 00:04:51,000 +in certain locations or to certain interfaces. + +93 +00:04:51,000 --> 00:04:53,000 +Restrict those IP addresses. + +94 +00:04:53,000 --> 00:04:58,000 +All managed switches like I have here supports Vlan VLANs. + +95 +00:04:58,000 --> 00:04:59,000 +Allows you to segment your network. + +96 +00:04:59,000 --> 00:05:02,000 +Implement a VLANs on all these switches. + +97 +00:05:02,000 --> 00:05:05,000 +Utilize ACLs to control traffic in and out the switch. + +98 +00:05:05,000 --> 00:05:13,000 +Now just like you would have on a windows box or Linux or Apple, you must update the switches firmware. + +99 +00:05:13,000 --> 00:05:17,000 +The firmware updates is how we would apply like Windows Update. + +100 +00:05:18,000 --> 00:05:23,000 +You also want to monitor the monitor them for any unusual activities against them. + +101 +00:05:24,000 --> 00:05:27,000 +Routers are going to be just like switches. + +102 +00:05:27,000 --> 00:05:31,000 +Now I know you guys have your the router that was given to you by your ISP. + +103 +00:05:31,000 --> 00:05:36,000 +Those routers are probably going to be something similar to what I have here. + +104 +00:05:36,000 --> 00:05:42,000 +Now these devices has to be updated just like your switches are. + +105 +00:05:42,000 --> 00:05:46,000 +You want to make sure a couple of things change the default passwords on these devices. + +106 +00:05:46,000 --> 00:05:51,000 +These devices does come at a lot of services that you may or may not need. + +107 +00:05:51,000 --> 00:05:53,000 +Make sure to update the firmware. + +108 +00:05:54,000 --> 00:05:55,000 +Strong encryption on them. + +109 +00:05:55,000 --> 00:06:00,000 +And when you configure the Wi-Fi, especially like on this one, you want to make sure you set up with + +110 +00:06:00,000 --> 00:06:02,000 +the latest wpa3. + +111 +00:06:02,000 --> 00:06:04,000 +If not at minimum Wpa2. + +112 +00:06:04,000 --> 00:06:06,000 +Make sure you use good passwords. + +113 +00:06:06,000 --> 00:06:08,000 +Configure the firewalls on them. + +114 +00:06:08,000 --> 00:06:12,000 +Don't open unnecessary ports on these particular if these particular devices. + +115 +00:06:12,000 --> 00:06:16,000 +If it's a firewall built in and configure that intrusion prevention system. + +116 +00:06:16,000 --> 00:06:19,000 +Now if your device. + +117 +00:06:20,000 --> 00:06:22,000 +If the device itself. + +118 +00:06:22,000 --> 00:06:29,000 +Supports VPN and you want to allow access in, then you may want to enable VPNs on the devices. + +119 +00:06:29,000 --> 00:06:31,000 +When it comes to cloud. + +120 +00:06:31,000 --> 00:06:39,000 +Cloud brings so much functionality, but it also brings a lot of problems. + +121 +00:06:39,000 --> 00:06:40,000 +Cloud. + +122 +00:06:41,000 --> 00:06:48,000 +Cloud, you know, reduces cost, increases availability, gives you tons of different services that + +123 +00:06:48,000 --> 00:06:50,000 +you can only dream of, have on. + +124 +00:06:50,000 --> 00:06:56,000 +The problem with cloud is that it brings in quite a lot of different issues. + +125 +00:06:57,000 --> 00:06:58,000 +Data being lost. + +126 +00:06:58,000 --> 00:07:03,000 +Remember, if I can access my data in the cloud from anywhere, you can also access my data in the cloud + +127 +00:07:03,000 --> 00:07:04,000 +from anywhere. + +128 +00:07:04,000 --> 00:07:06,000 +Maybe you're a bad person. + +129 +00:07:06,000 --> 00:07:08,000 +And you you want to hack people's data. + +130 +00:07:09,000 --> 00:07:13,000 +You find out my password on my login credentials on grass. + +131 +00:07:13,000 --> 00:07:15,000 +So you want to make sure that you secure it. + +132 +00:07:15,000 --> 00:07:16,000 +How are we going to do this? + +133 +00:07:16,000 --> 00:07:21,000 +Well, like I said, because I can access it anywhere. + +134 +00:07:21,000 --> 00:07:21,000 +So can you. + +135 +00:07:21,000 --> 00:07:24,000 +We got to implement strong identity and access management. + +136 +00:07:24,000 --> 00:07:27,000 +This is an IAM identity and access management. + +137 +00:07:27,000 --> 00:07:30,000 +This is going to be like multiple factor authentication. + +138 +00:07:30,000 --> 00:07:33,000 +Like no one should be able to log in to the cloud with just a password. + +139 +00:07:33,000 --> 00:07:34,000 +They put in a password. + +140 +00:07:34,000 --> 00:07:40,000 +Let them do a multi factor authentication, send a code to my phone, send a code to my email. + +141 +00:07:40,000 --> 00:07:42,000 +So it's not just a single factor authentication. + +142 +00:07:42,000 --> 00:07:44,000 +Make sure that you encrypt the data in the cloud. + +143 +00:07:44,000 --> 00:07:46,000 +Data coming out the cloud. + +144 +00:07:46,000 --> 00:07:52,000 +Make sure you're utilizing secure protocols like Https or SSL in there. + +145 +00:07:52,000 --> 00:07:54,000 +Use secure APIs. + +146 +00:07:54,000 --> 00:07:56,000 +APIs also need encryption APIs. + +147 +00:07:56,000 --> 00:08:00,000 +How we're going to transfer data between applications in the cloud and outside the cloud. + +148 +00:08:00,000 --> 00:08:03,000 +Make sure we put good security controls. + +149 +00:08:03,000 --> 00:08:10,000 +Now, cloud providers such as AWS will tell you some of the best practices they recommend when using + +150 +00:08:10,000 --> 00:08:11,000 +their cloud services. + +151 +00:08:11,000 --> 00:08:12,000 +You're going to want to make sure you follow that. + +152 +00:08:13,000 --> 00:08:14,000 +Service. + +153 +00:08:14,000 --> 00:08:16,000 +We talked about workstations. + +154 +00:08:16,000 --> 00:08:19,000 +Let's talk about servers, servers themselves. + +155 +00:08:20,000 --> 00:08:26,000 +Is going to follow almost the same thing as workstations, because technically they're just a workstation + +156 +00:08:26,000 --> 00:08:27,000 +used by a lot of people. + +157 +00:08:27,000 --> 00:08:32,000 +So service, we want to make sure, number one, you got to keep your servers updated, just like with + +158 +00:08:32,000 --> 00:08:38,000 +any other computer, with anything in your network, anything that runs software needs to be updated. + +159 +00:08:38,000 --> 00:08:40,000 +You want to minimize the number of running services. + +160 +00:08:40,000 --> 00:08:45,000 +Remember, the more application, the more services you're running on there. + +161 +00:08:45,000 --> 00:08:47,000 +Maybe you're running an FTP, maybe you're running telnet. + +162 +00:08:47,000 --> 00:08:51,000 +The maybe you're running a print server, maybe you're running a particular file service. + +163 +00:08:51,000 --> 00:08:58,000 +The more services you're running, the more vulnerable the bigger your attack surface. + +164 +00:08:58,000 --> 00:09:01,000 +The best thing here we can do is to reduce them. + +165 +00:09:01,000 --> 00:09:09,000 +If this server only serves as a web server disabled print, disable FTP or shut it off or make sure + +166 +00:09:09,000 --> 00:09:10,000 +it's not installed. + +167 +00:09:10,000 --> 00:09:13,000 +Telnet file services. + +168 +00:09:13,000 --> 00:09:19,000 +If it's only a web server, let it be just a good web server. + +169 +00:09:19,000 --> 00:09:22,000 +A hardened web server only does one thing serves web pages. + +170 +00:09:22,000 --> 00:09:27,000 +So disable all those services that it doesn't need strong authentication. + +171 +00:09:27,000 --> 00:09:31,000 +Make sure sometimes a windows box may only support password. + +172 +00:09:31,000 --> 00:09:33,000 +Make sure it's a long 12 digit password. + +173 +00:09:33,000 --> 00:09:36,000 +At least use firewalls and intrusion detection systems. + +174 +00:09:36,000 --> 00:09:39,000 +You're going to get this with good endpoint security. + +175 +00:09:39,000 --> 00:09:44,000 +Uh, and physically of course securing your servers I don't care how secure. + +176 +00:09:44,000 --> 00:09:45,000 +I don't care how secure. + +177 +00:09:45,000 --> 00:09:51,000 +You got your firewalls, intrusion detection system, all the great software you're using. + +178 +00:09:51,000 --> 00:09:56,000 +If I can walk in your organization and pick up your server, just walk back out. + +179 +00:09:57,000 --> 00:09:58,000 +You really don't have much security, do you? + +180 +00:09:59,000 --> 00:10:04,000 +So make sure you physically secure it and put them in server rooms, locked server rooms, put them + +181 +00:10:04,000 --> 00:10:06,000 +on racks where they are physically bolted in. + +182 +00:10:06,000 --> 00:10:08,000 +Make it hard to get out. + +183 +00:10:09,000 --> 00:10:10,000 +IX. + +184 +00:10:10,000 --> 00:10:13,000 +This one here scares the hell out of me. + +185 +00:10:14,000 --> 00:10:16,000 +Remember what IX systems are. + +186 +00:10:17,000 --> 00:10:23,000 +IX industrial controls, the control systems and basically skater based systems. + +187 +00:10:23,000 --> 00:10:28,000 +Now, the problem with these systems, you know, the thing that scares me, that creates a problem + +188 +00:10:28,000 --> 00:10:30,000 +is that these things controls. + +189 +00:10:30,000 --> 00:10:33,000 +If you remember, we did discuss this earlier in the class. + +190 +00:10:33,000 --> 00:10:40,000 +These things controls our water supply, uh, gas and power. + +191 +00:10:40,000 --> 00:10:41,000 +All right. + +192 +00:10:41,000 --> 00:10:44,000 +These are some of the things that controls this is industrial equipment. + +193 +00:10:44,000 --> 00:10:51,000 +And because they're industrial based systems, when these systems, if they get hacked and they go down, + +194 +00:10:51,000 --> 00:10:54,000 +now we start to disrupt lives and people could potentially dies. + +195 +00:10:54,000 --> 00:10:57,000 +Communities can be without water. + +196 +00:10:57,000 --> 00:11:00,000 +Communities can be without power for extended periods of time. + +197 +00:11:00,000 --> 00:11:02,000 +People can lose their lives because of this. + +198 +00:11:02,000 --> 00:11:04,000 +What happens if all the power shuts off? + +199 +00:11:04,000 --> 00:11:09,000 +One day, all the traffic lights start shutting off and traffic accidents start happening. + +200 +00:11:09,000 --> 00:11:09,000 +People start dying. + +201 +00:11:09,000 --> 00:11:13,000 +What happens if there's no water in a community for an extended period of time? + +202 +00:11:13,000 --> 00:11:18,000 +What if there's no power in a community for an extended period of time and hospitals lose power and + +203 +00:11:18,000 --> 00:11:20,000 +their generators don't last two weeks? + +204 +00:11:20,000 --> 00:11:21,000 +Now what happens? + +205 +00:11:21,000 --> 00:11:22,000 +People die. + +206 +00:11:22,000 --> 00:11:23,000 +This is serious business. + +207 +00:11:23,000 --> 00:11:25,000 +So we need to protect these systems. + +208 +00:11:25,000 --> 00:11:27,000 +First of all, you should segment them off. + +209 +00:11:27,000 --> 00:11:30,000 +Keep SCADA systems off the network. + +210 +00:11:30,000 --> 00:11:33,000 +Maybe even air gapped them so no one can get to them. + +211 +00:11:33,000 --> 00:11:34,000 +Restricting their access. + +212 +00:11:34,000 --> 00:11:36,000 +Their physical access like air gap. + +213 +00:11:36,000 --> 00:11:38,000 +Disable unneeded services. + +214 +00:11:38,000 --> 00:11:45,000 +Remember reduce the attack surface if you could patch it, but be careful how you patch it because patching + +215 +00:11:45,000 --> 00:11:46,000 +can bring these systems down. + +216 +00:11:47,000 --> 00:11:51,000 +And of course, consistent monitoring of these systems. + +217 +00:11:53,000 --> 00:11:54,000 +Embedded systems. + +218 +00:11:54,000 --> 00:11:56,000 +Now we went over embedded systems. + +219 +00:11:56,000 --> 00:11:57,000 +Right. + +220 +00:11:57,000 --> 00:12:01,000 +Embedded systems are going to be systems generally within another system performs a very particular + +221 +00:12:01,000 --> 00:12:02,000 +function. + +222 +00:12:02,000 --> 00:12:05,000 +You want to make sure that they have a secure boot process. + +223 +00:12:05,000 --> 00:12:11,000 +What that means is that no one can inject codes into the boot process to take them over, give them + +224 +00:12:11,000 --> 00:12:12,000 +least access. + +225 +00:12:12,000 --> 00:12:13,000 +All right. + +226 +00:12:13,000 --> 00:12:15,000 +Least access to in terms of access control. + +227 +00:12:16,000 --> 00:12:21,000 +Embedded systems is generally going to communicate to another system, use secure protocols or secure + +228 +00:12:21,000 --> 00:12:22,000 +communication channel. + +229 +00:12:22,000 --> 00:12:24,000 +And of course, audit them on a regular basis. + +230 +00:12:24,000 --> 00:12:29,000 +A lot of these embedded systems, for example, like the embedded systems you may have on your TV to + +231 +00:12:29,000 --> 00:12:33,000 +powers up your TV operating system, have when was the last you updated them? + +232 +00:12:33,000 --> 00:12:35,000 +Because it could have vulnerabilities. + +233 +00:12:36,000 --> 00:12:38,000 +Real time operating system. + +234 +00:12:38,000 --> 00:12:43,000 +Really small system performed generally a very particular task, these things. + +235 +00:12:43,000 --> 00:12:46,000 +The good thing is that they don't have a lot of services running. + +236 +00:12:46,000 --> 00:12:52,000 +They're very small and the very quick, but if they have a number of services that they could perform, + +237 +00:12:52,000 --> 00:12:58,000 +reduce that good access control, make them hard to get good communication protocol. + +238 +00:12:58,000 --> 00:13:03,000 +And once again, consistent updating of these systems is important. + +239 +00:13:04,000 --> 00:13:08,000 +Throughout your house, you're going to have tons of IoT devices. + +240 +00:13:09,000 --> 00:13:10,000 +Remember what IoT is. + +241 +00:13:10,000 --> 00:13:11,000 +Internet of things. + +242 +00:13:11,000 --> 00:13:18,000 +Anything that connects to the internet, your fridge, your TV, uh, your car. + +243 +00:13:19,000 --> 00:13:24,000 +Your watch, all these kinds of devices that now connects to the internet. + +244 +00:13:24,000 --> 00:13:27,000 +Now what we need to do is we need to secure them. + +245 +00:13:27,000 --> 00:13:30,000 +First of all, a lot of them come with default passwords. + +246 +00:13:30,000 --> 00:13:31,000 +Change the default password. + +247 +00:13:31,000 --> 00:13:38,000 +You want to make sure that the device is configured not to use things like Http, but to use Https, + +248 +00:13:38,000 --> 00:13:45,000 +not to use FTP, use SftP or ftps so it's secure, always updated, disable unneeded services, and + +249 +00:13:45,000 --> 00:13:49,000 +of course implement security at what's called the application layer. + +250 +00:13:49,000 --> 00:13:53,000 +This is going to be doing a lot to ensure that it has the right application on it. + +251 +00:13:53,000 --> 00:13:59,000 +In other words, good passwords like I mentioned don't use FTP Ftps. + +252 +00:13:59,000 --> 00:14:02,000 +All right quick review now. + +253 +00:14:02,000 --> 00:14:05,000 +There is now that I've gone through it. + +254 +00:14:06,000 --> 00:14:12,000 +If you notice there is a standard set of things. + +255 +00:14:12,000 --> 00:14:15,000 +Doesn't matter what the device is, you should be doing. + +256 +00:14:15,000 --> 00:14:16,000 +All right. + +257 +00:14:16,000 --> 00:14:21,000 +Let me go through that quickly, because these were all the devices that we should be familiar with + +258 +00:14:21,000 --> 00:14:22,000 +for our exam. + +259 +00:14:22,000 --> 00:14:25,000 +But there was a standard set of things that was in every one of them. + +260 +00:14:25,000 --> 00:14:30,000 +Number one updates anything that's software related. + +261 +00:14:30,000 --> 00:14:37,000 +Updated number two, reducing the attack surface, if anything is configurable, reduce its attack surface + +262 +00:14:37,000 --> 00:14:42,000 +by not installing applications and services that it just doesn't need to run. + +263 +00:14:43,000 --> 00:14:47,000 +The other thing you want to do is, of course change default credentials and have good authentication + +264 +00:14:47,000 --> 00:14:50,000 +mechanism across all these devices. + +265 +00:14:50,000 --> 00:14:52,000 +These were three of the most common things we saw. + +266 +00:14:52,000 --> 00:14:57,000 +These are the three of the most common things that you're probably going to be implementing. + +267 +00:14:57,000 --> 00:15:02,000 +The other common things that doesn't apply to all of them are going to be things that can stall an anti-malware, + +268 +00:15:02,000 --> 00:15:07,000 +um, things like antivirus, firewalls, IDs, systems, which you can't do that for every device. + +269 +00:15:07,000 --> 00:15:13,000 +You may not have the ability to go onto your TV and install an anti-malware software, but at minimum, + +270 +00:15:13,000 --> 00:15:14,000 +you should change its password. + +271 +00:15:14,000 --> 00:15:15,000 +All right. + +272 +00:15:15,000 --> 00:15:20,000 +Remember these methods to keeping all of the devices in your network secure. + diff --git a/13 - Common Security Techniques/003 Installations of Mobile Devices OB 4.1_en.srt b/13 - Common Security Techniques/003 Installations of Mobile Devices OB 4.1_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..1271ec1aa1b697fd1933f78252f9b4cfb23729ca --- /dev/null +++ b/13 - Common Security Techniques/003 Installations of Mobile Devices OB 4.1_en.srt @@ -0,0 +1,336 @@ +1 +00:00:00,000 --> 00:00:07,000 +Every single organization that I know of has some kind of mobile devices that they have running, whether + +2 +00:00:07,000 --> 00:00:11,000 +it's phones, tablets or even laptops. + +3 +00:00:11,000 --> 00:00:17,000 +Now, in order to make these mobile devices work, you have to install the wireless connection needed + +4 +00:00:17,000 --> 00:00:17,000 +to make them work. + +5 +00:00:17,000 --> 00:00:24,000 +So in this video, I want to take a look at two things that we should be considering when we're installing + +6 +00:00:24,000 --> 00:00:25,000 +mobile devices. + +7 +00:00:25,000 --> 00:00:26,000 +Two things we should be doing. + +8 +00:00:26,000 --> 00:00:33,000 +Basically, we should be doing a site survey and creating a heat map when we do install our mobile devices, + +9 +00:00:33,000 --> 00:00:37,000 +and I'm our wireless networks, and this is going to be something that you should be doing. + +10 +00:00:37,000 --> 00:00:39,000 +Like if you don't do this, you're going to be in big trouble. + +11 +00:00:39,000 --> 00:00:45,000 +And I'll explain why, especially with the heat map coming up in a few minutes, because wireless devices + +12 +00:00:45,000 --> 00:00:47,000 +require good performance. + +13 +00:00:47,000 --> 00:00:51,000 +In other words, depending on where I am in the network, I need good signal. + +14 +00:00:51,000 --> 00:00:54,000 +And of course, you want to make sure that they are secure. + +15 +00:00:54,000 --> 00:00:56,000 +So the first thing we want to talk about. + +16 +00:00:56,000 --> 00:01:00,000 +Is going to be a site survey. + +17 +00:01:00,000 --> 00:01:02,000 +Now, what exactly is a site survey? + +18 +00:01:02,000 --> 00:01:11,000 +Well, a site survey is literally walking around and quote unquote surveying the physical site that + +19 +00:01:11,000 --> 00:01:14,000 +actually needs the wireless signals. + +20 +00:01:14,000 --> 00:01:19,000 +So it involves identifying potential security vulnerabilities, like areas where the wireless signal + +21 +00:01:19,000 --> 00:01:22,000 +might bleed outside the intended coverage area. + +22 +00:01:22,000 --> 00:01:29,000 +For example, if you are installing a company's Wi-Fi, I should not be able to stand across the road + +23 +00:01:29,000 --> 00:01:33,000 +of your organization and pick up your company's Wi-Fi network. + +24 +00:01:33,000 --> 00:01:37,000 +That would be pretty bad, because then somebody can sit across the road and attempt to brute force + +25 +00:01:37,000 --> 00:01:38,000 +and break into your network. + +26 +00:01:38,000 --> 00:01:40,000 +You'll just never know about it. + +27 +00:01:40,000 --> 00:01:43,000 +So you would have to look for those things that could happen. + +28 +00:01:43,000 --> 00:01:47,000 +Where could the signal bleed out if I put the access point here? + +29 +00:01:47,000 --> 00:01:49,000 +If I put it here, what can happen? + +30 +00:01:49,000 --> 00:01:55,000 +So access point should be placed in secure tamper, uh, tamper resistant location to prevent physical + +31 +00:01:55,000 --> 00:01:56,000 +manipulation. + +32 +00:01:56,000 --> 00:02:00,000 +You don't want people just to be able to see the access point, remove the access point and tamper with + +33 +00:02:00,000 --> 00:02:01,000 +it. + +34 +00:02:01,000 --> 00:02:05,000 +When you're doing a site survey, ask yourself where would be best for me to place this access point? + +35 +00:02:05,000 --> 00:02:08,000 +Certain environmental factors. + +36 +00:02:08,000 --> 00:02:11,000 +What type of building materials can interfere with the signal. + +37 +00:02:11,000 --> 00:02:14,000 +Thick concrete wall may interfere with the signal. + +38 +00:02:14,000 --> 00:02:15,000 +Where? + +39 +00:02:15,000 --> 00:02:22,000 +Where you place it has a direct impact on the quality of the signal that people are going to get. + +40 +00:02:23,000 --> 00:02:27,000 +By placing an access point in certain locations, does it create a blind spot? + +41 +00:02:27,000 --> 00:02:28,000 +All right. + +42 +00:02:28,000 --> 00:02:32,000 +Now what is blind spot where potentially create blind spots where intruders could exploit the network + +43 +00:02:32,000 --> 00:02:33,000 +weaknesses. + +44 +00:02:33,000 --> 00:02:35,000 +Now heat maps. + +45 +00:02:35,000 --> 00:02:36,000 +This is important. + +46 +00:02:38,000 --> 00:02:43,000 +When you set up a wireless network, you have to draw the heat. + +47 +00:02:43,000 --> 00:02:47,000 +Heat maps basically look like a. + +48 +00:02:47,000 --> 00:02:53,000 +They look exactly like a map of your network, and it shows where it's red, which means it's good signal + +49 +00:02:53,000 --> 00:02:55,000 +and then it may show blue. + +50 +00:02:55,000 --> 00:02:56,000 +No signal. + +51 +00:02:56,000 --> 00:02:56,000 +It's cold. + +52 +00:02:56,000 --> 00:02:57,000 +So what exactly is this? + +53 +00:02:57,000 --> 00:03:03,000 +Well, it's a geographical representation of the wireless signal within a space they're used ensuring + +54 +00:03:03,000 --> 00:03:04,000 +uniform coverage. + +55 +00:03:04,000 --> 00:03:08,000 +Identify real weak signals are and identify where signals may be bleeding out. + +56 +00:03:08,000 --> 00:03:15,000 +So if you do a heat map of a wireless signal, you may find that in front of the organization built + +57 +00:03:15,000 --> 00:03:17,000 +in there's a strong signal. + +58 +00:03:17,000 --> 00:03:22,000 +But in the back of the organization where it still needed by some folks, there's not very good signal. + +59 +00:03:23,000 --> 00:03:25,000 +You then need to go and adjust the signal strength. + +60 +00:03:25,000 --> 00:03:31,000 +Certain access point, like Cisco's Aironet, does allow you to adjust the amount of signal. + +61 +00:03:31,000 --> 00:03:36,000 +For example, if you have an access point in the physical center, you may have it at full blast signal. + +62 +00:03:36,000 --> 00:03:40,000 +But if you have an access point more towards the edge of the building, you should decrease the signal + +63 +00:03:40,000 --> 00:03:46,000 +to ensure the signal doesn't bleed out, so the signal strength can be adjusted to minimize the chance + +64 +00:03:46,000 --> 00:03:48,000 +of interception or unauthorized access. + +65 +00:03:49,000 --> 00:03:49,000 +Now. + +66 +00:03:50,000 --> 00:03:52,000 +Heat maps are going to be particular. + +67 +00:03:52,000 --> 00:03:57,000 +You should be periodically revisiting after the deployments of your heat map. + +68 +00:03:57,000 --> 00:04:01,000 +There could be changes in the environment, changes of how people use in it. + +69 +00:04:01,000 --> 00:04:05,000 +You can even have new obsolete additional network devices can be joined in. + +70 +00:04:06,000 --> 00:04:12,000 +You have new devices, in particular joining your network that is absorbing a lot of that traffic or + +71 +00:04:12,000 --> 00:04:13,000 +the signal. + +72 +00:04:13,000 --> 00:04:14,000 +And before you know it, people starting getting slow down. + +73 +00:04:14,000 --> 00:04:17,000 +So it's important to do heat maps and keep adjusting. + +74 +00:04:17,000 --> 00:04:25,000 +Keep redoing the heat map, maybe on a periodic basis, such as at least once a year before you go out + +75 +00:04:25,000 --> 00:04:26,000 +and you set up a wireless network. + +76 +00:04:26,000 --> 00:04:28,000 +Just don't buy an access point. + +77 +00:04:28,000 --> 00:04:30,000 +Stick it on a wall and hopefully it's best. + +78 +00:04:30,000 --> 00:04:36,000 +The point of this discussion was, before you do that, you have to determine server your site. + +79 +00:04:36,000 --> 00:04:38,000 +Where is it best to place that access point? + +80 +00:04:38,000 --> 00:04:40,000 +What type of access point are we going to do? + +81 +00:04:40,000 --> 00:04:46,000 +You have access points that have the ability to boost their signal out very far, some of them not so + +82 +00:04:46,000 --> 00:04:47,000 +much. + +83 +00:04:47,000 --> 00:04:50,000 +You have to know your environment. + +84 +00:04:50,000 --> 00:04:54,000 +You have to understand your environment before setting up wireless. + diff --git a/13 - Common Security Techniques/004 Mobile Solutions and MDM OB 4.1_en.srt b/13 - Common Security Techniques/004 Mobile Solutions and MDM OB 4.1_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..45cc7a65c9f8a9a732f816fa1f03a21598f67f1e --- /dev/null +++ b/13 - Common Security Techniques/004 Mobile Solutions and MDM OB 4.1_en.srt @@ -0,0 +1,480 @@ +1 +00:00:00,000 --> 00:00:01,000 +The greatest challenge to it. + +2 +00:00:01,000 --> 00:00:07,000 +Security, I would say, in the last ten years, is this this is the greatest challenge. + +3 +00:00:07,000 --> 00:00:11,000 +The IT security people spend more time on this thing than ever before. + +4 +00:00:11,000 --> 00:00:13,000 +There's tons of corporate data. + +5 +00:00:13,000 --> 00:00:18,000 +For example, a lot of people check corporate emails on these devices. + +6 +00:00:18,000 --> 00:00:24,000 +In this video, I want to talk about some different solutions, some different deployment solutions + +7 +00:00:24,000 --> 00:00:26,000 +for managing these kinds of devices. + +8 +00:00:26,000 --> 00:00:28,000 +Now how to manage these devices in general. + +9 +00:00:28,000 --> 00:00:30,000 +So let's get started. + +10 +00:00:30,000 --> 00:00:31,000 +Mobile solutions. + +11 +00:00:31,000 --> 00:00:32,000 +What are we talking about. + +12 +00:00:32,000 --> 00:00:38,000 +We're talking about some strategies and technologies that we can use to help manage this particular + +13 +00:00:38,000 --> 00:00:38,000 +device. + +14 +00:00:39,000 --> 00:00:44,000 +Now this is going to be things such as managing the devices themselves. + +15 +00:00:44,000 --> 00:00:50,000 +How can we deploy it and how are they even connected within the organization when it comes to managing + +16 +00:00:50,000 --> 00:00:54,000 +that particular device, such as my phone? + +17 +00:00:55,000 --> 00:01:00,000 +One software that organizations should have is going to be an MDM. + +18 +00:01:00,000 --> 00:01:03,000 +Mobile device management software. + +19 +00:01:03,000 --> 00:01:08,000 +These are software that allows IT administrators to control, secure, and enforce policies on these + +20 +00:01:08,000 --> 00:01:09,000 +devices. + +21 +00:01:09,000 --> 00:01:16,000 +This is going to include remotely wiping out devices, managing what apps can be installed. + +22 +00:01:17,000 --> 00:01:22,000 +Uh, things that can force in configuration, such as authentication, like, oh, you got you got to + +23 +00:01:22,000 --> 00:01:24,000 +have a certain digits in your password. + +24 +00:01:24,000 --> 00:01:33,000 +Configuring settings for email, wireless and VPN MDM solutions such as VMware Airwatch is very popular. + +25 +00:01:33,000 --> 00:01:35,000 +These kinds of software. + +26 +00:01:35,000 --> 00:01:40,000 +Basically the organization would have you join the MDM. + +27 +00:01:40,000 --> 00:01:44,000 +When you join the MDM, the VM basically takes control of your phone. + +28 +00:01:44,000 --> 00:01:46,000 +It then applies a bunch of security policies on it. + +29 +00:01:46,000 --> 00:01:49,000 +It can limit what apps you can install. + +30 +00:01:49,000 --> 00:01:52,000 +It may force you to have a certain kind of authentication mechanism. + +31 +00:01:52,000 --> 00:01:59,000 +It may force certain kinds of, um, updates to your device and configure certain kinds of VPN. + +32 +00:01:59,000 --> 00:02:04,000 +So MDM is basically how it secures your phone. + +33 +00:02:04,000 --> 00:02:10,000 +It's a really important piece of software to use if you are using if your employees use a lot of mobile + +34 +00:02:10,000 --> 00:02:11,000 +devices. + +35 +00:02:11,000 --> 00:02:12,000 +Security compliance. + +36 +00:02:12,000 --> 00:02:16,000 +The MDM is critical for ensuring that these devices comply with certain standards. + +37 +00:02:16,000 --> 00:02:23,000 +A lot of times, people may not have, uh, people may not have the right configuration. + +38 +00:02:23,000 --> 00:02:25,000 +They may not be updating their phone. + +39 +00:02:25,000 --> 00:02:29,000 +They may not have some people may not have a password on their phone, for God's sake. + +40 +00:02:31,000 --> 00:02:36,000 +You may have what's called an application allow this, which is also known as a whitelist or an application, + +41 +00:02:37,000 --> 00:02:38,000 +uh, a list of application. + +42 +00:02:38,000 --> 00:02:40,000 +You shouldn't be installed, which is called a blacklist. + +43 +00:02:40,000 --> 00:02:45,000 +So like application allow lists would say something like, oh, you're only allowed to have these applications + +44 +00:02:45,000 --> 00:02:45,000 +on your phone. + +45 +00:02:45,000 --> 00:02:46,000 +These are a list of them. + +46 +00:02:46,000 --> 00:02:50,000 +Everything else you can't have device monitoring. + +47 +00:02:50,000 --> 00:02:56,000 +MDM uh MDM tools will allow you to monitor the health and security of these devices, giving you good + +48 +00:02:56,000 --> 00:02:58,000 +insight into whether there's any security issues. + +49 +00:02:58,000 --> 00:03:03,000 +So for example, if this phone gets any kind of hack, if this phone gets any kind of security issue, + +50 +00:03:03,000 --> 00:03:06,000 +it can notify the MDM who could notify it on it. + +51 +00:03:06,000 --> 00:03:10,000 +One of the greatest thing of why I use an MDM for Microsoft. + +52 +00:03:11,000 --> 00:03:18,000 +Is for the simple fact that if I ever lose this phone, we can go to the MDM and remotely wipe the phone + +53 +00:03:18,000 --> 00:03:19,000 +just like that. + +54 +00:03:19,000 --> 00:03:22,000 +So that makes it a lot easier. + +55 +00:03:22,000 --> 00:03:27,000 +MDM are also used, for example, when you're terminated, if you're terminated from an organization, + +56 +00:03:27,000 --> 00:03:33,000 +the organization upon terminating you will generally send a signal and erase your phone, erasing all + +57 +00:03:33,000 --> 00:03:35,000 +the corporate data that's stored on your phone. + +58 +00:03:36,000 --> 00:03:44,000 +Now when it comes to the deployment, there's three of them BYoD, C, o, p e and c o d. + +59 +00:03:44,000 --> 00:03:47,000 +Every organization is going to follow these, you know. + +60 +00:03:47,000 --> 00:03:51,000 +Some of them may have different variations of them. + +61 +00:03:51,000 --> 00:03:56,000 +One of the most popular ones that I am personally not a fan of, but it is the most popular because + +62 +00:03:56,000 --> 00:04:00,000 +it is the most cost effective version is bring your own device. + +63 +00:04:00,000 --> 00:04:05,000 +Now here at TI we do use this one also because again, it's the most effective, cost effective. + +64 +00:04:05,000 --> 00:04:13,000 +BYoD is when the employees use their phones, their personal device for work purposes. + +65 +00:04:13,000 --> 00:04:19,000 +So you go work for a company and the organization says, well, you're going to need to check your emails + +66 +00:04:19,000 --> 00:04:20,000 +on your phone. + +67 +00:04:21,000 --> 00:04:24,000 +Um, you're going to need to access these particular files. + +68 +00:04:24,000 --> 00:04:27,000 +So that may give you some kind of shared drive or VPN access. + +69 +00:04:27,000 --> 00:04:30,000 +But basically you're using your personal phone. + +70 +00:04:30,000 --> 00:04:38,000 +Now, while BYoD can increase employee satisfaction, it could because I don't want to carry two phones. + +71 +00:04:38,000 --> 00:04:41,000 +Realistically, the reason we have it because I don't want to carry two phones. + +72 +00:04:41,000 --> 00:04:42,000 +These phones are really big and it seems like a brick. + +73 +00:04:42,000 --> 00:04:44,000 +I don't want to have two bricks on me. + +74 +00:04:44,000 --> 00:04:46,000 +My pants are going to fall out every time I put two bricks in there. + +75 +00:04:46,000 --> 00:04:47,000 +It's going to the belt. + +76 +00:04:47,000 --> 00:04:48,000 +Has to be super tight. + +77 +00:04:49,000 --> 00:04:51,000 +Who wants two phones, right? + +78 +00:04:51,000 --> 00:04:58,000 +The problem with with this though, is now there's a wide variety of devices on the network. + +79 +00:04:58,000 --> 00:05:01,000 +I like Samsung, you like Google. + +80 +00:05:01,000 --> 00:05:05,000 +He likes, uh, Apple, right? + +81 +00:05:05,000 --> 00:05:10,000 +There's so many different devices that people can choose from, different versions of different operating + +82 +00:05:10,000 --> 00:05:13,000 +system, different configurations, different dates. + +83 +00:05:13,000 --> 00:05:15,000 +Some of them are really old, some of them are just brand new. + +84 +00:05:15,000 --> 00:05:17,000 +That came out yesterday. + +85 +00:05:17,000 --> 00:05:19,000 +That's the problem with BYoD. + +86 +00:05:20,000 --> 00:05:24,000 +Although it reduces cost, it rises security challenges. + +87 +00:05:24,000 --> 00:05:27,000 +The organization needs to implement strict policy to control this. + +88 +00:05:27,000 --> 00:05:30,000 +The best way to control this is of course to have an MDM. + +89 +00:05:30,000 --> 00:05:36,000 +Most Mdms will support most devices that are out there in order to minimize the risks. + +90 +00:05:36,000 --> 00:05:43,000 +With BYoD, you're going to have COPD corporate owned, personally enabled. + +91 +00:05:43,000 --> 00:05:49,000 +The organization provides a mobile device to the employees, but allows some personal use. + +92 +00:05:49,000 --> 00:05:54,000 +Now, because the company owns it, only certain apps are going to be installed in it. + +93 +00:05:54,000 --> 00:06:00,000 +It's going to be easier to enforce security policies like standardized across the organization, so + +94 +00:06:00,000 --> 00:06:05,000 +it makes it easier to fully enforce security controls since the company knows and owns the devices, + +95 +00:06:05,000 --> 00:06:09,000 +this has a less pushback, you see. + +96 +00:06:10,000 --> 00:06:12,000 +In companies today that uses BYoD. + +97 +00:06:12,000 --> 00:06:16,000 +Employees may feel like the company is. + +98 +00:06:17,000 --> 00:06:19,000 +Taking over their privacy, intruding on their privacy. + +99 +00:06:19,000 --> 00:06:23,000 +And the reason for that is because it's my personal phone. + +100 +00:06:23,000 --> 00:06:26,000 +Why do you have access to my personal phone? + +101 +00:06:26,000 --> 00:06:28,000 +That's the bind with this one. + +102 +00:06:28,000 --> 00:06:32,000 +No problem, because the company literally owns the device. + +103 +00:06:32,000 --> 00:06:35,000 +So the organization has full ownership and control of it. + +104 +00:06:35,000 --> 00:06:41,000 +However, balancing with personal use rights is a key challenge here because not everybody wants this. + +105 +00:06:43,000 --> 00:06:45,000 +The middle ground is choose your own device. + +106 +00:06:46,000 --> 00:06:46,000 +All right. + +107 +00:06:46,000 --> 00:06:52,000 +So allows employees to choose from a selection of devices provided by the organization. + +108 +00:06:52,000 --> 00:06:57,000 +So the organization is going to be like okay if you want you're going to use your own phone, but you've + +109 +00:06:57,000 --> 00:06:58,000 +got to. + +110 +00:06:58,000 --> 00:06:59,000 +Here's a list of things that we support. + +111 +00:06:59,000 --> 00:07:01,000 +You got to have one of these phones. + +112 +00:07:01,000 --> 00:07:06,000 +The model balance between personal preference and corporate control allows the company to enforce security + +113 +00:07:06,000 --> 00:07:10,000 +controls, while giving you some choice versus the other one was no choice. + +114 +00:07:11,000 --> 00:07:14,000 +BYoD is, of course, very chaotic to manage. + +115 +00:07:14,000 --> 00:07:18,000 +I think Sihd is probably your best bet here. + +116 +00:07:19,000 --> 00:07:24,000 +Uh, corporate owned devices is very, very difficult to manage because not a lot of people again want + +117 +00:07:24,000 --> 00:07:25,000 +two phones. + +118 +00:07:25,000 --> 00:07:26,000 +All right. + +119 +00:07:26,000 --> 00:07:31,000 +So keep this in mind that in order to secure these mobile devices, the best software we can use is + +120 +00:07:31,000 --> 00:07:33,000 +a mobile device management software. + diff --git a/13 - Common Security Techniques/005 Mobile Connection Methods OB 4.1_en.srt b/13 - Common Security Techniques/005 Mobile Connection Methods OB 4.1_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..35e9423103a85df041805fd84ff8a964865b0f32 --- /dev/null +++ b/13 - Common Security Techniques/005 Mobile Connection Methods OB 4.1_en.srt @@ -0,0 +1,448 @@ +1 +00:00:00,000 --> 00:00:06,000 +Wireless devices, such as my phone generally has three ways that they're going to connect to gather + +2 +00:00:06,000 --> 00:00:07,000 +data. + +3 +00:00:07,000 --> 00:00:12,000 +Either they're going to use some kind of cellular network, like I'm connected to the AT&T network here + +4 +00:00:12,000 --> 00:00:13,000 +in the United States. + +5 +00:00:13,000 --> 00:00:15,000 +We also have Wi-Fi and Bluetooth. + +6 +00:00:15,000 --> 00:00:22,000 +These are going to be the three general ways that your mobile device are going to connect to a network. + +7 +00:00:22,000 --> 00:00:27,000 +So in this video let's go over these three methods and give you some good practices when utilizing them. + +8 +00:00:27,000 --> 00:00:33,000 +Now each of them have some security considerations that we do want to mention. + +9 +00:00:33,000 --> 00:00:38,000 +First of all, things that are going to be involved here is what protocols do they support. + +10 +00:00:38,000 --> 00:00:42,000 +For example, Wi-Fi has wpa3, which we'll cover later in the course. + +11 +00:00:42,000 --> 00:00:43,000 +Bluetooth. + +12 +00:00:43,000 --> 00:00:47,000 +The newer versions are more secure than the old versions, and most cellular networks will generally + +13 +00:00:47,000 --> 00:00:49,000 +come with good encryption. + +14 +00:00:49,000 --> 00:00:53,000 +You want to beware of potential vulnerabilities, such as Bluetooth being discovered of these here, + +15 +00:00:53,000 --> 00:01:00,000 +Bluetooth may not be the best one, and you always want to continuously update and monitor network infrastructure + +16 +00:01:00,000 --> 00:01:02,000 +such as security equipment that we have. + +17 +00:01:02,000 --> 00:01:07,000 +For example, all network infrastructure equipment may only support Wpa2. + +18 +00:01:07,000 --> 00:01:09,000 +Newer ones will support Wpa3. + +19 +00:01:09,000 --> 00:01:11,000 +Once again, we'll cover Wi-Fi. + +20 +00:01:11,000 --> 00:01:14,000 +We'll cover Wi-Fi security in another video. + +21 +00:01:14,000 --> 00:01:18,000 +But let's take a look at these particular connection types. + +22 +00:01:18,000 --> 00:01:21,000 +The first thing we want to talk about is cellular connection. + +23 +00:01:21,000 --> 00:01:25,000 +This is going to be the connection that you're going to use to connect to your provider. + +24 +00:01:25,000 --> 00:01:32,000 +Now, in modern cellular networks, almost all of them, they incorporate strong encryption standard + +25 +00:01:32,000 --> 00:01:33,000 +to protect data. + +26 +00:01:33,000 --> 00:01:41,000 +So if you're using your phone to connect to something like AT&T, Verizon and all the other providers, + +27 +00:01:41,000 --> 00:01:43,000 +it is generally fully encrypted. + +28 +00:01:43,000 --> 00:01:48,000 +This makes ears dropping or people trying to sniff the network to gather your data, intercepting it + +29 +00:01:48,000 --> 00:01:51,000 +much more difficult, if not somewhat impossible. + +30 +00:01:51,000 --> 00:01:57,000 +Now, one of the things that we still recommend to do, even though this is encrypted, is if you're + +31 +00:01:57,000 --> 00:02:02,000 +going to be using your mobile device or your laptop for example, maybe your laptop. + +32 +00:02:03,000 --> 00:02:07,000 +Is connected to your mobile device with things like setting up hotspots here. + +33 +00:02:07,000 --> 00:02:13,000 +If you are utilizing cellular networks to connect to your corporate networks, the best thing to do + +34 +00:02:13,000 --> 00:02:16,000 +is to make sure you put a VPN on this. + +35 +00:02:16,000 --> 00:02:23,000 +The A VPN will encrypt the data traffic and ensures that even if the data isn't intercepted, it's encrypted. + +36 +00:02:23,000 --> 00:02:27,000 +So it's best if you're connected to a corporate network to use a VPN. + +37 +00:02:27,000 --> 00:02:31,000 +Another thing is that these cars, these phones have SIM cards in them. + +38 +00:02:31,000 --> 00:02:32,000 +What's a SIM card? + +39 +00:02:32,000 --> 00:02:39,000 +Well, Sims can be a major attack vulnerability because there is something called SIM swap and attacks. + +40 +00:02:39,000 --> 00:02:40,000 +This is. + +41 +00:02:41,000 --> 00:02:46,000 +This involves transferring a victim's phone number to a SIM card controlled by an attacker and impersonating + +42 +00:02:46,000 --> 00:02:47,000 +that person. + +43 +00:02:48,000 --> 00:02:54,000 +Now, when it comes to wi fi, all right, the most common used one here is going to be wi fi. + +44 +00:02:55,000 --> 00:02:57,000 +You want to make sure that your wi fi. + +45 +00:02:57,000 --> 00:03:03,000 +And again we'll cover more about Wi-Fi security coming up in later are secured with Wpa2 or Wpa3. + +46 +00:03:03,000 --> 00:03:06,000 +Never have open wi fi set up. + +47 +00:03:06,000 --> 00:03:12,000 +Never use open Wi-Fi or unencrypted wi fi in today's world. + +48 +00:03:12,000 --> 00:03:17,000 +You want to avoid public Wi-Fi for any kind of sensitive data. + +49 +00:03:17,000 --> 00:03:23,000 +I don't recommend anyone connecting to any public Wi-Fi networks at any point. + +50 +00:03:23,000 --> 00:03:30,000 +If I go to a coffee shop and I take out my laptop and I want to do some work, you best bet I'm going + +51 +00:03:30,000 --> 00:03:30,000 +to share. + +52 +00:03:31,000 --> 00:03:37,000 +I'm going to be sharing Wi-Fi or internet from my phone to my laptop would be the best thing here to + +53 +00:03:37,000 --> 00:03:38,000 +do. + +54 +00:03:38,000 --> 00:03:44,000 +Now, if you have wireless in your organization and high secure organization, most organizations, + +55 +00:03:44,000 --> 00:03:48,000 +what they're going to do is they're going to segment the Wi-Fi network off. + +56 +00:03:48,000 --> 00:03:50,000 +They're going to have a separate segment for Wi-Fi. + +57 +00:03:50,000 --> 00:03:53,000 +So if you need Wi-Fi, you connect to that segment. + +58 +00:03:53,000 --> 00:03:54,000 +It does. + +59 +00:03:54,000 --> 00:03:54,000 +And here's the thing. + +60 +00:03:54,000 --> 00:03:58,000 +The segmentation of the Wi-Fi puts it off the network. + +61 +00:03:58,000 --> 00:04:00,000 +They do have internet access. + +62 +00:04:00,000 --> 00:04:06,000 +And when those computers want to come back into the network, they will generate a VPN back in. + +63 +00:04:07,000 --> 00:04:10,000 +So you should have a separate Wi-Fi. + +64 +00:04:10,000 --> 00:04:12,000 +Uh, a segmented Wi-Fi. + +65 +00:04:12,000 --> 00:04:16,000 +Now, if you have different Wi-Fi, you have guests, uh, particularly guests coming in. + +66 +00:04:16,000 --> 00:04:21,000 +Make sure you have a guest Wi-Fi and not something that the guests can log in and see. + +67 +00:04:22,000 --> 00:04:24,000 +Employee computers in particular. + +68 +00:04:24,000 --> 00:04:29,000 +Make sure to regularly update your Wi-Fi hardware for the latest and best security updates, such as + +69 +00:04:29,000 --> 00:04:32,000 +on my sonicwall that I keep updating. + +70 +00:04:32,000 --> 00:04:33,000 +Now Bluetooth. + +71 +00:04:34,000 --> 00:04:40,000 +A lot of us have Bluetooth on our devices we haven't turned on. + +72 +00:04:40,000 --> 00:04:42,000 +What do we use Bluetooth for? + +73 +00:04:42,000 --> 00:04:45,000 +Well, I use it to connect to the infotainment in the car. + +74 +00:04:45,000 --> 00:04:47,000 +I use it to connect to my headphones. + +75 +00:04:47,000 --> 00:04:50,000 +Now, Bluetooth has a vulnerabilities. + +76 +00:04:51,000 --> 00:04:53,000 +I'm going to just jump down to right here. + +77 +00:04:53,000 --> 00:04:58,000 +The latest version of Bluetooth I believe is 5.3 or 5.4. + +78 +00:04:58,000 --> 00:05:03,000 +The later your device is the most updated your device, the later your Bluetooth is going to be. + +79 +00:05:03,000 --> 00:05:06,000 +Earlier versions of Bluetooth were not even encrypted. + +80 +00:05:06,000 --> 00:05:12,000 +The later version of Bluetooth has the better encryption, has better security in general. + +81 +00:05:12,000 --> 00:05:17,000 +So that's another reason why you want to keep your firmware updated now. + +82 +00:05:17,000 --> 00:05:18,000 +Pairing and discoverability. + +83 +00:05:18,000 --> 00:05:22,000 +When you set up Bluetooth, set the device to non discoverable. + +84 +00:05:22,000 --> 00:05:24,000 +Most of these phones do that. + +85 +00:05:24,000 --> 00:05:28,000 +In general they're in a non discovery mode so no one can find them when not in pairing. + +86 +00:05:28,000 --> 00:05:31,000 +When you want to pair then you put it into that. + +87 +00:05:31,000 --> 00:05:33,000 +Ideally in a private setting. + +88 +00:05:33,000 --> 00:05:35,000 +To prevent unauthorized devices from connecting. + +89 +00:05:35,000 --> 00:05:39,000 +You make sure you turn off or you put in non discoverable. + +90 +00:05:39,000 --> 00:05:40,000 +Limit the use. + +91 +00:05:40,000 --> 00:05:43,000 +Use Bluetooth functionality only when necessary. + +92 +00:05:43,000 --> 00:05:43,000 +Keep it. + +93 +00:05:43,000 --> 00:05:47,000 +Keeping Bluetooth on all the time doesn't increase your attack surface. + +94 +00:05:47,000 --> 00:05:50,000 +So here's something that I recommend for all all of you guys to do. + +95 +00:05:50,000 --> 00:05:53,000 +Take your Bluetooth, take your phone and turn it off. + +96 +00:05:53,000 --> 00:05:54,000 +If you're not using it, don't have it on. + +97 +00:05:54,000 --> 00:05:56,000 +There's two reasons I do that. + +98 +00:05:56,000 --> 00:05:59,000 +Number one, it reduces my attack surface. + +99 +00:05:59,000 --> 00:06:03,000 +If the Bluetooth is on, it is a potential connection into my phone. + +100 +00:06:03,000 --> 00:06:08,000 +The next thing is that it just saves battery, right? + +101 +00:06:08,000 --> 00:06:11,000 +If the less things on, the less bad less battery uses up. + +102 +00:06:11,000 --> 00:06:14,000 +So that's the two reasons why I would do that. + +103 +00:06:14,000 --> 00:06:19,000 +Now be aware, there's tons of different vulnerabilities where they can connect, exploit the Bluetooth + +104 +00:06:19,000 --> 00:06:23,000 +connection, access the device, and even inject malware into it. + +105 +00:06:24,000 --> 00:06:28,000 +Keep in mind, the best thing we can do at Bluetooth is keep it off until needed. + +106 +00:06:28,000 --> 00:06:29,000 +But wireless. + +107 +00:06:29,000 --> 00:06:32,000 +Make sure you keep your former updated. + +108 +00:06:32,000 --> 00:06:37,000 +Make sure that you use Wpa2 wpa3. + +109 +00:06:37,000 --> 00:06:41,000 +Make sure you use encrypted connection when it comes to cellular networks. + +110 +00:06:42,000 --> 00:06:47,000 +They're generally going to be well secure with, well, encryption, but if you're connected, it's + +111 +00:06:47,000 --> 00:06:49,000 +still considered a type of a public network. + +112 +00:06:49,000 --> 00:06:53,000 +If you are transferring secret data, make sure to use a VPN. + diff --git a/13 - Common Security Techniques/006 Wireless Security OB 4.1_en.srt b/13 - Common Security Techniques/006 Wireless Security OB 4.1_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..dd85bc2a0d65e4874eee9947af2821f0bdaa8c4b --- /dev/null +++ b/13 - Common Security Techniques/006 Wireless Security OB 4.1_en.srt @@ -0,0 +1,732 @@ +1 +00:00:00,000 --> 00:00:03,000 +In this video we're going to talk about wireless security. + +2 +00:00:03,000 --> 00:00:09,000 +But before I get into that, I want to show you a demo of this Sonic Walls interface. + +3 +00:00:09,000 --> 00:00:14,000 +Now, I thought about connecting this thing and doing it live on the device, but then none of you would + +4 +00:00:14,000 --> 00:00:15,000 +get a chance to do it. + +5 +00:00:15,000 --> 00:00:18,000 +So I did find Sonic Walls Live demo that they have. + +6 +00:00:18,000 --> 00:00:23,000 +It's basically the exact same thing that you can practice on, and they give it away absolutely free. + +7 +00:00:23,000 --> 00:00:25,000 +So you can try it to do a little bit of hands on. + +8 +00:00:25,000 --> 00:00:26,000 +So let's do that. + +9 +00:00:26,000 --> 00:00:28,000 +And then we're going to get in and talk about what we saw. + +10 +00:00:28,000 --> 00:00:32,000 +Just makes makes things easier when you see it to describe it. + +11 +00:00:32,000 --> 00:00:34,000 +So let's go take a look at it. + +12 +00:00:34,000 --> 00:00:37,000 +Uh so here I am at uh, this website. + +13 +00:00:37,000 --> 00:00:39,000 +And by the way, this link is in this slide. + +14 +00:00:39,000 --> 00:00:43,000 +This is Sonic wall firewall demo. + +15 +00:00:43,000 --> 00:00:45,000 +So they're going to give us the full access to the interface. + +16 +00:00:45,000 --> 00:00:53,000 +So right now I have open on in front of me here, uh, the TS 570 series, which is very similar to + +17 +00:00:53,000 --> 00:00:54,000 +what I have here. + +18 +00:00:54,000 --> 00:00:56,000 +Uh, and I'm going to say view demo. + +19 +00:00:56,000 --> 00:00:59,000 +I want the one with wireless because we're basically connecting Wi-Fi. + +20 +00:00:59,000 --> 00:01:03,000 +It's telling me that it's going to be using the username and password is password. + +21 +00:01:03,000 --> 00:01:09,000 +So we need to know that um oops it wants to block it I'll block up allow pop up. + +22 +00:01:09,000 --> 00:01:11,000 +So let's make this bigger so you guys can see. + +23 +00:01:11,000 --> 00:01:13,000 +So we're going to say demo. + +24 +00:01:13,000 --> 00:01:15,000 +And then the password is password. + +25 +00:01:16,000 --> 00:01:21,000 +Now what I want to do is I want to show you guys when we configure wireless on the computer we'll just + +26 +00:01:21,000 --> 00:01:25,000 +say proceed here when we configure wireless on these devices. + +27 +00:01:25,000 --> 00:01:27,000 +Now this is the device interface. + +28 +00:01:27,000 --> 00:01:34,000 +When we configure the wireless on here we have to make sure we select a good security protocol. + +29 +00:01:34,000 --> 00:01:36,000 +Let me show you guys how that's done on a device like this. + +30 +00:01:36,000 --> 00:01:40,000 +It's going to be pretty similar for all the network and devices that are out there. + +31 +00:01:41,000 --> 00:01:41,000 +Okay. + +32 +00:01:41,000 --> 00:01:43,000 +So I'm going to go to device. + +33 +00:01:43,000 --> 00:01:48,000 +And by going here, it opened up a lot of different devices that we have here. + +34 +00:01:48,000 --> 00:01:53,000 +So we're going to go to internal wireless and we're going to go down here. + +35 +00:01:53,000 --> 00:01:56,000 +If you see its status settings security. + +36 +00:01:56,000 --> 00:02:00,000 +So if you go to settings you have the different settings of the mode we can do. + +37 +00:02:01,000 --> 00:02:06,000 +Now this is not a networking course to go through all the different radio modes like 802, A, B, G + +38 +00:02:06,000 --> 00:02:06,000 +and N. + +39 +00:02:06,000 --> 00:02:11,000 +We're looking more at the security aspect of it, but we're going to go to security. + +40 +00:02:11,000 --> 00:02:15,000 +And you notice right now it's actually set to the worst security out there. + +41 +00:02:15,000 --> 00:02:17,000 +You never want to use WFP. + +42 +00:02:18,000 --> 00:02:20,000 +WFP is crackable and should not be used. + +43 +00:02:20,000 --> 00:02:23,000 +So is pretty much WPA. + +44 +00:02:23,000 --> 00:02:24,000 +At a minimum. + +45 +00:02:24,000 --> 00:02:26,000 +You want to go with Wpa2. + +46 +00:02:26,000 --> 00:02:33,000 +Wpa2 is still incredibly popular, and what I want to point out in this video is we have two things. + +47 +00:02:33,000 --> 00:02:38,000 +You have Wpa2, PSK or Pre-shared key and EAP Extensible Authentication Protocol. + +48 +00:02:38,000 --> 00:02:44,000 +You notice you also have that for WPA three, you have the PSK and the EAP. + +49 +00:02:44,000 --> 00:02:46,000 +So look what happens when I use WPA three. + +50 +00:02:46,000 --> 00:02:48,000 +Now if you have three you want to put that on your router. + +51 +00:02:48,000 --> 00:02:54,000 +The newer wireless routers and and um access points is going to support WPA three D. + +52 +00:02:54,000 --> 00:02:59,000 +All the ones will not WPA two while still a good option, Wpa3 is better. + +53 +00:02:59,000 --> 00:03:06,000 +If I go to Wpa3 and I say PSK basically wants me to enter the passphrase of the Pre-shared key that + +54 +00:03:06,000 --> 00:03:08,000 +all the machines will get. + +55 +00:03:08,000 --> 00:03:09,000 +Now, I do want you to watch. + +56 +00:03:09,000 --> 00:03:14,000 +If I select WPA three, you'll notice a lot of options changed. + +57 +00:03:15,000 --> 00:03:23,000 +And now it wants the radius servers IP address, and it wants to know a secret of the Radius server. + +58 +00:03:23,000 --> 00:03:26,000 +So this is a configuration of a Radius server. + +59 +00:03:26,000 --> 00:03:33,000 +So notice how WPA three is asking for a Radius server IP address. + +60 +00:03:33,000 --> 00:03:42,000 +So WPA three our WPA two when configured with EAP authentication notice WPA two here also has the same + +61 +00:03:42,000 --> 00:03:42,000 +thing. + +62 +00:03:42,000 --> 00:03:51,000 +So what exactly does WPA two EAP means now on certain routers, you guys may see this as, uh, if you + +63 +00:03:51,000 --> 00:03:54,000 +look at your router, it may say WPA two enterprise. + +64 +00:03:54,000 --> 00:03:55,000 +Same thing. + +65 +00:03:55,000 --> 00:03:57,000 +It's going to ask for the Radius server. + +66 +00:03:57,000 --> 00:03:59,000 +So what exactly is that. + +67 +00:03:59,000 --> 00:04:01,000 +Well that's what this video is about. + +68 +00:04:02,000 --> 00:04:10,000 +This video, I want to talk about some of the security settings that we just saw on our wireless router. + +69 +00:04:10,000 --> 00:04:10,000 +Right. + +70 +00:04:10,000 --> 00:04:12,000 +We want to talk about Wpa3. + +71 +00:04:13,000 --> 00:04:19,000 +You got to notice triple A, and we'll talk about the cryptographic protocols and authentication protocols + +72 +00:04:19,000 --> 00:04:20,000 +that we have out there. + +73 +00:04:20,000 --> 00:04:23,000 +So Wpa3 is about securing our wireless network. + +74 +00:04:23,000 --> 00:04:26,000 +And then in coming up in a few minutes we'll talk about triple A. + +75 +00:04:26,000 --> 00:04:30,000 +Now the link to that Sonicwall demo is right here. + +76 +00:04:30,000 --> 00:04:34,000 +So if you want to try that out, if you want to play around with the Sonicwall like I have here on my + +77 +00:04:34,000 --> 00:04:39,000 +desk, you want to play around with the interface, see how it's configured without actually purchasing + +78 +00:04:39,000 --> 00:04:42,000 +it for a couple of, well, $100. + +79 +00:04:42,000 --> 00:04:44,000 +You can just use the demo there now. + +80 +00:04:45,000 --> 00:04:46,000 +Let's get into this. + +81 +00:04:46,000 --> 00:04:47,000 +So wpa3. + +82 +00:04:47,000 --> 00:04:54,000 +This is going to be the latest security that we have in wireless protection preceding this with Wpa2, + +83 +00:04:54,000 --> 00:04:56,000 +which was around for quite a long time. + +84 +00:04:56,000 --> 00:04:57,000 +Then there's WPA. + +85 +00:04:57,000 --> 00:05:02,000 +The original one and then WEP, which is fully crackable and should not be used. + +86 +00:05:02,000 --> 00:05:04,000 +Now it improves upon Wpa2. + +87 +00:05:04,000 --> 00:05:10,000 +It has more enhanced cryptographic strength, more robust authentication method. + +88 +00:05:10,000 --> 00:05:15,000 +It does use something simultaneous authentication of equals or SAE protocol. + +89 +00:05:15,000 --> 00:05:20,000 +This replaced the old PSK or Pre-shared key methods that was used in Wpa2. + +90 +00:05:20,000 --> 00:05:24,000 +It protects against more offline dictionary attacks. + +91 +00:05:24,000 --> 00:05:27,000 +It enhance protection for open network? + +92 +00:05:28,000 --> 00:05:34,000 +Um, and it supports up to 192 bit encryption versus Wpa2 and 128 bit encryption. + +93 +00:05:34,000 --> 00:05:40,000 +If you have a router, a wireless access point and wireless routers that supports Wpa3, I would highly + +94 +00:05:40,000 --> 00:05:41,000 +recommend you put it on. + +95 +00:05:41,000 --> 00:05:46,000 +But you have to remember it's not just a machine, but the wireless cards also need to support it. + +96 +00:05:46,000 --> 00:05:47,000 +Now. + +97 +00:05:48,000 --> 00:05:52,000 +I want to talk to you guys here about something important. + +98 +00:05:53,000 --> 00:05:58,000 +On when you configure WPA 2 or 3 on your computer. + +99 +00:05:59,000 --> 00:06:01,000 +We have the option of doing a pre-shared key. + +100 +00:06:01,000 --> 00:06:03,000 +Most of us at home, that's what we have. + +101 +00:06:03,000 --> 00:06:06,000 +Pre-shared key with a Pre-shared key. + +102 +00:06:06,000 --> 00:06:12,000 +What you're doing is you're putting in a passcode and hopefully it's long and complex, and then you + +103 +00:06:12,000 --> 00:06:16,000 +have to share that pre-shared key with all the computers in the network to connect. + +104 +00:06:16,000 --> 00:06:18,000 +People call it the password to the WiFi. + +105 +00:06:18,000 --> 00:06:18,000 +Right. + +106 +00:06:18,000 --> 00:06:20,000 +So what's the password to the Wi-Fi? + +107 +00:06:20,000 --> 00:06:22,000 +That's the Pre-shared key. + +108 +00:06:22,000 --> 00:06:30,000 +Now the problem with this is that in corporates in corporate America, we're not going to have 5 or + +109 +00:06:30,000 --> 00:06:33,000 +6 or 2 or 3 computers. + +110 +00:06:33,000 --> 00:06:34,000 +We're going to have them by the hundreds. + +111 +00:06:34,000 --> 00:06:37,000 +Do we want to authenticate them with just the key. + +112 +00:06:37,000 --> 00:06:43,000 +Those keys, those pre-shared keys are actually kept in plain text on the computer. + +113 +00:06:43,000 --> 00:06:46,000 +So it's not the best thing to do. + +114 +00:06:46,000 --> 00:06:53,000 +What we want to do is we want to pass off the authentication of those particular devices to another + +115 +00:06:53,000 --> 00:06:54,000 +device. + +116 +00:06:54,000 --> 00:06:56,000 +So I want to draw you guys a quick diagram. + +117 +00:06:56,000 --> 00:06:57,000 +So here you have. + +118 +00:06:59,000 --> 00:07:04,000 +An access point that with all the access points coming out of it. + +119 +00:07:04,000 --> 00:07:11,000 +And then what you're going to do is instead of having, let's say you have a mobile phone, this phone + +120 +00:07:11,000 --> 00:07:13,000 +wants to connect to this using wireless. + +121 +00:07:13,000 --> 00:07:19,000 +Now what you could do is you could just have a pre-shared key and it'll just authenticate and it gets + +122 +00:07:19,000 --> 00:07:20,000 +internet access. + +123 +00:07:20,000 --> 00:07:28,000 +The best thing to do is to connect your access point or wireless router to a Radius server. + +124 +00:07:28,000 --> 00:07:30,000 +Now what exactly is a Radius server? + +125 +00:07:30,000 --> 00:07:32,000 +Well, a Radius server. + +126 +00:07:33,000 --> 00:07:34,000 +It's basically a device. + +127 +00:07:34,000 --> 00:07:39,000 +It's a networking protocol that centralizes authentication, authorization and accounting for users + +128 +00:07:39,000 --> 00:07:40,000 +accessing network. + +129 +00:07:40,000 --> 00:07:48,000 +Radius servers are separate servers that we set up on our network to authenticate all kinds of devices. + +130 +00:07:48,000 --> 00:07:51,000 +A Radius server can connect to your access point. + +131 +00:07:51,000 --> 00:07:52,000 +Remember how we selected Pre-shared? + +132 +00:07:52,000 --> 00:07:57,000 +We selected WPA 2 or 3 and we said EAP authentication. + +133 +00:07:57,000 --> 00:08:01,000 +Now it's using the Extensible Authentication Protocol to pass. + +134 +00:08:01,000 --> 00:08:04,000 +So here we would have an EAP authentication. + +135 +00:08:05,000 --> 00:08:06,000 +Authentication protocol. + +136 +00:08:06,000 --> 00:08:11,000 +This here would use this protocol to pass authentication information to a Radius server. + +137 +00:08:11,000 --> 00:08:15,000 +Radius server can then authenticate people with Active Directory accounts. + +138 +00:08:15,000 --> 00:08:20,000 +Certificates, for example, are different ways that Radius can authenticate you, so you don't have + +139 +00:08:20,000 --> 00:08:22,000 +to have a pre-shared key to all the machines. + +140 +00:08:22,000 --> 00:08:26,000 +You can use certificate based authentication, the Radius server. + +141 +00:08:26,000 --> 00:08:32,000 +So when the laptop or the phone wants to join the wireless access point, it would say, hey, can I + +142 +00:08:32,000 --> 00:08:33,000 +join? + +143 +00:08:33,000 --> 00:08:34,000 +It would send a request to the Radius server. + +144 +00:08:34,000 --> 00:08:37,000 +The Radius server accepts the authentication. + +145 +00:08:37,000 --> 00:08:43,000 +It would come back and let the the let the access point know to allow the laptop or phone to join. + +146 +00:08:44,000 --> 00:08:49,000 +This falls into the framework of what's known as triple A authentication, authorization and accounting. + +147 +00:08:49,000 --> 00:08:53,000 +So authentication is allowed them to get in what they can access as authorization. + +148 +00:08:53,000 --> 00:08:59,000 +And accounting is keeping like a log file and tracking and auditing of what this system when they logged + +149 +00:08:59,000 --> 00:09:00,000 +into it. + +150 +00:09:01,000 --> 00:09:04,000 +So how do we allow triple A in our network? + +151 +00:09:04,000 --> 00:09:07,000 +By utilizing a Radius server. + +152 +00:09:07,000 --> 00:09:15,000 +Now once again, radius servers are very popular in today's network because you're going to use a Radius + +153 +00:09:15,000 --> 00:09:22,000 +server not just to authenticate wireless, but you can also use Radius to authenticate VPNs. + +154 +00:09:22,000 --> 00:09:25,000 +So not just, uh, wireless in your network. + +155 +00:09:25,000 --> 00:09:27,000 +Now you can set up Radius on windows. + +156 +00:09:27,000 --> 00:09:32,000 +Also, Cisco has something just like radius. + +157 +00:09:32,000 --> 00:09:34,000 +If you on your exam you see something called Tacacs. + +158 +00:09:34,000 --> 00:09:40,000 +It's the same thing Tacacs radius basically does the same thing for your exam now. + +159 +00:09:42,000 --> 00:09:44,000 +Cryptographic protocols. + +160 +00:09:44,000 --> 00:09:44,000 +All right. + +161 +00:09:44,000 --> 00:09:45,000 +What exactly is this? + +162 +00:09:46,000 --> 00:09:49,000 +These are a series of processes that encrypt and decrypt data. + +163 +00:09:49,000 --> 00:09:50,000 +That's what a protocol does. + +164 +00:09:50,000 --> 00:09:51,000 +It encrypts and decrypts. + +165 +00:09:51,000 --> 00:09:54,000 +They use algorithms the to read. + +166 +00:09:54,000 --> 00:09:59,000 +And they use algorithms to transform readable data into unreadable data. + +167 +00:09:59,000 --> 00:10:05,000 +Now the cryptographic protocol is what's going to be the underlying technology with Wpa3. + +168 +00:10:05,000 --> 00:10:10,000 +Now Wpa3 I do want to point out does use AES encryption to encrypt its data. + +169 +00:10:10,000 --> 00:10:11,000 +So. + +170 +00:10:12,000 --> 00:10:12,000 +What? + +171 +00:10:12,000 --> 00:10:14,000 +What's going to power up? + +172 +00:10:14,000 --> 00:10:15,000 +Wpa3. + +173 +00:10:15,000 --> 00:10:21,000 +A cryptographic protocol, the authentication protocol, is what authenticates people to the actual + +174 +00:10:21,000 --> 00:10:23,000 +network used to verify the identity. + +175 +00:10:23,000 --> 00:10:25,000 +That part of a broader security. + +176 +00:10:25,000 --> 00:10:31,000 +Things like Radius will use authentication protocols to authenticate you on a network. + +177 +00:10:32,000 --> 00:10:35,000 +All right, so know for your exam. + +178 +00:10:35,000 --> 00:10:40,000 +Wpa3 is a strongest encryption we have out there on a smaller home network. + +179 +00:10:40,000 --> 00:10:47,000 +We may use a pre-shared key to secure the network, but on big networks, we're going to use EAP authentication + +180 +00:10:47,000 --> 00:10:51,000 +to send it off to a Radius server or a CAS server if you're using Cisco. + +181 +00:10:52,000 --> 00:10:56,000 +And that's going to give us a centralized form of authentication where we're just not going to use a + +182 +00:10:56,000 --> 00:11:01,000 +pre-shared key or a password, but we can use things like certificate based authentication, making + +183 +00:11:01,000 --> 00:11:02,000 +it a whole lot more secure. + diff --git a/13 - Common Security Techniques/007 Application Security Methods OB 4.1_en.srt b/13 - Common Security Techniques/007 Application Security Methods OB 4.1_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..2d16eeb4792d7408101db68bc92aeeb8e8702199 --- /dev/null +++ b/13 - Common Security Techniques/007 Application Security Methods OB 4.1_en.srt @@ -0,0 +1,740 @@ +1 +00:00:00,000 --> 00:00:03,000 +Almost all malware will exploit some kind of applications. + +2 +00:00:03,000 --> 00:00:07,000 +Very rarely do you have malware that can affect the hardware on the machine. + +3 +00:00:07,000 --> 00:00:14,000 +So in this video let's talk about application security and some things that we can do to keep our applications + +4 +00:00:14,000 --> 00:00:15,000 +secure. + +5 +00:00:15,000 --> 00:00:21,000 +So we all should understand that when it comes to application security, probably one of the most critical + +6 +00:00:21,000 --> 00:00:24,000 +aspect of managing any IT system. + +7 +00:00:24,000 --> 00:00:30,000 +Now in here I have about five things here that I want to go over with you, uh, that can keep your + +8 +00:00:30,000 --> 00:00:31,000 +applications secure. + +9 +00:00:31,000 --> 00:00:32,000 +Let's get started. + +10 +00:00:32,000 --> 00:00:36,000 +The first thing that we want to talk about is input validation. + +11 +00:00:36,000 --> 00:00:38,000 +Now, I've already covered some of these attacks. + +12 +00:00:38,000 --> 00:00:42,000 +We talked about cross-site scripting SQL injections. + +13 +00:00:42,000 --> 00:00:46,000 +These are all things that can be solved by input validation. + +14 +00:00:46,000 --> 00:00:48,000 +And I want to show it to you before we get started. + +15 +00:00:48,000 --> 00:00:49,000 +So here I am. + +16 +00:00:49,000 --> 00:00:49,000 +Oops. + +17 +00:00:49,000 --> 00:00:52,000 +Here I am at the Tia Educom. + +18 +00:00:52,000 --> 00:00:54,000 +This is our website. + +19 +00:00:54,000 --> 00:00:59,000 +If you want to sign up for a class you would come here and I want to show you guys what input validation + +20 +00:00:59,000 --> 00:01:00,000 +is. + +21 +00:01:00,000 --> 00:01:05,000 +You have a name and what I'm going to do here is I'm going to type in, uh, my name, but I want you + +22 +00:01:05,000 --> 00:01:06,000 +guys to watch what happens. + +23 +00:01:06,000 --> 00:01:08,000 +I'm just going to hold the one key down. + +24 +00:01:08,000 --> 00:01:14,000 +You notice it limits what can be typed into the box, the number of characters, the email address, + +25 +00:01:14,000 --> 00:01:15,000 +for example. + +26 +00:01:15,000 --> 00:01:19,000 +Also, I'm just going to put in my name phone number. + +27 +00:01:19,000 --> 00:01:20,000 +We allow anything in there. + +28 +00:01:20,000 --> 00:01:21,000 +Just a message. + +29 +00:01:21,000 --> 00:01:23,000 +And this is also limited. + +30 +00:01:23,000 --> 00:01:26,000 +So you watch what happens when I try to submit it. + +31 +00:01:26,000 --> 00:01:28,000 +You notice you got to have a valid email. + +32 +00:01:28,000 --> 00:01:31,000 +So to field only accept a valid email. + +33 +00:01:31,000 --> 00:01:34,000 +This is what's called input validation. + +34 +00:01:34,000 --> 00:01:39,000 +What we're doing is we're validating the input that's placed into the website. + +35 +00:01:39,000 --> 00:01:47,000 +That way the input itself that people are typing is being treated as untrusted and validated, both + +36 +00:01:47,000 --> 00:01:50,000 +on the client side for usability and on the server side. + +37 +00:01:50,000 --> 00:01:51,000 +So right now we're validating it. + +38 +00:01:51,000 --> 00:01:53,000 +What you saw was on the client side. + +39 +00:01:53,000 --> 00:01:56,000 +And then we will also check it on the server side. + +40 +00:01:56,000 --> 00:01:57,000 +Also. + +41 +00:01:57,000 --> 00:02:06,000 +Now I want to once again to point out for your exam input validation can solve things like SQL injections + +42 +00:02:06,000 --> 00:02:09,000 +and cross-site scripting or any kind of injection attacks. + +43 +00:02:09,000 --> 00:02:16,000 +Also, it can prevent attackers from using malicious data to exploit exploit the logic of the application. + +44 +00:02:16,000 --> 00:02:18,000 +So this is a wide. + +45 +00:02:18,000 --> 00:02:21,000 +By doing this it's safeguarding against a wide range of attacks. + +46 +00:02:22,000 --> 00:02:24,000 +The next thing is secure cookies. + +47 +00:02:24,000 --> 00:02:30,000 +Cookies are small pieces of data stored on a user device, and I'm pretty sure you guys are familiar + +48 +00:02:30,000 --> 00:02:33,000 +with it, as most website has it by the web browser. + +49 +00:02:33,000 --> 00:02:39,000 +While browser on a site, secure cookies have security attributes, including your personal data on + +50 +00:02:39,000 --> 00:02:40,000 +them. + +51 +00:02:40,000 --> 00:02:45,000 +What you want to do is you want to make sure that the cookies are secure, in other words, indicating + +52 +00:02:45,000 --> 00:02:53,000 +that cookies should only be sent over Https connection since these cookies have personal data attached + +53 +00:02:53,000 --> 00:02:56,000 +to them if they're ever intercepted. + +54 +00:02:56,000 --> 00:02:59,000 +Your your personal data could be gone. + +55 +00:02:59,000 --> 00:03:02,000 +And it can also be used in man in the middle uh, attacks also. + +56 +00:03:03,000 --> 00:03:05,000 +Remember this is now called an on path attack. + +57 +00:03:05,000 --> 00:03:10,000 +So you want to make sure that any website that's utilizing a cookie, or if you're building a website, + +58 +00:03:10,000 --> 00:03:17,000 +that cookie is encrypted with SSL or TLS static code analysis. + +59 +00:03:17,000 --> 00:03:23,000 +When programmers are writing codes, it is important to actually test the code. + +60 +00:03:23,000 --> 00:03:29,000 +Static analysis is the process of examining the source code of an application without executing it. + +61 +00:03:29,000 --> 00:03:33,000 +Like technically just reading the code of itself on a piece of paper. + +62 +00:03:34,000 --> 00:03:36,000 +Technically not on a paper, but on a screen. + +63 +00:03:36,000 --> 00:03:41,000 +The aim is to find vulnerability code flaws and ensuring compliance generally with code and guidelines. + +64 +00:03:42,000 --> 00:03:44,000 +Now this is an automated thing. + +65 +00:03:45,000 --> 00:03:48,000 +Now an application can have millions of line of code. + +66 +00:03:48,000 --> 00:03:49,000 +People can sit there and read that. + +67 +00:03:49,000 --> 00:03:55,000 +So this is generally done using tools that can automatically scan the code to detect issues like security + +68 +00:03:55,000 --> 00:03:58,000 +vulnerabilities, perform problems and so on. + +69 +00:03:58,000 --> 00:04:03,000 +Now this is one of the best things you can do as code is being written. + +70 +00:04:03,000 --> 00:04:04,000 +This should be done. + +71 +00:04:04,000 --> 00:04:07,000 +This helps to identify problems with development. + +72 +00:04:07,000 --> 00:04:07,000 +Will ask. + +73 +00:04:07,000 --> 00:04:10,000 +The code is being written so early in the development life cycle. + +74 +00:04:10,000 --> 00:04:14,000 +It's generally cost effective to do it since it's generally done by a tool. + +75 +00:04:14,000 --> 00:04:20,000 +This is going to help by looking at the code, thinking about this, if we can look at the source code + +76 +00:04:20,000 --> 00:04:27,000 +and we can fix the bugs, the vulnerabilities in the source code, by the time it's deployed, by the + +77 +00:04:27,000 --> 00:04:30,000 +time it's compiled and deployed, the vulnerabilities were fixed. + +78 +00:04:32,000 --> 00:04:33,000 +Code signing. + +79 +00:04:33,000 --> 00:04:40,000 +Now, when you receive code from, let's say you're using a block of code from a provider, how do you + +80 +00:04:40,000 --> 00:04:42,000 +know it came from that provider? + +81 +00:04:42,000 --> 00:04:46,000 +How do you know that code hasn't been modified? + +82 +00:04:46,000 --> 00:04:48,000 +Well, if you remember, we used it. + +83 +00:04:48,000 --> 00:04:52,000 +We covered something in cryptography called digital signatures. + +84 +00:04:52,000 --> 00:04:59,000 +Digital signatures is when you sign a document and when you send it to someone, there'll be 100% sure + +85 +00:04:59,000 --> 00:05:01,000 +it came from you, and it was never modified. + +86 +00:05:01,000 --> 00:05:05,000 +Now, please review the digital signature process in the cryptography section. + +87 +00:05:05,000 --> 00:05:07,000 +In code signing, it's basically the same thing. + +88 +00:05:08,000 --> 00:05:12,000 +This involves using a digital signature to sign executables and scripts. + +89 +00:05:12,000 --> 00:05:13,000 +This could. + +90 +00:05:13,000 --> 00:05:19,000 +This signature confirms a software author and guarantees that the code has not been altered. + +91 +00:05:19,000 --> 00:05:22,000 +So, you know, this code came from Microsoft. + +92 +00:05:22,000 --> 00:05:25,000 +So Microsoft would sign codes Microsoft signs updates. + +93 +00:05:25,000 --> 00:05:27,000 +This is a common thing. + +94 +00:05:27,000 --> 00:05:32,000 +Microsoft will sign driver files, or manufacturers will sign a driver file that you'll install for + +95 +00:05:32,000 --> 00:05:33,000 +your hardware. + +96 +00:05:34,000 --> 00:05:40,000 +That way, you are 100% sure that the software you're installing is from Microsoft and hasn't been modified + +97 +00:05:40,000 --> 00:05:42,000 +by any external entities. + +98 +00:05:42,000 --> 00:05:47,000 +A certificate is issued by a trusted CA is used to sign the code. + +99 +00:05:47,000 --> 00:05:49,000 +Now, we all generally have commercial trusted CA. + +100 +00:05:50,000 --> 00:05:55,000 +When users download or execute the code, the software will then check the CA on the machine. + +101 +00:05:55,000 --> 00:05:58,000 +This helps to establish integrity of the code. + +102 +00:05:58,000 --> 00:06:03,000 +That means the code was never modified and authenticity that the code actually came from the Microsoft. + +103 +00:06:04,000 --> 00:06:08,000 +Now, another time you want to be familiar with is sandboxing. + +104 +00:06:09,000 --> 00:06:16,000 +Sandboxing, just like the sandbox we see here, but in a digital world, is a technique we're going + +105 +00:06:16,000 --> 00:06:24,000 +to use to isolate application programs processes in a separate environment to prevent them from affecting + +106 +00:06:24,000 --> 00:06:25,000 +other systems. + +107 +00:06:25,000 --> 00:06:27,000 +Sandboxing when you have a sandbox. + +108 +00:06:27,000 --> 00:06:29,000 +So let's say we take this tablet. + +109 +00:06:29,000 --> 00:06:30,000 +All right. + +110 +00:06:30,000 --> 00:06:31,000 +Let's say what we do. + +111 +00:06:31,000 --> 00:06:33,000 +This is our sandbox. + +112 +00:06:33,000 --> 00:06:36,000 +Whatever we execute here stays in this box. + +113 +00:06:36,000 --> 00:06:38,000 +Whatever code here stays here. + +114 +00:06:38,000 --> 00:06:42,000 +The sand does not flow outside of the box. + +115 +00:06:42,000 --> 00:06:44,000 +That's what a sandbox does. + +116 +00:06:44,000 --> 00:06:46,000 +It allows us to do quite a lot of things. + +117 +00:06:46,000 --> 00:06:48,000 +Number one, it's about isolation. + +118 +00:06:48,000 --> 00:06:53,000 +It involves running codes applications or processes, an isolated environment. + +119 +00:06:53,000 --> 00:07:00,000 +So just within this box that I have here that simulates end user's operating environment, the main + +120 +00:07:00,000 --> 00:07:03,000 +idea is to execute it without affecting anything on a system or a network. + +121 +00:07:03,000 --> 00:07:10,000 +This now we just don't do it for application programming, but in IT security we also use it to test + +122 +00:07:10,000 --> 00:07:10,000 +things. + +123 +00:07:10,000 --> 00:07:12,000 +I'll explain this in a minute. + +124 +00:07:12,000 --> 00:07:17,000 +In security, this isolation helps to contain the effects of malicious or faulty code. + +125 +00:07:17,000 --> 00:07:26,000 +Let's say you receive what you perceive to be, uh, you're not sure your perception, but you're thinking + +126 +00:07:26,000 --> 00:07:27,000 +that you know what? + +127 +00:07:27,000 --> 00:07:29,000 +This attachment is probably bad. + +128 +00:07:29,000 --> 00:07:29,000 +It's probably full. + +129 +00:07:29,000 --> 00:07:31,000 +Full of viruses. + +130 +00:07:31,000 --> 00:07:33,000 +Well, don't execute on your machine. + +131 +00:07:33,000 --> 00:07:34,000 +You put it in a sandbox. + +132 +00:07:34,000 --> 00:07:37,000 +In that sandbox environment, you can then execute. + +133 +00:07:37,000 --> 00:07:39,000 +If it blows up, it is going to stay right here. + +134 +00:07:39,000 --> 00:07:41,000 +If nothing happens, well, then you're sure it's good. + +135 +00:07:41,000 --> 00:07:44,000 +When it comes to codes, you probably want to test the code in the sandbox. + +136 +00:07:44,000 --> 00:07:48,000 +If the code is faulty and crashes, it doesn't crash an entire system. + +137 +00:07:48,000 --> 00:07:51,000 +Everything is confined to the box we're going to use. + +138 +00:07:51,000 --> 00:07:55,000 +The sandbox are useful a use for safely running and analyzing suspicious code. + +139 +00:07:55,000 --> 00:07:59,000 +This is what I was just mentioning to you, especially if it's malware. + +140 +00:08:00,000 --> 00:08:02,000 +Now different sandboxes that are out there. + +141 +00:08:02,000 --> 00:08:04,000 +We have this application sandbox. + +142 +00:08:04,000 --> 00:08:06,000 +This is used for individual applications. + +143 +00:08:06,000 --> 00:08:12,000 +For example, web browsers use a sandbox, isolate certain web plugins just in case it's a potential + +144 +00:08:12,000 --> 00:08:16,000 +malware virtual sandbox or VM sandbox or virtual machines. + +145 +00:08:16,000 --> 00:08:20,000 +And we're running a virtual running a full VM as a sandbox. + +146 +00:08:20,000 --> 00:08:25,000 +It's more secure because it completely separates the sandbox environment from the host operating system. + +147 +00:08:25,000 --> 00:08:28,000 +So you can set up your VMs as a sandbox. + +148 +00:08:28,000 --> 00:08:33,000 +And what this means is that if you have what you perceive to probably be malicious code or you're testing + +149 +00:08:33,000 --> 00:08:40,000 +malicious code, maybe you're a red hat pentester that put it on that VM, don't execute it on your + +150 +00:08:40,000 --> 00:08:42,000 +full machine cloud based sandbox. + +151 +00:08:43,000 --> 00:08:49,000 +There's a variety of cloud resources we can use to create a sandbox in the cloud, to execute a variety + +152 +00:08:49,000 --> 00:08:50,000 +of codes in there. + +153 +00:08:50,000 --> 00:08:56,000 +This is, of course, going to be much scalable and can handle big needs, especially if a sandbox is + +154 +00:08:56,000 --> 00:08:56,000 +needed. + +155 +00:08:56,000 --> 00:09:00,000 +When it comes to security, we use sandboxes quite a lot here at TI. + +156 +00:09:00,000 --> 00:09:01,000 +We have a sandbox. + +157 +00:09:01,000 --> 00:09:05,000 +We have a virtual sandbox, a virtual machine sandbox. + +158 +00:09:05,000 --> 00:09:09,000 +When people send us emails, send any staff an email. + +159 +00:09:10,000 --> 00:09:12,000 +And we're not too sure if you know. + +160 +00:09:12,000 --> 00:09:13,000 +Is that link bad? + +161 +00:09:14,000 --> 00:09:16,000 +Is that PDF any good? + +162 +00:09:16,000 --> 00:09:17,000 +Right. + +163 +00:09:17,000 --> 00:09:18,000 +Is that going to give us a virus. + +164 +00:09:18,000 --> 00:09:20,000 +They send it to the security person. + +165 +00:09:20,000 --> 00:09:23,000 +The security person that takes that email opens it in a sandbox. + +166 +00:09:23,000 --> 00:09:26,000 +If it's all good and we're verifying that it's good, great. + +167 +00:09:26,000 --> 00:09:28,000 +We tell the user, call the user, hey, it's fine. + +168 +00:09:28,000 --> 00:09:29,000 +Open. + +169 +00:09:29,000 --> 00:09:33,000 +If not, if it executes and it blows up and it's a virus, we tell a user delete right away, it's no + +170 +00:09:33,000 --> 00:09:34,000 +good. + +171 +00:09:34,000 --> 00:09:38,000 +So malware analysis you can also use to test environments. + +172 +00:09:38,000 --> 00:09:41,000 +So if you're not sure if the code will crash your system this would be good. + +173 +00:09:41,000 --> 00:09:46,000 +That way if it does crash, it doesn't crash an entire network, it just crashes in the sandbox. + +174 +00:09:47,000 --> 00:09:50,000 +It does help to protect end users from potentially harmful content. + +175 +00:09:50,000 --> 00:09:57,000 +For example, in that email attachment sandboxing is something that is incredibly useful in any environment. + +176 +00:09:57,000 --> 00:09:59,000 +I highly recommend you get one. + +177 +00:09:59,000 --> 00:10:01,000 +Okay, just a quick recap. + +178 +00:10:01,000 --> 00:10:07,000 +Remember, input validation is going to be used to solve things like cross-site scripting and injection + +179 +00:10:07,000 --> 00:10:07,000 +attacks. + +180 +00:10:07,000 --> 00:10:10,000 +We use secure cookies. + +181 +00:10:10,000 --> 00:10:12,000 +Make sure all cookies are secure as they're being transferred. + +182 +00:10:12,000 --> 00:10:17,000 +Code signing is when you digitally sign codes, especially software codes. + +183 +00:10:17,000 --> 00:10:22,000 +That way, you know it came from a particular manufacturer and it was never modified. + +184 +00:10:23,000 --> 00:10:25,000 +And then make sure you understand. + +185 +00:10:25,000 --> 00:10:31,000 +Sandboxing is an amazing utility that helps us to test codes or tests for potential malware. + diff --git a/13 - Common Security Techniques/008 Security Monitoring OB 4.1_en.srt b/13 - Common Security Techniques/008 Security Monitoring OB 4.1_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..1a4ea59e1b93f70c295367b824054867af3d06bc --- /dev/null +++ b/13 - Common Security Techniques/008 Security Monitoring OB 4.1_en.srt @@ -0,0 +1,296 @@ +1 +00:00:00,000 --> 00:00:02,000 +You're working in your network on a daily basis. + +2 +00:00:02,000 --> 00:00:05,000 +The question is, how do you know if you're being attacked? + +3 +00:00:05,000 --> 00:00:08,000 +You're sitting at your desktop, you're browsing the internet. + +4 +00:00:08,000 --> 00:00:10,000 +You're doing some work that your organization wants you to do. + +5 +00:00:10,000 --> 00:00:12,000 +Your security administrator. + +6 +00:00:12,000 --> 00:00:17,000 +How do you know that something bad is happening in that organization at that given moment? + +7 +00:00:17,000 --> 00:00:24,000 +The only way you're going to notice is if you are consistently monitoring the entire network. + +8 +00:00:24,000 --> 00:00:27,000 +You're monitoring what's happening in your system. + +9 +00:00:27,000 --> 00:00:31,000 +So this brings me to this topic of security monitoring. + +10 +00:00:31,000 --> 00:00:38,000 +You see, security monitoring is about monitoring traffic across your entire network, the horses and + +11 +00:00:38,000 --> 00:00:44,000 +the traffic flowing around the the lines, the networking devices for security issues and security problems + +12 +00:00:45,000 --> 00:00:48,000 +such as security attacks that can take place. + +13 +00:00:48,000 --> 00:00:51,000 +Now, a couple of things here we want to talk about when it comes to monitoring. + +14 +00:00:51,000 --> 00:00:54,000 +First of all, let's talk about network monitoring. + +15 +00:00:54,000 --> 00:00:58,000 +This involves tracking and analyzing network traffic. + +16 +00:00:58,000 --> 00:01:04,000 +You want to detect any abnormal any kind of abnormalities, any kind of abnormal traffic, unauthorized + +17 +00:01:04,000 --> 00:01:06,000 +access or other signs of malicious activity. + +18 +00:01:06,000 --> 00:01:09,000 +Then you have systems and application monitoring. + +19 +00:01:09,000 --> 00:01:11,000 +This is focused on performance and security. + +20 +00:01:11,000 --> 00:01:13,000 +Specific systems and applications. + +21 +00:01:13,000 --> 00:01:19,000 +Monitor monitoring for indication of security activities on a system like on a server or a workstation, + +22 +00:01:19,000 --> 00:01:23,000 +or maybe tracking what's happening in certain applications that we're using. + +23 +00:01:23,000 --> 00:01:27,000 +So if we look at this, we're going to be monitoring all the traffic flowing around the network and + +24 +00:01:27,000 --> 00:01:29,000 +all the traffic on the actual system. + +25 +00:01:29,000 --> 00:01:35,000 +The problem with monitoring is the enormous amount of data you're going to get. + +26 +00:01:35,000 --> 00:01:39,000 +Being able to correlate and track all this data is almost impossible. + +27 +00:01:39,000 --> 00:01:45,000 +That's why you need somewhere to collect and analyze the logs from the different network and devices + +28 +00:01:45,000 --> 00:01:47,000 +and systems on your network. + +29 +00:01:47,000 --> 00:01:51,000 +The tool we're going to use for this, and we're going to cover more about this tool later in this course + +30 +00:01:51,000 --> 00:01:52,000 +is the Siem system. + +31 +00:01:53,000 --> 00:01:56,000 +It sends the security information and event management there. + +32 +00:01:56,000 --> 00:02:03,000 +This is what's going to be we're going to use to aggregate correlate and analyze all this data that + +33 +00:02:03,000 --> 00:02:04,000 +you're going to be capturing. + +34 +00:02:05,000 --> 00:02:10,000 +Famous offer for this is going to be like Splunk is a very famous software that does this. + +35 +00:02:11,000 --> 00:02:14,000 +When you monitor, you're going to get some really good benefits. + +36 +00:02:14,000 --> 00:02:16,000 +Number one, early detection of threats. + +37 +00:02:16,000 --> 00:02:24,000 +If you're not monitoring, you may not know the threat is there until our systems are down or data has + +38 +00:02:24,000 --> 00:02:29,000 +been reported lost, versus if you are proactively monitoring, you would know the threat just came + +39 +00:02:29,000 --> 00:02:36,000 +in performance uh management ensuring that IT infrastructure operates efficiently. + +40 +00:02:36,000 --> 00:02:42,000 +The moment you see that servers are being pushed up too much, uh, in terms of Ram and CPU. + +41 +00:02:42,000 --> 00:02:44,000 +In other words, they're being taxed too much. + +42 +00:02:44,000 --> 00:02:48,000 +They become the resources are starting to be depleted quick. + +43 +00:02:48,000 --> 00:02:53,000 +You can quickly go in there and up your resources to make sure you stay at a certain performance. + +44 +00:02:54,000 --> 00:02:57,000 +Monitoring also helps with compliance. + +45 +00:02:57,000 --> 00:02:57,000 +All right. + +46 +00:02:57,000 --> 00:02:59,000 +Maintaining various regulatory compliance. + +47 +00:02:59,000 --> 00:03:08,000 +Because in certain times there may be security incidents that may occur that does require you to keep + +48 +00:03:08,000 --> 00:03:11,000 +an eye on different kinds of activities in your network. + +49 +00:03:11,000 --> 00:03:12,000 +Insights. + +50 +00:03:12,000 --> 00:03:15,000 +This provides valuable insights into the security posture. + +51 +00:03:15,000 --> 00:03:17,000 +How well is the security doing? + +52 +00:03:17,000 --> 00:03:20,000 +Listen, you don't know if your company is doing well in security. + +53 +00:03:20,000 --> 00:03:25,000 +If you're not checking anything, how do you know if you're losing weight, if you never really check + +54 +00:03:25,000 --> 00:03:26,000 +the scale? + +55 +00:03:27,000 --> 00:03:30,000 +Now, technically you can tell in the mirror, but it's hard to do that. + +56 +00:03:30,000 --> 00:03:35,000 +So the best thing to do is a continuous check to see how well security is. + +57 +00:03:35,000 --> 00:03:42,000 +Now, the best thing here is going to be real time monitoring, immediate analysis and alerts for ongoing + +58 +00:03:42,000 --> 00:03:43,000 +activities. + +59 +00:03:43,000 --> 00:03:44,000 +This is going to be critical. + +60 +00:03:44,000 --> 00:03:47,000 +You want to do rapid response real time. + +61 +00:03:47,000 --> 00:03:51,000 +But this does have a major problem significant power process and power. + +62 +00:03:51,000 --> 00:03:54,000 +And sophisticated tools like Siem systems. + +63 +00:03:54,000 --> 00:04:00,000 +Now if you do it on a regular basis, once, twice, three times a week, regular schedule checks for + +64 +00:04:00,000 --> 00:04:02,000 +analysis of certain uh systems. + +65 +00:04:03,000 --> 00:04:07,000 +Maybe if you're doing maybe once or twice a week, you can do less critical systems. + +66 +00:04:07,000 --> 00:04:14,000 +Maybe you want to do critical systems five days a week, or maybe you can combine both of them. + +67 +00:04:14,000 --> 00:04:20,000 +In other words, real time monitoring, not for everything, but for critical systems and periodic monitoring + +68 +00:04:20,000 --> 00:04:22,000 +for less critical system. + +69 +00:04:23,000 --> 00:04:28,000 +You would never know the security posture of the organization if you don't monitor. + +70 +00:04:28,000 --> 00:04:34,000 +If we don't monitor what's there, if we don't monitor the traffic, if we don't monitor the workstations + +71 +00:04:34,000 --> 00:04:36,000 +in our network, we wouldn't know if we're being attacked. + +72 +00:04:36,000 --> 00:04:42,000 +We wouldn't know how many times we're being attacked, wouldn't know what was solved, what wasn't solved, + +73 +00:04:42,000 --> 00:04:43,000 +and even how fast we fix it. + +74 +00:04:43,000 --> 00:04:49,000 +So monitoring is an essential part of keeping our organizations secure. + diff --git a/13 - Common Security Techniques/009 Quick Quiz.html b/13 - Common Security Techniques/009 Quick Quiz.html new file mode 100644 index 0000000000000000000000000000000000000000..159fd41678e8a2ff3cd62c8176ad9d08c4b1c144 --- /dev/null +++ b/13 - Common Security Techniques/009 Quick Quiz.html @@ -0,0 +1,479 @@ + + + + + + + Quiz + + + + +
+
+

+

+
+
+
+ Score: 999 of + 999% +
+
Correct: 999
+
Incorrect: 999
+
+ +
+ + + + +
+ + + + diff --git a/14 - Hardware, software and Data Asset Management/001 Acquisition Procurement OB 4.2_en.srt b/14 - Hardware, software and Data Asset Management/001 Acquisition Procurement OB 4.2_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..dac97fc8c3764a29830c128ebb1245d488d46339 --- /dev/null +++ b/14 - Hardware, software and Data Asset Management/001 Acquisition Procurement OB 4.2_en.srt @@ -0,0 +1,400 @@ +1 +00:00:00,000 --> 00:00:06,000 +90% of what you're going to be dealing with in large businesses is purchased from outside the company. + +2 +00:00:06,000 --> 00:00:12,000 +All the different hardware they use, such as the Sonicwall and different software such as windows CRM + +3 +00:00:12,000 --> 00:00:13,000 +software databases. + +4 +00:00:13,000 --> 00:00:18,000 +90% of what you use in large businesses is acquired from outside, if not more. + +5 +00:00:18,000 --> 00:00:24,000 +When it comes to small to mid-sized businesses, that percentage is probably close to 100%, if not + +6 +00:00:24,000 --> 00:00:25,000 +100%. + +7 +00:00:25,000 --> 00:00:30,000 +Every organization needs to have a process in place for acquisition and procurement. + +8 +00:00:30,000 --> 00:00:37,000 +That means they have to have a certain procedure in place for the selection of vendors and purchasing + +9 +00:00:37,000 --> 00:00:40,000 +of hardware and software from outside the business. + +10 +00:00:40,000 --> 00:00:44,000 +You see, this particular process for acquiring these hardware. + +11 +00:00:44,000 --> 00:00:51,000 +Software and data assets carry big security problems because if it's done wrong, you could be introducing + +12 +00:00:51,000 --> 00:00:53,000 +all kinds of security risks to your organization. + +13 +00:00:53,000 --> 00:00:56,000 +So in this video, let's take a quick look at this process. + +14 +00:00:56,000 --> 00:01:01,000 +Now I do want to just mention that this is just something you should be aware that exists, that businesses + +15 +00:01:01,000 --> 00:01:08,000 +is going to have a process and a procedure to acquire hardware and software, and every business has + +16 +00:01:08,000 --> 00:01:12,000 +it is just going to it's just going to be different for every business. + +17 +00:01:12,000 --> 00:01:15,000 +So in this video, I just want to point out a couple of things that we should be familiar with. + +18 +00:01:16,000 --> 00:01:23,000 +So each stage of the process of acquiring hardware and or software of this process can introduce vulnerability, + +19 +00:01:23,000 --> 00:01:24,000 +if not risk in it. + +20 +00:01:24,000 --> 00:01:26,000 +Now there's a couple of things here. + +21 +00:01:26,000 --> 00:01:33,000 +First of all, the importance of accuracy before we go out and we purchase. + +22 +00:01:33,000 --> 00:01:35,000 +This particular thing. + +23 +00:01:35,000 --> 00:01:37,000 +The needs assessment must be done. + +24 +00:01:37,000 --> 00:01:40,000 +Now, what a needs assessment is, do you actually need it? + +25 +00:01:40,000 --> 00:01:45,000 +Failing to accurately assess the organization's requirement can lead to acquiring assets that are either + +26 +00:01:45,000 --> 00:01:51,000 +that that are either overprivileged or lack the necessary security features, and thereby introducing + +27 +00:01:51,000 --> 00:01:52,000 +vulnerability. + +28 +00:01:52,000 --> 00:01:58,000 +For example, if you don't really need something, or you haven't done a good assessment on something + +29 +00:01:58,000 --> 00:02:03,000 +and you purchase something that the organization just doesn't need right now or just doesn't add any + +30 +00:02:03,000 --> 00:02:09,000 +value to it, you could be putting in hardware maybe not as good as a sonicwall, but some kind of hardware + +31 +00:02:09,000 --> 00:02:12,000 +and or software that can lead to vulnerability. + +32 +00:02:12,000 --> 00:02:20,000 +If you don't assess your vendors correctly and you purchase from vendors with history of dealing or + +33 +00:02:20,000 --> 00:02:25,000 +having issues, you could be introducing vulnerabilities into your environment. + +34 +00:02:25,000 --> 00:02:30,000 +So when it comes to particularly choosing a vendor, choosing a vendor with a poor security track record + +35 +00:02:30,000 --> 00:02:35,000 +or inadequate support for security features can expose you to massive risks. + +36 +00:02:35,000 --> 00:02:41,000 +Vendors compromised by cyber threats can inadvertently introduce new malware vulnerabilities, let's + +37 +00:02:41,000 --> 00:02:44,000 +say, for whatever reason. + +38 +00:02:44,000 --> 00:02:47,000 +And I'm going to tell you guys, you should never purchase security products from vendors, have never + +39 +00:02:47,000 --> 00:02:52,000 +heard about buy it from the big vendors who has massive crews to keep them secure. + +40 +00:02:52,000 --> 00:02:58,000 +Let's say your organization is trying to save money and decide they don't want to spend the thousand + +41 +00:02:58,000 --> 00:03:00,000 +dollars it takes to purchase this equipment. + +42 +00:03:00,000 --> 00:03:02,000 +And this is again, this is a small business. + +43 +00:03:02,000 --> 00:03:08,000 +For midsize businesses, purchasing Sonicwall can go thousands and thousands of dollars and with its + +44 +00:03:08,000 --> 00:03:10,000 +licensing, can go over way over $10,000. + +45 +00:03:10,000 --> 00:03:11,000 +Now. + +46 +00:03:11,000 --> 00:03:13,000 +Let's say you guys decide that you know what? + +47 +00:03:13,000 --> 00:03:16,000 +We don't want to spend a lot of money. + +48 +00:03:16,000 --> 00:03:21,000 +So you go with a smaller supplier or smaller maker or a new maker that just came out of a particular + +49 +00:03:21,000 --> 00:03:22,000 +firewall device. + +50 +00:03:22,000 --> 00:03:29,000 +Well, that new vendor that just came into the market may not have the resources and for example, the + +51 +00:03:29,000 --> 00:03:30,000 +manpower. + +52 +00:03:30,000 --> 00:03:38,000 +They may not have the resources and knowledge it takes to produce a device that has less security vulnerabilities + +53 +00:03:38,000 --> 00:03:39,000 +and the risks. + +54 +00:03:39,000 --> 00:03:44,000 +For example, let's say this Sonicwall there's a vulnerability discovered. + +55 +00:03:44,000 --> 00:03:48,000 +Well, Sonicwall is owned by Dell, and Sonicwall is a big company by itself. + +56 +00:03:48,000 --> 00:03:50,000 +And Dell is a is a massive IT company now. + +57 +00:03:52,000 --> 00:03:58,000 +I'm pretty sure Dell and Sonicwall has the resources needed in order to fix that vulnerability. + +58 +00:03:58,000 --> 00:03:59,000 +Right away. + +59 +00:03:59,000 --> 00:04:04,000 +You purchase from a small vendor if there's a vulnerability in their device and their software, you + +60 +00:04:04,000 --> 00:04:10,000 +might have to wait weeks, maybe months before you can get a fix if you even get a fix. + +61 +00:04:10,000 --> 00:04:15,000 +Not to mention, when you purchase from large vendors, they're less likely to go out of business. + +62 +00:04:15,000 --> 00:04:20,000 +For example, if you purchase a sonicwall device and for whatever reason, Dell goes out of business + +63 +00:04:20,000 --> 00:04:23,000 +and Sonicwall goes out of business, then what happens? + +64 +00:04:23,000 --> 00:04:24,000 +Well, no. + +65 +00:04:24,000 --> 00:04:25,000 +No more support. + +66 +00:04:25,000 --> 00:04:28,000 +The device you just purchased is pretty useless. + +67 +00:04:28,000 --> 00:04:32,000 +It becomes a paperweight as it's full of vulnerabilities with nobody to fix it. + +68 +00:04:32,000 --> 00:04:33,000 +That becomes an issue. + +69 +00:04:33,000 --> 00:04:33,000 +Right? + +70 +00:04:33,000 --> 00:04:40,000 +So there's a lot of things that you want to think about when selecting a vendor you don't do. + +71 +00:04:41,000 --> 00:04:49,000 +Uh, a good, thorough review of that vendor and their track record for how, for example, a security + +72 +00:04:49,000 --> 00:04:50,000 +track record. + +73 +00:04:50,000 --> 00:04:55,000 +What that means is how many vulnerabilities was against their device, how often is their device hacked, + +74 +00:04:55,000 --> 00:04:58,000 +and how fast do they fix those devices? + +75 +00:04:58,000 --> 00:04:59,000 +That can be a problem. + +76 +00:04:59,000 --> 00:05:02,000 +Another thing you want to take a look at is the supply chain attacks. + +77 +00:05:02,000 --> 00:05:06,000 +If the vendor supply chain is compromised, it can affect the integrity of the hardware. + +78 +00:05:06,000 --> 00:05:12,000 +For example, you may want to take a look at where the vendor sources their materials from. + +79 +00:05:12,000 --> 00:05:15,000 +For example, what does it mean by that source? + +80 +00:05:15,000 --> 00:05:16,000 +And the material means that. + +81 +00:05:17,000 --> 00:05:19,000 +Where did he get into hardware? + +82 +00:05:19,000 --> 00:05:20,000 +Where to get into steel. + +83 +00:05:20,000 --> 00:05:24,000 +Are they using suppliers in countries that are vulnerable? + +84 +00:05:24,000 --> 00:05:25,000 +And maybe they have political unrest? + +85 +00:05:25,000 --> 00:05:30,000 +Maybe the country is subject to all kinds of extreme weather conditions or natural disasters. + +86 +00:05:30,000 --> 00:05:37,000 +If you didn't do your assessment on the vendors, what eventually can happen is these vendors can drop + +87 +00:05:37,000 --> 00:05:42,000 +quickly because the moment there's a major disruption, the whole supply chain gets kicked out and the + +88 +00:05:42,000 --> 00:05:43,000 +vendor can't produce the hardware. + +89 +00:05:44,000 --> 00:05:51,000 +Okay, just keep in mind that the whole thing of procuring, the processes of procuring all, like all + +90 +00:05:51,000 --> 00:05:54,000 +I basically concentrated on was the selection of the vendor. + +91 +00:05:54,000 --> 00:05:59,000 +But every organization, they have to do some kind of a needs assessment. + +92 +00:05:59,000 --> 00:06:02,000 +Do we need this particular hardware, this particular software. + +93 +00:06:02,000 --> 00:06:04,000 +Why are we purchasing this. + +94 +00:06:04,000 --> 00:06:07,000 +They're going to have to go through a process of selecting a vendor. + +95 +00:06:07,000 --> 00:06:12,000 +They're going to have to do a process of onboarding that vendor into the organization. + +96 +00:06:12,000 --> 00:06:16,000 +And then the process of purchasing that actual hardware or software. + +97 +00:06:16,000 --> 00:06:18,000 +And keeping it updated. + +98 +00:06:18,000 --> 00:06:21,000 +This is not this is an your exam. + +99 +00:06:21,000 --> 00:06:27,000 +Your exam maker does not specify a process that they should follow because every organization is different. + +100 +00:06:27,000 --> 00:06:29,000 +So just be familiar that it exists. + diff --git a/14 - Hardware, software and Data Asset Management/002 Assignment and Accounting OB 4.2_en.srt b/14 - Hardware, software and Data Asset Management/002 Assignment and Accounting OB 4.2_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..e018dc09863cb1054add71d1de8c32fbc0e58705 --- /dev/null +++ b/14 - Hardware, software and Data Asset Management/002 Assignment and Accounting OB 4.2_en.srt @@ -0,0 +1,212 @@ +1 +00:00:00,000 --> 00:00:06,000 +When hardware and or software is purchased in an organization, it is generally assigned some kind of + +2 +00:00:06,000 --> 00:00:07,000 +ownership. + +3 +00:00:07,000 --> 00:00:12,000 +For example, when this thing is purchased to secure a particular department and or the entire business. + +4 +00:00:12,000 --> 00:00:16,000 +Most businesses is going to assign this thing some kind of ownership. + +5 +00:00:16,000 --> 00:00:18,000 +What department owns it? + +6 +00:00:18,000 --> 00:00:24,000 +Now, this is going to be important because ownership brings a lot of responsibilities when it comes + +7 +00:00:24,000 --> 00:00:25,000 +to the hardware and software. + +8 +00:00:25,000 --> 00:00:26,000 +Let's talk about this. + +9 +00:00:26,000 --> 00:00:32,000 +Ownership in cyber security reflects a designation of responsibility for an asset to an individual or + +10 +00:00:32,000 --> 00:00:34,000 +a department within the business. + +11 +00:00:34,000 --> 00:00:38,000 +It ensures that there is a specific party responsible for security, maintenance and compliance. + +12 +00:00:38,000 --> 00:00:44,000 +So more than likely something like this will be owned by the IT department. + +13 +00:00:44,000 --> 00:00:48,000 +Now, what does it mean when the organization says, well, you own that device? + +14 +00:00:48,000 --> 00:00:54,000 +Well, that means that this that department of it is responsible for the security of it, making sure + +15 +00:00:54,000 --> 00:01:00,000 +that they apply best security practices, the maintenance of it, updating it, for example. + +16 +00:01:01,000 --> 00:01:02,000 +And compliance of it. + +17 +00:01:02,000 --> 00:01:04,000 +Maybe there's different regulations. + +18 +00:01:04,000 --> 00:01:08,000 +Owners are going to be in charge of defining access control. + +19 +00:01:08,000 --> 00:01:14,000 +So the IT department, and particularly the security section of the IT department is going to be defining + +20 +00:01:14,000 --> 00:01:19,000 +on who should have access to this, how it should be configured, the permissions within it, and is + +21 +00:01:19,000 --> 00:01:21,000 +it used for any type of compliance. + +22 +00:01:21,000 --> 00:01:26,000 +So when assets are acquired it's important that ownership is assigned. + +23 +00:01:26,000 --> 00:01:30,000 +That way somebody holds the responsibility for defining this. + +24 +00:01:30,000 --> 00:01:36,000 +Another thing is that some organizations will implement a classification on the device. + +25 +00:01:36,000 --> 00:01:37,000 +Now this is important. + +26 +00:01:37,000 --> 00:01:40,000 +We talked about data classification previously. + +27 +00:01:40,000 --> 00:01:44,000 +Data classification affects all aspects of information. + +28 +00:01:44,000 --> 00:01:48,000 +Data classification is going to affect where the data is stored. + +29 +00:01:49,000 --> 00:01:50,000 +How is the data managed. + +30 +00:01:50,000 --> 00:01:56,000 +Who has access to the data, how is it backed up, what type of encryption and so on. + +31 +00:01:56,000 --> 00:02:00,000 +In this particular section, what we're doing is we're categorizing the assets. + +32 +00:02:00,000 --> 00:02:02,000 +This is a classification here. + +33 +00:02:02,000 --> 00:02:07,000 +It's categorizing this based on their sensitivity of value and their impact. + +34 +00:02:07,000 --> 00:02:13,000 +Now this is important because if we classify it as device to have something such as oh it's public or + +35 +00:02:13,000 --> 00:02:18,000 +it's internal only or it's confidential or something like that, that means that it can only process + +36 +00:02:18,000 --> 00:02:21,000 +data that's top secret or confidential. + +37 +00:02:21,000 --> 00:02:23,000 +For example, let's say you have. + +38 +00:02:24,000 --> 00:02:25,000 +Top secret data. + +39 +00:02:25,000 --> 00:02:29,000 +But did this device in your organization is not ranked as top secret? + +40 +00:02:29,000 --> 00:02:33,000 +Maybe because it doesn't have enough security protection built in it. + +41 +00:02:33,000 --> 00:02:39,000 +So that means this device can't ever process top secret data through its internal memory structure. + +42 +00:02:39,000 --> 00:02:43,000 +Certain organizations may use different devices for that, or they may not allow it on the network at + +43 +00:02:43,000 --> 00:02:44,000 +all. + +44 +00:02:44,000 --> 00:02:46,000 +Every organization is going to be different. + +45 +00:02:46,000 --> 00:02:52,000 +The purpose of doing this is to apply an appropriate level of security controls based on the classification + +46 +00:02:52,000 --> 00:02:56,000 +sensitive high value assets require, of course, much more protection. + +47 +00:02:56,000 --> 00:03:02,000 +For example, something in top secret is going to require much more protection than something that's + +48 +00:03:02,000 --> 00:03:02,000 +not. + +49 +00:03:03,000 --> 00:03:05,000 +When it comes to ownership and classification. + +50 +00:03:05,000 --> 00:03:07,000 +This is something that's unique to every business. + +51 +00:03:07,000 --> 00:03:12,000 +Every business has their own way of classifying information and or devices. + +52 +00:03:12,000 --> 00:03:17,000 +Basically, hardware, software and data will all have to go through a classification scheme. + +53 +00:03:17,000 --> 00:03:19,000 +This is different for every business. + diff --git a/14 - Hardware, software and Data Asset Management/003 Monitoring and Tracking OB 4.2_en.srt b/14 - Hardware, software and Data Asset Management/003 Monitoring and Tracking OB 4.2_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..5e909dcf95a3bbf688b9d9d189bf2622736e40a4 --- /dev/null +++ b/14 - Hardware, software and Data Asset Management/003 Monitoring and Tracking OB 4.2_en.srt @@ -0,0 +1,304 @@ +1 +00:00:00,000 --> 00:00:06,000 +If there is one thing that the IT department has probably heard too much of, is that you guys have + +2 +00:00:06,000 --> 00:00:07,000 +too much stuff. + +3 +00:00:07,000 --> 00:00:11,000 +If you walk into an IT department, they're going to have tons and tons of hardware that they don't + +4 +00:00:11,000 --> 00:00:13,000 +use, or tons of hardware that they do use. + +5 +00:00:13,000 --> 00:00:19,000 +I'm talking all kinds of routers and switches and gears and workstations and servers and laptops and + +6 +00:00:19,000 --> 00:00:21,000 +and tablets and phones. + +7 +00:00:21,000 --> 00:00:22,000 +Oh my God, it's a lot. + +8 +00:00:22,000 --> 00:00:28,000 +So in this video I want to talk about what's called monitoring and tracking of inventory. + +9 +00:00:28,000 --> 00:00:35,000 +Basically, do we have a system in place to keep track of all the physical hardware and software that + +10 +00:00:35,000 --> 00:00:39,000 +we use to produce or manage IT services? + +11 +00:00:39,000 --> 00:00:40,000 +So let's talk about this. + +12 +00:00:40,000 --> 00:00:43,000 +So the first thing I want to talk about here is inventory management. + +13 +00:00:44,000 --> 00:00:48,000 +Inventory management answers simple questions like this. + +14 +00:00:48,000 --> 00:00:51,000 +Well, in your network, how many workstations do you have? + +15 +00:00:51,000 --> 00:00:54,000 +How many servers you have, how many printers you got? + +16 +00:00:54,000 --> 00:00:58,000 +How many phones you have, how many firewalls you have? + +17 +00:00:58,000 --> 00:01:00,000 +You know, where is it stored? + +18 +00:01:00,000 --> 00:01:01,000 +Who owns it? + +19 +00:01:01,000 --> 00:01:02,000 +Is it identified? + +20 +00:01:02,000 --> 00:01:04,000 +Where is it in the lifecycle? + +21 +00:01:04,000 --> 00:01:05,000 +So this is what this is. + +22 +00:01:05,000 --> 00:01:06,000 +So let's go through it. + +23 +00:01:06,000 --> 00:01:08,000 +So asset identification. + +24 +00:01:08,000 --> 00:01:14,000 +What we need to do is we need to catalog all assets including the type model specification and version. + +25 +00:01:14,000 --> 00:01:18,000 +So how about if I told you guys I want you guys to go in your network now. + +26 +00:01:18,000 --> 00:01:19,000 +And I need you guys to. + +27 +00:01:20,000 --> 00:01:28,000 +Actually produce a list of every single desktop laptop, uh, server workstation. + +28 +00:01:28,000 --> 00:01:31,000 +Tell me not just their type. + +29 +00:01:31,000 --> 00:01:33,000 +Tell me their model. + +30 +00:01:33,000 --> 00:01:36,000 +How many models of the f 22 desktop do you have? + +31 +00:01:36,000 --> 00:01:37,000 +Their specifications? + +32 +00:01:38,000 --> 00:01:40,000 +How many i5 machines do we have? + +33 +00:01:40,000 --> 00:01:40,000 +How many i7's? + +34 +00:01:40,000 --> 00:01:45,000 +How many Macs and what versions are there record who is responsible for the asset. + +35 +00:01:45,000 --> 00:01:51,000 +For example, some assets are owned by the accounting department, some are owned by the sales department. + +36 +00:01:51,000 --> 00:01:53,000 +And where are they in their life cycle? + +37 +00:01:53,000 --> 00:01:56,000 +Most businesses will probably replace hardware every five years. + +38 +00:01:56,000 --> 00:02:01,000 +They may replace software every four or 3 to 8 years, depending on what it is. + +39 +00:02:01,000 --> 00:02:07,000 +Where in the life cycle is it, uh, from acquisition, like when did we acquire it and when is it left + +40 +00:02:07,000 --> 00:02:08,000 +to be disposed of? + +41 +00:02:08,000 --> 00:02:10,000 +So this is important. + +42 +00:02:10,000 --> 00:02:13,000 +You're probably saying, well, how does this relate to security? + +43 +00:02:13,000 --> 00:02:19,000 +Well, a well maintained inventory allows for the identification of unauthorized or rogue devices. + +44 +00:02:19,000 --> 00:02:22,000 +And software, which could pose potential security risks. + +45 +00:02:22,000 --> 00:02:29,000 +Because if you do this and you do this correctly, what's going to happen is that you'll know, well, + +46 +00:02:29,000 --> 00:02:30,000 +what's this doing here? + +47 +00:02:30,000 --> 00:02:31,000 +We never bought this. + +48 +00:02:31,000 --> 00:02:33,000 +This was something that wasn't belong on this network. + +49 +00:02:33,000 --> 00:02:39,000 +And it could be a hacker or some bad guy having hardware in your network you don't even know about. + +50 +00:02:40,000 --> 00:02:40,000 +This is. + +51 +00:02:40,000 --> 00:02:42,000 +Of course, I find this very challenging. + +52 +00:02:43,000 --> 00:02:45,000 +Even in our small network. + +53 +00:02:45,000 --> 00:02:50,000 +I find this very challenging because IT departments changes on a daily basis. + +54 +00:02:50,000 --> 00:02:56,000 +We're always ordering, changing, looking for new parts, and what happens is that keeping the inventory + +55 +00:02:56,000 --> 00:02:58,000 +up to date is a challenge for me. + +56 +00:02:58,000 --> 00:03:04,000 +New assets are frequently added and old ones are retired without people not managing it correctly. + +57 +00:03:04,000 --> 00:03:07,000 +Now enumerate means basically counting. + +58 +00:03:07,000 --> 00:03:10,000 +So in here we're going to identify quantify them. + +59 +00:03:10,000 --> 00:03:11,000 +How do we do this. + +60 +00:03:11,000 --> 00:03:13,000 +How do we enumerate these devices or count them. + +61 +00:03:13,000 --> 00:03:16,000 +Basically what we're going to be doing is we're going to use a scanning tool. + +62 +00:03:16,000 --> 00:03:18,000 +There's a great tool called Spiceworks that does this. + +63 +00:03:18,000 --> 00:03:18,000 +It's free. + +64 +00:03:18,000 --> 00:03:22,000 +Also used to scan the network for connected devices. + +65 +00:03:23,000 --> 00:03:28,000 +You can also determine what services are running on the devices, and some of them can even look for + +66 +00:03:28,000 --> 00:03:31,000 +vulnerabilities on these devices. + +67 +00:03:31,000 --> 00:03:36,000 +This helps in identifying all types of security weaknesses, and it gives you a good visibility into + +68 +00:03:36,000 --> 00:03:38,000 +the things on your network. + +69 +00:03:38,000 --> 00:03:43,000 +Now, one of the things is that if when you're doing enumeration activities, you don't disrupt normal + +70 +00:03:44,000 --> 00:03:50,000 +business operations, because when you enumerate, what starts to happen is that you're using up a lot + +71 +00:03:50,000 --> 00:03:54,000 +of bandwidth and particularly network traffic. + +72 +00:03:54,000 --> 00:03:54,000 +All right. + +73 +00:03:54,000 --> 00:03:57,000 +This particular thing here, I think is important. + +74 +00:03:57,000 --> 00:04:02,000 +Every network out there needs to have some kind of software. + +75 +00:04:03,000 --> 00:04:10,000 +Um, even a small as an Excel sheet that keeps track of all their hardware and software, basically + +76 +00:04:10,000 --> 00:04:12,000 +inventory tracking in their network. + diff --git a/14 - Hardware, software and Data Asset Management/004 Disposal and Decommission OB 4.2_en.srt b/14 - Hardware, software and Data Asset Management/004 Disposal and Decommission OB 4.2_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..7b7c1fd3c6c581b892066a7d05acacfd756d8c09 --- /dev/null +++ b/14 - Hardware, software and Data Asset Management/004 Disposal and Decommission OB 4.2_en.srt @@ -0,0 +1,592 @@ +1 +00:00:00,000 --> 00:00:05,000 +Every single piece of hardware and or software in an organization will reach an end of life at some + +2 +00:00:05,000 --> 00:00:06,000 +point. + +3 +00:00:06,000 --> 00:00:12,000 +Now, in most organizations, hardware like this will probably last 3 to 5, three to 5 to 8 years, + +4 +00:00:12,000 --> 00:00:14,000 +depending on what it is. + +5 +00:00:14,000 --> 00:00:17,000 +A device like this may be more like 5 to 8 years. + +6 +00:00:17,000 --> 00:00:22,000 +Certain hardware high end game, um, video editing hardware may only last three years. + +7 +00:00:22,000 --> 00:00:24,000 +Every piece of hardware is different. + +8 +00:00:24,000 --> 00:00:29,000 +Every piece of software is different as they all have different life cycles to different businesses. + +9 +00:00:29,000 --> 00:00:35,000 +Sometimes hardware and software comes to an end when the manufacturer brings it to an end. + +10 +00:00:35,000 --> 00:00:39,000 +For example, Microsoft stopped supporting windows XP or Windows 7. + +11 +00:00:39,000 --> 00:00:42,000 +Sonicwall makes a new device and stops supporting this. + +12 +00:00:42,000 --> 00:00:48,000 +The topic we're talking about here is called disposal and decommissioning of hardware and or software. + +13 +00:00:49,000 --> 00:00:54,000 +It's a process in cybersecurity that's it's not just about removing assets from operations, which is + +14 +00:00:54,000 --> 00:00:55,000 +what we're doing. + +15 +00:00:55,000 --> 00:01:00,000 +It's about ensuring that the end of life handling of those assets does not introduce new security risks. + +16 +00:01:00,000 --> 00:01:04,000 +Let me give you a quick, uh, example of a security problem. + +17 +00:01:05,000 --> 00:01:09,000 +This computer is no longer needed in Tia. + +18 +00:01:09,000 --> 00:01:11,000 +Somebody takes the hard drive. + +19 +00:01:11,000 --> 00:01:16,000 +Uh, somebody takes takes the machine off the desk, puts it in the garbage. + +20 +00:01:16,000 --> 00:01:16,000 +Just like that. + +21 +00:01:16,000 --> 00:01:17,000 +They just did that. + +22 +00:01:17,000 --> 00:01:22,000 +The machine is decomposed up, but then a hacker dumpster diving. + +23 +00:01:22,000 --> 00:01:26,000 +This is when they go through your trash, gets the hard drive, take gets the machine, takes out the + +24 +00:01:26,000 --> 00:01:27,000 +hard drive. + +25 +00:01:27,000 --> 00:01:34,000 +And because no one sanitized the drives, all Tia's data, they just got massive security problem. + +26 +00:01:34,000 --> 00:01:36,000 +So what do we need to do about this? + +27 +00:01:36,000 --> 00:01:43,000 +Well, when it comes to the end of life handling, especially when it comes to it, equipment, software, + +28 +00:01:43,000 --> 00:01:48,000 +hardware and software, we must understand this process of sanitization. + +29 +00:01:48,000 --> 00:01:54,000 +This is the process of removing sensitive data from storage device to ensure that it cannot be recovered + +30 +00:01:54,000 --> 00:01:56,000 +by unauthorized individuals. + +31 +00:01:57,000 --> 00:02:00,000 +That's what this is we need to remove. + +32 +00:02:00,000 --> 00:02:05,000 +So we need to take out, for example, the hard drive on that particular machine. + +33 +00:02:05,000 --> 00:02:07,000 +And maybe then we can dispose of the machine. + +34 +00:02:07,000 --> 00:02:12,000 +But the hard drive needs to go through a way to permanently remove the data. + +35 +00:02:12,000 --> 00:02:16,000 +One way of doing this is by shredding your hard drive or melting them. + +36 +00:02:16,000 --> 00:02:18,000 +This is called physical destruction. + +37 +00:02:18,000 --> 00:02:20,000 +This is physically destroying the drive. + +38 +00:02:20,000 --> 00:02:22,000 +Now I do have a slide on this. + +39 +00:02:22,000 --> 00:02:23,000 +I'll come back to this in a minute. + +40 +00:02:23,000 --> 00:02:27,000 +Something that you may want, that you may see on your exam is something called degaussing. + +41 +00:02:27,000 --> 00:02:28,000 +Degaussing works. + +42 +00:02:28,000 --> 00:02:36,000 +It's works on hard disk drives, not SSDs or solid state drives like a USB stick or just an Mdot two + +43 +00:02:36,000 --> 00:02:38,000 +drive or a Sata solid state drive. + +44 +00:02:38,000 --> 00:02:41,000 +I'm talking a good old fashioned hard drive. + +45 +00:02:41,000 --> 00:02:46,000 +And degausser is when they take a powerful magnet and they put it across that hard drive. + +46 +00:02:46,000 --> 00:02:49,000 +What that's going to do is it's going to completely erase the data. + +47 +00:02:49,000 --> 00:02:54,000 +Another thing you can do here is overwrite the drive with new data. + +48 +00:02:54,000 --> 00:02:58,000 +Several times I can't remember the number, but NIST I believe is 7 or 8 times. + +49 +00:02:58,000 --> 00:03:01,000 +Overwrite will make the data unrecoverable. + +50 +00:03:01,000 --> 00:03:02,000 +Now there's something I want to point out. + +51 +00:03:02,000 --> 00:03:07,000 +Generally, when you physically destroy the drive or degauss it, the drive is not reusable. + +52 +00:03:07,000 --> 00:03:13,000 +So if you ever plan to reuse the hard drive in a less sensitive way, then you want to make sure you + +53 +00:03:13,000 --> 00:03:16,000 +overwrite it multiple times. + +54 +00:03:16,000 --> 00:03:19,000 +Sometimes people call this thing purging of the drive. + +55 +00:03:19,000 --> 00:03:21,000 +Uh, degaussing and general physical destruction. + +56 +00:03:21,000 --> 00:03:23,000 +The drive is not usable. + +57 +00:03:23,000 --> 00:03:26,000 +Now, sanitization is critical for data breaches. + +58 +00:03:26,000 --> 00:03:28,000 +Preventing data breaches. + +59 +00:03:28,000 --> 00:03:32,000 +The reason is because if you just take a hard drive, you leave the machine, the hard drive in there, + +60 +00:03:32,000 --> 00:03:36,000 +and you throw a machine out, people will probably pick up the machine. + +61 +00:03:36,000 --> 00:03:41,000 +And before you know it, your data is gone and you have to comply with certain regulations. + +62 +00:03:41,000 --> 00:03:47,000 +In fact, things like HIPAA regulations, PCI compliance, when you're throwing those drives out those + +63 +00:03:47,000 --> 00:03:54,000 +regulations, you have to dispose of the media in a certain way, such as shredding the drives or degaussing + +64 +00:03:54,000 --> 00:03:57,000 +the actual hard drives themselves. + +65 +00:03:57,000 --> 00:03:58,000 +What's the challenges here? + +66 +00:03:58,000 --> 00:04:04,000 +Well, it's ensuring that the chosen sanitation method is appropriate for the type of storage that we + +67 +00:04:04,000 --> 00:04:05,000 +are doing. + +68 +00:04:05,000 --> 00:04:09,000 +Now, I want to talk quickly here about destruction. + +69 +00:04:09,000 --> 00:04:14,000 +This is physical dismantling or destruction of hardware. + +70 +00:04:14,000 --> 00:04:16,000 +That's what this is that cannot be used. + +71 +00:04:16,000 --> 00:04:22,000 +Again, remember, if you take a drive and you shred the hard drive, guys, there's no way that drive + +72 +00:04:22,000 --> 00:04:23,000 +will ever come back. + +73 +00:04:24,000 --> 00:04:28,000 +Uh, it is often used in storage devices cannot be readily sanitized. + +74 +00:04:28,000 --> 00:04:34,000 +Now, I want to just point out something before I move on here, is that degaussing will not work for + +75 +00:04:34,000 --> 00:04:39,000 +a solid state drive, because it's a big magnet and put the magnet over solid state since it's not magnetic, + +76 +00:04:39,000 --> 00:04:41,000 +doesn't do anything to it. + +77 +00:04:41,000 --> 00:04:43,000 +But when you physically destroy it, such a shredded. + +78 +00:04:44,000 --> 00:04:45,000 +Uh. + +79 +00:04:45,000 --> 00:04:46,000 +You will. + +80 +00:04:46,000 --> 00:04:48,000 +Definitely doesn't matter what the drive is. + +81 +00:04:48,000 --> 00:04:54,000 +USB stick, CDs, DVDs, uh, physical hard drives, solid state drive. + +82 +00:04:54,000 --> 00:04:54,000 +Doesn't matter. + +83 +00:04:55,000 --> 00:04:59,000 +This is a definite way to ensure data cannot be recovered. + +84 +00:04:59,000 --> 00:05:00,000 +Cannot be recovered. + +85 +00:05:00,000 --> 00:05:05,000 +The challenge is there is this must be carried out in a way that is environmentally responsible. + +86 +00:05:05,000 --> 00:05:10,000 +Now, I want you guys to keep in mind that more than likely you're not going to do this. + +87 +00:05:10,000 --> 00:05:12,000 +You're probably going to hire a company to do this. + +88 +00:05:13,000 --> 00:05:17,000 +Disposing of media is generally done by a third party organization. + +89 +00:05:17,000 --> 00:05:21,000 +You give them the media and they will destroy it for you. + +90 +00:05:21,000 --> 00:05:24,000 +What do you get back when when you hire them? + +91 +00:05:24,000 --> 00:05:30,000 +This thing, a certification in context of disposal as the documentation that the process confirmed + +92 +00:05:30,000 --> 00:05:32,000 +a proper sanitization. + +93 +00:05:32,000 --> 00:05:36,000 +It serves as proof that your organization has been has done this responsible. + +94 +00:05:36,000 --> 00:05:37,000 +Here's why. + +95 +00:05:37,000 --> 00:05:45,000 +Certain laws like HIPAA compliance, PCI compliance will make it mandatory that you dispose of the media + +96 +00:05:45,000 --> 00:05:46,000 +in a certain way. + +97 +00:05:47,000 --> 00:05:52,000 +When the hippo auditors come and they say, well, how did you dispose of those drives? + +98 +00:05:52,000 --> 00:05:53,000 +You're going to say, well, I shred it. + +99 +00:05:53,000 --> 00:05:55,000 +You have proof that you shred it. + +100 +00:05:55,000 --> 00:05:58,000 +Well, here is a certification. + +101 +00:05:58,000 --> 00:06:04,000 +Here's a document from, uh, Iron Mountain that they shredded the data for me. + +102 +00:06:04,000 --> 00:06:04,000 +Right. + +103 +00:06:04,000 --> 00:06:05,000 +They shredded the drive for me. + +104 +00:06:05,000 --> 00:06:07,000 +And the auditor looks and checks the box. + +105 +00:06:07,000 --> 00:06:07,000 +Okay. + +106 +00:06:07,000 --> 00:06:08,000 +Yeah, they did it right. + +107 +00:06:08,000 --> 00:06:08,000 +Here's the. + +108 +00:06:09,000 --> 00:06:10,000 +That's why this is important. + +109 +00:06:10,000 --> 00:06:16,000 +This helps in demonstrating compliance with legal and regulatory, uh, uh, laws that you have to follow. + +110 +00:06:17,000 --> 00:06:21,000 +Now, one thing I do want to mention is data retention. + +111 +00:06:23,000 --> 00:06:29,000 +Before we get into shredding all of these things, we have to understand that by law, retaining certain + +112 +00:06:29,000 --> 00:06:33,000 +data for specific periods of time is mandatory. + +113 +00:06:34,000 --> 00:06:39,000 +I believe in the United States colleges, if you're a college, you have to maintain for 80 years. + +114 +00:06:39,000 --> 00:06:42,000 +I think trade schools in New York is 20 years. + +115 +00:06:42,000 --> 00:06:44,000 +Uh, the IRS says 7 or 8 years. + +116 +00:06:44,000 --> 00:06:49,000 +I believe you have to maintain tax records for, um, they're required by law. + +117 +00:06:49,000 --> 00:06:54,000 +Certain, even organizational policies may want to keep things for a certain amount of time. + +118 +00:06:54,000 --> 00:07:00,000 +Now, it's important to balance data retention with the need to eliminate unnecessary data. + +119 +00:07:00,000 --> 00:07:03,000 +You can't just keep retaining data for long periods of time. + +120 +00:07:03,000 --> 00:07:07,000 +Retaining data takes up storage costs, money and security. + +121 +00:07:07,000 --> 00:07:08,000 +Of doing this. + +122 +00:07:08,000 --> 00:07:11,000 +Retaining data must be protected against it's classification. + +123 +00:07:11,000 --> 00:07:13,000 +So the more you have, the more you got to protect. + +124 +00:07:14,000 --> 00:07:16,000 +But you have to be careful with this. + +125 +00:07:16,000 --> 00:07:18,000 +You just can't go and delete data. + +126 +00:07:18,000 --> 00:07:18,000 +Oh, we don't need any more. + +127 +00:07:18,000 --> 00:07:19,000 +Just delete it. + +128 +00:07:19,000 --> 00:07:19,000 +No. + +129 +00:07:19,000 --> 00:07:23,000 +Check with the compliance department to see what laws are following. + +130 +00:07:23,000 --> 00:07:27,000 +Maybe PCI has specific laws of how long you have to keep that. + +131 +00:07:27,000 --> 00:07:31,000 +And so this HIPAA regulations for example medical records. + +132 +00:07:32,000 --> 00:07:36,000 +When it comes to data disposal, it is super important that you just don't take data and just throw + +133 +00:07:36,000 --> 00:07:37,000 +it out. + +134 +00:07:37,000 --> 00:07:38,000 +Media. + +135 +00:07:38,000 --> 00:07:40,000 +I mean, you don't take media and just throw it out. + +136 +00:07:40,000 --> 00:07:42,000 +You have to dig out that media. + +137 +00:07:42,000 --> 00:07:46,000 +You have to sanitize that media correctly before throwing it out. + +138 +00:07:46,000 --> 00:07:51,000 +And if you do, the best way to do it is not by you doing it as an IT professional or security. + +139 +00:07:51,000 --> 00:07:57,000 +The best way to do this is to hire a third party company, and there are many who will come to your + +140 +00:07:57,000 --> 00:07:59,000 +organization and shred your media. + +141 +00:07:59,000 --> 00:08:04,000 +When they're done, they're going to give you a certification that they have done it that is recognized + +142 +00:08:04,000 --> 00:08:10,000 +by many authorities, especially government regulators and auditors, to show that you did it correctly. + +143 +00:08:10,000 --> 00:08:15,000 +But before disposing of media, make sure you keep an eye on when is it okay to dispose of it. + +144 +00:08:15,000 --> 00:08:17,000 +You know, when do we have to get rid of this data? + +145 +00:08:17,000 --> 00:08:26,000 +Because tons of regulations does have, um, particular policies that says you have to retain the data + +146 +00:08:26,000 --> 00:08:30,000 +for a certain amount of time, but after that time is up, you can go ahead and get rid of it and you + +147 +00:08:30,000 --> 00:08:32,000 +have to sanitize the media. + +148 +00:08:32,000 --> 00:08:35,000 +So keep that in mind the next time you just throw away a hard drive. + diff --git a/14 - Hardware, software and Data Asset Management/005 Quick Quiz.html b/14 - Hardware, software and Data Asset Management/005 Quick Quiz.html new file mode 100644 index 0000000000000000000000000000000000000000..35a5bc18bb4e8112f160ce81e18df8e3d893d5e3 --- /dev/null +++ b/14 - Hardware, software and Data Asset Management/005 Quick Quiz.html @@ -0,0 +1,479 @@ + + + + + + + Quiz + + + + +
+
+

+

+
+
+
+ Score: 999 of + 999% +
+
Correct: 999
+
Incorrect: 999
+
+ +
+ + + + +
+ + + + diff --git a/15 - Vulnerability Management/001 Vulnerability Scan OB 4.3_en.srt b/15 - Vulnerability Management/001 Vulnerability Scan OB 4.3_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..84a5eb817e380b1b00937602a79a45617c74fb96 --- /dev/null +++ b/15 - Vulnerability Management/001 Vulnerability Scan OB 4.3_en.srt @@ -0,0 +1,200 @@ +1 +00:00:00,000 --> 00:00:03,000 +One of the most basic things you're going to be doing when you work in it. + +2 +00:00:03,000 --> 00:00:06,000 +Security is scanning your system. + +3 +00:00:06,000 --> 00:00:14,000 +You're going to have to scan all the devices, all your different desktops, laptops, windows and servers + +4 +00:00:14,000 --> 00:00:19,000 +and all this different software you have in your organization for known vulnerabilities. + +5 +00:00:19,000 --> 00:00:20,000 +Now for your exam. + +6 +00:00:20,000 --> 00:00:24,000 +I'm not going to spend a lot of time on this because you just really need to know what it is for your + +7 +00:00:24,000 --> 00:00:24,000 +exam. + +8 +00:00:24,000 --> 00:00:29,000 +Although this is a whole course by itself, let's just go through this pretty quickly. + +9 +00:00:29,000 --> 00:00:31,000 +And again, I could spend a lot of time on this. + +10 +00:00:31,000 --> 00:00:37,000 +If you know me personally, I teach a lot of white Hat hacking or Certified Ethical Hacker, and we + +11 +00:00:37,000 --> 00:00:38,000 +do this quite a lot. + +12 +00:00:38,000 --> 00:00:40,000 +So what is a vulnerability scan? + +13 +00:00:40,000 --> 00:00:46,000 +Well, a vulnerability scan is an automated it's an automated tool to scan systems, network and application + +14 +00:00:46,000 --> 00:00:53,000 +to identify known vulnerabilities such as unpatched software misconfiguration and security weakness. + +15 +00:00:53,000 --> 00:01:00,000 +The usage with regular scans help maintain an up to date understanding of security posture in your organization. + +16 +00:01:00,000 --> 00:01:01,000 +It's the first step in vulnerability. + +17 +00:01:01,000 --> 00:01:03,000 +Now, I'm going to tell you guys a couple of things here. + +18 +00:01:04,000 --> 00:01:11,000 +When it comes to vulnerability scans, one of the best scanner that I use is the Nexus security scanner. + +19 +00:01:11,000 --> 00:01:12,000 +You can look this up. + +20 +00:01:12,000 --> 00:01:13,000 +Just Google Nexus security scanner. + +21 +00:01:13,000 --> 00:01:16,000 +I'm not sure if they still have that free version. + +22 +00:01:16,000 --> 00:01:19,000 +These have a free version of it for smaller networks. + +23 +00:01:19,000 --> 00:01:24,000 +Now, what this thing is going to do is you install it, it scans all the computers in your network. + +24 +00:01:24,000 --> 00:01:27,000 +And then what it does is that it says that machine needs patches. + +25 +00:01:27,000 --> 00:01:31,000 +That machine has a blank administrator password. + +26 +00:01:31,000 --> 00:01:35,000 +What it's doing is that it's identifying vulnerabilities on your network. + +27 +00:01:35,000 --> 00:01:40,000 +It's identifying computers that are just not patched or misconfigured. + +28 +00:01:40,000 --> 00:01:49,000 +This is important to have because it is, in my opinion, impossible for you to go around to 2300 computers + +29 +00:01:49,000 --> 00:01:57,000 +and scan and scan it individually and or figure it out yourself if they're up to date or not, if they're + +30 +00:01:57,000 --> 00:01:59,000 +missing certain configuration. + +31 +00:01:59,000 --> 00:02:04,000 +You see these vulnerability scanners have a giant database of vulnerabilities that they're looking for, + +32 +00:02:05,000 --> 00:02:11,000 +and their databases is continuously updated with the latest vulnerabilities for whatever hardware and + +33 +00:02:11,000 --> 00:02:14,000 +or software application that they're checking. + +34 +00:02:14,000 --> 00:02:17,000 +So it's important to get a good vulnerability scanner. + +35 +00:02:17,000 --> 00:02:20,000 +Now I like the Nexus security scanner. + +36 +00:02:20,000 --> 00:02:22,000 +It's my favorite scanner to use. + +37 +00:02:22,000 --> 00:02:24,000 +There are tons of other scanners out there. + +38 +00:02:24,000 --> 00:02:27,000 +I remember Microsoft had the Microsoft Security Baseline Analyzer. + +39 +00:02:27,000 --> 00:02:29,000 +That one I thought was pretty good too. + +40 +00:02:29,000 --> 00:02:34,000 +So if you guys want to try this, you guys can go and download the Nexus security scanner. + +41 +00:02:34,000 --> 00:02:35,000 +Just give it a go in your own network. + +42 +00:02:35,000 --> 00:02:42,000 +But when it comes to your exam, I just want you guys to understand that a vulnerability scan is generally + +43 +00:02:42,000 --> 00:02:50,000 +an automated tool that scans all your systems, network gears and devices and application for vulnerabilities + +44 +00:02:50,000 --> 00:02:51,000 +on them. + +45 +00:02:51,000 --> 00:02:56,000 +It will then give you a nice report that says, here are some systems with vulnerabilities and what + +46 +00:02:56,000 --> 00:02:58,000 +they have, and these are things that you should do to fix it. + +47 +00:02:59,000 --> 00:03:02,000 +If you manage an IT security vulnerability. + +48 +00:03:02,000 --> 00:03:04,000 +Scanning is Basic Security 101. + +49 +00:03:04,000 --> 00:03:08,000 +So I highly recommend for you guys to download one of those and try it that way. + +50 +00:03:08,000 --> 00:03:13,000 +You're familiar with it because when you start working you will definitely be doing this. + diff --git a/15 - Vulnerability Management/002 Application Security Testing OB 4.3_en.srt b/15 - Vulnerability Management/002 Application Security Testing OB 4.3_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..d19c14afa216ce56c03fa9b5a936a2dee1b2f8dc --- /dev/null +++ b/15 - Vulnerability Management/002 Application Security Testing OB 4.3_en.srt @@ -0,0 +1,144 @@ +1 +00:00:00,000 --> 00:00:06,000 +When applications are finished coding or programmers has finished coding an application, it is super + +2 +00:00:06,000 --> 00:00:08,000 +important that we test the application. + +3 +00:00:08,000 --> 00:00:14,000 +So in this video, let's take a look at three kinds of tests that application developers should be doing. + +4 +00:00:14,000 --> 00:00:18,000 +NSA Security Administrator you should be familiar with the these tests has to get done. + +5 +00:00:18,000 --> 00:00:25,000 +The first one up we'll talk about is called a static application, a static application security tests, + +6 +00:00:25,000 --> 00:00:27,000 +also known as static analysis. + +7 +00:00:27,000 --> 00:00:33,000 +This is known as dynamic application security testing or dynamic analysis and package monitoring. + +8 +00:00:33,000 --> 00:00:34,000 +So let's get started. + +9 +00:00:34,000 --> 00:00:37,000 +The first thing I will talk about is static analysis. + +10 +00:00:37,000 --> 00:00:42,000 +Now this involves examining application code to detect security flaws. + +11 +00:00:42,000 --> 00:00:46,000 +It doesn't execute the code, it just reads the code code by code. + +12 +00:00:46,000 --> 00:00:51,000 +Now I want to just point out that this is generally a piece of software that does this for you. + +13 +00:00:51,000 --> 00:00:57,000 +It's not something that you do by looking at code line by line static application. + +14 +00:00:57,000 --> 00:01:03,000 +Uh, testing is a review of the source code looking for common vulnerabilities that are in codes. + +15 +00:01:03,000 --> 00:01:08,000 +So it's useful for finding things like code injection, buffer overflows and other vulnerabilities. + +16 +00:01:08,000 --> 00:01:10,000 +That is usually in the code itself. + +17 +00:01:10,000 --> 00:01:13,000 +The other one is called dynamic testing. + +18 +00:01:13,000 --> 00:01:18,000 +Now dynamic testing is testing the application in runtime to identify any security issues that only + +19 +00:01:18,000 --> 00:01:20,000 +appear during execution. + +20 +00:01:20,000 --> 00:01:25,000 +This helps identify runtime errors like memory leaks, static analysis if you're doing things like injection + +21 +00:01:25,000 --> 00:01:30,000 +attacks, and so on, that's going to fall into this one of dynamic application security testing. + +22 +00:01:30,000 --> 00:01:35,000 +The last thing here we have is something we call, uh, package monitoring. + +23 +00:01:35,000 --> 00:01:41,000 +This is monitoring the software libraries and package use an application for known vulnerabilities. + +24 +00:01:41,000 --> 00:01:47,000 +This keeps what what you want to do is it involves keeping track of updates and patches for third party + +25 +00:01:47,000 --> 00:01:48,000 +components. + +26 +00:01:48,000 --> 00:01:53,000 +You see, package monitoring applications comes with a variety of different packages that are out there. + +27 +00:01:53,000 --> 00:01:58,000 +All kinds of add ons to basically the software package monitoring is checking to make sure that the + +28 +00:01:58,000 --> 00:02:03,000 +the packages that we do have for those applications don't have vulnerabilities in them. + +29 +00:02:04,000 --> 00:02:10,000 +Okay, static analysis and dynamic analysis is probably the two most common application security testing + +30 +00:02:10,000 --> 00:02:12,000 +that you need to be familiar with for your exam. + +31 +00:02:12,000 --> 00:02:14,000 +Remember static analysis. + +32 +00:02:14,000 --> 00:02:17,000 +We've used the code line by line, generally done by a piece of software. + +33 +00:02:17,000 --> 00:02:23,000 +Versus dynamic analysis is when they're going to run the code, basically run the application itself + +34 +00:02:23,000 --> 00:02:26,000 +and then analyze it while it's running. + +35 +00:02:26,000 --> 00:02:27,000 +Keep that in mind. + +36 +00:02:27,000 --> 00:02:28,000 +Taking your tests. + diff --git a/15 - Vulnerability Management/003 Threat Feeds OB 4.3_en.srt b/15 - Vulnerability Management/003 Threat Feeds OB 4.3_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..30c805f6838e7ca7058e4c800deedfa14b89db31 --- /dev/null +++ b/15 - Vulnerability Management/003 Threat Feeds OB 4.3_en.srt @@ -0,0 +1,300 @@ +1 +00:00:00,000 --> 00:00:06,000 +A good security administrator is going to be able to detect threats about their particular business + +2 +00:00:06,000 --> 00:00:07,000 +before it even appears. + +3 +00:00:07,000 --> 00:00:12,000 +This person is going to be able to do research on its company and to see what's out there on its own + +4 +00:00:12,000 --> 00:00:13,000 +business. + +5 +00:00:13,000 --> 00:00:17,000 +Now, in order to do this, you're going to have to gather a lot of information. + +6 +00:00:17,000 --> 00:00:20,000 +And that brings me to this particular video. + +7 +00:00:20,000 --> 00:00:22,000 +We're going to be talking about threat feeds. + +8 +00:00:22,000 --> 00:00:27,000 +This is going to be how do we find information basically gathering information on different threats + +9 +00:00:27,000 --> 00:00:29,000 +to our organization. + +10 +00:00:29,000 --> 00:00:30,000 +Let's get started with this. + +11 +00:00:30,000 --> 00:00:35,000 +So the first thing we're going to be talking about is what's called Osint or open source intelligence. + +12 +00:00:35,000 --> 00:00:40,000 +This is about gathering data, all kinds of data, whether it's data about your business, your domain + +13 +00:00:40,000 --> 00:00:47,000 +name about other people, potential threats that are out there from publicly available sources to identify + +14 +00:00:47,000 --> 00:00:49,000 +emerging threats and vulnerability. + +15 +00:00:49,000 --> 00:00:55,000 +Now Osint, there is a framework that we can use for this and a really good website that we can use + +16 +00:00:55,000 --> 00:00:58,000 +that will help us find information on a wide variety of things. + +17 +00:00:58,000 --> 00:01:02,000 +And let's go to that website as I've already opened it. + +18 +00:01:02,000 --> 00:01:04,000 +Let's see what it looks like. + +19 +00:01:04,000 --> 00:01:08,000 +So if you use the link in this slide and you go here, this is what it looks like. + +20 +00:01:08,000 --> 00:01:15,000 +This here is going to allow me to find tons of information, whether it's trying to find email addresses + +21 +00:01:15,000 --> 00:01:21,000 +about a certain person, IP addresses, uh, just to make make this video generic. + +22 +00:01:21,000 --> 00:01:23,000 +You don't want to search for anything that'll put us in trouble. + +23 +00:01:23,000 --> 00:01:29,000 +I'm just going to go and get company general information on, uh, Technical School of America. + +24 +00:01:29,000 --> 00:01:32,000 +So let's just use this like as this link here, general information. + +25 +00:01:32,000 --> 00:01:38,000 +And we'll do a corporation wiki just to see what we find and notice how it takes out a website. + +26 +00:01:38,000 --> 00:01:40,000 +So we're going to search for technical. + +27 +00:01:40,000 --> 00:01:41,000 +So. + +28 +00:01:45,000 --> 00:01:46,000 +Let's search for my company. + +29 +00:01:46,000 --> 00:01:50,000 +And notice that it found Technical School of America. + +30 +00:01:50,000 --> 00:01:51,000 +It's owned by me. + +31 +00:01:51,000 --> 00:01:54,000 +And so they misspelled my name uh on their. + +32 +00:01:55,000 --> 00:02:01,000 +And basically it's going to give you information on the corporation itself when we were founded. + +33 +00:02:01,000 --> 00:02:04,000 +We are a corporation in New York City from 2009. + +34 +00:02:04,000 --> 00:02:06,000 +We're 14 years old. + +35 +00:02:06,000 --> 00:02:10,000 +I doesn't have a ton of information on us, but it will help you to find information. + +36 +00:02:10,000 --> 00:02:15,000 +And this is this begins your hunt for actual data itself. + +37 +00:02:15,000 --> 00:02:17,000 +So I think that's a pretty cool framework. + +38 +00:02:17,000 --> 00:02:19,000 +You guys can I don't want to go too much into it. + +39 +00:02:19,000 --> 00:02:20,000 +It's really outside the scope of this. + +40 +00:02:20,000 --> 00:02:25,000 +But if you're taking my ethical hacking course, we use that website quite a lot so you guys can have + +41 +00:02:25,000 --> 00:02:28,000 +some fun looking at the old Saint framework. + +42 +00:02:29,000 --> 00:02:33,000 +Uh, going back here to this here, uh, proprietary third party. + +43 +00:02:33,000 --> 00:02:40,000 +So subscribing to specialized services that provide information on the latest threats and vulnerabilities. + +44 +00:02:40,000 --> 00:02:42,000 +This offers more tailored, more real time information. + +45 +00:02:42,000 --> 00:02:48,000 +So if your organization is subscribed to a certain threat feeds and you can get this from providers, + +46 +00:02:48,000 --> 00:02:54,000 +makers of different kinds of firewall or security software, this would really help you to find vulnerabilities + +47 +00:02:54,000 --> 00:02:57,000 +more specific to your organization. + +48 +00:02:57,000 --> 00:02:59,000 +Information sharing organization. + +49 +00:02:59,000 --> 00:03:03,000 +There is an organization such as information sharing and analysis centers. + +50 +00:03:03,000 --> 00:03:07,000 +These are groups that share information on different vulnerabilities, such as. + +51 +00:03:07,000 --> 00:03:12,000 +If I had a vulnerability in my organization, let me share that information with you. + +52 +00:03:13,000 --> 00:03:18,000 +This facilitates collaboration with with security folks like yourself. + +53 +00:03:18,000 --> 00:03:22,000 +Now, the other one that I don't recommend looking at is going to be the dark web. + +54 +00:03:22,000 --> 00:03:25,000 +Now, this is not a course on the dark web, but just really quick. + +55 +00:03:25,000 --> 00:03:30,000 +The dark web is basically a set of servers that are not indexed. + +56 +00:03:30,000 --> 00:03:33,000 +In other words, you're not going to find what's on the dark web on Google Index. + +57 +00:03:33,000 --> 00:03:35,000 +A Google doesn't index these particular servers. + +58 +00:03:35,000 --> 00:03:41,000 +Sometimes getting to them is difficult because sometimes you have to use an IP address or some very + +59 +00:03:41,000 --> 00:03:42,000 +weird domain name. + +60 +00:03:42,000 --> 00:03:47,000 +Now, monitoring the dark web forums and marketplace to gather intelligence on new vulnerabilities. + +61 +00:03:47,000 --> 00:03:48,000 +Exploit a threat. + +62 +00:03:48,000 --> 00:03:50,000 +Actors is a good way to do this. + +63 +00:03:50,000 --> 00:03:56,000 +When I teach ethical hacking courses like Certified Ethical Hacker, I do show them how to use the dark + +64 +00:03:56,000 --> 00:03:59,000 +web in order to monitor forms. + +65 +00:03:59,000 --> 00:04:03,000 +A lot of the attacks that are going to be coming out towards your organization, especially like different + +66 +00:04:03,000 --> 00:04:05,000 +forms of crypto. + +67 +00:04:06,000 --> 00:04:09,000 +Crypto malware and all that type of stuff. + +68 +00:04:09,000 --> 00:04:12,000 +Uh, things that are going on, ransomware, I should say, that are coming out. + +69 +00:04:12,000 --> 00:04:16,000 +These kinds of software originates on the dark web and is shared on there. + +70 +00:04:16,000 --> 00:04:23,000 +So if you play on the dark web and you go to these forums, you'll be better able to see what things + +71 +00:04:23,000 --> 00:04:24,000 +could affect your business. + +72 +00:04:24,000 --> 00:04:29,000 +A good security administrator once again will know the different threats that are affecting the that + +73 +00:04:29,000 --> 00:04:34,000 +are that could be affecting their business or affect their business in the future. + +74 +00:04:34,000 --> 00:04:37,000 +The best thing we can do is learn about the threats before they come. + +75 +00:04:37,000 --> 00:04:42,000 +That way we can protect ourselves from that threat before they even show up. + diff --git a/15 - Vulnerability Management/004 Penetration Testing OB 4.3_en.srt b/15 - Vulnerability Management/004 Penetration Testing OB 4.3_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..3ea02a43ab4335964750c5265c31d2ba949add17 --- /dev/null +++ b/15 - Vulnerability Management/004 Penetration Testing OB 4.3_en.srt @@ -0,0 +1,1024 @@ +1 +00:00:00,000 --> 00:00:05,000 +I spent many years of my career being a pen tester and I like teaching pen testing. + +2 +00:00:05,000 --> 00:00:09,000 +So in this video I'm going to talk about my most favorite topic, pen testing. + +3 +00:00:09,000 --> 00:00:14,000 +I'm going to try to keep it short just to your exam, but it's still going to be pretty long because + +4 +00:00:14,000 --> 00:00:18,000 +in this video I'm going to cover everything you need to know about pen testing. + +5 +00:00:18,000 --> 00:00:26,000 +I'll start out this by saying this you never really understand how good your network actually is until + +6 +00:00:26,000 --> 00:00:27,000 +somebody tries to hack it. + +7 +00:00:28,000 --> 00:00:33,000 +You really don't know how good your controls work until you actually test it. + +8 +00:00:33,000 --> 00:00:38,000 +You don't know how much weight you can actually lift until you actually try to pick up the weight, + +9 +00:00:38,000 --> 00:00:38,000 +right? + +10 +00:00:39,000 --> 00:00:40,000 +So. + +11 +00:00:41,000 --> 00:00:47,000 +This topic of pen testing will answer the question of how secure are we really? + +12 +00:00:47,000 --> 00:00:50,000 +Are those controls actually working? + +13 +00:00:50,000 --> 00:00:55,000 +You don't really know if a car can hit 200 miles an hour, unless you actually try to make it hit 200 + +14 +00:00:55,000 --> 00:00:56,000 +miles an hour. + +15 +00:00:56,000 --> 00:01:01,000 +You don't know if your server can actually protect against a certain attack until you attack it. + +16 +00:01:01,000 --> 00:01:06,000 +Pen testing is the ultimate security test. + +17 +00:01:06,000 --> 00:01:12,000 +Pen testing is when you hire folks, generally from outside your organization to hack your business. + +18 +00:01:12,000 --> 00:01:16,000 +Now they're not going to hack it to destroy it, but they're going to hack it to test the controls. + +19 +00:01:16,000 --> 00:01:22,000 +They're basically going to hack your network the way a real hacker would do it. + +20 +00:01:22,000 --> 00:01:28,000 +Now, pen testing is a practice of testing a computer system network, a web application to find vulnerabilities + +21 +00:01:28,000 --> 00:01:31,000 +that an attacker could exploit during pen testing. + +22 +00:01:31,000 --> 00:01:33,000 +They might even exploit it for you. + +23 +00:01:33,000 --> 00:01:37,000 +This is generally done using manual or all types of automated technology. + +24 +00:01:38,000 --> 00:01:43,000 +This this course doesn't cover all the tools that we use in pen testing, but whether we're using an + +25 +00:01:43,000 --> 00:01:50,000 +nmap scanner, some kind of automated vulnerability scanner, it could get very technical when you do + +26 +00:01:50,000 --> 00:01:51,000 +it. + +27 +00:01:51,000 --> 00:01:56,000 +The goal of this thing here is to determine the feasibility of a particular set of attack vectors. + +28 +00:01:56,000 --> 00:01:59,000 +Like what attack vectors can they use against you? + +29 +00:01:59,000 --> 00:02:05,000 +Identify high risk vulnerabilities from a combination of lower risk vulnerabilities exploited. + +30 +00:02:05,000 --> 00:02:11,000 +So people think, well, I can't lose all this data, but a combination of small holes you have in your + +31 +00:02:11,000 --> 00:02:13,000 +network could lead to big data loss. + +32 +00:02:13,000 --> 00:02:19,000 +Identify vulnerabilities may be difficult or impossible to detect with automated network or application + +33 +00:02:19,000 --> 00:02:21,000 +vulnerability scanners. + +34 +00:02:21,000 --> 00:02:26,000 +You know, one thing I want to point out is that if you use a vulnerability scanner like the Nexus security + +35 +00:02:26,000 --> 00:02:33,000 +scanner, it doesn't replace a pen test that'll just be able to find vulnerabilities, but it's not + +36 +00:02:33,000 --> 00:02:35,000 +going to find every vulnerability that is out there. + +37 +00:02:35,000 --> 00:02:39,000 +Assess the magnitude of potential business and operational impacts. + +38 +00:02:39,000 --> 00:02:41,000 +What happens if there is a successful attack? + +39 +00:02:41,000 --> 00:02:43,000 +How does it impact the business? + +40 +00:02:43,000 --> 00:02:48,000 +This will tell you that testability of the different network defenders to detect and respond. + +41 +00:02:48,000 --> 00:02:53,000 +Sometimes pen tests aren't even told to the people in the network and department. + +42 +00:02:53,000 --> 00:02:56,000 +They think they're being attacked and they start to respond to it. + +43 +00:02:57,000 --> 00:03:01,000 +Provide evidence to support increased investment in security personnel and technology. + +44 +00:03:01,000 --> 00:03:05,000 +I like this one because, you know, if there's one thing management doesn't like about us, IT folks, + +45 +00:03:05,000 --> 00:03:09,000 +is we spend a lot of money and they always ask us to justify it. + +46 +00:03:09,000 --> 00:03:15,000 +But when you do a pen test and you could show that this network is incredibly vulnerable, they're probably + +47 +00:03:15,000 --> 00:03:17,000 +going to up their budget on you. + +48 +00:03:17,000 --> 00:03:20,000 +Now, this is the part of the exam that you really want to know. + +49 +00:03:20,000 --> 00:03:22,000 +There are three pen tests. + +50 +00:03:22,000 --> 00:03:24,000 +There's black box, gray box and white box. + +51 +00:03:24,000 --> 00:03:27,000 +A black box test is known as a zero knowledge test. + +52 +00:03:27,000 --> 00:03:29,000 +This is known as a closed test. + +53 +00:03:29,000 --> 00:03:32,000 +In other words, they zero knowledge. + +54 +00:03:32,000 --> 00:03:37,000 +In other words, whoever is doing the pen test has no knowledge about your network. + +55 +00:03:37,000 --> 00:03:43,000 +This is usually an external test done by a third party organization that you hire. + +56 +00:03:43,000 --> 00:03:46,000 +Basically, you're going to call them up and say, hey man, can you do this test for me? + +57 +00:03:46,000 --> 00:03:51,000 +They're going to stay in their location and they're going to hack you the same way an external hacker + +58 +00:03:51,000 --> 00:03:52,000 +would hack your network. + +59 +00:03:52,000 --> 00:03:57,000 +Now, this is from the outsider hackers perspective. + +60 +00:03:57,000 --> 00:03:59,000 +I'm going to go down here to white box. + +61 +00:03:59,000 --> 00:04:03,000 +Now white box is full knowledge test. + +62 +00:04:03,000 --> 00:04:10,000 +Now they in this kind of test the network administrators they will tell you if you're a pen tester all + +63 +00:04:10,000 --> 00:04:15,000 +the information about the network from the network schematics such as IP addresses, locations of devices, + +64 +00:04:15,000 --> 00:04:20,000 +different kinds of security protocols have implemented as much documentation as possible. + +65 +00:04:20,000 --> 00:04:25,000 +They're going to give you it's called open or crystal test because you can see everything this is done + +66 +00:04:25,000 --> 00:04:28,000 +from an administrator perspective. + +67 +00:04:28,000 --> 00:04:28,000 +All right. + +68 +00:04:28,000 --> 00:04:30,000 +This is done from an administrator perspective. + +69 +00:04:30,000 --> 00:04:35,000 +Now white box testing from my experience has always been something very specific. + +70 +00:04:35,000 --> 00:04:39,000 +You're not testing a whole network, which you might be testing a very specific thing such as a particular + +71 +00:04:39,000 --> 00:04:41,000 +application gray box testing. + +72 +00:04:41,000 --> 00:04:46,000 +Well, as you can imagine, if this is white, this is black, this is gray, this is limited. + +73 +00:04:46,000 --> 00:04:47,000 +Information is provided. + +74 +00:04:47,000 --> 00:04:48,000 +Not a lot. + +75 +00:04:48,000 --> 00:04:50,000 +Maybe IP addresses and domain names. + +76 +00:04:51,000 --> 00:04:56,000 +Uh, generally it is from an insider's perspective on the test. + +77 +00:04:57,000 --> 00:05:02,000 +Now when it comes to pen testing, I want all of you guys to be in the white hat hacker. + +78 +00:05:02,000 --> 00:05:03,000 +This is an ethical hacker. + +79 +00:05:03,000 --> 00:05:07,000 +This is when you test, with permission, black hat hackers. + +80 +00:05:07,000 --> 00:05:08,000 +Unethical. + +81 +00:05:08,000 --> 00:05:10,000 +But this one is testing without authorization. + +82 +00:05:10,000 --> 00:05:14,000 +This one is basically what we would call a hacker gray hat. + +83 +00:05:14,000 --> 00:05:19,000 +You know, there are some really good, uh, pen testers out there who in the day? + +84 +00:05:19,000 --> 00:05:20,000 +They're good guys. + +85 +00:05:20,000 --> 00:05:22,000 +And in the night, they turn to bad guys. + +86 +00:05:22,000 --> 00:05:25,000 +They start doing bad things because they already have the knowledge. + +87 +00:05:25,000 --> 00:05:26,000 +That's a gray hat. + +88 +00:05:26,000 --> 00:05:28,000 +Script, kiddies is more of an insultive worm. + +89 +00:05:28,000 --> 00:05:33,000 +Script kiddies are folks that don't have technical skill now. + +90 +00:05:34,000 --> 00:05:40,000 +If you want to be a pen tester, I tell all my students there are a few things you need to know. + +91 +00:05:40,000 --> 00:05:44,000 +All right, obviously you need to have a great networking background. + +92 +00:05:45,000 --> 00:05:51,000 +But when it comes to pen testing, you need to know Bash and Python. + +93 +00:05:51,000 --> 00:05:54,000 +Those are the two things that you should be very familiar with. + +94 +00:05:54,000 --> 00:05:58,000 +You don't need to be a programmer, but you do need to understand them. + +95 +00:05:58,000 --> 00:06:01,000 +Be able to read them and be able to somewhat write them. + +96 +00:06:01,000 --> 00:06:06,000 +You don't need to be a super expert, but if you're a kind of person that doesn't know any kind of scripting + +97 +00:06:06,000 --> 00:06:11,000 +and you just execute other people's script, your script kiddie, they have little to no skill. + +98 +00:06:11,000 --> 00:06:14,000 +They may not understand full networking. + +99 +00:06:14,000 --> 00:06:17,000 +They don't write their own codes or program or even edit it. + +100 +00:06:18,000 --> 00:06:26,000 +Now, when you're doing a pen test, it is important that the organization that you hire to do the pen + +101 +00:06:26,000 --> 00:06:31,000 +tests and you, let's say you're hiring someone, have what's called a rule of engagement. + +102 +00:06:32,000 --> 00:06:36,000 +This specifies what the tester can do. + +103 +00:06:36,000 --> 00:06:41,000 +Like what range can of IPS can they scan, when can they do the test? + +104 +00:06:41,000 --> 00:06:44,000 +What methodology or tools should they be using? + +105 +00:06:44,000 --> 00:06:46,000 +Can they do a DDoS? + +106 +00:06:46,000 --> 00:06:46,000 +Maybe. + +107 +00:06:46,000 --> 00:06:47,000 +Maybe not. + +108 +00:06:47,000 --> 00:06:50,000 +Can they social engineer your workers? + +109 +00:06:50,000 --> 00:06:52,000 +Can they attempt physical intrusion? + +110 +00:06:52,000 --> 00:06:54,000 +Is there a set of IP should be excluded? + +111 +00:06:54,000 --> 00:06:55,000 +How do you want your report? + +112 +00:06:55,000 --> 00:06:57,000 +How should the communication be done? + +113 +00:06:57,000 --> 00:07:01,000 +There's a lot of things here pen testing has. + +114 +00:07:01,000 --> 00:07:02,000 +Why are we doing this well. + +115 +00:07:04,000 --> 00:07:06,000 +Because there is a lot. + +116 +00:07:06,000 --> 00:07:06,000 +I'm going to skip this one. + +117 +00:07:06,000 --> 00:07:07,000 +We'll come back to that. + +118 +00:07:07,000 --> 00:07:10,000 +There's a lot of risk associated with a pen test. + +119 +00:07:10,000 --> 00:07:18,000 +When pen testers are done, you have to remember that things can can be broken, for example, your + +120 +00:07:18,000 --> 00:07:20,000 +phone system or your PBX. + +121 +00:07:20,000 --> 00:07:26,000 +Private branch exchange means your phone system can stop if you try to scan certain phone systems, + +122 +00:07:26,000 --> 00:07:31,000 +especially SCADA based systems, or try to try to test them, they could go right down and cause a massive + +123 +00:07:31,000 --> 00:07:32,000 +disaster. + +124 +00:07:32,000 --> 00:07:37,000 +So there's a lot of risk expected with tinti's pen testing. + +125 +00:07:37,000 --> 00:07:42,000 +What if the pen testers tries to do a DDoS against your web server in the middle of the day, now all + +126 +00:07:42,000 --> 00:07:45,000 +of a sudden takes your web server out, the business starts to lose money. + +127 +00:07:46,000 --> 00:07:54,000 +Pym tests because of the risks that is associated with a pen test, and also because technically they're + +128 +00:07:54,000 --> 00:07:55,000 +hacking you. + +129 +00:07:55,000 --> 00:08:01,000 +Before a pen test can done, you must have a signed agreement. + +130 +00:08:01,000 --> 00:08:02,000 +All right. + +131 +00:08:02,000 --> 00:08:05,000 +A signed document giving the pen tester permission. + +132 +00:08:05,000 --> 00:08:13,000 +Understand the difference between a pen test and an actual hack is one has permission and one doesn't. + +133 +00:08:14,000 --> 00:08:14,000 +All right. + +134 +00:08:14,000 --> 00:08:20,000 +A hacker coming in and hacking your organization to destroy data is not very much different than a pen + +135 +00:08:20,000 --> 00:08:24,000 +test, except the pen test has permission to do it and will inform you at the end what they did. + +136 +00:08:24,000 --> 00:08:26,000 +And here are things you should fix. + +137 +00:08:26,000 --> 00:08:29,000 +So a pen tester must have this document. + +138 +00:08:30,000 --> 00:08:33,000 +On the Y on the person while it's getting done. + +139 +00:08:33,000 --> 00:08:33,000 +Should include. + +140 +00:08:33,000 --> 00:08:39,000 +It should include a contract and contact information of the authority who will be available during the + +141 +00:08:39,000 --> 00:08:42,000 +test and signed by person of authority. + +142 +00:08:42,000 --> 00:08:46,000 +You want to make sure maybe the CIO signs off on this. + +143 +00:08:47,000 --> 00:08:47,000 +Now. + +144 +00:08:49,000 --> 00:08:50,000 +What exactly is the process? + +145 +00:08:50,000 --> 00:08:57,000 +Well, here I have a pen test process or a methodology that pen testers follow. + +146 +00:08:57,000 --> 00:09:04,000 +The first thing now this is technically what hackers will do, except they don't do number six. + +147 +00:09:04,000 --> 00:09:07,000 +So if you're looking if you're thinking, okay, well how does hackers work? + +148 +00:09:07,000 --> 00:09:10,000 +Well, they do basically everything except number six. + +149 +00:09:10,000 --> 00:09:10,000 +Let's get started. + +150 +00:09:10,000 --> 00:09:13,000 +The first thing that they're going to do is they're going to do reconnaissance notice. + +151 +00:09:13,000 --> 00:09:18,000 +They're reconnaissance means to find information about the organization. + +152 +00:09:18,000 --> 00:09:19,000 +This is called footprinting. + +153 +00:09:19,000 --> 00:09:26,000 +When we do reconnaissance, what we're doing is we're looking to see are people who work in the organization, + +154 +00:09:26,000 --> 00:09:30,000 +domain names, physical locations, product sales. + +155 +00:09:31,000 --> 00:09:33,000 +What technology are you guys using? + +156 +00:09:33,000 --> 00:09:34,000 +Do you guys use windows? + +157 +00:09:34,000 --> 00:09:36,000 +Do you use stored data in AWS? + +158 +00:09:37,000 --> 00:09:39,000 +What do you use for your CRM? + +159 +00:09:39,000 --> 00:09:41,000 +What can you guys use for your email client? + +160 +00:09:41,000 --> 00:09:42,000 +All the things we can find. + +161 +00:09:42,000 --> 00:09:44,000 +So we're going to scan you. + +162 +00:09:44,000 --> 00:09:47,000 +We're going to look up all kinds of information on the internet about you. + +163 +00:09:50,000 --> 00:09:51,000 +We're going to enumerate you. + +164 +00:09:51,000 --> 00:09:57,000 +Enumeration is connected directly to the host to find out more information about the host. + +165 +00:09:57,000 --> 00:10:03,000 +Once we find out that you're using things like Windows Server, we're using you're using like a sonic + +166 +00:10:03,000 --> 00:10:04,000 +wall of some kind. + +167 +00:10:04,000 --> 00:10:08,000 +Then we're going to do some research on those vulnerabilities. + +168 +00:10:08,000 --> 00:10:11,000 +Is there a vulnerability on this sonic wall. + +169 +00:10:11,000 --> 00:10:15,000 +Now you're going to use things like CVE. + +170 +00:10:16,000 --> 00:10:18,000 +In order to find these vulnerabilities. + +171 +00:10:18,000 --> 00:10:20,000 +This is a great place to find it. + +172 +00:10:20,000 --> 00:10:24,000 +Common Vulnerability and exposure database, which is a topic we'll cover a little bit later. + +173 +00:10:25,000 --> 00:10:31,000 +Once you have found the vulnerabilities for the devices or software, then the next thing to do is to + +174 +00:10:31,000 --> 00:10:34,000 +execute those vulnerabilities and to attempt to gain access. + +175 +00:10:34,000 --> 00:10:37,000 +When you're done, you will clear the log files. + +176 +00:10:37,000 --> 00:10:37,000 +All right. + +177 +00:10:37,000 --> 00:10:43,000 +So clearing the log files, hiding your tracks as if you were never there. + +178 +00:10:43,000 --> 00:10:45,000 +And then of course, document your finding. + +179 +00:10:46,000 --> 00:10:51,000 +Keep in mind, hackers just steal your data or destroy it. + +180 +00:10:51,000 --> 00:10:54,000 +They're not going to be documenting findings after that. + +181 +00:10:54,000 --> 00:10:58,000 +Now, I do want to point out that this is a generic methodology. + +182 +00:10:58,000 --> 00:11:00,000 +Uh, NIST has something very similar. + +183 +00:11:00,000 --> 00:11:04,000 +Here's the NIST for stage pen test and methodology. + +184 +00:11:04,000 --> 00:11:07,000 +First, you plan it, you discover hosts that they have. + +185 +00:11:07,000 --> 00:11:11,000 +You attack it, you discover additional holes, you attack it. + +186 +00:11:11,000 --> 00:11:14,000 +And then of course, everything is reported because it is a pen test. + +187 +00:11:14,000 --> 00:11:17,000 +It is something that is done with permission. + +188 +00:11:18,000 --> 00:11:24,000 +Now, at the end of a pen test, they're going to have things that we should include in their report. + +189 +00:11:24,000 --> 00:11:29,000 +The finding number one is going to say, what did they find is this vulnerability. + +190 +00:11:29,000 --> 00:11:34,000 +Is it a low thing that you don't have to fix right away, or is it high something that should be fixed + +191 +00:11:34,000 --> 00:11:34,000 +right away? + +192 +00:11:34,000 --> 00:11:39,000 +The summary of what they did, what they found, what techniques was used. + +193 +00:11:39,000 --> 00:11:42,000 +They're going to give you what you should do now, what you should do next. + +194 +00:11:42,000 --> 00:11:46,000 +A plan of action like this is what you guys should be doing over the next five months. + +195 +00:11:46,000 --> 00:11:47,000 +What did they find? + +196 +00:11:47,000 --> 00:11:53,000 +What holes is, what rogue services they give you a technical report regression or progression report. + +197 +00:11:53,000 --> 00:11:59,000 +Sensible basically, since if they did the test previously, what have they found that changed or if + +198 +00:11:59,000 --> 00:12:00,000 +anything changed at all? + +199 +00:12:01,000 --> 00:12:04,000 +Did you guys lack policies or training? + +200 +00:12:04,000 --> 00:12:05,000 +Now? + +201 +00:12:06,000 --> 00:12:09,000 +One thing about a pen test are the tools that we use. + +202 +00:12:09,000 --> 00:12:15,000 +Some of these tools, like nmap, has no report versus some of them like the Nexus scanner has tons + +203 +00:12:15,000 --> 00:12:17,000 +of great automated report. + +204 +00:12:17,000 --> 00:12:20,000 +So some tools are going to give you manual. + +205 +00:12:20,000 --> 00:12:24,000 +You got to make it yourself versus some gives you an automated report. + +206 +00:12:24,000 --> 00:12:25,000 +All right. + +207 +00:12:25,000 --> 00:12:29,000 +Any report that's given to you by a pen testers will be validated. + +208 +00:12:29,000 --> 00:12:31,000 +They should read the report to make sure they're accurate. + +209 +00:12:31,000 --> 00:12:34,000 +It's good practice to use two lead and tools. + +210 +00:12:34,000 --> 00:12:35,000 +Just don't use one. + +211 +00:12:35,000 --> 00:12:42,000 +Automated tools are limited in scope because they are programmed versus a manual is not more manual + +212 +00:12:42,000 --> 00:12:45,000 +or manual tools generally give you more control of what you're looking for. + +213 +00:12:46,000 --> 00:12:52,000 +Um, if the tools are outdated that the Pentester is using, well, you're not going to get the latest + +214 +00:12:52,000 --> 00:12:53,000 +vulnerability. + +215 +00:12:53,000 --> 00:12:55,000 +So the tools has to be updated. + +216 +00:12:55,000 --> 00:12:59,000 +The tools are needed to date to create summaries of what we have. + +217 +00:12:59,000 --> 00:13:01,000 +There's so many vulnerabilities. + +218 +00:13:01,000 --> 00:13:01,000 +All right. + +219 +00:13:01,000 --> 00:13:03,000 +There's a lot of info to look at. + +220 +00:13:03,000 --> 00:13:08,000 +And a manual process alone is generally not enough because there's too many vulnerabilities. + +221 +00:13:08,000 --> 00:13:12,000 +There's too many systems, especially on large networks. + +222 +00:13:13,000 --> 00:13:17,000 +When the pen test is over and you have your report, now you have to fix things. + +223 +00:13:17,000 --> 00:13:18,000 +What are we fixing? + +224 +00:13:18,000 --> 00:13:22,000 +Well, you're probably going to go and disable or remove unnecessary services. + +225 +00:13:23,000 --> 00:13:26,000 +Um, modify vulnerable hosts. + +226 +00:13:26,000 --> 00:13:30,000 +Maybe there are hosts out there that didn't have good passwords. + +227 +00:13:30,000 --> 00:13:33,000 +All right, uh, modify enterprise firewall, restrict outside access. + +228 +00:13:33,000 --> 00:13:40,000 +Maybe you guys had open ports, upgrade or patch systems, deploy all types of mitigation countermeasures. + +229 +00:13:40,000 --> 00:13:44,000 +Maybe they found hoses that was connected to the networks. + +230 +00:13:44,000 --> 00:13:45,000 +Maybe they didn't have patching. + +231 +00:13:45,000 --> 00:13:46,000 +Maybe they didn't have firewalls on them. + +232 +00:13:47,000 --> 00:13:48,000 +Configuration management. + +233 +00:13:48,000 --> 00:13:51,000 +Maybe people were making configs to systems without people knowing. + +234 +00:13:51,000 --> 00:13:53,000 +Monitor vulnerability alert lists. + +235 +00:13:53,000 --> 00:13:56,000 +Examine the application environment. + +236 +00:13:56,000 --> 00:13:59,000 +Is there bugs in your application? + +237 +00:14:00,000 --> 00:14:03,000 +Initiated proves appropriate system changes. + +238 +00:14:03,000 --> 00:14:06,000 +Anytime a pen test is done, the first thing you do, you get the reports. + +239 +00:14:06,000 --> 00:14:11,000 +You got to change your system and of course modify the security policies if they found any problems + +240 +00:14:11,000 --> 00:14:12,000 +with them. + +241 +00:14:13,000 --> 00:14:17,000 +Of all the pen testers I've done, I've never found a I've never done a pen test where it was all clean + +242 +00:14:17,000 --> 00:14:18,000 +and the report came back. + +243 +00:14:18,000 --> 00:14:20,000 +You guys are absolutely amazing. + +244 +00:14:20,000 --> 00:14:21,000 +Keep doing what you're doing. + +245 +00:14:21,000 --> 00:14:26,000 +That has never in my life I've never seen that or wrote that. + +246 +00:14:26,000 --> 00:14:28,000 +So you you will have. + +247 +00:14:28,000 --> 00:14:30,000 +They will find something. + +248 +00:14:30,000 --> 00:14:31,000 +All right. + +249 +00:14:31,000 --> 00:14:33,000 +When we do pen tests, we find things. + +250 +00:14:33,000 --> 00:14:35,000 +Things that you don't even think about. + +251 +00:14:36,000 --> 00:14:38,000 +Now, granted, some of them may not have a. + +252 +00:14:39,000 --> 00:14:41,000 +I think that needs to be fixed right away. + +253 +00:14:41,000 --> 00:14:49,000 +But you have to remember that the small things can sometimes turns out to be big things, so it doesn't + +254 +00:14:49,000 --> 00:14:49,000 +matter what it is. + +255 +00:14:49,000 --> 00:14:56,000 +Make sure any time you get a pen test report, you fix those things on there because you never know + +256 +00:14:56,000 --> 00:14:58,000 +where the next attack will come from. + diff --git a/15 - Vulnerability Management/005 Bug Bounty Program OB 4.3_en.srt b/15 - Vulnerability Management/005 Bug Bounty Program OB 4.3_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..5927dc7df3a1ed3888ee49749caf65b972305088 --- /dev/null +++ b/15 - Vulnerability Management/005 Bug Bounty Program OB 4.3_en.srt @@ -0,0 +1,212 @@ +1 +00:00:00,000 --> 00:00:06,000 +When an organization builds a product such as Samsung building this phone or Sonicwall making their + +2 +00:00:06,000 --> 00:00:12,000 +firewall here, you would think that big companies like Samsung or Dell who own Sonicwall will have + +3 +00:00:12,000 --> 00:00:19,000 +enough resources, basically people and teams to test these devices for vulnerabilities. + +4 +00:00:19,000 --> 00:00:25,000 +Well, it doesn't matter how much people they have, they'll never have unlimited people. + +5 +00:00:25,000 --> 00:00:27,000 +And generally a lot of the same. + +6 +00:00:27,000 --> 00:00:32,000 +A lot of the people that's working on the team has generally the same methodology or the same thinking. + +7 +00:00:32,000 --> 00:00:39,000 +They don't think outside the box, something that's so off the rail that the team can't find. + +8 +00:00:39,000 --> 00:00:41,000 +The point of this discussion is that. + +9 +00:00:42,000 --> 00:00:46,000 +We can't think of every possible way to, you know, Samsung can think of every possible way somebody + +10 +00:00:46,000 --> 00:00:48,000 +will attempt to hack this device. + +11 +00:00:48,000 --> 00:00:49,000 +So you know what Samsung can do? + +12 +00:00:49,000 --> 00:00:52,000 +They can pay people to hack this device. + +13 +00:00:52,000 --> 00:00:54,000 +Just random people. + +14 +00:00:56,000 --> 00:00:57,000 +Bug bounty. + +15 +00:00:57,000 --> 00:00:59,000 +What exactly is it? + +16 +00:00:59,000 --> 00:01:06,000 +Well, this falls into the topic of responsible disclosure program bug bounty encourages ethical hackers + +17 +00:01:06,000 --> 00:01:12,000 +to report vulnerabilities in exchange for rewards, helps in identifying and addressing vulnerabilities + +18 +00:01:12,000 --> 00:01:15,000 +before they're exploited in the wild. + +19 +00:01:15,000 --> 00:01:16,000 +Now. + +20 +00:01:17,000 --> 00:01:22,000 +They are different bug bounty programs that are out there. + +21 +00:01:23,000 --> 00:01:28,000 +So let's take a look at one of the bug bounty programs that are out there. + +22 +00:01:28,000 --> 00:01:34,000 +So what these are are basically organizations paying you that if you find vulnerabilities in their system, + +23 +00:01:34,000 --> 00:01:36,000 +report it to them and they're going to pay you. + +24 +00:01:36,000 --> 00:01:38,000 +So I want to show you guys one of them. + +25 +00:01:38,000 --> 00:01:40,000 +The most famous website for this is hacker one. + +26 +00:01:41,000 --> 00:01:44,000 +So it's basically hacker 1.com. + +27 +00:01:44,000 --> 00:01:48,000 +And before I did this video I went to this and I found Amazon. + +28 +00:01:48,000 --> 00:01:49,000 +What's Amazon paying. + +29 +00:01:49,000 --> 00:01:52,000 +So here is hacker 1.com. + +30 +00:01:52,000 --> 00:01:53,000 +And this is as of today. + +31 +00:01:53,000 --> 00:01:57,000 +Today is this no December 7th 2023. + +32 +00:01:57,000 --> 00:02:00,000 +This program is launched on April 20th. + +33 +00:02:00,000 --> 00:02:05,000 +Um and here in this one Amazon vulnerability research program. + +34 +00:02:05,000 --> 00:02:06,000 +All right. + +35 +00:02:06,000 --> 00:02:09,000 +Our rewards are based on the severity of the vulnerability. + +36 +00:02:09,000 --> 00:02:11,000 +Hackers here. + +37 +00:02:11,000 --> 00:02:17,000 +If they find things and they report it to Amazon, they are rewarded for something that's low. + +38 +00:02:17,000 --> 00:02:19,000 +You get 150 bucks for something that's critical. + +39 +00:02:19,000 --> 00:02:22,000 +You get all the way up to $20,000. + +40 +00:02:22,000 --> 00:02:28,000 +So if you are an amazing hacker and there are tons and tons of different vulnerabilities that are out + +41 +00:02:28,000 --> 00:02:33,000 +there that you guys can take a look at, it's called hacker 1.com. + +42 +00:02:34,000 --> 00:02:41,000 +So bug bounty is an interesting thing because in this one you're actually paid. + +43 +00:02:41,000 --> 00:02:45,000 +Uh, rewarded, I should say, to find vulnerabilities. + +44 +00:02:46,000 --> 00:02:53,000 +So I had a couple of students in my career that has when I started training them, they weren't the + +45 +00:02:53,000 --> 00:02:57,000 +best in technology, but over years they became very good. + +46 +00:02:57,000 --> 00:03:03,000 +And very recently I met one of them that does this on a part time for side money because he is very + +47 +00:03:03,000 --> 00:03:03,000 +good. + +48 +00:03:03,000 --> 00:03:09,000 +The benefits here is you're going to gather diverse insights from the global security community, often + +49 +00:03:09,000 --> 00:03:12,000 +uncovering issues that internal testing fails. + +50 +00:03:12,000 --> 00:03:18,000 +So the organization, like Amazon, gathers security from from folks all around the world, all different + +51 +00:03:18,000 --> 00:03:24,000 +types of communities that their internal systems will miss or their internal testing would make. + +52 +00:03:24,000 --> 00:03:32,000 +If you ever get and you become amazing ethical hacker or pentester, try out bug, do some bug bounty + +53 +00:03:32,000 --> 00:03:35,000 +programs to make some side money. + diff --git a/15 - Vulnerability Management/006 False Positive vs. False Negative OB 4.3_en.srt b/15 - Vulnerability Management/006 False Positive vs. False Negative OB 4.3_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..1bed0f95b2f49e5dfbe7b4771bbaf976ced101ef --- /dev/null +++ b/15 - Vulnerability Management/006 False Positive vs. False Negative OB 4.3_en.srt @@ -0,0 +1,140 @@ +1 +00:00:00,000 --> 00:00:06,000 +When you use vulnerability scanning software like the Nexus security scanner, or you have log files + +2 +00:00:06,000 --> 00:00:11,000 +that are reporting potential vulnerabilities, you have to make sure you investigate really well. + +3 +00:00:11,000 --> 00:00:16,000 +There are times when it's telling you it's a vulnerability, but it actually isn't. + +4 +00:00:16,000 --> 00:00:20,000 +It's normal and it's time that's telling you it's normal and it actually is a vulnerability. + +5 +00:00:20,000 --> 00:00:24,000 +Two terms make sure you're familiar with for your exam. + +6 +00:00:24,000 --> 00:00:28,000 +Because if you don't really understand them, it can really confuse you. + +7 +00:00:28,000 --> 00:00:30,000 +The first one is called a false positive. + +8 +00:00:30,000 --> 00:00:37,000 +This occurs when a system incorrectly identifies a normal or benign activity as a threat. + +9 +00:00:37,000 --> 00:00:40,000 +Requires verification immediately. + +10 +00:00:40,000 --> 00:00:44,000 +You should to avoid wasting resources on non-existent issues. + +11 +00:00:44,000 --> 00:00:45,000 +So imagine. + +12 +00:00:46,000 --> 00:00:50,000 +Uh, as security scanning software sends you. + +13 +00:00:50,000 --> 00:00:55,000 +Alert that server one that's sitting on his desk has a major vulnerability. + +14 +00:00:55,000 --> 00:00:57,000 +I mean, you go into the machine, you realize it was nothing. + +15 +00:00:57,000 --> 00:01:01,000 +That thing was not actually what it's saying was vulnerability was not. + +16 +00:01:01,000 --> 00:01:03,000 +That would be a false positive. + +17 +00:01:03,000 --> 00:01:07,000 +The worst thing that can happen, though, is a false negative. + +18 +00:01:07,000 --> 00:01:11,000 +This happens when a system fails to detect an actual vulnerability or threat. + +19 +00:01:11,000 --> 00:01:15,000 +So what it's saying is that this activity is normal. + +20 +00:01:15,000 --> 00:01:18,000 +So it's a false negative. + +21 +00:01:18,000 --> 00:01:24,000 +Now more dangerous as it's most dangerous as it leaves the system unknowingly open. + +22 +00:01:24,000 --> 00:01:24,000 +Right. + +23 +00:01:24,000 --> 00:01:30,000 +Because you're going to think that, hey, my systems are working great when they're actually not, + +24 +00:01:30,000 --> 00:01:34,000 +so it's unknowingly exposed it to potential exploits coming up in the future. + +25 +00:01:34,000 --> 00:01:41,000 +So while false positives is more of a waste of resources, um, and just drives up your blood pressure + +26 +00:01:41,000 --> 00:01:47,000 +for no reason, false negatives makes your blood pressure go down and makes you feel great when actuality, + +27 +00:01:47,000 --> 00:01:48,000 +that's how you're going to get hacked. + +28 +00:01:48,000 --> 00:01:51,000 +So you have to be careful with these kinds of things. + +29 +00:01:51,000 --> 00:01:52,000 +That does happen. + +30 +00:01:52,000 --> 00:01:55,000 +In my experience, they're not going to happen very often. + +31 +00:01:55,000 --> 00:02:03,000 +But anytime something seems abnormal to you, even though systems are security, scanners are saying + +32 +00:02:03,000 --> 00:02:04,000 +it's okay. + +33 +00:02:04,000 --> 00:02:06,000 +It's probably best to investigate just in case. + +34 +00:02:06,000 --> 00:02:13,000 +And of course, if you do get vulnerable software reported vulnerabilities, go ahead and investigate + +35 +00:02:13,000 --> 00:02:15,000 +them just in case it's a false positive. + diff --git a/15 - Vulnerability Management/007 CVE and CVSS OB 4.3_en.srt b/15 - Vulnerability Management/007 CVE and CVSS OB 4.3_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..c5947f54cfaf3c65cacc06aafcba0639cc7531a9 --- /dev/null +++ b/15 - Vulnerability Management/007 CVE and CVSS OB 4.3_en.srt @@ -0,0 +1,1136 @@ +1 +00:00:00,000 --> 00:00:05,000 +What if I told you guys there is a giant database of all the different vulnerabilities out there that + +2 +00:00:05,000 --> 00:00:11,000 +can affect all the different devices, software or hardware that you have in your organization and you + +3 +00:00:11,000 --> 00:00:12,000 +can actually search it. + +4 +00:00:12,000 --> 00:00:16,000 +So let's say you go work for a company and you realize that they have a sonicwall. + +5 +00:00:16,000 --> 00:00:21,000 +You can actually search for Sonicwall and it will tell you all the vulnerabilities against this device. + +6 +00:00:21,000 --> 00:00:24,000 +This would be amazing for a network administrator. + +7 +00:00:24,000 --> 00:00:30,000 +And then I'll show you guys in this video how severe are those vulnerabilities and how to read what + +8 +00:00:30,000 --> 00:00:32,000 +is called the Cvss score. + +9 +00:00:33,000 --> 00:00:35,000 +This brings me to this video. + +10 +00:00:35,000 --> 00:00:41,000 +What I'm talking about here is something we call CVE Common Vulnerabilities and Exposures Database. + +11 +00:00:41,000 --> 00:00:45,000 +Once again, links to the two website I'm using will be in the slides. + +12 +00:00:45,000 --> 00:00:47,000 +This is CVE. + +13 +00:00:47,000 --> 00:00:55,000 +Now what CVE is is that it's a program to identify, define and catalog publicly disclosed cybersecurity + +14 +00:00:55,000 --> 00:00:56,000 +vulnerabilities. + +15 +00:00:56,000 --> 00:00:58,000 +And this goes against every product. + +16 +00:00:58,000 --> 00:01:02,000 +To use this you basically are going to search for your product. + +17 +00:01:02,000 --> 00:01:03,000 +So let's say. + +18 +00:01:04,000 --> 00:01:08,000 +Let's say you're looking for something like Sonic Wall. + +19 +00:01:08,000 --> 00:01:12,000 +So I click on search and it takes me to their newer website here. + +20 +00:01:12,000 --> 00:01:15,000 +And you notice CV list download. + +21 +00:01:15,000 --> 00:01:20,000 +Uh now because it's in transition it's not as easy to use anymore. + +22 +00:01:20,000 --> 00:01:24,000 +Uh, but what I'm going to do here is I'm going to go we don't want to download it. + +23 +00:01:25,000 --> 00:01:25,000 +All right. + +24 +00:01:25,000 --> 00:01:29,000 +We don't want to download all the CVS that are out there. + +25 +00:01:29,000 --> 00:01:35,000 +I'm going to go to CVS list keyword search and I'm just going to type in here Sonicwall. + +26 +00:01:35,000 --> 00:01:36,000 +And I'm going to oops, not RSA. + +27 +00:01:36,000 --> 00:01:39,000 +I was looking for that earlier Sonicwall. + +28 +00:01:39,000 --> 00:01:46,000 +And here are all the vulnerabilities that has been reported against Sonicwall devices. + +29 +00:01:47,000 --> 00:01:49,000 +And I want you guys to look at this. + +30 +00:01:49,000 --> 00:01:52,000 +Here's how you read it CVE is common vulnerability and exposure. + +31 +00:01:52,000 --> 00:01:54,000 +The year is 2023. + +32 +00:01:54,000 --> 00:01:57,000 +And this is this number that you see here. + +33 +00:01:57,000 --> 00:01:57,000 +Make this bigger. + +34 +00:01:57,000 --> 00:02:03,000 +This number that we see here is just the number associated with that particular CVE. + +35 +00:02:04,000 --> 00:02:07,000 +So you can see like this one is 34 137. + +36 +00:02:07,000 --> 00:02:13,000 +This one here is going to be 441244A21944220. + +37 +00:02:13,000 --> 00:02:20,000 +Now when you click on these here it's going to explain more of that particular vulnerability to you. + +38 +00:02:20,000 --> 00:02:23,000 +So let's go ahead and find one of these vulnerabilities. + +39 +00:02:23,000 --> 00:02:25,000 +I'm just going to click on the latest one. + +40 +00:02:26,000 --> 00:02:28,000 +And it gives you a description. + +41 +00:02:28,000 --> 00:02:32,000 +On the vulnerability that's going to affect the Sonicwall. + +42 +00:02:32,000 --> 00:02:34,000 +Net extender for windows. + +43 +00:02:34,000 --> 00:02:41,000 +And what it does is that it's going to then give you generally puts you back to the manufacturer's website + +44 +00:02:41,000 --> 00:02:43,000 +to tell you how to fix it. + +45 +00:02:43,000 --> 00:02:48,000 +The good thing about CVE is that generally when it's posted here, it's been fixed by the manufacturer. + +46 +00:02:48,000 --> 00:02:53,000 +So if you find a vulnerability here, you should go to the manufacturer's website and they'll tell you + +47 +00:02:53,000 --> 00:02:54,000 +how to fix it. + +48 +00:02:54,000 --> 00:02:57,000 +So it's given me two links of how to get there. + +49 +00:02:57,000 --> 00:02:58,000 +Let's click on this one. + +50 +00:02:59,000 --> 00:03:01,000 +So I want you guys to look at this. + +51 +00:03:01,000 --> 00:03:01,000 +It's. + +52 +00:03:01,000 --> 00:03:06,000 +This is a security advisory from Sonicwall themselves. + +53 +00:03:06,000 --> 00:03:10,000 +You notice that it's given a score of 7.3. + +54 +00:03:10,000 --> 00:03:12,000 +What the hell does that mean? + +55 +00:03:12,000 --> 00:03:15,000 +7.3 and then you have this thing here. + +56 +00:03:15,000 --> 00:03:16,000 +Watch this. + +57 +00:03:18,000 --> 00:03:25,000 +It says Cvss score 7.3 and then it gives you this weird looking thing like, what is that? + +58 +00:03:25,000 --> 00:03:27,000 +Well, I want you guys to understand this. + +59 +00:03:28,000 --> 00:03:29,000 +CV. + +60 +00:03:29,000 --> 00:03:33,000 +CVS is a common vulnerability scoring system. + +61 +00:03:33,000 --> 00:03:39,000 +CVS um is basically a system and I want to show this to you again. + +62 +00:03:39,000 --> 00:03:41,000 +Link in the link is going to be in the slide. + +63 +00:03:41,000 --> 00:03:52,000 +CVS is basically a scoring system that scores how deadly, how bad a vulnerability is to a particular + +64 +00:03:52,000 --> 00:03:52,000 +system. + +65 +00:03:52,000 --> 00:03:55,000 +Seven is bad, but it's not terrible bad. + +66 +00:03:55,000 --> 00:03:59,000 +Or is that 17.3 is bad, but it's not terribly bad. + +67 +00:04:00,000 --> 00:04:03,000 +The scoring system goes from 0 to 1. + +68 +00:04:03,000 --> 00:04:07,000 +So if I'm 0 to 10, if it's ten, it's really bad. + +69 +00:04:07,000 --> 00:04:11,000 +If it's one, not really. + +70 +00:04:11,000 --> 00:04:13,000 +If it's like a five, it's a moderate. + +71 +00:04:13,000 --> 00:04:15,000 +Let me show you guys how to use the Cvss. + +72 +00:04:15,000 --> 00:04:18,000 +So if I go to Cvss, remember Cvss is a score. + +73 +00:04:18,000 --> 00:04:26,000 +So when you look at a vulnerability and it says Cvss 567, if you see a cvss, that's a eight, 9 or + +74 +00:04:26,000 --> 00:04:27,000 +10. + +75 +00:04:27,000 --> 00:04:30,000 +Wake up and go and fix it like it needs to be fixed yesterday. + +76 +00:04:30,000 --> 00:04:34,000 +If it's a ten, don't sleep until it's fixed. + +77 +00:04:34,000 --> 00:04:38,000 +So let's take a look and I'm going to show you guys how to calculate it. + +78 +00:04:39,000 --> 00:04:40,000 +Now. + +79 +00:04:40,000 --> 00:04:43,000 +Cvss let me see the scoring system that they were using. + +80 +00:04:43,000 --> 00:04:45,000 +So this was Cvss 3.0. + +81 +00:04:45,000 --> 00:04:49,000 +They're telling us there's different version of the calculator that's here. + +82 +00:04:49,000 --> 00:04:51,000 +You notice they have a 3.1. + +83 +00:04:51,000 --> 00:04:52,000 +There's a 3.0. + +84 +00:04:52,000 --> 00:04:55,000 +So I'm going to use the 3.0 calculator just to match up with them. + +85 +00:04:55,000 --> 00:04:56,000 +There is a 4.0. + +86 +00:04:56,000 --> 00:04:58,000 +Also you guys can play around with these here. + +87 +00:04:59,000 --> 00:05:02,000 +Uh so I'm going to go to 3.0 to calculate I want to show you how it's done. + +88 +00:05:02,000 --> 00:05:06,000 +So let's say there was an attack against a network. + +89 +00:05:06,000 --> 00:05:09,000 +Let's say it was a network attack. + +90 +00:05:10,000 --> 00:05:12,000 +It wasn't complex at all. + +91 +00:05:12,000 --> 00:05:12,000 +So it was. + +92 +00:05:12,000 --> 00:05:14,000 +Complexity is low. + +93 +00:05:14,000 --> 00:05:17,000 +Did it require privileges like username and passwords? + +94 +00:05:17,000 --> 00:05:18,000 +No. + +95 +00:05:18,000 --> 00:05:21,000 +Did it require your users to maybe click on a link? + +96 +00:05:21,000 --> 00:05:22,000 +No. + +97 +00:05:23,000 --> 00:05:26,000 +Did it change anything in the network? + +98 +00:05:26,000 --> 00:05:28,000 +Let's say it could change anything. + +99 +00:05:28,000 --> 00:05:29,000 +It changed anything. + +100 +00:05:29,000 --> 00:05:33,000 +It can steal your data confidentiality. + +101 +00:05:33,000 --> 00:05:38,000 +The vulnerability really affects confidentiality, integrity and availability. + +102 +00:05:38,000 --> 00:05:41,000 +Well, disguise is the perfect attack. + +103 +00:05:41,000 --> 00:05:45,000 +This is an attack where it's super easy to do. + +104 +00:05:46,000 --> 00:05:51,000 +It doesn't require any interaction on your part and they can steal your data, manipulate your data, + +105 +00:05:51,000 --> 00:05:53,000 +bring your system down. + +106 +00:05:53,000 --> 00:06:00,000 +If you ever see an attack that's listed as a ten, because I can't remember ever seeing an attack listed + +107 +00:06:00,000 --> 00:06:00,000 +as a ten. + +108 +00:06:00,000 --> 00:06:03,000 +This is the perfect and the highest on the calculator. + +109 +00:06:03,000 --> 00:06:08,000 +But let's say this attack doesn't do confidentiality. + +110 +00:06:08,000 --> 00:06:09,000 +It doesn't do integrity. + +111 +00:06:09,000 --> 00:06:12,000 +Now it's 8.6. + +112 +00:06:12,000 --> 00:06:14,000 +Maybe it doesn't do availability. + +113 +00:06:14,000 --> 00:06:15,000 +Nothing. + +114 +00:06:15,000 --> 00:06:15,000 +It's zero. + +115 +00:06:15,000 --> 00:06:16,000 +That means there's no attack here. + +116 +00:06:17,000 --> 00:06:20,000 +But what if it only did confidentiality okay eight. + +117 +00:06:20,000 --> 00:06:24,000 +What if it required user interaction okay. + +118 +00:06:24,000 --> 00:06:27,000 +That means if you train your users, maybe it's not going to happen. + +119 +00:06:27,000 --> 00:06:29,000 +What if it needs privileges, right. + +120 +00:06:29,000 --> 00:06:31,000 +Maybe it needs high privileges. + +121 +00:06:32,000 --> 00:06:32,000 +All right. + +122 +00:06:32,000 --> 00:06:35,000 +What if it was super complex? + +123 +00:06:35,000 --> 00:06:39,000 +What if they had to be locally present or physically present? + +124 +00:06:40,000 --> 00:06:40,000 +Right. + +125 +00:06:40,000 --> 00:06:43,000 +This all of these things here affects how it's done. + +126 +00:06:44,000 --> 00:06:48,000 +What if they just stole could steal a little bit of information? + +127 +00:06:48,000 --> 00:06:51,000 +Now you see how this thing is changing. + +128 +00:06:51,000 --> 00:06:52,000 +Now I want you guys. + +129 +00:06:52,000 --> 00:06:57,000 +I know this is hard to see in the video, but I want you guys to look at the top here. + +130 +00:06:58,000 --> 00:06:59,000 +You see this? + +131 +00:06:59,000 --> 00:06:59,000 +Watch this. + +132 +00:06:59,000 --> 00:07:02,000 +If I click and change these things you'll see this change. + +133 +00:07:02,000 --> 00:07:08,000 +Like right now if you see this as a it says n because this a is n the letter. + +134 +00:07:08,000 --> 00:07:19,000 +You see how this is AV is P or AV is n a c is h, PR is h, UI is r, c is h. + +135 +00:07:19,000 --> 00:07:20,000 +What am I showing you here. + +136 +00:07:20,000 --> 00:07:22,000 +Well I'm going to copy I'm going to you know what. + +137 +00:07:22,000 --> 00:07:23,000 +We can just use this. + +138 +00:07:23,000 --> 00:07:24,000 +You see right here. + +139 +00:07:24,000 --> 00:07:26,000 +This is what it's telling you. + +140 +00:07:26,000 --> 00:07:27,000 +The attack vector. + +141 +00:07:27,000 --> 00:07:29,000 +It has to be local. + +142 +00:07:30,000 --> 00:07:33,000 +This one attack complexity is low. + +143 +00:07:33,000 --> 00:07:35,000 +You see this attack vector? + +144 +00:07:35,000 --> 00:07:39,000 +You can tell this is AV is L, so AV and this one is L. + +145 +00:07:40,000 --> 00:07:42,000 +You see this one here AC is L. + +146 +00:07:42,000 --> 00:07:46,000 +So in the vulnerability AC is low. + +147 +00:07:48,000 --> 00:07:51,000 +See, if we do this, we should get the score that they have. + +148 +00:07:51,000 --> 00:07:52,000 +So let's go through it. + +149 +00:07:52,000 --> 00:07:53,000 +PR. + +150 +00:07:55,000 --> 00:08:01,000 +Is which one that they had PR they have is L, so it's low then it requires low privilege. + +151 +00:08:01,000 --> 00:08:05,000 +User interaction is are required. + +152 +00:08:05,000 --> 00:08:06,000 +What about the scope? + +153 +00:08:06,000 --> 00:08:08,000 +The scope is unchanged. + +154 +00:08:08,000 --> 00:08:09,000 +It's not going to really modify anything. + +155 +00:08:11,000 --> 00:08:13,000 +Confidentiality is high, integrity high. + +156 +00:08:13,000 --> 00:08:14,000 +Everything out here is high. + +157 +00:08:14,000 --> 00:08:19,000 +So integrity confidentiality is H or high integrity which is the eye is high. + +158 +00:08:20,000 --> 00:08:23,000 +So high, high and high. + +159 +00:08:23,000 --> 00:08:24,000 +7.3. + +160 +00:08:24,000 --> 00:08:27,000 +Same as this 7.3. + +161 +00:08:28,000 --> 00:08:29,000 +Okay. + +162 +00:08:29,000 --> 00:08:29,000 +Very good. + +163 +00:08:29,000 --> 00:08:37,000 +So now that you guys understand CVE and CVEs, CVE and Cvss are some of the greatest friends you have + +164 +00:08:37,000 --> 00:08:41,000 +as a security administrator and a hacker. + +165 +00:08:41,000 --> 00:08:44,000 +Yes, hackers and pentesters. + +166 +00:08:44,000 --> 00:08:50,000 +You see, you got to understand this a knife, you could take a knife and you could cook dinner, or + +167 +00:08:50,000 --> 00:08:54,000 +you can take that same knife and you can commit murder, right? + +168 +00:08:54,000 --> 00:08:56,000 +It's the same knife. + +169 +00:08:56,000 --> 00:09:03,000 +So what I want you guys to understand is we use CVE to find vulnerabilities, and then we go to the + +170 +00:09:03,000 --> 00:09:04,000 +vendor websites. + +171 +00:09:04,000 --> 00:09:08,000 +By the way, the Sonicwall website, we're showing you how to fix that particular vulnerability. + +172 +00:09:08,000 --> 00:09:10,000 +We use that in order to uh. + +173 +00:09:11,000 --> 00:09:13,000 +Find vulnerabilities and then patch them up. + +174 +00:09:13,000 --> 00:09:17,000 +But when hackers are after you, they use the exact same tools. + +175 +00:09:17,000 --> 00:09:20,000 +They're going to use CVE to find vulnerabilities. + +176 +00:09:20,000 --> 00:09:26,000 +For example, if I'm hacking you, I'm going to scan your systems and I'm going to find out you use + +177 +00:09:26,000 --> 00:09:27,000 +Sonicwall. + +178 +00:09:27,000 --> 00:09:32,000 +Then I'm going to go to CVE, find all the vulnerabilities against Sonicwall and try them all against + +179 +00:09:32,000 --> 00:09:32,000 +you. + +180 +00:09:32,000 --> 00:09:34,000 +That's why you better update your system. + +181 +00:09:34,000 --> 00:09:35,000 +Let's get into this here. + +182 +00:09:36,000 --> 00:09:38,000 +So this is what we're talking about. + +183 +00:09:38,000 --> 00:09:39,000 +What is CVE. + +184 +00:09:39,000 --> 00:09:45,000 +Well, it's a list or our database of publicly known and cybersecurity vulnerabilities and exposures. + +185 +00:09:45,000 --> 00:09:49,000 +Now each vulnerability is given a unique identifier that we have. + +186 +00:09:49,000 --> 00:09:50,000 +That's the CV. + +187 +00:09:50,000 --> 00:09:52,000 +That's the ID that I showed you. + +188 +00:09:52,000 --> 00:09:53,000 +To make them easy. + +189 +00:09:53,000 --> 00:09:55,000 +This is the website that we have on it. + +190 +00:09:55,000 --> 00:09:58,000 +Now remember what the Cvss score is. + +191 +00:09:58,000 --> 00:10:00,000 +I showed you guys how to calculate that. + +192 +00:10:00,000 --> 00:10:03,000 +And I gave you the link right here for you to try it on the calculator. + +193 +00:10:03,000 --> 00:10:05,000 +It's rated how severity it is. + +194 +00:10:06,000 --> 00:10:07,000 +Zero. + +195 +00:10:07,000 --> 00:10:08,000 +Nothing. + +196 +00:10:08,000 --> 00:10:11,000 +Ten well, ten is really bad. + +197 +00:10:11,000 --> 00:10:15,000 +Based on various metrics that you have, the number higher, the worse. + +198 +00:10:15,000 --> 00:10:20,000 +Now this is going to help to prioritize those vulnerabilities. + +199 +00:10:20,000 --> 00:10:26,000 +For example, a vulnerability that has a ten would require more resources. + +200 +00:10:26,000 --> 00:10:30,000 +And you should be focusing your resources on those critical vulnerabilities. + +201 +00:10:30,000 --> 00:10:33,000 +So if you ever wonder, well, Andrew, how would I know? + +202 +00:10:33,000 --> 00:10:37,000 +You know what resource, you know, where I should be prioritizing my resources. + +203 +00:10:37,000 --> 00:10:40,000 +Well, look at the Cvss score. + +204 +00:10:40,000 --> 00:10:41,000 +And that will tell you. + +205 +00:10:42,000 --> 00:10:45,000 +The next thing here is the classification. + +206 +00:10:45,000 --> 00:10:51,000 +Different organizations will classify their vulnerabilities differently. + +207 +00:10:51,000 --> 00:10:52,000 +All right. + +208 +00:10:52,000 --> 00:10:57,000 +Categorizing vulnerability into types such as SQL Injection Buff to streamline the analysis so you can + +209 +00:10:57,000 --> 00:10:58,000 +streamline them. + +210 +00:10:58,000 --> 00:10:59,000 +Like these are buff overflows. + +211 +00:10:59,000 --> 00:11:01,000 +These are going to be SQL injections. + +212 +00:11:01,000 --> 00:11:02,000 +This is programming. + +213 +00:11:02,000 --> 00:11:04,000 +This is network vulnerabilities. + +214 +00:11:04,000 --> 00:11:05,000 +These are systems. + +215 +00:11:05,000 --> 00:11:11,000 +This helps in understanding the nature and standardizing some mitigation strategies. + +216 +00:11:11,000 --> 00:11:15,000 +That way teams can work on like that team only does system vulnerabilities. + +217 +00:11:15,000 --> 00:11:18,000 +That team only does network vulnerabilities. + +218 +00:11:19,000 --> 00:11:22,000 +Terme you should be familiar with is something we call. + +219 +00:11:23,000 --> 00:11:26,000 +Uh, exposure factor. + +220 +00:11:26,000 --> 00:11:28,000 +What exactly is an exposure factor? + +221 +00:11:28,000 --> 00:11:34,000 +Well, this represents potential loss or damage to an asset if it's exploited. + +222 +00:11:34,000 --> 00:11:36,000 +Helps in evaluating the potential impact. + +223 +00:11:36,000 --> 00:11:38,000 +So you guys got to understand this. + +224 +00:11:38,000 --> 00:11:44,000 +Generally speaking, the bigger that cvss score, the bigger exposure factor to whatever systems or + +225 +00:11:44,000 --> 00:11:45,000 +network. + +226 +00:11:45,000 --> 00:11:50,000 +If that Sonicwall score was a ten, there is a massive exposure factor. + +227 +00:11:50,000 --> 00:11:54,000 +If the if the value is five, it's moderate exposure factor. + +228 +00:11:54,000 --> 00:11:57,000 +So the Cvss score that we just mentioned. + +229 +00:11:58,000 --> 00:12:00,000 +Is really important. + +230 +00:12:00,000 --> 00:12:03,000 +The next thing here we have is environmental variables. + +231 +00:12:03,000 --> 00:12:07,000 +You got to keep in mind that the environment will influence how severe it is. + +232 +00:12:07,000 --> 00:12:13,000 +Factors like network architecture or existing security control software dependencies can influence the + +233 +00:12:13,000 --> 00:12:17,000 +severity of how severe a particular vulnerability is. + +234 +00:12:18,000 --> 00:12:27,000 +Take, for example, if we have different kinds of systems in our network that are fully updated and + +235 +00:12:27,000 --> 00:12:28,000 +fully patched. + +236 +00:12:28,000 --> 00:12:29,000 +All right. + +237 +00:12:29,000 --> 00:12:36,000 +We have systems that are well secure around a system that's not so secure. + +238 +00:12:36,000 --> 00:12:41,000 +Now, even though the system may have a high cvss score and a vulnerability that maybe has 2 or 3 of + +239 +00:12:41,000 --> 00:12:46,000 +them, it may not be that big because it's surrounded by good technology. + +240 +00:12:46,000 --> 00:12:48,000 +Some systems may not be fixed right away. + +241 +00:12:48,000 --> 00:12:53,000 +Some systems, even though you discovered a vulnerability, may stay vulnerable for a period of time. + +242 +00:12:53,000 --> 00:12:57,000 +And the reason for that is because you have to test the patches. + +243 +00:12:57,000 --> 00:12:59,000 +You just don't deploy a patch. + +244 +00:12:59,000 --> 00:13:00,000 +It may break the system. + +245 +00:13:02,000 --> 00:13:10,000 +So we have to understand the impact, the potential effect of vulnerabilities on specific industries. + +246 +00:13:10,000 --> 00:13:15,000 +Uh, considering things like regulatory requirements, business operations and of course, the public + +247 +00:13:15,000 --> 00:13:19,000 +image, you know, what happens when a vulnerability impacts your organization? + +248 +00:13:19,000 --> 00:13:20,000 +Consider that impact. + +249 +00:13:20,000 --> 00:13:27,000 +Yes, we may look at the impact that that thing we saw against the sonic wall may break the sonic wall, + +250 +00:13:27,000 --> 00:13:28,000 +but what impact will it have? + +251 +00:13:28,000 --> 00:13:31,000 +How much of operations could be lost? + +252 +00:13:31,000 --> 00:13:34,000 +How much would the public hate us if we lose all their information? + +253 +00:13:35,000 --> 00:13:38,000 +You see, all of that comes down to your risk tolerance. + +254 +00:13:38,000 --> 00:13:41,000 +That's what this is going to come down to your risk tolerance. + +255 +00:13:41,000 --> 00:13:43,000 +What exactly is that? + +256 +00:13:43,000 --> 00:13:48,000 +That's a level of risk an organization is willing to accept influenced by its risk management strategies, + +257 +00:13:48,000 --> 00:13:53,000 +business objectives and regulatory environment, determines how aggressively an organization should + +258 +00:13:53,000 --> 00:13:55,000 +respond to different levels of vulnerability. + +259 +00:13:55,000 --> 00:13:57,000 +Let me give you a good example of risk tolerance. + +260 +00:13:58,000 --> 00:14:02,000 +So you found a vulnerability against the sonicwall. + +261 +00:14:03,000 --> 00:14:07,000 +You run to the boss and you says, hey boss, we found this massive vulnerability. + +262 +00:14:07,000 --> 00:14:11,000 +They can log into the firewall and they can be in our network within ten minutes. + +263 +00:14:11,000 --> 00:14:14,000 +And your boss says, all right, that's not so bad. + +264 +00:14:15,000 --> 00:14:17,000 +What, is he, insane? + +265 +00:14:17,000 --> 00:14:20,000 +His tolerance for risk is really high. + +266 +00:14:20,000 --> 00:14:23,000 +Versus your tolerance for risk is lower. + +267 +00:14:23,000 --> 00:14:26,000 +Now, maybe he has a maybe he has some kind of rezident. + +268 +00:14:26,000 --> 00:14:30,000 +Maybe the sonicwall is protecting just public data. + +269 +00:14:30,000 --> 00:14:34,000 +Maybe everything in that network protected by that sonicwall is public data. + +270 +00:14:34,000 --> 00:14:35,000 +It's public web servers. + +271 +00:14:35,000 --> 00:14:37,000 +So there's really no confidentiality. + +272 +00:14:37,000 --> 00:14:41,000 +But if they log in and they take out the web servers, they may lose availability to whatever those + +273 +00:14:41,000 --> 00:14:43,000 +websites were provided. + +274 +00:14:43,000 --> 00:14:47,000 +So maybe he says, don't fix it right away and concentrate your efforts on something else. + +275 +00:14:47,000 --> 00:14:48,000 +Risk tolerance. + +276 +00:14:48,000 --> 00:14:52,000 +The point is varies by everybody and different organizations. + +277 +00:14:52,000 --> 00:14:58,000 +How we respond to vulnerabilities and problems is determined by the risk tolerance, so keep that in + +278 +00:14:58,000 --> 00:14:59,000 +mind. + +279 +00:14:59,000 --> 00:15:04,000 +Risk tolerance really affects the organization's risk tolerance, especially the upper management affects + +280 +00:15:04,000 --> 00:15:05,000 +how we respond to vulnerability. + +281 +00:15:07,000 --> 00:15:15,000 +A good network administrator is going to really utilize things like CVE cvss in order to manage all + +282 +00:15:15,000 --> 00:15:16,000 +those vulnerabilities. + +283 +00:15:16,000 --> 00:15:22,000 +Remember, the tools of CVE is used by you and by hackers, so make sure you review it to keep your + +284 +00:15:22,000 --> 00:15:24,000 +systems safe. + diff --git a/15 - Vulnerability Management/008 Vulnerability Responses OB 4.3_en.srt b/15 - Vulnerability Management/008 Vulnerability Responses OB 4.3_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..7cff03b885926f8e99f78c708b67207b8d47b267 --- /dev/null +++ b/15 - Vulnerability Management/008 Vulnerability Responses OB 4.3_en.srt @@ -0,0 +1,764 @@ +1 +00:00:00,000 --> 00:00:06,000 +Okay, so you have used something like the Nexus security scanner and CVV to find vulnerabilities against + +2 +00:00:06,000 --> 00:00:07,000 +your system. + +3 +00:00:08,000 --> 00:00:09,000 +But what do you do now? + +4 +00:00:09,000 --> 00:00:11,000 +Now that you okay, here's the vulnerability. + +5 +00:00:11,000 --> 00:00:12,000 +But what do we do now? + +6 +00:00:12,000 --> 00:00:14,000 +Well, we need to fix those vulnerabilities. + +7 +00:00:14,000 --> 00:00:15,000 +God forbid. + +8 +00:00:15,000 --> 00:00:16,000 +What if we're hacked? + +9 +00:00:16,000 --> 00:00:16,000 +What do we do now? + +10 +00:00:16,000 --> 00:00:23,000 +So in this video, let's take a look at some of the things that we can do to fix those vulnerabilities, + +11 +00:00:23,000 --> 00:00:29,000 +because we want to be able to address them promptly to minimize any kind of a risk of exploitation of + +12 +00:00:29,000 --> 00:00:31,000 +those particular vulnerabilities. + +13 +00:00:31,000 --> 00:00:35,000 +What are we going to be patching it, utilizing insurance, segmenting them, looking for alternative + +14 +00:00:35,000 --> 00:00:37,000 +controls and compensating. + +15 +00:00:37,000 --> 00:00:41,000 +Or maybe there is some kind of exception or exemption that needs to be made. + +16 +00:00:41,000 --> 00:00:42,000 +Let's take a look. + +17 +00:00:42,000 --> 00:00:44,000 +Now I'm just going to make a statement. + +18 +00:00:44,000 --> 00:00:50,000 +If I remember from seeing the website CVE a few minutes ago when we when we just made that video, I + +19 +00:00:50,000 --> 00:00:53,000 +think there was 218,000 vulnerabilities listed there. + +20 +00:00:53,000 --> 00:00:55,000 +And, uh. + +21 +00:00:56,000 --> 00:01:01,000 +In my opinion on based on my experience, I'm saying 80 to 90%. + +22 +00:01:01,000 --> 00:01:02,000 +There's no statistics on this. + +23 +00:01:02,000 --> 00:01:04,000 +This is Andrew's opinion. + +24 +00:01:04,000 --> 00:01:10,000 +80 to 90% of the CVE vulnerabilities that I've ever experienced in my life was fixed with a patch. + +25 +00:01:10,000 --> 00:01:14,000 +More than likely the vendor knows about it and they're going to release a patch. + +26 +00:01:14,000 --> 00:01:17,000 +I'm even going to say that number is probably low. + +27 +00:01:17,000 --> 00:01:18,000 +That number is too low. + +28 +00:01:18,000 --> 00:01:25,000 +It's probably 95 plus percent of those 218,000 vulnerabilities that was listed there. + +29 +00:01:25,000 --> 00:01:27,000 +It's probably going to be fixed by a patch. + +30 +00:01:27,000 --> 00:01:27,000 +So what does patching do? + +31 +00:01:27,000 --> 00:01:32,000 +Well, it's generally an update to the system to generally fix some kind of security hole. + +32 +00:01:32,000 --> 00:01:39,000 +When software developers realize that there is some kind of hack against their systems, they will generally + +33 +00:01:39,000 --> 00:01:39,000 +fix it. + +34 +00:01:39,000 --> 00:01:45,000 +And don't think it's just software like an application, because every piece of hardware needs software. + +35 +00:01:45,000 --> 00:01:48,000 +Hardware without software is paper wheat. + +36 +00:01:48,000 --> 00:01:53,000 +That's why patches fix devices and of course software like an operating system. + +37 +00:01:53,000 --> 00:01:57,000 +It's important to regularly patch security loopholes. + +38 +00:01:57,000 --> 00:01:59,000 +If not, hackers will take advantage of it. + +39 +00:01:59,000 --> 00:02:08,000 +The challenge, though, is there are so many vendors managing patches, numerous systems and and compatibility. + +40 +00:02:08,000 --> 00:02:11,000 +Sometimes patches can even break systems. + +41 +00:02:12,000 --> 00:02:15,000 +There is such a thing as cybersecurity insurance. + +42 +00:02:15,000 --> 00:02:16,000 +That's a small business like us. + +43 +00:02:16,000 --> 00:02:19,000 +Even we have cybersecurity insurance. + +44 +00:02:19,000 --> 00:02:25,000 +If we are hacked, we can utilize that cybersecurity insurance to help recover from losses in particularly + +45 +00:02:25,000 --> 00:02:27,000 +financial loss. + +46 +00:02:27,000 --> 00:02:34,000 +For example, if the cybersecurity risk or vulnerability are attack, if they affected us and they took + +47 +00:02:34,000 --> 00:02:41,000 +us out of business for a particular while or we lost some functional information, cybersecurity insurance + +48 +00:02:41,000 --> 00:02:44,000 +can help come in and help with the financial loss. + +49 +00:02:44,000 --> 00:02:48,000 +So this insurance helps mitigate financial risk associated with cyber incidents. + +50 +00:02:49,000 --> 00:02:54,000 +Now consider it's important to understand that the covered scope is a lot of these policies does vary + +51 +00:02:54,000 --> 00:02:56,000 +and some of them are really expensive. + +52 +00:02:56,000 --> 00:03:02,000 +And the cheaper ones may not give you the complete, uh, ability to rebuild your business because they + +53 +00:03:02,000 --> 00:03:04,000 +give you very low money. + +54 +00:03:05,000 --> 00:03:07,000 +Segmentation. + +55 +00:03:08,000 --> 00:03:09,000 +When it comes to it. + +56 +00:03:09,000 --> 00:03:12,000 +Security updating is 101. + +57 +00:03:12,000 --> 00:03:15,000 +Segmentation is also 101. + +58 +00:03:15,000 --> 00:03:19,000 +Segmentation is breaking your network into separate parts. + +59 +00:03:19,000 --> 00:03:23,000 +Earlier in this course we discussed things like utilizing VLANs like I would have on my switch. + +60 +00:03:24,000 --> 00:03:30,000 +You need to do this because if a particular device in a segment is vulnerable and does get attacked, + +61 +00:03:30,000 --> 00:03:33,000 +that attack doesn't spread to every machine in the network. + +62 +00:03:33,000 --> 00:03:35,000 +It can only spread on the segment. + +63 +00:03:35,000 --> 00:03:38,000 +The smaller the segments, the less impact you're going to have. + +64 +00:03:38,000 --> 00:03:41,000 +So it's divided in network into smaller things. + +65 +00:03:41,000 --> 00:03:48,000 +This will limit the spread of a breach within a within a network makes it harder to move laterally. + +66 +00:03:48,000 --> 00:03:50,000 +In other words, move across your network. + +67 +00:03:50,000 --> 00:03:55,000 +Careful planning and setup of segmentation is critical. + +68 +00:03:55,000 --> 00:04:00,000 +Sometimes you're not going to be able to put the best controls. + +69 +00:04:00,000 --> 00:04:06,000 +Sometimes you may not have the resources to implement the best controls in an organization. + +70 +00:04:06,000 --> 00:04:09,000 +That way, you're going to have to come up with what's called compensating controls. + +71 +00:04:09,000 --> 00:04:16,000 +These are security measures that are in place to offset the risk when standard controls cannot be applied. + +72 +00:04:17,000 --> 00:04:22,000 +One of the best security controls you can implement is call separation of duties. + +73 +00:04:22,000 --> 00:04:32,000 +Separation of duties is when instead of having one person do a lot of task, break the task up to multiple + +74 +00:04:32,000 --> 00:04:32,000 +people. + +75 +00:04:32,000 --> 00:04:38,000 +The reason you do this is so that one person doesn't have the ability to commit fraud and not get checked, + +76 +00:04:38,000 --> 00:04:40,000 +or be or be found out. + +77 +00:04:40,000 --> 00:04:44,000 +For example, if you have somebody working in the accounting department and they have the ability to + +78 +00:04:44,000 --> 00:04:47,000 +enter the bill, pay the bill. + +79 +00:04:47,000 --> 00:04:50,000 +In other words, write the check and then reconcile the bank account. + +80 +00:04:50,000 --> 00:04:55,000 +This person has the ability basically to enter a fake bill, send out a fake check to themself, and + +81 +00:04:55,000 --> 00:04:57,000 +who's going to be checking the fake check themselves. + +82 +00:04:57,000 --> 00:05:01,000 +So why don't you have somebody else write checks and somebody else pay bills? + +83 +00:05:01,000 --> 00:05:02,000 +This is a great control. + +84 +00:05:02,000 --> 00:05:04,000 +That separation of duties. + +85 +00:05:04,000 --> 00:05:07,000 +It's break into duties up to prevent fraud. + +86 +00:05:07,000 --> 00:05:15,000 +The problem with separation of duties, it requires more people to do a single task or to complete something. + +87 +00:05:15,000 --> 00:05:16,000 +Now. + +88 +00:05:17,000 --> 00:05:22,000 +Obviously not a lot of companies have the resources to do this or money, so they will put in a compensating + +89 +00:05:22,000 --> 00:05:24,000 +control a lot of time. + +90 +00:05:24,000 --> 00:05:26,000 +A compensating control involves monitoring. + +91 +00:05:26,000 --> 00:05:30,000 +So maybe we hire one person to monitor multiple people. + +92 +00:05:30,000 --> 00:05:33,000 +So this one person can then keep an eye on people. + +93 +00:05:33,000 --> 00:05:38,000 +This is a way to prevent, uh, people from stealing money because they know. + +94 +00:05:38,000 --> 00:05:41,000 +Well, if I make a fake check and I write it and I check it, there's still somebody going to check + +95 +00:05:41,000 --> 00:05:42,000 +the bank account. + +96 +00:05:43,000 --> 00:05:45,000 +So this would be a compensating control. + +97 +00:05:46,000 --> 00:05:47,000 +Now. + +98 +00:05:48,000 --> 00:05:50,000 +Exceptions and exemptions. + +99 +00:05:50,000 --> 00:05:57,000 +This is situation when standard security policies and controls are not applied, often due to some requirement + +100 +00:05:57,000 --> 00:05:58,000 +or limitation. + +101 +00:05:59,000 --> 00:06:08,000 +There may be a point in the organization where putting in the standard fix or doing the standard configurations + +102 +00:06:08,000 --> 00:06:14,000 +cannot be done because an application may fail to work, or particularly speaking, the device may not + +103 +00:06:14,000 --> 00:06:15,000 +support it. + +104 +00:06:15,000 --> 00:06:21,000 +In these situations, you're going to have to make an exception to allowing this thing to work, but + +105 +00:06:21,000 --> 00:06:24,000 +you're going to have to maybe pat it up with other devices around it. + +106 +00:06:25,000 --> 00:06:34,000 +Managing exceptions and exemptions requires a formal process to elevate and approve, ensuring that + +107 +00:06:34,000 --> 00:06:37,000 +any variations from any security policy are justified. + +108 +00:06:37,000 --> 00:06:41,000 +Although sometimes necessary, this does introduce extra risks. + +109 +00:06:41,000 --> 00:06:45,000 +For example, if there is an exception that we're going to allow this vulnerability because fixing it + +110 +00:06:45,000 --> 00:06:47,000 +requires a massive amount of work. + +111 +00:06:47,000 --> 00:06:54,000 +This could result in more risk, of course, but you may want to monitor the device more once you have + +112 +00:06:54,000 --> 00:06:57,000 +put your. + +113 +00:06:57,000 --> 00:06:58,000 +Once you have put. + +114 +00:06:59,000 --> 00:07:02,000 +Your fixes like your patches into place. + +115 +00:07:02,000 --> 00:07:06,000 +Now comes this section validation of the remediation. + +116 +00:07:06,000 --> 00:07:09,000 +Did it actually fix the problem? + +117 +00:07:09,000 --> 00:07:12,000 +Did it fix the vulnerability? + +118 +00:07:12,000 --> 00:07:13,000 +So what are we going to be doing? + +119 +00:07:13,000 --> 00:07:18,000 +Well the first thing up is let's rescan the system. + +120 +00:07:18,000 --> 00:07:24,000 +If the Nexus security scanner says that that machine has is vulnerable to this, this and this, then + +121 +00:07:24,000 --> 00:07:29,000 +the next thing to do is to have the Nexus security scanner scan it again. + +122 +00:07:29,000 --> 00:07:30,000 +Oh, you fixed it. + +123 +00:07:30,000 --> 00:07:31,000 +Scan it again. + +124 +00:07:31,000 --> 00:07:37,000 +Re scan it is used an automated tools to scan the application that were subject to remediation. + +125 +00:07:37,000 --> 00:07:41,000 +This is done to ensure the vulnerabilities identified was patched. + +126 +00:07:41,000 --> 00:07:46,000 +For example, if you scan this machine and you found there was 1010 vulnerabilities, you fixed it. + +127 +00:07:46,000 --> 00:07:48,000 +How do you know you fixed it? + +128 +00:07:48,000 --> 00:07:49,000 +Well, scan it again. + +129 +00:07:51,000 --> 00:07:52,000 +Now. + +130 +00:07:52,000 --> 00:07:53,000 +Auditing. + +131 +00:07:53,000 --> 00:08:00,000 +Auditing is generally going to be a thorough review and examination of security measures and processes + +132 +00:08:00,000 --> 00:08:03,000 +related to those remediation. + +133 +00:08:03,000 --> 00:08:06,000 +Generally, auditing is going to follow a kind of a standard that needs to get done. + +134 +00:08:06,000 --> 00:08:12,000 +That's going to be things like reviewing documents, uh, change management logs, interviewing staff. + +135 +00:08:12,000 --> 00:08:19,000 +The goal here is to ensure that remediation was carried out with a planned procedure and security standards. + +136 +00:08:19,000 --> 00:08:26,000 +Now, any time you fix something, you should have followed a standard security plan or a standard security + +137 +00:08:26,000 --> 00:08:27,000 +procedure. + +138 +00:08:27,000 --> 00:08:32,000 +Auditors will come out and verify that you followed that standard procedure. + +139 +00:08:33,000 --> 00:08:37,000 +Now verification the system comes online. + +140 +00:08:37,000 --> 00:08:41,000 +How do we know that it's actually been remediated? + +141 +00:08:41,000 --> 00:08:43,000 +Well, the scan says hey, we're good. + +142 +00:08:43,000 --> 00:08:50,000 +So verification is the process confirming that a remediation efforts have not only closed the vulnerabilities, + +143 +00:08:50,000 --> 00:08:53,000 +but also that it haven't introduced new vulnerabilities. + +144 +00:08:53,000 --> 00:08:56,000 +That's a common thing or negatively impact the system performance. + +145 +00:08:56,000 --> 00:08:59,000 +So verification do you're scan it. + +146 +00:08:59,000 --> 00:09:00,000 +You realize vulnerability is gone. + +147 +00:09:00,000 --> 00:09:03,000 +But you need to verify the system is fully functional. + +148 +00:09:03,000 --> 00:09:08,000 +Sometimes you may patch a system but the patch fixes the hole. + +149 +00:09:08,000 --> 00:09:10,000 +But the patch broke another part. + +150 +00:09:11,000 --> 00:09:12,000 +You may scan. + +151 +00:09:12,000 --> 00:09:16,000 +You may scan a system and find out that it is vulnerable to this thing. + +152 +00:09:16,000 --> 00:09:21,000 +There's a hole in this system, so you put the patch in, you walk away, you run the scan. + +153 +00:09:21,000 --> 00:09:22,000 +The scan is great. + +154 +00:09:22,000 --> 00:09:25,000 +User calls you ten minutes later and says Microsoft Word doesn't open. + +155 +00:09:25,000 --> 00:09:26,000 +The internet doesn't work. + +156 +00:09:26,000 --> 00:09:28,000 +The patch just broke the Nic card. + +157 +00:09:29,000 --> 00:09:34,000 +Did you verify that whatever you put in didn't break other parts? + +158 +00:09:34,000 --> 00:09:40,000 +This can include manual system testing like manually go in and see if the system works, reviewing its + +159 +00:09:40,000 --> 00:09:45,000 +logs, looking at if performance was decreased in the system with performance metrics. + +160 +00:09:46,000 --> 00:09:49,000 +Basically, the system is operating as expected. + +161 +00:09:50,000 --> 00:09:56,000 +A lot of times we're going to fix things, and in the process of fixing things, we break things. + +162 +00:09:56,000 --> 00:10:01,000 +And if we don't test the system to see if it actually works, we may never know that we actually broke + +163 +00:10:01,000 --> 00:10:03,000 +it while we were trying to patch it. + +164 +00:10:03,000 --> 00:10:04,000 +It's a common thing in it. + +165 +00:10:04,000 --> 00:10:07,000 +Believe that or not involving a user feedback. + +166 +00:10:07,000 --> 00:10:08,000 +Get user feedback. + +167 +00:10:08,000 --> 00:10:10,000 +This is when I said you left. + +168 +00:10:10,000 --> 00:10:14,000 +The user calls you back and says, hey, my system doesn't work anymore. + +169 +00:10:14,000 --> 00:10:17,000 +I know you just fixed it, but now it's even slower. + +170 +00:10:17,000 --> 00:10:19,000 +You need user feedback to to do this. + +171 +00:10:20,000 --> 00:10:21,000 +Who are you going to be reporting to? + +172 +00:10:21,000 --> 00:10:23,000 +Vulnerability fixing? + +173 +00:10:24,000 --> 00:10:30,000 +Any time you fix vulnerabilities in your patched systems, this is generally generally going to be reported + +174 +00:10:30,000 --> 00:10:31,000 +maybe to decision makers. + +175 +00:10:31,000 --> 00:10:38,000 +Sometimes, if the vulnerability was found by compliance officers and government agencies, you might + +176 +00:10:38,000 --> 00:10:39,000 +need to report. + +177 +00:10:40,000 --> 00:10:42,000 +To compliance. + +178 +00:10:42,000 --> 00:10:47,000 +Uh agencies communicate with stakeholders or people involved on your network. + +179 +00:10:47,000 --> 00:10:49,000 +Tracking and accountability. + +180 +00:10:49,000 --> 00:10:52,000 +Continuous improvement on systems are going to be important. + +181 +00:10:52,000 --> 00:10:57,000 +You see, good, good reporting is important to good vulnerability management. + +182 +00:10:58,000 --> 00:10:58,000 +All right. + +183 +00:10:58,000 --> 00:11:02,000 +Don't think that just by discovering a vulnerability you're just going to fix it. + +184 +00:11:02,000 --> 00:11:03,000 +Remember the steps to fix it. + +185 +00:11:03,000 --> 00:11:05,000 +If you patch it re scan it. + +186 +00:11:05,000 --> 00:11:07,000 +After you're scan it what do you do. + +187 +00:11:07,000 --> 00:11:08,000 +Verify it. + +188 +00:11:08,000 --> 00:11:09,000 +Verify that. + +189 +00:11:09,000 --> 00:11:10,000 +You know what? + +190 +00:11:10,000 --> 00:11:15,000 +Not only did we fix the vulnerability, but the system functions. + +191 +00:11:15,000 --> 00:11:16,000 +That's normal. + diff --git a/15 - Vulnerability Management/009 Internal and External Assessments OB 5.5_en.srt b/15 - Vulnerability Management/009 Internal and External Assessments OB 5.5_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..8c2b174023b343ef84d3a0210d40f25b6a516dc5 --- /dev/null +++ b/15 - Vulnerability Management/009 Internal and External Assessments OB 5.5_en.srt @@ -0,0 +1,408 @@ +1 +00:00:00,000 --> 00:00:05,000 +As a cybersecurity professional, you're going to be working with all kinds of different folks within + +2 +00:00:05,000 --> 00:00:11,000 +the organization, whether that's senior management, higher up technical folks, or even lower technical + +3 +00:00:11,000 --> 00:00:15,000 +folks such as the help desk or systems manager or systems engineer. + +4 +00:00:15,000 --> 00:00:20,000 +But one set of folks that IT professionals generally don't like dealing with is auditors. + +5 +00:00:20,000 --> 00:00:25,000 +You see, auditors are folks that comes into your organization, particularly external auditors, and + +6 +00:00:25,000 --> 00:00:32,000 +verify that your policies and your procedures matches certain kinds of regulations that you have to + +7 +00:00:32,000 --> 00:00:34,000 +meet or to meet certain. + +8 +00:00:34,000 --> 00:00:37,000 +Maybe your procedures are not meeting certain policies that even you set. + +9 +00:00:37,000 --> 00:00:41,000 +So in this video, let's take a look at talking about these auditors. + +10 +00:00:41,000 --> 00:00:46,000 +And in particular we're going to look at internal audits and external audits and all the ups and downs + +11 +00:00:46,000 --> 00:00:47,000 +about them. + +12 +00:00:47,000 --> 00:00:48,000 +So let's get started. + +13 +00:00:48,000 --> 00:00:51,000 +The first thing we'll talk about what's known as an internal assessment or audit. + +14 +00:00:52,000 --> 00:00:58,000 +These are audits, assessment and procedures conducted within the organisation by its own employees + +15 +00:00:58,000 --> 00:01:00,000 +or designated internal audit team. + +16 +00:01:00,000 --> 00:01:04,000 +Lots of large organisations have internal audit teams. + +17 +00:01:04,000 --> 00:01:09,000 +These are teams that audit all the different procedures that the organisation follow to ensure that + +18 +00:01:09,000 --> 00:01:13,000 +they're up to date on certain regulations and their policies. + +19 +00:01:13,000 --> 00:01:17,000 +These internal activities are critical for maintaining improvement security measures. + +20 +00:01:17,000 --> 00:01:20,000 +If we want to ensure that we, of course, meet certain compliance. + +21 +00:01:20,000 --> 00:01:25,000 +Now when it comes to these internal audits, one of the main reasons we do them is, of course, for + +22 +00:01:25,000 --> 00:01:26,000 +compliance. + +23 +00:01:26,000 --> 00:01:29,000 +You have to ensure that you meet certain compliance. + +24 +00:01:29,000 --> 00:01:35,000 +For example, what if you have to follow GDPR, HIPAA compliance, PCI compliance and so on depending + +25 +00:01:35,000 --> 00:01:39,000 +on whatever compliance you have to follow, how do you know if you actually meet them? + +26 +00:01:39,000 --> 00:01:42,000 +How do you know the organization is doing the right procedures to meet them? + +27 +00:01:42,000 --> 00:01:45,000 +Well, that's where internal audits will come into play. + +28 +00:01:46,000 --> 00:01:53,000 +This is when internal folks, such as an internal audit team, are actually checking to see, are we + +29 +00:01:53,000 --> 00:01:55,000 +encrypting those credit card information? + +30 +00:01:55,000 --> 00:01:58,000 +Can we prove that we encrypted the credit card information? + +31 +00:01:58,000 --> 00:02:00,000 +They give you the PCI, DSS. + +32 +00:02:00,000 --> 00:02:05,000 +By regular reviewing and assessing internal process control, your organization can identify. + +33 +00:02:05,000 --> 00:02:07,000 +Hey, is there any gap? + +34 +00:02:07,000 --> 00:02:09,000 +Are we supposed to be doing this? + +35 +00:02:09,000 --> 00:02:10,000 +But we're now doing this. + +36 +00:02:10,000 --> 00:02:11,000 +There's a gap there. + +37 +00:02:13,000 --> 00:02:17,000 +One thing that you should have in your organization is going to be an audit committee. + +38 +00:02:17,000 --> 00:02:18,000 +All right. + +39 +00:02:18,000 --> 00:02:21,000 +These are the folks that typically oversee the internal audit function. + +40 +00:02:21,000 --> 00:02:27,000 +They ensure audits are conducted objectively, thoroughly and aligned with the organization goal. + +41 +00:02:27,000 --> 00:02:32,000 +Now, your audit committee is going to be made up of generally folks from different departments, including + +42 +00:02:32,000 --> 00:02:36,000 +legal department, technical department, senior managers, and so on. + +43 +00:02:36,000 --> 00:02:41,000 +These audit committees are set up in order to ensure that all the audit functions are done correctly + +44 +00:02:41,000 --> 00:02:43,000 +in the business, such as do we have one? + +45 +00:02:43,000 --> 00:02:44,000 +Do we have a team? + +46 +00:02:44,000 --> 00:02:49,000 +Are they conducting the right procedures to ensure that we stay on those policies? + +47 +00:02:49,000 --> 00:02:55,000 +The audit Committee plays a key role in evaluating the findings of the internal audits and ensure appropriate + +48 +00:02:55,000 --> 00:02:56,000 +actions are taken. + +49 +00:02:56,000 --> 00:03:04,000 +Now, internal audits are basically known as a self-assessment because the organization is assessing + +50 +00:03:04,000 --> 00:03:09,000 +themselves against some kind of policy or some kind of regulation. + +51 +00:03:09,000 --> 00:03:16,000 +So this is when internal security teams regularly evaluate their own cyber security measures. + +52 +00:03:17,000 --> 00:03:18,000 +Now they should be proactive. + +53 +00:03:18,000 --> 00:03:21,000 +This is a proactive approach allows continuous monitoring. + +54 +00:03:21,000 --> 00:03:23,000 +In other words they're trying to see what we're doing. + +55 +00:03:23,000 --> 00:03:26,000 +So if we are out of compliance we can fix it before we get in trouble. + +56 +00:03:27,000 --> 00:03:33,000 +Self self-assessment is going to help us identify any vulnerabilities or gaps, assess the effectiveness + +57 +00:03:33,000 --> 00:03:38,000 +of our security programs or security measures, and guide the allocation of resources. + +58 +00:03:38,000 --> 00:03:40,000 +So we're going to identify vulnerabilities. + +59 +00:03:40,000 --> 00:03:44,000 +We're going to assess these vulnerabilities or how effective our controls are. + +60 +00:03:44,000 --> 00:03:48,000 +And then we're going to guide and say well let's allocate our resources correctly. + +61 +00:03:49,000 --> 00:03:53,000 +Now the other thing here we have is going to be external assessments. + +62 +00:03:53,000 --> 00:03:54,000 +So what is this. + +63 +00:03:54,000 --> 00:04:00,000 +Well external assessments are audits examinations and assessment done by outside organizations. + +64 +00:04:01,000 --> 00:04:09,000 +Now almost all businesses are going to be externally assessed, for example by a CPA firm or an accounting + +65 +00:04:09,000 --> 00:04:10,000 +firm for their books. + +66 +00:04:10,000 --> 00:04:16,000 +So when they submit tax returns to the IRS or the tax agency, well, we have an external firm saying + +67 +00:04:16,000 --> 00:04:19,000 +they're not lying about their income or their expenses. + +68 +00:04:19,000 --> 00:04:23,000 +Now, in the world of cybersecurity, we have a ton of external auditors that comes in and checks the + +69 +00:04:23,000 --> 00:04:27,000 +controls to see if we're in compliance to certain controls. + +70 +00:04:27,000 --> 00:04:30,000 +This is going to be an objective view. + +71 +00:04:30,000 --> 00:04:31,000 +In other words, it's not subjective. + +72 +00:04:31,000 --> 00:04:34,000 +It's very objective, which means they have no conflict of interest here. + +73 +00:04:34,000 --> 00:04:36,000 +It ensures compliance with regulations. + +74 +00:04:36,000 --> 00:04:39,000 +And it's going to check your internal controls. + +75 +00:04:39,000 --> 00:04:46,000 +Now one of the main reasons for external assessments is of course going to be more regulation, external + +76 +00:04:46,000 --> 00:04:47,000 +regulations. + +77 +00:04:47,000 --> 00:04:49,000 +This is what this is all about. + +78 +00:04:49,000 --> 00:04:56,000 +Typically mandated by government bodies, these external auditors or are I should say external audits + +79 +00:04:56,000 --> 00:05:05,000 +are done to see do you meet certain cybersecurity laws and independent third party audits? + +80 +00:05:05,000 --> 00:05:06,000 +Now what exactly is this? + +81 +00:05:06,000 --> 00:05:12,000 +Well, this is when an independent third party auditor and they come from large organizations. + +82 +00:05:12,000 --> 00:05:17,000 +If you work for a big company, you may hear of names like Ernst and Young Pricewaterhouse Coopers. + +83 +00:05:17,000 --> 00:05:23,000 +These are giant accounting organizations that audits Big Fortune 1000 companies, and they charge hundreds + +84 +00:05:23,000 --> 00:05:26,000 +of thousands, if not millions of dollars for their audits. + +85 +00:05:26,000 --> 00:05:34,000 +But this is an external party coming into your organization, and they do a comprehensive review of + +86 +00:05:34,000 --> 00:05:40,000 +all of your security procedures and your policies, all the things that you are doing, all those controls + +87 +00:05:40,000 --> 00:05:42,000 +that you have implemented, they're going to check it. + +88 +00:05:42,000 --> 00:05:42,000 +Now. + +89 +00:05:43,000 --> 00:05:47,000 +This is going to validate the accuracy of your organization. + +90 +00:05:47,000 --> 00:05:51,000 +Cybersecurity claim to ensure that the controls are effective and in line with industry best practice. + +91 +00:05:51,000 --> 00:05:55,000 +So the organization may say that we have all these policies and procedures, but can you prove it? + +92 +00:05:55,000 --> 00:05:57,000 +Do you actually have all that? + +93 +00:05:57,000 --> 00:06:01,000 +Well, this third party audit will check that this is critical for building trust. + +94 +00:06:01,000 --> 00:06:06,000 +Anytime I want to do business with a vendor, I check to see can I get a third party audit of that vendor + +95 +00:06:06,000 --> 00:06:13,000 +that's going to give me, that's going to give me more in depth information about that particular vendor? + +96 +00:06:13,000 --> 00:06:17,000 +I like to keep in mind, guys, internal auditors are something that you're going to be dealing is a + +97 +00:06:17,000 --> 00:06:19,000 +function that you're going to be working with. + +98 +00:06:19,000 --> 00:06:26,000 +A lot internal auditors within the organization is going to work with all levels of folks in it to ensure + +99 +00:06:26,000 --> 00:06:29,000 +that you guys, or anybody in it, is following the right procedures. + +100 +00:06:29,000 --> 00:06:30,000 +Are they actually doing it? + +101 +00:06:30,000 --> 00:06:35,000 +And then, of course, external auditors comes in after them to verify from an external perspective + +102 +00:06:35,000 --> 00:06:40,000 +or a more trusted perspective that the company is actually in compliance. + diff --git a/15 - Vulnerability Management/010 Quick Quiz.html b/15 - Vulnerability Management/010 Quick Quiz.html new file mode 100644 index 0000000000000000000000000000000000000000..bd4d8c168ecc25c0e266e7378582ed83d7779b39 --- /dev/null +++ b/15 - Vulnerability Management/010 Quick Quiz.html @@ -0,0 +1,479 @@ + + + + + + + Quiz + + + + +
+
+

+

+
+
+
+ Score: 999 of + 999% +
+
Correct: 999
+
Incorrect: 999
+
+ +
+ + + + +
+ + + + diff --git a/16 - Alerting and Monitoring IT/001 Monitoring Resources OB 4.4_en.srt b/16 - Alerting and Monitoring IT/001 Monitoring Resources OB 4.4_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..4f5b3dec187b458ef54bd134531d4026ec8af74a --- /dev/null +++ b/16 - Alerting and Monitoring IT/001 Monitoring Resources OB 4.4_en.srt @@ -0,0 +1,360 @@ +1 +00:00:00,000 --> 00:00:04,000 +When it comes to being a good administrator, you have to be monitoring. + +2 +00:00:04,000 --> 00:00:09,000 +Good security administrator keeps a consistent eye on a couple of things. + +3 +00:00:09,000 --> 00:00:13,000 +That's going to be their systems, their applications and their infrastructure. + +4 +00:00:13,000 --> 00:00:18,000 +You have to keep monitoring on a consistent basis. + +5 +00:00:18,000 --> 00:00:24,000 +If you're not monitoring whatever it is in your infrastructure, you'll never know when something went + +6 +00:00:24,000 --> 00:00:28,000 +down, when something got hacked, or God forbid, information was stolen. + +7 +00:00:28,000 --> 00:00:32,000 +So let's get into this here and we're going to take a look at these three things. + +8 +00:00:32,000 --> 00:00:39,000 +But don't forget the word monitoring is about continuously overseeing various components of your infrastructure. + +9 +00:00:39,000 --> 00:00:40,000 +So let's get into this. + +10 +00:00:40,000 --> 00:00:44,000 +The first thing we're going to talk about is individual system monitoring. + +11 +00:00:44,000 --> 00:00:48,000 +So this focuses on the health and performance of individual computing. + +12 +00:00:48,000 --> 00:00:56,000 +Think of think servers workstations and other endpoint devices like my famous Sonicwall that we have + +13 +00:00:56,000 --> 00:00:57,000 +seen in every video. + +14 +00:00:57,000 --> 00:00:58,000 +A key aspect here. + +15 +00:00:58,000 --> 00:01:03,000 +What are we looking for when I say monitoring you'll say, Andrew, what are what are we monitoring + +16 +00:01:03,000 --> 00:01:03,000 +for? + +17 +00:01:03,000 --> 00:01:06,000 +Well, we're monitoring for any unusual unauthorized changes. + +18 +00:01:06,000 --> 00:01:09,000 +That means somebody's changing a configuration. + +19 +00:01:09,000 --> 00:01:11,000 +Resource utilization. + +20 +00:01:12,000 --> 00:01:15,000 +You're watching monitoring this device. + +21 +00:01:15,000 --> 00:01:22,000 +When you monitor this device, you may notice that on a good day, it stays at a consistent 10 to 15% + +22 +00:01:22,000 --> 00:01:25,000 +CPU and memory usage. + +23 +00:01:25,000 --> 00:01:31,000 +But you're monitoring one day and you notice it's hitting 100% memory, 100% CPU usage, and the lines + +24 +00:01:31,000 --> 00:01:32,000 +are being clogged. + +25 +00:01:32,000 --> 00:01:36,000 +That's a type of a DDoS attack or some kind of DDoS attack. + +26 +00:01:36,000 --> 00:01:37,000 +You want to investigate that? + +27 +00:01:37,000 --> 00:01:43,000 +How long has it been up, or has it been dropping performance metrics like how fast should it be accomplishing + +28 +00:01:43,000 --> 00:01:44,000 +certain tasks? + +29 +00:01:44,000 --> 00:01:48,000 +This is really important to monitor individual systems. + +30 +00:01:48,000 --> 00:01:56,000 +Now, by monitoring these elements, organization can detect any type of potential security incident. + +31 +00:01:56,000 --> 00:02:01,000 +Now potential security incident like I just mentioned for example, like a DDoS attack. + +32 +00:02:03,000 --> 00:02:07,000 +When it comes to your systems, you also have to monitor your applications. + +33 +00:02:07,000 --> 00:02:14,000 +Now I want to point out that systems is individual, applications is what's running on those systems, + +34 +00:02:14,000 --> 00:02:20,000 +and infrastructure is all of the infrastructure gear that you have when like traffic flowing around + +35 +00:02:20,000 --> 00:02:21,000 +your network? + +36 +00:02:21,000 --> 00:02:28,000 +Now, applications is what people use these applications is going to run on these particular systems. + +37 +00:02:28,000 --> 00:02:30,000 +So what are we concerned with? + +38 +00:02:30,000 --> 00:02:33,000 +Well we're concerned with the performance and security of these apps. + +39 +00:02:33,000 --> 00:02:35,000 +Look at the application performance. + +40 +00:02:35,000 --> 00:02:40,000 +Is it getting slower or more users that the help desk complaining that the thing got too slow? + +41 +00:02:40,000 --> 00:02:41,000 +User activity. + +42 +00:02:41,000 --> 00:02:45,000 +How are people utilizing the application? + +43 +00:02:45,000 --> 00:02:51,000 +They may be utilizing it for bad reasons or using it in bad ways. + +44 +00:02:51,000 --> 00:02:56,000 +They may be copying data out of an account in an application, such as credit card numbers. + +45 +00:02:56,000 --> 00:02:57,000 +Look at the error logs. + +46 +00:02:57,000 --> 00:03:05,000 +Everything has logs, devices, uh servers, uh applications, operating systems, you name it, everything + +47 +00:03:05,000 --> 00:03:08,000 +has a log transaction times. + +48 +00:03:08,000 --> 00:03:09,000 +When did things occur? + +49 +00:03:09,000 --> 00:03:13,000 +This is going to help for monitoring for unusual activity. + +50 +00:03:13,000 --> 00:03:20,000 +Any kind of security breach for example unexpected data access pattern for example let's say. + +51 +00:03:20,000 --> 00:03:25,000 +Somebody working in the accounts payable department only always accesses vendor information. + +52 +00:03:26,000 --> 00:03:31,000 +But you notice over the last couple of weeks they've been accessing payroll information because they + +53 +00:03:31,000 --> 00:03:33,000 +have access to the accounting system. + +54 +00:03:33,000 --> 00:03:36,000 +They have access to everything, but they generally don't access those records. + +55 +00:03:36,000 --> 00:03:38,000 +You better find out why they're doing that. + +56 +00:03:39,000 --> 00:03:45,000 +Uh, look, for any kind of anomalies or any kind of weird volume of transaction, you notice that this + +57 +00:03:45,000 --> 00:03:47,000 +guy's pulling more records than he used to. + +58 +00:03:47,000 --> 00:03:48,000 +Could be a problem. + +59 +00:03:49,000 --> 00:03:50,000 +Benefits. + +60 +00:03:50,000 --> 00:03:54,000 +Effective application monitoring is going to help identify and address performance bottlenecks in case + +61 +00:03:54,000 --> 00:03:59,000 +the application is slowing down software bugs and maybe even security vulnerabilities. + +62 +00:04:00,000 --> 00:04:02,000 +Then comes your infrastructure. + +63 +00:04:02,000 --> 00:04:08,000 +When it comes to infrastructure, this is going to refer to overseeing the entire IT infrastructure + +64 +00:04:08,000 --> 00:04:14,000 +of an organization that includes network components, data centers, cloud services, and other critical + +65 +00:04:14,000 --> 00:04:14,000 +elements. + +66 +00:04:14,000 --> 00:04:23,000 +Now I'm talking everything servers and routers in particular, our servers, uh, servers that generate + +67 +00:04:23,000 --> 00:04:28,000 +and send the data switches that passes the data and routes, routers that moves the data across multiple + +68 +00:04:28,000 --> 00:04:29,000 +networks. + +69 +00:04:29,000 --> 00:04:32,000 +The big goal here is network traffic analysis. + +70 +00:04:32,000 --> 00:04:38,000 +You're going to have a ton of traffic flowing through your coming out of your servers, into those switches, + +71 +00:04:38,000 --> 00:04:40,000 +across those lines, over those routers. + +72 +00:04:40,000 --> 00:04:42,000 +You have to analyze the network traffic. + +73 +00:04:42,000 --> 00:04:48,000 +You need to see what's happening across routers, switches, firewalls and other network and device. + +74 +00:04:48,000 --> 00:04:52,000 +Remember, data originates from things like servers and workstation. + +75 +00:04:52,000 --> 00:04:56,000 +And as that data starts to move across that network, you have all kinds of devices that you need to + +76 +00:04:56,000 --> 00:04:58,000 +keep a good eye on. + +77 +00:04:58,000 --> 00:04:59,000 +Check the performance. + +78 +00:04:59,000 --> 00:05:02,000 +Is the network getting slower or faster? + +79 +00:05:02,000 --> 00:05:04,000 +The goal here is to ensure that the infrastructure is integrity. + +80 +00:05:04,000 --> 00:05:07,000 +It means nobody's modifying data like bad people. + +81 +00:05:07,000 --> 00:05:10,000 +Data isn't being stolen for confidentiality. + +82 +00:05:10,000 --> 00:05:15,000 +And of course the actual availability of the network is up. + +83 +00:05:15,000 --> 00:05:21,000 +This includes identifying particular security threats like network breaches, for example, like someone + +84 +00:05:21,000 --> 00:05:24,000 +unauthorized traffic, unauthorized devices in your network. + +85 +00:05:24,000 --> 00:05:25,000 +Unusual pattern. + +86 +00:05:25,000 --> 00:05:31,000 +Also, quite a lot of things here when you're thinking about monitoring your entire systems, whether + +87 +00:05:31,000 --> 00:05:37,000 +that's an individual system, your entire infrastructure, or all kinds of application, all of these + +88 +00:05:37,000 --> 00:05:38,000 +things needs monitoring. + +89 +00:05:39,000 --> 00:05:45,000 +If you don't monitor your systems, you will never know if there's problems in your network and you + +90 +00:05:45,000 --> 00:05:46,000 +probably will never fix it. + diff --git a/16 - Alerting and Monitoring IT/002 Monitoring Activities OB 4.4_en.srt b/16 - Alerting and Monitoring IT/002 Monitoring Activities OB 4.4_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..dc5400a9820b215c3177e75b720883dcc6b70ef0 --- /dev/null +++ b/16 - Alerting and Monitoring IT/002 Monitoring Activities OB 4.4_en.srt @@ -0,0 +1,460 @@ +1 +00:00:00,000 --> 00:00:04,000 +When it comes to monitoring your network, there are certain activities that you're going to need to + +2 +00:00:04,000 --> 00:00:06,000 +get done to ensure it's done efficiently. + +3 +00:00:06,000 --> 00:00:09,000 +In a previous video, I talked about why monitoring is important. + +4 +00:00:09,000 --> 00:00:13,000 +Without monitoring, we're not going to know if we're being attacked without monitoring. + +5 +00:00:13,000 --> 00:00:15,000 +We're not going to know if our network is slowing down. + +6 +00:00:16,000 --> 00:00:22,000 +When we monitor and we do it effectively, we're able to pick up on security breaches quickly. + +7 +00:00:22,000 --> 00:00:26,000 +That way, if a breach does happen, we could minimize the impact because we're probably going to fix + +8 +00:00:26,000 --> 00:00:32,000 +it right away versus if you're not monitoring, here's a set of activities that I want to talk about + +9 +00:00:32,000 --> 00:00:38,000 +in this video that we should be doing, such as aggregating those log files, archiving them, and report + +10 +00:00:38,000 --> 00:00:41,000 +it to the correct authority, even quarantine certain systems. + +11 +00:00:41,000 --> 00:00:52,000 +Let's get into this on a network, you're going to have logs from all kinds of devices, multiple multiple + +12 +00:00:52,000 --> 00:00:58,000 +sources or various sources such as servers, applications, network devices, and security systems. + +13 +00:00:58,000 --> 00:01:02,000 +But just not that you're going to have switches and routers. + +14 +00:01:02,000 --> 00:01:08,000 +If you think about the network device, everything has log files, including an application log. + +15 +00:01:08,000 --> 00:01:13,000 +Aggregation is about collecting and consolidating these log files. + +16 +00:01:13,000 --> 00:01:20,000 +We're going to put them hopefully in a central location or a central repository, some kind of a database. + +17 +00:01:20,000 --> 00:01:26,000 +Later on in this course we're going to cover Siem systems or security information and event management + +18 +00:01:26,000 --> 00:01:27,000 +systems. + +19 +00:01:27,000 --> 00:01:32,000 +This helps to simplify the analysis aids and detecting patterns or any kind of anomalies within the + +20 +00:01:32,000 --> 00:01:33,000 +log files themselves. + +21 +00:01:33,000 --> 00:01:37,000 +We need this for monitoring our network. + +22 +00:01:37,000 --> 00:01:43,000 +You can't monitor your network without a good, good theme system. + +23 +00:01:43,000 --> 00:01:45,000 +And the reason is because it's just too many log files. + +24 +00:01:45,000 --> 00:01:49,000 +You know how many entries are in a log file, and if you have thousands of devices, you're going to + +25 +00:01:49,000 --> 00:01:53,000 +have thousands of log files to have one user going through it. + +26 +00:01:53,000 --> 00:01:55,000 +It's probably not efficient. + +27 +00:01:56,000 --> 00:02:02,000 +Alert him when you are working on your network and you're gathering all of these log files. + +28 +00:02:03,000 --> 00:02:11,000 +You're going to have to configure your system, your login system, or your monitoring system to look + +29 +00:02:11,000 --> 00:02:17,000 +for certain things that should alert an administrator, such as if this breach happened. + +30 +00:02:17,000 --> 00:02:19,000 +Alert the administrator if this threshold meets. + +31 +00:02:19,000 --> 00:02:20,000 +Alert the administrator. + +32 +00:02:20,000 --> 00:02:25,000 +So this refers to the process of configuring security systems to notify the administrator or security + +33 +00:02:25,000 --> 00:02:27,000 +team of potential security incident. + +34 +00:02:28,000 --> 00:02:29,000 +The key feature here. + +35 +00:02:30,000 --> 00:02:36,000 +Effective alerting should minimize false positives and and provide actionable insights. + +36 +00:02:36,000 --> 00:02:39,000 +They include meeting certain thresholds or triggers. + +37 +00:02:39,000 --> 00:02:40,000 +So let me explain. + +38 +00:02:41,000 --> 00:02:42,000 +A lot of times. + +39 +00:02:43,000 --> 00:02:49,000 +The administrators don't have the time to go to each machine and check things. + +40 +00:02:49,000 --> 00:02:54,000 +One of the main jobs is to make sure that you fix things before they break. + +41 +00:02:54,000 --> 00:03:01,000 +For example, you can set an alert on a server that when the server hard drive meets, 80%, fail to + +42 +00:03:01,000 --> 00:03:08,000 +send an alert when the when it's reached that 80%, let's say 81%, it sends an alert to the administrator. + +43 +00:03:08,000 --> 00:03:13,000 +Alerting is important because now the administrator can fix the problem of the server running out of + +44 +00:03:13,000 --> 00:03:15,000 +drive space before it actually runs out of drive space. + +45 +00:03:15,000 --> 00:03:20,000 +Alerting is important, so the threshold here would have been 80%. + +46 +00:03:21,000 --> 00:03:22,000 +Scanning. + +47 +00:03:22,000 --> 00:03:26,000 +Now, we talked about different kinds of vulnerability scanning. + +48 +00:03:26,000 --> 00:03:28,000 +But scanning is not something you do once. + +49 +00:03:28,000 --> 00:03:30,000 +It's something you do on a consistent basis. + +50 +00:03:30,000 --> 00:03:36,000 +A scan that was done today, and let's say you cleared the scan, no vulnerabilities, tells me that + +51 +00:03:36,000 --> 00:03:40,000 +as of that time on the report, your system was secure. + +52 +00:03:40,000 --> 00:03:43,000 +What happens one second later is different. + +53 +00:03:43,000 --> 00:03:47,000 +One second later, a new vulnerability could have could have been introduced, or a new system could + +54 +00:03:47,000 --> 00:03:50,000 +have lost an update, or a new system could have just been hacked. + +55 +00:03:51,000 --> 00:03:56,000 +Scanning includes various types of security scans, vulnerability scans, network and application scan. + +56 +00:03:56,000 --> 00:04:01,000 +The goal is to identify vulnerabilities, maybe even misconfigurations or other security weakness. + +57 +00:04:01,000 --> 00:04:05,000 +Now make sure you use a good vulnerability scanner in the scanning section of this course. + +58 +00:04:05,000 --> 00:04:08,000 +I did talk of, uh, things like the Nexus scanner. + +59 +00:04:10,000 --> 00:04:12,000 +Who are you going to report this to? + +60 +00:04:12,000 --> 00:04:20,000 +So report involves the generation of detailed reports about the security status of it, of the entire + +61 +00:04:20,000 --> 00:04:22,000 +entire, entire IT department. + +62 +00:04:22,000 --> 00:04:26,000 +Now, who are we going to be sending this to? + +63 +00:04:26,000 --> 00:04:32,000 +So these detailed reports are going to be sent out to management and potentially regulatory agencies. + +64 +00:04:32,000 --> 00:04:40,000 +Report includes vulnerabilities that was identified, the outcome of the scans, insights that what + +65 +00:04:40,000 --> 00:04:43,000 +we did and what can decision makers do about them. + +66 +00:04:45,000 --> 00:04:45,000 +Archiving. + +67 +00:04:45,000 --> 00:04:50,000 +Now, when it comes to these log files, it might be. + +68 +00:04:51,000 --> 00:04:56,000 +Best to not delete them after you finish analyzing them. + +69 +00:04:56,000 --> 00:05:03,000 +They are regulatory requirements in place that makes you keep those log files for a period of time. + +70 +00:05:03,000 --> 00:05:09,000 +Certain regulations may make you keep them for multiple years five, ten, 15 years. + +71 +00:05:10,000 --> 00:05:17,000 +This is the process of securely storing historical security data, such as logs and incident reports, + +72 +00:05:17,000 --> 00:05:18,000 +for future reference. + +73 +00:05:18,000 --> 00:05:25,000 +It's critical for compliance with legal and regulatory requirements as long as well as historical analysis. + +74 +00:05:26,000 --> 00:05:28,000 +Now two terms here. + +75 +00:05:28,000 --> 00:05:29,000 +I want you guys to know. + +76 +00:05:30,000 --> 00:05:32,000 +Quarantining and alert. + +77 +00:05:32,000 --> 00:05:32,000 +Tuning. + +78 +00:05:33,000 --> 00:05:41,000 +When a system is involved in some kind of security incident, you guys should be quarantining that system + +79 +00:05:41,000 --> 00:05:41,000 +of the network. + +80 +00:05:41,000 --> 00:05:42,000 +What does that mean? + +81 +00:05:42,000 --> 00:05:48,000 +So this involves isolating affected systems or components to prevent the spread of the threat. + +82 +00:05:48,000 --> 00:05:50,000 +Quarantine is often an immediate response. + +83 +00:05:50,000 --> 00:05:52,000 +So let me give you an example. + +84 +00:05:52,000 --> 00:05:59,000 +Let's say in the accounting department we found there's ten machines and we found six of them to have + +85 +00:05:59,000 --> 00:06:00,000 +a potential worm on it. + +86 +00:06:00,000 --> 00:06:02,000 +This worm seems to be spreading. + +87 +00:06:02,000 --> 00:06:05,000 +The best thing to do is unplug that system off the network, not system. + +88 +00:06:05,000 --> 00:06:06,000 +I'm sorry. + +89 +00:06:06,000 --> 00:06:09,000 +That segment, that entire accounting department. + +90 +00:06:09,000 --> 00:06:13,000 +That way it could stop that worm from trying to get out the segment. + +91 +00:06:13,000 --> 00:06:18,000 +Machines that are infected, those six machines, unplug them off the network, quarantine those things. + +92 +00:06:18,000 --> 00:06:20,000 +So that way the worm can't spread. + +93 +00:06:20,000 --> 00:06:25,000 +I would still disconnect the entire segment because we don't know if the other machines have it. + +94 +00:06:25,000 --> 00:06:33,000 +So remember quarantine is about removing, isolating, effective either an entire system or an entire + +95 +00:06:33,000 --> 00:06:35,000 +segment of the network. + +96 +00:06:35,000 --> 00:06:43,000 +Alert tuning refers to refining alerting mechanism to reduce false positives and ensures that alerts + +97 +00:06:43,000 --> 00:06:44,000 +are relevant. + +98 +00:06:45,000 --> 00:06:47,000 +So remember what false positive is. + +99 +00:06:47,000 --> 00:06:52,000 +It's when they say, hey, something is wrong, it's all right, but there's nothing wrong. + +100 +00:06:52,000 --> 00:06:56,000 +If you're alert in is not set up correctly, you bet your best bet. + +101 +00:06:56,000 --> 00:06:58,000 +You're going to get a lot of false positives. + +102 +00:06:58,000 --> 00:07:01,000 +You're going to run around fixing things that don't need fixing. + +103 +00:07:01,000 --> 00:07:08,000 +You have to adjust or tune your alerts to make sure that they don't overwhelm you with things that are + +104 +00:07:08,000 --> 00:07:09,000 +just not real. + +105 +00:07:09,000 --> 00:07:15,000 +This might involve adjusting thresholds, revising rules, or implementing more sophisticated detection + +106 +00:07:15,000 --> 00:07:16,000 +algorithms. + +107 +00:07:16,000 --> 00:07:19,000 +Sometimes the detection algorithms just don't work well. + +108 +00:07:20,000 --> 00:07:24,000 +Okay, we talked a lot about different things in this video. + +109 +00:07:24,000 --> 00:07:26,000 +I want you guys to keep in mind. + +110 +00:07:26,000 --> 00:07:31,000 +Then any kind of monitoring activity is going to be different for every organization. + +111 +00:07:31,000 --> 00:07:36,000 +Some of these things I mentioned is pretty common in most organizations, but some organizations have + +112 +00:07:36,000 --> 00:07:38,000 +their own policy procedures and more. + +113 +00:07:38,000 --> 00:07:41,000 +In particularly, every organization just uses different software. + +114 +00:07:41,000 --> 00:07:46,000 +So keep in mind that you're going to be doing these things in most companies, but keep in mind that + +115 +00:07:46,000 --> 00:07:49,000 +the software they use is probably going to be different. + diff --git a/16 - Alerting and Monitoring IT/003 Alerting and Monitoring Tools SIEM and DLP's OB 4.4_en.srt b/16 - Alerting and Monitoring IT/003 Alerting and Monitoring Tools SIEM and DLP's OB 4.4_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..df657eaefd523c1e0bb26d5a5190914a39d5bfa2 --- /dev/null +++ b/16 - Alerting and Monitoring IT/003 Alerting and Monitoring Tools SIEM and DLP's OB 4.4_en.srt @@ -0,0 +1,740 @@ +1 +00:00:00,000 --> 00:00:01,000 +In this section. + +2 +00:00:01,000 --> 00:00:02,000 +I've been talking about monitoring. + +3 +00:00:02,000 --> 00:00:09,000 +Now, what I want to show you guys are different things or tools that we can use to monitor our network. + +4 +00:00:09,000 --> 00:00:12,000 +Now, I want you guys to keep in mind for your exam. + +5 +00:00:12,000 --> 00:00:15,000 +You don't need to know how to use any of these tools. + +6 +00:00:15,000 --> 00:00:21,000 +You don't need to be installing things like vulnerability scanners or downloading that Splunk software, + +7 +00:00:21,000 --> 00:00:23,000 +or using McAfee DLP. + +8 +00:00:23,000 --> 00:00:25,000 +You don't need to do any of that. + +9 +00:00:25,000 --> 00:00:29,000 +What I do need you guys to know is the function. + +10 +00:00:29,000 --> 00:00:31,000 +What is the purpose of these things? + +11 +00:00:31,000 --> 00:00:36,000 +They might give you questions on the exam where they give you a problem and you're going to have to + +12 +00:00:36,000 --> 00:00:38,000 +say, well, this tool does that. + +13 +00:00:38,000 --> 00:00:41,000 +This is the tool that I can use to resolve that problem. + +14 +00:00:41,000 --> 00:00:41,000 +So let's get started. + +15 +00:00:41,000 --> 00:00:48,000 +So these are a wide variety of tools to ensure that the integrity and security of your systems stays + +16 +00:00:48,000 --> 00:00:48,000 +intact. + +17 +00:00:48,000 --> 00:00:49,000 +So let's get started. + +18 +00:00:49,000 --> 00:00:55,000 +The first thing I want to mention is something we call security content automation protocols. + +19 +00:00:55,000 --> 00:01:02,000 +What exactly is this or Scap well, this is a suite of standards for automating the process of configuring. + +20 +00:01:02,000 --> 00:01:08,000 +Now this is by the way is a Cisco based thing configuring a monitor and network devices for compliance + +21 +00:01:08,000 --> 00:01:10,000 +with a security policy. + +22 +00:01:10,000 --> 00:01:13,000 +So this thing here could configure and monitor. + +23 +00:01:13,000 --> 00:01:16,000 +Keyboard is monitor because that's the part we need. + +24 +00:01:16,000 --> 00:01:17,000 +What is it going to be used for. + +25 +00:01:17,000 --> 00:01:19,000 +Well it's used for vulnerabilities vulnerability management. + +26 +00:01:19,000 --> 00:01:25,000 +It could detect that measuring how the device is performing and whether it meets certain policies. + +27 +00:01:26,000 --> 00:01:33,000 +SAP can automatically verify if patches were done, check system security configurations and even exam + +28 +00:01:33,000 --> 00:01:35,000 +if there's some kind of flaw against it. + +29 +00:01:36,000 --> 00:01:38,000 +When it comes to benchmarking. + +30 +00:01:39,000 --> 00:01:42,000 +Benchmarking is industries best practices. + +31 +00:01:42,000 --> 00:01:44,000 +For example, let me give you a benchmark. + +32 +00:01:44,000 --> 00:01:48,000 +Websites should load in 0.5 of a second. + +33 +00:01:48,000 --> 00:01:49,000 +That's an industry standard. + +34 +00:01:49,000 --> 00:01:54,000 +How fast the general website should load when let's say there's 500 users. + +35 +00:01:54,000 --> 00:01:58,000 +If that's a benchmark, then your website should be able to load that quick. + +36 +00:01:58,000 --> 00:01:59,000 +So it's a security. + +37 +00:01:59,000 --> 00:02:07,000 +It's a rip in security refers to a standardized set of best practices and configuration that are known + +38 +00:02:07,000 --> 00:02:09,000 +to ensure a high level of security. + +39 +00:02:09,000 --> 00:02:18,000 +So when we talk security, generally when we configure this particular device, what is the best practices + +40 +00:02:18,000 --> 00:02:19,000 +for configuring this device. + +41 +00:02:19,000 --> 00:02:21,000 +And it's wireless. + +42 +00:02:21,000 --> 00:02:24,000 +That would be the benchmark that we would need to make sure that we reach that. + +43 +00:02:24,000 --> 00:02:30,000 +What would be the speed or the minimum, uh, resources that should always be available when this device + +44 +00:02:30,000 --> 00:02:32,000 +is actually being used by users. + +45 +00:02:32,000 --> 00:02:34,000 +Those are all benchmarks. + +46 +00:02:34,000 --> 00:02:40,000 +Organization uses these to configure systems and application to an industry accepted standard. + +47 +00:02:41,000 --> 00:02:44,000 +Now agents versus Agentless. + +48 +00:02:44,000 --> 00:02:49,000 +When you're monitoring systems, some software will have to install an agent. + +49 +00:02:49,000 --> 00:02:55,000 +Software agents are installed on servers or devices to monitor, collect and send data to a central + +50 +00:02:55,000 --> 00:02:55,000 +server. + +51 +00:02:55,000 --> 00:02:58,000 +We'll talk about that central server in a minute, but. + +52 +00:02:59,000 --> 00:03:06,000 +If you have a central software that goes out and grabbed all the log files from the systems, the question + +53 +00:03:06,000 --> 00:03:08,000 +is, how do you know that? + +54 +00:03:09,000 --> 00:03:12,000 +How do you know that it's actually functioning well? + +55 +00:03:12,000 --> 00:03:18,000 +Well, a lot of times a decentral server software generally requires some kind of software to be installed + +56 +00:03:18,000 --> 00:03:19,000 +on the workstation. + +57 +00:03:19,000 --> 00:03:24,000 +Those software on the workstation can tell the main server that it sent the log files already. + +58 +00:03:24,000 --> 00:03:28,000 +So software agents works well. + +59 +00:03:28,000 --> 00:03:31,000 +Agent less software is when there's nothing to install. + +60 +00:03:31,000 --> 00:03:37,000 +Agent less systems monitor the devices without installing dedicated software on them, often utilizing + +61 +00:03:37,000 --> 00:03:39,000 +existing protocols. + +62 +00:03:39,000 --> 00:03:44,000 +I'm going to tell you from my experience, a lot of these software that captures log files will generally + +63 +00:03:44,000 --> 00:03:48,000 +use some kind of agents on the machine, and these do a really good job. + +64 +00:03:48,000 --> 00:03:54,000 +Now, some famous ones actually are agent less and they also do a good job, but I like the ones with + +65 +00:03:54,000 --> 00:03:55,000 +the agents. + +66 +00:03:55,000 --> 00:04:01,000 +Comparison agent based solutions can provide more detailed data, but can be more resource intensive. + +67 +00:04:01,000 --> 00:04:07,000 +Yes, because they actually have a software and they can take anything they want if you have agent less. + +68 +00:04:07,000 --> 00:04:11,000 +In other words, the central login server doesn't install anything on any machine. + +69 +00:04:12,000 --> 00:04:19,000 +It's limited to whatever protocol that desktop or server is running, other servers running, and only + +70 +00:04:19,000 --> 00:04:21,000 +what it can get out of that. + +71 +00:04:21,000 --> 00:04:24,000 +So it's probably going to be less comprehensive. + +72 +00:04:25,000 --> 00:04:30,000 +One software that networks today has to have. + +73 +00:04:30,000 --> 00:04:35,000 +In my opinion, the only reason you probably wouldn't have it is the incredible cost associated with + +74 +00:04:35,000 --> 00:04:35,000 +it. + +75 +00:04:36,000 --> 00:04:38,000 +Midsize and large businesses need it. + +76 +00:04:38,000 --> 00:04:39,000 +Here's the thing. + +77 +00:04:40,000 --> 00:04:49,000 +It is humanly impossible for humans to read log files on more than a few machines. + +78 +00:04:50,000 --> 00:04:56,000 +Computers nowadays generate thousands of entries depending on like a server every minute. + +79 +00:04:57,000 --> 00:05:00,000 +It is impossible for humans to read that. + +80 +00:05:01,000 --> 00:05:07,000 +And, you know, I always say this if you're capturing detailed log information and nobody's reading + +81 +00:05:07,000 --> 00:05:13,000 +them or nothing is reading them, it kind of defeats the purpose about what they are. + +82 +00:05:14,000 --> 00:05:17,000 +It kind of defeats the purpose on why are you even doing that? + +83 +00:05:17,000 --> 00:05:22,000 +If you capture camera footage and nobody ever looks at them, it's probably never it's probably not + +84 +00:05:22,000 --> 00:05:26,000 +very useful because then people can steal things and you probably wouldn't know. + +85 +00:05:27,000 --> 00:05:27,000 +Right. + +86 +00:05:27,000 --> 00:05:32,000 +Or security incidents can happen in a network and no one would know because no one was up watching the + +87 +00:05:32,000 --> 00:05:33,000 +log files. + +88 +00:05:34,000 --> 00:05:39,000 +Now because it's humanly impossible to read log files. + +89 +00:05:39,000 --> 00:05:41,000 +We can have a computer do it. + +90 +00:05:41,000 --> 00:05:42,000 +We can have a piece of software. + +91 +00:05:42,000 --> 00:05:43,000 +Do it. + +92 +00:05:43,000 --> 00:05:46,000 +This thing is called security information and event management. + +93 +00:05:47,000 --> 00:05:54,000 +Now, what this Siem system does is that it's basically going to be a correlation of log files. + +94 +00:05:54,000 --> 00:06:01,000 +It's a solution that provides real time analysis of security alerts by applications and network cards. + +95 +00:06:01,000 --> 00:06:03,000 +It's used for log management. + +96 +00:06:03,000 --> 00:06:04,000 +That's its big thing. + +97 +00:06:04,000 --> 00:06:06,000 +It correlates events. + +98 +00:06:06,000 --> 00:06:10,000 +It alerts administrator and give you good reports on the systems that are out there. + +99 +00:06:11,000 --> 00:06:15,000 +This helps detect, understand and respond to security incidents. + +100 +00:06:15,000 --> 00:06:18,000 +Here's a quick picture of a Siem system. + +101 +00:06:18,000 --> 00:06:19,000 +So. + +102 +00:06:20,000 --> 00:06:22,000 +This system has what's called collectors. + +103 +00:06:22,000 --> 00:06:28,000 +And you see all those collectors, these collectors go out and grab the log files from all of these + +104 +00:06:28,000 --> 00:06:36,000 +different devices that we have, such as the IPS, the routers, the web servers, applications across + +105 +00:06:36,000 --> 00:06:36,000 +them. + +106 +00:06:36,000 --> 00:06:40,000 +They go out and grab all these log files from these devices. + +107 +00:06:40,000 --> 00:06:44,000 +Then what it does is it feeds it into this giant database. + +108 +00:06:44,000 --> 00:06:48,000 +This database now is then analyzed by a central engine. + +109 +00:06:48,000 --> 00:06:54,000 +The central engine will then has a beautiful dashboard on it. + +110 +00:06:54,000 --> 00:06:57,000 +You can go and has specific algorithms and then you can set up alerts. + +111 +00:06:57,000 --> 00:06:59,000 +It correlates these log files. + +112 +00:06:59,000 --> 00:07:02,000 +This is the thing that reads the log files for you. + +113 +00:07:02,000 --> 00:07:04,000 +So remember what this is. + +114 +00:07:04,000 --> 00:07:10,000 +Remember what a Siem system is is basically a central login system that captures all the logs and analyzes + +115 +00:07:10,000 --> 00:07:11,000 +it for you. + +116 +00:07:11,000 --> 00:07:14,000 +Now antivirus. + +117 +00:07:14,000 --> 00:07:16,000 +We spoke about anti-malware already. + +118 +00:07:16,000 --> 00:07:22,000 +When you're monitoring your network, the best one or the best things you can do is have anti-malware + +119 +00:07:22,000 --> 00:07:29,000 +antivirus software detect, prevent, remove viruses, including all types of worms and trojans. + +120 +00:07:29,000 --> 00:07:33,000 +But remember, antivirus sends alerts a lot of corporate antivirus. + +121 +00:07:33,000 --> 00:07:40,000 +What they do is they have a central server that then installs agent antivirus on all the machines that + +122 +00:07:40,000 --> 00:07:42,000 +if you have a workstation, like in the corner over there. + +123 +00:07:43,000 --> 00:07:45,000 +That gets a potential virus. + +124 +00:07:45,000 --> 00:07:47,000 +It then reports it back to the central server. + +125 +00:07:47,000 --> 00:07:50,000 +This way we can easily pick up that. + +126 +00:07:50,000 --> 00:07:50,000 +You know what? + +127 +00:07:50,000 --> 00:07:53,000 +Something is wrong on that particular machine. + +128 +00:07:54,000 --> 00:07:59,000 +Another important software you're going to want to know for your exam is something we call data loss + +129 +00:07:59,000 --> 00:08:01,000 +prevention or DLP. + +130 +00:08:01,000 --> 00:08:03,000 +This can get very big and very complex. + +131 +00:08:03,000 --> 00:08:07,000 +I'm going to try to give you a simple explanation for your exam DLP. + +132 +00:08:07,000 --> 00:08:16,000 +Identify, monitor and protect data in use in motion and arrest through deep content inspection and + +133 +00:08:16,000 --> 00:08:18,000 +contextual security analysis. + +134 +00:08:19,000 --> 00:08:24,000 +Main thing this helps to prevent sensitive data from being lost, misused, or accessed by unauthorized + +135 +00:08:24,000 --> 00:08:24,000 +users. + +136 +00:08:25,000 --> 00:08:27,000 +If you're wondering, Andrew, what the hell is all that mean? + +137 +00:08:27,000 --> 00:08:29,000 +I'm going to give you a couple examples. + +138 +00:08:29,000 --> 00:08:31,000 +So here's what DLP does. + +139 +00:08:32,000 --> 00:08:40,000 +DLP stops data from leaving the organization that shouldn't be leaving DLP. + +140 +00:08:40,000 --> 00:08:46,000 +Software is configured to stop things like emails going out that contains sensitive data. + +141 +00:08:46,000 --> 00:08:56,000 +For example, let's say you have a user that types credit card numbers and then emails it out to customers + +142 +00:08:56,000 --> 00:08:57,000 +or vendors. + +143 +00:08:57,000 --> 00:09:02,000 +Maybe you don't want that and you shouldn't have that because it's clear text anytime somebody tries + +144 +00:09:02,000 --> 00:09:08,000 +to send confidential data from your organization out. + +145 +00:09:08,000 --> 00:09:13,000 +DLP software can stop that, or at least alert them, hey, you shouldn't do that. + +146 +00:09:14,000 --> 00:09:18,000 +On our we use office 365. + +147 +00:09:18,000 --> 00:09:26,000 +Office 365 has policies that you can configure for DLP that if somebody tries to attempt to send, uh, + +148 +00:09:26,000 --> 00:09:31,000 +numbers that looks like credit card numbers, Social Security numbers and health care information, + +149 +00:09:31,000 --> 00:09:34,000 +it can actually detect that and stop it from happening. + +150 +00:09:34,000 --> 00:09:40,000 +DLP stops confidential or sensitive data from leaving the organization. + +151 +00:09:40,000 --> 00:09:41,000 +How does it do it? + +152 +00:09:41,000 --> 00:09:45,000 +It does it by content inspection. + +153 +00:09:45,000 --> 00:09:48,000 +It's looking to see okay, what exactly is that particular content. + +154 +00:09:50,000 --> 00:09:57,000 +That way the data the sensitive data is never lost or misused or sent to unauthorized users. + +155 +00:09:57,000 --> 00:10:00,000 +So DLP is very famous in organizations today. + +156 +00:10:00,000 --> 00:10:09,000 +If you run companies where you have a high potential that your users can send confidential data such + +157 +00:10:09,000 --> 00:10:16,000 +as people's email and not even a credit card, um, health information, even your own company's confidential + +158 +00:10:16,000 --> 00:10:17,000 +data. + +159 +00:10:17,000 --> 00:10:20,000 +Configure and install DLP software. + +160 +00:10:21,000 --> 00:10:26,000 +Simple network management protocol SNMp traps. + +161 +00:10:26,000 --> 00:10:32,000 +So SNMp is basically a way to track and correlate logs. + +162 +00:10:32,000 --> 00:10:38,000 +So these traps are alerts sent by network devices to management stations indicate an event or change + +163 +00:10:38,000 --> 00:10:39,000 +has occurred. + +164 +00:10:40,000 --> 00:10:42,000 +The use of manager in a monitoring network and devices. + +165 +00:10:42,000 --> 00:10:49,000 +Notice is network management protocol for managing and monitoring devices, helping administrators know + +166 +00:10:49,000 --> 00:10:50,000 +the health of the device. + +167 +00:10:50,000 --> 00:10:57,000 +So if anybody changes anything on the device, whether it's configurations of the devices or something + +168 +00:10:57,000 --> 00:11:02,000 +that you set up like a threshold, as happened on on the device, this particular trap can send you + +169 +00:11:02,000 --> 00:11:03,000 +alerts. + +170 +00:11:05,000 --> 00:11:06,000 +Net flow. + +171 +00:11:06,000 --> 00:11:08,000 +Net flow is basically a protocol. + +172 +00:11:08,000 --> 00:11:14,000 +Another Cisco thing for collecting IP traffic information and monitoring traffic flow. + +173 +00:11:15,000 --> 00:11:20,000 +It's valuable for network traffic analysis, helping to understand traffic pattern usage and detecting + +174 +00:11:20,000 --> 00:11:20,000 +anomalies. + +175 +00:11:21,000 --> 00:11:26,000 +Now NetFlow, I want you guys to know for your exam that what this is going to do. + +176 +00:11:26,000 --> 00:11:31,000 +Its main job is about analyzing network traffic. + +177 +00:11:31,000 --> 00:11:36,000 +So if you utilize a lot of Cisco equipment, this is something you can use to help you monitor your + +178 +00:11:36,000 --> 00:11:36,000 +traffic. + +179 +00:11:37,000 --> 00:11:44,000 +Vulnerability scanners we covered already things like the Nexus security scanner tools to help us assess + +180 +00:11:44,000 --> 00:11:47,000 +computers and find non vulnerabilities on our systems. + +181 +00:11:47,000 --> 00:11:53,000 +This we went over when we talked about vulnerabilities in the previous uh, earlier in the class. + +182 +00:11:53,000 --> 00:11:53,000 +All right. + +183 +00:11:53,000 --> 00:12:00,000 +So we just went over quite a lot of things there when it comes to different kinds of alerting tools. + +184 +00:12:00,000 --> 00:12:02,000 +Although a lot some of it was repeated. + +185 +00:12:02,000 --> 00:12:08,000 +Keep in mind these are things that we can use to keep us alert and monitor our systems. + diff --git a/16 - Alerting and Monitoring IT/004 Quick Quiz.html b/16 - Alerting and Monitoring IT/004 Quick Quiz.html new file mode 100644 index 0000000000000000000000000000000000000000..25840e6c4b0d9155337aa1717f730fb2f27085fe --- /dev/null +++ b/16 - Alerting and Monitoring IT/004 Quick Quiz.html @@ -0,0 +1,479 @@ + + + + + + + Quiz + + + + +
+
+

+

+
+
+
+ Score: 999 of + 999% +
+
Correct: 999
+
Incorrect: 999
+
+ +
+ + + + +
+ + + + diff --git a/17 - Enhance Security/001 Firewall Configuration OB 4.5_en.srt b/17 - Enhance Security/001 Firewall Configuration OB 4.5_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..ed5029356e96515d58ba828d74238e12a9ae561b --- /dev/null +++ b/17 - Enhance Security/001 Firewall Configuration OB 4.5_en.srt @@ -0,0 +1,1160 @@ +1 +00:00:00,000 --> 00:00:07,000 +In this video, I'm going to be talking about firewalls in particularly exactly how do they operate? + +2 +00:00:07,000 --> 00:00:12,000 +How do they block traffic from coming into your network and destroying your systems. + +3 +00:00:12,000 --> 00:00:20,000 +So we're going to be talking about things such as access rules, access lists, the protocols and screened + +4 +00:00:20,000 --> 00:00:21,000 +subnet or DMZ. + +5 +00:00:21,000 --> 00:00:25,000 +Now before I get started here, I really want to discuss something with you. + +6 +00:00:25,000 --> 00:00:29,000 +I am actually going to show you how to configure the Sonicwall. + +7 +00:00:29,000 --> 00:00:32,000 +I'm going to add a rule to it and show you how that's done, but I'm going to do that towards the end + +8 +00:00:32,000 --> 00:00:33,000 +of the video. + +9 +00:00:34,000 --> 00:00:41,000 +I want you guys to remember your exam will not ask you to configure firewalls. + +10 +00:00:41,000 --> 00:00:50,000 +No security vendor neutral security exam will ever do that unless the only certification that does that + +11 +00:00:50,000 --> 00:00:56,000 +is if you're taking a certification from Sonicwall, from Cisco, from Palo Alto, and so on. + +12 +00:00:56,000 --> 00:01:01,000 +The reason is because every single firewall is configured differently. + +13 +00:01:01,000 --> 00:01:06,000 +So the configuration that I'm going to show you at the end of the video is just for your visualization + +14 +00:01:06,000 --> 00:01:06,000 +purposes. + +15 +00:01:06,000 --> 00:01:08,000 +So you can see exactly how it's done. + +16 +00:01:08,000 --> 00:01:13,000 +But remember, if you go to configure a Sonicwall and it's running on a different version, it's a different + +17 +00:01:13,000 --> 00:01:14,000 +device, it will look different. + +18 +00:01:14,000 --> 00:01:19,000 +And if you do any other firewall but a sonicwall, I'm pretty sure it's going to be completely different. + +19 +00:01:19,000 --> 00:01:24,000 +Although the theory is the same, the the way the configurations are done is different. + +20 +00:01:24,000 --> 00:01:25,000 +So let's get started. + +21 +00:01:26,000 --> 00:01:28,000 +When I'm ready to configure it, I will let you know. + +22 +00:01:28,000 --> 00:01:29,000 +So if you want to watch it, you you could. + +23 +00:01:29,000 --> 00:01:31,000 +If not you don't have to. + +24 +00:01:31,000 --> 00:01:32,000 +Firewall. + +25 +00:01:32,000 --> 00:01:35,000 +We talked about firewalls earlier in the class. + +26 +00:01:35,000 --> 00:01:41,000 +By default there are security devices that monitors and filters incoming and outgoing traffic or particularly + +27 +00:01:41,000 --> 00:01:42,000 +network traffic. + +28 +00:01:42,000 --> 00:01:46,000 +They basically have to establish organization security policies. + +29 +00:01:46,000 --> 00:01:48,000 +What we let in and what we let out. + +30 +00:01:48,000 --> 00:01:51,000 +At the most basic, it's a barrier between public and private. + +31 +00:01:51,000 --> 00:01:55,000 +At the most basic level, it blocks all ports and all traffic coming in. + +32 +00:01:55,000 --> 00:01:56,000 +How does it do it? + +33 +00:01:56,000 --> 00:02:00,000 +Well, it does it with rules, access lists and protocols, these three things. + +34 +00:02:00,000 --> 00:02:03,000 +And then we'll talk about what exactly is a screen subnet. + +35 +00:02:04,000 --> 00:02:06,000 +So let's take a look. + +36 +00:02:06,000 --> 00:02:09,000 +There's something we call rules and access lists. + +37 +00:02:09,000 --> 00:02:10,000 +All right. + +38 +00:02:10,000 --> 00:02:13,000 +How do we implement rules? + +39 +00:02:13,000 --> 00:02:13,000 +All right. + +40 +00:02:13,000 --> 00:02:15,000 +We do that with the access list. + +41 +00:02:15,000 --> 00:02:16,000 +Let's take a look. + +42 +00:02:16,000 --> 00:02:17,000 +What is rules? + +43 +00:02:17,000 --> 00:02:22,000 +Firewall rules are specific configurations that control how the firewall operates. + +44 +00:02:22,000 --> 00:02:26,000 +These rules determine which traffic should be allowed or block. + +45 +00:02:26,000 --> 00:02:30,000 +Now these rules are placed on an access list. + +46 +00:02:30,000 --> 00:02:37,000 +The access list are a series of commands or rules applied to the firewall, which would selectively + +47 +00:02:37,000 --> 00:02:42,000 +filter traffic based on the source and destination address protocols and ports. + +48 +00:02:42,000 --> 00:02:48,000 +Now, for example, a rule might specify that all inbound traffic on port 80 is allowed while they don't + +49 +00:02:48,000 --> 00:02:49,000 +allow port 23. + +50 +00:02:49,000 --> 00:02:52,000 +Now you have to know ports and protocols. + +51 +00:02:52,000 --> 00:02:55,000 +Ports and protocol is how network communications are done. + +52 +00:02:55,000 --> 00:02:57,000 +For example, web traffic comes in on port 80. + +53 +00:02:57,000 --> 00:03:00,000 +Secure web traffic on port 443. + +54 +00:03:02,000 --> 00:03:04,000 +Now screened subnet. + +55 +00:03:04,000 --> 00:03:13,000 +This is important to know because if your organization is going to be doing any kind of, uh, external + +56 +00:03:13,000 --> 00:03:21,000 +server hosting internally, which means you actually keep external servers in your premises, you cannot + +57 +00:03:21,000 --> 00:03:22,000 +have let's move that down. + +58 +00:03:22,000 --> 00:03:28,000 +You cannot have those externally facing servers in your lab. + +59 +00:03:28,000 --> 00:03:29,000 +Let me show you guys this diagram. + +60 +00:03:29,000 --> 00:03:30,000 +Watch this. + +61 +00:03:30,000 --> 00:03:36,000 +So this external router which is connected to the external network this is going to connect to the internet. + +62 +00:03:37,000 --> 00:03:42,000 +When traffic from the internet comes into your network because they want to access. + +63 +00:03:42,000 --> 00:03:44,000 +This is a web server, mail server. + +64 +00:03:44,000 --> 00:03:45,000 +This is a DNS server. + +65 +00:03:45,000 --> 00:03:48,000 +When traffic from the internet comes in and they want to access. + +66 +00:03:48,000 --> 00:03:50,000 +This is your firewall, by the way. + +67 +00:03:50,000 --> 00:03:54,000 +Uh, when they want to access this web server, they go here. + +68 +00:03:54,000 --> 00:03:56,000 +This is the DMZ. + +69 +00:03:56,000 --> 00:04:00,000 +A DMZ is known as a screen subnet or demilitarized zone. + +70 +00:04:00,000 --> 00:04:01,000 +They're going to go here. + +71 +00:04:01,000 --> 00:04:04,000 +They're going to grab the web page and they're going to go right back out. + +72 +00:04:04,000 --> 00:04:10,000 +Now this is good because notice that you don't have public traffic coming into your internal LAN. + +73 +00:04:10,000 --> 00:04:15,000 +If the internal LAN wants to access web pages or something, they're just going to go here and it's + +74 +00:04:15,000 --> 00:04:17,000 +going to give it right back to them. + +75 +00:04:17,000 --> 00:04:25,000 +This way you never have internal I'm sorry, external web traffic coming in to your internal network. + +76 +00:04:25,000 --> 00:04:30,000 +Now you can actually do this on a small device like this okay. + +77 +00:04:30,000 --> 00:04:30,000 +So keep that in mind. + +78 +00:04:30,000 --> 00:04:32,000 +I'm actually going to show you that in a few minutes. + +79 +00:04:32,000 --> 00:04:34,000 +So what exactly is this? + +80 +00:04:34,000 --> 00:04:40,000 +Well, a screen subnet or DMZ is a physical or logical segmentation subnetwork that contains and exposes + +81 +00:04:40,000 --> 00:04:43,000 +an organization external facing services. + +82 +00:04:43,000 --> 00:04:48,000 +Those external facing services, 99% of the time is going to be web servers to an untrusted network. + +83 +00:04:48,000 --> 00:04:54,000 +Usually the internet firewalls are configured to to allow limited traffic from the DMZ to the internal + +84 +00:04:54,000 --> 00:04:55,000 +network with strict rules. + +85 +00:04:55,000 --> 00:05:01,000 +Sometimes we might allow certain traffic from the DMZ to that internal. + +86 +00:05:01,000 --> 00:05:03,000 +So that's what this is. + +87 +00:05:03,000 --> 00:05:04,000 +Why do we want a DMZ? + +88 +00:05:04,000 --> 00:05:08,000 +DMZ are used to host publicly accessible servers. + +89 +00:05:09,000 --> 00:05:11,000 +Um, if you have any server. + +90 +00:05:12,000 --> 00:05:14,000 +That is going to be publicly accessible. + +91 +00:05:14,000 --> 00:05:19,000 +Web servers, mail servers, DNS servers more than likely. + +92 +00:05:19,000 --> 00:05:22,000 +You can also have different kinds of application servers. + +93 +00:05:22,000 --> 00:05:25,000 +Maybe you have specific people outside it's going to access. + +94 +00:05:25,000 --> 00:05:26,000 +Put them in the DMZ. + +95 +00:05:27,000 --> 00:05:28,000 +Okay. + +96 +00:05:28,000 --> 00:05:37,000 +Now the part of the video that's remember for your exam before we move on to this, a firewall allows + +97 +00:05:37,000 --> 00:05:39,000 +traffic in and out based on the rules. + +98 +00:05:39,000 --> 00:05:43,000 +These rules are going to be basically stored on what's called an access list. + +99 +00:05:43,000 --> 00:05:46,000 +You have to know ports and protocol when configuring your rules. + +100 +00:05:46,000 --> 00:05:49,000 +These rules is what allow and denies things coming in and out. + +101 +00:05:49,000 --> 00:05:54,000 +If you're hosting publicly accessible servers, make sure you implement a DMZ. + +102 +00:05:54,000 --> 00:05:58,000 +Don't put publicly accessible servers in the actual LAN itself. + +103 +00:05:59,000 --> 00:06:02,000 +All right, if you're done, you can turn the video off right now. + +104 +00:06:02,000 --> 00:06:04,000 +That's all you need to know for your exam. + +105 +00:06:04,000 --> 00:06:08,000 +But if you want to see how to configure this thing, let's have some fun with this device. + +106 +00:06:09,000 --> 00:06:11,000 +Let's take a look at an access list. + +107 +00:06:11,000 --> 00:06:14,000 +Let's make a quick rule inside of it. + +108 +00:06:14,000 --> 00:06:15,000 +So let's go into this. + +109 +00:06:16,000 --> 00:06:17,000 +Uh, I have to be shut off. + +110 +00:06:17,000 --> 00:06:18,000 +Presentation. + +111 +00:06:20,000 --> 00:06:21,000 +All right, here we go. + +112 +00:06:21,000 --> 00:06:22,000 +Where are we? + +113 +00:06:22,000 --> 00:06:23,000 +Where are we? + +114 +00:06:23,000 --> 00:06:23,000 +Where are we? + +115 +00:06:23,000 --> 00:06:25,000 +All right, here we go. + +116 +00:06:25,000 --> 00:06:27,000 +To our sonic wall. + +117 +00:06:27,000 --> 00:06:29,000 +All right, so it's logged me out. + +118 +00:06:29,000 --> 00:06:30,000 +Okay, so let's log in to the sonic world. + +119 +00:06:30,000 --> 00:06:33,000 +I'm actually directly connected to this thing. + +120 +00:06:40,000 --> 00:06:40,000 +Okay. + +121 +00:06:40,000 --> 00:06:41,000 +It's coming on up. + +122 +00:06:42,000 --> 00:06:47,000 +We got to make sure we're in manage because we want to manage the actual firewall. + +123 +00:06:47,000 --> 00:06:50,000 +Uh, and I want to go here right now. + +124 +00:06:50,000 --> 00:06:54,000 +Now, you'll notice that you have a lot of options on this section of it. + +125 +00:06:55,000 --> 00:06:59,000 +And I'm going to go to rules and I want to show you guys the rules. + +126 +00:06:59,000 --> 00:07:02,000 +Notice it says access rules. + +127 +00:07:02,000 --> 00:07:03,000 +All right. + +128 +00:07:03,000 --> 00:07:06,000 +So you notice if we come here these are all the access rules. + +129 +00:07:06,000 --> 00:07:10,000 +This is basically an access a list of all the rules the access list. + +130 +00:07:11,000 --> 00:07:15,000 +You'll notice that these are all the rules that it has. + +131 +00:07:15,000 --> 00:07:16,000 +And there is a lot. + +132 +00:07:16,000 --> 00:07:20,000 +But I'll just go through some of them to show you guys what it is. + +133 +00:07:20,000 --> 00:07:20,000 +So. + +134 +00:07:22,000 --> 00:07:22,000 +I'll check this out. + +135 +00:07:23,000 --> 00:07:26,000 +Notice how they have from DMZ to DMZ. + +136 +00:07:26,000 --> 00:07:28,000 +They're going to allow this. + +137 +00:07:28,000 --> 00:07:29,000 +You can see that. + +138 +00:07:30,000 --> 00:07:32,000 +Uh, DMZ to land denied. + +139 +00:07:32,000 --> 00:07:32,000 +So what this is doing? + +140 +00:07:32,000 --> 00:07:35,000 +No traffic from the DMZ can come into the land. + +141 +00:07:36,000 --> 00:07:38,000 +DMs to Wang. + +142 +00:07:38,000 --> 00:07:42,000 +We're going to allow that so DMs can go out to the Wang ports. + +143 +00:07:42,000 --> 00:07:47,000 +Um, lan to DMs we're going to allow anything to land can hit the DMs. + +144 +00:07:48,000 --> 00:07:50,000 +Uh, we also have land to land. + +145 +00:07:50,000 --> 00:07:51,000 +It's going to allow this. + +146 +00:07:51,000 --> 00:07:51,000 +This is within. + +147 +00:07:51,000 --> 00:07:53,000 +This is on this particular interface, though. + +148 +00:07:54,000 --> 00:07:55,000 +Um. + +149 +00:07:55,000 --> 00:07:56,000 +Let's go. + +150 +00:07:56,000 --> 00:07:56,000 +Keep going down. + +151 +00:07:56,000 --> 00:08:00,000 +These are all the access routes, you guys lanta SSL. + +152 +00:08:00,000 --> 00:08:03,000 +So folks in the land can speak to people coming in through this. + +153 +00:08:03,000 --> 00:08:05,000 +Has an SSL VPN built into it. + +154 +00:08:05,000 --> 00:08:07,000 +People on the land can go out to the internet. + +155 +00:08:07,000 --> 00:08:11,000 +Notice how it says that just to not spend too long on rules here. + +156 +00:08:11,000 --> 00:08:15,000 +But notice Wang to DMZ deny right now that is being denied. + +157 +00:08:16,000 --> 00:08:20,000 +That means they're not allowed any traffic from Wang to DMZ. + +158 +00:08:21,000 --> 00:08:23,000 +That means any traffic coming through the Wang will not go. + +159 +00:08:23,000 --> 00:08:26,000 +We have to specifically allow what we want to go into the DMZ. + +160 +00:08:26,000 --> 00:08:31,000 +Any traffic from the Wang, from the internet trying to come onto your land is denied. + +161 +00:08:31,000 --> 00:08:34,000 +Now, from lan to Wang, I'm sorry. + +162 +00:08:34,000 --> 00:08:38,000 +From Wang internet to the LAN is denied by default. + +163 +00:08:38,000 --> 00:08:40,000 +That's how all firewalls work. + +164 +00:08:40,000 --> 00:08:44,000 +They don't allow anything from the public coming in to the internal network. + +165 +00:08:44,000 --> 00:08:47,000 +These are how all firewalls are designed. + +166 +00:08:48,000 --> 00:08:49,000 +Okay. + +167 +00:08:49,000 --> 00:08:51,000 +Let's go ahead and add a server. + +168 +00:08:51,000 --> 00:09:00,000 +So let's say if I go back to this, uh, if I go back to this presentation here that I want to show + +169 +00:09:00,000 --> 00:09:01,000 +you guys. + +170 +00:09:02,000 --> 00:09:05,000 +Take a look at this presentation here that we have. + +171 +00:09:06,000 --> 00:09:09,000 +Because we want to implement this, let's say. + +172 +00:09:10,000 --> 00:09:11,000 +We have. + +173 +00:09:11,000 --> 00:09:14,000 +We want to implement a web server right here. + +174 +00:09:15,000 --> 00:09:15,000 +All right. + +175 +00:09:15,000 --> 00:09:17,000 +We have the external port, the Wang port. + +176 +00:09:17,000 --> 00:09:20,000 +This green box is a firewall. + +177 +00:09:20,000 --> 00:09:21,000 +We want to put a. + +178 +00:09:21,000 --> 00:09:26,000 +We want to put a web server in the DMZ to be accessible from the outside world. + +179 +00:09:26,000 --> 00:09:27,000 +How are we going to do that? + +180 +00:09:27,000 --> 00:09:29,000 +Well, we have to configure the firewall. + +181 +00:09:29,000 --> 00:09:32,000 +In this particular firewall we got to add first an object. + +182 +00:09:32,000 --> 00:09:35,000 +So we're going to go to address object. + +183 +00:09:35,000 --> 00:09:36,000 +We're going to say add. + +184 +00:09:37,000 --> 00:09:43,000 +We're going to say, let's put Andrew's web. + +185 +00:09:44,000 --> 00:09:45,000 +It's my web server. + +186 +00:09:45,000 --> 00:09:53,000 +It's on a DMZ to host its IP address, give it a quick IP address, uh, 20 that, let's say 250. + +187 +00:09:56,000 --> 00:09:58,000 +Okay, so it's ah Andrew's web. + +188 +00:09:58,000 --> 00:09:59,000 +All right. + +189 +00:09:59,000 --> 00:10:00,000 +Then add an object. + +190 +00:10:00,000 --> 00:10:01,000 +Okay. + +191 +00:10:01,000 --> 00:10:01,000 +Andrew's web. + +192 +00:10:01,000 --> 00:10:04,000 +So what we want to do now this thing is in the DMZ. + +193 +00:10:04,000 --> 00:10:06,000 +We want to say when traffic comes in. + +194 +00:10:06,000 --> 00:10:10,000 +Now I know you guys can barely see this, but where is that camera? + +195 +00:10:10,000 --> 00:10:12,000 +Let me show you guys some stuff. + +196 +00:10:12,000 --> 00:10:13,000 +Hide my face to the camera. + +197 +00:10:13,000 --> 00:10:14,000 +Focuses on that. + +198 +00:10:14,000 --> 00:10:15,000 +Ah. + +199 +00:10:16,000 --> 00:10:21,000 +Okay, so it's a little hard to see there, but you could see that. + +200 +00:10:23,000 --> 00:10:23,000 +It. + +201 +00:10:23,000 --> 00:10:24,000 +Focus. + +202 +00:10:24,000 --> 00:10:24,000 +Come on. + +203 +00:10:24,000 --> 00:10:25,000 +Autofocus. + +204 +00:10:25,000 --> 00:10:26,000 +Do your job. + +205 +00:10:26,000 --> 00:10:26,000 +All right. + +206 +00:10:26,000 --> 00:10:28,000 +We're not going to get that to autofocus. + +207 +00:10:28,000 --> 00:10:32,000 +So this port here I know you guys can see that but. + +208 +00:10:33,000 --> 00:10:35,000 +You see, it comes on and off. + +209 +00:10:35,000 --> 00:10:36,000 +It doesn't like me. + +210 +00:10:38,000 --> 00:10:40,000 +Uh, hide my face. + +211 +00:10:40,000 --> 00:10:40,000 +Yeah. + +212 +00:10:40,000 --> 00:10:40,000 +So it's an auto. + +213 +00:10:40,000 --> 00:10:43,000 +It's a camera that focuses on faces all the time. + +214 +00:10:43,000 --> 00:10:43,000 +All right. + +215 +00:10:43,000 --> 00:10:44,000 +Any which way? + +216 +00:10:44,000 --> 00:10:47,000 +Uh, this port, this port here and this port. + +217 +00:10:47,000 --> 00:10:48,000 +All right. + +218 +00:10:48,000 --> 00:10:49,000 +This one says lan. + +219 +00:10:49,000 --> 00:10:50,000 +There it is. + +220 +00:10:50,000 --> 00:10:51,000 +This one says Wang. + +221 +00:10:52,000 --> 00:10:52,000 +All right. + +222 +00:10:52,000 --> 00:10:52,000 +You're gonna. + +223 +00:10:52,000 --> 00:10:56,000 +If you want a DMZ port, you have to designate a port here as DMZ. + +224 +00:10:56,000 --> 00:10:59,000 +So we haven't configured that though. + +225 +00:10:59,000 --> 00:11:01,000 +So you would need to plug in your internet into this port. + +226 +00:11:01,000 --> 00:11:03,000 +This would be a internet router. + +227 +00:11:03,000 --> 00:11:08,000 +You'd plug a switch into this LAN port and then give all your computers access to this. + +228 +00:11:09,000 --> 00:11:10,000 +Did I switch plugged in here. + +229 +00:11:10,000 --> 00:11:13,000 +You can also plug a switch like um, I have my computer plugged in. + +230 +00:11:13,000 --> 00:11:16,000 +You would also plug a switch into this and then designate that as the DMZ. + +231 +00:11:16,000 --> 00:11:23,000 +And then plug your web server into that particular port is how this would be physically configured. + +232 +00:11:23,000 --> 00:11:28,000 +Now let's go into our rules and we're going to say access rules. + +233 +00:11:28,000 --> 00:11:30,000 +And we're going to say add. + +234 +00:11:32,000 --> 00:11:39,000 +So we want to give we want to see traffic coming in from the Wang port is going to go into the DMZ port, + +235 +00:11:40,000 --> 00:11:42,000 +but it has to be for that web server. + +236 +00:11:42,000 --> 00:11:43,000 +So we're going to give it a name. + +237 +00:11:43,000 --> 00:11:45,000 +Uh, Andrew's web. + +238 +00:11:47,000 --> 00:11:52,000 +And from the DMZ to. + +239 +00:11:53,000 --> 00:11:53,000 +Nope. + +240 +00:11:53,000 --> 00:11:54,000 +Said that wrong. + +241 +00:11:54,000 --> 00:11:56,000 +From the Wang to the DMZ. + +242 +00:11:58,000 --> 00:12:04,000 +The sauce is going to be Http, not just H, but https service. + +243 +00:12:04,000 --> 00:12:05,000 +The same thing. + +244 +00:12:08,000 --> 00:12:11,000 +Https the source. + +245 +00:12:12,000 --> 00:12:14,000 +It's going to be any Wang IP address. + +246 +00:12:14,000 --> 00:12:20,000 +We can even you can even granular it down to only certain IP addresses from certain external IPS. + +247 +00:12:20,000 --> 00:12:24,000 +We don't want that the destination we're going to have to go. + +248 +00:12:24,000 --> 00:12:29,000 +We're going to say well don't send it anywhere but the Android web server. + +249 +00:12:29,000 --> 00:12:31,000 +In the DMZ. + +250 +00:12:31,000 --> 00:12:32,000 +That's it. + +251 +00:12:32,000 --> 00:12:33,000 +We've configured it. + +252 +00:12:33,000 --> 00:12:34,000 +We're going to go ahead. + +253 +00:12:34,000 --> 00:12:35,000 +Now we're going to say add. + +254 +00:12:39,000 --> 00:12:40,000 +All done. + +255 +00:12:40,000 --> 00:12:41,000 +Please check the table. + +256 +00:12:41,000 --> 00:12:42,000 +We're going to close that out. + +257 +00:12:43,000 --> 00:12:50,000 +And we should have somewhere in here that something coming from the Wang. + +258 +00:12:51,000 --> 00:12:52,000 +It's going to go to the DMZ. + +259 +00:12:53,000 --> 00:12:54,000 +It's going to allow it. + +260 +00:12:54,000 --> 00:12:57,000 +Now I want you guys to notice something. + +261 +00:12:57,000 --> 00:13:09,000 +Notice that this sits on top of this rule that says Andrews Webb is Wang to DMZ is allowed only Https. + +262 +00:13:09,000 --> 00:13:14,000 +The next rule says Wang DMZ any any any is denied. + +263 +00:13:14,000 --> 00:13:19,000 +Now it's important to see the way firewall rules work is they work in an order. + +264 +00:13:19,000 --> 00:13:25,000 +In other words, when traffic comes in, any traffic that comes in through a firewall, a firewall processes + +265 +00:13:25,000 --> 00:13:29,000 +that traffic based on the order that those rules are written. + +266 +00:13:30,000 --> 00:13:35,000 +So right now I have a rule that says if you're coming on port, if somebody wants to come in on port, + +267 +00:13:35,000 --> 00:13:42,000 +um, 443 over Https, send it to this machine in the DMZ. + +268 +00:13:42,000 --> 00:13:43,000 +Anything else? + +269 +00:13:43,000 --> 00:13:44,000 +Deny it. + +270 +00:13:45,000 --> 00:13:46,000 +Okay, because that's what this specifies. + +271 +00:13:46,000 --> 00:13:56,000 +It's like if any traffic is coming in on where is it any traffic coming from, all Wang IP addresses + +272 +00:13:56,000 --> 00:13:57,000 +that are coming in. + +273 +00:13:58,000 --> 00:14:01,000 +From the internet, particularly on this Wan port. + +274 +00:14:01,000 --> 00:14:02,000 +Send it. + +275 +00:14:02,000 --> 00:14:04,000 +If it's Https, send it to this machine. + +276 +00:14:04,000 --> 00:14:07,000 +The next one says, well then anything else, just deny it. + +277 +00:14:07,000 --> 00:14:08,000 +That's what he's deny. + +278 +00:14:08,000 --> 00:14:10,000 +Statements are there. + +279 +00:14:10,000 --> 00:14:12,000 +In other words, they're not going to allow anything else. + +280 +00:14:12,000 --> 00:14:13,000 +Everything else they can allow. + +281 +00:14:13,000 --> 00:14:17,000 +So firewall rules are processed in the order that is listed in. + +282 +00:14:19,000 --> 00:14:19,000 +Okay. + +283 +00:14:20,000 --> 00:14:22,000 +That's a quick way. + +284 +00:14:22,000 --> 00:14:27,000 +Quick video on how to configure this, just so you could see that firewalls do work on rules. + +285 +00:14:27,000 --> 00:14:31,000 +Now you do not need to know this for your exam. + +286 +00:14:31,000 --> 00:14:34,000 +In fact this video is touching 15 minutes. + +287 +00:14:34,000 --> 00:14:39,000 +You don't need to know this for your exam, but understand that firewall works with rules. + +288 +00:14:39,000 --> 00:14:43,000 +Without these rules, these firewalls wouldn't know what to do. + +289 +00:14:43,000 --> 00:14:48,000 +When you want to set up the organization security policy, you have to edit, change and manipulate + +290 +00:14:49,000 --> 00:14:50,000 +the rules. + diff --git a/17 - Enhance Security/002 Web Filters OB 4.5_en.srt b/17 - Enhance Security/002 Web Filters OB 4.5_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..14f3524b307a9d52a6008e961239f3d9e26829d8 --- /dev/null +++ b/17 - Enhance Security/002 Web Filters OB 4.5_en.srt @@ -0,0 +1,352 @@ +1 +00:00:00,000 --> 00:00:02,000 +I said this earlier in the class. + +2 +00:00:02,000 --> 00:00:05,000 +My mother have always told me the more choices, the more mistakes. + +3 +00:00:05,000 --> 00:00:10,000 +When you go into an organization and you start working, they should limit your choice of where you + +4 +00:00:10,000 --> 00:00:11,000 +can go and what you can do. + +5 +00:00:11,000 --> 00:00:16,000 +The more websites you can access, the more likely you can introduce malware into your organization. + +6 +00:00:16,000 --> 00:00:19,000 +Now look at it from a security professional perspective. + +7 +00:00:19,000 --> 00:00:25,000 +We want to limit websites that users can access, and they should only be accessed in websites or have + +8 +00:00:25,000 --> 00:00:28,000 +access to websites that allows them to get their job done. + +9 +00:00:28,000 --> 00:00:32,000 +Users don't come to your organization to play and have fun. + +10 +00:00:32,000 --> 00:00:34,000 +That's what being at home for. + +11 +00:00:34,000 --> 00:00:35,000 +They come to work. + +12 +00:00:35,000 --> 00:00:42,000 +What we want to do is we want to use web filtering technologies and different kinds of servers to control + +13 +00:00:42,000 --> 00:00:46,000 +the websites and content that these users can access. + +14 +00:00:46,000 --> 00:00:49,000 +So let's see some ways that organizations can do this. + +15 +00:00:49,000 --> 00:00:53,000 +One thing they can do is they can install what's called agent based web filtering. + +16 +00:00:53,000 --> 00:01:00,000 +This this involves installing web filters by installing a specific piece of software on the individual + +17 +00:01:00,000 --> 00:01:02,000 +user, computers or devices. + +18 +00:01:02,000 --> 00:01:05,000 +These agents will enforce web policies set by the organization. + +19 +00:01:05,000 --> 00:01:10,000 +Now these agents are going to work generally with what's known as proxy servers, which we'll come to + +20 +00:01:10,000 --> 00:01:11,000 +in a minute. + +21 +00:01:11,000 --> 00:01:15,000 +They are the ones that's going to control what websites you can access. + +22 +00:01:15,000 --> 00:01:16,000 +Use case. + +23 +00:01:16,000 --> 00:01:22,000 +This approach is particularly useful for managing web access of remote or mobile employees, who might + +24 +00:01:22,000 --> 00:01:24,000 +not always be connected to the corporate network. + +25 +00:01:24,000 --> 00:01:25,000 +Here's why. + +26 +00:01:25,000 --> 00:01:35,000 +Because if you give, uh, remote users particularly like salespeople or traveling users, uh, a laptop, + +27 +00:01:35,000 --> 00:01:39,000 +and they connect to a particular network, it's not your network. + +28 +00:01:39,000 --> 00:01:41,000 +It's a network at Starbucks. + +29 +00:01:41,000 --> 00:01:42,000 +It's the hotel's network. + +30 +00:01:42,000 --> 00:01:47,000 +Well, because you can control everything in your network, you can restrict what people can access. + +31 +00:01:47,000 --> 00:01:51,000 +But if they go to that hotel, there's nothing that restricts them. + +32 +00:01:51,000 --> 00:01:53,000 +So now they can access anything. + +33 +00:01:53,000 --> 00:01:57,000 +But if you have an agent install a software on the machine, that doesn't matter what network they're + +34 +00:01:57,000 --> 00:02:00,000 +connected to, you can restrict their website. + +35 +00:02:00,000 --> 00:02:03,000 +That's why agent based web filtering is great. + +36 +00:02:03,000 --> 00:02:08,000 +Now a lot of times we're going to use some kind of something called a centralized proxy or proxy servers. + +37 +00:02:08,000 --> 00:02:12,000 +This is often part of a larger network appliance security appliance. + +38 +00:02:12,000 --> 00:02:17,000 +Now you can also have this thing as a service that acts as the intermediary. + +39 +00:02:18,000 --> 00:02:20,000 +You can pronounce that word between users and the internet. + +40 +00:02:20,000 --> 00:02:24,000 +All web traffic passes through these proxies and it filters it. + +41 +00:02:24,000 --> 00:02:30,000 +I remember working at different jobs and going to different big companies, and you would try to go + +42 +00:02:30,000 --> 00:02:34,000 +to a particular website, you might go to Facebook and it might redirect your company policies and allow + +43 +00:02:34,000 --> 00:02:34,000 +that. + +44 +00:02:34,000 --> 00:02:37,000 +That's what a proxy server does. + +45 +00:02:37,000 --> 00:02:43,000 +This method offers a centralized management and control, making it easier to manage your web policies. + +46 +00:02:43,000 --> 00:02:48,000 +Now all of these things are going to be doing what's known as URL scanning. + +47 +00:02:48,000 --> 00:02:53,000 +This involves examining the URLs requested by users to determine, hey, should we allow this or can + +48 +00:02:53,000 --> 00:02:55,000 +we not allow this? + +49 +00:02:55,000 --> 00:03:01,000 +This can be based on the data set of, uh, customized or categorized URLs. + +50 +00:03:01,000 --> 00:03:07,000 +So the organization can have a giant database of particular URLs that you're allowed to access. + +51 +00:03:07,000 --> 00:03:13,000 +The application URL is effective and preventing access to known malicious or inappropriate website. + +52 +00:03:13,000 --> 00:03:19,000 +So if we just give them a list of websites that we they want, that we want them to access, more than + +53 +00:03:19,000 --> 00:03:21,000 +likely they're not going to be going anywhere else. + +54 +00:03:22,000 --> 00:03:24,000 +Content categorization. + +55 +00:03:24,000 --> 00:03:31,000 +How do we categorize content well classifies web pages into different like social media adult content + +56 +00:03:31,000 --> 00:03:32,000 +games based on their content. + +57 +00:03:33,000 --> 00:03:38,000 +This allows organizations to block or allow entire categories of websites. + +58 +00:03:38,000 --> 00:03:45,000 +For example, if you're working in it, a lot of times we may allow only IT folks to visit IT related + +59 +00:03:45,000 --> 00:03:50,000 +websites, but we're not going to allow IT folks to visit social media. + +60 +00:03:50,000 --> 00:03:55,000 +But the people in the marketing department, they could visit social media, but they can't visit other + +61 +00:03:55,000 --> 00:03:56,000 +types of websites. + +62 +00:03:56,000 --> 00:04:03,000 +This is great because now we are giving folks a block of content that is related to their job. + +63 +00:04:03,000 --> 00:04:06,000 +This, of course, restricts what they can access. + +64 +00:04:06,000 --> 00:04:13,000 +The block rule in web filtering a specific criteria set to block access to certain websites. + +65 +00:04:13,000 --> 00:04:19,000 +We could block things on URLs, keywords, categories, or anything that we can identify on that web + +66 +00:04:19,000 --> 00:04:19,000 +page. + +67 +00:04:19,000 --> 00:04:25,000 +They can block, hey, you can't go to this URL, or you can go to social media sites, or you can go + +68 +00:04:25,000 --> 00:04:26,000 +to video sharing website. + +69 +00:04:26,000 --> 00:04:28,000 +So you could block lots of things. + +70 +00:04:28,000 --> 00:04:34,000 +Your organization is going to customize these block rules to ensure that they're meeting their policies, + +71 +00:04:34,000 --> 00:04:36,000 +even certain regulatory compliance. + +72 +00:04:38,000 --> 00:04:45,000 +Now there are these kinds of filters called reputation filters, uses the reputation score of websites + +73 +00:04:45,000 --> 00:04:47,000 +to determine whether they should be allowed or not. + +74 +00:04:48,000 --> 00:04:52,000 +Reputation scores are literally coming from various factors like the history, presence of malware, + +75 +00:04:52,000 --> 00:04:54,000 +and even user feedback. + +76 +00:04:54,000 --> 00:04:55,000 +This. + +77 +00:04:56,000 --> 00:05:02,000 +Is really important because the reputation score of certain website, if it has a low reputation, could + +78 +00:05:02,000 --> 00:05:03,000 +mean that the website was passed in malware. + +79 +00:05:03,000 --> 00:05:04,000 +Quite often. + +80 +00:05:04,000 --> 00:05:10,000 +This is a very effective way in protecting against newly created malicious site, because new sites + +81 +00:05:10,000 --> 00:05:12,000 +probably wouldn't have a good reputation score. + +82 +00:05:12,000 --> 00:05:14,000 +So it hasn't been around long enough. + +83 +00:05:14,000 --> 00:05:17,000 +And because it hasn't been around long enough, its reputation score is going to be low. + +84 +00:05:17,000 --> 00:05:19,000 +You're not going to be able to access it. + +85 +00:05:19,000 --> 00:05:27,000 +I strongly believe that web filtering is one of the core concepts that we should have in security. + +86 +00:05:27,000 --> 00:05:34,000 +By having web filtering, we'll better be able to restrict what people can do within the organization, + +87 +00:05:34,000 --> 00:05:36,000 +and hopefully that keeps them doing their job. + +88 +00:05:36,000 --> 00:05:43,000 +But most importantly, web filtering is probably one of the best ways to reduce malware infections. + diff --git a/17 - Enhance Security/003 Operating System Security OB 4.5_en.srt b/17 - Enhance Security/003 Operating System Security OB 4.5_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..02cc0d6686621f29b448c2cd537d1c1ea0344382 --- /dev/null +++ b/17 - Enhance Security/003 Operating System Security OB 4.5_en.srt @@ -0,0 +1,448 @@ +1 +00:00:00,000 --> 00:00:05,000 +When it comes to securing and operating system, one of the best things we can do in particularly windows + +2 +00:00:05,000 --> 00:00:07,000 +is what's called group policies. + +3 +00:00:07,000 --> 00:00:13,000 +When people say in today's corporate world or security world, when you hear somebody say, we're going + +4 +00:00:13,000 --> 00:00:18,000 +to lock down that operating system, we're going to lock down their desktop, we're going to restrict + +5 +00:00:18,000 --> 00:00:19,000 +what they can access. + +6 +00:00:19,000 --> 00:00:21,000 +We're going to set password policies. + +7 +00:00:21,000 --> 00:00:22,000 +That's all with group policy. + +8 +00:00:22,000 --> 00:00:25,000 +Now for this course, you just need to understand what it is. + +9 +00:00:25,000 --> 00:00:31,000 +I'm going to also show you group policy on on on my windows machine. + +10 +00:00:31,000 --> 00:00:34,000 +You don't need to configure group policy for your exam. + +11 +00:00:34,000 --> 00:00:36,000 +So we'll do that at the end of the video. + +12 +00:00:36,000 --> 00:00:39,000 +So if you want to stick around to see some group policies in action stick with me. + +13 +00:00:39,000 --> 00:00:40,000 +Let's get started. + +14 +00:00:41,000 --> 00:00:43,000 +Um, so let's talk about this. + +15 +00:00:43,000 --> 00:00:48,000 +When you're securing it particularly windows, the best thing we're going to be using is group policies. + +16 +00:00:48,000 --> 00:00:54,000 +It's a feature in windows that allows administrators to control the work and environment of users and + +17 +00:00:54,000 --> 00:00:54,000 +computers. + +18 +00:00:54,000 --> 00:00:57,000 +And it could do a lot of things. + +19 +00:00:57,000 --> 00:01:01,000 +First of all, it could be centralized, and it could be centralized. + +20 +00:01:01,000 --> 00:01:06,000 +And it's basically the configuration of operating system applications and user setup. + +21 +00:01:06,000 --> 00:01:11,000 +We centralized this by implementing things like Active Directory that can then push out group policies + +22 +00:01:11,000 --> 00:01:13,000 +to large sections of your machine. + +23 +00:01:13,000 --> 00:01:17,000 +You can also edit the group policy locally on your computer. + +24 +00:01:17,000 --> 00:01:23,000 +The applications of security Settings group policy can enforce many types of security settings, such + +25 +00:01:23,000 --> 00:01:28,000 +as password policies, lockout policies if you put your password in too many times, wrong audit policies + +26 +00:01:28,000 --> 00:01:32,000 +to keep track of what's going on in the machine, it can even control what users can do. + +27 +00:01:32,000 --> 00:01:39,000 +Security options and even access to file folders and registry group policies has way too many options + +28 +00:01:39,000 --> 00:01:41,000 +for me just to talk about in a video a few minutes. + +29 +00:01:41,000 --> 00:01:48,000 +But for your exam, just know group policy is how we maintain the security settings on windows Machine. + +30 +00:01:48,000 --> 00:01:56,000 +Now there is a version of Linux that you guys should be familiar with for your exam, and that's called + +31 +00:01:56,000 --> 00:02:00,000 +SE Linux or Secure Enhanced Linux. + +32 +00:02:00,000 --> 00:02:07,000 +Now this is a security module in Linux systems that provides a mechanism for supporting access control + +33 +00:02:07,000 --> 00:02:08,000 +security policies. + +34 +00:02:08,000 --> 00:02:12,000 +It implements what is known as mandatory access control. + +35 +00:02:12,000 --> 00:02:18,000 +You see, traditional operating systems such as windows implements a type of access control we call + +36 +00:02:18,000 --> 00:02:21,000 +Dak or discretionary access control. + +37 +00:02:21,000 --> 00:02:24,000 +Basically, in windows, whoever creates the objects owns the objects. + +38 +00:02:24,000 --> 00:02:28,000 +Whoever makes the objects can even set permissions on the objects. + +39 +00:02:28,000 --> 00:02:33,000 +Because I'm on this windows box, I can make a folder and share it and do whatever I want with it on + +40 +00:02:33,000 --> 00:02:33,000 +the network. + +41 +00:02:33,000 --> 00:02:37,000 +But if you install a Linux system doesn't work like that. + +42 +00:02:37,000 --> 00:02:44,000 +You see, unlike traditional discretionary access control systems or Dak like windows SE, Linux enforces + +43 +00:02:44,000 --> 00:02:50,000 +mandatory that access control administrators can define the control access to all processes and files. + +44 +00:02:51,000 --> 00:02:56,000 +Basically, when they install Linux SE, the administrator sets the permissions on the machine, and + +45 +00:02:56,000 --> 00:03:02,000 +users can't just create files and change permissions and grant and grant access to anybody they want. + +46 +00:03:02,000 --> 00:03:08,000 +So the actual permissions or security of the systems is set by the administrators and not by the users + +47 +00:03:08,000 --> 00:03:10,000 +or set by the organization. + +48 +00:03:10,000 --> 00:03:16,000 +In other words, SE Linux is not something that's popular in corporate environments. + +49 +00:03:16,000 --> 00:03:19,000 +SE Linux is used by places like the NSA and the DoD. + +50 +00:03:20,000 --> 00:03:23,000 +In fact, it was I think it was developed by them. + +51 +00:03:23,000 --> 00:03:30,000 +In fact, the word mandatory access control does have quite a lot of different terminologies that belongs + +52 +00:03:30,000 --> 00:03:30,000 +with it. + +53 +00:03:30,000 --> 00:03:33,000 +But that's something we're going to cover in another video. + +54 +00:03:33,000 --> 00:03:40,000 +But for now, just remember Linux SE implements mandatory access control and to control security features + +55 +00:03:40,000 --> 00:03:43,000 +in windows we're going to use group policy okay. + +56 +00:03:43,000 --> 00:03:44,000 +That's the end of this video. + +57 +00:03:44,000 --> 00:03:50,000 +If you want to pass your exam, if you want to see how do how does group policies work. + +58 +00:03:50,000 --> 00:03:53,000 +Well let's do a quick little demonstration. + +59 +00:03:53,000 --> 00:03:55,000 +And I'm going to show you guys how to get it. + +60 +00:03:56,000 --> 00:03:56,000 +All right. + +61 +00:03:56,000 --> 00:03:58,000 +So we're going to go back here to my desktop. + +62 +00:03:59,000 --> 00:04:01,000 +We're going to go to run. + +63 +00:04:01,000 --> 00:04:01,000 +We're going to do window. + +64 +00:04:01,000 --> 00:04:02,000 +Are to go to run. + +65 +00:04:02,000 --> 00:04:09,000 +We're going to do uh I like to do an MMC console, Microsoft Management console, MMC. + +66 +00:04:11,000 --> 00:04:13,000 +Now you could do Gpedit.msc. + +67 +00:04:14,000 --> 00:04:16,000 +Uh, but this. + +68 +00:04:16,000 --> 00:04:18,000 +I like to do a console, so I'm going to open up a console. + +69 +00:04:18,000 --> 00:04:23,000 +I'll do a snapping of the group policy object editor, let's say file add remove snapping. + +70 +00:04:24,000 --> 00:04:27,000 +And then we want to find group policy object editor. + +71 +00:04:27,000 --> 00:04:29,000 +We're going to say add for this computer. + +72 +00:04:29,000 --> 00:04:33,000 +If you have administrator privileges you can actually browse, select all the computers in your network + +73 +00:04:33,000 --> 00:04:35,000 +and administer policies remotely. + +74 +00:04:35,000 --> 00:04:38,000 +So in here notice I have. + +75 +00:04:38,000 --> 00:04:45,000 +My group policy senior, I can go in and notice I have user configuration and I have computer configuration. + +76 +00:04:45,000 --> 00:04:52,000 +So in here for example in administrative template I can go in here and I can configure the active desktop. + +77 +00:04:52,000 --> 00:04:53,000 +Like we can go in here. + +78 +00:04:53,000 --> 00:04:58,000 +And we could prohibit adding items uh items to the desktop. + +79 +00:04:59,000 --> 00:05:03,000 +Uh we can go in here and set the desktop wallpaper. + +80 +00:05:03,000 --> 00:05:06,000 +We can disable all items on a desktop. + +81 +00:05:06,000 --> 00:05:08,000 +But this only applies to certain versions of windows. + +82 +00:05:08,000 --> 00:05:11,000 +It'll tell you what versions of windows that applies to. + +83 +00:05:11,000 --> 00:05:13,000 +So you can go in there. + +84 +00:05:13,000 --> 00:05:15,000 +You can set many, many things. + +85 +00:05:16,000 --> 00:05:16,000 +Um. + +86 +00:05:17,000 --> 00:05:21,000 +The ones I want to show you guys is going to be in the computer settings. + +87 +00:05:22,000 --> 00:05:29,000 +We're going to go, uh, sorry, not windows computer configuration, windows settings, security settings. + +88 +00:05:29,000 --> 00:05:33,000 +And in here you have tons of things you can do, like password policies. + +89 +00:05:33,000 --> 00:05:39,000 +You can specify that this machine must have a password right now has eight minimum. + +90 +00:05:39,000 --> 00:05:40,000 +You can say it must have ten. + +91 +00:05:40,000 --> 00:05:44,000 +You could say that the password must be complex. + +92 +00:05:44,000 --> 00:05:46,000 +Right now that's disabled. + +93 +00:05:46,000 --> 00:05:47,000 +All right. + +94 +00:05:47,000 --> 00:05:48,000 +We can do an account lockout. + +95 +00:05:48,000 --> 00:05:50,000 +Like if they put their password too many times. + +96 +00:05:50,000 --> 00:05:54,000 +Right now it's zero, which means you can put as many times as they want. + +97 +00:05:55,000 --> 00:05:57,000 +Um, you could put that if they put it in. + +98 +00:05:57,000 --> 00:05:59,000 +If they put password three times, it'll lock it out. + +99 +00:05:59,000 --> 00:06:03,000 +So you could do quite a lot of things in local policy. + +100 +00:06:03,000 --> 00:06:05,000 +You can go in here and say user right assignment. + +101 +00:06:05,000 --> 00:06:08,000 +You could deny a variety of things. + +102 +00:06:09,000 --> 00:06:12,000 +Or allow certain things are logged, certain things. + +103 +00:06:12,000 --> 00:06:15,000 +So then you can see all of these things that are listed here. + +104 +00:06:16,000 --> 00:06:21,000 +Um, now I do want to point out that, you know, there's a lot of things here from firewall policies, + +105 +00:06:21,000 --> 00:06:22,000 +even administrative. + +106 +00:06:22,000 --> 00:06:28,000 +You can even go in and for example, don't have users access to control panel. + +107 +00:06:28,000 --> 00:06:30,000 +All this type of things you can do here. + +108 +00:06:30,000 --> 00:06:36,000 +Now, I do want to point out that when it comes to group policies, it's not something you should play + +109 +00:06:36,000 --> 00:06:38,000 +around with if you don't know what you're doing. + +110 +00:06:38,000 --> 00:06:46,000 +I learned group policies back when I studied Windows Server 2000, in the year 2000, so a long, long + +111 +00:06:46,000 --> 00:06:48,000 +time ago, and we've used it since. + +112 +00:06:48,000 --> 00:06:54,000 +Group policy is still used today to keep windows operating systems secure. + diff --git a/17 - Enhance Security/004 Secure Protocols OB 4.5_en.srt b/17 - Enhance Security/004 Secure Protocols OB 4.5_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..48a3d65dfcddd755157449cbc2dafaa205e22ac2 --- /dev/null +++ b/17 - Enhance Security/004 Secure Protocols OB 4.5_en.srt @@ -0,0 +1,256 @@ +1 +00:00:00,000 --> 00:00:04,000 +You always want to choose a secure way over an unsecure way. + +2 +00:00:04,000 --> 00:00:09,000 +So in this video, I want to go through what you should be choosing. + +3 +00:00:09,000 --> 00:00:14,000 +You know which one over which one of some of the most common protocols that we have. + +4 +00:00:14,000 --> 00:00:20,000 +So implementation of secure protocols is an enterprise in enterprise environment is critical because + +5 +00:00:20,000 --> 00:00:26,000 +if you choose an insecure protocol, you could be opening the organization to tons of vulnerability. + +6 +00:00:26,000 --> 00:00:32,000 +So this process involves careful selections of protocols, ports and transport methods. + +7 +00:00:32,000 --> 00:00:32,000 +Let's get into this. + +8 +00:00:32,000 --> 00:00:33,000 +So protocols. + +9 +00:00:33,000 --> 00:00:37,000 +So the first thing up you should understand that Http is not secure. + +10 +00:00:38,000 --> 00:00:43,000 +Http is how we transfer a web page from different web servers to your desktop. + +11 +00:00:43,000 --> 00:00:47,000 +In particular, for web traffic, Https is the secure option. + +12 +00:00:47,000 --> 00:00:49,000 +This is the one that we should be using. + +13 +00:00:49,000 --> 00:00:59,000 +Https basically encapsulates um http into ssl tls tunnel to make them more secure. + +14 +00:00:59,000 --> 00:01:05,000 +This can safeguard against ears dropping or even on path attacks or what's known now known as on path. + +15 +00:01:05,000 --> 00:01:10,000 +Previously known as man in the middle attacks SSH over telnet. + +16 +00:01:10,000 --> 00:01:16,000 +So for remote administration, if you want to configure your computer remotely, especially things like + +17 +00:01:16,000 --> 00:01:21,000 +Cisco routers and Linux boxes, telnet was popular, but telnet is not encrypted. + +18 +00:01:21,000 --> 00:01:24,000 +What we should be using now is SSH. + +19 +00:01:24,000 --> 00:01:27,000 +SSH encrypts the data. + +20 +00:01:27,000 --> 00:01:28,000 +Okay. + +21 +00:01:28,000 --> 00:01:31,000 +When SSH encrypts it, it means that anyone is dropping on it. + +22 +00:01:31,000 --> 00:01:33,000 +Can't listen to it. + +23 +00:01:33,000 --> 00:01:38,000 +Now for email you want to use good email secure protocols. + +24 +00:01:38,000 --> 00:01:45,000 +SMTp, iMap, and Pop3 can now use TLS or SSL encryption. + +25 +00:01:45,000 --> 00:01:49,000 +You don't want to send email in plain text, generally without the use of TLS. + +26 +00:01:49,000 --> 00:01:51,000 +Your email is sent in plain text. + +27 +00:01:52,000 --> 00:01:59,000 +So if you email someone some really secure or private information, somebody with access to your to + +28 +00:01:59,000 --> 00:02:01,000 +your lines in your network can actually read it. + +29 +00:02:02,000 --> 00:02:08,000 +Secure File transfer FTP is one of the still one of the most popular ways to upload and download files + +30 +00:02:08,000 --> 00:02:10,000 +off a web servers in particular. + +31 +00:02:10,000 --> 00:02:15,000 +Now, back in the days we used to use it to share files over the internet, although now we have things + +32 +00:02:15,000 --> 00:02:21,000 +like Dropbox, but we still use FTP to transfer files to and from web servers. + +33 +00:02:21,000 --> 00:02:30,000 +If you maintain a web server now, don't use FTP, use SftP which is combined in FTP with SSH or ftps + +34 +00:02:30,000 --> 00:02:32,000 +which combines it with SSL. + +35 +00:02:32,000 --> 00:02:34,000 +This makes it more secure. + +36 +00:02:34,000 --> 00:02:38,000 +Now this is going to be some of the most popular protocols out there. + +37 +00:02:39,000 --> 00:02:46,000 +When it comes to ports, you guys should know that standard ports are going to be generally unsecure. + +38 +00:02:46,000 --> 00:02:49,000 +Port 80 is not secure. + +39 +00:02:49,000 --> 00:02:52,000 +Using standard ports for correspondent. + +40 +00:02:52,000 --> 00:02:55,000 +For correspondent, secure ports is generally recommended. + +41 +00:02:55,000 --> 00:02:55,000 +All right. + +42 +00:02:55,000 --> 00:03:02,000 +So what are we going to be doing well for Https we're going to use port 443 for things like SSH. + +43 +00:03:02,000 --> 00:03:05,000 +We're going to use port 22 and for email. + +44 +00:03:05,000 --> 00:03:08,000 +Now if you're using SSL um. + +45 +00:03:09,000 --> 00:03:13,000 +If you're going to be using SSL, which you should be, it's going to change some of the ports. + +46 +00:03:13,000 --> 00:03:22,000 +So for SMTp, which used to be 25, we're going to use 587 for iMap uh, which I believe is 143. + +47 +00:03:22,000 --> 00:03:24,000 +By default we're going to use 993. + +48 +00:03:24,000 --> 00:03:29,000 +And for Pop3, which I believe is 110, Andrew doesn't remember all his ports anymore. + +49 +00:03:29,000 --> 00:03:32,000 +Guys is now 995. + +50 +00:03:33,000 --> 00:03:37,000 +Now when it comes to transport methods you want to transport. + +51 +00:03:37,000 --> 00:03:38,000 +Um. + +52 +00:03:39,000 --> 00:03:41,000 +You want to transport data across the internet? + +53 +00:03:41,000 --> 00:03:43,000 +How are we going to do this? + +54 +00:03:43,000 --> 00:03:49,000 +Especially like if you're transporting private information, like when somebody connects to a VPN, + +55 +00:03:49,000 --> 00:03:52,000 +if you're tasked to transport data, we got to get data across the internet. + +56 +00:03:52,000 --> 00:03:56,000 +The best thing to do is to do a VPN creates a secure tunnel between two sites. + +57 +00:03:56,000 --> 00:04:02,000 +When you do that VPN, make sure you use IPsec, which is when you configure what's known as L2tpv3, + +58 +00:04:03,000 --> 00:04:04,000 +which we covered earlier in the course. + +59 +00:04:04,000 --> 00:04:09,000 +You're going to want to use IPsec, which we did cover earlier in the course, and our TLS. + +60 +00:04:09,000 --> 00:04:12,000 +So you can do an SSL based VPN. + +61 +00:04:12,000 --> 00:04:15,000 +This is the best way to transport information okay. + +62 +00:04:15,000 --> 00:04:19,000 +This video was a quick review of things that we probably have already covered already, especially if + +63 +00:04:19,000 --> 00:04:21,000 +you watch the cryptography section. + +64 +00:04:21,000 --> 00:04:26,000 +Always choose secure protocols over on secure protocols. + diff --git a/17 - Enhance Security/005 DNS Filter OB 4.5_en.srt b/17 - Enhance Security/005 DNS Filter OB 4.5_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..ceb5bc53d805895e8c06cf96e0a2f20d830c1f07 --- /dev/null +++ b/17 - Enhance Security/005 DNS Filter OB 4.5_en.srt @@ -0,0 +1,104 @@ +1 +00:00:00,000 --> 00:00:07,000 +For your exam, you're going to want to be familiar that you can't just only block web traffic by utilizing + +2 +00:00:07,000 --> 00:00:12,000 +proxy servers, but you can also block web traffic by using DNS filtering. + +3 +00:00:12,000 --> 00:00:19,000 +So DNS filtering is DNS filtering is the network security technique used to block access to malicious + +4 +00:00:19,000 --> 00:00:24,000 +websites and content that is inappropriate or non-compliant with your company policy. + +5 +00:00:24,000 --> 00:00:26,000 +It involves using DNS to do this. + +6 +00:00:26,000 --> 00:00:28,000 +Now remember how DNS works. + +7 +00:00:28,000 --> 00:00:37,000 +DNS translates domain names to IP addresses, so when you try to access a domain, you send that request + +8 +00:00:37,000 --> 00:00:38,000 +to a DNS server. + +9 +00:00:38,000 --> 00:00:41,000 +Now the DNS server requests gets the request first. + +10 +00:00:41,000 --> 00:00:45,000 +So this would be one of the best things you can do if you can implement this filter. + +11 +00:00:45,000 --> 00:00:50,000 +Because since the DNS server is getting the requests first, the DNS server can say, wait a minute, + +12 +00:00:50,000 --> 00:00:51,000 +you're trying to go to this domain? + +13 +00:00:51,000 --> 00:00:52,000 +Well, I'm not allowing you there. + +14 +00:00:53,000 --> 00:00:55,000 +Now there's a variety of ways of doing this. + +15 +00:00:55,000 --> 00:00:57,000 +You can use a commercial DNS filtering service. + +16 +00:00:57,000 --> 00:01:03,000 +These services offer robust filtering options, and they're generally updated with websites that are + +17 +00:01:03,000 --> 00:01:07,000 +considered, uh, malicious in nature or considered a threat to your business. + +18 +00:01:07,000 --> 00:01:13,000 +They could be cloud or on premises, and there's tons of third party DNS filtering services. + +19 +00:01:13,000 --> 00:01:15,000 +There are open source ones that you can use. + +20 +00:01:16,000 --> 00:01:18,000 +That can be customized. + +21 +00:01:18,000 --> 00:01:22,000 +Uh, but generally going to require much more knowledge to do. + +22 +00:01:22,000 --> 00:01:29,000 +Now, DNS filtering, in my opinion, is very important because, remember, it's one of the first things + +23 +00:01:29,000 --> 00:01:34,000 +that people are going to get to is one of the first lines that they're going to ask, hey, can I go + +24 +00:01:34,000 --> 00:01:35,000 +to this website? + +25 +00:01:35,000 --> 00:01:42,000 +So if we can stop or filter out web traffic from right at the start, it would be a whole lot better + +26 +00:01:42,000 --> 00:01:43,000 +than using anything else. + diff --git a/17 - Enhance Security/006 Email security OB 4.5_en.srt b/17 - Enhance Security/006 Email security OB 4.5_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..07f4281a71ecb8ddd776bca5355f63c207f4fa52 --- /dev/null +++ b/17 - Enhance Security/006 Email security OB 4.5_en.srt @@ -0,0 +1,432 @@ +1 +00:00:00,000 --> 00:00:07,000 +Many email providers such as Yahoo, Gmail, and your private organization is trying their best to deal + +2 +00:00:07,000 --> 00:00:15,000 +with the massive amount of spam that is coming in and also the delivery of malicious email email coming + +3 +00:00:15,000 --> 00:00:21,000 +to you, not just as spam trying to sell you something or some useless message in an email, but also + +4 +00:00:21,000 --> 00:00:22,000 +malware. + +5 +00:00:22,000 --> 00:00:27,000 +What organizations needs to be doing is setting up the things that I'm going to be covering in this + +6 +00:00:27,000 --> 00:00:28,000 +video. + +7 +00:00:28,000 --> 00:00:33,000 +At a minimum, you should have these things to ensure that your domain is set up correctly. + +8 +00:00:33,000 --> 00:00:38,000 +Your domain wouldn't be marked as spam and of course, to reduce spam in your company. + +9 +00:00:38,000 --> 00:00:39,000 +So let's talk about this. + +10 +00:00:39,000 --> 00:00:41,000 +The first thing we need to talk about is an email security gateway. + +11 +00:00:43,000 --> 00:00:49,000 +This is a hardware software used to monitor and manage incoming and outgoing emails. + +12 +00:00:49,000 --> 00:00:53,000 +This thing is used to prevent spam, phishing attacks, and malware from coming in. + +13 +00:00:53,000 --> 00:00:59,000 +It scans your emails for viruses and other malware, filters out spam, and and can encrypt data and + +14 +00:00:59,000 --> 00:01:01,000 +prevent all kinds of data losses. + +15 +00:01:01,000 --> 00:01:05,000 +Gateways can be deployed on premises, but you're probably going to have this in cloud. + +16 +00:01:05,000 --> 00:01:10,000 +Most people don't maintain on prem email anymore. + +17 +00:01:10,000 --> 00:01:16,000 +I remember back in the days I had set up exchange servers, Microsoft Exchange servers as email servers + +18 +00:01:16,000 --> 00:01:17,000 +on prem. + +19 +00:01:17,000 --> 00:01:20,000 +We don't do that anymore because it's just cheaper to have it outside. + +20 +00:01:20,000 --> 00:01:27,000 +We're going to combine your email gateway with things like dMarc, DKIM, and SPF records in order to + +21 +00:01:27,000 --> 00:01:28,000 +come up with good security. + +22 +00:01:28,000 --> 00:01:31,000 +Now let's go through some of it. + +23 +00:01:31,000 --> 00:01:36,000 +The first thing I want to talk about is something we call Sender Policy Framework. + +24 +00:01:36,000 --> 00:01:45,000 +Now before I get into these three things Sender Policy Framework, DKIM, and dMarc, I want to mention + +25 +00:01:45,000 --> 00:01:45,000 +something. + +26 +00:01:46,000 --> 00:01:47,000 +Right now. + +27 +00:01:47,000 --> 00:01:54,000 +If your domain is not set up with these things correctly, more than likely Gmail, Yahoo! + +28 +00:01:54,000 --> 00:02:00,000 +And I think Microsoft is going to start marking emails coming from your domain as spam. + +29 +00:02:00,000 --> 00:02:05,000 +Spammers are going to have to stop sending emails unless they can verify their domain. + +30 +00:02:05,000 --> 00:02:08,000 +And that's what this that's what these things are going to be doing. + +31 +00:02:08,000 --> 00:02:09,000 +So let's get started. + +32 +00:02:09,000 --> 00:02:09,000 +What they are. + +33 +00:02:09,000 --> 00:02:16,000 +Sender Policy Framework is an email authentication method used to prevent spammers from sending messages + +34 +00:02:16,000 --> 00:02:18,000 +on behalf of you. + +35 +00:02:19,000 --> 00:02:20,000 +You got that? + +36 +00:02:20,000 --> 00:02:27,000 +When you implement SPF, what happens is it stops spammers from sending stuff from your domain. + +37 +00:02:27,000 --> 00:02:27,000 +How does it do it? + +38 +00:02:27,000 --> 00:02:35,000 +Well, SPF verified the sender the sender's IP address against a list of authorized sending IPS published + +39 +00:02:35,000 --> 00:02:37,000 +in the DNS records of the sender domain. + +40 +00:02:37,000 --> 00:02:39,000 +Here's how this is set up. + +41 +00:02:39,000 --> 00:02:43,000 +You have to be able to manage your company's domain name. + +42 +00:02:43,000 --> 00:02:45,000 +This is who who holds your domain name. + +43 +00:02:45,000 --> 00:02:47,000 +You know, where do you host your domain name? + +44 +00:02:47,000 --> 00:02:53,000 +Maybe you hosted GoDaddy, you can go to GoDaddy and you're going to add what's called a txt record. + +45 +00:02:53,000 --> 00:02:57,000 +Now GoDaddy is going to have specific instructions on this. + +46 +00:02:57,000 --> 00:03:03,000 +And I found the instructions for GoDaddy just to show you guys what it looks like. + +47 +00:03:03,000 --> 00:03:10,000 +So if you have GoDaddy and again this is just for demonstration purposes, if you have GoDaddy, this + +48 +00:03:10,000 --> 00:03:12,000 +is how you would add an SPF record. + +49 +00:03:12,000 --> 00:03:14,000 +It goes through the instructions. + +50 +00:03:14,000 --> 00:03:15,000 +It tells you to select your domain name. + +51 +00:03:15,000 --> 00:03:22,000 +You add a DNS record and then you're going to add basically a text record. + +52 +00:03:22,000 --> 00:03:26,000 +And in the text record you're going to put in specific values. + +53 +00:03:26,000 --> 00:03:33,000 +You're going to put in where for example, what server is going to be allowed to send out emails. + +54 +00:03:33,000 --> 00:03:34,000 +This is important. + +55 +00:03:34,000 --> 00:03:36,000 +So here's what this does. + +56 +00:03:36,000 --> 00:03:44,000 +What SPF is actually doing is that it's specifying that only these servers that I list here has the + +57 +00:03:44,000 --> 00:03:48,000 +right to send emails for this domain. + +58 +00:03:48,000 --> 00:03:54,000 +So if a spammer decides to use his server or some other server, it is not going to happen. + +59 +00:03:54,000 --> 00:03:59,000 +The domain is going to register the domain registrar, like GoDaddy is going to be like, well, the + +60 +00:03:59,000 --> 00:04:01,000 +SPF says that that server can't. + +61 +00:04:01,000 --> 00:04:03,000 +Only this server could. + +62 +00:04:03,000 --> 00:04:06,000 +So that's why you want to go and update or add an SPF record. + +63 +00:04:06,000 --> 00:04:10,000 +Another record you want to add is called a DKIM record. + +64 +00:04:11,000 --> 00:04:17,000 +This provides a method for validating a domain name identity associated with the email message through + +65 +00:04:17,000 --> 00:04:18,000 +cryptographic authentication. + +66 +00:04:18,000 --> 00:04:24,000 +What it does is that it uses a digital signature linked to the domain name to verify that the message + +67 +00:04:24,000 --> 00:04:27,000 +wasn't altered and thereby authenticating the sender. + +68 +00:04:27,000 --> 00:04:28,000 +So here's what it does. + +69 +00:04:29,000 --> 00:04:36,000 +You set up DKIM by generating by going once again to your register. + +70 +00:04:36,000 --> 00:04:38,000 +You're going to set this up with a txt record. + +71 +00:04:38,000 --> 00:04:42,000 +What it does is that it creates a signature for all your outbound emails. + +72 +00:04:42,000 --> 00:04:48,000 +What this means is that the actual, uh, email servers are digitally signed in your email. + +73 +00:04:48,000 --> 00:04:54,000 +So when people receive it, they know, okay, so it actually came from that email server. + +74 +00:04:54,000 --> 00:05:00,000 +This way when Google receives an email, their Gmail servers receives an email from your organization. + +75 +00:05:00,000 --> 00:05:04,000 +Google know it didn't come from no spammer, it came from a legitimate organization. + +76 +00:05:05,000 --> 00:05:08,000 +That's why DKIM is important. + +77 +00:05:08,000 --> 00:05:10,000 +Now the other one here is called dMarc. + +78 +00:05:10,000 --> 00:05:15,000 +It stands for domain based message authentication, reporting and conformance. + +79 +00:05:15,000 --> 00:05:21,000 +This is an email validation system designed to detect and prevent email spoofing. + +80 +00:05:22,000 --> 00:05:25,000 +It uses DKIM and SPF to determine the authenticity of the email. + +81 +00:05:25,000 --> 00:05:26,000 +Now here's how it works. + +82 +00:05:27,000 --> 00:05:30,000 +All right, this thing is more of a policy enforcer. + +83 +00:05:30,000 --> 00:05:36,000 +So the primary goal is to enable email senders and receivers to determine whether a given message align + +84 +00:05:36,000 --> 00:05:37,000 +with what they want. + +85 +00:05:37,000 --> 00:05:41,000 +If not, dMarc provides instructions on how to handle discrepancies. + +86 +00:05:41,000 --> 00:05:45,000 +So what happens if your domain receives emails? + +87 +00:05:46,000 --> 00:05:51,000 +That the other domain the senders weren't using SPF, DKIM. + +88 +00:05:52,000 --> 00:05:53,000 +What happens? + +89 +00:05:53,000 --> 00:05:56,000 +All right, this is where dMarc comes in. + +90 +00:05:56,000 --> 00:05:57,000 +dMarc comes in. + +91 +00:05:57,000 --> 00:06:01,000 +Your organization can set policies of what to do with those particular emails. + +92 +00:06:01,000 --> 00:06:09,000 +Now combine the three things the dMarc, DKIM, and SPF is how we're going to stop most spam from coming + +93 +00:06:09,000 --> 00:06:14,000 +through and from spammers using your domain name. + +94 +00:06:14,000 --> 00:06:15,000 +A few weeks ago. + +95 +00:06:15,000 --> 00:06:16,000 +This is not a joke. + +96 +00:06:16,000 --> 00:06:20,000 +A few weeks ago I have a friend that started a small business. + +97 +00:06:21,000 --> 00:06:25,000 +And he started getting a whole bunch of bounce back. + +98 +00:06:25,000 --> 00:06:31,000 +In other words, somebody was using his domain name, his email in particular with his domain name, + +99 +00:06:31,000 --> 00:06:35,000 +to start sending spam over a course of every minute. + +100 +00:06:35,000 --> 00:06:37,000 +He was getting about 1 to 200. + +101 +00:06:37,000 --> 00:06:43,000 +Bounce back that that's how much emails they were using his email to send emails like crazy. + +102 +00:06:43,000 --> 00:06:47,000 +But his his, uh, register, which was GoDaddy, was not compromised. + +103 +00:06:47,000 --> 00:06:49,000 +No one he changed the password. + +104 +00:06:49,000 --> 00:06:51,000 +Didn't stop when I checked. + +105 +00:06:51,000 --> 00:06:56,000 +He did not have the, uh, SPF and DKIM. + +106 +00:06:56,000 --> 00:07:02,000 +So what I did was I added those records, set up the dMarc, and instantly when I did that, it stopped. + +107 +00:07:02,000 --> 00:07:06,000 +This is how we're going to stop people by using these email technology. + +108 +00:07:06,000 --> 00:07:09,000 +This is how we're going to stop spammers from taking over your domain. + diff --git a/17 - Enhance Security/007 File Integrity Monitoring OB 4.5_en.srt b/17 - Enhance Security/007 File Integrity Monitoring OB 4.5_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..6cdcb4c7d0eb2da4aa3aed0aa8c83d6e6b005794 --- /dev/null +++ b/17 - Enhance Security/007 File Integrity Monitoring OB 4.5_en.srt @@ -0,0 +1,128 @@ +1 +00:00:00,000 --> 00:00:05,000 +In every network, you're going to have a whole bunch of files, whether it's data files that users + +2 +00:00:05,000 --> 00:00:12,000 +are using to produce Excel sheets to do financial analysis or accounting users paying bills. + +3 +00:00:12,000 --> 00:00:17,000 +You're also going to have operating system files, things, files that windows uses just to be windows. + +4 +00:00:18,000 --> 00:00:24,000 +Now what we want to do is we want to track if these files are being altered for malicious or in malicious + +5 +00:00:24,000 --> 00:00:24,000 +ways. + +6 +00:00:24,000 --> 00:00:29,000 +So this brings me to a class of software we call films. + +7 +00:00:29,000 --> 00:00:33,000 +These are software that can track a file has changed. + +8 +00:00:33,000 --> 00:00:37,000 +Now the key word here is integrity file integrity monitoring. + +9 +00:00:37,000 --> 00:00:38,000 +And the key word is integrity. + +10 +00:00:38,000 --> 00:00:42,000 +Remember integrity is about if things have changed. + +11 +00:00:42,000 --> 00:00:48,000 +So file integrity monitoring is critical is a critical security process that involves the detection + +12 +00:00:48,000 --> 00:00:52,000 +and alerting of changes to files and directories on a system. + +13 +00:00:52,000 --> 00:00:57,000 +Now you could set this up to detect operating system files, data files and all kinds of files. + +14 +00:00:57,000 --> 00:01:02,000 +There are tons of software like this that exist for major security manufacturers. + +15 +00:01:02,000 --> 00:01:05,000 +One of the most famous one is from a company called tripwire. + +16 +00:01:05,000 --> 00:01:08,000 +You also have sonar, SolarWinds, and so on. + +17 +00:01:08,000 --> 00:01:10,000 +That makes a ton of these types of software. + +18 +00:01:10,000 --> 00:01:13,000 +So if your company is interested, look it up. + +19 +00:01:13,000 --> 00:01:14,000 +You're going to find a lot. + +20 +00:01:14,000 --> 00:01:17,000 +Now what is it that we're trying to do? + +21 +00:01:17,000 --> 00:01:23,000 +It's used to ensure that files has not been tampered with or altered by unauthorized parties. + +22 +00:01:23,000 --> 00:01:28,000 +They typically work by creating a baseline of files that caches signs and permissions, and then continuously + +23 +00:01:28,000 --> 00:01:30,000 +monitor these files for any changes against them. + +24 +00:01:30,000 --> 00:01:32,000 +So let's talk about how this works briefly. + +25 +00:01:32,000 --> 00:01:36,000 +So the way this thing works is you install it on your computer. + +26 +00:01:36,000 --> 00:01:39,000 +It makes a baseline of all the kinds of files that you have. + +27 +00:01:39,000 --> 00:01:45,000 +If those files get modified, the software continuously monitors the system and then alerts you that + +28 +00:01:45,000 --> 00:01:46,000 +the file has been changed. + +29 +00:01:46,000 --> 00:01:48,000 +Then what you need to do is investigate that change. + +30 +00:01:48,000 --> 00:01:53,000 +It could be because of some kind of malicious reason, or it could be because somebody changed it that + +31 +00:01:53,000 --> 00:01:54,000 +they shouldn't be. + +32 +00:01:54,000 --> 00:01:59,000 +But these kinds of software is important to keep track of, of if any file has changed. + diff --git a/17 - Enhance Security/008 Network Access Control OB 4.5_en.srt b/17 - Enhance Security/008 Network Access Control OB 4.5_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..40c8e544658e189b78f5992169a0447a03d9d91f --- /dev/null +++ b/17 - Enhance Security/008 Network Access Control OB 4.5_en.srt @@ -0,0 +1,276 @@ +1 +00:00:00,000 --> 00:00:05,000 +When you're managing a network, be prepared for all kinds of computers connecting to your network. + +2 +00:00:05,000 --> 00:00:09,000 +One of the problems with this, though, is when you have computers that connect to your network. + +3 +00:00:09,000 --> 00:00:13,000 +How do you know that that computer is quote unquote healthy? + +4 +00:00:13,000 --> 00:00:18,000 +How do you know that machine has, for example, windows updated or the machine is fully updated? + +5 +00:00:18,000 --> 00:00:22,000 +How do you know the machine has valid or updated anti-malware software? + +6 +00:00:22,000 --> 00:00:26,000 +Now these kinds of things are security 101. + +7 +00:00:26,000 --> 00:00:30,000 +In other words, you shouldn't have quote unquote unhealthy machines on your network, machines that + +8 +00:00:30,000 --> 00:00:37,000 +are basically not updated or machines that are has no anti-malware that could have malware on it. + +9 +00:00:37,000 --> 00:00:40,000 +Everybody wants good, healthy machines to connect to the network. + +10 +00:00:40,000 --> 00:00:43,000 +That brings me to this technology. + +11 +00:00:43,000 --> 00:00:46,000 +This is called dnac or network access control. + +12 +00:00:47,000 --> 00:00:53,000 +Now, Nak is a kind of a technology that when you come to the network and you attempt to join it. + +13 +00:00:53,000 --> 00:00:54,000 +So let's say I have this setup. + +14 +00:00:54,000 --> 00:00:59,000 +Let's say I go to Tia and I set this particular technology up, this piece of software. + +15 +00:00:59,000 --> 00:01:02,000 +Now in Microsoft's Windows Server, you could do this. + +16 +00:01:02,000 --> 00:01:04,000 +It's called Network Access Protection. + +17 +00:01:04,000 --> 00:01:08,000 +So if you have a Windows Server, you can actually set this up with an 801 x switch. + +18 +00:01:08,000 --> 00:01:10,000 +This class isn't about setting this up. + +19 +00:01:10,000 --> 00:01:11,000 +Let me let me explain it to you. + +20 +00:01:12,000 --> 00:01:19,000 +So let's say I go to Tia and I set this up, I configure it, I set it all up and it's ready to go. + +21 +00:01:19,000 --> 00:01:25,000 +Now you, a user, comes into my network and you see a switch port and you plug your computer into the + +22 +00:01:25,000 --> 00:01:26,000 +switch. + +23 +00:01:26,000 --> 00:01:26,000 +Now here's what. + +24 +00:01:27,000 --> 00:01:28,000 +Now here's what's going to happen. + +25 +00:01:28,000 --> 00:01:34,000 +This particular piece of technology or software basically is going to check the health of the machine. + +26 +00:01:34,000 --> 00:01:41,000 +Now, if I set up my Nak server or my nap and nap or network access protection or network access control, + +27 +00:01:41,000 --> 00:01:47,000 +if I set it up that the machine has to be fully updated and the machine has to have good anti-malware + +28 +00:01:47,000 --> 00:01:49,000 +to basically it's going to check that on your machine. + +29 +00:01:49,000 --> 00:01:54,000 +If your machine meets my health check, I'm going to give you an IP address and allow you to join this + +30 +00:01:54,000 --> 00:01:55,000 +network. + +31 +00:01:55,000 --> 00:02:00,000 +In other words, you have access to general resources on this particular or the Tia network. + +32 +00:02:00,000 --> 00:02:03,000 +Now let's say you don't meet the health policies. + +33 +00:02:03,000 --> 00:02:08,000 +Let's say your machine isn't updated and you don't have any anti malware on your machine. + +34 +00:02:08,000 --> 00:02:12,000 +Well then we're going to put you in a remediation network. + +35 +00:02:12,000 --> 00:02:16,000 +And network you don't really get access to much resources, maybe just the internet. + +36 +00:02:16,000 --> 00:02:19,000 +So you can go and download those updates and antivirus. + +37 +00:02:19,000 --> 00:02:25,000 +What this technology does is that it's going to allow computers on your network to stay healthy. + +38 +00:02:25,000 --> 00:02:30,000 +It's going to ensure that all computers on your network meets a certain health compliance that you set + +39 +00:02:30,000 --> 00:02:30,000 +up. + +40 +00:02:30,000 --> 00:02:31,000 +So what is the goal here? + +41 +00:02:31,000 --> 00:02:38,000 +Well, it's to prevent unauthorized access to network resources and to ensure that all devices and users + +42 +00:02:38,000 --> 00:02:42,000 +comply with whatever policies and baselines that you have set up. + +43 +00:02:42,000 --> 00:02:47,000 +This is going to help mitigate all kinds of risk for noncompliance or infected device, because, first + +44 +00:02:47,000 --> 00:02:52,000 +of all, if the device is infected or the device doesn't meet a certain health check, it's not going + +45 +00:02:52,000 --> 00:02:55,000 +to allow that device to join that particular network. + +46 +00:02:55,000 --> 00:03:00,000 +What it's doing is that it's going to do health checks, assessing the security status of the device, + +47 +00:03:00,000 --> 00:03:04,000 +including the presence of antivirus system updates and even security patches. + +48 +00:03:04,000 --> 00:03:07,000 +It could do other things, but these are just some of the things it could do. + +49 +00:03:07,000 --> 00:03:13,000 +This is going to help you to stay in compliance with regulations, help an organization stay in compliance + +50 +00:03:13,000 --> 00:03:19,000 +with regulations such as HIPAA regulation, for example, you can't really have machines infected or + +51 +00:03:19,000 --> 00:03:20,000 +machines that's not encrypted. + +52 +00:03:20,000 --> 00:03:22,000 +Now what does it do? + +53 +00:03:22,000 --> 00:03:25,000 +Well, the way it works is like this pre admissions. + +54 +00:03:25,000 --> 00:03:29,000 +This means before it allows you to join the network. + +55 +00:03:29,000 --> 00:03:33,000 +It includes devices authentication and policy enforcement before allowing. + +56 +00:03:33,000 --> 00:03:38,000 +So what it's going to do is that it has to authenticate you and it has to check if those policies are + +57 +00:03:38,000 --> 00:03:41,000 +there after it's post. + +58 +00:03:41,000 --> 00:03:46,000 +Admission involves continuous monitoring of the device to ensure it remained compliant, so you better + +59 +00:03:46,000 --> 00:03:51,000 +ensure that your computer stays updated and has the latest Anti-Malware software. + +60 +00:03:52,000 --> 00:03:59,000 +Network Access Control, or NAC, is a, in my opinion, one of the most important things that we should + +61 +00:03:59,000 --> 00:04:00,000 +be doing in networks today. + +62 +00:04:00,000 --> 00:04:06,000 +The reason is because you never want computers join a network that is outdated or just doesn't have + +63 +00:04:06,000 --> 00:04:09,000 +the right malware anti-malware software. + +64 +00:04:09,000 --> 00:04:14,000 +The reason is because remember, if one computer gets infected and you allow it to join, it might start + +65 +00:04:14,000 --> 00:04:15,000 +infecting everyone else. + +66 +00:04:15,000 --> 00:04:16,000 +Think of like a flu. + +67 +00:04:16,000 --> 00:04:19,000 +You allow somebody in in your family to have flu. + +68 +00:04:19,000 --> 00:04:21,000 +That person can then spread it to all the others. + +69 +00:04:21,000 --> 00:04:25,000 +So let's just keep the unhealthy machines off our networks. + diff --git a/17 - Enhance Security/009 EDR OB 4.5_en.srt b/17 - Enhance Security/009 EDR OB 4.5_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..a97d1f095866b106fb1919ef6d6b603d62c926d8 --- /dev/null +++ b/17 - Enhance Security/009 EDR OB 4.5_en.srt @@ -0,0 +1,144 @@ +1 +00:00:00,000 --> 00:00:05,000 +One piece of software that has become incredibly popular in corporate environments today is the software + +2 +00:00:05,000 --> 00:00:07,000 +we're going to call EDR. + +3 +00:00:07,000 --> 00:00:12,000 +Our EDR endpoint detection and response and extended detection and response. + +4 +00:00:12,000 --> 00:00:19,000 +What these are are basically a really good security solutions designed basically for comprehensive threat + +5 +00:00:19,000 --> 00:00:21,000 +detection, analysis and response. + +6 +00:00:21,000 --> 00:00:27,000 +Now these kinds of software famous a very famous one is done by CrowdStrike, which you guys can check + +7 +00:00:27,000 --> 00:00:28,000 +out online. + +8 +00:00:29,000 --> 00:00:34,000 +And there is a ton of others also now EDR software, basically what it's going to do is things that + +9 +00:00:34,000 --> 00:00:39,000 +you're going to install on things like laptops, workstations and mobile devices. + +10 +00:00:39,000 --> 00:00:45,000 +They're basically going to be looking to detect, investigate and mitigate suspicious activity on all + +11 +00:00:45,000 --> 00:00:46,000 +the endpoints. + +12 +00:00:46,000 --> 00:00:51,000 +Now, endpoints is anything that can basically be infected, like some of the names that they have here. + +13 +00:00:51,000 --> 00:00:53,000 +Now EDR software does a few things. + +14 +00:00:53,000 --> 00:00:55,000 +Number one, continuous monitoring. + +15 +00:00:55,000 --> 00:00:59,000 +It continuously monitors all of the endpoint devices. + +16 +00:00:59,000 --> 00:01:02,000 +Endpoint devices are anything you can consider. + +17 +00:01:02,000 --> 00:01:04,000 +Anything that could bring in malware. + +18 +00:01:04,000 --> 00:01:06,000 +Whether it's a server, it's a laptop, it's a workstation. + +19 +00:01:06,000 --> 00:01:08,000 +It's some kind of mobile device. + +20 +00:01:08,000 --> 00:01:10,000 +It's a type of an IoT device. + +21 +00:01:10,000 --> 00:01:14,000 +Doesn't matter what it is, if you can get malware in there, you can get or you can use it to inject + +22 +00:01:14,000 --> 00:01:14,000 +malware. + +23 +00:01:14,000 --> 00:01:16,000 +It's some kind of an endpoint. + +24 +00:01:16,000 --> 00:01:22,000 +So basically this thing is going to continuously monitor your devices to see if threats are happening + +25 +00:01:22,000 --> 00:01:24,000 +or if there is a threat on the machine. + +26 +00:01:24,000 --> 00:01:26,000 +It's going to be able to detect the threat. + +27 +00:01:26,000 --> 00:01:29,000 +That's one of the main things utilizes advanced analytics. + +28 +00:01:29,000 --> 00:01:33,000 +Now, sometimes it's going to use all kinds of cloud based technology to do this. + +29 +00:01:33,000 --> 00:01:35,000 +And then response to that. + +30 +00:01:35,000 --> 00:01:37,000 +This thing is going to offer all kinds of malware. + +31 +00:01:37,000 --> 00:01:43,000 +And a lot of these, you know, a lot of these EDR software is going to come with the ability to respond + +32 +00:01:43,000 --> 00:01:46,000 +to these particular threats and removed all kinds of malware. + +33 +00:01:47,000 --> 00:01:52,000 +This kind of software is getting more and more popular in technology in companies to today. + +34 +00:01:52,000 --> 00:01:54,000 +That utilizes a lot of technology. + +35 +00:01:54,000 --> 00:01:55,000 +You know why? + +36 +00:01:55,000 --> 00:01:58,000 +Because the malware itself is becoming more complex. + diff --git a/17 - Enhance Security/010 User Behavior Analytics OB 4.5_en.srt b/17 - Enhance Security/010 User Behavior Analytics OB 4.5_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..ab47bbbd845bc5bf03313d4c828fad2813a88482 --- /dev/null +++ b/17 - Enhance Security/010 User Behavior Analytics OB 4.5_en.srt @@ -0,0 +1,184 @@ +1 +00:00:00,000 --> 00:00:06,000 +Organizations today are building profiles of how users use a computer. + +2 +00:00:06,000 --> 00:00:08,000 +Organizations today will know how you're going to use a computer. + +3 +00:00:08,000 --> 00:00:12,000 +Like how much data do you transfer at 9:00? + +4 +00:00:12,000 --> 00:00:15,000 +What kind of files do you access between 9 and 10:00 in the morning? + +5 +00:00:15,000 --> 00:00:22,000 +What the company is doing is they're doing a profile of you and what we're going to call user behavior + +6 +00:00:22,000 --> 00:00:23,000 +analytics. + +7 +00:00:23,000 --> 00:00:29,000 +What this has done is basically monitor and evaluate the user behavior on IT systems and network. + +8 +00:00:29,000 --> 00:00:31,000 +And if you're wondering, well, why would they want to do that? + +9 +00:00:31,000 --> 00:00:38,000 +Why would they want to create a profile of how I use the systems, what kind of files I access, how + +10 +00:00:38,000 --> 00:00:45,000 +much data I transfer, what devices I access when I access device, the, the server or the or the network. + +11 +00:00:45,000 --> 00:00:47,000 +Where do I access it from? + +12 +00:00:47,000 --> 00:00:49,000 +You might ask yourself, why are they doing this? + +13 +00:00:49,000 --> 00:00:51,000 +Because that's what behavior analytics is. + +14 +00:00:51,000 --> 00:00:53,000 +It's how you use the system. + +15 +00:00:53,000 --> 00:00:58,000 +It involves collecting, analyzing data on how users interact with the systems and network. + +16 +00:00:58,000 --> 00:01:01,000 +This includes access to systems, data, network operations. + +17 +00:01:01,000 --> 00:01:03,000 +If you're asking Andrew, why are they doing that? + +18 +00:01:03,000 --> 00:01:05,000 +Why are they collecting all this data on me? + +19 +00:01:05,000 --> 00:01:13,000 +Well, that's because they want to be able to detect abnormal and deviations from normal user behavior + +20 +00:01:13,000 --> 00:01:18,000 +that could indicate potential security threats, such as insider threats, compromise accounts, and + +21 +00:01:18,000 --> 00:01:23,000 +even compromise accounts or external attacks using stolen credentials. + +22 +00:01:23,000 --> 00:01:24,000 +Let me give you some examples. + +23 +00:01:25,000 --> 00:01:26,000 +Let's say your company is doing this. + +24 +00:01:26,000 --> 00:01:32,000 +Let's say your company creates a user behavior analytical profile on you. + +25 +00:01:32,000 --> 00:01:37,000 +And they know that at 9:00 you log in generally from this computer. + +26 +00:01:37,000 --> 00:01:39,000 +You access these particular files. + +27 +00:01:39,000 --> 00:01:43,000 +You stay you stay using those files from 9 to 12:00. + +28 +00:01:43,000 --> 00:01:46,000 +Then you go away for lunch and so on and so on, basically the entire day. + +29 +00:01:46,000 --> 00:01:49,000 +And you do this almost in a everyday basis. + +30 +00:01:49,000 --> 00:01:56,000 +Now, what if on Thursday you decide to take the day off, but all of a sudden your account starts to + +31 +00:01:56,000 --> 00:02:00,000 +access files, but not from that IP address from a different IP address. + +32 +00:02:00,000 --> 00:02:06,000 +Then it starts to access all kinds of files that generally you don't access, and it starts to download + +33 +00:02:06,000 --> 00:02:08,000 +it to its local machine. + +34 +00:02:08,000 --> 00:02:08,000 +What does that sound like? + +35 +00:02:08,000 --> 00:02:12,000 +That sounds like somebody may be using your credentials that could have been stolen. + +36 +00:02:13,000 --> 00:02:17,000 +It sounds like data is being stolen from the organization. + +37 +00:02:17,000 --> 00:02:21,000 +Now all of a sudden, because they have this user profile on you. + +38 +00:02:21,000 --> 00:02:24,000 +Basically, now they can come in and say, well, this is abnormal. + +39 +00:02:24,000 --> 00:02:29,000 +Shut this user down or shut, or get this person off the network and then they can verify with you, + +40 +00:02:29,000 --> 00:02:30,000 +were you doing this? + +41 +00:02:30,000 --> 00:02:31,000 +And you're going to say, no, I wasn't me, okay. + +42 +00:02:31,000 --> 00:02:34,000 +That way they're able to minimize this attack. + +43 +00:02:34,000 --> 00:02:40,000 +So this is something that is very useful in the world of it, because we need to know how users interact + +44 +00:02:40,000 --> 00:02:41,000 +with our systems. + +45 +00:02:41,000 --> 00:02:48,000 +That way if somebody does something abnormal, we can detect it and see if it was actually them or a + +46 +00:02:48,000 --> 00:02:49,000 +hacker. + diff --git a/17 - Enhance Security/011 Deception and Disruption Technology OB 1.2_en.srt b/17 - Enhance Security/011 Deception and Disruption Technology OB 1.2_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..28c5cd1a0e526c760d9620e3e8eab0b80a5f1fc6 --- /dev/null +++ b/17 - Enhance Security/011 Deception and Disruption Technology OB 1.2_en.srt @@ -0,0 +1,400 @@ +1 +00:00:00,000 --> 00:00:05,000 +Any time an attacker breaks into the organization, they're going to immediately start looking for the + +2 +00:00:05,000 --> 00:00:06,000 +good stuff. + +3 +00:00:06,000 --> 00:00:11,000 +They're going to start looking for things like servers that have credit card information, your customer's + +4 +00:00:11,000 --> 00:00:14,000 +credit card, or your employees private information. + +5 +00:00:14,000 --> 00:00:16,000 +They're going to start looking for business secrets. + +6 +00:00:16,000 --> 00:00:21,000 +Now, the best thing we can do is, of course, to secure these things. + +7 +00:00:21,000 --> 00:00:25,000 +Another thing we should be doing is just give it to them. + +8 +00:00:25,000 --> 00:00:27,000 +Yeah, that sounds kind of crazy, right? + +9 +00:00:27,000 --> 00:00:33,000 +You see, there is an old saying if somebody breaks into the organization, just give them what they + +10 +00:00:33,000 --> 00:00:34,000 +want so they can go, right. + +11 +00:00:34,000 --> 00:00:37,000 +It's an all time thing that people would do before. + +12 +00:00:37,000 --> 00:00:40,000 +In the world of information technology, we have these things. + +13 +00:00:40,000 --> 00:00:44,000 +And this is going to be called like honey pots, honey nets, honey files, honey tokens. + +14 +00:00:44,000 --> 00:00:48,000 +You see what these are are decoy systems and decoy data. + +15 +00:00:48,000 --> 00:00:53,000 +Basically what we're going to do is we're going to set up a system that when people break into the organization, + +16 +00:00:53,000 --> 00:00:56,000 +they're going to get a system that looks legit. + +17 +00:00:56,000 --> 00:00:59,000 +It has or what they believe legit data. + +18 +00:00:59,000 --> 00:01:02,000 +It has data that looks good to them. + +19 +00:01:02,000 --> 00:01:04,000 +Basically it's honey for them. + +20 +00:01:04,000 --> 00:01:10,000 +You see, if we give them what they want, they're probably just going to take it and go instead of + +21 +00:01:10,000 --> 00:01:13,000 +just keep looking around for the actual information. + +22 +00:01:14,000 --> 00:01:18,000 +Now what we're trying to do here is basically deceive them. + +23 +00:01:18,000 --> 00:01:19,000 +That's basically what we're trying to do. + +24 +00:01:19,000 --> 00:01:25,000 +So deception and disruption technology refers to a set of cybersecurity strategies and tools designed + +25 +00:01:25,000 --> 00:01:28,000 +to we want to mislead them. + +26 +00:01:28,000 --> 00:01:34,000 +We want to confuse them or disrupt the actions of these bad people or malicious actors. + +27 +00:01:34,000 --> 00:01:41,000 +These technologies are going to use to create traps or illusions that protected real network assets. + +28 +00:01:42,000 --> 00:01:47,000 +That protected real network assets by diverting attackers to decoy systems or files. + +29 +00:01:47,000 --> 00:01:51,000 +So what we're going to do is we're going to want to create a trap, and what we're going to do is actually + +30 +00:01:51,000 --> 00:01:56,000 +we're protecting our real network, because what we're doing is we're going to be giving them a decoy + +31 +00:01:56,000 --> 00:01:57,000 +system or a fake system. + +32 +00:01:57,000 --> 00:02:01,000 +Now let's go through some of the different technologies we want to be familiar with. + +33 +00:02:01,000 --> 00:02:02,000 +The first one is a honeypot. + +34 +00:02:03,000 --> 00:02:04,000 +Now, what exactly is this? + +35 +00:02:04,000 --> 00:02:06,000 +Well, a honeypot is basically a big server. + +36 +00:02:06,000 --> 00:02:10,000 +It's a system on your network that has big data on it. + +37 +00:02:10,000 --> 00:02:16,000 +So a honeypot is a security mechanism set up to detect deflate or. + +38 +00:02:16,000 --> 00:02:20,000 +Are study hacking attempts. + +39 +00:02:20,000 --> 00:02:21,000 +I want you to point that out. + +40 +00:02:21,000 --> 00:02:22,000 +Study hacking attempts. + +41 +00:02:22,000 --> 00:02:28,000 +You see, let's say somebody breaks into your organization and you have this server that looks all beautiful + +42 +00:02:28,000 --> 00:02:30,000 +and sweet, like this honeypot here. + +43 +00:02:31,000 --> 00:02:37,000 +So they break in and they see the server and you call it a financial file server. + +44 +00:02:37,000 --> 00:02:39,000 +So it has a good name. + +45 +00:02:39,000 --> 00:02:42,000 +They look at it, the hacker goes, oh this looks great. + +46 +00:02:42,000 --> 00:02:43,000 +All the financial data is there. + +47 +00:02:43,000 --> 00:02:44,000 +They double click on it right. + +48 +00:02:44,000 --> 00:02:45,000 +They try to get into it. + +49 +00:02:45,000 --> 00:02:49,000 +Now it's probably going to have some vulnerabilities that should be easily exploitable. + +50 +00:02:49,000 --> 00:02:52,000 +So they get in and they start to see all this data. + +51 +00:02:52,000 --> 00:02:54,000 +So what are we doing now. + +52 +00:02:54,000 --> 00:02:56,000 +We have all kinds of detection software in that server. + +53 +00:02:56,000 --> 00:02:59,000 +So we can detect this attempted intrusion. + +54 +00:02:59,000 --> 00:03:05,000 +What we did do is we basically deflect the intrusion the the intrusion off to somebody else. + +55 +00:03:05,000 --> 00:03:06,000 +Right. + +56 +00:03:06,000 --> 00:03:12,000 +Because instead of them looking for the actual financial server there have been deflected to this fake + +57 +00:03:12,000 --> 00:03:13,000 +server that we set up. + +58 +00:03:13,000 --> 00:03:17,000 +And now what we could do is we could study the hacking attempts basically. + +59 +00:03:17,000 --> 00:03:23,000 +Now we could see how exactly are they, how how are they getting in, what techniques are they using? + +60 +00:03:23,000 --> 00:03:28,000 +It's basically a decoy intimidating a real computer system or network. + +61 +00:03:28,000 --> 00:03:30,000 +But it's isolated and it's heavily monitored. + +62 +00:03:30,000 --> 00:03:34,000 +Attackers will engage with the honeypot, provide valuable information about their techniques. + +63 +00:03:34,000 --> 00:03:39,000 +Remember, again, we're studying it and intentions without endangering actual network. + +64 +00:03:39,000 --> 00:03:39,000 +Why? + +65 +00:03:39,000 --> 00:03:42,000 +Because what's there we know it doesn't have anything secure. + +66 +00:03:42,000 --> 00:03:46,000 +Now, if you want to go all out, I would suggest you set up a honey net. + +67 +00:03:46,000 --> 00:03:52,000 +It's basically a bunch of these honeypots, a bunch of these fake systems to simulate a whole network + +68 +00:03:52,000 --> 00:03:52,000 +environment. + +69 +00:03:52,000 --> 00:03:56,000 +So they're going to think, wow, we just got the mother lode of the entire company. + +70 +00:03:56,000 --> 00:03:57,000 +We just got the whole network. + +71 +00:03:57,000 --> 00:03:59,000 +But basically it's a fake network. + +72 +00:03:59,000 --> 00:04:04,000 +It's much more complex, but it does provide deeper insights on how they can interact with network components, + +73 +00:04:04,000 --> 00:04:06,000 +what strategy they use, and how they move. + +74 +00:04:07,000 --> 00:04:08,000 +Within that network. + +75 +00:04:08,000 --> 00:04:11,000 +Now another one you have is going to be a honey file. + +76 +00:04:11,000 --> 00:04:14,000 +Now honey files you can put on different systems. + +77 +00:04:14,000 --> 00:04:15,000 +You can put them on legitimate system. + +78 +00:04:15,000 --> 00:04:20,000 +Now these are going to be decoy files placed within a networks file system. + +79 +00:04:20,000 --> 00:04:24,000 +Honey files are designed to appear legitimate and contains, uh, attractive data. + +80 +00:04:24,000 --> 00:04:26,000 +So you may name a honey file. + +81 +00:04:27,000 --> 00:04:29,000 +Username and passwords. + +82 +00:04:29,000 --> 00:04:35,000 +You may name a honey file something as a customer's credit card information, but what you're doing + +83 +00:04:35,000 --> 00:04:38,000 +is you're going to put it on the server, you're going to leave it there. + +84 +00:04:38,000 --> 00:04:41,000 +And if anybody tries to access this, you're going to know, because you're monitoring this file. + +85 +00:04:41,000 --> 00:04:47,000 +Any kind of access to the honey file can alert security professionals, uh, personnel about this. + +86 +00:04:47,000 --> 00:04:50,000 +Another thing you might have is something called a honey token. + +87 +00:04:50,000 --> 00:04:52,000 +And this is a little bit more granular. + +88 +00:04:52,000 --> 00:04:56,000 +A honey token is a broader tum refers to any decoy data or token inserted into a system. + +89 +00:04:56,000 --> 00:05:02,000 +Now, it could be things like a fake user account, even a database record, or the type of digital + +90 +00:05:02,000 --> 00:05:03,000 +bait. + +91 +00:05:04,000 --> 00:05:09,000 +So, for example, inserting fake records into a customer's database. + +92 +00:05:09,000 --> 00:05:14,000 +And if anybody tries to pull or manipulate that data, it would alert a security professional. + +93 +00:05:14,000 --> 00:05:15,000 +So there would be a honey token. + +94 +00:05:16,000 --> 00:05:18,000 +Honey nets are incredibly popular. + +95 +00:05:19,000 --> 00:05:22,000 +Uh, honey pots are also incredibly popular. + +96 +00:05:22,000 --> 00:05:22,000 +Why? + +97 +00:05:22,000 --> 00:05:26,000 +Because remember, like I said, when somebody breaks into your house, give them what they want so + +98 +00:05:26,000 --> 00:05:27,000 +they can go. + +99 +00:05:27,000 --> 00:05:29,000 +That's the easiest way to do it. + +100 +00:05:29,000 --> 00:05:33,000 +And an IT security, we're basically going to do the same with these technology. + diff --git a/17 - Enhance Security/012 Automation and Orchestration OB 4.7_en.srt b/17 - Enhance Security/012 Automation and Orchestration OB 4.7_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..8cef44288ee7f9b7ec500661dab2edcffe4028cb --- /dev/null +++ b/17 - Enhance Security/012 Automation and Orchestration OB 4.7_en.srt @@ -0,0 +1,832 @@ +1 +00:00:00,000 --> 00:00:06,000 +When it comes to managing an IT system across a large network, dealing with a large number of users, + +2 +00:00:06,000 --> 00:00:13,000 +you need to automate as many things as possible without automation and or orchestration. + +3 +00:00:13,000 --> 00:00:18,000 +Keep in mind, orchestration generally means to automate things when it comes to orchestrations within + +4 +00:00:18,000 --> 00:00:22,000 +large networks, one of the best ways to do that is with scripting. + +5 +00:00:22,000 --> 00:00:26,000 +You see in it we have many, many tasks that are just repetitive over and over. + +6 +00:00:26,000 --> 00:00:28,000 +So why would you have humans do that? + +7 +00:00:28,000 --> 00:00:30,000 +If you can just have a script that does it? + +8 +00:00:30,000 --> 00:00:36,000 +There are also times when we need to respond to things quickly, and if we are dependent on humans to + +9 +00:00:36,000 --> 00:00:37,000 +do it, it might take a while. + +10 +00:00:37,000 --> 00:00:42,000 +But if we have some kind of a script or automation to do that, it will probably be better. + +11 +00:00:42,000 --> 00:00:49,000 +So in this video, we're going to go through some of the practical applications or the use cases for + +12 +00:00:49,000 --> 00:00:50,000 +scripting. + +13 +00:00:50,000 --> 00:00:50,000 +All right. + +14 +00:00:50,000 --> 00:00:52,000 +So where can we apply scripting from. + +15 +00:00:52,000 --> 00:00:57,000 +Because scripting is how we're going to get that automation and orchestration that we need in order + +16 +00:00:57,000 --> 00:01:00,000 +to keep our networks running smoothly. + +17 +00:01:00,000 --> 00:01:04,000 +So let's go through some of the things here that scripting can help us with. + +18 +00:01:04,000 --> 00:01:06,000 +So the first thing up is user provisioning. + +19 +00:01:06,000 --> 00:01:08,000 +This is one of the best things that a script can do. + +20 +00:01:08,000 --> 00:01:13,000 +So automated in user provisioning involves scripts or automated workflows. + +21 +00:01:13,000 --> 00:01:15,000 +To create manage accounts. + +22 +00:01:15,000 --> 00:01:20,000 +We can have scripts that can create accounts and delete accounts or disable accounts on the fly. + +23 +00:01:20,000 --> 00:01:24,000 +This includes setting up accounts, assigning privileges, removing access. + +24 +00:01:24,000 --> 00:01:29,000 +So instead of having somebody right click Open Active Directory, right click make a user create passwords, + +25 +00:01:29,000 --> 00:01:30,000 +put them. + +26 +00:01:30,000 --> 00:01:32,000 +We can automate the entire thing. + +27 +00:01:32,000 --> 00:01:33,000 +We just put in a few parameters. + +28 +00:01:33,000 --> 00:01:35,000 +Run a script and we're done. + +29 +00:01:36,000 --> 00:01:37,000 +Resource provisioning. + +30 +00:01:37,000 --> 00:01:46,000 +So this in this use case involves automatically allocating and managing computer resources such as CPU + +31 +00:01:46,000 --> 00:01:46,000 +and memory. + +32 +00:01:47,000 --> 00:01:51,000 +Automations help in dynamically adjusting resources, so if you have a system. + +33 +00:01:52,000 --> 00:01:56,000 +That you're running on a particular, you're running a particular service, and you need to readjust + +34 +00:01:56,000 --> 00:01:58,000 +the hardware allocation in that system. + +35 +00:01:58,000 --> 00:02:00,000 +You can write a script that does that. + +36 +00:02:00,000 --> 00:02:02,000 +You don't have to go and manually do it. + +37 +00:02:02,000 --> 00:02:04,000 +Another case where this can help. + +38 +00:02:04,000 --> 00:02:05,000 +Guardrails. + +39 +00:02:05,000 --> 00:02:06,000 +Guardrails. + +40 +00:02:07,000 --> 00:02:08,000 +You do this too? + +41 +00:02:08,000 --> 00:02:15,000 +Automation involves setting up scripts or automated security controls to enforce security policies for + +42 +00:02:15,000 --> 00:02:16,000 +operational best practices. + +43 +00:02:16,000 --> 00:02:17,000 +Limits. + +44 +00:02:17,000 --> 00:02:23,000 +This includes limits on user access, automated compliance checks, and restrictions on type of action. + +45 +00:02:23,000 --> 00:02:30,000 +So guardrails are basically if a user attempts to do a task that they weren't supposed to be doing. + +46 +00:02:30,000 --> 00:02:36,000 +Basically, scripts can come in and and deny access to that thing that they're trying to do. + +47 +00:02:36,000 --> 00:02:40,000 +This, of course, limits them or puts a guardrail around them so they can't get out. + +48 +00:02:41,000 --> 00:02:43,000 +Security groups. + +49 +00:02:43,000 --> 00:02:45,000 +Automation is used to manage security groups. + +50 +00:02:45,000 --> 00:02:46,000 +What is security groups? + +51 +00:02:46,000 --> 00:02:51,000 +So think of like the accountant, the salespeople, the accountant or the sales groups, which are a + +52 +00:02:51,000 --> 00:02:55,000 +set of users or systems that have common security requirements. + +53 +00:02:55,000 --> 00:02:57,000 +Now scripts are automated. + +54 +00:02:57,000 --> 00:03:03,000 +Tools can ensure these groups are kept up to date, so we can write scripts to remove users when that + +55 +00:03:03,000 --> 00:03:05,000 +person leaves or that account is deleted. + +56 +00:03:05,000 --> 00:03:08,000 +And we can also write scripts to add people to security groups. + +57 +00:03:08,000 --> 00:03:09,000 +Tickets. + +58 +00:03:10,000 --> 00:03:15,000 +In incident response service management automation plays a critical role. + +59 +00:03:15,000 --> 00:03:15,000 +Why? + +60 +00:03:15,000 --> 00:03:18,000 +Because remember what ticketing is when it comes to tickets. + +61 +00:03:18,000 --> 00:03:19,000 +And we're not talking those tickets. + +62 +00:03:19,000 --> 00:03:24,000 +Actually, when it comes to ticket we're talking help desk tickets. + +63 +00:03:24,000 --> 00:03:29,000 +So help desk tickets is when somebody has a problem with their computer, they call the local help desk. + +64 +00:03:29,000 --> 00:03:30,000 +Help desk creates a ticket. + +65 +00:03:30,000 --> 00:03:35,000 +Now that ticket is going to have to go through like the ticket is open. + +66 +00:03:35,000 --> 00:03:36,000 +The ticket is analyzed. + +67 +00:03:36,000 --> 00:03:38,000 +The ticket, uh, we fixed the problem. + +68 +00:03:38,000 --> 00:03:40,000 +The ticket has to be closed. + +69 +00:03:40,000 --> 00:03:45,000 +Automation can help detect any kind of problems with issuing and generating that ticket. + +70 +00:03:45,000 --> 00:03:50,000 +And it can also do things such as close the ticket for you or let the user know the ticket is closed. + +71 +00:03:50,000 --> 00:03:54,000 +But one of the main things is going to do is it's going to ensure that potential security incidents + +72 +00:03:55,000 --> 00:03:56,000 +are promptly recorded and addressed. + +73 +00:03:56,000 --> 00:04:00,000 +You see, all security incidents are generally reported to the help desk. + +74 +00:04:00,000 --> 00:04:05,000 +If you have an automated system that does it that keeps the track of these tickets, it just makes recording + +75 +00:04:05,000 --> 00:04:07,000 +those security incidents better. + +76 +00:04:09,000 --> 00:04:09,000 +Escalation. + +77 +00:04:09,000 --> 00:04:17,000 +We can use automation in escalation involved using scripts or tool to identify high priority incidents + +78 +00:04:17,000 --> 00:04:18,000 +and escalate them. + +79 +00:04:18,000 --> 00:04:21,000 +So let's say a security incident comes right into the help desk. + +80 +00:04:21,000 --> 00:04:25,000 +And in the help desk it comes it has these potential characteristics. + +81 +00:04:25,000 --> 00:04:31,000 +We can write scripts that looks at those characteristics and say, well, this here has to be escalated + +82 +00:04:31,000 --> 00:04:34,000 +up to level two or level three IT security support. + +83 +00:04:34,000 --> 00:04:38,000 +This saves time, especially when it's a critical issue. + +84 +00:04:39,000 --> 00:04:41,000 +Enable and disable and services. + +85 +00:04:42,000 --> 00:04:48,000 +So automation can help start and stop certain services on systems. + +86 +00:04:48,000 --> 00:04:56,000 +Scripts can automatically disable access for users who are no longer needed, uh, or it enables for + +87 +00:04:56,000 --> 00:05:02,000 +users based on a predefined so we can run certain services when needed. + +88 +00:05:02,000 --> 00:05:07,000 +When not needed, we can add users to those servers or remove users when not needed. + +89 +00:05:07,000 --> 00:05:11,000 +Can continuous integration and testing. + +90 +00:05:11,000 --> 00:05:11,000 +So. + +91 +00:05:12,000 --> 00:05:14,000 +When users, when not users. + +92 +00:05:14,000 --> 00:05:19,000 +When programmers write codes, what happens as they write code? + +93 +00:05:19,000 --> 00:05:26,000 +We can test the code as they're writing, so we're consistently integrating and testing codes. + +94 +00:05:26,000 --> 00:05:31,000 +Automation is used for continuous integration and testing, where code changes are automatically tested + +95 +00:05:31,000 --> 00:05:32,000 +for security flaws. + +96 +00:05:32,000 --> 00:05:36,000 +So the moment people write code, we can test the code before pushing it out. + +97 +00:05:36,000 --> 00:05:40,000 +This helps early detection of code or any kind of software development issues. + +98 +00:05:40,000 --> 00:05:41,000 +Now. + +99 +00:05:41,000 --> 00:05:42,000 +APIs. + +100 +00:05:43,000 --> 00:05:50,000 +Automation will involve the use of many APIs to integrate different tools. + +101 +00:05:50,000 --> 00:05:54,000 +If we're going to be automating this system to communicate with this system, you bet. + +102 +00:05:54,000 --> 00:05:57,000 +Our best bet to allow two systems to communicate. + +103 +00:05:57,000 --> 00:06:00,000 +We're going to use some kind of API to have them integrate. + +104 +00:06:00,000 --> 00:06:02,000 +This is going to allow data exchanges on system. + +105 +00:06:03,000 --> 00:06:10,000 +Now automation is going to have quite a few benefits that we want. + +106 +00:06:10,000 --> 00:06:10,000 +All right. + +107 +00:06:10,000 --> 00:06:16,000 +They just not only enhance security by being able, for example, respond to tickets quickly and escalate + +108 +00:06:16,000 --> 00:06:18,000 +those tickets quickly like we just mentioned before. + +109 +00:06:18,000 --> 00:06:22,000 +But they're going to have some other benefits that we want to consider. + +110 +00:06:22,000 --> 00:06:23,000 +Number one. + +111 +00:06:23,000 --> 00:06:31,000 +Automation in its nature is able to save time because automation, we don't have to wait for somebody + +112 +00:06:31,000 --> 00:06:34,000 +to come and manually do the task. + +113 +00:06:34,000 --> 00:06:39,000 +So automation significantly reduces the time to perform repetitive or complex tasks. + +114 +00:06:39,000 --> 00:06:42,000 +It frees up your IT staff to do other things. + +115 +00:06:42,000 --> 00:06:45,000 +It enforces a particular baseline. + +116 +00:06:46,000 --> 00:06:47,000 +Remember what's a baseline? + +117 +00:06:47,000 --> 00:06:53,000 +A baseline is a standard set of configuration that a computer has any changes to. + +118 +00:06:53,000 --> 00:06:56,000 +That would be a variation for the baseline, maybe against security policy. + +119 +00:06:57,000 --> 00:07:01,000 +Now where automation comes in or scripting, they're going to automatically enforce this across all + +120 +00:07:01,000 --> 00:07:03,000 +the systems. + +121 +00:07:03,000 --> 00:07:08,000 +If there is anything that comes out of compliance, automation can tell you that this system is out + +122 +00:07:08,000 --> 00:07:09,000 +of compliance. + +123 +00:07:10,000 --> 00:07:13,000 +It standardizes infrastructure configuration. + +124 +00:07:13,000 --> 00:07:17,000 +Automation helps in doing that reduces the risk of configuration errors. + +125 +00:07:17,000 --> 00:07:22,000 +Now let's say you got to configure ten switches on a network. + +126 +00:07:22,000 --> 00:07:24,000 +And it must have all the same configs. + +127 +00:07:24,000 --> 00:07:30,000 +Well you could give it to different uh network engineers or to configure it. + +128 +00:07:30,000 --> 00:07:36,000 +Or you can just run a script and have the script configure them all at the same time with the same configuration. + +129 +00:07:36,000 --> 00:07:39,000 +So this reduces the risk of configuration errors. + +130 +00:07:40,000 --> 00:07:41,000 +Now scaling. + +131 +00:07:42,000 --> 00:07:48,000 +Of course, the more we're able to do right, the bigger our systems can get. + +132 +00:07:48,000 --> 00:07:51,000 +It allows us to scale our operations. + +133 +00:07:51,000 --> 00:07:53,000 +If we don't have automation, we can't scale. + +134 +00:07:53,000 --> 00:07:56,000 +Because remember, scale means to get bigger. + +135 +00:07:56,000 --> 00:07:57,000 +If we get bigger. + +136 +00:07:58,000 --> 00:08:02,000 +The manpower is going to be too much that we're going to need to maintain without automation. + +137 +00:08:02,000 --> 00:08:03,000 +It helps us to grow. + +138 +00:08:03,000 --> 00:08:04,000 +It helps us to manage our security. + +139 +00:08:04,000 --> 00:08:12,000 +It helps us to for, uh, like like the previous thing we mentioned, to ensure our baselines are standardized + +140 +00:08:12,000 --> 00:08:16,000 +and consistent, ensures our configurations are consistent. + +141 +00:08:18,000 --> 00:08:18,000 +Now. + +142 +00:08:18,000 --> 00:08:20,000 +It also helps in employee retention. + +143 +00:08:20,000 --> 00:08:23,000 +I know you guys are saying how is that a benefit? + +144 +00:08:23,000 --> 00:08:28,000 +Well, higher employee satisfaction, reducing the burden of repetitive tasks. + +145 +00:08:28,000 --> 00:08:31,000 +You know, nobody wants to sit and do the same thing over and over and over. + +146 +00:08:31,000 --> 00:08:34,000 +That's what a computer is good at, something doing over and over. + +147 +00:08:34,000 --> 00:08:35,000 +It allows them. + +148 +00:08:35,000 --> 00:08:41,000 +It folks, me and you included, to focus on more challenging and rewarding work, leading to better + +149 +00:08:41,000 --> 00:08:42,000 +job satisfaction. + +150 +00:08:43,000 --> 00:08:46,000 +Reaction time is reduced. + +151 +00:08:46,000 --> 00:08:47,000 +All right. + +152 +00:08:47,000 --> 00:08:51,000 +So quicker responses to different systems is amazing. + +153 +00:08:51,000 --> 00:08:56,000 +We want to keep reaction time low especially in security incidents. + +154 +00:08:57,000 --> 00:08:59,000 +For example if a computer. + +155 +00:09:00,000 --> 00:09:01,000 +On a network gets hacked. + +156 +00:09:02,000 --> 00:09:05,000 +You want to respond to that ASAP. + +157 +00:09:05,000 --> 00:09:10,000 +Take that machine off the network before that malware spreads to other computers. + +158 +00:09:10,000 --> 00:09:11,000 +You don't want that. + +159 +00:09:11,000 --> 00:09:17,000 +So automated system can detect and response to threat real time reducing the damage on it. + +160 +00:09:17,000 --> 00:09:19,000 +Workforce multiplier. + +161 +00:09:19,000 --> 00:09:20,000 +What exactly is that? + +162 +00:09:20,000 --> 00:09:25,000 +Automation acts as a force multiplier for cybersecurity workforce. + +163 +00:09:25,000 --> 00:09:29,000 +Remember with this it allows us to do more with less. + +164 +00:09:29,000 --> 00:09:34,000 +While automation handles routine tasks, a smaller team can effectively manage a large network. + +165 +00:09:34,000 --> 00:09:41,000 +So remember more less folks can do more because now we have more automation, more scripting in there. + +166 +00:09:41,000 --> 00:09:50,000 +Now, while while it's it seems good and you know, in this video, almost everything I've talked about, + +167 +00:09:50,000 --> 00:09:58,000 +all the good security aspects, the benefits of it, it does come with a couple of things that does + +168 +00:09:58,000 --> 00:10:01,000 +increase, such as complexity, some negative things. + +169 +00:10:01,000 --> 00:10:04,000 +It does introduce complexity into the systems. + +170 +00:10:04,000 --> 00:10:05,000 +It simplifies. + +171 +00:10:05,000 --> 00:10:10,000 +It sounds simple to write scripts to do something, but write in scripts itself is not simple. + +172 +00:10:11,000 --> 00:10:17,000 +Whether you're using PowerShell scripts or using some kind of JavaScript Python scripting to do your + +173 +00:10:17,000 --> 00:10:24,000 +task or bash bash scripting and Linux, keep in mind that is a specialized knowledge that's needed. + +174 +00:10:25,000 --> 00:10:25,000 +Now. + +175 +00:10:25,000 --> 00:10:30,000 +Simple things you can probably do, like setting up and managing certain automated workflows. + +176 +00:10:30,000 --> 00:10:37,000 +But a lot of this does require specialized knowledge and it does require specialized tools costs. + +177 +00:10:37,000 --> 00:10:42,000 +Writing these scripts and managing these scripts generally will involve a certain amount of costs. + +178 +00:10:44,000 --> 00:10:51,000 +Now the initial investment in the scripting or the technology or the training for staff, for example, + +179 +00:10:51,000 --> 00:10:56,000 +not many IT folks are good at Python like I wasn't. + +180 +00:10:56,000 --> 00:11:02,000 +I studied, I had many, many Microsoft and Cisco certification and didn't know Python at all. + +181 +00:11:02,000 --> 00:11:06,000 +When I started doing pen testing, I actually had to learn that in order to add to the scripts, so + +182 +00:11:06,000 --> 00:11:07,000 +it will involve training. + +183 +00:11:09,000 --> 00:11:12,000 +They can lead to long time savings, but the upfront cost could be significant. + +184 +00:11:12,000 --> 00:11:14,000 +So in the long run it might save money. + +185 +00:11:14,000 --> 00:11:16,000 +But in the beginning it might cost. + +186 +00:11:16,000 --> 00:11:21,000 +Scripting system could be a single point of failure, relying heavily on automated system. + +187 +00:11:21,000 --> 00:11:27,000 +If that automated system fail and that automated system scripts a lot of things single point of failure. + +188 +00:11:27,000 --> 00:11:32,000 +In other words, when that system fails, many of the system that depends on the automated script will + +189 +00:11:32,000 --> 00:11:33,000 +fail. + +190 +00:11:33,000 --> 00:11:35,000 +So have redundancy in place. + +191 +00:11:35,000 --> 00:11:43,000 +Technical debt automation leads to it, uh, if it's implemented without adequate planning. + +192 +00:11:43,000 --> 00:11:47,000 +Quick fixes and workaround might solve immediate problem but create long terme issues. + +193 +00:11:47,000 --> 00:11:49,000 +So here's what technical debt is. + +194 +00:11:49,000 --> 00:11:53,000 +When you have a problem and you don't fix it, then you have another problem. + +195 +00:11:53,000 --> 00:11:57,000 +But then you leave that problem and then you don't fix that and then you don't fix it. + +196 +00:11:57,000 --> 00:12:01,000 +So the script may break this thing and then it may, you don't fix it and you may move on to something + +197 +00:12:01,000 --> 00:12:01,000 +else. + +198 +00:12:01,000 --> 00:12:09,000 +And this, of course leads to more debt being built up, ongoing supportability they do require an onboarding + +199 +00:12:09,000 --> 00:12:12,000 +because you know why system changes internally and those scripts needs to be adjusted. + +200 +00:12:12,000 --> 00:12:15,000 +Regular update and monitoring issues is going to be a problem. + +201 +00:12:15,000 --> 00:12:16,000 +Ensure it is adequate. + +202 +00:12:16,000 --> 00:12:19,000 +Support for these system is going to be important. + +203 +00:12:19,000 --> 00:12:20,000 +All right. + +204 +00:12:20,000 --> 00:12:24,000 +So keep in mind that when it comes to scripting it sounds amazing. + +205 +00:12:24,000 --> 00:12:29,000 +All these great benefits and security and of course cost savings for management. + +206 +00:12:29,000 --> 00:12:34,000 +But it does generally have some down or problems with it. + +207 +00:12:34,000 --> 00:12:40,000 +But keep in mind, when it comes to automation or orchestration and automation, the benefits here will + +208 +00:12:40,000 --> 00:12:42,000 +generally outweigh the risks. + diff --git a/17 - Enhance Security/013 Quick Quiz.html b/17 - Enhance Security/013 Quick Quiz.html new file mode 100644 index 0000000000000000000000000000000000000000..978b6dbed02d3ec5e5ca6dbbe109902b4ae3de59 --- /dev/null +++ b/17 - Enhance Security/013 Quick Quiz.html @@ -0,0 +1,479 @@ + + + + + + + Quiz + + + + +
+
+

+

+
+
+
+ Score: 999 of + 999% +
+
Correct: 999
+
Incorrect: 999
+
+ +
+ + + + +
+ + + + diff --git a/18 - Identity and Access Management (IAM)/001 Provisioning Users OB 4.6_en.srt b/18 - Identity and Access Management (IAM)/001 Provisioning Users OB 4.6_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..b4821b7044fe9b9355481b29968bdd45592ef8c3 --- /dev/null +++ b/18 - Identity and Access Management (IAM)/001 Provisioning Users OB 4.6_en.srt @@ -0,0 +1,592 @@ +1 +00:00:00,000 --> 00:00:05,000 +As a security administrator, one of the most basic things you're going to be doing is adding users + +2 +00:00:05,000 --> 00:00:08,000 +to your network every single day. + +3 +00:00:08,000 --> 00:00:11,000 +In large companies, users are fired and users are hired. + +4 +00:00:11,000 --> 00:00:14,000 +We have to disable accounts and we have to create accounts. + +5 +00:00:14,000 --> 00:00:20,000 +Let's take a look at a standard security process that we're going to use before we can create user accounts, + +6 +00:00:20,000 --> 00:00:21,000 +create user accounts. + +7 +00:00:21,000 --> 00:00:25,000 +And whenever, whenever they have to leave the company, we're going to disable their account. + +8 +00:00:25,000 --> 00:00:26,000 +So let's get started. + +9 +00:00:26,000 --> 00:00:32,000 +The first thing that happens, or the first thing that happens in this process of when we hire someone, + +10 +00:00:32,000 --> 00:00:34,000 +should be identity proofing. + +11 +00:00:34,000 --> 00:00:35,000 +What exactly is this? + +12 +00:00:35,000 --> 00:00:39,000 +Well, it says validated that a person is who they claim to be. + +13 +00:00:39,000 --> 00:00:41,000 +Did you guys know I'm Andrew Ramdayal? + +14 +00:00:41,000 --> 00:00:42,000 +Did you know that? + +15 +00:00:42,000 --> 00:00:44,000 +Well, you really don't know that, do you? + +16 +00:00:44,000 --> 00:00:47,000 +I said, you believe it because I said it. + +17 +00:00:47,000 --> 00:00:48,000 +I haven't proven it to you yet. + +18 +00:00:48,000 --> 00:00:50,000 +Have I showed you a driver's license? + +19 +00:00:50,000 --> 00:00:51,000 +That I am that person? + +20 +00:00:51,000 --> 00:00:52,000 +No. + +21 +00:00:52,000 --> 00:00:53,000 +So how do you know it's me? + +22 +00:00:54,000 --> 00:00:58,000 +So when you hire someone, you have to be able to prove their identity. + +23 +00:00:58,000 --> 00:00:59,000 +And that's what this is. + +24 +00:00:59,000 --> 00:01:05,000 +It involves verifying individual identity through various means and before granting them access to your + +25 +00:01:05,000 --> 00:01:06,000 +system. + +26 +00:01:06,000 --> 00:01:12,000 +Effective identity is key to maintaining security, ensuring regulatory compliance. + +27 +00:01:12,000 --> 00:01:17,000 +There will be many, many regulations that ensure that when you hire people, you check their identity + +28 +00:01:17,000 --> 00:01:19,000 +building trust in digital transaction. + +29 +00:01:19,000 --> 00:01:25,000 +If you don't do this right, you could end up with getting people that's basically they are. + +30 +00:01:25,000 --> 00:01:26,000 +They're not who they say they are. + +31 +00:01:26,000 --> 00:01:27,000 +How do you do this? + +32 +00:01:27,000 --> 00:01:30,000 +Well, there there are various different ways here. + +33 +00:01:30,000 --> 00:01:32,000 +And I've got a few different ways here that we can take a look. + +34 +00:01:32,000 --> 00:01:35,000 +Number one, verification of personal information. + +35 +00:01:35,000 --> 00:01:40,000 +This is going to involve some kind of government issued ID, maybe like my driver's license or Social + +36 +00:01:40,000 --> 00:01:42,000 +Security card passports and so on. + +37 +00:01:42,000 --> 00:01:48,000 +Biometric data check if you work for the federal or try to get a job at the federal government, they + +38 +00:01:48,000 --> 00:01:49,000 +may do a biometric check on you. + +39 +00:01:49,000 --> 00:01:52,000 +In other words, you got to give your thumbprint and then they're going to run you against all kinds + +40 +00:01:52,000 --> 00:01:54,000 +of databases and other personal information. + +41 +00:01:54,000 --> 00:01:57,000 +You then you're going to check them against sources. + +42 +00:01:57,000 --> 00:02:02,000 +For example, if they give you a driver's license, you're going to probably verify it against the DMV. + +43 +00:02:02,000 --> 00:02:07,000 +There's also knowledge check asking personal questions like, hey, what's your previous address that + +44 +00:02:07,000 --> 00:02:08,000 +you have lived at? + +45 +00:02:08,000 --> 00:02:09,000 +Document verification. + +46 +00:02:09,000 --> 00:02:12,000 +If you do give them things like a passport please, we're going to verify that. + +47 +00:02:12,000 --> 00:02:17,000 +And the biometric fingerprints facial recognition could be confirmed. + +48 +00:02:18,000 --> 00:02:22,000 +Uh, you could even use a third party service of database to verify folks. + +49 +00:02:22,000 --> 00:02:27,000 +Now, once people are verified, basically we know. + +50 +00:02:27,000 --> 00:02:28,000 +Okay, this is Bob. + +51 +00:02:28,000 --> 00:02:31,000 +Now let's go ahead and create Bob an account. + +52 +00:02:31,000 --> 00:02:36,000 +This is going to be called provisioning user accounts or creating user accounts. + +53 +00:02:36,000 --> 00:02:41,000 +This refers to creating and setting up a new user account with the appropriate rights on the network. + +54 +00:02:41,000 --> 00:02:47,000 +Now the first step once again when it comes to provisioning or creating a user account is of course + +55 +00:02:47,000 --> 00:02:48,000 +ID. + +56 +00:02:48,000 --> 00:02:48,000 +And the person. + +57 +00:02:48,000 --> 00:02:50,000 +Now we talked about that. + +58 +00:02:50,000 --> 00:02:55,000 +One of the things we want to do though, is when we create or allow people to join our networks, we + +59 +00:02:55,000 --> 00:02:58,000 +have to be careful with the rights that we give them. + +60 +00:02:58,000 --> 00:03:00,000 +We don't want to give them too much rights. + +61 +00:03:00,000 --> 00:03:04,000 +We want to give them just enough rights so that they can do their job. + +62 +00:03:04,000 --> 00:03:06,000 +This is known as the principles of least privileges. + +63 +00:03:06,000 --> 00:03:10,000 +So assign an appropriate access level based on the user role. + +64 +00:03:10,000 --> 00:03:15,000 +For example, they're going to be working in the accounting department. + +65 +00:03:15,000 --> 00:03:17,000 +Then make them a member of the accounting group. + +66 +00:03:17,000 --> 00:03:20,000 +And then they only have access to the account and applications. + +67 +00:03:20,000 --> 00:03:24,000 +If in the accounting department they only work in accounts payable, then just give them access to accounts + +68 +00:03:24,000 --> 00:03:25,000 +payable. + +69 +00:03:25,000 --> 00:03:27,000 +They only need to be entering bills and paying bills. + +70 +00:03:27,000 --> 00:03:32,000 +They don't need to be doing bank reconciliation or running payroll, or maybe in the accounting department. + +71 +00:03:32,000 --> 00:03:34,000 +They're going to be doing all that. + +72 +00:03:34,000 --> 00:03:36,000 +You have to know what they're doing to give a minimum access. + +73 +00:03:36,000 --> 00:03:41,000 +The next thing you want to do is to create that user account, actually go into your Windows Server, + +74 +00:03:41,000 --> 00:03:43,000 +your Active Directory, and create it. + +75 +00:03:45,000 --> 00:03:47,000 +Now the other thing here is going to be security measures. + +76 +00:03:47,000 --> 00:03:51,000 +This is going to be well what kind of password do we have. + +77 +00:03:51,000 --> 00:03:54,000 +Hopefully we have multi-factor authentication. + +78 +00:03:54,000 --> 00:03:57,000 +We're using strong passwords when doing this. + +79 +00:03:58,000 --> 00:04:04,000 +Now unfortunately at some point every user is going to come to the life of that business or the life + +80 +00:04:04,000 --> 00:04:07,000 +of them being in that business because they're going to be out. + +81 +00:04:07,000 --> 00:04:10,000 +They'll probably quit the job or the organization is not happy and terminate them. + +82 +00:04:10,000 --> 00:04:14,000 +This is called deprovisioning user accounts. + +83 +00:04:14,000 --> 00:04:21,000 +This involves a process of removing or disabling user accounts when they're no longer no longer needed + +84 +00:04:21,000 --> 00:04:22,000 +within the organization. + +85 +00:04:23,000 --> 00:04:24,000 +Now. + +86 +00:04:24,000 --> 00:04:30,000 +The first thing you want to do is you want to terminate, disable the account. + +87 +00:04:30,000 --> 00:04:32,000 +Now, here's here's something I want to tell you guys. + +88 +00:04:33,000 --> 00:04:36,000 +If you are work in it security. + +89 +00:04:36,000 --> 00:04:41,000 +You know when people are fired before they even know they're fired. + +90 +00:04:41,000 --> 00:04:41,000 +All right. + +91 +00:04:41,000 --> 00:04:45,000 +If you're sitting, if you're sitting at it security and you get a call from a manager, let's say the + +92 +00:04:45,000 --> 00:04:46,000 +accounting manager. + +93 +00:04:46,000 --> 00:04:50,000 +Hey, you know, um, can you terminate Bob's account for me? + +94 +00:04:50,000 --> 00:04:50,000 +Yeah. + +95 +00:04:50,000 --> 00:04:52,000 +Bob's been fired, all right. + +96 +00:04:52,000 --> 00:04:55,000 +And we they generally do this before Bob knows. + +97 +00:04:55,000 --> 00:05:02,000 +So if you ever go to work one day and you try to log in and it says account disabled, you've been canned, + +98 +00:05:02,000 --> 00:05:02,000 +buddy. + +99 +00:05:02,000 --> 00:05:03,000 +Terminated. + +100 +00:05:04,000 --> 00:05:05,000 +You've been you you've been kicked out. + +101 +00:05:05,000 --> 00:05:06,000 +You've been fired. + +102 +00:05:07,000 --> 00:05:14,000 +Organizations should terminate or disable the user account before telling the user that they have been + +103 +00:05:14,000 --> 00:05:15,000 +terminated. + +104 +00:05:15,000 --> 00:05:20,000 +This way, it prevents any kind of negative retaliation against the the network. + +105 +00:05:20,000 --> 00:05:27,000 +Because if I call you, let's say you're in the network and I say, hey, you're fired and your account + +106 +00:05:27,000 --> 00:05:27,000 +may still be valid. + +107 +00:05:27,000 --> 00:05:32,000 +Now you can log in and you could be malicious, disgruntled employees. + +108 +00:05:32,000 --> 00:05:37,000 +And then before you know it, you start deleting data or start, uh, stealing the data, sending it + +109 +00:05:37,000 --> 00:05:38,000 +to personal accounts and so on. + +110 +00:05:38,000 --> 00:05:42,000 +So one of the first things we're going to do is we're going to terminate the user's access to all the + +111 +00:05:42,000 --> 00:05:43,000 +systems and applications. + +112 +00:05:43,000 --> 00:05:47,000 +This generally involves terminating at least all the different accounts, ensuring any data associated + +113 +00:05:47,000 --> 00:05:52,000 +with the user is handled according to the organizational legal requirements a lot of times. + +114 +00:05:53,000 --> 00:05:56,000 +When you terminate people, you're going to have to give them an interview. + +115 +00:05:56,000 --> 00:06:00,000 +You're going to have to let them know that they're terminal, but also get back all of the company's + +116 +00:06:00,000 --> 00:06:06,000 +data, such as, for example, maybe you issued company phones to them, maybe you issued company laptops + +117 +00:06:06,000 --> 00:06:06,000 +to them. + +118 +00:06:06,000 --> 00:06:11,000 +You're also going to have to transfer ownership of the emails and files to other employees. + +119 +00:06:11,000 --> 00:06:13,000 +Generally, when they fire Bob and replace Bob with Mary. + +120 +00:06:13,000 --> 00:06:17,000 +Generally, Mary now needs access to what Bob is doing because she's going to be doing his job. + +121 +00:06:17,000 --> 00:06:19,000 +So this is going to be involved. + +122 +00:06:19,000 --> 00:06:21,000 +Terminating terminating the account. + +123 +00:06:21,000 --> 00:06:26,000 +Now, when it comes to creating and managing user accounts, I can't emphasize this enough, but permission + +124 +00:06:26,000 --> 00:06:28,000 +assignment is core here. + +125 +00:06:28,000 --> 00:06:29,000 +It's going to be key. + +126 +00:06:29,000 --> 00:06:36,000 +Anytime we add users to the network, we have to make sure that those users are only given access to + +127 +00:06:36,000 --> 00:06:38,000 +what they need and nothing more. + +128 +00:06:38,000 --> 00:06:40,000 +We don't want to give them too much access. + +129 +00:06:40,000 --> 00:06:43,000 +We want to give them just enough access to get their job done. + +130 +00:06:44,000 --> 00:06:48,000 +So permission assignments is one of the core thing of identity and access management. + +131 +00:06:48,000 --> 00:06:50,000 +We want to make sure that they have the right rights. + +132 +00:06:50,000 --> 00:06:54,000 +And we're going to follow principles like least privileges, role based access. + +133 +00:06:54,000 --> 00:06:58,000 +Role based access means that whatever role they're going to be doing, if they're an accountant, they + +134 +00:06:58,000 --> 00:07:02,000 +only do accounting in order to give them minimum access. + +135 +00:07:02,000 --> 00:07:03,000 +So keep these things in mind. + +136 +00:07:03,000 --> 00:07:05,000 +When you manage user accounts, remember something. + +137 +00:07:05,000 --> 00:07:07,000 +Make sure they you know who they are. + +138 +00:07:07,000 --> 00:07:09,000 +Make sure you prove their identity. + +139 +00:07:09,000 --> 00:07:13,000 +When you create that user accounts follow the principles of least privileges. + +140 +00:07:13,000 --> 00:07:18,000 +Give them access to only what they need and when you terminate them, anyone for that matter, make + +141 +00:07:18,000 --> 00:07:19,000 +sure you disable the access. + +142 +00:07:19,000 --> 00:07:21,000 +Then tell them that they have been terminated. + +143 +00:07:21,000 --> 00:07:23,000 +Collect all company equipment. + +144 +00:07:23,000 --> 00:07:27,000 +Make sure you do an exit interview, letting them know all the policies that they signed to get all + +145 +00:07:27,000 --> 00:07:29,000 +company equipment back. + +146 +00:07:29,000 --> 00:07:33,000 +Transfer ownership of whatever files and folders they have to people. + +147 +00:07:33,000 --> 00:07:34,000 +That's probably replacing them. + +148 +00:07:34,000 --> 00:07:39,000 +By doing all of this, you're going to have good hiring and firing policies. + diff --git a/18 - Identity and Access Management (IAM)/002 Single Sign-on OB 4.6_en.srt b/18 - Identity and Access Management (IAM)/002 Single Sign-on OB 4.6_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..6b0ad4bdc32732242c3744cd68163761859af022 --- /dev/null +++ b/18 - Identity and Access Management (IAM)/002 Single Sign-on OB 4.6_en.srt @@ -0,0 +1,368 @@ +1 +00:00:00,000 --> 00:00:05,000 +The greatest technology that has ever been invented, in Andrew's opinion, when it comes to the world + +2 +00:00:05,000 --> 00:00:06,000 +of security. + +3 +00:00:06,000 --> 00:00:10,000 +Is this thing SS or single sign on? + +4 +00:00:10,000 --> 00:00:12,000 +You see, I hate passwords. + +5 +00:00:12,000 --> 00:00:13,000 +I hate remembering passwords. + +6 +00:00:13,000 --> 00:00:17,000 +I never remember passwords because my memory really sucks. + +7 +00:00:17,000 --> 00:00:25,000 +Single sign on is a feature where a user logs in once and gain access to multiple systems without the + +8 +00:00:25,000 --> 00:00:26,000 +need to reauthenticate. + +9 +00:00:26,000 --> 00:00:28,000 +This enhances user experience. + +10 +00:00:28,000 --> 00:00:29,000 +Yes it does. + +11 +00:00:29,000 --> 00:00:37,000 +So what this is going to do is this every single time you log into a network, basically you put your + +12 +00:00:37,000 --> 00:00:41,000 +username and password once and you can access tons of resources. + +13 +00:00:41,000 --> 00:00:47,000 +You can access files on a file server, databases, your emails, for example, you can access specific + +14 +00:00:47,000 --> 00:00:49,000 +intranet sites and so on. + +15 +00:00:49,000 --> 00:00:55,000 +Single sign on is amazing because without single sign on, I'll have to remember username and password + +16 +00:00:55,000 --> 00:00:56,000 +to log into my windows. + +17 +00:00:56,000 --> 00:01:02,000 +I'll then have to remember a password to the email password to the database, password to this intranet + +18 +00:01:02,000 --> 00:01:04,000 +site, and so on and drive me crazy. + +19 +00:01:04,000 --> 00:01:07,000 +So we want to use single sign on. + +20 +00:01:07,000 --> 00:01:09,000 +Single sign on has a ton of benefits. + +21 +00:01:09,000 --> 00:01:10,000 +Here we go. + +22 +00:01:11,000 --> 00:01:18,000 +Number one, like I told you so, reduces the number of passwords users must manage. + +23 +00:01:18,000 --> 00:01:20,000 +Guys, we can't remember all these passwords. + +24 +00:01:20,000 --> 00:01:23,000 +Not to mention passwords has to be complex. + +25 +00:01:23,000 --> 00:01:27,000 +And more and more software is making it mandatory that you memorize ten characters. + +26 +00:01:27,000 --> 00:01:29,000 +And it must be complex. + +27 +00:01:29,000 --> 00:01:33,000 +And a lot of us ends up just using the same password for everything, which is something you should + +28 +00:01:33,000 --> 00:01:34,000 +never do. + +29 +00:01:34,000 --> 00:01:39,000 +Uh, reuse very simple passwords that are long on somewhat complex. + +30 +00:01:39,000 --> 00:01:45,000 +This, of course, leads to bad security, so this decrease the likelihood of weak passwords. + +31 +00:01:45,000 --> 00:01:51,000 +Another great thing is centralized authentication provides centralized control over user access to multiple + +32 +00:01:51,000 --> 00:01:51,000 +systems. + +33 +00:01:51,000 --> 00:01:53,000 +Makes it easier to enforce security policy. + +34 +00:01:53,000 --> 00:01:54,000 +So. + +35 +00:01:55,000 --> 00:01:56,000 +For example. + +36 +00:01:56,000 --> 00:02:00,000 +Now we can just add you into the system, add you to a few things, and you get access to everything, + +37 +00:02:00,000 --> 00:02:07,000 +versus the administrator having to create a user account for the for windows user account for this website, + +38 +00:02:07,000 --> 00:02:13,000 +a user account for that website, a user account for the VPN, a user account for the email. + +39 +00:02:13,000 --> 00:02:16,000 +Now they don't need to create 500 user accounts. + +40 +00:02:16,000 --> 00:02:20,000 +So this of course makes it easy for it. + +41 +00:02:20,000 --> 00:02:26,000 +It reduces the the user account management for I for it a lot easier. + +42 +00:02:26,000 --> 00:02:30,000 +And of course you don't have to keep calling the help desk 500 times to reset your password. + +43 +00:02:30,000 --> 00:02:32,000 +One famous. + +44 +00:02:32,000 --> 00:02:33,000 +So technology. + +45 +00:02:34,000 --> 00:02:39,000 +That is utilized a lot in the world today is Ldap. + +46 +00:02:39,000 --> 00:02:47,000 +Now, if you have worked in corporate America today and they had a windows box and they were using Microsoft's + +47 +00:02:47,000 --> 00:02:52,000 +Active Directory, that was Ldap, that's the Microsoft version of it. + +48 +00:02:52,000 --> 00:02:57,000 +So Ldap stands for Lightweight Directory Access Protocol. + +49 +00:02:57,000 --> 00:03:00,000 +And this is a so example. + +50 +00:03:00,000 --> 00:03:03,000 +So if you say so okay I like so how do I implement it. + +51 +00:03:03,000 --> 00:03:09,000 +Well Ldap does this if you're if you were run in the world of Windows or Microsoft based stuff, you're + +52 +00:03:09,000 --> 00:03:10,000 +going to have Microsoft Active Directory. + +53 +00:03:10,000 --> 00:03:13,000 +If you're using pure Linux you could use Open Directory also. + +54 +00:03:14,000 --> 00:03:20,000 +Now it's a protocol for accessing and maintaining distributed directory information such as what but + +55 +00:03:20,000 --> 00:03:23,000 +like users and group details over an IP network. + +56 +00:03:23,000 --> 00:03:31,000 +So now we can pass user information across an entire network primarily used for directory services. + +57 +00:03:31,000 --> 00:03:36,000 +Commonly utilize utilize for storing credentials and groups. + +58 +00:03:36,000 --> 00:03:39,000 +Now once again this is Active Directory. + +59 +00:03:39,000 --> 00:03:43,000 +Now this course is not meant to teach you Active Directory. + +60 +00:03:44,000 --> 00:03:46,000 +How to set it up or anything for your exam. + +61 +00:03:46,000 --> 00:03:48,000 +I need you guys to know that. + +62 +00:03:48,000 --> 00:03:54,000 +So single sign on user logs in ones means they can gain access to everything. + +63 +00:03:54,000 --> 00:03:56,000 +Also remember this. + +64 +00:03:56,000 --> 00:03:58,000 +This reduces password. + +65 +00:03:58,000 --> 00:04:00,000 +People have to memorize password. + +66 +00:04:00,000 --> 00:04:06,000 +It makes it actually more secure because now users just have to memorize one really good strong password + +67 +00:04:06,000 --> 00:04:07,000 +to access the network. + +68 +00:04:07,000 --> 00:04:09,000 +So it reduces it workload. + +69 +00:04:09,000 --> 00:04:12,000 +So it doesn't have to make a bunch of user accounts. + +70 +00:04:12,000 --> 00:04:14,000 +One good example of it was Ldap. + +71 +00:04:14,000 --> 00:04:17,000 +Now remember Active Directory is based on Ldap. + +72 +00:04:17,000 --> 00:04:20,000 +It's used to store user accounts and the information associated with them. + +73 +00:04:20,000 --> 00:04:25,000 +Now one of the things that we want to discuss before we leave is what's negative about Ldap. + +74 +00:04:25,000 --> 00:04:28,000 +What's one of the bad things about Ldap or so? + +75 +00:04:28,000 --> 00:04:31,000 +What's one of the bad things with CISOs. + +76 +00:04:31,000 --> 00:04:41,000 +Well, its biggest negative is if one user account is compromised, it compromises all the system. + +77 +00:04:41,000 --> 00:04:48,000 +The reason is because you see, when you have one account that accesses all the data and all systems, + +78 +00:04:48,000 --> 00:04:54,000 +if that user account is lost, whoever gets it can then access everything on the network. + +79 +00:04:54,000 --> 00:04:58,000 +Think about this if you have one user account that accesses your your computer, like your Active Directory + +80 +00:04:58,000 --> 00:05:01,000 +account, you can use this to log in to to windows. + +81 +00:05:02,000 --> 00:05:06,000 +You can use check your email your database company's intranet site. + +82 +00:05:06,000 --> 00:05:12,000 +But if you lose that account and that password, oh well, whoever gets it now has access to everything + +83 +00:05:12,000 --> 00:05:15,000 +on the network that you did, so that's its downfall. + +84 +00:05:15,000 --> 00:05:23,000 +But in this situation, the benefit of not having to remember 7000 password outweighs that risk of that + +85 +00:05:23,000 --> 00:05:24,000 +single point of failure. + +86 +00:05:24,000 --> 00:05:28,000 +And that's what it is, because that single account becomes a failure on the network. + +87 +00:05:28,000 --> 00:05:31,000 +Basically they just compromise one account. + +88 +00:05:31,000 --> 00:05:32,000 +They have access to everything. + +89 +00:05:32,000 --> 00:05:40,000 +So in this particular one, the benefit here outweighs the risk of the actual, uh, problem with. + +90 +00:05:40,000 --> 00:05:46,000 +So now we do implement so across all networks today because almost everybody uses Microsoft Active Directory. + +91 +00:05:46,000 --> 00:05:51,000 +If you have if you have windows and if you use a variety of websites, you can also implement it with + +92 +00:05:51,000 --> 00:05:53,000 +Federation coming next. + diff --git a/18 - Identity and Access Management (IAM)/003 Federation and SAML OB 4.6_en.srt b/18 - Identity and Access Management (IAM)/003 Federation and SAML OB 4.6_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..e1b5975ba621548131084f92c0a512dbe414b189 --- /dev/null +++ b/18 - Identity and Access Management (IAM)/003 Federation and SAML OB 4.6_en.srt @@ -0,0 +1,664 @@ +1 +00:00:00,000 --> 00:00:05,000 +When it comes to using the internet, there's nothing more annoying than forgetting your password to + +2 +00:00:05,000 --> 00:00:06,000 +a particular website. + +3 +00:00:06,000 --> 00:00:07,000 +How many? + +4 +00:00:07,000 --> 00:00:08,000 +How many of you guys hate that? + +5 +00:00:08,000 --> 00:00:14,000 +I can't stand using the internet today for the simple fact that every single website you go to that + +6 +00:00:14,000 --> 00:00:17,000 +needs anything, you have to create a user account. + +7 +00:00:17,000 --> 00:00:18,000 +You have to remember the password. + +8 +00:00:19,000 --> 00:00:21,000 +It's not easy to do this. + +9 +00:00:21,000 --> 00:00:26,000 +So here's what I do every time I go to a website and it's like, create an account. + +10 +00:00:26,000 --> 00:00:28,000 +For whatever reason, I got to create an account. + +11 +00:00:28,000 --> 00:00:31,000 +So I create an account and then it says, would you like to use your Gmail to log in here? + +12 +00:00:31,000 --> 00:00:34,000 +And I'm like, oh yeah, let's do that. + +13 +00:00:34,000 --> 00:00:39,000 +If you've ever done that, you have used a technology we referred to as what's called Federation. + +14 +00:00:40,000 --> 00:00:43,000 +Now this you want to know this terms for your exam. + +15 +00:00:44,000 --> 00:00:44,000 +Federation is. + +16 +00:00:44,000 --> 00:00:51,000 +Cybersecurity is the process of linking and managing identities across different systems and organizational + +17 +00:00:51,000 --> 00:00:52,000 +boundaries. + +18 +00:00:52,000 --> 00:00:57,000 +Basically, it's going to enable users to use the same identity or set of credentials across multiple + +19 +00:00:57,000 --> 00:00:59,000 +applications and services. + +20 +00:00:59,000 --> 00:01:01,000 +Basically, federation is. + +21 +00:01:01,000 --> 00:01:06,000 +So for websites, that's what that's what you need to know for your exam. + +22 +00:01:06,000 --> 00:01:10,000 +This allows you to log in to one website and then you can then log in. + +23 +00:01:10,000 --> 00:01:12,000 +Basically go to other websites. + +24 +00:01:12,000 --> 00:01:16,000 +And that login credential will stay with you throughout the others. + +25 +00:01:16,000 --> 00:01:21,000 +It allows for single sign on and streamline access management to enhance user experience. + +26 +00:01:21,000 --> 00:01:22,000 +Remember that. + +27 +00:01:22,000 --> 00:01:23,000 +What exactly is Federation? + +28 +00:01:23,000 --> 00:01:27,000 +Well, Federation allows me to log in to this particular website. + +29 +00:01:28,000 --> 00:01:32,000 +And then I can go to all the different all the web sites that trust is that site. + +30 +00:01:33,000 --> 00:01:34,000 +It's one of the things we have to remember. + +31 +00:01:34,000 --> 00:01:38,000 +And then we basically we don't need to log in 100 times anymore. + +32 +00:01:39,000 --> 00:01:46,000 +Federation makes the internet a lot easier to use because it's bringing it's bringing single sign on + +33 +00:01:46,000 --> 00:01:48,000 +to websites. + +34 +00:01:48,000 --> 00:01:53,000 +Now, Federation involves identity providers, service providers and all kinds of protocols that goes + +35 +00:01:53,000 --> 00:01:54,000 +along with it. + +36 +00:01:54,000 --> 00:01:57,000 +And in this video we want to talk about some of those. + +37 +00:01:57,000 --> 00:02:05,000 +One of the most famous protocol that we have for Federation on the internet today is something we call + +38 +00:02:05,000 --> 00:02:06,000 +Saml. + +39 +00:02:06,000 --> 00:02:08,000 +Saml is security. + +40 +00:02:09,000 --> 00:02:11,000 +Assertion Markup Language. + +41 +00:02:11,000 --> 00:02:14,000 +Yeah, my my pronunciation of complex words is not the best. + +42 +00:02:14,000 --> 00:02:15,000 +Sorry about that guys. + +43 +00:02:15,000 --> 00:02:17,000 +This is basically an open standard. + +44 +00:02:17,000 --> 00:02:18,000 +And you guys to listen carefully. + +45 +00:02:18,000 --> 00:02:27,000 +Exchange in authentication and authorization data between parties, specifically an identity provider + +46 +00:02:27,000 --> 00:02:28,000 +and a service provider. + +47 +00:02:28,000 --> 00:02:31,000 +Now I have a diagram that I'm going to show you about Saml in a minute. + +48 +00:02:31,000 --> 00:02:37,000 +But I want to talk about the difference between authentication and authorization. + +49 +00:02:37,000 --> 00:02:39,000 +It's really important to understand this. + +50 +00:02:40,000 --> 00:02:43,000 +So authentication is this. + +51 +00:02:43,000 --> 00:02:49,000 +If you have a if you log in to one website you can then transfer that authentication to another. + +52 +00:02:49,000 --> 00:02:51,000 +So let's say you have a website A and website B. + +53 +00:02:52,000 --> 00:02:57,000 +Now let's say you authenticate to website A, but because website A trust this website B because you're + +54 +00:02:57,000 --> 00:03:00,000 +logged in to A, you automatically logged in to B. + +55 +00:03:01,000 --> 00:03:02,000 +That's all it is. + +56 +00:03:02,000 --> 00:03:05,000 +But authentication is not authorization. + +57 +00:03:05,000 --> 00:03:09,000 +Authorization is telling people what you have access to. + +58 +00:03:09,000 --> 00:03:12,000 +Authentication is proving your identity to a system. + +59 +00:03:13,000 --> 00:03:16,000 +Authorization is what can you access? + +60 +00:03:16,000 --> 00:03:21,000 +For example, I can log in to this box, but I'm not authorized to access anything. + +61 +00:03:21,000 --> 00:03:23,000 +Everything I double click says access denied. + +62 +00:03:24,000 --> 00:03:26,000 +But there's a folder on the desktop that I could access. + +63 +00:03:26,000 --> 00:03:29,000 +When I double click on that, I opens it and I can add files to it. + +64 +00:03:30,000 --> 00:03:31,000 +That's authorization. + +65 +00:03:31,000 --> 00:03:36,000 +So Samuel passes both authentication and authorization. + +66 +00:03:36,000 --> 00:03:41,000 +So for example, if there's website A and B when you log in to this one you're already logged in to + +67 +00:03:41,000 --> 00:03:43,000 +this one that's authentication. + +68 +00:03:43,000 --> 00:03:49,000 +But because you can access certain files and folders or certain web pages on this site. + +69 +00:03:49,000 --> 00:03:52,000 +Now Samuel is able to pass over that authorization to the other site. + +70 +00:03:52,000 --> 00:03:57,000 +And now you can also access certain files and folders or pages on this site, both A and B, that's + +71 +00:03:57,000 --> 00:03:58,000 +authorization. + +72 +00:03:59,000 --> 00:04:02,000 +This is one of the most widely used so for the internet. + +73 +00:04:02,000 --> 00:04:06,000 +Now Samuel does use what's called XML. + +74 +00:04:06,000 --> 00:04:08,000 +That is a type of a format. + +75 +00:04:08,000 --> 00:04:10,000 +That's how it's able to transfer data. + +76 +00:04:10,000 --> 00:04:16,000 +Think of think of XML or Extensible Markup Language as the format that it used to transfer information + +77 +00:04:16,000 --> 00:04:22,000 +between one to the other for data exchange, and it focuses on both authentication and authorization. + +78 +00:04:22,000 --> 00:04:25,000 +Now XML has two main components. + +79 +00:04:25,000 --> 00:04:31,000 +We want to talk about what's called the identity provider and what's called the service provider the + +80 +00:04:31,000 --> 00:04:32,000 +identity provider. + +81 +00:04:33,000 --> 00:04:37,000 +Is basically the services that authenticate users and provide identity. + +82 +00:04:37,000 --> 00:04:43,000 +This is going to be things like Microsoft Azure or for example, using your Gmail at Google Identity. + +83 +00:04:43,000 --> 00:04:49,000 +What identity providers are doing notice terms for your exam is attestation. + +84 +00:04:49,000 --> 00:04:53,000 +This basically is a form of verification that something is true. + +85 +00:04:53,000 --> 00:04:56,000 +It's done with the identity providers. + +86 +00:04:56,000 --> 00:04:59,000 +They attest that this user is who they claim to be. + +87 +00:04:59,000 --> 00:05:00,000 +Stay with me. + +88 +00:05:00,000 --> 00:05:02,000 +I know this doesn't make sense yet, but I'm gonna have a diagram. + +89 +00:05:02,000 --> 00:05:03,000 +It's going to make you make sense of this. + +90 +00:05:03,000 --> 00:05:10,000 +The service provider is the application or service that they rely that that you're going to rely on + +91 +00:05:10,000 --> 00:05:14,000 +for information from the identity provider. + +92 +00:05:14,000 --> 00:05:18,000 +So basically the service provider is what is who you're going to. + +93 +00:05:18,000 --> 00:05:23,000 +For example, let's say you use your Gmail to log in to BestBuy. + +94 +00:05:23,000 --> 00:05:25,000 +I don't know if BestBuy allows it, but let's say you do. + +95 +00:05:26,000 --> 00:05:32,000 +If you're using your Gmail to log in to BestBuy, then Gmail is the identity provider. + +96 +00:05:32,000 --> 00:05:36,000 +But who's providing you the service of buying tech stuff at Best Buy? + +97 +00:05:36,000 --> 00:05:37,000 +So they're the service provider. + +98 +00:05:37,000 --> 00:05:43,000 +The service provider relies on the identity provider for the identifying information. + +99 +00:05:44,000 --> 00:05:49,000 +Now, there is a great diagram here that I want to review with you. + +100 +00:05:49,000 --> 00:05:50,000 +Shows you how Saml works. + +101 +00:05:50,000 --> 00:05:52,000 +Here are the steps to Saml. + +102 +00:05:52,000 --> 00:05:55,000 +So this is you. + +103 +00:05:55,000 --> 00:05:59,000 +You're a user and you have a mobile device. + +104 +00:05:59,000 --> 00:06:03,000 +Now the service provider let's say is Best Buy. + +105 +00:06:04,000 --> 00:06:07,000 +The identity provider is going to be like Google. + +106 +00:06:07,000 --> 00:06:10,000 +Let's say you're using like your Gmail to log in somewhere else. + +107 +00:06:10,000 --> 00:06:11,000 +Let's see what happens. + +108 +00:06:11,000 --> 00:06:14,000 +So you go to the service provider. + +109 +00:06:14,000 --> 00:06:16,000 +You request access to a resource. + +110 +00:06:17,000 --> 00:06:25,000 +The second step, the service provider then goes to the identity provider and says unattended unauthenticated + +111 +00:06:25,000 --> 00:06:25,000 +request. + +112 +00:06:25,000 --> 00:06:29,000 +He basically sends a Saml request saying, hey, do you know this guy? + +113 +00:06:30,000 --> 00:06:34,000 +Google then displays a login page on your phone. + +114 +00:06:34,000 --> 00:06:38,000 +You get a login, you try to click, and Google is like, hey, you need to log in with this username + +115 +00:06:38,000 --> 00:06:40,000 +and password to Google, not to Best Buy. + +116 +00:06:40,000 --> 00:06:45,000 +You put in your username and password and you send it back to their database. + +117 +00:06:45,000 --> 00:06:48,000 +Google's database credentials sends for verification. + +118 +00:06:49,000 --> 00:06:56,000 +Google then authenticates your credential and then sends a verification back to Google's Saml server + +119 +00:06:56,000 --> 00:06:58,000 +or their identity provider. + +120 +00:06:58,000 --> 00:07:05,000 +The Saml ID provider then sends a request back to Best Buy saying, hey, yeah, log them in, they're + +121 +00:07:05,000 --> 00:07:05,000 +all good. + +122 +00:07:05,000 --> 00:07:09,000 +And then you request access to whatever resources that you want on Best Buy. + +123 +00:07:11,000 --> 00:07:11,000 +Okay. + +124 +00:07:11,000 --> 00:07:13,000 +This exam is not going to go in depth into this. + +125 +00:07:13,000 --> 00:07:19,000 +I just wanted to show you guys know identity providers and know what service providers are. + +126 +00:07:19,000 --> 00:07:23,000 +Service providers are the folks that you are going to. + +127 +00:07:23,000 --> 00:07:27,000 +They're providing the internet service you want, whether it's buying tech stuff or reading some kind + +128 +00:07:27,000 --> 00:07:29,000 +of article or something like that. + +129 +00:07:29,000 --> 00:07:33,000 +Basically, the website you're visiting and the identity providers who you're using to log in to that + +130 +00:07:33,000 --> 00:07:35,000 +website to, such as Google. + +131 +00:07:35,000 --> 00:07:36,000 +I think you could use Facebook and stuff like that. + +132 +00:07:39,000 --> 00:07:39,000 +All right. + +133 +00:07:39,000 --> 00:07:44,000 +Now there are some other so based federation technology that you should be familiar with. + +134 +00:07:44,000 --> 00:07:48,000 +There is OAuth and this stands for open authorization. + +135 +00:07:48,000 --> 00:07:51,000 +This is open standard for access delegation. + +136 +00:07:51,000 --> 00:07:56,000 +It's used to grant websites or applications access to their information on other websites without giving + +137 +00:07:56,000 --> 00:07:57,000 +them a password. + +138 +00:07:57,000 --> 00:08:02,000 +Commonly used for authorizing third party applications to access a user data. + +139 +00:08:02,000 --> 00:08:04,000 +Now here's the thing with OAuth. + +140 +00:08:04,000 --> 00:08:08,000 +OAuth does not do basically authentication. + +141 +00:08:08,000 --> 00:08:12,000 +That's not what it does a lot only does authorization. + +142 +00:08:12,000 --> 00:08:19,000 +So if you have, for example, a particular application that needs access to this particular website, + +143 +00:08:19,000 --> 00:08:21,000 +then you can use OAuth for this. + +144 +00:08:21,000 --> 00:08:26,000 +It doesn't need the user, it doesn't need the user to authenticate, but just a particular application. + +145 +00:08:26,000 --> 00:08:33,000 +So remember for your exam OAuth is basically authorization only not authentication and authorization. + +146 +00:08:33,000 --> 00:08:41,000 +Now, if you're looking to do, uh, to add to OAuth, you want to add that authentication part, then + +147 +00:08:41,000 --> 00:08:43,000 +you can use OpenID connect. + +148 +00:08:43,000 --> 00:08:48,000 +Basically, it's an identity layer on top of a 2.0 that allows client to verify the identity of the + +149 +00:08:48,000 --> 00:08:53,000 +end user, um, on the authentication performed by the authorization. + +150 +00:08:53,000 --> 00:08:59,000 +So it's primarily used for for authentication in modern applications, especially on mobile sites. + +151 +00:09:00,000 --> 00:09:04,000 +Now the thing with these kinds of systems are, you know, some people are going to say, so, Andrew, + +152 +00:09:04,000 --> 00:09:07,000 +why should I, should I use OAuth or Saml for your exam? + +153 +00:09:07,000 --> 00:09:08,000 +Don't worry about that. + +154 +00:09:08,000 --> 00:09:12,000 +I just need I need you guys to know the technology. + +155 +00:09:12,000 --> 00:09:17,000 +For example, when it comes to Federation, one of the most popular implementation of federation is + +156 +00:09:17,000 --> 00:09:18,000 +Saml. + +157 +00:09:18,000 --> 00:09:19,000 +Samuel has two main components. + +158 +00:09:19,000 --> 00:09:21,000 +They have a identity provider. + +159 +00:09:22,000 --> 00:09:26,000 +And a service provider and identity provider is basically who holds your username and password and who's + +160 +00:09:26,000 --> 00:09:27,000 +going to verify you. + +161 +00:09:27,000 --> 00:09:33,000 +And the service provider is the folks that you the website that you've been to to get a particular service, + +162 +00:09:33,000 --> 00:09:35,000 +such as buying stuff at Best Buy. + +163 +00:09:35,000 --> 00:09:42,000 +And don't forget, OAuth is open authorization that only provides authorization if you want to add authentication + +164 +00:09:42,000 --> 00:09:45,000 +on top of what you use OpenID connect. + +165 +00:09:45,000 --> 00:09:45,000 +All right. + +166 +00:09:45,000 --> 00:09:51,000 +Just note that these technologies are basically all that's used with Federation. + diff --git a/18 - Identity and Access Management (IAM)/004 Access Control Models OB 4.6_en.srt b/18 - Identity and Access Management (IAM)/004 Access Control Models OB 4.6_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..fe3ccfd6619d54f11f95c050a09b799974d64c3e --- /dev/null +++ b/18 - Identity and Access Management (IAM)/004 Access Control Models OB 4.6_en.srt @@ -0,0 +1,508 @@ +1 +00:00:00,000 --> 00:00:05,000 +When you log into a computer, what kind of access do you have to that machine? + +2 +00:00:05,000 --> 00:00:10,000 +Can you just make files and folders and share it as you like to anyone on the network? + +3 +00:00:10,000 --> 00:00:11,000 +Or could you not? + +4 +00:00:11,000 --> 00:00:17,000 +Could you access anything on the network or anything on the computer, or is there certain restrictions? + +5 +00:00:17,000 --> 00:00:19,000 +You see, this comes down to access control. + +6 +00:00:19,000 --> 00:00:26,000 +And there are a set of access controls that we need to know for our exam and work in, in real life. + +7 +00:00:26,000 --> 00:00:33,000 +So access controls are are basically mechanisms and policies used to manage and restrict access to resources + +8 +00:00:33,000 --> 00:00:34,000 +in an entire network. + +9 +00:00:34,000 --> 00:00:37,000 +It could be individual systems or the entire network. + +10 +00:00:37,000 --> 00:00:43,000 +Now there is a bunch we want to talk about from discretionary access control, mandatory access control + +11 +00:00:43,000 --> 00:00:49,000 +role and rule based access control and attribute based access control for your exam, you're going to + +12 +00:00:49,000 --> 00:00:51,000 +want to know the difference between them. + +13 +00:00:51,000 --> 00:00:55,000 +This particular topic has been a very popular topic on your exam. + +14 +00:00:56,000 --> 00:01:01,000 +The effective implementation of access control is require balance and security and complexity and usability. + +15 +00:01:01,000 --> 00:01:02,000 +Why? + +16 +00:01:02,000 --> 00:01:08,000 +You see, it's all about balance and security and complexity, because some of these access controls + +17 +00:01:08,000 --> 00:01:11,000 +are super restrictive, like mandatory access control. + +18 +00:01:11,000 --> 00:01:15,000 +And some of them are pretty loose, like discretionary access control. + +19 +00:01:15,000 --> 00:01:17,000 +Let's get into it and see these kinds of access controls. + +20 +00:01:17,000 --> 00:01:23,000 +The first one I want to talk about is the most restrictive access control out there, which is called + +21 +00:01:23,000 --> 00:01:25,000 +mandatory access control. + +22 +00:01:25,000 --> 00:01:30,000 +First of all, I want to start out by saying that mandatory access control is only really used in the + +23 +00:01:30,000 --> 00:01:35,000 +government and military, where classification of the information is needed. + +24 +00:01:35,000 --> 00:01:43,000 +Now mandatory access control utilizes a variety of system labels in order to keep the system secure. + +25 +00:01:43,000 --> 00:01:44,000 +But what exactly is it? + +26 +00:01:44,000 --> 00:01:50,000 +It's a security model in which access rights are regulated by central authority, based on different + +27 +00:01:50,000 --> 00:01:51,000 +levels of security clearance. + +28 +00:01:51,000 --> 00:01:55,000 +Now, it does utilize a particular security clearance and a security label. + +29 +00:01:55,000 --> 00:01:57,000 +The scope of that is beyond your exam. + +30 +00:01:57,000 --> 00:02:01,000 +But I'm going to give you guys, uh, a couple a couple examples in a minute. + +31 +00:02:02,000 --> 00:02:02,000 +Key aspect. + +32 +00:02:02,000 --> 00:02:06,000 +Users cannot change access permissions they are set enforce by the administrator. + +33 +00:02:06,000 --> 00:02:14,000 +So basically on windows, which is basically based on a DAC system, on a mandatory access control system. + +34 +00:02:14,000 --> 00:02:16,000 +And I'm not talking Mac here, by the way. + +35 +00:02:16,000 --> 00:02:17,000 +Like Apple. + +36 +00:02:17,000 --> 00:02:17,000 +I just thought of that. + +37 +00:02:17,000 --> 00:02:18,000 +I'm not talking. + +38 +00:02:18,000 --> 00:02:19,000 +That's a completely different thing. + +39 +00:02:20,000 --> 00:02:25,000 +What we're talking about here is a system that when you log, when you create a user account and they + +40 +00:02:25,000 --> 00:02:28,000 +log in, they have permission basically to nothing. + +41 +00:02:28,000 --> 00:02:29,000 +And they can't change anything. + +42 +00:02:29,000 --> 00:02:32,000 +They can access only what the administrator. + +43 +00:02:32,000 --> 00:02:35,000 +It's not like they could make a folder and then they can change the permission. + +44 +00:02:35,000 --> 00:02:40,000 +You see in discretionary access control devices, when you make a folder, you own it. + +45 +00:02:40,000 --> 00:02:42,000 +You can change whatever you like about it. + +46 +00:02:42,000 --> 00:02:43,000 +And discretionary tour. + +47 +00:02:43,000 --> 00:02:45,000 +When you make a folder, it changes. + +48 +00:02:46,000 --> 00:02:52,000 +But when you make a folder, the folder actually will stay with the system and get the system permission. + +49 +00:02:52,000 --> 00:02:56,000 +You see, one of the things we got to remember with mandatory access control in the government, the + +50 +00:02:56,000 --> 00:02:59,000 +government uses what's called security clearances. + +51 +00:02:59,000 --> 00:03:09,000 +And this is important, you see, for you to gain access to something you just cannot, uh, double + +52 +00:03:09,000 --> 00:03:13,000 +click and access it if you have a certain clearance, let's say a top secret, it doesn't mean you can + +53 +00:03:13,000 --> 00:03:16,000 +access all top secret data. + +54 +00:03:16,000 --> 00:03:19,000 +So you got to have rights by the owner. + +55 +00:03:19,000 --> 00:03:23,000 +Basically, you got to have a need to know, and you got to have a certain set of clearance in order + +56 +00:03:23,000 --> 00:03:24,000 +to access the data. + +57 +00:03:24,000 --> 00:03:25,000 +Let me explain. + +58 +00:03:25,000 --> 00:03:33,000 +In the military, you're going to have top secret and secret now, not some like in windows where like + +59 +00:03:33,000 --> 00:03:35,000 +you're an administrator, you get access to everything. + +60 +00:03:35,000 --> 00:03:35,000 +No. + +61 +00:03:35,000 --> 00:03:39,000 +If you have a top secret clearance, you can't access all top secret data. + +62 +00:03:39,000 --> 00:03:42,000 +You have to have what's called a need to know. + +63 +00:03:42,000 --> 00:03:47,000 +Now, these kinds of systems will implement that need to know and the clearance, and it utilizes security + +64 +00:03:47,000 --> 00:03:49,000 +labels to do it. + +65 +00:03:49,000 --> 00:03:56,000 +The operating system that does this is an operating system known as Linux SE or SE Linux Secure Enhanced + +66 +00:03:56,000 --> 00:03:57,000 +Linux. + +67 +00:03:57,000 --> 00:04:00,000 +They do this with kernel patches and different kinds of things. + +68 +00:04:00,000 --> 00:04:02,000 +In Red Hat Linux. + +69 +00:04:02,000 --> 00:04:07,000 +And you can actually download this next thing up we have is discretionary access control. + +70 +00:04:07,000 --> 00:04:10,000 +The resource owner decides on the access level. + +71 +00:04:10,000 --> 00:04:12,000 +It's the most flexible of all the access control. + +72 +00:04:13,000 --> 00:04:19,000 +Using environments where users need control over resources they own, like setting file permissions. + +73 +00:04:19,000 --> 00:04:22,000 +Now this is normal windows. + +74 +00:04:22,000 --> 00:04:25,000 +If you have or Mac that you're I'm talking not Mac like this. + +75 +00:04:25,000 --> 00:04:32,000 +I'm talking like you're if you have a MacBook air or MacBook Pro or whatever you're using, you'll log + +76 +00:04:32,000 --> 00:04:33,000 +into it. + +77 +00:04:33,000 --> 00:04:36,000 +You create a folder on the desktop, you can set the permissions. + +78 +00:04:36,000 --> 00:04:41,000 +Anybody can access any file on it because you said this have a risk because you're giving users access + +79 +00:04:41,000 --> 00:04:42,000 +over that. + +80 +00:04:42,000 --> 00:04:50,000 +In order to be a little bit more restrictive, let's implement one of the most widely used access control + +81 +00:04:50,000 --> 00:04:55,000 +in the entire world is called role based access control. + +82 +00:04:55,000 --> 00:04:59,000 +This assigns permissions based on a user's role within the business. + +83 +00:04:59,000 --> 00:05:04,000 +Now, this is common in corporate environments where the roles defined the job function. + +84 +00:05:05,000 --> 00:05:12,000 +So basically they set up roles which in Active Directory or if you manage users would be groups. + +85 +00:05:12,000 --> 00:05:18,000 +You're going to have accounting, sales, finance, management, it and so on. + +86 +00:05:18,000 --> 00:05:24,000 +And basically you don't assign individual users to resources. + +87 +00:05:24,000 --> 00:05:26,000 +Basically you assign them to a group. + +88 +00:05:26,000 --> 00:05:28,000 +The group then gives them access to the resource. + +89 +00:05:28,000 --> 00:05:32,000 +So if they're not in the role, they can't get access to the resource. + +90 +00:05:32,000 --> 00:05:37,000 +This streamlines access in the business, making it a lot easier to manage them. + +91 +00:05:37,000 --> 00:05:40,000 +Now there are two others that you want to be familiar with. + +92 +00:05:40,000 --> 00:05:46,000 +That's called rule based access control and attribute based rule based access control is decision are + +93 +00:05:46,000 --> 00:05:52,000 +based on a set of rules defined by an administrator, useful in environments where stringent access + +94 +00:05:52,000 --> 00:05:53,000 +control is needed. + +95 +00:05:53,000 --> 00:05:57,000 +Now rule based access control I showed you this when I showed you firewalls. + +96 +00:05:57,000 --> 00:06:02,000 +If you watch a video with me setting up a configuring a firewall, that's a rule based access control. + +97 +00:06:02,000 --> 00:06:07,000 +Basically, configuring a firewall and setting up its rules is a rule based access control. + +98 +00:06:07,000 --> 00:06:11,000 +The only thing here that's going to be using rule based access control is basically routers with their + +99 +00:06:11,000 --> 00:06:12,000 +access lists. + +100 +00:06:12,000 --> 00:06:13,000 +And of course firewalls. + +101 +00:06:13,000 --> 00:06:16,000 +The other one is attribute based access control. + +102 +00:06:16,000 --> 00:06:22,000 +This one is incredibly popular today, and you have probably have been using this without your knowledge. + +103 +00:06:23,000 --> 00:06:28,000 +Uses policies that evaluate attributes or characteristics of a user. + +104 +00:06:28,000 --> 00:06:35,000 +Effective and complex environments with diverse and dynamic user attributes provides fine grained control, + +105 +00:06:35,000 --> 00:06:39,000 +allowing for multiple decisions before you give access. + +106 +00:06:39,000 --> 00:06:41,000 +Now, let me give you a bunch of examples of this. + +107 +00:06:41,000 --> 00:06:43,000 +So you use Netflix, right? + +108 +00:06:43,000 --> 00:06:44,000 +Who does it right. + +109 +00:06:44,000 --> 00:06:45,000 +You log in to Netflix. + +110 +00:06:45,000 --> 00:06:50,000 +And did you know based on your IP addresses, the content you're going to see? + +111 +00:06:51,000 --> 00:06:55,000 +Did you guys know that if you have a European IP, you see this, if you have a United States IP, you + +112 +00:06:55,000 --> 00:06:58,000 +see this and people even try to get around with VPNs. + +113 +00:06:59,000 --> 00:07:07,000 +Um, basically, if you the attribute based access control utilizes many attributes to determine what + +114 +00:07:07,000 --> 00:07:08,000 +you can access. + +115 +00:07:08,000 --> 00:07:12,000 +For example, if you log in with a mobile browser because the browser screen is small, you can only + +116 +00:07:12,000 --> 00:07:17,000 +access this content if you log in that's an attribute, the browser or the screen size. + +117 +00:07:17,000 --> 00:07:19,000 +Another attribute could be things like day. + +118 +00:07:19,000 --> 00:07:23,000 +Maybe at a certain time you can access this versus a certain time you can't. + +119 +00:07:23,000 --> 00:07:26,000 +It could be an IP address or a location. + +120 +00:07:26,000 --> 00:07:27,000 +Those are all attributes. + +121 +00:07:27,000 --> 00:07:32,000 +Basically, you're utilizing multiple attributes in order to determine what they can access. + +122 +00:07:33,000 --> 00:07:38,000 +Now you want to make sure that you really know the you want to make sure that you really know. + +123 +00:07:39,000 --> 00:07:47,000 +Uh, these kinds of access control, these terms mandatory access control, discretionary role based, + +124 +00:07:47,000 --> 00:07:49,000 +be the most popular, one rule based. + +125 +00:07:49,000 --> 00:07:53,000 +And of course, the last one we talked about attribute based access control. + +126 +00:07:53,000 --> 00:07:55,000 +Rewatch this video a few times. + +127 +00:07:55,000 --> 00:07:57,000 +Make sure you really understand them before taking your test. + diff --git a/18 - Identity and Access Management (IAM)/005 Multifactor Authentication OB 4.6_en.srt b/18 - Identity and Access Management (IAM)/005 Multifactor Authentication OB 4.6_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..626ec1de63daf4aff8d46a9f305ce9eeb7e22218 --- /dev/null +++ b/18 - Identity and Access Management (IAM)/005 Multifactor Authentication OB 4.6_en.srt @@ -0,0 +1,220 @@ +1 +00:00:00,000 --> 00:00:01,000 +When it comes to it. + +2 +00:00:01,000 --> 00:00:01,000 +Security. + +3 +00:00:01,000 --> 00:00:08,000 +One of the most important thing we have to secure or have secured is our authentication information. + +4 +00:00:08,000 --> 00:00:12,000 +Authentication is basically proven our identity to a machine. + +5 +00:00:12,000 --> 00:00:17,000 +Now we covered, uh, authentication a little bit. + +6 +00:00:17,000 --> 00:00:21,000 +Or we briefly covered it when we spoke about authentication right at the beginning of the course. + +7 +00:00:21,000 --> 00:00:27,000 +In this section we're going to go more in depth into things like tokens, passwords and biometric. + +8 +00:00:27,000 --> 00:00:30,000 +But before we do that, let's do a quick review. + +9 +00:00:30,000 --> 00:00:32,000 +When it comes to authentication, authentication is proven. + +10 +00:00:32,000 --> 00:00:34,000 +Identification. + +11 +00:00:34,000 --> 00:00:37,000 +The way you would do that is most people know is with a password. + +12 +00:00:37,000 --> 00:00:42,000 +Now in particularly in this section we're looking at multi-factor authentication. + +13 +00:00:42,000 --> 00:00:49,000 +MFA is a security system that requires more than one method to authenticate while we use things such + +14 +00:00:49,000 --> 00:00:50,000 +as just a password. + +15 +00:00:50,000 --> 00:00:52,000 +That would just be a single factor. + +16 +00:00:52,000 --> 00:00:55,000 +In this section, we want to look at other factors more than just a password. + +17 +00:00:55,000 --> 00:01:01,000 +So it requires more than one method to authenticate from an independent category of credential to verify + +18 +00:01:01,000 --> 00:01:03,000 +a user's identity for a login. + +19 +00:01:03,000 --> 00:01:07,000 +This combined uses two or more distinctive factors. + +20 +00:01:07,000 --> 00:01:13,000 +Now, when it comes to the different factors, we have to look that the factors are going to fall into + +21 +00:01:13,000 --> 00:01:16,000 +one of these four main categories. + +22 +00:01:16,000 --> 00:01:19,000 +So the first one up is what we are all familiar with. + +23 +00:01:19,000 --> 00:01:20,000 +It's what we're all used. + +24 +00:01:20,000 --> 00:01:21,000 +It's password. + +25 +00:01:21,000 --> 00:01:25,000 +It's something you know commonly used but is vulnerable to theft. + +26 +00:01:25,000 --> 00:01:31,000 +People can steal your passwords or guess and or even brute force attack where they can try every combination. + +27 +00:01:31,000 --> 00:01:35,000 +Now you got to remember, pins and passwords are going to be this. + +28 +00:01:35,000 --> 00:01:40,000 +Now, if you have something like your cell phone and it takes four digits to get in, that's 10,000 + +29 +00:01:40,000 --> 00:01:41,000 +combinations. + +30 +00:01:41,000 --> 00:01:43,000 +That's subject to brute force attack. + +31 +00:01:43,000 --> 00:01:46,000 +Or maybe the password on your cell, maybe the. + +32 +00:01:47,000 --> 00:01:49,000 +The log into your cell phone. + +33 +00:01:49,000 --> 00:01:53,000 +If it's four digits and it's just a Pin, a lot of people put their birthday, for example. + +34 +00:01:53,000 --> 00:01:55,000 +That would be me guessing it. + +35 +00:01:55,000 --> 00:02:00,000 +Okay, the other thing here is going to be something you have, which adds a layer of security by requiring + +36 +00:02:00,000 --> 00:02:05,000 +some kind of physical device that's going to be done either with a hard token or an app on your phone. + +37 +00:02:05,000 --> 00:02:10,000 +So you got to have either some you got to have your mobile phone with you, some kind of security token, + +38 +00:02:10,000 --> 00:02:12,000 +or even a smart card. + +39 +00:02:12,000 --> 00:02:16,000 +The other thing here is going to be something you are, which is going to be biometrics. + +40 +00:02:16,000 --> 00:02:20,000 +Now, we do have a big discussion and a whole presentation on biometrics. + +41 +00:02:20,000 --> 00:02:25,000 +This one is highly secure, but implementation is generally going to be more expensive than all of this. + +42 +00:02:25,000 --> 00:02:31,000 +This is going to be used in things either an iris scanner or a thumbprint, facial, facial recognition, + +43 +00:02:31,000 --> 00:02:35,000 +hand geometry, and many others we'll discuss in another video. + +44 +00:02:35,000 --> 00:02:37,000 +The other one here is called location based. + +45 +00:02:37,000 --> 00:02:38,000 +This is. + +46 +00:02:38,000 --> 00:02:40,000 +Somewhere you are. + +47 +00:02:40,000 --> 00:02:44,000 +This adds contextual security by restricting to a specific IP address. + +48 +00:02:44,000 --> 00:02:48,000 +And basically that IP address is going to look into your location. + +49 +00:02:48,000 --> 00:02:51,000 +So for example, you can't log in if you're not in the United States. + +50 +00:02:51,000 --> 00:02:55,000 +So they may restrict the application to just United States login. + +51 +00:02:55,000 --> 00:02:56,000 +All right. + +52 +00:02:56,000 --> 00:02:59,000 +So this is going to be multi-factor authentication. + +53 +00:02:59,000 --> 00:03:00,000 +This was a review. + +54 +00:03:00,000 --> 00:03:01,000 +We did cover this at the beginning of the course. + +55 +00:03:01,000 --> 00:03:05,000 +Let's get more in depth into things other than just passwords. + diff --git a/18 - Identity and Access Management (IAM)/006 Authentication tokens OB 4.6_en.srt b/18 - Identity and Access Management (IAM)/006 Authentication tokens OB 4.6_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..5aae688ae975aa770fa30cf5d3b617ae9538fcff --- /dev/null +++ b/18 - Identity and Access Management (IAM)/006 Authentication tokens OB 4.6_en.srt @@ -0,0 +1,268 @@ +1 +00:00:00,000 --> 00:00:05,000 +When it comes to multi-factor authentication, keep in mind that you have to use two of the four possible + +2 +00:00:05,000 --> 00:00:07,000 +factors that we outlined. + +3 +00:00:07,000 --> 00:00:13,000 +If you remember the four factors something you know something you have, some something you are and + +4 +00:00:13,000 --> 00:00:14,000 +some where you are. + +5 +00:00:14,000 --> 00:00:19,000 +So for example, you can use something you know, which would be like a password and something you have + +6 +00:00:19,000 --> 00:00:22,000 +like an RSA token, like I'm about to show you now. + +7 +00:00:22,000 --> 00:00:27,000 +Or you can use a password and a thumbprint, or you could use a security key and a thumbprint, something + +8 +00:00:27,000 --> 00:00:28,000 +like that. + +9 +00:00:28,000 --> 00:00:31,000 +So you're going to have to use at least two of those. + +10 +00:00:31,000 --> 00:00:33,000 +Now for your exam. + +11 +00:00:33,000 --> 00:00:34,000 +I want you guys to remember. + +12 +00:00:35,000 --> 00:00:39,000 +The most the most secure way is multi factor. + +13 +00:00:39,000 --> 00:00:43,000 +So if they say something, if they give you a question where they were like well here is uh what's, + +14 +00:00:43,000 --> 00:00:49,000 +what's more secure and a 20 digit password, then they say a bank card and a and a four digit Pin. + +15 +00:00:49,000 --> 00:00:51,000 +The answer is a bank card and a four digit Pin. + +16 +00:00:51,000 --> 00:00:57,000 +If they give you if they give you three choices, such as a really long, complex 20 digit password, + +17 +00:00:57,000 --> 00:00:59,000 +bank card and Pin and iris scan. + +18 +00:00:59,000 --> 00:01:04,000 +You still do bank card and Pin, because a bank card and a Pin is two factors. + +19 +00:01:04,000 --> 00:01:07,000 +It's something you know, the Pin and something you have is the is the card. + +20 +00:01:07,000 --> 00:01:13,000 +Now in this video I want you guys to I want to concentrate on the something you have. + +21 +00:01:13,000 --> 00:01:18,000 +So there's basically going to uh, it's basically going to give us three things. + +22 +00:01:18,000 --> 00:01:22,000 +Number one is going to be some kind of a token. + +23 +00:01:22,000 --> 00:01:25,000 +And I want to show you guys this in the first one. + +24 +00:01:25,000 --> 00:01:33,000 +So one of the most popular, uh, authentication devices of something you have is this thing here. + +25 +00:01:33,000 --> 00:01:34,000 +This is a hard token. + +26 +00:01:34,000 --> 00:01:38,000 +So hard tokens are physical devices, key fobs or smart cards. + +27 +00:01:38,000 --> 00:01:42,000 +So this is going to be a key fab used to generate secure codes. + +28 +00:01:42,000 --> 00:01:47,000 +Now these things these RSA tokens the way this would be this would be paired to your system. + +29 +00:01:47,000 --> 00:01:50,000 +And when you want to log in it's going to say give me the code. + +30 +00:01:50,000 --> 00:01:54,000 +Now the thing is the the codes on this device changes all the time. + +31 +00:01:54,000 --> 00:01:55,000 +All right. + +32 +00:01:55,000 --> 00:01:55,000 +It continues. + +33 +00:01:55,000 --> 00:01:58,000 +It consistently changes changes changes. + +34 +00:01:58,000 --> 00:02:04,000 +The other thing they have is something called a soft token software, uh, software based approaches + +35 +00:02:04,000 --> 00:02:06,000 +to generate a secure code on the user device. + +36 +00:02:06,000 --> 00:02:11,000 +Now, a soft token is when you have a software. + +37 +00:02:11,000 --> 00:02:18,000 +Now there is a software in RSA, Securid software that you can get that has that sends a code to the + +38 +00:02:18,000 --> 00:02:20,000 +actual soft device on your phone. + +39 +00:02:20,000 --> 00:02:27,000 +So you still need your phone to log in versus using this, using this physical device to log in. + +40 +00:02:28,000 --> 00:02:34,000 +Now these both are used to provide real time sensitive passcode as an additional authentication factor, + +41 +00:02:34,000 --> 00:02:35,000 +which work well. + +42 +00:02:35,000 --> 00:02:38,000 +Now you see this quite a lot being implemented. + +43 +00:02:38,000 --> 00:02:42,000 +Also, generally when you try to log into a website, it may send a code to your phone. + +44 +00:02:42,000 --> 00:02:45,000 +I see that a lot, especially when I'm trying to log into Google. + +45 +00:02:45,000 --> 00:02:50,000 +That is a type of something you have, because you must have the phone that is linked to that particular + +46 +00:02:50,000 --> 00:02:51,000 +phone number. + +47 +00:02:51,000 --> 00:02:55,000 +The other thing I want to mention is something very secure is called a security key. + +48 +00:02:55,000 --> 00:03:01,000 +This is a physical hardware device used for verifying a user's identity, uses part of a multi-factor + +49 +00:03:01,000 --> 00:03:05,000 +such as you're more than likely going to have to put in a password, and then you have to plug the key + +50 +00:03:05,000 --> 00:03:05,000 +in. + +51 +00:03:05,000 --> 00:03:07,000 +So you must have this key. + +52 +00:03:07,000 --> 00:03:12,000 +Now, unlike hard tokens, which generate a passcode, the key usually doesn't work like that. + +53 +00:03:12,000 --> 00:03:15,000 +All it has to be is just plugged in to the actual network. + +54 +00:03:15,000 --> 00:03:19,000 +Now, I used to use this for a particular software. + +55 +00:03:19,000 --> 00:03:22,000 +In order to make the software start, you would. + +56 +00:03:22,000 --> 00:03:24,000 +You'd have to push the USB key in. + +57 +00:03:24,000 --> 00:03:27,000 +The key had a code that would then allow the software to start. + +58 +00:03:27,000 --> 00:03:29,000 +So I did use this at one point. + +59 +00:03:29,000 --> 00:03:31,000 +Now these things do use protocols. + +60 +00:03:31,000 --> 00:03:34,000 +Uh, there's one called Universal Second factor. + +61 +00:03:34,000 --> 00:03:36,000 +Uh, that's one of the most popular one. + +62 +00:03:37,000 --> 00:03:39,000 +And again, you just have to push the key in. + +63 +00:03:39,000 --> 00:03:40,000 +And there's a variety of different ones. + +64 +00:03:40,000 --> 00:03:42,000 +Here is one of them. + +65 +00:03:42,000 --> 00:03:45,000 +There's also a famous one from Google Titan okay. + +66 +00:03:46,000 --> 00:03:54,000 +So those are going to be some of the things that falls into the category of something you have. + +67 +00:03:54,000 --> 00:03:58,000 +Keep in mind that something you have and something you know is a combination of multifactor. + diff --git a/18 - Identity and Access Management (IAM)/007 Biometric OB 4.6_en.srt b/18 - Identity and Access Management (IAM)/007 Biometric OB 4.6_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..6aa9f158e8878f6dbe37d5a1f2467c6e7eae9e4b --- /dev/null +++ b/18 - Identity and Access Management (IAM)/007 Biometric OB 4.6_en.srt @@ -0,0 +1,680 @@ +1 +00:00:00,000 --> 00:00:02,000 +When it comes to logging into a computer. + +2 +00:00:02,000 --> 00:00:07,000 +My most favorite one to use if the device supports is going to be biometrics. + +3 +00:00:07,000 --> 00:00:09,000 +I use biometrics to log into everything. + +4 +00:00:09,000 --> 00:00:14,000 +When it comes to my cell phone, I'll use a fingerprint and also my windows. + +5 +00:00:14,000 --> 00:00:18,000 +My my windows laptop has a biometrics reader on it again, a fingerprint. + +6 +00:00:18,000 --> 00:00:20,000 +Now biometrics is great. + +7 +00:00:20,000 --> 00:00:26,000 +Biometrics is based on a unique physical attribute or a behavior that the user is going to do. + +8 +00:00:26,000 --> 00:00:30,000 +Now in this video, I want to go through all of the different types of biometrics that are out there. + +9 +00:00:31,000 --> 00:00:33,000 +And which one is accurate. + +10 +00:00:33,000 --> 00:00:37,000 +We'll also take a look at what makes them accurate and how exactly is a process they work. + +11 +00:00:37,000 --> 00:00:44,000 +So biometric authentication is a type of system that relies on the unique biological characteristics + +12 +00:00:44,000 --> 00:00:44,000 +of you. + +13 +00:00:45,000 --> 00:00:45,000 +All right. + +14 +00:00:45,000 --> 00:00:50,000 +It's sophisticated, but it's generally always going to be more expensive than implementing passwords. + +15 +00:00:50,000 --> 00:00:51,000 +Let's go down the list here. + +16 +00:00:51,000 --> 00:00:54,000 +And there's quite a few of them of different biometrics. + +17 +00:00:54,000 --> 00:01:02,000 +You can use the first one up that most people no are familiar with in today's world is fingerprint and + +18 +00:01:02,000 --> 00:01:03,000 +face scans. + +19 +00:01:03,000 --> 00:01:04,000 +Okay. + +20 +00:01:04,000 --> 00:01:04,000 +Why? + +21 +00:01:04,000 --> 00:01:09,000 +Because the iPhone supports one and a lot of androids uses the thumbprint. + +22 +00:01:09,000 --> 00:01:10,000 +So fingerprints. + +23 +00:01:10,000 --> 00:01:14,000 +Uh, this here is going to be the visible patterns on your fingers, on your thumb. + +24 +00:01:14,000 --> 00:01:17,000 +Everybody does have a unique fingerprint. + +25 +00:01:17,000 --> 00:01:23,000 +Face scans or facial recognition will look for the geometrical patterns of your actual face. + +26 +00:01:24,000 --> 00:01:26,000 +Uh, now, there's two of them that confuses folks. + +27 +00:01:26,000 --> 00:01:28,000 +It's called retina and iris. + +28 +00:01:28,000 --> 00:01:31,000 +Now, both of these here will scan your eye. + +29 +00:01:31,000 --> 00:01:37,000 +So retina scanners focuses on patterns of blood vessels at the back of the eyes. + +30 +00:01:37,000 --> 00:01:42,000 +This is considered the most accurate, but least acceptable. + +31 +00:01:43,000 --> 00:01:45,000 +The this thing also has a problem. + +32 +00:01:45,000 --> 00:01:48,000 +It could reveal high blood pressure and pregnancy. + +33 +00:01:48,000 --> 00:01:57,000 +So remember for your exam, retina scanners is the most accurate biometric, uh, biometric authentication. + +34 +00:01:57,000 --> 00:01:58,000 +But it has a problem. + +35 +00:01:58,000 --> 00:02:07,000 +You see, this thing here could reveal health issues with people making it an invasion of health, privacy + +36 +00:02:07,000 --> 00:02:08,000 +or privacy in general. + +37 +00:02:08,000 --> 00:02:12,000 +So this is probably not the most acceptable one out there. + +38 +00:02:12,000 --> 00:02:18,000 +Iris scanners focuses on the colored area around the pupil, not the back of the eye around the pupil. + +39 +00:02:18,000 --> 00:02:22,000 +Second most accurate, uh, longer authentication lifespan. + +40 +00:02:22,000 --> 00:02:25,000 +The reason is because, uh, this one doesn't degrade over time. + +41 +00:02:25,000 --> 00:02:27,000 +A lot of times your thumbprint may degrade over time. + +42 +00:02:27,000 --> 00:02:29,000 +Your face patterns may change. + +43 +00:02:29,000 --> 00:02:31,000 +Palm scans, scans. + +44 +00:02:31,000 --> 00:02:33,000 +The Prom uses infrared light to measure. + +45 +00:02:33,000 --> 00:02:39,000 +So palm scans measures the vein patterns in your arm. + +46 +00:02:39,000 --> 00:02:46,000 +Now, I remember doing this because when you go to Pearson Vue or Vue to take your exam in person, + +47 +00:02:46,000 --> 00:02:53,000 +if you do that, if you do take this exam in person, um, like a CISSP or CISSP exam that's in person, + +48 +00:02:53,000 --> 00:02:56,000 +but CompTIA exams, you can do it at home any which way you go. + +49 +00:02:56,000 --> 00:03:02,000 +And you put it over a box, this v shaped box, and it actually sends a light to your hands and it measures + +50 +00:03:02,000 --> 00:03:04,000 +the vein pattern in your hands. + +51 +00:03:04,000 --> 00:03:08,000 +Now hand geometry is different than than what I just mentioned. + +52 +00:03:08,000 --> 00:03:13,000 +This recognizes the physical dimensions of the hand, including the width and length, so that one is + +53 +00:03:13,000 --> 00:03:18,000 +looking for the physical dimensions, how long your fingers are, how wide your hand is, something + +54 +00:03:18,000 --> 00:03:19,000 +that a lot of people. + +55 +00:03:20,000 --> 00:03:22,000 +Don't believe that exists, but it does. + +56 +00:03:22,000 --> 00:03:24,000 +It's not actually a primary. + +57 +00:03:24,000 --> 00:03:25,000 +It's a secondary. + +58 +00:03:25,000 --> 00:03:30,000 +It's called heart pattern, often employed as a secondary biometric to support another. + +59 +00:03:30,000 --> 00:03:32,000 +Now if you're wondering it measures the pulse. + +60 +00:03:32,000 --> 00:03:32,000 +Yes. + +61 +00:03:32,000 --> 00:03:35,000 +It measures to see if you're alive basically. + +62 +00:03:35,000 --> 00:03:41,000 +In other words in high military systems, for example, uh, they may use a retina scanner and then + +63 +00:03:41,000 --> 00:03:42,000 +use a heart pulse. + +64 +00:03:42,000 --> 00:03:46,000 +That way you're trying to get into a secure facility. + +65 +00:03:46,000 --> 00:03:52,000 +You don't cut off the guy's head and put his eye there, take his eyeball out and try to authenticate + +66 +00:03:52,000 --> 00:03:55,000 +to the machine because the machine is going to see, hey, this guy alive or what? + +67 +00:03:55,000 --> 00:03:58,000 +Sounds it sounds funny, but it's true. + +68 +00:03:58,000 --> 00:03:59,000 +All right. + +69 +00:03:59,000 --> 00:04:00,000 +Uh, voice pattern. + +70 +00:04:00,000 --> 00:04:05,000 +This year will relies on the characteristics of how the person's sound signature dynamics. + +71 +00:04:06,000 --> 00:04:07,000 +This is how you write. + +72 +00:04:07,000 --> 00:04:13,000 +It looks for the pressure on how you apply the pen, how you do certain stroke, and how fast. + +73 +00:04:13,000 --> 00:04:19,000 +And basically you write something, uh, keystroke patterns, of course, how fast you type. + +74 +00:04:19,000 --> 00:04:19,000 +All right. + +75 +00:04:19,000 --> 00:04:24,000 +So this one is going to look at how long you particularly like hold a key down when you're typing. + +76 +00:04:24,000 --> 00:04:25,000 +Okay. + +77 +00:04:25,000 --> 00:04:28,000 +So these are going to be some popular biometrics out there. + +78 +00:04:28,000 --> 00:04:32,000 +Let's take a look though at what's called biometrics error rating. + +79 +00:04:32,000 --> 00:04:34,000 +Now you need to know this for your exam. + +80 +00:04:34,000 --> 00:04:40,000 +This is there's two error rating that you should be familiar with what's called type one and type two + +81 +00:04:40,000 --> 00:04:41,000 +errors. + +82 +00:04:41,000 --> 00:04:44,000 +So type one error occurs when a subject is not authenticated. + +83 +00:04:45,000 --> 00:04:50,000 +So when a valid subject is not authenticated, this is the more common of the device when it's set to + +84 +00:04:50,000 --> 00:04:51,000 +sensitive. + +85 +00:04:51,000 --> 00:04:54,000 +Now type one is this okay. + +86 +00:04:54,000 --> 00:04:58,000 +Type one is when I, I go and I put my thumbprint and it did it didn't log me on. + +87 +00:04:58,000 --> 00:05:00,000 +All right let me show you a type one log. + +88 +00:05:00,000 --> 00:05:03,000 +Type one I'm going to put my thumbprint here. + +89 +00:05:03,000 --> 00:05:06,000 +And I'm going to uh, didn't log me in. + +90 +00:05:06,000 --> 00:05:08,000 +Uh, didn't, uh, doesn't like me. + +91 +00:05:08,000 --> 00:05:08,000 +Nope. + +92 +00:05:08,000 --> 00:05:08,000 +Doesn't like me. + +93 +00:05:09,000 --> 00:05:10,000 +That's a type one. + +94 +00:05:10,000 --> 00:05:11,000 +Annoying. + +95 +00:05:11,000 --> 00:05:12,000 +Doesn't doesn't log me in. + +96 +00:05:13,000 --> 00:05:18,000 +Now, type one errors are known as false rejection rate. + +97 +00:05:18,000 --> 00:05:20,000 +This is when the device is generally set to sensitive. + +98 +00:05:21,000 --> 00:05:22,000 +Now. + +99 +00:05:22,000 --> 00:05:27,000 +Type one errors are not bad in terms of security. + +100 +00:05:27,000 --> 00:05:30,000 +In other words, they're not going to allow bad guys to get in. + +101 +00:05:30,000 --> 00:05:31,000 +But type two is. + +102 +00:05:31,000 --> 00:05:34,000 +Type two occurs when an invalid subject is authenticated. + +103 +00:05:34,000 --> 00:05:39,000 +This is when there's somebody named Bob that's built similarly to me. + +104 +00:05:39,000 --> 00:05:42,000 +Um, and he probably lets you using hand geometry. + +105 +00:05:42,000 --> 00:05:47,000 +And he puts his hand, I put my hand and it logs me in because he's built similarly to me. + +106 +00:05:47,000 --> 00:05:51,000 +He puts his hand logs in as a logs him in as me. + +107 +00:05:51,000 --> 00:05:53,000 +This is when, um. + +108 +00:05:54,000 --> 00:05:57,000 +Invalid subject is authenticated. + +109 +00:05:57,000 --> 00:05:59,000 +So now Bob is basically logging in as me. + +110 +00:05:59,000 --> 00:06:02,000 +More common when the device is not sensitive enough. + +111 +00:06:02,000 --> 00:06:05,000 +So the device allows a wide variety of logins. + +112 +00:06:05,000 --> 00:06:07,000 +This is known as a false acceptance rate. + +113 +00:06:07,000 --> 00:06:13,000 +Now, in order to make the device good, you want to make sure you do what's called a crossover error + +114 +00:06:13,000 --> 00:06:14,000 +rate or an equal error rate. + +115 +00:06:14,000 --> 00:06:17,000 +Now for your exam, the lower this percentage is better. + +116 +00:06:17,000 --> 00:06:23,000 +In other words, they look at the device and see well how much type one error does it generate and how + +117 +00:06:23,000 --> 00:06:24,000 +much type two error is it generate. + +118 +00:06:24,000 --> 00:06:30,000 +Now, if you think about it, the least amount of type one, the better the device, the least amount + +119 +00:06:30,000 --> 00:06:31,000 +of type two, the better the device. + +120 +00:06:31,000 --> 00:06:36,000 +So what they do is they plotted on a graph and they're like, well, at this point here, it seems like + +121 +00:06:36,000 --> 00:06:38,000 +that's when we get the lowest type one and type two. + +122 +00:06:38,000 --> 00:06:44,000 +Now for your exam, if they give you some percentages you go with the lowest percentage. + +123 +00:06:44,000 --> 00:06:45,000 +All right. + +124 +00:06:45,000 --> 00:06:48,000 +So if there's a percentage of 4567 go with four. + +125 +00:06:48,000 --> 00:06:50,000 +That's going to be the lowest number. + +126 +00:06:50,000 --> 00:06:52,000 +So the crossover error rate the lower the better. + +127 +00:06:52,000 --> 00:06:54,000 +This is also known as the equal error rate. + +128 +00:06:54,000 --> 00:06:56,000 +How does biometrics actually work. + +129 +00:06:56,000 --> 00:06:59,000 +Now I do have a chart here that I want to go over. + +130 +00:06:59,000 --> 00:07:04,000 +So when you want to set up biometrics generally on some kind of computer system, the first thing has + +131 +00:07:04,000 --> 00:07:06,000 +to have is an enrollment process. + +132 +00:07:06,000 --> 00:07:10,000 +This extracts and stores the unique features of that person. + +133 +00:07:10,000 --> 00:07:14,000 +So if you're enrolling for the thumbprint, you're gonna have to put their thumbprint quite a few times + +134 +00:07:14,000 --> 00:07:16,000 +to create what's known as a reference template. + +135 +00:07:17,000 --> 00:07:19,000 +Comparison. + +136 +00:07:19,000 --> 00:07:21,000 +Real time comparison of the user templates. + +137 +00:07:21,000 --> 00:07:22,000 +So when you put your thumbprint. + +138 +00:07:23,000 --> 00:07:27,000 +Uh, what starts to happen is going to start to compare to what it has in its database. + +139 +00:07:28,000 --> 00:07:29,000 +Is it match or does it match? + +140 +00:07:29,000 --> 00:07:33,000 +Now keep in mind that it's generally should do this in one second or less. + +141 +00:07:33,000 --> 00:07:38,000 +Now, I do want to point out that biometrics can be 1 to 1 for authentication. + +142 +00:07:39,000 --> 00:07:41,000 +A one to many for identification also. + +143 +00:07:42,000 --> 00:07:43,000 +Here's what I mean by that. + +144 +00:07:43,000 --> 00:07:51,000 +So there's some biometrics machine where you have to put in a number, like I used to work at a place + +145 +00:07:51,000 --> 00:07:56,000 +where the, the clock in, you know, you have to clock in to go to when you go to work, you have to + +146 +00:07:56,000 --> 00:07:58,000 +clock in in the morning, clock out in the afternoon. + +147 +00:07:58,000 --> 00:08:03,000 +So you had a code, a four digit code you put in your code and then you put your hand. + +148 +00:08:03,000 --> 00:08:06,000 +So this was a hand geometry machine and would measure the size of your hand. + +149 +00:08:06,000 --> 00:08:08,000 +That was a 1 to 1. + +150 +00:08:08,000 --> 00:08:10,000 +In other words it's matching. + +151 +00:08:10,000 --> 00:08:13,000 +It knows the user and it's matching this one. + +152 +00:08:13,000 --> 00:08:19,000 +The handprint against that user template versus your phone is more of a one to many. + +153 +00:08:19,000 --> 00:08:24,000 +So what that means is this when you put your thumbprint, it takes and it has to match it against many + +154 +00:08:24,000 --> 00:08:25,000 +profiles it has. + +155 +00:08:25,000 --> 00:08:27,000 +And see whichever one matches up log you in. + +156 +00:08:28,000 --> 00:08:28,000 +Okay. + +157 +00:08:28,000 --> 00:08:30,000 +Keep in mind guys, biometrics. + +158 +00:08:30,000 --> 00:08:34,000 +Yes, biometrics is easier to use than passwords. + +159 +00:08:34,000 --> 00:08:37,000 +And, uh, what do you call hard tokens or soft tokens? + +160 +00:08:37,000 --> 00:08:42,000 +Something you have and something you know on your exam. + +161 +00:08:42,000 --> 00:08:46,000 +They might give you a question where they say which one of these is more secure. + +162 +00:08:46,000 --> 00:08:47,000 +And I've mentioned this before. + +163 +00:08:47,000 --> 00:08:53,000 +I mentioned in a previous video they're going to give you choice a ten digit password choice B uh, + +164 +00:08:53,000 --> 00:09:00,000 +retina scanner choice C, fingerprint choice D bank card and Pin or something very simple. + +165 +00:09:00,000 --> 00:09:02,000 +And the answer is, of course, a bank card and a Pin. + +166 +00:09:02,000 --> 00:09:05,000 +I mentioned this earlier because that is considered multi-factor. + +167 +00:09:05,000 --> 00:09:07,000 +While the single factor the bet. + +168 +00:09:07,000 --> 00:09:11,000 +The best answer here though, would be something like a password or a thumbprint. + +169 +00:09:11,000 --> 00:09:17,000 +That's one of the best combinations because something, you know, complex password and something you + +170 +00:09:17,000 --> 00:09:18,000 +are biometric. + diff --git a/18 - Identity and Access Management (IAM)/008 Password Management OB 4.6_en.srt b/18 - Identity and Access Management (IAM)/008 Password Management OB 4.6_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..9d84b204a3dcadeb3c23e7f8eaae263a218039eb --- /dev/null +++ b/18 - Identity and Access Management (IAM)/008 Password Management OB 4.6_en.srt @@ -0,0 +1,476 @@ +1 +00:00:00,000 --> 00:00:02,000 +When it comes to IT security. + +2 +00:00:02,000 --> 00:00:09,000 +Unfortunately, the least secure way to log into a system is the most used way. + +3 +00:00:09,000 --> 00:00:11,000 +And of course, I'm talking about passwords. + +4 +00:00:12,000 --> 00:00:12,000 +All right. + +5 +00:00:12,000 --> 00:00:19,000 +Passwords is what we use to log into almost every system out there that does support things like biometrics + +6 +00:00:19,000 --> 00:00:24,000 +or something you have will also support passwords and many systems will only utilize passwords. + +7 +00:00:24,000 --> 00:00:28,000 +So let's see in this video let's learn more about passwords. + +8 +00:00:28,000 --> 00:00:29,000 +Let's go through it. + +9 +00:00:29,000 --> 00:00:35,000 +So when it comes to password uh let's go through some best practices. + +10 +00:00:35,000 --> 00:00:36,000 +When it comes to password. + +11 +00:00:36,000 --> 00:00:39,000 +The longer the password the more secure it is. + +12 +00:00:39,000 --> 00:00:42,000 +This prevents against brute force attacks against those passwords. + +13 +00:00:42,000 --> 00:00:48,000 +Now when it comes to different attacks against a password, brute force attack, if the password is + +14 +00:00:48,000 --> 00:00:52,000 +very small, can potentially guess every single combination. + +15 +00:00:52,000 --> 00:00:54,000 +At eight, it's somewhat secure. + +16 +00:00:54,000 --> 00:00:58,000 +And around 10 or 12 it becomes very secure now. + +17 +00:00:59,000 --> 00:01:04,000 +Also, you never want your password to just be, uh, lowercase letters or something. + +18 +00:01:04,000 --> 00:01:10,000 +That is a normal word in a dictionary because they basically run dictionaries against your prompt for + +19 +00:01:10,000 --> 00:01:11,000 +dictionary attacks. + +20 +00:01:11,000 --> 00:01:17,000 +So password should include a mix of uppercase, lowercase letters, numbers, and special characters + +21 +00:01:17,000 --> 00:01:19,000 +to resist brute force attack. + +22 +00:01:20,000 --> 00:01:21,000 +Now. + +23 +00:01:21,000 --> 00:01:23,000 +You don't want passwords to be reused. + +24 +00:01:23,000 --> 00:01:25,000 +Never reuse passwords. + +25 +00:01:25,000 --> 00:01:31,000 +Avoid using the same password, uh, across multiple accounts. + +26 +00:01:31,000 --> 00:01:31,000 +Right? + +27 +00:01:31,000 --> 00:01:36,000 +This is something that people are very guilty of doing that way, if I guess one of your password, + +28 +00:01:36,000 --> 00:01:41,000 +I can then use that password to log into many other accounts. + +29 +00:01:41,000 --> 00:01:42,000 +The other thing is expiration. + +30 +00:01:42,000 --> 00:01:46,000 +You should be changing your password about every 90 days. + +31 +00:01:46,000 --> 00:01:49,000 +Some organizations are going to say every 60 days to change your password. + +32 +00:01:49,000 --> 00:01:54,000 +That way if your password was ever compromised, maybe because its length was small and it wasn't complex + +33 +00:01:54,000 --> 00:01:56,000 +enough, at least you changed it. + +34 +00:01:56,000 --> 00:01:58,000 +Another thing is password age. + +35 +00:01:58,000 --> 00:02:03,000 +How often do you have to update your password? + +36 +00:02:04,000 --> 00:02:06,000 +Monitoring the age of the passengers to enforce the update. + +37 +00:02:06,000 --> 00:02:14,000 +You see, it's important with password age because what people do is their password expires and then + +38 +00:02:14,000 --> 00:02:18,000 +they change the password to the same password they had. + +39 +00:02:18,000 --> 00:02:20,000 +So password age says what? + +40 +00:02:20,000 --> 00:02:21,000 +You can't reuse that. + +41 +00:02:21,000 --> 00:02:24,000 +Basically you can't reuse that password over and over. + +42 +00:02:24,000 --> 00:02:28,000 +Now I know managing a password is complex. + +43 +00:02:28,000 --> 00:02:34,000 +So and because you have passwords for everything is there's a billion sites and you can't remember them + +44 +00:02:34,000 --> 00:02:35,000 +all. + +45 +00:02:35,000 --> 00:02:39,000 +Uh, especially if you try to make complex passwords that are really long. + +46 +00:02:39,000 --> 00:02:45,000 +Like for me, all my passwords and all my websites are probably touching 20 characters. + +47 +00:02:45,000 --> 00:02:50,000 +They are incredibly complex, and I don't memorize any of them because I like to use a password manager. + +48 +00:02:50,000 --> 00:02:58,000 +And there are tons of password manager such as Dashlane, which is a really good one, or LastPass. + +49 +00:02:58,000 --> 00:02:59,000 +That one is okay too. + +50 +00:02:59,000 --> 00:03:01,000 +So these are password managers. + +51 +00:03:01,000 --> 00:03:06,000 +These are software that you can download some of them are free, or they have free versions of them + +52 +00:03:06,000 --> 00:03:11,000 +that basically they store passwords for you, and some of them can even retype it on the website, so + +53 +00:03:11,000 --> 00:03:13,000 +you never need to memorize it like I do. + +54 +00:03:13,000 --> 00:03:18,000 +I don't memorize passwords at all because I'm too old to to memorize those complex things. + +55 +00:03:18,000 --> 00:03:23,000 +Now it's encouraged for managing large number of complex password password managers store and encrypt + +56 +00:03:23,000 --> 00:03:24,000 +passwords for you. + +57 +00:03:24,000 --> 00:03:27,000 +You only have to remember one strong master password. + +58 +00:03:27,000 --> 00:03:32,000 +And yes, my master password is incredibly complex and no one knows it. + +59 +00:03:33,000 --> 00:03:41,000 +Now we are moving into the world of passwordless authentication. + +60 +00:03:41,000 --> 00:03:43,000 +This is a new trend, and this is you're going to find more. + +61 +00:03:43,000 --> 00:03:48,000 +They're being replaced with alternative methods like biometric security keys at one time. + +62 +00:03:48,000 --> 00:03:50,000 +Have you guys gone to a website lately? + +63 +00:03:50,000 --> 00:03:57,000 +And you try to log in and it's like, well, you just put your username and you press enter and it says, + +64 +00:03:57,000 --> 00:04:04,000 +hey, you have your phone, let me send you a one time key or token to your, to your phone, and you + +65 +00:04:04,000 --> 00:04:06,000 +get the code to type it in and boom, it logs you in. + +66 +00:04:06,000 --> 00:04:07,000 +I know quite a few websites are doing that. + +67 +00:04:07,000 --> 00:04:11,000 +This is known as passwordless authentication. + +68 +00:04:12,000 --> 00:04:17,000 +This enhances security by eliminating the risk associated with weaker compromise password. + +69 +00:04:18,000 --> 00:04:24,000 +Another thing that we can use when it comes to managing users and passwords is something we call Pam, + +70 +00:04:24,000 --> 00:04:28,000 +or privileged access management tools, and this is something you want to implement on your network. + +71 +00:04:28,000 --> 00:04:35,000 +These are things that used to control, manage and monitor access to critical systems within the business. + +72 +00:04:35,000 --> 00:04:39,000 +They focus on people basically as good or privileged users in the network. + +73 +00:04:39,000 --> 00:04:40,000 +Now. + +74 +00:04:40,000 --> 00:04:42,000 +They do have. + +75 +00:04:42,000 --> 00:04:46,000 +Pam itself is going to give us three technology, what's called just in time. + +76 +00:04:46,000 --> 00:04:54,000 +We can use uh, basically for time limited access password vault in to store our credentials and what's + +77 +00:04:54,000 --> 00:04:55,000 +called a ephemeral credential. + +78 +00:04:55,000 --> 00:04:56,000 +Let's get into it. + +79 +00:04:56,000 --> 00:05:00,000 +So the first one up I want to mention is something called Just in time. + +80 +00:05:00,000 --> 00:05:07,000 +Just in time is when permissions are granted, uh, permissions granted privilege access on an as needed + +81 +00:05:07,000 --> 00:05:07,000 +basis. + +82 +00:05:07,000 --> 00:05:12,000 +So basically you log in, you need a certain amount of permissions to access a file. + +83 +00:05:12,000 --> 00:05:13,000 +Just in time. + +84 +00:05:13,000 --> 00:05:16,000 +We'll give you just that permission just when you need it. + +85 +00:05:17,000 --> 00:05:20,000 +And when you're done, it removes the credentials away from you. + +86 +00:05:20,000 --> 00:05:27,000 +So this reduces the risk of privilege abuse by ensuring privileges are only granted when they are needed. + +87 +00:05:27,000 --> 00:05:31,000 +So, for example, ideal for situations where users need temporary elevated access. + +88 +00:05:31,000 --> 00:05:36,000 +So let's say you're working in a network today and you're working in the accounting department. + +89 +00:05:36,000 --> 00:05:39,000 +But you need to do some bank reconciliation because Mary is not in. + +90 +00:05:39,000 --> 00:05:40,000 +But that's not your job. + +91 +00:05:40,000 --> 00:05:43,000 +So just in time they grant you that access to do that. + +92 +00:05:43,000 --> 00:05:46,000 +And then when you come back the next day it's gone. + +93 +00:05:46,000 --> 00:05:48,000 +The privilege to do that is gone. + +94 +00:05:49,000 --> 00:05:52,000 +In big companies, we're going to need to store those passwords. + +95 +00:05:52,000 --> 00:05:54,000 +So we're going to use what's called password vault in. + +96 +00:05:54,000 --> 00:06:00,000 +This is securely storing and managing credentials for privileged accounts in a central repository. + +97 +00:06:00,000 --> 00:06:05,000 +Now the good thing here is that this allows you to check in and check out the credentials when they + +98 +00:06:05,000 --> 00:06:05,000 +need. + +99 +00:06:05,000 --> 00:06:09,000 +The vault automatically manages and rotates and update passwords as needed. + +100 +00:06:09,000 --> 00:06:13,000 +That way, you could know if a credential is being used in your network, and the other one here is + +101 +00:06:13,000 --> 00:06:15,000 +called ephemeral credentials. + +102 +00:06:15,000 --> 00:06:18,000 +Now what this does, this is good technology that comes with the Pam. + +103 +00:06:18,000 --> 00:06:20,000 +Because what this does is this is able to. + +104 +00:06:22,000 --> 00:06:25,000 +These are temporary credentials that are generated on demand and expire. + +105 +00:06:25,000 --> 00:06:29,000 +So this is an entire username and password is generated when you need it. + +106 +00:06:29,000 --> 00:06:33,000 +It's only for a short period of time and then boom, it's gone forever. + +107 +00:06:33,000 --> 00:06:39,000 +So enhance the security by ensuring credentials are only valid for a short period of time. + +108 +00:06:39,000 --> 00:06:41,000 +Now you're going to specify what that is. + +109 +00:06:41,000 --> 00:06:45,000 +This is using dynamic environments like cloud, where credentials are needed for a short period of time + +110 +00:06:45,000 --> 00:06:47,000 +to complete a certain task, and then it's gone. + +111 +00:06:48,000 --> 00:06:48,000 +All right. + +112 +00:06:48,000 --> 00:06:50,000 +So when it comes to Pam. + +113 +00:06:50,000 --> 00:06:56,000 +Pam is really good to manage and credentials, uh, on a network, pushing up privileges when needed, + +114 +00:06:56,000 --> 00:07:02,000 +like with just in time or just giving out username and passwords, uh, like with ephemeral credentials. + +115 +00:07:02,000 --> 00:07:04,000 +But also we covered passwords. + +116 +00:07:04,000 --> 00:07:07,000 +Keep in mind passwords should be moderately long 8 to 12 characters. + +117 +00:07:07,000 --> 00:07:09,000 +Change your password at least every 90 days. + +118 +00:07:09,000 --> 00:07:16,000 +Keep it complex uppercase, lowercase numbers and symbols in your password and make sure don't reuse + +119 +00:07:16,000 --> 00:07:18,000 +the same password over and over. + diff --git a/18 - Identity and Access Management (IAM)/009 Quick Quiz.html b/18 - Identity and Access Management (IAM)/009 Quick Quiz.html new file mode 100644 index 0000000000000000000000000000000000000000..455aa698669b63ef0e5cbd82e3bd0b97abecaf7d --- /dev/null +++ b/18 - Identity and Access Management (IAM)/009 Quick Quiz.html @@ -0,0 +1,479 @@ + + + + + + + Quiz + + + + +
+
+

+

+
+
+
+ Score: 999 of + 999% +
+
Correct: 999
+
Incorrect: 999
+
+ +
+ + + + +
+ + + + diff --git a/19 - Incident Response/001 Incident Response Steps OB 4.8_en.srt b/19 - Incident Response/001 Incident Response Steps OB 4.8_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..c7cb8877ab55a56eecc0dcf0b45e68753ef1ef59 --- /dev/null +++ b/19 - Incident Response/001 Incident Response Steps OB 4.8_en.srt @@ -0,0 +1,544 @@ +1 +00:00:00,000 --> 00:00:06,000 +When you work in cybersecurity, you should expect to get a security incident almost on a daily basis. + +2 +00:00:06,000 --> 00:00:10,000 +If not, you're going to have multiple security incidents every single day. + +3 +00:00:10,000 --> 00:00:14,000 +Depending on your organization, some security incidents are going to be really small, and some of + +4 +00:00:14,000 --> 00:00:16,000 +them are going to be really big. + +5 +00:00:16,000 --> 00:00:18,000 +That needs to be responded to right away. + +6 +00:00:18,000 --> 00:00:24,000 +In this video, I want to talk about what exactly is a security incident, what is the definition of + +7 +00:00:24,000 --> 00:00:25,000 +a security incident. + +8 +00:00:25,000 --> 00:00:31,000 +And of course, we want to go through the security incident steps that you need to know for your exam. + +9 +00:00:31,000 --> 00:00:32,000 +So let's get started. + +10 +00:00:33,000 --> 00:00:37,000 +First of all, what exactly is a security incident? + +11 +00:00:37,000 --> 00:00:39,000 +How do you define a security incident? + +12 +00:00:39,000 --> 00:00:46,000 +Well, by definition, a security incident is an event that that compromises the confidentiality, integrity + +13 +00:00:46,000 --> 00:00:48,000 +or availability of information assets. + +14 +00:00:48,000 --> 00:00:54,000 +Now, basically anything that affects CIA is considered a security incident. + +15 +00:00:54,000 --> 00:00:55,000 +Let me give you a few examples. + +16 +00:00:55,000 --> 00:00:58,000 +Obviously, a hacker stealing data, that's confidentiality. + +17 +00:00:58,000 --> 00:01:03,000 +It's affecting confidential de DDoS against your server. + +18 +00:01:03,000 --> 00:01:05,000 +Well, that's affecting availability. + +19 +00:01:05,000 --> 00:01:08,000 +Hacker changing data or bad people changing your information. + +20 +00:01:08,000 --> 00:01:10,000 +That's against integrity. + +21 +00:01:10,000 --> 00:01:12,000 +Now it just doesn't include that. + +22 +00:01:12,000 --> 00:01:15,000 +But what about a printer drop in server going offline. + +23 +00:01:15,000 --> 00:01:18,000 +Those are both against availability within the network. + +24 +00:01:18,000 --> 00:01:20,000 +What if a user workstation crashes? + +25 +00:01:20,000 --> 00:01:22,000 +That again is availability. + +26 +00:01:22,000 --> 00:01:24,000 +What if a user gets a virus on their computer? + +27 +00:01:24,000 --> 00:01:28,000 +Potential confidentiality, integrity and availability that's getting hit. + +28 +00:01:28,000 --> 00:01:32,000 +So security incidents are pretty broad. + +29 +00:01:32,000 --> 00:01:35,000 +In other words, it's not just hacker coming in. + +30 +00:01:35,000 --> 00:01:41,000 +In fact, 90% of security incidents comes happens because of internal users doing things. + +31 +00:01:41,000 --> 00:01:46,000 +For example, a user may open an email link, a user station may die. + +32 +00:01:47,000 --> 00:01:52,000 +Don't think all your security incidents are coming from outside that you have to remove from your mind. + +33 +00:01:52,000 --> 00:01:56,000 +Most of the security incidents occurs with the people who have access to the information. + +34 +00:01:56,000 --> 00:01:58,000 +Now that you have it, you got to have a process. + +35 +00:01:58,000 --> 00:02:03,000 +You got to have a process and steps in order to deal with this incident. + +36 +00:02:03,000 --> 00:02:09,000 +It is super important that you memorize this in the order that you see it in. + +37 +00:02:09,000 --> 00:02:18,000 +So we have to prepare, detect, analyze, contain, eradicate, recover and then do our lesson learn. + +38 +00:02:18,000 --> 00:02:19,000 +Let's get started on this. + +39 +00:02:19,000 --> 00:02:21,000 +So the first step. + +40 +00:02:22,000 --> 00:02:25,000 +When it comes to security incident is preparation. + +41 +00:02:25,000 --> 00:02:33,000 +This is where the organization develops the incident response plans, establishes the response teams, + +42 +00:02:33,000 --> 00:02:35,000 +set up the tools and communication channel. + +43 +00:02:35,000 --> 00:02:40,000 +So listen, before you respond to any incident, you have to build a team. + +44 +00:02:40,000 --> 00:02:42,000 +You have to come up with plans okay. + +45 +00:02:42,000 --> 00:02:44,000 +When this happens we do this. + +46 +00:02:44,000 --> 00:02:46,000 +You have to know who's going to be on the team. + +47 +00:02:46,000 --> 00:02:48,000 +You have to train the team. + +48 +00:02:48,000 --> 00:02:50,000 +You have to train the people when they're doing this. + +49 +00:02:50,000 --> 00:02:53,000 +They just can't go and respond to incidents if they weren't trained on this. + +50 +00:02:53,000 --> 00:02:59,000 +So this includes training people, conducting regular security assessments within the business and ensuring + +51 +00:02:59,000 --> 00:03:00,000 +that the team have the right resources. + +52 +00:03:00,000 --> 00:03:03,000 +So do this before you respond to any incident. + +53 +00:03:03,000 --> 00:03:10,000 +Now let's say let's play a, uh, let's come up with a scenario. + +54 +00:03:10,000 --> 00:03:14,000 +So the scenario is a user workstation was potentially hacked. + +55 +00:03:14,000 --> 00:03:23,000 +The user called in and said the workstation, uh, is is showing a message that the data is encrypted + +56 +00:03:23,000 --> 00:03:25,000 +and they want $10,000 to get the data back. + +57 +00:03:25,000 --> 00:03:27,000 +So this is a kind of a ransomware. + +58 +00:03:27,000 --> 00:03:29,000 +So this is what the user sees on the screen. + +59 +00:03:29,000 --> 00:03:32,000 +The first thing up is we have to detect this ransomware. + +60 +00:03:32,000 --> 00:03:35,000 +So detection involves identifying the security incidents. + +61 +00:03:35,000 --> 00:03:41,000 +This can be achieved through various means network monitoring intrusion detection system regular security + +62 +00:03:41,000 --> 00:03:42,000 +scans. + +63 +00:03:42,000 --> 00:03:48,000 +So something like this could have been detected with the user's endpoint security or antivirus software. + +64 +00:03:48,000 --> 00:03:52,000 +It could have been detected by the IDs system on the user's machine also. + +65 +00:03:53,000 --> 00:03:59,000 +Or it if it was a different kind of incident, something on a server, maybe a security audit by auditors + +66 +00:03:59,000 --> 00:03:59,000 +would have done. + +67 +00:03:59,000 --> 00:04:00,000 +So. + +68 +00:04:00,000 --> 00:04:05,000 +The first thing is to quickly I, uh, detect it. + +69 +00:04:05,000 --> 00:04:07,000 +If you don't detect it, you'll never respond to it. + +70 +00:04:07,000 --> 00:04:12,000 +The quicker you detect it means the faster you can respond. + +71 +00:04:12,000 --> 00:04:13,000 +Now analysis. + +72 +00:04:13,000 --> 00:04:14,000 +So now that we. + +73 +00:04:14,000 --> 00:04:16,000 +Okay, there's an incident we have to detect. + +74 +00:04:16,000 --> 00:04:19,000 +There's an incident on Mary's workstation. + +75 +00:04:19,000 --> 00:04:21,000 +Let's go analyze the incident. + +76 +00:04:21,000 --> 00:04:26,000 +Once the potential is is detected, it must be analyzed. + +77 +00:04:27,000 --> 00:04:27,000 +One. + +78 +00:04:27,000 --> 00:04:29,000 +We want to understand its nature. + +79 +00:04:29,000 --> 00:04:31,000 +Like what exactly is it doing? + +80 +00:04:31,000 --> 00:04:31,000 +Like what? + +81 +00:04:31,000 --> 00:04:33,000 +What is it that it wants? + +82 +00:04:33,000 --> 00:04:34,000 +Is it? + +83 +00:04:34,000 --> 00:04:39,000 +Well, in our case, we know it's a ransomware and it wants money, but has it stolen the data? + +84 +00:04:39,000 --> 00:04:40,000 +Is it modifying data? + +85 +00:04:40,000 --> 00:04:42,000 +Is it bringing down the system? + +86 +00:04:42,000 --> 00:04:46,000 +This involves determining the type of attack the system is affected. + +87 +00:04:46,000 --> 00:04:48,000 +Is data compromise. + +88 +00:04:48,000 --> 00:04:51,000 +This analysis is really important. + +89 +00:04:52,000 --> 00:04:55,000 +Because from here we can know what steps to take in order to fix it. + +90 +00:04:56,000 --> 00:05:00,000 +Now, one of the things we should be doing, depending on what the incident is we have to contain that + +91 +00:05:00,000 --> 00:05:01,000 +incident. + +92 +00:05:01,000 --> 00:05:06,000 +Containing the incident is to ensure the incident doesn't spread to limit the scope and magnitude. + +93 +00:05:06,000 --> 00:05:09,000 +This involves isolating systems, blocking malicious traffic. + +94 +00:05:09,000 --> 00:05:11,000 +The best thing here we can do, we go, we see. + +95 +00:05:11,000 --> 00:05:12,000 +Oh boy. + +96 +00:05:12,000 --> 00:05:13,000 +That's ransomware okay. + +97 +00:05:13,000 --> 00:05:14,000 +Unplug it. + +98 +00:05:14,000 --> 00:05:15,000 +Take it off the network. + +99 +00:05:15,000 --> 00:05:20,000 +So if it is a worm or some kind of malware that can spread, it doesn't spread that way. + +100 +00:05:20,000 --> 00:05:24,000 +It doesn't, uh, doesn't produce further damage on your network. + +101 +00:05:24,000 --> 00:05:25,000 +Eradicate it. + +102 +00:05:26,000 --> 00:05:27,000 +After the incident. + +103 +00:05:27,000 --> 00:05:30,000 +We have to get it off the entire system. + +104 +00:05:30,000 --> 00:05:32,000 +Eradication. + +105 +00:05:32,000 --> 00:05:34,000 +Uh, looks for that root cause, you know. + +106 +00:05:34,000 --> 00:05:36,000 +You know what is causing that? + +107 +00:05:36,000 --> 00:05:40,000 +This involves removing the malware, closing the security gap, restoring the system. + +108 +00:05:40,000 --> 00:05:42,000 +For example, something like this. + +109 +00:05:42,000 --> 00:05:43,000 +Like this ransomware. + +110 +00:05:43,000 --> 00:05:48,000 +The best thing here we can do is just reimage windows, reinstall windows, reinstall all the applications, + +111 +00:05:48,000 --> 00:05:50,000 +and hopefully no data was lost. + +112 +00:05:51,000 --> 00:05:52,000 +Recovery. + +113 +00:05:53,000 --> 00:05:57,000 +You want to restore the system, restore it to normal. + +114 +00:05:57,000 --> 00:05:59,000 +This includes ensuring that all systems are clean. + +115 +00:05:59,000 --> 00:06:01,000 +You want to make sure we reinstall windows. + +116 +00:06:01,000 --> 00:06:02,000 +You got to put it back on the network. + +117 +00:06:02,000 --> 00:06:03,000 +You got to put back all the applications. + +118 +00:06:03,000 --> 00:06:04,000 +You got to get the data. + +119 +00:06:05,000 --> 00:06:10,000 +And we got to make sure that the system is functioning just as she had it the day before. + +120 +00:06:10,000 --> 00:06:15,000 +Monitoring and then connecting to it and making sure that this malware does not come back. + +121 +00:06:15,000 --> 00:06:19,000 +Finally, lesson learned after the incident. + +122 +00:06:19,000 --> 00:06:19,000 +Resolve. + +123 +00:06:19,000 --> 00:06:25,000 +It's important to conduct a post incident review analyzing what happened, how it was handled, what + +124 +00:06:25,000 --> 00:06:26,000 +could have been done. + +125 +00:06:26,000 --> 00:06:34,000 +Now, keep in mind the lesson learned is more of, uh, the process, the incident response process. + +126 +00:06:34,000 --> 00:06:35,000 +Like a faster response. + +127 +00:06:35,000 --> 00:06:38,000 +Did we contain it right or wrong? + +128 +00:06:38,000 --> 00:06:40,000 +What could we have done better the next time? + +129 +00:06:41,000 --> 00:06:46,000 +So let's learn about more about the process of the actual incident response now. + +130 +00:06:47,000 --> 00:06:50,000 +These are steps that you're going to know for your exam. + +131 +00:06:50,000 --> 00:06:52,000 +Know these steps in the order. + +132 +00:06:52,000 --> 00:06:55,000 +Be prepared for questions where they're going to say, okay, they did this. + +133 +00:06:55,000 --> 00:06:57,000 +And then what should they do next? + +134 +00:06:57,000 --> 00:07:00,000 +Make sure to know these steps for your tests. + +135 +00:07:00,000 --> 00:07:05,000 +Now keep in mind that different organizations may have different steps, but these are the ones you + +136 +00:07:05,000 --> 00:07:07,000 +need to know for your exam. + diff --git a/19 - Incident Response/002 Incident Response Training OB 4.8_en.srt b/19 - Incident Response/002 Incident Response Training OB 4.8_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..9ec15d97b14faace57c32e6bd5610e2922a72364 --- /dev/null +++ b/19 - Incident Response/002 Incident Response Training OB 4.8_en.srt @@ -0,0 +1,488 @@ +1 +00:00:00,000 --> 00:00:07,000 +If you're working in cybersecurity and you're working on the incident response team, there are some + +2 +00:00:07,000 --> 00:00:08,000 +things that you should be familiar with. + +3 +00:00:08,000 --> 00:00:10,000 +So in this video, let's take a look at that. + +4 +00:00:10,000 --> 00:00:15,000 +First of all, if you're working on an incident response team, you have to have the appropriate training + +5 +00:00:15,000 --> 00:00:17,000 +in the right incident response activity. + +6 +00:00:17,000 --> 00:00:25,000 +You see, incident response is a very important or a critical process in IT security because it's not + +7 +00:00:25,000 --> 00:00:28,000 +if we're going to have an incident, it's just when we're going to have an incident and we're going + +8 +00:00:28,000 --> 00:00:32,000 +to have the right people to know what to do ASAP. + +9 +00:00:32,000 --> 00:00:37,000 +The longer incidents are out there or the longer incidents stays open or not responded to, or at least + +10 +00:00:37,000 --> 00:00:42,000 +not contained, the more data could be stolen modified. + +11 +00:00:42,000 --> 00:00:46,000 +Basically, the longer the systems are vulnerable or the more damage is happening. + +12 +00:00:46,000 --> 00:00:50,000 +So we want to make sure that we train our users correctly. + +13 +00:00:50,000 --> 00:00:57,000 +So training focuses on the educational and the skill based skills needed for preparing individuals and + +14 +00:00:57,000 --> 00:00:59,000 +teams to respond effectively. + +15 +00:00:59,000 --> 00:01:02,000 +Now the training is going to be a wide variety. + +16 +00:01:02,000 --> 00:01:04,000 +Good incident response. + +17 +00:01:04,000 --> 00:01:11,000 +Folks should have good skills and knowledge of different kinds of systems, networking and all kinds + +18 +00:01:11,000 --> 00:01:13,000 +of IT security tools. + +19 +00:01:13,000 --> 00:01:20,000 +You can't be an incident response person that has never worked on windows, or never worked on a windows + +20 +00:01:20,000 --> 00:01:26,000 +server, or don't understand how networking works or don't know IP addressing, you know, basic networking. + +21 +00:01:26,000 --> 00:01:31,000 +Because the simple fact is, you wouldn't understand the scope of how an incident affect a system if + +22 +00:01:31,000 --> 00:01:34,000 +you really don't know how that system works. + +23 +00:01:34,000 --> 00:01:39,000 +Now, also, when it comes to working an incident response and we come up with our incident response + +24 +00:01:39,000 --> 00:01:46,000 +process procedures of actually responding to an incident or fixing incidents, we have to have ways + +25 +00:01:46,000 --> 00:01:50,000 +of testing those responses or testing our process. + +26 +00:01:50,000 --> 00:01:53,000 +So what is testing is about? + +27 +00:01:53,000 --> 00:01:58,000 +Well, how prepared are we and how, you know, what's our capabilities in doing this. + +28 +00:01:58,000 --> 00:02:03,000 +So there's two kinds of tests I want to talk about table top tests and simulations. + +29 +00:02:03,000 --> 00:02:06,000 +So the first one up is a tabletop exercise. + +30 +00:02:06,000 --> 00:02:11,000 +Let's say your organization comes up with their own incident response process. + +31 +00:02:11,000 --> 00:02:16,000 +We're going to do this if an incident happened here's how we're going to detect it. + +32 +00:02:16,000 --> 00:02:19,000 +Here's how we're going to respond to it. + +33 +00:02:19,000 --> 00:02:23,000 +Here's how we're going to eradicate it now contain it and so on and so on. + +34 +00:02:24,000 --> 00:02:29,000 +So one of the first things they should be doing is what's called a tabletop exercise. + +35 +00:02:29,000 --> 00:02:36,000 +Remember, for your exam, tabletop exercise is a discussion based session where team members walk through + +36 +00:02:36,000 --> 00:02:37,000 +various incidents. + +37 +00:02:37,000 --> 00:02:42,000 +Scenario it is they're sitting at a table and they're discussing it. + +38 +00:02:42,000 --> 00:02:50,000 +For example, they're going to say, well, if there if a computer gets a virus and then they talk, + +39 +00:02:50,000 --> 00:02:55,000 +they go around and they talk about what they're going to do, how are they going to respond to this + +40 +00:02:55,000 --> 00:02:57,000 +computer that gets a virus? + +41 +00:02:57,000 --> 00:03:03,000 +The purpose of this is to assess the effectiveness of the incident response plan and the team's understanding. + +42 +00:03:03,000 --> 00:03:08,000 +So they're going to go around, they're going to say, Bob is going to say, well, I'm the one that. + +43 +00:03:08,000 --> 00:03:10,000 +Recovers the system. + +44 +00:03:10,000 --> 00:03:13,000 +Mary is going to say, well, before you do that, Bob, I got to contain the system. + +45 +00:03:13,000 --> 00:03:14,000 +Here is how I'm going to do that. + +46 +00:03:14,000 --> 00:03:20,000 +So they're basically understanding their roles and they're understanding exactly what they're going + +47 +00:03:20,000 --> 00:03:20,000 +to be doing. + +48 +00:03:20,000 --> 00:03:23,000 +Now, the thing is, they're not actually doing it. + +49 +00:03:24,000 --> 00:03:30,000 +You're not going to get up and do hands on of containing a, you know, containing a computer, for + +50 +00:03:30,000 --> 00:03:39,000 +example, that simulations, these are more hands on and involved in creating a realistic cyber incident + +51 +00:03:39,000 --> 00:03:40,000 +environment. + +52 +00:03:40,000 --> 00:03:43,000 +We're the response team can practice responding. + +53 +00:03:43,000 --> 00:03:46,000 +This includes the use of real tools and systems. + +54 +00:03:46,000 --> 00:03:48,000 +So if they're going to be. + +55 +00:03:49,000 --> 00:03:54,000 +Are contained in the system by taking it off the Vlan or taking it off the network. + +56 +00:03:54,000 --> 00:03:55,000 +You can actually go and do that. + +57 +00:03:55,000 --> 00:03:59,000 +They're going to go and maybe disable the Nic card or remove the cable from there. + +58 +00:03:59,000 --> 00:04:06,000 +If it involves utilizing certain malware, software anti-malware to clean the infection, then use that + +59 +00:04:06,000 --> 00:04:07,000 +tool. + +60 +00:04:07,000 --> 00:04:13,000 +This is going to give them a more realistic handling of the tools and to respond to incidents. + +61 +00:04:13,000 --> 00:04:16,000 +So this is a better test now. + +62 +00:04:17,000 --> 00:04:21,000 +When you manage an incident, you got to really look at the root cause of the incident. + +63 +00:04:21,000 --> 00:04:29,000 +This involves exploring systematic processes to identify the underlying reasons why a security incident + +64 +00:04:29,000 --> 00:04:29,000 +occurred. + +65 +00:04:29,000 --> 00:04:32,000 +RCA is critical, helps prevent future incidents. + +66 +00:04:32,000 --> 00:04:39,000 +So let's say you get, uh, somebody that gets, um. + +67 +00:04:40,000 --> 00:04:47,000 +Ransomware on their computer and you guys go, you do your incident response process, you respond to + +68 +00:04:47,000 --> 00:04:49,000 +it, you clean it up. + +69 +00:04:50,000 --> 00:04:53,000 +Three days later they got the same thing again. + +70 +00:04:53,000 --> 00:04:55,000 +And you go, you go, you clean it up. + +71 +00:04:55,000 --> 00:04:57,000 +But you got to keep asking yourself. + +72 +00:04:58,000 --> 00:05:00,000 +Why exactly is this happening? + +73 +00:05:00,000 --> 00:05:04,000 +What's the root cause of this person always getting malware? + +74 +00:05:04,000 --> 00:05:11,000 +After doing some digging, you came to understand that this person failed to attend the user awareness + +75 +00:05:11,000 --> 00:05:12,000 +training sessions. + +76 +00:05:13,000 --> 00:05:15,000 +That's why this user was not trained. + +77 +00:05:15,000 --> 00:05:19,000 +This user just kept clicking on things that says that they're going to be a millionaire if they click + +78 +00:05:19,000 --> 00:05:20,000 +on this. + +79 +00:05:21,000 --> 00:05:24,000 +So they kept falling for the same trick over and over. + +80 +00:05:24,000 --> 00:05:28,000 +Root cause analysis is when you're looking for the main cause. + +81 +00:05:28,000 --> 00:05:30,000 +Why is this incident happening? + +82 +00:05:30,000 --> 00:05:34,000 +By doing this, you are able to eradicate many incidents in your network. + +83 +00:05:34,000 --> 00:05:40,000 +So remember what root cause analysis is looking at the deep end like the deep, deep, deep end. + +84 +00:05:40,000 --> 00:05:41,000 +Why is this happening? + +85 +00:05:43,000 --> 00:05:48,000 +One other thing you might be doing when it comes to working on incident response is knowing who your + +86 +00:05:48,000 --> 00:05:49,000 +threats are. + +87 +00:05:49,000 --> 00:05:54,000 +Threat hunting is a whole different thing than working just in IT security. + +88 +00:05:54,000 --> 00:05:55,000 +So. + +89 +00:05:56,000 --> 00:06:03,000 +It involves exploring the proactive and iterative approach to detecting and isolating advanced threats + +90 +00:06:03,000 --> 00:06:05,000 +that evade security solution. + +91 +00:06:06,000 --> 00:06:09,000 +Critical components of a good security program. + +92 +00:06:09,000 --> 00:06:11,000 +Identifying mitigating sophisticated cyber threats. + +93 +00:06:11,000 --> 00:06:13,000 +Now, here's here's what threat hunting is. + +94 +00:06:13,000 --> 00:06:16,000 +You see in traditional cyber security. + +95 +00:06:18,000 --> 00:06:26,000 +We put in all the great practices to keep our system secure firewalls, IDs, all kinds of updates. + +96 +00:06:26,000 --> 00:06:30,000 +We trained our users multi layers of firewalls and so on. + +97 +00:06:30,000 --> 00:06:32,000 +Now here's the problem. + +98 +00:06:33,000 --> 00:06:36,000 +We then we sat back and we waited for the threat to come. + +99 +00:06:36,000 --> 00:06:37,000 +The threat come. + +100 +00:06:37,000 --> 00:06:38,000 +And it got in. + +101 +00:06:38,000 --> 00:06:41,000 +But we respond like we talked about in this section. + +102 +00:06:41,000 --> 00:06:43,000 +How about if we go after the threat. + +103 +00:06:43,000 --> 00:06:48,000 +How about if we proactively go after the threat? + +104 +00:06:48,000 --> 00:06:51,000 +Like this says exploring the proactive iterative approach to detecting. + +105 +00:06:51,000 --> 00:06:53,000 +How about if we go after? + +106 +00:06:53,000 --> 00:06:56,000 +How about if we go to the dark web and see what threats are coming? + +107 +00:06:56,000 --> 00:07:03,000 +How about if we learn about cyber threats that are out there that hasn't actually affected us yet, + +108 +00:07:03,000 --> 00:07:07,000 +and then build our systems proactively to stop those things? + +109 +00:07:07,000 --> 00:07:13,000 +So let's say there is malware a circulating the world right now, but it hasn't affected us. + +110 +00:07:14,000 --> 00:07:16,000 +How about if we go and we learn about malware? + +111 +00:07:16,000 --> 00:07:20,000 +A we explore what it is and now we hunt the threat. + +112 +00:07:20,000 --> 00:07:21,000 +We don't let the threat hunt us. + +113 +00:07:21,000 --> 00:07:23,000 +That was our whole methodology. + +114 +00:07:23,000 --> 00:07:27,000 +We just we built a fortress and we just waited for the threat to come. + +115 +00:07:27,000 --> 00:07:29,000 +Now we're going to build a fortress. + +116 +00:07:29,000 --> 00:07:30,000 +Now we're going to go and hunt the threat. + +117 +00:07:30,000 --> 00:07:35,000 +Now we're going to go and see who's coming after us, and then we can build our fortress even better. + +118 +00:07:35,000 --> 00:07:39,000 +So if it does come, it's not going to get us it's threat hunting. + +119 +00:07:39,000 --> 00:07:41,000 +So this takes a different approach to it. + +120 +00:07:41,000 --> 00:07:45,000 +Keep in mind that working on IT security at as many aspects of IT security. + +121 +00:07:45,000 --> 00:07:48,000 +But in this particular one, you got to understand the different threats out there. + +122 +00:07:48,000 --> 00:07:54,000 +And working on an incident response team is is a critical part of keeping your network secure. + diff --git a/19 - Incident Response/003 Digital Forensics OB 4.8_en.srt b/19 - Incident Response/003 Digital Forensics OB 4.8_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..a36fa4e4cc4bfa41d77e70826acb7aa1a3cce8f6 --- /dev/null +++ b/19 - Incident Response/003 Digital Forensics OB 4.8_en.srt @@ -0,0 +1,748 @@ +1 +00:00:00,000 --> 00:00:08,000 +When it comes to crime in modern society, most of it is going to be using a computer at some point, + +2 +00:00:08,000 --> 00:00:11,000 +either to do the crime or help to get the crime done. + +3 +00:00:11,000 --> 00:00:12,000 +Here's what I mean. + +4 +00:00:13,000 --> 00:00:17,000 +In the world of crime, there's two kinds of crime. + +5 +00:00:17,000 --> 00:00:21,000 +Crime where the computer helps you, or crime against the computer. + +6 +00:00:21,000 --> 00:00:24,000 +So crime, for example, let's say you want to kill someone. + +7 +00:00:24,000 --> 00:00:26,000 +I know it's an extreme example. + +8 +00:00:26,000 --> 00:00:31,000 +I know you want to kill someone, and you're not sure how to dispose of a body or the quickest way to + +9 +00:00:31,000 --> 00:00:31,000 +kill them. + +10 +00:00:31,000 --> 00:00:34,000 +So you go to Google and you type in, how do I kill someone? + +11 +00:00:34,000 --> 00:00:36,000 +How do I dispose of a body? + +12 +00:00:36,000 --> 00:00:39,000 +Well, that's where the computer is helping you do the crime. + +13 +00:00:39,000 --> 00:00:43,000 +Maybe you want to rob a bank and you're like, well, how does bank, how are bank secure? + +14 +00:00:43,000 --> 00:00:44,000 +Same thing. + +15 +00:00:44,000 --> 00:00:46,000 +But then there are crimes against the computer. + +16 +00:00:46,000 --> 00:00:53,000 +This is going to be like when you utilize malware to steal data, or like when you're doing a DDoS attack + +17 +00:00:53,000 --> 00:00:58,000 +to take out an entire system any which way, if you're ever caught, and hopefully you are, if that's + +18 +00:00:58,000 --> 00:01:02,000 +what you're doing, all those criminals, hopefully they get caught. + +19 +00:01:02,000 --> 00:01:04,000 +We are going to now need to. + +20 +00:01:06,000 --> 00:01:08,000 +Get the evidence to prosecute them. + +21 +00:01:08,000 --> 00:01:11,000 +And this brings me to this topic of digital forensics. + +22 +00:01:12,000 --> 00:01:19,000 +This is going to go into the methodologies and principles applied in the investigation of cyber incidents, + +23 +00:01:19,000 --> 00:01:24,000 +specifically focused identification, collection, examination and preservation of digital evidence. + +24 +00:01:24,000 --> 00:01:30,000 +So now remember this one here is talking about cyber, uh, cyber incidents. + +25 +00:01:30,000 --> 00:01:37,000 +But the things I'm talking about here applies to not just, uh, crimes against the computer, but crimes + +26 +00:01:37,000 --> 00:01:41,000 +that are utilized, crimes that utilize the computer as part of it. + +27 +00:01:42,000 --> 00:01:47,000 +It underscores the need for a good ethical handling of the digital evidence. + +28 +00:01:47,000 --> 00:01:49,000 +Now you want to remember something. + +29 +00:01:49,000 --> 00:01:56,000 +If digital evidence is, for example, like the Google search the criminal did to how to rob a bank, + +30 +00:01:56,000 --> 00:01:58,000 +that's digital evidence. + +31 +00:01:58,000 --> 00:02:02,000 +The problem with digital evidence versus physical evidence, like a murder body or murder weapon, is + +32 +00:02:02,000 --> 00:02:05,000 +that it can easily be manipulated and change. + +33 +00:02:05,000 --> 00:02:07,000 +So we have to know how to handle that. + +34 +00:02:07,000 --> 00:02:11,000 +So there are a couple of things here in this section of the course that I want to go over. + +35 +00:02:11,000 --> 00:02:15,000 +Keep in mind, I'm just going to tell you what you need to know for your exam. + +36 +00:02:15,000 --> 00:02:21,000 +Digital forensics is an entire industry within it that if you're interested in working for law enforcement, + +37 +00:02:21,000 --> 00:02:24,000 +please explore their certifications in it. + +38 +00:02:24,000 --> 00:02:29,000 +They're specialized tools like EnCase or Access Data Forensics Toolkit or the Fctc. + +39 +00:02:30,000 --> 00:02:34,000 +There are many tools, many you know, there's a whole industry on this. + +40 +00:02:34,000 --> 00:02:37,000 +Let's just go into what you need to know for your exam. + +41 +00:02:37,000 --> 00:02:39,000 +The first thing I want to mention is something called a legal hold. + +42 +00:02:39,000 --> 00:02:43,000 +This is a firm that means, um, we're potentially relevant. + +43 +00:02:43,000 --> 00:02:47,000 +Data is preserved for legal and investigative purpose. + +44 +00:02:47,000 --> 00:02:50,000 +This involves ensuring that such data is not altered, delete or destroyed. + +45 +00:02:50,000 --> 00:02:57,000 +So first of all, let's say somebody within an organization was stealing money out of the company. + +46 +00:02:58,000 --> 00:02:58,000 +All right. + +47 +00:02:58,000 --> 00:03:03,000 +And the we call the police and reported them to police, arrested the person. + +48 +00:03:03,000 --> 00:03:07,000 +The investigators are going to come in and say, we need a legal hold on all the data from our systems, + +49 +00:03:07,000 --> 00:03:14,000 +because that data and the system she was using is now going to be used as part of evidence to prosecute + +50 +00:03:14,000 --> 00:03:14,000 +her. + +51 +00:03:15,000 --> 00:03:18,000 +So they put a legal hold on it. + +52 +00:03:18,000 --> 00:03:26,000 +That means that such data is not altered, deleted, destroyed during the course of the investigation. + +53 +00:03:26,000 --> 00:03:27,000 +So they say it's a legal hold. + +54 +00:03:27,000 --> 00:03:29,000 +That means nobody can touch it. + +55 +00:03:29,000 --> 00:03:29,000 +All right. + +56 +00:03:29,000 --> 00:03:31,000 +That's for them to use. + +57 +00:03:31,000 --> 00:03:35,000 +Now, a hot topic for your exam is going to be this firm called the Chain of Custody. + +58 +00:03:35,000 --> 00:03:41,000 +This referred to the documentation of paper trail that records or other records control, transfer, + +59 +00:03:41,000 --> 00:03:44,000 +analysis and disposition of physical or electronic evidence. + +60 +00:03:44,000 --> 00:03:45,000 +Here's what it is. + +61 +00:03:46,000 --> 00:03:48,000 +When evidence is collected. + +62 +00:03:49,000 --> 00:03:54,000 +Who took it, when they took it, how they took it, where they took it to, what method it was used + +63 +00:03:54,000 --> 00:03:59,000 +to, to collect it, where they put it, how long it was there, who had access to it, when did they + +64 +00:03:59,000 --> 00:04:00,000 +take it? + +65 +00:04:00,000 --> 00:04:01,000 +What did they do with it? + +66 +00:04:01,000 --> 00:04:03,000 +Basically, it's like the life of the evidence. + +67 +00:04:03,000 --> 00:04:06,000 +It's a step by step life of the evidence. + +68 +00:04:06,000 --> 00:04:11,000 +It talks of things like it's a sequence of, you know, who had it, what did they do with it? + +69 +00:04:11,000 --> 00:04:13,000 +Who did they give it to transfer? + +70 +00:04:13,000 --> 00:04:15,000 +How did they analyze it? + +71 +00:04:15,000 --> 00:04:17,000 +How did they maybe gave it back? + +72 +00:04:18,000 --> 00:04:21,000 +And it's both for physical and electronic evidence. + +73 +00:04:21,000 --> 00:04:22,000 +You have to understand something. + +74 +00:04:22,000 --> 00:04:24,000 +The key word is integrity. + +75 +00:04:24,000 --> 00:04:30,000 +You see, how many times have you guys ever heard of court cases where they say something like, well, + +76 +00:04:30,000 --> 00:04:33,000 +the evidence was thrown out because the evidence was tampered with. + +77 +00:04:33,000 --> 00:04:34,000 +All right. + +78 +00:04:34,000 --> 00:04:35,000 +The evidence was tampered with. + +79 +00:04:35,000 --> 00:04:36,000 +So the evidence was no good. + +80 +00:04:36,000 --> 00:04:43,000 +The chain of custody ensures that the evidence was never tampered with in a way that makes the evidence + +81 +00:04:43,000 --> 00:04:44,000 +invalid. + +82 +00:04:44,000 --> 00:04:45,000 +So remember what it does. + +83 +00:04:45,000 --> 00:04:49,000 +Who took it when they took it, how they took it, what they did with it, where they put it, who accessed + +84 +00:04:49,000 --> 00:04:49,000 +it, and so on. + +85 +00:04:49,000 --> 00:04:52,000 +And it continues for the life of the evidence that way. + +86 +00:04:52,000 --> 00:04:57,000 +Let's say the prosecution is using this that way the defense can't look at it and say, well, this + +87 +00:04:57,000 --> 00:05:01,000 +evidence was tampered with in a way that that that corrupted it. + +88 +00:05:01,000 --> 00:05:02,000 +That way. + +89 +00:05:02,000 --> 00:05:06,000 +When the defense does look at it, defense can say, okay, well, this guy reanalyzed it. + +90 +00:05:06,000 --> 00:05:07,000 +You know, he's really smart. + +91 +00:05:07,000 --> 00:05:09,000 +So I guess it was it was the right. + +92 +00:05:09,000 --> 00:05:10,000 +It was the right analysis. + +93 +00:05:12,000 --> 00:05:14,000 +Acquiring digital evidence. + +94 +00:05:14,000 --> 00:05:18,000 +All right, is the process of collecting digital evidence while ensuring the data is. + +95 +00:05:18,000 --> 00:05:19,000 +Now this is the big thing. + +96 +00:05:19,000 --> 00:05:22,000 +I mentioned this when we talk digital evidence. + +97 +00:05:22,000 --> 00:05:24,000 +The big thing is manipulation. + +98 +00:05:24,000 --> 00:05:28,000 +The integrity of the evidence is important during the process. + +99 +00:05:28,000 --> 00:05:34,000 +This involves creating exact copies of hard drives, memory or other storage media, uh, using specialized + +100 +00:05:34,000 --> 00:05:34,000 +tools. + +101 +00:05:34,000 --> 00:05:39,000 +Now, I want to talk about this a little bit when it comes to digital evidence. + +102 +00:05:39,000 --> 00:05:43,000 +When we take, for example, all of those evidence are going to be stored on hard drive. + +103 +00:05:43,000 --> 00:05:48,000 +One of the things you want to do is you want to do what's called a bit by bit duplication of the drive. + +104 +00:05:48,000 --> 00:05:49,000 +So. + +105 +00:05:50,000 --> 00:05:53,000 +Here's how they collect digital evidence. + +106 +00:05:53,000 --> 00:05:56,000 +So let's say we had an employee at the company. + +107 +00:05:56,000 --> 00:05:57,000 +His name is Bob. + +108 +00:05:57,000 --> 00:05:59,000 +And Bob was stealing data. + +109 +00:05:59,000 --> 00:06:03,000 +So this computer that we had, we took we took Bob's hard drive out. + +110 +00:06:03,000 --> 00:06:05,000 +Now here's what we should do. + +111 +00:06:06,000 --> 00:06:11,000 +We're going to take the hard drive and we are going to duplicate. + +112 +00:06:11,000 --> 00:06:14,000 +This is the hard, hard drive. + +113 +00:06:14,000 --> 00:06:15,000 +This is the original one. + +114 +00:06:15,000 --> 00:06:17,000 +What we're going to do is we're going to make a copy. + +115 +00:06:18,000 --> 00:06:20,000 +To to analyze. + +116 +00:06:21,000 --> 00:06:22,000 +All right. + +117 +00:06:22,000 --> 00:06:23,000 +That's going to be one. + +118 +00:06:23,000 --> 00:06:24,000 +Copy. + +119 +00:06:24,000 --> 00:06:31,000 +Now, what we should do is you're going to make maybe not one, maybe two copies to analyze what we + +120 +00:06:31,000 --> 00:06:33,000 +should do with this original one is put it away. + +121 +00:06:33,000 --> 00:06:36,000 +This one should never be analyzed, should not be tampered with. + +122 +00:06:36,000 --> 00:06:37,000 +Now. + +123 +00:06:39,000 --> 00:06:44,000 +You don't want to just do a normal duplication of the original hard drive. + +124 +00:06:45,000 --> 00:06:45,000 +All right. + +125 +00:06:45,000 --> 00:06:53,000 +What we want to do is we want to do what's called a bit by bit duplicator. + +126 +00:06:53,000 --> 00:06:58,000 +This means that it's going to duplicate the drive every single sector you see. + +127 +00:06:58,000 --> 00:07:03,000 +If you just do a normal duplication or copy of the drive, it only copies just the just the data that's + +128 +00:07:03,000 --> 00:07:03,000 +there. + +129 +00:07:03,000 --> 00:07:05,000 +It doesn't copy all the data that was deleted. + +130 +00:07:05,000 --> 00:07:12,000 +You want to when you take this drive, when when you analyze it, you want to get all the blank spaces, + +131 +00:07:12,000 --> 00:07:15,000 +all the spaces that there is no data there, even though there is data there. + +132 +00:07:15,000 --> 00:07:17,000 +So do what's called a bit by bit duplication. + +133 +00:07:17,000 --> 00:07:19,000 +So you're going to want to take out the drive. + +134 +00:07:19,000 --> 00:07:21,000 +You're going to want to make a couple of copies of it. + +135 +00:07:23,000 --> 00:07:29,000 +And one copy that you should be making before I leave here is going to be is another duplication. + +136 +00:07:29,000 --> 00:07:29,000 +Copy. + +137 +00:07:30,000 --> 00:07:30,000 +Duplicate. + +138 +00:07:30,000 --> 00:07:31,000 +Hard drive. + +139 +00:07:31,000 --> 00:07:31,000 +Copy. + +140 +00:07:31,000 --> 00:07:32,000 +We'll call this. + +141 +00:07:32,000 --> 00:07:38,000 +What this is is this is an additional this is the drive you're going to use to make even more copies. + +142 +00:07:39,000 --> 00:07:40,000 +These means analyze drives. + +143 +00:07:40,000 --> 00:07:43,000 +So you make a couple of them but at least have one. + +144 +00:07:43,000 --> 00:07:45,000 +And then this drive here can be put into a vault. + +145 +00:07:45,000 --> 00:07:49,000 +This drive here can be put in stored away that no one has access to it. + +146 +00:07:49,000 --> 00:07:52,000 +No one is modifying or troubling it. + +147 +00:07:53,000 --> 00:07:54,000 +All right. + +148 +00:07:56,000 --> 00:07:57,000 +Reporting. + +149 +00:07:57,000 --> 00:08:01,000 +So report involves documenting the finding of the forensics. + +150 +00:08:01,000 --> 00:08:02,000 +What did you find? + +151 +00:08:02,000 --> 00:08:06,000 +Forensics tools like the access data forensics or the forensics toolkit. + +152 +00:08:06,000 --> 00:08:11,000 +Or in case, uh, in case these are all forensic software. + +153 +00:08:11,000 --> 00:08:13,000 +How was the evidence collected, analyzed and preserved? + +154 +00:08:13,000 --> 00:08:16,000 +And what conclusion can be drawn when you analyze the evidence? + +155 +00:08:16,000 --> 00:08:17,000 +Did he do the crime? + +156 +00:08:17,000 --> 00:08:18,000 +Did he not do the crime? + +157 +00:08:18,000 --> 00:08:21,000 +So you have to come up with a good reporting on this. + +158 +00:08:21,000 --> 00:08:23,000 +Preservation is the big thing. + +159 +00:08:25,000 --> 00:08:29,000 +Digital forensics refers to the process of protecting and maintaining the integrity. + +160 +00:08:29,000 --> 00:08:30,000 +The digital. + +161 +00:08:30,000 --> 00:08:32,000 +The main word is the integrity, right? + +162 +00:08:32,000 --> 00:08:35,000 +Because we said that it is important. + +163 +00:08:36,000 --> 00:08:39,000 +That you keep things the same. + +164 +00:08:39,000 --> 00:08:42,000 +If the evidence is ever modified, they're going to throw it out. + +165 +00:08:42,000 --> 00:08:47,000 +Storing the evidence in a secure environment, ensuring that is protected from alteration, tampering + +166 +00:08:47,000 --> 00:08:48,000 +or degradation. + +167 +00:08:48,000 --> 00:08:51,000 +You also, when I got here you see this hard drive. + +168 +00:08:51,000 --> 00:08:52,000 +The best thing to do is make a hash of it. + +169 +00:08:52,000 --> 00:08:55,000 +If you hash the entire drive, it was any modification. + +170 +00:08:55,000 --> 00:08:56,000 +You can detect that. + +171 +00:08:58,000 --> 00:08:59,000 +E-Discovery. + +172 +00:08:59,000 --> 00:09:01,000 +If you've ever heard of this firm e-discovery. + +173 +00:09:01,000 --> 00:09:07,000 +This is the process of identifying, collecting and producing electronically stored information. + +174 +00:09:07,000 --> 00:09:12,000 +So ESI in in response to a request for production legal case. + +175 +00:09:12,000 --> 00:09:17,000 +So e-discovery is identifying and collecting. + +176 +00:09:19,000 --> 00:09:21,000 +Electronic evidence emails. + +177 +00:09:22,000 --> 00:09:25,000 +Documents, databases, audio files, and video files. + +178 +00:09:25,000 --> 00:09:32,000 +So when you heard a storm eDiscovery, remember it's basically they're looking for electronic evidence, + +179 +00:09:32,000 --> 00:09:32,000 +right? + +180 +00:09:32,000 --> 00:09:33,000 +They're looking for. + +181 +00:09:34,000 --> 00:09:41,000 +That web page, that audio file, that video, that email that proves some kind of thing in a case where + +182 +00:09:41,000 --> 00:09:43,000 +it's proven the guy guilty or not guilty. + +183 +00:09:43,000 --> 00:09:43,000 +All right. + +184 +00:09:43,000 --> 00:09:48,000 +These are some terms here that you want to be familiar with when it comes to digital forensics. + +185 +00:09:48,000 --> 00:09:52,000 +Keep in mind this is an entire industry by itself. + +186 +00:09:52,000 --> 00:09:56,000 +It does require specialized training, but this is a good introduction to it if you ever want to give + +187 +00:09:56,000 --> 00:09:58,000 +it a shot in real life. + diff --git a/19 - Incident Response/004 Types of logs OB 4.9_en.srt b/19 - Incident Response/004 Types of logs OB 4.9_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..29bf04cf6874f0d2cb45ee968f90d2f9f3928361 --- /dev/null +++ b/19 - Incident Response/004 Types of logs OB 4.9_en.srt @@ -0,0 +1,456 @@ +1 +00:00:00,000 --> 00:00:05,000 +One of the most important things in IT security is log files. + +2 +00:00:05,000 --> 00:00:10,000 +Keep in mind that log files tells you all the activities happen in your network. + +3 +00:00:10,000 --> 00:00:16,000 +In fact, there are tons of different log files and firewall logs, application logs, network logs, + +4 +00:00:16,000 --> 00:00:17,000 +IDs, logs. + +5 +00:00:17,000 --> 00:00:19,000 +Everything has log files. + +6 +00:00:19,000 --> 00:00:24,000 +Let's do a quick review of some of these kinds of log files and where they come from in this video. + +7 +00:00:24,000 --> 00:00:26,000 +Now this is not an all end video. + +8 +00:00:26,000 --> 00:00:27,000 +Every device has log files. + +9 +00:00:27,000 --> 00:00:31,000 +And I just want to go through some of the most common log files that you're going to encounter. + +10 +00:00:31,000 --> 00:00:36,000 +Now, I do want to keep in mind that it is probably impossible to read all these log files. + +11 +00:00:36,000 --> 00:00:41,000 +That's why you're going to have a Siem system, Siem systems or security information and event management + +12 +00:00:41,000 --> 00:00:43,000 +is able to correlate. + +13 +00:00:43,000 --> 00:00:47,000 +Grab these log files for you and then read them for you. + +14 +00:00:47,000 --> 00:00:51,000 +And based on their algorithms, they can do alerts and tell you if there's any issues. + +15 +00:00:51,000 --> 00:00:54,000 +Let's go through some of the most common log files and where we get them from. + +16 +00:00:54,000 --> 00:01:03,000 +So when it comes to IT security, the first device that comes to my mind is actually this device, which + +17 +00:01:03,000 --> 00:01:04,000 +is your firewall. + +18 +00:01:04,000 --> 00:01:07,000 +Your firewall is going to come with a ton of log file. + +19 +00:01:07,000 --> 00:01:12,000 +In fact, if I log in here, there's a ton of log files that says all the traffic coming in and out, + +20 +00:01:12,000 --> 00:01:14,000 +what was denied, what was not denied. + +21 +00:01:14,000 --> 00:01:17,000 +So this is going to be included. + +22 +00:01:17,000 --> 00:01:19,000 +Attempted and blocked connections. + +23 +00:01:19,000 --> 00:01:20,000 +What was allowed? + +24 +00:01:20,000 --> 00:01:24,000 +Was there any did anybody modify this thing logged into it changes anything. + +25 +00:01:24,000 --> 00:01:28,000 +Unauthorized attempt, potential breaches is all going to be within the log files. + +26 +00:01:28,000 --> 00:01:32,000 +Thousands and thousands of entries every day for firewall logs. + +27 +00:01:32,000 --> 00:01:34,000 +Application log. + +28 +00:01:34,000 --> 00:01:39,000 +This is going to be logs that record events from specific application. + +29 +00:01:39,000 --> 00:01:44,000 +Think like Microsoft Word or a custom application you may have at crash did open it. + +30 +00:01:44,000 --> 00:01:46,000 +It corrupted data. + +31 +00:01:46,000 --> 00:01:48,000 +This includes information about its performance. + +32 +00:01:48,000 --> 00:01:56,000 +Maybe it keeps crashing how users or when users used it, any errors that might be generated on any + +33 +00:01:56,000 --> 00:01:56,000 +security events. + +34 +00:01:56,000 --> 00:01:59,000 +Maybe there's detection in there. + +35 +00:01:59,000 --> 00:02:04,000 +Maybe there's abnormal behavior with people using the application endpoint logs. + +36 +00:02:04,000 --> 00:02:09,000 +These are going to be generated by endpoint devices, laptops, desktop mobile devices. + +37 +00:02:09,000 --> 00:02:13,000 +Now you could have endpoint security software installed generating these logs too. + +38 +00:02:13,000 --> 00:02:15,000 +They contain information or operation. + +39 +00:02:15,000 --> 00:02:19,000 +But the activity on the device such as was there any changes on the device. + +40 +00:02:19,000 --> 00:02:21,000 +What are users using the device? + +41 +00:02:21,000 --> 00:02:27,000 +Is there any antivirus alerts such as the system infected with malware this is going to use to help + +42 +00:02:27,000 --> 00:02:28,000 +detect malware? + +43 +00:02:28,000 --> 00:02:32,000 +This is going to use to detect if there's any unattempted unauthorized access to these devices in the + +44 +00:02:32,000 --> 00:02:33,000 +first place. + +45 +00:02:34,000 --> 00:02:38,000 +Operating system specific security log. + +46 +00:02:38,000 --> 00:02:43,000 +Now the operating system, like windows, is going to have something called a system log that says any + +47 +00:02:43,000 --> 00:02:46,000 +problems and issues that happens with windows. + +48 +00:02:46,000 --> 00:02:49,000 +But there is in windows something called a security log. + +49 +00:02:49,000 --> 00:02:56,000 +This tells us specific things, such as when users are logging on and off, is there any errors, policy + +50 +00:02:56,000 --> 00:03:00,000 +changes, or even somebody manipulated things like group policies on it? + +51 +00:03:00,000 --> 00:03:03,000 +Now this is going to be within the operating system itself. + +52 +00:03:03,000 --> 00:03:07,000 +IDs, IPS, IDs helps to detect intrusions. + +53 +00:03:07,000 --> 00:03:13,000 +IPS can prevent intrusions such as shutting off connections or disabling connections. + +54 +00:03:13,000 --> 00:03:18,000 +Of course, anything that comes through these systems are going to be recorded and logged. + +55 +00:03:18,000 --> 00:03:23,000 +And this is going to give you log in information about network traffic and security threats. + +56 +00:03:24,000 --> 00:03:29,000 +They have to identify suspicious activity policy violations within your network. + +57 +00:03:29,000 --> 00:03:31,000 +Network logs. + +58 +00:03:31,000 --> 00:03:33,000 +Now this is going to come from your network devices. + +59 +00:03:33,000 --> 00:03:39,000 +Record data about the activities within a network including traffic flows, connectivity, even network + +60 +00:03:39,000 --> 00:03:40,000 +errors. + +61 +00:03:40,000 --> 00:03:41,000 +Maybe there's corruption of the data. + +62 +00:03:41,000 --> 00:03:43,000 +Maybe the data is taken too long. + +63 +00:03:43,000 --> 00:03:49,000 +Maybe there's rejection of the data from certain devices on the stand and the baseline activity. + +64 +00:03:49,000 --> 00:03:55,000 +So you should know what is the baseline network activity, especially the flow of traffic. + +65 +00:03:55,000 --> 00:04:01,000 +And if there's any variation, network logs can tell you that there's a worm you want to be familiar + +66 +00:04:01,000 --> 00:04:04,000 +with that is going to give you a ton of info. + +67 +00:04:04,000 --> 00:04:05,000 +It's called metadata. + +68 +00:04:05,000 --> 00:04:08,000 +Metadata refers to data about data. + +69 +00:04:08,000 --> 00:04:13,000 +For example, in cybersecurity, like like a file contains data. + +70 +00:04:13,000 --> 00:04:15,000 +But what is data about that data? + +71 +00:04:15,000 --> 00:04:21,000 +Well, things like file creation when it was created, when it was modified, who had access to it, + +72 +00:04:21,000 --> 00:04:22,000 +what did they do with it? + +73 +00:04:22,000 --> 00:04:24,000 +Did they send it in an email? + +74 +00:04:24,000 --> 00:04:25,000 +Where is it located? + +75 +00:04:25,000 --> 00:04:31,000 +So metadata are used to trace activities and look at patterns of what's happening with that data. + +76 +00:04:31,000 --> 00:04:34,000 +Now where are we getting these log files from right. + +77 +00:04:34,000 --> 00:04:38,000 +Where are the sources that you're going to get information about your network from? + +78 +00:04:38,000 --> 00:04:46,000 +Well, the most common way that you're going to find information about potential impacts or potential + +79 +00:04:46,000 --> 00:04:52,000 +vulnerabilities or potential holes or malware is going to be in a vulnerability scan. + +80 +00:04:52,000 --> 00:04:59,000 +There's going to be automated tools that you're going to use to scan systems across the network. + +81 +00:04:59,000 --> 00:05:05,000 +And the application security weakness vulnerability scanners, like the Nexus security scanner will + +82 +00:05:05,000 --> 00:05:08,000 +be able to tell you that that machine over there is not patched. + +83 +00:05:08,000 --> 00:05:09,000 +It has a weak password. + +84 +00:05:09,000 --> 00:05:13,000 +Also, they give you detailed information about each system. + +85 +00:05:15,000 --> 00:05:16,000 +Automated reports. + +86 +00:05:16,000 --> 00:05:19,000 +So you're going to have a variety of security tools and systems. + +87 +00:05:19,000 --> 00:05:23,000 +Think of like IPS systems Siem systems. + +88 +00:05:23,000 --> 00:05:26,000 +That's going to generate all kinds of automated reports. + +89 +00:05:26,000 --> 00:05:28,000 +That's going to give you a ton of information about your network. + +90 +00:05:28,000 --> 00:05:33,000 +First of all, a high level overview of your security posture, like, hey, how secure really is your + +91 +00:05:33,000 --> 00:05:33,000 +network? + +92 +00:05:33,000 --> 00:05:39,000 +And then it's going to go into different patterns that shows whether you are being more secure or you're + +93 +00:05:39,000 --> 00:05:39,000 +not. + +94 +00:05:40,000 --> 00:05:41,000 +Dashboard. + +95 +00:05:42,000 --> 00:05:45,000 +In things like seem systems and software like Splunk. + +96 +00:05:45,000 --> 00:05:50,000 +They have dashboards that does a real time overview of the organization, security status, the aggregate + +97 +00:05:50,000 --> 00:05:55,000 +data from multiple log files or multiple sources in a single interface. + +98 +00:05:55,000 --> 00:05:57,000 +They can even give you alerts. + +99 +00:05:57,000 --> 00:06:01,000 +Dashboards are good for monitoring your systems in real time. + +100 +00:06:01,000 --> 00:06:06,000 +Now, if you monitor a network, you're going to have what's you're going to be doing packet capture. + +101 +00:06:06,000 --> 00:06:11,000 +Packet captures is when you utilize software like Wireshark. + +102 +00:06:11,000 --> 00:06:16,000 +This records network traffic and analyze the traffic that traverse across your network. + +103 +00:06:16,000 --> 00:06:22,000 +The Wireshark allows you to capture that network traffic, and then you're going to have to analyze + +104 +00:06:22,000 --> 00:06:22,000 +it. + +105 +00:06:22,000 --> 00:06:27,000 +And if you have the good skills, you can know, okay, this is abnormal traffic or this is normal traffic. + +106 +00:06:27,000 --> 00:06:30,000 +And but it's going to give you a good understand the nature of the network. + +107 +00:06:30,000 --> 00:06:36,000 +Now when you analyze it you can see is data being sent away from your network. + +108 +00:06:36,000 --> 00:06:40,000 +Is there a communications between attackers and normal systems? + +109 +00:06:41,000 --> 00:06:46,000 +Uh, if you haven't played around with packet capture and tools such as Wireshark, I strongly suggest + +110 +00:06:46,000 --> 00:06:47,000 +that you do. + +111 +00:06:47,000 --> 00:06:52,000 +Keep in mind this is just a quick overview of some common log files or common places we're going to + +112 +00:06:52,000 --> 00:06:53,000 +learn about our network. + +113 +00:06:53,000 --> 00:06:59,000 +Keep in mind, every device and every application on the network has log files, and I know reading + +114 +00:06:59,000 --> 00:07:04,000 +them is impossible, but that's why you have Siem systems to make it a lot easier. + diff --git a/19 - Incident Response/005 Quick Quiz.html b/19 - Incident Response/005 Quick Quiz.html new file mode 100644 index 0000000000000000000000000000000000000000..160eb538e2db4a5be682cc4ea8e2ea1c20464496 --- /dev/null +++ b/19 - Incident Response/005 Quick Quiz.html @@ -0,0 +1,479 @@ + + + + + + + Quiz + + + + +
+
+

+

+
+
+
+ Score: 999 of + 999% +
+
Correct: 999
+
Incorrect: 999
+
+ +
+ + + + +
+ + + + diff --git a/20 - Security Governance and Privacy/001 Security Polices, Standards, Guidelines and Procedures OB 5.1_en.srt b/20 - Security Governance and Privacy/001 Security Polices, Standards, Guidelines and Procedures OB 5.1_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..1f2a80d29ec28faa849842dd71f7ad2470b398bf --- /dev/null +++ b/20 - Security Governance and Privacy/001 Security Polices, Standards, Guidelines and Procedures OB 5.1_en.srt @@ -0,0 +1,1200 @@ +1 +00:00:00,000 --> 00:00:06,000 +When it comes to building a good security program and ensuring that you have support from senior management + +2 +00:00:06,000 --> 00:00:11,000 +to build programs, that's going to stop threats and protect your asset. + +3 +00:00:11,000 --> 00:00:15,000 +It is critical that we have what's called security governance. + +4 +00:00:15,000 --> 00:00:20,000 +Now, before I get into all of this great terminologies here, I want to talk about the word governance. + +5 +00:00:20,000 --> 00:00:26,000 +You see, in an organization, most people have probably heard of what's called corporate governance. + +6 +00:00:26,000 --> 00:00:34,000 +Corporate governance are all the steps that management takes in order to run the business. + +7 +00:00:34,000 --> 00:00:38,000 +Corporate governance is about accomplishing the mission of the business. + +8 +00:00:38,000 --> 00:00:41,000 +It's about accomplishing goals of the business. + +9 +00:00:41,000 --> 00:00:44,000 +So the business has a particular plan. + +10 +00:00:44,000 --> 00:00:47,000 +That said, increase revenue by 30% over the next one year. + +11 +00:00:47,000 --> 00:00:49,000 +Corporate governance would step in that. + +12 +00:00:49,000 --> 00:00:52,000 +Now a subset of corporate governance is IT governance. + +13 +00:00:52,000 --> 00:00:55,000 +And then a subset of that is IT security governance. + +14 +00:00:55,000 --> 00:01:01,000 +Now in recent years, security governance has started to branch away and just become a standalone thing + +15 +00:01:01,000 --> 00:01:07,000 +as security is now not just a function of just pure it, but it's basically has become its own department + +16 +00:01:07,000 --> 00:01:08,000 +now. + +17 +00:01:08,000 --> 00:01:12,000 +So depending on the structure you you follow in a business security governance, what we're going to + +18 +00:01:12,000 --> 00:01:17,000 +be covering could be a standalone thing, or it could be part of an IT department. + +19 +00:01:17,000 --> 00:01:22,000 +But keep in mind, whether it's IT or it's security, IT governance or just security governance, they're + +20 +00:01:22,000 --> 00:01:26,000 +all going to be a subset of corporate governance. + +21 +00:01:26,000 --> 00:01:28,000 +So in this course obviously we're talking about security. + +22 +00:01:28,000 --> 00:01:30,000 +So let's stick with security governance. + +23 +00:01:31,000 --> 00:01:35,000 +When you think of governance I want you guys to think of what the word manage. + +24 +00:01:35,000 --> 00:01:41,000 +It's basically what are we going to be doing or what are we going to be managing in order to accomplish + +25 +00:01:41,000 --> 00:01:45,000 +the goal of the IT security or the security department? + +26 +00:01:45,000 --> 00:01:52,000 +So it's a collection of practices for supporting, evaluating, defining and directing the security + +27 +00:01:52,000 --> 00:01:52,000 +efforts. + +28 +00:01:52,000 --> 00:01:54,000 +So what are we doing? + +29 +00:01:54,000 --> 00:01:55,000 +What are we going to support the security efforts. + +30 +00:01:55,000 --> 00:01:56,000 +We're going to evaluate it. + +31 +00:01:56,000 --> 00:01:58,000 +We're going to define it and we're going to direct it. + +32 +00:01:58,000 --> 00:02:01,000 +But you got to understand this word. + +33 +00:02:01,000 --> 00:02:03,000 +What exactly is security efforts. + +34 +00:02:03,000 --> 00:02:10,000 +Security efforts is defined as the activities that we do in the security department to protect our assets. + +35 +00:02:10,000 --> 00:02:16,000 +So whether you're configuring a firewall, updating an IDs, install an anti-malware on a computer, + +36 +00:02:16,000 --> 00:02:19,000 +those are all considered security efforts. + +37 +00:02:19,000 --> 00:02:23,000 +Now, if you have good security governance or good security management, because that's really what + +38 +00:02:23,000 --> 00:02:23,000 +this is saying. + +39 +00:02:23,000 --> 00:02:28,000 +Security management, if you have good security management, what are what are we going to try to get + +40 +00:02:28,000 --> 00:02:28,000 +out of it? + +41 +00:02:28,000 --> 00:02:33,000 +Well, these things we're going to try to establish and sustain a culture of security. + +42 +00:02:34,000 --> 00:02:39,000 +Within the within the company's culture, we're going to establish and maintain a framework to provide + +43 +00:02:39,000 --> 00:02:43,000 +assurance that information security aligns with business objectives. + +44 +00:02:43,000 --> 00:02:48,000 +Now, this particular, uh, second bulleted point is the main one. + +45 +00:02:49,000 --> 00:02:54,000 +Is security aligned with the company's objectives now? + +46 +00:02:55,000 --> 00:02:58,000 +I've always said this about organizations. + +47 +00:02:58,000 --> 00:03:00,000 +It is not the organization. + +48 +00:03:00,000 --> 00:03:06,000 +It is not the security department to dictate the direction of the business. + +49 +00:03:06,000 --> 00:03:09,000 +The direction of the business is dictated by the senior management. + +50 +00:03:10,000 --> 00:03:11,000 +I'll give you guys an example. + +51 +00:03:11,000 --> 00:03:15,000 +Let's say we go to Penn Station where we catch the Amtrak from New York. + +52 +00:03:15,000 --> 00:03:18,000 +The Amtrak is a train that goes all over the country. + +53 +00:03:18,000 --> 00:03:24,000 +It is not the security folks that dictates which Amtrak we're going to take. + +54 +00:03:24,000 --> 00:03:27,000 +We could take an Amtrak to go north to Boston. + +55 +00:03:27,000 --> 00:03:29,000 +We could take one to go to Florida. + +56 +00:03:30,000 --> 00:03:32,000 +We can even take one to go to California. + +57 +00:03:32,000 --> 00:03:38,000 +That is not the objectives of the actual IT department or the security department. + +58 +00:03:38,000 --> 00:03:40,000 +That's senior management. + +59 +00:03:40,000 --> 00:03:42,000 +They determined that they want to go to Boston. + +60 +00:03:42,000 --> 00:03:45,000 +It's our job to make sure the train don't fall off the track, if you know what I mean. + +61 +00:03:45,000 --> 00:03:47,000 +It's our job to make sure people don't fall off the train. + +62 +00:03:47,000 --> 00:03:50,000 +It's our job to keep that train on the track and keep it secure. + +63 +00:03:50,000 --> 00:03:55,000 +We need to make sure that what we do as security folks is aligned with the business to ensure the business + +64 +00:03:55,000 --> 00:04:00,000 +accomplishes its goal safely and within reasonable expenses. + +65 +00:04:00,000 --> 00:04:04,000 +We don't want to spend too much money and then go way off of the actual goal. + +66 +00:04:05,000 --> 00:04:10,000 +Ensure that security is consistent with the laws and regulations, and there is a lot that we have to + +67 +00:04:10,000 --> 00:04:10,000 +follow. + +68 +00:04:10,000 --> 00:04:15,000 +We want to assess the emerging threats and provide good security leadership. + +69 +00:04:15,000 --> 00:04:19,000 +Now, there are a couple of things here that I need you guys to know. + +70 +00:04:20,000 --> 00:04:29,000 +When you're talking security governance, you should develop policies, standards, guidelines and procedures. + +71 +00:04:29,000 --> 00:04:36,000 +In this section, I want you guys to know these four terms policies, standards, guidelines and procedures. + +72 +00:04:36,000 --> 00:04:44,000 +I'm going to go through these four things and I'll give you some examples of policies or different procedures + +73 +00:04:44,000 --> 00:04:44,000 +and so on. + +74 +00:04:44,000 --> 00:04:45,000 +So let's take a look. + +75 +00:04:46,000 --> 00:04:47,000 +Policies. + +76 +00:04:47,000 --> 00:04:49,000 +What exactly are policies? + +77 +00:04:49,000 --> 00:04:51,000 +What policies are critical component? + +78 +00:04:51,000 --> 00:04:55,000 +They provide a framework for the consistent and secure operations. + +79 +00:04:55,000 --> 00:04:56,000 +So what are policies? + +80 +00:04:56,000 --> 00:05:02,000 +Policies are basically framework for consistent and secure operations across the entire business. + +81 +00:05:02,000 --> 00:05:05,000 +Now in particularly we're talking security policies here. + +82 +00:05:06,000 --> 00:05:10,000 +They formed a foundation of how an organization's assets are secure. + +83 +00:05:11,000 --> 00:05:17,000 +Effective governance relies on the development, implementation and enforcement of these policies. + +84 +00:05:17,000 --> 00:05:21,000 +Now, every business that you work for should have policies in place. + +85 +00:05:22,000 --> 00:05:27,000 +Every business that you go and you sign up for during your employment, you probably got that employee + +86 +00:05:27,000 --> 00:05:32,000 +handbook that has tons of policies in it, whether it was an acceptable use policy, for example. + +87 +00:05:33,000 --> 00:05:37,000 +Uh, most people look at like vacation policies and time off policies, but in this one we really want + +88 +00:05:37,000 --> 00:05:39,000 +to look at security policies. + +89 +00:05:39,000 --> 00:05:40,000 +If you ask them, well, where do they come from? + +90 +00:05:41,000 --> 00:05:49,000 +In a good approach, policies should be developed by management or at least a supporting of the development + +91 +00:05:49,000 --> 00:05:50,000 +by management. + +92 +00:05:50,000 --> 00:05:56,000 +Policies should be developed using what's called a top down approach, which means policies comes from + +93 +00:05:56,000 --> 00:05:56,000 +management. + +94 +00:05:57,000 --> 00:05:58,000 +For your exam. + +95 +00:05:58,000 --> 00:06:04,000 +And in real life, the most important concept of a policy senior management support. + +96 +00:06:04,000 --> 00:06:07,000 +If senior management does not support the policy. + +97 +00:06:08,000 --> 00:06:09,000 +No one is going to follow it. + +98 +00:06:10,000 --> 00:06:11,000 +No one is going to read it. + +99 +00:06:11,000 --> 00:06:12,000 +No one is going to abide by it. + +100 +00:06:12,000 --> 00:06:17,000 +If senior management breaks the policy on a consistent basis, trust me, that policy has no way of + +101 +00:06:17,000 --> 00:06:19,000 +being being actually implemented. + +102 +00:06:20,000 --> 00:06:24,000 +So we want to make sure that the policy is top down, which means that policies comes from management + +103 +00:06:24,000 --> 00:06:25,000 +and is pushed down. + +104 +00:06:25,000 --> 00:06:30,000 +Policies is management way of telling what they want in the organization. + +105 +00:06:31,000 --> 00:06:34,000 +Now, what exactly are some policies? + +106 +00:06:34,000 --> 00:06:38,000 +Well, the first one up we have is what's called an acceptable use policy. + +107 +00:06:38,000 --> 00:06:43,000 +This defines the acceptable ways in which network or systems should be used. + +108 +00:06:43,000 --> 00:06:49,000 +For example, acceptable use policy will say the desktops and the laptops and the mobile phones should + +109 +00:06:49,000 --> 00:06:56,000 +only be used when accessing company resources, and no other time they're going to do this for all kinds + +110 +00:06:56,000 --> 00:07:00,000 +of things, from whether it's your desktop to your internet usage, like your email should only be used + +111 +00:07:00,000 --> 00:07:02,000 +for business purposes. + +112 +00:07:02,000 --> 00:07:05,000 +This, of course, is to protect the organization and resources. + +113 +00:07:05,000 --> 00:07:09,000 +Another policy is, of course going to be our information security policy. + +114 +00:07:09,000 --> 00:07:14,000 +This is now this is a broad range of different guidelines that we're going to be implementing to protect + +115 +00:07:14,000 --> 00:07:15,000 +the CIA. + +116 +00:07:15,000 --> 00:07:20,000 +It's going to cover things like data classification, access control, cryptography and even physical + +117 +00:07:20,000 --> 00:07:21,000 +security. + +118 +00:07:22,000 --> 00:07:29,000 +Now business continuity and disaster recovery policies now understand what business continuity is. + +119 +00:07:30,000 --> 00:07:34,000 +Business continuity is what we're going to do. + +120 +00:07:34,000 --> 00:07:38,000 +All right is what we're going to do after there is a disaster. + +121 +00:07:38,000 --> 00:07:40,000 +How do we continue to function? + +122 +00:07:40,000 --> 00:07:42,000 +How do we continue to function? + +123 +00:07:42,000 --> 00:07:49,000 +Uh, if there is a disaster such as a data center falling out, this includes essential functions during + +124 +00:07:49,000 --> 00:07:51,000 +and after a major disruption. + +125 +00:07:51,000 --> 00:07:56,000 +So let's say a major disaster has occurred. + +126 +00:07:56,000 --> 00:07:58,000 +One of the data centers is down. + +127 +00:07:58,000 --> 00:08:00,000 +50% of the business is not functioning. + +128 +00:08:00,000 --> 00:08:05,000 +What is your organization going to do while that data center is being rebuilt? + +129 +00:08:05,000 --> 00:08:07,000 +So that's business continuity. + +130 +00:08:07,000 --> 00:08:09,000 +The other one is called disaster recovery. + +131 +00:08:09,000 --> 00:08:12,000 +Disaster recovery is what you do to recover from the disaster. + +132 +00:08:12,000 --> 00:08:15,000 +So the data center dropped okay. + +133 +00:08:15,000 --> 00:08:20,000 +The business continuity was moved all of the processing to the cloud. + +134 +00:08:20,000 --> 00:08:25,000 +Now we have to repair that data center that that actually blew up like kind of like this picture. + +135 +00:08:26,000 --> 00:08:31,000 +But that's going to include things like data backup recover and systems knowing what roles and responsibilities + +136 +00:08:31,000 --> 00:08:32,000 +and who to do what. + +137 +00:08:32,000 --> 00:08:34,000 +So that's disaster recovery. + +138 +00:08:34,000 --> 00:08:39,000 +How do we recover from that particular disaster incident response policy? + +139 +00:08:39,000 --> 00:08:44,000 +Earlier in the course, we talked about an incident response plan or steps that you should know for + +140 +00:08:44,000 --> 00:08:45,000 +your exam. + +141 +00:08:45,000 --> 00:08:50,000 +Now, we want to have a policy in place that provides a structured approach for managing all kinds of + +142 +00:08:50,000 --> 00:08:53,000 +incidents and breaches, such as defining roles. + +143 +00:08:53,000 --> 00:08:57,000 +We talked about the processes that they want you to know and the communication strategy. + +144 +00:08:57,000 --> 00:09:03,000 +We want to minimize the impact of all of those particular security incidents. + +145 +00:09:03,000 --> 00:09:06,000 +Software development, life cycle policy. + +146 +00:09:06,000 --> 00:09:06,000 +What is this? + +147 +00:09:06,000 --> 00:09:13,000 +Well, most organizations, especially big organizations, are going to be developing their own software. + +148 +00:09:13,000 --> 00:09:17,000 +And if they're developing, deploying and maintaining their software, they have to have a policy that + +149 +00:09:17,000 --> 00:09:20,000 +states, how are they going to be doing these particular things? + +150 +00:09:20,000 --> 00:09:25,000 +What is management expected for when it comes to developing and deploying and maintaining their own + +151 +00:09:25,000 --> 00:09:25,000 +software? + +152 +00:09:25,000 --> 00:09:30,000 +What's the security in every stage of the software development life cycle? + +153 +00:09:31,000 --> 00:09:34,000 +Change will happen in every business. + +154 +00:09:34,000 --> 00:09:38,000 +We need a policy that dictates how are we going to be doing changes right? + +155 +00:09:38,000 --> 00:09:41,000 +What is critical about change management? + +156 +00:09:41,000 --> 00:09:46,000 +Well, you see, when it comes to change management, lots of errors can go wrong. + +157 +00:09:46,000 --> 00:09:50,000 +If there's one thing that we know is when something breaks in it, the first thing people say is, hey, + +158 +00:09:50,000 --> 00:09:51,000 +who changed what? + +159 +00:09:51,000 --> 00:09:57,000 +So we need a good procedures to make sure that changes are evaluated, approved and documented. + +160 +00:09:57,000 --> 00:10:02,000 +We don't want people just going and making unauthorized modification because they feel something needs + +161 +00:10:02,000 --> 00:10:03,000 +to change in a system. + +162 +00:10:04,000 --> 00:10:06,000 +So those were policies. + +163 +00:10:07,000 --> 00:10:10,000 +Under under policy, something a little bit more detail. + +164 +00:10:10,000 --> 00:10:11,000 +It's going to be a standard. + +165 +00:10:12,000 --> 00:10:19,000 +Standards are established benchmarks or sets of criteria against which security generally are measured + +166 +00:10:19,000 --> 00:10:20,000 +and designed. + +167 +00:10:20,000 --> 00:10:24,000 +They guide organizations in implementing the policies. + +168 +00:10:24,000 --> 00:10:29,000 +So while a policy is generally going to be more high level, a standard is going to be something much + +169 +00:10:29,000 --> 00:10:30,000 +more specific. + +170 +00:10:30,000 --> 00:10:33,000 +Let me give you a couple of examples of standards, like a password standard. + +171 +00:10:33,000 --> 00:10:38,000 +Password standards define the criteria for creating and for example managing passwords. + +172 +00:10:38,000 --> 00:10:42,000 +So your organization should have a password standard like what are the standards for passwords that + +173 +00:10:42,000 --> 00:10:43,000 +you guys follow. + +174 +00:10:43,000 --> 00:10:45,000 +What is the length that you guys. + +175 +00:10:45,000 --> 00:10:46,000 +Some people do eight, some people do ten. + +176 +00:10:47,000 --> 00:10:50,000 +The what's the complexity requirement? + +177 +00:10:50,000 --> 00:10:53,000 +How frequently does your company want to change passwords? + +178 +00:10:53,000 --> 00:10:55,000 +Access control standards. + +179 +00:10:55,000 --> 00:10:59,000 +How do you guys in your organization or the companies that you're going to work for? + +180 +00:10:59,000 --> 00:11:04,000 +How are you guys going to give access to the information systems and the data on them? + +181 +00:11:04,000 --> 00:11:12,000 +Is there a particular, uh, set of procedures or I should say, step by step things of doing this? + +182 +00:11:12,000 --> 00:11:14,000 +The standards can help dictate this. + +183 +00:11:14,000 --> 00:11:20,000 +So they're going to be guidelines for user authentication authentication, authorization levels. + +184 +00:11:20,000 --> 00:11:26,000 +These standards ensure that users have only the necessary resources, access to the necessary resources + +185 +00:11:26,000 --> 00:11:28,000 +they need to get their job done. + +186 +00:11:28,000 --> 00:11:34,000 +Physical security standards what standards do you guys follow to physically secure physical assets such + +187 +00:11:34,000 --> 00:11:39,000 +as tables, chairs, furniture, fixtures, computers, laptops, servers, and so on? + +188 +00:11:39,000 --> 00:11:45,000 +Address the protection of hardware, software, network and data from physical events. + +189 +00:11:45,000 --> 00:11:50,000 +This is going to include standards for securing our facilities, controlling physical access. + +190 +00:11:50,000 --> 00:11:54,000 +In the physical security section, we talked about all the different things we can do to physically + +191 +00:11:54,000 --> 00:11:55,000 +secure our network. + +192 +00:11:55,000 --> 00:11:58,000 +These are the standards that we're going to follow to do those things. + +193 +00:12:00,000 --> 00:12:01,000 +Encryption standards. + +194 +00:12:01,000 --> 00:12:06,000 +Every organization needs to follow some kind of standard when it comes to encryption. + +195 +00:12:06,000 --> 00:12:11,000 +For example, what bit strength, what algorithm do we want to use when it comes to securing our data. + +196 +00:12:11,000 --> 00:12:15,000 +So this is going to outline the requirements for encrypting data. + +197 +00:12:15,000 --> 00:12:19,000 +Remember encryption is data at rest and data in transit. + +198 +00:12:19,000 --> 00:12:22,000 +The coveted use of encryption algorithms key management and encryption protocols. + +199 +00:12:23,000 --> 00:12:25,000 +Now what are guidelines? + +200 +00:12:25,000 --> 00:12:28,000 +Guidelines are all throughout the industry. + +201 +00:12:28,000 --> 00:12:32,000 +Guidelines are best practices and cybersecurity. + +202 +00:12:32,000 --> 00:12:37,000 +Essential sets of recommendations and best practices that help shapes the organization posture. + +203 +00:12:37,000 --> 00:12:43,000 +They provide the roadmap for organizations in developing, implementing, and maintaining robust security + +204 +00:12:43,000 --> 00:12:43,000 +practices. + +205 +00:12:43,000 --> 00:12:44,000 +So. + +206 +00:12:45,000 --> 00:12:48,000 +How does guidelines influence standard standards you see? + +207 +00:12:48,000 --> 00:12:50,000 +Guidelines are best practices. + +208 +00:12:50,000 --> 00:12:55,000 +Basically, the industry said that we should have ten characters. + +209 +00:12:55,000 --> 00:12:56,000 +Let's say that's the new guideline. + +210 +00:12:57,000 --> 00:13:02,000 +Then your standard is going to say, well, we have ten character passwords, so where are we pulling + +211 +00:13:02,000 --> 00:13:03,000 +those standards from? + +212 +00:13:03,000 --> 00:13:04,000 +Where are we getting those standards from? + +213 +00:13:04,000 --> 00:13:06,000 +Generally from the guidelines. + +214 +00:13:06,000 --> 00:13:10,000 +Now we can't forget about what's called procedures. + +215 +00:13:10,000 --> 00:13:11,000 +So what are procedures? + +216 +00:13:11,000 --> 00:13:19,000 +Well, in the world of cybersecurity, governance procedures are the most detailed operational level + +217 +00:13:19,000 --> 00:13:22,000 +instructions that guide listen carefully day to day activities. + +218 +00:13:22,000 --> 00:13:31,000 +They are the actionable step by step, uh, they're basically the step by steps that operationalize + +219 +00:13:31,000 --> 00:13:32,000 +security policy standards. + +220 +00:13:32,000 --> 00:13:34,000 +Insurance security governance is implemented. + +221 +00:13:35,000 --> 00:13:39,000 +How do we implement that policy? + +222 +00:13:40,000 --> 00:13:44,000 +Well, review the standard to see the specifics of the policy. + +223 +00:13:44,000 --> 00:13:47,000 +Well, how do we how do we get that standard done? + +224 +00:13:47,000 --> 00:13:49,000 +Well, the procedures is it. + +225 +00:13:49,000 --> 00:13:50,000 +Let me give you an example. + +226 +00:13:50,000 --> 00:13:54,000 +So senior management I'm going to give you an example of a policy. + +227 +00:13:55,000 --> 00:13:57,000 +Uh, a policy, a standard. + +228 +00:13:58,000 --> 00:14:00,000 +A guideline and a procedure. + +229 +00:14:00,000 --> 00:14:01,000 +All for. + +230 +00:14:01,000 --> 00:14:02,000 +Let me use an example. + +231 +00:14:02,000 --> 00:14:04,000 +So senior management is going to write. + +232 +00:14:04,000 --> 00:14:06,000 +They're going to create a pass. + +233 +00:14:06,000 --> 00:14:08,000 +They're going to create an authentication policy. + +234 +00:14:08,000 --> 00:14:11,000 +The policy is going to be very generic because policies are high level. + +235 +00:14:11,000 --> 00:14:17,000 +They're going to say that all logins to the computers should be secured. + +236 +00:14:17,000 --> 00:14:19,000 +That's really it's going to say it's not going to go much. + +237 +00:14:19,000 --> 00:14:21,000 +It shouldn't be very detailed. + +238 +00:14:21,000 --> 00:14:26,000 +Now they're going to review the guidelines and say, well, in order to have secure logins they need + +239 +00:14:26,000 --> 00:14:28,000 +passwords with ten characters. + +240 +00:14:28,000 --> 00:14:30,000 +So the standard is going to come out. + +241 +00:14:30,000 --> 00:14:31,000 +The standard is going to be written. + +242 +00:14:31,000 --> 00:14:35,000 +The password standard is going to say ten characters change every 60 days. + +243 +00:14:36,000 --> 00:14:37,000 +But what's the procedure? + +244 +00:14:37,000 --> 00:14:40,000 +The procedure is how do we implement that? + +245 +00:14:40,000 --> 00:14:45,000 +What are we going to do to implement this secure authentication policy? + +246 +00:14:45,000 --> 00:14:51,000 +Well, the procedure is going to say something that goes like, well, go to Windows Server, go to + +247 +00:14:51,000 --> 00:14:53,000 +a Windows Server, that's a domain controller. + +248 +00:14:53,000 --> 00:14:55,000 +Click on the windows button. + +249 +00:14:55,000 --> 00:15:02,000 +Open up server manager, go to Active Directory users and computers and then administer the domain. + +250 +00:15:02,000 --> 00:15:06,000 +Change the domain policy to up to ten characters because by default it's eight. + +251 +00:15:06,000 --> 00:15:08,000 +Notice this is a step by step thing. + +252 +00:15:08,000 --> 00:15:14,000 +This is where you're clicking to implement that particular thing that gives you your policy. + +253 +00:15:14,000 --> 00:15:21,000 +Now you should have procedures for many things within your organization, not just one. + +254 +00:15:22,000 --> 00:15:26,000 +You can't implement a policy without a procedure. + +255 +00:15:26,000 --> 00:15:31,000 +The procedure is the step by step actions to implement that particular policy. + +256 +00:15:31,000 --> 00:15:33,000 +So something like change management procedures. + +257 +00:15:33,000 --> 00:15:34,000 +What is this. + +258 +00:15:34,000 --> 00:15:39,000 +Well these are procedures are critical to ensuring all IT system stays secure. + +259 +00:15:39,000 --> 00:15:40,000 +Why. + +260 +00:15:40,000 --> 00:15:44,000 +Because you see we need a step by step. + +261 +00:15:44,000 --> 00:15:46,000 +How do we request a change. + +262 +00:15:46,000 --> 00:15:48,000 +How do we review a change. + +263 +00:15:48,000 --> 00:15:49,000 +How do we approve a change. + +264 +00:15:49,000 --> 00:15:50,000 +How do we implement the change. + +265 +00:15:50,000 --> 00:15:52,000 +How do we document a change. + +266 +00:15:52,000 --> 00:15:56,000 +This is going to be a systematic way to manage changes. + +267 +00:15:57,000 --> 00:16:07,000 +What is the step by step actions we need to onboard people into the business and release people from + +268 +00:16:07,000 --> 00:16:07,000 +the business. + +269 +00:16:08,000 --> 00:16:10,000 +What is the steps for when we get a new employee? + +270 +00:16:10,000 --> 00:16:12,000 +How do we prove their identity? + +271 +00:16:12,000 --> 00:16:14,000 +How do we create that user account? + +272 +00:16:14,000 --> 00:16:16,000 +How do we add it to the group? + +273 +00:16:16,000 --> 00:16:18,000 +How do we ensure that they get the right access? + +274 +00:16:18,000 --> 00:16:21,000 +That's going to be onboarding when they're terminated? + +275 +00:16:21,000 --> 00:16:23,000 +What exactly are those steps? + +276 +00:16:23,000 --> 00:16:28,000 +How do we remove access to systems and data that they had access to? + +277 +00:16:29,000 --> 00:16:36,000 +Now playbook playbook is important in the world of IT security incidents. + +278 +00:16:36,000 --> 00:16:37,000 +You have to have a playbook. + +279 +00:16:37,000 --> 00:16:41,000 +When there is an incident, you basically play the book. + +280 +00:16:41,000 --> 00:16:46,000 +In other words, you open up a book that's going to have a bunch of procedures that you need to follow + +281 +00:16:46,000 --> 00:16:48,000 +when there is this incident. + +282 +00:16:48,000 --> 00:16:54,000 +So a playbook is a set of procedures that detail the steps to be taken in response to a particular incident. + +283 +00:16:54,000 --> 00:16:57,000 +So the moment there is an incident, we're going to basically run the playbook. + +284 +00:16:57,000 --> 00:17:03,000 +The playbook is going to give us all the steps we should be taking when managing that particular incident. + +285 +00:17:03,000 --> 00:17:04,000 +Security incident. + +286 +00:17:04,000 --> 00:17:09,000 +There's basically it's basically a predefined set of actions to follow, basically ensuring that consistent + +287 +00:17:09,000 --> 00:17:14,000 +and effective response to these particular incident, they cover a wide range of scenarios from data + +288 +00:17:14,000 --> 00:17:16,000 +breaches all the way to DDoS attack. + +289 +00:17:16,000 --> 00:17:17,000 +Okay. + +290 +00:17:17,000 --> 00:17:22,000 +Very important in this particular video, what was security governance? + +291 +00:17:22,000 --> 00:17:29,000 +Security governance is basically the management of all of IT security to keep our assets secure and + +292 +00:17:29,000 --> 00:17:35,000 +to ensure we align the security actions with business objectives. + +293 +00:17:35,000 --> 00:17:41,000 +When we're managing or when we are implementing security governance, we need to make sure we have policies + +294 +00:17:41,000 --> 00:17:42,000 +that are top down. + +295 +00:17:42,000 --> 00:17:47,000 +They're coming from senior management policies, are high level documents that implements the wishes + +296 +00:17:47,000 --> 00:17:49,000 +or desires of senior management. + +297 +00:17:49,000 --> 00:17:51,000 +Underneath that, you can have a standard. + +298 +00:17:52,000 --> 00:17:57,000 +Standards are basically more detailed information about those particular policies. + +299 +00:17:57,000 --> 00:18:02,000 +Where are we going to get a lot of the standards from guidelines or best practices in the industry, + +300 +00:18:02,000 --> 00:18:08,000 +and the step by step things or actions we need to implement those policies are in the procedures. + diff --git a/20 - Security Governance and Privacy/002 Security Governance Considerations and Revisions OB 5.1_en.srt b/20 - Security Governance and Privacy/002 Security Governance Considerations and Revisions OB 5.1_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..01731c1d52a0183abfe3622b837535e6324f2acf --- /dev/null +++ b/20 - Security Governance and Privacy/002 Security Governance Considerations and Revisions OB 5.1_en.srt @@ -0,0 +1,332 @@ +1 +00:00:00,000 --> 00:00:06,000 +When you are developing a good security governance program and making all of your standards, guidelines, + +2 +00:00:06,000 --> 00:00:11,000 +procedures and policies, there's a couple of things to think about and that's going to be external + +3 +00:00:11,000 --> 00:00:17,000 +considerations, things external to your business that's going to influence the development of those + +4 +00:00:17,000 --> 00:00:18,000 +particular documents. + +5 +00:00:18,000 --> 00:00:20,000 +So let's get started with this. + +6 +00:00:21,000 --> 00:00:22,000 +Things that you should consider? + +7 +00:00:22,000 --> 00:00:23,000 +I should say so. + +8 +00:00:23,000 --> 00:00:29,000 +These considerations is going to shape and often mandate aspects of security governance making them + +9 +00:00:29,000 --> 00:00:30,000 +critical. + +10 +00:00:30,000 --> 00:00:35,000 +Right now every organization is generally different in the way they're structured. + +11 +00:00:35,000 --> 00:00:40,000 +But if you are in a particular industry, for example, there's going to be specific laws that you're + +12 +00:00:40,000 --> 00:00:41,000 +going to be following. + +13 +00:00:41,000 --> 00:00:47,000 +So this is going to highlight the need for organization to be aware of and compliant with diverse range + +14 +00:00:47,000 --> 00:00:54,000 +of external factors such as legal and regulatory, technological, society changes, industry changes + +15 +00:00:54,000 --> 00:00:56,000 +or industry consideration. + +16 +00:00:56,000 --> 00:00:59,000 +Let's take a look at a few of these considerations. + +17 +00:00:59,000 --> 00:01:04,000 +The first thing up is going to be national regulatory and legal consideration. + +18 +00:01:04,000 --> 00:01:10,000 +Any time an organization builds a security governance program, keep in mind that all the different + +19 +00:01:10,000 --> 00:01:14,000 +laws and regulations that that company is going to have to follow. + +20 +00:01:14,000 --> 00:01:20,000 +For example, if the organization is located or does business in the European Union, they're going + +21 +00:01:20,000 --> 00:01:26,000 +to have to protect the privacy of your European Union citizens or EU citizens with GDPR. + +22 +00:01:27,000 --> 00:01:31,000 +Now, if you're in the United States and you're managing health records, you're going to have to follow + +23 +00:01:31,000 --> 00:01:32,000 +HIPAA. + +24 +00:01:32,000 --> 00:01:37,000 +If you are in the United States, you're managing credit card information, you're collecting credit + +25 +00:01:37,000 --> 00:01:37,000 +cards. + +26 +00:01:37,000 --> 00:01:41,000 +You're going to have to secure that using the PCI standard. + +27 +00:01:41,000 --> 00:01:46,000 +So these are some of the regulatory and regulations that you have to consider. + +28 +00:01:46,000 --> 00:01:50,000 +Now the other thing is that just don't think about things. + +29 +00:01:50,000 --> 00:01:56,000 +All the different regulatory laws that are like national, but they might be local or regional considerations + +30 +00:01:56,000 --> 00:01:58,000 +that you may have to follow. + +31 +00:01:58,000 --> 00:02:03,000 +Laws can be can affect an organization's security governance, for example, local governance law. + +32 +00:02:03,000 --> 00:02:06,000 +Maybe you doing physical security and the local. + +33 +00:02:07,000 --> 00:02:13,000 +Uh, city that you're in has laws on how structures has to be built, how much entries they have to + +34 +00:02:13,000 --> 00:02:15,000 +have, where cameras can be placed, and so on. + +35 +00:02:15,000 --> 00:02:21,000 +So this is state or other regional laws that you may have to be familiar with. + +36 +00:02:21,000 --> 00:02:23,000 +Another thing is going to be global consideration. + +37 +00:02:23,000 --> 00:02:30,000 +Now if your organization is a global entity there's a lot of things to think about. + +38 +00:02:31,000 --> 00:02:37,000 +Now this is going to include understanding and compliant with cybersecurity laws and regulations of + +39 +00:02:37,000 --> 00:02:38,000 +all the countries that you operate. + +40 +00:02:38,000 --> 00:02:44,000 +So if you're a global business and you take money from all of the countries in the world, be prepared + +41 +00:02:44,000 --> 00:02:49,000 +to manage a massive legal department, because now you have to know all the laws and regulations and + +42 +00:02:49,000 --> 00:02:52,000 +protecting the users data, following the laws that they're in. + +43 +00:02:53,000 --> 00:02:56,000 +So this of course could be very large scale. + +44 +00:02:56,000 --> 00:03:00,000 +Global consideration also involves dealing with cross border data transfer. + +45 +00:03:00,000 --> 00:03:05,000 +If you're collecting data on the EU citizens and you transfer and store in the United States, what + +46 +00:03:05,000 --> 00:03:06,000 +laws do you have to follow? + +47 +00:03:06,000 --> 00:03:08,000 +Industry considerations. + +48 +00:03:08,000 --> 00:03:11,000 +Different industries have unique cybersecurity challenges. + +49 +00:03:11,000 --> 00:03:13,000 +I give you guys a good example. + +50 +00:03:13,000 --> 00:03:15,000 +It's the cyber financial sector. + +51 +00:03:16,000 --> 00:03:23,000 +They might have some of the most stringent requirements because they carry some of the most the most + +52 +00:03:23,000 --> 00:03:27,000 +open data or the most confidential data, because they have all your credit card information, all your + +53 +00:03:27,000 --> 00:03:28,000 +banking information. + +54 +00:03:28,000 --> 00:03:31,000 +Another industry is going to be things like health care information. + +55 +00:03:31,000 --> 00:03:37,000 +So just because you're in that industry, be prepared for more cyber attacks than someone that's not. + +56 +00:03:37,000 --> 00:03:43,000 +So they're going to have a lot of stringent requirements when it comes to data encryption, for example, + +57 +00:03:43,000 --> 00:03:45,000 +in transaction security. + +58 +00:03:46,000 --> 00:03:54,000 +All right, so when you're making your, um, your policies, your procedures, you're creating that + +59 +00:03:54,000 --> 00:03:58,000 +entire program, you have to keep in mind all of these considerations. + +60 +00:03:58,000 --> 00:03:59,000 +Now. + +61 +00:04:00,000 --> 00:04:04,000 +I want you guys to keep in mind that it's not just. + +62 +00:04:05,000 --> 00:04:10,000 +Making all these policies and procedures and being familiar with some of these things, like laws and + +63 +00:04:10,000 --> 00:04:12,000 +regulations that you have to follow. + +64 +00:04:13,000 --> 00:04:20,000 +A good security governance program will need to be consistently updated, changed and revised. + +65 +00:04:20,000 --> 00:04:27,000 +And that's this last thing here that I want to just briefly mention and something that you should always + +66 +00:04:27,000 --> 00:04:27,000 +understand. + +67 +00:04:27,000 --> 00:04:35,000 +The world changes, laws changes, technology changes, people change, management change, CEO change. + +68 +00:04:35,000 --> 00:04:37,000 +Things change all the time. + +69 +00:04:38,000 --> 00:04:40,000 +So what is what are we going to be doing? + +70 +00:04:40,000 --> 00:04:45,000 +Well, keep in mind that those policies and procedures from yesterday may not be valid today. + +71 +00:04:45,000 --> 00:04:52,000 +So this involves understanding the ongoing process of overseeing security operations and making adjustment + +72 +00:04:52,000 --> 00:04:53,000 +keyword. + +73 +00:04:53,000 --> 00:04:57,000 +Make an adjustment because it's not just monitoring and keeping an eye on it. + +74 +00:04:57,000 --> 00:05:00,000 +It's about revising it for the current times. + +75 +00:05:00,000 --> 00:05:05,000 +As threats get more technical, threats becomes more difficult. + +76 +00:05:05,000 --> 00:05:08,000 +The program has to evolve to match the threats. + +77 +00:05:08,000 --> 00:05:09,000 +Security. + +78 +00:05:09,000 --> 00:05:15,000 +Governance requires not only the implementation of a good security measures, but also ongoing evaluation + +79 +00:05:15,000 --> 00:05:17,000 +and adapt to security changes. + +80 +00:05:18,000 --> 00:05:22,000 +All right, don't think that just creating a security program is just about making a few policies and + +81 +00:05:22,000 --> 00:05:22,000 +putting them in place. + +82 +00:05:22,000 --> 00:05:28,000 +No, it's about considering all the things that can affect those policies and consider how the environment + +83 +00:05:28,000 --> 00:05:32,000 +is consistently changed so you can keep it updated. + diff --git a/20 - Security Governance and Privacy/003 Security Governance Structures OB 5.1_en.srt b/20 - Security Governance and Privacy/003 Security Governance Structures OB 5.1_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..8b0f338c3e2cdf62c2195e17b29242251569fcd5 --- /dev/null +++ b/20 - Security Governance and Privacy/003 Security Governance Structures OB 5.1_en.srt @@ -0,0 +1,400 @@ +1 +00:00:00,000 --> 00:00:06,000 +When it comes to building a good security governance program, be prepared to deal with a lot of different + +2 +00:00:06,000 --> 00:00:11,000 +folks from different levels of the organization also outside the organization. + +3 +00:00:11,000 --> 00:00:16,000 +So let's take a look at some of these different governance structures that you're basically going to + +4 +00:00:16,000 --> 00:00:17,000 +be dealing with. + +5 +00:00:17,000 --> 00:00:19,000 +These structures have different sais. + +6 +00:00:19,000 --> 00:00:24,000 +They also have different opinions or different leverage over your governance program. + +7 +00:00:24,000 --> 00:00:30,000 +For example, government entities that sets regulations have a big part or a big say in your governance + +8 +00:00:30,000 --> 00:00:33,000 +program because you have to meet their laws. + +9 +00:00:33,000 --> 00:00:35,000 +While the board may dictate where we're going with this. + +10 +00:00:35,000 --> 00:00:39,000 +So let's go through these five basic entities here. + +11 +00:00:39,000 --> 00:00:40,000 +The first one that we want to mention is the board. + +12 +00:00:40,000 --> 00:00:47,000 +So when you're working in an organization, the top, top, top of the organization is the board of + +13 +00:00:47,000 --> 00:00:47,000 +directors. + +14 +00:00:47,000 --> 00:00:53,000 +The board of directors generally hires the CEO, who then hires almost all the staff underneath that, + +15 +00:00:53,000 --> 00:00:55,000 +underneath that person. + +16 +00:00:55,000 --> 00:00:56,000 +So board of directors are a similar. + +17 +00:00:56,000 --> 00:01:00,000 +Governance has the ultimate responsibility for cybersecurity governance. + +18 +00:01:00,000 --> 00:01:01,000 +Now you're probably saying. + +19 +00:01:02,000 --> 00:01:03,000 +Hmm. + +20 +00:01:04,000 --> 00:01:05,000 +They have the responsibility. + +21 +00:01:05,000 --> 00:01:06,000 +Yes. + +22 +00:01:06,000 --> 00:01:13,000 +I want you guys to remember, the senior management has the ultimate responsibility for security in + +23 +00:01:13,000 --> 00:01:14,000 +an organization. + +24 +00:01:14,000 --> 00:01:19,000 +You see, senior management sets the tone for security in the business. + +25 +00:01:19,000 --> 00:01:23,000 +When there are security breaches and security hacks, who takes the brunt of the blame? + +26 +00:01:23,000 --> 00:01:24,000 +Senior management. + +27 +00:01:24,000 --> 00:01:27,000 +And they don't get more senior than the board. + +28 +00:01:27,000 --> 00:01:33,000 +The board sets the tone at the top, establishes strategic priorities and ensure that cyber risks are + +29 +00:01:33,000 --> 00:01:35,000 +adequately covered in the overall organization. + +30 +00:01:35,000 --> 00:01:36,000 +Risk management. + +31 +00:01:36,000 --> 00:01:39,000 +I want you guys to remember something for your exam senior management. + +32 +00:01:40,000 --> 00:01:46,000 +Such as the board will support, will help to fund security activities. + +33 +00:01:46,000 --> 00:01:50,000 +They're going to support the creation of things like policies, but they don't actually do it. + +34 +00:01:50,000 --> 00:01:56,000 +If you ever see a question on your exam, such as senior management, editing policy, change in policies + +35 +00:01:56,000 --> 00:01:58,000 +or conduct an assessment, they don't do that. + +36 +00:01:58,000 --> 00:02:05,000 +The big job of the board or senior management is going to be to support the security governance program. + +37 +00:02:05,000 --> 00:02:10,000 +Remember something if they don't support it and the program is never implemented and the company's hacked, + +38 +00:02:10,000 --> 00:02:12,000 +they're going to take the brunt of that blame. + +39 +00:02:12,000 --> 00:02:16,000 +So remember who's ultimately responsible for security in a business exam. + +40 +00:02:16,000 --> 00:02:19,000 +Senior management. + +41 +00:02:19,000 --> 00:02:24,000 +Now within a business you're going to have different types of committees that are out there. + +42 +00:02:24,000 --> 00:02:31,000 +Cybersecurity committees often compromises of cross-functional members from various departments. + +43 +00:02:31,000 --> 00:02:32,000 +This include. + +44 +00:02:33,000 --> 00:02:38,000 +These may include cybersecurity steering committee A steering committee basically dictates the direction + +45 +00:02:39,000 --> 00:02:40,000 +of somebody's steering a car. + +46 +00:02:40,000 --> 00:02:44,000 +They're basically going to set the tone of where we want to go, what technology we should be using, + +47 +00:02:44,000 --> 00:02:49,000 +what actions or steps we should be taking to keep our system secure. + +48 +00:02:49,000 --> 00:02:50,000 +IT risk commuter. + +49 +00:02:50,000 --> 00:02:55,000 +Even Data Privacy Committee committees have one or more specialization and responsible for seeing the + +50 +00:02:55,000 --> 00:02:58,000 +implementation of things such as policies. + +51 +00:02:58,000 --> 00:03:03,000 +Keep in mind there's all going to be all kinds of different committees within the business, and committees + +52 +00:03:03,000 --> 00:03:05,000 +should never be made up of just one set of folks. + +53 +00:03:05,000 --> 00:03:11,000 +For example, the cybersecurity steering committee should just, you know, it shouldn't just be, uh, + +54 +00:03:11,000 --> 00:03:13,000 +IT security folks. + +55 +00:03:13,000 --> 00:03:16,000 +How would a cyber breach affect the accounting department? + +56 +00:03:16,000 --> 00:03:17,000 +Well, I don't know. + +57 +00:03:17,000 --> 00:03:18,000 +I don't work in accounting. + +58 +00:03:18,000 --> 00:03:21,000 +Maybe we should have an accounting person on this committee. + +59 +00:03:21,000 --> 00:03:22,000 +See what I mean? + +60 +00:03:22,000 --> 00:03:26,000 +You want to make sure your committee has a diverse set of folks? + +61 +00:03:26,000 --> 00:03:30,000 +Well, not not much to say here except government entities. + +62 +00:03:30,000 --> 00:03:35,000 +When you're developing any kind of security governance program, you better be prepared to deal with + +63 +00:03:35,000 --> 00:03:41,000 +a lot of government regulators, especially if you work in certain industries like the financial sector, + +64 +00:03:41,000 --> 00:03:43,000 +health care sector. + +65 +00:03:44,000 --> 00:03:49,000 +So government entities and regulatory bodies will play a critical role in your governance program, + +66 +00:03:49,000 --> 00:03:54,000 +because they're going to define all the legal and regulatory frameworks that you better follow or you + +67 +00:03:54,000 --> 00:03:55,000 +have to follow. + +68 +00:03:55,000 --> 00:03:56,000 +All right. + +69 +00:03:56,000 --> 00:03:59,000 +These entities set standards and regulations such as GDPR. + +70 +00:03:59,000 --> 00:04:05,000 +Now centralized governance versus decentralized governance. + +71 +00:04:05,000 --> 00:04:07,000 +This is going to be up to your business. + +72 +00:04:07,000 --> 00:04:11,000 +So a centralized not government I'm talking governance. + +73 +00:04:11,000 --> 00:04:18,000 +So governance in a centralized governance structures, cybersecurity policies and decision making are + +74 +00:04:18,000 --> 00:04:22,000 +consolidated with one central entity or generally group. + +75 +00:04:22,000 --> 00:04:28,000 +This is usually under under the leadership of the CIO or the CISO. + +76 +00:04:29,000 --> 00:04:35,000 +Now if the organization has a CIO underneath the CIO chief information officer, you might have a CISO + +77 +00:04:35,000 --> 00:04:37,000 +or the IT director. + +78 +00:04:37,000 --> 00:04:38,000 +It depends on how the company is. + +79 +00:04:38,000 --> 00:04:41,000 +Sometimes this is the, uh, work of the CIO. + +80 +00:04:41,000 --> 00:04:43,000 +Also, it depends how the company is structured. + +81 +00:04:43,000 --> 00:04:49,000 +Centralized governance is good because it allows for uniform, in other words, pretty standard policies + +82 +00:04:49,000 --> 00:04:56,000 +and enforcement across the business now versus a decentralized governance structure. + +83 +00:04:56,000 --> 00:05:00,000 +Cybersecurity governance are distributed to various departments or even units. + +84 +00:05:00,000 --> 00:05:06,000 +So every unit or department may have their own um, IT steering committee. + +85 +00:05:06,000 --> 00:05:10,000 +They may have their own way of managing security or governance programs. + +86 +00:05:11,000 --> 00:05:19,000 +Um, this makes it greater specialization and may even align more with those departments and their security + +87 +00:05:19,000 --> 00:05:19,000 +needs. + +88 +00:05:19,000 --> 00:05:25,000 +Because if you think about it, if you go back to a centralized governance program, it may not have + +89 +00:05:25,000 --> 00:05:31,000 +the flexibility and it may apply too much security to departments that just doesn't deal with things + +90 +00:05:31,000 --> 00:05:36,000 +that are super secure and needs a level of security that the financial department needs. + +91 +00:05:36,000 --> 00:05:41,000 +For example, a lot of things that the salespeople work on is generally public knowledge versus a almost + +92 +00:05:41,000 --> 00:05:47,000 +everything the research and development or the financial department does is very needs more security + +93 +00:05:47,000 --> 00:05:48,000 +or is more secret. + +94 +00:05:48,000 --> 00:05:55,000 +So maybe in a decentralized environment this may be better as every department can pretty much set their + +95 +00:05:55,000 --> 00:05:56,000 +own policies. + +96 +00:05:56,000 --> 00:05:58,000 +Now, there's no right or wrong way. + +97 +00:05:58,000 --> 00:06:04,000 +I'm not going to tell you guys that there is a good way, or there is a correct way of doing this that's + +98 +00:06:04,000 --> 00:06:06,000 +going to be dependent on your organization. + +99 +00:06:06,000 --> 00:06:13,000 +But just keep in mind that these different structures exist and they will influence the way you manage + +100 +00:06:13,000 --> 00:06:14,000 +your security governance. + diff --git a/20 - Security Governance and Privacy/004 Security Governance Roles OB 5.1_en.srt b/20 - Security Governance and Privacy/004 Security Governance Roles OB 5.1_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..b53b6a0165707eb647f22e942197a57b385e44a4 --- /dev/null +++ b/20 - Security Governance and Privacy/004 Security Governance Roles OB 5.1_en.srt @@ -0,0 +1,368 @@ +1 +00:00:00,000 --> 00:00:05,000 +When it comes to implementing a security governance program, there are a few roles that you want to + +2 +00:00:05,000 --> 00:00:10,000 +be familiar with to ensure that they are assigned to ensure a perfect or good implementation. + +3 +00:00:10,000 --> 00:00:16,000 +Now those two, there's two roles here that is mandatory, and depending on the laws and regulations + +4 +00:00:16,000 --> 00:00:18,000 +you follow, you may have the other two. + +5 +00:00:18,000 --> 00:00:24,000 +So the two roles that you should have in every single governance program is going to be owners and custodians + +6 +00:00:24,000 --> 00:00:25,000 +or stewards. + +7 +00:00:25,000 --> 00:00:29,000 +Now, depending on the laws and regulations you follow, like if you're following the general data protection, + +8 +00:00:29,000 --> 00:00:35,000 +which is GDPR and the European Union, you may have things that controllers and processors. + +9 +00:00:35,000 --> 00:00:37,000 +So let's go into these roles here. + +10 +00:00:37,000 --> 00:00:42,000 +The first one up I want to mention is going to be an owner data owner system owner is how you would + +11 +00:00:42,000 --> 00:00:43,000 +see this show up. + +12 +00:00:43,000 --> 00:00:46,000 +So what exactly is an owner. + +13 +00:00:46,000 --> 00:00:52,000 +Well owners are generally senior management or members of departmental heads who have overall accountability + +14 +00:00:52,000 --> 00:00:54,000 +for specific information assets. + +15 +00:00:54,000 --> 00:01:01,000 +They're responsible for ensuring that proper controls are in place to protect the data and making strategic + +16 +00:01:01,000 --> 00:01:02,000 +decisions. + +17 +00:01:02,000 --> 00:01:06,000 +Owners define the classification of the data and approve access control. + +18 +00:01:06,000 --> 00:01:08,000 +Let me give you guys a whole bunch of examples. + +19 +00:01:08,000 --> 00:01:10,000 +The data owners for example. + +20 +00:01:11,000 --> 00:01:14,000 +Is generally the people at the head of the department. + +21 +00:01:14,000 --> 00:01:16,000 +Data has to be broken down by department. + +22 +00:01:16,000 --> 00:01:19,000 +So let's say you work in a company and is the head of the accounting department. + +23 +00:01:19,000 --> 00:01:24,000 +The person who heads that accounting department is generally the data owner of the account in data. + +24 +00:01:24,000 --> 00:01:31,000 +That person is generally going to be responsible for determining who has access to the data and what + +25 +00:01:31,000 --> 00:01:32,000 +type of access they need. + +26 +00:01:32,000 --> 00:01:38,000 +For example, let's say the head of the accounting department is Mary, and Mary is the data owner. + +27 +00:01:38,000 --> 00:01:45,000 +For all the accounting data, Mary can dictate that Bob can only have access to this accounting data. + +28 +00:01:45,000 --> 00:01:48,000 +He can read to this and he can write to that. + +29 +00:01:48,000 --> 00:01:48,000 +He can't. + +30 +00:01:48,000 --> 00:01:50,000 +He can't read and he can't. + +31 +00:01:50,000 --> 00:01:53,000 +He doesn't have full control over any of the data. + +32 +00:01:53,000 --> 00:01:57,000 +Mary can also dictate that Peter can only read to this and nothing more. + +33 +00:01:57,000 --> 00:02:01,000 +So notice Mary is determining the access control. + +34 +00:02:01,000 --> 00:02:03,000 +Mary is determining who can access this data. + +35 +00:02:03,000 --> 00:02:09,000 +Mary can determine whether you know where in the level of data classification does this data rank. + +36 +00:02:09,000 --> 00:02:13,000 +Mary has to ensure that the proper controls are in place. + +37 +00:02:13,000 --> 00:02:15,000 +Mary should dictate things like when this. + +38 +00:02:15,000 --> 00:02:17,000 +When should this data be backed up? + +39 +00:02:17,000 --> 00:02:19,000 +What type of encryption does it need? + +40 +00:02:19,000 --> 00:02:24,000 +So the data owner sets a lot of parameters about the particular data. + +41 +00:02:24,000 --> 00:02:29,000 +The other famous firm that you may see on your exam is going to be what's known as a custodian. + +42 +00:02:29,000 --> 00:02:30,000 +That's us. + +43 +00:02:30,000 --> 00:02:32,000 +We are the tech folks. + +44 +00:02:32,000 --> 00:02:39,000 +Custodians are data stewards are responsible for the technical and protection of the data. + +45 +00:02:39,000 --> 00:02:45,000 +So technical management, the implement security measures, manage access control and ensure proper + +46 +00:02:45,000 --> 00:02:47,000 +operations of that system. + +47 +00:02:47,000 --> 00:02:51,000 +Now where are they going to get what type of measures. + +48 +00:02:51,000 --> 00:02:52,000 +Where are they going to get? + +49 +00:02:52,000 --> 00:02:54,000 +What type of access controller? + +50 +00:02:54,000 --> 00:02:55,000 +Who should have access. + +51 +00:02:55,000 --> 00:02:56,000 +Right. + +52 +00:02:56,000 --> 00:02:58,000 +We're going to where are they going to get that from the data owner. + +53 +00:02:58,000 --> 00:03:04,000 +The data owner is going to say, well, the data should be backed up every Monday, Wednesday and Friday + +54 +00:03:04,000 --> 00:03:05,000 +at seven in the night. + +55 +00:03:05,000 --> 00:03:07,000 +You know who's going to do the backup? + +56 +00:03:07,000 --> 00:03:08,000 +Not the owner. + +57 +00:03:08,000 --> 00:03:15,000 +This guy, the custodian, the steward is going to be the one that's doing the actual backup. + +58 +00:03:15,000 --> 00:03:20,000 +Custodians handle the day to day management of the data and ensuring the CIA here. + +59 +00:03:20,000 --> 00:03:27,000 +Now, if you're following things like GDPR, you're going to have additional terms such as controllers + +60 +00:03:27,000 --> 00:03:28,000 +and processors. + +61 +00:03:28,000 --> 00:03:36,000 +Now, in the context of data protection, regulations like GDPR, controllers are entities that determine + +62 +00:03:36,000 --> 00:03:39,000 +the purpose and means of processing personal data. + +63 +00:03:39,000 --> 00:03:43,000 +So they're going to determine, wait, why do we need this data? + +64 +00:03:43,000 --> 00:03:46,000 +They have to be able to justify this to regulators. + +65 +00:03:46,000 --> 00:03:49,000 +And how are we going to process people's private data. + +66 +00:03:49,000 --> 00:03:53,000 +They make decisions about the data processing activity and they have to make sure. + +67 +00:03:53,000 --> 00:03:59,000 +So the data processor is the person that's going to report to the regulators within those countries. + +68 +00:03:59,000 --> 00:04:06,000 +So they're going to have to ensure that the right security measures are implemented to ensure the data + +69 +00:04:06,000 --> 00:04:06,000 +is protected. + +70 +00:04:06,000 --> 00:04:13,000 +And they're generally the general point of contact or the primary point of contact for regulatory officers. + +71 +00:04:13,000 --> 00:04:19,000 +So, for example, if you follow things like GDPR, because you your company does business in the EU + +72 +00:04:20,000 --> 00:04:25,000 +or the European Union, you're going to have generally a person as assigned as the controller. + +73 +00:04:25,000 --> 00:04:28,000 +This controller is the one that is the bridge between. + +74 +00:04:29,000 --> 00:04:33,000 +The regulators, the GDPR law and the data that we're collecting in the IT department. + +75 +00:04:33,000 --> 00:04:37,000 +This person has to ensure that the data is collected for a reason. + +76 +00:04:37,000 --> 00:04:42,000 +The data is processed within the confines of the law, and they're going to ensure that when regulators + +77 +00:04:42,000 --> 00:04:45,000 +come, they're the one that they're going to be talking to. + +78 +00:04:46,000 --> 00:04:48,000 +Also related to this is going to be processors. + +79 +00:04:48,000 --> 00:04:53,000 +Processors are entities that process data on behalf of the controllers. + +80 +00:04:53,000 --> 00:05:00,000 +This could be things like third party service providers or internal departments that handles data. + +81 +00:05:00,000 --> 00:05:05,000 +They're responsible including processing data securely as the controllers instructions and ensure that + +82 +00:05:05,000 --> 00:05:06,000 +they comply with all laws. + +83 +00:05:06,000 --> 00:05:09,000 +So the controller is going to work with the processor. + +84 +00:05:09,000 --> 00:05:11,000 +Wait, whatever we're doing with the data, how are we analyzing the data? + +85 +00:05:11,000 --> 00:05:14,000 +Where is the data being analyzed that we're collecting. + +86 +00:05:14,000 --> 00:05:16,000 +That's what the processor is going to be doing, the analyzing the data. + +87 +00:05:16,000 --> 00:05:22,000 +But they better make sure they follow the laws that the controller had specified because the controller + +88 +00:05:22,000 --> 00:05:24,000 +reports back to the regulators. + +89 +00:05:25,000 --> 00:05:25,000 +Okay. + +90 +00:05:25,000 --> 00:05:32,000 +So, uh, just for quick roles that you're going to see appearing on your exam, make sure you know + +91 +00:05:32,000 --> 00:05:33,000 +what they are. + +92 +00:05:34,000 --> 00:05:38,000 +Um, because more than likely, you're probably going to get a few questions on this particular topic. + diff --git a/20 - Security Governance and Privacy/005 Compliance Reporting OB 5.4_en.srt b/20 - Security Governance and Privacy/005 Compliance Reporting OB 5.4_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..47e3aebd7c762de1a919caa92f2835353f8efa8f --- /dev/null +++ b/20 - Security Governance and Privacy/005 Compliance Reporting OB 5.4_en.srt @@ -0,0 +1,736 @@ +1 +00:00:00,000 --> 00:00:07,000 +When it comes to working in the world of technology, be prepared to deal with tons of different regulations. + +2 +00:00:07,000 --> 00:00:14,000 +Regulations are laws passed by government entities that we have to follow, and they dictate many of + +3 +00:00:14,000 --> 00:00:20,000 +the different aspects of it, such as how should we secure this phone to not lose private data? + +4 +00:00:20,000 --> 00:00:24,000 +How should we set up this firewall to ensure data is encrypted? + +5 +00:00:24,000 --> 00:00:29,000 +How should we configure the access points to ensure no unauthorized access and encryption of wireless + +6 +00:00:29,000 --> 00:00:30,000 +data? + +7 +00:00:30,000 --> 00:00:37,000 +These these kinds of regulations will affect many, many, if not all aspects of what we do in it. + +8 +00:00:37,000 --> 00:00:42,000 +Now, in this video, we're not going to go into the different laws that we have to follow, but we + +9 +00:00:42,000 --> 00:00:47,000 +want to talk about what's called compliance reporting and what happens if you're not in compliance to + +10 +00:00:47,000 --> 00:00:49,000 +the different regulations you have to follow. + +11 +00:00:49,000 --> 00:00:52,000 +Let's start out by talking about compliance reporting. + +12 +00:00:52,000 --> 00:00:53,000 +What exactly is this? + +13 +00:00:53,000 --> 00:01:00,000 +This is refers to the processes of documenting and convey an organization's adherence to various various + +14 +00:01:00,000 --> 00:01:03,000 +cybersecurity regulations, standards, and policies. + +15 +00:01:03,000 --> 00:01:07,000 +For example, maybe your organization deals with medical records. + +16 +00:01:07,000 --> 00:01:13,000 +Maybe you're a hospital or clinic, and you get a lot of folks medical records, such as their insurance + +17 +00:01:13,000 --> 00:01:17,000 +information, illnesses they may have or different medications they take. + +18 +00:01:18,000 --> 00:01:25,000 +You're going to follow what's known as HIPAA compliance, high HIPAA compliance. + +19 +00:01:25,000 --> 00:01:28,000 +That is a kind of regulation that you have to follow. + +20 +00:01:28,000 --> 00:01:33,000 +If you collect credit cards, for example, you're going to follow what's called PCI Compliance Payment + +21 +00:01:33,000 --> 00:01:38,000 +card industry, what's known as PCI, DSS Payment Card Industry Data Security Standard PCI. + +22 +00:01:38,000 --> 00:01:44,000 +If you collect credit cards, PCI compliance says that you have to follow a standard in order to ensure + +23 +00:01:44,000 --> 00:01:45,000 +that data is secure. + +24 +00:01:45,000 --> 00:01:51,000 +Now, when it comes to these kinds of compliance reporting, you're basically going to be doing two + +25 +00:01:51,000 --> 00:01:52,000 +kinds of reporting. + +26 +00:01:52,000 --> 00:01:56,000 +You're going to be reporting it internal reporting and external reporting. + +27 +00:01:56,000 --> 00:02:02,000 +So internal reporting involves generating reports for use within the organization. + +28 +00:02:02,000 --> 00:02:08,000 +Typically for folks like management internal audit teams or your IT security department. + +29 +00:02:08,000 --> 00:02:13,000 +Why would you, uh, report internal audits. + +30 +00:02:13,000 --> 00:02:14,000 +Right. + +31 +00:02:14,000 --> 00:02:17,000 +Why would you report internally to management? + +32 +00:02:17,000 --> 00:02:26,000 +Well, when you do a security assessment within the organization to see are we meeting a certain regulation? + +33 +00:02:26,000 --> 00:02:30,000 +What you're basically doing is you're doing what's known as self evaluation. + +34 +00:02:30,000 --> 00:02:36,000 +The organization basically does a self evaluation to see are we in compliance to HIPAA regulation. + +35 +00:02:36,000 --> 00:02:39,000 +Are we in compliance to the PCI standards. + +36 +00:02:40,000 --> 00:02:42,000 +And what they're looking for is areas for improvement. + +37 +00:02:42,000 --> 00:02:44,000 +So they identify areas for improvement. + +38 +00:02:44,000 --> 00:02:49,000 +They may say well we are 99% in compliance but we're missing this particular aspect. + +39 +00:02:49,000 --> 00:02:51,000 +So we need to now need to fix that. + +40 +00:02:51,000 --> 00:02:54,000 +This is internal compliance external compliance. + +41 +00:02:54,000 --> 00:03:00,000 +So you could imagine it's going to go outside outside entities regulatory bodies clients or third party + +42 +00:03:00,000 --> 00:03:01,000 +auditors. + +43 +00:03:01,000 --> 00:03:02,000 +Let me give you an example. + +44 +00:03:03,000 --> 00:03:09,000 +If you process tons of credit cards through your e-commerce website and you're using a bank, let's + +45 +00:03:09,000 --> 00:03:14,000 +say you're using Bank of America to process as your credit card processors. + +46 +00:03:14,000 --> 00:03:18,000 +Those are the people that's going to actually run the card for you. + +47 +00:03:18,000 --> 00:03:22,000 +Bank of America makes it mandatory that you follow PCI compliance. + +48 +00:03:22,000 --> 00:03:28,000 +So what happens is you're going to have to report to Bank of America, how are you staying with PCI. + +49 +00:03:28,000 --> 00:03:33,000 +So they're you're going to have to report to this third party entity of Bank of America. + +50 +00:03:33,000 --> 00:03:38,000 +So this type of report reporting demonstrates compliance with external security standards. + +51 +00:03:38,000 --> 00:03:41,000 +Uh, there's a bunch here, whether it's ISO standard. + +52 +00:03:41,000 --> 00:03:45,000 +Maybe you're following this to show how good of a security system you have. + +53 +00:03:45,000 --> 00:03:50,000 +Nice GDPR, HIPAA, GDPR is a European privacy law. + +54 +00:03:50,000 --> 00:03:54,000 +HIPAA is going to be an American medical records law. + +55 +00:03:55,000 --> 00:04:01,000 +Now external reporting might require specific might be required periodically or in response to a specific + +56 +00:04:01,000 --> 00:04:02,000 +compliance audit. + +57 +00:04:02,000 --> 00:04:04,000 +For example PCI compliance. + +58 +00:04:04,000 --> 00:04:12,000 +You may have to report PCI, um standard requirements or how you are in requirements sometimes on a + +59 +00:04:12,000 --> 00:04:14,000 +monthly, quarterly, or even yearly basis. + +60 +00:04:14,000 --> 00:04:17,000 +So remember what external it's for outside entities. + +61 +00:04:17,000 --> 00:04:24,000 +The other thing we want to talk about is what happens if you are not in compliance. + +62 +00:04:24,000 --> 00:04:25,000 +What is the consequences of compliance. + +63 +00:04:25,000 --> 00:04:26,000 +Let's go through this quickly. + +64 +00:04:26,000 --> 00:04:29,000 +Conformance of noncompliance. + +65 +00:04:29,000 --> 00:04:35,000 +It's going to be some kind of adverse effect that the organization would fail if you fail to meet certain + +66 +00:04:35,000 --> 00:04:37,000 +regulations or standards. + +67 +00:04:37,000 --> 00:04:41,000 +Let's go through some of them here that I have fine sanctions, all these different things here. + +68 +00:04:42,000 --> 00:04:43,000 +Let's go through some of them. + +69 +00:04:43,000 --> 00:04:44,000 +The first one is fine. + +70 +00:04:44,000 --> 00:04:48,000 +If you don't meet a certain compliance, be prepared to be fine. + +71 +00:04:48,000 --> 00:04:50,000 +This is a standard thing. + +72 +00:04:50,000 --> 00:04:57,000 +If you don't meet a certain, uh, regulations such as HIPAA regulation, if you don't meet certain + +73 +00:04:57,000 --> 00:04:59,000 +GDPR, especially GDPR. + +74 +00:05:00,000 --> 00:05:02,000 +Um, this is general data protection. + +75 +00:05:03,000 --> 00:05:05,000 +So this is going to be a European privacy law. + +76 +00:05:05,000 --> 00:05:07,000 +If you don't meet it, you're going to get fined. + +77 +00:05:07,000 --> 00:05:10,000 +The fines and penalty could be substantive. + +78 +00:05:10,000 --> 00:05:13,000 +It could really affect your organization. + +79 +00:05:13,000 --> 00:05:17,000 +So another reason why you want to get it is to make sure that you don't pay any hefty fees. + +80 +00:05:18,000 --> 00:05:20,000 +Another one here you have is going to be sanctions. + +81 +00:05:20,000 --> 00:05:24,000 +This is when not just formal penalties, but they could restrict you. + +82 +00:05:24,000 --> 00:05:29,000 +They may sanction your organization and restrict you from doing certain kinds of businesses. + +83 +00:05:29,000 --> 00:05:33,000 +They may restrict you for selling a certain product or doing business in a certain country. + +84 +00:05:33,000 --> 00:05:37,000 +So make sure once again you stay in compliance. + +85 +00:05:38,000 --> 00:05:43,000 +If you fall out of compliance, your reputation may take a hit. + +86 +00:05:44,000 --> 00:05:51,000 +Non-compliance can lead to significant reputation damages, the public disclosure of compliance failures, + +87 +00:05:51,000 --> 00:05:54,000 +especially those that compromises consumer data. + +88 +00:05:54,000 --> 00:06:01,000 +For example, let's say you didn't encrypt a customer's data when you should have, uh, the data was + +89 +00:06:01,000 --> 00:06:07,000 +stolen and it was all in clear text that leaks out or auditors release it. + +90 +00:06:07,000 --> 00:06:10,000 +That company A has lost the customer's data. + +91 +00:06:10,000 --> 00:06:15,000 +You better best believe your customers may not want to do business with you anymore because you lose + +92 +00:06:15,000 --> 00:06:19,000 +their data all the time, so your reputation will take a hit. + +93 +00:06:19,000 --> 00:06:20,000 +They're not going to trust you anymore. + +94 +00:06:20,000 --> 00:06:25,000 +Their confidence is going to decline, not just with your customers, but partners also. + +95 +00:06:25,000 --> 00:06:28,000 +So B be ready for that. + +96 +00:06:29,000 --> 00:06:35,000 +If you don't manage regulations and you work in a business that needs certain licenses, like in finance + +97 +00:06:35,000 --> 00:06:40,000 +or in health care, and you don't have and you don't meet certain compliance, you may lose the license + +98 +00:06:40,000 --> 00:06:42,000 +to continue working. + +99 +00:06:42,000 --> 00:06:46,000 +Some organizations, like we own medical schools in the state of New York. + +100 +00:06:46,000 --> 00:06:53,000 +Tia is the owner of big medical schools, and those medical schools require a license to stay open if + +101 +00:06:53,000 --> 00:06:59,000 +you don't meet certain regulations, whether it's safety regulations for our students or licensure regulations + +102 +00:06:59,000 --> 00:07:01,000 +for our instructors. + +103 +00:07:01,000 --> 00:07:04,000 +The school will lose its license and its ability to operate. + +104 +00:07:04,000 --> 00:07:09,000 +So if our license is revoked, we could be shut down. + +105 +00:07:10,000 --> 00:07:16,000 +Contractual impacts well, failure to comply with cybersecurity clauses and contracts could lead to + +106 +00:07:16,000 --> 00:07:17,000 +a contract breach. + +107 +00:07:17,000 --> 00:07:24,000 +This can lead to legal disputes, which means, uh, you and a vendor in court, you can even lose contracts. + +108 +00:07:25,000 --> 00:07:34,000 +Or the contract may have financial penalties associated with failure to meet certain kinds of regulations. + +109 +00:07:34,000 --> 00:07:40,000 +For example, let's say you're working with a vendor, and that vendor has to stay in PCI compliance + +110 +00:07:40,000 --> 00:07:41,000 +because they're processing your credit card. + +111 +00:07:41,000 --> 00:07:43,000 +They don't want managing your website. + +112 +00:07:43,000 --> 00:07:43,000 +Well. + +113 +00:07:43,000 --> 00:07:48,000 +If that vendor fails PCI compliance or fails to meet it, you might terminate the contract with them, + +114 +00:07:48,000 --> 00:07:50,000 +which would generally be a good idea. + +115 +00:07:51,000 --> 00:07:52,000 +This is especially significant. + +116 +00:07:52,000 --> 00:07:58,000 +B2B means business to business where, uh, cybersecurity compliance is mandatory. + +117 +00:07:58,000 --> 00:08:03,000 +Now you want to continuously monitor this compliance. + +118 +00:08:03,000 --> 00:08:05,000 +Monitoring is an ongoing thing. + +119 +00:08:06,000 --> 00:08:08,000 +I've said this before in security. + +120 +00:08:08,000 --> 00:08:14,000 +When it comes to security, what happens is basically what's happening today. + +121 +00:08:14,000 --> 00:08:16,000 +What's it's what's happening today is just today. + +122 +00:08:17,000 --> 00:08:18,000 +New things happen tomorrow. + +123 +00:08:18,000 --> 00:08:20,000 +New viruses comes out. + +124 +00:08:20,000 --> 00:08:27,000 +Tomorrow, new vulnerabilities are discovered tomorrow new hackers are coming on the market tomorrow. + +125 +00:08:27,000 --> 00:08:33,000 +Tonight there's some guy contemplating should I, should I, should I bring this system down. + +126 +00:08:33,000 --> 00:08:35,000 +Should I try this right now. + +127 +00:08:35,000 --> 00:08:37,000 +And he's probably going to say yes. + +128 +00:08:37,000 --> 00:08:39,000 +So the world changes all the time. + +129 +00:08:39,000 --> 00:08:40,000 +And the same thing with compliance. + +130 +00:08:40,000 --> 00:08:43,000 +You're in compliance today doesn't mean you're in compliance tomorrow. + +131 +00:08:43,000 --> 00:08:45,000 +So you have to continuously do this. + +132 +00:08:45,000 --> 00:08:51,000 +It's an ongoing process of ensuring that an organization consistently meet the needs. + +133 +00:08:51,000 --> 00:08:52,000 +If not. + +134 +00:08:53,000 --> 00:08:56,000 +You're going to, you're going to suffer some of the consequences. + +135 +00:08:56,000 --> 00:08:59,000 +Now due diligence and due care. + +136 +00:08:59,000 --> 00:09:07,000 +So due diligence in compliance monitoring is the effort of is involves a continuous effort to ensure + +137 +00:09:07,000 --> 00:09:13,000 +that all cybersecurity practices policies are in controls, are in line with the latest and regulatory + +138 +00:09:13,000 --> 00:09:15,000 +requirements for due care. + +139 +00:09:15,000 --> 00:09:21,000 +This is the ongoing management and upkeep of these practices, demonstrating that the organization is + +140 +00:09:21,000 --> 00:09:24,000 +actively maintaining its cybersecurity posture. + +141 +00:09:24,000 --> 00:09:26,000 +Now, let me give you a couple of examples. + +142 +00:09:26,000 --> 00:09:30,000 +When it comes to due diligence, due diligence is doing a lot of research. + +143 +00:09:30,000 --> 00:09:35,000 +It's seeing what are the different practices, what is the different policies, what is the different + +144 +00:09:35,000 --> 00:09:43,000 +regulations that we need to be involved in to be good in order to stay in compliance? + +145 +00:09:43,000 --> 00:09:47,000 +And then due care is actual following those things. + +146 +00:09:47,000 --> 00:09:48,000 +Are we following those things? + +147 +00:09:48,000 --> 00:09:52,000 +Are we showing that we're following those things? + +148 +00:09:53,000 --> 00:09:55,000 +Now a couple of words here. + +149 +00:09:56,000 --> 00:10:03,000 +Attestation could never get that word right involves formal verification confirming data organization + +150 +00:10:03,000 --> 00:10:04,000 +cybersecurity controls. + +151 +00:10:04,000 --> 00:10:13,000 +So at attestation is when the organization assesses that we follow these particular policies or we aren't + +152 +00:10:13,000 --> 00:10:18,000 +compliant to something in certain regulations, especially like in PCI compliance. + +153 +00:10:18,000 --> 00:10:22,000 +What happens is if you're really small, you don't process many credit cards. + +154 +00:10:22,000 --> 00:10:26,000 +You can the organization can just attest that they are without a formal audit. + +155 +00:10:28,000 --> 00:10:36,000 +An acknowledgement refers to the organization's recognition and acceptance of its cyber security responsibilities. + +156 +00:10:37,000 --> 00:10:41,000 +Now, how do we acknowledge that we are going to follow these things? + +157 +00:10:42,000 --> 00:10:44,000 +How do we acknowledge, okay, we are going to be held responsible for this? + +158 +00:10:44,000 --> 00:10:48,000 +Well, that's going to be the different policies that you follow in your business. + +159 +00:10:48,000 --> 00:10:53,000 +Now internal and external monitoring. + +160 +00:10:53,000 --> 00:10:58,000 +So internal monitoring is activities conducted within the business to ensure compliance. + +161 +00:10:58,000 --> 00:11:03,000 +This is when you're going to do internal audits regular audits reviews and assessments. + +162 +00:11:03,000 --> 00:11:07,000 +External monitoring is generally done by an external parties. + +163 +00:11:07,000 --> 00:11:11,000 +This is going to be external auditors or external compliance folks. + +164 +00:11:11,000 --> 00:11:13,000 +You are going to be monitored by both. + +165 +00:11:13,000 --> 00:11:16,000 +You're going to be doing internal monitoring. + +166 +00:11:16,000 --> 00:11:19,000 +The internal monitoring is going to lead to internal reporting. + +167 +00:11:19,000 --> 00:11:22,000 +External monitoring could lead to external reporting. + +168 +00:11:24,000 --> 00:11:28,000 +When it comes to compliance, one of the best things we can do is automation. + +169 +00:11:28,000 --> 00:11:34,000 +Automation and compliance is the use of different kinds of software, tools and technology to continuously + +170 +00:11:34,000 --> 00:11:35,000 +monitor compliance. + +171 +00:11:35,000 --> 00:11:43,000 +Remember, compliance may stay the same, that rule may stay the same, but your environment doesn't + +172 +00:11:43,000 --> 00:11:44,000 +stay the same. + +173 +00:11:44,000 --> 00:11:49,000 +And if there's changes in the environment, new malware and new hackers, new vulnerabilities, and + +174 +00:11:49,000 --> 00:11:51,000 +so on, how do you check it on? + +175 +00:11:51,000 --> 00:11:56,000 +You can't say if you have automated systems like a CRM system or a SIM system. + +176 +00:11:56,000 --> 00:12:02,000 +These types of systems like Splunk, which we covered already, remember Siem systems, security information, + +177 +00:12:02,000 --> 00:12:07,000 +event management, these are systems that is consistently checking all your log files to see if you + +178 +00:12:07,000 --> 00:12:11,000 +are out of compliance or if there's something wrong within the organization. + +179 +00:12:11,000 --> 00:12:14,000 +This is going to be an automated system to do that because you can't do it all. + +180 +00:12:15,000 --> 00:12:18,000 +The contract changes in regulatory requirements. + +181 +00:12:18,000 --> 00:12:21,000 +Monitor security in real time and give you good alerts. + +182 +00:12:21,000 --> 00:12:26,000 +Okay, so keep in mind, guys, when it comes to compliance, if we are out of compliance, there's + +183 +00:12:26,000 --> 00:12:31,000 +tons of consequences that can happen, whether it's fines or basically losing your business. + +184 +00:12:31,000 --> 00:12:35,000 +So if those are some of the consequences, make sure your organization stays in compliance. +