diff --git a/.gitattributes b/.gitattributes
index 8272af31b311785108f0a0d047f4ca74fb3d1e6a..4cf99daff613be2e80703175abf0bd9c6c09859f 100644
--- a/.gitattributes
+++ b/.gitattributes
@@ -96,3 +96,40 @@ saved_model/**/* filter=lfs diff=lfs merge=lfs -text
06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/011[[:space:]]DDOS[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text
06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/014[[:space:]]Credential[[:space:]]Replay[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text
06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/015[[:space:]]Privilege[[:space:]]Escalation[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text
+06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/016[[:space:]]Request[[:space:]]Forgery[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text
+06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/017[[:space:]]Directory[[:space:]]Traversal[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text
+06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/018[[:space:]]Indicators[[:space:]]of[[:space:]]Malicious[[:space:]]Activity[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text
+07[[:space:]]-[[:space:]]Cryptography/002[[:space:]]Crypto[[:space:]]Terms[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
+07[[:space:]]-[[:space:]]Cryptography/001[[:space:]]Intro[[:space:]]to[[:space:]]cryptography[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
+07[[:space:]]-[[:space:]]Cryptography/003[[:space:]]Goals[[:space:]]Cryptography[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
+07[[:space:]]-[[:space:]]Cryptography/005[[:space:]]Ciphers[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
+07[[:space:]]-[[:space:]]Cryptography/006[[:space:]]Symmetric[[:space:]]Encryption[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
+07[[:space:]]-[[:space:]]Cryptography/007[[:space:]]Symmetric[[:space:]]Algorithms[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
+07[[:space:]]-[[:space:]]Cryptography/004[[:space:]]Algorithm[[:space:]]vs[[:space:]]Keys[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
+07[[:space:]]-[[:space:]]Cryptography/009[[:space:]]Asymmetric[[:space:]]Algorithms[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
+07[[:space:]]-[[:space:]]Cryptography/008[[:space:]]Asymmetric[[:space:]]Encryption[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
+07[[:space:]]-[[:space:]]Cryptography/010[[:space:]]Hybrid[[:space:]]Cryptography[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
+07[[:space:]]-[[:space:]]Cryptography/012[[:space:]]Hashing[[:space:]]Algorithms[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
+07[[:space:]]-[[:space:]]Cryptography/013[[:space:]]Digital[[:space:]]Signatures[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
+07[[:space:]]-[[:space:]]Cryptography/014[[:space:]]Intro[[:space:]]to[[:space:]]PKI[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
+07[[:space:]]-[[:space:]]Cryptography/011[[:space:]]Hashing[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
+07[[:space:]]-[[:space:]]Cryptography/015[[:space:]]PKI[[:space:]]Purpose[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
+07[[:space:]]-[[:space:]]Cryptography/016[[:space:]]SSLTLS[[:space:]]Handshake[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
+07[[:space:]]-[[:space:]]Cryptography/017[[:space:]]PKI[[:space:]]Process[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
+07[[:space:]]-[[:space:]]Cryptography/018[[:space:]]Certificates[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
+07[[:space:]]-[[:space:]]Cryptography/019[[:space:]]PKI[[:space:]]Root[[:space:]]of[[:space:]]Trust[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
+07[[:space:]]-[[:space:]]Cryptography/020[[:space:]]PKI[[:space:]]Verification[[:space:]]and[[:space:]]Revocation[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
+07[[:space:]]-[[:space:]]Cryptography/022[[:space:]]Blockchain[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
+07[[:space:]]-[[:space:]]Cryptography/021[[:space:]]Steganography[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
+07[[:space:]]-[[:space:]]Cryptography/023[[:space:]]Salting[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
+07[[:space:]]-[[:space:]]Cryptography/024[[:space:]]TPM[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
+07[[:space:]]-[[:space:]]Cryptography/025[[:space:]]Secure[[:space:]]Enclave[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
+07[[:space:]]-[[:space:]]Cryptography/026[[:space:]]Obfuscation[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
+07[[:space:]]-[[:space:]]Cryptography/027[[:space:]]Tokenization[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
+07[[:space:]]-[[:space:]]Cryptography/028[[:space:]]Key[[:space:]]Escrow[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
+08[[:space:]]-[[:space:]]Social[[:space:]]Engineering/001[[:space:]]Social[[:space:]]Engineering[[:space:]]OB[[:space:]]2.2.mp4 filter=lfs diff=lfs merge=lfs -text
+07[[:space:]]-[[:space:]]Cryptography/029[[:space:]]HSM[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
+08[[:space:]]-[[:space:]]Social[[:space:]]Engineering/004[[:space:]]Smishing[[:space:]]OB[[:space:]]2.2.mp4 filter=lfs diff=lfs merge=lfs -text
+08[[:space:]]-[[:space:]]Social[[:space:]]Engineering/003[[:space:]]Vishing[[:space:]]OB[[:space:]]2.2.mp4 filter=lfs diff=lfs merge=lfs -text
+08[[:space:]]-[[:space:]]Social[[:space:]]Engineering/002[[:space:]]Phishing[[:space:]]OB[[:space:]]2.2.mp4 filter=lfs diff=lfs merge=lfs -text
+08[[:space:]]-[[:space:]]Social[[:space:]]Engineering/006[[:space:]]Misinformation[[:space:]]and[[:space:]]Disinformation[[:space:]]OB[[:space:]]2.2.mp4 filter=lfs diff=lfs merge=lfs -text
diff --git a/06 - Signs of Attacks/016 Request Forgery OB 2.4.mp4 b/06 - Signs of Attacks/016 Request Forgery OB 2.4.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..6bc883fa67ccd74b2103a94f84fe23707c0d0e3d
--- /dev/null
+++ b/06 - Signs of Attacks/016 Request Forgery OB 2.4.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:7fb67cb33e669a0cd4db9d175ab0af64cf6e2f395928443fba926e046fc6628e
+size 252434757
diff --git a/06 - Signs of Attacks/017 Directory Traversal OB 2.4.mp4 b/06 - Signs of Attacks/017 Directory Traversal OB 2.4.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..73d2fe3d7425557296fe28f57864096cb008982a
--- /dev/null
+++ b/06 - Signs of Attacks/017 Directory Traversal OB 2.4.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:e1744255f84e98cd7a85e260f4fc4c456a930a8571773c1fd4b050aab4b2b0a7
+size 55519440
diff --git a/06 - Signs of Attacks/018 Indicators of Malicious Activity OB 2.4.mp4 b/06 - Signs of Attacks/018 Indicators of Malicious Activity OB 2.4.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..4ebbd5da6cd81232538390718b857ea1badff160
--- /dev/null
+++ b/06 - Signs of Attacks/018 Indicators of Malicious Activity OB 2.4.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:a06d972cbc8ff0a0f5b8a0649fdaa9420454c21fc6ca8bc85c96236a062be796
+size 165107189
diff --git a/07 - Cryptography/001 Intro to cryptography OB 1.4.mp4 b/07 - Cryptography/001 Intro to cryptography OB 1.4.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..84f5c7c07f2298234b47ea845ec2c6c80d92b3cd
--- /dev/null
+++ b/07 - Cryptography/001 Intro to cryptography OB 1.4.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:f410dce7cb4466cf86b270c58220847a1b2f51ea6d5c26c8cbdff507a7b0146d
+size 96326919
diff --git a/07 - Cryptography/002 Crypto Terms OB 1.4.mp4 b/07 - Cryptography/002 Crypto Terms OB 1.4.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..9b7995f85f0a6a1773d2149e616e382489566c05
--- /dev/null
+++ b/07 - Cryptography/002 Crypto Terms OB 1.4.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:4cc3556f416a37507fb252d2fcb7a996064cef75b2e419837b7599182af66fa7
+size 61060517
diff --git a/07 - Cryptography/003 Goals Cryptography OB 1.4.mp4 b/07 - Cryptography/003 Goals Cryptography OB 1.4.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..23bd9405737a2dd111daed928189152b29378764
--- /dev/null
+++ b/07 - Cryptography/003 Goals Cryptography OB 1.4.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:9d6ea104492a374d07c1016b6b3503ab89fc91d8adebba0c830495dd01b8c89f
+size 158674618
diff --git a/07 - Cryptography/004 Algorithm vs Keys OB 1.4.mp4 b/07 - Cryptography/004 Algorithm vs Keys OB 1.4.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..71d7b2fa99ecc00b14be2922bdfec808f1639cfc
--- /dev/null
+++ b/07 - Cryptography/004 Algorithm vs Keys OB 1.4.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:bd0304e7831242c9f3d707d88bf9856f97d6277b74d575b9f8a96aaf40b98c15
+size 904992896
diff --git a/07 - Cryptography/005 Ciphers OB 1.4.mp4 b/07 - Cryptography/005 Ciphers OB 1.4.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..d7293a4c6858390d6ac9c3c76ac3e872d964aaf2
--- /dev/null
+++ b/07 - Cryptography/005 Ciphers OB 1.4.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:44c1f607cb008792070ba7bc251a782124aa6b4674fd3ad4923b099c04b6bee7
+size 70642872
diff --git a/07 - Cryptography/006 Symmetric Encryption OB 1.4.mp4 b/07 - Cryptography/006 Symmetric Encryption OB 1.4.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..0a333fe7207f85a91a6d90054dbf7329ef1e1fc3
--- /dev/null
+++ b/07 - Cryptography/006 Symmetric Encryption OB 1.4.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:906c0006508ac8feebd61b1a0a4236cb2a073add324119275f6653f3819e6ce3
+size 301229092
diff --git a/07 - Cryptography/007 Symmetric Algorithms OB 1.4.mp4 b/07 - Cryptography/007 Symmetric Algorithms OB 1.4.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..21a61a72dfe9fd6f6af0f449ed600e8d206759fe
--- /dev/null
+++ b/07 - Cryptography/007 Symmetric Algorithms OB 1.4.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:6e3357e07a707570a5d682d8711ce37c3257871f01c1cd9f57259d102c765260
+size 208197734
diff --git a/07 - Cryptography/008 Asymmetric Encryption OB 1.4.mp4 b/07 - Cryptography/008 Asymmetric Encryption OB 1.4.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..7ccb1a2b7c8ab75630d0da85f832414f4c37659c
--- /dev/null
+++ b/07 - Cryptography/008 Asymmetric Encryption OB 1.4.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:d30021a868903bbb6ab27a33c128faaa343205a4698dda444d1cff8cdc4899ec
+size 262306688
diff --git a/07 - Cryptography/009 Asymmetric Algorithms OB 1.4.mp4 b/07 - Cryptography/009 Asymmetric Algorithms OB 1.4.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..e16683a95acbd55791a6bec428889a221dade8a9
--- /dev/null
+++ b/07 - Cryptography/009 Asymmetric Algorithms OB 1.4.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:bc4dbc91ef6e892dab0aeef519323e3958ec5cf1ce1db38b429d073da21e96d2
+size 99626564
diff --git a/07 - Cryptography/010 Hybrid Cryptography OB 1.4.mp4 b/07 - Cryptography/010 Hybrid Cryptography OB 1.4.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..174f7ec50ea6126c895c07f478266a0e13358fac
--- /dev/null
+++ b/07 - Cryptography/010 Hybrid Cryptography OB 1.4.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:b4c0b7ee7d7b0df27553d841c16df9d203d01d47527a33c0ddadd96219b95743
+size 157908953
diff --git a/07 - Cryptography/011 Hashing OB 1.4.mp4 b/07 - Cryptography/011 Hashing OB 1.4.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..bdfef8f2f2fee27ab0099e5c33e5b5ab392448f5
--- /dev/null
+++ b/07 - Cryptography/011 Hashing OB 1.4.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:849824f981dde0483565115c45f8a19348912f37864040c2b47282373b86a777
+size 628967987
diff --git a/07 - Cryptography/012 Hashing Algorithms OB 1.4.mp4 b/07 - Cryptography/012 Hashing Algorithms OB 1.4.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..584140d50d0bf34f9b6c9f27fb4175d7b9d217e3
--- /dev/null
+++ b/07 - Cryptography/012 Hashing Algorithms OB 1.4.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:690cf391d2d7106d916db9e072c2fe74c170e259fc4bfa27a8008d18dec5e460
+size 80731663
diff --git a/07 - Cryptography/013 Digital Signatures OB 1.4.mp4 b/07 - Cryptography/013 Digital Signatures OB 1.4.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..daa26ea153f1dfd36b3f130f2185c2df18ce4c2b
--- /dev/null
+++ b/07 - Cryptography/013 Digital Signatures OB 1.4.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:7dd7fb58914ad32f6f6037638e36e90d4e8c5e4870af7330d6862ec5ebe11888
+size 181001409
diff --git a/07 - Cryptography/014 Intro to PKI OB 1.4.mp4 b/07 - Cryptography/014 Intro to PKI OB 1.4.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..b16f59e3a06f23e004b144467b773b27de1d8bf3
--- /dev/null
+++ b/07 - Cryptography/014 Intro to PKI OB 1.4.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:4f8ac279e3d05da47bb0b7ead6b020e9b23a7ff9145d497f2c3680f7fbc8974d
+size 46048784
diff --git a/07 - Cryptography/015 PKI Purpose OB 1.4.mp4 b/07 - Cryptography/015 PKI Purpose OB 1.4.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..e31b6b11e16c5ce0445daf2b36728f4b60a22f22
--- /dev/null
+++ b/07 - Cryptography/015 PKI Purpose OB 1.4.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:b6a8128beb36e602748800e10f620fac19457721cfec27ba8a1208a8e8ea12c7
+size 133257759
diff --git a/07 - Cryptography/016 SSLTLS Handshake OB 1.4.mp4 b/07 - Cryptography/016 SSLTLS Handshake OB 1.4.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..80b7145b5d72a6bbca9f8ea741944b53fd6aa06b
--- /dev/null
+++ b/07 - Cryptography/016 SSLTLS Handshake OB 1.4.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:62b288a9b3d91f94aa4c663902299a0b3ca0c5e205f4f4c20e900c47806db25c
+size 322894899
diff --git a/07 - Cryptography/017 PKI Process OB 1.4.mp4 b/07 - Cryptography/017 PKI Process OB 1.4.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..88428e48ad93ba4e57a1de42126ed40c611d04f2
--- /dev/null
+++ b/07 - Cryptography/017 PKI Process OB 1.4.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:2df30749129881a7cdb3eab017a1014418a5a912554e22b8eb690cf4509aa84a
+size 227238978
diff --git a/07 - Cryptography/018 Certificates OB 1.4.mp4 b/07 - Cryptography/018 Certificates OB 1.4.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..9fa513c5ad20466fa9f3172e94a3b4493577f70e
--- /dev/null
+++ b/07 - Cryptography/018 Certificates OB 1.4.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:289b439dc3db3773da97e6e921bc16082cc4444a987c3656c4a1d5b857b828c0
+size 256419507
diff --git a/07 - Cryptography/019 PKI Root of Trust OB 1.4.mp4 b/07 - Cryptography/019 PKI Root of Trust OB 1.4.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..8d49ecb60dbefd707ae17d29d1550294d94b6a6d
--- /dev/null
+++ b/07 - Cryptography/019 PKI Root of Trust OB 1.4.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:52767a81cd65b574262fbbd167b541891ab823e4ac5db0e29ed817cbda7e6dc4
+size 81385638
diff --git a/07 - Cryptography/020 PKI Verification and Revocation OB 1.4.mp4 b/07 - Cryptography/020 PKI Verification and Revocation OB 1.4.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..f5d588bc36c2989eb849cb1588952c7bdde0dcf1
--- /dev/null
+++ b/07 - Cryptography/020 PKI Verification and Revocation OB 1.4.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:209b9a6ce812392bc253484a273d19429e764f0bcdcd28708ea3e58839128724
+size 119243591
diff --git a/07 - Cryptography/021 Steganography OB 1.4.mp4 b/07 - Cryptography/021 Steganography OB 1.4.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..ca2c1619e074b474c81e618454aab0d8a3c73f8d
--- /dev/null
+++ b/07 - Cryptography/021 Steganography OB 1.4.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:5d9c971a71471963a520a76520af39e504725a61525bc23c8f5d6709490ba1c8
+size 123486561
diff --git a/07 - Cryptography/022 Blockchain OB 1.4.mp4 b/07 - Cryptography/022 Blockchain OB 1.4.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..49af1c5d0719105e6c9cc244bc524c1f07763c02
--- /dev/null
+++ b/07 - Cryptography/022 Blockchain OB 1.4.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:ed31645711f61269c6b6fa2247c7449246b79aaafce6519c607363918480a821
+size 166936677
diff --git a/07 - Cryptography/023 Salting OB 1.4.mp4 b/07 - Cryptography/023 Salting OB 1.4.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..42978eac196d129ed2889b9107f679e2e1f77ff5
--- /dev/null
+++ b/07 - Cryptography/023 Salting OB 1.4.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:292386772cd6a1688e30efb201a3988ca58d06e896327cfd71fdaae5ffac4877
+size 106670783
diff --git a/07 - Cryptography/024 TPM OB 1.4.mp4 b/07 - Cryptography/024 TPM OB 1.4.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..00cc5442b594deb729babc59e1557d4aac84f2d4
--- /dev/null
+++ b/07 - Cryptography/024 TPM OB 1.4.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:f74bc83f1e5177358d6e3e3e86d1f672f862d0020c9acbd846a82f86fcf17699
+size 211209531
diff --git a/07 - Cryptography/025 Secure Enclave OB 1.4.mp4 b/07 - Cryptography/025 Secure Enclave OB 1.4.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..5e347e22a9f90befce210c8ff67b7d72f62284a8
--- /dev/null
+++ b/07 - Cryptography/025 Secure Enclave OB 1.4.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:ce54c6de590a73b2aef9782418559b1a6786fdce05d43f42062ebfc39a900367
+size 48690063
diff --git a/07 - Cryptography/026 Obfuscation OB 1.4.mp4 b/07 - Cryptography/026 Obfuscation OB 1.4.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..e7dcb7d16bfb783f39adc4e20c0350bd0a07dd9c
--- /dev/null
+++ b/07 - Cryptography/026 Obfuscation OB 1.4.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:7ba3668198ef774869f0fbe4319f1ea976482d18207dda79987d4378752c580c
+size 73746741
diff --git a/07 - Cryptography/027 Tokenization OB 1.4.mp4 b/07 - Cryptography/027 Tokenization OB 1.4.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..d2ce2f1b55582e64ee2fabf78b2a4e02402db56b
--- /dev/null
+++ b/07 - Cryptography/027 Tokenization OB 1.4.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:2277841e3deee35b12cc4fccfb98aff9375d8702e7f442aa74490a2d740ecefd
+size 130278517
diff --git a/07 - Cryptography/028 Key Escrow OB 1.4.mp4 b/07 - Cryptography/028 Key Escrow OB 1.4.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..183214c80f92a13504135813d222239fd688b449
--- /dev/null
+++ b/07 - Cryptography/028 Key Escrow OB 1.4.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:5c6271142b89e04576eed08ad160813cefe56719b9af87f786a9510fa7caadea
+size 51540744
diff --git a/07 - Cryptography/029 HSM OB 1.4.mp4 b/07 - Cryptography/029 HSM OB 1.4.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..458a808324c7fadf66223451feadcd34cdcd88da
--- /dev/null
+++ b/07 - Cryptography/029 HSM OB 1.4.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:99202e513878337137a489c03b2c879e67c59e0db229c0c1c1e1742a2252f81f
+size 144313020
diff --git a/08 - Social Engineering/001 Social Engineering OB 2.2.mp4 b/08 - Social Engineering/001 Social Engineering OB 2.2.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..2cdbc16ab4e4d540b055b5bd02107a5ee1b82fba
--- /dev/null
+++ b/08 - Social Engineering/001 Social Engineering OB 2.2.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:1b587c47573275e81970968d5e20e90df0fd2e7d8f98c6ec6f7bf5dbb34e378c
+size 66534314
diff --git a/08 - Social Engineering/002 Phishing OB 2.2.mp4 b/08 - Social Engineering/002 Phishing OB 2.2.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..b2243c9cefd0308f773a91019672513e84786958
--- /dev/null
+++ b/08 - Social Engineering/002 Phishing OB 2.2.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:32a70e3ca9956d8b8f75af1d0b550e43d275be845e0c144849a5775c60845682
+size 215560454
diff --git a/08 - Social Engineering/003 Vishing OB 2.2.mp4 b/08 - Social Engineering/003 Vishing OB 2.2.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..80805336a2369e0eac97664d1ad9a9bf2519b991
--- /dev/null
+++ b/08 - Social Engineering/003 Vishing OB 2.2.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:dcf480e016947a06fea15c3193380cb7c1833950a49957f0e8f5fb76222acc85
+size 165005146
diff --git a/08 - Social Engineering/004 Smishing OB 2.2.mp4 b/08 - Social Engineering/004 Smishing OB 2.2.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..0ad242020291489d83ab02953ed6d75f34ab1d69
--- /dev/null
+++ b/08 - Social Engineering/004 Smishing OB 2.2.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:b55d80c0072c02bf3e4d2532d021c9d07fb581e5601030ab9ff18e69663d5649
+size 57310806
diff --git a/08 - Social Engineering/006 Misinformation and Disinformation OB 2.2.mp4 b/08 - Social Engineering/006 Misinformation and Disinformation OB 2.2.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..5cf0878e74138f7e046654c3a817d191ee7b23f6
--- /dev/null
+++ b/08 - Social Engineering/006 Misinformation and Disinformation OB 2.2.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:d4a538f128b09d0177e2f5a358dd49a0d2bd111550e618bb33ddd367785f342b
+size 165923487
diff --git a/11 - Security Principles/010 IDSIPS OB 3.2_en.srt b/11 - Security Principles/010 IDSIPS OB 3.2_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..49111dd8e44ef4ce0756eb6b74cc09054618780f
--- /dev/null
+++ b/11 - Security Principles/010 IDSIPS OB 3.2_en.srt
@@ -0,0 +1,912 @@
+1
+00:00:00,000 --> 00:00:06,000
+One of the most common network, software and or device that you should have set up in your network
+
+2
+00:00:06,000 --> 00:00:14,000
+today is an IDs, Intrusion Detection Systems, or IPS intrusion prevention systems, and the simple
+
+3
+00:00:14,000 --> 00:00:21,000
+reason is that there is no way you can go around to every machine and check if an intrusion is coming
+
+4
+00:00:21,000 --> 00:00:23,000
+from one of those machines.
+
+5
+00:00:23,000 --> 00:00:27,000
+And the other reason is because the best one is actually free.
+
+6
+00:00:27,000 --> 00:00:32,000
+You see, I want to talk in this, in this particular one, in this particular video, that's going
+
+7
+00:00:32,000 --> 00:00:33,000
+to be pretty long.
+
+8
+00:00:33,000 --> 00:00:35,000
+By the way, a lot of slides is going to cover here.
+
+9
+00:00:35,000 --> 00:00:41,000
+In this particular video, we want to go through all the things we need to know about IDs and IPS for
+
+10
+00:00:41,000 --> 00:00:45,000
+our exam and why you need to have one of these in your network if you don't.
+
+11
+00:00:45,000 --> 00:00:48,000
+By the way, the free one I'm talking about is snort.
+
+12
+00:00:48,000 --> 00:00:50,000
+Snort is is maintained by Cisco.
+
+13
+00:00:50,000 --> 00:00:58,000
+It is the best, in Andrew's opinion IDs out there and it is 100% free maintained by Cisco.
+
+14
+00:00:58,000 --> 00:01:01,000
+Let's get started with what exactly is it?
+
+15
+00:01:01,000 --> 00:01:03,000
+I want to give you a scenario before I get started.
+
+16
+00:01:05,000 --> 00:01:09,000
+Imagine you have a network with 500 computers.
+
+17
+00:01:09,000 --> 00:01:15,000
+All of a sudden people starts calling the help desk and they say, oh, there's tons of network traffic.
+
+18
+00:01:15,000 --> 00:01:16,000
+The network is too slow.
+
+19
+00:01:16,000 --> 00:01:18,000
+No one can get to the internet.
+
+20
+00:01:18,000 --> 00:01:20,000
+File services are not loaded.
+
+21
+00:01:20,000 --> 00:01:24,000
+Well, there is some kind of thing going on in this network.
+
+22
+00:01:24,000 --> 00:01:26,000
+Somebody is using up all the traffic.
+
+23
+00:01:26,000 --> 00:01:29,000
+Maybe there's a worm spreading from machine to machine.
+
+24
+00:01:29,000 --> 00:01:33,000
+Maybe somebody has a virus that's downloading and utilizing all the bandwidth.
+
+25
+00:01:34,000 --> 00:01:35,000
+You got two choices.
+
+26
+00:01:35,000 --> 00:01:44,000
+You can decide to do nothing, or you can go to every single one of the machines and attempt to to to
+
+27
+00:01:44,000 --> 00:01:46,000
+find which one of them is broken.
+
+28
+00:01:46,000 --> 00:01:48,000
+This is a nightmare scenario.
+
+29
+00:01:48,000 --> 00:01:55,000
+This is a scenario that I had faced at Tia many, many years ago because I was an idiot and didn't have
+
+30
+00:01:55,000 --> 00:01:55,000
+one.
+
+31
+00:01:56,000 --> 00:01:59,000
+Now we do and we have them in every one of our locations.
+
+32
+00:01:59,000 --> 00:02:01,000
+We have IDs snorting in particular set up.
+
+33
+00:02:01,000 --> 00:02:07,000
+So if there is some kind of intrusion, especially like worm or viruses or malware on the student machines,
+
+34
+00:02:07,000 --> 00:02:09,000
+we could say, okay, it's that machine and that lab, let's go fix it.
+
+35
+00:02:10,000 --> 00:02:17,000
+IDs are able to suck up the network traffic on your network, analyze the traffic and say, that computer
+
+36
+00:02:17,000 --> 00:02:19,000
+over there, that one is bad.
+
+37
+00:02:19,000 --> 00:02:25,000
+That's why you need to have these particular things now when it comes to this.
+
+38
+00:02:25,000 --> 00:02:32,000
+It's basically a technology for real time monitoring and analysis of network activity and data for potential
+
+39
+00:02:32,000 --> 00:02:32,000
+intrusions.
+
+40
+00:02:33,000 --> 00:02:34,000
+Now, what is it going to do?
+
+41
+00:02:34,000 --> 00:02:39,000
+Well, it's going to monitor and analyze user and systems activities to see what's happening on it.
+
+42
+00:02:39,000 --> 00:02:41,000
+It's going to audit our systems and configuration.
+
+43
+00:02:41,000 --> 00:02:43,000
+If there's any vulnerabilities, it'll let you know.
+
+44
+00:02:43,000 --> 00:02:48,000
+It looks at the integrity of critical systems and any kind of data files.
+
+45
+00:02:48,000 --> 00:02:51,000
+It's going to recognize different patterns.
+
+46
+00:02:51,000 --> 00:02:55,000
+And maybe if there is any kind of abnormal activities out there.
+
+47
+00:02:56,000 --> 00:03:02,000
+Now in this video we want to talk, not just okay, this is what an IDs does, but I want to talk.
+
+48
+00:03:02,000 --> 00:03:05,000
+Exactly how does it is it a passive active.
+
+49
+00:03:06,000 --> 00:03:07,000
+Is it a behavioral based.
+
+50
+00:03:07,000 --> 00:03:10,000
+Is it a signature based IDs.
+
+51
+00:03:10,000 --> 00:03:12,000
+Um, is it an IDs or an IDs?
+
+52
+00:03:12,000 --> 00:03:14,000
+These are all terms that you can need to know for your exam.
+
+53
+00:03:14,000 --> 00:03:16,000
+So let's knock them out okay.
+
+54
+00:03:16,000 --> 00:03:23,000
+The first thing I want to talk about is how does an IDs know that this traffic is good or this traffic
+
+55
+00:03:23,000 --> 00:03:24,000
+is bad.
+
+56
+00:03:24,000 --> 00:03:29,000
+How does it is how is it able to differentiate good traffic versus bad traffic.
+
+57
+00:03:29,000 --> 00:03:31,000
+So this goes into its detection.
+
+58
+00:03:31,000 --> 00:03:38,000
+There's two ways the IDs is able to detect either it's a knowledge based system or it's a behavior or
+
+59
+00:03:38,000 --> 00:03:40,000
+slash anomaly based systems.
+
+60
+00:03:40,000 --> 00:03:44,000
+So knowledge based systems are also known as signature based systems.
+
+61
+00:03:44,000 --> 00:03:48,000
+They have a signature for all known vulnerabilities.
+
+62
+00:03:48,000 --> 00:03:54,000
+This thing has a database of all the vulnerabilities that are out there, all of the different worms
+
+63
+00:03:54,000 --> 00:03:55,000
+and attacks that are out there.
+
+64
+00:03:55,000 --> 00:03:56,000
+This is good.
+
+65
+00:03:56,000 --> 00:03:59,000
+I like these these types of systems.
+
+66
+00:03:59,000 --> 00:04:04,000
+They're you know, the main reason here is because it has a very low false alarm.
+
+67
+00:04:04,000 --> 00:04:10,000
+And what that means is this when this system tells you there is a virus, oh, there's probably a virus,
+
+68
+00:04:10,000 --> 00:04:11,000
+there is an intrusion.
+
+69
+00:04:11,000 --> 00:04:13,000
+There is a worm going on in there.
+
+70
+00:04:13,000 --> 00:04:17,000
+Alarms are more standardized and more easily to understand because it's coming from a signature.
+
+71
+00:04:17,000 --> 00:04:23,000
+The same way you have to update your antivirus software with signatures the same way this particular
+
+72
+00:04:23,000 --> 00:04:24,000
+thing works.
+
+73
+00:04:24,000 --> 00:04:29,000
+The disadvantage with this though, you have to continuously update the signatures.
+
+74
+00:04:29,000 --> 00:04:35,000
+Like if you have snort, you have to go and get the definitions, the updates on a consistent basis.
+
+75
+00:04:36,000 --> 00:04:41,000
+Um, and the other problem, if it's a signature based system, is you're waiting on the manufacturer
+
+76
+00:04:41,000 --> 00:04:48,000
+of the device or the software to actually send you the signature for new, unique, or for all the new
+
+77
+00:04:48,000 --> 00:04:49,000
+attacks that are coming out.
+
+78
+00:04:49,000 --> 00:04:55,000
+So if there's a new attack, a unique attack that the manufacturer doesn't know about yet, you're going
+
+79
+00:04:55,000 --> 00:04:59,000
+to get killed with it because the devices just doesn't know about it.
+
+80
+00:04:59,000 --> 00:05:04,000
+Now, what you should do is then turn the device into what's called an anomaly based device, or also
+
+81
+00:05:04,000 --> 00:05:06,000
+known as behavioral devices.
+
+82
+00:05:06,000 --> 00:05:09,000
+So behavioral based detection is this.
+
+83
+00:05:09,000 --> 00:05:15,000
+What it does is that it creates a baseline or learn the patterns of the normal activity within your
+
+84
+00:05:15,000 --> 00:05:16,000
+network.
+
+85
+00:05:16,000 --> 00:05:21,000
+It then it builds this statistical pattern of traffic within your network.
+
+86
+00:05:21,000 --> 00:05:25,000
+Any deviations, any variations from that.
+
+87
+00:05:25,000 --> 00:05:32,000
+It's going to tell you the great thing, the reason why it does this, since it's adapting to the traffic,
+
+88
+00:05:32,000 --> 00:05:35,000
+anything that's abnormal that people haven't done before, boom.
+
+89
+00:05:35,000 --> 00:05:38,000
+It tells you right away that there's something going on there.
+
+90
+00:05:38,000 --> 00:05:44,000
+You should check it out so it's able to tell you new or unique attacks that are out there.
+
+91
+00:05:46,000 --> 00:05:49,000
+It's less dependent on operating system vulnerability.
+
+92
+00:05:49,000 --> 00:05:52,000
+It's not going to find, you know, this is not going to affect it.
+
+93
+00:05:52,000 --> 00:05:54,000
+Now the disadvantage is there.
+
+94
+00:05:54,000 --> 00:05:56,000
+It's a higher false alarm.
+
+95
+00:05:56,000 --> 00:05:58,000
+This is going to suck.
+
+96
+00:05:58,000 --> 00:06:03,000
+Because if somebody decides to transfer a big file, the IDs is like, well, they've never done that
+
+97
+00:06:03,000 --> 00:06:07,000
+before and sends out an alarm and you're probably going to go investigate it.
+
+98
+00:06:07,000 --> 00:06:10,000
+Uh, usage pattern often changes in network.
+
+99
+00:06:10,000 --> 00:06:17,000
+And because of this, if user if user behavior pattern changes lots of false alarms.
+
+100
+00:06:17,000 --> 00:06:18,000
+Now.
+
+101
+00:06:18,000 --> 00:06:23,000
+IEDs are generally going to be a passive device.
+
+102
+00:06:23,000 --> 00:06:28,000
+Passive means that they just sit back and write passive responses.
+
+103
+00:06:28,000 --> 00:06:29,000
+They just sit back.
+
+104
+00:06:29,000 --> 00:06:34,000
+They make a log of the event, and they just tell you they'll send you a notification, either through
+
+105
+00:06:34,000 --> 00:06:38,000
+an email or a text message saying, hey, you know what?
+
+106
+00:06:39,000 --> 00:06:41,000
+With that email, you know what?
+
+107
+00:06:41,000 --> 00:06:44,000
+There is a there is a virus on that machine.
+
+108
+00:06:44,000 --> 00:06:46,000
+There's a worm on that particular machine.
+
+109
+00:06:46,000 --> 00:06:51,000
+So they're just basically telling you they're not going to do anything about the attack.
+
+110
+00:06:51,000 --> 00:06:54,000
+They're just going to they're just going to inform you that it's there.
+
+111
+00:06:55,000 --> 00:06:59,000
+Now, an active response is when it changes the environment to block it.
+
+112
+00:06:59,000 --> 00:07:05,000
+Modifying ACLs, blocking ports, blocking traffic, blocking certain network address, disable communications
+
+113
+00:07:05,000 --> 00:07:06,000
+on network segments.
+
+114
+00:07:06,000 --> 00:07:11,000
+This is more of going to be of an IPS, not just an IDs, which we'll come to in a little while.
+
+115
+00:07:13,000 --> 00:07:18,000
+Now, when it comes to IDs, there's really two main ways you're going to have them.
+
+116
+00:07:18,000 --> 00:07:19,000
+Ideally, you're going to have both.
+
+117
+00:07:19,000 --> 00:07:24,000
+You're going to have what's called a whole space IDs, and you're going to have a network based IDs.
+
+118
+00:07:25,000 --> 00:07:30,000
+Now, a host based IDs is something that you're going to install on your computer, on your desktop,
+
+119
+00:07:30,000 --> 00:07:33,000
+just like you would on anti-malware.
+
+120
+00:07:33,000 --> 00:07:39,000
+Now, if you have endpoint security software like Symantec's or Broadcom endpoint, McAfee endpoint
+
+121
+00:07:39,000 --> 00:07:45,000
+endpoint security software generally will come with a host based IDs on it.
+
+122
+00:07:46,000 --> 00:07:50,000
+Well, this is going to do is going to just monitor the host machine.
+
+123
+00:07:50,000 --> 00:07:55,000
+Maybe you go to a particular website, maybe you were downloading something, maybe an email brought
+
+124
+00:07:55,000 --> 00:07:57,000
+in a particular malware.
+
+125
+00:07:58,000 --> 00:08:02,000
+The host base IDs is going to be able to detect that.
+
+126
+00:08:02,000 --> 00:08:06,000
+Now this is going to respond by logging the activity and notifying you.
+
+127
+00:08:06,000 --> 00:08:12,000
+But it's probably going to notify a central console that, for example, the help desk, that something
+
+128
+00:08:12,000 --> 00:08:13,000
+needs to be done here.
+
+129
+00:08:13,000 --> 00:08:17,000
+Now the advantages there is that it can detect anomalies on the whole systems.
+
+130
+00:08:17,000 --> 00:08:20,000
+Uh, that that the network IDs can.
+
+131
+00:08:20,000 --> 00:08:24,000
+So if there's something going on in this machine that doesn't flow around the network traffic, the
+
+132
+00:08:24,000 --> 00:08:25,000
+network IDs can, but this could.
+
+133
+00:08:26,000 --> 00:08:30,000
+Now, the disadvantage, it's always going to be more costly because it's a per device.
+
+134
+00:08:30,000 --> 00:08:35,000
+So if you have a 10,000 device imagine 10,000 times the cost of each of those things.
+
+135
+00:08:36,000 --> 00:08:40,000
+Lots of administrative attention on each machine can detect network attacks.
+
+136
+00:08:40,000 --> 00:08:49,000
+One of the problems I have with installing endpoint security, even though we need it with Hids in particular,
+
+137
+00:08:49,000 --> 00:08:51,000
+is because it just consumes a lot of resources.
+
+138
+00:08:51,000 --> 00:08:54,000
+It slows your machine down, not significantly, but it does.
+
+139
+00:08:54,000 --> 00:08:59,000
+If you're running high, intense applications and you really need all your power and you put that IDs
+
+140
+00:08:59,000 --> 00:09:01,000
+on there, you might want to up your Ram and CPU.
+
+141
+00:09:03,000 --> 00:09:05,000
+Easier for intrusion to to discover and disable.
+
+142
+00:09:05,000 --> 00:09:09,000
+And I h IDs because they're right on the machine.
+
+143
+00:09:09,000 --> 00:09:15,000
+With less security, the logs are maintained in the system, and that means that hackers can easily
+
+144
+00:09:15,000 --> 00:09:18,000
+manipulate it, especially if it's on one machine.
+
+145
+00:09:18,000 --> 00:09:20,000
+Your machine in particular.
+
+146
+00:09:21,000 --> 00:09:23,000
+Now the other one is going to be a network based idea.
+
+147
+00:09:23,000 --> 00:09:25,000
+So what exactly is that?
+
+148
+00:09:25,000 --> 00:09:30,000
+A network based IDs is not just a piece of software on a desktop.
+
+149
+00:09:30,000 --> 00:09:32,000
+A network based IDs is a computer.
+
+150
+00:09:32,000 --> 00:09:33,000
+Like if you have snort.
+
+151
+00:09:33,000 --> 00:09:34,000
+All right.
+
+152
+00:09:34,000 --> 00:09:36,000
+So if I open the calculator.
+
+153
+00:09:36,000 --> 00:09:44,000
+So for example if you have snort you would install snort on a computer.
+
+154
+00:09:44,000 --> 00:09:45,000
+All right.
+
+155
+00:09:45,000 --> 00:09:46,000
+Just a normal desktop.
+
+156
+00:09:46,000 --> 00:09:50,000
+And what you're going to do is you're just going to plug it in to the switch.
+
+157
+00:09:50,000 --> 00:09:55,000
+Now once you guys look at this diagram that I have here, here's how you would set up your network.
+
+158
+00:09:55,000 --> 00:09:58,000
+You would first take your switch.
+
+159
+00:09:58,000 --> 00:10:04,000
+You would install snort on a normal everyday computer, ideally a type of a server.
+
+160
+00:10:04,000 --> 00:10:08,000
+And you're going to do what's called port spanning Port Spanner or Port Marion.
+
+161
+00:10:08,000 --> 00:10:10,000
+What this means let me get the switch here.
+
+162
+00:10:10,000 --> 00:10:18,000
+So what this means is this you would have to go into the switch and you would select one of these ports
+
+163
+00:10:18,000 --> 00:10:19,000
+to be this port spanner.
+
+164
+00:10:19,000 --> 00:10:25,000
+Let's say you go with this port right here, the second port you would go into the switches configuration.
+
+165
+00:10:25,000 --> 00:10:28,000
+If you guys studied Cisco you'll be familiar with this.
+
+166
+00:10:28,000 --> 00:10:30,000
+If you go into the switch you would port span this switch.
+
+167
+00:10:30,000 --> 00:10:35,000
+And what's going to happen here is that all traffic that comes through the rest of these switches,
+
+168
+00:10:35,000 --> 00:10:40,000
+all these ports will be copied to this second port that I have here.
+
+169
+00:10:40,000 --> 00:10:43,000
+So what this is doing is that all traffic.
+
+170
+00:10:43,000 --> 00:10:49,000
+So let's say somebody is talking from this port here to this port, maybe this port to this port, this
+
+171
+00:10:49,000 --> 00:10:49,000
+port, to this port.
+
+172
+00:10:49,000 --> 00:10:50,000
+What?
+
+173
+00:10:50,000 --> 00:10:50,000
+It doesn't matter.
+
+174
+00:10:51,000 --> 00:10:55,000
+Okay, as all these ports are talking, traffic coming in and out, all these ports.
+
+175
+00:10:55,000 --> 00:11:01,000
+This switch is sending a copy of every single one of the frames to that port.
+
+176
+00:11:02,000 --> 00:11:03,000
+Now.
+
+177
+00:11:03,000 --> 00:11:04,000
+What happens then?
+
+178
+00:11:04,000 --> 00:11:11,000
+Well, what's going to happen then is that remember, the snort box is connected to that span port.
+
+179
+00:11:12,000 --> 00:11:19,000
+The snort box snorts up all of this traffic, analyzes it in its database, and it's going to be able
+
+180
+00:11:19,000 --> 00:11:24,000
+to tell you if there is some kind of intrusion on this machine, or this machine or that machine or
+
+181
+00:11:24,000 --> 00:11:26,000
+that segment and so on.
+
+182
+00:11:26,000 --> 00:11:28,000
+So it reads all the incoming packet.
+
+183
+00:11:28,000 --> 00:11:31,000
+It searches for any kind of suspicious patterns.
+
+184
+00:11:31,000 --> 00:11:34,000
+Uh, when threats are discovered based on the severity.
+
+185
+00:11:36,000 --> 00:11:37,000
+Uh, it will alert you now.
+
+186
+00:11:37,000 --> 00:11:40,000
+It cannot monitor encrypted.
+
+187
+00:11:40,000 --> 00:11:40,000
+It's going to be this one.
+
+188
+00:11:40,000 --> 00:11:41,000
+This.
+
+189
+00:11:41,000 --> 00:11:43,000
+It can't monitor encrypted traffic.
+
+190
+00:11:43,000 --> 00:11:49,000
+If you use a lot of encrypted traffic, it may not be able to see it harder for attackers to discover.
+
+191
+00:11:49,000 --> 00:11:55,000
+Have very little, little negative effect on traffic because it's just copying traffic over.
+
+192
+00:11:55,000 --> 00:12:00,000
+It's not like it's going to be flying extra traffic around the network now.
+
+193
+00:12:00,000 --> 00:12:06,000
+And Nids is like, snort, I think is something we should all have on our networks.
+
+194
+00:12:06,000 --> 00:12:06,000
+Why?
+
+195
+00:12:06,000 --> 00:12:08,000
+Because once again it's free.
+
+196
+00:12:08,000 --> 00:12:11,000
+Please install it if you don't have it now.
+
+197
+00:12:12,000 --> 00:12:13,000
+All right.
+
+198
+00:12:13,000 --> 00:12:14,000
+You're not really going to find many things.
+
+199
+00:12:14,000 --> 00:12:17,000
+That is pure ideas in today's world.
+
+200
+00:12:17,000 --> 00:12:22,000
+Today's world with all the unified devices that are out there, we're going to get some kind of an IP.
+
+201
+00:12:22,000 --> 00:12:24,000
+A snort is technically an IPS.
+
+202
+00:12:24,000 --> 00:12:26,000
+So what exactly is the IPS?
+
+203
+00:12:26,000 --> 00:12:28,000
+An IPS is an inline device.
+
+204
+00:12:28,000 --> 00:12:29,000
+I want you guys watch this diagram here.
+
+205
+00:12:29,000 --> 00:12:31,000
+So you see this firewall.
+
+206
+00:12:31,000 --> 00:12:35,000
+The IDs sits like a normal box off the firewall.
+
+207
+00:12:35,000 --> 00:12:39,000
+It grabs traffic to protect your internal network.
+
+208
+00:12:39,000 --> 00:12:46,000
+Notice the IPS technically is the firewall a lot of IPS like so this has an IPS built into it.
+
+209
+00:12:46,000 --> 00:12:49,000
+You just have to pay to enable its license.
+
+210
+00:12:49,000 --> 00:12:56,000
+So what an IPS does is that not only does it examine the traffic to detect intrusions, but if it finds
+
+211
+00:12:56,000 --> 00:13:01,000
+intrusions or problems, it prevents the vulnerabilities it prevents.
+
+212
+00:13:01,000 --> 00:13:08,000
+It can shut segments down, it can shut hoses off, it can choose what to forward and what to block.
+
+213
+00:13:08,000 --> 00:13:11,000
+So it prevents attacks from happening in your network.
+
+214
+00:13:11,000 --> 00:13:14,000
+So this is something important to consider.
+
+215
+00:13:14,000 --> 00:13:22,000
+IPS IPS is of course going to be better than an IDs system, but any which way.
+
+216
+00:13:22,000 --> 00:13:26,000
+Remember snort is free and it is an ID it is a network IPS.
+
+217
+00:13:26,000 --> 00:13:30,000
+If you go to the website and you look at it, you'll notice it says that.
+
+218
+00:13:30,000 --> 00:13:31,000
+All right.
+
+219
+00:13:31,000 --> 00:13:37,000
+To end this discussion, IDs IPS are mandatory devices in my opinion, on any network.
+
+220
+00:13:37,000 --> 00:13:39,000
+In my opinion, this is not for your exam.
+
+221
+00:13:39,000 --> 00:13:41,000
+I'm just telling you this from experience.
+
+222
+00:13:41,000 --> 00:13:47,000
+If you have a network that's more than ten computers, please put an IDs in just between me and you.
+
+223
+00:13:47,000 --> 00:13:49,000
+If you're installing snort, it doesn't need a lot of resources.
+
+224
+00:13:49,000 --> 00:13:53,000
+Use an old box, old computer you have in a corner.
+
+225
+00:13:53,000 --> 00:13:55,000
+Put an SSD into it.
+
+226
+00:13:55,000 --> 00:13:56,000
+Install snort, put Linux on it.
+
+227
+00:13:56,000 --> 00:13:58,000
+Do not install on windows.
+
+228
+00:13:58,000 --> 00:14:03,000
+It doesn't work really well and have some fun monitoring traffic and securing your network.
+
diff --git a/11 - Security Principles/011 Load Balancer OB 3.2_en.srt b/11 - Security Principles/011 Load Balancer OB 3.2_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..e715b591f59a3f59cfc343e1db9c19a9d62e0abc
--- /dev/null
+++ b/11 - Security Principles/011 Load Balancer OB 3.2_en.srt
@@ -0,0 +1,380 @@
+1
+00:00:00,000 --> 00:00:07,000
+When you're building large networks, that's going to take in tens of thousands or millions of requests.
+
+2
+00:00:07,000 --> 00:00:13,000
+One critical device that you're going to need to set up is something we call a load balancer.
+
+3
+00:00:13,000 --> 00:00:15,000
+What exactly is it?
+
+4
+00:00:15,000 --> 00:00:15,000
+What?
+
+5
+00:00:15,000 --> 00:00:16,000
+I want to show you a picture of it.
+
+6
+00:00:16,000 --> 00:00:20,000
+Let's just jump a couple of slides around before we come back to it.
+
+7
+00:00:20,000 --> 00:00:24,000
+So I want you guys watch this particular diagram again.
+
+8
+00:00:24,000 --> 00:00:25,000
+We'll come back to this in a minute.
+
+9
+00:00:25,000 --> 00:00:29,000
+But what a load balancer does is exactly what it says it does.
+
+10
+00:00:29,000 --> 00:00:31,000
+It balances a load.
+
+11
+00:00:31,000 --> 00:00:37,000
+Let's say you have let's say these five computers each represents 1000 connections.
+
+12
+00:00:37,000 --> 00:00:39,000
+So right now you've got 5000 connections coming in.
+
+13
+00:00:39,000 --> 00:00:40,000
+You have a choice.
+
+14
+00:00:40,000 --> 00:00:44,000
+You can just have one single web server taking all the connections.
+
+15
+00:00:44,000 --> 00:00:48,000
+And if that server dies oh well every no more internet site for them.
+
+16
+00:00:48,000 --> 00:00:49,000
+Your sites down.
+
+17
+00:00:49,000 --> 00:00:51,000
+The best thing here is to get a load balancer.
+
+18
+00:00:51,000 --> 00:00:56,000
+What a load balancer does is that it distributes the load between two different servers.
+
+19
+00:00:56,000 --> 00:00:59,000
+So look at it right now it's given this one server.
+
+20
+00:00:59,000 --> 00:01:01,000
+It's computer one is getting this.
+
+21
+00:01:01,000 --> 00:01:03,000
+Then it's given this to computer two.
+
+22
+00:01:03,000 --> 00:01:05,000
+And when computer three comes in gives it to this one.
+
+23
+00:01:05,000 --> 00:01:09,000
+Computer four comes in gives it to this one, five comes in to this one.
+
+24
+00:01:09,000 --> 00:01:09,000
+Then six would go.
+
+25
+00:01:09,000 --> 00:01:15,000
+So it's going like this 123456789.
+
+26
+00:01:15,000 --> 00:01:16,000
+So what is it doing.
+
+27
+00:01:16,000 --> 00:01:18,000
+It's distributing the load between the machines.
+
+28
+00:01:18,000 --> 00:01:26,000
+That way one machine doesn't get all the load of the internet of the website requests is basically splitting
+
+29
+00:01:26,000 --> 00:01:27,000
+it 5050.
+
+30
+00:01:27,000 --> 00:01:33,000
+This of course helps to speed up the traffic on the speed up traffic hitting the system.
+
+31
+00:01:33,000 --> 00:01:34,000
+So what exactly is it?
+
+32
+00:01:34,000 --> 00:01:41,000
+Well, it's basically a device or software that evenly distributes network or application traffic across
+
+33
+00:01:41,000 --> 00:01:45,000
+multiple servers to prevent any single one of them from becoming overburdened.
+
+34
+00:01:45,000 --> 00:01:48,000
+It improves performance and reliability.
+
+35
+00:01:48,000 --> 00:01:48,000
+It makes it quick.
+
+36
+00:01:48,000 --> 00:01:52,000
+But if one of those servers die, your whole website doesn't go offline.
+
+37
+00:01:52,000 --> 00:01:56,000
+It does become slower because now one machine has to serve all of them.
+
+38
+00:01:56,000 --> 00:01:59,000
+Load balancers comes in different in two kinds.
+
+39
+00:01:59,000 --> 00:02:01,000
+You have a hardware and a software.
+
+40
+00:02:01,000 --> 00:02:06,000
+What I have here is a hardware load balancer from Barracuda, very famous device.
+
+41
+00:02:06,000 --> 00:02:13,000
+So a hardware load balancer is a physical device specifically designed for balancing the load.
+
+42
+00:02:13,000 --> 00:02:19,000
+They are more powerful, more expensive, and most of most of most of the load balancers we have today,
+
+43
+00:02:19,000 --> 00:02:23,000
+especially on large server farms, web server farms are going to be these kinds of devices.
+
+44
+00:02:23,000 --> 00:02:24,000
+You could do this.
+
+45
+00:02:25,000 --> 00:02:26,000
+With software.
+
+46
+00:02:27,000 --> 00:02:31,000
+So for example Windows Server supports this.
+
+47
+00:02:31,000 --> 00:02:33,000
+These are applications that can run on a standard hardware.
+
+48
+00:02:33,000 --> 00:02:37,000
+And cloud environments are more flexible and more cost effective.
+
+49
+00:02:37,000 --> 00:02:41,000
+Now when you set up a load balancer, there's basically two kinds of setups.
+
+50
+00:02:41,000 --> 00:02:44,000
+You have what's called active passive.
+
+51
+00:02:44,000 --> 00:02:46,000
+And the other one is called active active.
+
+52
+00:02:46,000 --> 00:02:47,000
+So what is exactly this one.
+
+53
+00:02:47,000 --> 00:02:53,000
+So active passive is this this is really not to improve performance.
+
+54
+00:02:53,000 --> 00:02:56,000
+This one is to improve reliability.
+
+55
+00:02:56,000 --> 00:02:58,000
+What this means is that what you do.
+
+56
+00:02:59,000 --> 00:03:07,000
+Is you're going to have one server take on all of the requests, all of them.
+
+57
+00:03:07,000 --> 00:03:11,000
+Maybe this is good for you because you don't have a lot of requests.
+
+58
+00:03:11,000 --> 00:03:16,000
+Maybe you have a really beefy server with a big line, and you don't need to split the request between
+
+59
+00:03:16,000 --> 00:03:16,000
+them.
+
+60
+00:03:16,000 --> 00:03:22,000
+It doesn't make sense, because the request you have is only utilized in a small percentage of resources
+
+61
+00:03:22,000 --> 00:03:23,000
+on the machine.
+
+62
+00:03:23,000 --> 00:03:25,000
+So what you do, you set up this thing called active passive.
+
+63
+00:03:25,000 --> 00:03:26,000
+So one machine is active.
+
+64
+00:03:26,000 --> 00:03:28,000
+It's taking all the requests.
+
+65
+00:03:28,000 --> 00:03:32,000
+And then if this machine fails then this one kicks in.
+
+66
+00:03:32,000 --> 00:03:33,000
+So this is a failover server.
+
+67
+00:03:33,000 --> 00:03:37,000
+So if the primary one fails the failover kicks in.
+
+68
+00:03:37,000 --> 00:03:40,000
+So it has to have some kind of failover mechanism between them.
+
+69
+00:03:40,000 --> 00:03:41,000
+So the switch knows it.
+
+70
+00:03:41,000 --> 00:03:47,000
+The hardware load balancer generally will knows it ideally for scenarios where uninterrupted service
+
+71
+00:03:47,000 --> 00:03:48,000
+is critical.
+
+72
+00:03:49,000 --> 00:03:53,000
+But you don't need the power of just two of them at the same time.
+
+73
+00:03:53,000 --> 00:03:57,000
+It provides a reliable backup in case a primary one fails.
+
+74
+00:03:57,000 --> 00:04:01,000
+So once again, if you just don't need that power, this is going to work out.
+
+75
+00:04:01,000 --> 00:04:08,000
+Now, if you have massive amounts of client traffic coming in and you have 50 servers set up there,
+
+76
+00:04:08,000 --> 00:04:13,000
+and you need all of your servers to be hammering out those requests, this is your thing here.
+
+77
+00:04:13,000 --> 00:04:14,000
+Both.
+
+78
+00:04:15,000 --> 00:04:21,000
+Load balancers are active in shared traffic simultaneously, so they're both sharing the traffic.
+
+79
+00:04:21,000 --> 00:04:26,000
+Traffic is distributed between two, generally two load balancers or different hoses.
+
+80
+00:04:26,000 --> 00:04:28,000
+Um they use something called round robin.
+
+81
+00:04:28,000 --> 00:04:29,000
+So you get it, then you get it.
+
+82
+00:04:29,000 --> 00:04:31,000
+So it'll be like you get it, then you get it, then you get it.
+
+83
+00:04:31,000 --> 00:04:34,000
+If there was three of them, it would be like, you get it, you get it, you get it.
+
+84
+00:04:34,000 --> 00:04:38,000
+Usage for high end traffic environments this year.
+
+85
+00:04:38,000 --> 00:04:42,000
+The big advantages here good capacity and reliability.
+
+86
+00:04:42,000 --> 00:04:48,000
+Now this could be done with multiple load balancers or it could be done with a single load balancer.
+
+87
+00:04:48,000 --> 00:04:51,000
+Although if you have multiple load balancers because if this device fails you're in trouble.
+
+88
+00:04:51,000 --> 00:04:56,000
+So you could have multiple load balancers uh, different forms.
+
+89
+00:04:56,000 --> 00:04:59,000
+Maybe each load balancer has ten machines.
+
+90
+00:04:59,000 --> 00:05:02,000
+There are different ways to set this up for your exam.
+
+91
+00:05:02,000 --> 00:05:04,000
+Just understand what a load balancer is.
+
+92
+00:05:04,000 --> 00:05:05,000
+It is what it says it is.
+
+93
+00:05:05,000 --> 00:05:07,000
+It distributes loads between machines.
+
+94
+00:05:07,000 --> 00:05:14,000
+Key reason for that is going to be because we want to not just distribute the traffic, but we want
+
+95
+00:05:14,000 --> 00:05:20,000
+the reliability in case one of those machines fail, it doesn't bring down the entire network.
+
diff --git a/11 - Security Principles/012 802.1x and EAP OB 3.2_en.srt b/11 - Security Principles/012 802.1x and EAP OB 3.2_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..5b538bc496ce708541d93e3968d1483918f8350a
--- /dev/null
+++ b/11 - Security Principles/012 802.1x and EAP OB 3.2_en.srt
@@ -0,0 +1,356 @@
+1
+00:00:00,000 --> 00:00:00,000
+All right.
+
+2
+00:00:00,000 --> 00:00:02,000
+Take a look at the switch that I have here.
+
+3
+00:00:02,000 --> 00:00:03,000
+So we got this switch.
+
+4
+00:00:03,000 --> 00:00:07,000
+We plug you're going to plug your computer into my switch.
+
+5
+00:00:07,000 --> 00:00:10,000
+And you're going to be able to gain access to the network.
+
+6
+00:00:10,000 --> 00:00:17,000
+Or are you one of the just having a switch lying around is one of the worst things you can ever do.
+
+7
+00:00:17,000 --> 00:00:23,000
+If you're right now, if your switch is set up to the point where anyone can just walk in, plug a computer
+
+8
+00:00:23,000 --> 00:00:28,000
+into it, and gain full network access without any form of authentication.
+
+9
+00:00:28,000 --> 00:00:29,000
+That is bad news.
+
+10
+00:00:29,000 --> 00:00:36,000
+So what we want to do is we want to be able we put this down before it kills me here.
+
+11
+00:00:36,000 --> 00:00:41,000
+We want to be able to do what is called port security.
+
+12
+00:00:41,000 --> 00:00:43,000
+But what exactly is that?
+
+13
+00:00:43,000 --> 00:00:48,000
+So port security is used to secure network ports on computers and network devices, and particularly
+
+14
+00:00:48,000 --> 00:00:55,000
+switches guarding against on authorized access and insurance, secure communication.
+
+15
+00:00:55,000 --> 00:00:57,000
+This is more than likely going to be secured.
+
+16
+00:00:57,000 --> 00:01:03,000
+Network switch ports now generally, port security can also mean things like filtering ports through
+
+17
+00:01:03,000 --> 00:01:04,000
+TCP and UDP.
+
+18
+00:01:04,000 --> 00:01:05,000
+This is going to be done with like firewalls.
+
+19
+00:01:06,000 --> 00:01:10,000
+It's meant to stop unauthorized access to your network.
+
+20
+00:01:10,000 --> 00:01:15,000
+But in this particular video, what I want to talk about is not just filtering traffic through ports.
+
+21
+00:01:15,000 --> 00:01:17,000
+This is going to be done generally through a firewall.
+
+22
+00:01:17,000 --> 00:01:21,000
+I want to talk about the physical port security, like on this switch.
+
+23
+00:01:21,000 --> 00:01:28,000
+And in particular there's two terms that we want to be familiar with something called 821 X and EAP
+
+24
+00:01:28,000 --> 00:01:31,000
+or Extensible Authentication Protocol.
+
+25
+00:01:31,000 --> 00:01:32,000
+Let me explain what this is to you.
+
+26
+00:01:32,000 --> 00:01:36,000
+So 821 x you have to come into the switch and enable these things.
+
+27
+00:01:36,000 --> 00:01:40,000
+You you configure the ports on the switch and you enable this.
+
+28
+00:01:40,000 --> 00:01:42,000
+This is an IEEE standard.
+
+29
+00:01:43,000 --> 00:01:44,000
+For port.
+
+30
+00:01:44,000 --> 00:01:46,000
+Port based access control.
+
+31
+00:01:46,000 --> 00:01:50,000
+It's used to authenticate device that are attempting to connect to your LAN.
+
+32
+00:01:50,000 --> 00:01:53,000
+And you can also do this for your wireless connection.
+
+33
+00:01:53,000 --> 00:01:59,000
+Also not just for your wired switch, but you can also enable it on your wireless.
+
+34
+00:01:59,000 --> 00:02:00,000
+Here's how it works.
+
+35
+00:02:00,000 --> 00:02:06,000
+When a device attempts to connect to a network that's that has 801 enabled, the authenticator blocks
+
+36
+00:02:06,000 --> 00:02:11,000
+all traffic except the 8021, and the client is authenticated.
+
+37
+00:02:11,000 --> 00:02:12,000
+Now I want to show you guys something.
+
+38
+00:02:12,000 --> 00:02:14,000
+I have a diagram of this from Wikipedia.
+
+39
+00:02:15,000 --> 00:02:21,000
+So when you want to connect to a network, notice the switch that is going to be utilizing.
+
+40
+00:02:22,000 --> 00:02:24,000
+That's going to be utilizing 801 x.
+
+41
+00:02:24,000 --> 00:02:31,000
+So what you do is you configure the switch to say if the computer does not authenticate and go through
+
+42
+00:02:31,000 --> 00:02:34,000
+8 to 1 x, we're not going to allow you access in.
+
+43
+00:02:34,000 --> 00:02:37,000
+So it only accepts that kind of access.
+
+44
+00:02:37,000 --> 00:02:38,000
+So here's how it works.
+
+45
+00:02:39,000 --> 00:02:40,000
+The supplicant is you.
+
+46
+00:02:40,000 --> 00:02:41,000
+That's the user.
+
+47
+00:02:41,000 --> 00:02:44,000
+You connect to the switch and you're trying to gain access to the network.
+
+48
+00:02:44,000 --> 00:02:51,000
+But before the switch can grant you access to the LAN resources, what you have to do, you have to
+
+49
+00:02:51,000 --> 00:02:55,000
+send a request to the authenticator to switch.
+
+50
+00:02:55,000 --> 00:03:00,000
+The authenticator then sends that request to an authentication server.
+
+51
+00:03:00,000 --> 00:03:04,000
+That authentication server is going to authenticate you username password.
+
+52
+00:03:04,000 --> 00:03:08,000
+It can do a variety of different things certificate based authentication.
+
+53
+00:03:08,000 --> 00:03:10,000
+So there's many different ways it can do this.
+
+54
+00:03:10,000 --> 00:03:16,000
+You can use a Radius server something we'll cover in another class in another video when the when the
+
+55
+00:03:16,000 --> 00:03:23,000
+authentication server said it's okay, then the authenticator tells you and then you can access resources.
+
+56
+00:03:24,000 --> 00:03:29,000
+Now the supplicant I just mentioned to you, you send the credential to the authenticator, which forwards
+
+57
+00:03:29,000 --> 00:03:30,000
+them to the authentication server.
+
+58
+00:03:30,000 --> 00:03:34,000
+And the authentication server is something that's going to run like a Radius server.
+
+59
+00:03:34,000 --> 00:03:39,000
+If the server approves it, it gives you access and then you can access the network.
+
+60
+00:03:39,000 --> 00:03:42,000
+Now you notice I have these things called EAP here.
+
+61
+00:03:42,000 --> 00:03:46,000
+See that EAP stands for Extensible Authentication Protocol.
+
+62
+00:03:46,000 --> 00:03:50,000
+You are authenticating to a particular device.
+
+63
+00:03:50,000 --> 00:03:53,000
+This here is this is the protocol that's going to allow that.
+
+64
+00:03:54,000 --> 00:03:56,000
+It's a framework frequently used in network access.
+
+65
+00:03:57,000 --> 00:03:58,000
+All right.
+
+66
+00:03:58,000 --> 00:04:02,000
+It's designed to support multiple authentication passwords, tokens, certificates.
+
+67
+00:04:02,000 --> 00:04:07,000
+So if you want to authenticate to my network and you plug a computer into my switch.
+
+68
+00:04:08,000 --> 00:04:11,000
+You're going to have to provide either some kind of certificate.
+
+69
+00:04:11,000 --> 00:04:13,000
+You can use tokens.
+
+70
+00:04:14,000 --> 00:04:15,000
+Uh, certificates is a good one.
+
+71
+00:04:15,000 --> 00:04:16,000
+I like that one.
+
+72
+00:04:17,000 --> 00:04:19,000
+The worst, of course, is passwords.
+
+73
+00:04:19,000 --> 00:04:21,000
+This thing is widely used.
+
+74
+00:04:21,000 --> 00:04:25,000
+It's mostly it was widely used in PGP or point to point connections.
+
+75
+00:04:26,000 --> 00:04:26,000
+Um.
+
+76
+00:04:27,000 --> 00:04:34,000
+But it's a lot of time now using 821 X, and it's used generally in conjunction with a Radius server
+
+77
+00:04:34,000 --> 00:04:35,000
+to centralize authentication.
+
+78
+00:04:35,000 --> 00:04:40,000
+That way you can have tons of switches all foward to a single.
+
+79
+00:04:41,000 --> 00:04:44,000
+Authentication server like a radius.
+
+80
+00:04:45,000 --> 00:04:47,000
+Why would you want this?
+
+81
+00:04:47,000 --> 00:04:47,000
+Right?
+
+82
+00:04:47,000 --> 00:04:48,000
+You think about this.
+
+83
+00:04:49,000 --> 00:04:53,000
+One of the worst things that can happen to somebody walking into a network and just plug a computer
+
+84
+00:04:53,000 --> 00:04:57,000
+into your to plug a computer into your network, gain all your network access.
+
+85
+00:04:57,000 --> 00:04:59,000
+That would severely suck.
+
+86
+00:04:59,000 --> 00:05:01,000
+The best thing to do is to have this on your network.
+
+87
+00:05:01,000 --> 00:05:07,000
+Now, it's not difficult to set up, but it is more setup that needs to get done.
+
+88
+00:05:07,000 --> 00:05:12,000
+That way, when somebody plugs a computer into your network, you're 100% sure this person actually
+
+89
+00:05:12,000 --> 00:05:14,000
+belongs in the network.
+
diff --git a/11 - Security Principles/013 Firewalls OB 3.2_en.srt b/11 - Security Principles/013 Firewalls OB 3.2_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..fe305010615fa92e09f5779ffb91cc9a00efb41b
--- /dev/null
+++ b/11 - Security Principles/013 Firewalls OB 3.2_en.srt
@@ -0,0 +1,520 @@
+1
+00:00:00,000 --> 00:00:04,000
+In this course, I discussed a lot of different ways to secure a network.
+
+2
+00:00:04,000 --> 00:00:11,000
+But when it comes to network security, Network Security 101 is a firewall.
+
+3
+00:00:11,000 --> 00:00:17,000
+And in this video we're going to talk about firewalls in particularly like this little firewall that
+
+4
+00:00:17,000 --> 00:00:19,000
+I have right here.
+
+5
+00:00:19,000 --> 00:00:19,000
+All right.
+
+6
+00:00:19,000 --> 00:00:20,000
+That one has two USBs.
+
+7
+00:00:20,000 --> 00:00:21,000
+This one doesn't.
+
+8
+00:00:21,000 --> 00:00:23,000
+All right let's get started with different kinds of firewall.
+
+9
+00:00:23,000 --> 00:00:26,000
+And I'm going to explain to you that this is an next generation firewall.
+
+10
+00:00:26,000 --> 00:00:28,000
+And what makes this one unique.
+
+11
+00:00:28,000 --> 00:00:29,000
+Let's get started.
+
+12
+00:00:30,000 --> 00:00:36,000
+When it comes to basic network security, one of the most basic things you've got to have on a computer
+
+13
+00:00:37,000 --> 00:00:38,000
+or on a network is a firewall.
+
+14
+00:00:38,000 --> 00:00:44,000
+Now firewalls comes in to basically going to come in two main designs.
+
+15
+00:00:44,000 --> 00:00:48,000
+You have, uh, host based firewalls and network firewalls.
+
+16
+00:00:48,000 --> 00:00:49,000
+This is a network firewall.
+
+17
+00:00:49,000 --> 00:00:55,000
+You have a host based firewall that's installed on your physical box, like on your your desktop, like
+
+18
+00:00:55,000 --> 00:00:56,000
+Windows Firewall.
+
+19
+00:00:56,000 --> 00:00:59,000
+Now, what exactly is it?
+
+20
+00:00:59,000 --> 00:01:02,000
+Well, a network security system, it's basically a network.
+
+21
+00:01:02,000 --> 00:01:05,000
+The monitors and controls incoming and outgoing network traffic.
+
+22
+00:01:05,000 --> 00:01:10,000
+Whether that's coming into your host or coming into your network, typically establishes a barrier between
+
+23
+00:01:10,000 --> 00:01:14,000
+a trusted, secure internal network and an outside external network.
+
+24
+00:01:14,000 --> 00:01:19,000
+So if it's a network, if it's a network based firewall, they're talking about this one here has a
+
+25
+00:01:19,000 --> 00:01:20,000
+Wang port.
+
+26
+00:01:22,000 --> 00:01:27,000
+Anything connected here would be considered on the public side, and anything connected here, the land
+
+27
+00:01:27,000 --> 00:01:29,000
+port would be considered good traffic.
+
+28
+00:01:29,000 --> 00:01:32,000
+Now it's implemented in hardware and software.
+
+29
+00:01:32,000 --> 00:01:35,000
+So obviously this is an appliance that we would have.
+
+30
+00:01:35,000 --> 00:01:41,000
+Of course you would have software firewalls like something uh, that you would install like like Windows
+
+31
+00:01:41,000 --> 00:01:41,000
+Firewall.
+
+32
+00:01:41,000 --> 00:01:42,000
+That's a good example.
+
+33
+00:01:42,000 --> 00:01:46,000
+But you can also have like Symantec's or Broadcom endpoint, McAfee endpoint.
+
+34
+00:01:46,000 --> 00:01:49,000
+These will generally come with software based firewalls.
+
+35
+00:01:49,000 --> 00:01:54,000
+They're going to enforce a security policy like allow or disallow these kinds of traffic.
+
+36
+00:01:54,000 --> 00:01:58,000
+They control the flow of traffic does not differentiate data versus command.
+
+37
+00:01:58,000 --> 00:02:02,000
+It just doesn't know whether something is a command or a particular data.
+
+38
+00:02:02,000 --> 00:02:06,000
+So it might be difficult to detect that controls the flow of traffic.
+
+39
+00:02:06,000 --> 00:02:10,000
+Um, controls the flow of traffic between hosts and network.
+
+40
+00:02:10,000 --> 00:02:16,000
+Now, there are different kinds of firewalls that we want to be familiar with for our exam.
+
+41
+00:02:16,000 --> 00:02:23,000
+The first kind of firewall that came out when I was a little boy was packet filtering firewalls.
+
+42
+00:02:23,000 --> 00:02:26,000
+And these things are not firewalls, they were just routers.
+
+43
+00:02:26,000 --> 00:02:32,000
+When an access control list, they were subject to many kinds of attacks and they do not exist today.
+
+44
+00:02:33,000 --> 00:02:37,000
+Today we're all stateful packet inspection.
+
+45
+00:02:37,000 --> 00:02:38,000
+This was known as stateless.
+
+46
+00:02:38,000 --> 00:02:43,000
+The reason for this is because this type of firewall didn't know traffic that left.
+
+47
+00:02:43,000 --> 00:02:46,000
+So it was subject to something called source routing.
+
+48
+00:02:46,000 --> 00:02:49,000
+Once again, this thing doesn't really exist.
+
+49
+00:02:49,000 --> 00:02:54,000
+All firewalls today and all the firewalls that I'm going to be talking about, such as web application
+
+50
+00:02:54,000 --> 00:03:04,000
+firewalls, utms, and next gen firewalls are all based on stateful packet inspection or Spice or stateful
+
+51
+00:03:04,000 --> 00:03:05,000
+inspection firewalls.
+
+52
+00:03:05,000 --> 00:03:08,000
+This is the most they're more advanced than packet filtering.
+
+53
+00:03:08,000 --> 00:03:09,000
+They keep a track.
+
+54
+00:03:09,000 --> 00:03:12,000
+They have a state table of who left and who's coming back in.
+
+55
+00:03:12,000 --> 00:03:19,000
+They're incredibly popular on all firewall technology, including what I have here is based on it now.
+
+56
+00:03:20,000 --> 00:03:26,000
+One kind of firewall that is popular if you're hosting web servers is going to be something called a
+
+57
+00:03:26,000 --> 00:03:29,000
+WAF or a web application firewall.
+
+58
+00:03:29,000 --> 00:03:34,000
+The design to protect web applications by filtering and monitoring web traffic.
+
+59
+00:03:34,000 --> 00:03:39,000
+Let me show you guys a particular diagram from a very famous company called Akamai.
+
+60
+00:03:39,000 --> 00:03:42,000
+So imagine you have a web for a web server farm.
+
+61
+00:03:42,000 --> 00:03:43,000
+All right.
+
+62
+00:03:43,000 --> 00:03:44,000
+All these are all your web servers.
+
+63
+00:03:44,000 --> 00:03:51,000
+You have all kinds of end users coming through the internet to get to your web server.
+
+64
+00:03:51,000 --> 00:03:59,000
+You put the web application firewall between you and the public, any kind of negative traffic that
+
+65
+00:03:59,000 --> 00:04:06,000
+is attempting to hit your web servers, things such as SQL injection, cross site scripting, session
+
+66
+00:04:06,000 --> 00:04:11,000
+hijacking, anything that's negative that's going to attempt to hit your.
+
+67
+00:04:12,000 --> 00:04:14,000
+Hit your, uh, your web server.
+
+68
+00:04:14,000 --> 00:04:16,000
+This thing is going to stop.
+
+69
+00:04:16,000 --> 00:04:20,000
+So this is really important if you're running web applications.
+
+70
+00:04:21,000 --> 00:04:23,000
+Uh, they operate at the application layer.
+
+71
+00:04:23,000 --> 00:04:24,000
+The rules are customized.
+
+72
+00:04:24,000 --> 00:04:26,000
+They're generally could be a hardware or software.
+
+73
+00:04:26,000 --> 00:04:31,000
+But a lot of times now, being that a lot of people have all their web servers are in the cloud, they're
+
+74
+00:04:31,000 --> 00:04:33,000
+probably going to be part of a cloud service.
+
+75
+00:04:34,000 --> 00:04:38,000
+Now, the other two confuses a lot of folks.
+
+76
+00:04:38,000 --> 00:04:41,000
+And I'll tell you the difference between them, because as I go through them, they're going to sound
+
+77
+00:04:41,000 --> 00:04:42,000
+alike.
+
+78
+00:04:42,000 --> 00:04:50,000
+Unified threat management systems are this this, by the way, is is this one this is an NDF w.
+
+79
+00:04:51,000 --> 00:04:55,000
+So if you go to Sonicwall and you look up Sonicwall firewalls, you'll see this this big across the
+
+80
+00:04:55,000 --> 00:04:58,000
+top next generation firewalls.
+
+81
+00:04:58,000 --> 00:04:59,000
+But what exactly is this one now?
+
+82
+00:04:59,000 --> 00:05:00,000
+Utms.
+
+83
+00:05:00,000 --> 00:05:07,000
+This is a great this is a big comprehensive solution that includes things like antivirus, anti-spyware,
+
+84
+00:05:07,000 --> 00:05:11,000
+firewalls, intrusion detections, preventions, and content filtering.
+
+85
+00:05:12,000 --> 00:05:13,000
+They're easy to use.
+
+86
+00:05:13,000 --> 00:05:14,000
+They're very.
+
+87
+00:05:14,000 --> 00:05:20,000
+They come pre-built with many policies ideal for small to mid sized business.
+
+88
+00:05:20,000 --> 00:05:22,000
+Now it's going to sound the same.
+
+89
+00:05:22,000 --> 00:05:24,000
+Okay, I'm just giving you a heads up now.
+
+90
+00:05:24,000 --> 00:05:28,000
+Far more advanced than traditional firewalls include functionalities.
+
+91
+00:05:28,000 --> 00:05:29,000
+Deep packet inspection.
+
+92
+00:05:29,000 --> 00:05:36,000
+They include intrusion prevention systems application awareness deep packet inspection.
+
+93
+00:05:36,000 --> 00:05:39,000
+They can actually see within the packet good threat intelligence.
+
+94
+00:05:39,000 --> 00:05:44,000
+They will also come with antivirus, anti-spyware firewall, intrusion detection, prevention system
+
+95
+00:05:44,000 --> 00:05:46,000
+and content filtering.
+
+96
+00:05:46,000 --> 00:05:50,000
+These two things sound very much alike.
+
+97
+00:05:50,000 --> 00:05:55,000
+Now, if you are a small business and you just want something to take out the box and you just plug
+
+98
+00:05:55,000 --> 00:05:58,000
+it in and it comes with a great set of policies.
+
+99
+00:05:58,000 --> 00:06:01,000
+UTM is easy to manage and it comes with most policies.
+
+100
+00:06:01,000 --> 00:06:07,000
+If you're looking for something more customizable to best match your business needs, then you get the
+
+101
+00:06:07,000 --> 00:06:08,000
+Ngfw.
+
+102
+00:06:08,000 --> 00:06:11,000
+These particular are the engine firewalls.
+
+103
+00:06:11,000 --> 00:06:18,000
+The engine firewalls are much more customizable, more robust than the Utms.
+
+104
+00:06:19,000 --> 00:06:20,000
+Okay, so keep that in mind.
+
+105
+00:06:20,000 --> 00:06:22,000
+The difference is customization.
+
+106
+00:06:22,000 --> 00:06:26,000
+One is just really more customization than others.
+
+107
+00:06:26,000 --> 00:06:27,000
+Okay.
+
+108
+00:06:27,000 --> 00:06:29,000
+Great discussion on firewalls.
+
+109
+00:06:29,000 --> 00:06:36,000
+Now I'm not sure if you guys remember the OSI model from previous classes, but one of the things that
+
+110
+00:06:36,000 --> 00:06:42,000
+we should be familiar with is where firewalls operate layer four and layer seven.
+
+111
+00:06:42,000 --> 00:06:49,000
+So layer four firewalls focus on data transport because they operate at the transport layer, the control
+
+112
+00:06:49,000 --> 00:06:50,000
+traffic based on TCP, UDP.
+
+113
+00:06:51,000 --> 00:06:54,000
+You got to remember something at the basic level.
+
+114
+00:06:54,000 --> 00:06:56,000
+All firewalls do one thing.
+
+115
+00:06:56,000 --> 00:07:03,000
+They block ports at the most conceptual level of firewall should block ports and ports operate at layer
+
+116
+00:07:03,000 --> 00:07:06,000
+four, your transport layer, not your network layer.
+
+117
+00:07:06,000 --> 00:07:08,000
+That's going to be IP.
+
+118
+00:07:09,000 --> 00:07:16,000
+Now, if the firewall can read into the application and stop certain traffic based on things like a
+
+119
+00:07:16,000 --> 00:07:22,000
+URL, this is going to be a layer four firewall inspects the content of the traffic there, make more
+
+120
+00:07:22,000 --> 00:07:26,000
+informed pretty much decisions, so keep that in mind.
+
+121
+00:07:26,000 --> 00:07:28,000
+Now application.
+
+122
+00:07:28,000 --> 00:07:34,000
+Anytime you hear the terms application firewall that is considered application firewall is considered
+
+123
+00:07:34,000 --> 00:07:35,000
+a layer seven.
+
+124
+00:07:35,000 --> 00:07:37,000
+Because remember layer seven is application.
+
+125
+00:07:37,000 --> 00:07:41,000
+But generally if the exam doesn't specify anything it says what layer is a firewall.
+
+126
+00:07:41,000 --> 00:07:42,000
+It's layer four.
+
+127
+00:07:42,000 --> 00:07:46,000
+Unless they say something like web application firewall.
+
+128
+00:07:46,000 --> 00:07:51,000
+Uh, by the way, proxy servers are also a type of a firewall.
+
+129
+00:07:51,000 --> 00:07:54,000
+And that's a proxy server is a layer seven device.
+
+130
+00:07:54,000 --> 00:07:58,000
+So keep that in mind in case you got a question about that on your test.
+
diff --git a/11 - Security Principles/014 VPN OB 3.2_en.srt b/11 - Security Principles/014 VPN OB 3.2_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..a83190783617ae7e4df75a2d666f016076af1a19
--- /dev/null
+++ b/11 - Security Principles/014 VPN OB 3.2_en.srt
@@ -0,0 +1,672 @@
+1
+00:00:00,000 --> 00:00:03,000
+One very popular thing to do today is to work from home.
+
+2
+00:00:03,000 --> 00:00:07,000
+Maybe you're doing that right now, or maybe you're looking for a job to work from home.
+
+3
+00:00:07,000 --> 00:00:14,000
+The technology that allows work from home, that allows you to connect to a corporate network and utilize
+
+4
+00:00:14,000 --> 00:00:19,000
+all the corporate network resources, is called a VPN.
+
+5
+00:00:19,000 --> 00:00:20,000
+So what exactly is that?
+
+6
+00:00:21,000 --> 00:00:23,000
+Well, here's what it is.
+
+7
+00:00:23,000 --> 00:00:28,000
+A VPN is a technology that creates an encrypted connection over a less secure network.
+
+8
+00:00:28,000 --> 00:00:34,000
+It builds on top of an existing physical network, provides a connection mechanism between you and that
+
+9
+00:00:34,000 --> 00:00:38,000
+corporate network, generally across a public network such as the internet.
+
+10
+00:00:38,000 --> 00:00:41,000
+It allows secure connection between endpoints.
+
+11
+00:00:41,000 --> 00:00:48,000
+Basically, it's going to allow employees to securely access corporate intranet or internal resources
+
+12
+00:00:48,000 --> 00:00:50,000
+can securely connect.
+
+13
+00:00:50,000 --> 00:00:53,000
+It can even connect global offices together.
+
+14
+00:00:53,000 --> 00:00:56,000
+And it provides a connection over the public internet.
+
+15
+00:00:56,000 --> 00:00:58,000
+Now let me give you some good examples of this.
+
+16
+00:00:58,000 --> 00:01:01,000
+So I use VPNs quite often.
+
+17
+00:01:01,000 --> 00:01:03,000
+In fact, I work from home quite a lot.
+
+18
+00:01:03,000 --> 00:01:07,000
+When I'm at home, I want to be able to access the server at work.
+
+19
+00:01:07,000 --> 00:01:11,000
+That server at work has a database with all the students and the information for the school.
+
+20
+00:01:11,000 --> 00:01:16,000
+It has a file server for different documents that I need access to so I could stay home.
+
+21
+00:01:16,000 --> 00:01:20,000
+I connect to my workplace VPN and then it's like I'm sitting there.
+
+22
+00:01:20,000 --> 00:01:27,000
+I have access to every single thing in the actual network to have a bunch of locations.
+
+23
+00:01:27,000 --> 00:01:30,000
+For example, we have a location in Long Island, New York and Manhattan.
+
+24
+00:01:31,000 --> 00:01:33,000
+In New York City, Midtown Manhattan.
+
+25
+00:01:33,000 --> 00:01:40,000
+We connect these two locations with a VPN, so folks in Manhattan can share data with folks in Long
+
+26
+00:01:40,000 --> 00:01:41,000
+Island.
+
+27
+00:01:41,000 --> 00:01:43,000
+So VPNs are pretty robust.
+
+28
+00:01:43,000 --> 00:01:49,000
+You can use it as a user access VPN, like I'm using it to connect to my workplace, or you can use
+
+29
+00:01:49,000 --> 00:01:51,000
+it to connect different sites together.
+
+30
+00:01:51,000 --> 00:01:52,000
+Now.
+
+31
+00:01:54,000 --> 00:01:55,000
+Take a look at this here.
+
+32
+00:01:55,000 --> 00:01:58,000
+This here is called a site to site VPN.
+
+33
+00:01:58,000 --> 00:01:59,000
+This is like site one.
+
+34
+00:01:59,000 --> 00:02:02,000
+Could be like our new Manhattan site.
+
+35
+00:02:02,000 --> 00:02:05,000
+Site two could be like our Long Island site.
+
+36
+00:02:05,000 --> 00:02:09,000
+And notice it's going across the internet utilizing VPN devices.
+
+37
+00:02:09,000 --> 00:02:11,000
+What would you say would do that?
+
+38
+00:02:11,000 --> 00:02:14,000
+This is what we use to do our VPN.
+
+39
+00:02:14,000 --> 00:02:16,000
+Our Sonicwall is our VPN buddy.
+
+40
+00:02:16,000 --> 00:02:21,000
+We set up the VPN on this device, and I'm going to go through some of the technology that this thing
+
+41
+00:02:21,000 --> 00:02:22,000
+uses.
+
+42
+00:02:22,000 --> 00:02:29,000
+This thing uses IPsec is what it utilizes to create a tunnel between the two endpoints.
+
+43
+00:02:29,000 --> 00:02:32,000
+And we'll describe what that is coming up in a few minutes.
+
+44
+00:02:32,000 --> 00:02:33,000
+So.
+
+45
+00:02:33,000 --> 00:02:37,000
+This type of VPN is a virtual point to point connection.
+
+46
+00:02:38,000 --> 00:02:45,000
+All right through and it encapsulate the data, virtual encapsulation of the data to the untrusted internet.
+
+47
+00:02:45,000 --> 00:02:47,000
+So it's all encrypted.
+
+48
+00:02:47,000 --> 00:02:48,000
+How does it do it?
+
+49
+00:02:48,000 --> 00:02:50,000
+Well, it does it by tunnelling.
+
+50
+00:02:51,000 --> 00:02:51,000
+All right.
+
+51
+00:02:51,000 --> 00:02:56,000
+Tunneling means that it encapsulate all the packets inside of something else.
+
+52
+00:02:57,000 --> 00:03:00,000
+When it comes to tunneling, they're basically two tunnels.
+
+53
+00:03:00,000 --> 00:03:06,000
+VPNs utilizes in today's world to transport confidential companies data.
+
+54
+00:03:06,000 --> 00:03:13,000
+We're going to utilize either a TLS tunnel or we're going to be using L2, TCP with IPsec tunnels.
+
+55
+00:03:13,000 --> 00:03:14,000
+All right.
+
+56
+00:03:14,000 --> 00:03:17,000
+Those are going to be the two tunnels that we're going to be needing to know.
+
+57
+00:03:19,000 --> 00:03:26,000
+So the first thing I want to show you is what's called an LL2MLS tunnel or SSL tunnels.
+
+58
+00:03:26,000 --> 00:03:33,000
+These are tunnels or tunnels that are set up utilizing TLS, SSL, the operator layer four of the OSI
+
+59
+00:03:33,000 --> 00:03:34,000
+model.
+
+60
+00:03:34,000 --> 00:03:40,000
+Now, if you remember from cryptography or if you haven't watched that section yet, go through it.
+
+61
+00:03:40,000 --> 00:03:43,000
+In cryptography, I go through the whole SSL handshake with you.
+
+62
+00:03:43,000 --> 00:03:44,000
+It's very secure.
+
+63
+00:03:44,000 --> 00:03:47,000
+We are using SSL all the time.
+
+64
+00:03:47,000 --> 00:03:50,000
+Every website you go to is protected with SSL.
+
+65
+00:03:50,000 --> 00:03:56,000
+What we're doing is we're encapsulating the VPN traffic or tunneling it into an SSL.
+
+66
+00:03:56,000 --> 00:03:59,000
+Now we're going to use this for encryption.
+
+67
+00:03:59,000 --> 00:04:01,000
+No need to open any additional ports.
+
+68
+00:04:01,000 --> 00:04:05,000
+Mostly use on user access VPN.
+
+69
+00:04:05,000 --> 00:04:06,000
+Now what does that mean.
+
+70
+00:04:06,000 --> 00:04:11,000
+These are going to be VPNs that you use to access a corporate network, not necessarily between site
+
+71
+00:04:11,000 --> 00:04:19,000
+to site, like my Manhattan location to our Long Island location, maybe just a website or access to
+
+72
+00:04:19,000 --> 00:04:26,000
+a client that needs access to a client that needs to be installed, something like OpenVPN we also use
+
+73
+00:04:26,000 --> 00:04:29,000
+as a client, but things like Sonicwall.
+
+74
+00:04:30,000 --> 00:04:32,000
+Has SSL based VPNs.
+
+75
+00:04:32,000 --> 00:04:35,000
+And with that, I'm going to show you guys what that looks like.
+
+76
+00:04:35,000 --> 00:04:39,000
+There's a link there that you guys can try that I have already opened for you.
+
+77
+00:04:39,000 --> 00:04:41,000
+So when you went to that link.
+
+78
+00:04:42,000 --> 00:04:43,000
+Uh, I want to show you.
+
+79
+00:04:43,000 --> 00:04:44,000
+Oh, here we go.
+
+80
+00:04:44,000 --> 00:04:46,000
+So when you guys went to that link.
+
+81
+00:04:48,000 --> 00:04:50,000
+This is a demo of their SSL based VPN.
+
+82
+00:04:50,000 --> 00:04:55,000
+So you would just view the demo and it's going to log you into the VPN.
+
+83
+00:04:55,000 --> 00:04:58,000
+So this is actually what what it looks like.
+
+84
+00:04:58,000 --> 00:05:00,000
+It doesn't want to work here for us.
+
+85
+00:05:00,000 --> 00:05:03,000
+Hopefully this works for us.
+
+86
+00:05:04,000 --> 00:05:06,000
+All right demo let's log in.
+
+87
+00:05:06,000 --> 00:05:07,000
+You just demo.
+
+88
+00:05:07,000 --> 00:05:08,000
+And the password is like password.
+
+89
+00:05:08,000 --> 00:05:10,000
+It puts it there for you.
+
+90
+00:05:10,000 --> 00:05:11,000
+So this is a VPN.
+
+91
+00:05:11,000 --> 00:05:13,000
+This is an SSL based VPN.
+
+92
+00:05:13,000 --> 00:05:18,000
+And basically I have access to things like a file share on their network.
+
+93
+00:05:18,000 --> 00:05:21,000
+And I can go in and I can access particular files.
+
+94
+00:05:21,000 --> 00:05:25,000
+As you can see, uh, I can go in and, um.
+
+95
+00:05:26,000 --> 00:05:27,000
+What else more we have here.
+
+96
+00:05:27,000 --> 00:05:30,000
+RDP to a particular computer.
+
+97
+00:05:30,000 --> 00:05:33,000
+Let's say we know what is going to log me into one of their systems.
+
+98
+00:05:33,000 --> 00:05:37,000
+So now look, I'm logging in to a system on their network.
+
+99
+00:05:38,000 --> 00:05:40,000
+This is all done through the web browser, right?
+
+100
+00:05:40,000 --> 00:05:42,000
+This is all done.
+
+101
+00:05:42,000 --> 00:05:43,000
+This is a computer.
+
+102
+00:05:43,000 --> 00:05:43,000
+It's already logged in.
+
+103
+00:05:43,000 --> 00:05:45,000
+Is this that screen?
+
+104
+00:05:45,000 --> 00:05:45,000
+See?
+
+105
+00:05:46,000 --> 00:05:50,000
+Yeah, it's a really old system that Sonic was given the demo on old server here.
+
+106
+00:05:50,000 --> 00:05:52,000
+So let me close this out.
+
+107
+00:05:53,000 --> 00:05:55,000
+So you can access Outlook Web access.
+
+108
+00:05:55,000 --> 00:05:58,000
+So it's just a demo that you can set up.
+
+109
+00:05:58,000 --> 00:06:00,000
+Now this is great.
+
+110
+00:06:00,000 --> 00:06:05,000
+If you set up a VPN like this, there's really nothing for no one to install.
+
+111
+00:06:05,000 --> 00:06:11,000
+It's heavily secured because it runs on TLS, which is pretty much the standards of all internet security.
+
+112
+00:06:11,000 --> 00:06:17,000
+Now let's talk of another kind of implementation we can implement.
+
+113
+00:06:17,000 --> 00:06:20,000
+And that's going to be what's called L2 Tpns.
+
+114
+00:06:20,000 --> 00:06:25,000
+L2 Tpns are layer two tunneling protocol.
+
+115
+00:06:25,000 --> 00:06:32,000
+These are kind of VPNs that were basically a hybrid of what was called L2 f and an older one called
+
+116
+00:06:32,000 --> 00:06:32,000
+PCP.
+
+117
+00:06:33,000 --> 00:06:34,000
+It's basically a point to point tunnel.
+
+118
+00:06:34,000 --> 00:06:40,000
+And it utilizes something called IPsec in order to encrypt your data, which we'll talk about in a minute.
+
+119
+00:06:40,000 --> 00:06:47,000
+It supports all types of radius are used on like windows boxes or Texas for, uh, Cisco boxes.
+
+120
+00:06:47,000 --> 00:06:51,000
+Now, IPsec is something you want to be familiar with for your exam.
+
+121
+00:06:51,000 --> 00:06:58,000
+Instead of using something such as TLS to secure your VPN, you can use IPsec.
+
+122
+00:06:58,000 --> 00:07:01,000
+IPsec is a standalone VPN protocol.
+
+123
+00:07:01,000 --> 00:07:09,000
+It's the main security anytime you set up L2tpv3, L2, TCP based VPNs, which you could do on my Sonicwall,
+
+124
+00:07:09,000 --> 00:07:11,000
+you're going to use IPsec.
+
+125
+00:07:11,000 --> 00:07:16,000
+IPsec comes in a variety of different components that you want to be familiar with for your exam.
+
+126
+00:07:16,000 --> 00:07:18,000
+If you're asking, what the hell is all this?
+
+127
+00:07:18,000 --> 00:07:26,000
+Well, when you set it up on the firewall on your VPN devices, particularly things like VPN concentrators,
+
+128
+00:07:26,000 --> 00:07:32,000
+when you set these things up, like on a VPN concentrator, especially IPsec, you have to determine,
+
+129
+00:07:32,000 --> 00:07:35,000
+do you want to set it up with RH or ESP?
+
+130
+00:07:35,000 --> 00:07:40,000
+Ideally, you'll do both RH if you configure this, provides authentication.
+
+131
+00:07:41,000 --> 00:07:44,000
+Integrity and non-repudiation of the data.
+
+132
+00:07:44,000 --> 00:07:48,000
+That's important because you don't want anybody to log in authentication.
+
+133
+00:07:48,000 --> 00:07:52,000
+You want to check if the data was modified and you want to be verified where the data is coming from.
+
+134
+00:07:53,000 --> 00:07:57,000
+E does not support, uh, encryption of the data.
+
+135
+00:07:57,000 --> 00:08:02,000
+It doesn't support confidentiality of data that's going to be encapsulating security payload.
+
+136
+00:08:02,000 --> 00:08:03,000
+So make sure you enable both boxes.
+
+137
+00:08:03,000 --> 00:08:06,000
+In fact, when you set up a VPN, these two are enabled by default.
+
+138
+00:08:06,000 --> 00:08:16,000
+Now also when you set up these kinds of firewalls, uh, VPNs, especially in IPsec, it runs in two
+
+139
+00:08:16,000 --> 00:08:19,000
+modes tunnel mode and transport mode.
+
+140
+00:08:19,000 --> 00:08:20,000
+In tunnel mode.
+
+141
+00:08:20,000 --> 00:08:25,000
+What's happening here is that it's it's protecting the IP header.
+
+142
+00:08:25,000 --> 00:08:29,000
+Notice this green box right here the IP header I could just highlight it.
+
+143
+00:08:29,000 --> 00:08:34,000
+It protects the IP header and trailer and the payload being the data.
+
+144
+00:08:35,000 --> 00:08:43,000
+It encapsulates everything an IP header includes, like the source IP and destination IP in transport
+
+145
+00:08:43,000 --> 00:08:45,000
+mode is just the payload that's being detected.
+
+146
+00:08:45,000 --> 00:08:47,000
+The final destination is visible.
+
+147
+00:08:47,000 --> 00:08:55,000
+So if you're going across a network where you control all the routers so it can encrypt and decrypt
+
+148
+00:08:55,000 --> 00:08:59,000
+the packet at every one of the routers, then it's okay to use tunnel mode.
+
+149
+00:08:59,000 --> 00:09:03,000
+But if it has to go across a network that you can't control, you're probably going to set it up in
+
+150
+00:09:03,000 --> 00:09:05,000
+transport mode.
+
+151
+00:09:05,000 --> 00:09:06,000
+Now.
+
+152
+00:09:07,000 --> 00:09:10,000
+When it comes to setting up a VPN.
+
+153
+00:09:10,000 --> 00:09:12,000
+In today's world.
+
+154
+00:09:12,000 --> 00:09:18,000
+As of right now, as I speak to you, more and more VPNs are being deployed with TLS setup, and the
+
+155
+00:09:18,000 --> 00:09:23,000
+reason for that is because TLS doesn't require you to open a bunch of ports.
+
+156
+00:09:23,000 --> 00:09:29,000
+Like if you want to set up an L2, TCP based VPN, it's much easier to configure and more familiar to
+
+157
+00:09:29,000 --> 00:09:30,000
+users.
+
+158
+00:09:30,000 --> 00:09:35,000
+And just like you saw with the Sonicwall, you could pretty much run it off of your browser versus L2.
+
+159
+00:09:35,000 --> 00:09:40,000
+TCP based VPNs almost always have to have you install a client on the machine.
+
+160
+00:09:40,000 --> 00:09:43,000
+That client needs to be configured.
+
+161
+00:09:43,000 --> 00:09:49,000
+Different types of L2, TCP, or VPN keys needs to be set up on the machine, so it's much more of an
+
+162
+00:09:49,000 --> 00:09:54,000
+administrative work if you control the machines like the clients, like the clients that people are
+
+163
+00:09:54,000 --> 00:09:57,000
+using at home is owned by the company.
+
+164
+00:09:57,000 --> 00:09:59,000
+The company sets it up and they can't do anything on that machine.
+
+165
+00:09:59,000 --> 00:10:00,000
+But companies work.
+
+166
+00:10:00,000 --> 00:10:03,000
+Then it's probably okay to use an L2, TCP based VPN.
+
+167
+00:10:03,000 --> 00:10:10,000
+If not, if people are working from home and they're utilizing their own machine, the best thing to
+
+168
+00:10:10,000 --> 00:10:14,000
+do is use a TLS or SSL VPN.
+
diff --git a/11 - Security Principles/015 SD-WAN OB 3.2_en.srt b/11 - Security Principles/015 SD-WAN OB 3.2_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..af1577e1af867dc53cefcc03414aa2d7121ece1f
--- /dev/null
+++ b/11 - Security Principles/015 SD-WAN OB 3.2_en.srt
@@ -0,0 +1,228 @@
+1
+00:00:00,000 --> 00:00:04,000
+In today's world, networking is becoming crazy complex.
+
+2
+00:00:04,000 --> 00:00:10,000
+You see, back in the days when you worked in a large network, you had generally one data center that
+
+3
+00:00:10,000 --> 00:00:14,000
+the company controlled and all the other branch offices would connect to it.
+
+4
+00:00:15,000 --> 00:00:18,000
+But today it's a lot complex.
+
+5
+00:00:18,000 --> 00:00:19,000
+And I want to show you a diagram.
+
+6
+00:00:20,000 --> 00:00:25,000
+Now I want you guys to forget all the connection into the cloud for now.
+
+7
+00:00:25,000 --> 00:00:30,000
+I want you guys just to look at this thing here with just where it says data center.
+
+8
+00:00:30,000 --> 00:00:36,000
+Back in the days when we had set up networks, what we would do is we would just have every branch would
+
+9
+00:00:36,000 --> 00:00:43,000
+connect to the data center, like this branch here would connect to the data center, this branch data
+
+10
+00:00:43,000 --> 00:00:45,000
+center, this branch data center, this branch, this branch, this branch.
+
+11
+00:00:46,000 --> 00:00:48,000
+And everything was like a centralized thing.
+
+12
+00:00:49,000 --> 00:00:52,000
+But now it's all over the place.
+
+13
+00:00:52,000 --> 00:01:00,000
+Right now the applications are in the cloud all over, split across different cloud based systems.
+
+14
+00:01:00,000 --> 00:01:06,000
+The applications are stored partially in the data center and partially in the cloud.
+
+15
+00:01:06,000 --> 00:01:08,000
+Now branch offices are going to the cloud.
+
+16
+00:01:08,000 --> 00:01:10,000
+They're also going to the data center.
+
+17
+00:01:10,000 --> 00:01:12,000
+Some of the app is in the cloud.
+
+18
+00:01:12,000 --> 00:01:14,000
+Some of it is in the data center.
+
+19
+00:01:14,000 --> 00:01:17,000
+Some of the policies in the data center, some of the policy in the cloud.
+
+20
+00:01:17,000 --> 00:01:20,000
+This can get complex very fast, very quick.
+
+21
+00:01:20,000 --> 00:01:22,000
+So there's a couple of things here.
+
+22
+00:01:23,000 --> 00:01:26,000
+Let's talk about software defined networking.
+
+23
+00:01:26,000 --> 00:01:35,000
+Software defined networking is basically to simplify a branch office networking and get optimal application
+
+24
+00:01:35,000 --> 00:01:36,000
+performance.
+
+25
+00:01:36,000 --> 00:01:42,000
+It provides a centralized control function to securely and intelligently intelligently transfer network
+
+26
+00:01:42,000 --> 00:01:43,000
+traffic.
+
+27
+00:01:43,000 --> 00:01:46,000
+What I need you guys to know for your exam is this.
+
+28
+00:01:46,000 --> 00:01:52,000
+This thing overlays your network and what it does is that it's going to allow for efficient network,
+
+29
+00:01:52,000 --> 00:02:01,000
+um, traffic that allows applications to be used correctly and efficiently, making data routing more
+
+30
+00:02:01,000 --> 00:02:02,000
+efficient.
+
+31
+00:02:02,000 --> 00:02:06,000
+You see, if we don't have this, the data routing would be all over the.
+
+32
+00:02:06,000 --> 00:02:10,000
+They would have to go and pull some of the data from the cloud and pull it, some of it from the data
+
+33
+00:02:10,000 --> 00:02:10,000
+center.
+
+34
+00:02:11,000 --> 00:02:17,000
+Another thing you want to have in here when you set this up is sassy SASE.
+
+35
+00:02:17,000 --> 00:02:20,000
+It stands for Secure Access Service Edge.
+
+36
+00:02:20,000 --> 00:02:22,000
+This is a cloud native network and architect.
+
+37
+00:02:22,000 --> 00:02:26,000
+It combines network security functions with Wan capability.
+
+38
+00:02:26,000 --> 00:02:31,000
+It merges the SD SD-Wan capabilities with security services.
+
+39
+00:02:31,000 --> 00:02:32,000
+What is it doing?
+
+40
+00:02:32,000 --> 00:02:38,000
+Well, this is going to allow those tunnels that you see between those connections to become encrypted,
+
+41
+00:02:38,000 --> 00:02:41,000
+to connect them to cloud based services, to make them more efficient.
+
+42
+00:02:41,000 --> 00:02:44,000
+So let's go back here and talk more about this.
+
+43
+00:02:45,000 --> 00:02:47,000
+So when you set up things like SD-Wan.
+
+44
+00:02:47,000 --> 00:02:53,000
+SD-Wan is going to allow you to efficiently utilize all types of network connections.
+
+45
+00:02:55,000 --> 00:02:57,000
+All types of multiple connections.
+
+46
+00:02:57,000 --> 00:03:02,000
+So imagine you're sitting in this branch office and you need to access some of the applications in the
+
+47
+00:03:02,000 --> 00:03:04,000
+cloud, some of it in the data center.
+
+48
+00:03:04,000 --> 00:03:06,000
+Applications can even be split apart.
+
+49
+00:03:06,000 --> 00:03:10,000
+Now you have SD-Wan, comes in, sets up a variety.
+
+50
+00:03:10,000 --> 00:03:16,000
+It's it's a type of software defined networking or Sdn that allows it.
+
+51
+00:03:16,000 --> 00:03:21,000
+It's basically a higher controller level that sits over all these connections and determines the best,
+
+52
+00:03:21,000 --> 00:03:25,000
+most efficient and secure path to get through the data.
+
+53
+00:03:25,000 --> 00:03:27,000
+If you're wondering, why do we do all this?
+
+54
+00:03:27,000 --> 00:03:34,000
+Well, imagine right now how complex networking is without getting too technical and in depth into it,
+
+55
+00:03:34,000 --> 00:03:36,000
+because you don't need it basically for your exam.
+
+56
+00:03:36,000 --> 00:03:38,000
+What this really is going to allow you to do?
+
+57
+00:03:39,000 --> 00:03:44,000
+All the apps the company is using is is going to make it faster and more secure to use.
+
diff --git a/11 - Security Principles/016 Selecting Effective Controls OB 3.2_en.srt b/11 - Security Principles/016 Selecting Effective Controls OB 3.2_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..2ac01090d2db1f0521d544b542768b2e6a20ffe9
--- /dev/null
+++ b/11 - Security Principles/016 Selecting Effective Controls OB 3.2_en.srt
@@ -0,0 +1,400 @@
+1
+00:00:00,000 --> 00:00:07,000
+So far we have seen quite a lot of different security security network appliances that we can implement.
+
+2
+00:00:07,000 --> 00:00:13,000
+But there's a couple of things that we got to think about selecting the effective controls, selecting
+
+3
+00:00:13,000 --> 00:00:21,000
+the right amount of security to apply to a network, selecting the right device that we have to put
+
+4
+00:00:21,000 --> 00:00:28,000
+in our network, selecting the right configuration that we put onto these devices.
+
+5
+00:00:28,000 --> 00:00:31,000
+So in this video we want to talk about selecting effective controls.
+
+6
+00:00:31,000 --> 00:00:36,000
+What is the process of identifying and implementing the right security measure for your organization.
+
+7
+00:00:37,000 --> 00:00:40,000
+Now this is going to get very complex.
+
+8
+00:00:40,000 --> 00:00:43,000
+Every single organization is built differently.
+
+9
+00:00:43,000 --> 00:00:45,000
+Every organization has assets of different value.
+
+10
+00:00:45,000 --> 00:00:48,000
+Every organization values assets differently.
+
+11
+00:00:48,000 --> 00:00:53,000
+Some organization doesn't have much value on their data on their.
+
+12
+00:00:53,000 --> 00:00:54,000
+Because you know why?
+
+13
+00:00:54,000 --> 00:00:56,000
+Well, maybe some of the employee data.
+
+14
+00:00:56,000 --> 00:01:00,000
+But the company's main data don't really put a value on because it's all public knowledge.
+
+15
+00:01:00,000 --> 00:01:01,000
+Think of like a.
+
+16
+00:01:02,000 --> 00:01:03,000
+Like something on.
+
+17
+00:01:03,000 --> 00:01:04,000
+If you're managing Wikipedia.
+
+18
+00:01:04,000 --> 00:01:08,000
+All the data that Wikipedia have, it's pretty much public data.
+
+19
+00:01:08,000 --> 00:01:13,000
+The only thing that's private is their credit card information that they collect and the employee resources.
+
+20
+00:01:13,000 --> 00:01:16,000
+But if you work for the military, it's vastly different.
+
+21
+00:01:16,000 --> 00:01:23,000
+Everything there, most of it, especially like in the NSA, it's all private or top secret information
+
+22
+00:01:23,000 --> 00:01:24,000
+versus Wikipedia.
+
+23
+00:01:24,000 --> 00:01:31,000
+90% of what they collect is public data, vast differences between organization and what they value,
+
+24
+00:01:31,000 --> 00:01:33,000
+vast differences on how they value it.
+
+25
+00:01:33,000 --> 00:01:38,000
+So when you select security controls, these are things you have to consider.
+
+26
+00:01:38,000 --> 00:01:42,000
+And that starts with a risk assessment starts with a thorough risk assessment.
+
+27
+00:01:42,000 --> 00:01:49,000
+What exactly identify what exact risks do you guys face and how do you want to mitigate those potential
+
+28
+00:01:49,000 --> 00:01:50,000
+threats?
+
+29
+00:01:51,000 --> 00:01:54,000
+I mentioned at the beginning of this course Layered Defense.
+
+30
+00:01:55,000 --> 00:01:57,000
+You have to implement a variety of different controls.
+
+31
+00:01:57,000 --> 00:01:59,000
+No single point.
+
+32
+00:02:00,000 --> 00:02:00,000
+All right.
+
+33
+00:02:00,000 --> 00:02:01,000
+No single.
+
+34
+00:02:01,000 --> 00:02:02,000
+Everything needs layered.
+
+35
+00:02:02,000 --> 00:02:03,000
+Layered approach.
+
+36
+00:02:03,000 --> 00:02:07,000
+And what you should be consideration is what are the different layers.
+
+37
+00:02:07,000 --> 00:02:08,000
+How are you going to layer them?
+
+38
+00:02:08,000 --> 00:02:13,000
+You may have cameras in different locations and maybe you need security guard and cameras.
+
+39
+00:02:13,000 --> 00:02:19,000
+Maybe you you have particularly, uh, doors that are built a certain way and you don't have security
+
+40
+00:02:19,000 --> 00:02:21,000
+guards, things to consider.
+
+41
+00:02:21,000 --> 00:02:28,000
+But if there's one thing I know, but living long enough in this world, a lot of times the consideration
+
+42
+00:02:28,000 --> 00:02:31,000
+may come to selecting the right controls for your business.
+
+43
+00:02:31,000 --> 00:02:36,000
+Unfortunately, almost always comes back to money.
+
+44
+00:02:37,000 --> 00:02:38,000
+Evaluating the course.
+
+45
+00:02:38,000 --> 00:02:42,000
+What is the cost of implementing a control against the potential risk benefit that is given?
+
+46
+00:02:43,000 --> 00:02:48,000
+If there's one thing we're going to talk about when we get to a risk assessment is can't spend $10,
+
+47
+00:02:48,000 --> 00:02:51,000
+protecting $5 doesn't make sense.
+
+48
+00:02:51,000 --> 00:02:58,000
+A lot of times, the control that we select, the kind of firewall that we implement, the kind of IDs
+
+49
+00:02:58,000 --> 00:03:06,000
+that we put into place, um, whether we have a load balancer, the type of VPN we set up, a lot of
+
+50
+00:03:06,000 --> 00:03:08,000
+these things are going to be determined basically.
+
+51
+00:03:08,000 --> 00:03:09,000
+And do you have the budget for it?
+
+52
+00:03:09,000 --> 00:03:10,000
+Yeah.
+
+53
+00:03:10,000 --> 00:03:16,000
+We all want the latest and greatest engine firewall, but we can't afford it because it's super expensive.
+
+54
+00:03:16,000 --> 00:03:19,000
+So you have to be able to understand that cost is a big thing.
+
+55
+00:03:19,000 --> 00:03:24,000
+Another thing that you have to really keep in consideration is regulation.
+
+56
+00:03:24,000 --> 00:03:30,000
+Certain regulations will make it mandatory for you to encrypt and store certain data in a certain way.
+
+57
+00:03:30,000 --> 00:03:35,000
+For example, in HIPAA regulation, you're going to have to secure a certain medical records.
+
+58
+00:03:35,000 --> 00:03:37,000
+If you follow PCI compliance.
+
+59
+00:03:37,000 --> 00:03:41,000
+This is a kind of a standard that you're going to have to encrypt credit card information.
+
+60
+00:03:41,000 --> 00:03:47,000
+So the controls you select their technical stability, assessing the technical capability of feasibilities
+
+61
+00:03:47,000 --> 00:03:47,000
+controls.
+
+62
+00:03:47,000 --> 00:03:49,000
+Can you even implement it?
+
+63
+00:03:49,000 --> 00:03:55,000
+Does your environment even support a particular control that you want to implement every time you implement
+
+64
+00:03:55,000 --> 00:03:59,000
+a particular risk, maybe a new kind of firewall or a load balancer or something?
+
+65
+00:04:00,000 --> 00:04:07,000
+You know it identifies more risk into the organization's control, should be directly relevant for the
+
+66
+00:04:07,000 --> 00:04:09,000
+risk that they're implementing does.
+
+67
+00:04:10,000 --> 00:04:16,000
+And the other thing is that if you implement this control, does it result in reducing a particular
+
+68
+00:04:16,000 --> 00:04:18,000
+risk, the risk of hackers breaking in?
+
+69
+00:04:18,000 --> 00:04:19,000
+So you put a firewall in place.
+
+70
+00:04:19,000 --> 00:04:21,000
+Does the firewall address that?
+
+71
+00:04:22,000 --> 00:04:27,000
+The risk of a worm spreading around inside of a network.
+
+72
+00:04:27,000 --> 00:04:28,000
+Does the firewall address that?
+
+73
+00:04:28,000 --> 00:04:32,000
+Well, network firewalls generally is not going to stop a worm from spreading around inside of the network
+
+74
+00:04:32,000 --> 00:04:33,000
+if it's already there.
+
+75
+00:04:33,000 --> 00:04:35,000
+Host based firewalls does.
+
+76
+00:04:35,000 --> 00:04:42,000
+So you have to make sure that the what you're implementing addresses that risk stability and adaptability.
+
+77
+00:04:42,000 --> 00:04:44,000
+Controls should be able to scale with the company.
+
+78
+00:04:44,000 --> 00:04:52,000
+Don't buy a particular appliance, and it's only good for 100 users in the company right now is at 80,
+
+79
+00:04:52,000 --> 00:04:53,000
+and it's going to go to 200in a few months.
+
+80
+00:04:53,000 --> 00:04:54,000
+That's not scalable.
+
+81
+00:04:55,000 --> 00:05:01,000
+Always evaluate regular monitor, review and update these types of controls for effectiveness is going
+
+82
+00:05:01,000 --> 00:05:02,000
+to be important.
+
+83
+00:05:02,000 --> 00:05:04,000
+Monitor your environment.
+
+84
+00:05:05,000 --> 00:05:15,000
+If there's one thing we know in it that sometimes I can't stand is the constant nonstop change of technology,
+
+85
+00:05:15,000 --> 00:05:21,000
+such as different kinds of software, hardware, different kinds of attacks that comes out, pushes
+
+86
+00:05:21,000 --> 00:05:26,000
+us to consistently modify and change the technology that we work in.
+
+87
+00:05:27,000 --> 00:05:28,000
+Our environments will change.
+
+88
+00:05:28,000 --> 00:05:35,000
+Whatever it secure environment that you're working in right now will not will cease to exist and completely
+
+89
+00:05:35,000 --> 00:05:38,000
+do a major change.
+
+90
+00:05:39,000 --> 00:05:45,000
+I guarantee you, within the next 5 to 8 years on on a general rotation, every 5 to 8 years, the whole
+
+91
+00:05:45,000 --> 00:05:46,000
+thing will change.
+
+92
+00:05:46,000 --> 00:05:51,000
+All technology changes, all the operating systems will change, all the devices will change.
+
+93
+00:05:51,000 --> 00:05:55,000
+For example, Sonicwall is not going to allow us to keep using this particular device because they're
+
+94
+00:05:55,000 --> 00:05:56,000
+going to say it's outdated.
+
+95
+00:05:56,000 --> 00:05:57,000
+We'll have to get a new one.
+
+96
+00:05:58,000 --> 00:06:04,000
+So the and a consistent changes is the control effective new attacks will come out.
+
+97
+00:06:04,000 --> 00:06:05,000
+And then what are you going to do.
+
+98
+00:06:05,000 --> 00:06:09,000
+You're going to have to update your devices, update your software.
+
+99
+00:06:09,000 --> 00:06:13,000
+If there's one thing that's a constant when it managing security.
+
+100
+00:06:13,000 --> 00:06:19,000
+One thing that's that's a constant when managing security uh, is change.
+
diff --git a/11 - Security Principles/017 Quick Quiz.html b/11 - Security Principles/017 Quick Quiz.html
new file mode 100644
index 0000000000000000000000000000000000000000..3d98d1bdfb03561bac229c500139a327759ee18c
--- /dev/null
+++ b/11 - Security Principles/017 Quick Quiz.html
@@ -0,0 +1,479 @@
+
+
+
+
+
+
+ Quiz
+
+
+
+
+
+
+
+
+ Score: 999 of
+ 999%
+
+ Correct: 999
+ Incorrect: 999
+
+
+
+
+
+
+
+
+
+
diff --git a/12 - Data Protection/001 Regulated Data OB 3.3_en.srt b/12 - Data Protection/001 Regulated Data OB 3.3_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..20eb27da53adbba68f26007dd1133de1ee3de11c
--- /dev/null
+++ b/12 - Data Protection/001 Regulated Data OB 3.3_en.srt
@@ -0,0 +1,148 @@
+1
+00:00:00,000 --> 00:00:07,000
+Most organizations nowadays will follow some kind of regulations pertaining to the data that it collects.
+
+2
+00:00:07,000 --> 00:00:12,000
+In today's world, especially in the United States, we have tons of laws that we have to follow, whether
+
+3
+00:00:12,000 --> 00:00:18,000
+it's collecting medical information and having to follow HIPAA compliance, collecting credit card information,
+
+4
+00:00:18,000 --> 00:00:22,000
+and following things such as PCI standards now.
+
+5
+00:00:23,000 --> 00:00:26,000
+What happens is this is known as regulated data.
+
+6
+00:00:26,000 --> 00:00:32,000
+This includes data that's subject to all kinds of regulatory requirements, different kind of laws and
+
+7
+00:00:32,000 --> 00:00:34,000
+regulations, personal data.
+
+8
+00:00:34,000 --> 00:00:41,000
+So if you work in places, if you collect personal data and your organization does business or is located
+
+9
+00:00:41,000 --> 00:00:43,000
+in Europe, you'll have to follow GDPR.
+
+10
+00:00:44,000 --> 00:00:45,000
+Uh, in the United States.
+
+11
+00:00:45,000 --> 00:00:51,000
+Here we have things like HIPAA compliance where health health information and then financial data,
+
+12
+00:00:52,000 --> 00:00:55,000
+uh, for PCI compliance is going to be like credit card information.
+
+13
+00:00:55,000 --> 00:01:01,000
+Now, all of these laws here, uh, that are covered, we're going to be covering some of these laws
+
+14
+00:01:01,000 --> 00:01:03,000
+a little bit later in this course.
+
+15
+00:01:03,000 --> 00:01:04,000
+So hold on to that.
+
+16
+00:01:04,000 --> 00:01:09,000
+But for now we want to talk about how just that data is regulated.
+
+17
+00:01:09,000 --> 00:01:14,000
+Don't think that by collecting people's information, especially people's name, address, social security
+
+18
+00:01:14,000 --> 00:01:20,000
+number, health care information, like diseases, they may have, medications, they may be taken credit
+
+19
+00:01:20,000 --> 00:01:21,000
+card information.
+
+20
+00:01:21,000 --> 00:01:24,000
+This is all data that's going to be regulated.
+
+21
+00:01:24,000 --> 00:01:32,000
+In fact things that GDPR, the general data protection, this uh, things like GDPR, this is a this
+
+22
+00:01:32,000 --> 00:01:36,000
+is a this is basically a law that protects Europeans.
+
+23
+00:01:36,000 --> 00:01:36,000
+Okay.
+
+24
+00:01:36,000 --> 00:01:38,000
+Or the European Union citizens data.
+
+25
+00:01:38,000 --> 00:01:41,000
+Things like browsing information is what this collects.
+
+26
+00:01:41,000 --> 00:01:48,000
+So when you start collecting data on your users, you have to keep in mind that a lot of the data will
+
+27
+00:01:48,000 --> 00:01:54,000
+be subject to certain laws and regulations within the country that you're collecting that data from.
+
+28
+00:01:54,000 --> 00:01:59,000
+Compliance with these legal and regulatory standards are critical.
+
+29
+00:01:59,000 --> 00:02:05,000
+First of all, it will be against the law if you don't, and it's probably going to be mandatory.
+
+30
+00:02:05,000 --> 00:02:12,000
+This involves good security measurements, access control, and of course ensuring the privacy or confidentiality
+
+31
+00:02:12,000 --> 00:02:15,000
+and integrity of the data.
+
+32
+00:02:15,000 --> 00:02:22,000
+So don't think that you can just set up a business or don't think most companies can just go and set
+
+33
+00:02:22,000 --> 00:02:28,000
+up businesses, start collecting information and not worry about the laws that they should be following.
+
+34
+00:02:28,000 --> 00:02:35,000
+So make sure as a security professional, you are aware of what local laws within your country that
+
+35
+00:02:35,000 --> 00:02:38,000
+you should be following when it comes to data compliance.
+
+36
+00:02:38,000 --> 00:02:43,000
+And also if you're collecting data from overseas or you're doing business overseas from your country,
+
+37
+00:02:43,000 --> 00:02:46,000
+what laws you should be following there also.
+
diff --git a/12 - Data Protection/002 Intellectual Property OB 3.3_en.srt b/12 - Data Protection/002 Intellectual Property OB 3.3_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..13435af1412ec450b970fb60acf2e12e3fadcb58
--- /dev/null
+++ b/12 - Data Protection/002 Intellectual Property OB 3.3_en.srt
@@ -0,0 +1,696 @@
+1
+00:00:00,000 --> 00:00:08,000
+People and organizations in today's world create specific things such as invention, expression, such
+
+2
+00:00:08,000 --> 00:00:12,000
+as art, or expressions like write in a book.
+
+3
+00:00:12,000 --> 00:00:16,000
+These things that they create is valuable to them and is worth money to them.
+
+4
+00:00:17,000 --> 00:00:23,000
+In fact, I am an author and I wrote one of the world's best selling project management book, the PMP
+
+5
+00:00:23,000 --> 00:00:25,000
+Exam Prep Simplified.
+
+6
+00:00:25,000 --> 00:00:29,000
+Now, this particular book is an expression of me.
+
+7
+00:00:29,000 --> 00:00:31,000
+This particular book does bring me in an income.
+
+8
+00:00:31,000 --> 00:00:36,000
+And for anybody to steal my particular work would result in damages to me.
+
+9
+00:00:36,000 --> 00:00:41,000
+You see, organizations also have this problem, especially with people that create inventions.
+
+10
+00:00:41,000 --> 00:00:45,000
+If you make a unique invention that only you.
+
+11
+00:00:46,000 --> 00:00:48,000
+Uh, should be using in order to profit from that invention.
+
+12
+00:00:48,000 --> 00:00:50,000
+Because that is your idea.
+
+13
+00:00:50,000 --> 00:00:52,000
+You need to protect your invention.
+
+14
+00:00:52,000 --> 00:00:54,000
+I need to protect my expression.
+
+15
+00:00:54,000 --> 00:00:57,000
+You see, this is called intellectual property.
+
+16
+00:00:58,000 --> 00:00:59,000
+This is the creation.
+
+17
+00:00:59,000 --> 00:01:01,000
+This is creations of the mind.
+
+18
+00:01:01,000 --> 00:01:09,000
+Like inventions, literacy work, artistic work, design symbols and names that is used in commerce.
+
+19
+00:01:09,000 --> 00:01:16,000
+Now, in this video, I want to go through the different ways we can that we can use to protect our
+
+20
+00:01:16,000 --> 00:01:17,000
+intellectual property.
+
+21
+00:01:17,000 --> 00:01:17,000
+Our.
+
+22
+00:01:17,000 --> 00:01:21,000
+The organization thinks that copyrights and patents and trademarks.
+
+23
+00:01:21,000 --> 00:01:23,000
+That's what we're cover in this video.
+
+24
+00:01:23,000 --> 00:01:29,000
+IP theft can result in significant economic loss and competitive disadvantage.
+
+25
+00:01:29,000 --> 00:01:34,000
+Now, if this is something that I have personal experience with because I have personally experienced
+
+26
+00:01:34,000 --> 00:01:41,000
+this, my study guide or my book was published on Amazon, and Amazon has exclusive rights as the only
+
+27
+00:01:41,000 --> 00:01:43,000
+distributor of the book.
+
+28
+00:01:44,000 --> 00:01:46,000
+After a couple of years and it was doing well.
+
+29
+00:01:46,000 --> 00:01:50,000
+All of a sudden we started having a seller that started to sell my book.
+
+30
+00:01:50,000 --> 00:01:51,000
+They were buying.
+
+31
+00:01:51,000 --> 00:01:55,000
+They were printing the book themselves and selling it on Amazon.
+
+32
+00:01:55,000 --> 00:01:59,000
+They were priced at Amazon, so people were buying their book and we didn't realize it for a while.
+
+33
+00:01:59,000 --> 00:02:03,000
+So we actually lost a significant amount of money due to IP theft.
+
+34
+00:02:03,000 --> 00:02:05,000
+This book is copyrighted.
+
+35
+00:02:05,000 --> 00:02:11,000
+Protection includes rights management, strict access control, even watermarking to trace and identify
+
+36
+00:02:11,000 --> 00:02:13,000
+unauthorized copies.
+
+37
+00:02:13,000 --> 00:02:15,000
+Now, the book does have a unique mark that we know.
+
+38
+00:02:15,000 --> 00:02:17,000
+If you copy it, we'll know.
+
+39
+00:02:17,000 --> 00:02:22,000
+So how does organizations protect their intellectual property?
+
+40
+00:02:22,000 --> 00:02:27,000
+Well, let's go through some of the most common ways that you're going to need to know for your exam.
+
+41
+00:02:27,000 --> 00:02:30,000
+The first one here I have is copyrights.
+
+42
+00:02:30,000 --> 00:02:37,000
+So copyrights are laws that protects against unauthorized duplication of an original creative work.
+
+43
+00:02:37,000 --> 00:02:41,000
+Now when people think of okay, what can I copyright?
+
+44
+00:02:41,000 --> 00:02:49,000
+Well, these are some of the things here that you can copyright, literacy work, musical work, uh,
+
+45
+00:02:49,000 --> 00:02:56,000
+all kinds of pictorial work like pictures, motion pictures, sound recordings, architectural work,
+
+46
+00:02:56,000 --> 00:02:59,000
+all of these are copyrightable.
+
+47
+00:02:59,000 --> 00:03:03,000
+Now I want to before I get into this, I want to make something clear.
+
+48
+00:03:03,000 --> 00:03:09,000
+The moment work is created, it is copyrighted.
+
+49
+00:03:10,000 --> 00:03:11,000
+There's two kinds of copyrights.
+
+50
+00:03:11,000 --> 00:03:13,000
+In the United States.
+
+51
+00:03:13,000 --> 00:03:17,000
+There is a regular copyright, and then there's a registered copyright.
+
+52
+00:03:18,000 --> 00:03:25,000
+The moment you have an idea of an expression of some kind and you draw it on a piece of paper, or you
+
+53
+00:03:25,000 --> 00:03:29,000
+write it down on a piece of paper, it is automatically copyrighted.
+
+54
+00:03:29,000 --> 00:03:32,000
+You do not need to register it.
+
+55
+00:03:33,000 --> 00:03:40,000
+Now, if you feel that this work will be public, will be on the public shelves, such as a book on
+
+56
+00:03:40,000 --> 00:03:45,000
+Amazon, or you're going to be selling this picture online, or it's going to be like a motion picture
+
+57
+00:03:45,000 --> 00:03:49,000
+where everybody's going to be seeing it, or it's going to be some kind of play or something like that,
+
+58
+00:03:50,000 --> 00:03:52,000
+then it's best to get it registered.
+
+59
+00:03:52,000 --> 00:03:58,000
+A registered copyright is when you go to your copyright office, like we do here in the United States,
+
+60
+00:03:58,000 --> 00:04:01,000
+and we submit the work to the Copyright Office.
+
+61
+00:04:01,000 --> 00:04:02,000
+And we claim that that is our work.
+
+62
+00:04:02,000 --> 00:04:09,000
+The Copyright Office then puts a stamp on it that says, as of this day, Bob says this is his work.
+
+63
+00:04:09,000 --> 00:04:14,000
+They actually don't check to see if anybody else owns it, but they're just saying that that it is there.
+
+64
+00:04:15,000 --> 00:04:16,000
+Now, why do we want to register?
+
+65
+00:04:16,000 --> 00:04:18,000
+What's the benefit of registration?
+
+66
+00:04:18,000 --> 00:04:23,000
+When you register a copyright, it's the only time you can actually bring lawsuits against people.
+
+67
+00:04:23,000 --> 00:04:24,000
+So if anybody.
+
+68
+00:04:24,000 --> 00:04:30,000
+So let's say you wrote something down on a copyright and somebody else stole your idea and you're sure
+
+69
+00:04:30,000 --> 00:04:32,000
+of it, you can't sue them yet.
+
+70
+00:04:32,000 --> 00:04:33,000
+You have to go and register it.
+
+71
+00:04:33,000 --> 00:04:34,000
+Then you can sue them.
+
+72
+00:04:34,000 --> 00:04:35,000
+So it's best to do it right away.
+
+73
+00:04:36,000 --> 00:04:42,000
+Uh, also, you're entitled to all kinds of different damages in case somebody steals your copyright.
+
+74
+00:04:42,000 --> 00:04:43,000
+This is not a law course.
+
+75
+00:04:43,000 --> 00:04:48,000
+I'm not going to get into the specifics, but if you do have work that are made, publish, go and register
+
+76
+00:04:48,000 --> 00:04:48,000
+it.
+
+77
+00:04:48,000 --> 00:04:49,000
+Registry.
+
+78
+00:04:50,000 --> 00:04:51,000
+Registering a copyright.
+
+79
+00:04:51,000 --> 00:04:53,000
+It's actually something that is very easy.
+
+80
+00:04:53,000 --> 00:04:54,000
+I did it myself online.
+
+81
+00:04:54,000 --> 00:04:55,000
+It takes about ten minutes.
+
+82
+00:04:55,000 --> 00:04:57,000
+Do not pay companies to do it.
+
+83
+00:04:57,000 --> 00:05:01,000
+And I think I paid about $40 to register the book, so keep that in mind.
+
+84
+00:05:01,000 --> 00:05:03,000
+It's not difficult.
+
+85
+00:05:03,000 --> 00:05:05,000
+Now remember remember what I'm talking about.
+
+86
+00:05:05,000 --> 00:05:09,000
+Copyrights does not have to be registered to have the protection.
+
+87
+00:05:09,000 --> 00:05:12,000
+The protection we're talking about is right here.
+
+88
+00:05:12,000 --> 00:05:16,000
+So remember a copyright is an expression of idea or resources.
+
+89
+00:05:16,000 --> 00:05:22,000
+Authors can control how whoever owns the copyright controls how the work is distributed, reproduced
+
+90
+00:05:22,000 --> 00:05:23,000
+and used now.
+
+91
+00:05:24,000 --> 00:05:28,000
+Copyrights are valid for very long periods of time.
+
+92
+00:05:28,000 --> 00:05:36,000
+It's valid generally for 70 years after the death of the last remaining author, unless it's work for
+
+93
+00:05:36,000 --> 00:05:36,000
+hire.
+
+94
+00:05:36,000 --> 00:05:44,000
+So work for hire is this work for hire is when somebody hires you to create work for an organization.
+
+95
+00:05:44,000 --> 00:05:48,000
+So if you go to a company and you wrote procedures and policies, that's called work for hire, work
+
+96
+00:05:48,000 --> 00:05:49,000
+for hire.
+
+97
+00:05:49,000 --> 00:05:56,000
+An anonymous works are protected for 95 years from the date of the first publication of 120 days from
+
+98
+00:05:56,000 --> 00:05:58,000
+the date of creation, which one ever is shortest?
+
+99
+00:05:58,000 --> 00:06:03,000
+If it was published dated, it's 95 years or it's 120 years.
+
+100
+00:06:04,000 --> 00:06:09,000
+So let's say you're a bad person and you want to steal my book, right?
+
+101
+00:06:09,000 --> 00:06:10,000
+My PMP study guide.
+
+102
+00:06:10,000 --> 00:06:17,000
+Well, if you want to steal it well or use it, I'm going to sue you because I have the legal copyright.
+
+103
+00:06:17,000 --> 00:06:22,000
+But if you want to wait for the copyright to expire to republish the work, you have to wait.
+
+104
+00:06:22,000 --> 00:06:26,000
+You have to wait for me to die and then you have to wait 70 years.
+
+105
+00:06:27,000 --> 00:06:31,000
+Penalties can penalties is going to be up to $1.1 million in damages.
+
+106
+00:06:31,000 --> 00:06:31,000
+Now.
+
+107
+00:06:31,000 --> 00:06:34,000
+This number can change depending on when you're watching this video.
+
+108
+00:06:34,000 --> 00:06:36,000
+Ten years in prison now.
+
+109
+00:06:37,000 --> 00:06:41,000
+This is copyright and these are things that are copyrightable that I have here.
+
+110
+00:06:41,000 --> 00:06:47,000
+Now, the other thing here that we can use to protect our IP is going to be trademarks.
+
+111
+00:06:47,000 --> 00:06:55,000
+Trademarks protect words, names, symbols, sounds, shapes, colors, musical tones or a combination.
+
+112
+00:06:56,000 --> 00:07:01,000
+Uh, they protect someone from stealing another person's quote unquote look and feel.
+
+113
+00:07:01,000 --> 00:07:04,000
+The primary purpose is to avoid confusion in the marketplace.
+
+114
+00:07:04,000 --> 00:07:06,000
+This protects intellectual property.
+
+115
+00:07:06,000 --> 00:07:12,000
+The good thing with trademarks is that they're valid, unlike a copyright, which generally, when I
+
+116
+00:07:12,000 --> 00:07:16,000
+die, it's 70 years technically trademarks, you can keep renewing it over and over.
+
+117
+00:07:16,000 --> 00:07:18,000
+They're valid for ten years with unlimited renewal.
+
+118
+00:07:19,000 --> 00:07:19,000
+Um.
+
+119
+00:07:20,000 --> 00:07:22,000
+On unlimited.
+
+120
+00:07:22,000 --> 00:07:27,000
+You can renew an unlimited number of times, so you can keep renewing that over and over and over.
+
+121
+00:07:27,000 --> 00:07:29,000
+Now, what are things that are going to be trademarked?
+
+122
+00:07:29,000 --> 00:07:32,000
+Lots of things that are trademark are generally things like symbols.
+
+123
+00:07:32,000 --> 00:07:37,000
+The Technical Institute of America, if you look at our name and symbols, those are all trademarks.
+
+124
+00:07:37,000 --> 00:07:41,000
+We own the trademark to the Technical Institute of America.
+
+125
+00:07:41,000 --> 00:07:44,000
+The the the actual company's name.
+
+126
+00:07:44,000 --> 00:07:48,000
+The Technical Institute of America is a trademark name.
+
+127
+00:07:48,000 --> 00:07:52,000
+The symbol of itself, the shield that we use is also trademarked.
+
+128
+00:07:52,000 --> 00:07:56,000
+This helps to ensure that we protect our brand.
+
+129
+00:07:56,000 --> 00:08:01,000
+Many, many companies are trademarking their content, their brands, their logo.
+
+130
+00:08:01,000 --> 00:08:04,000
+How do you know when you see a particular logo?
+
+131
+00:08:04,000 --> 00:08:07,000
+You might see a little circle that says TM on it.
+
+132
+00:08:07,000 --> 00:08:10,000
+If you see a little circle with a C with a circle, that's a copyright.
+
+133
+00:08:11,000 --> 00:08:13,000
+Now the other one here you have is patents.
+
+134
+00:08:13,000 --> 00:08:15,000
+If you have an invention.
+
+135
+00:08:16,000 --> 00:08:21,000
+Unique invention that you have invented to help the world progress.
+
+136
+00:08:21,000 --> 00:08:25,000
+You're going to get exclusive use of your invention if you patent your invention.
+
+137
+00:08:25,000 --> 00:08:31,000
+So patent protects the right of inventors and their inventions, protection of those who have legal
+
+138
+00:08:31,000 --> 00:08:32,000
+ownership of the patent.
+
+139
+00:08:33,000 --> 00:08:37,000
+The invention, must be new, must be useful, and must not be obvious.
+
+140
+00:08:37,000 --> 00:08:42,000
+The owner has exclusive control of the invention for 20 years.
+
+141
+00:08:42,000 --> 00:08:47,000
+After that it goes to the public domain and anyone can produce your work.
+
+142
+00:08:47,000 --> 00:08:52,000
+This is why when organizations like drug companies first make a drug that they've spent billions of
+
+143
+00:08:52,000 --> 00:08:58,000
+dollars producing, they have about 20 years because they have patent that formula for that drug to
+
+144
+00:08:58,000 --> 00:09:02,000
+sell it as much as they want so they can recuperate their costs.
+
+145
+00:09:02,000 --> 00:09:06,000
+And after that it becomes a generic medication, and then anyone can take the formula.
+
+146
+00:09:08,000 --> 00:09:16,000
+Another thing that you want to protect is the secret recipe to the McDonald's Big Mac sauce, or the
+
+147
+00:09:16,000 --> 00:09:20,000
+secret recipe to KFC's fried chicken.
+
+148
+00:09:21,000 --> 00:09:22,000
+It's coming up to lunch time.
+
+149
+00:09:22,000 --> 00:09:26,000
+It's actually around 11:00 in the morning, so I'm thinking about I could use a Big Mac right now.
+
+150
+00:09:27,000 --> 00:09:36,000
+Organizations have top secret information that they use in order for the survivability of that company.
+
+151
+00:09:36,000 --> 00:09:38,000
+These are called trade secrets.
+
+152
+00:09:38,000 --> 00:09:45,000
+It's any form of information, device, method, process, or formula such as that Big Mac sauce that,
+
+153
+00:09:45,000 --> 00:09:49,000
+if disclosed, will cause significant damage to the organization.
+
+154
+00:09:50,000 --> 00:09:53,000
+Now resources generally is going to provide.
+
+155
+00:09:53,000 --> 00:09:59,000
+Must be of competitive value, must be protected from unauthorized use, is proprietary to the company
+
+156
+00:09:59,000 --> 00:10:01,000
+essential for them to survive.
+
+157
+00:10:01,000 --> 00:10:11,000
+Now there is really nothing to register like we do with copyrights or patents or, uh, or trademarks.
+
+158
+00:10:11,000 --> 00:10:13,000
+Trade secrets just has to be protected.
+
+159
+00:10:14,000 --> 00:10:18,000
+There is a law in the United States you don't need to know this one for your exam.
+
+160
+00:10:18,000 --> 00:10:19,000
+I just put it there.
+
+161
+00:10:19,000 --> 00:10:25,000
+For your knowledge, the Espionage Act of 1996 is a law that specifies that if anyone ever steals a
+
+162
+00:10:25,000 --> 00:10:31,000
+trade secrets and discloses that they can be fined, as you can see here, potential jail time.
+
+163
+00:10:32,000 --> 00:10:38,000
+So the way to protect trade secrets as a security professional is just do your normal security things,
+
+164
+00:10:38,000 --> 00:10:45,000
+encrypt it, put good windows permission or file permission like access control firewalls, IDs systems
+
+165
+00:10:45,000 --> 00:10:49,000
+may be used potential air gapped systems to store this kind of information.
+
+166
+00:10:49,000 --> 00:10:53,000
+Whoever gets the information should be signing a non-disclosure agreement.
+
+167
+00:10:53,000 --> 00:10:56,000
+This prohibits them from sharing this information.
+
+168
+00:10:56,000 --> 00:11:04,000
+And if they do share it, they could, uh, be subject to potential fines or the company can sue them
+
+169
+00:11:04,000 --> 00:11:05,000
+for the loss of income and so on.
+
+170
+00:11:07,000 --> 00:11:07,000
+Okay.
+
+171
+00:11:07,000 --> 00:11:11,000
+These are some ways that we're going to protect our intellectual property.
+
+172
+00:11:11,000 --> 00:11:16,000
+Keep in mind, intellectual property is how lots of organizations survives in today's day and time.
+
+173
+00:11:16,000 --> 00:11:21,000
+And a lot of these IPS is essential for the survival of the business.
+
+174
+00:11:21,000 --> 00:11:25,000
+So as an IT professional, make sure you protect them.
+
diff --git a/12 - Data Protection/003 Legal and Financial Data OB 3.3_en.srt b/12 - Data Protection/003 Legal and Financial Data OB 3.3_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..d991fa23b18ce2d90d017b3f7e26c2032c07eaf2
--- /dev/null
+++ b/12 - Data Protection/003 Legal and Financial Data OB 3.3_en.srt
@@ -0,0 +1,276 @@
+1
+00:00:00,000 --> 00:00:05,000
+As you collect information, you're going to be collecting different kinds of information in particularly,
+
+2
+00:00:05,000 --> 00:00:11,000
+some of the data that we collect on a network may be considered, uh, legal information.
+
+3
+00:00:11,000 --> 00:00:14,000
+While some of the information we collect may be financial information.
+
+4
+00:00:14,000 --> 00:00:20,000
+And then some of this information we collect is easily readable by us.
+
+5
+00:00:20,000 --> 00:00:24,000
+And versus some of it is not and can only be read by a computer.
+
+6
+00:00:24,000 --> 00:00:26,000
+So let's talk about the first one I have here.
+
+7
+00:00:26,000 --> 00:00:28,000
+Legal information.
+
+8
+00:00:28,000 --> 00:00:35,000
+A lot of times some of the data that we collect on clients, or that we create ourselves internally
+
+9
+00:00:35,000 --> 00:00:39,000
+could fall into the to to the realm of legal information.
+
+10
+00:00:39,000 --> 00:00:44,000
+Legal information are things that deals with legal matters, including case files, legal advice and
+
+11
+00:00:44,000 --> 00:00:46,000
+other sensitive legal documents.
+
+12
+00:00:47,000 --> 00:00:52,000
+A breach of these type, a breach of this kind of information, or the release of this kind of information,
+
+13
+00:00:52,000 --> 00:00:57,000
+especially if the company is in some kind of a lawsuit, could result in attorney client privileges
+
+14
+00:00:57,000 --> 00:00:59,000
+being compromised.
+
+15
+00:00:59,000 --> 00:01:00,000
+Uh, case integrity.
+
+16
+00:01:00,000 --> 00:01:04,000
+So ensuring the confidentiality encryption of this kind of information is critical.
+
+17
+00:01:04,000 --> 00:01:05,000
+Let me give you an example.
+
+18
+00:01:06,000 --> 00:01:13,000
+Let's say the organization, uh, has gotten sued by another company because that company is claiming
+
+19
+00:01:13,000 --> 00:01:16,000
+that it stole its IP topic.
+
+20
+00:01:16,000 --> 00:01:19,000
+We just covered it, stole its design.
+
+21
+00:01:19,000 --> 00:01:26,000
+But your organization has proof that it didn't stole the design, and it actually created the actual
+
+22
+00:01:26,000 --> 00:01:28,000
+product itself from scratch.
+
+23
+00:01:28,000 --> 00:01:36,000
+The documents that proves that we created the design ourselves now falls into a legal into a legal case,
+
+24
+00:01:36,000 --> 00:01:39,000
+or now it becomes legal information.
+
+25
+00:01:39,000 --> 00:01:42,000
+This means that it's going to have to be presented in a court of law.
+
+26
+00:01:42,000 --> 00:01:47,000
+As an IT professional, you're going to have to make sure that you protect the integrity, make sure
+
+27
+00:01:47,000 --> 00:01:52,000
+that it never gets modified, because you're going to use this as proof in the case you have to encrypt
+
+28
+00:01:52,000 --> 00:01:57,000
+it so it doesn't get leaked out, or the other sides don't get to see it because they have an assumption
+
+29
+00:01:57,000 --> 00:01:58,000
+that may not be true.
+
+30
+00:01:58,000 --> 00:02:01,000
+Another thing is financial information.
+
+31
+00:02:01,000 --> 00:02:07,000
+It is super easy to get in trouble with the law nowadays, because you're collecting financial information
+
+32
+00:02:07,000 --> 00:02:09,000
+and may not even be realized in it.
+
+33
+00:02:09,000 --> 00:02:11,000
+How important it is.
+
+34
+00:02:12,000 --> 00:02:17,000
+This is going to be things, transactions, financial records, credit card information, and other
+
+35
+00:02:17,000 --> 00:02:19,000
+monetary data that you're collecting from your customers.
+
+36
+00:02:19,000 --> 00:02:25,000
+Right now, most organizations that sells products online will collect some kind of payment information.
+
+37
+00:02:26,000 --> 00:02:30,000
+Now, financial data is always going to be the target for these.
+
+38
+00:02:30,000 --> 00:02:35,000
+I don't want to say always, 90% of the time is going to be the target for these hackers that comes
+
+39
+00:02:35,000 --> 00:02:37,000
+in, breaks into your company.
+
+40
+00:02:37,000 --> 00:02:40,000
+What they're looking for are those credit card information.
+
+41
+00:02:40,000 --> 00:02:45,000
+We're going to have to do things like encrypted, encrypt the processing and make sure that if there
+
+42
+00:02:45,000 --> 00:02:50,000
+is standards like PCI compliance, PCI means payment card industry.
+
+43
+00:02:52,000 --> 00:02:54,000
+DSS data security standard.
+
+44
+00:02:54,000 --> 00:03:01,000
+It's basically a standard that organizations have to follow to secure credit card information or financial
+
+45
+00:03:01,000 --> 00:03:02,000
+information.
+
+46
+00:03:02,000 --> 00:03:06,000
+Now, the other thing here that we're going to be talking about is what's called readable data.
+
+47
+00:03:06,000 --> 00:03:08,000
+Readable data falls into two kinds.
+
+48
+00:03:08,000 --> 00:03:14,000
+Human readable, US readable and non-human readable things that we can interpret and see on a network,
+
+49
+00:03:14,000 --> 00:03:18,000
+such as text, documents, images, printable information.
+
+50
+00:03:18,000 --> 00:03:24,000
+And then non readable is going to be non human readable things that only the computer can read.
+
+51
+00:03:24,000 --> 00:03:27,000
+Think of things like machine code.
+
+52
+00:03:27,000 --> 00:03:30,000
+No one can read machine code ones and zeros.
+
+53
+00:03:30,000 --> 00:03:34,000
+Certain kind of log files, encrypted data that only computers can decrypt.
+
+54
+00:03:35,000 --> 00:03:38,000
+Both of these will require protection.
+
+55
+00:03:38,000 --> 00:03:39,000
+Okay.
+
+56
+00:03:39,000 --> 00:03:41,000
+Both of these will require protection.
+
+57
+00:03:41,000 --> 00:03:45,000
+That only that only that organization or whoever needs to see it.
+
+58
+00:03:45,000 --> 00:03:53,000
+This is going to be things such as encryption, firewalls, intrusion detection systems, access controls
+
+59
+00:03:53,000 --> 00:03:54,000
+and so on.
+
+60
+00:03:54,000 --> 00:03:57,000
+All the protection mechanisms that we have spoken about.
+
+61
+00:03:57,000 --> 00:04:02,000
+So human readable is, is very likely to get stolen.
+
+62
+00:04:02,000 --> 00:04:06,000
+Because that's what if they break into the company, that's what they're going to be coming after.
+
+63
+00:04:06,000 --> 00:04:13,000
+Cybercriminals could be attacking non human readable for decryption or misuse of that data.
+
+64
+00:04:14,000 --> 00:04:16,000
+Data protection is super important.
+
+65
+00:04:16,000 --> 00:04:18,000
+If the company is in some kind of a lawsuit.
+
+66
+00:04:18,000 --> 00:04:23,000
+You've got to remember as a security person to protect that data, because that data could be the one
+
+67
+00:04:23,000 --> 00:04:26,000
+that proves that the company did nothing wrong.
+
+68
+00:04:26,000 --> 00:04:29,000
+And you will be collecting tons of financial information.
+
+69
+00:04:29,000 --> 00:04:34,000
+So you want to make sure you protect both of them to keep your company secure.
+
diff --git a/12 - Data Protection/004 Data Classification OB 3.3_en.srt b/12 - Data Protection/004 Data Classification OB 3.3_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..456cc25dc307dbf8b9d1239404e8f3d76c606036
--- /dev/null
+++ b/12 - Data Protection/004 Data Classification OB 3.3_en.srt
@@ -0,0 +1,644 @@
+1
+00:00:00,000 --> 00:00:05,000
+Organizations today store a lot of information or particularly a lot of data.
+
+2
+00:00:05,000 --> 00:00:10,000
+We have tons and tons of data, and the longer that company stays in business, the more data you're
+
+3
+00:00:10,000 --> 00:00:11,000
+going to get.
+
+4
+00:00:11,000 --> 00:00:18,000
+Now the question comes down to does all of that data have the same value?
+
+5
+00:00:18,000 --> 00:00:24,000
+Do we apply the same set of controls to all of all the data?
+
+6
+00:00:24,000 --> 00:00:25,000
+The answer is no.
+
+7
+00:00:25,000 --> 00:00:27,000
+Different data sets have different value.
+
+8
+00:00:27,000 --> 00:00:31,000
+For example, what's on a company's website is public information.
+
+9
+00:00:31,000 --> 00:00:35,000
+That particular data, if it's lost, doesn't cost much harm to the business.
+
+10
+00:00:35,000 --> 00:00:40,000
+But if the company uses a very particular manufacturing method or formula to produce a product, if
+
+11
+00:00:40,000 --> 00:00:45,000
+that's lost, that's going to cause the company significant financial harm.
+
+12
+00:00:45,000 --> 00:00:49,000
+We don't protect data, all the data with the same set of controls.
+
+13
+00:00:49,000 --> 00:00:58,000
+We don't have unlimited resources to buy things like IDs systems, IPS, endpoint protection, firewall
+
+14
+00:00:58,000 --> 00:01:01,000
+encryption, redundant systems, cloud storages, and so on and so on.
+
+15
+00:01:01,000 --> 00:01:04,000
+All the different security controls you can think about.
+
+16
+00:01:04,000 --> 00:01:10,000
+We don't have unlimited amount of money and people to buy, configure, setup and maintain all those
+
+17
+00:01:10,000 --> 00:01:11,000
+controls.
+
+18
+00:01:11,000 --> 00:01:14,000
+So what we have is we have a limited set of controls.
+
+19
+00:01:14,000 --> 00:01:15,000
+We have a ton of data.
+
+20
+00:01:15,000 --> 00:01:22,000
+So we have to take the limited resources and allocate it to ensure the right data gets the right protection.
+
+21
+00:01:22,000 --> 00:01:25,000
+Or in other words, the right data gets the right control.
+
+22
+00:01:25,000 --> 00:01:27,000
+The question is how do we determine that?
+
+23
+00:01:27,000 --> 00:01:29,000
+How do we determine.
+
+24
+00:01:29,000 --> 00:01:32,000
+Well, you're going to get those controls and you're going to get those controls.
+
+25
+00:01:32,000 --> 00:01:36,000
+You're going to have a ton of controls and you're not going to have any control.
+
+26
+00:01:36,000 --> 00:01:39,000
+The answer is data classification.
+
+27
+00:01:39,000 --> 00:01:42,000
+And this starts this discussion on this topic.
+
+28
+00:01:43,000 --> 00:01:44,000
+Now.
+
+29
+00:01:44,000 --> 00:01:48,000
+Data classification affects all aspects of A of the data.
+
+30
+00:01:48,000 --> 00:01:50,000
+When should a data.
+
+31
+00:01:50,000 --> 00:01:52,000
+When should the data be backed up?
+
+32
+00:01:52,000 --> 00:01:53,000
+Depends on a classification.
+
+33
+00:01:53,000 --> 00:01:54,000
+Where should it be stored?
+
+34
+00:01:54,000 --> 00:01:56,000
+Depends on this classification.
+
+35
+00:01:56,000 --> 00:02:00,000
+Who should have access to it depends on its classification.
+
+36
+00:02:00,000 --> 00:02:02,000
+How should it be processed?
+
+37
+00:02:02,000 --> 00:02:03,000
+Depends on its classification.
+
+38
+00:02:03,000 --> 00:02:05,000
+What type of machine should it be stored on?
+
+39
+00:02:05,000 --> 00:02:07,000
+Depends on its classification.
+
+40
+00:02:07,000 --> 00:02:08,000
+You get the point.
+
+41
+00:02:08,000 --> 00:02:12,000
+Every single aspect of the data.
+
+42
+00:02:13,000 --> 00:02:18,000
+Is going to be, or what happens to it is going to be dependent on that classification.
+
+43
+00:02:18,000 --> 00:02:24,000
+So data classification helps in determining the level of security controls and handling protocols that
+
+44
+00:02:24,000 --> 00:02:26,000
+should be applied to various kinds of data.
+
+45
+00:02:27,000 --> 00:02:34,000
+Data classification helps with the creation, usage and determination and destruction of the data.
+
+46
+00:02:34,000 --> 00:02:39,000
+For example public information information that's on your public website.
+
+47
+00:02:39,000 --> 00:02:44,000
+When the when that server that was just storing public data, whenever you're ready to throw that server
+
+48
+00:02:44,000 --> 00:02:48,000
+out or destroy the server, just put it in a garbage.
+
+49
+00:02:48,000 --> 00:02:49,000
+Nothing else to do.
+
+50
+00:02:49,000 --> 00:02:53,000
+Take out the hard drive and dump it in the bin because everything on the drive is public.
+
+51
+00:02:53,000 --> 00:02:59,000
+But if that if that server was storing top secret data, you would want to degauss and shred the hard
+
+52
+00:02:59,000 --> 00:03:00,000
+drive.
+
+53
+00:03:00,000 --> 00:03:06,000
+So it has a different procedure to destroy the data depending on its classification.
+
+54
+00:03:07,000 --> 00:03:12,000
+Now for your exam, the data owner determines the classification.
+
+55
+00:03:12,000 --> 00:03:15,000
+You have to remember that who determines classification?
+
+56
+00:03:15,000 --> 00:03:17,000
+The data owner does that.
+
+57
+00:03:17,000 --> 00:03:21,000
+They will determine how critical it is, how sensitive it is.
+
+58
+00:03:21,000 --> 00:03:23,000
+They're going to determine its value.
+
+59
+00:03:23,000 --> 00:03:24,000
+They need to know.
+
+60
+00:03:24,000 --> 00:03:26,000
+Don't forget the data owner determines Bob has access.
+
+61
+00:03:26,000 --> 00:03:28,000
+Mary doesn't, or vice versa.
+
+62
+00:03:28,000 --> 00:03:32,000
+They determine how to declassify it if it needs to be or destroy it.
+
+63
+00:03:32,000 --> 00:03:38,000
+The whole objective of data classification, like I mentioned earlier, is to get the right controls
+
+64
+00:03:38,000 --> 00:03:43,000
+to the right data owner will define the retention requirements.
+
+65
+00:03:43,000 --> 00:03:46,000
+Data classifications will also define how long you keep it.
+
+66
+00:03:47,000 --> 00:03:54,000
+Basically, the whole point of this entire topic is to the optimization of resources and keeping our
+
+67
+00:03:54,000 --> 00:03:55,000
+data secure.
+
+68
+00:03:55,000 --> 00:03:56,000
+Now.
+
+69
+00:03:57,000 --> 00:03:59,000
+There's a couple of things here I want to mention.
+
+70
+00:04:00,000 --> 00:04:05,000
+When it comes to classification, you have to think of the entire CIA.
+
+71
+00:04:05,000 --> 00:04:10,000
+How sensitive it is, how critical it is sensitivity and critical, and how critical it is generally
+
+72
+00:04:10,000 --> 00:04:12,000
+relate back to confidentiality.
+
+73
+00:04:12,000 --> 00:04:19,000
+So you want to keep in mind these particular things when you're thinking about, for example, top secret
+
+74
+00:04:19,000 --> 00:04:26,000
+data, secret data, public data, unclassified data, you have to think about these particular things.
+
+75
+00:04:26,000 --> 00:04:34,000
+For example, in the military, they they prioritize our emphasized confidentiality.
+
+76
+00:04:34,000 --> 00:04:39,000
+Fully emphasizing confidentiality may give up, for example, availability.
+
+77
+00:04:41,000 --> 00:04:47,000
+A machine that is super secure, that no one can go in and just tamper with the machine and steal its
+
+78
+00:04:47,000 --> 00:04:47,000
+data.
+
+79
+00:04:47,000 --> 00:04:52,000
+A machine that's turned off and unplugged airgap the machine.
+
+80
+00:04:52,000 --> 00:04:56,000
+Well, if it's air gapped, then only two people can get access to it and they have to put the machine
+
+81
+00:04:56,000 --> 00:04:57,000
+on because it's not turned on.
+
+82
+00:04:58,000 --> 00:05:02,000
+The problem with this is that, yes, good confidentiality, but it's not available to anyone except
+
+83
+00:05:02,000 --> 00:05:03,000
+a few people.
+
+84
+00:05:03,000 --> 00:05:10,000
+Low availability in private industries, though, we're going to emphasize the full CIA.
+
+85
+00:05:10,000 --> 00:05:12,000
+We're going to want to push the full thing.
+
+86
+00:05:12,000 --> 00:05:16,000
+We're going to try to get CIA for most of our data, not all of it.
+
+87
+00:05:16,000 --> 00:05:19,000
+Keep your classification scheme simple.
+
+88
+00:05:19,000 --> 00:05:24,000
+I'm going to talk about a different classification scheme that we can use, the different terms you
+
+89
+00:05:24,000 --> 00:05:25,000
+can use in a minute.
+
+90
+00:05:25,000 --> 00:05:28,000
+Here's an example though of a classification scheme.
+
+91
+00:05:28,000 --> 00:05:31,000
+So for example this is just an example.
+
+92
+00:05:31,000 --> 00:05:34,000
+Like in the military when we're talking protection of data.
+
+93
+00:05:34,000 --> 00:05:39,000
+Look at how the different classification will determine what type of controls.
+
+94
+00:05:40,000 --> 00:05:41,000
+If you have data.
+
+95
+00:05:42,000 --> 00:05:46,000
+Particularly something like on paper, if it's top secret, put it in a vault.
+
+96
+00:05:46,000 --> 00:05:49,000
+If it's secret, a safe would be okay.
+
+97
+00:05:49,000 --> 00:05:53,000
+Confidential, maybe a filing cabinet with a metal bar and a lock.
+
+98
+00:05:53,000 --> 00:05:54,000
+And on classified.
+
+99
+00:05:54,000 --> 00:05:54,000
+No protection.
+
+100
+00:05:54,000 --> 00:05:55,000
+Leave it on the desk.
+
+101
+00:05:55,000 --> 00:06:00,000
+Notice the different classification results in different controls.
+
+102
+00:06:01,000 --> 00:06:08,000
+Now, the question that a lot of people ask me is, Andrew, what are the different classification schemes
+
+103
+00:06:08,000 --> 00:06:09,000
+that we can use?
+
+104
+00:06:09,000 --> 00:06:18,000
+There is no official definition of any potential or any classification scheme that is out there.
+
+105
+00:06:18,000 --> 00:06:25,000
+Many books that we read, CISSP books, Security+ books, even the books on Ec-council.
+
+106
+00:06:25,000 --> 00:06:31,000
+They're going to vary in the definitions because there's no definition and the exam will never ask you,
+
+107
+00:06:31,000 --> 00:06:34,000
+is this secret, top secret or confidential?
+
+108
+00:06:34,000 --> 00:06:35,000
+They'll never do that.
+
+109
+00:06:35,000 --> 00:06:38,000
+Just understand what data classification is.
+
+110
+00:06:38,000 --> 00:06:42,000
+I want to show you an example of what you could use though.
+
+111
+00:06:43,000 --> 00:06:46,000
+Uh, this is a classification scheme that you could use.
+
+112
+00:06:46,000 --> 00:06:50,000
+And I want to show you how different schemes mean different things.
+
+113
+00:06:50,000 --> 00:06:52,000
+So let's take a look here.
+
+114
+00:06:52,000 --> 00:06:54,000
+So here's a data classification scheme.
+
+115
+00:06:54,000 --> 00:06:57,000
+So on this one we have four classes 0 to 3.
+
+116
+00:06:58,000 --> 00:07:01,000
+And on the bottom of the triangle let's go with non-government.
+
+117
+00:07:01,000 --> 00:07:03,000
+First let's see a private organization.
+
+118
+00:07:03,000 --> 00:07:05,000
+Class zero is no damage.
+
+119
+00:07:05,000 --> 00:07:09,000
+Any data that's classified as public has no damage.
+
+120
+00:07:09,000 --> 00:07:11,000
+If it's released to the public no damage.
+
+121
+00:07:11,000 --> 00:07:12,000
+All right.
+
+122
+00:07:12,000 --> 00:07:19,000
+Maybe like upcoming projects, the company is doing class one sensitive does cause damage to the business.
+
+123
+00:07:19,000 --> 00:07:23,000
+Things like the company's financial, like its profit and loss statement.
+
+124
+00:07:23,000 --> 00:07:25,000
+Serious damage like a class two.
+
+125
+00:07:25,000 --> 00:07:27,000
+This one is private.
+
+126
+00:07:27,000 --> 00:07:30,000
+This would be like releasing air information about the company's employees.
+
+127
+00:07:30,000 --> 00:07:33,000
+And then of course, grave damage to that business.
+
+128
+00:07:33,000 --> 00:07:36,000
+Confidential or proprietary data like trade secrets.
+
+129
+00:07:36,000 --> 00:07:41,000
+If you are the federal government, here's a classification that you can use.
+
+130
+00:07:41,000 --> 00:07:43,000
+Top secret wartime information.
+
+131
+00:07:43,000 --> 00:07:44,000
+This is released.
+
+132
+00:07:44,000 --> 00:07:48,000
+Grave damage to national security troop deployment information.
+
+133
+00:07:48,000 --> 00:07:51,000
+This would be serious damage to national security.
+
+134
+00:07:51,000 --> 00:07:56,000
+Confidential is like trade secrets or health care information of government workers that are non classified
+
+135
+00:07:56,000 --> 00:07:58,000
+is going to be their version of public.
+
+136
+00:07:58,000 --> 00:08:01,000
+Now this is just an example.
+
+137
+00:08:01,000 --> 00:08:02,000
+Okay.
+
+138
+00:08:02,000 --> 00:08:04,000
+This is just an example.
+
+139
+00:08:04,000 --> 00:08:05,000
+All right.
+
+140
+00:08:05,000 --> 00:08:10,000
+Here at TI we only use three levels of data classification I know companies that only use two.
+
+141
+00:08:10,000 --> 00:08:12,000
+You don't have to use them all.
+
+142
+00:08:12,000 --> 00:08:18,000
+But when it comes to data classification, here are some different, uh, terms that you can use.
+
+143
+00:08:18,000 --> 00:08:20,000
+Sensitive confidential.
+
+144
+00:08:20,000 --> 00:08:21,000
+Public I think has a universal meaning.
+
+145
+00:08:21,000 --> 00:08:23,000
+Anyone can access it.
+
+146
+00:08:23,000 --> 00:08:25,000
+But for example, what are some companies may call it private.
+
+147
+00:08:25,000 --> 00:08:32,000
+Some may call it confidential, what some call sensitive, some may call restricted, what some call
+
+148
+00:08:32,000 --> 00:08:34,000
+confidential, some may call it critical.
+
+149
+00:08:34,000 --> 00:08:39,000
+And then of course, the military will add things like secret and top secret on top of this.
+
+150
+00:08:39,000 --> 00:08:41,000
+Or maybe a line in here with these.
+
+151
+00:08:41,000 --> 00:08:45,000
+There really isn't a full definition.
+
+152
+00:08:46,000 --> 00:08:50,000
+Now when it comes to your exam and data classification, remember something.
+
+153
+00:08:50,000 --> 00:08:52,000
+Data classification is a big terme.
+
+154
+00:08:52,000 --> 00:09:00,000
+Data classification is the umbrella terms that affects all controls of the data.
+
+155
+00:09:01,000 --> 00:09:04,000
+Like I mentioned earlier in the beginning, let's do a quick recap.
+
+156
+00:09:04,000 --> 00:09:11,000
+Data classification affects everything about the data, determines what controls is applied to what
+
+157
+00:09:11,000 --> 00:09:15,000
+data, determines who should have access to it, or you can't access this because you're not in the
+
+158
+00:09:15,000 --> 00:09:18,000
+top secret clearance, or you can't access this because you don't.
+
+159
+00:09:18,000 --> 00:09:20,000
+You can't access confidential data.
+
+160
+00:09:20,000 --> 00:09:23,000
+You can access public data, things like that.
+
+161
+00:09:23,000 --> 00:09:26,000
+Keep this in mind when answering your exam questions.
+
diff --git a/12 - Data Protection/005 Geolocation and Sovereignty OB 3.3_en.srt b/12 - Data Protection/005 Geolocation and Sovereignty OB 3.3_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..48c7a17efbea31aa0e90190d0a8340b83344db88
--- /dev/null
+++ b/12 - Data Protection/005 Geolocation and Sovereignty OB 3.3_en.srt
@@ -0,0 +1,144 @@
+1
+00:00:00,000 --> 00:00:04,000
+Organizations today collect data from multiple parts of the world.
+
+2
+00:00:04,000 --> 00:00:08,000
+You see, most organizations do business internationally.
+
+3
+00:00:08,000 --> 00:00:13,000
+For example, if you have an e-commerce site, you may have people purchasing products on your e-commerce
+
+4
+00:00:13,000 --> 00:00:18,000
+site that is located in Europe, Asia, United States, and the rest of the world.
+
+5
+00:00:18,000 --> 00:00:26,000
+So what happens is this is this is important to know because the geographic location of the data matters.
+
+6
+00:00:26,000 --> 00:00:31,000
+Depending on where that data is collected, it's subject to different regulatory compliance.
+
+7
+00:00:31,000 --> 00:00:33,000
+That's that's going to be important.
+
+8
+00:00:33,000 --> 00:00:39,000
+For example, collecting data from EU citizens results in you following GDPR.
+
+9
+00:00:39,000 --> 00:00:44,000
+Now also the other things to think about is the latency and performance of the data.
+
+10
+00:00:44,000 --> 00:00:49,000
+If you're capturing or getting data from around the world and your servers are in the United States,
+
+11
+00:00:49,000 --> 00:00:53,000
+that could be a problem as the performance of the data look at the risk management.
+
+12
+00:00:54,000 --> 00:00:57,000
+With collecting data from around the world.
+
+13
+00:00:57,000 --> 00:01:03,000
+Does your organization have the legal department and the resources it takes to comply with legal laws
+
+14
+00:01:03,000 --> 00:01:04,000
+around the world?
+
+15
+00:01:04,000 --> 00:01:08,000
+This brings me to this topic of data sovereignty.
+
+16
+00:01:08,000 --> 00:01:14,000
+Now, data sovereignty is basically a legal concept that data is subject to the laws and governance
+
+17
+00:01:14,000 --> 00:01:19,000
+structure of the country in which it is collected, stored and processed.
+
+18
+00:01:19,000 --> 00:01:24,000
+This is important if you collect data from folks within the United States.
+
+19
+00:01:24,000 --> 00:01:29,000
+Your servers are here, your processes and data processing the data here.
+
+20
+00:01:30,000 --> 00:01:32,000
+But maybe your company is international.
+
+21
+00:01:32,000 --> 00:01:35,000
+You should still be following the United States data.
+
+22
+00:01:36,000 --> 00:01:39,000
+Now this is really important, especially when it comes to storing data.
+
+23
+00:01:39,000 --> 00:01:45,000
+Not because you decide to take data and store it somewhere else that doesn't have a lot of laws means
+
+24
+00:01:45,000 --> 00:01:49,000
+that you don't have to follow the law where you actually collected the data from.
+
+25
+00:01:49,000 --> 00:01:55,000
+Organizations must ensure that their data handling and storage comply with laws of those countries from
+
+26
+00:01:55,000 --> 00:01:56,000
+where we collected it.
+
+27
+00:01:56,000 --> 00:02:01,000
+For example, you collect EU citizens data, but you're storing that data in South Asia, which doesn't
+
+28
+00:02:01,000 --> 00:02:04,000
+have a ton of privacy laws.
+
+29
+00:02:04,000 --> 00:02:10,000
+You you're still under the jurisdiction of GDPR, doesn't matter where you're storing that particular
+
+30
+00:02:10,000 --> 00:02:11,000
+data.
+
+31
+00:02:11,000 --> 00:02:14,000
+This is particularly important for multinational companies.
+
+32
+00:02:14,000 --> 00:02:20,000
+You see, multinational companies are going to be collecting data from folks all around the world.
+
+33
+00:02:20,000 --> 00:02:26,000
+And what becomes cumbersome to deal with is all the different regulations that different countries may
+
+34
+00:02:26,000 --> 00:02:26,000
+have.
+
+35
+00:02:26,000 --> 00:02:32,000
+And then you now have to comply with all of those country requirements in order to keep the data secure,
+
+36
+00:02:32,000 --> 00:02:40,000
+but just not to keep it secure, to actually be doing the right thing and be doing it legally.
+
diff --git a/12 - Data Protection/006 Methods to Secure Data OB 3.3_en.srt b/12 - Data Protection/006 Methods to Secure Data OB 3.3_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..1ecd8ef8c4da5ecac347876aa9923910f62ea059
--- /dev/null
+++ b/12 - Data Protection/006 Methods to Secure Data OB 3.3_en.srt
@@ -0,0 +1,524 @@
+1
+00:00:00,000 --> 00:00:04,000
+In this video, I'm going to give you some ways that you should be secure in your data.
+
+2
+00:00:04,000 --> 00:00:09,000
+Now, this video acts more as a summary of the things that are most of the things that I've already
+
+3
+00:00:09,000 --> 00:00:11,000
+covered so far in this course.
+
+4
+00:00:11,000 --> 00:00:18,000
+So since this topic is all about data, let's take a look at some of the things that we should be doing
+
+5
+00:00:18,000 --> 00:00:20,000
+when it comes to securing our data.
+
+6
+00:00:20,000 --> 00:00:23,000
+Now, once again, I've gone through almost all of these things.
+
+7
+00:00:23,000 --> 00:00:28,000
+For example, in cryptography, we talked we talked about obfuscation and tokenization.
+
+8
+00:00:28,000 --> 00:00:35,000
+I'm going to give you also hashing will give you guys a quick, just a quick review of these particular
+
+9
+00:00:35,000 --> 00:00:36,000
+ways to secure data.
+
+10
+00:00:36,000 --> 00:00:42,000
+If you want more explanation on those topics, remember to revert back to those particular sections.
+
+11
+00:00:43,000 --> 00:00:48,000
+The first thing we'll start out with is the geographic restrictions of data.
+
+12
+00:00:48,000 --> 00:00:53,000
+This involves restricting the physical access where data could be stored and accessible.
+
+13
+00:00:53,000 --> 00:00:59,000
+By this, we spoke about when we talked about data sovereignty, where we collect that data, where
+
+14
+00:00:59,000 --> 00:01:07,000
+we're storing that data more than likely will determine the actual laws and regulations that applies
+
+15
+00:01:07,000 --> 00:01:08,000
+to the data.
+
+16
+00:01:08,000 --> 00:01:11,000
+You have to be sure that data is only stored, processed in certain locations.
+
+17
+00:01:11,000 --> 00:01:17,000
+You can't take data and store them in a location that is against the laws of that particular country.
+
+18
+00:01:17,000 --> 00:01:21,000
+Certain countries have laws that says the data can't be stored outside the country.
+
+19
+00:01:21,000 --> 00:01:26,000
+So if you decide if you determine that you're going to take this data and move it out of the country,
+
+20
+00:01:26,000 --> 00:01:29,000
+you're breaking the laws of that particular country.
+
+21
+00:01:29,000 --> 00:01:31,000
+This would be a type of a geographic restriction.
+
+22
+00:01:32,000 --> 00:01:33,000
+So by process.
+
+23
+00:01:34,000 --> 00:01:39,000
+Let's go through this by ensuring data is only processed, stored and processed in certain locations.
+
+24
+00:01:39,000 --> 00:01:44,000
+Organizations can more easily comply with this kind of regulation.
+
+25
+00:01:44,000 --> 00:01:46,000
+The next thing here is encryption.
+
+26
+00:01:46,000 --> 00:01:49,000
+The entire cryptographic section of this course reviews this.
+
+27
+00:01:49,000 --> 00:01:54,000
+Remember what encryption is converting data into a coded format which we call ciphertext.
+
+28
+00:01:54,000 --> 00:01:58,000
+That is unreasonable, that is unreadable without a specific key.
+
+29
+00:01:58,000 --> 00:02:02,000
+So you need that key to decrypt the data to get the plain text.
+
+30
+00:02:03,000 --> 00:02:05,000
+You can also you can also encrypt them using passwords.
+
+31
+00:02:05,000 --> 00:02:09,000
+Now this is fundamentally how we're going to protect data.
+
+32
+00:02:09,000 --> 00:02:14,000
+When most people think of think of encryption they think in confidentiality.
+
+33
+00:02:14,000 --> 00:02:18,000
+Remember encryption protects data at rest and data in transit.
+
+34
+00:02:19,000 --> 00:02:21,000
+Remember it really doesn't affect data in use.
+
+35
+00:02:21,000 --> 00:02:25,000
+Remember, data at rest is going to be things like hard drive based encryption versus data.
+
+36
+00:02:25,000 --> 00:02:29,000
+And use is going to be things like SSL, TLS encryption.
+
+37
+00:02:29,000 --> 00:02:34,000
+Now, anytime you encrypt data, you have to use a decryption key to decrypt that data.
+
+38
+00:02:34,000 --> 00:02:40,000
+99% of the time when people are thinking data security, they're thinking encryption.
+
+39
+00:02:41,000 --> 00:02:48,000
+Uh, also in the world of cryptography, in the cryptography section, we spoke about hashing.
+
+40
+00:02:48,000 --> 00:02:50,000
+Remember what hashing does?
+
+41
+00:02:50,000 --> 00:02:59,000
+Hashing transforms a string of characters into a into usually shorter fixed length value or basically
+
+42
+00:02:59,000 --> 00:03:00,000
+hashes itself.
+
+43
+00:03:00,000 --> 00:03:02,000
+These strings are hashes.
+
+44
+00:03:02,000 --> 00:03:08,000
+Now, what hashing does is that it basically encrypts something, produces a cryptographic hash, or
+
+45
+00:03:08,000 --> 00:03:11,000
+it hashes text of any length to produce a cryptographic hash.
+
+46
+00:03:11,000 --> 00:03:17,000
+These cryptographic hashes are known as one way, which means that you cannot take the hash and turn
+
+47
+00:03:17,000 --> 00:03:17,000
+it back.
+
+48
+00:03:18,000 --> 00:03:21,000
+Now it is common for us to do this in password.
+
+49
+00:03:21,000 --> 00:03:23,000
+This is what passwords Paul.
+
+50
+00:03:23,000 --> 00:03:25,000
+Passwords are hash.
+
+51
+00:03:25,000 --> 00:03:27,000
+So unlike encryption hashing is a one way function.
+
+52
+00:03:27,000 --> 00:03:31,000
+You cannot take the hash and go back to the actual data.
+
+53
+00:03:31,000 --> 00:03:32,000
+Why do we do this?
+
+54
+00:03:32,000 --> 00:03:36,000
+Hashing produces integrity of the information.
+
+55
+00:03:36,000 --> 00:03:44,000
+Remember that for your exam, once again there is a full 20 or 30 minute video on hashing in the cryptography
+
+56
+00:03:44,000 --> 00:03:45,000
+section.
+
+57
+00:03:45,000 --> 00:03:48,000
+The other thing that we have is what's called data masking.
+
+58
+00:03:48,000 --> 00:03:49,000
+All right.
+
+59
+00:03:49,000 --> 00:03:55,000
+Data masking is basically protecting the data from you not being able to see it.
+
+60
+00:03:55,000 --> 00:03:56,000
+But the data is still there.
+
+61
+00:03:56,000 --> 00:03:58,000
+They do this a lot in databases.
+
+62
+00:03:58,000 --> 00:04:00,000
+And you guys see this quite often.
+
+63
+00:04:00,000 --> 00:04:04,000
+Like when you're typing in a password on a computer, it doesn't actually show the password.
+
+64
+00:04:04,000 --> 00:04:09,000
+It shows you x, x, x or it may show you asterisks instead.
+
+65
+00:04:09,000 --> 00:04:10,000
+That's a form of data masking.
+
+66
+00:04:10,000 --> 00:04:17,000
+This is to protect sensitive data while still allowing users to work with the realistic format of the
+
+67
+00:04:17,000 --> 00:04:18,000
+actual data.
+
+68
+00:04:19,000 --> 00:04:21,000
+The other one here is tokenization.
+
+69
+00:04:21,000 --> 00:04:26,000
+Now we also have a whole video on this in the cryptography section.
+
+70
+00:04:26,000 --> 00:04:28,000
+So what is tokenization?
+
+71
+00:04:28,000 --> 00:04:34,000
+Well, tokenization is when we replace sensitive data with non-sensitive substitutes called tokens.
+
+72
+00:04:34,000 --> 00:04:41,000
+The token can represent a set of data organizations or systems and software will use that token as it
+
+73
+00:04:41,000 --> 00:04:44,000
+would use the actual sensitive data.
+
+74
+00:04:44,000 --> 00:04:48,000
+Only the token server will know that this token represents this data.
+
+75
+00:04:48,000 --> 00:04:54,000
+For example, you can go to a token server, give it your credit card number, your actual credit card
+
+76
+00:04:54,000 --> 00:04:54,000
+number.
+
+77
+00:04:54,000 --> 00:04:55,000
+It'll give you a token.
+
+78
+00:04:55,000 --> 00:05:01,000
+You can then use that token to purchase stuff all over the internet like you would on PayPal.
+
+79
+00:05:01,000 --> 00:05:07,000
+And then what would happen is no one would be able to take that token and decrypt it back to your credit
+
+80
+00:05:07,000 --> 00:05:07,000
+card.
+
+81
+00:05:08,000 --> 00:05:13,000
+They would have to hack the token server because the token server knows this token represents this credit
+
+82
+00:05:13,000 --> 00:05:13,000
+card.
+
+83
+00:05:13,000 --> 00:05:17,000
+So these tokens can be used in a system without ever showing your sensitive data.
+
+84
+00:05:17,000 --> 00:05:21,000
+So you're basically given all the vendors your token, but you're not actually giving them your credit
+
+85
+00:05:21,000 --> 00:05:23,000
+card information.
+
+86
+00:05:24,000 --> 00:05:25,000
+Obfuscation.
+
+87
+00:05:25,000 --> 00:05:29,000
+This is also not a topic we covered in cryptography.
+
+88
+00:05:29,000 --> 00:05:33,000
+This involves making data more ambiguous or unclear.
+
+89
+00:05:33,000 --> 00:05:38,000
+We obfuscate many things, whether in the obfuscation video.
+
+90
+00:05:38,000 --> 00:05:42,000
+I showed you guys how I obfuscated source code in an application.
+
+91
+00:05:42,000 --> 00:05:46,000
+We did that with JavaScript, and now it can be done using a variety of means, whether it's mixing
+
+92
+00:05:46,000 --> 00:05:49,000
+mixing data with other non-sensitive data.
+
+93
+00:05:49,000 --> 00:05:51,000
+Change in file name.
+
+94
+00:05:51,000 --> 00:05:56,000
+Basically, this makes it unclear obscure the meaning of actual data.
+
+95
+00:05:56,000 --> 00:05:58,000
+Now we do this a lot.
+
+96
+00:05:58,000 --> 00:05:59,000
+Obfuscation.
+
+97
+00:05:59,000 --> 00:06:00,000
+We do this a lot in source codes.
+
+98
+00:06:00,000 --> 00:06:04,000
+This protects the source code from easily being exploited.
+
+99
+00:06:04,000 --> 00:06:06,000
+Segmentation.
+
+100
+00:06:06,000 --> 00:06:14,000
+This area we covered in the network security segmentation is when you break your network in different
+
+101
+00:06:14,000 --> 00:06:20,000
+parts, especially like logical segmentations where we would do it utilizing things like VLANs.
+
+102
+00:06:20,000 --> 00:06:27,000
+So this divides the network into smaller segments, uh, to control access and reduce the risk of widespread
+
+103
+00:06:27,000 --> 00:06:28,000
+network breaches.
+
+104
+00:06:28,000 --> 00:06:34,000
+For example, if you break your network into ten different segments, maybe you have one for finance,
+
+105
+00:06:34,000 --> 00:06:40,000
+one for account and one for sales, marketing, management, research and development, inventory tracking,
+
+106
+00:06:40,000 --> 00:06:41,000
+and so on.
+
+107
+00:06:41,000 --> 00:06:46,000
+If one segment like sales get a particular virus, that virus is not going to go and infect other segments
+
+108
+00:06:46,000 --> 00:06:49,000
+because it blocks the flow of traffic.
+
+109
+00:06:49,000 --> 00:06:56,000
+This reduces cyber attacks or cyber breaches to one particular segment, so you can limit access to
+
+110
+00:06:56,000 --> 00:06:57,000
+sensitive data.
+
+111
+00:06:57,000 --> 00:07:03,000
+That's one of its main other points, because if you think about this, people in the sales don't need
+
+112
+00:07:03,000 --> 00:07:04,000
+access to accounting information.
+
+113
+00:07:04,000 --> 00:07:09,000
+If you segment it, people in sales can only see sales things.
+
+114
+00:07:11,000 --> 00:07:13,000
+Permission restrictions.
+
+115
+00:07:13,000 --> 00:07:15,000
+This is going to be like file permissions.
+
+116
+00:07:15,000 --> 00:07:16,000
+In this particular one.
+
+117
+00:07:16,000 --> 00:07:24,000
+You're going to set up an enforced policies that control who has access to what data and what are they
+
+118
+00:07:24,000 --> 00:07:24,000
+allowed to do with it.
+
+119
+00:07:24,000 --> 00:07:28,000
+So you could say someone can read this, they can write to it, but they can't.
+
+120
+00:07:28,000 --> 00:07:30,000
+They can't actually delete it.
+
+121
+00:07:30,000 --> 00:07:32,000
+They can't change permission to it.
+
+122
+00:07:32,000 --> 00:07:33,000
+So we're going to set permissions.
+
+123
+00:07:33,000 --> 00:07:34,000
+Now.
+
+124
+00:07:34,000 --> 00:07:40,000
+Permission restrictions is one of the most common and basic things we should be doing when we manage
+
+125
+00:07:40,000 --> 00:07:41,000
+security.
+
+126
+00:07:42,000 --> 00:07:42,000
+All right.
+
+127
+00:07:42,000 --> 00:07:44,000
+These were some basic things.
+
+128
+00:07:44,000 --> 00:07:46,000
+And once again we went over quite a lot of these.
+
+129
+00:07:46,000 --> 00:07:48,000
+And these here were some great reviews.
+
+130
+00:07:48,000 --> 00:07:51,000
+This is just a great review or list of things.
+
+131
+00:07:51,000 --> 00:07:56,000
+If you forgot, these are list of things that you can do to protect your data.
+
diff --git a/12 - Data Protection/007 Quick Quiz.html b/12 - Data Protection/007 Quick Quiz.html
new file mode 100644
index 0000000000000000000000000000000000000000..d80b5290a80ebd039723665fb95a7dfbf7833dc1
--- /dev/null
+++ b/12 - Data Protection/007 Quick Quiz.html
@@ -0,0 +1,479 @@
+
+
+
+
+
+
+ Quiz
+
+
+
+
+
+
+
+
+ Score: 999 of
+ 999%
+
+ Correct: 999
+ Incorrect: 999
+
+
+
+
+
+
+
+
+
+
diff --git a/13 - Common Security Techniques/001 Secure Baselines OB 4.1_en.srt b/13 - Common Security Techniques/001 Secure Baselines OB 4.1_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..7ddebf84ea4ce25978f524b78dcd3726bf1bb8c8
--- /dev/null
+++ b/13 - Common Security Techniques/001 Secure Baselines OB 4.1_en.srt
@@ -0,0 +1,568 @@
+1
+00:00:00,000 --> 00:00:07,000
+I remember working in organizations where every single workstation had different configurations.
+
+2
+00:00:07,000 --> 00:00:14,000
+There was no standardized base of configurations that was out there, and the organization had a lot
+
+3
+00:00:14,000 --> 00:00:20,000
+of trouble fixing things, because every time they would go to a machine, it would be configured different
+
+4
+00:00:20,000 --> 00:00:21,000
+than another machine.
+
+5
+00:00:21,000 --> 00:00:24,000
+This resulted in massive security holes.
+
+6
+00:00:24,000 --> 00:00:29,000
+Since there was no standardized configurations for all computers across the network, we weren't too
+
+7
+00:00:29,000 --> 00:00:31,000
+sure what machine was really secure.
+
+8
+00:00:31,000 --> 00:00:37,000
+With the right software and the right configs versus other machines just didn't have any.
+
+9
+00:00:37,000 --> 00:00:42,000
+And anytime new machines were brought in, there wasn't like a standard procedure of how to configure
+
+10
+00:00:42,000 --> 00:00:45,000
+this machine to make it secure to join the network.
+
+11
+00:00:45,000 --> 00:00:48,000
+You see what this organization lacked.
+
+12
+00:00:48,000 --> 00:00:51,000
+And this happens a lot in small businesses, by the way.
+
+13
+00:00:51,000 --> 00:00:58,000
+But this organization lack is what's called a baseline or what's known as baseline configs.
+
+14
+00:00:58,000 --> 00:01:01,000
+So in this topic let's talk about secure baselines.
+
+15
+00:01:01,000 --> 00:01:03,000
+So what exactly is this.
+
+16
+00:01:03,000 --> 00:01:10,000
+Well this refers to a set of security standards and configurations that an organization establishes
+
+17
+00:01:10,000 --> 00:01:12,000
+to protect its systems and its data.
+
+18
+00:01:12,000 --> 00:01:14,000
+Here's the perfect world.
+
+19
+00:01:15,000 --> 00:01:22,000
+In the perfect world, every single organization is going to have a standard set of configurations that
+
+20
+00:01:22,000 --> 00:01:26,000
+it applies to all the computers in its network.
+
+21
+00:01:26,000 --> 00:01:31,000
+Every time a computer is brought in, uh, it's probably wiped out.
+
+22
+00:01:31,000 --> 00:01:36,000
+It's given a standard installation of maybe windows with a standard set of configurations, security
+
+23
+00:01:36,000 --> 00:01:40,000
+software and functionality software like Microsoft Office.
+
+24
+00:01:40,000 --> 00:01:42,000
+Everything is configured in this way.
+
+25
+00:01:42,000 --> 00:01:43,000
+It's joined to the domain.
+
+26
+00:01:43,000 --> 00:01:49,000
+It has this level of, um, this level of patching applied to it and so on.
+
+27
+00:01:49,000 --> 00:01:50,000
+This is good.
+
+28
+00:01:50,000 --> 00:01:57,000
+Every machine has the same configuration in terms of security configurations of software and so on.
+
+29
+00:01:57,000 --> 00:02:00,000
+This helps for you to predict if anything can go wrong.
+
+30
+00:02:00,000 --> 00:02:02,000
+No more ad hoc.
+
+31
+00:02:02,000 --> 00:02:04,000
+This is what a baseline is.
+
+32
+00:02:04,000 --> 00:02:09,000
+They're developed based on industry best practices, regulatory requirements especially.
+
+33
+00:02:09,000 --> 00:02:15,000
+So let's say the this the computer would be in the financial department.
+
+34
+00:02:15,000 --> 00:02:21,000
+The financial department due to the type of data may follow, certain kinds of encryption or certain
+
+35
+00:02:21,000 --> 00:02:27,000
+kinds of configuration to match certain regulatory laws, or it may have organization specific needs.
+
+36
+00:02:27,000 --> 00:02:34,000
+Now, if this sounds good to you and you want to have a standardized configuration to all machines in
+
+37
+00:02:34,000 --> 00:02:38,000
+your organization, now remember the standardized configurations could be customized.
+
+38
+00:02:38,000 --> 00:02:44,000
+You can have a standard config for sales, standard config for finance, for management, and so on
+
+39
+00:02:44,000 --> 00:02:47,000
+as long as you have a good standardization going on.
+
+40
+00:02:47,000 --> 00:02:50,000
+If this sounds good, well here are the steps to doing it.
+
+41
+00:02:50,000 --> 00:02:54,000
+Let's go take a look at how the how to build a good secure baseline.
+
+42
+00:02:54,000 --> 00:02:59,000
+So the first step is going to be to establish then deploy then maintain.
+
+43
+00:02:59,000 --> 00:03:02,000
+The first step in doing a secure baseline is establish.
+
+44
+00:03:03,000 --> 00:03:08,000
+The first thing you have to do is you have to do what's called assessment and analysis.
+
+45
+00:03:09,000 --> 00:03:13,000
+What you're doing is you're going to assess the current security posture, like what's happening in
+
+46
+00:03:13,000 --> 00:03:14,000
+the in the company right here.
+
+47
+00:03:14,000 --> 00:03:16,000
+Where are we right now?
+
+48
+00:03:16,000 --> 00:03:22,000
+You know, before you embark on a trip to our journey to standardize your baseline, ask yourself,
+
+49
+00:03:22,000 --> 00:03:23,000
+where are we right now?
+
+50
+00:03:23,000 --> 00:03:24,000
+What's happening?
+
+51
+00:03:24,000 --> 00:03:29,000
+Then the next thing we want to do is we want to understand the needs of the business.
+
+52
+00:03:29,000 --> 00:03:31,000
+What type of threats and vulnerabilities do we have?
+
+53
+00:03:31,000 --> 00:03:33,000
+What type of threats do we face?
+
+54
+00:03:33,000 --> 00:03:38,000
+What kind of, for example, regulations do we face?
+
+55
+00:03:38,000 --> 00:03:41,000
+Then you want to start to define those standards.
+
+56
+00:03:41,000 --> 00:03:44,000
+Once you know, hey, this is what these are the threats.
+
+57
+00:03:44,000 --> 00:03:45,000
+These are the vulnerabilities.
+
+58
+00:03:45,000 --> 00:03:47,000
+These are the laws.
+
+59
+00:03:47,000 --> 00:03:50,000
+The next thing we're going to do is now we have to go out.
+
+60
+00:03:50,000 --> 00:03:54,000
+We have to start to define those configurations and controls.
+
+61
+00:03:54,000 --> 00:04:01,000
+You can go to companies like NIST or I should say government agencies like NIST, ISO and other kinds
+
+62
+00:04:01,000 --> 00:04:04,000
+of big name businesses out there.
+
+63
+00:04:04,000 --> 00:04:11,000
+Microsoft has standard baseline configs, two that you can now use in order to start to build your configuration.
+
+64
+00:04:11,000 --> 00:04:15,000
+Now, you might want to include all kinds of regulatory requirements.
+
+65
+00:04:15,000 --> 00:04:17,000
+The next thing you want to do is to document this.
+
+66
+00:04:17,000 --> 00:04:21,000
+The establish baseline configs and standards are documented.
+
+67
+00:04:21,000 --> 00:04:25,000
+And this is going to serve as a reference for implementing and maintaining your baseline.
+
+68
+00:04:25,000 --> 00:04:28,000
+Now before I move on, I want to give you an example.
+
+69
+00:04:29,000 --> 00:04:30,000
+Right.
+
+70
+00:04:30,000 --> 00:04:32,000
+I want to give you guys an example of all of these particular things here.
+
+71
+00:04:32,000 --> 00:04:38,000
+Now a baseline I'm going to give you an example of a baseline configuration that we have at Tia.
+
+72
+00:04:38,000 --> 00:04:40,000
+For student machines.
+
+73
+00:04:40,000 --> 00:04:47,000
+The baseline configure a secure baseline configuration is every time we buy a computer we do not buy
+
+74
+00:04:47,000 --> 00:04:48,000
+pre pre-built.
+
+75
+00:04:48,000 --> 00:04:49,000
+We build our own.
+
+76
+00:04:49,000 --> 00:04:54,000
+So every time a machine is comes off the assembly line, it's always a desktop.
+
+77
+00:04:54,000 --> 00:05:01,000
+The first thing we do is the machine has to have the latest installation of its firmware.
+
+78
+00:05:01,000 --> 00:05:03,000
+So we make sure firmwares are updated.
+
+79
+00:05:03,000 --> 00:05:08,000
+Windows is installed and fully patched at to that particular time.
+
+80
+00:05:08,000 --> 00:05:11,000
+We then install Microsoft Office.
+
+81
+00:05:11,000 --> 00:05:16,000
+We then do a variety of configurations to the group policy on the machine.
+
+82
+00:05:16,000 --> 00:05:21,000
+Since we run a decentralized network, we don't have a domain controller for our student workstations
+
+83
+00:05:21,000 --> 00:05:22,000
+because we change them up a lot.
+
+84
+00:05:22,000 --> 00:05:29,000
+Student accounts are created as standard account passwords are implemented, certain programs are blocked.
+
+85
+00:05:29,000 --> 00:05:32,000
+Things such as access to the control panel is wiped out.
+
+86
+00:05:32,000 --> 00:05:34,000
+So we have a certain set.
+
+87
+00:05:34,000 --> 00:05:41,000
+These are all configurations that has to get done before the machine can go on to the network and people
+
+88
+00:05:41,000 --> 00:05:43,000
+to start using it now.
+
+89
+00:05:44,000 --> 00:05:50,000
+Now that we have documented and this is all we want done, we get to deploy this configuration.
+
+90
+00:05:50,000 --> 00:05:57,000
+So implementation the secure baselines are implemented across the entire entire network.
+
+91
+00:05:57,000 --> 00:05:59,000
+This includes servers workstations.
+
+92
+00:05:59,000 --> 00:06:05,000
+Now I want to point out that secure baselines just doesn't only apply to workstations, they apply to
+
+93
+00:06:05,000 --> 00:06:05,000
+servers.
+
+94
+00:06:05,000 --> 00:06:09,000
+They're going to apply to routers, switches, firewalls and so on.
+
+95
+00:06:09,000 --> 00:06:14,000
+The best way to push this out is with image and software.
+
+96
+00:06:14,000 --> 00:06:21,000
+Image and software helps to automate the deployment of these configurations.
+
+97
+00:06:21,000 --> 00:06:22,000
+So what is an image.
+
+98
+00:06:22,000 --> 00:06:23,000
+So here's what we do.
+
+99
+00:06:23,000 --> 00:06:29,000
+The easiest way for us to ensure that all these machines have a standard set of configuration is we
+
+100
+00:06:29,000 --> 00:06:30,000
+take one machine.
+
+101
+00:06:30,000 --> 00:06:36,000
+We build this machine absolutely perfect with the right windows installation configurations of the group
+
+102
+00:06:36,000 --> 00:06:42,000
+policies, file permission, user accounts, installed software patches, and so on.
+
+103
+00:06:43,000 --> 00:06:45,000
+We then image that machine.
+
+104
+00:06:45,000 --> 00:06:49,000
+We pull out an image and then we apply that image to the other computers.
+
+105
+00:06:49,000 --> 00:06:51,000
+Now this can be done manually.
+
+106
+00:06:51,000 --> 00:06:52,000
+You know there's a variety.
+
+107
+00:06:52,000 --> 00:06:54,000
+You know we used to use a software.
+
+108
+00:06:54,000 --> 00:06:56,000
+It was really good called Clone Deploy.
+
+109
+00:06:56,000 --> 00:06:58,000
+There was tons of Imogen back in the days.
+
+110
+00:06:58,000 --> 00:07:00,000
+I'm not sure if this one still exists.
+
+111
+00:07:00,000 --> 00:07:03,000
+Very famous was Norton, Ghost or Enterprise goals.
+
+112
+00:07:03,000 --> 00:07:06,000
+Those are amazing software that you can just push images out.
+
+113
+00:07:06,000 --> 00:07:08,000
+Helps to automate it.
+
+114
+00:07:08,000 --> 00:07:09,000
+When it's done.
+
+115
+00:07:09,000 --> 00:07:14,000
+You want to verify and make sure that after the deployment the configurations are there.
+
+116
+00:07:14,000 --> 00:07:15,000
+Compliance check.
+
+117
+00:07:15,000 --> 00:07:18,000
+Make sure that they are configured to the standard.
+
+118
+00:07:18,000 --> 00:07:21,000
+Go through the machines and verify whatever you had set up.
+
+119
+00:07:21,000 --> 00:07:24,000
+Whatever your company wanted is actually there.
+
+120
+00:07:24,000 --> 00:07:26,000
+Now comes maintenance.
+
+121
+00:07:28,000 --> 00:07:31,000
+This is the hard part, trust me.
+
+122
+00:07:31,000 --> 00:07:36,000
+You see, when the machine goes into production, people start installing things.
+
+123
+00:07:36,000 --> 00:07:39,000
+People start requesting changes.
+
+124
+00:07:39,000 --> 00:07:44,000
+The machine may lose some of its patches or not get updated to the current patches.
+
+125
+00:07:44,000 --> 00:07:49,000
+So you have to make sure that you continuously monitor.
+
+126
+00:07:49,000 --> 00:07:51,000
+You have to audit machines.
+
+127
+00:07:51,000 --> 00:07:55,000
+So continuously monitoring is to ensure the system remains in compliance.
+
+128
+00:07:55,000 --> 00:07:58,000
+No one is changing those configurations.
+
+129
+00:07:58,000 --> 00:07:59,000
+Audit them.
+
+130
+00:07:59,000 --> 00:08:01,000
+Audit them means to literally go and check them.
+
+131
+00:08:01,000 --> 00:08:08,000
+Take a couple of machines and couple departments at random and see, well, are they actually still
+
+132
+00:08:08,000 --> 00:08:11,000
+in or still on the baseline?
+
+133
+00:08:12,000 --> 00:08:17,000
+You want to make sure that you continuously update and patch machines.
+
+134
+00:08:17,000 --> 00:08:22,000
+I have never seen a baseline that didn't have updated patches, and then ongoing training and awareness
+
+135
+00:08:22,000 --> 00:08:24,000
+let people know that there is a baseline.
+
+136
+00:08:24,000 --> 00:08:27,000
+We do have a program for this and all texts coming in.
+
+137
+00:08:27,000 --> 00:08:29,000
+All users are aware of your baseline.
+
+138
+00:08:31,000 --> 00:08:36,000
+Do not manage your workstations, your computers, your server or your network.
+
+139
+00:08:36,000 --> 00:08:37,000
+AD hoc.
+
+140
+00:08:38,000 --> 00:08:43,000
+Every machine, especially when they're bound to departments, should have a standard set of configurations,
+
+141
+00:08:43,000 --> 00:08:47,000
+and those standard set of configurations help you to keep your network secure.
+
+142
+00:08:47,000 --> 00:08:53,000
+And this is one of the reasons I should say the main reasons that we should be using baselines.
+
diff --git a/13 - Common Security Techniques/002 Hardening Devices OB 4.1_en.srt b/13 - Common Security Techniques/002 Hardening Devices OB 4.1_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..abddda0949a5b7b2e1450cf48ebadb2a9104a214
--- /dev/null
+++ b/13 - Common Security Techniques/002 Hardening Devices OB 4.1_en.srt
@@ -0,0 +1,1088 @@
+1
+00:00:00,000 --> 00:00:06,000
+On your network, you're going to have a wide variety of devices from mobile devices, routers, IoT
+
+2
+00:00:06,000 --> 00:00:08,000
+devices, and everything else in between.
+
+3
+00:00:08,000 --> 00:00:15,000
+In this video, I want to do a quick review of how to secure a wide variety of devices on your network.
+
+4
+00:00:15,000 --> 00:00:16,000
+So let's knock this out.
+
+5
+00:00:16,000 --> 00:00:19,000
+Now this is more like a review video.
+
+6
+00:00:19,000 --> 00:00:20,000
+That's something you should be learning new.
+
+7
+00:00:20,000 --> 00:00:22,000
+As I've covered most of these things.
+
+8
+00:00:22,000 --> 00:00:24,000
+The team here is called Harden.
+
+9
+00:00:24,000 --> 00:00:24,000
+It.
+
+10
+00:00:24,000 --> 00:00:26,000
+Harden makes things more secure.
+
+11
+00:00:26,000 --> 00:00:27,000
+Harden against what.
+
+12
+00:00:28,000 --> 00:00:29,000
+Harden against cyber attacks.
+
+13
+00:00:29,000 --> 00:00:31,000
+That's what this is.
+
+14
+00:00:31,000 --> 00:00:37,000
+So it refers to the process of strengthening various hardware components to make them more secure.
+
+15
+00:00:37,000 --> 00:00:41,000
+This is going to involve implementing different types of security measures and different configurations
+
+16
+00:00:41,000 --> 00:00:43,000
+to these devices.
+
+17
+00:00:43,000 --> 00:00:45,000
+So let's get started.
+
+18
+00:00:45,000 --> 00:00:46,000
+And all of these different things.
+
+19
+00:00:46,000 --> 00:00:52,000
+Number one we're going to talk about what I consider device that most people spend most of their time
+
+20
+00:00:52,000 --> 00:00:53,000
+on.
+
+21
+00:00:53,000 --> 00:00:56,000
+This one little thing, our mobile devices.
+
+22
+00:00:56,000 --> 00:01:03,000
+Now when it comes to mobile devices such as my phone now this video is not about functionality.
+
+23
+00:01:03,000 --> 00:01:03,000
+All right?
+
+24
+00:01:03,000 --> 00:01:06,000
+This video is just about how do we secure these devices.
+
+25
+00:01:06,000 --> 00:01:08,000
+So the first thing we want to do is strong authentication.
+
+26
+00:01:08,000 --> 00:01:10,000
+You guys should have a strong Pin.
+
+27
+00:01:10,000 --> 00:01:12,000
+You should have dual authentication.
+
+28
+00:01:12,000 --> 00:01:15,000
+You can put pins and biometrics.
+
+29
+00:01:15,000 --> 00:01:17,000
+The data on these devices are encrypted.
+
+30
+00:01:17,000 --> 00:01:18,000
+And that's good.
+
+31
+00:01:18,000 --> 00:01:23,000
+If not you want to make sure that encryption is is enabled.
+
+32
+00:01:23,000 --> 00:01:25,000
+Installation of security software.
+
+33
+00:01:25,000 --> 00:01:30,000
+It boggles my mind that many devices, many people don't have antivirus software installed on their
+
+34
+00:01:30,000 --> 00:01:31,000
+devices.
+
+35
+00:01:31,000 --> 00:01:36,000
+You want to be able to control app permissions, and a lot of mobile devices does allow you to control
+
+36
+00:01:36,000 --> 00:01:37,000
+that.
+
+37
+00:01:37,000 --> 00:01:39,000
+Certain apps cannot access certain data.
+
+38
+00:01:39,000 --> 00:01:44,000
+Anytime you install an app, and the app asks you to access to certain data, such as your phone book
+
+39
+00:01:44,000 --> 00:01:46,000
+or your geolocation.
+
+40
+00:01:46,000 --> 00:01:49,000
+Unless you really need that app, it's probably not a good idea.
+
+41
+00:01:49,000 --> 00:01:55,000
+The more app that has access you have granted access to your private information is, the bigger the
+
+42
+00:01:55,000 --> 00:01:56,000
+attack surface.
+
+43
+00:01:56,000 --> 00:02:02,000
+Because if one of those apps ever get a vulnerability, your data is history, regularly updated.
+
+44
+00:02:03,000 --> 00:02:06,000
+Samsung pushes updates and a consistent basis.
+
+45
+00:02:06,000 --> 00:02:12,000
+Maybe on a weekly basis you should be updating apps and your operating system as much as possible.
+
+46
+00:02:12,000 --> 00:02:15,000
+It also included you secure Wi-Fi.
+
+47
+00:02:15,000 --> 00:02:17,000
+Don't join public Wi-Fi.
+
+48
+00:02:17,000 --> 00:02:19,000
+Public Wi-Fi are bad news.
+
+49
+00:02:19,000 --> 00:02:22,000
+You don't know who's on there or where it's coming from.
+
+50
+00:02:22,000 --> 00:02:27,000
+The best thing to do is always try to use your phone internet connection to your ISP and if you do need
+
+51
+00:02:27,000 --> 00:02:28,000
+a Wi-Fi.
+
+52
+00:02:29,000 --> 00:02:34,000
+If you do need some kind of Wi-Fi connection, like on your laptop, you can always do internet connection
+
+53
+00:02:34,000 --> 00:02:36,000
+sharing from your phone, but never use public Wi-Fi.
+
+54
+00:02:36,000 --> 00:02:38,000
+I try to stay off of public Wi-Fi.
+
+55
+00:02:38,000 --> 00:02:45,000
+Use secure Wi-Fi, and if you ever connect to a public Wi-Fi, you need to get to your corporate network.
+
+56
+00:02:45,000 --> 00:02:48,000
+Make sure to use a VPN for another layer of encryption.
+
+57
+00:02:49,000 --> 00:02:50,000
+Okay, moving on here.
+
+58
+00:02:50,000 --> 00:02:50,000
+Workstation.
+
+59
+00:02:50,000 --> 00:02:52,000
+This is what you're going to have at work.
+
+60
+00:02:52,000 --> 00:02:54,000
+Like that picture shows you.
+
+61
+00:02:54,000 --> 00:02:57,000
+So when it comes to workstations, what are we going to do?
+
+62
+00:02:57,000 --> 00:03:04,000
+Well, good endpoint security software should give you things like antivirus, anti-malware, firewalls
+
+63
+00:03:04,000 --> 00:03:06,000
+are going to be some of the most common things.
+
+64
+00:03:06,000 --> 00:03:11,000
+You want to make sure that you're always patching all the time.
+
+65
+00:03:11,000 --> 00:03:12,000
+I like automatic updates.
+
+66
+00:03:12,000 --> 00:03:15,000
+I understand that certain organizations like to test updates.
+
+67
+00:03:15,000 --> 00:03:18,000
+That's fine, but roll out those updates as soon as you could.
+
+68
+00:03:18,000 --> 00:03:20,000
+Good access controls, for example.
+
+69
+00:03:20,000 --> 00:03:23,000
+File permissions is going to be important.
+
+70
+00:03:23,000 --> 00:03:25,000
+Remember the principles of least privileges and so on.
+
+71
+00:03:25,000 --> 00:03:30,000
+Users shouldn't have admin privileges on the boxes, and something that a lot of people don't think
+
+72
+00:03:30,000 --> 00:03:34,000
+about when it comes to workstations is the actual physical security.
+
+73
+00:03:34,000 --> 00:03:37,000
+You know, here's something in organizations.
+
+74
+00:03:37,000 --> 00:03:43,000
+Sometimes organizations will the cases are actually padlocked.
+
+75
+00:03:43,000 --> 00:03:46,000
+You can't get into the case to take out the hard drive.
+
+76
+00:03:46,000 --> 00:03:50,000
+Malicious employees, when they want to steal data, copies all the data to the hard drive.
+
+77
+00:03:51,000 --> 00:03:55,000
+It opens the case, takes the hard drive out, put in their pocket and walk out the organization and
+
+78
+00:03:55,000 --> 00:03:57,000
+your data is leaving with them.
+
+79
+00:03:57,000 --> 00:03:59,000
+So you may.
+
+80
+00:03:59,000 --> 00:04:04,000
+Or maybe you should physically protect the workstations on those desks.
+
+81
+00:04:04,000 --> 00:04:08,000
+Of course, you want to also have things like the TPM chip.
+
+82
+00:04:08,000 --> 00:04:16,000
+TPM chips enables BitLocker encryption or hard disk hard drive based encryptions on those machines.
+
+83
+00:04:16,000 --> 00:04:18,000
+The next thing you have is switches.
+
+84
+00:04:18,000 --> 00:04:19,000
+All right.
+
+85
+00:04:19,000 --> 00:04:24,000
+So if you remember we talked about securing these giant switches.
+
+86
+00:04:24,000 --> 00:04:28,000
+And this is a 24 port Cisco switch that I have here.
+
+87
+00:04:28,000 --> 00:04:32,000
+We want to be able to secure these kinds of devices.
+
+88
+00:04:32,000 --> 00:04:33,000
+Now how do we harden switches.
+
+89
+00:04:34,000 --> 00:04:39,000
+Switches especially managed switches comes with a lot of services that you may not need.
+
+90
+00:04:39,000 --> 00:04:41,000
+Make sure to shut them off.
+
+91
+00:04:41,000 --> 00:04:48,000
+In short that the management, the secure management and the login to its interfaces can only be done
+
+92
+00:04:48,000 --> 00:04:51,000
+in certain locations or to certain interfaces.
+
+93
+00:04:51,000 --> 00:04:53,000
+Restrict those IP addresses.
+
+94
+00:04:53,000 --> 00:04:58,000
+All managed switches like I have here supports Vlan VLANs.
+
+95
+00:04:58,000 --> 00:04:59,000
+Allows you to segment your network.
+
+96
+00:04:59,000 --> 00:05:02,000
+Implement a VLANs on all these switches.
+
+97
+00:05:02,000 --> 00:05:05,000
+Utilize ACLs to control traffic in and out the switch.
+
+98
+00:05:05,000 --> 00:05:13,000
+Now just like you would have on a windows box or Linux or Apple, you must update the switches firmware.
+
+99
+00:05:13,000 --> 00:05:17,000
+The firmware updates is how we would apply like Windows Update.
+
+100
+00:05:18,000 --> 00:05:23,000
+You also want to monitor the monitor them for any unusual activities against them.
+
+101
+00:05:24,000 --> 00:05:27,000
+Routers are going to be just like switches.
+
+102
+00:05:27,000 --> 00:05:31,000
+Now I know you guys have your the router that was given to you by your ISP.
+
+103
+00:05:31,000 --> 00:05:36,000
+Those routers are probably going to be something similar to what I have here.
+
+104
+00:05:36,000 --> 00:05:42,000
+Now these devices has to be updated just like your switches are.
+
+105
+00:05:42,000 --> 00:05:46,000
+You want to make sure a couple of things change the default passwords on these devices.
+
+106
+00:05:46,000 --> 00:05:51,000
+These devices does come at a lot of services that you may or may not need.
+
+107
+00:05:51,000 --> 00:05:53,000
+Make sure to update the firmware.
+
+108
+00:05:54,000 --> 00:05:55,000
+Strong encryption on them.
+
+109
+00:05:55,000 --> 00:06:00,000
+And when you configure the Wi-Fi, especially like on this one, you want to make sure you set up with
+
+110
+00:06:00,000 --> 00:06:02,000
+the latest wpa3.
+
+111
+00:06:02,000 --> 00:06:04,000
+If not at minimum Wpa2.
+
+112
+00:06:04,000 --> 00:06:06,000
+Make sure you use good passwords.
+
+113
+00:06:06,000 --> 00:06:08,000
+Configure the firewalls on them.
+
+114
+00:06:08,000 --> 00:06:12,000
+Don't open unnecessary ports on these particular if these particular devices.
+
+115
+00:06:12,000 --> 00:06:16,000
+If it's a firewall built in and configure that intrusion prevention system.
+
+116
+00:06:16,000 --> 00:06:19,000
+Now if your device.
+
+117
+00:06:20,000 --> 00:06:22,000
+If the device itself.
+
+118
+00:06:22,000 --> 00:06:29,000
+Supports VPN and you want to allow access in, then you may want to enable VPNs on the devices.
+
+119
+00:06:29,000 --> 00:06:31,000
+When it comes to cloud.
+
+120
+00:06:31,000 --> 00:06:39,000
+Cloud brings so much functionality, but it also brings a lot of problems.
+
+121
+00:06:39,000 --> 00:06:40,000
+Cloud.
+
+122
+00:06:41,000 --> 00:06:48,000
+Cloud, you know, reduces cost, increases availability, gives you tons of different services that
+
+123
+00:06:48,000 --> 00:06:50,000
+you can only dream of, have on.
+
+124
+00:06:50,000 --> 00:06:56,000
+The problem with cloud is that it brings in quite a lot of different issues.
+
+125
+00:06:57,000 --> 00:06:58,000
+Data being lost.
+
+126
+00:06:58,000 --> 00:07:03,000
+Remember, if I can access my data in the cloud from anywhere, you can also access my data in the cloud
+
+127
+00:07:03,000 --> 00:07:04,000
+from anywhere.
+
+128
+00:07:04,000 --> 00:07:06,000
+Maybe you're a bad person.
+
+129
+00:07:06,000 --> 00:07:08,000
+And you you want to hack people's data.
+
+130
+00:07:09,000 --> 00:07:13,000
+You find out my password on my login credentials on grass.
+
+131
+00:07:13,000 --> 00:07:15,000
+So you want to make sure that you secure it.
+
+132
+00:07:15,000 --> 00:07:16,000
+How are we going to do this?
+
+133
+00:07:16,000 --> 00:07:21,000
+Well, like I said, because I can access it anywhere.
+
+134
+00:07:21,000 --> 00:07:21,000
+So can you.
+
+135
+00:07:21,000 --> 00:07:24,000
+We got to implement strong identity and access management.
+
+136
+00:07:24,000 --> 00:07:27,000
+This is an IAM identity and access management.
+
+137
+00:07:27,000 --> 00:07:30,000
+This is going to be like multiple factor authentication.
+
+138
+00:07:30,000 --> 00:07:33,000
+Like no one should be able to log in to the cloud with just a password.
+
+139
+00:07:33,000 --> 00:07:34,000
+They put in a password.
+
+140
+00:07:34,000 --> 00:07:40,000
+Let them do a multi factor authentication, send a code to my phone, send a code to my email.
+
+141
+00:07:40,000 --> 00:07:42,000
+So it's not just a single factor authentication.
+
+142
+00:07:42,000 --> 00:07:44,000
+Make sure that you encrypt the data in the cloud.
+
+143
+00:07:44,000 --> 00:07:46,000
+Data coming out the cloud.
+
+144
+00:07:46,000 --> 00:07:52,000
+Make sure you're utilizing secure protocols like Https or SSL in there.
+
+145
+00:07:52,000 --> 00:07:54,000
+Use secure APIs.
+
+146
+00:07:54,000 --> 00:07:56,000
+APIs also need encryption APIs.
+
+147
+00:07:56,000 --> 00:08:00,000
+How we're going to transfer data between applications in the cloud and outside the cloud.
+
+148
+00:08:00,000 --> 00:08:03,000
+Make sure we put good security controls.
+
+149
+00:08:03,000 --> 00:08:10,000
+Now, cloud providers such as AWS will tell you some of the best practices they recommend when using
+
+150
+00:08:10,000 --> 00:08:11,000
+their cloud services.
+
+151
+00:08:11,000 --> 00:08:12,000
+You're going to want to make sure you follow that.
+
+152
+00:08:13,000 --> 00:08:14,000
+Service.
+
+153
+00:08:14,000 --> 00:08:16,000
+We talked about workstations.
+
+154
+00:08:16,000 --> 00:08:19,000
+Let's talk about servers, servers themselves.
+
+155
+00:08:20,000 --> 00:08:26,000
+Is going to follow almost the same thing as workstations, because technically they're just a workstation
+
+156
+00:08:26,000 --> 00:08:27,000
+used by a lot of people.
+
+157
+00:08:27,000 --> 00:08:32,000
+So service, we want to make sure, number one, you got to keep your servers updated, just like with
+
+158
+00:08:32,000 --> 00:08:38,000
+any other computer, with anything in your network, anything that runs software needs to be updated.
+
+159
+00:08:38,000 --> 00:08:40,000
+You want to minimize the number of running services.
+
+160
+00:08:40,000 --> 00:08:45,000
+Remember, the more application, the more services you're running on there.
+
+161
+00:08:45,000 --> 00:08:47,000
+Maybe you're running an FTP, maybe you're running telnet.
+
+162
+00:08:47,000 --> 00:08:51,000
+The maybe you're running a print server, maybe you're running a particular file service.
+
+163
+00:08:51,000 --> 00:08:58,000
+The more services you're running, the more vulnerable the bigger your attack surface.
+
+164
+00:08:58,000 --> 00:09:01,000
+The best thing here we can do is to reduce them.
+
+165
+00:09:01,000 --> 00:09:09,000
+If this server only serves as a web server disabled print, disable FTP or shut it off or make sure
+
+166
+00:09:09,000 --> 00:09:10,000
+it's not installed.
+
+167
+00:09:10,000 --> 00:09:13,000
+Telnet file services.
+
+168
+00:09:13,000 --> 00:09:19,000
+If it's only a web server, let it be just a good web server.
+
+169
+00:09:19,000 --> 00:09:22,000
+A hardened web server only does one thing serves web pages.
+
+170
+00:09:22,000 --> 00:09:27,000
+So disable all those services that it doesn't need strong authentication.
+
+171
+00:09:27,000 --> 00:09:31,000
+Make sure sometimes a windows box may only support password.
+
+172
+00:09:31,000 --> 00:09:33,000
+Make sure it's a long 12 digit password.
+
+173
+00:09:33,000 --> 00:09:36,000
+At least use firewalls and intrusion detection systems.
+
+174
+00:09:36,000 --> 00:09:39,000
+You're going to get this with good endpoint security.
+
+175
+00:09:39,000 --> 00:09:44,000
+Uh, and physically of course securing your servers I don't care how secure.
+
+176
+00:09:44,000 --> 00:09:45,000
+I don't care how secure.
+
+177
+00:09:45,000 --> 00:09:51,000
+You got your firewalls, intrusion detection system, all the great software you're using.
+
+178
+00:09:51,000 --> 00:09:56,000
+If I can walk in your organization and pick up your server, just walk back out.
+
+179
+00:09:57,000 --> 00:09:58,000
+You really don't have much security, do you?
+
+180
+00:09:59,000 --> 00:10:04,000
+So make sure you physically secure it and put them in server rooms, locked server rooms, put them
+
+181
+00:10:04,000 --> 00:10:06,000
+on racks where they are physically bolted in.
+
+182
+00:10:06,000 --> 00:10:08,000
+Make it hard to get out.
+
+183
+00:10:09,000 --> 00:10:10,000
+IX.
+
+184
+00:10:10,000 --> 00:10:13,000
+This one here scares the hell out of me.
+
+185
+00:10:14,000 --> 00:10:16,000
+Remember what IX systems are.
+
+186
+00:10:17,000 --> 00:10:23,000
+IX industrial controls, the control systems and basically skater based systems.
+
+187
+00:10:23,000 --> 00:10:28,000
+Now, the problem with these systems, you know, the thing that scares me, that creates a problem
+
+188
+00:10:28,000 --> 00:10:30,000
+is that these things controls.
+
+189
+00:10:30,000 --> 00:10:33,000
+If you remember, we did discuss this earlier in the class.
+
+190
+00:10:33,000 --> 00:10:40,000
+These things controls our water supply, uh, gas and power.
+
+191
+00:10:40,000 --> 00:10:41,000
+All right.
+
+192
+00:10:41,000 --> 00:10:44,000
+These are some of the things that controls this is industrial equipment.
+
+193
+00:10:44,000 --> 00:10:51,000
+And because they're industrial based systems, when these systems, if they get hacked and they go down,
+
+194
+00:10:51,000 --> 00:10:54,000
+now we start to disrupt lives and people could potentially dies.
+
+195
+00:10:54,000 --> 00:10:57,000
+Communities can be without water.
+
+196
+00:10:57,000 --> 00:11:00,000
+Communities can be without power for extended periods of time.
+
+197
+00:11:00,000 --> 00:11:02,000
+People can lose their lives because of this.
+
+198
+00:11:02,000 --> 00:11:04,000
+What happens if all the power shuts off?
+
+199
+00:11:04,000 --> 00:11:09,000
+One day, all the traffic lights start shutting off and traffic accidents start happening.
+
+200
+00:11:09,000 --> 00:11:09,000
+People start dying.
+
+201
+00:11:09,000 --> 00:11:13,000
+What happens if there's no water in a community for an extended period of time?
+
+202
+00:11:13,000 --> 00:11:18,000
+What if there's no power in a community for an extended period of time and hospitals lose power and
+
+203
+00:11:18,000 --> 00:11:20,000
+their generators don't last two weeks?
+
+204
+00:11:20,000 --> 00:11:21,000
+Now what happens?
+
+205
+00:11:21,000 --> 00:11:22,000
+People die.
+
+206
+00:11:22,000 --> 00:11:23,000
+This is serious business.
+
+207
+00:11:23,000 --> 00:11:25,000
+So we need to protect these systems.
+
+208
+00:11:25,000 --> 00:11:27,000
+First of all, you should segment them off.
+
+209
+00:11:27,000 --> 00:11:30,000
+Keep SCADA systems off the network.
+
+210
+00:11:30,000 --> 00:11:33,000
+Maybe even air gapped them so no one can get to them.
+
+211
+00:11:33,000 --> 00:11:34,000
+Restricting their access.
+
+212
+00:11:34,000 --> 00:11:36,000
+Their physical access like air gap.
+
+213
+00:11:36,000 --> 00:11:38,000
+Disable unneeded services.
+
+214
+00:11:38,000 --> 00:11:45,000
+Remember reduce the attack surface if you could patch it, but be careful how you patch it because patching
+
+215
+00:11:45,000 --> 00:11:46,000
+can bring these systems down.
+
+216
+00:11:47,000 --> 00:11:51,000
+And of course, consistent monitoring of these systems.
+
+217
+00:11:53,000 --> 00:11:54,000
+Embedded systems.
+
+218
+00:11:54,000 --> 00:11:56,000
+Now we went over embedded systems.
+
+219
+00:11:56,000 --> 00:11:57,000
+Right.
+
+220
+00:11:57,000 --> 00:12:01,000
+Embedded systems are going to be systems generally within another system performs a very particular
+
+221
+00:12:01,000 --> 00:12:02,000
+function.
+
+222
+00:12:02,000 --> 00:12:05,000
+You want to make sure that they have a secure boot process.
+
+223
+00:12:05,000 --> 00:12:11,000
+What that means is that no one can inject codes into the boot process to take them over, give them
+
+224
+00:12:11,000 --> 00:12:12,000
+least access.
+
+225
+00:12:12,000 --> 00:12:13,000
+All right.
+
+226
+00:12:13,000 --> 00:12:15,000
+Least access to in terms of access control.
+
+227
+00:12:16,000 --> 00:12:21,000
+Embedded systems is generally going to communicate to another system, use secure protocols or secure
+
+228
+00:12:21,000 --> 00:12:22,000
+communication channel.
+
+229
+00:12:22,000 --> 00:12:24,000
+And of course, audit them on a regular basis.
+
+230
+00:12:24,000 --> 00:12:29,000
+A lot of these embedded systems, for example, like the embedded systems you may have on your TV to
+
+231
+00:12:29,000 --> 00:12:33,000
+powers up your TV operating system, have when was the last you updated them?
+
+232
+00:12:33,000 --> 00:12:35,000
+Because it could have vulnerabilities.
+
+233
+00:12:36,000 --> 00:12:38,000
+Real time operating system.
+
+234
+00:12:38,000 --> 00:12:43,000
+Really small system performed generally a very particular task, these things.
+
+235
+00:12:43,000 --> 00:12:46,000
+The good thing is that they don't have a lot of services running.
+
+236
+00:12:46,000 --> 00:12:52,000
+They're very small and the very quick, but if they have a number of services that they could perform,
+
+237
+00:12:52,000 --> 00:12:58,000
+reduce that good access control, make them hard to get good communication protocol.
+
+238
+00:12:58,000 --> 00:13:03,000
+And once again, consistent updating of these systems is important.
+
+239
+00:13:04,000 --> 00:13:08,000
+Throughout your house, you're going to have tons of IoT devices.
+
+240
+00:13:09,000 --> 00:13:10,000
+Remember what IoT is.
+
+241
+00:13:10,000 --> 00:13:11,000
+Internet of things.
+
+242
+00:13:11,000 --> 00:13:18,000
+Anything that connects to the internet, your fridge, your TV, uh, your car.
+
+243
+00:13:19,000 --> 00:13:24,000
+Your watch, all these kinds of devices that now connects to the internet.
+
+244
+00:13:24,000 --> 00:13:27,000
+Now what we need to do is we need to secure them.
+
+245
+00:13:27,000 --> 00:13:30,000
+First of all, a lot of them come with default passwords.
+
+246
+00:13:30,000 --> 00:13:31,000
+Change the default password.
+
+247
+00:13:31,000 --> 00:13:38,000
+You want to make sure that the device is configured not to use things like Http, but to use Https,
+
+248
+00:13:38,000 --> 00:13:45,000
+not to use FTP, use SftP or ftps so it's secure, always updated, disable unneeded services, and
+
+249
+00:13:45,000 --> 00:13:49,000
+of course implement security at what's called the application layer.
+
+250
+00:13:49,000 --> 00:13:53,000
+This is going to be doing a lot to ensure that it has the right application on it.
+
+251
+00:13:53,000 --> 00:13:59,000
+In other words, good passwords like I mentioned don't use FTP Ftps.
+
+252
+00:13:59,000 --> 00:14:02,000
+All right quick review now.
+
+253
+00:14:02,000 --> 00:14:05,000
+There is now that I've gone through it.
+
+254
+00:14:06,000 --> 00:14:12,000
+If you notice there is a standard set of things.
+
+255
+00:14:12,000 --> 00:14:15,000
+Doesn't matter what the device is, you should be doing.
+
+256
+00:14:15,000 --> 00:14:16,000
+All right.
+
+257
+00:14:16,000 --> 00:14:21,000
+Let me go through that quickly, because these were all the devices that we should be familiar with
+
+258
+00:14:21,000 --> 00:14:22,000
+for our exam.
+
+259
+00:14:22,000 --> 00:14:25,000
+But there was a standard set of things that was in every one of them.
+
+260
+00:14:25,000 --> 00:14:30,000
+Number one updates anything that's software related.
+
+261
+00:14:30,000 --> 00:14:37,000
+Updated number two, reducing the attack surface, if anything is configurable, reduce its attack surface
+
+262
+00:14:37,000 --> 00:14:42,000
+by not installing applications and services that it just doesn't need to run.
+
+263
+00:14:43,000 --> 00:14:47,000
+The other thing you want to do is, of course change default credentials and have good authentication
+
+264
+00:14:47,000 --> 00:14:50,000
+mechanism across all these devices.
+
+265
+00:14:50,000 --> 00:14:52,000
+These were three of the most common things we saw.
+
+266
+00:14:52,000 --> 00:14:57,000
+These are the three of the most common things that you're probably going to be implementing.
+
+267
+00:14:57,000 --> 00:15:02,000
+The other common things that doesn't apply to all of them are going to be things that can stall an anti-malware,
+
+268
+00:15:02,000 --> 00:15:07,000
+um, things like antivirus, firewalls, IDs, systems, which you can't do that for every device.
+
+269
+00:15:07,000 --> 00:15:13,000
+You may not have the ability to go onto your TV and install an anti-malware software, but at minimum,
+
+270
+00:15:13,000 --> 00:15:14,000
+you should change its password.
+
+271
+00:15:14,000 --> 00:15:15,000
+All right.
+
+272
+00:15:15,000 --> 00:15:20,000
+Remember these methods to keeping all of the devices in your network secure.
+
diff --git a/13 - Common Security Techniques/003 Installations of Mobile Devices OB 4.1_en.srt b/13 - Common Security Techniques/003 Installations of Mobile Devices OB 4.1_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..1271ec1aa1b697fd1933f78252f9b4cfb23729ca
--- /dev/null
+++ b/13 - Common Security Techniques/003 Installations of Mobile Devices OB 4.1_en.srt
@@ -0,0 +1,336 @@
+1
+00:00:00,000 --> 00:00:07,000
+Every single organization that I know of has some kind of mobile devices that they have running, whether
+
+2
+00:00:07,000 --> 00:00:11,000
+it's phones, tablets or even laptops.
+
+3
+00:00:11,000 --> 00:00:17,000
+Now, in order to make these mobile devices work, you have to install the wireless connection needed
+
+4
+00:00:17,000 --> 00:00:17,000
+to make them work.
+
+5
+00:00:17,000 --> 00:00:24,000
+So in this video, I want to take a look at two things that we should be considering when we're installing
+
+6
+00:00:24,000 --> 00:00:25,000
+mobile devices.
+
+7
+00:00:25,000 --> 00:00:26,000
+Two things we should be doing.
+
+8
+00:00:26,000 --> 00:00:33,000
+Basically, we should be doing a site survey and creating a heat map when we do install our mobile devices,
+
+9
+00:00:33,000 --> 00:00:37,000
+and I'm our wireless networks, and this is going to be something that you should be doing.
+
+10
+00:00:37,000 --> 00:00:39,000
+Like if you don't do this, you're going to be in big trouble.
+
+11
+00:00:39,000 --> 00:00:45,000
+And I'll explain why, especially with the heat map coming up in a few minutes, because wireless devices
+
+12
+00:00:45,000 --> 00:00:47,000
+require good performance.
+
+13
+00:00:47,000 --> 00:00:51,000
+In other words, depending on where I am in the network, I need good signal.
+
+14
+00:00:51,000 --> 00:00:54,000
+And of course, you want to make sure that they are secure.
+
+15
+00:00:54,000 --> 00:00:56,000
+So the first thing we want to talk about.
+
+16
+00:00:56,000 --> 00:01:00,000
+Is going to be a site survey.
+
+17
+00:01:00,000 --> 00:01:02,000
+Now, what exactly is a site survey?
+
+18
+00:01:02,000 --> 00:01:11,000
+Well, a site survey is literally walking around and quote unquote surveying the physical site that
+
+19
+00:01:11,000 --> 00:01:14,000
+actually needs the wireless signals.
+
+20
+00:01:14,000 --> 00:01:19,000
+So it involves identifying potential security vulnerabilities, like areas where the wireless signal
+
+21
+00:01:19,000 --> 00:01:22,000
+might bleed outside the intended coverage area.
+
+22
+00:01:22,000 --> 00:01:29,000
+For example, if you are installing a company's Wi-Fi, I should not be able to stand across the road
+
+23
+00:01:29,000 --> 00:01:33,000
+of your organization and pick up your company's Wi-Fi network.
+
+24
+00:01:33,000 --> 00:01:37,000
+That would be pretty bad, because then somebody can sit across the road and attempt to brute force
+
+25
+00:01:37,000 --> 00:01:38,000
+and break into your network.
+
+26
+00:01:38,000 --> 00:01:40,000
+You'll just never know about it.
+
+27
+00:01:40,000 --> 00:01:43,000
+So you would have to look for those things that could happen.
+
+28
+00:01:43,000 --> 00:01:47,000
+Where could the signal bleed out if I put the access point here?
+
+29
+00:01:47,000 --> 00:01:49,000
+If I put it here, what can happen?
+
+30
+00:01:49,000 --> 00:01:55,000
+So access point should be placed in secure tamper, uh, tamper resistant location to prevent physical
+
+31
+00:01:55,000 --> 00:01:56,000
+manipulation.
+
+32
+00:01:56,000 --> 00:02:00,000
+You don't want people just to be able to see the access point, remove the access point and tamper with
+
+33
+00:02:00,000 --> 00:02:01,000
+it.
+
+34
+00:02:01,000 --> 00:02:05,000
+When you're doing a site survey, ask yourself where would be best for me to place this access point?
+
+35
+00:02:05,000 --> 00:02:08,000
+Certain environmental factors.
+
+36
+00:02:08,000 --> 00:02:11,000
+What type of building materials can interfere with the signal.
+
+37
+00:02:11,000 --> 00:02:14,000
+Thick concrete wall may interfere with the signal.
+
+38
+00:02:14,000 --> 00:02:15,000
+Where?
+
+39
+00:02:15,000 --> 00:02:22,000
+Where you place it has a direct impact on the quality of the signal that people are going to get.
+
+40
+00:02:23,000 --> 00:02:27,000
+By placing an access point in certain locations, does it create a blind spot?
+
+41
+00:02:27,000 --> 00:02:28,000
+All right.
+
+42
+00:02:28,000 --> 00:02:32,000
+Now what is blind spot where potentially create blind spots where intruders could exploit the network
+
+43
+00:02:32,000 --> 00:02:33,000
+weaknesses.
+
+44
+00:02:33,000 --> 00:02:35,000
+Now heat maps.
+
+45
+00:02:35,000 --> 00:02:36,000
+This is important.
+
+46
+00:02:38,000 --> 00:02:43,000
+When you set up a wireless network, you have to draw the heat.
+
+47
+00:02:43,000 --> 00:02:47,000
+Heat maps basically look like a.
+
+48
+00:02:47,000 --> 00:02:53,000
+They look exactly like a map of your network, and it shows where it's red, which means it's good signal
+
+49
+00:02:53,000 --> 00:02:55,000
+and then it may show blue.
+
+50
+00:02:55,000 --> 00:02:56,000
+No signal.
+
+51
+00:02:56,000 --> 00:02:56,000
+It's cold.
+
+52
+00:02:56,000 --> 00:02:57,000
+So what exactly is this?
+
+53
+00:02:57,000 --> 00:03:03,000
+Well, it's a geographical representation of the wireless signal within a space they're used ensuring
+
+54
+00:03:03,000 --> 00:03:04,000
+uniform coverage.
+
+55
+00:03:04,000 --> 00:03:08,000
+Identify real weak signals are and identify where signals may be bleeding out.
+
+56
+00:03:08,000 --> 00:03:15,000
+So if you do a heat map of a wireless signal, you may find that in front of the organization built
+
+57
+00:03:15,000 --> 00:03:17,000
+in there's a strong signal.
+
+58
+00:03:17,000 --> 00:03:22,000
+But in the back of the organization where it still needed by some folks, there's not very good signal.
+
+59
+00:03:23,000 --> 00:03:25,000
+You then need to go and adjust the signal strength.
+
+60
+00:03:25,000 --> 00:03:31,000
+Certain access point, like Cisco's Aironet, does allow you to adjust the amount of signal.
+
+61
+00:03:31,000 --> 00:03:36,000
+For example, if you have an access point in the physical center, you may have it at full blast signal.
+
+62
+00:03:36,000 --> 00:03:40,000
+But if you have an access point more towards the edge of the building, you should decrease the signal
+
+63
+00:03:40,000 --> 00:03:46,000
+to ensure the signal doesn't bleed out, so the signal strength can be adjusted to minimize the chance
+
+64
+00:03:46,000 --> 00:03:48,000
+of interception or unauthorized access.
+
+65
+00:03:49,000 --> 00:03:49,000
+Now.
+
+66
+00:03:50,000 --> 00:03:52,000
+Heat maps are going to be particular.
+
+67
+00:03:52,000 --> 00:03:57,000
+You should be periodically revisiting after the deployments of your heat map.
+
+68
+00:03:57,000 --> 00:04:01,000
+There could be changes in the environment, changes of how people use in it.
+
+69
+00:04:01,000 --> 00:04:05,000
+You can even have new obsolete additional network devices can be joined in.
+
+70
+00:04:06,000 --> 00:04:12,000
+You have new devices, in particular joining your network that is absorbing a lot of that traffic or
+
+71
+00:04:12,000 --> 00:04:13,000
+the signal.
+
+72
+00:04:13,000 --> 00:04:14,000
+And before you know it, people starting getting slow down.
+
+73
+00:04:14,000 --> 00:04:17,000
+So it's important to do heat maps and keep adjusting.
+
+74
+00:04:17,000 --> 00:04:25,000
+Keep redoing the heat map, maybe on a periodic basis, such as at least once a year before you go out
+
+75
+00:04:25,000 --> 00:04:26,000
+and you set up a wireless network.
+
+76
+00:04:26,000 --> 00:04:28,000
+Just don't buy an access point.
+
+77
+00:04:28,000 --> 00:04:30,000
+Stick it on a wall and hopefully it's best.
+
+78
+00:04:30,000 --> 00:04:36,000
+The point of this discussion was, before you do that, you have to determine server your site.
+
+79
+00:04:36,000 --> 00:04:38,000
+Where is it best to place that access point?
+
+80
+00:04:38,000 --> 00:04:40,000
+What type of access point are we going to do?
+
+81
+00:04:40,000 --> 00:04:46,000
+You have access points that have the ability to boost their signal out very far, some of them not so
+
+82
+00:04:46,000 --> 00:04:47,000
+much.
+
+83
+00:04:47,000 --> 00:04:50,000
+You have to know your environment.
+
+84
+00:04:50,000 --> 00:04:54,000
+You have to understand your environment before setting up wireless.
+
diff --git a/13 - Common Security Techniques/004 Mobile Solutions and MDM OB 4.1_en.srt b/13 - Common Security Techniques/004 Mobile Solutions and MDM OB 4.1_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..45cc7a65c9f8a9a732f816fa1f03a21598f67f1e
--- /dev/null
+++ b/13 - Common Security Techniques/004 Mobile Solutions and MDM OB 4.1_en.srt
@@ -0,0 +1,480 @@
+1
+00:00:00,000 --> 00:00:01,000
+The greatest challenge to it.
+
+2
+00:00:01,000 --> 00:00:07,000
+Security, I would say, in the last ten years, is this this is the greatest challenge.
+
+3
+00:00:07,000 --> 00:00:11,000
+The IT security people spend more time on this thing than ever before.
+
+4
+00:00:11,000 --> 00:00:13,000
+There's tons of corporate data.
+
+5
+00:00:13,000 --> 00:00:18,000
+For example, a lot of people check corporate emails on these devices.
+
+6
+00:00:18,000 --> 00:00:24,000
+In this video, I want to talk about some different solutions, some different deployment solutions
+
+7
+00:00:24,000 --> 00:00:26,000
+for managing these kinds of devices.
+
+8
+00:00:26,000 --> 00:00:28,000
+Now how to manage these devices in general.
+
+9
+00:00:28,000 --> 00:00:30,000
+So let's get started.
+
+10
+00:00:30,000 --> 00:00:31,000
+Mobile solutions.
+
+11
+00:00:31,000 --> 00:00:32,000
+What are we talking about.
+
+12
+00:00:32,000 --> 00:00:38,000
+We're talking about some strategies and technologies that we can use to help manage this particular
+
+13
+00:00:38,000 --> 00:00:38,000
+device.
+
+14
+00:00:39,000 --> 00:00:44,000
+Now this is going to be things such as managing the devices themselves.
+
+15
+00:00:44,000 --> 00:00:50,000
+How can we deploy it and how are they even connected within the organization when it comes to managing
+
+16
+00:00:50,000 --> 00:00:54,000
+that particular device, such as my phone?
+
+17
+00:00:55,000 --> 00:01:00,000
+One software that organizations should have is going to be an MDM.
+
+18
+00:01:00,000 --> 00:01:03,000
+Mobile device management software.
+
+19
+00:01:03,000 --> 00:01:08,000
+These are software that allows IT administrators to control, secure, and enforce policies on these
+
+20
+00:01:08,000 --> 00:01:09,000
+devices.
+
+21
+00:01:09,000 --> 00:01:16,000
+This is going to include remotely wiping out devices, managing what apps can be installed.
+
+22
+00:01:17,000 --> 00:01:22,000
+Uh, things that can force in configuration, such as authentication, like, oh, you got you got to
+
+23
+00:01:22,000 --> 00:01:24,000
+have a certain digits in your password.
+
+24
+00:01:24,000 --> 00:01:33,000
+Configuring settings for email, wireless and VPN MDM solutions such as VMware Airwatch is very popular.
+
+25
+00:01:33,000 --> 00:01:35,000
+These kinds of software.
+
+26
+00:01:35,000 --> 00:01:40,000
+Basically the organization would have you join the MDM.
+
+27
+00:01:40,000 --> 00:01:44,000
+When you join the MDM, the VM basically takes control of your phone.
+
+28
+00:01:44,000 --> 00:01:46,000
+It then applies a bunch of security policies on it.
+
+29
+00:01:46,000 --> 00:01:49,000
+It can limit what apps you can install.
+
+30
+00:01:49,000 --> 00:01:52,000
+It may force you to have a certain kind of authentication mechanism.
+
+31
+00:01:52,000 --> 00:01:59,000
+It may force certain kinds of, um, updates to your device and configure certain kinds of VPN.
+
+32
+00:01:59,000 --> 00:02:04,000
+So MDM is basically how it secures your phone.
+
+33
+00:02:04,000 --> 00:02:10,000
+It's a really important piece of software to use if you are using if your employees use a lot of mobile
+
+34
+00:02:10,000 --> 00:02:11,000
+devices.
+
+35
+00:02:11,000 --> 00:02:12,000
+Security compliance.
+
+36
+00:02:12,000 --> 00:02:16,000
+The MDM is critical for ensuring that these devices comply with certain standards.
+
+37
+00:02:16,000 --> 00:02:23,000
+A lot of times, people may not have, uh, people may not have the right configuration.
+
+38
+00:02:23,000 --> 00:02:25,000
+They may not be updating their phone.
+
+39
+00:02:25,000 --> 00:02:29,000
+They may not have some people may not have a password on their phone, for God's sake.
+
+40
+00:02:31,000 --> 00:02:36,000
+You may have what's called an application allow this, which is also known as a whitelist or an application,
+
+41
+00:02:37,000 --> 00:02:38,000
+uh, a list of application.
+
+42
+00:02:38,000 --> 00:02:40,000
+You shouldn't be installed, which is called a blacklist.
+
+43
+00:02:40,000 --> 00:02:45,000
+So like application allow lists would say something like, oh, you're only allowed to have these applications
+
+44
+00:02:45,000 --> 00:02:45,000
+on your phone.
+
+45
+00:02:45,000 --> 00:02:46,000
+These are a list of them.
+
+46
+00:02:46,000 --> 00:02:50,000
+Everything else you can't have device monitoring.
+
+47
+00:02:50,000 --> 00:02:56,000
+MDM uh MDM tools will allow you to monitor the health and security of these devices, giving you good
+
+48
+00:02:56,000 --> 00:02:58,000
+insight into whether there's any security issues.
+
+49
+00:02:58,000 --> 00:03:03,000
+So for example, if this phone gets any kind of hack, if this phone gets any kind of security issue,
+
+50
+00:03:03,000 --> 00:03:06,000
+it can notify the MDM who could notify it on it.
+
+51
+00:03:06,000 --> 00:03:10,000
+One of the greatest thing of why I use an MDM for Microsoft.
+
+52
+00:03:11,000 --> 00:03:18,000
+Is for the simple fact that if I ever lose this phone, we can go to the MDM and remotely wipe the phone
+
+53
+00:03:18,000 --> 00:03:19,000
+just like that.
+
+54
+00:03:19,000 --> 00:03:22,000
+So that makes it a lot easier.
+
+55
+00:03:22,000 --> 00:03:27,000
+MDM are also used, for example, when you're terminated, if you're terminated from an organization,
+
+56
+00:03:27,000 --> 00:03:33,000
+the organization upon terminating you will generally send a signal and erase your phone, erasing all
+
+57
+00:03:33,000 --> 00:03:35,000
+the corporate data that's stored on your phone.
+
+58
+00:03:36,000 --> 00:03:44,000
+Now when it comes to the deployment, there's three of them BYoD, C, o, p e and c o d.
+
+59
+00:03:44,000 --> 00:03:47,000
+Every organization is going to follow these, you know.
+
+60
+00:03:47,000 --> 00:03:51,000
+Some of them may have different variations of them.
+
+61
+00:03:51,000 --> 00:03:56,000
+One of the most popular ones that I am personally not a fan of, but it is the most popular because
+
+62
+00:03:56,000 --> 00:04:00,000
+it is the most cost effective version is bring your own device.
+
+63
+00:04:00,000 --> 00:04:05,000
+Now here at TI we do use this one also because again, it's the most effective, cost effective.
+
+64
+00:04:05,000 --> 00:04:13,000
+BYoD is when the employees use their phones, their personal device for work purposes.
+
+65
+00:04:13,000 --> 00:04:19,000
+So you go work for a company and the organization says, well, you're going to need to check your emails
+
+66
+00:04:19,000 --> 00:04:20,000
+on your phone.
+
+67
+00:04:21,000 --> 00:04:24,000
+Um, you're going to need to access these particular files.
+
+68
+00:04:24,000 --> 00:04:27,000
+So that may give you some kind of shared drive or VPN access.
+
+69
+00:04:27,000 --> 00:04:30,000
+But basically you're using your personal phone.
+
+70
+00:04:30,000 --> 00:04:38,000
+Now, while BYoD can increase employee satisfaction, it could because I don't want to carry two phones.
+
+71
+00:04:38,000 --> 00:04:41,000
+Realistically, the reason we have it because I don't want to carry two phones.
+
+72
+00:04:41,000 --> 00:04:42,000
+These phones are really big and it seems like a brick.
+
+73
+00:04:42,000 --> 00:04:44,000
+I don't want to have two bricks on me.
+
+74
+00:04:44,000 --> 00:04:46,000
+My pants are going to fall out every time I put two bricks in there.
+
+75
+00:04:46,000 --> 00:04:47,000
+It's going to the belt.
+
+76
+00:04:47,000 --> 00:04:48,000
+Has to be super tight.
+
+77
+00:04:49,000 --> 00:04:51,000
+Who wants two phones, right?
+
+78
+00:04:51,000 --> 00:04:58,000
+The problem with with this though, is now there's a wide variety of devices on the network.
+
+79
+00:04:58,000 --> 00:05:01,000
+I like Samsung, you like Google.
+
+80
+00:05:01,000 --> 00:05:05,000
+He likes, uh, Apple, right?
+
+81
+00:05:05,000 --> 00:05:10,000
+There's so many different devices that people can choose from, different versions of different operating
+
+82
+00:05:10,000 --> 00:05:13,000
+system, different configurations, different dates.
+
+83
+00:05:13,000 --> 00:05:15,000
+Some of them are really old, some of them are just brand new.
+
+84
+00:05:15,000 --> 00:05:17,000
+That came out yesterday.
+
+85
+00:05:17,000 --> 00:05:19,000
+That's the problem with BYoD.
+
+86
+00:05:20,000 --> 00:05:24,000
+Although it reduces cost, it rises security challenges.
+
+87
+00:05:24,000 --> 00:05:27,000
+The organization needs to implement strict policy to control this.
+
+88
+00:05:27,000 --> 00:05:30,000
+The best way to control this is of course to have an MDM.
+
+89
+00:05:30,000 --> 00:05:36,000
+Most Mdms will support most devices that are out there in order to minimize the risks.
+
+90
+00:05:36,000 --> 00:05:43,000
+With BYoD, you're going to have COPD corporate owned, personally enabled.
+
+91
+00:05:43,000 --> 00:05:49,000
+The organization provides a mobile device to the employees, but allows some personal use.
+
+92
+00:05:49,000 --> 00:05:54,000
+Now, because the company owns it, only certain apps are going to be installed in it.
+
+93
+00:05:54,000 --> 00:06:00,000
+It's going to be easier to enforce security policies like standardized across the organization, so
+
+94
+00:06:00,000 --> 00:06:05,000
+it makes it easier to fully enforce security controls since the company knows and owns the devices,
+
+95
+00:06:05,000 --> 00:06:09,000
+this has a less pushback, you see.
+
+96
+00:06:10,000 --> 00:06:12,000
+In companies today that uses BYoD.
+
+97
+00:06:12,000 --> 00:06:16,000
+Employees may feel like the company is.
+
+98
+00:06:17,000 --> 00:06:19,000
+Taking over their privacy, intruding on their privacy.
+
+99
+00:06:19,000 --> 00:06:23,000
+And the reason for that is because it's my personal phone.
+
+100
+00:06:23,000 --> 00:06:26,000
+Why do you have access to my personal phone?
+
+101
+00:06:26,000 --> 00:06:28,000
+That's the bind with this one.
+
+102
+00:06:28,000 --> 00:06:32,000
+No problem, because the company literally owns the device.
+
+103
+00:06:32,000 --> 00:06:35,000
+So the organization has full ownership and control of it.
+
+104
+00:06:35,000 --> 00:06:41,000
+However, balancing with personal use rights is a key challenge here because not everybody wants this.
+
+105
+00:06:43,000 --> 00:06:45,000
+The middle ground is choose your own device.
+
+106
+00:06:46,000 --> 00:06:46,000
+All right.
+
+107
+00:06:46,000 --> 00:06:52,000
+So allows employees to choose from a selection of devices provided by the organization.
+
+108
+00:06:52,000 --> 00:06:57,000
+So the organization is going to be like okay if you want you're going to use your own phone, but you've
+
+109
+00:06:57,000 --> 00:06:58,000
+got to.
+
+110
+00:06:58,000 --> 00:06:59,000
+Here's a list of things that we support.
+
+111
+00:06:59,000 --> 00:07:01,000
+You got to have one of these phones.
+
+112
+00:07:01,000 --> 00:07:06,000
+The model balance between personal preference and corporate control allows the company to enforce security
+
+113
+00:07:06,000 --> 00:07:10,000
+controls, while giving you some choice versus the other one was no choice.
+
+114
+00:07:11,000 --> 00:07:14,000
+BYoD is, of course, very chaotic to manage.
+
+115
+00:07:14,000 --> 00:07:18,000
+I think Sihd is probably your best bet here.
+
+116
+00:07:19,000 --> 00:07:24,000
+Uh, corporate owned devices is very, very difficult to manage because not a lot of people again want
+
+117
+00:07:24,000 --> 00:07:25,000
+two phones.
+
+118
+00:07:25,000 --> 00:07:26,000
+All right.
+
+119
+00:07:26,000 --> 00:07:31,000
+So keep this in mind that in order to secure these mobile devices, the best software we can use is
+
+120
+00:07:31,000 --> 00:07:33,000
+a mobile device management software.
+
diff --git a/13 - Common Security Techniques/005 Mobile Connection Methods OB 4.1_en.srt b/13 - Common Security Techniques/005 Mobile Connection Methods OB 4.1_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..35e9423103a85df041805fd84ff8a964865b0f32
--- /dev/null
+++ b/13 - Common Security Techniques/005 Mobile Connection Methods OB 4.1_en.srt
@@ -0,0 +1,448 @@
+1
+00:00:00,000 --> 00:00:06,000
+Wireless devices, such as my phone generally has three ways that they're going to connect to gather
+
+2
+00:00:06,000 --> 00:00:07,000
+data.
+
+3
+00:00:07,000 --> 00:00:12,000
+Either they're going to use some kind of cellular network, like I'm connected to the AT&T network here
+
+4
+00:00:12,000 --> 00:00:13,000
+in the United States.
+
+5
+00:00:13,000 --> 00:00:15,000
+We also have Wi-Fi and Bluetooth.
+
+6
+00:00:15,000 --> 00:00:22,000
+These are going to be the three general ways that your mobile device are going to connect to a network.
+
+7
+00:00:22,000 --> 00:00:27,000
+So in this video let's go over these three methods and give you some good practices when utilizing them.
+
+8
+00:00:27,000 --> 00:00:33,000
+Now each of them have some security considerations that we do want to mention.
+
+9
+00:00:33,000 --> 00:00:38,000
+First of all, things that are going to be involved here is what protocols do they support.
+
+10
+00:00:38,000 --> 00:00:42,000
+For example, Wi-Fi has wpa3, which we'll cover later in the course.
+
+11
+00:00:42,000 --> 00:00:43,000
+Bluetooth.
+
+12
+00:00:43,000 --> 00:00:47,000
+The newer versions are more secure than the old versions, and most cellular networks will generally
+
+13
+00:00:47,000 --> 00:00:49,000
+come with good encryption.
+
+14
+00:00:49,000 --> 00:00:53,000
+You want to beware of potential vulnerabilities, such as Bluetooth being discovered of these here,
+
+15
+00:00:53,000 --> 00:01:00,000
+Bluetooth may not be the best one, and you always want to continuously update and monitor network infrastructure
+
+16
+00:01:00,000 --> 00:01:02,000
+such as security equipment that we have.
+
+17
+00:01:02,000 --> 00:01:07,000
+For example, all network infrastructure equipment may only support Wpa2.
+
+18
+00:01:07,000 --> 00:01:09,000
+Newer ones will support Wpa3.
+
+19
+00:01:09,000 --> 00:01:11,000
+Once again, we'll cover Wi-Fi.
+
+20
+00:01:11,000 --> 00:01:14,000
+We'll cover Wi-Fi security in another video.
+
+21
+00:01:14,000 --> 00:01:18,000
+But let's take a look at these particular connection types.
+
+22
+00:01:18,000 --> 00:01:21,000
+The first thing we want to talk about is cellular connection.
+
+23
+00:01:21,000 --> 00:01:25,000
+This is going to be the connection that you're going to use to connect to your provider.
+
+24
+00:01:25,000 --> 00:01:32,000
+Now, in modern cellular networks, almost all of them, they incorporate strong encryption standard
+
+25
+00:01:32,000 --> 00:01:33,000
+to protect data.
+
+26
+00:01:33,000 --> 00:01:41,000
+So if you're using your phone to connect to something like AT&T, Verizon and all the other providers,
+
+27
+00:01:41,000 --> 00:01:43,000
+it is generally fully encrypted.
+
+28
+00:01:43,000 --> 00:01:48,000
+This makes ears dropping or people trying to sniff the network to gather your data, intercepting it
+
+29
+00:01:48,000 --> 00:01:51,000
+much more difficult, if not somewhat impossible.
+
+30
+00:01:51,000 --> 00:01:57,000
+Now, one of the things that we still recommend to do, even though this is encrypted, is if you're
+
+31
+00:01:57,000 --> 00:02:02,000
+going to be using your mobile device or your laptop for example, maybe your laptop.
+
+32
+00:02:03,000 --> 00:02:07,000
+Is connected to your mobile device with things like setting up hotspots here.
+
+33
+00:02:07,000 --> 00:02:13,000
+If you are utilizing cellular networks to connect to your corporate networks, the best thing to do
+
+34
+00:02:13,000 --> 00:02:16,000
+is to make sure you put a VPN on this.
+
+35
+00:02:16,000 --> 00:02:23,000
+The A VPN will encrypt the data traffic and ensures that even if the data isn't intercepted, it's encrypted.
+
+36
+00:02:23,000 --> 00:02:27,000
+So it's best if you're connected to a corporate network to use a VPN.
+
+37
+00:02:27,000 --> 00:02:31,000
+Another thing is that these cars, these phones have SIM cards in them.
+
+38
+00:02:31,000 --> 00:02:32,000
+What's a SIM card?
+
+39
+00:02:32,000 --> 00:02:39,000
+Well, Sims can be a major attack vulnerability because there is something called SIM swap and attacks.
+
+40
+00:02:39,000 --> 00:02:40,000
+This is.
+
+41
+00:02:41,000 --> 00:02:46,000
+This involves transferring a victim's phone number to a SIM card controlled by an attacker and impersonating
+
+42
+00:02:46,000 --> 00:02:47,000
+that person.
+
+43
+00:02:48,000 --> 00:02:54,000
+Now, when it comes to wi fi, all right, the most common used one here is going to be wi fi.
+
+44
+00:02:55,000 --> 00:02:57,000
+You want to make sure that your wi fi.
+
+45
+00:02:57,000 --> 00:03:03,000
+And again we'll cover more about Wi-Fi security coming up in later are secured with Wpa2 or Wpa3.
+
+46
+00:03:03,000 --> 00:03:06,000
+Never have open wi fi set up.
+
+47
+00:03:06,000 --> 00:03:12,000
+Never use open Wi-Fi or unencrypted wi fi in today's world.
+
+48
+00:03:12,000 --> 00:03:17,000
+You want to avoid public Wi-Fi for any kind of sensitive data.
+
+49
+00:03:17,000 --> 00:03:23,000
+I don't recommend anyone connecting to any public Wi-Fi networks at any point.
+
+50
+00:03:23,000 --> 00:03:30,000
+If I go to a coffee shop and I take out my laptop and I want to do some work, you best bet I'm going
+
+51
+00:03:30,000 --> 00:03:30,000
+to share.
+
+52
+00:03:31,000 --> 00:03:37,000
+I'm going to be sharing Wi-Fi or internet from my phone to my laptop would be the best thing here to
+
+53
+00:03:37,000 --> 00:03:38,000
+do.
+
+54
+00:03:38,000 --> 00:03:44,000
+Now, if you have wireless in your organization and high secure organization, most organizations,
+
+55
+00:03:44,000 --> 00:03:48,000
+what they're going to do is they're going to segment the Wi-Fi network off.
+
+56
+00:03:48,000 --> 00:03:50,000
+They're going to have a separate segment for Wi-Fi.
+
+57
+00:03:50,000 --> 00:03:53,000
+So if you need Wi-Fi, you connect to that segment.
+
+58
+00:03:53,000 --> 00:03:54,000
+It does.
+
+59
+00:03:54,000 --> 00:03:54,000
+And here's the thing.
+
+60
+00:03:54,000 --> 00:03:58,000
+The segmentation of the Wi-Fi puts it off the network.
+
+61
+00:03:58,000 --> 00:04:00,000
+They do have internet access.
+
+62
+00:04:00,000 --> 00:04:06,000
+And when those computers want to come back into the network, they will generate a VPN back in.
+
+63
+00:04:07,000 --> 00:04:10,000
+So you should have a separate Wi-Fi.
+
+64
+00:04:10,000 --> 00:04:12,000
+Uh, a segmented Wi-Fi.
+
+65
+00:04:12,000 --> 00:04:16,000
+Now, if you have different Wi-Fi, you have guests, uh, particularly guests coming in.
+
+66
+00:04:16,000 --> 00:04:21,000
+Make sure you have a guest Wi-Fi and not something that the guests can log in and see.
+
+67
+00:04:22,000 --> 00:04:24,000
+Employee computers in particular.
+
+68
+00:04:24,000 --> 00:04:29,000
+Make sure to regularly update your Wi-Fi hardware for the latest and best security updates, such as
+
+69
+00:04:29,000 --> 00:04:32,000
+on my sonicwall that I keep updating.
+
+70
+00:04:32,000 --> 00:04:33,000
+Now Bluetooth.
+
+71
+00:04:34,000 --> 00:04:40,000
+A lot of us have Bluetooth on our devices we haven't turned on.
+
+72
+00:04:40,000 --> 00:04:42,000
+What do we use Bluetooth for?
+
+73
+00:04:42,000 --> 00:04:45,000
+Well, I use it to connect to the infotainment in the car.
+
+74
+00:04:45,000 --> 00:04:47,000
+I use it to connect to my headphones.
+
+75
+00:04:47,000 --> 00:04:50,000
+Now, Bluetooth has a vulnerabilities.
+
+76
+00:04:51,000 --> 00:04:53,000
+I'm going to just jump down to right here.
+
+77
+00:04:53,000 --> 00:04:58,000
+The latest version of Bluetooth I believe is 5.3 or 5.4.
+
+78
+00:04:58,000 --> 00:05:03,000
+The later your device is the most updated your device, the later your Bluetooth is going to be.
+
+79
+00:05:03,000 --> 00:05:06,000
+Earlier versions of Bluetooth were not even encrypted.
+
+80
+00:05:06,000 --> 00:05:12,000
+The later version of Bluetooth has the better encryption, has better security in general.
+
+81
+00:05:12,000 --> 00:05:17,000
+So that's another reason why you want to keep your firmware updated now.
+
+82
+00:05:17,000 --> 00:05:18,000
+Pairing and discoverability.
+
+83
+00:05:18,000 --> 00:05:22,000
+When you set up Bluetooth, set the device to non discoverable.
+
+84
+00:05:22,000 --> 00:05:24,000
+Most of these phones do that.
+
+85
+00:05:24,000 --> 00:05:28,000
+In general they're in a non discovery mode so no one can find them when not in pairing.
+
+86
+00:05:28,000 --> 00:05:31,000
+When you want to pair then you put it into that.
+
+87
+00:05:31,000 --> 00:05:33,000
+Ideally in a private setting.
+
+88
+00:05:33,000 --> 00:05:35,000
+To prevent unauthorized devices from connecting.
+
+89
+00:05:35,000 --> 00:05:39,000
+You make sure you turn off or you put in non discoverable.
+
+90
+00:05:39,000 --> 00:05:40,000
+Limit the use.
+
+91
+00:05:40,000 --> 00:05:43,000
+Use Bluetooth functionality only when necessary.
+
+92
+00:05:43,000 --> 00:05:43,000
+Keep it.
+
+93
+00:05:43,000 --> 00:05:47,000
+Keeping Bluetooth on all the time doesn't increase your attack surface.
+
+94
+00:05:47,000 --> 00:05:50,000
+So here's something that I recommend for all all of you guys to do.
+
+95
+00:05:50,000 --> 00:05:53,000
+Take your Bluetooth, take your phone and turn it off.
+
+96
+00:05:53,000 --> 00:05:54,000
+If you're not using it, don't have it on.
+
+97
+00:05:54,000 --> 00:05:56,000
+There's two reasons I do that.
+
+98
+00:05:56,000 --> 00:05:59,000
+Number one, it reduces my attack surface.
+
+99
+00:05:59,000 --> 00:06:03,000
+If the Bluetooth is on, it is a potential connection into my phone.
+
+100
+00:06:03,000 --> 00:06:08,000
+The next thing is that it just saves battery, right?
+
+101
+00:06:08,000 --> 00:06:11,000
+If the less things on, the less bad less battery uses up.
+
+102
+00:06:11,000 --> 00:06:14,000
+So that's the two reasons why I would do that.
+
+103
+00:06:14,000 --> 00:06:19,000
+Now be aware, there's tons of different vulnerabilities where they can connect, exploit the Bluetooth
+
+104
+00:06:19,000 --> 00:06:23,000
+connection, access the device, and even inject malware into it.
+
+105
+00:06:24,000 --> 00:06:28,000
+Keep in mind, the best thing we can do at Bluetooth is keep it off until needed.
+
+106
+00:06:28,000 --> 00:06:29,000
+But wireless.
+
+107
+00:06:29,000 --> 00:06:32,000
+Make sure you keep your former updated.
+
+108
+00:06:32,000 --> 00:06:37,000
+Make sure that you use Wpa2 wpa3.
+
+109
+00:06:37,000 --> 00:06:41,000
+Make sure you use encrypted connection when it comes to cellular networks.
+
+110
+00:06:42,000 --> 00:06:47,000
+They're generally going to be well secure with, well, encryption, but if you're connected, it's
+
+111
+00:06:47,000 --> 00:06:49,000
+still considered a type of a public network.
+
+112
+00:06:49,000 --> 00:06:53,000
+If you are transferring secret data, make sure to use a VPN.
+
diff --git a/13 - Common Security Techniques/006 Wireless Security OB 4.1_en.srt b/13 - Common Security Techniques/006 Wireless Security OB 4.1_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..dd85bc2a0d65e4874eee9947af2821f0bdaa8c4b
--- /dev/null
+++ b/13 - Common Security Techniques/006 Wireless Security OB 4.1_en.srt
@@ -0,0 +1,732 @@
+1
+00:00:00,000 --> 00:00:03,000
+In this video we're going to talk about wireless security.
+
+2
+00:00:03,000 --> 00:00:09,000
+But before I get into that, I want to show you a demo of this Sonic Walls interface.
+
+3
+00:00:09,000 --> 00:00:14,000
+Now, I thought about connecting this thing and doing it live on the device, but then none of you would
+
+4
+00:00:14,000 --> 00:00:15,000
+get a chance to do it.
+
+5
+00:00:15,000 --> 00:00:18,000
+So I did find Sonic Walls Live demo that they have.
+
+6
+00:00:18,000 --> 00:00:23,000
+It's basically the exact same thing that you can practice on, and they give it away absolutely free.
+
+7
+00:00:23,000 --> 00:00:25,000
+So you can try it to do a little bit of hands on.
+
+8
+00:00:25,000 --> 00:00:26,000
+So let's do that.
+
+9
+00:00:26,000 --> 00:00:28,000
+And then we're going to get in and talk about what we saw.
+
+10
+00:00:28,000 --> 00:00:32,000
+Just makes makes things easier when you see it to describe it.
+
+11
+00:00:32,000 --> 00:00:34,000
+So let's go take a look at it.
+
+12
+00:00:34,000 --> 00:00:37,000
+Uh so here I am at uh, this website.
+
+13
+00:00:37,000 --> 00:00:39,000
+And by the way, this link is in this slide.
+
+14
+00:00:39,000 --> 00:00:43,000
+This is Sonic wall firewall demo.
+
+15
+00:00:43,000 --> 00:00:45,000
+So they're going to give us the full access to the interface.
+
+16
+00:00:45,000 --> 00:00:53,000
+So right now I have open on in front of me here, uh, the TS 570 series, which is very similar to
+
+17
+00:00:53,000 --> 00:00:54,000
+what I have here.
+
+18
+00:00:54,000 --> 00:00:56,000
+Uh, and I'm going to say view demo.
+
+19
+00:00:56,000 --> 00:00:59,000
+I want the one with wireless because we're basically connecting Wi-Fi.
+
+20
+00:00:59,000 --> 00:01:03,000
+It's telling me that it's going to be using the username and password is password.
+
+21
+00:01:03,000 --> 00:01:09,000
+So we need to know that um oops it wants to block it I'll block up allow pop up.
+
+22
+00:01:09,000 --> 00:01:11,000
+So let's make this bigger so you guys can see.
+
+23
+00:01:11,000 --> 00:01:13,000
+So we're going to say demo.
+
+24
+00:01:13,000 --> 00:01:15,000
+And then the password is password.
+
+25
+00:01:16,000 --> 00:01:21,000
+Now what I want to do is I want to show you guys when we configure wireless on the computer we'll just
+
+26
+00:01:21,000 --> 00:01:25,000
+say proceed here when we configure wireless on these devices.
+
+27
+00:01:25,000 --> 00:01:27,000
+Now this is the device interface.
+
+28
+00:01:27,000 --> 00:01:34,000
+When we configure the wireless on here we have to make sure we select a good security protocol.
+
+29
+00:01:34,000 --> 00:01:36,000
+Let me show you guys how that's done on a device like this.
+
+30
+00:01:36,000 --> 00:01:40,000
+It's going to be pretty similar for all the network and devices that are out there.
+
+31
+00:01:41,000 --> 00:01:41,000
+Okay.
+
+32
+00:01:41,000 --> 00:01:43,000
+So I'm going to go to device.
+
+33
+00:01:43,000 --> 00:01:48,000
+And by going here, it opened up a lot of different devices that we have here.
+
+34
+00:01:48,000 --> 00:01:53,000
+So we're going to go to internal wireless and we're going to go down here.
+
+35
+00:01:53,000 --> 00:01:56,000
+If you see its status settings security.
+
+36
+00:01:56,000 --> 00:02:00,000
+So if you go to settings you have the different settings of the mode we can do.
+
+37
+00:02:01,000 --> 00:02:06,000
+Now this is not a networking course to go through all the different radio modes like 802, A, B, G
+
+38
+00:02:06,000 --> 00:02:06,000
+and N.
+
+39
+00:02:06,000 --> 00:02:11,000
+We're looking more at the security aspect of it, but we're going to go to security.
+
+40
+00:02:11,000 --> 00:02:15,000
+And you notice right now it's actually set to the worst security out there.
+
+41
+00:02:15,000 --> 00:02:17,000
+You never want to use WFP.
+
+42
+00:02:18,000 --> 00:02:20,000
+WFP is crackable and should not be used.
+
+43
+00:02:20,000 --> 00:02:23,000
+So is pretty much WPA.
+
+44
+00:02:23,000 --> 00:02:24,000
+At a minimum.
+
+45
+00:02:24,000 --> 00:02:26,000
+You want to go with Wpa2.
+
+46
+00:02:26,000 --> 00:02:33,000
+Wpa2 is still incredibly popular, and what I want to point out in this video is we have two things.
+
+47
+00:02:33,000 --> 00:02:38,000
+You have Wpa2, PSK or Pre-shared key and EAP Extensible Authentication Protocol.
+
+48
+00:02:38,000 --> 00:02:44,000
+You notice you also have that for WPA three, you have the PSK and the EAP.
+
+49
+00:02:44,000 --> 00:02:46,000
+So look what happens when I use WPA three.
+
+50
+00:02:46,000 --> 00:02:48,000
+Now if you have three you want to put that on your router.
+
+51
+00:02:48,000 --> 00:02:54,000
+The newer wireless routers and and um access points is going to support WPA three D.
+
+52
+00:02:54,000 --> 00:02:59,000
+All the ones will not WPA two while still a good option, Wpa3 is better.
+
+53
+00:02:59,000 --> 00:03:06,000
+If I go to Wpa3 and I say PSK basically wants me to enter the passphrase of the Pre-shared key that
+
+54
+00:03:06,000 --> 00:03:08,000
+all the machines will get.
+
+55
+00:03:08,000 --> 00:03:09,000
+Now, I do want you to watch.
+
+56
+00:03:09,000 --> 00:03:14,000
+If I select WPA three, you'll notice a lot of options changed.
+
+57
+00:03:15,000 --> 00:03:23,000
+And now it wants the radius servers IP address, and it wants to know a secret of the Radius server.
+
+58
+00:03:23,000 --> 00:03:26,000
+So this is a configuration of a Radius server.
+
+59
+00:03:26,000 --> 00:03:33,000
+So notice how WPA three is asking for a Radius server IP address.
+
+60
+00:03:33,000 --> 00:03:42,000
+So WPA three our WPA two when configured with EAP authentication notice WPA two here also has the same
+
+61
+00:03:42,000 --> 00:03:42,000
+thing.
+
+62
+00:03:42,000 --> 00:03:51,000
+So what exactly does WPA two EAP means now on certain routers, you guys may see this as, uh, if you
+
+63
+00:03:51,000 --> 00:03:54,000
+look at your router, it may say WPA two enterprise.
+
+64
+00:03:54,000 --> 00:03:55,000
+Same thing.
+
+65
+00:03:55,000 --> 00:03:57,000
+It's going to ask for the Radius server.
+
+66
+00:03:57,000 --> 00:03:59,000
+So what exactly is that.
+
+67
+00:03:59,000 --> 00:04:01,000
+Well that's what this video is about.
+
+68
+00:04:02,000 --> 00:04:10,000
+This video, I want to talk about some of the security settings that we just saw on our wireless router.
+
+69
+00:04:10,000 --> 00:04:10,000
+Right.
+
+70
+00:04:10,000 --> 00:04:12,000
+We want to talk about Wpa3.
+
+71
+00:04:13,000 --> 00:04:19,000
+You got to notice triple A, and we'll talk about the cryptographic protocols and authentication protocols
+
+72
+00:04:19,000 --> 00:04:20,000
+that we have out there.
+
+73
+00:04:20,000 --> 00:04:23,000
+So Wpa3 is about securing our wireless network.
+
+74
+00:04:23,000 --> 00:04:26,000
+And then in coming up in a few minutes we'll talk about triple A.
+
+75
+00:04:26,000 --> 00:04:30,000
+Now the link to that Sonicwall demo is right here.
+
+76
+00:04:30,000 --> 00:04:34,000
+So if you want to try that out, if you want to play around with the Sonicwall like I have here on my
+
+77
+00:04:34,000 --> 00:04:39,000
+desk, you want to play around with the interface, see how it's configured without actually purchasing
+
+78
+00:04:39,000 --> 00:04:42,000
+it for a couple of, well, $100.
+
+79
+00:04:42,000 --> 00:04:44,000
+You can just use the demo there now.
+
+80
+00:04:45,000 --> 00:04:46,000
+Let's get into this.
+
+81
+00:04:46,000 --> 00:04:47,000
+So wpa3.
+
+82
+00:04:47,000 --> 00:04:54,000
+This is going to be the latest security that we have in wireless protection preceding this with Wpa2,
+
+83
+00:04:54,000 --> 00:04:56,000
+which was around for quite a long time.
+
+84
+00:04:56,000 --> 00:04:57,000
+Then there's WPA.
+
+85
+00:04:57,000 --> 00:05:02,000
+The original one and then WEP, which is fully crackable and should not be used.
+
+86
+00:05:02,000 --> 00:05:04,000
+Now it improves upon Wpa2.
+
+87
+00:05:04,000 --> 00:05:10,000
+It has more enhanced cryptographic strength, more robust authentication method.
+
+88
+00:05:10,000 --> 00:05:15,000
+It does use something simultaneous authentication of equals or SAE protocol.
+
+89
+00:05:15,000 --> 00:05:20,000
+This replaced the old PSK or Pre-shared key methods that was used in Wpa2.
+
+90
+00:05:20,000 --> 00:05:24,000
+It protects against more offline dictionary attacks.
+
+91
+00:05:24,000 --> 00:05:27,000
+It enhance protection for open network?
+
+92
+00:05:28,000 --> 00:05:34,000
+Um, and it supports up to 192 bit encryption versus Wpa2 and 128 bit encryption.
+
+93
+00:05:34,000 --> 00:05:40,000
+If you have a router, a wireless access point and wireless routers that supports Wpa3, I would highly
+
+94
+00:05:40,000 --> 00:05:41,000
+recommend you put it on.
+
+95
+00:05:41,000 --> 00:05:46,000
+But you have to remember it's not just a machine, but the wireless cards also need to support it.
+
+96
+00:05:46,000 --> 00:05:47,000
+Now.
+
+97
+00:05:48,000 --> 00:05:52,000
+I want to talk to you guys here about something important.
+
+98
+00:05:53,000 --> 00:05:58,000
+On when you configure WPA 2 or 3 on your computer.
+
+99
+00:05:59,000 --> 00:06:01,000
+We have the option of doing a pre-shared key.
+
+100
+00:06:01,000 --> 00:06:03,000
+Most of us at home, that's what we have.
+
+101
+00:06:03,000 --> 00:06:06,000
+Pre-shared key with a Pre-shared key.
+
+102
+00:06:06,000 --> 00:06:12,000
+What you're doing is you're putting in a passcode and hopefully it's long and complex, and then you
+
+103
+00:06:12,000 --> 00:06:16,000
+have to share that pre-shared key with all the computers in the network to connect.
+
+104
+00:06:16,000 --> 00:06:18,000
+People call it the password to the WiFi.
+
+105
+00:06:18,000 --> 00:06:18,000
+Right.
+
+106
+00:06:18,000 --> 00:06:20,000
+So what's the password to the Wi-Fi?
+
+107
+00:06:20,000 --> 00:06:22,000
+That's the Pre-shared key.
+
+108
+00:06:22,000 --> 00:06:30,000
+Now the problem with this is that in corporates in corporate America, we're not going to have 5 or
+
+109
+00:06:30,000 --> 00:06:33,000
+6 or 2 or 3 computers.
+
+110
+00:06:33,000 --> 00:06:34,000
+We're going to have them by the hundreds.
+
+111
+00:06:34,000 --> 00:06:37,000
+Do we want to authenticate them with just the key.
+
+112
+00:06:37,000 --> 00:06:43,000
+Those keys, those pre-shared keys are actually kept in plain text on the computer.
+
+113
+00:06:43,000 --> 00:06:46,000
+So it's not the best thing to do.
+
+114
+00:06:46,000 --> 00:06:53,000
+What we want to do is we want to pass off the authentication of those particular devices to another
+
+115
+00:06:53,000 --> 00:06:54,000
+device.
+
+116
+00:06:54,000 --> 00:06:56,000
+So I want to draw you guys a quick diagram.
+
+117
+00:06:56,000 --> 00:06:57,000
+So here you have.
+
+118
+00:06:59,000 --> 00:07:04,000
+An access point that with all the access points coming out of it.
+
+119
+00:07:04,000 --> 00:07:11,000
+And then what you're going to do is instead of having, let's say you have a mobile phone, this phone
+
+120
+00:07:11,000 --> 00:07:13,000
+wants to connect to this using wireless.
+
+121
+00:07:13,000 --> 00:07:19,000
+Now what you could do is you could just have a pre-shared key and it'll just authenticate and it gets
+
+122
+00:07:19,000 --> 00:07:20,000
+internet access.
+
+123
+00:07:20,000 --> 00:07:28,000
+The best thing to do is to connect your access point or wireless router to a Radius server.
+
+124
+00:07:28,000 --> 00:07:30,000
+Now what exactly is a Radius server?
+
+125
+00:07:30,000 --> 00:07:32,000
+Well, a Radius server.
+
+126
+00:07:33,000 --> 00:07:34,000
+It's basically a device.
+
+127
+00:07:34,000 --> 00:07:39,000
+It's a networking protocol that centralizes authentication, authorization and accounting for users
+
+128
+00:07:39,000 --> 00:07:40,000
+accessing network.
+
+129
+00:07:40,000 --> 00:07:48,000
+Radius servers are separate servers that we set up on our network to authenticate all kinds of devices.
+
+130
+00:07:48,000 --> 00:07:51,000
+A Radius server can connect to your access point.
+
+131
+00:07:51,000 --> 00:07:52,000
+Remember how we selected Pre-shared?
+
+132
+00:07:52,000 --> 00:07:57,000
+We selected WPA 2 or 3 and we said EAP authentication.
+
+133
+00:07:57,000 --> 00:08:01,000
+Now it's using the Extensible Authentication Protocol to pass.
+
+134
+00:08:01,000 --> 00:08:04,000
+So here we would have an EAP authentication.
+
+135
+00:08:05,000 --> 00:08:06,000
+Authentication protocol.
+
+136
+00:08:06,000 --> 00:08:11,000
+This here would use this protocol to pass authentication information to a Radius server.
+
+137
+00:08:11,000 --> 00:08:15,000
+Radius server can then authenticate people with Active Directory accounts.
+
+138
+00:08:15,000 --> 00:08:20,000
+Certificates, for example, are different ways that Radius can authenticate you, so you don't have
+
+139
+00:08:20,000 --> 00:08:22,000
+to have a pre-shared key to all the machines.
+
+140
+00:08:22,000 --> 00:08:26,000
+You can use certificate based authentication, the Radius server.
+
+141
+00:08:26,000 --> 00:08:32,000
+So when the laptop or the phone wants to join the wireless access point, it would say, hey, can I
+
+142
+00:08:32,000 --> 00:08:33,000
+join?
+
+143
+00:08:33,000 --> 00:08:34,000
+It would send a request to the Radius server.
+
+144
+00:08:34,000 --> 00:08:37,000
+The Radius server accepts the authentication.
+
+145
+00:08:37,000 --> 00:08:43,000
+It would come back and let the the let the access point know to allow the laptop or phone to join.
+
+146
+00:08:44,000 --> 00:08:49,000
+This falls into the framework of what's known as triple A authentication, authorization and accounting.
+
+147
+00:08:49,000 --> 00:08:53,000
+So authentication is allowed them to get in what they can access as authorization.
+
+148
+00:08:53,000 --> 00:08:59,000
+And accounting is keeping like a log file and tracking and auditing of what this system when they logged
+
+149
+00:08:59,000 --> 00:09:00,000
+into it.
+
+150
+00:09:01,000 --> 00:09:04,000
+So how do we allow triple A in our network?
+
+151
+00:09:04,000 --> 00:09:07,000
+By utilizing a Radius server.
+
+152
+00:09:07,000 --> 00:09:15,000
+Now once again, radius servers are very popular in today's network because you're going to use a Radius
+
+153
+00:09:15,000 --> 00:09:22,000
+server not just to authenticate wireless, but you can also use Radius to authenticate VPNs.
+
+154
+00:09:22,000 --> 00:09:25,000
+So not just, uh, wireless in your network.
+
+155
+00:09:25,000 --> 00:09:27,000
+Now you can set up Radius on windows.
+
+156
+00:09:27,000 --> 00:09:32,000
+Also, Cisco has something just like radius.
+
+157
+00:09:32,000 --> 00:09:34,000
+If you on your exam you see something called Tacacs.
+
+158
+00:09:34,000 --> 00:09:40,000
+It's the same thing Tacacs radius basically does the same thing for your exam now.
+
+159
+00:09:42,000 --> 00:09:44,000
+Cryptographic protocols.
+
+160
+00:09:44,000 --> 00:09:44,000
+All right.
+
+161
+00:09:44,000 --> 00:09:45,000
+What exactly is this?
+
+162
+00:09:46,000 --> 00:09:49,000
+These are a series of processes that encrypt and decrypt data.
+
+163
+00:09:49,000 --> 00:09:50,000
+That's what a protocol does.
+
+164
+00:09:50,000 --> 00:09:51,000
+It encrypts and decrypts.
+
+165
+00:09:51,000 --> 00:09:54,000
+They use algorithms the to read.
+
+166
+00:09:54,000 --> 00:09:59,000
+And they use algorithms to transform readable data into unreadable data.
+
+167
+00:09:59,000 --> 00:10:05,000
+Now the cryptographic protocol is what's going to be the underlying technology with Wpa3.
+
+168
+00:10:05,000 --> 00:10:10,000
+Now Wpa3 I do want to point out does use AES encryption to encrypt its data.
+
+169
+00:10:10,000 --> 00:10:11,000
+So.
+
+170
+00:10:12,000 --> 00:10:12,000
+What?
+
+171
+00:10:12,000 --> 00:10:14,000
+What's going to power up?
+
+172
+00:10:14,000 --> 00:10:15,000
+Wpa3.
+
+173
+00:10:15,000 --> 00:10:21,000
+A cryptographic protocol, the authentication protocol, is what authenticates people to the actual
+
+174
+00:10:21,000 --> 00:10:23,000
+network used to verify the identity.
+
+175
+00:10:23,000 --> 00:10:25,000
+That part of a broader security.
+
+176
+00:10:25,000 --> 00:10:31,000
+Things like Radius will use authentication protocols to authenticate you on a network.
+
+177
+00:10:32,000 --> 00:10:35,000
+All right, so know for your exam.
+
+178
+00:10:35,000 --> 00:10:40,000
+Wpa3 is a strongest encryption we have out there on a smaller home network.
+
+179
+00:10:40,000 --> 00:10:47,000
+We may use a pre-shared key to secure the network, but on big networks, we're going to use EAP authentication
+
+180
+00:10:47,000 --> 00:10:51,000
+to send it off to a Radius server or a CAS server if you're using Cisco.
+
+181
+00:10:52,000 --> 00:10:56,000
+And that's going to give us a centralized form of authentication where we're just not going to use a
+
+182
+00:10:56,000 --> 00:11:01,000
+pre-shared key or a password, but we can use things like certificate based authentication, making
+
+183
+00:11:01,000 --> 00:11:02,000
+it a whole lot more secure.
+
diff --git a/13 - Common Security Techniques/007 Application Security Methods OB 4.1_en.srt b/13 - Common Security Techniques/007 Application Security Methods OB 4.1_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..2d16eeb4792d7408101db68bc92aeeb8e8702199
--- /dev/null
+++ b/13 - Common Security Techniques/007 Application Security Methods OB 4.1_en.srt
@@ -0,0 +1,740 @@
+1
+00:00:00,000 --> 00:00:03,000
+Almost all malware will exploit some kind of applications.
+
+2
+00:00:03,000 --> 00:00:07,000
+Very rarely do you have malware that can affect the hardware on the machine.
+
+3
+00:00:07,000 --> 00:00:14,000
+So in this video let's talk about application security and some things that we can do to keep our applications
+
+4
+00:00:14,000 --> 00:00:15,000
+secure.
+
+5
+00:00:15,000 --> 00:00:21,000
+So we all should understand that when it comes to application security, probably one of the most critical
+
+6
+00:00:21,000 --> 00:00:24,000
+aspect of managing any IT system.
+
+7
+00:00:24,000 --> 00:00:30,000
+Now in here I have about five things here that I want to go over with you, uh, that can keep your
+
+8
+00:00:30,000 --> 00:00:31,000
+applications secure.
+
+9
+00:00:31,000 --> 00:00:32,000
+Let's get started.
+
+10
+00:00:32,000 --> 00:00:36,000
+The first thing that we want to talk about is input validation.
+
+11
+00:00:36,000 --> 00:00:38,000
+Now, I've already covered some of these attacks.
+
+12
+00:00:38,000 --> 00:00:42,000
+We talked about cross-site scripting SQL injections.
+
+13
+00:00:42,000 --> 00:00:46,000
+These are all things that can be solved by input validation.
+
+14
+00:00:46,000 --> 00:00:48,000
+And I want to show it to you before we get started.
+
+15
+00:00:48,000 --> 00:00:49,000
+So here I am.
+
+16
+00:00:49,000 --> 00:00:49,000
+Oops.
+
+17
+00:00:49,000 --> 00:00:52,000
+Here I am at the Tia Educom.
+
+18
+00:00:52,000 --> 00:00:54,000
+This is our website.
+
+19
+00:00:54,000 --> 00:00:59,000
+If you want to sign up for a class you would come here and I want to show you guys what input validation
+
+20
+00:00:59,000 --> 00:01:00,000
+is.
+
+21
+00:01:00,000 --> 00:01:05,000
+You have a name and what I'm going to do here is I'm going to type in, uh, my name, but I want you
+
+22
+00:01:05,000 --> 00:01:06,000
+guys to watch what happens.
+
+23
+00:01:06,000 --> 00:01:08,000
+I'm just going to hold the one key down.
+
+24
+00:01:08,000 --> 00:01:14,000
+You notice it limits what can be typed into the box, the number of characters, the email address,
+
+25
+00:01:14,000 --> 00:01:15,000
+for example.
+
+26
+00:01:15,000 --> 00:01:19,000
+Also, I'm just going to put in my name phone number.
+
+27
+00:01:19,000 --> 00:01:20,000
+We allow anything in there.
+
+28
+00:01:20,000 --> 00:01:21,000
+Just a message.
+
+29
+00:01:21,000 --> 00:01:23,000
+And this is also limited.
+
+30
+00:01:23,000 --> 00:01:26,000
+So you watch what happens when I try to submit it.
+
+31
+00:01:26,000 --> 00:01:28,000
+You notice you got to have a valid email.
+
+32
+00:01:28,000 --> 00:01:31,000
+So to field only accept a valid email.
+
+33
+00:01:31,000 --> 00:01:34,000
+This is what's called input validation.
+
+34
+00:01:34,000 --> 00:01:39,000
+What we're doing is we're validating the input that's placed into the website.
+
+35
+00:01:39,000 --> 00:01:47,000
+That way the input itself that people are typing is being treated as untrusted and validated, both
+
+36
+00:01:47,000 --> 00:01:50,000
+on the client side for usability and on the server side.
+
+37
+00:01:50,000 --> 00:01:51,000
+So right now we're validating it.
+
+38
+00:01:51,000 --> 00:01:53,000
+What you saw was on the client side.
+
+39
+00:01:53,000 --> 00:01:56,000
+And then we will also check it on the server side.
+
+40
+00:01:56,000 --> 00:01:57,000
+Also.
+
+41
+00:01:57,000 --> 00:02:06,000
+Now I want to once again to point out for your exam input validation can solve things like SQL injections
+
+42
+00:02:06,000 --> 00:02:09,000
+and cross-site scripting or any kind of injection attacks.
+
+43
+00:02:09,000 --> 00:02:16,000
+Also, it can prevent attackers from using malicious data to exploit exploit the logic of the application.
+
+44
+00:02:16,000 --> 00:02:18,000
+So this is a wide.
+
+45
+00:02:18,000 --> 00:02:21,000
+By doing this it's safeguarding against a wide range of attacks.
+
+46
+00:02:22,000 --> 00:02:24,000
+The next thing is secure cookies.
+
+47
+00:02:24,000 --> 00:02:30,000
+Cookies are small pieces of data stored on a user device, and I'm pretty sure you guys are familiar
+
+48
+00:02:30,000 --> 00:02:33,000
+with it, as most website has it by the web browser.
+
+49
+00:02:33,000 --> 00:02:39,000
+While browser on a site, secure cookies have security attributes, including your personal data on
+
+50
+00:02:39,000 --> 00:02:40,000
+them.
+
+51
+00:02:40,000 --> 00:02:45,000
+What you want to do is you want to make sure that the cookies are secure, in other words, indicating
+
+52
+00:02:45,000 --> 00:02:53,000
+that cookies should only be sent over Https connection since these cookies have personal data attached
+
+53
+00:02:53,000 --> 00:02:56,000
+to them if they're ever intercepted.
+
+54
+00:02:56,000 --> 00:02:59,000
+Your your personal data could be gone.
+
+55
+00:02:59,000 --> 00:03:02,000
+And it can also be used in man in the middle uh, attacks also.
+
+56
+00:03:03,000 --> 00:03:05,000
+Remember this is now called an on path attack.
+
+57
+00:03:05,000 --> 00:03:10,000
+So you want to make sure that any website that's utilizing a cookie, or if you're building a website,
+
+58
+00:03:10,000 --> 00:03:17,000
+that cookie is encrypted with SSL or TLS static code analysis.
+
+59
+00:03:17,000 --> 00:03:23,000
+When programmers are writing codes, it is important to actually test the code.
+
+60
+00:03:23,000 --> 00:03:29,000
+Static analysis is the process of examining the source code of an application without executing it.
+
+61
+00:03:29,000 --> 00:03:33,000
+Like technically just reading the code of itself on a piece of paper.
+
+62
+00:03:34,000 --> 00:03:36,000
+Technically not on a paper, but on a screen.
+
+63
+00:03:36,000 --> 00:03:41,000
+The aim is to find vulnerability code flaws and ensuring compliance generally with code and guidelines.
+
+64
+00:03:42,000 --> 00:03:44,000
+Now this is an automated thing.
+
+65
+00:03:45,000 --> 00:03:48,000
+Now an application can have millions of line of code.
+
+66
+00:03:48,000 --> 00:03:49,000
+People can sit there and read that.
+
+67
+00:03:49,000 --> 00:03:55,000
+So this is generally done using tools that can automatically scan the code to detect issues like security
+
+68
+00:03:55,000 --> 00:03:58,000
+vulnerabilities, perform problems and so on.
+
+69
+00:03:58,000 --> 00:04:03,000
+Now this is one of the best things you can do as code is being written.
+
+70
+00:04:03,000 --> 00:04:04,000
+This should be done.
+
+71
+00:04:04,000 --> 00:04:07,000
+This helps to identify problems with development.
+
+72
+00:04:07,000 --> 00:04:07,000
+Will ask.
+
+73
+00:04:07,000 --> 00:04:10,000
+The code is being written so early in the development life cycle.
+
+74
+00:04:10,000 --> 00:04:14,000
+It's generally cost effective to do it since it's generally done by a tool.
+
+75
+00:04:14,000 --> 00:04:20,000
+This is going to help by looking at the code, thinking about this, if we can look at the source code
+
+76
+00:04:20,000 --> 00:04:27,000
+and we can fix the bugs, the vulnerabilities in the source code, by the time it's deployed, by the
+
+77
+00:04:27,000 --> 00:04:30,000
+time it's compiled and deployed, the vulnerabilities were fixed.
+
+78
+00:04:32,000 --> 00:04:33,000
+Code signing.
+
+79
+00:04:33,000 --> 00:04:40,000
+Now, when you receive code from, let's say you're using a block of code from a provider, how do you
+
+80
+00:04:40,000 --> 00:04:42,000
+know it came from that provider?
+
+81
+00:04:42,000 --> 00:04:46,000
+How do you know that code hasn't been modified?
+
+82
+00:04:46,000 --> 00:04:48,000
+Well, if you remember, we used it.
+
+83
+00:04:48,000 --> 00:04:52,000
+We covered something in cryptography called digital signatures.
+
+84
+00:04:52,000 --> 00:04:59,000
+Digital signatures is when you sign a document and when you send it to someone, there'll be 100% sure
+
+85
+00:04:59,000 --> 00:05:01,000
+it came from you, and it was never modified.
+
+86
+00:05:01,000 --> 00:05:05,000
+Now, please review the digital signature process in the cryptography section.
+
+87
+00:05:05,000 --> 00:05:07,000
+In code signing, it's basically the same thing.
+
+88
+00:05:08,000 --> 00:05:12,000
+This involves using a digital signature to sign executables and scripts.
+
+89
+00:05:12,000 --> 00:05:13,000
+This could.
+
+90
+00:05:13,000 --> 00:05:19,000
+This signature confirms a software author and guarantees that the code has not been altered.
+
+91
+00:05:19,000 --> 00:05:22,000
+So, you know, this code came from Microsoft.
+
+92
+00:05:22,000 --> 00:05:25,000
+So Microsoft would sign codes Microsoft signs updates.
+
+93
+00:05:25,000 --> 00:05:27,000
+This is a common thing.
+
+94
+00:05:27,000 --> 00:05:32,000
+Microsoft will sign driver files, or manufacturers will sign a driver file that you'll install for
+
+95
+00:05:32,000 --> 00:05:33,000
+your hardware.
+
+96
+00:05:34,000 --> 00:05:40,000
+That way, you are 100% sure that the software you're installing is from Microsoft and hasn't been modified
+
+97
+00:05:40,000 --> 00:05:42,000
+by any external entities.
+
+98
+00:05:42,000 --> 00:05:47,000
+A certificate is issued by a trusted CA is used to sign the code.
+
+99
+00:05:47,000 --> 00:05:49,000
+Now, we all generally have commercial trusted CA.
+
+100
+00:05:50,000 --> 00:05:55,000
+When users download or execute the code, the software will then check the CA on the machine.
+
+101
+00:05:55,000 --> 00:05:58,000
+This helps to establish integrity of the code.
+
+102
+00:05:58,000 --> 00:06:03,000
+That means the code was never modified and authenticity that the code actually came from the Microsoft.
+
+103
+00:06:04,000 --> 00:06:08,000
+Now, another time you want to be familiar with is sandboxing.
+
+104
+00:06:09,000 --> 00:06:16,000
+Sandboxing, just like the sandbox we see here, but in a digital world, is a technique we're going
+
+105
+00:06:16,000 --> 00:06:24,000
+to use to isolate application programs processes in a separate environment to prevent them from affecting
+
+106
+00:06:24,000 --> 00:06:25,000
+other systems.
+
+107
+00:06:25,000 --> 00:06:27,000
+Sandboxing when you have a sandbox.
+
+108
+00:06:27,000 --> 00:06:29,000
+So let's say we take this tablet.
+
+109
+00:06:29,000 --> 00:06:30,000
+All right.
+
+110
+00:06:30,000 --> 00:06:31,000
+Let's say what we do.
+
+111
+00:06:31,000 --> 00:06:33,000
+This is our sandbox.
+
+112
+00:06:33,000 --> 00:06:36,000
+Whatever we execute here stays in this box.
+
+113
+00:06:36,000 --> 00:06:38,000
+Whatever code here stays here.
+
+114
+00:06:38,000 --> 00:06:42,000
+The sand does not flow outside of the box.
+
+115
+00:06:42,000 --> 00:06:44,000
+That's what a sandbox does.
+
+116
+00:06:44,000 --> 00:06:46,000
+It allows us to do quite a lot of things.
+
+117
+00:06:46,000 --> 00:06:48,000
+Number one, it's about isolation.
+
+118
+00:06:48,000 --> 00:06:53,000
+It involves running codes applications or processes, an isolated environment.
+
+119
+00:06:53,000 --> 00:07:00,000
+So just within this box that I have here that simulates end user's operating environment, the main
+
+120
+00:07:00,000 --> 00:07:03,000
+idea is to execute it without affecting anything on a system or a network.
+
+121
+00:07:03,000 --> 00:07:10,000
+This now we just don't do it for application programming, but in IT security we also use it to test
+
+122
+00:07:10,000 --> 00:07:10,000
+things.
+
+123
+00:07:10,000 --> 00:07:12,000
+I'll explain this in a minute.
+
+124
+00:07:12,000 --> 00:07:17,000
+In security, this isolation helps to contain the effects of malicious or faulty code.
+
+125
+00:07:17,000 --> 00:07:26,000
+Let's say you receive what you perceive to be, uh, you're not sure your perception, but you're thinking
+
+126
+00:07:26,000 --> 00:07:27,000
+that you know what?
+
+127
+00:07:27,000 --> 00:07:29,000
+This attachment is probably bad.
+
+128
+00:07:29,000 --> 00:07:29,000
+It's probably full.
+
+129
+00:07:29,000 --> 00:07:31,000
+Full of viruses.
+
+130
+00:07:31,000 --> 00:07:33,000
+Well, don't execute on your machine.
+
+131
+00:07:33,000 --> 00:07:34,000
+You put it in a sandbox.
+
+132
+00:07:34,000 --> 00:07:37,000
+In that sandbox environment, you can then execute.
+
+133
+00:07:37,000 --> 00:07:39,000
+If it blows up, it is going to stay right here.
+
+134
+00:07:39,000 --> 00:07:41,000
+If nothing happens, well, then you're sure it's good.
+
+135
+00:07:41,000 --> 00:07:44,000
+When it comes to codes, you probably want to test the code in the sandbox.
+
+136
+00:07:44,000 --> 00:07:48,000
+If the code is faulty and crashes, it doesn't crash an entire system.
+
+137
+00:07:48,000 --> 00:07:51,000
+Everything is confined to the box we're going to use.
+
+138
+00:07:51,000 --> 00:07:55,000
+The sandbox are useful a use for safely running and analyzing suspicious code.
+
+139
+00:07:55,000 --> 00:07:59,000
+This is what I was just mentioning to you, especially if it's malware.
+
+140
+00:08:00,000 --> 00:08:02,000
+Now different sandboxes that are out there.
+
+141
+00:08:02,000 --> 00:08:04,000
+We have this application sandbox.
+
+142
+00:08:04,000 --> 00:08:06,000
+This is used for individual applications.
+
+143
+00:08:06,000 --> 00:08:12,000
+For example, web browsers use a sandbox, isolate certain web plugins just in case it's a potential
+
+144
+00:08:12,000 --> 00:08:16,000
+malware virtual sandbox or VM sandbox or virtual machines.
+
+145
+00:08:16,000 --> 00:08:20,000
+And we're running a virtual running a full VM as a sandbox.
+
+146
+00:08:20,000 --> 00:08:25,000
+It's more secure because it completely separates the sandbox environment from the host operating system.
+
+147
+00:08:25,000 --> 00:08:28,000
+So you can set up your VMs as a sandbox.
+
+148
+00:08:28,000 --> 00:08:33,000
+And what this means is that if you have what you perceive to probably be malicious code or you're testing
+
+149
+00:08:33,000 --> 00:08:40,000
+malicious code, maybe you're a red hat pentester that put it on that VM, don't execute it on your
+
+150
+00:08:40,000 --> 00:08:42,000
+full machine cloud based sandbox.
+
+151
+00:08:43,000 --> 00:08:49,000
+There's a variety of cloud resources we can use to create a sandbox in the cloud, to execute a variety
+
+152
+00:08:49,000 --> 00:08:50,000
+of codes in there.
+
+153
+00:08:50,000 --> 00:08:56,000
+This is, of course, going to be much scalable and can handle big needs, especially if a sandbox is
+
+154
+00:08:56,000 --> 00:08:56,000
+needed.
+
+155
+00:08:56,000 --> 00:09:00,000
+When it comes to security, we use sandboxes quite a lot here at TI.
+
+156
+00:09:00,000 --> 00:09:01,000
+We have a sandbox.
+
+157
+00:09:01,000 --> 00:09:05,000
+We have a virtual sandbox, a virtual machine sandbox.
+
+158
+00:09:05,000 --> 00:09:09,000
+When people send us emails, send any staff an email.
+
+159
+00:09:10,000 --> 00:09:12,000
+And we're not too sure if you know.
+
+160
+00:09:12,000 --> 00:09:13,000
+Is that link bad?
+
+161
+00:09:14,000 --> 00:09:16,000
+Is that PDF any good?
+
+162
+00:09:16,000 --> 00:09:17,000
+Right.
+
+163
+00:09:17,000 --> 00:09:18,000
+Is that going to give us a virus.
+
+164
+00:09:18,000 --> 00:09:20,000
+They send it to the security person.
+
+165
+00:09:20,000 --> 00:09:23,000
+The security person that takes that email opens it in a sandbox.
+
+166
+00:09:23,000 --> 00:09:26,000
+If it's all good and we're verifying that it's good, great.
+
+167
+00:09:26,000 --> 00:09:28,000
+We tell the user, call the user, hey, it's fine.
+
+168
+00:09:28,000 --> 00:09:29,000
+Open.
+
+169
+00:09:29,000 --> 00:09:33,000
+If not, if it executes and it blows up and it's a virus, we tell a user delete right away, it's no
+
+170
+00:09:33,000 --> 00:09:34,000
+good.
+
+171
+00:09:34,000 --> 00:09:38,000
+So malware analysis you can also use to test environments.
+
+172
+00:09:38,000 --> 00:09:41,000
+So if you're not sure if the code will crash your system this would be good.
+
+173
+00:09:41,000 --> 00:09:46,000
+That way if it does crash, it doesn't crash an entire network, it just crashes in the sandbox.
+
+174
+00:09:47,000 --> 00:09:50,000
+It does help to protect end users from potentially harmful content.
+
+175
+00:09:50,000 --> 00:09:57,000
+For example, in that email attachment sandboxing is something that is incredibly useful in any environment.
+
+176
+00:09:57,000 --> 00:09:59,000
+I highly recommend you get one.
+
+177
+00:09:59,000 --> 00:10:01,000
+Okay, just a quick recap.
+
+178
+00:10:01,000 --> 00:10:07,000
+Remember, input validation is going to be used to solve things like cross-site scripting and injection
+
+179
+00:10:07,000 --> 00:10:07,000
+attacks.
+
+180
+00:10:07,000 --> 00:10:10,000
+We use secure cookies.
+
+181
+00:10:10,000 --> 00:10:12,000
+Make sure all cookies are secure as they're being transferred.
+
+182
+00:10:12,000 --> 00:10:17,000
+Code signing is when you digitally sign codes, especially software codes.
+
+183
+00:10:17,000 --> 00:10:22,000
+That way, you know it came from a particular manufacturer and it was never modified.
+
+184
+00:10:23,000 --> 00:10:25,000
+And then make sure you understand.
+
+185
+00:10:25,000 --> 00:10:31,000
+Sandboxing is an amazing utility that helps us to test codes or tests for potential malware.
+
diff --git a/13 - Common Security Techniques/008 Security Monitoring OB 4.1_en.srt b/13 - Common Security Techniques/008 Security Monitoring OB 4.1_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..1a4ea59e1b93f70c295367b824054867af3d06bc
--- /dev/null
+++ b/13 - Common Security Techniques/008 Security Monitoring OB 4.1_en.srt
@@ -0,0 +1,296 @@
+1
+00:00:00,000 --> 00:00:02,000
+You're working in your network on a daily basis.
+
+2
+00:00:02,000 --> 00:00:05,000
+The question is, how do you know if you're being attacked?
+
+3
+00:00:05,000 --> 00:00:08,000
+You're sitting at your desktop, you're browsing the internet.
+
+4
+00:00:08,000 --> 00:00:10,000
+You're doing some work that your organization wants you to do.
+
+5
+00:00:10,000 --> 00:00:12,000
+Your security administrator.
+
+6
+00:00:12,000 --> 00:00:17,000
+How do you know that something bad is happening in that organization at that given moment?
+
+7
+00:00:17,000 --> 00:00:24,000
+The only way you're going to notice is if you are consistently monitoring the entire network.
+
+8
+00:00:24,000 --> 00:00:27,000
+You're monitoring what's happening in your system.
+
+9
+00:00:27,000 --> 00:00:31,000
+So this brings me to this topic of security monitoring.
+
+10
+00:00:31,000 --> 00:00:38,000
+You see, security monitoring is about monitoring traffic across your entire network, the horses and
+
+11
+00:00:38,000 --> 00:00:44,000
+the traffic flowing around the the lines, the networking devices for security issues and security problems
+
+12
+00:00:45,000 --> 00:00:48,000
+such as security attacks that can take place.
+
+13
+00:00:48,000 --> 00:00:51,000
+Now, a couple of things here we want to talk about when it comes to monitoring.
+
+14
+00:00:51,000 --> 00:00:54,000
+First of all, let's talk about network monitoring.
+
+15
+00:00:54,000 --> 00:00:58,000
+This involves tracking and analyzing network traffic.
+
+16
+00:00:58,000 --> 00:01:04,000
+You want to detect any abnormal any kind of abnormalities, any kind of abnormal traffic, unauthorized
+
+17
+00:01:04,000 --> 00:01:06,000
+access or other signs of malicious activity.
+
+18
+00:01:06,000 --> 00:01:09,000
+Then you have systems and application monitoring.
+
+19
+00:01:09,000 --> 00:01:11,000
+This is focused on performance and security.
+
+20
+00:01:11,000 --> 00:01:13,000
+Specific systems and applications.
+
+21
+00:01:13,000 --> 00:01:19,000
+Monitor monitoring for indication of security activities on a system like on a server or a workstation,
+
+22
+00:01:19,000 --> 00:01:23,000
+or maybe tracking what's happening in certain applications that we're using.
+
+23
+00:01:23,000 --> 00:01:27,000
+So if we look at this, we're going to be monitoring all the traffic flowing around the network and
+
+24
+00:01:27,000 --> 00:01:29,000
+all the traffic on the actual system.
+
+25
+00:01:29,000 --> 00:01:35,000
+The problem with monitoring is the enormous amount of data you're going to get.
+
+26
+00:01:35,000 --> 00:01:39,000
+Being able to correlate and track all this data is almost impossible.
+
+27
+00:01:39,000 --> 00:01:45,000
+That's why you need somewhere to collect and analyze the logs from the different network and devices
+
+28
+00:01:45,000 --> 00:01:47,000
+and systems on your network.
+
+29
+00:01:47,000 --> 00:01:51,000
+The tool we're going to use for this, and we're going to cover more about this tool later in this course
+
+30
+00:01:51,000 --> 00:01:52,000
+is the Siem system.
+
+31
+00:01:53,000 --> 00:01:56,000
+It sends the security information and event management there.
+
+32
+00:01:56,000 --> 00:02:03,000
+This is what's going to be we're going to use to aggregate correlate and analyze all this data that
+
+33
+00:02:03,000 --> 00:02:04,000
+you're going to be capturing.
+
+34
+00:02:05,000 --> 00:02:10,000
+Famous offer for this is going to be like Splunk is a very famous software that does this.
+
+35
+00:02:11,000 --> 00:02:14,000
+When you monitor, you're going to get some really good benefits.
+
+36
+00:02:14,000 --> 00:02:16,000
+Number one, early detection of threats.
+
+37
+00:02:16,000 --> 00:02:24,000
+If you're not monitoring, you may not know the threat is there until our systems are down or data has
+
+38
+00:02:24,000 --> 00:02:29,000
+been reported lost, versus if you are proactively monitoring, you would know the threat just came
+
+39
+00:02:29,000 --> 00:02:36,000
+in performance uh management ensuring that IT infrastructure operates efficiently.
+
+40
+00:02:36,000 --> 00:02:42,000
+The moment you see that servers are being pushed up too much, uh, in terms of Ram and CPU.
+
+41
+00:02:42,000 --> 00:02:44,000
+In other words, they're being taxed too much.
+
+42
+00:02:44,000 --> 00:02:48,000
+They become the resources are starting to be depleted quick.
+
+43
+00:02:48,000 --> 00:02:53,000
+You can quickly go in there and up your resources to make sure you stay at a certain performance.
+
+44
+00:02:54,000 --> 00:02:57,000
+Monitoring also helps with compliance.
+
+45
+00:02:57,000 --> 00:02:57,000
+All right.
+
+46
+00:02:57,000 --> 00:02:59,000
+Maintaining various regulatory compliance.
+
+47
+00:02:59,000 --> 00:03:08,000
+Because in certain times there may be security incidents that may occur that does require you to keep
+
+48
+00:03:08,000 --> 00:03:11,000
+an eye on different kinds of activities in your network.
+
+49
+00:03:11,000 --> 00:03:12,000
+Insights.
+
+50
+00:03:12,000 --> 00:03:15,000
+This provides valuable insights into the security posture.
+
+51
+00:03:15,000 --> 00:03:17,000
+How well is the security doing?
+
+52
+00:03:17,000 --> 00:03:20,000
+Listen, you don't know if your company is doing well in security.
+
+53
+00:03:20,000 --> 00:03:25,000
+If you're not checking anything, how do you know if you're losing weight, if you never really check
+
+54
+00:03:25,000 --> 00:03:26,000
+the scale?
+
+55
+00:03:27,000 --> 00:03:30,000
+Now, technically you can tell in the mirror, but it's hard to do that.
+
+56
+00:03:30,000 --> 00:03:35,000
+So the best thing to do is a continuous check to see how well security is.
+
+57
+00:03:35,000 --> 00:03:42,000
+Now, the best thing here is going to be real time monitoring, immediate analysis and alerts for ongoing
+
+58
+00:03:42,000 --> 00:03:43,000
+activities.
+
+59
+00:03:43,000 --> 00:03:44,000
+This is going to be critical.
+
+60
+00:03:44,000 --> 00:03:47,000
+You want to do rapid response real time.
+
+61
+00:03:47,000 --> 00:03:51,000
+But this does have a major problem significant power process and power.
+
+62
+00:03:51,000 --> 00:03:54,000
+And sophisticated tools like Siem systems.
+
+63
+00:03:54,000 --> 00:04:00,000
+Now if you do it on a regular basis, once, twice, three times a week, regular schedule checks for
+
+64
+00:04:00,000 --> 00:04:02,000
+analysis of certain uh systems.
+
+65
+00:04:03,000 --> 00:04:07,000
+Maybe if you're doing maybe once or twice a week, you can do less critical systems.
+
+66
+00:04:07,000 --> 00:04:14,000
+Maybe you want to do critical systems five days a week, or maybe you can combine both of them.
+
+67
+00:04:14,000 --> 00:04:20,000
+In other words, real time monitoring, not for everything, but for critical systems and periodic monitoring
+
+68
+00:04:20,000 --> 00:04:22,000
+for less critical system.
+
+69
+00:04:23,000 --> 00:04:28,000
+You would never know the security posture of the organization if you don't monitor.
+
+70
+00:04:28,000 --> 00:04:34,000
+If we don't monitor what's there, if we don't monitor the traffic, if we don't monitor the workstations
+
+71
+00:04:34,000 --> 00:04:36,000
+in our network, we wouldn't know if we're being attacked.
+
+72
+00:04:36,000 --> 00:04:42,000
+We wouldn't know how many times we're being attacked, wouldn't know what was solved, what wasn't solved,
+
+73
+00:04:42,000 --> 00:04:43,000
+and even how fast we fix it.
+
+74
+00:04:43,000 --> 00:04:49,000
+So monitoring is an essential part of keeping our organizations secure.
+
diff --git a/13 - Common Security Techniques/009 Quick Quiz.html b/13 - Common Security Techniques/009 Quick Quiz.html
new file mode 100644
index 0000000000000000000000000000000000000000..159fd41678e8a2ff3cd62c8176ad9d08c4b1c144
--- /dev/null
+++ b/13 - Common Security Techniques/009 Quick Quiz.html
@@ -0,0 +1,479 @@
+
+
+
+
+
+
+ Quiz
+
+
+
+
+
+
+
+
+ Score: 999 of
+ 999%
+
+ Correct: 999
+ Incorrect: 999
+
+
+
+
+
+
+
+
+
+
diff --git a/14 - Hardware, software and Data Asset Management/001 Acquisition Procurement OB 4.2_en.srt b/14 - Hardware, software and Data Asset Management/001 Acquisition Procurement OB 4.2_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..dac97fc8c3764a29830c128ebb1245d488d46339
--- /dev/null
+++ b/14 - Hardware, software and Data Asset Management/001 Acquisition Procurement OB 4.2_en.srt
@@ -0,0 +1,400 @@
+1
+00:00:00,000 --> 00:00:06,000
+90% of what you're going to be dealing with in large businesses is purchased from outside the company.
+
+2
+00:00:06,000 --> 00:00:12,000
+All the different hardware they use, such as the Sonicwall and different software such as windows CRM
+
+3
+00:00:12,000 --> 00:00:13,000
+software databases.
+
+4
+00:00:13,000 --> 00:00:18,000
+90% of what you use in large businesses is acquired from outside, if not more.
+
+5
+00:00:18,000 --> 00:00:24,000
+When it comes to small to mid-sized businesses, that percentage is probably close to 100%, if not
+
+6
+00:00:24,000 --> 00:00:25,000
+100%.
+
+7
+00:00:25,000 --> 00:00:30,000
+Every organization needs to have a process in place for acquisition and procurement.
+
+8
+00:00:30,000 --> 00:00:37,000
+That means they have to have a certain procedure in place for the selection of vendors and purchasing
+
+9
+00:00:37,000 --> 00:00:40,000
+of hardware and software from outside the business.
+
+10
+00:00:40,000 --> 00:00:44,000
+You see, this particular process for acquiring these hardware.
+
+11
+00:00:44,000 --> 00:00:51,000
+Software and data assets carry big security problems because if it's done wrong, you could be introducing
+
+12
+00:00:51,000 --> 00:00:53,000
+all kinds of security risks to your organization.
+
+13
+00:00:53,000 --> 00:00:56,000
+So in this video, let's take a quick look at this process.
+
+14
+00:00:56,000 --> 00:01:01,000
+Now I do want to just mention that this is just something you should be aware that exists, that businesses
+
+15
+00:01:01,000 --> 00:01:08,000
+is going to have a process and a procedure to acquire hardware and software, and every business has
+
+16
+00:01:08,000 --> 00:01:12,000
+it is just going to it's just going to be different for every business.
+
+17
+00:01:12,000 --> 00:01:15,000
+So in this video, I just want to point out a couple of things that we should be familiar with.
+
+18
+00:01:16,000 --> 00:01:23,000
+So each stage of the process of acquiring hardware and or software of this process can introduce vulnerability,
+
+19
+00:01:23,000 --> 00:01:24,000
+if not risk in it.
+
+20
+00:01:24,000 --> 00:01:26,000
+Now there's a couple of things here.
+
+21
+00:01:26,000 --> 00:01:33,000
+First of all, the importance of accuracy before we go out and we purchase.
+
+22
+00:01:33,000 --> 00:01:35,000
+This particular thing.
+
+23
+00:01:35,000 --> 00:01:37,000
+The needs assessment must be done.
+
+24
+00:01:37,000 --> 00:01:40,000
+Now, what a needs assessment is, do you actually need it?
+
+25
+00:01:40,000 --> 00:01:45,000
+Failing to accurately assess the organization's requirement can lead to acquiring assets that are either
+
+26
+00:01:45,000 --> 00:01:51,000
+that that are either overprivileged or lack the necessary security features, and thereby introducing
+
+27
+00:01:51,000 --> 00:01:52,000
+vulnerability.
+
+28
+00:01:52,000 --> 00:01:58,000
+For example, if you don't really need something, or you haven't done a good assessment on something
+
+29
+00:01:58,000 --> 00:02:03,000
+and you purchase something that the organization just doesn't need right now or just doesn't add any
+
+30
+00:02:03,000 --> 00:02:09,000
+value to it, you could be putting in hardware maybe not as good as a sonicwall, but some kind of hardware
+
+31
+00:02:09,000 --> 00:02:12,000
+and or software that can lead to vulnerability.
+
+32
+00:02:12,000 --> 00:02:20,000
+If you don't assess your vendors correctly and you purchase from vendors with history of dealing or
+
+33
+00:02:20,000 --> 00:02:25,000
+having issues, you could be introducing vulnerabilities into your environment.
+
+34
+00:02:25,000 --> 00:02:30,000
+So when it comes to particularly choosing a vendor, choosing a vendor with a poor security track record
+
+35
+00:02:30,000 --> 00:02:35,000
+or inadequate support for security features can expose you to massive risks.
+
+36
+00:02:35,000 --> 00:02:41,000
+Vendors compromised by cyber threats can inadvertently introduce new malware vulnerabilities, let's
+
+37
+00:02:41,000 --> 00:02:44,000
+say, for whatever reason.
+
+38
+00:02:44,000 --> 00:02:47,000
+And I'm going to tell you guys, you should never purchase security products from vendors, have never
+
+39
+00:02:47,000 --> 00:02:52,000
+heard about buy it from the big vendors who has massive crews to keep them secure.
+
+40
+00:02:52,000 --> 00:02:58,000
+Let's say your organization is trying to save money and decide they don't want to spend the thousand
+
+41
+00:02:58,000 --> 00:03:00,000
+dollars it takes to purchase this equipment.
+
+42
+00:03:00,000 --> 00:03:02,000
+And this is again, this is a small business.
+
+43
+00:03:02,000 --> 00:03:08,000
+For midsize businesses, purchasing Sonicwall can go thousands and thousands of dollars and with its
+
+44
+00:03:08,000 --> 00:03:10,000
+licensing, can go over way over $10,000.
+
+45
+00:03:10,000 --> 00:03:11,000
+Now.
+
+46
+00:03:11,000 --> 00:03:13,000
+Let's say you guys decide that you know what?
+
+47
+00:03:13,000 --> 00:03:16,000
+We don't want to spend a lot of money.
+
+48
+00:03:16,000 --> 00:03:21,000
+So you go with a smaller supplier or smaller maker or a new maker that just came out of a particular
+
+49
+00:03:21,000 --> 00:03:22,000
+firewall device.
+
+50
+00:03:22,000 --> 00:03:29,000
+Well, that new vendor that just came into the market may not have the resources and for example, the
+
+51
+00:03:29,000 --> 00:03:30,000
+manpower.
+
+52
+00:03:30,000 --> 00:03:38,000
+They may not have the resources and knowledge it takes to produce a device that has less security vulnerabilities
+
+53
+00:03:38,000 --> 00:03:39,000
+and the risks.
+
+54
+00:03:39,000 --> 00:03:44,000
+For example, let's say this Sonicwall there's a vulnerability discovered.
+
+55
+00:03:44,000 --> 00:03:48,000
+Well, Sonicwall is owned by Dell, and Sonicwall is a big company by itself.
+
+56
+00:03:48,000 --> 00:03:50,000
+And Dell is a is a massive IT company now.
+
+57
+00:03:52,000 --> 00:03:58,000
+I'm pretty sure Dell and Sonicwall has the resources needed in order to fix that vulnerability.
+
+58
+00:03:58,000 --> 00:03:59,000
+Right away.
+
+59
+00:03:59,000 --> 00:04:04,000
+You purchase from a small vendor if there's a vulnerability in their device and their software, you
+
+60
+00:04:04,000 --> 00:04:10,000
+might have to wait weeks, maybe months before you can get a fix if you even get a fix.
+
+61
+00:04:10,000 --> 00:04:15,000
+Not to mention, when you purchase from large vendors, they're less likely to go out of business.
+
+62
+00:04:15,000 --> 00:04:20,000
+For example, if you purchase a sonicwall device and for whatever reason, Dell goes out of business
+
+63
+00:04:20,000 --> 00:04:23,000
+and Sonicwall goes out of business, then what happens?
+
+64
+00:04:23,000 --> 00:04:24,000
+Well, no.
+
+65
+00:04:24,000 --> 00:04:25,000
+No more support.
+
+66
+00:04:25,000 --> 00:04:28,000
+The device you just purchased is pretty useless.
+
+67
+00:04:28,000 --> 00:04:32,000
+It becomes a paperweight as it's full of vulnerabilities with nobody to fix it.
+
+68
+00:04:32,000 --> 00:04:33,000
+That becomes an issue.
+
+69
+00:04:33,000 --> 00:04:33,000
+Right?
+
+70
+00:04:33,000 --> 00:04:40,000
+So there's a lot of things that you want to think about when selecting a vendor you don't do.
+
+71
+00:04:41,000 --> 00:04:49,000
+Uh, a good, thorough review of that vendor and their track record for how, for example, a security
+
+72
+00:04:49,000 --> 00:04:50,000
+track record.
+
+73
+00:04:50,000 --> 00:04:55,000
+What that means is how many vulnerabilities was against their device, how often is their device hacked,
+
+74
+00:04:55,000 --> 00:04:58,000
+and how fast do they fix those devices?
+
+75
+00:04:58,000 --> 00:04:59,000
+That can be a problem.
+
+76
+00:04:59,000 --> 00:05:02,000
+Another thing you want to take a look at is the supply chain attacks.
+
+77
+00:05:02,000 --> 00:05:06,000
+If the vendor supply chain is compromised, it can affect the integrity of the hardware.
+
+78
+00:05:06,000 --> 00:05:12,000
+For example, you may want to take a look at where the vendor sources their materials from.
+
+79
+00:05:12,000 --> 00:05:15,000
+For example, what does it mean by that source?
+
+80
+00:05:15,000 --> 00:05:16,000
+And the material means that.
+
+81
+00:05:17,000 --> 00:05:19,000
+Where did he get into hardware?
+
+82
+00:05:19,000 --> 00:05:20,000
+Where to get into steel.
+
+83
+00:05:20,000 --> 00:05:24,000
+Are they using suppliers in countries that are vulnerable?
+
+84
+00:05:24,000 --> 00:05:25,000
+And maybe they have political unrest?
+
+85
+00:05:25,000 --> 00:05:30,000
+Maybe the country is subject to all kinds of extreme weather conditions or natural disasters.
+
+86
+00:05:30,000 --> 00:05:37,000
+If you didn't do your assessment on the vendors, what eventually can happen is these vendors can drop
+
+87
+00:05:37,000 --> 00:05:42,000
+quickly because the moment there's a major disruption, the whole supply chain gets kicked out and the
+
+88
+00:05:42,000 --> 00:05:43,000
+vendor can't produce the hardware.
+
+89
+00:05:44,000 --> 00:05:51,000
+Okay, just keep in mind that the whole thing of procuring, the processes of procuring all, like all
+
+90
+00:05:51,000 --> 00:05:54,000
+I basically concentrated on was the selection of the vendor.
+
+91
+00:05:54,000 --> 00:05:59,000
+But every organization, they have to do some kind of a needs assessment.
+
+92
+00:05:59,000 --> 00:06:02,000
+Do we need this particular hardware, this particular software.
+
+93
+00:06:02,000 --> 00:06:04,000
+Why are we purchasing this.
+
+94
+00:06:04,000 --> 00:06:07,000
+They're going to have to go through a process of selecting a vendor.
+
+95
+00:06:07,000 --> 00:06:12,000
+They're going to have to do a process of onboarding that vendor into the organization.
+
+96
+00:06:12,000 --> 00:06:16,000
+And then the process of purchasing that actual hardware or software.
+
+97
+00:06:16,000 --> 00:06:18,000
+And keeping it updated.
+
+98
+00:06:18,000 --> 00:06:21,000
+This is not this is an your exam.
+
+99
+00:06:21,000 --> 00:06:27,000
+Your exam maker does not specify a process that they should follow because every organization is different.
+
+100
+00:06:27,000 --> 00:06:29,000
+So just be familiar that it exists.
+
diff --git a/14 - Hardware, software and Data Asset Management/002 Assignment and Accounting OB 4.2_en.srt b/14 - Hardware, software and Data Asset Management/002 Assignment and Accounting OB 4.2_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..e018dc09863cb1054add71d1de8c32fbc0e58705
--- /dev/null
+++ b/14 - Hardware, software and Data Asset Management/002 Assignment and Accounting OB 4.2_en.srt
@@ -0,0 +1,212 @@
+1
+00:00:00,000 --> 00:00:06,000
+When hardware and or software is purchased in an organization, it is generally assigned some kind of
+
+2
+00:00:06,000 --> 00:00:07,000
+ownership.
+
+3
+00:00:07,000 --> 00:00:12,000
+For example, when this thing is purchased to secure a particular department and or the entire business.
+
+4
+00:00:12,000 --> 00:00:16,000
+Most businesses is going to assign this thing some kind of ownership.
+
+5
+00:00:16,000 --> 00:00:18,000
+What department owns it?
+
+6
+00:00:18,000 --> 00:00:24,000
+Now, this is going to be important because ownership brings a lot of responsibilities when it comes
+
+7
+00:00:24,000 --> 00:00:25,000
+to the hardware and software.
+
+8
+00:00:25,000 --> 00:00:26,000
+Let's talk about this.
+
+9
+00:00:26,000 --> 00:00:32,000
+Ownership in cyber security reflects a designation of responsibility for an asset to an individual or
+
+10
+00:00:32,000 --> 00:00:34,000
+a department within the business.
+
+11
+00:00:34,000 --> 00:00:38,000
+It ensures that there is a specific party responsible for security, maintenance and compliance.
+
+12
+00:00:38,000 --> 00:00:44,000
+So more than likely something like this will be owned by the IT department.
+
+13
+00:00:44,000 --> 00:00:48,000
+Now, what does it mean when the organization says, well, you own that device?
+
+14
+00:00:48,000 --> 00:00:54,000
+Well, that means that this that department of it is responsible for the security of it, making sure
+
+15
+00:00:54,000 --> 00:01:00,000
+that they apply best security practices, the maintenance of it, updating it, for example.
+
+16
+00:01:01,000 --> 00:01:02,000
+And compliance of it.
+
+17
+00:01:02,000 --> 00:01:04,000
+Maybe there's different regulations.
+
+18
+00:01:04,000 --> 00:01:08,000
+Owners are going to be in charge of defining access control.
+
+19
+00:01:08,000 --> 00:01:14,000
+So the IT department, and particularly the security section of the IT department is going to be defining
+
+20
+00:01:14,000 --> 00:01:19,000
+on who should have access to this, how it should be configured, the permissions within it, and is
+
+21
+00:01:19,000 --> 00:01:21,000
+it used for any type of compliance.
+
+22
+00:01:21,000 --> 00:01:26,000
+So when assets are acquired it's important that ownership is assigned.
+
+23
+00:01:26,000 --> 00:01:30,000
+That way somebody holds the responsibility for defining this.
+
+24
+00:01:30,000 --> 00:01:36,000
+Another thing is that some organizations will implement a classification on the device.
+
+25
+00:01:36,000 --> 00:01:37,000
+Now this is important.
+
+26
+00:01:37,000 --> 00:01:40,000
+We talked about data classification previously.
+
+27
+00:01:40,000 --> 00:01:44,000
+Data classification affects all aspects of information.
+
+28
+00:01:44,000 --> 00:01:48,000
+Data classification is going to affect where the data is stored.
+
+29
+00:01:49,000 --> 00:01:50,000
+How is the data managed.
+
+30
+00:01:50,000 --> 00:01:56,000
+Who has access to the data, how is it backed up, what type of encryption and so on.
+
+31
+00:01:56,000 --> 00:02:00,000
+In this particular section, what we're doing is we're categorizing the assets.
+
+32
+00:02:00,000 --> 00:02:02,000
+This is a classification here.
+
+33
+00:02:02,000 --> 00:02:07,000
+It's categorizing this based on their sensitivity of value and their impact.
+
+34
+00:02:07,000 --> 00:02:13,000
+Now this is important because if we classify it as device to have something such as oh it's public or
+
+35
+00:02:13,000 --> 00:02:18,000
+it's internal only or it's confidential or something like that, that means that it can only process
+
+36
+00:02:18,000 --> 00:02:21,000
+data that's top secret or confidential.
+
+37
+00:02:21,000 --> 00:02:23,000
+For example, let's say you have.
+
+38
+00:02:24,000 --> 00:02:25,000
+Top secret data.
+
+39
+00:02:25,000 --> 00:02:29,000
+But did this device in your organization is not ranked as top secret?
+
+40
+00:02:29,000 --> 00:02:33,000
+Maybe because it doesn't have enough security protection built in it.
+
+41
+00:02:33,000 --> 00:02:39,000
+So that means this device can't ever process top secret data through its internal memory structure.
+
+42
+00:02:39,000 --> 00:02:43,000
+Certain organizations may use different devices for that, or they may not allow it on the network at
+
+43
+00:02:43,000 --> 00:02:44,000
+all.
+
+44
+00:02:44,000 --> 00:02:46,000
+Every organization is going to be different.
+
+45
+00:02:46,000 --> 00:02:52,000
+The purpose of doing this is to apply an appropriate level of security controls based on the classification
+
+46
+00:02:52,000 --> 00:02:56,000
+sensitive high value assets require, of course, much more protection.
+
+47
+00:02:56,000 --> 00:03:02,000
+For example, something in top secret is going to require much more protection than something that's
+
+48
+00:03:02,000 --> 00:03:02,000
+not.
+
+49
+00:03:03,000 --> 00:03:05,000
+When it comes to ownership and classification.
+
+50
+00:03:05,000 --> 00:03:07,000
+This is something that's unique to every business.
+
+51
+00:03:07,000 --> 00:03:12,000
+Every business has their own way of classifying information and or devices.
+
+52
+00:03:12,000 --> 00:03:17,000
+Basically, hardware, software and data will all have to go through a classification scheme.
+
+53
+00:03:17,000 --> 00:03:19,000
+This is different for every business.
+
diff --git a/14 - Hardware, software and Data Asset Management/003 Monitoring and Tracking OB 4.2_en.srt b/14 - Hardware, software and Data Asset Management/003 Monitoring and Tracking OB 4.2_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..5e909dcf95a3bbf688b9d9d189bf2622736e40a4
--- /dev/null
+++ b/14 - Hardware, software and Data Asset Management/003 Monitoring and Tracking OB 4.2_en.srt
@@ -0,0 +1,304 @@
+1
+00:00:00,000 --> 00:00:06,000
+If there is one thing that the IT department has probably heard too much of, is that you guys have
+
+2
+00:00:06,000 --> 00:00:07,000
+too much stuff.
+
+3
+00:00:07,000 --> 00:00:11,000
+If you walk into an IT department, they're going to have tons and tons of hardware that they don't
+
+4
+00:00:11,000 --> 00:00:13,000
+use, or tons of hardware that they do use.
+
+5
+00:00:13,000 --> 00:00:19,000
+I'm talking all kinds of routers and switches and gears and workstations and servers and laptops and
+
+6
+00:00:19,000 --> 00:00:21,000
+and tablets and phones.
+
+7
+00:00:21,000 --> 00:00:22,000
+Oh my God, it's a lot.
+
+8
+00:00:22,000 --> 00:00:28,000
+So in this video I want to talk about what's called monitoring and tracking of inventory.
+
+9
+00:00:28,000 --> 00:00:35,000
+Basically, do we have a system in place to keep track of all the physical hardware and software that
+
+10
+00:00:35,000 --> 00:00:39,000
+we use to produce or manage IT services?
+
+11
+00:00:39,000 --> 00:00:40,000
+So let's talk about this.
+
+12
+00:00:40,000 --> 00:00:43,000
+So the first thing I want to talk about here is inventory management.
+
+13
+00:00:44,000 --> 00:00:48,000
+Inventory management answers simple questions like this.
+
+14
+00:00:48,000 --> 00:00:51,000
+Well, in your network, how many workstations do you have?
+
+15
+00:00:51,000 --> 00:00:54,000
+How many servers you have, how many printers you got?
+
+16
+00:00:54,000 --> 00:00:58,000
+How many phones you have, how many firewalls you have?
+
+17
+00:00:58,000 --> 00:01:00,000
+You know, where is it stored?
+
+18
+00:01:00,000 --> 00:01:01,000
+Who owns it?
+
+19
+00:01:01,000 --> 00:01:02,000
+Is it identified?
+
+20
+00:01:02,000 --> 00:01:04,000
+Where is it in the lifecycle?
+
+21
+00:01:04,000 --> 00:01:05,000
+So this is what this is.
+
+22
+00:01:05,000 --> 00:01:06,000
+So let's go through it.
+
+23
+00:01:06,000 --> 00:01:08,000
+So asset identification.
+
+24
+00:01:08,000 --> 00:01:14,000
+What we need to do is we need to catalog all assets including the type model specification and version.
+
+25
+00:01:14,000 --> 00:01:18,000
+So how about if I told you guys I want you guys to go in your network now.
+
+26
+00:01:18,000 --> 00:01:19,000
+And I need you guys to.
+
+27
+00:01:20,000 --> 00:01:28,000
+Actually produce a list of every single desktop laptop, uh, server workstation.
+
+28
+00:01:28,000 --> 00:01:31,000
+Tell me not just their type.
+
+29
+00:01:31,000 --> 00:01:33,000
+Tell me their model.
+
+30
+00:01:33,000 --> 00:01:36,000
+How many models of the f 22 desktop do you have?
+
+31
+00:01:36,000 --> 00:01:37,000
+Their specifications?
+
+32
+00:01:38,000 --> 00:01:40,000
+How many i5 machines do we have?
+
+33
+00:01:40,000 --> 00:01:40,000
+How many i7's?
+
+34
+00:01:40,000 --> 00:01:45,000
+How many Macs and what versions are there record who is responsible for the asset.
+
+35
+00:01:45,000 --> 00:01:51,000
+For example, some assets are owned by the accounting department, some are owned by the sales department.
+
+36
+00:01:51,000 --> 00:01:53,000
+And where are they in their life cycle?
+
+37
+00:01:53,000 --> 00:01:56,000
+Most businesses will probably replace hardware every five years.
+
+38
+00:01:56,000 --> 00:02:01,000
+They may replace software every four or 3 to 8 years, depending on what it is.
+
+39
+00:02:01,000 --> 00:02:07,000
+Where in the life cycle is it, uh, from acquisition, like when did we acquire it and when is it left
+
+40
+00:02:07,000 --> 00:02:08,000
+to be disposed of?
+
+41
+00:02:08,000 --> 00:02:10,000
+So this is important.
+
+42
+00:02:10,000 --> 00:02:13,000
+You're probably saying, well, how does this relate to security?
+
+43
+00:02:13,000 --> 00:02:19,000
+Well, a well maintained inventory allows for the identification of unauthorized or rogue devices.
+
+44
+00:02:19,000 --> 00:02:22,000
+And software, which could pose potential security risks.
+
+45
+00:02:22,000 --> 00:02:29,000
+Because if you do this and you do this correctly, what's going to happen is that you'll know, well,
+
+46
+00:02:29,000 --> 00:02:30,000
+what's this doing here?
+
+47
+00:02:30,000 --> 00:02:31,000
+We never bought this.
+
+48
+00:02:31,000 --> 00:02:33,000
+This was something that wasn't belong on this network.
+
+49
+00:02:33,000 --> 00:02:39,000
+And it could be a hacker or some bad guy having hardware in your network you don't even know about.
+
+50
+00:02:40,000 --> 00:02:40,000
+This is.
+
+51
+00:02:40,000 --> 00:02:42,000
+Of course, I find this very challenging.
+
+52
+00:02:43,000 --> 00:02:45,000
+Even in our small network.
+
+53
+00:02:45,000 --> 00:02:50,000
+I find this very challenging because IT departments changes on a daily basis.
+
+54
+00:02:50,000 --> 00:02:56,000
+We're always ordering, changing, looking for new parts, and what happens is that keeping the inventory
+
+55
+00:02:56,000 --> 00:02:58,000
+up to date is a challenge for me.
+
+56
+00:02:58,000 --> 00:03:04,000
+New assets are frequently added and old ones are retired without people not managing it correctly.
+
+57
+00:03:04,000 --> 00:03:07,000
+Now enumerate means basically counting.
+
+58
+00:03:07,000 --> 00:03:10,000
+So in here we're going to identify quantify them.
+
+59
+00:03:10,000 --> 00:03:11,000
+How do we do this.
+
+60
+00:03:11,000 --> 00:03:13,000
+How do we enumerate these devices or count them.
+
+61
+00:03:13,000 --> 00:03:16,000
+Basically what we're going to be doing is we're going to use a scanning tool.
+
+62
+00:03:16,000 --> 00:03:18,000
+There's a great tool called Spiceworks that does this.
+
+63
+00:03:18,000 --> 00:03:18,000
+It's free.
+
+64
+00:03:18,000 --> 00:03:22,000
+Also used to scan the network for connected devices.
+
+65
+00:03:23,000 --> 00:03:28,000
+You can also determine what services are running on the devices, and some of them can even look for
+
+66
+00:03:28,000 --> 00:03:31,000
+vulnerabilities on these devices.
+
+67
+00:03:31,000 --> 00:03:36,000
+This helps in identifying all types of security weaknesses, and it gives you a good visibility into
+
+68
+00:03:36,000 --> 00:03:38,000
+the things on your network.
+
+69
+00:03:38,000 --> 00:03:43,000
+Now, one of the things is that if when you're doing enumeration activities, you don't disrupt normal
+
+70
+00:03:44,000 --> 00:03:50,000
+business operations, because when you enumerate, what starts to happen is that you're using up a lot
+
+71
+00:03:50,000 --> 00:03:54,000
+of bandwidth and particularly network traffic.
+
+72
+00:03:54,000 --> 00:03:54,000
+All right.
+
+73
+00:03:54,000 --> 00:03:57,000
+This particular thing here, I think is important.
+
+74
+00:03:57,000 --> 00:04:02,000
+Every network out there needs to have some kind of software.
+
+75
+00:04:03,000 --> 00:04:10,000
+Um, even a small as an Excel sheet that keeps track of all their hardware and software, basically
+
+76
+00:04:10,000 --> 00:04:12,000
+inventory tracking in their network.
+
diff --git a/14 - Hardware, software and Data Asset Management/004 Disposal and Decommission OB 4.2_en.srt b/14 - Hardware, software and Data Asset Management/004 Disposal and Decommission OB 4.2_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..7b7c1fd3c6c581b892066a7d05acacfd756d8c09
--- /dev/null
+++ b/14 - Hardware, software and Data Asset Management/004 Disposal and Decommission OB 4.2_en.srt
@@ -0,0 +1,592 @@
+1
+00:00:00,000 --> 00:00:05,000
+Every single piece of hardware and or software in an organization will reach an end of life at some
+
+2
+00:00:05,000 --> 00:00:06,000
+point.
+
+3
+00:00:06,000 --> 00:00:12,000
+Now, in most organizations, hardware like this will probably last 3 to 5, three to 5 to 8 years,
+
+4
+00:00:12,000 --> 00:00:14,000
+depending on what it is.
+
+5
+00:00:14,000 --> 00:00:17,000
+A device like this may be more like 5 to 8 years.
+
+6
+00:00:17,000 --> 00:00:22,000
+Certain hardware high end game, um, video editing hardware may only last three years.
+
+7
+00:00:22,000 --> 00:00:24,000
+Every piece of hardware is different.
+
+8
+00:00:24,000 --> 00:00:29,000
+Every piece of software is different as they all have different life cycles to different businesses.
+
+9
+00:00:29,000 --> 00:00:35,000
+Sometimes hardware and software comes to an end when the manufacturer brings it to an end.
+
+10
+00:00:35,000 --> 00:00:39,000
+For example, Microsoft stopped supporting windows XP or Windows 7.
+
+11
+00:00:39,000 --> 00:00:42,000
+Sonicwall makes a new device and stops supporting this.
+
+12
+00:00:42,000 --> 00:00:48,000
+The topic we're talking about here is called disposal and decommissioning of hardware and or software.
+
+13
+00:00:49,000 --> 00:00:54,000
+It's a process in cybersecurity that's it's not just about removing assets from operations, which is
+
+14
+00:00:54,000 --> 00:00:55,000
+what we're doing.
+
+15
+00:00:55,000 --> 00:01:00,000
+It's about ensuring that the end of life handling of those assets does not introduce new security risks.
+
+16
+00:01:00,000 --> 00:01:04,000
+Let me give you a quick, uh, example of a security problem.
+
+17
+00:01:05,000 --> 00:01:09,000
+This computer is no longer needed in Tia.
+
+18
+00:01:09,000 --> 00:01:11,000
+Somebody takes the hard drive.
+
+19
+00:01:11,000 --> 00:01:16,000
+Uh, somebody takes takes the machine off the desk, puts it in the garbage.
+
+20
+00:01:16,000 --> 00:01:16,000
+Just like that.
+
+21
+00:01:16,000 --> 00:01:17,000
+They just did that.
+
+22
+00:01:17,000 --> 00:01:22,000
+The machine is decomposed up, but then a hacker dumpster diving.
+
+23
+00:01:22,000 --> 00:01:26,000
+This is when they go through your trash, gets the hard drive, take gets the machine, takes out the
+
+24
+00:01:26,000 --> 00:01:27,000
+hard drive.
+
+25
+00:01:27,000 --> 00:01:34,000
+And because no one sanitized the drives, all Tia's data, they just got massive security problem.
+
+26
+00:01:34,000 --> 00:01:36,000
+So what do we need to do about this?
+
+27
+00:01:36,000 --> 00:01:43,000
+Well, when it comes to the end of life handling, especially when it comes to it, equipment, software,
+
+28
+00:01:43,000 --> 00:01:48,000
+hardware and software, we must understand this process of sanitization.
+
+29
+00:01:48,000 --> 00:01:54,000
+This is the process of removing sensitive data from storage device to ensure that it cannot be recovered
+
+30
+00:01:54,000 --> 00:01:56,000
+by unauthorized individuals.
+
+31
+00:01:57,000 --> 00:02:00,000
+That's what this is we need to remove.
+
+32
+00:02:00,000 --> 00:02:05,000
+So we need to take out, for example, the hard drive on that particular machine.
+
+33
+00:02:05,000 --> 00:02:07,000
+And maybe then we can dispose of the machine.
+
+34
+00:02:07,000 --> 00:02:12,000
+But the hard drive needs to go through a way to permanently remove the data.
+
+35
+00:02:12,000 --> 00:02:16,000
+One way of doing this is by shredding your hard drive or melting them.
+
+36
+00:02:16,000 --> 00:02:18,000
+This is called physical destruction.
+
+37
+00:02:18,000 --> 00:02:20,000
+This is physically destroying the drive.
+
+38
+00:02:20,000 --> 00:02:22,000
+Now I do have a slide on this.
+
+39
+00:02:22,000 --> 00:02:23,000
+I'll come back to this in a minute.
+
+40
+00:02:23,000 --> 00:02:27,000
+Something that you may want, that you may see on your exam is something called degaussing.
+
+41
+00:02:27,000 --> 00:02:28,000
+Degaussing works.
+
+42
+00:02:28,000 --> 00:02:36,000
+It's works on hard disk drives, not SSDs or solid state drives like a USB stick or just an Mdot two
+
+43
+00:02:36,000 --> 00:02:38,000
+drive or a Sata solid state drive.
+
+44
+00:02:38,000 --> 00:02:41,000
+I'm talking a good old fashioned hard drive.
+
+45
+00:02:41,000 --> 00:02:46,000
+And degausser is when they take a powerful magnet and they put it across that hard drive.
+
+46
+00:02:46,000 --> 00:02:49,000
+What that's going to do is it's going to completely erase the data.
+
+47
+00:02:49,000 --> 00:02:54,000
+Another thing you can do here is overwrite the drive with new data.
+
+48
+00:02:54,000 --> 00:02:58,000
+Several times I can't remember the number, but NIST I believe is 7 or 8 times.
+
+49
+00:02:58,000 --> 00:03:01,000
+Overwrite will make the data unrecoverable.
+
+50
+00:03:01,000 --> 00:03:02,000
+Now there's something I want to point out.
+
+51
+00:03:02,000 --> 00:03:07,000
+Generally, when you physically destroy the drive or degauss it, the drive is not reusable.
+
+52
+00:03:07,000 --> 00:03:13,000
+So if you ever plan to reuse the hard drive in a less sensitive way, then you want to make sure you
+
+53
+00:03:13,000 --> 00:03:16,000
+overwrite it multiple times.
+
+54
+00:03:16,000 --> 00:03:19,000
+Sometimes people call this thing purging of the drive.
+
+55
+00:03:19,000 --> 00:03:21,000
+Uh, degaussing and general physical destruction.
+
+56
+00:03:21,000 --> 00:03:23,000
+The drive is not usable.
+
+57
+00:03:23,000 --> 00:03:26,000
+Now, sanitization is critical for data breaches.
+
+58
+00:03:26,000 --> 00:03:28,000
+Preventing data breaches.
+
+59
+00:03:28,000 --> 00:03:32,000
+The reason is because if you just take a hard drive, you leave the machine, the hard drive in there,
+
+60
+00:03:32,000 --> 00:03:36,000
+and you throw a machine out, people will probably pick up the machine.
+
+61
+00:03:36,000 --> 00:03:41,000
+And before you know it, your data is gone and you have to comply with certain regulations.
+
+62
+00:03:41,000 --> 00:03:47,000
+In fact, things like HIPAA regulations, PCI compliance, when you're throwing those drives out those
+
+63
+00:03:47,000 --> 00:03:54,000
+regulations, you have to dispose of the media in a certain way, such as shredding the drives or degaussing
+
+64
+00:03:54,000 --> 00:03:57,000
+the actual hard drives themselves.
+
+65
+00:03:57,000 --> 00:03:58,000
+What's the challenges here?
+
+66
+00:03:58,000 --> 00:04:04,000
+Well, it's ensuring that the chosen sanitation method is appropriate for the type of storage that we
+
+67
+00:04:04,000 --> 00:04:05,000
+are doing.
+
+68
+00:04:05,000 --> 00:04:09,000
+Now, I want to talk quickly here about destruction.
+
+69
+00:04:09,000 --> 00:04:14,000
+This is physical dismantling or destruction of hardware.
+
+70
+00:04:14,000 --> 00:04:16,000
+That's what this is that cannot be used.
+
+71
+00:04:16,000 --> 00:04:22,000
+Again, remember, if you take a drive and you shred the hard drive, guys, there's no way that drive
+
+72
+00:04:22,000 --> 00:04:23,000
+will ever come back.
+
+73
+00:04:24,000 --> 00:04:28,000
+Uh, it is often used in storage devices cannot be readily sanitized.
+
+74
+00:04:28,000 --> 00:04:34,000
+Now, I want to just point out something before I move on here, is that degaussing will not work for
+
+75
+00:04:34,000 --> 00:04:39,000
+a solid state drive, because it's a big magnet and put the magnet over solid state since it's not magnetic,
+
+76
+00:04:39,000 --> 00:04:41,000
+doesn't do anything to it.
+
+77
+00:04:41,000 --> 00:04:43,000
+But when you physically destroy it, such a shredded.
+
+78
+00:04:44,000 --> 00:04:45,000
+Uh.
+
+79
+00:04:45,000 --> 00:04:46,000
+You will.
+
+80
+00:04:46,000 --> 00:04:48,000
+Definitely doesn't matter what the drive is.
+
+81
+00:04:48,000 --> 00:04:54,000
+USB stick, CDs, DVDs, uh, physical hard drives, solid state drive.
+
+82
+00:04:54,000 --> 00:04:54,000
+Doesn't matter.
+
+83
+00:04:55,000 --> 00:04:59,000
+This is a definite way to ensure data cannot be recovered.
+
+84
+00:04:59,000 --> 00:05:00,000
+Cannot be recovered.
+
+85
+00:05:00,000 --> 00:05:05,000
+The challenge is there is this must be carried out in a way that is environmentally responsible.
+
+86
+00:05:05,000 --> 00:05:10,000
+Now, I want you guys to keep in mind that more than likely you're not going to do this.
+
+87
+00:05:10,000 --> 00:05:12,000
+You're probably going to hire a company to do this.
+
+88
+00:05:13,000 --> 00:05:17,000
+Disposing of media is generally done by a third party organization.
+
+89
+00:05:17,000 --> 00:05:21,000
+You give them the media and they will destroy it for you.
+
+90
+00:05:21,000 --> 00:05:24,000
+What do you get back when when you hire them?
+
+91
+00:05:24,000 --> 00:05:30,000
+This thing, a certification in context of disposal as the documentation that the process confirmed
+
+92
+00:05:30,000 --> 00:05:32,000
+a proper sanitization.
+
+93
+00:05:32,000 --> 00:05:36,000
+It serves as proof that your organization has been has done this responsible.
+
+94
+00:05:36,000 --> 00:05:37,000
+Here's why.
+
+95
+00:05:37,000 --> 00:05:45,000
+Certain laws like HIPAA compliance, PCI compliance will make it mandatory that you dispose of the media
+
+96
+00:05:45,000 --> 00:05:46,000
+in a certain way.
+
+97
+00:05:47,000 --> 00:05:52,000
+When the hippo auditors come and they say, well, how did you dispose of those drives?
+
+98
+00:05:52,000 --> 00:05:53,000
+You're going to say, well, I shred it.
+
+99
+00:05:53,000 --> 00:05:55,000
+You have proof that you shred it.
+
+100
+00:05:55,000 --> 00:05:58,000
+Well, here is a certification.
+
+101
+00:05:58,000 --> 00:06:04,000
+Here's a document from, uh, Iron Mountain that they shredded the data for me.
+
+102
+00:06:04,000 --> 00:06:04,000
+Right.
+
+103
+00:06:04,000 --> 00:06:05,000
+They shredded the drive for me.
+
+104
+00:06:05,000 --> 00:06:07,000
+And the auditor looks and checks the box.
+
+105
+00:06:07,000 --> 00:06:07,000
+Okay.
+
+106
+00:06:07,000 --> 00:06:08,000
+Yeah, they did it right.
+
+107
+00:06:08,000 --> 00:06:08,000
+Here's the.
+
+108
+00:06:09,000 --> 00:06:10,000
+That's why this is important.
+
+109
+00:06:10,000 --> 00:06:16,000
+This helps in demonstrating compliance with legal and regulatory, uh, uh, laws that you have to follow.
+
+110
+00:06:17,000 --> 00:06:21,000
+Now, one thing I do want to mention is data retention.
+
+111
+00:06:23,000 --> 00:06:29,000
+Before we get into shredding all of these things, we have to understand that by law, retaining certain
+
+112
+00:06:29,000 --> 00:06:33,000
+data for specific periods of time is mandatory.
+
+113
+00:06:34,000 --> 00:06:39,000
+I believe in the United States colleges, if you're a college, you have to maintain for 80 years.
+
+114
+00:06:39,000 --> 00:06:42,000
+I think trade schools in New York is 20 years.
+
+115
+00:06:42,000 --> 00:06:44,000
+Uh, the IRS says 7 or 8 years.
+
+116
+00:06:44,000 --> 00:06:49,000
+I believe you have to maintain tax records for, um, they're required by law.
+
+117
+00:06:49,000 --> 00:06:54,000
+Certain, even organizational policies may want to keep things for a certain amount of time.
+
+118
+00:06:54,000 --> 00:07:00,000
+Now, it's important to balance data retention with the need to eliminate unnecessary data.
+
+119
+00:07:00,000 --> 00:07:03,000
+You can't just keep retaining data for long periods of time.
+
+120
+00:07:03,000 --> 00:07:07,000
+Retaining data takes up storage costs, money and security.
+
+121
+00:07:07,000 --> 00:07:08,000
+Of doing this.
+
+122
+00:07:08,000 --> 00:07:11,000
+Retaining data must be protected against it's classification.
+
+123
+00:07:11,000 --> 00:07:13,000
+So the more you have, the more you got to protect.
+
+124
+00:07:14,000 --> 00:07:16,000
+But you have to be careful with this.
+
+125
+00:07:16,000 --> 00:07:18,000
+You just can't go and delete data.
+
+126
+00:07:18,000 --> 00:07:18,000
+Oh, we don't need any more.
+
+127
+00:07:18,000 --> 00:07:19,000
+Just delete it.
+
+128
+00:07:19,000 --> 00:07:19,000
+No.
+
+129
+00:07:19,000 --> 00:07:23,000
+Check with the compliance department to see what laws are following.
+
+130
+00:07:23,000 --> 00:07:27,000
+Maybe PCI has specific laws of how long you have to keep that.
+
+131
+00:07:27,000 --> 00:07:31,000
+And so this HIPAA regulations for example medical records.
+
+132
+00:07:32,000 --> 00:07:36,000
+When it comes to data disposal, it is super important that you just don't take data and just throw
+
+133
+00:07:36,000 --> 00:07:37,000
+it out.
+
+134
+00:07:37,000 --> 00:07:38,000
+Media.
+
+135
+00:07:38,000 --> 00:07:40,000
+I mean, you don't take media and just throw it out.
+
+136
+00:07:40,000 --> 00:07:42,000
+You have to dig out that media.
+
+137
+00:07:42,000 --> 00:07:46,000
+You have to sanitize that media correctly before throwing it out.
+
+138
+00:07:46,000 --> 00:07:51,000
+And if you do, the best way to do it is not by you doing it as an IT professional or security.
+
+139
+00:07:51,000 --> 00:07:57,000
+The best way to do this is to hire a third party company, and there are many who will come to your
+
+140
+00:07:57,000 --> 00:07:59,000
+organization and shred your media.
+
+141
+00:07:59,000 --> 00:08:04,000
+When they're done, they're going to give you a certification that they have done it that is recognized
+
+142
+00:08:04,000 --> 00:08:10,000
+by many authorities, especially government regulators and auditors, to show that you did it correctly.
+
+143
+00:08:10,000 --> 00:08:15,000
+But before disposing of media, make sure you keep an eye on when is it okay to dispose of it.
+
+144
+00:08:15,000 --> 00:08:17,000
+You know, when do we have to get rid of this data?
+
+145
+00:08:17,000 --> 00:08:26,000
+Because tons of regulations does have, um, particular policies that says you have to retain the data
+
+146
+00:08:26,000 --> 00:08:30,000
+for a certain amount of time, but after that time is up, you can go ahead and get rid of it and you
+
+147
+00:08:30,000 --> 00:08:32,000
+have to sanitize the media.
+
+148
+00:08:32,000 --> 00:08:35,000
+So keep that in mind the next time you just throw away a hard drive.
+
diff --git a/14 - Hardware, software and Data Asset Management/005 Quick Quiz.html b/14 - Hardware, software and Data Asset Management/005 Quick Quiz.html
new file mode 100644
index 0000000000000000000000000000000000000000..35a5bc18bb4e8112f160ce81e18df8e3d893d5e3
--- /dev/null
+++ b/14 - Hardware, software and Data Asset Management/005 Quick Quiz.html
@@ -0,0 +1,479 @@
+
+
+
+
+
+
+ Quiz
+
+
+
+
+
+
+
+
+ Score: 999 of
+ 999%
+
+ Correct: 999
+ Incorrect: 999
+
+
+
+
+
+
+
+
+
+
diff --git a/15 - Vulnerability Management/001 Vulnerability Scan OB 4.3_en.srt b/15 - Vulnerability Management/001 Vulnerability Scan OB 4.3_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..84a5eb817e380b1b00937602a79a45617c74fb96
--- /dev/null
+++ b/15 - Vulnerability Management/001 Vulnerability Scan OB 4.3_en.srt
@@ -0,0 +1,200 @@
+1
+00:00:00,000 --> 00:00:03,000
+One of the most basic things you're going to be doing when you work in it.
+
+2
+00:00:03,000 --> 00:00:06,000
+Security is scanning your system.
+
+3
+00:00:06,000 --> 00:00:14,000
+You're going to have to scan all the devices, all your different desktops, laptops, windows and servers
+
+4
+00:00:14,000 --> 00:00:19,000
+and all this different software you have in your organization for known vulnerabilities.
+
+5
+00:00:19,000 --> 00:00:20,000
+Now for your exam.
+
+6
+00:00:20,000 --> 00:00:24,000
+I'm not going to spend a lot of time on this because you just really need to know what it is for your
+
+7
+00:00:24,000 --> 00:00:24,000
+exam.
+
+8
+00:00:24,000 --> 00:00:29,000
+Although this is a whole course by itself, let's just go through this pretty quickly.
+
+9
+00:00:29,000 --> 00:00:31,000
+And again, I could spend a lot of time on this.
+
+10
+00:00:31,000 --> 00:00:37,000
+If you know me personally, I teach a lot of white Hat hacking or Certified Ethical Hacker, and we
+
+11
+00:00:37,000 --> 00:00:38,000
+do this quite a lot.
+
+12
+00:00:38,000 --> 00:00:40,000
+So what is a vulnerability scan?
+
+13
+00:00:40,000 --> 00:00:46,000
+Well, a vulnerability scan is an automated it's an automated tool to scan systems, network and application
+
+14
+00:00:46,000 --> 00:00:53,000
+to identify known vulnerabilities such as unpatched software misconfiguration and security weakness.
+
+15
+00:00:53,000 --> 00:01:00,000
+The usage with regular scans help maintain an up to date understanding of security posture in your organization.
+
+16
+00:01:00,000 --> 00:01:01,000
+It's the first step in vulnerability.
+
+17
+00:01:01,000 --> 00:01:03,000
+Now, I'm going to tell you guys a couple of things here.
+
+18
+00:01:04,000 --> 00:01:11,000
+When it comes to vulnerability scans, one of the best scanner that I use is the Nexus security scanner.
+
+19
+00:01:11,000 --> 00:01:12,000
+You can look this up.
+
+20
+00:01:12,000 --> 00:01:13,000
+Just Google Nexus security scanner.
+
+21
+00:01:13,000 --> 00:01:16,000
+I'm not sure if they still have that free version.
+
+22
+00:01:16,000 --> 00:01:19,000
+These have a free version of it for smaller networks.
+
+23
+00:01:19,000 --> 00:01:24,000
+Now, what this thing is going to do is you install it, it scans all the computers in your network.
+
+24
+00:01:24,000 --> 00:01:27,000
+And then what it does is that it says that machine needs patches.
+
+25
+00:01:27,000 --> 00:01:31,000
+That machine has a blank administrator password.
+
+26
+00:01:31,000 --> 00:01:35,000
+What it's doing is that it's identifying vulnerabilities on your network.
+
+27
+00:01:35,000 --> 00:01:40,000
+It's identifying computers that are just not patched or misconfigured.
+
+28
+00:01:40,000 --> 00:01:49,000
+This is important to have because it is, in my opinion, impossible for you to go around to 2300 computers
+
+29
+00:01:49,000 --> 00:01:57,000
+and scan and scan it individually and or figure it out yourself if they're up to date or not, if they're
+
+30
+00:01:57,000 --> 00:01:59,000
+missing certain configuration.
+
+31
+00:01:59,000 --> 00:02:04,000
+You see these vulnerability scanners have a giant database of vulnerabilities that they're looking for,
+
+32
+00:02:05,000 --> 00:02:11,000
+and their databases is continuously updated with the latest vulnerabilities for whatever hardware and
+
+33
+00:02:11,000 --> 00:02:14,000
+or software application that they're checking.
+
+34
+00:02:14,000 --> 00:02:17,000
+So it's important to get a good vulnerability scanner.
+
+35
+00:02:17,000 --> 00:02:20,000
+Now I like the Nexus security scanner.
+
+36
+00:02:20,000 --> 00:02:22,000
+It's my favorite scanner to use.
+
+37
+00:02:22,000 --> 00:02:24,000
+There are tons of other scanners out there.
+
+38
+00:02:24,000 --> 00:02:27,000
+I remember Microsoft had the Microsoft Security Baseline Analyzer.
+
+39
+00:02:27,000 --> 00:02:29,000
+That one I thought was pretty good too.
+
+40
+00:02:29,000 --> 00:02:34,000
+So if you guys want to try this, you guys can go and download the Nexus security scanner.
+
+41
+00:02:34,000 --> 00:02:35,000
+Just give it a go in your own network.
+
+42
+00:02:35,000 --> 00:02:42,000
+But when it comes to your exam, I just want you guys to understand that a vulnerability scan is generally
+
+43
+00:02:42,000 --> 00:02:50,000
+an automated tool that scans all your systems, network gears and devices and application for vulnerabilities
+
+44
+00:02:50,000 --> 00:02:51,000
+on them.
+
+45
+00:02:51,000 --> 00:02:56,000
+It will then give you a nice report that says, here are some systems with vulnerabilities and what
+
+46
+00:02:56,000 --> 00:02:58,000
+they have, and these are things that you should do to fix it.
+
+47
+00:02:59,000 --> 00:03:02,000
+If you manage an IT security vulnerability.
+
+48
+00:03:02,000 --> 00:03:04,000
+Scanning is Basic Security 101.
+
+49
+00:03:04,000 --> 00:03:08,000
+So I highly recommend for you guys to download one of those and try it that way.
+
+50
+00:03:08,000 --> 00:03:13,000
+You're familiar with it because when you start working you will definitely be doing this.
+
diff --git a/15 - Vulnerability Management/002 Application Security Testing OB 4.3_en.srt b/15 - Vulnerability Management/002 Application Security Testing OB 4.3_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..d19c14afa216ce56c03fa9b5a936a2dee1b2f8dc
--- /dev/null
+++ b/15 - Vulnerability Management/002 Application Security Testing OB 4.3_en.srt
@@ -0,0 +1,144 @@
+1
+00:00:00,000 --> 00:00:06,000
+When applications are finished coding or programmers has finished coding an application, it is super
+
+2
+00:00:06,000 --> 00:00:08,000
+important that we test the application.
+
+3
+00:00:08,000 --> 00:00:14,000
+So in this video, let's take a look at three kinds of tests that application developers should be doing.
+
+4
+00:00:14,000 --> 00:00:18,000
+NSA Security Administrator you should be familiar with the these tests has to get done.
+
+5
+00:00:18,000 --> 00:00:25,000
+The first one up we'll talk about is called a static application, a static application security tests,
+
+6
+00:00:25,000 --> 00:00:27,000
+also known as static analysis.
+
+7
+00:00:27,000 --> 00:00:33,000
+This is known as dynamic application security testing or dynamic analysis and package monitoring.
+
+8
+00:00:33,000 --> 00:00:34,000
+So let's get started.
+
+9
+00:00:34,000 --> 00:00:37,000
+The first thing I will talk about is static analysis.
+
+10
+00:00:37,000 --> 00:00:42,000
+Now this involves examining application code to detect security flaws.
+
+11
+00:00:42,000 --> 00:00:46,000
+It doesn't execute the code, it just reads the code code by code.
+
+12
+00:00:46,000 --> 00:00:51,000
+Now I want to just point out that this is generally a piece of software that does this for you.
+
+13
+00:00:51,000 --> 00:00:57,000
+It's not something that you do by looking at code line by line static application.
+
+14
+00:00:57,000 --> 00:01:03,000
+Uh, testing is a review of the source code looking for common vulnerabilities that are in codes.
+
+15
+00:01:03,000 --> 00:01:08,000
+So it's useful for finding things like code injection, buffer overflows and other vulnerabilities.
+
+16
+00:01:08,000 --> 00:01:10,000
+That is usually in the code itself.
+
+17
+00:01:10,000 --> 00:01:13,000
+The other one is called dynamic testing.
+
+18
+00:01:13,000 --> 00:01:18,000
+Now dynamic testing is testing the application in runtime to identify any security issues that only
+
+19
+00:01:18,000 --> 00:01:20,000
+appear during execution.
+
+20
+00:01:20,000 --> 00:01:25,000
+This helps identify runtime errors like memory leaks, static analysis if you're doing things like injection
+
+21
+00:01:25,000 --> 00:01:30,000
+attacks, and so on, that's going to fall into this one of dynamic application security testing.
+
+22
+00:01:30,000 --> 00:01:35,000
+The last thing here we have is something we call, uh, package monitoring.
+
+23
+00:01:35,000 --> 00:01:41,000
+This is monitoring the software libraries and package use an application for known vulnerabilities.
+
+24
+00:01:41,000 --> 00:01:47,000
+This keeps what what you want to do is it involves keeping track of updates and patches for third party
+
+25
+00:01:47,000 --> 00:01:48,000
+components.
+
+26
+00:01:48,000 --> 00:01:53,000
+You see, package monitoring applications comes with a variety of different packages that are out there.
+
+27
+00:01:53,000 --> 00:01:58,000
+All kinds of add ons to basically the software package monitoring is checking to make sure that the
+
+28
+00:01:58,000 --> 00:02:03,000
+the packages that we do have for those applications don't have vulnerabilities in them.
+
+29
+00:02:04,000 --> 00:02:10,000
+Okay, static analysis and dynamic analysis is probably the two most common application security testing
+
+30
+00:02:10,000 --> 00:02:12,000
+that you need to be familiar with for your exam.
+
+31
+00:02:12,000 --> 00:02:14,000
+Remember static analysis.
+
+32
+00:02:14,000 --> 00:02:17,000
+We've used the code line by line, generally done by a piece of software.
+
+33
+00:02:17,000 --> 00:02:23,000
+Versus dynamic analysis is when they're going to run the code, basically run the application itself
+
+34
+00:02:23,000 --> 00:02:26,000
+and then analyze it while it's running.
+
+35
+00:02:26,000 --> 00:02:27,000
+Keep that in mind.
+
+36
+00:02:27,000 --> 00:02:28,000
+Taking your tests.
+
diff --git a/15 - Vulnerability Management/003 Threat Feeds OB 4.3_en.srt b/15 - Vulnerability Management/003 Threat Feeds OB 4.3_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..30c805f6838e7ca7058e4c800deedfa14b89db31
--- /dev/null
+++ b/15 - Vulnerability Management/003 Threat Feeds OB 4.3_en.srt
@@ -0,0 +1,300 @@
+1
+00:00:00,000 --> 00:00:06,000
+A good security administrator is going to be able to detect threats about their particular business
+
+2
+00:00:06,000 --> 00:00:07,000
+before it even appears.
+
+3
+00:00:07,000 --> 00:00:12,000
+This person is going to be able to do research on its company and to see what's out there on its own
+
+4
+00:00:12,000 --> 00:00:13,000
+business.
+
+5
+00:00:13,000 --> 00:00:17,000
+Now, in order to do this, you're going to have to gather a lot of information.
+
+6
+00:00:17,000 --> 00:00:20,000
+And that brings me to this particular video.
+
+7
+00:00:20,000 --> 00:00:22,000
+We're going to be talking about threat feeds.
+
+8
+00:00:22,000 --> 00:00:27,000
+This is going to be how do we find information basically gathering information on different threats
+
+9
+00:00:27,000 --> 00:00:29,000
+to our organization.
+
+10
+00:00:29,000 --> 00:00:30,000
+Let's get started with this.
+
+11
+00:00:30,000 --> 00:00:35,000
+So the first thing we're going to be talking about is what's called Osint or open source intelligence.
+
+12
+00:00:35,000 --> 00:00:40,000
+This is about gathering data, all kinds of data, whether it's data about your business, your domain
+
+13
+00:00:40,000 --> 00:00:47,000
+name about other people, potential threats that are out there from publicly available sources to identify
+
+14
+00:00:47,000 --> 00:00:49,000
+emerging threats and vulnerability.
+
+15
+00:00:49,000 --> 00:00:55,000
+Now Osint, there is a framework that we can use for this and a really good website that we can use
+
+16
+00:00:55,000 --> 00:00:58,000
+that will help us find information on a wide variety of things.
+
+17
+00:00:58,000 --> 00:01:02,000
+And let's go to that website as I've already opened it.
+
+18
+00:01:02,000 --> 00:01:04,000
+Let's see what it looks like.
+
+19
+00:01:04,000 --> 00:01:08,000
+So if you use the link in this slide and you go here, this is what it looks like.
+
+20
+00:01:08,000 --> 00:01:15,000
+This here is going to allow me to find tons of information, whether it's trying to find email addresses
+
+21
+00:01:15,000 --> 00:01:21,000
+about a certain person, IP addresses, uh, just to make make this video generic.
+
+22
+00:01:21,000 --> 00:01:23,000
+You don't want to search for anything that'll put us in trouble.
+
+23
+00:01:23,000 --> 00:01:29,000
+I'm just going to go and get company general information on, uh, Technical School of America.
+
+24
+00:01:29,000 --> 00:01:32,000
+So let's just use this like as this link here, general information.
+
+25
+00:01:32,000 --> 00:01:38,000
+And we'll do a corporation wiki just to see what we find and notice how it takes out a website.
+
+26
+00:01:38,000 --> 00:01:40,000
+So we're going to search for technical.
+
+27
+00:01:40,000 --> 00:01:41,000
+So.
+
+28
+00:01:45,000 --> 00:01:46,000
+Let's search for my company.
+
+29
+00:01:46,000 --> 00:01:50,000
+And notice that it found Technical School of America.
+
+30
+00:01:50,000 --> 00:01:51,000
+It's owned by me.
+
+31
+00:01:51,000 --> 00:01:54,000
+And so they misspelled my name uh on their.
+
+32
+00:01:55,000 --> 00:02:01,000
+And basically it's going to give you information on the corporation itself when we were founded.
+
+33
+00:02:01,000 --> 00:02:04,000
+We are a corporation in New York City from 2009.
+
+34
+00:02:04,000 --> 00:02:06,000
+We're 14 years old.
+
+35
+00:02:06,000 --> 00:02:10,000
+I doesn't have a ton of information on us, but it will help you to find information.
+
+36
+00:02:10,000 --> 00:02:15,000
+And this is this begins your hunt for actual data itself.
+
+37
+00:02:15,000 --> 00:02:17,000
+So I think that's a pretty cool framework.
+
+38
+00:02:17,000 --> 00:02:19,000
+You guys can I don't want to go too much into it.
+
+39
+00:02:19,000 --> 00:02:20,000
+It's really outside the scope of this.
+
+40
+00:02:20,000 --> 00:02:25,000
+But if you're taking my ethical hacking course, we use that website quite a lot so you guys can have
+
+41
+00:02:25,000 --> 00:02:28,000
+some fun looking at the old Saint framework.
+
+42
+00:02:29,000 --> 00:02:33,000
+Uh, going back here to this here, uh, proprietary third party.
+
+43
+00:02:33,000 --> 00:02:40,000
+So subscribing to specialized services that provide information on the latest threats and vulnerabilities.
+
+44
+00:02:40,000 --> 00:02:42,000
+This offers more tailored, more real time information.
+
+45
+00:02:42,000 --> 00:02:48,000
+So if your organization is subscribed to a certain threat feeds and you can get this from providers,
+
+46
+00:02:48,000 --> 00:02:54,000
+makers of different kinds of firewall or security software, this would really help you to find vulnerabilities
+
+47
+00:02:54,000 --> 00:02:57,000
+more specific to your organization.
+
+48
+00:02:57,000 --> 00:02:59,000
+Information sharing organization.
+
+49
+00:02:59,000 --> 00:03:03,000
+There is an organization such as information sharing and analysis centers.
+
+50
+00:03:03,000 --> 00:03:07,000
+These are groups that share information on different vulnerabilities, such as.
+
+51
+00:03:07,000 --> 00:03:12,000
+If I had a vulnerability in my organization, let me share that information with you.
+
+52
+00:03:13,000 --> 00:03:18,000
+This facilitates collaboration with with security folks like yourself.
+
+53
+00:03:18,000 --> 00:03:22,000
+Now, the other one that I don't recommend looking at is going to be the dark web.
+
+54
+00:03:22,000 --> 00:03:25,000
+Now, this is not a course on the dark web, but just really quick.
+
+55
+00:03:25,000 --> 00:03:30,000
+The dark web is basically a set of servers that are not indexed.
+
+56
+00:03:30,000 --> 00:03:33,000
+In other words, you're not going to find what's on the dark web on Google Index.
+
+57
+00:03:33,000 --> 00:03:35,000
+A Google doesn't index these particular servers.
+
+58
+00:03:35,000 --> 00:03:41,000
+Sometimes getting to them is difficult because sometimes you have to use an IP address or some very
+
+59
+00:03:41,000 --> 00:03:42,000
+weird domain name.
+
+60
+00:03:42,000 --> 00:03:47,000
+Now, monitoring the dark web forums and marketplace to gather intelligence on new vulnerabilities.
+
+61
+00:03:47,000 --> 00:03:48,000
+Exploit a threat.
+
+62
+00:03:48,000 --> 00:03:50,000
+Actors is a good way to do this.
+
+63
+00:03:50,000 --> 00:03:56,000
+When I teach ethical hacking courses like Certified Ethical Hacker, I do show them how to use the dark
+
+64
+00:03:56,000 --> 00:03:59,000
+web in order to monitor forms.
+
+65
+00:03:59,000 --> 00:04:03,000
+A lot of the attacks that are going to be coming out towards your organization, especially like different
+
+66
+00:04:03,000 --> 00:04:05,000
+forms of crypto.
+
+67
+00:04:06,000 --> 00:04:09,000
+Crypto malware and all that type of stuff.
+
+68
+00:04:09,000 --> 00:04:12,000
+Uh, things that are going on, ransomware, I should say, that are coming out.
+
+69
+00:04:12,000 --> 00:04:16,000
+These kinds of software originates on the dark web and is shared on there.
+
+70
+00:04:16,000 --> 00:04:23,000
+So if you play on the dark web and you go to these forums, you'll be better able to see what things
+
+71
+00:04:23,000 --> 00:04:24,000
+could affect your business.
+
+72
+00:04:24,000 --> 00:04:29,000
+A good security administrator once again will know the different threats that are affecting the that
+
+73
+00:04:29,000 --> 00:04:34,000
+are that could be affecting their business or affect their business in the future.
+
+74
+00:04:34,000 --> 00:04:37,000
+The best thing we can do is learn about the threats before they come.
+
+75
+00:04:37,000 --> 00:04:42,000
+That way we can protect ourselves from that threat before they even show up.
+
diff --git a/15 - Vulnerability Management/004 Penetration Testing OB 4.3_en.srt b/15 - Vulnerability Management/004 Penetration Testing OB 4.3_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..3ea02a43ab4335964750c5265c31d2ba949add17
--- /dev/null
+++ b/15 - Vulnerability Management/004 Penetration Testing OB 4.3_en.srt
@@ -0,0 +1,1024 @@
+1
+00:00:00,000 --> 00:00:05,000
+I spent many years of my career being a pen tester and I like teaching pen testing.
+
+2
+00:00:05,000 --> 00:00:09,000
+So in this video I'm going to talk about my most favorite topic, pen testing.
+
+3
+00:00:09,000 --> 00:00:14,000
+I'm going to try to keep it short just to your exam, but it's still going to be pretty long because
+
+4
+00:00:14,000 --> 00:00:18,000
+in this video I'm going to cover everything you need to know about pen testing.
+
+5
+00:00:18,000 --> 00:00:26,000
+I'll start out this by saying this you never really understand how good your network actually is until
+
+6
+00:00:26,000 --> 00:00:27,000
+somebody tries to hack it.
+
+7
+00:00:28,000 --> 00:00:33,000
+You really don't know how good your controls work until you actually test it.
+
+8
+00:00:33,000 --> 00:00:38,000
+You don't know how much weight you can actually lift until you actually try to pick up the weight,
+
+9
+00:00:38,000 --> 00:00:38,000
+right?
+
+10
+00:00:39,000 --> 00:00:40,000
+So.
+
+11
+00:00:41,000 --> 00:00:47,000
+This topic of pen testing will answer the question of how secure are we really?
+
+12
+00:00:47,000 --> 00:00:50,000
+Are those controls actually working?
+
+13
+00:00:50,000 --> 00:00:55,000
+You don't really know if a car can hit 200 miles an hour, unless you actually try to make it hit 200
+
+14
+00:00:55,000 --> 00:00:56,000
+miles an hour.
+
+15
+00:00:56,000 --> 00:01:01,000
+You don't know if your server can actually protect against a certain attack until you attack it.
+
+16
+00:01:01,000 --> 00:01:06,000
+Pen testing is the ultimate security test.
+
+17
+00:01:06,000 --> 00:01:12,000
+Pen testing is when you hire folks, generally from outside your organization to hack your business.
+
+18
+00:01:12,000 --> 00:01:16,000
+Now they're not going to hack it to destroy it, but they're going to hack it to test the controls.
+
+19
+00:01:16,000 --> 00:01:22,000
+They're basically going to hack your network the way a real hacker would do it.
+
+20
+00:01:22,000 --> 00:01:28,000
+Now, pen testing is a practice of testing a computer system network, a web application to find vulnerabilities
+
+21
+00:01:28,000 --> 00:01:31,000
+that an attacker could exploit during pen testing.
+
+22
+00:01:31,000 --> 00:01:33,000
+They might even exploit it for you.
+
+23
+00:01:33,000 --> 00:01:37,000
+This is generally done using manual or all types of automated technology.
+
+24
+00:01:38,000 --> 00:01:43,000
+This this course doesn't cover all the tools that we use in pen testing, but whether we're using an
+
+25
+00:01:43,000 --> 00:01:50,000
+nmap scanner, some kind of automated vulnerability scanner, it could get very technical when you do
+
+26
+00:01:50,000 --> 00:01:51,000
+it.
+
+27
+00:01:51,000 --> 00:01:56,000
+The goal of this thing here is to determine the feasibility of a particular set of attack vectors.
+
+28
+00:01:56,000 --> 00:01:59,000
+Like what attack vectors can they use against you?
+
+29
+00:01:59,000 --> 00:02:05,000
+Identify high risk vulnerabilities from a combination of lower risk vulnerabilities exploited.
+
+30
+00:02:05,000 --> 00:02:11,000
+So people think, well, I can't lose all this data, but a combination of small holes you have in your
+
+31
+00:02:11,000 --> 00:02:13,000
+network could lead to big data loss.
+
+32
+00:02:13,000 --> 00:02:19,000
+Identify vulnerabilities may be difficult or impossible to detect with automated network or application
+
+33
+00:02:19,000 --> 00:02:21,000
+vulnerability scanners.
+
+34
+00:02:21,000 --> 00:02:26,000
+You know, one thing I want to point out is that if you use a vulnerability scanner like the Nexus security
+
+35
+00:02:26,000 --> 00:02:33,000
+scanner, it doesn't replace a pen test that'll just be able to find vulnerabilities, but it's not
+
+36
+00:02:33,000 --> 00:02:35,000
+going to find every vulnerability that is out there.
+
+37
+00:02:35,000 --> 00:02:39,000
+Assess the magnitude of potential business and operational impacts.
+
+38
+00:02:39,000 --> 00:02:41,000
+What happens if there is a successful attack?
+
+39
+00:02:41,000 --> 00:02:43,000
+How does it impact the business?
+
+40
+00:02:43,000 --> 00:02:48,000
+This will tell you that testability of the different network defenders to detect and respond.
+
+41
+00:02:48,000 --> 00:02:53,000
+Sometimes pen tests aren't even told to the people in the network and department.
+
+42
+00:02:53,000 --> 00:02:56,000
+They think they're being attacked and they start to respond to it.
+
+43
+00:02:57,000 --> 00:03:01,000
+Provide evidence to support increased investment in security personnel and technology.
+
+44
+00:03:01,000 --> 00:03:05,000
+I like this one because, you know, if there's one thing management doesn't like about us, IT folks,
+
+45
+00:03:05,000 --> 00:03:09,000
+is we spend a lot of money and they always ask us to justify it.
+
+46
+00:03:09,000 --> 00:03:15,000
+But when you do a pen test and you could show that this network is incredibly vulnerable, they're probably
+
+47
+00:03:15,000 --> 00:03:17,000
+going to up their budget on you.
+
+48
+00:03:17,000 --> 00:03:20,000
+Now, this is the part of the exam that you really want to know.
+
+49
+00:03:20,000 --> 00:03:22,000
+There are three pen tests.
+
+50
+00:03:22,000 --> 00:03:24,000
+There's black box, gray box and white box.
+
+51
+00:03:24,000 --> 00:03:27,000
+A black box test is known as a zero knowledge test.
+
+52
+00:03:27,000 --> 00:03:29,000
+This is known as a closed test.
+
+53
+00:03:29,000 --> 00:03:32,000
+In other words, they zero knowledge.
+
+54
+00:03:32,000 --> 00:03:37,000
+In other words, whoever is doing the pen test has no knowledge about your network.
+
+55
+00:03:37,000 --> 00:03:43,000
+This is usually an external test done by a third party organization that you hire.
+
+56
+00:03:43,000 --> 00:03:46,000
+Basically, you're going to call them up and say, hey man, can you do this test for me?
+
+57
+00:03:46,000 --> 00:03:51,000
+They're going to stay in their location and they're going to hack you the same way an external hacker
+
+58
+00:03:51,000 --> 00:03:52,000
+would hack your network.
+
+59
+00:03:52,000 --> 00:03:57,000
+Now, this is from the outsider hackers perspective.
+
+60
+00:03:57,000 --> 00:03:59,000
+I'm going to go down here to white box.
+
+61
+00:03:59,000 --> 00:04:03,000
+Now white box is full knowledge test.
+
+62
+00:04:03,000 --> 00:04:10,000
+Now they in this kind of test the network administrators they will tell you if you're a pen tester all
+
+63
+00:04:10,000 --> 00:04:15,000
+the information about the network from the network schematics such as IP addresses, locations of devices,
+
+64
+00:04:15,000 --> 00:04:20,000
+different kinds of security protocols have implemented as much documentation as possible.
+
+65
+00:04:20,000 --> 00:04:25,000
+They're going to give you it's called open or crystal test because you can see everything this is done
+
+66
+00:04:25,000 --> 00:04:28,000
+from an administrator perspective.
+
+67
+00:04:28,000 --> 00:04:28,000
+All right.
+
+68
+00:04:28,000 --> 00:04:30,000
+This is done from an administrator perspective.
+
+69
+00:04:30,000 --> 00:04:35,000
+Now white box testing from my experience has always been something very specific.
+
+70
+00:04:35,000 --> 00:04:39,000
+You're not testing a whole network, which you might be testing a very specific thing such as a particular
+
+71
+00:04:39,000 --> 00:04:41,000
+application gray box testing.
+
+72
+00:04:41,000 --> 00:04:46,000
+Well, as you can imagine, if this is white, this is black, this is gray, this is limited.
+
+73
+00:04:46,000 --> 00:04:47,000
+Information is provided.
+
+74
+00:04:47,000 --> 00:04:48,000
+Not a lot.
+
+75
+00:04:48,000 --> 00:04:50,000
+Maybe IP addresses and domain names.
+
+76
+00:04:51,000 --> 00:04:56,000
+Uh, generally it is from an insider's perspective on the test.
+
+77
+00:04:57,000 --> 00:05:02,000
+Now when it comes to pen testing, I want all of you guys to be in the white hat hacker.
+
+78
+00:05:02,000 --> 00:05:03,000
+This is an ethical hacker.
+
+79
+00:05:03,000 --> 00:05:07,000
+This is when you test, with permission, black hat hackers.
+
+80
+00:05:07,000 --> 00:05:08,000
+Unethical.
+
+81
+00:05:08,000 --> 00:05:10,000
+But this one is testing without authorization.
+
+82
+00:05:10,000 --> 00:05:14,000
+This one is basically what we would call a hacker gray hat.
+
+83
+00:05:14,000 --> 00:05:19,000
+You know, there are some really good, uh, pen testers out there who in the day?
+
+84
+00:05:19,000 --> 00:05:20,000
+They're good guys.
+
+85
+00:05:20,000 --> 00:05:22,000
+And in the night, they turn to bad guys.
+
+86
+00:05:22,000 --> 00:05:25,000
+They start doing bad things because they already have the knowledge.
+
+87
+00:05:25,000 --> 00:05:26,000
+That's a gray hat.
+
+88
+00:05:26,000 --> 00:05:28,000
+Script, kiddies is more of an insultive worm.
+
+89
+00:05:28,000 --> 00:05:33,000
+Script kiddies are folks that don't have technical skill now.
+
+90
+00:05:34,000 --> 00:05:40,000
+If you want to be a pen tester, I tell all my students there are a few things you need to know.
+
+91
+00:05:40,000 --> 00:05:44,000
+All right, obviously you need to have a great networking background.
+
+92
+00:05:45,000 --> 00:05:51,000
+But when it comes to pen testing, you need to know Bash and Python.
+
+93
+00:05:51,000 --> 00:05:54,000
+Those are the two things that you should be very familiar with.
+
+94
+00:05:54,000 --> 00:05:58,000
+You don't need to be a programmer, but you do need to understand them.
+
+95
+00:05:58,000 --> 00:06:01,000
+Be able to read them and be able to somewhat write them.
+
+96
+00:06:01,000 --> 00:06:06,000
+You don't need to be a super expert, but if you're a kind of person that doesn't know any kind of scripting
+
+97
+00:06:06,000 --> 00:06:11,000
+and you just execute other people's script, your script kiddie, they have little to no skill.
+
+98
+00:06:11,000 --> 00:06:14,000
+They may not understand full networking.
+
+99
+00:06:14,000 --> 00:06:17,000
+They don't write their own codes or program or even edit it.
+
+100
+00:06:18,000 --> 00:06:26,000
+Now, when you're doing a pen test, it is important that the organization that you hire to do the pen
+
+101
+00:06:26,000 --> 00:06:31,000
+tests and you, let's say you're hiring someone, have what's called a rule of engagement.
+
+102
+00:06:32,000 --> 00:06:36,000
+This specifies what the tester can do.
+
+103
+00:06:36,000 --> 00:06:41,000
+Like what range can of IPS can they scan, when can they do the test?
+
+104
+00:06:41,000 --> 00:06:44,000
+What methodology or tools should they be using?
+
+105
+00:06:44,000 --> 00:06:46,000
+Can they do a DDoS?
+
+106
+00:06:46,000 --> 00:06:46,000
+Maybe.
+
+107
+00:06:46,000 --> 00:06:47,000
+Maybe not.
+
+108
+00:06:47,000 --> 00:06:50,000
+Can they social engineer your workers?
+
+109
+00:06:50,000 --> 00:06:52,000
+Can they attempt physical intrusion?
+
+110
+00:06:52,000 --> 00:06:54,000
+Is there a set of IP should be excluded?
+
+111
+00:06:54,000 --> 00:06:55,000
+How do you want your report?
+
+112
+00:06:55,000 --> 00:06:57,000
+How should the communication be done?
+
+113
+00:06:57,000 --> 00:07:01,000
+There's a lot of things here pen testing has.
+
+114
+00:07:01,000 --> 00:07:02,000
+Why are we doing this well.
+
+115
+00:07:04,000 --> 00:07:06,000
+Because there is a lot.
+
+116
+00:07:06,000 --> 00:07:06,000
+I'm going to skip this one.
+
+117
+00:07:06,000 --> 00:07:07,000
+We'll come back to that.
+
+118
+00:07:07,000 --> 00:07:10,000
+There's a lot of risk associated with a pen test.
+
+119
+00:07:10,000 --> 00:07:18,000
+When pen testers are done, you have to remember that things can can be broken, for example, your
+
+120
+00:07:18,000 --> 00:07:20,000
+phone system or your PBX.
+
+121
+00:07:20,000 --> 00:07:26,000
+Private branch exchange means your phone system can stop if you try to scan certain phone systems,
+
+122
+00:07:26,000 --> 00:07:31,000
+especially SCADA based systems, or try to try to test them, they could go right down and cause a massive
+
+123
+00:07:31,000 --> 00:07:32,000
+disaster.
+
+124
+00:07:32,000 --> 00:07:37,000
+So there's a lot of risk expected with tinti's pen testing.
+
+125
+00:07:37,000 --> 00:07:42,000
+What if the pen testers tries to do a DDoS against your web server in the middle of the day, now all
+
+126
+00:07:42,000 --> 00:07:45,000
+of a sudden takes your web server out, the business starts to lose money.
+
+127
+00:07:46,000 --> 00:07:54,000
+Pym tests because of the risks that is associated with a pen test, and also because technically they're
+
+128
+00:07:54,000 --> 00:07:55,000
+hacking you.
+
+129
+00:07:55,000 --> 00:08:01,000
+Before a pen test can done, you must have a signed agreement.
+
+130
+00:08:01,000 --> 00:08:02,000
+All right.
+
+131
+00:08:02,000 --> 00:08:05,000
+A signed document giving the pen tester permission.
+
+132
+00:08:05,000 --> 00:08:13,000
+Understand the difference between a pen test and an actual hack is one has permission and one doesn't.
+
+133
+00:08:14,000 --> 00:08:14,000
+All right.
+
+134
+00:08:14,000 --> 00:08:20,000
+A hacker coming in and hacking your organization to destroy data is not very much different than a pen
+
+135
+00:08:20,000 --> 00:08:24,000
+test, except the pen test has permission to do it and will inform you at the end what they did.
+
+136
+00:08:24,000 --> 00:08:26,000
+And here are things you should fix.
+
+137
+00:08:26,000 --> 00:08:29,000
+So a pen tester must have this document.
+
+138
+00:08:30,000 --> 00:08:33,000
+On the Y on the person while it's getting done.
+
+139
+00:08:33,000 --> 00:08:33,000
+Should include.
+
+140
+00:08:33,000 --> 00:08:39,000
+It should include a contract and contact information of the authority who will be available during the
+
+141
+00:08:39,000 --> 00:08:42,000
+test and signed by person of authority.
+
+142
+00:08:42,000 --> 00:08:46,000
+You want to make sure maybe the CIO signs off on this.
+
+143
+00:08:47,000 --> 00:08:47,000
+Now.
+
+144
+00:08:49,000 --> 00:08:50,000
+What exactly is the process?
+
+145
+00:08:50,000 --> 00:08:57,000
+Well, here I have a pen test process or a methodology that pen testers follow.
+
+146
+00:08:57,000 --> 00:09:04,000
+The first thing now this is technically what hackers will do, except they don't do number six.
+
+147
+00:09:04,000 --> 00:09:07,000
+So if you're looking if you're thinking, okay, well how does hackers work?
+
+148
+00:09:07,000 --> 00:09:10,000
+Well, they do basically everything except number six.
+
+149
+00:09:10,000 --> 00:09:10,000
+Let's get started.
+
+150
+00:09:10,000 --> 00:09:13,000
+The first thing that they're going to do is they're going to do reconnaissance notice.
+
+151
+00:09:13,000 --> 00:09:18,000
+They're reconnaissance means to find information about the organization.
+
+152
+00:09:18,000 --> 00:09:19,000
+This is called footprinting.
+
+153
+00:09:19,000 --> 00:09:26,000
+When we do reconnaissance, what we're doing is we're looking to see are people who work in the organization,
+
+154
+00:09:26,000 --> 00:09:30,000
+domain names, physical locations, product sales.
+
+155
+00:09:31,000 --> 00:09:33,000
+What technology are you guys using?
+
+156
+00:09:33,000 --> 00:09:34,000
+Do you guys use windows?
+
+157
+00:09:34,000 --> 00:09:36,000
+Do you use stored data in AWS?
+
+158
+00:09:37,000 --> 00:09:39,000
+What do you use for your CRM?
+
+159
+00:09:39,000 --> 00:09:41,000
+What can you guys use for your email client?
+
+160
+00:09:41,000 --> 00:09:42,000
+All the things we can find.
+
+161
+00:09:42,000 --> 00:09:44,000
+So we're going to scan you.
+
+162
+00:09:44,000 --> 00:09:47,000
+We're going to look up all kinds of information on the internet about you.
+
+163
+00:09:50,000 --> 00:09:51,000
+We're going to enumerate you.
+
+164
+00:09:51,000 --> 00:09:57,000
+Enumeration is connected directly to the host to find out more information about the host.
+
+165
+00:09:57,000 --> 00:10:03,000
+Once we find out that you're using things like Windows Server, we're using you're using like a sonic
+
+166
+00:10:03,000 --> 00:10:04,000
+wall of some kind.
+
+167
+00:10:04,000 --> 00:10:08,000
+Then we're going to do some research on those vulnerabilities.
+
+168
+00:10:08,000 --> 00:10:11,000
+Is there a vulnerability on this sonic wall.
+
+169
+00:10:11,000 --> 00:10:15,000
+Now you're going to use things like CVE.
+
+170
+00:10:16,000 --> 00:10:18,000
+In order to find these vulnerabilities.
+
+171
+00:10:18,000 --> 00:10:20,000
+This is a great place to find it.
+
+172
+00:10:20,000 --> 00:10:24,000
+Common Vulnerability and exposure database, which is a topic we'll cover a little bit later.
+
+173
+00:10:25,000 --> 00:10:31,000
+Once you have found the vulnerabilities for the devices or software, then the next thing to do is to
+
+174
+00:10:31,000 --> 00:10:34,000
+execute those vulnerabilities and to attempt to gain access.
+
+175
+00:10:34,000 --> 00:10:37,000
+When you're done, you will clear the log files.
+
+176
+00:10:37,000 --> 00:10:37,000
+All right.
+
+177
+00:10:37,000 --> 00:10:43,000
+So clearing the log files, hiding your tracks as if you were never there.
+
+178
+00:10:43,000 --> 00:10:45,000
+And then of course, document your finding.
+
+179
+00:10:46,000 --> 00:10:51,000
+Keep in mind, hackers just steal your data or destroy it.
+
+180
+00:10:51,000 --> 00:10:54,000
+They're not going to be documenting findings after that.
+
+181
+00:10:54,000 --> 00:10:58,000
+Now, I do want to point out that this is a generic methodology.
+
+182
+00:10:58,000 --> 00:11:00,000
+Uh, NIST has something very similar.
+
+183
+00:11:00,000 --> 00:11:04,000
+Here's the NIST for stage pen test and methodology.
+
+184
+00:11:04,000 --> 00:11:07,000
+First, you plan it, you discover hosts that they have.
+
+185
+00:11:07,000 --> 00:11:11,000
+You attack it, you discover additional holes, you attack it.
+
+186
+00:11:11,000 --> 00:11:14,000
+And then of course, everything is reported because it is a pen test.
+
+187
+00:11:14,000 --> 00:11:17,000
+It is something that is done with permission.
+
+188
+00:11:18,000 --> 00:11:24,000
+Now, at the end of a pen test, they're going to have things that we should include in their report.
+
+189
+00:11:24,000 --> 00:11:29,000
+The finding number one is going to say, what did they find is this vulnerability.
+
+190
+00:11:29,000 --> 00:11:34,000
+Is it a low thing that you don't have to fix right away, or is it high something that should be fixed
+
+191
+00:11:34,000 --> 00:11:34,000
+right away?
+
+192
+00:11:34,000 --> 00:11:39,000
+The summary of what they did, what they found, what techniques was used.
+
+193
+00:11:39,000 --> 00:11:42,000
+They're going to give you what you should do now, what you should do next.
+
+194
+00:11:42,000 --> 00:11:46,000
+A plan of action like this is what you guys should be doing over the next five months.
+
+195
+00:11:46,000 --> 00:11:47,000
+What did they find?
+
+196
+00:11:47,000 --> 00:11:53,000
+What holes is, what rogue services they give you a technical report regression or progression report.
+
+197
+00:11:53,000 --> 00:11:59,000
+Sensible basically, since if they did the test previously, what have they found that changed or if
+
+198
+00:11:59,000 --> 00:12:00,000
+anything changed at all?
+
+199
+00:12:01,000 --> 00:12:04,000
+Did you guys lack policies or training?
+
+200
+00:12:04,000 --> 00:12:05,000
+Now?
+
+201
+00:12:06,000 --> 00:12:09,000
+One thing about a pen test are the tools that we use.
+
+202
+00:12:09,000 --> 00:12:15,000
+Some of these tools, like nmap, has no report versus some of them like the Nexus scanner has tons
+
+203
+00:12:15,000 --> 00:12:17,000
+of great automated report.
+
+204
+00:12:17,000 --> 00:12:20,000
+So some tools are going to give you manual.
+
+205
+00:12:20,000 --> 00:12:24,000
+You got to make it yourself versus some gives you an automated report.
+
+206
+00:12:24,000 --> 00:12:25,000
+All right.
+
+207
+00:12:25,000 --> 00:12:29,000
+Any report that's given to you by a pen testers will be validated.
+
+208
+00:12:29,000 --> 00:12:31,000
+They should read the report to make sure they're accurate.
+
+209
+00:12:31,000 --> 00:12:34,000
+It's good practice to use two lead and tools.
+
+210
+00:12:34,000 --> 00:12:35,000
+Just don't use one.
+
+211
+00:12:35,000 --> 00:12:42,000
+Automated tools are limited in scope because they are programmed versus a manual is not more manual
+
+212
+00:12:42,000 --> 00:12:45,000
+or manual tools generally give you more control of what you're looking for.
+
+213
+00:12:46,000 --> 00:12:52,000
+Um, if the tools are outdated that the Pentester is using, well, you're not going to get the latest
+
+214
+00:12:52,000 --> 00:12:53,000
+vulnerability.
+
+215
+00:12:53,000 --> 00:12:55,000
+So the tools has to be updated.
+
+216
+00:12:55,000 --> 00:12:59,000
+The tools are needed to date to create summaries of what we have.
+
+217
+00:12:59,000 --> 00:13:01,000
+There's so many vulnerabilities.
+
+218
+00:13:01,000 --> 00:13:01,000
+All right.
+
+219
+00:13:01,000 --> 00:13:03,000
+There's a lot of info to look at.
+
+220
+00:13:03,000 --> 00:13:08,000
+And a manual process alone is generally not enough because there's too many vulnerabilities.
+
+221
+00:13:08,000 --> 00:13:12,000
+There's too many systems, especially on large networks.
+
+222
+00:13:13,000 --> 00:13:17,000
+When the pen test is over and you have your report, now you have to fix things.
+
+223
+00:13:17,000 --> 00:13:18,000
+What are we fixing?
+
+224
+00:13:18,000 --> 00:13:22,000
+Well, you're probably going to go and disable or remove unnecessary services.
+
+225
+00:13:23,000 --> 00:13:26,000
+Um, modify vulnerable hosts.
+
+226
+00:13:26,000 --> 00:13:30,000
+Maybe there are hosts out there that didn't have good passwords.
+
+227
+00:13:30,000 --> 00:13:33,000
+All right, uh, modify enterprise firewall, restrict outside access.
+
+228
+00:13:33,000 --> 00:13:40,000
+Maybe you guys had open ports, upgrade or patch systems, deploy all types of mitigation countermeasures.
+
+229
+00:13:40,000 --> 00:13:44,000
+Maybe they found hoses that was connected to the networks.
+
+230
+00:13:44,000 --> 00:13:45,000
+Maybe they didn't have patching.
+
+231
+00:13:45,000 --> 00:13:46,000
+Maybe they didn't have firewalls on them.
+
+232
+00:13:47,000 --> 00:13:48,000
+Configuration management.
+
+233
+00:13:48,000 --> 00:13:51,000
+Maybe people were making configs to systems without people knowing.
+
+234
+00:13:51,000 --> 00:13:53,000
+Monitor vulnerability alert lists.
+
+235
+00:13:53,000 --> 00:13:56,000
+Examine the application environment.
+
+236
+00:13:56,000 --> 00:13:59,000
+Is there bugs in your application?
+
+237
+00:14:00,000 --> 00:14:03,000
+Initiated proves appropriate system changes.
+
+238
+00:14:03,000 --> 00:14:06,000
+Anytime a pen test is done, the first thing you do, you get the reports.
+
+239
+00:14:06,000 --> 00:14:11,000
+You got to change your system and of course modify the security policies if they found any problems
+
+240
+00:14:11,000 --> 00:14:12,000
+with them.
+
+241
+00:14:13,000 --> 00:14:17,000
+Of all the pen testers I've done, I've never found a I've never done a pen test where it was all clean
+
+242
+00:14:17,000 --> 00:14:18,000
+and the report came back.
+
+243
+00:14:18,000 --> 00:14:20,000
+You guys are absolutely amazing.
+
+244
+00:14:20,000 --> 00:14:21,000
+Keep doing what you're doing.
+
+245
+00:14:21,000 --> 00:14:26,000
+That has never in my life I've never seen that or wrote that.
+
+246
+00:14:26,000 --> 00:14:28,000
+So you you will have.
+
+247
+00:14:28,000 --> 00:14:30,000
+They will find something.
+
+248
+00:14:30,000 --> 00:14:31,000
+All right.
+
+249
+00:14:31,000 --> 00:14:33,000
+When we do pen tests, we find things.
+
+250
+00:14:33,000 --> 00:14:35,000
+Things that you don't even think about.
+
+251
+00:14:36,000 --> 00:14:38,000
+Now, granted, some of them may not have a.
+
+252
+00:14:39,000 --> 00:14:41,000
+I think that needs to be fixed right away.
+
+253
+00:14:41,000 --> 00:14:49,000
+But you have to remember that the small things can sometimes turns out to be big things, so it doesn't
+
+254
+00:14:49,000 --> 00:14:49,000
+matter what it is.
+
+255
+00:14:49,000 --> 00:14:56,000
+Make sure any time you get a pen test report, you fix those things on there because you never know
+
+256
+00:14:56,000 --> 00:14:58,000
+where the next attack will come from.
+
diff --git a/15 - Vulnerability Management/005 Bug Bounty Program OB 4.3_en.srt b/15 - Vulnerability Management/005 Bug Bounty Program OB 4.3_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..5927dc7df3a1ed3888ee49749caf65b972305088
--- /dev/null
+++ b/15 - Vulnerability Management/005 Bug Bounty Program OB 4.3_en.srt
@@ -0,0 +1,212 @@
+1
+00:00:00,000 --> 00:00:06,000
+When an organization builds a product such as Samsung building this phone or Sonicwall making their
+
+2
+00:00:06,000 --> 00:00:12,000
+firewall here, you would think that big companies like Samsung or Dell who own Sonicwall will have
+
+3
+00:00:12,000 --> 00:00:19,000
+enough resources, basically people and teams to test these devices for vulnerabilities.
+
+4
+00:00:19,000 --> 00:00:25,000
+Well, it doesn't matter how much people they have, they'll never have unlimited people.
+
+5
+00:00:25,000 --> 00:00:27,000
+And generally a lot of the same.
+
+6
+00:00:27,000 --> 00:00:32,000
+A lot of the people that's working on the team has generally the same methodology or the same thinking.
+
+7
+00:00:32,000 --> 00:00:39,000
+They don't think outside the box, something that's so off the rail that the team can't find.
+
+8
+00:00:39,000 --> 00:00:41,000
+The point of this discussion is that.
+
+9
+00:00:42,000 --> 00:00:46,000
+We can't think of every possible way to, you know, Samsung can think of every possible way somebody
+
+10
+00:00:46,000 --> 00:00:48,000
+will attempt to hack this device.
+
+11
+00:00:48,000 --> 00:00:49,000
+So you know what Samsung can do?
+
+12
+00:00:49,000 --> 00:00:52,000
+They can pay people to hack this device.
+
+13
+00:00:52,000 --> 00:00:54,000
+Just random people.
+
+14
+00:00:56,000 --> 00:00:57,000
+Bug bounty.
+
+15
+00:00:57,000 --> 00:00:59,000
+What exactly is it?
+
+16
+00:00:59,000 --> 00:01:06,000
+Well, this falls into the topic of responsible disclosure program bug bounty encourages ethical hackers
+
+17
+00:01:06,000 --> 00:01:12,000
+to report vulnerabilities in exchange for rewards, helps in identifying and addressing vulnerabilities
+
+18
+00:01:12,000 --> 00:01:15,000
+before they're exploited in the wild.
+
+19
+00:01:15,000 --> 00:01:16,000
+Now.
+
+20
+00:01:17,000 --> 00:01:22,000
+They are different bug bounty programs that are out there.
+
+21
+00:01:23,000 --> 00:01:28,000
+So let's take a look at one of the bug bounty programs that are out there.
+
+22
+00:01:28,000 --> 00:01:34,000
+So what these are are basically organizations paying you that if you find vulnerabilities in their system,
+
+23
+00:01:34,000 --> 00:01:36,000
+report it to them and they're going to pay you.
+
+24
+00:01:36,000 --> 00:01:38,000
+So I want to show you guys one of them.
+
+25
+00:01:38,000 --> 00:01:40,000
+The most famous website for this is hacker one.
+
+26
+00:01:41,000 --> 00:01:44,000
+So it's basically hacker 1.com.
+
+27
+00:01:44,000 --> 00:01:48,000
+And before I did this video I went to this and I found Amazon.
+
+28
+00:01:48,000 --> 00:01:49,000
+What's Amazon paying.
+
+29
+00:01:49,000 --> 00:01:52,000
+So here is hacker 1.com.
+
+30
+00:01:52,000 --> 00:01:53,000
+And this is as of today.
+
+31
+00:01:53,000 --> 00:01:57,000
+Today is this no December 7th 2023.
+
+32
+00:01:57,000 --> 00:02:00,000
+This program is launched on April 20th.
+
+33
+00:02:00,000 --> 00:02:05,000
+Um and here in this one Amazon vulnerability research program.
+
+34
+00:02:05,000 --> 00:02:06,000
+All right.
+
+35
+00:02:06,000 --> 00:02:09,000
+Our rewards are based on the severity of the vulnerability.
+
+36
+00:02:09,000 --> 00:02:11,000
+Hackers here.
+
+37
+00:02:11,000 --> 00:02:17,000
+If they find things and they report it to Amazon, they are rewarded for something that's low.
+
+38
+00:02:17,000 --> 00:02:19,000
+You get 150 bucks for something that's critical.
+
+39
+00:02:19,000 --> 00:02:22,000
+You get all the way up to $20,000.
+
+40
+00:02:22,000 --> 00:02:28,000
+So if you are an amazing hacker and there are tons and tons of different vulnerabilities that are out
+
+41
+00:02:28,000 --> 00:02:33,000
+there that you guys can take a look at, it's called hacker 1.com.
+
+42
+00:02:34,000 --> 00:02:41,000
+So bug bounty is an interesting thing because in this one you're actually paid.
+
+43
+00:02:41,000 --> 00:02:45,000
+Uh, rewarded, I should say, to find vulnerabilities.
+
+44
+00:02:46,000 --> 00:02:53,000
+So I had a couple of students in my career that has when I started training them, they weren't the
+
+45
+00:02:53,000 --> 00:02:57,000
+best in technology, but over years they became very good.
+
+46
+00:02:57,000 --> 00:03:03,000
+And very recently I met one of them that does this on a part time for side money because he is very
+
+47
+00:03:03,000 --> 00:03:03,000
+good.
+
+48
+00:03:03,000 --> 00:03:09,000
+The benefits here is you're going to gather diverse insights from the global security community, often
+
+49
+00:03:09,000 --> 00:03:12,000
+uncovering issues that internal testing fails.
+
+50
+00:03:12,000 --> 00:03:18,000
+So the organization, like Amazon, gathers security from from folks all around the world, all different
+
+51
+00:03:18,000 --> 00:03:24,000
+types of communities that their internal systems will miss or their internal testing would make.
+
+52
+00:03:24,000 --> 00:03:32,000
+If you ever get and you become amazing ethical hacker or pentester, try out bug, do some bug bounty
+
+53
+00:03:32,000 --> 00:03:35,000
+programs to make some side money.
+
diff --git a/15 - Vulnerability Management/006 False Positive vs. False Negative OB 4.3_en.srt b/15 - Vulnerability Management/006 False Positive vs. False Negative OB 4.3_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..1bed0f95b2f49e5dfbe7b4771bbaf976ced101ef
--- /dev/null
+++ b/15 - Vulnerability Management/006 False Positive vs. False Negative OB 4.3_en.srt
@@ -0,0 +1,140 @@
+1
+00:00:00,000 --> 00:00:06,000
+When you use vulnerability scanning software like the Nexus security scanner, or you have log files
+
+2
+00:00:06,000 --> 00:00:11,000
+that are reporting potential vulnerabilities, you have to make sure you investigate really well.
+
+3
+00:00:11,000 --> 00:00:16,000
+There are times when it's telling you it's a vulnerability, but it actually isn't.
+
+4
+00:00:16,000 --> 00:00:20,000
+It's normal and it's time that's telling you it's normal and it actually is a vulnerability.
+
+5
+00:00:20,000 --> 00:00:24,000
+Two terms make sure you're familiar with for your exam.
+
+6
+00:00:24,000 --> 00:00:28,000
+Because if you don't really understand them, it can really confuse you.
+
+7
+00:00:28,000 --> 00:00:30,000
+The first one is called a false positive.
+
+8
+00:00:30,000 --> 00:00:37,000
+This occurs when a system incorrectly identifies a normal or benign activity as a threat.
+
+9
+00:00:37,000 --> 00:00:40,000
+Requires verification immediately.
+
+10
+00:00:40,000 --> 00:00:44,000
+You should to avoid wasting resources on non-existent issues.
+
+11
+00:00:44,000 --> 00:00:45,000
+So imagine.
+
+12
+00:00:46,000 --> 00:00:50,000
+Uh, as security scanning software sends you.
+
+13
+00:00:50,000 --> 00:00:55,000
+Alert that server one that's sitting on his desk has a major vulnerability.
+
+14
+00:00:55,000 --> 00:00:57,000
+I mean, you go into the machine, you realize it was nothing.
+
+15
+00:00:57,000 --> 00:01:01,000
+That thing was not actually what it's saying was vulnerability was not.
+
+16
+00:01:01,000 --> 00:01:03,000
+That would be a false positive.
+
+17
+00:01:03,000 --> 00:01:07,000
+The worst thing that can happen, though, is a false negative.
+
+18
+00:01:07,000 --> 00:01:11,000
+This happens when a system fails to detect an actual vulnerability or threat.
+
+19
+00:01:11,000 --> 00:01:15,000
+So what it's saying is that this activity is normal.
+
+20
+00:01:15,000 --> 00:01:18,000
+So it's a false negative.
+
+21
+00:01:18,000 --> 00:01:24,000
+Now more dangerous as it's most dangerous as it leaves the system unknowingly open.
+
+22
+00:01:24,000 --> 00:01:24,000
+Right.
+
+23
+00:01:24,000 --> 00:01:30,000
+Because you're going to think that, hey, my systems are working great when they're actually not,
+
+24
+00:01:30,000 --> 00:01:34,000
+so it's unknowingly exposed it to potential exploits coming up in the future.
+
+25
+00:01:34,000 --> 00:01:41,000
+So while false positives is more of a waste of resources, um, and just drives up your blood pressure
+
+26
+00:01:41,000 --> 00:01:47,000
+for no reason, false negatives makes your blood pressure go down and makes you feel great when actuality,
+
+27
+00:01:47,000 --> 00:01:48,000
+that's how you're going to get hacked.
+
+28
+00:01:48,000 --> 00:01:51,000
+So you have to be careful with these kinds of things.
+
+29
+00:01:51,000 --> 00:01:52,000
+That does happen.
+
+30
+00:01:52,000 --> 00:01:55,000
+In my experience, they're not going to happen very often.
+
+31
+00:01:55,000 --> 00:02:03,000
+But anytime something seems abnormal to you, even though systems are security, scanners are saying
+
+32
+00:02:03,000 --> 00:02:04,000
+it's okay.
+
+33
+00:02:04,000 --> 00:02:06,000
+It's probably best to investigate just in case.
+
+34
+00:02:06,000 --> 00:02:13,000
+And of course, if you do get vulnerable software reported vulnerabilities, go ahead and investigate
+
+35
+00:02:13,000 --> 00:02:15,000
+them just in case it's a false positive.
+
diff --git a/15 - Vulnerability Management/007 CVE and CVSS OB 4.3_en.srt b/15 - Vulnerability Management/007 CVE and CVSS OB 4.3_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..c5947f54cfaf3c65cacc06aafcba0639cc7531a9
--- /dev/null
+++ b/15 - Vulnerability Management/007 CVE and CVSS OB 4.3_en.srt
@@ -0,0 +1,1136 @@
+1
+00:00:00,000 --> 00:00:05,000
+What if I told you guys there is a giant database of all the different vulnerabilities out there that
+
+2
+00:00:05,000 --> 00:00:11,000
+can affect all the different devices, software or hardware that you have in your organization and you
+
+3
+00:00:11,000 --> 00:00:12,000
+can actually search it.
+
+4
+00:00:12,000 --> 00:00:16,000
+So let's say you go work for a company and you realize that they have a sonicwall.
+
+5
+00:00:16,000 --> 00:00:21,000
+You can actually search for Sonicwall and it will tell you all the vulnerabilities against this device.
+
+6
+00:00:21,000 --> 00:00:24,000
+This would be amazing for a network administrator.
+
+7
+00:00:24,000 --> 00:00:30,000
+And then I'll show you guys in this video how severe are those vulnerabilities and how to read what
+
+8
+00:00:30,000 --> 00:00:32,000
+is called the Cvss score.
+
+9
+00:00:33,000 --> 00:00:35,000
+This brings me to this video.
+
+10
+00:00:35,000 --> 00:00:41,000
+What I'm talking about here is something we call CVE Common Vulnerabilities and Exposures Database.
+
+11
+00:00:41,000 --> 00:00:45,000
+Once again, links to the two website I'm using will be in the slides.
+
+12
+00:00:45,000 --> 00:00:47,000
+This is CVE.
+
+13
+00:00:47,000 --> 00:00:55,000
+Now what CVE is is that it's a program to identify, define and catalog publicly disclosed cybersecurity
+
+14
+00:00:55,000 --> 00:00:56,000
+vulnerabilities.
+
+15
+00:00:56,000 --> 00:00:58,000
+And this goes against every product.
+
+16
+00:00:58,000 --> 00:01:02,000
+To use this you basically are going to search for your product.
+
+17
+00:01:02,000 --> 00:01:03,000
+So let's say.
+
+18
+00:01:04,000 --> 00:01:08,000
+Let's say you're looking for something like Sonic Wall.
+
+19
+00:01:08,000 --> 00:01:12,000
+So I click on search and it takes me to their newer website here.
+
+20
+00:01:12,000 --> 00:01:15,000
+And you notice CV list download.
+
+21
+00:01:15,000 --> 00:01:20,000
+Uh now because it's in transition it's not as easy to use anymore.
+
+22
+00:01:20,000 --> 00:01:24,000
+Uh, but what I'm going to do here is I'm going to go we don't want to download it.
+
+23
+00:01:25,000 --> 00:01:25,000
+All right.
+
+24
+00:01:25,000 --> 00:01:29,000
+We don't want to download all the CVS that are out there.
+
+25
+00:01:29,000 --> 00:01:35,000
+I'm going to go to CVS list keyword search and I'm just going to type in here Sonicwall.
+
+26
+00:01:35,000 --> 00:01:36,000
+And I'm going to oops, not RSA.
+
+27
+00:01:36,000 --> 00:01:39,000
+I was looking for that earlier Sonicwall.
+
+28
+00:01:39,000 --> 00:01:46,000
+And here are all the vulnerabilities that has been reported against Sonicwall devices.
+
+29
+00:01:47,000 --> 00:01:49,000
+And I want you guys to look at this.
+
+30
+00:01:49,000 --> 00:01:52,000
+Here's how you read it CVE is common vulnerability and exposure.
+
+31
+00:01:52,000 --> 00:01:54,000
+The year is 2023.
+
+32
+00:01:54,000 --> 00:01:57,000
+And this is this number that you see here.
+
+33
+00:01:57,000 --> 00:01:57,000
+Make this bigger.
+
+34
+00:01:57,000 --> 00:02:03,000
+This number that we see here is just the number associated with that particular CVE.
+
+35
+00:02:04,000 --> 00:02:07,000
+So you can see like this one is 34 137.
+
+36
+00:02:07,000 --> 00:02:13,000
+This one here is going to be 441244A21944220.
+
+37
+00:02:13,000 --> 00:02:20,000
+Now when you click on these here it's going to explain more of that particular vulnerability to you.
+
+38
+00:02:20,000 --> 00:02:23,000
+So let's go ahead and find one of these vulnerabilities.
+
+39
+00:02:23,000 --> 00:02:25,000
+I'm just going to click on the latest one.
+
+40
+00:02:26,000 --> 00:02:28,000
+And it gives you a description.
+
+41
+00:02:28,000 --> 00:02:32,000
+On the vulnerability that's going to affect the Sonicwall.
+
+42
+00:02:32,000 --> 00:02:34,000
+Net extender for windows.
+
+43
+00:02:34,000 --> 00:02:41,000
+And what it does is that it's going to then give you generally puts you back to the manufacturer's website
+
+44
+00:02:41,000 --> 00:02:43,000
+to tell you how to fix it.
+
+45
+00:02:43,000 --> 00:02:48,000
+The good thing about CVE is that generally when it's posted here, it's been fixed by the manufacturer.
+
+46
+00:02:48,000 --> 00:02:53,000
+So if you find a vulnerability here, you should go to the manufacturer's website and they'll tell you
+
+47
+00:02:53,000 --> 00:02:54,000
+how to fix it.
+
+48
+00:02:54,000 --> 00:02:57,000
+So it's given me two links of how to get there.
+
+49
+00:02:57,000 --> 00:02:58,000
+Let's click on this one.
+
+50
+00:02:59,000 --> 00:03:01,000
+So I want you guys to look at this.
+
+51
+00:03:01,000 --> 00:03:01,000
+It's.
+
+52
+00:03:01,000 --> 00:03:06,000
+This is a security advisory from Sonicwall themselves.
+
+53
+00:03:06,000 --> 00:03:10,000
+You notice that it's given a score of 7.3.
+
+54
+00:03:10,000 --> 00:03:12,000
+What the hell does that mean?
+
+55
+00:03:12,000 --> 00:03:15,000
+7.3 and then you have this thing here.
+
+56
+00:03:15,000 --> 00:03:16,000
+Watch this.
+
+57
+00:03:18,000 --> 00:03:25,000
+It says Cvss score 7.3 and then it gives you this weird looking thing like, what is that?
+
+58
+00:03:25,000 --> 00:03:27,000
+Well, I want you guys to understand this.
+
+59
+00:03:28,000 --> 00:03:29,000
+CV.
+
+60
+00:03:29,000 --> 00:03:33,000
+CVS is a common vulnerability scoring system.
+
+61
+00:03:33,000 --> 00:03:39,000
+CVS um is basically a system and I want to show this to you again.
+
+62
+00:03:39,000 --> 00:03:41,000
+Link in the link is going to be in the slide.
+
+63
+00:03:41,000 --> 00:03:52,000
+CVS is basically a scoring system that scores how deadly, how bad a vulnerability is to a particular
+
+64
+00:03:52,000 --> 00:03:52,000
+system.
+
+65
+00:03:52,000 --> 00:03:55,000
+Seven is bad, but it's not terrible bad.
+
+66
+00:03:55,000 --> 00:03:59,000
+Or is that 17.3 is bad, but it's not terribly bad.
+
+67
+00:04:00,000 --> 00:04:03,000
+The scoring system goes from 0 to 1.
+
+68
+00:04:03,000 --> 00:04:07,000
+So if I'm 0 to 10, if it's ten, it's really bad.
+
+69
+00:04:07,000 --> 00:04:11,000
+If it's one, not really.
+
+70
+00:04:11,000 --> 00:04:13,000
+If it's like a five, it's a moderate.
+
+71
+00:04:13,000 --> 00:04:15,000
+Let me show you guys how to use the Cvss.
+
+72
+00:04:15,000 --> 00:04:18,000
+So if I go to Cvss, remember Cvss is a score.
+
+73
+00:04:18,000 --> 00:04:26,000
+So when you look at a vulnerability and it says Cvss 567, if you see a cvss, that's a eight, 9 or
+
+74
+00:04:26,000 --> 00:04:27,000
+10.
+
+75
+00:04:27,000 --> 00:04:30,000
+Wake up and go and fix it like it needs to be fixed yesterday.
+
+76
+00:04:30,000 --> 00:04:34,000
+If it's a ten, don't sleep until it's fixed.
+
+77
+00:04:34,000 --> 00:04:38,000
+So let's take a look and I'm going to show you guys how to calculate it.
+
+78
+00:04:39,000 --> 00:04:40,000
+Now.
+
+79
+00:04:40,000 --> 00:04:43,000
+Cvss let me see the scoring system that they were using.
+
+80
+00:04:43,000 --> 00:04:45,000
+So this was Cvss 3.0.
+
+81
+00:04:45,000 --> 00:04:49,000
+They're telling us there's different version of the calculator that's here.
+
+82
+00:04:49,000 --> 00:04:51,000
+You notice they have a 3.1.
+
+83
+00:04:51,000 --> 00:04:52,000
+There's a 3.0.
+
+84
+00:04:52,000 --> 00:04:55,000
+So I'm going to use the 3.0 calculator just to match up with them.
+
+85
+00:04:55,000 --> 00:04:56,000
+There is a 4.0.
+
+86
+00:04:56,000 --> 00:04:58,000
+Also you guys can play around with these here.
+
+87
+00:04:59,000 --> 00:05:02,000
+Uh so I'm going to go to 3.0 to calculate I want to show you how it's done.
+
+88
+00:05:02,000 --> 00:05:06,000
+So let's say there was an attack against a network.
+
+89
+00:05:06,000 --> 00:05:09,000
+Let's say it was a network attack.
+
+90
+00:05:10,000 --> 00:05:12,000
+It wasn't complex at all.
+
+91
+00:05:12,000 --> 00:05:12,000
+So it was.
+
+92
+00:05:12,000 --> 00:05:14,000
+Complexity is low.
+
+93
+00:05:14,000 --> 00:05:17,000
+Did it require privileges like username and passwords?
+
+94
+00:05:17,000 --> 00:05:18,000
+No.
+
+95
+00:05:18,000 --> 00:05:21,000
+Did it require your users to maybe click on a link?
+
+96
+00:05:21,000 --> 00:05:22,000
+No.
+
+97
+00:05:23,000 --> 00:05:26,000
+Did it change anything in the network?
+
+98
+00:05:26,000 --> 00:05:28,000
+Let's say it could change anything.
+
+99
+00:05:28,000 --> 00:05:29,000
+It changed anything.
+
+100
+00:05:29,000 --> 00:05:33,000
+It can steal your data confidentiality.
+
+101
+00:05:33,000 --> 00:05:38,000
+The vulnerability really affects confidentiality, integrity and availability.
+
+102
+00:05:38,000 --> 00:05:41,000
+Well, disguise is the perfect attack.
+
+103
+00:05:41,000 --> 00:05:45,000
+This is an attack where it's super easy to do.
+
+104
+00:05:46,000 --> 00:05:51,000
+It doesn't require any interaction on your part and they can steal your data, manipulate your data,
+
+105
+00:05:51,000 --> 00:05:53,000
+bring your system down.
+
+106
+00:05:53,000 --> 00:06:00,000
+If you ever see an attack that's listed as a ten, because I can't remember ever seeing an attack listed
+
+107
+00:06:00,000 --> 00:06:00,000
+as a ten.
+
+108
+00:06:00,000 --> 00:06:03,000
+This is the perfect and the highest on the calculator.
+
+109
+00:06:03,000 --> 00:06:08,000
+But let's say this attack doesn't do confidentiality.
+
+110
+00:06:08,000 --> 00:06:09,000
+It doesn't do integrity.
+
+111
+00:06:09,000 --> 00:06:12,000
+Now it's 8.6.
+
+112
+00:06:12,000 --> 00:06:14,000
+Maybe it doesn't do availability.
+
+113
+00:06:14,000 --> 00:06:15,000
+Nothing.
+
+114
+00:06:15,000 --> 00:06:15,000
+It's zero.
+
+115
+00:06:15,000 --> 00:06:16,000
+That means there's no attack here.
+
+116
+00:06:17,000 --> 00:06:20,000
+But what if it only did confidentiality okay eight.
+
+117
+00:06:20,000 --> 00:06:24,000
+What if it required user interaction okay.
+
+118
+00:06:24,000 --> 00:06:27,000
+That means if you train your users, maybe it's not going to happen.
+
+119
+00:06:27,000 --> 00:06:29,000
+What if it needs privileges, right.
+
+120
+00:06:29,000 --> 00:06:31,000
+Maybe it needs high privileges.
+
+121
+00:06:32,000 --> 00:06:32,000
+All right.
+
+122
+00:06:32,000 --> 00:06:35,000
+What if it was super complex?
+
+123
+00:06:35,000 --> 00:06:39,000
+What if they had to be locally present or physically present?
+
+124
+00:06:40,000 --> 00:06:40,000
+Right.
+
+125
+00:06:40,000 --> 00:06:43,000
+This all of these things here affects how it's done.
+
+126
+00:06:44,000 --> 00:06:48,000
+What if they just stole could steal a little bit of information?
+
+127
+00:06:48,000 --> 00:06:51,000
+Now you see how this thing is changing.
+
+128
+00:06:51,000 --> 00:06:52,000
+Now I want you guys.
+
+129
+00:06:52,000 --> 00:06:57,000
+I know this is hard to see in the video, but I want you guys to look at the top here.
+
+130
+00:06:58,000 --> 00:06:59,000
+You see this?
+
+131
+00:06:59,000 --> 00:06:59,000
+Watch this.
+
+132
+00:06:59,000 --> 00:07:02,000
+If I click and change these things you'll see this change.
+
+133
+00:07:02,000 --> 00:07:08,000
+Like right now if you see this as a it says n because this a is n the letter.
+
+134
+00:07:08,000 --> 00:07:19,000
+You see how this is AV is P or AV is n a c is h, PR is h, UI is r, c is h.
+
+135
+00:07:19,000 --> 00:07:20,000
+What am I showing you here.
+
+136
+00:07:20,000 --> 00:07:22,000
+Well I'm going to copy I'm going to you know what.
+
+137
+00:07:22,000 --> 00:07:23,000
+We can just use this.
+
+138
+00:07:23,000 --> 00:07:24,000
+You see right here.
+
+139
+00:07:24,000 --> 00:07:26,000
+This is what it's telling you.
+
+140
+00:07:26,000 --> 00:07:27,000
+The attack vector.
+
+141
+00:07:27,000 --> 00:07:29,000
+It has to be local.
+
+142
+00:07:30,000 --> 00:07:33,000
+This one attack complexity is low.
+
+143
+00:07:33,000 --> 00:07:35,000
+You see this attack vector?
+
+144
+00:07:35,000 --> 00:07:39,000
+You can tell this is AV is L, so AV and this one is L.
+
+145
+00:07:40,000 --> 00:07:42,000
+You see this one here AC is L.
+
+146
+00:07:42,000 --> 00:07:46,000
+So in the vulnerability AC is low.
+
+147
+00:07:48,000 --> 00:07:51,000
+See, if we do this, we should get the score that they have.
+
+148
+00:07:51,000 --> 00:07:52,000
+So let's go through it.
+
+149
+00:07:52,000 --> 00:07:53,000
+PR.
+
+150
+00:07:55,000 --> 00:08:01,000
+Is which one that they had PR they have is L, so it's low then it requires low privilege.
+
+151
+00:08:01,000 --> 00:08:05,000
+User interaction is are required.
+
+152
+00:08:05,000 --> 00:08:06,000
+What about the scope?
+
+153
+00:08:06,000 --> 00:08:08,000
+The scope is unchanged.
+
+154
+00:08:08,000 --> 00:08:09,000
+It's not going to really modify anything.
+
+155
+00:08:11,000 --> 00:08:13,000
+Confidentiality is high, integrity high.
+
+156
+00:08:13,000 --> 00:08:14,000
+Everything out here is high.
+
+157
+00:08:14,000 --> 00:08:19,000
+So integrity confidentiality is H or high integrity which is the eye is high.
+
+158
+00:08:20,000 --> 00:08:23,000
+So high, high and high.
+
+159
+00:08:23,000 --> 00:08:24,000
+7.3.
+
+160
+00:08:24,000 --> 00:08:27,000
+Same as this 7.3.
+
+161
+00:08:28,000 --> 00:08:29,000
+Okay.
+
+162
+00:08:29,000 --> 00:08:29,000
+Very good.
+
+163
+00:08:29,000 --> 00:08:37,000
+So now that you guys understand CVE and CVEs, CVE and Cvss are some of the greatest friends you have
+
+164
+00:08:37,000 --> 00:08:41,000
+as a security administrator and a hacker.
+
+165
+00:08:41,000 --> 00:08:44,000
+Yes, hackers and pentesters.
+
+166
+00:08:44,000 --> 00:08:50,000
+You see, you got to understand this a knife, you could take a knife and you could cook dinner, or
+
+167
+00:08:50,000 --> 00:08:54,000
+you can take that same knife and you can commit murder, right?
+
+168
+00:08:54,000 --> 00:08:56,000
+It's the same knife.
+
+169
+00:08:56,000 --> 00:09:03,000
+So what I want you guys to understand is we use CVE to find vulnerabilities, and then we go to the
+
+170
+00:09:03,000 --> 00:09:04,000
+vendor websites.
+
+171
+00:09:04,000 --> 00:09:08,000
+By the way, the Sonicwall website, we're showing you how to fix that particular vulnerability.
+
+172
+00:09:08,000 --> 00:09:10,000
+We use that in order to uh.
+
+173
+00:09:11,000 --> 00:09:13,000
+Find vulnerabilities and then patch them up.
+
+174
+00:09:13,000 --> 00:09:17,000
+But when hackers are after you, they use the exact same tools.
+
+175
+00:09:17,000 --> 00:09:20,000
+They're going to use CVE to find vulnerabilities.
+
+176
+00:09:20,000 --> 00:09:26,000
+For example, if I'm hacking you, I'm going to scan your systems and I'm going to find out you use
+
+177
+00:09:26,000 --> 00:09:27,000
+Sonicwall.
+
+178
+00:09:27,000 --> 00:09:32,000
+Then I'm going to go to CVE, find all the vulnerabilities against Sonicwall and try them all against
+
+179
+00:09:32,000 --> 00:09:32,000
+you.
+
+180
+00:09:32,000 --> 00:09:34,000
+That's why you better update your system.
+
+181
+00:09:34,000 --> 00:09:35,000
+Let's get into this here.
+
+182
+00:09:36,000 --> 00:09:38,000
+So this is what we're talking about.
+
+183
+00:09:38,000 --> 00:09:39,000
+What is CVE.
+
+184
+00:09:39,000 --> 00:09:45,000
+Well, it's a list or our database of publicly known and cybersecurity vulnerabilities and exposures.
+
+185
+00:09:45,000 --> 00:09:49,000
+Now each vulnerability is given a unique identifier that we have.
+
+186
+00:09:49,000 --> 00:09:50,000
+That's the CV.
+
+187
+00:09:50,000 --> 00:09:52,000
+That's the ID that I showed you.
+
+188
+00:09:52,000 --> 00:09:53,000
+To make them easy.
+
+189
+00:09:53,000 --> 00:09:55,000
+This is the website that we have on it.
+
+190
+00:09:55,000 --> 00:09:58,000
+Now remember what the Cvss score is.
+
+191
+00:09:58,000 --> 00:10:00,000
+I showed you guys how to calculate that.
+
+192
+00:10:00,000 --> 00:10:03,000
+And I gave you the link right here for you to try it on the calculator.
+
+193
+00:10:03,000 --> 00:10:05,000
+It's rated how severity it is.
+
+194
+00:10:06,000 --> 00:10:07,000
+Zero.
+
+195
+00:10:07,000 --> 00:10:08,000
+Nothing.
+
+196
+00:10:08,000 --> 00:10:11,000
+Ten well, ten is really bad.
+
+197
+00:10:11,000 --> 00:10:15,000
+Based on various metrics that you have, the number higher, the worse.
+
+198
+00:10:15,000 --> 00:10:20,000
+Now this is going to help to prioritize those vulnerabilities.
+
+199
+00:10:20,000 --> 00:10:26,000
+For example, a vulnerability that has a ten would require more resources.
+
+200
+00:10:26,000 --> 00:10:30,000
+And you should be focusing your resources on those critical vulnerabilities.
+
+201
+00:10:30,000 --> 00:10:33,000
+So if you ever wonder, well, Andrew, how would I know?
+
+202
+00:10:33,000 --> 00:10:37,000
+You know what resource, you know, where I should be prioritizing my resources.
+
+203
+00:10:37,000 --> 00:10:40,000
+Well, look at the Cvss score.
+
+204
+00:10:40,000 --> 00:10:41,000
+And that will tell you.
+
+205
+00:10:42,000 --> 00:10:45,000
+The next thing here is the classification.
+
+206
+00:10:45,000 --> 00:10:51,000
+Different organizations will classify their vulnerabilities differently.
+
+207
+00:10:51,000 --> 00:10:52,000
+All right.
+
+208
+00:10:52,000 --> 00:10:57,000
+Categorizing vulnerability into types such as SQL Injection Buff to streamline the analysis so you can
+
+209
+00:10:57,000 --> 00:10:58,000
+streamline them.
+
+210
+00:10:58,000 --> 00:10:59,000
+Like these are buff overflows.
+
+211
+00:10:59,000 --> 00:11:01,000
+These are going to be SQL injections.
+
+212
+00:11:01,000 --> 00:11:02,000
+This is programming.
+
+213
+00:11:02,000 --> 00:11:04,000
+This is network vulnerabilities.
+
+214
+00:11:04,000 --> 00:11:05,000
+These are systems.
+
+215
+00:11:05,000 --> 00:11:11,000
+This helps in understanding the nature and standardizing some mitigation strategies.
+
+216
+00:11:11,000 --> 00:11:15,000
+That way teams can work on like that team only does system vulnerabilities.
+
+217
+00:11:15,000 --> 00:11:18,000
+That team only does network vulnerabilities.
+
+218
+00:11:19,000 --> 00:11:22,000
+Terme you should be familiar with is something we call.
+
+219
+00:11:23,000 --> 00:11:26,000
+Uh, exposure factor.
+
+220
+00:11:26,000 --> 00:11:28,000
+What exactly is an exposure factor?
+
+221
+00:11:28,000 --> 00:11:34,000
+Well, this represents potential loss or damage to an asset if it's exploited.
+
+222
+00:11:34,000 --> 00:11:36,000
+Helps in evaluating the potential impact.
+
+223
+00:11:36,000 --> 00:11:38,000
+So you guys got to understand this.
+
+224
+00:11:38,000 --> 00:11:44,000
+Generally speaking, the bigger that cvss score, the bigger exposure factor to whatever systems or
+
+225
+00:11:44,000 --> 00:11:45,000
+network.
+
+226
+00:11:45,000 --> 00:11:50,000
+If that Sonicwall score was a ten, there is a massive exposure factor.
+
+227
+00:11:50,000 --> 00:11:54,000
+If the if the value is five, it's moderate exposure factor.
+
+228
+00:11:54,000 --> 00:11:57,000
+So the Cvss score that we just mentioned.
+
+229
+00:11:58,000 --> 00:12:00,000
+Is really important.
+
+230
+00:12:00,000 --> 00:12:03,000
+The next thing here we have is environmental variables.
+
+231
+00:12:03,000 --> 00:12:07,000
+You got to keep in mind that the environment will influence how severe it is.
+
+232
+00:12:07,000 --> 00:12:13,000
+Factors like network architecture or existing security control software dependencies can influence the
+
+233
+00:12:13,000 --> 00:12:17,000
+severity of how severe a particular vulnerability is.
+
+234
+00:12:18,000 --> 00:12:27,000
+Take, for example, if we have different kinds of systems in our network that are fully updated and
+
+235
+00:12:27,000 --> 00:12:28,000
+fully patched.
+
+236
+00:12:28,000 --> 00:12:29,000
+All right.
+
+237
+00:12:29,000 --> 00:12:36,000
+We have systems that are well secure around a system that's not so secure.
+
+238
+00:12:36,000 --> 00:12:41,000
+Now, even though the system may have a high cvss score and a vulnerability that maybe has 2 or 3 of
+
+239
+00:12:41,000 --> 00:12:46,000
+them, it may not be that big because it's surrounded by good technology.
+
+240
+00:12:46,000 --> 00:12:48,000
+Some systems may not be fixed right away.
+
+241
+00:12:48,000 --> 00:12:53,000
+Some systems, even though you discovered a vulnerability, may stay vulnerable for a period of time.
+
+242
+00:12:53,000 --> 00:12:57,000
+And the reason for that is because you have to test the patches.
+
+243
+00:12:57,000 --> 00:12:59,000
+You just don't deploy a patch.
+
+244
+00:12:59,000 --> 00:13:00,000
+It may break the system.
+
+245
+00:13:02,000 --> 00:13:10,000
+So we have to understand the impact, the potential effect of vulnerabilities on specific industries.
+
+246
+00:13:10,000 --> 00:13:15,000
+Uh, considering things like regulatory requirements, business operations and of course, the public
+
+247
+00:13:15,000 --> 00:13:19,000
+image, you know, what happens when a vulnerability impacts your organization?
+
+248
+00:13:19,000 --> 00:13:20,000
+Consider that impact.
+
+249
+00:13:20,000 --> 00:13:27,000
+Yes, we may look at the impact that that thing we saw against the sonic wall may break the sonic wall,
+
+250
+00:13:27,000 --> 00:13:28,000
+but what impact will it have?
+
+251
+00:13:28,000 --> 00:13:31,000
+How much of operations could be lost?
+
+252
+00:13:31,000 --> 00:13:34,000
+How much would the public hate us if we lose all their information?
+
+253
+00:13:35,000 --> 00:13:38,000
+You see, all of that comes down to your risk tolerance.
+
+254
+00:13:38,000 --> 00:13:41,000
+That's what this is going to come down to your risk tolerance.
+
+255
+00:13:41,000 --> 00:13:43,000
+What exactly is that?
+
+256
+00:13:43,000 --> 00:13:48,000
+That's a level of risk an organization is willing to accept influenced by its risk management strategies,
+
+257
+00:13:48,000 --> 00:13:53,000
+business objectives and regulatory environment, determines how aggressively an organization should
+
+258
+00:13:53,000 --> 00:13:55,000
+respond to different levels of vulnerability.
+
+259
+00:13:55,000 --> 00:13:57,000
+Let me give you a good example of risk tolerance.
+
+260
+00:13:58,000 --> 00:14:02,000
+So you found a vulnerability against the sonicwall.
+
+261
+00:14:03,000 --> 00:14:07,000
+You run to the boss and you says, hey boss, we found this massive vulnerability.
+
+262
+00:14:07,000 --> 00:14:11,000
+They can log into the firewall and they can be in our network within ten minutes.
+
+263
+00:14:11,000 --> 00:14:14,000
+And your boss says, all right, that's not so bad.
+
+264
+00:14:15,000 --> 00:14:17,000
+What, is he, insane?
+
+265
+00:14:17,000 --> 00:14:20,000
+His tolerance for risk is really high.
+
+266
+00:14:20,000 --> 00:14:23,000
+Versus your tolerance for risk is lower.
+
+267
+00:14:23,000 --> 00:14:26,000
+Now, maybe he has a maybe he has some kind of rezident.
+
+268
+00:14:26,000 --> 00:14:30,000
+Maybe the sonicwall is protecting just public data.
+
+269
+00:14:30,000 --> 00:14:34,000
+Maybe everything in that network protected by that sonicwall is public data.
+
+270
+00:14:34,000 --> 00:14:35,000
+It's public web servers.
+
+271
+00:14:35,000 --> 00:14:37,000
+So there's really no confidentiality.
+
+272
+00:14:37,000 --> 00:14:41,000
+But if they log in and they take out the web servers, they may lose availability to whatever those
+
+273
+00:14:41,000 --> 00:14:43,000
+websites were provided.
+
+274
+00:14:43,000 --> 00:14:47,000
+So maybe he says, don't fix it right away and concentrate your efforts on something else.
+
+275
+00:14:47,000 --> 00:14:48,000
+Risk tolerance.
+
+276
+00:14:48,000 --> 00:14:52,000
+The point is varies by everybody and different organizations.
+
+277
+00:14:52,000 --> 00:14:58,000
+How we respond to vulnerabilities and problems is determined by the risk tolerance, so keep that in
+
+278
+00:14:58,000 --> 00:14:59,000
+mind.
+
+279
+00:14:59,000 --> 00:15:04,000
+Risk tolerance really affects the organization's risk tolerance, especially the upper management affects
+
+280
+00:15:04,000 --> 00:15:05,000
+how we respond to vulnerability.
+
+281
+00:15:07,000 --> 00:15:15,000
+A good network administrator is going to really utilize things like CVE cvss in order to manage all
+
+282
+00:15:15,000 --> 00:15:16,000
+those vulnerabilities.
+
+283
+00:15:16,000 --> 00:15:22,000
+Remember, the tools of CVE is used by you and by hackers, so make sure you review it to keep your
+
+284
+00:15:22,000 --> 00:15:24,000
+systems safe.
+
diff --git a/15 - Vulnerability Management/008 Vulnerability Responses OB 4.3_en.srt b/15 - Vulnerability Management/008 Vulnerability Responses OB 4.3_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..7cff03b885926f8e99f78c708b67207b8d47b267
--- /dev/null
+++ b/15 - Vulnerability Management/008 Vulnerability Responses OB 4.3_en.srt
@@ -0,0 +1,764 @@
+1
+00:00:00,000 --> 00:00:06,000
+Okay, so you have used something like the Nexus security scanner and CVV to find vulnerabilities against
+
+2
+00:00:06,000 --> 00:00:07,000
+your system.
+
+3
+00:00:08,000 --> 00:00:09,000
+But what do you do now?
+
+4
+00:00:09,000 --> 00:00:11,000
+Now that you okay, here's the vulnerability.
+
+5
+00:00:11,000 --> 00:00:12,000
+But what do we do now?
+
+6
+00:00:12,000 --> 00:00:14,000
+Well, we need to fix those vulnerabilities.
+
+7
+00:00:14,000 --> 00:00:15,000
+God forbid.
+
+8
+00:00:15,000 --> 00:00:16,000
+What if we're hacked?
+
+9
+00:00:16,000 --> 00:00:16,000
+What do we do now?
+
+10
+00:00:16,000 --> 00:00:23,000
+So in this video, let's take a look at some of the things that we can do to fix those vulnerabilities,
+
+11
+00:00:23,000 --> 00:00:29,000
+because we want to be able to address them promptly to minimize any kind of a risk of exploitation of
+
+12
+00:00:29,000 --> 00:00:31,000
+those particular vulnerabilities.
+
+13
+00:00:31,000 --> 00:00:35,000
+What are we going to be patching it, utilizing insurance, segmenting them, looking for alternative
+
+14
+00:00:35,000 --> 00:00:37,000
+controls and compensating.
+
+15
+00:00:37,000 --> 00:00:41,000
+Or maybe there is some kind of exception or exemption that needs to be made.
+
+16
+00:00:41,000 --> 00:00:42,000
+Let's take a look.
+
+17
+00:00:42,000 --> 00:00:44,000
+Now I'm just going to make a statement.
+
+18
+00:00:44,000 --> 00:00:50,000
+If I remember from seeing the website CVE a few minutes ago when we when we just made that video, I
+
+19
+00:00:50,000 --> 00:00:53,000
+think there was 218,000 vulnerabilities listed there.
+
+20
+00:00:53,000 --> 00:00:55,000
+And, uh.
+
+21
+00:00:56,000 --> 00:01:01,000
+In my opinion on based on my experience, I'm saying 80 to 90%.
+
+22
+00:01:01,000 --> 00:01:02,000
+There's no statistics on this.
+
+23
+00:01:02,000 --> 00:01:04,000
+This is Andrew's opinion.
+
+24
+00:01:04,000 --> 00:01:10,000
+80 to 90% of the CVE vulnerabilities that I've ever experienced in my life was fixed with a patch.
+
+25
+00:01:10,000 --> 00:01:14,000
+More than likely the vendor knows about it and they're going to release a patch.
+
+26
+00:01:14,000 --> 00:01:17,000
+I'm even going to say that number is probably low.
+
+27
+00:01:17,000 --> 00:01:18,000
+That number is too low.
+
+28
+00:01:18,000 --> 00:01:25,000
+It's probably 95 plus percent of those 218,000 vulnerabilities that was listed there.
+
+29
+00:01:25,000 --> 00:01:27,000
+It's probably going to be fixed by a patch.
+
+30
+00:01:27,000 --> 00:01:27,000
+So what does patching do?
+
+31
+00:01:27,000 --> 00:01:32,000
+Well, it's generally an update to the system to generally fix some kind of security hole.
+
+32
+00:01:32,000 --> 00:01:39,000
+When software developers realize that there is some kind of hack against their systems, they will generally
+
+33
+00:01:39,000 --> 00:01:39,000
+fix it.
+
+34
+00:01:39,000 --> 00:01:45,000
+And don't think it's just software like an application, because every piece of hardware needs software.
+
+35
+00:01:45,000 --> 00:01:48,000
+Hardware without software is paper wheat.
+
+36
+00:01:48,000 --> 00:01:53,000
+That's why patches fix devices and of course software like an operating system.
+
+37
+00:01:53,000 --> 00:01:57,000
+It's important to regularly patch security loopholes.
+
+38
+00:01:57,000 --> 00:01:59,000
+If not, hackers will take advantage of it.
+
+39
+00:01:59,000 --> 00:02:08,000
+The challenge, though, is there are so many vendors managing patches, numerous systems and and compatibility.
+
+40
+00:02:08,000 --> 00:02:11,000
+Sometimes patches can even break systems.
+
+41
+00:02:12,000 --> 00:02:15,000
+There is such a thing as cybersecurity insurance.
+
+42
+00:02:15,000 --> 00:02:16,000
+That's a small business like us.
+
+43
+00:02:16,000 --> 00:02:19,000
+Even we have cybersecurity insurance.
+
+44
+00:02:19,000 --> 00:02:25,000
+If we are hacked, we can utilize that cybersecurity insurance to help recover from losses in particularly
+
+45
+00:02:25,000 --> 00:02:27,000
+financial loss.
+
+46
+00:02:27,000 --> 00:02:34,000
+For example, if the cybersecurity risk or vulnerability are attack, if they affected us and they took
+
+47
+00:02:34,000 --> 00:02:41,000
+us out of business for a particular while or we lost some functional information, cybersecurity insurance
+
+48
+00:02:41,000 --> 00:02:44,000
+can help come in and help with the financial loss.
+
+49
+00:02:44,000 --> 00:02:48,000
+So this insurance helps mitigate financial risk associated with cyber incidents.
+
+50
+00:02:49,000 --> 00:02:54,000
+Now consider it's important to understand that the covered scope is a lot of these policies does vary
+
+51
+00:02:54,000 --> 00:02:56,000
+and some of them are really expensive.
+
+52
+00:02:56,000 --> 00:03:02,000
+And the cheaper ones may not give you the complete, uh, ability to rebuild your business because they
+
+53
+00:03:02,000 --> 00:03:04,000
+give you very low money.
+
+54
+00:03:05,000 --> 00:03:07,000
+Segmentation.
+
+55
+00:03:08,000 --> 00:03:09,000
+When it comes to it.
+
+56
+00:03:09,000 --> 00:03:12,000
+Security updating is 101.
+
+57
+00:03:12,000 --> 00:03:15,000
+Segmentation is also 101.
+
+58
+00:03:15,000 --> 00:03:19,000
+Segmentation is breaking your network into separate parts.
+
+59
+00:03:19,000 --> 00:03:23,000
+Earlier in this course we discussed things like utilizing VLANs like I would have on my switch.
+
+60
+00:03:24,000 --> 00:03:30,000
+You need to do this because if a particular device in a segment is vulnerable and does get attacked,
+
+61
+00:03:30,000 --> 00:03:33,000
+that attack doesn't spread to every machine in the network.
+
+62
+00:03:33,000 --> 00:03:35,000
+It can only spread on the segment.
+
+63
+00:03:35,000 --> 00:03:38,000
+The smaller the segments, the less impact you're going to have.
+
+64
+00:03:38,000 --> 00:03:41,000
+So it's divided in network into smaller things.
+
+65
+00:03:41,000 --> 00:03:48,000
+This will limit the spread of a breach within a within a network makes it harder to move laterally.
+
+66
+00:03:48,000 --> 00:03:50,000
+In other words, move across your network.
+
+67
+00:03:50,000 --> 00:03:55,000
+Careful planning and setup of segmentation is critical.
+
+68
+00:03:55,000 --> 00:04:00,000
+Sometimes you're not going to be able to put the best controls.
+
+69
+00:04:00,000 --> 00:04:06,000
+Sometimes you may not have the resources to implement the best controls in an organization.
+
+70
+00:04:06,000 --> 00:04:09,000
+That way, you're going to have to come up with what's called compensating controls.
+
+71
+00:04:09,000 --> 00:04:16,000
+These are security measures that are in place to offset the risk when standard controls cannot be applied.
+
+72
+00:04:17,000 --> 00:04:22,000
+One of the best security controls you can implement is call separation of duties.
+
+73
+00:04:22,000 --> 00:04:32,000
+Separation of duties is when instead of having one person do a lot of task, break the task up to multiple
+
+74
+00:04:32,000 --> 00:04:32,000
+people.
+
+75
+00:04:32,000 --> 00:04:38,000
+The reason you do this is so that one person doesn't have the ability to commit fraud and not get checked,
+
+76
+00:04:38,000 --> 00:04:40,000
+or be or be found out.
+
+77
+00:04:40,000 --> 00:04:44,000
+For example, if you have somebody working in the accounting department and they have the ability to
+
+78
+00:04:44,000 --> 00:04:47,000
+enter the bill, pay the bill.
+
+79
+00:04:47,000 --> 00:04:50,000
+In other words, write the check and then reconcile the bank account.
+
+80
+00:04:50,000 --> 00:04:55,000
+This person has the ability basically to enter a fake bill, send out a fake check to themself, and
+
+81
+00:04:55,000 --> 00:04:57,000
+who's going to be checking the fake check themselves.
+
+82
+00:04:57,000 --> 00:05:01,000
+So why don't you have somebody else write checks and somebody else pay bills?
+
+83
+00:05:01,000 --> 00:05:02,000
+This is a great control.
+
+84
+00:05:02,000 --> 00:05:04,000
+That separation of duties.
+
+85
+00:05:04,000 --> 00:05:07,000
+It's break into duties up to prevent fraud.
+
+86
+00:05:07,000 --> 00:05:15,000
+The problem with separation of duties, it requires more people to do a single task or to complete something.
+
+87
+00:05:15,000 --> 00:05:16,000
+Now.
+
+88
+00:05:17,000 --> 00:05:22,000
+Obviously not a lot of companies have the resources to do this or money, so they will put in a compensating
+
+89
+00:05:22,000 --> 00:05:24,000
+control a lot of time.
+
+90
+00:05:24,000 --> 00:05:26,000
+A compensating control involves monitoring.
+
+91
+00:05:26,000 --> 00:05:30,000
+So maybe we hire one person to monitor multiple people.
+
+92
+00:05:30,000 --> 00:05:33,000
+So this one person can then keep an eye on people.
+
+93
+00:05:33,000 --> 00:05:38,000
+This is a way to prevent, uh, people from stealing money because they know.
+
+94
+00:05:38,000 --> 00:05:41,000
+Well, if I make a fake check and I write it and I check it, there's still somebody going to check
+
+95
+00:05:41,000 --> 00:05:42,000
+the bank account.
+
+96
+00:05:43,000 --> 00:05:45,000
+So this would be a compensating control.
+
+97
+00:05:46,000 --> 00:05:47,000
+Now.
+
+98
+00:05:48,000 --> 00:05:50,000
+Exceptions and exemptions.
+
+99
+00:05:50,000 --> 00:05:57,000
+This is situation when standard security policies and controls are not applied, often due to some requirement
+
+100
+00:05:57,000 --> 00:05:58,000
+or limitation.
+
+101
+00:05:59,000 --> 00:06:08,000
+There may be a point in the organization where putting in the standard fix or doing the standard configurations
+
+102
+00:06:08,000 --> 00:06:14,000
+cannot be done because an application may fail to work, or particularly speaking, the device may not
+
+103
+00:06:14,000 --> 00:06:15,000
+support it.
+
+104
+00:06:15,000 --> 00:06:21,000
+In these situations, you're going to have to make an exception to allowing this thing to work, but
+
+105
+00:06:21,000 --> 00:06:24,000
+you're going to have to maybe pat it up with other devices around it.
+
+106
+00:06:25,000 --> 00:06:34,000
+Managing exceptions and exemptions requires a formal process to elevate and approve, ensuring that
+
+107
+00:06:34,000 --> 00:06:37,000
+any variations from any security policy are justified.
+
+108
+00:06:37,000 --> 00:06:41,000
+Although sometimes necessary, this does introduce extra risks.
+
+109
+00:06:41,000 --> 00:06:45,000
+For example, if there is an exception that we're going to allow this vulnerability because fixing it
+
+110
+00:06:45,000 --> 00:06:47,000
+requires a massive amount of work.
+
+111
+00:06:47,000 --> 00:06:54,000
+This could result in more risk, of course, but you may want to monitor the device more once you have
+
+112
+00:06:54,000 --> 00:06:57,000
+put your.
+
+113
+00:06:57,000 --> 00:06:58,000
+Once you have put.
+
+114
+00:06:59,000 --> 00:07:02,000
+Your fixes like your patches into place.
+
+115
+00:07:02,000 --> 00:07:06,000
+Now comes this section validation of the remediation.
+
+116
+00:07:06,000 --> 00:07:09,000
+Did it actually fix the problem?
+
+117
+00:07:09,000 --> 00:07:12,000
+Did it fix the vulnerability?
+
+118
+00:07:12,000 --> 00:07:13,000
+So what are we going to be doing?
+
+119
+00:07:13,000 --> 00:07:18,000
+Well the first thing up is let's rescan the system.
+
+120
+00:07:18,000 --> 00:07:24,000
+If the Nexus security scanner says that that machine has is vulnerable to this, this and this, then
+
+121
+00:07:24,000 --> 00:07:29,000
+the next thing to do is to have the Nexus security scanner scan it again.
+
+122
+00:07:29,000 --> 00:07:30,000
+Oh, you fixed it.
+
+123
+00:07:30,000 --> 00:07:31,000
+Scan it again.
+
+124
+00:07:31,000 --> 00:07:37,000
+Re scan it is used an automated tools to scan the application that were subject to remediation.
+
+125
+00:07:37,000 --> 00:07:41,000
+This is done to ensure the vulnerabilities identified was patched.
+
+126
+00:07:41,000 --> 00:07:46,000
+For example, if you scan this machine and you found there was 1010 vulnerabilities, you fixed it.
+
+127
+00:07:46,000 --> 00:07:48,000
+How do you know you fixed it?
+
+128
+00:07:48,000 --> 00:07:49,000
+Well, scan it again.
+
+129
+00:07:51,000 --> 00:07:52,000
+Now.
+
+130
+00:07:52,000 --> 00:07:53,000
+Auditing.
+
+131
+00:07:53,000 --> 00:08:00,000
+Auditing is generally going to be a thorough review and examination of security measures and processes
+
+132
+00:08:00,000 --> 00:08:03,000
+related to those remediation.
+
+133
+00:08:03,000 --> 00:08:06,000
+Generally, auditing is going to follow a kind of a standard that needs to get done.
+
+134
+00:08:06,000 --> 00:08:12,000
+That's going to be things like reviewing documents, uh, change management logs, interviewing staff.
+
+135
+00:08:12,000 --> 00:08:19,000
+The goal here is to ensure that remediation was carried out with a planned procedure and security standards.
+
+136
+00:08:19,000 --> 00:08:26,000
+Now, any time you fix something, you should have followed a standard security plan or a standard security
+
+137
+00:08:26,000 --> 00:08:27,000
+procedure.
+
+138
+00:08:27,000 --> 00:08:32,000
+Auditors will come out and verify that you followed that standard procedure.
+
+139
+00:08:33,000 --> 00:08:37,000
+Now verification the system comes online.
+
+140
+00:08:37,000 --> 00:08:41,000
+How do we know that it's actually been remediated?
+
+141
+00:08:41,000 --> 00:08:43,000
+Well, the scan says hey, we're good.
+
+142
+00:08:43,000 --> 00:08:50,000
+So verification is the process confirming that a remediation efforts have not only closed the vulnerabilities,
+
+143
+00:08:50,000 --> 00:08:53,000
+but also that it haven't introduced new vulnerabilities.
+
+144
+00:08:53,000 --> 00:08:56,000
+That's a common thing or negatively impact the system performance.
+
+145
+00:08:56,000 --> 00:08:59,000
+So verification do you're scan it.
+
+146
+00:08:59,000 --> 00:09:00,000
+You realize vulnerability is gone.
+
+147
+00:09:00,000 --> 00:09:03,000
+But you need to verify the system is fully functional.
+
+148
+00:09:03,000 --> 00:09:08,000
+Sometimes you may patch a system but the patch fixes the hole.
+
+149
+00:09:08,000 --> 00:09:10,000
+But the patch broke another part.
+
+150
+00:09:11,000 --> 00:09:12,000
+You may scan.
+
+151
+00:09:12,000 --> 00:09:16,000
+You may scan a system and find out that it is vulnerable to this thing.
+
+152
+00:09:16,000 --> 00:09:21,000
+There's a hole in this system, so you put the patch in, you walk away, you run the scan.
+
+153
+00:09:21,000 --> 00:09:22,000
+The scan is great.
+
+154
+00:09:22,000 --> 00:09:25,000
+User calls you ten minutes later and says Microsoft Word doesn't open.
+
+155
+00:09:25,000 --> 00:09:26,000
+The internet doesn't work.
+
+156
+00:09:26,000 --> 00:09:28,000
+The patch just broke the Nic card.
+
+157
+00:09:29,000 --> 00:09:34,000
+Did you verify that whatever you put in didn't break other parts?
+
+158
+00:09:34,000 --> 00:09:40,000
+This can include manual system testing like manually go in and see if the system works, reviewing its
+
+159
+00:09:40,000 --> 00:09:45,000
+logs, looking at if performance was decreased in the system with performance metrics.
+
+160
+00:09:46,000 --> 00:09:49,000
+Basically, the system is operating as expected.
+
+161
+00:09:50,000 --> 00:09:56,000
+A lot of times we're going to fix things, and in the process of fixing things, we break things.
+
+162
+00:09:56,000 --> 00:10:01,000
+And if we don't test the system to see if it actually works, we may never know that we actually broke
+
+163
+00:10:01,000 --> 00:10:03,000
+it while we were trying to patch it.
+
+164
+00:10:03,000 --> 00:10:04,000
+It's a common thing in it.
+
+165
+00:10:04,000 --> 00:10:07,000
+Believe that or not involving a user feedback.
+
+166
+00:10:07,000 --> 00:10:08,000
+Get user feedback.
+
+167
+00:10:08,000 --> 00:10:10,000
+This is when I said you left.
+
+168
+00:10:10,000 --> 00:10:14,000
+The user calls you back and says, hey, my system doesn't work anymore.
+
+169
+00:10:14,000 --> 00:10:17,000
+I know you just fixed it, but now it's even slower.
+
+170
+00:10:17,000 --> 00:10:19,000
+You need user feedback to to do this.
+
+171
+00:10:20,000 --> 00:10:21,000
+Who are you going to be reporting to?
+
+172
+00:10:21,000 --> 00:10:23,000
+Vulnerability fixing?
+
+173
+00:10:24,000 --> 00:10:30,000
+Any time you fix vulnerabilities in your patched systems, this is generally generally going to be reported
+
+174
+00:10:30,000 --> 00:10:31,000
+maybe to decision makers.
+
+175
+00:10:31,000 --> 00:10:38,000
+Sometimes, if the vulnerability was found by compliance officers and government agencies, you might
+
+176
+00:10:38,000 --> 00:10:39,000
+need to report.
+
+177
+00:10:40,000 --> 00:10:42,000
+To compliance.
+
+178
+00:10:42,000 --> 00:10:47,000
+Uh agencies communicate with stakeholders or people involved on your network.
+
+179
+00:10:47,000 --> 00:10:49,000
+Tracking and accountability.
+
+180
+00:10:49,000 --> 00:10:52,000
+Continuous improvement on systems are going to be important.
+
+181
+00:10:52,000 --> 00:10:57,000
+You see, good, good reporting is important to good vulnerability management.
+
+182
+00:10:58,000 --> 00:10:58,000
+All right.
+
+183
+00:10:58,000 --> 00:11:02,000
+Don't think that just by discovering a vulnerability you're just going to fix it.
+
+184
+00:11:02,000 --> 00:11:03,000
+Remember the steps to fix it.
+
+185
+00:11:03,000 --> 00:11:05,000
+If you patch it re scan it.
+
+186
+00:11:05,000 --> 00:11:07,000
+After you're scan it what do you do.
+
+187
+00:11:07,000 --> 00:11:08,000
+Verify it.
+
+188
+00:11:08,000 --> 00:11:09,000
+Verify that.
+
+189
+00:11:09,000 --> 00:11:10,000
+You know what?
+
+190
+00:11:10,000 --> 00:11:15,000
+Not only did we fix the vulnerability, but the system functions.
+
+191
+00:11:15,000 --> 00:11:16,000
+That's normal.
+
diff --git a/15 - Vulnerability Management/009 Internal and External Assessments OB 5.5_en.srt b/15 - Vulnerability Management/009 Internal and External Assessments OB 5.5_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..8c2b174023b343ef84d3a0210d40f25b6a516dc5
--- /dev/null
+++ b/15 - Vulnerability Management/009 Internal and External Assessments OB 5.5_en.srt
@@ -0,0 +1,408 @@
+1
+00:00:00,000 --> 00:00:05,000
+As a cybersecurity professional, you're going to be working with all kinds of different folks within
+
+2
+00:00:05,000 --> 00:00:11,000
+the organization, whether that's senior management, higher up technical folks, or even lower technical
+
+3
+00:00:11,000 --> 00:00:15,000
+folks such as the help desk or systems manager or systems engineer.
+
+4
+00:00:15,000 --> 00:00:20,000
+But one set of folks that IT professionals generally don't like dealing with is auditors.
+
+5
+00:00:20,000 --> 00:00:25,000
+You see, auditors are folks that comes into your organization, particularly external auditors, and
+
+6
+00:00:25,000 --> 00:00:32,000
+verify that your policies and your procedures matches certain kinds of regulations that you have to
+
+7
+00:00:32,000 --> 00:00:34,000
+meet or to meet certain.
+
+8
+00:00:34,000 --> 00:00:37,000
+Maybe your procedures are not meeting certain policies that even you set.
+
+9
+00:00:37,000 --> 00:00:41,000
+So in this video, let's take a look at talking about these auditors.
+
+10
+00:00:41,000 --> 00:00:46,000
+And in particular we're going to look at internal audits and external audits and all the ups and downs
+
+11
+00:00:46,000 --> 00:00:47,000
+about them.
+
+12
+00:00:47,000 --> 00:00:48,000
+So let's get started.
+
+13
+00:00:48,000 --> 00:00:51,000
+The first thing we'll talk about what's known as an internal assessment or audit.
+
+14
+00:00:52,000 --> 00:00:58,000
+These are audits, assessment and procedures conducted within the organisation by its own employees
+
+15
+00:00:58,000 --> 00:01:00,000
+or designated internal audit team.
+
+16
+00:01:00,000 --> 00:01:04,000
+Lots of large organisations have internal audit teams.
+
+17
+00:01:04,000 --> 00:01:09,000
+These are teams that audit all the different procedures that the organisation follow to ensure that
+
+18
+00:01:09,000 --> 00:01:13,000
+they're up to date on certain regulations and their policies.
+
+19
+00:01:13,000 --> 00:01:17,000
+These internal activities are critical for maintaining improvement security measures.
+
+20
+00:01:17,000 --> 00:01:20,000
+If we want to ensure that we, of course, meet certain compliance.
+
+21
+00:01:20,000 --> 00:01:25,000
+Now when it comes to these internal audits, one of the main reasons we do them is, of course, for
+
+22
+00:01:25,000 --> 00:01:26,000
+compliance.
+
+23
+00:01:26,000 --> 00:01:29,000
+You have to ensure that you meet certain compliance.
+
+24
+00:01:29,000 --> 00:01:35,000
+For example, what if you have to follow GDPR, HIPAA compliance, PCI compliance and so on depending
+
+25
+00:01:35,000 --> 00:01:39,000
+on whatever compliance you have to follow, how do you know if you actually meet them?
+
+26
+00:01:39,000 --> 00:01:42,000
+How do you know the organization is doing the right procedures to meet them?
+
+27
+00:01:42,000 --> 00:01:45,000
+Well, that's where internal audits will come into play.
+
+28
+00:01:46,000 --> 00:01:53,000
+This is when internal folks, such as an internal audit team, are actually checking to see, are we
+
+29
+00:01:53,000 --> 00:01:55,000
+encrypting those credit card information?
+
+30
+00:01:55,000 --> 00:01:58,000
+Can we prove that we encrypted the credit card information?
+
+31
+00:01:58,000 --> 00:02:00,000
+They give you the PCI, DSS.
+
+32
+00:02:00,000 --> 00:02:05,000
+By regular reviewing and assessing internal process control, your organization can identify.
+
+33
+00:02:05,000 --> 00:02:07,000
+Hey, is there any gap?
+
+34
+00:02:07,000 --> 00:02:09,000
+Are we supposed to be doing this?
+
+35
+00:02:09,000 --> 00:02:10,000
+But we're now doing this.
+
+36
+00:02:10,000 --> 00:02:11,000
+There's a gap there.
+
+37
+00:02:13,000 --> 00:02:17,000
+One thing that you should have in your organization is going to be an audit committee.
+
+38
+00:02:17,000 --> 00:02:18,000
+All right.
+
+39
+00:02:18,000 --> 00:02:21,000
+These are the folks that typically oversee the internal audit function.
+
+40
+00:02:21,000 --> 00:02:27,000
+They ensure audits are conducted objectively, thoroughly and aligned with the organization goal.
+
+41
+00:02:27,000 --> 00:02:32,000
+Now, your audit committee is going to be made up of generally folks from different departments, including
+
+42
+00:02:32,000 --> 00:02:36,000
+legal department, technical department, senior managers, and so on.
+
+43
+00:02:36,000 --> 00:02:41,000
+These audit committees are set up in order to ensure that all the audit functions are done correctly
+
+44
+00:02:41,000 --> 00:02:43,000
+in the business, such as do we have one?
+
+45
+00:02:43,000 --> 00:02:44,000
+Do we have a team?
+
+46
+00:02:44,000 --> 00:02:49,000
+Are they conducting the right procedures to ensure that we stay on those policies?
+
+47
+00:02:49,000 --> 00:02:55,000
+The audit Committee plays a key role in evaluating the findings of the internal audits and ensure appropriate
+
+48
+00:02:55,000 --> 00:02:56,000
+actions are taken.
+
+49
+00:02:56,000 --> 00:03:04,000
+Now, internal audits are basically known as a self-assessment because the organization is assessing
+
+50
+00:03:04,000 --> 00:03:09,000
+themselves against some kind of policy or some kind of regulation.
+
+51
+00:03:09,000 --> 00:03:16,000
+So this is when internal security teams regularly evaluate their own cyber security measures.
+
+52
+00:03:17,000 --> 00:03:18,000
+Now they should be proactive.
+
+53
+00:03:18,000 --> 00:03:21,000
+This is a proactive approach allows continuous monitoring.
+
+54
+00:03:21,000 --> 00:03:23,000
+In other words they're trying to see what we're doing.
+
+55
+00:03:23,000 --> 00:03:26,000
+So if we are out of compliance we can fix it before we get in trouble.
+
+56
+00:03:27,000 --> 00:03:33,000
+Self self-assessment is going to help us identify any vulnerabilities or gaps, assess the effectiveness
+
+57
+00:03:33,000 --> 00:03:38,000
+of our security programs or security measures, and guide the allocation of resources.
+
+58
+00:03:38,000 --> 00:03:40,000
+So we're going to identify vulnerabilities.
+
+59
+00:03:40,000 --> 00:03:44,000
+We're going to assess these vulnerabilities or how effective our controls are.
+
+60
+00:03:44,000 --> 00:03:48,000
+And then we're going to guide and say well let's allocate our resources correctly.
+
+61
+00:03:49,000 --> 00:03:53,000
+Now the other thing here we have is going to be external assessments.
+
+62
+00:03:53,000 --> 00:03:54,000
+So what is this.
+
+63
+00:03:54,000 --> 00:04:00,000
+Well external assessments are audits examinations and assessment done by outside organizations.
+
+64
+00:04:01,000 --> 00:04:09,000
+Now almost all businesses are going to be externally assessed, for example by a CPA firm or an accounting
+
+65
+00:04:09,000 --> 00:04:10,000
+firm for their books.
+
+66
+00:04:10,000 --> 00:04:16,000
+So when they submit tax returns to the IRS or the tax agency, well, we have an external firm saying
+
+67
+00:04:16,000 --> 00:04:19,000
+they're not lying about their income or their expenses.
+
+68
+00:04:19,000 --> 00:04:23,000
+Now, in the world of cybersecurity, we have a ton of external auditors that comes in and checks the
+
+69
+00:04:23,000 --> 00:04:27,000
+controls to see if we're in compliance to certain controls.
+
+70
+00:04:27,000 --> 00:04:30,000
+This is going to be an objective view.
+
+71
+00:04:30,000 --> 00:04:31,000
+In other words, it's not subjective.
+
+72
+00:04:31,000 --> 00:04:34,000
+It's very objective, which means they have no conflict of interest here.
+
+73
+00:04:34,000 --> 00:04:36,000
+It ensures compliance with regulations.
+
+74
+00:04:36,000 --> 00:04:39,000
+And it's going to check your internal controls.
+
+75
+00:04:39,000 --> 00:04:46,000
+Now one of the main reasons for external assessments is of course going to be more regulation, external
+
+76
+00:04:46,000 --> 00:04:47,000
+regulations.
+
+77
+00:04:47,000 --> 00:04:49,000
+This is what this is all about.
+
+78
+00:04:49,000 --> 00:04:56,000
+Typically mandated by government bodies, these external auditors or are I should say external audits
+
+79
+00:04:56,000 --> 00:05:05,000
+are done to see do you meet certain cybersecurity laws and independent third party audits?
+
+80
+00:05:05,000 --> 00:05:06,000
+Now what exactly is this?
+
+81
+00:05:06,000 --> 00:05:12,000
+Well, this is when an independent third party auditor and they come from large organizations.
+
+82
+00:05:12,000 --> 00:05:17,000
+If you work for a big company, you may hear of names like Ernst and Young Pricewaterhouse Coopers.
+
+83
+00:05:17,000 --> 00:05:23,000
+These are giant accounting organizations that audits Big Fortune 1000 companies, and they charge hundreds
+
+84
+00:05:23,000 --> 00:05:26,000
+of thousands, if not millions of dollars for their audits.
+
+85
+00:05:26,000 --> 00:05:34,000
+But this is an external party coming into your organization, and they do a comprehensive review of
+
+86
+00:05:34,000 --> 00:05:40,000
+all of your security procedures and your policies, all the things that you are doing, all those controls
+
+87
+00:05:40,000 --> 00:05:42,000
+that you have implemented, they're going to check it.
+
+88
+00:05:42,000 --> 00:05:42,000
+Now.
+
+89
+00:05:43,000 --> 00:05:47,000
+This is going to validate the accuracy of your organization.
+
+90
+00:05:47,000 --> 00:05:51,000
+Cybersecurity claim to ensure that the controls are effective and in line with industry best practice.
+
+91
+00:05:51,000 --> 00:05:55,000
+So the organization may say that we have all these policies and procedures, but can you prove it?
+
+92
+00:05:55,000 --> 00:05:57,000
+Do you actually have all that?
+
+93
+00:05:57,000 --> 00:06:01,000
+Well, this third party audit will check that this is critical for building trust.
+
+94
+00:06:01,000 --> 00:06:06,000
+Anytime I want to do business with a vendor, I check to see can I get a third party audit of that vendor
+
+95
+00:06:06,000 --> 00:06:13,000
+that's going to give me, that's going to give me more in depth information about that particular vendor?
+
+96
+00:06:13,000 --> 00:06:17,000
+I like to keep in mind, guys, internal auditors are something that you're going to be dealing is a
+
+97
+00:06:17,000 --> 00:06:19,000
+function that you're going to be working with.
+
+98
+00:06:19,000 --> 00:06:26,000
+A lot internal auditors within the organization is going to work with all levels of folks in it to ensure
+
+99
+00:06:26,000 --> 00:06:29,000
+that you guys, or anybody in it, is following the right procedures.
+
+100
+00:06:29,000 --> 00:06:30,000
+Are they actually doing it?
+
+101
+00:06:30,000 --> 00:06:35,000
+And then, of course, external auditors comes in after them to verify from an external perspective
+
+102
+00:06:35,000 --> 00:06:40,000
+or a more trusted perspective that the company is actually in compliance.
+
diff --git a/15 - Vulnerability Management/010 Quick Quiz.html b/15 - Vulnerability Management/010 Quick Quiz.html
new file mode 100644
index 0000000000000000000000000000000000000000..bd4d8c168ecc25c0e266e7378582ed83d7779b39
--- /dev/null
+++ b/15 - Vulnerability Management/010 Quick Quiz.html
@@ -0,0 +1,479 @@
+
+
+
+
+
+
+ Quiz
+
+
+
+
+
+
+
+
+ Score: 999 of
+ 999%
+
+ Correct: 999
+ Incorrect: 999
+
+
+
+
+
+
+
+
+
+
diff --git a/16 - Alerting and Monitoring IT/001 Monitoring Resources OB 4.4_en.srt b/16 - Alerting and Monitoring IT/001 Monitoring Resources OB 4.4_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..4f5b3dec187b458ef54bd134531d4026ec8af74a
--- /dev/null
+++ b/16 - Alerting and Monitoring IT/001 Monitoring Resources OB 4.4_en.srt
@@ -0,0 +1,360 @@
+1
+00:00:00,000 --> 00:00:04,000
+When it comes to being a good administrator, you have to be monitoring.
+
+2
+00:00:04,000 --> 00:00:09,000
+Good security administrator keeps a consistent eye on a couple of things.
+
+3
+00:00:09,000 --> 00:00:13,000
+That's going to be their systems, their applications and their infrastructure.
+
+4
+00:00:13,000 --> 00:00:18,000
+You have to keep monitoring on a consistent basis.
+
+5
+00:00:18,000 --> 00:00:24,000
+If you're not monitoring whatever it is in your infrastructure, you'll never know when something went
+
+6
+00:00:24,000 --> 00:00:28,000
+down, when something got hacked, or God forbid, information was stolen.
+
+7
+00:00:28,000 --> 00:00:32,000
+So let's get into this here and we're going to take a look at these three things.
+
+8
+00:00:32,000 --> 00:00:39,000
+But don't forget the word monitoring is about continuously overseeing various components of your infrastructure.
+
+9
+00:00:39,000 --> 00:00:40,000
+So let's get into this.
+
+10
+00:00:40,000 --> 00:00:44,000
+The first thing we're going to talk about is individual system monitoring.
+
+11
+00:00:44,000 --> 00:00:48,000
+So this focuses on the health and performance of individual computing.
+
+12
+00:00:48,000 --> 00:00:56,000
+Think of think servers workstations and other endpoint devices like my famous Sonicwall that we have
+
+13
+00:00:56,000 --> 00:00:57,000
+seen in every video.
+
+14
+00:00:57,000 --> 00:00:58,000
+A key aspect here.
+
+15
+00:00:58,000 --> 00:01:03,000
+What are we looking for when I say monitoring you'll say, Andrew, what are what are we monitoring
+
+16
+00:01:03,000 --> 00:01:03,000
+for?
+
+17
+00:01:03,000 --> 00:01:06,000
+Well, we're monitoring for any unusual unauthorized changes.
+
+18
+00:01:06,000 --> 00:01:09,000
+That means somebody's changing a configuration.
+
+19
+00:01:09,000 --> 00:01:11,000
+Resource utilization.
+
+20
+00:01:12,000 --> 00:01:15,000
+You're watching monitoring this device.
+
+21
+00:01:15,000 --> 00:01:22,000
+When you monitor this device, you may notice that on a good day, it stays at a consistent 10 to 15%
+
+22
+00:01:22,000 --> 00:01:25,000
+CPU and memory usage.
+
+23
+00:01:25,000 --> 00:01:31,000
+But you're monitoring one day and you notice it's hitting 100% memory, 100% CPU usage, and the lines
+
+24
+00:01:31,000 --> 00:01:32,000
+are being clogged.
+
+25
+00:01:32,000 --> 00:01:36,000
+That's a type of a DDoS attack or some kind of DDoS attack.
+
+26
+00:01:36,000 --> 00:01:37,000
+You want to investigate that?
+
+27
+00:01:37,000 --> 00:01:43,000
+How long has it been up, or has it been dropping performance metrics like how fast should it be accomplishing
+
+28
+00:01:43,000 --> 00:01:44,000
+certain tasks?
+
+29
+00:01:44,000 --> 00:01:48,000
+This is really important to monitor individual systems.
+
+30
+00:01:48,000 --> 00:01:56,000
+Now, by monitoring these elements, organization can detect any type of potential security incident.
+
+31
+00:01:56,000 --> 00:02:01,000
+Now potential security incident like I just mentioned for example, like a DDoS attack.
+
+32
+00:02:03,000 --> 00:02:07,000
+When it comes to your systems, you also have to monitor your applications.
+
+33
+00:02:07,000 --> 00:02:14,000
+Now I want to point out that systems is individual, applications is what's running on those systems,
+
+34
+00:02:14,000 --> 00:02:20,000
+and infrastructure is all of the infrastructure gear that you have when like traffic flowing around
+
+35
+00:02:20,000 --> 00:02:21,000
+your network?
+
+36
+00:02:21,000 --> 00:02:28,000
+Now, applications is what people use these applications is going to run on these particular systems.
+
+37
+00:02:28,000 --> 00:02:30,000
+So what are we concerned with?
+
+38
+00:02:30,000 --> 00:02:33,000
+Well we're concerned with the performance and security of these apps.
+
+39
+00:02:33,000 --> 00:02:35,000
+Look at the application performance.
+
+40
+00:02:35,000 --> 00:02:40,000
+Is it getting slower or more users that the help desk complaining that the thing got too slow?
+
+41
+00:02:40,000 --> 00:02:41,000
+User activity.
+
+42
+00:02:41,000 --> 00:02:45,000
+How are people utilizing the application?
+
+43
+00:02:45,000 --> 00:02:51,000
+They may be utilizing it for bad reasons or using it in bad ways.
+
+44
+00:02:51,000 --> 00:02:56,000
+They may be copying data out of an account in an application, such as credit card numbers.
+
+45
+00:02:56,000 --> 00:02:57,000
+Look at the error logs.
+
+46
+00:02:57,000 --> 00:03:05,000
+Everything has logs, devices, uh servers, uh applications, operating systems, you name it, everything
+
+47
+00:03:05,000 --> 00:03:08,000
+has a log transaction times.
+
+48
+00:03:08,000 --> 00:03:09,000
+When did things occur?
+
+49
+00:03:09,000 --> 00:03:13,000
+This is going to help for monitoring for unusual activity.
+
+50
+00:03:13,000 --> 00:03:20,000
+Any kind of security breach for example unexpected data access pattern for example let's say.
+
+51
+00:03:20,000 --> 00:03:25,000
+Somebody working in the accounts payable department only always accesses vendor information.
+
+52
+00:03:26,000 --> 00:03:31,000
+But you notice over the last couple of weeks they've been accessing payroll information because they
+
+53
+00:03:31,000 --> 00:03:33,000
+have access to the accounting system.
+
+54
+00:03:33,000 --> 00:03:36,000
+They have access to everything, but they generally don't access those records.
+
+55
+00:03:36,000 --> 00:03:38,000
+You better find out why they're doing that.
+
+56
+00:03:39,000 --> 00:03:45,000
+Uh, look, for any kind of anomalies or any kind of weird volume of transaction, you notice that this
+
+57
+00:03:45,000 --> 00:03:47,000
+guy's pulling more records than he used to.
+
+58
+00:03:47,000 --> 00:03:48,000
+Could be a problem.
+
+59
+00:03:49,000 --> 00:03:50,000
+Benefits.
+
+60
+00:03:50,000 --> 00:03:54,000
+Effective application monitoring is going to help identify and address performance bottlenecks in case
+
+61
+00:03:54,000 --> 00:03:59,000
+the application is slowing down software bugs and maybe even security vulnerabilities.
+
+62
+00:04:00,000 --> 00:04:02,000
+Then comes your infrastructure.
+
+63
+00:04:02,000 --> 00:04:08,000
+When it comes to infrastructure, this is going to refer to overseeing the entire IT infrastructure
+
+64
+00:04:08,000 --> 00:04:14,000
+of an organization that includes network components, data centers, cloud services, and other critical
+
+65
+00:04:14,000 --> 00:04:14,000
+elements.
+
+66
+00:04:14,000 --> 00:04:23,000
+Now I'm talking everything servers and routers in particular, our servers, uh, servers that generate
+
+67
+00:04:23,000 --> 00:04:28,000
+and send the data switches that passes the data and routes, routers that moves the data across multiple
+
+68
+00:04:28,000 --> 00:04:29,000
+networks.
+
+69
+00:04:29,000 --> 00:04:32,000
+The big goal here is network traffic analysis.
+
+70
+00:04:32,000 --> 00:04:38,000
+You're going to have a ton of traffic flowing through your coming out of your servers, into those switches,
+
+71
+00:04:38,000 --> 00:04:40,000
+across those lines, over those routers.
+
+72
+00:04:40,000 --> 00:04:42,000
+You have to analyze the network traffic.
+
+73
+00:04:42,000 --> 00:04:48,000
+You need to see what's happening across routers, switches, firewalls and other network and device.
+
+74
+00:04:48,000 --> 00:04:52,000
+Remember, data originates from things like servers and workstation.
+
+75
+00:04:52,000 --> 00:04:56,000
+And as that data starts to move across that network, you have all kinds of devices that you need to
+
+76
+00:04:56,000 --> 00:04:58,000
+keep a good eye on.
+
+77
+00:04:58,000 --> 00:04:59,000
+Check the performance.
+
+78
+00:04:59,000 --> 00:05:02,000
+Is the network getting slower or faster?
+
+79
+00:05:02,000 --> 00:05:04,000
+The goal here is to ensure that the infrastructure is integrity.
+
+80
+00:05:04,000 --> 00:05:07,000
+It means nobody's modifying data like bad people.
+
+81
+00:05:07,000 --> 00:05:10,000
+Data isn't being stolen for confidentiality.
+
+82
+00:05:10,000 --> 00:05:15,000
+And of course the actual availability of the network is up.
+
+83
+00:05:15,000 --> 00:05:21,000
+This includes identifying particular security threats like network breaches, for example, like someone
+
+84
+00:05:21,000 --> 00:05:24,000
+unauthorized traffic, unauthorized devices in your network.
+
+85
+00:05:24,000 --> 00:05:25,000
+Unusual pattern.
+
+86
+00:05:25,000 --> 00:05:31,000
+Also, quite a lot of things here when you're thinking about monitoring your entire systems, whether
+
+87
+00:05:31,000 --> 00:05:37,000
+that's an individual system, your entire infrastructure, or all kinds of application, all of these
+
+88
+00:05:37,000 --> 00:05:38,000
+things needs monitoring.
+
+89
+00:05:39,000 --> 00:05:45,000
+If you don't monitor your systems, you will never know if there's problems in your network and you
+
+90
+00:05:45,000 --> 00:05:46,000
+probably will never fix it.
+
diff --git a/16 - Alerting and Monitoring IT/002 Monitoring Activities OB 4.4_en.srt b/16 - Alerting and Monitoring IT/002 Monitoring Activities OB 4.4_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..dc5400a9820b215c3177e75b720883dcc6b70ef0
--- /dev/null
+++ b/16 - Alerting and Monitoring IT/002 Monitoring Activities OB 4.4_en.srt
@@ -0,0 +1,460 @@
+1
+00:00:00,000 --> 00:00:04,000
+When it comes to monitoring your network, there are certain activities that you're going to need to
+
+2
+00:00:04,000 --> 00:00:06,000
+get done to ensure it's done efficiently.
+
+3
+00:00:06,000 --> 00:00:09,000
+In a previous video, I talked about why monitoring is important.
+
+4
+00:00:09,000 --> 00:00:13,000
+Without monitoring, we're not going to know if we're being attacked without monitoring.
+
+5
+00:00:13,000 --> 00:00:15,000
+We're not going to know if our network is slowing down.
+
+6
+00:00:16,000 --> 00:00:22,000
+When we monitor and we do it effectively, we're able to pick up on security breaches quickly.
+
+7
+00:00:22,000 --> 00:00:26,000
+That way, if a breach does happen, we could minimize the impact because we're probably going to fix
+
+8
+00:00:26,000 --> 00:00:32,000
+it right away versus if you're not monitoring, here's a set of activities that I want to talk about
+
+9
+00:00:32,000 --> 00:00:38,000
+in this video that we should be doing, such as aggregating those log files, archiving them, and report
+
+10
+00:00:38,000 --> 00:00:41,000
+it to the correct authority, even quarantine certain systems.
+
+11
+00:00:41,000 --> 00:00:52,000
+Let's get into this on a network, you're going to have logs from all kinds of devices, multiple multiple
+
+12
+00:00:52,000 --> 00:00:58,000
+sources or various sources such as servers, applications, network devices, and security systems.
+
+13
+00:00:58,000 --> 00:01:02,000
+But just not that you're going to have switches and routers.
+
+14
+00:01:02,000 --> 00:01:08,000
+If you think about the network device, everything has log files, including an application log.
+
+15
+00:01:08,000 --> 00:01:13,000
+Aggregation is about collecting and consolidating these log files.
+
+16
+00:01:13,000 --> 00:01:20,000
+We're going to put them hopefully in a central location or a central repository, some kind of a database.
+
+17
+00:01:20,000 --> 00:01:26,000
+Later on in this course we're going to cover Siem systems or security information and event management
+
+18
+00:01:26,000 --> 00:01:27,000
+systems.
+
+19
+00:01:27,000 --> 00:01:32,000
+This helps to simplify the analysis aids and detecting patterns or any kind of anomalies within the
+
+20
+00:01:32,000 --> 00:01:33,000
+log files themselves.
+
+21
+00:01:33,000 --> 00:01:37,000
+We need this for monitoring our network.
+
+22
+00:01:37,000 --> 00:01:43,000
+You can't monitor your network without a good, good theme system.
+
+23
+00:01:43,000 --> 00:01:45,000
+And the reason is because it's just too many log files.
+
+24
+00:01:45,000 --> 00:01:49,000
+You know how many entries are in a log file, and if you have thousands of devices, you're going to
+
+25
+00:01:49,000 --> 00:01:53,000
+have thousands of log files to have one user going through it.
+
+26
+00:01:53,000 --> 00:01:55,000
+It's probably not efficient.
+
+27
+00:01:56,000 --> 00:02:02,000
+Alert him when you are working on your network and you're gathering all of these log files.
+
+28
+00:02:03,000 --> 00:02:11,000
+You're going to have to configure your system, your login system, or your monitoring system to look
+
+29
+00:02:11,000 --> 00:02:17,000
+for certain things that should alert an administrator, such as if this breach happened.
+
+30
+00:02:17,000 --> 00:02:19,000
+Alert the administrator if this threshold meets.
+
+31
+00:02:19,000 --> 00:02:20,000
+Alert the administrator.
+
+32
+00:02:20,000 --> 00:02:25,000
+So this refers to the process of configuring security systems to notify the administrator or security
+
+33
+00:02:25,000 --> 00:02:27,000
+team of potential security incident.
+
+34
+00:02:28,000 --> 00:02:29,000
+The key feature here.
+
+35
+00:02:30,000 --> 00:02:36,000
+Effective alerting should minimize false positives and and provide actionable insights.
+
+36
+00:02:36,000 --> 00:02:39,000
+They include meeting certain thresholds or triggers.
+
+37
+00:02:39,000 --> 00:02:40,000
+So let me explain.
+
+38
+00:02:41,000 --> 00:02:42,000
+A lot of times.
+
+39
+00:02:43,000 --> 00:02:49,000
+The administrators don't have the time to go to each machine and check things.
+
+40
+00:02:49,000 --> 00:02:54,000
+One of the main jobs is to make sure that you fix things before they break.
+
+41
+00:02:54,000 --> 00:03:01,000
+For example, you can set an alert on a server that when the server hard drive meets, 80%, fail to
+
+42
+00:03:01,000 --> 00:03:08,000
+send an alert when the when it's reached that 80%, let's say 81%, it sends an alert to the administrator.
+
+43
+00:03:08,000 --> 00:03:13,000
+Alerting is important because now the administrator can fix the problem of the server running out of
+
+44
+00:03:13,000 --> 00:03:15,000
+drive space before it actually runs out of drive space.
+
+45
+00:03:15,000 --> 00:03:20,000
+Alerting is important, so the threshold here would have been 80%.
+
+46
+00:03:21,000 --> 00:03:22,000
+Scanning.
+
+47
+00:03:22,000 --> 00:03:26,000
+Now, we talked about different kinds of vulnerability scanning.
+
+48
+00:03:26,000 --> 00:03:28,000
+But scanning is not something you do once.
+
+49
+00:03:28,000 --> 00:03:30,000
+It's something you do on a consistent basis.
+
+50
+00:03:30,000 --> 00:03:36,000
+A scan that was done today, and let's say you cleared the scan, no vulnerabilities, tells me that
+
+51
+00:03:36,000 --> 00:03:40,000
+as of that time on the report, your system was secure.
+
+52
+00:03:40,000 --> 00:03:43,000
+What happens one second later is different.
+
+53
+00:03:43,000 --> 00:03:47,000
+One second later, a new vulnerability could have could have been introduced, or a new system could
+
+54
+00:03:47,000 --> 00:03:50,000
+have lost an update, or a new system could have just been hacked.
+
+55
+00:03:51,000 --> 00:03:56,000
+Scanning includes various types of security scans, vulnerability scans, network and application scan.
+
+56
+00:03:56,000 --> 00:04:01,000
+The goal is to identify vulnerabilities, maybe even misconfigurations or other security weakness.
+
+57
+00:04:01,000 --> 00:04:05,000
+Now make sure you use a good vulnerability scanner in the scanning section of this course.
+
+58
+00:04:05,000 --> 00:04:08,000
+I did talk of, uh, things like the Nexus scanner.
+
+59
+00:04:10,000 --> 00:04:12,000
+Who are you going to report this to?
+
+60
+00:04:12,000 --> 00:04:20,000
+So report involves the generation of detailed reports about the security status of it, of the entire
+
+61
+00:04:20,000 --> 00:04:22,000
+entire, entire IT department.
+
+62
+00:04:22,000 --> 00:04:26,000
+Now, who are we going to be sending this to?
+
+63
+00:04:26,000 --> 00:04:32,000
+So these detailed reports are going to be sent out to management and potentially regulatory agencies.
+
+64
+00:04:32,000 --> 00:04:40,000
+Report includes vulnerabilities that was identified, the outcome of the scans, insights that what
+
+65
+00:04:40,000 --> 00:04:43,000
+we did and what can decision makers do about them.
+
+66
+00:04:45,000 --> 00:04:45,000
+Archiving.
+
+67
+00:04:45,000 --> 00:04:50,000
+Now, when it comes to these log files, it might be.
+
+68
+00:04:51,000 --> 00:04:56,000
+Best to not delete them after you finish analyzing them.
+
+69
+00:04:56,000 --> 00:05:03,000
+They are regulatory requirements in place that makes you keep those log files for a period of time.
+
+70
+00:05:03,000 --> 00:05:09,000
+Certain regulations may make you keep them for multiple years five, ten, 15 years.
+
+71
+00:05:10,000 --> 00:05:17,000
+This is the process of securely storing historical security data, such as logs and incident reports,
+
+72
+00:05:17,000 --> 00:05:18,000
+for future reference.
+
+73
+00:05:18,000 --> 00:05:25,000
+It's critical for compliance with legal and regulatory requirements as long as well as historical analysis.
+
+74
+00:05:26,000 --> 00:05:28,000
+Now two terms here.
+
+75
+00:05:28,000 --> 00:05:29,000
+I want you guys to know.
+
+76
+00:05:30,000 --> 00:05:32,000
+Quarantining and alert.
+
+77
+00:05:32,000 --> 00:05:32,000
+Tuning.
+
+78
+00:05:33,000 --> 00:05:41,000
+When a system is involved in some kind of security incident, you guys should be quarantining that system
+
+79
+00:05:41,000 --> 00:05:41,000
+of the network.
+
+80
+00:05:41,000 --> 00:05:42,000
+What does that mean?
+
+81
+00:05:42,000 --> 00:05:48,000
+So this involves isolating affected systems or components to prevent the spread of the threat.
+
+82
+00:05:48,000 --> 00:05:50,000
+Quarantine is often an immediate response.
+
+83
+00:05:50,000 --> 00:05:52,000
+So let me give you an example.
+
+84
+00:05:52,000 --> 00:05:59,000
+Let's say in the accounting department we found there's ten machines and we found six of them to have
+
+85
+00:05:59,000 --> 00:06:00,000
+a potential worm on it.
+
+86
+00:06:00,000 --> 00:06:02,000
+This worm seems to be spreading.
+
+87
+00:06:02,000 --> 00:06:05,000
+The best thing to do is unplug that system off the network, not system.
+
+88
+00:06:05,000 --> 00:06:06,000
+I'm sorry.
+
+89
+00:06:06,000 --> 00:06:09,000
+That segment, that entire accounting department.
+
+90
+00:06:09,000 --> 00:06:13,000
+That way it could stop that worm from trying to get out the segment.
+
+91
+00:06:13,000 --> 00:06:18,000
+Machines that are infected, those six machines, unplug them off the network, quarantine those things.
+
+92
+00:06:18,000 --> 00:06:20,000
+So that way the worm can't spread.
+
+93
+00:06:20,000 --> 00:06:25,000
+I would still disconnect the entire segment because we don't know if the other machines have it.
+
+94
+00:06:25,000 --> 00:06:33,000
+So remember quarantine is about removing, isolating, effective either an entire system or an entire
+
+95
+00:06:33,000 --> 00:06:35,000
+segment of the network.
+
+96
+00:06:35,000 --> 00:06:43,000
+Alert tuning refers to refining alerting mechanism to reduce false positives and ensures that alerts
+
+97
+00:06:43,000 --> 00:06:44,000
+are relevant.
+
+98
+00:06:45,000 --> 00:06:47,000
+So remember what false positive is.
+
+99
+00:06:47,000 --> 00:06:52,000
+It's when they say, hey, something is wrong, it's all right, but there's nothing wrong.
+
+100
+00:06:52,000 --> 00:06:56,000
+If you're alert in is not set up correctly, you bet your best bet.
+
+101
+00:06:56,000 --> 00:06:58,000
+You're going to get a lot of false positives.
+
+102
+00:06:58,000 --> 00:07:01,000
+You're going to run around fixing things that don't need fixing.
+
+103
+00:07:01,000 --> 00:07:08,000
+You have to adjust or tune your alerts to make sure that they don't overwhelm you with things that are
+
+104
+00:07:08,000 --> 00:07:09,000
+just not real.
+
+105
+00:07:09,000 --> 00:07:15,000
+This might involve adjusting thresholds, revising rules, or implementing more sophisticated detection
+
+106
+00:07:15,000 --> 00:07:16,000
+algorithms.
+
+107
+00:07:16,000 --> 00:07:19,000
+Sometimes the detection algorithms just don't work well.
+
+108
+00:07:20,000 --> 00:07:24,000
+Okay, we talked a lot about different things in this video.
+
+109
+00:07:24,000 --> 00:07:26,000
+I want you guys to keep in mind.
+
+110
+00:07:26,000 --> 00:07:31,000
+Then any kind of monitoring activity is going to be different for every organization.
+
+111
+00:07:31,000 --> 00:07:36,000
+Some of these things I mentioned is pretty common in most organizations, but some organizations have
+
+112
+00:07:36,000 --> 00:07:38,000
+their own policy procedures and more.
+
+113
+00:07:38,000 --> 00:07:41,000
+In particularly, every organization just uses different software.
+
+114
+00:07:41,000 --> 00:07:46,000
+So keep in mind that you're going to be doing these things in most companies, but keep in mind that
+
+115
+00:07:46,000 --> 00:07:49,000
+the software they use is probably going to be different.
+
diff --git a/16 - Alerting and Monitoring IT/003 Alerting and Monitoring Tools SIEM and DLP's OB 4.4_en.srt b/16 - Alerting and Monitoring IT/003 Alerting and Monitoring Tools SIEM and DLP's OB 4.4_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..df657eaefd523c1e0bb26d5a5190914a39d5bfa2
--- /dev/null
+++ b/16 - Alerting and Monitoring IT/003 Alerting and Monitoring Tools SIEM and DLP's OB 4.4_en.srt
@@ -0,0 +1,740 @@
+1
+00:00:00,000 --> 00:00:01,000
+In this section.
+
+2
+00:00:01,000 --> 00:00:02,000
+I've been talking about monitoring.
+
+3
+00:00:02,000 --> 00:00:09,000
+Now, what I want to show you guys are different things or tools that we can use to monitor our network.
+
+4
+00:00:09,000 --> 00:00:12,000
+Now, I want you guys to keep in mind for your exam.
+
+5
+00:00:12,000 --> 00:00:15,000
+You don't need to know how to use any of these tools.
+
+6
+00:00:15,000 --> 00:00:21,000
+You don't need to be installing things like vulnerability scanners or downloading that Splunk software,
+
+7
+00:00:21,000 --> 00:00:23,000
+or using McAfee DLP.
+
+8
+00:00:23,000 --> 00:00:25,000
+You don't need to do any of that.
+
+9
+00:00:25,000 --> 00:00:29,000
+What I do need you guys to know is the function.
+
+10
+00:00:29,000 --> 00:00:31,000
+What is the purpose of these things?
+
+11
+00:00:31,000 --> 00:00:36,000
+They might give you questions on the exam where they give you a problem and you're going to have to
+
+12
+00:00:36,000 --> 00:00:38,000
+say, well, this tool does that.
+
+13
+00:00:38,000 --> 00:00:41,000
+This is the tool that I can use to resolve that problem.
+
+14
+00:00:41,000 --> 00:00:41,000
+So let's get started.
+
+15
+00:00:41,000 --> 00:00:48,000
+So these are a wide variety of tools to ensure that the integrity and security of your systems stays
+
+16
+00:00:48,000 --> 00:00:48,000
+intact.
+
+17
+00:00:48,000 --> 00:00:49,000
+So let's get started.
+
+18
+00:00:49,000 --> 00:00:55,000
+The first thing I want to mention is something we call security content automation protocols.
+
+19
+00:00:55,000 --> 00:01:02,000
+What exactly is this or Scap well, this is a suite of standards for automating the process of configuring.
+
+20
+00:01:02,000 --> 00:01:08,000
+Now this is by the way is a Cisco based thing configuring a monitor and network devices for compliance
+
+21
+00:01:08,000 --> 00:01:10,000
+with a security policy.
+
+22
+00:01:10,000 --> 00:01:13,000
+So this thing here could configure and monitor.
+
+23
+00:01:13,000 --> 00:01:16,000
+Keyboard is monitor because that's the part we need.
+
+24
+00:01:16,000 --> 00:01:17,000
+What is it going to be used for.
+
+25
+00:01:17,000 --> 00:01:19,000
+Well it's used for vulnerabilities vulnerability management.
+
+26
+00:01:19,000 --> 00:01:25,000
+It could detect that measuring how the device is performing and whether it meets certain policies.
+
+27
+00:01:26,000 --> 00:01:33,000
+SAP can automatically verify if patches were done, check system security configurations and even exam
+
+28
+00:01:33,000 --> 00:01:35,000
+if there's some kind of flaw against it.
+
+29
+00:01:36,000 --> 00:01:38,000
+When it comes to benchmarking.
+
+30
+00:01:39,000 --> 00:01:42,000
+Benchmarking is industries best practices.
+
+31
+00:01:42,000 --> 00:01:44,000
+For example, let me give you a benchmark.
+
+32
+00:01:44,000 --> 00:01:48,000
+Websites should load in 0.5 of a second.
+
+33
+00:01:48,000 --> 00:01:49,000
+That's an industry standard.
+
+34
+00:01:49,000 --> 00:01:54,000
+How fast the general website should load when let's say there's 500 users.
+
+35
+00:01:54,000 --> 00:01:58,000
+If that's a benchmark, then your website should be able to load that quick.
+
+36
+00:01:58,000 --> 00:01:59,000
+So it's a security.
+
+37
+00:01:59,000 --> 00:02:07,000
+It's a rip in security refers to a standardized set of best practices and configuration that are known
+
+38
+00:02:07,000 --> 00:02:09,000
+to ensure a high level of security.
+
+39
+00:02:09,000 --> 00:02:18,000
+So when we talk security, generally when we configure this particular device, what is the best practices
+
+40
+00:02:18,000 --> 00:02:19,000
+for configuring this device.
+
+41
+00:02:19,000 --> 00:02:21,000
+And it's wireless.
+
+42
+00:02:21,000 --> 00:02:24,000
+That would be the benchmark that we would need to make sure that we reach that.
+
+43
+00:02:24,000 --> 00:02:30,000
+What would be the speed or the minimum, uh, resources that should always be available when this device
+
+44
+00:02:30,000 --> 00:02:32,000
+is actually being used by users.
+
+45
+00:02:32,000 --> 00:02:34,000
+Those are all benchmarks.
+
+46
+00:02:34,000 --> 00:02:40,000
+Organization uses these to configure systems and application to an industry accepted standard.
+
+47
+00:02:41,000 --> 00:02:44,000
+Now agents versus Agentless.
+
+48
+00:02:44,000 --> 00:02:49,000
+When you're monitoring systems, some software will have to install an agent.
+
+49
+00:02:49,000 --> 00:02:55,000
+Software agents are installed on servers or devices to monitor, collect and send data to a central
+
+50
+00:02:55,000 --> 00:02:55,000
+server.
+
+51
+00:02:55,000 --> 00:02:58,000
+We'll talk about that central server in a minute, but.
+
+52
+00:02:59,000 --> 00:03:06,000
+If you have a central software that goes out and grabbed all the log files from the systems, the question
+
+53
+00:03:06,000 --> 00:03:08,000
+is, how do you know that?
+
+54
+00:03:09,000 --> 00:03:12,000
+How do you know that it's actually functioning well?
+
+55
+00:03:12,000 --> 00:03:18,000
+Well, a lot of times a decentral server software generally requires some kind of software to be installed
+
+56
+00:03:18,000 --> 00:03:19,000
+on the workstation.
+
+57
+00:03:19,000 --> 00:03:24,000
+Those software on the workstation can tell the main server that it sent the log files already.
+
+58
+00:03:24,000 --> 00:03:28,000
+So software agents works well.
+
+59
+00:03:28,000 --> 00:03:31,000
+Agent less software is when there's nothing to install.
+
+60
+00:03:31,000 --> 00:03:37,000
+Agent less systems monitor the devices without installing dedicated software on them, often utilizing
+
+61
+00:03:37,000 --> 00:03:39,000
+existing protocols.
+
+62
+00:03:39,000 --> 00:03:44,000
+I'm going to tell you from my experience, a lot of these software that captures log files will generally
+
+63
+00:03:44,000 --> 00:03:48,000
+use some kind of agents on the machine, and these do a really good job.
+
+64
+00:03:48,000 --> 00:03:54,000
+Now, some famous ones actually are agent less and they also do a good job, but I like the ones with
+
+65
+00:03:54,000 --> 00:03:55,000
+the agents.
+
+66
+00:03:55,000 --> 00:04:01,000
+Comparison agent based solutions can provide more detailed data, but can be more resource intensive.
+
+67
+00:04:01,000 --> 00:04:07,000
+Yes, because they actually have a software and they can take anything they want if you have agent less.
+
+68
+00:04:07,000 --> 00:04:11,000
+In other words, the central login server doesn't install anything on any machine.
+
+69
+00:04:12,000 --> 00:04:19,000
+It's limited to whatever protocol that desktop or server is running, other servers running, and only
+
+70
+00:04:19,000 --> 00:04:21,000
+what it can get out of that.
+
+71
+00:04:21,000 --> 00:04:24,000
+So it's probably going to be less comprehensive.
+
+72
+00:04:25,000 --> 00:04:30,000
+One software that networks today has to have.
+
+73
+00:04:30,000 --> 00:04:35,000
+In my opinion, the only reason you probably wouldn't have it is the incredible cost associated with
+
+74
+00:04:35,000 --> 00:04:35,000
+it.
+
+75
+00:04:36,000 --> 00:04:38,000
+Midsize and large businesses need it.
+
+76
+00:04:38,000 --> 00:04:39,000
+Here's the thing.
+
+77
+00:04:40,000 --> 00:04:49,000
+It is humanly impossible for humans to read log files on more than a few machines.
+
+78
+00:04:50,000 --> 00:04:56,000
+Computers nowadays generate thousands of entries depending on like a server every minute.
+
+79
+00:04:57,000 --> 00:05:00,000
+It is impossible for humans to read that.
+
+80
+00:05:01,000 --> 00:05:07,000
+And, you know, I always say this if you're capturing detailed log information and nobody's reading
+
+81
+00:05:07,000 --> 00:05:13,000
+them or nothing is reading them, it kind of defeats the purpose about what they are.
+
+82
+00:05:14,000 --> 00:05:17,000
+It kind of defeats the purpose on why are you even doing that?
+
+83
+00:05:17,000 --> 00:05:22,000
+If you capture camera footage and nobody ever looks at them, it's probably never it's probably not
+
+84
+00:05:22,000 --> 00:05:26,000
+very useful because then people can steal things and you probably wouldn't know.
+
+85
+00:05:27,000 --> 00:05:27,000
+Right.
+
+86
+00:05:27,000 --> 00:05:32,000
+Or security incidents can happen in a network and no one would know because no one was up watching the
+
+87
+00:05:32,000 --> 00:05:33,000
+log files.
+
+88
+00:05:34,000 --> 00:05:39,000
+Now because it's humanly impossible to read log files.
+
+89
+00:05:39,000 --> 00:05:41,000
+We can have a computer do it.
+
+90
+00:05:41,000 --> 00:05:42,000
+We can have a piece of software.
+
+91
+00:05:42,000 --> 00:05:43,000
+Do it.
+
+92
+00:05:43,000 --> 00:05:46,000
+This thing is called security information and event management.
+
+93
+00:05:47,000 --> 00:05:54,000
+Now, what this Siem system does is that it's basically going to be a correlation of log files.
+
+94
+00:05:54,000 --> 00:06:01,000
+It's a solution that provides real time analysis of security alerts by applications and network cards.
+
+95
+00:06:01,000 --> 00:06:03,000
+It's used for log management.
+
+96
+00:06:03,000 --> 00:06:04,000
+That's its big thing.
+
+97
+00:06:04,000 --> 00:06:06,000
+It correlates events.
+
+98
+00:06:06,000 --> 00:06:10,000
+It alerts administrator and give you good reports on the systems that are out there.
+
+99
+00:06:11,000 --> 00:06:15,000
+This helps detect, understand and respond to security incidents.
+
+100
+00:06:15,000 --> 00:06:18,000
+Here's a quick picture of a Siem system.
+
+101
+00:06:18,000 --> 00:06:19,000
+So.
+
+102
+00:06:20,000 --> 00:06:22,000
+This system has what's called collectors.
+
+103
+00:06:22,000 --> 00:06:28,000
+And you see all those collectors, these collectors go out and grab the log files from all of these
+
+104
+00:06:28,000 --> 00:06:36,000
+different devices that we have, such as the IPS, the routers, the web servers, applications across
+
+105
+00:06:36,000 --> 00:06:36,000
+them.
+
+106
+00:06:36,000 --> 00:06:40,000
+They go out and grab all these log files from these devices.
+
+107
+00:06:40,000 --> 00:06:44,000
+Then what it does is it feeds it into this giant database.
+
+108
+00:06:44,000 --> 00:06:48,000
+This database now is then analyzed by a central engine.
+
+109
+00:06:48,000 --> 00:06:54,000
+The central engine will then has a beautiful dashboard on it.
+
+110
+00:06:54,000 --> 00:06:57,000
+You can go and has specific algorithms and then you can set up alerts.
+
+111
+00:06:57,000 --> 00:06:59,000
+It correlates these log files.
+
+112
+00:06:59,000 --> 00:07:02,000
+This is the thing that reads the log files for you.
+
+113
+00:07:02,000 --> 00:07:04,000
+So remember what this is.
+
+114
+00:07:04,000 --> 00:07:10,000
+Remember what a Siem system is is basically a central login system that captures all the logs and analyzes
+
+115
+00:07:10,000 --> 00:07:11,000
+it for you.
+
+116
+00:07:11,000 --> 00:07:14,000
+Now antivirus.
+
+117
+00:07:14,000 --> 00:07:16,000
+We spoke about anti-malware already.
+
+118
+00:07:16,000 --> 00:07:22,000
+When you're monitoring your network, the best one or the best things you can do is have anti-malware
+
+119
+00:07:22,000 --> 00:07:29,000
+antivirus software detect, prevent, remove viruses, including all types of worms and trojans.
+
+120
+00:07:29,000 --> 00:07:33,000
+But remember, antivirus sends alerts a lot of corporate antivirus.
+
+121
+00:07:33,000 --> 00:07:40,000
+What they do is they have a central server that then installs agent antivirus on all the machines that
+
+122
+00:07:40,000 --> 00:07:42,000
+if you have a workstation, like in the corner over there.
+
+123
+00:07:43,000 --> 00:07:45,000
+That gets a potential virus.
+
+124
+00:07:45,000 --> 00:07:47,000
+It then reports it back to the central server.
+
+125
+00:07:47,000 --> 00:07:50,000
+This way we can easily pick up that.
+
+126
+00:07:50,000 --> 00:07:50,000
+You know what?
+
+127
+00:07:50,000 --> 00:07:53,000
+Something is wrong on that particular machine.
+
+128
+00:07:54,000 --> 00:07:59,000
+Another important software you're going to want to know for your exam is something we call data loss
+
+129
+00:07:59,000 --> 00:08:01,000
+prevention or DLP.
+
+130
+00:08:01,000 --> 00:08:03,000
+This can get very big and very complex.
+
+131
+00:08:03,000 --> 00:08:07,000
+I'm going to try to give you a simple explanation for your exam DLP.
+
+132
+00:08:07,000 --> 00:08:16,000
+Identify, monitor and protect data in use in motion and arrest through deep content inspection and
+
+133
+00:08:16,000 --> 00:08:18,000
+contextual security analysis.
+
+134
+00:08:19,000 --> 00:08:24,000
+Main thing this helps to prevent sensitive data from being lost, misused, or accessed by unauthorized
+
+135
+00:08:24,000 --> 00:08:24,000
+users.
+
+136
+00:08:25,000 --> 00:08:27,000
+If you're wondering, Andrew, what the hell is all that mean?
+
+137
+00:08:27,000 --> 00:08:29,000
+I'm going to give you a couple examples.
+
+138
+00:08:29,000 --> 00:08:31,000
+So here's what DLP does.
+
+139
+00:08:32,000 --> 00:08:40,000
+DLP stops data from leaving the organization that shouldn't be leaving DLP.
+
+140
+00:08:40,000 --> 00:08:46,000
+Software is configured to stop things like emails going out that contains sensitive data.
+
+141
+00:08:46,000 --> 00:08:56,000
+For example, let's say you have a user that types credit card numbers and then emails it out to customers
+
+142
+00:08:56,000 --> 00:08:57,000
+or vendors.
+
+143
+00:08:57,000 --> 00:09:02,000
+Maybe you don't want that and you shouldn't have that because it's clear text anytime somebody tries
+
+144
+00:09:02,000 --> 00:09:08,000
+to send confidential data from your organization out.
+
+145
+00:09:08,000 --> 00:09:13,000
+DLP software can stop that, or at least alert them, hey, you shouldn't do that.
+
+146
+00:09:14,000 --> 00:09:18,000
+On our we use office 365.
+
+147
+00:09:18,000 --> 00:09:26,000
+Office 365 has policies that you can configure for DLP that if somebody tries to attempt to send, uh,
+
+148
+00:09:26,000 --> 00:09:31,000
+numbers that looks like credit card numbers, Social Security numbers and health care information,
+
+149
+00:09:31,000 --> 00:09:34,000
+it can actually detect that and stop it from happening.
+
+150
+00:09:34,000 --> 00:09:40,000
+DLP stops confidential or sensitive data from leaving the organization.
+
+151
+00:09:40,000 --> 00:09:41,000
+How does it do it?
+
+152
+00:09:41,000 --> 00:09:45,000
+It does it by content inspection.
+
+153
+00:09:45,000 --> 00:09:48,000
+It's looking to see okay, what exactly is that particular content.
+
+154
+00:09:50,000 --> 00:09:57,000
+That way the data the sensitive data is never lost or misused or sent to unauthorized users.
+
+155
+00:09:57,000 --> 00:10:00,000
+So DLP is very famous in organizations today.
+
+156
+00:10:00,000 --> 00:10:09,000
+If you run companies where you have a high potential that your users can send confidential data such
+
+157
+00:10:09,000 --> 00:10:16,000
+as people's email and not even a credit card, um, health information, even your own company's confidential
+
+158
+00:10:16,000 --> 00:10:17,000
+data.
+
+159
+00:10:17,000 --> 00:10:20,000
+Configure and install DLP software.
+
+160
+00:10:21,000 --> 00:10:26,000
+Simple network management protocol SNMp traps.
+
+161
+00:10:26,000 --> 00:10:32,000
+So SNMp is basically a way to track and correlate logs.
+
+162
+00:10:32,000 --> 00:10:38,000
+So these traps are alerts sent by network devices to management stations indicate an event or change
+
+163
+00:10:38,000 --> 00:10:39,000
+has occurred.
+
+164
+00:10:40,000 --> 00:10:42,000
+The use of manager in a monitoring network and devices.
+
+165
+00:10:42,000 --> 00:10:49,000
+Notice is network management protocol for managing and monitoring devices, helping administrators know
+
+166
+00:10:49,000 --> 00:10:50,000
+the health of the device.
+
+167
+00:10:50,000 --> 00:10:57,000
+So if anybody changes anything on the device, whether it's configurations of the devices or something
+
+168
+00:10:57,000 --> 00:11:02,000
+that you set up like a threshold, as happened on on the device, this particular trap can send you
+
+169
+00:11:02,000 --> 00:11:03,000
+alerts.
+
+170
+00:11:05,000 --> 00:11:06,000
+Net flow.
+
+171
+00:11:06,000 --> 00:11:08,000
+Net flow is basically a protocol.
+
+172
+00:11:08,000 --> 00:11:14,000
+Another Cisco thing for collecting IP traffic information and monitoring traffic flow.
+
+173
+00:11:15,000 --> 00:11:20,000
+It's valuable for network traffic analysis, helping to understand traffic pattern usage and detecting
+
+174
+00:11:20,000 --> 00:11:20,000
+anomalies.
+
+175
+00:11:21,000 --> 00:11:26,000
+Now NetFlow, I want you guys to know for your exam that what this is going to do.
+
+176
+00:11:26,000 --> 00:11:31,000
+Its main job is about analyzing network traffic.
+
+177
+00:11:31,000 --> 00:11:36,000
+So if you utilize a lot of Cisco equipment, this is something you can use to help you monitor your
+
+178
+00:11:36,000 --> 00:11:36,000
+traffic.
+
+179
+00:11:37,000 --> 00:11:44,000
+Vulnerability scanners we covered already things like the Nexus security scanner tools to help us assess
+
+180
+00:11:44,000 --> 00:11:47,000
+computers and find non vulnerabilities on our systems.
+
+181
+00:11:47,000 --> 00:11:53,000
+This we went over when we talked about vulnerabilities in the previous uh, earlier in the class.
+
+182
+00:11:53,000 --> 00:11:53,000
+All right.
+
+183
+00:11:53,000 --> 00:12:00,000
+So we just went over quite a lot of things there when it comes to different kinds of alerting tools.
+
+184
+00:12:00,000 --> 00:12:02,000
+Although a lot some of it was repeated.
+
+185
+00:12:02,000 --> 00:12:08,000
+Keep in mind these are things that we can use to keep us alert and monitor our systems.
+
diff --git a/16 - Alerting and Monitoring IT/004 Quick Quiz.html b/16 - Alerting and Monitoring IT/004 Quick Quiz.html
new file mode 100644
index 0000000000000000000000000000000000000000..25840e6c4b0d9155337aa1717f730fb2f27085fe
--- /dev/null
+++ b/16 - Alerting and Monitoring IT/004 Quick Quiz.html
@@ -0,0 +1,479 @@
+
+
+
+
+
+
+ Quiz
+
+
+
+
+
+
+
+
+ Score: 999 of
+ 999%
+
+ Correct: 999
+ Incorrect: 999
+
+
+
+
+
+
+
+
+
+
diff --git a/17 - Enhance Security/001 Firewall Configuration OB 4.5_en.srt b/17 - Enhance Security/001 Firewall Configuration OB 4.5_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..ed5029356e96515d58ba828d74238e12a9ae561b
--- /dev/null
+++ b/17 - Enhance Security/001 Firewall Configuration OB 4.5_en.srt
@@ -0,0 +1,1160 @@
+1
+00:00:00,000 --> 00:00:07,000
+In this video, I'm going to be talking about firewalls in particularly exactly how do they operate?
+
+2
+00:00:07,000 --> 00:00:12,000
+How do they block traffic from coming into your network and destroying your systems.
+
+3
+00:00:12,000 --> 00:00:20,000
+So we're going to be talking about things such as access rules, access lists, the protocols and screened
+
+4
+00:00:20,000 --> 00:00:21,000
+subnet or DMZ.
+
+5
+00:00:21,000 --> 00:00:25,000
+Now before I get started here, I really want to discuss something with you.
+
+6
+00:00:25,000 --> 00:00:29,000
+I am actually going to show you how to configure the Sonicwall.
+
+7
+00:00:29,000 --> 00:00:32,000
+I'm going to add a rule to it and show you how that's done, but I'm going to do that towards the end
+
+8
+00:00:32,000 --> 00:00:33,000
+of the video.
+
+9
+00:00:34,000 --> 00:00:41,000
+I want you guys to remember your exam will not ask you to configure firewalls.
+
+10
+00:00:41,000 --> 00:00:50,000
+No security vendor neutral security exam will ever do that unless the only certification that does that
+
+11
+00:00:50,000 --> 00:00:56,000
+is if you're taking a certification from Sonicwall, from Cisco, from Palo Alto, and so on.
+
+12
+00:00:56,000 --> 00:01:01,000
+The reason is because every single firewall is configured differently.
+
+13
+00:01:01,000 --> 00:01:06,000
+So the configuration that I'm going to show you at the end of the video is just for your visualization
+
+14
+00:01:06,000 --> 00:01:06,000
+purposes.
+
+15
+00:01:06,000 --> 00:01:08,000
+So you can see exactly how it's done.
+
+16
+00:01:08,000 --> 00:01:13,000
+But remember, if you go to configure a Sonicwall and it's running on a different version, it's a different
+
+17
+00:01:13,000 --> 00:01:14,000
+device, it will look different.
+
+18
+00:01:14,000 --> 00:01:19,000
+And if you do any other firewall but a sonicwall, I'm pretty sure it's going to be completely different.
+
+19
+00:01:19,000 --> 00:01:24,000
+Although the theory is the same, the the way the configurations are done is different.
+
+20
+00:01:24,000 --> 00:01:25,000
+So let's get started.
+
+21
+00:01:26,000 --> 00:01:28,000
+When I'm ready to configure it, I will let you know.
+
+22
+00:01:28,000 --> 00:01:29,000
+So if you want to watch it, you you could.
+
+23
+00:01:29,000 --> 00:01:31,000
+If not you don't have to.
+
+24
+00:01:31,000 --> 00:01:32,000
+Firewall.
+
+25
+00:01:32,000 --> 00:01:35,000
+We talked about firewalls earlier in the class.
+
+26
+00:01:35,000 --> 00:01:41,000
+By default there are security devices that monitors and filters incoming and outgoing traffic or particularly
+
+27
+00:01:41,000 --> 00:01:42,000
+network traffic.
+
+28
+00:01:42,000 --> 00:01:46,000
+They basically have to establish organization security policies.
+
+29
+00:01:46,000 --> 00:01:48,000
+What we let in and what we let out.
+
+30
+00:01:48,000 --> 00:01:51,000
+At the most basic, it's a barrier between public and private.
+
+31
+00:01:51,000 --> 00:01:55,000
+At the most basic level, it blocks all ports and all traffic coming in.
+
+32
+00:01:55,000 --> 00:01:56,000
+How does it do it?
+
+33
+00:01:56,000 --> 00:02:00,000
+Well, it does it with rules, access lists and protocols, these three things.
+
+34
+00:02:00,000 --> 00:02:03,000
+And then we'll talk about what exactly is a screen subnet.
+
+35
+00:02:04,000 --> 00:02:06,000
+So let's take a look.
+
+36
+00:02:06,000 --> 00:02:09,000
+There's something we call rules and access lists.
+
+37
+00:02:09,000 --> 00:02:10,000
+All right.
+
+38
+00:02:10,000 --> 00:02:13,000
+How do we implement rules?
+
+39
+00:02:13,000 --> 00:02:13,000
+All right.
+
+40
+00:02:13,000 --> 00:02:15,000
+We do that with the access list.
+
+41
+00:02:15,000 --> 00:02:16,000
+Let's take a look.
+
+42
+00:02:16,000 --> 00:02:17,000
+What is rules?
+
+43
+00:02:17,000 --> 00:02:22,000
+Firewall rules are specific configurations that control how the firewall operates.
+
+44
+00:02:22,000 --> 00:02:26,000
+These rules determine which traffic should be allowed or block.
+
+45
+00:02:26,000 --> 00:02:30,000
+Now these rules are placed on an access list.
+
+46
+00:02:30,000 --> 00:02:37,000
+The access list are a series of commands or rules applied to the firewall, which would selectively
+
+47
+00:02:37,000 --> 00:02:42,000
+filter traffic based on the source and destination address protocols and ports.
+
+48
+00:02:42,000 --> 00:02:48,000
+Now, for example, a rule might specify that all inbound traffic on port 80 is allowed while they don't
+
+49
+00:02:48,000 --> 00:02:49,000
+allow port 23.
+
+50
+00:02:49,000 --> 00:02:52,000
+Now you have to know ports and protocols.
+
+51
+00:02:52,000 --> 00:02:55,000
+Ports and protocol is how network communications are done.
+
+52
+00:02:55,000 --> 00:02:57,000
+For example, web traffic comes in on port 80.
+
+53
+00:02:57,000 --> 00:03:00,000
+Secure web traffic on port 443.
+
+54
+00:03:02,000 --> 00:03:04,000
+Now screened subnet.
+
+55
+00:03:04,000 --> 00:03:13,000
+This is important to know because if your organization is going to be doing any kind of, uh, external
+
+56
+00:03:13,000 --> 00:03:21,000
+server hosting internally, which means you actually keep external servers in your premises, you cannot
+
+57
+00:03:21,000 --> 00:03:22,000
+have let's move that down.
+
+58
+00:03:22,000 --> 00:03:28,000
+You cannot have those externally facing servers in your lab.
+
+59
+00:03:28,000 --> 00:03:29,000
+Let me show you guys this diagram.
+
+60
+00:03:29,000 --> 00:03:30,000
+Watch this.
+
+61
+00:03:30,000 --> 00:03:36,000
+So this external router which is connected to the external network this is going to connect to the internet.
+
+62
+00:03:37,000 --> 00:03:42,000
+When traffic from the internet comes into your network because they want to access.
+
+63
+00:03:42,000 --> 00:03:44,000
+This is a web server, mail server.
+
+64
+00:03:44,000 --> 00:03:45,000
+This is a DNS server.
+
+65
+00:03:45,000 --> 00:03:48,000
+When traffic from the internet comes in and they want to access.
+
+66
+00:03:48,000 --> 00:03:50,000
+This is your firewall, by the way.
+
+67
+00:03:50,000 --> 00:03:54,000
+Uh, when they want to access this web server, they go here.
+
+68
+00:03:54,000 --> 00:03:56,000
+This is the DMZ.
+
+69
+00:03:56,000 --> 00:04:00,000
+A DMZ is known as a screen subnet or demilitarized zone.
+
+70
+00:04:00,000 --> 00:04:01,000
+They're going to go here.
+
+71
+00:04:01,000 --> 00:04:04,000
+They're going to grab the web page and they're going to go right back out.
+
+72
+00:04:04,000 --> 00:04:10,000
+Now this is good because notice that you don't have public traffic coming into your internal LAN.
+
+73
+00:04:10,000 --> 00:04:15,000
+If the internal LAN wants to access web pages or something, they're just going to go here and it's
+
+74
+00:04:15,000 --> 00:04:17,000
+going to give it right back to them.
+
+75
+00:04:17,000 --> 00:04:25,000
+This way you never have internal I'm sorry, external web traffic coming in to your internal network.
+
+76
+00:04:25,000 --> 00:04:30,000
+Now you can actually do this on a small device like this okay.
+
+77
+00:04:30,000 --> 00:04:30,000
+So keep that in mind.
+
+78
+00:04:30,000 --> 00:04:32,000
+I'm actually going to show you that in a few minutes.
+
+79
+00:04:32,000 --> 00:04:34,000
+So what exactly is this?
+
+80
+00:04:34,000 --> 00:04:40,000
+Well, a screen subnet or DMZ is a physical or logical segmentation subnetwork that contains and exposes
+
+81
+00:04:40,000 --> 00:04:43,000
+an organization external facing services.
+
+82
+00:04:43,000 --> 00:04:48,000
+Those external facing services, 99% of the time is going to be web servers to an untrusted network.
+
+83
+00:04:48,000 --> 00:04:54,000
+Usually the internet firewalls are configured to to allow limited traffic from the DMZ to the internal
+
+84
+00:04:54,000 --> 00:04:55,000
+network with strict rules.
+
+85
+00:04:55,000 --> 00:05:01,000
+Sometimes we might allow certain traffic from the DMZ to that internal.
+
+86
+00:05:01,000 --> 00:05:03,000
+So that's what this is.
+
+87
+00:05:03,000 --> 00:05:04,000
+Why do we want a DMZ?
+
+88
+00:05:04,000 --> 00:05:08,000
+DMZ are used to host publicly accessible servers.
+
+89
+00:05:09,000 --> 00:05:11,000
+Um, if you have any server.
+
+90
+00:05:12,000 --> 00:05:14,000
+That is going to be publicly accessible.
+
+91
+00:05:14,000 --> 00:05:19,000
+Web servers, mail servers, DNS servers more than likely.
+
+92
+00:05:19,000 --> 00:05:22,000
+You can also have different kinds of application servers.
+
+93
+00:05:22,000 --> 00:05:25,000
+Maybe you have specific people outside it's going to access.
+
+94
+00:05:25,000 --> 00:05:26,000
+Put them in the DMZ.
+
+95
+00:05:27,000 --> 00:05:28,000
+Okay.
+
+96
+00:05:28,000 --> 00:05:37,000
+Now the part of the video that's remember for your exam before we move on to this, a firewall allows
+
+97
+00:05:37,000 --> 00:05:39,000
+traffic in and out based on the rules.
+
+98
+00:05:39,000 --> 00:05:43,000
+These rules are going to be basically stored on what's called an access list.
+
+99
+00:05:43,000 --> 00:05:46,000
+You have to know ports and protocol when configuring your rules.
+
+100
+00:05:46,000 --> 00:05:49,000
+These rules is what allow and denies things coming in and out.
+
+101
+00:05:49,000 --> 00:05:54,000
+If you're hosting publicly accessible servers, make sure you implement a DMZ.
+
+102
+00:05:54,000 --> 00:05:58,000
+Don't put publicly accessible servers in the actual LAN itself.
+
+103
+00:05:59,000 --> 00:06:02,000
+All right, if you're done, you can turn the video off right now.
+
+104
+00:06:02,000 --> 00:06:04,000
+That's all you need to know for your exam.
+
+105
+00:06:04,000 --> 00:06:08,000
+But if you want to see how to configure this thing, let's have some fun with this device.
+
+106
+00:06:09,000 --> 00:06:11,000
+Let's take a look at an access list.
+
+107
+00:06:11,000 --> 00:06:14,000
+Let's make a quick rule inside of it.
+
+108
+00:06:14,000 --> 00:06:15,000
+So let's go into this.
+
+109
+00:06:16,000 --> 00:06:17,000
+Uh, I have to be shut off.
+
+110
+00:06:17,000 --> 00:06:18,000
+Presentation.
+
+111
+00:06:20,000 --> 00:06:21,000
+All right, here we go.
+
+112
+00:06:21,000 --> 00:06:22,000
+Where are we?
+
+113
+00:06:22,000 --> 00:06:23,000
+Where are we?
+
+114
+00:06:23,000 --> 00:06:23,000
+Where are we?
+
+115
+00:06:23,000 --> 00:06:25,000
+All right, here we go.
+
+116
+00:06:25,000 --> 00:06:27,000
+To our sonic wall.
+
+117
+00:06:27,000 --> 00:06:29,000
+All right, so it's logged me out.
+
+118
+00:06:29,000 --> 00:06:30,000
+Okay, so let's log in to the sonic world.
+
+119
+00:06:30,000 --> 00:06:33,000
+I'm actually directly connected to this thing.
+
+120
+00:06:40,000 --> 00:06:40,000
+Okay.
+
+121
+00:06:40,000 --> 00:06:41,000
+It's coming on up.
+
+122
+00:06:42,000 --> 00:06:47,000
+We got to make sure we're in manage because we want to manage the actual firewall.
+
+123
+00:06:47,000 --> 00:06:50,000
+Uh, and I want to go here right now.
+
+124
+00:06:50,000 --> 00:06:54,000
+Now, you'll notice that you have a lot of options on this section of it.
+
+125
+00:06:55,000 --> 00:06:59,000
+And I'm going to go to rules and I want to show you guys the rules.
+
+126
+00:06:59,000 --> 00:07:02,000
+Notice it says access rules.
+
+127
+00:07:02,000 --> 00:07:03,000
+All right.
+
+128
+00:07:03,000 --> 00:07:06,000
+So you notice if we come here these are all the access rules.
+
+129
+00:07:06,000 --> 00:07:10,000
+This is basically an access a list of all the rules the access list.
+
+130
+00:07:11,000 --> 00:07:15,000
+You'll notice that these are all the rules that it has.
+
+131
+00:07:15,000 --> 00:07:16,000
+And there is a lot.
+
+132
+00:07:16,000 --> 00:07:20,000
+But I'll just go through some of them to show you guys what it is.
+
+133
+00:07:20,000 --> 00:07:20,000
+So.
+
+134
+00:07:22,000 --> 00:07:22,000
+I'll check this out.
+
+135
+00:07:23,000 --> 00:07:26,000
+Notice how they have from DMZ to DMZ.
+
+136
+00:07:26,000 --> 00:07:28,000
+They're going to allow this.
+
+137
+00:07:28,000 --> 00:07:29,000
+You can see that.
+
+138
+00:07:30,000 --> 00:07:32,000
+Uh, DMZ to land denied.
+
+139
+00:07:32,000 --> 00:07:32,000
+So what this is doing?
+
+140
+00:07:32,000 --> 00:07:35,000
+No traffic from the DMZ can come into the land.
+
+141
+00:07:36,000 --> 00:07:38,000
+DMs to Wang.
+
+142
+00:07:38,000 --> 00:07:42,000
+We're going to allow that so DMs can go out to the Wang ports.
+
+143
+00:07:42,000 --> 00:07:47,000
+Um, lan to DMs we're going to allow anything to land can hit the DMs.
+
+144
+00:07:48,000 --> 00:07:50,000
+Uh, we also have land to land.
+
+145
+00:07:50,000 --> 00:07:51,000
+It's going to allow this.
+
+146
+00:07:51,000 --> 00:07:51,000
+This is within.
+
+147
+00:07:51,000 --> 00:07:53,000
+This is on this particular interface, though.
+
+148
+00:07:54,000 --> 00:07:55,000
+Um.
+
+149
+00:07:55,000 --> 00:07:56,000
+Let's go.
+
+150
+00:07:56,000 --> 00:07:56,000
+Keep going down.
+
+151
+00:07:56,000 --> 00:08:00,000
+These are all the access routes, you guys lanta SSL.
+
+152
+00:08:00,000 --> 00:08:03,000
+So folks in the land can speak to people coming in through this.
+
+153
+00:08:03,000 --> 00:08:05,000
+Has an SSL VPN built into it.
+
+154
+00:08:05,000 --> 00:08:07,000
+People on the land can go out to the internet.
+
+155
+00:08:07,000 --> 00:08:11,000
+Notice how it says that just to not spend too long on rules here.
+
+156
+00:08:11,000 --> 00:08:15,000
+But notice Wang to DMZ deny right now that is being denied.
+
+157
+00:08:16,000 --> 00:08:20,000
+That means they're not allowed any traffic from Wang to DMZ.
+
+158
+00:08:21,000 --> 00:08:23,000
+That means any traffic coming through the Wang will not go.
+
+159
+00:08:23,000 --> 00:08:26,000
+We have to specifically allow what we want to go into the DMZ.
+
+160
+00:08:26,000 --> 00:08:31,000
+Any traffic from the Wang, from the internet trying to come onto your land is denied.
+
+161
+00:08:31,000 --> 00:08:34,000
+Now, from lan to Wang, I'm sorry.
+
+162
+00:08:34,000 --> 00:08:38,000
+From Wang internet to the LAN is denied by default.
+
+163
+00:08:38,000 --> 00:08:40,000
+That's how all firewalls work.
+
+164
+00:08:40,000 --> 00:08:44,000
+They don't allow anything from the public coming in to the internal network.
+
+165
+00:08:44,000 --> 00:08:47,000
+These are how all firewalls are designed.
+
+166
+00:08:48,000 --> 00:08:49,000
+Okay.
+
+167
+00:08:49,000 --> 00:08:51,000
+Let's go ahead and add a server.
+
+168
+00:08:51,000 --> 00:09:00,000
+So let's say if I go back to this, uh, if I go back to this presentation here that I want to show
+
+169
+00:09:00,000 --> 00:09:01,000
+you guys.
+
+170
+00:09:02,000 --> 00:09:05,000
+Take a look at this presentation here that we have.
+
+171
+00:09:06,000 --> 00:09:09,000
+Because we want to implement this, let's say.
+
+172
+00:09:10,000 --> 00:09:11,000
+We have.
+
+173
+00:09:11,000 --> 00:09:14,000
+We want to implement a web server right here.
+
+174
+00:09:15,000 --> 00:09:15,000
+All right.
+
+175
+00:09:15,000 --> 00:09:17,000
+We have the external port, the Wang port.
+
+176
+00:09:17,000 --> 00:09:20,000
+This green box is a firewall.
+
+177
+00:09:20,000 --> 00:09:21,000
+We want to put a.
+
+178
+00:09:21,000 --> 00:09:26,000
+We want to put a web server in the DMZ to be accessible from the outside world.
+
+179
+00:09:26,000 --> 00:09:27,000
+How are we going to do that?
+
+180
+00:09:27,000 --> 00:09:29,000
+Well, we have to configure the firewall.
+
+181
+00:09:29,000 --> 00:09:32,000
+In this particular firewall we got to add first an object.
+
+182
+00:09:32,000 --> 00:09:35,000
+So we're going to go to address object.
+
+183
+00:09:35,000 --> 00:09:36,000
+We're going to say add.
+
+184
+00:09:37,000 --> 00:09:43,000
+We're going to say, let's put Andrew's web.
+
+185
+00:09:44,000 --> 00:09:45,000
+It's my web server.
+
+186
+00:09:45,000 --> 00:09:53,000
+It's on a DMZ to host its IP address, give it a quick IP address, uh, 20 that, let's say 250.
+
+187
+00:09:56,000 --> 00:09:58,000
+Okay, so it's ah Andrew's web.
+
+188
+00:09:58,000 --> 00:09:59,000
+All right.
+
+189
+00:09:59,000 --> 00:10:00,000
+Then add an object.
+
+190
+00:10:00,000 --> 00:10:01,000
+Okay.
+
+191
+00:10:01,000 --> 00:10:01,000
+Andrew's web.
+
+192
+00:10:01,000 --> 00:10:04,000
+So what we want to do now this thing is in the DMZ.
+
+193
+00:10:04,000 --> 00:10:06,000
+We want to say when traffic comes in.
+
+194
+00:10:06,000 --> 00:10:10,000
+Now I know you guys can barely see this, but where is that camera?
+
+195
+00:10:10,000 --> 00:10:12,000
+Let me show you guys some stuff.
+
+196
+00:10:12,000 --> 00:10:13,000
+Hide my face to the camera.
+
+197
+00:10:13,000 --> 00:10:14,000
+Focuses on that.
+
+198
+00:10:14,000 --> 00:10:15,000
+Ah.
+
+199
+00:10:16,000 --> 00:10:21,000
+Okay, so it's a little hard to see there, but you could see that.
+
+200
+00:10:23,000 --> 00:10:23,000
+It.
+
+201
+00:10:23,000 --> 00:10:24,000
+Focus.
+
+202
+00:10:24,000 --> 00:10:24,000
+Come on.
+
+203
+00:10:24,000 --> 00:10:25,000
+Autofocus.
+
+204
+00:10:25,000 --> 00:10:26,000
+Do your job.
+
+205
+00:10:26,000 --> 00:10:26,000
+All right.
+
+206
+00:10:26,000 --> 00:10:28,000
+We're not going to get that to autofocus.
+
+207
+00:10:28,000 --> 00:10:32,000
+So this port here I know you guys can see that but.
+
+208
+00:10:33,000 --> 00:10:35,000
+You see, it comes on and off.
+
+209
+00:10:35,000 --> 00:10:36,000
+It doesn't like me.
+
+210
+00:10:38,000 --> 00:10:40,000
+Uh, hide my face.
+
+211
+00:10:40,000 --> 00:10:40,000
+Yeah.
+
+212
+00:10:40,000 --> 00:10:40,000
+So it's an auto.
+
+213
+00:10:40,000 --> 00:10:43,000
+It's a camera that focuses on faces all the time.
+
+214
+00:10:43,000 --> 00:10:43,000
+All right.
+
+215
+00:10:43,000 --> 00:10:44,000
+Any which way?
+
+216
+00:10:44,000 --> 00:10:47,000
+Uh, this port, this port here and this port.
+
+217
+00:10:47,000 --> 00:10:48,000
+All right.
+
+218
+00:10:48,000 --> 00:10:49,000
+This one says lan.
+
+219
+00:10:49,000 --> 00:10:50,000
+There it is.
+
+220
+00:10:50,000 --> 00:10:51,000
+This one says Wang.
+
+221
+00:10:52,000 --> 00:10:52,000
+All right.
+
+222
+00:10:52,000 --> 00:10:52,000
+You're gonna.
+
+223
+00:10:52,000 --> 00:10:56,000
+If you want a DMZ port, you have to designate a port here as DMZ.
+
+224
+00:10:56,000 --> 00:10:59,000
+So we haven't configured that though.
+
+225
+00:10:59,000 --> 00:11:01,000
+So you would need to plug in your internet into this port.
+
+226
+00:11:01,000 --> 00:11:03,000
+This would be a internet router.
+
+227
+00:11:03,000 --> 00:11:08,000
+You'd plug a switch into this LAN port and then give all your computers access to this.
+
+228
+00:11:09,000 --> 00:11:10,000
+Did I switch plugged in here.
+
+229
+00:11:10,000 --> 00:11:13,000
+You can also plug a switch like um, I have my computer plugged in.
+
+230
+00:11:13,000 --> 00:11:16,000
+You would also plug a switch into this and then designate that as the DMZ.
+
+231
+00:11:16,000 --> 00:11:23,000
+And then plug your web server into that particular port is how this would be physically configured.
+
+232
+00:11:23,000 --> 00:11:28,000
+Now let's go into our rules and we're going to say access rules.
+
+233
+00:11:28,000 --> 00:11:30,000
+And we're going to say add.
+
+234
+00:11:32,000 --> 00:11:39,000
+So we want to give we want to see traffic coming in from the Wang port is going to go into the DMZ port,
+
+235
+00:11:40,000 --> 00:11:42,000
+but it has to be for that web server.
+
+236
+00:11:42,000 --> 00:11:43,000
+So we're going to give it a name.
+
+237
+00:11:43,000 --> 00:11:45,000
+Uh, Andrew's web.
+
+238
+00:11:47,000 --> 00:11:52,000
+And from the DMZ to.
+
+239
+00:11:53,000 --> 00:11:53,000
+Nope.
+
+240
+00:11:53,000 --> 00:11:54,000
+Said that wrong.
+
+241
+00:11:54,000 --> 00:11:56,000
+From the Wang to the DMZ.
+
+242
+00:11:58,000 --> 00:12:04,000
+The sauce is going to be Http, not just H, but https service.
+
+243
+00:12:04,000 --> 00:12:05,000
+The same thing.
+
+244
+00:12:08,000 --> 00:12:11,000
+Https the source.
+
+245
+00:12:12,000 --> 00:12:14,000
+It's going to be any Wang IP address.
+
+246
+00:12:14,000 --> 00:12:20,000
+We can even you can even granular it down to only certain IP addresses from certain external IPS.
+
+247
+00:12:20,000 --> 00:12:24,000
+We don't want that the destination we're going to have to go.
+
+248
+00:12:24,000 --> 00:12:29,000
+We're going to say well don't send it anywhere but the Android web server.
+
+249
+00:12:29,000 --> 00:12:31,000
+In the DMZ.
+
+250
+00:12:31,000 --> 00:12:32,000
+That's it.
+
+251
+00:12:32,000 --> 00:12:33,000
+We've configured it.
+
+252
+00:12:33,000 --> 00:12:34,000
+We're going to go ahead.
+
+253
+00:12:34,000 --> 00:12:35,000
+Now we're going to say add.
+
+254
+00:12:39,000 --> 00:12:40,000
+All done.
+
+255
+00:12:40,000 --> 00:12:41,000
+Please check the table.
+
+256
+00:12:41,000 --> 00:12:42,000
+We're going to close that out.
+
+257
+00:12:43,000 --> 00:12:50,000
+And we should have somewhere in here that something coming from the Wang.
+
+258
+00:12:51,000 --> 00:12:52,000
+It's going to go to the DMZ.
+
+259
+00:12:53,000 --> 00:12:54,000
+It's going to allow it.
+
+260
+00:12:54,000 --> 00:12:57,000
+Now I want you guys to notice something.
+
+261
+00:12:57,000 --> 00:13:09,000
+Notice that this sits on top of this rule that says Andrews Webb is Wang to DMZ is allowed only Https.
+
+262
+00:13:09,000 --> 00:13:14,000
+The next rule says Wang DMZ any any any is denied.
+
+263
+00:13:14,000 --> 00:13:19,000
+Now it's important to see the way firewall rules work is they work in an order.
+
+264
+00:13:19,000 --> 00:13:25,000
+In other words, when traffic comes in, any traffic that comes in through a firewall, a firewall processes
+
+265
+00:13:25,000 --> 00:13:29,000
+that traffic based on the order that those rules are written.
+
+266
+00:13:30,000 --> 00:13:35,000
+So right now I have a rule that says if you're coming on port, if somebody wants to come in on port,
+
+267
+00:13:35,000 --> 00:13:42,000
+um, 443 over Https, send it to this machine in the DMZ.
+
+268
+00:13:42,000 --> 00:13:43,000
+Anything else?
+
+269
+00:13:43,000 --> 00:13:44,000
+Deny it.
+
+270
+00:13:45,000 --> 00:13:46,000
+Okay, because that's what this specifies.
+
+271
+00:13:46,000 --> 00:13:56,000
+It's like if any traffic is coming in on where is it any traffic coming from, all Wang IP addresses
+
+272
+00:13:56,000 --> 00:13:57,000
+that are coming in.
+
+273
+00:13:58,000 --> 00:14:01,000
+From the internet, particularly on this Wan port.
+
+274
+00:14:01,000 --> 00:14:02,000
+Send it.
+
+275
+00:14:02,000 --> 00:14:04,000
+If it's Https, send it to this machine.
+
+276
+00:14:04,000 --> 00:14:07,000
+The next one says, well then anything else, just deny it.
+
+277
+00:14:07,000 --> 00:14:08,000
+That's what he's deny.
+
+278
+00:14:08,000 --> 00:14:10,000
+Statements are there.
+
+279
+00:14:10,000 --> 00:14:12,000
+In other words, they're not going to allow anything else.
+
+280
+00:14:12,000 --> 00:14:13,000
+Everything else they can allow.
+
+281
+00:14:13,000 --> 00:14:17,000
+So firewall rules are processed in the order that is listed in.
+
+282
+00:14:19,000 --> 00:14:19,000
+Okay.
+
+283
+00:14:20,000 --> 00:14:22,000
+That's a quick way.
+
+284
+00:14:22,000 --> 00:14:27,000
+Quick video on how to configure this, just so you could see that firewalls do work on rules.
+
+285
+00:14:27,000 --> 00:14:31,000
+Now you do not need to know this for your exam.
+
+286
+00:14:31,000 --> 00:14:34,000
+In fact this video is touching 15 minutes.
+
+287
+00:14:34,000 --> 00:14:39,000
+You don't need to know this for your exam, but understand that firewall works with rules.
+
+288
+00:14:39,000 --> 00:14:43,000
+Without these rules, these firewalls wouldn't know what to do.
+
+289
+00:14:43,000 --> 00:14:48,000
+When you want to set up the organization security policy, you have to edit, change and manipulate
+
+290
+00:14:49,000 --> 00:14:50,000
+the rules.
+
diff --git a/17 - Enhance Security/002 Web Filters OB 4.5_en.srt b/17 - Enhance Security/002 Web Filters OB 4.5_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..14f3524b307a9d52a6008e961239f3d9e26829d8
--- /dev/null
+++ b/17 - Enhance Security/002 Web Filters OB 4.5_en.srt
@@ -0,0 +1,352 @@
+1
+00:00:00,000 --> 00:00:02,000
+I said this earlier in the class.
+
+2
+00:00:02,000 --> 00:00:05,000
+My mother have always told me the more choices, the more mistakes.
+
+3
+00:00:05,000 --> 00:00:10,000
+When you go into an organization and you start working, they should limit your choice of where you
+
+4
+00:00:10,000 --> 00:00:11,000
+can go and what you can do.
+
+5
+00:00:11,000 --> 00:00:16,000
+The more websites you can access, the more likely you can introduce malware into your organization.
+
+6
+00:00:16,000 --> 00:00:19,000
+Now look at it from a security professional perspective.
+
+7
+00:00:19,000 --> 00:00:25,000
+We want to limit websites that users can access, and they should only be accessed in websites or have
+
+8
+00:00:25,000 --> 00:00:28,000
+access to websites that allows them to get their job done.
+
+9
+00:00:28,000 --> 00:00:32,000
+Users don't come to your organization to play and have fun.
+
+10
+00:00:32,000 --> 00:00:34,000
+That's what being at home for.
+
+11
+00:00:34,000 --> 00:00:35,000
+They come to work.
+
+12
+00:00:35,000 --> 00:00:42,000
+What we want to do is we want to use web filtering technologies and different kinds of servers to control
+
+13
+00:00:42,000 --> 00:00:46,000
+the websites and content that these users can access.
+
+14
+00:00:46,000 --> 00:00:49,000
+So let's see some ways that organizations can do this.
+
+15
+00:00:49,000 --> 00:00:53,000
+One thing they can do is they can install what's called agent based web filtering.
+
+16
+00:00:53,000 --> 00:01:00,000
+This this involves installing web filters by installing a specific piece of software on the individual
+
+17
+00:01:00,000 --> 00:01:02,000
+user, computers or devices.
+
+18
+00:01:02,000 --> 00:01:05,000
+These agents will enforce web policies set by the organization.
+
+19
+00:01:05,000 --> 00:01:10,000
+Now these agents are going to work generally with what's known as proxy servers, which we'll come to
+
+20
+00:01:10,000 --> 00:01:11,000
+in a minute.
+
+21
+00:01:11,000 --> 00:01:15,000
+They are the ones that's going to control what websites you can access.
+
+22
+00:01:15,000 --> 00:01:16,000
+Use case.
+
+23
+00:01:16,000 --> 00:01:22,000
+This approach is particularly useful for managing web access of remote or mobile employees, who might
+
+24
+00:01:22,000 --> 00:01:24,000
+not always be connected to the corporate network.
+
+25
+00:01:24,000 --> 00:01:25,000
+Here's why.
+
+26
+00:01:25,000 --> 00:01:35,000
+Because if you give, uh, remote users particularly like salespeople or traveling users, uh, a laptop,
+
+27
+00:01:35,000 --> 00:01:39,000
+and they connect to a particular network, it's not your network.
+
+28
+00:01:39,000 --> 00:01:41,000
+It's a network at Starbucks.
+
+29
+00:01:41,000 --> 00:01:42,000
+It's the hotel's network.
+
+30
+00:01:42,000 --> 00:01:47,000
+Well, because you can control everything in your network, you can restrict what people can access.
+
+31
+00:01:47,000 --> 00:01:51,000
+But if they go to that hotel, there's nothing that restricts them.
+
+32
+00:01:51,000 --> 00:01:53,000
+So now they can access anything.
+
+33
+00:01:53,000 --> 00:01:57,000
+But if you have an agent install a software on the machine, that doesn't matter what network they're
+
+34
+00:01:57,000 --> 00:02:00,000
+connected to, you can restrict their website.
+
+35
+00:02:00,000 --> 00:02:03,000
+That's why agent based web filtering is great.
+
+36
+00:02:03,000 --> 00:02:08,000
+Now a lot of times we're going to use some kind of something called a centralized proxy or proxy servers.
+
+37
+00:02:08,000 --> 00:02:12,000
+This is often part of a larger network appliance security appliance.
+
+38
+00:02:12,000 --> 00:02:17,000
+Now you can also have this thing as a service that acts as the intermediary.
+
+39
+00:02:18,000 --> 00:02:20,000
+You can pronounce that word between users and the internet.
+
+40
+00:02:20,000 --> 00:02:24,000
+All web traffic passes through these proxies and it filters it.
+
+41
+00:02:24,000 --> 00:02:30,000
+I remember working at different jobs and going to different big companies, and you would try to go
+
+42
+00:02:30,000 --> 00:02:34,000
+to a particular website, you might go to Facebook and it might redirect your company policies and allow
+
+43
+00:02:34,000 --> 00:02:34,000
+that.
+
+44
+00:02:34,000 --> 00:02:37,000
+That's what a proxy server does.
+
+45
+00:02:37,000 --> 00:02:43,000
+This method offers a centralized management and control, making it easier to manage your web policies.
+
+46
+00:02:43,000 --> 00:02:48,000
+Now all of these things are going to be doing what's known as URL scanning.
+
+47
+00:02:48,000 --> 00:02:53,000
+This involves examining the URLs requested by users to determine, hey, should we allow this or can
+
+48
+00:02:53,000 --> 00:02:55,000
+we not allow this?
+
+49
+00:02:55,000 --> 00:03:01,000
+This can be based on the data set of, uh, customized or categorized URLs.
+
+50
+00:03:01,000 --> 00:03:07,000
+So the organization can have a giant database of particular URLs that you're allowed to access.
+
+51
+00:03:07,000 --> 00:03:13,000
+The application URL is effective and preventing access to known malicious or inappropriate website.
+
+52
+00:03:13,000 --> 00:03:19,000
+So if we just give them a list of websites that we they want, that we want them to access, more than
+
+53
+00:03:19,000 --> 00:03:21,000
+likely they're not going to be going anywhere else.
+
+54
+00:03:22,000 --> 00:03:24,000
+Content categorization.
+
+55
+00:03:24,000 --> 00:03:31,000
+How do we categorize content well classifies web pages into different like social media adult content
+
+56
+00:03:31,000 --> 00:03:32,000
+games based on their content.
+
+57
+00:03:33,000 --> 00:03:38,000
+This allows organizations to block or allow entire categories of websites.
+
+58
+00:03:38,000 --> 00:03:45,000
+For example, if you're working in it, a lot of times we may allow only IT folks to visit IT related
+
+59
+00:03:45,000 --> 00:03:50,000
+websites, but we're not going to allow IT folks to visit social media.
+
+60
+00:03:50,000 --> 00:03:55,000
+But the people in the marketing department, they could visit social media, but they can't visit other
+
+61
+00:03:55,000 --> 00:03:56,000
+types of websites.
+
+62
+00:03:56,000 --> 00:04:03,000
+This is great because now we are giving folks a block of content that is related to their job.
+
+63
+00:04:03,000 --> 00:04:06,000
+This, of course, restricts what they can access.
+
+64
+00:04:06,000 --> 00:04:13,000
+The block rule in web filtering a specific criteria set to block access to certain websites.
+
+65
+00:04:13,000 --> 00:04:19,000
+We could block things on URLs, keywords, categories, or anything that we can identify on that web
+
+66
+00:04:19,000 --> 00:04:19,000
+page.
+
+67
+00:04:19,000 --> 00:04:25,000
+They can block, hey, you can't go to this URL, or you can go to social media sites, or you can go
+
+68
+00:04:25,000 --> 00:04:26,000
+to video sharing website.
+
+69
+00:04:26,000 --> 00:04:28,000
+So you could block lots of things.
+
+70
+00:04:28,000 --> 00:04:34,000
+Your organization is going to customize these block rules to ensure that they're meeting their policies,
+
+71
+00:04:34,000 --> 00:04:36,000
+even certain regulatory compliance.
+
+72
+00:04:38,000 --> 00:04:45,000
+Now there are these kinds of filters called reputation filters, uses the reputation score of websites
+
+73
+00:04:45,000 --> 00:04:47,000
+to determine whether they should be allowed or not.
+
+74
+00:04:48,000 --> 00:04:52,000
+Reputation scores are literally coming from various factors like the history, presence of malware,
+
+75
+00:04:52,000 --> 00:04:54,000
+and even user feedback.
+
+76
+00:04:54,000 --> 00:04:55,000
+This.
+
+77
+00:04:56,000 --> 00:05:02,000
+Is really important because the reputation score of certain website, if it has a low reputation, could
+
+78
+00:05:02,000 --> 00:05:03,000
+mean that the website was passed in malware.
+
+79
+00:05:03,000 --> 00:05:04,000
+Quite often.
+
+80
+00:05:04,000 --> 00:05:10,000
+This is a very effective way in protecting against newly created malicious site, because new sites
+
+81
+00:05:10,000 --> 00:05:12,000
+probably wouldn't have a good reputation score.
+
+82
+00:05:12,000 --> 00:05:14,000
+So it hasn't been around long enough.
+
+83
+00:05:14,000 --> 00:05:17,000
+And because it hasn't been around long enough, its reputation score is going to be low.
+
+84
+00:05:17,000 --> 00:05:19,000
+You're not going to be able to access it.
+
+85
+00:05:19,000 --> 00:05:27,000
+I strongly believe that web filtering is one of the core concepts that we should have in security.
+
+86
+00:05:27,000 --> 00:05:34,000
+By having web filtering, we'll better be able to restrict what people can do within the organization,
+
+87
+00:05:34,000 --> 00:05:36,000
+and hopefully that keeps them doing their job.
+
+88
+00:05:36,000 --> 00:05:43,000
+But most importantly, web filtering is probably one of the best ways to reduce malware infections.
+
diff --git a/17 - Enhance Security/003 Operating System Security OB 4.5_en.srt b/17 - Enhance Security/003 Operating System Security OB 4.5_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..02cc0d6686621f29b448c2cd537d1c1ea0344382
--- /dev/null
+++ b/17 - Enhance Security/003 Operating System Security OB 4.5_en.srt
@@ -0,0 +1,448 @@
+1
+00:00:00,000 --> 00:00:05,000
+When it comes to securing and operating system, one of the best things we can do in particularly windows
+
+2
+00:00:05,000 --> 00:00:07,000
+is what's called group policies.
+
+3
+00:00:07,000 --> 00:00:13,000
+When people say in today's corporate world or security world, when you hear somebody say, we're going
+
+4
+00:00:13,000 --> 00:00:18,000
+to lock down that operating system, we're going to lock down their desktop, we're going to restrict
+
+5
+00:00:18,000 --> 00:00:19,000
+what they can access.
+
+6
+00:00:19,000 --> 00:00:21,000
+We're going to set password policies.
+
+7
+00:00:21,000 --> 00:00:22,000
+That's all with group policy.
+
+8
+00:00:22,000 --> 00:00:25,000
+Now for this course, you just need to understand what it is.
+
+9
+00:00:25,000 --> 00:00:31,000
+I'm going to also show you group policy on on on my windows machine.
+
+10
+00:00:31,000 --> 00:00:34,000
+You don't need to configure group policy for your exam.
+
+11
+00:00:34,000 --> 00:00:36,000
+So we'll do that at the end of the video.
+
+12
+00:00:36,000 --> 00:00:39,000
+So if you want to stick around to see some group policies in action stick with me.
+
+13
+00:00:39,000 --> 00:00:40,000
+Let's get started.
+
+14
+00:00:41,000 --> 00:00:43,000
+Um, so let's talk about this.
+
+15
+00:00:43,000 --> 00:00:48,000
+When you're securing it particularly windows, the best thing we're going to be using is group policies.
+
+16
+00:00:48,000 --> 00:00:54,000
+It's a feature in windows that allows administrators to control the work and environment of users and
+
+17
+00:00:54,000 --> 00:00:54,000
+computers.
+
+18
+00:00:54,000 --> 00:00:57,000
+And it could do a lot of things.
+
+19
+00:00:57,000 --> 00:01:01,000
+First of all, it could be centralized, and it could be centralized.
+
+20
+00:01:01,000 --> 00:01:06,000
+And it's basically the configuration of operating system applications and user setup.
+
+21
+00:01:06,000 --> 00:01:11,000
+We centralized this by implementing things like Active Directory that can then push out group policies
+
+22
+00:01:11,000 --> 00:01:13,000
+to large sections of your machine.
+
+23
+00:01:13,000 --> 00:01:17,000
+You can also edit the group policy locally on your computer.
+
+24
+00:01:17,000 --> 00:01:23,000
+The applications of security Settings group policy can enforce many types of security settings, such
+
+25
+00:01:23,000 --> 00:01:28,000
+as password policies, lockout policies if you put your password in too many times, wrong audit policies
+
+26
+00:01:28,000 --> 00:01:32,000
+to keep track of what's going on in the machine, it can even control what users can do.
+
+27
+00:01:32,000 --> 00:01:39,000
+Security options and even access to file folders and registry group policies has way too many options
+
+28
+00:01:39,000 --> 00:01:41,000
+for me just to talk about in a video a few minutes.
+
+29
+00:01:41,000 --> 00:01:48,000
+But for your exam, just know group policy is how we maintain the security settings on windows Machine.
+
+30
+00:01:48,000 --> 00:01:56,000
+Now there is a version of Linux that you guys should be familiar with for your exam, and that's called
+
+31
+00:01:56,000 --> 00:02:00,000
+SE Linux or Secure Enhanced Linux.
+
+32
+00:02:00,000 --> 00:02:07,000
+Now this is a security module in Linux systems that provides a mechanism for supporting access control
+
+33
+00:02:07,000 --> 00:02:08,000
+security policies.
+
+34
+00:02:08,000 --> 00:02:12,000
+It implements what is known as mandatory access control.
+
+35
+00:02:12,000 --> 00:02:18,000
+You see, traditional operating systems such as windows implements a type of access control we call
+
+36
+00:02:18,000 --> 00:02:21,000
+Dak or discretionary access control.
+
+37
+00:02:21,000 --> 00:02:24,000
+Basically, in windows, whoever creates the objects owns the objects.
+
+38
+00:02:24,000 --> 00:02:28,000
+Whoever makes the objects can even set permissions on the objects.
+
+39
+00:02:28,000 --> 00:02:33,000
+Because I'm on this windows box, I can make a folder and share it and do whatever I want with it on
+
+40
+00:02:33,000 --> 00:02:33,000
+the network.
+
+41
+00:02:33,000 --> 00:02:37,000
+But if you install a Linux system doesn't work like that.
+
+42
+00:02:37,000 --> 00:02:44,000
+You see, unlike traditional discretionary access control systems or Dak like windows SE, Linux enforces
+
+43
+00:02:44,000 --> 00:02:50,000
+mandatory that access control administrators can define the control access to all processes and files.
+
+44
+00:02:51,000 --> 00:02:56,000
+Basically, when they install Linux SE, the administrator sets the permissions on the machine, and
+
+45
+00:02:56,000 --> 00:03:02,000
+users can't just create files and change permissions and grant and grant access to anybody they want.
+
+46
+00:03:02,000 --> 00:03:08,000
+So the actual permissions or security of the systems is set by the administrators and not by the users
+
+47
+00:03:08,000 --> 00:03:10,000
+or set by the organization.
+
+48
+00:03:10,000 --> 00:03:16,000
+In other words, SE Linux is not something that's popular in corporate environments.
+
+49
+00:03:16,000 --> 00:03:19,000
+SE Linux is used by places like the NSA and the DoD.
+
+50
+00:03:20,000 --> 00:03:23,000
+In fact, it was I think it was developed by them.
+
+51
+00:03:23,000 --> 00:03:30,000
+In fact, the word mandatory access control does have quite a lot of different terminologies that belongs
+
+52
+00:03:30,000 --> 00:03:30,000
+with it.
+
+53
+00:03:30,000 --> 00:03:33,000
+But that's something we're going to cover in another video.
+
+54
+00:03:33,000 --> 00:03:40,000
+But for now, just remember Linux SE implements mandatory access control and to control security features
+
+55
+00:03:40,000 --> 00:03:43,000
+in windows we're going to use group policy okay.
+
+56
+00:03:43,000 --> 00:03:44,000
+That's the end of this video.
+
+57
+00:03:44,000 --> 00:03:50,000
+If you want to pass your exam, if you want to see how do how does group policies work.
+
+58
+00:03:50,000 --> 00:03:53,000
+Well let's do a quick little demonstration.
+
+59
+00:03:53,000 --> 00:03:55,000
+And I'm going to show you guys how to get it.
+
+60
+00:03:56,000 --> 00:03:56,000
+All right.
+
+61
+00:03:56,000 --> 00:03:58,000
+So we're going to go back here to my desktop.
+
+62
+00:03:59,000 --> 00:04:01,000
+We're going to go to run.
+
+63
+00:04:01,000 --> 00:04:01,000
+We're going to do window.
+
+64
+00:04:01,000 --> 00:04:02,000
+Are to go to run.
+
+65
+00:04:02,000 --> 00:04:09,000
+We're going to do uh I like to do an MMC console, Microsoft Management console, MMC.
+
+66
+00:04:11,000 --> 00:04:13,000
+Now you could do Gpedit.msc.
+
+67
+00:04:14,000 --> 00:04:16,000
+Uh, but this.
+
+68
+00:04:16,000 --> 00:04:18,000
+I like to do a console, so I'm going to open up a console.
+
+69
+00:04:18,000 --> 00:04:23,000
+I'll do a snapping of the group policy object editor, let's say file add remove snapping.
+
+70
+00:04:24,000 --> 00:04:27,000
+And then we want to find group policy object editor.
+
+71
+00:04:27,000 --> 00:04:29,000
+We're going to say add for this computer.
+
+72
+00:04:29,000 --> 00:04:33,000
+If you have administrator privileges you can actually browse, select all the computers in your network
+
+73
+00:04:33,000 --> 00:04:35,000
+and administer policies remotely.
+
+74
+00:04:35,000 --> 00:04:38,000
+So in here notice I have.
+
+75
+00:04:38,000 --> 00:04:45,000
+My group policy senior, I can go in and notice I have user configuration and I have computer configuration.
+
+76
+00:04:45,000 --> 00:04:52,000
+So in here for example in administrative template I can go in here and I can configure the active desktop.
+
+77
+00:04:52,000 --> 00:04:53,000
+Like we can go in here.
+
+78
+00:04:53,000 --> 00:04:58,000
+And we could prohibit adding items uh items to the desktop.
+
+79
+00:04:59,000 --> 00:05:03,000
+Uh we can go in here and set the desktop wallpaper.
+
+80
+00:05:03,000 --> 00:05:06,000
+We can disable all items on a desktop.
+
+81
+00:05:06,000 --> 00:05:08,000
+But this only applies to certain versions of windows.
+
+82
+00:05:08,000 --> 00:05:11,000
+It'll tell you what versions of windows that applies to.
+
+83
+00:05:11,000 --> 00:05:13,000
+So you can go in there.
+
+84
+00:05:13,000 --> 00:05:15,000
+You can set many, many things.
+
+85
+00:05:16,000 --> 00:05:16,000
+Um.
+
+86
+00:05:17,000 --> 00:05:21,000
+The ones I want to show you guys is going to be in the computer settings.
+
+87
+00:05:22,000 --> 00:05:29,000
+We're going to go, uh, sorry, not windows computer configuration, windows settings, security settings.
+
+88
+00:05:29,000 --> 00:05:33,000
+And in here you have tons of things you can do, like password policies.
+
+89
+00:05:33,000 --> 00:05:39,000
+You can specify that this machine must have a password right now has eight minimum.
+
+90
+00:05:39,000 --> 00:05:40,000
+You can say it must have ten.
+
+91
+00:05:40,000 --> 00:05:44,000
+You could say that the password must be complex.
+
+92
+00:05:44,000 --> 00:05:46,000
+Right now that's disabled.
+
+93
+00:05:46,000 --> 00:05:47,000
+All right.
+
+94
+00:05:47,000 --> 00:05:48,000
+We can do an account lockout.
+
+95
+00:05:48,000 --> 00:05:50,000
+Like if they put their password too many times.
+
+96
+00:05:50,000 --> 00:05:54,000
+Right now it's zero, which means you can put as many times as they want.
+
+97
+00:05:55,000 --> 00:05:57,000
+Um, you could put that if they put it in.
+
+98
+00:05:57,000 --> 00:05:59,000
+If they put password three times, it'll lock it out.
+
+99
+00:05:59,000 --> 00:06:03,000
+So you could do quite a lot of things in local policy.
+
+100
+00:06:03,000 --> 00:06:05,000
+You can go in here and say user right assignment.
+
+101
+00:06:05,000 --> 00:06:08,000
+You could deny a variety of things.
+
+102
+00:06:09,000 --> 00:06:12,000
+Or allow certain things are logged, certain things.
+
+103
+00:06:12,000 --> 00:06:15,000
+So then you can see all of these things that are listed here.
+
+104
+00:06:16,000 --> 00:06:21,000
+Um, now I do want to point out that, you know, there's a lot of things here from firewall policies,
+
+105
+00:06:21,000 --> 00:06:22,000
+even administrative.
+
+106
+00:06:22,000 --> 00:06:28,000
+You can even go in and for example, don't have users access to control panel.
+
+107
+00:06:28,000 --> 00:06:30,000
+All this type of things you can do here.
+
+108
+00:06:30,000 --> 00:06:36,000
+Now, I do want to point out that when it comes to group policies, it's not something you should play
+
+109
+00:06:36,000 --> 00:06:38,000
+around with if you don't know what you're doing.
+
+110
+00:06:38,000 --> 00:06:46,000
+I learned group policies back when I studied Windows Server 2000, in the year 2000, so a long, long
+
+111
+00:06:46,000 --> 00:06:48,000
+time ago, and we've used it since.
+
+112
+00:06:48,000 --> 00:06:54,000
+Group policy is still used today to keep windows operating systems secure.
+
diff --git a/17 - Enhance Security/004 Secure Protocols OB 4.5_en.srt b/17 - Enhance Security/004 Secure Protocols OB 4.5_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..48a3d65dfcddd755157449cbc2dafaa205e22ac2
--- /dev/null
+++ b/17 - Enhance Security/004 Secure Protocols OB 4.5_en.srt
@@ -0,0 +1,256 @@
+1
+00:00:00,000 --> 00:00:04,000
+You always want to choose a secure way over an unsecure way.
+
+2
+00:00:04,000 --> 00:00:09,000
+So in this video, I want to go through what you should be choosing.
+
+3
+00:00:09,000 --> 00:00:14,000
+You know which one over which one of some of the most common protocols that we have.
+
+4
+00:00:14,000 --> 00:00:20,000
+So implementation of secure protocols is an enterprise in enterprise environment is critical because
+
+5
+00:00:20,000 --> 00:00:26,000
+if you choose an insecure protocol, you could be opening the organization to tons of vulnerability.
+
+6
+00:00:26,000 --> 00:00:32,000
+So this process involves careful selections of protocols, ports and transport methods.
+
+7
+00:00:32,000 --> 00:00:32,000
+Let's get into this.
+
+8
+00:00:32,000 --> 00:00:33,000
+So protocols.
+
+9
+00:00:33,000 --> 00:00:37,000
+So the first thing up you should understand that Http is not secure.
+
+10
+00:00:38,000 --> 00:00:43,000
+Http is how we transfer a web page from different web servers to your desktop.
+
+11
+00:00:43,000 --> 00:00:47,000
+In particular, for web traffic, Https is the secure option.
+
+12
+00:00:47,000 --> 00:00:49,000
+This is the one that we should be using.
+
+13
+00:00:49,000 --> 00:00:59,000
+Https basically encapsulates um http into ssl tls tunnel to make them more secure.
+
+14
+00:00:59,000 --> 00:01:05,000
+This can safeguard against ears dropping or even on path attacks or what's known now known as on path.
+
+15
+00:01:05,000 --> 00:01:10,000
+Previously known as man in the middle attacks SSH over telnet.
+
+16
+00:01:10,000 --> 00:01:16,000
+So for remote administration, if you want to configure your computer remotely, especially things like
+
+17
+00:01:16,000 --> 00:01:21,000
+Cisco routers and Linux boxes, telnet was popular, but telnet is not encrypted.
+
+18
+00:01:21,000 --> 00:01:24,000
+What we should be using now is SSH.
+
+19
+00:01:24,000 --> 00:01:27,000
+SSH encrypts the data.
+
+20
+00:01:27,000 --> 00:01:28,000
+Okay.
+
+21
+00:01:28,000 --> 00:01:31,000
+When SSH encrypts it, it means that anyone is dropping on it.
+
+22
+00:01:31,000 --> 00:01:33,000
+Can't listen to it.
+
+23
+00:01:33,000 --> 00:01:38,000
+Now for email you want to use good email secure protocols.
+
+24
+00:01:38,000 --> 00:01:45,000
+SMTp, iMap, and Pop3 can now use TLS or SSL encryption.
+
+25
+00:01:45,000 --> 00:01:49,000
+You don't want to send email in plain text, generally without the use of TLS.
+
+26
+00:01:49,000 --> 00:01:51,000
+Your email is sent in plain text.
+
+27
+00:01:52,000 --> 00:01:59,000
+So if you email someone some really secure or private information, somebody with access to your to
+
+28
+00:01:59,000 --> 00:02:01,000
+your lines in your network can actually read it.
+
+29
+00:02:02,000 --> 00:02:08,000
+Secure File transfer FTP is one of the still one of the most popular ways to upload and download files
+
+30
+00:02:08,000 --> 00:02:10,000
+off a web servers in particular.
+
+31
+00:02:10,000 --> 00:02:15,000
+Now, back in the days we used to use it to share files over the internet, although now we have things
+
+32
+00:02:15,000 --> 00:02:21,000
+like Dropbox, but we still use FTP to transfer files to and from web servers.
+
+33
+00:02:21,000 --> 00:02:30,000
+If you maintain a web server now, don't use FTP, use SftP which is combined in FTP with SSH or ftps
+
+34
+00:02:30,000 --> 00:02:32,000
+which combines it with SSL.
+
+35
+00:02:32,000 --> 00:02:34,000
+This makes it more secure.
+
+36
+00:02:34,000 --> 00:02:38,000
+Now this is going to be some of the most popular protocols out there.
+
+37
+00:02:39,000 --> 00:02:46,000
+When it comes to ports, you guys should know that standard ports are going to be generally unsecure.
+
+38
+00:02:46,000 --> 00:02:49,000
+Port 80 is not secure.
+
+39
+00:02:49,000 --> 00:02:52,000
+Using standard ports for correspondent.
+
+40
+00:02:52,000 --> 00:02:55,000
+For correspondent, secure ports is generally recommended.
+
+41
+00:02:55,000 --> 00:02:55,000
+All right.
+
+42
+00:02:55,000 --> 00:03:02,000
+So what are we going to be doing well for Https we're going to use port 443 for things like SSH.
+
+43
+00:03:02,000 --> 00:03:05,000
+We're going to use port 22 and for email.
+
+44
+00:03:05,000 --> 00:03:08,000
+Now if you're using SSL um.
+
+45
+00:03:09,000 --> 00:03:13,000
+If you're going to be using SSL, which you should be, it's going to change some of the ports.
+
+46
+00:03:13,000 --> 00:03:22,000
+So for SMTp, which used to be 25, we're going to use 587 for iMap uh, which I believe is 143.
+
+47
+00:03:22,000 --> 00:03:24,000
+By default we're going to use 993.
+
+48
+00:03:24,000 --> 00:03:29,000
+And for Pop3, which I believe is 110, Andrew doesn't remember all his ports anymore.
+
+49
+00:03:29,000 --> 00:03:32,000
+Guys is now 995.
+
+50
+00:03:33,000 --> 00:03:37,000
+Now when it comes to transport methods you want to transport.
+
+51
+00:03:37,000 --> 00:03:38,000
+Um.
+
+52
+00:03:39,000 --> 00:03:41,000
+You want to transport data across the internet?
+
+53
+00:03:41,000 --> 00:03:43,000
+How are we going to do this?
+
+54
+00:03:43,000 --> 00:03:49,000
+Especially like if you're transporting private information, like when somebody connects to a VPN,
+
+55
+00:03:49,000 --> 00:03:52,000
+if you're tasked to transport data, we got to get data across the internet.
+
+56
+00:03:52,000 --> 00:03:56,000
+The best thing to do is to do a VPN creates a secure tunnel between two sites.
+
+57
+00:03:56,000 --> 00:04:02,000
+When you do that VPN, make sure you use IPsec, which is when you configure what's known as L2tpv3,
+
+58
+00:04:03,000 --> 00:04:04,000
+which we covered earlier in the course.
+
+59
+00:04:04,000 --> 00:04:09,000
+You're going to want to use IPsec, which we did cover earlier in the course, and our TLS.
+
+60
+00:04:09,000 --> 00:04:12,000
+So you can do an SSL based VPN.
+
+61
+00:04:12,000 --> 00:04:15,000
+This is the best way to transport information okay.
+
+62
+00:04:15,000 --> 00:04:19,000
+This video was a quick review of things that we probably have already covered already, especially if
+
+63
+00:04:19,000 --> 00:04:21,000
+you watch the cryptography section.
+
+64
+00:04:21,000 --> 00:04:26,000
+Always choose secure protocols over on secure protocols.
+
diff --git a/17 - Enhance Security/005 DNS Filter OB 4.5_en.srt b/17 - Enhance Security/005 DNS Filter OB 4.5_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..ceb5bc53d805895e8c06cf96e0a2f20d830c1f07
--- /dev/null
+++ b/17 - Enhance Security/005 DNS Filter OB 4.5_en.srt
@@ -0,0 +1,104 @@
+1
+00:00:00,000 --> 00:00:07,000
+For your exam, you're going to want to be familiar that you can't just only block web traffic by utilizing
+
+2
+00:00:07,000 --> 00:00:12,000
+proxy servers, but you can also block web traffic by using DNS filtering.
+
+3
+00:00:12,000 --> 00:00:19,000
+So DNS filtering is DNS filtering is the network security technique used to block access to malicious
+
+4
+00:00:19,000 --> 00:00:24,000
+websites and content that is inappropriate or non-compliant with your company policy.
+
+5
+00:00:24,000 --> 00:00:26,000
+It involves using DNS to do this.
+
+6
+00:00:26,000 --> 00:00:28,000
+Now remember how DNS works.
+
+7
+00:00:28,000 --> 00:00:37,000
+DNS translates domain names to IP addresses, so when you try to access a domain, you send that request
+
+8
+00:00:37,000 --> 00:00:38,000
+to a DNS server.
+
+9
+00:00:38,000 --> 00:00:41,000
+Now the DNS server requests gets the request first.
+
+10
+00:00:41,000 --> 00:00:45,000
+So this would be one of the best things you can do if you can implement this filter.
+
+11
+00:00:45,000 --> 00:00:50,000
+Because since the DNS server is getting the requests first, the DNS server can say, wait a minute,
+
+12
+00:00:50,000 --> 00:00:51,000
+you're trying to go to this domain?
+
+13
+00:00:51,000 --> 00:00:52,000
+Well, I'm not allowing you there.
+
+14
+00:00:53,000 --> 00:00:55,000
+Now there's a variety of ways of doing this.
+
+15
+00:00:55,000 --> 00:00:57,000
+You can use a commercial DNS filtering service.
+
+16
+00:00:57,000 --> 00:01:03,000
+These services offer robust filtering options, and they're generally updated with websites that are
+
+17
+00:01:03,000 --> 00:01:07,000
+considered, uh, malicious in nature or considered a threat to your business.
+
+18
+00:01:07,000 --> 00:01:13,000
+They could be cloud or on premises, and there's tons of third party DNS filtering services.
+
+19
+00:01:13,000 --> 00:01:15,000
+There are open source ones that you can use.
+
+20
+00:01:16,000 --> 00:01:18,000
+That can be customized.
+
+21
+00:01:18,000 --> 00:01:22,000
+Uh, but generally going to require much more knowledge to do.
+
+22
+00:01:22,000 --> 00:01:29,000
+Now, DNS filtering, in my opinion, is very important because, remember, it's one of the first things
+
+23
+00:01:29,000 --> 00:01:34,000
+that people are going to get to is one of the first lines that they're going to ask, hey, can I go
+
+24
+00:01:34,000 --> 00:01:35,000
+to this website?
+
+25
+00:01:35,000 --> 00:01:42,000
+So if we can stop or filter out web traffic from right at the start, it would be a whole lot better
+
+26
+00:01:42,000 --> 00:01:43,000
+than using anything else.
+
diff --git a/17 - Enhance Security/006 Email security OB 4.5_en.srt b/17 - Enhance Security/006 Email security OB 4.5_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..07f4281a71ecb8ddd776bca5355f63c207f4fa52
--- /dev/null
+++ b/17 - Enhance Security/006 Email security OB 4.5_en.srt
@@ -0,0 +1,432 @@
+1
+00:00:00,000 --> 00:00:07,000
+Many email providers such as Yahoo, Gmail, and your private organization is trying their best to deal
+
+2
+00:00:07,000 --> 00:00:15,000
+with the massive amount of spam that is coming in and also the delivery of malicious email email coming
+
+3
+00:00:15,000 --> 00:00:21,000
+to you, not just as spam trying to sell you something or some useless message in an email, but also
+
+4
+00:00:21,000 --> 00:00:22,000
+malware.
+
+5
+00:00:22,000 --> 00:00:27,000
+What organizations needs to be doing is setting up the things that I'm going to be covering in this
+
+6
+00:00:27,000 --> 00:00:28,000
+video.
+
+7
+00:00:28,000 --> 00:00:33,000
+At a minimum, you should have these things to ensure that your domain is set up correctly.
+
+8
+00:00:33,000 --> 00:00:38,000
+Your domain wouldn't be marked as spam and of course, to reduce spam in your company.
+
+9
+00:00:38,000 --> 00:00:39,000
+So let's talk about this.
+
+10
+00:00:39,000 --> 00:00:41,000
+The first thing we need to talk about is an email security gateway.
+
+11
+00:00:43,000 --> 00:00:49,000
+This is a hardware software used to monitor and manage incoming and outgoing emails.
+
+12
+00:00:49,000 --> 00:00:53,000
+This thing is used to prevent spam, phishing attacks, and malware from coming in.
+
+13
+00:00:53,000 --> 00:00:59,000
+It scans your emails for viruses and other malware, filters out spam, and and can encrypt data and
+
+14
+00:00:59,000 --> 00:01:01,000
+prevent all kinds of data losses.
+
+15
+00:01:01,000 --> 00:01:05,000
+Gateways can be deployed on premises, but you're probably going to have this in cloud.
+
+16
+00:01:05,000 --> 00:01:10,000
+Most people don't maintain on prem email anymore.
+
+17
+00:01:10,000 --> 00:01:16,000
+I remember back in the days I had set up exchange servers, Microsoft Exchange servers as email servers
+
+18
+00:01:16,000 --> 00:01:17,000
+on prem.
+
+19
+00:01:17,000 --> 00:01:20,000
+We don't do that anymore because it's just cheaper to have it outside.
+
+20
+00:01:20,000 --> 00:01:27,000
+We're going to combine your email gateway with things like dMarc, DKIM, and SPF records in order to
+
+21
+00:01:27,000 --> 00:01:28,000
+come up with good security.
+
+22
+00:01:28,000 --> 00:01:31,000
+Now let's go through some of it.
+
+23
+00:01:31,000 --> 00:01:36,000
+The first thing I want to talk about is something we call Sender Policy Framework.
+
+24
+00:01:36,000 --> 00:01:45,000
+Now before I get into these three things Sender Policy Framework, DKIM, and dMarc, I want to mention
+
+25
+00:01:45,000 --> 00:01:45,000
+something.
+
+26
+00:01:46,000 --> 00:01:47,000
+Right now.
+
+27
+00:01:47,000 --> 00:01:54,000
+If your domain is not set up with these things correctly, more than likely Gmail, Yahoo!
+
+28
+00:01:54,000 --> 00:02:00,000
+And I think Microsoft is going to start marking emails coming from your domain as spam.
+
+29
+00:02:00,000 --> 00:02:05,000
+Spammers are going to have to stop sending emails unless they can verify their domain.
+
+30
+00:02:05,000 --> 00:02:08,000
+And that's what this that's what these things are going to be doing.
+
+31
+00:02:08,000 --> 00:02:09,000
+So let's get started.
+
+32
+00:02:09,000 --> 00:02:09,000
+What they are.
+
+33
+00:02:09,000 --> 00:02:16,000
+Sender Policy Framework is an email authentication method used to prevent spammers from sending messages
+
+34
+00:02:16,000 --> 00:02:18,000
+on behalf of you.
+
+35
+00:02:19,000 --> 00:02:20,000
+You got that?
+
+36
+00:02:20,000 --> 00:02:27,000
+When you implement SPF, what happens is it stops spammers from sending stuff from your domain.
+
+37
+00:02:27,000 --> 00:02:27,000
+How does it do it?
+
+38
+00:02:27,000 --> 00:02:35,000
+Well, SPF verified the sender the sender's IP address against a list of authorized sending IPS published
+
+39
+00:02:35,000 --> 00:02:37,000
+in the DNS records of the sender domain.
+
+40
+00:02:37,000 --> 00:02:39,000
+Here's how this is set up.
+
+41
+00:02:39,000 --> 00:02:43,000
+You have to be able to manage your company's domain name.
+
+42
+00:02:43,000 --> 00:02:45,000
+This is who who holds your domain name.
+
+43
+00:02:45,000 --> 00:02:47,000
+You know, where do you host your domain name?
+
+44
+00:02:47,000 --> 00:02:53,000
+Maybe you hosted GoDaddy, you can go to GoDaddy and you're going to add what's called a txt record.
+
+45
+00:02:53,000 --> 00:02:57,000
+Now GoDaddy is going to have specific instructions on this.
+
+46
+00:02:57,000 --> 00:03:03,000
+And I found the instructions for GoDaddy just to show you guys what it looks like.
+
+47
+00:03:03,000 --> 00:03:10,000
+So if you have GoDaddy and again this is just for demonstration purposes, if you have GoDaddy, this
+
+48
+00:03:10,000 --> 00:03:12,000
+is how you would add an SPF record.
+
+49
+00:03:12,000 --> 00:03:14,000
+It goes through the instructions.
+
+50
+00:03:14,000 --> 00:03:15,000
+It tells you to select your domain name.
+
+51
+00:03:15,000 --> 00:03:22,000
+You add a DNS record and then you're going to add basically a text record.
+
+52
+00:03:22,000 --> 00:03:26,000
+And in the text record you're going to put in specific values.
+
+53
+00:03:26,000 --> 00:03:33,000
+You're going to put in where for example, what server is going to be allowed to send out emails.
+
+54
+00:03:33,000 --> 00:03:34,000
+This is important.
+
+55
+00:03:34,000 --> 00:03:36,000
+So here's what this does.
+
+56
+00:03:36,000 --> 00:03:44,000
+What SPF is actually doing is that it's specifying that only these servers that I list here has the
+
+57
+00:03:44,000 --> 00:03:48,000
+right to send emails for this domain.
+
+58
+00:03:48,000 --> 00:03:54,000
+So if a spammer decides to use his server or some other server, it is not going to happen.
+
+59
+00:03:54,000 --> 00:03:59,000
+The domain is going to register the domain registrar, like GoDaddy is going to be like, well, the
+
+60
+00:03:59,000 --> 00:04:01,000
+SPF says that that server can't.
+
+61
+00:04:01,000 --> 00:04:03,000
+Only this server could.
+
+62
+00:04:03,000 --> 00:04:06,000
+So that's why you want to go and update or add an SPF record.
+
+63
+00:04:06,000 --> 00:04:10,000
+Another record you want to add is called a DKIM record.
+
+64
+00:04:11,000 --> 00:04:17,000
+This provides a method for validating a domain name identity associated with the email message through
+
+65
+00:04:17,000 --> 00:04:18,000
+cryptographic authentication.
+
+66
+00:04:18,000 --> 00:04:24,000
+What it does is that it uses a digital signature linked to the domain name to verify that the message
+
+67
+00:04:24,000 --> 00:04:27,000
+wasn't altered and thereby authenticating the sender.
+
+68
+00:04:27,000 --> 00:04:28,000
+So here's what it does.
+
+69
+00:04:29,000 --> 00:04:36,000
+You set up DKIM by generating by going once again to your register.
+
+70
+00:04:36,000 --> 00:04:38,000
+You're going to set this up with a txt record.
+
+71
+00:04:38,000 --> 00:04:42,000
+What it does is that it creates a signature for all your outbound emails.
+
+72
+00:04:42,000 --> 00:04:48,000
+What this means is that the actual, uh, email servers are digitally signed in your email.
+
+73
+00:04:48,000 --> 00:04:54,000
+So when people receive it, they know, okay, so it actually came from that email server.
+
+74
+00:04:54,000 --> 00:05:00,000
+This way when Google receives an email, their Gmail servers receives an email from your organization.
+
+75
+00:05:00,000 --> 00:05:04,000
+Google know it didn't come from no spammer, it came from a legitimate organization.
+
+76
+00:05:05,000 --> 00:05:08,000
+That's why DKIM is important.
+
+77
+00:05:08,000 --> 00:05:10,000
+Now the other one here is called dMarc.
+
+78
+00:05:10,000 --> 00:05:15,000
+It stands for domain based message authentication, reporting and conformance.
+
+79
+00:05:15,000 --> 00:05:21,000
+This is an email validation system designed to detect and prevent email spoofing.
+
+80
+00:05:22,000 --> 00:05:25,000
+It uses DKIM and SPF to determine the authenticity of the email.
+
+81
+00:05:25,000 --> 00:05:26,000
+Now here's how it works.
+
+82
+00:05:27,000 --> 00:05:30,000
+All right, this thing is more of a policy enforcer.
+
+83
+00:05:30,000 --> 00:05:36,000
+So the primary goal is to enable email senders and receivers to determine whether a given message align
+
+84
+00:05:36,000 --> 00:05:37,000
+with what they want.
+
+85
+00:05:37,000 --> 00:05:41,000
+If not, dMarc provides instructions on how to handle discrepancies.
+
+86
+00:05:41,000 --> 00:05:45,000
+So what happens if your domain receives emails?
+
+87
+00:05:46,000 --> 00:05:51,000
+That the other domain the senders weren't using SPF, DKIM.
+
+88
+00:05:52,000 --> 00:05:53,000
+What happens?
+
+89
+00:05:53,000 --> 00:05:56,000
+All right, this is where dMarc comes in.
+
+90
+00:05:56,000 --> 00:05:57,000
+dMarc comes in.
+
+91
+00:05:57,000 --> 00:06:01,000
+Your organization can set policies of what to do with those particular emails.
+
+92
+00:06:01,000 --> 00:06:09,000
+Now combine the three things the dMarc, DKIM, and SPF is how we're going to stop most spam from coming
+
+93
+00:06:09,000 --> 00:06:14,000
+through and from spammers using your domain name.
+
+94
+00:06:14,000 --> 00:06:15,000
+A few weeks ago.
+
+95
+00:06:15,000 --> 00:06:16,000
+This is not a joke.
+
+96
+00:06:16,000 --> 00:06:20,000
+A few weeks ago I have a friend that started a small business.
+
+97
+00:06:21,000 --> 00:06:25,000
+And he started getting a whole bunch of bounce back.
+
+98
+00:06:25,000 --> 00:06:31,000
+In other words, somebody was using his domain name, his email in particular with his domain name,
+
+99
+00:06:31,000 --> 00:06:35,000
+to start sending spam over a course of every minute.
+
+100
+00:06:35,000 --> 00:06:37,000
+He was getting about 1 to 200.
+
+101
+00:06:37,000 --> 00:06:43,000
+Bounce back that that's how much emails they were using his email to send emails like crazy.
+
+102
+00:06:43,000 --> 00:06:47,000
+But his his, uh, register, which was GoDaddy, was not compromised.
+
+103
+00:06:47,000 --> 00:06:49,000
+No one he changed the password.
+
+104
+00:06:49,000 --> 00:06:51,000
+Didn't stop when I checked.
+
+105
+00:06:51,000 --> 00:06:56,000
+He did not have the, uh, SPF and DKIM.
+
+106
+00:06:56,000 --> 00:07:02,000
+So what I did was I added those records, set up the dMarc, and instantly when I did that, it stopped.
+
+107
+00:07:02,000 --> 00:07:06,000
+This is how we're going to stop people by using these email technology.
+
+108
+00:07:06,000 --> 00:07:09,000
+This is how we're going to stop spammers from taking over your domain.
+
diff --git a/17 - Enhance Security/007 File Integrity Monitoring OB 4.5_en.srt b/17 - Enhance Security/007 File Integrity Monitoring OB 4.5_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..6cdcb4c7d0eb2da4aa3aed0aa8c83d6e6b005794
--- /dev/null
+++ b/17 - Enhance Security/007 File Integrity Monitoring OB 4.5_en.srt
@@ -0,0 +1,128 @@
+1
+00:00:00,000 --> 00:00:05,000
+In every network, you're going to have a whole bunch of files, whether it's data files that users
+
+2
+00:00:05,000 --> 00:00:12,000
+are using to produce Excel sheets to do financial analysis or accounting users paying bills.
+
+3
+00:00:12,000 --> 00:00:17,000
+You're also going to have operating system files, things, files that windows uses just to be windows.
+
+4
+00:00:18,000 --> 00:00:24,000
+Now what we want to do is we want to track if these files are being altered for malicious or in malicious
+
+5
+00:00:24,000 --> 00:00:24,000
+ways.
+
+6
+00:00:24,000 --> 00:00:29,000
+So this brings me to a class of software we call films.
+
+7
+00:00:29,000 --> 00:00:33,000
+These are software that can track a file has changed.
+
+8
+00:00:33,000 --> 00:00:37,000
+Now the key word here is integrity file integrity monitoring.
+
+9
+00:00:37,000 --> 00:00:38,000
+And the key word is integrity.
+
+10
+00:00:38,000 --> 00:00:42,000
+Remember integrity is about if things have changed.
+
+11
+00:00:42,000 --> 00:00:48,000
+So file integrity monitoring is critical is a critical security process that involves the detection
+
+12
+00:00:48,000 --> 00:00:52,000
+and alerting of changes to files and directories on a system.
+
+13
+00:00:52,000 --> 00:00:57,000
+Now you could set this up to detect operating system files, data files and all kinds of files.
+
+14
+00:00:57,000 --> 00:01:02,000
+There are tons of software like this that exist for major security manufacturers.
+
+15
+00:01:02,000 --> 00:01:05,000
+One of the most famous one is from a company called tripwire.
+
+16
+00:01:05,000 --> 00:01:08,000
+You also have sonar, SolarWinds, and so on.
+
+17
+00:01:08,000 --> 00:01:10,000
+That makes a ton of these types of software.
+
+18
+00:01:10,000 --> 00:01:13,000
+So if your company is interested, look it up.
+
+19
+00:01:13,000 --> 00:01:14,000
+You're going to find a lot.
+
+20
+00:01:14,000 --> 00:01:17,000
+Now what is it that we're trying to do?
+
+21
+00:01:17,000 --> 00:01:23,000
+It's used to ensure that files has not been tampered with or altered by unauthorized parties.
+
+22
+00:01:23,000 --> 00:01:28,000
+They typically work by creating a baseline of files that caches signs and permissions, and then continuously
+
+23
+00:01:28,000 --> 00:01:30,000
+monitor these files for any changes against them.
+
+24
+00:01:30,000 --> 00:01:32,000
+So let's talk about how this works briefly.
+
+25
+00:01:32,000 --> 00:01:36,000
+So the way this thing works is you install it on your computer.
+
+26
+00:01:36,000 --> 00:01:39,000
+It makes a baseline of all the kinds of files that you have.
+
+27
+00:01:39,000 --> 00:01:45,000
+If those files get modified, the software continuously monitors the system and then alerts you that
+
+28
+00:01:45,000 --> 00:01:46,000
+the file has been changed.
+
+29
+00:01:46,000 --> 00:01:48,000
+Then what you need to do is investigate that change.
+
+30
+00:01:48,000 --> 00:01:53,000
+It could be because of some kind of malicious reason, or it could be because somebody changed it that
+
+31
+00:01:53,000 --> 00:01:54,000
+they shouldn't be.
+
+32
+00:01:54,000 --> 00:01:59,000
+But these kinds of software is important to keep track of, of if any file has changed.
+
diff --git a/17 - Enhance Security/008 Network Access Control OB 4.5_en.srt b/17 - Enhance Security/008 Network Access Control OB 4.5_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..40c8e544658e189b78f5992169a0447a03d9d91f
--- /dev/null
+++ b/17 - Enhance Security/008 Network Access Control OB 4.5_en.srt
@@ -0,0 +1,276 @@
+1
+00:00:00,000 --> 00:00:05,000
+When you're managing a network, be prepared for all kinds of computers connecting to your network.
+
+2
+00:00:05,000 --> 00:00:09,000
+One of the problems with this, though, is when you have computers that connect to your network.
+
+3
+00:00:09,000 --> 00:00:13,000
+How do you know that that computer is quote unquote healthy?
+
+4
+00:00:13,000 --> 00:00:18,000
+How do you know that machine has, for example, windows updated or the machine is fully updated?
+
+5
+00:00:18,000 --> 00:00:22,000
+How do you know the machine has valid or updated anti-malware software?
+
+6
+00:00:22,000 --> 00:00:26,000
+Now these kinds of things are security 101.
+
+7
+00:00:26,000 --> 00:00:30,000
+In other words, you shouldn't have quote unquote unhealthy machines on your network, machines that
+
+8
+00:00:30,000 --> 00:00:37,000
+are basically not updated or machines that are has no anti-malware that could have malware on it.
+
+9
+00:00:37,000 --> 00:00:40,000
+Everybody wants good, healthy machines to connect to the network.
+
+10
+00:00:40,000 --> 00:00:43,000
+That brings me to this technology.
+
+11
+00:00:43,000 --> 00:00:46,000
+This is called dnac or network access control.
+
+12
+00:00:47,000 --> 00:00:53,000
+Now, Nak is a kind of a technology that when you come to the network and you attempt to join it.
+
+13
+00:00:53,000 --> 00:00:54,000
+So let's say I have this setup.
+
+14
+00:00:54,000 --> 00:00:59,000
+Let's say I go to Tia and I set this particular technology up, this piece of software.
+
+15
+00:00:59,000 --> 00:01:02,000
+Now in Microsoft's Windows Server, you could do this.
+
+16
+00:01:02,000 --> 00:01:04,000
+It's called Network Access Protection.
+
+17
+00:01:04,000 --> 00:01:08,000
+So if you have a Windows Server, you can actually set this up with an 801 x switch.
+
+18
+00:01:08,000 --> 00:01:10,000
+This class isn't about setting this up.
+
+19
+00:01:10,000 --> 00:01:11,000
+Let me let me explain it to you.
+
+20
+00:01:12,000 --> 00:01:19,000
+So let's say I go to Tia and I set this up, I configure it, I set it all up and it's ready to go.
+
+21
+00:01:19,000 --> 00:01:25,000
+Now you, a user, comes into my network and you see a switch port and you plug your computer into the
+
+22
+00:01:25,000 --> 00:01:26,000
+switch.
+
+23
+00:01:26,000 --> 00:01:26,000
+Now here's what.
+
+24
+00:01:27,000 --> 00:01:28,000
+Now here's what's going to happen.
+
+25
+00:01:28,000 --> 00:01:34,000
+This particular piece of technology or software basically is going to check the health of the machine.
+
+26
+00:01:34,000 --> 00:01:41,000
+Now, if I set up my Nak server or my nap and nap or network access protection or network access control,
+
+27
+00:01:41,000 --> 00:01:47,000
+if I set it up that the machine has to be fully updated and the machine has to have good anti-malware
+
+28
+00:01:47,000 --> 00:01:49,000
+to basically it's going to check that on your machine.
+
+29
+00:01:49,000 --> 00:01:54,000
+If your machine meets my health check, I'm going to give you an IP address and allow you to join this
+
+30
+00:01:54,000 --> 00:01:55,000
+network.
+
+31
+00:01:55,000 --> 00:02:00,000
+In other words, you have access to general resources on this particular or the Tia network.
+
+32
+00:02:00,000 --> 00:02:03,000
+Now let's say you don't meet the health policies.
+
+33
+00:02:03,000 --> 00:02:08,000
+Let's say your machine isn't updated and you don't have any anti malware on your machine.
+
+34
+00:02:08,000 --> 00:02:12,000
+Well then we're going to put you in a remediation network.
+
+35
+00:02:12,000 --> 00:02:16,000
+And network you don't really get access to much resources, maybe just the internet.
+
+36
+00:02:16,000 --> 00:02:19,000
+So you can go and download those updates and antivirus.
+
+37
+00:02:19,000 --> 00:02:25,000
+What this technology does is that it's going to allow computers on your network to stay healthy.
+
+38
+00:02:25,000 --> 00:02:30,000
+It's going to ensure that all computers on your network meets a certain health compliance that you set
+
+39
+00:02:30,000 --> 00:02:30,000
+up.
+
+40
+00:02:30,000 --> 00:02:31,000
+So what is the goal here?
+
+41
+00:02:31,000 --> 00:02:38,000
+Well, it's to prevent unauthorized access to network resources and to ensure that all devices and users
+
+42
+00:02:38,000 --> 00:02:42,000
+comply with whatever policies and baselines that you have set up.
+
+43
+00:02:42,000 --> 00:02:47,000
+This is going to help mitigate all kinds of risk for noncompliance or infected device, because, first
+
+44
+00:02:47,000 --> 00:02:52,000
+of all, if the device is infected or the device doesn't meet a certain health check, it's not going
+
+45
+00:02:52,000 --> 00:02:55,000
+to allow that device to join that particular network.
+
+46
+00:02:55,000 --> 00:03:00,000
+What it's doing is that it's going to do health checks, assessing the security status of the device,
+
+47
+00:03:00,000 --> 00:03:04,000
+including the presence of antivirus system updates and even security patches.
+
+48
+00:03:04,000 --> 00:03:07,000
+It could do other things, but these are just some of the things it could do.
+
+49
+00:03:07,000 --> 00:03:13,000
+This is going to help you to stay in compliance with regulations, help an organization stay in compliance
+
+50
+00:03:13,000 --> 00:03:19,000
+with regulations such as HIPAA regulation, for example, you can't really have machines infected or
+
+51
+00:03:19,000 --> 00:03:20,000
+machines that's not encrypted.
+
+52
+00:03:20,000 --> 00:03:22,000
+Now what does it do?
+
+53
+00:03:22,000 --> 00:03:25,000
+Well, the way it works is like this pre admissions.
+
+54
+00:03:25,000 --> 00:03:29,000
+This means before it allows you to join the network.
+
+55
+00:03:29,000 --> 00:03:33,000
+It includes devices authentication and policy enforcement before allowing.
+
+56
+00:03:33,000 --> 00:03:38,000
+So what it's going to do is that it has to authenticate you and it has to check if those policies are
+
+57
+00:03:38,000 --> 00:03:41,000
+there after it's post.
+
+58
+00:03:41,000 --> 00:03:46,000
+Admission involves continuous monitoring of the device to ensure it remained compliant, so you better
+
+59
+00:03:46,000 --> 00:03:51,000
+ensure that your computer stays updated and has the latest Anti-Malware software.
+
+60
+00:03:52,000 --> 00:03:59,000
+Network Access Control, or NAC, is a, in my opinion, one of the most important things that we should
+
+61
+00:03:59,000 --> 00:04:00,000
+be doing in networks today.
+
+62
+00:04:00,000 --> 00:04:06,000
+The reason is because you never want computers join a network that is outdated or just doesn't have
+
+63
+00:04:06,000 --> 00:04:09,000
+the right malware anti-malware software.
+
+64
+00:04:09,000 --> 00:04:14,000
+The reason is because remember, if one computer gets infected and you allow it to join, it might start
+
+65
+00:04:14,000 --> 00:04:15,000
+infecting everyone else.
+
+66
+00:04:15,000 --> 00:04:16,000
+Think of like a flu.
+
+67
+00:04:16,000 --> 00:04:19,000
+You allow somebody in in your family to have flu.
+
+68
+00:04:19,000 --> 00:04:21,000
+That person can then spread it to all the others.
+
+69
+00:04:21,000 --> 00:04:25,000
+So let's just keep the unhealthy machines off our networks.
+
diff --git a/17 - Enhance Security/009 EDR OB 4.5_en.srt b/17 - Enhance Security/009 EDR OB 4.5_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..a97d1f095866b106fb1919ef6d6b603d62c926d8
--- /dev/null
+++ b/17 - Enhance Security/009 EDR OB 4.5_en.srt
@@ -0,0 +1,144 @@
+1
+00:00:00,000 --> 00:00:05,000
+One piece of software that has become incredibly popular in corporate environments today is the software
+
+2
+00:00:05,000 --> 00:00:07,000
+we're going to call EDR.
+
+3
+00:00:07,000 --> 00:00:12,000
+Our EDR endpoint detection and response and extended detection and response.
+
+4
+00:00:12,000 --> 00:00:19,000
+What these are are basically a really good security solutions designed basically for comprehensive threat
+
+5
+00:00:19,000 --> 00:00:21,000
+detection, analysis and response.
+
+6
+00:00:21,000 --> 00:00:27,000
+Now these kinds of software famous a very famous one is done by CrowdStrike, which you guys can check
+
+7
+00:00:27,000 --> 00:00:28,000
+out online.
+
+8
+00:00:29,000 --> 00:00:34,000
+And there is a ton of others also now EDR software, basically what it's going to do is things that
+
+9
+00:00:34,000 --> 00:00:39,000
+you're going to install on things like laptops, workstations and mobile devices.
+
+10
+00:00:39,000 --> 00:00:45,000
+They're basically going to be looking to detect, investigate and mitigate suspicious activity on all
+
+11
+00:00:45,000 --> 00:00:46,000
+the endpoints.
+
+12
+00:00:46,000 --> 00:00:51,000
+Now, endpoints is anything that can basically be infected, like some of the names that they have here.
+
+13
+00:00:51,000 --> 00:00:53,000
+Now EDR software does a few things.
+
+14
+00:00:53,000 --> 00:00:55,000
+Number one, continuous monitoring.
+
+15
+00:00:55,000 --> 00:00:59,000
+It continuously monitors all of the endpoint devices.
+
+16
+00:00:59,000 --> 00:01:02,000
+Endpoint devices are anything you can consider.
+
+17
+00:01:02,000 --> 00:01:04,000
+Anything that could bring in malware.
+
+18
+00:01:04,000 --> 00:01:06,000
+Whether it's a server, it's a laptop, it's a workstation.
+
+19
+00:01:06,000 --> 00:01:08,000
+It's some kind of mobile device.
+
+20
+00:01:08,000 --> 00:01:10,000
+It's a type of an IoT device.
+
+21
+00:01:10,000 --> 00:01:14,000
+Doesn't matter what it is, if you can get malware in there, you can get or you can use it to inject
+
+22
+00:01:14,000 --> 00:01:14,000
+malware.
+
+23
+00:01:14,000 --> 00:01:16,000
+It's some kind of an endpoint.
+
+24
+00:01:16,000 --> 00:01:22,000
+So basically this thing is going to continuously monitor your devices to see if threats are happening
+
+25
+00:01:22,000 --> 00:01:24,000
+or if there is a threat on the machine.
+
+26
+00:01:24,000 --> 00:01:26,000
+It's going to be able to detect the threat.
+
+27
+00:01:26,000 --> 00:01:29,000
+That's one of the main things utilizes advanced analytics.
+
+28
+00:01:29,000 --> 00:01:33,000
+Now, sometimes it's going to use all kinds of cloud based technology to do this.
+
+29
+00:01:33,000 --> 00:01:35,000
+And then response to that.
+
+30
+00:01:35,000 --> 00:01:37,000
+This thing is going to offer all kinds of malware.
+
+31
+00:01:37,000 --> 00:01:43,000
+And a lot of these, you know, a lot of these EDR software is going to come with the ability to respond
+
+32
+00:01:43,000 --> 00:01:46,000
+to these particular threats and removed all kinds of malware.
+
+33
+00:01:47,000 --> 00:01:52,000
+This kind of software is getting more and more popular in technology in companies to today.
+
+34
+00:01:52,000 --> 00:01:54,000
+That utilizes a lot of technology.
+
+35
+00:01:54,000 --> 00:01:55,000
+You know why?
+
+36
+00:01:55,000 --> 00:01:58,000
+Because the malware itself is becoming more complex.
+
diff --git a/17 - Enhance Security/010 User Behavior Analytics OB 4.5_en.srt b/17 - Enhance Security/010 User Behavior Analytics OB 4.5_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..ab47bbbd845bc5bf03313d4c828fad2813a88482
--- /dev/null
+++ b/17 - Enhance Security/010 User Behavior Analytics OB 4.5_en.srt
@@ -0,0 +1,184 @@
+1
+00:00:00,000 --> 00:00:06,000
+Organizations today are building profiles of how users use a computer.
+
+2
+00:00:06,000 --> 00:00:08,000
+Organizations today will know how you're going to use a computer.
+
+3
+00:00:08,000 --> 00:00:12,000
+Like how much data do you transfer at 9:00?
+
+4
+00:00:12,000 --> 00:00:15,000
+What kind of files do you access between 9 and 10:00 in the morning?
+
+5
+00:00:15,000 --> 00:00:22,000
+What the company is doing is they're doing a profile of you and what we're going to call user behavior
+
+6
+00:00:22,000 --> 00:00:23,000
+analytics.
+
+7
+00:00:23,000 --> 00:00:29,000
+What this has done is basically monitor and evaluate the user behavior on IT systems and network.
+
+8
+00:00:29,000 --> 00:00:31,000
+And if you're wondering, well, why would they want to do that?
+
+9
+00:00:31,000 --> 00:00:38,000
+Why would they want to create a profile of how I use the systems, what kind of files I access, how
+
+10
+00:00:38,000 --> 00:00:45,000
+much data I transfer, what devices I access when I access device, the, the server or the or the network.
+
+11
+00:00:45,000 --> 00:00:47,000
+Where do I access it from?
+
+12
+00:00:47,000 --> 00:00:49,000
+You might ask yourself, why are they doing this?
+
+13
+00:00:49,000 --> 00:00:51,000
+Because that's what behavior analytics is.
+
+14
+00:00:51,000 --> 00:00:53,000
+It's how you use the system.
+
+15
+00:00:53,000 --> 00:00:58,000
+It involves collecting, analyzing data on how users interact with the systems and network.
+
+16
+00:00:58,000 --> 00:01:01,000
+This includes access to systems, data, network operations.
+
+17
+00:01:01,000 --> 00:01:03,000
+If you're asking Andrew, why are they doing that?
+
+18
+00:01:03,000 --> 00:01:05,000
+Why are they collecting all this data on me?
+
+19
+00:01:05,000 --> 00:01:13,000
+Well, that's because they want to be able to detect abnormal and deviations from normal user behavior
+
+20
+00:01:13,000 --> 00:01:18,000
+that could indicate potential security threats, such as insider threats, compromise accounts, and
+
+21
+00:01:18,000 --> 00:01:23,000
+even compromise accounts or external attacks using stolen credentials.
+
+22
+00:01:23,000 --> 00:01:24,000
+Let me give you some examples.
+
+23
+00:01:25,000 --> 00:01:26,000
+Let's say your company is doing this.
+
+24
+00:01:26,000 --> 00:01:32,000
+Let's say your company creates a user behavior analytical profile on you.
+
+25
+00:01:32,000 --> 00:01:37,000
+And they know that at 9:00 you log in generally from this computer.
+
+26
+00:01:37,000 --> 00:01:39,000
+You access these particular files.
+
+27
+00:01:39,000 --> 00:01:43,000
+You stay you stay using those files from 9 to 12:00.
+
+28
+00:01:43,000 --> 00:01:46,000
+Then you go away for lunch and so on and so on, basically the entire day.
+
+29
+00:01:46,000 --> 00:01:49,000
+And you do this almost in a everyday basis.
+
+30
+00:01:49,000 --> 00:01:56,000
+Now, what if on Thursday you decide to take the day off, but all of a sudden your account starts to
+
+31
+00:01:56,000 --> 00:02:00,000
+access files, but not from that IP address from a different IP address.
+
+32
+00:02:00,000 --> 00:02:06,000
+Then it starts to access all kinds of files that generally you don't access, and it starts to download
+
+33
+00:02:06,000 --> 00:02:08,000
+it to its local machine.
+
+34
+00:02:08,000 --> 00:02:08,000
+What does that sound like?
+
+35
+00:02:08,000 --> 00:02:12,000
+That sounds like somebody may be using your credentials that could have been stolen.
+
+36
+00:02:13,000 --> 00:02:17,000
+It sounds like data is being stolen from the organization.
+
+37
+00:02:17,000 --> 00:02:21,000
+Now all of a sudden, because they have this user profile on you.
+
+38
+00:02:21,000 --> 00:02:24,000
+Basically, now they can come in and say, well, this is abnormal.
+
+39
+00:02:24,000 --> 00:02:29,000
+Shut this user down or shut, or get this person off the network and then they can verify with you,
+
+40
+00:02:29,000 --> 00:02:30,000
+were you doing this?
+
+41
+00:02:30,000 --> 00:02:31,000
+And you're going to say, no, I wasn't me, okay.
+
+42
+00:02:31,000 --> 00:02:34,000
+That way they're able to minimize this attack.
+
+43
+00:02:34,000 --> 00:02:40,000
+So this is something that is very useful in the world of it, because we need to know how users interact
+
+44
+00:02:40,000 --> 00:02:41,000
+with our systems.
+
+45
+00:02:41,000 --> 00:02:48,000
+That way if somebody does something abnormal, we can detect it and see if it was actually them or a
+
+46
+00:02:48,000 --> 00:02:49,000
+hacker.
+
diff --git a/17 - Enhance Security/011 Deception and Disruption Technology OB 1.2_en.srt b/17 - Enhance Security/011 Deception and Disruption Technology OB 1.2_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..28c5cd1a0e526c760d9620e3e8eab0b80a5f1fc6
--- /dev/null
+++ b/17 - Enhance Security/011 Deception and Disruption Technology OB 1.2_en.srt
@@ -0,0 +1,400 @@
+1
+00:00:00,000 --> 00:00:05,000
+Any time an attacker breaks into the organization, they're going to immediately start looking for the
+
+2
+00:00:05,000 --> 00:00:06,000
+good stuff.
+
+3
+00:00:06,000 --> 00:00:11,000
+They're going to start looking for things like servers that have credit card information, your customer's
+
+4
+00:00:11,000 --> 00:00:14,000
+credit card, or your employees private information.
+
+5
+00:00:14,000 --> 00:00:16,000
+They're going to start looking for business secrets.
+
+6
+00:00:16,000 --> 00:00:21,000
+Now, the best thing we can do is, of course, to secure these things.
+
+7
+00:00:21,000 --> 00:00:25,000
+Another thing we should be doing is just give it to them.
+
+8
+00:00:25,000 --> 00:00:27,000
+Yeah, that sounds kind of crazy, right?
+
+9
+00:00:27,000 --> 00:00:33,000
+You see, there is an old saying if somebody breaks into the organization, just give them what they
+
+10
+00:00:33,000 --> 00:00:34,000
+want so they can go, right.
+
+11
+00:00:34,000 --> 00:00:37,000
+It's an all time thing that people would do before.
+
+12
+00:00:37,000 --> 00:00:40,000
+In the world of information technology, we have these things.
+
+13
+00:00:40,000 --> 00:00:44,000
+And this is going to be called like honey pots, honey nets, honey files, honey tokens.
+
+14
+00:00:44,000 --> 00:00:48,000
+You see what these are are decoy systems and decoy data.
+
+15
+00:00:48,000 --> 00:00:53,000
+Basically what we're going to do is we're going to set up a system that when people break into the organization,
+
+16
+00:00:53,000 --> 00:00:56,000
+they're going to get a system that looks legit.
+
+17
+00:00:56,000 --> 00:00:59,000
+It has or what they believe legit data.
+
+18
+00:00:59,000 --> 00:01:02,000
+It has data that looks good to them.
+
+19
+00:01:02,000 --> 00:01:04,000
+Basically it's honey for them.
+
+20
+00:01:04,000 --> 00:01:10,000
+You see, if we give them what they want, they're probably just going to take it and go instead of
+
+21
+00:01:10,000 --> 00:01:13,000
+just keep looking around for the actual information.
+
+22
+00:01:14,000 --> 00:01:18,000
+Now what we're trying to do here is basically deceive them.
+
+23
+00:01:18,000 --> 00:01:19,000
+That's basically what we're trying to do.
+
+24
+00:01:19,000 --> 00:01:25,000
+So deception and disruption technology refers to a set of cybersecurity strategies and tools designed
+
+25
+00:01:25,000 --> 00:01:28,000
+to we want to mislead them.
+
+26
+00:01:28,000 --> 00:01:34,000
+We want to confuse them or disrupt the actions of these bad people or malicious actors.
+
+27
+00:01:34,000 --> 00:01:41,000
+These technologies are going to use to create traps or illusions that protected real network assets.
+
+28
+00:01:42,000 --> 00:01:47,000
+That protected real network assets by diverting attackers to decoy systems or files.
+
+29
+00:01:47,000 --> 00:01:51,000
+So what we're going to do is we're going to want to create a trap, and what we're going to do is actually
+
+30
+00:01:51,000 --> 00:01:56,000
+we're protecting our real network, because what we're doing is we're going to be giving them a decoy
+
+31
+00:01:56,000 --> 00:01:57,000
+system or a fake system.
+
+32
+00:01:57,000 --> 00:02:01,000
+Now let's go through some of the different technologies we want to be familiar with.
+
+33
+00:02:01,000 --> 00:02:02,000
+The first one is a honeypot.
+
+34
+00:02:03,000 --> 00:02:04,000
+Now, what exactly is this?
+
+35
+00:02:04,000 --> 00:02:06,000
+Well, a honeypot is basically a big server.
+
+36
+00:02:06,000 --> 00:02:10,000
+It's a system on your network that has big data on it.
+
+37
+00:02:10,000 --> 00:02:16,000
+So a honeypot is a security mechanism set up to detect deflate or.
+
+38
+00:02:16,000 --> 00:02:20,000
+Are study hacking attempts.
+
+39
+00:02:20,000 --> 00:02:21,000
+I want you to point that out.
+
+40
+00:02:21,000 --> 00:02:22,000
+Study hacking attempts.
+
+41
+00:02:22,000 --> 00:02:28,000
+You see, let's say somebody breaks into your organization and you have this server that looks all beautiful
+
+42
+00:02:28,000 --> 00:02:30,000
+and sweet, like this honeypot here.
+
+43
+00:02:31,000 --> 00:02:37,000
+So they break in and they see the server and you call it a financial file server.
+
+44
+00:02:37,000 --> 00:02:39,000
+So it has a good name.
+
+45
+00:02:39,000 --> 00:02:42,000
+They look at it, the hacker goes, oh this looks great.
+
+46
+00:02:42,000 --> 00:02:43,000
+All the financial data is there.
+
+47
+00:02:43,000 --> 00:02:44,000
+They double click on it right.
+
+48
+00:02:44,000 --> 00:02:45,000
+They try to get into it.
+
+49
+00:02:45,000 --> 00:02:49,000
+Now it's probably going to have some vulnerabilities that should be easily exploitable.
+
+50
+00:02:49,000 --> 00:02:52,000
+So they get in and they start to see all this data.
+
+51
+00:02:52,000 --> 00:02:54,000
+So what are we doing now.
+
+52
+00:02:54,000 --> 00:02:56,000
+We have all kinds of detection software in that server.
+
+53
+00:02:56,000 --> 00:02:59,000
+So we can detect this attempted intrusion.
+
+54
+00:02:59,000 --> 00:03:05,000
+What we did do is we basically deflect the intrusion the the intrusion off to somebody else.
+
+55
+00:03:05,000 --> 00:03:06,000
+Right.
+
+56
+00:03:06,000 --> 00:03:12,000
+Because instead of them looking for the actual financial server there have been deflected to this fake
+
+57
+00:03:12,000 --> 00:03:13,000
+server that we set up.
+
+58
+00:03:13,000 --> 00:03:17,000
+And now what we could do is we could study the hacking attempts basically.
+
+59
+00:03:17,000 --> 00:03:23,000
+Now we could see how exactly are they, how how are they getting in, what techniques are they using?
+
+60
+00:03:23,000 --> 00:03:28,000
+It's basically a decoy intimidating a real computer system or network.
+
+61
+00:03:28,000 --> 00:03:30,000
+But it's isolated and it's heavily monitored.
+
+62
+00:03:30,000 --> 00:03:34,000
+Attackers will engage with the honeypot, provide valuable information about their techniques.
+
+63
+00:03:34,000 --> 00:03:39,000
+Remember, again, we're studying it and intentions without endangering actual network.
+
+64
+00:03:39,000 --> 00:03:39,000
+Why?
+
+65
+00:03:39,000 --> 00:03:42,000
+Because what's there we know it doesn't have anything secure.
+
+66
+00:03:42,000 --> 00:03:46,000
+Now, if you want to go all out, I would suggest you set up a honey net.
+
+67
+00:03:46,000 --> 00:03:52,000
+It's basically a bunch of these honeypots, a bunch of these fake systems to simulate a whole network
+
+68
+00:03:52,000 --> 00:03:52,000
+environment.
+
+69
+00:03:52,000 --> 00:03:56,000
+So they're going to think, wow, we just got the mother lode of the entire company.
+
+70
+00:03:56,000 --> 00:03:57,000
+We just got the whole network.
+
+71
+00:03:57,000 --> 00:03:59,000
+But basically it's a fake network.
+
+72
+00:03:59,000 --> 00:04:04,000
+It's much more complex, but it does provide deeper insights on how they can interact with network components,
+
+73
+00:04:04,000 --> 00:04:06,000
+what strategy they use, and how they move.
+
+74
+00:04:07,000 --> 00:04:08,000
+Within that network.
+
+75
+00:04:08,000 --> 00:04:11,000
+Now another one you have is going to be a honey file.
+
+76
+00:04:11,000 --> 00:04:14,000
+Now honey files you can put on different systems.
+
+77
+00:04:14,000 --> 00:04:15,000
+You can put them on legitimate system.
+
+78
+00:04:15,000 --> 00:04:20,000
+Now these are going to be decoy files placed within a networks file system.
+
+79
+00:04:20,000 --> 00:04:24,000
+Honey files are designed to appear legitimate and contains, uh, attractive data.
+
+80
+00:04:24,000 --> 00:04:26,000
+So you may name a honey file.
+
+81
+00:04:27,000 --> 00:04:29,000
+Username and passwords.
+
+82
+00:04:29,000 --> 00:04:35,000
+You may name a honey file something as a customer's credit card information, but what you're doing
+
+83
+00:04:35,000 --> 00:04:38,000
+is you're going to put it on the server, you're going to leave it there.
+
+84
+00:04:38,000 --> 00:04:41,000
+And if anybody tries to access this, you're going to know, because you're monitoring this file.
+
+85
+00:04:41,000 --> 00:04:47,000
+Any kind of access to the honey file can alert security professionals, uh, personnel about this.
+
+86
+00:04:47,000 --> 00:04:50,000
+Another thing you might have is something called a honey token.
+
+87
+00:04:50,000 --> 00:04:52,000
+And this is a little bit more granular.
+
+88
+00:04:52,000 --> 00:04:56,000
+A honey token is a broader tum refers to any decoy data or token inserted into a system.
+
+89
+00:04:56,000 --> 00:05:02,000
+Now, it could be things like a fake user account, even a database record, or the type of digital
+
+90
+00:05:02,000 --> 00:05:03,000
+bait.
+
+91
+00:05:04,000 --> 00:05:09,000
+So, for example, inserting fake records into a customer's database.
+
+92
+00:05:09,000 --> 00:05:14,000
+And if anybody tries to pull or manipulate that data, it would alert a security professional.
+
+93
+00:05:14,000 --> 00:05:15,000
+So there would be a honey token.
+
+94
+00:05:16,000 --> 00:05:18,000
+Honey nets are incredibly popular.
+
+95
+00:05:19,000 --> 00:05:22,000
+Uh, honey pots are also incredibly popular.
+
+96
+00:05:22,000 --> 00:05:22,000
+Why?
+
+97
+00:05:22,000 --> 00:05:26,000
+Because remember, like I said, when somebody breaks into your house, give them what they want so
+
+98
+00:05:26,000 --> 00:05:27,000
+they can go.
+
+99
+00:05:27,000 --> 00:05:29,000
+That's the easiest way to do it.
+
+100
+00:05:29,000 --> 00:05:33,000
+And an IT security, we're basically going to do the same with these technology.
+
diff --git a/17 - Enhance Security/012 Automation and Orchestration OB 4.7_en.srt b/17 - Enhance Security/012 Automation and Orchestration OB 4.7_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..8cef44288ee7f9b7ec500661dab2edcffe4028cb
--- /dev/null
+++ b/17 - Enhance Security/012 Automation and Orchestration OB 4.7_en.srt
@@ -0,0 +1,832 @@
+1
+00:00:00,000 --> 00:00:06,000
+When it comes to managing an IT system across a large network, dealing with a large number of users,
+
+2
+00:00:06,000 --> 00:00:13,000
+you need to automate as many things as possible without automation and or orchestration.
+
+3
+00:00:13,000 --> 00:00:18,000
+Keep in mind, orchestration generally means to automate things when it comes to orchestrations within
+
+4
+00:00:18,000 --> 00:00:22,000
+large networks, one of the best ways to do that is with scripting.
+
+5
+00:00:22,000 --> 00:00:26,000
+You see in it we have many, many tasks that are just repetitive over and over.
+
+6
+00:00:26,000 --> 00:00:28,000
+So why would you have humans do that?
+
+7
+00:00:28,000 --> 00:00:30,000
+If you can just have a script that does it?
+
+8
+00:00:30,000 --> 00:00:36,000
+There are also times when we need to respond to things quickly, and if we are dependent on humans to
+
+9
+00:00:36,000 --> 00:00:37,000
+do it, it might take a while.
+
+10
+00:00:37,000 --> 00:00:42,000
+But if we have some kind of a script or automation to do that, it will probably be better.
+
+11
+00:00:42,000 --> 00:00:49,000
+So in this video, we're going to go through some of the practical applications or the use cases for
+
+12
+00:00:49,000 --> 00:00:50,000
+scripting.
+
+13
+00:00:50,000 --> 00:00:50,000
+All right.
+
+14
+00:00:50,000 --> 00:00:52,000
+So where can we apply scripting from.
+
+15
+00:00:52,000 --> 00:00:57,000
+Because scripting is how we're going to get that automation and orchestration that we need in order
+
+16
+00:00:57,000 --> 00:01:00,000
+to keep our networks running smoothly.
+
+17
+00:01:00,000 --> 00:01:04,000
+So let's go through some of the things here that scripting can help us with.
+
+18
+00:01:04,000 --> 00:01:06,000
+So the first thing up is user provisioning.
+
+19
+00:01:06,000 --> 00:01:08,000
+This is one of the best things that a script can do.
+
+20
+00:01:08,000 --> 00:01:13,000
+So automated in user provisioning involves scripts or automated workflows.
+
+21
+00:01:13,000 --> 00:01:15,000
+To create manage accounts.
+
+22
+00:01:15,000 --> 00:01:20,000
+We can have scripts that can create accounts and delete accounts or disable accounts on the fly.
+
+23
+00:01:20,000 --> 00:01:24,000
+This includes setting up accounts, assigning privileges, removing access.
+
+24
+00:01:24,000 --> 00:01:29,000
+So instead of having somebody right click Open Active Directory, right click make a user create passwords,
+
+25
+00:01:29,000 --> 00:01:30,000
+put them.
+
+26
+00:01:30,000 --> 00:01:32,000
+We can automate the entire thing.
+
+27
+00:01:32,000 --> 00:01:33,000
+We just put in a few parameters.
+
+28
+00:01:33,000 --> 00:01:35,000
+Run a script and we're done.
+
+29
+00:01:36,000 --> 00:01:37,000
+Resource provisioning.
+
+30
+00:01:37,000 --> 00:01:46,000
+So this in this use case involves automatically allocating and managing computer resources such as CPU
+
+31
+00:01:46,000 --> 00:01:46,000
+and memory.
+
+32
+00:01:47,000 --> 00:01:51,000
+Automations help in dynamically adjusting resources, so if you have a system.
+
+33
+00:01:52,000 --> 00:01:56,000
+That you're running on a particular, you're running a particular service, and you need to readjust
+
+34
+00:01:56,000 --> 00:01:58,000
+the hardware allocation in that system.
+
+35
+00:01:58,000 --> 00:02:00,000
+You can write a script that does that.
+
+36
+00:02:00,000 --> 00:02:02,000
+You don't have to go and manually do it.
+
+37
+00:02:02,000 --> 00:02:04,000
+Another case where this can help.
+
+38
+00:02:04,000 --> 00:02:05,000
+Guardrails.
+
+39
+00:02:05,000 --> 00:02:06,000
+Guardrails.
+
+40
+00:02:07,000 --> 00:02:08,000
+You do this too?
+
+41
+00:02:08,000 --> 00:02:15,000
+Automation involves setting up scripts or automated security controls to enforce security policies for
+
+42
+00:02:15,000 --> 00:02:16,000
+operational best practices.
+
+43
+00:02:16,000 --> 00:02:17,000
+Limits.
+
+44
+00:02:17,000 --> 00:02:23,000
+This includes limits on user access, automated compliance checks, and restrictions on type of action.
+
+45
+00:02:23,000 --> 00:02:30,000
+So guardrails are basically if a user attempts to do a task that they weren't supposed to be doing.
+
+46
+00:02:30,000 --> 00:02:36,000
+Basically, scripts can come in and and deny access to that thing that they're trying to do.
+
+47
+00:02:36,000 --> 00:02:40,000
+This, of course, limits them or puts a guardrail around them so they can't get out.
+
+48
+00:02:41,000 --> 00:02:43,000
+Security groups.
+
+49
+00:02:43,000 --> 00:02:45,000
+Automation is used to manage security groups.
+
+50
+00:02:45,000 --> 00:02:46,000
+What is security groups?
+
+51
+00:02:46,000 --> 00:02:51,000
+So think of like the accountant, the salespeople, the accountant or the sales groups, which are a
+
+52
+00:02:51,000 --> 00:02:55,000
+set of users or systems that have common security requirements.
+
+53
+00:02:55,000 --> 00:02:57,000
+Now scripts are automated.
+
+54
+00:02:57,000 --> 00:03:03,000
+Tools can ensure these groups are kept up to date, so we can write scripts to remove users when that
+
+55
+00:03:03,000 --> 00:03:05,000
+person leaves or that account is deleted.
+
+56
+00:03:05,000 --> 00:03:08,000
+And we can also write scripts to add people to security groups.
+
+57
+00:03:08,000 --> 00:03:09,000
+Tickets.
+
+58
+00:03:10,000 --> 00:03:15,000
+In incident response service management automation plays a critical role.
+
+59
+00:03:15,000 --> 00:03:15,000
+Why?
+
+60
+00:03:15,000 --> 00:03:18,000
+Because remember what ticketing is when it comes to tickets.
+
+61
+00:03:18,000 --> 00:03:19,000
+And we're not talking those tickets.
+
+62
+00:03:19,000 --> 00:03:24,000
+Actually, when it comes to ticket we're talking help desk tickets.
+
+63
+00:03:24,000 --> 00:03:29,000
+So help desk tickets is when somebody has a problem with their computer, they call the local help desk.
+
+64
+00:03:29,000 --> 00:03:30,000
+Help desk creates a ticket.
+
+65
+00:03:30,000 --> 00:03:35,000
+Now that ticket is going to have to go through like the ticket is open.
+
+66
+00:03:35,000 --> 00:03:36,000
+The ticket is analyzed.
+
+67
+00:03:36,000 --> 00:03:38,000
+The ticket, uh, we fixed the problem.
+
+68
+00:03:38,000 --> 00:03:40,000
+The ticket has to be closed.
+
+69
+00:03:40,000 --> 00:03:45,000
+Automation can help detect any kind of problems with issuing and generating that ticket.
+
+70
+00:03:45,000 --> 00:03:50,000
+And it can also do things such as close the ticket for you or let the user know the ticket is closed.
+
+71
+00:03:50,000 --> 00:03:54,000
+But one of the main things is going to do is it's going to ensure that potential security incidents
+
+72
+00:03:55,000 --> 00:03:56,000
+are promptly recorded and addressed.
+
+73
+00:03:56,000 --> 00:04:00,000
+You see, all security incidents are generally reported to the help desk.
+
+74
+00:04:00,000 --> 00:04:05,000
+If you have an automated system that does it that keeps the track of these tickets, it just makes recording
+
+75
+00:04:05,000 --> 00:04:07,000
+those security incidents better.
+
+76
+00:04:09,000 --> 00:04:09,000
+Escalation.
+
+77
+00:04:09,000 --> 00:04:17,000
+We can use automation in escalation involved using scripts or tool to identify high priority incidents
+
+78
+00:04:17,000 --> 00:04:18,000
+and escalate them.
+
+79
+00:04:18,000 --> 00:04:21,000
+So let's say a security incident comes right into the help desk.
+
+80
+00:04:21,000 --> 00:04:25,000
+And in the help desk it comes it has these potential characteristics.
+
+81
+00:04:25,000 --> 00:04:31,000
+We can write scripts that looks at those characteristics and say, well, this here has to be escalated
+
+82
+00:04:31,000 --> 00:04:34,000
+up to level two or level three IT security support.
+
+83
+00:04:34,000 --> 00:04:38,000
+This saves time, especially when it's a critical issue.
+
+84
+00:04:39,000 --> 00:04:41,000
+Enable and disable and services.
+
+85
+00:04:42,000 --> 00:04:48,000
+So automation can help start and stop certain services on systems.
+
+86
+00:04:48,000 --> 00:04:56,000
+Scripts can automatically disable access for users who are no longer needed, uh, or it enables for
+
+87
+00:04:56,000 --> 00:05:02,000
+users based on a predefined so we can run certain services when needed.
+
+88
+00:05:02,000 --> 00:05:07,000
+When not needed, we can add users to those servers or remove users when not needed.
+
+89
+00:05:07,000 --> 00:05:11,000
+Can continuous integration and testing.
+
+90
+00:05:11,000 --> 00:05:11,000
+So.
+
+91
+00:05:12,000 --> 00:05:14,000
+When users, when not users.
+
+92
+00:05:14,000 --> 00:05:19,000
+When programmers write codes, what happens as they write code?
+
+93
+00:05:19,000 --> 00:05:26,000
+We can test the code as they're writing, so we're consistently integrating and testing codes.
+
+94
+00:05:26,000 --> 00:05:31,000
+Automation is used for continuous integration and testing, where code changes are automatically tested
+
+95
+00:05:31,000 --> 00:05:32,000
+for security flaws.
+
+96
+00:05:32,000 --> 00:05:36,000
+So the moment people write code, we can test the code before pushing it out.
+
+97
+00:05:36,000 --> 00:05:40,000
+This helps early detection of code or any kind of software development issues.
+
+98
+00:05:40,000 --> 00:05:41,000
+Now.
+
+99
+00:05:41,000 --> 00:05:42,000
+APIs.
+
+100
+00:05:43,000 --> 00:05:50,000
+Automation will involve the use of many APIs to integrate different tools.
+
+101
+00:05:50,000 --> 00:05:54,000
+If we're going to be automating this system to communicate with this system, you bet.
+
+102
+00:05:54,000 --> 00:05:57,000
+Our best bet to allow two systems to communicate.
+
+103
+00:05:57,000 --> 00:06:00,000
+We're going to use some kind of API to have them integrate.
+
+104
+00:06:00,000 --> 00:06:02,000
+This is going to allow data exchanges on system.
+
+105
+00:06:03,000 --> 00:06:10,000
+Now automation is going to have quite a few benefits that we want.
+
+106
+00:06:10,000 --> 00:06:10,000
+All right.
+
+107
+00:06:10,000 --> 00:06:16,000
+They just not only enhance security by being able, for example, respond to tickets quickly and escalate
+
+108
+00:06:16,000 --> 00:06:18,000
+those tickets quickly like we just mentioned before.
+
+109
+00:06:18,000 --> 00:06:22,000
+But they're going to have some other benefits that we want to consider.
+
+110
+00:06:22,000 --> 00:06:23,000
+Number one.
+
+111
+00:06:23,000 --> 00:06:31,000
+Automation in its nature is able to save time because automation, we don't have to wait for somebody
+
+112
+00:06:31,000 --> 00:06:34,000
+to come and manually do the task.
+
+113
+00:06:34,000 --> 00:06:39,000
+So automation significantly reduces the time to perform repetitive or complex tasks.
+
+114
+00:06:39,000 --> 00:06:42,000
+It frees up your IT staff to do other things.
+
+115
+00:06:42,000 --> 00:06:45,000
+It enforces a particular baseline.
+
+116
+00:06:46,000 --> 00:06:47,000
+Remember what's a baseline?
+
+117
+00:06:47,000 --> 00:06:53,000
+A baseline is a standard set of configuration that a computer has any changes to.
+
+118
+00:06:53,000 --> 00:06:56,000
+That would be a variation for the baseline, maybe against security policy.
+
+119
+00:06:57,000 --> 00:07:01,000
+Now where automation comes in or scripting, they're going to automatically enforce this across all
+
+120
+00:07:01,000 --> 00:07:03,000
+the systems.
+
+121
+00:07:03,000 --> 00:07:08,000
+If there is anything that comes out of compliance, automation can tell you that this system is out
+
+122
+00:07:08,000 --> 00:07:09,000
+of compliance.
+
+123
+00:07:10,000 --> 00:07:13,000
+It standardizes infrastructure configuration.
+
+124
+00:07:13,000 --> 00:07:17,000
+Automation helps in doing that reduces the risk of configuration errors.
+
+125
+00:07:17,000 --> 00:07:22,000
+Now let's say you got to configure ten switches on a network.
+
+126
+00:07:22,000 --> 00:07:24,000
+And it must have all the same configs.
+
+127
+00:07:24,000 --> 00:07:30,000
+Well you could give it to different uh network engineers or to configure it.
+
+128
+00:07:30,000 --> 00:07:36,000
+Or you can just run a script and have the script configure them all at the same time with the same configuration.
+
+129
+00:07:36,000 --> 00:07:39,000
+So this reduces the risk of configuration errors.
+
+130
+00:07:40,000 --> 00:07:41,000
+Now scaling.
+
+131
+00:07:42,000 --> 00:07:48,000
+Of course, the more we're able to do right, the bigger our systems can get.
+
+132
+00:07:48,000 --> 00:07:51,000
+It allows us to scale our operations.
+
+133
+00:07:51,000 --> 00:07:53,000
+If we don't have automation, we can't scale.
+
+134
+00:07:53,000 --> 00:07:56,000
+Because remember, scale means to get bigger.
+
+135
+00:07:56,000 --> 00:07:57,000
+If we get bigger.
+
+136
+00:07:58,000 --> 00:08:02,000
+The manpower is going to be too much that we're going to need to maintain without automation.
+
+137
+00:08:02,000 --> 00:08:03,000
+It helps us to grow.
+
+138
+00:08:03,000 --> 00:08:04,000
+It helps us to manage our security.
+
+139
+00:08:04,000 --> 00:08:12,000
+It helps us to for, uh, like like the previous thing we mentioned, to ensure our baselines are standardized
+
+140
+00:08:12,000 --> 00:08:16,000
+and consistent, ensures our configurations are consistent.
+
+141
+00:08:18,000 --> 00:08:18,000
+Now.
+
+142
+00:08:18,000 --> 00:08:20,000
+It also helps in employee retention.
+
+143
+00:08:20,000 --> 00:08:23,000
+I know you guys are saying how is that a benefit?
+
+144
+00:08:23,000 --> 00:08:28,000
+Well, higher employee satisfaction, reducing the burden of repetitive tasks.
+
+145
+00:08:28,000 --> 00:08:31,000
+You know, nobody wants to sit and do the same thing over and over and over.
+
+146
+00:08:31,000 --> 00:08:34,000
+That's what a computer is good at, something doing over and over.
+
+147
+00:08:34,000 --> 00:08:35,000
+It allows them.
+
+148
+00:08:35,000 --> 00:08:41,000
+It folks, me and you included, to focus on more challenging and rewarding work, leading to better
+
+149
+00:08:41,000 --> 00:08:42,000
+job satisfaction.
+
+150
+00:08:43,000 --> 00:08:46,000
+Reaction time is reduced.
+
+151
+00:08:46,000 --> 00:08:47,000
+All right.
+
+152
+00:08:47,000 --> 00:08:51,000
+So quicker responses to different systems is amazing.
+
+153
+00:08:51,000 --> 00:08:56,000
+We want to keep reaction time low especially in security incidents.
+
+154
+00:08:57,000 --> 00:08:59,000
+For example if a computer.
+
+155
+00:09:00,000 --> 00:09:01,000
+On a network gets hacked.
+
+156
+00:09:02,000 --> 00:09:05,000
+You want to respond to that ASAP.
+
+157
+00:09:05,000 --> 00:09:10,000
+Take that machine off the network before that malware spreads to other computers.
+
+158
+00:09:10,000 --> 00:09:11,000
+You don't want that.
+
+159
+00:09:11,000 --> 00:09:17,000
+So automated system can detect and response to threat real time reducing the damage on it.
+
+160
+00:09:17,000 --> 00:09:19,000
+Workforce multiplier.
+
+161
+00:09:19,000 --> 00:09:20,000
+What exactly is that?
+
+162
+00:09:20,000 --> 00:09:25,000
+Automation acts as a force multiplier for cybersecurity workforce.
+
+163
+00:09:25,000 --> 00:09:29,000
+Remember with this it allows us to do more with less.
+
+164
+00:09:29,000 --> 00:09:34,000
+While automation handles routine tasks, a smaller team can effectively manage a large network.
+
+165
+00:09:34,000 --> 00:09:41,000
+So remember more less folks can do more because now we have more automation, more scripting in there.
+
+166
+00:09:41,000 --> 00:09:50,000
+Now, while while it's it seems good and you know, in this video, almost everything I've talked about,
+
+167
+00:09:50,000 --> 00:09:58,000
+all the good security aspects, the benefits of it, it does come with a couple of things that does
+
+168
+00:09:58,000 --> 00:10:01,000
+increase, such as complexity, some negative things.
+
+169
+00:10:01,000 --> 00:10:04,000
+It does introduce complexity into the systems.
+
+170
+00:10:04,000 --> 00:10:05,000
+It simplifies.
+
+171
+00:10:05,000 --> 00:10:10,000
+It sounds simple to write scripts to do something, but write in scripts itself is not simple.
+
+172
+00:10:11,000 --> 00:10:17,000
+Whether you're using PowerShell scripts or using some kind of JavaScript Python scripting to do your
+
+173
+00:10:17,000 --> 00:10:24,000
+task or bash bash scripting and Linux, keep in mind that is a specialized knowledge that's needed.
+
+174
+00:10:25,000 --> 00:10:25,000
+Now.
+
+175
+00:10:25,000 --> 00:10:30,000
+Simple things you can probably do, like setting up and managing certain automated workflows.
+
+176
+00:10:30,000 --> 00:10:37,000
+But a lot of this does require specialized knowledge and it does require specialized tools costs.
+
+177
+00:10:37,000 --> 00:10:42,000
+Writing these scripts and managing these scripts generally will involve a certain amount of costs.
+
+178
+00:10:44,000 --> 00:10:51,000
+Now the initial investment in the scripting or the technology or the training for staff, for example,
+
+179
+00:10:51,000 --> 00:10:56,000
+not many IT folks are good at Python like I wasn't.
+
+180
+00:10:56,000 --> 00:11:02,000
+I studied, I had many, many Microsoft and Cisco certification and didn't know Python at all.
+
+181
+00:11:02,000 --> 00:11:06,000
+When I started doing pen testing, I actually had to learn that in order to add to the scripts, so
+
+182
+00:11:06,000 --> 00:11:07,000
+it will involve training.
+
+183
+00:11:09,000 --> 00:11:12,000
+They can lead to long time savings, but the upfront cost could be significant.
+
+184
+00:11:12,000 --> 00:11:14,000
+So in the long run it might save money.
+
+185
+00:11:14,000 --> 00:11:16,000
+But in the beginning it might cost.
+
+186
+00:11:16,000 --> 00:11:21,000
+Scripting system could be a single point of failure, relying heavily on automated system.
+
+187
+00:11:21,000 --> 00:11:27,000
+If that automated system fail and that automated system scripts a lot of things single point of failure.
+
+188
+00:11:27,000 --> 00:11:32,000
+In other words, when that system fails, many of the system that depends on the automated script will
+
+189
+00:11:32,000 --> 00:11:33,000
+fail.
+
+190
+00:11:33,000 --> 00:11:35,000
+So have redundancy in place.
+
+191
+00:11:35,000 --> 00:11:43,000
+Technical debt automation leads to it, uh, if it's implemented without adequate planning.
+
+192
+00:11:43,000 --> 00:11:47,000
+Quick fixes and workaround might solve immediate problem but create long terme issues.
+
+193
+00:11:47,000 --> 00:11:49,000
+So here's what technical debt is.
+
+194
+00:11:49,000 --> 00:11:53,000
+When you have a problem and you don't fix it, then you have another problem.
+
+195
+00:11:53,000 --> 00:11:57,000
+But then you leave that problem and then you don't fix that and then you don't fix it.
+
+196
+00:11:57,000 --> 00:12:01,000
+So the script may break this thing and then it may, you don't fix it and you may move on to something
+
+197
+00:12:01,000 --> 00:12:01,000
+else.
+
+198
+00:12:01,000 --> 00:12:09,000
+And this, of course leads to more debt being built up, ongoing supportability they do require an onboarding
+
+199
+00:12:09,000 --> 00:12:12,000
+because you know why system changes internally and those scripts needs to be adjusted.
+
+200
+00:12:12,000 --> 00:12:15,000
+Regular update and monitoring issues is going to be a problem.
+
+201
+00:12:15,000 --> 00:12:16,000
+Ensure it is adequate.
+
+202
+00:12:16,000 --> 00:12:19,000
+Support for these system is going to be important.
+
+203
+00:12:19,000 --> 00:12:20,000
+All right.
+
+204
+00:12:20,000 --> 00:12:24,000
+So keep in mind that when it comes to scripting it sounds amazing.
+
+205
+00:12:24,000 --> 00:12:29,000
+All these great benefits and security and of course cost savings for management.
+
+206
+00:12:29,000 --> 00:12:34,000
+But it does generally have some down or problems with it.
+
+207
+00:12:34,000 --> 00:12:40,000
+But keep in mind, when it comes to automation or orchestration and automation, the benefits here will
+
+208
+00:12:40,000 --> 00:12:42,000
+generally outweigh the risks.
+
diff --git a/17 - Enhance Security/013 Quick Quiz.html b/17 - Enhance Security/013 Quick Quiz.html
new file mode 100644
index 0000000000000000000000000000000000000000..978b6dbed02d3ec5e5ca6dbbe109902b4ae3de59
--- /dev/null
+++ b/17 - Enhance Security/013 Quick Quiz.html
@@ -0,0 +1,479 @@
+
+
+
+
+
+
+ Quiz
+
+
+
+
+
+
+
+
+ Score: 999 of
+ 999%
+
+ Correct: 999
+ Incorrect: 999
+
+
+
+
+
+
+
+
+
+
diff --git a/18 - Identity and Access Management (IAM)/001 Provisioning Users OB 4.6_en.srt b/18 - Identity and Access Management (IAM)/001 Provisioning Users OB 4.6_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..b4821b7044fe9b9355481b29968bdd45592ef8c3
--- /dev/null
+++ b/18 - Identity and Access Management (IAM)/001 Provisioning Users OB 4.6_en.srt
@@ -0,0 +1,592 @@
+1
+00:00:00,000 --> 00:00:05,000
+As a security administrator, one of the most basic things you're going to be doing is adding users
+
+2
+00:00:05,000 --> 00:00:08,000
+to your network every single day.
+
+3
+00:00:08,000 --> 00:00:11,000
+In large companies, users are fired and users are hired.
+
+4
+00:00:11,000 --> 00:00:14,000
+We have to disable accounts and we have to create accounts.
+
+5
+00:00:14,000 --> 00:00:20,000
+Let's take a look at a standard security process that we're going to use before we can create user accounts,
+
+6
+00:00:20,000 --> 00:00:21,000
+create user accounts.
+
+7
+00:00:21,000 --> 00:00:25,000
+And whenever, whenever they have to leave the company, we're going to disable their account.
+
+8
+00:00:25,000 --> 00:00:26,000
+So let's get started.
+
+9
+00:00:26,000 --> 00:00:32,000
+The first thing that happens, or the first thing that happens in this process of when we hire someone,
+
+10
+00:00:32,000 --> 00:00:34,000
+should be identity proofing.
+
+11
+00:00:34,000 --> 00:00:35,000
+What exactly is this?
+
+12
+00:00:35,000 --> 00:00:39,000
+Well, it says validated that a person is who they claim to be.
+
+13
+00:00:39,000 --> 00:00:41,000
+Did you guys know I'm Andrew Ramdayal?
+
+14
+00:00:41,000 --> 00:00:42,000
+Did you know that?
+
+15
+00:00:42,000 --> 00:00:44,000
+Well, you really don't know that, do you?
+
+16
+00:00:44,000 --> 00:00:47,000
+I said, you believe it because I said it.
+
+17
+00:00:47,000 --> 00:00:48,000
+I haven't proven it to you yet.
+
+18
+00:00:48,000 --> 00:00:50,000
+Have I showed you a driver's license?
+
+19
+00:00:50,000 --> 00:00:51,000
+That I am that person?
+
+20
+00:00:51,000 --> 00:00:52,000
+No.
+
+21
+00:00:52,000 --> 00:00:53,000
+So how do you know it's me?
+
+22
+00:00:54,000 --> 00:00:58,000
+So when you hire someone, you have to be able to prove their identity.
+
+23
+00:00:58,000 --> 00:00:59,000
+And that's what this is.
+
+24
+00:00:59,000 --> 00:01:05,000
+It involves verifying individual identity through various means and before granting them access to your
+
+25
+00:01:05,000 --> 00:01:06,000
+system.
+
+26
+00:01:06,000 --> 00:01:12,000
+Effective identity is key to maintaining security, ensuring regulatory compliance.
+
+27
+00:01:12,000 --> 00:01:17,000
+There will be many, many regulations that ensure that when you hire people, you check their identity
+
+28
+00:01:17,000 --> 00:01:19,000
+building trust in digital transaction.
+
+29
+00:01:19,000 --> 00:01:25,000
+If you don't do this right, you could end up with getting people that's basically they are.
+
+30
+00:01:25,000 --> 00:01:26,000
+They're not who they say they are.
+
+31
+00:01:26,000 --> 00:01:27,000
+How do you do this?
+
+32
+00:01:27,000 --> 00:01:30,000
+Well, there there are various different ways here.
+
+33
+00:01:30,000 --> 00:01:32,000
+And I've got a few different ways here that we can take a look.
+
+34
+00:01:32,000 --> 00:01:35,000
+Number one, verification of personal information.
+
+35
+00:01:35,000 --> 00:01:40,000
+This is going to involve some kind of government issued ID, maybe like my driver's license or Social
+
+36
+00:01:40,000 --> 00:01:42,000
+Security card passports and so on.
+
+37
+00:01:42,000 --> 00:01:48,000
+Biometric data check if you work for the federal or try to get a job at the federal government, they
+
+38
+00:01:48,000 --> 00:01:49,000
+may do a biometric check on you.
+
+39
+00:01:49,000 --> 00:01:52,000
+In other words, you got to give your thumbprint and then they're going to run you against all kinds
+
+40
+00:01:52,000 --> 00:01:54,000
+of databases and other personal information.
+
+41
+00:01:54,000 --> 00:01:57,000
+You then you're going to check them against sources.
+
+42
+00:01:57,000 --> 00:02:02,000
+For example, if they give you a driver's license, you're going to probably verify it against the DMV.
+
+43
+00:02:02,000 --> 00:02:07,000
+There's also knowledge check asking personal questions like, hey, what's your previous address that
+
+44
+00:02:07,000 --> 00:02:08,000
+you have lived at?
+
+45
+00:02:08,000 --> 00:02:09,000
+Document verification.
+
+46
+00:02:09,000 --> 00:02:12,000
+If you do give them things like a passport please, we're going to verify that.
+
+47
+00:02:12,000 --> 00:02:17,000
+And the biometric fingerprints facial recognition could be confirmed.
+
+48
+00:02:18,000 --> 00:02:22,000
+Uh, you could even use a third party service of database to verify folks.
+
+49
+00:02:22,000 --> 00:02:27,000
+Now, once people are verified, basically we know.
+
+50
+00:02:27,000 --> 00:02:28,000
+Okay, this is Bob.
+
+51
+00:02:28,000 --> 00:02:31,000
+Now let's go ahead and create Bob an account.
+
+52
+00:02:31,000 --> 00:02:36,000
+This is going to be called provisioning user accounts or creating user accounts.
+
+53
+00:02:36,000 --> 00:02:41,000
+This refers to creating and setting up a new user account with the appropriate rights on the network.
+
+54
+00:02:41,000 --> 00:02:47,000
+Now the first step once again when it comes to provisioning or creating a user account is of course
+
+55
+00:02:47,000 --> 00:02:48,000
+ID.
+
+56
+00:02:48,000 --> 00:02:48,000
+And the person.
+
+57
+00:02:48,000 --> 00:02:50,000
+Now we talked about that.
+
+58
+00:02:50,000 --> 00:02:55,000
+One of the things we want to do though, is when we create or allow people to join our networks, we
+
+59
+00:02:55,000 --> 00:02:58,000
+have to be careful with the rights that we give them.
+
+60
+00:02:58,000 --> 00:03:00,000
+We don't want to give them too much rights.
+
+61
+00:03:00,000 --> 00:03:04,000
+We want to give them just enough rights so that they can do their job.
+
+62
+00:03:04,000 --> 00:03:06,000
+This is known as the principles of least privileges.
+
+63
+00:03:06,000 --> 00:03:10,000
+So assign an appropriate access level based on the user role.
+
+64
+00:03:10,000 --> 00:03:15,000
+For example, they're going to be working in the accounting department.
+
+65
+00:03:15,000 --> 00:03:17,000
+Then make them a member of the accounting group.
+
+66
+00:03:17,000 --> 00:03:20,000
+And then they only have access to the account and applications.
+
+67
+00:03:20,000 --> 00:03:24,000
+If in the accounting department they only work in accounts payable, then just give them access to accounts
+
+68
+00:03:24,000 --> 00:03:25,000
+payable.
+
+69
+00:03:25,000 --> 00:03:27,000
+They only need to be entering bills and paying bills.
+
+70
+00:03:27,000 --> 00:03:32,000
+They don't need to be doing bank reconciliation or running payroll, or maybe in the accounting department.
+
+71
+00:03:32,000 --> 00:03:34,000
+They're going to be doing all that.
+
+72
+00:03:34,000 --> 00:03:36,000
+You have to know what they're doing to give a minimum access.
+
+73
+00:03:36,000 --> 00:03:41,000
+The next thing you want to do is to create that user account, actually go into your Windows Server,
+
+74
+00:03:41,000 --> 00:03:43,000
+your Active Directory, and create it.
+
+75
+00:03:45,000 --> 00:03:47,000
+Now the other thing here is going to be security measures.
+
+76
+00:03:47,000 --> 00:03:51,000
+This is going to be well what kind of password do we have.
+
+77
+00:03:51,000 --> 00:03:54,000
+Hopefully we have multi-factor authentication.
+
+78
+00:03:54,000 --> 00:03:57,000
+We're using strong passwords when doing this.
+
+79
+00:03:58,000 --> 00:04:04,000
+Now unfortunately at some point every user is going to come to the life of that business or the life
+
+80
+00:04:04,000 --> 00:04:07,000
+of them being in that business because they're going to be out.
+
+81
+00:04:07,000 --> 00:04:10,000
+They'll probably quit the job or the organization is not happy and terminate them.
+
+82
+00:04:10,000 --> 00:04:14,000
+This is called deprovisioning user accounts.
+
+83
+00:04:14,000 --> 00:04:21,000
+This involves a process of removing or disabling user accounts when they're no longer no longer needed
+
+84
+00:04:21,000 --> 00:04:22,000
+within the organization.
+
+85
+00:04:23,000 --> 00:04:24,000
+Now.
+
+86
+00:04:24,000 --> 00:04:30,000
+The first thing you want to do is you want to terminate, disable the account.
+
+87
+00:04:30,000 --> 00:04:32,000
+Now, here's here's something I want to tell you guys.
+
+88
+00:04:33,000 --> 00:04:36,000
+If you are work in it security.
+
+89
+00:04:36,000 --> 00:04:41,000
+You know when people are fired before they even know they're fired.
+
+90
+00:04:41,000 --> 00:04:41,000
+All right.
+
+91
+00:04:41,000 --> 00:04:45,000
+If you're sitting, if you're sitting at it security and you get a call from a manager, let's say the
+
+92
+00:04:45,000 --> 00:04:46,000
+accounting manager.
+
+93
+00:04:46,000 --> 00:04:50,000
+Hey, you know, um, can you terminate Bob's account for me?
+
+94
+00:04:50,000 --> 00:04:50,000
+Yeah.
+
+95
+00:04:50,000 --> 00:04:52,000
+Bob's been fired, all right.
+
+96
+00:04:52,000 --> 00:04:55,000
+And we they generally do this before Bob knows.
+
+97
+00:04:55,000 --> 00:05:02,000
+So if you ever go to work one day and you try to log in and it says account disabled, you've been canned,
+
+98
+00:05:02,000 --> 00:05:02,000
+buddy.
+
+99
+00:05:02,000 --> 00:05:03,000
+Terminated.
+
+100
+00:05:04,000 --> 00:05:05,000
+You've been you you've been kicked out.
+
+101
+00:05:05,000 --> 00:05:06,000
+You've been fired.
+
+102
+00:05:07,000 --> 00:05:14,000
+Organizations should terminate or disable the user account before telling the user that they have been
+
+103
+00:05:14,000 --> 00:05:15,000
+terminated.
+
+104
+00:05:15,000 --> 00:05:20,000
+This way, it prevents any kind of negative retaliation against the the network.
+
+105
+00:05:20,000 --> 00:05:27,000
+Because if I call you, let's say you're in the network and I say, hey, you're fired and your account
+
+106
+00:05:27,000 --> 00:05:27,000
+may still be valid.
+
+107
+00:05:27,000 --> 00:05:32,000
+Now you can log in and you could be malicious, disgruntled employees.
+
+108
+00:05:32,000 --> 00:05:37,000
+And then before you know it, you start deleting data or start, uh, stealing the data, sending it
+
+109
+00:05:37,000 --> 00:05:38,000
+to personal accounts and so on.
+
+110
+00:05:38,000 --> 00:05:42,000
+So one of the first things we're going to do is we're going to terminate the user's access to all the
+
+111
+00:05:42,000 --> 00:05:43,000
+systems and applications.
+
+112
+00:05:43,000 --> 00:05:47,000
+This generally involves terminating at least all the different accounts, ensuring any data associated
+
+113
+00:05:47,000 --> 00:05:52,000
+with the user is handled according to the organizational legal requirements a lot of times.
+
+114
+00:05:53,000 --> 00:05:56,000
+When you terminate people, you're going to have to give them an interview.
+
+115
+00:05:56,000 --> 00:06:00,000
+You're going to have to let them know that they're terminal, but also get back all of the company's
+
+116
+00:06:00,000 --> 00:06:06,000
+data, such as, for example, maybe you issued company phones to them, maybe you issued company laptops
+
+117
+00:06:06,000 --> 00:06:06,000
+to them.
+
+118
+00:06:06,000 --> 00:06:11,000
+You're also going to have to transfer ownership of the emails and files to other employees.
+
+119
+00:06:11,000 --> 00:06:13,000
+Generally, when they fire Bob and replace Bob with Mary.
+
+120
+00:06:13,000 --> 00:06:17,000
+Generally, Mary now needs access to what Bob is doing because she's going to be doing his job.
+
+121
+00:06:17,000 --> 00:06:19,000
+So this is going to be involved.
+
+122
+00:06:19,000 --> 00:06:21,000
+Terminating terminating the account.
+
+123
+00:06:21,000 --> 00:06:26,000
+Now, when it comes to creating and managing user accounts, I can't emphasize this enough, but permission
+
+124
+00:06:26,000 --> 00:06:28,000
+assignment is core here.
+
+125
+00:06:28,000 --> 00:06:29,000
+It's going to be key.
+
+126
+00:06:29,000 --> 00:06:36,000
+Anytime we add users to the network, we have to make sure that those users are only given access to
+
+127
+00:06:36,000 --> 00:06:38,000
+what they need and nothing more.
+
+128
+00:06:38,000 --> 00:06:40,000
+We don't want to give them too much access.
+
+129
+00:06:40,000 --> 00:06:43,000
+We want to give them just enough access to get their job done.
+
+130
+00:06:44,000 --> 00:06:48,000
+So permission assignments is one of the core thing of identity and access management.
+
+131
+00:06:48,000 --> 00:06:50,000
+We want to make sure that they have the right rights.
+
+132
+00:06:50,000 --> 00:06:54,000
+And we're going to follow principles like least privileges, role based access.
+
+133
+00:06:54,000 --> 00:06:58,000
+Role based access means that whatever role they're going to be doing, if they're an accountant, they
+
+134
+00:06:58,000 --> 00:07:02,000
+only do accounting in order to give them minimum access.
+
+135
+00:07:02,000 --> 00:07:03,000
+So keep these things in mind.
+
+136
+00:07:03,000 --> 00:07:05,000
+When you manage user accounts, remember something.
+
+137
+00:07:05,000 --> 00:07:07,000
+Make sure they you know who they are.
+
+138
+00:07:07,000 --> 00:07:09,000
+Make sure you prove their identity.
+
+139
+00:07:09,000 --> 00:07:13,000
+When you create that user accounts follow the principles of least privileges.
+
+140
+00:07:13,000 --> 00:07:18,000
+Give them access to only what they need and when you terminate them, anyone for that matter, make
+
+141
+00:07:18,000 --> 00:07:19,000
+sure you disable the access.
+
+142
+00:07:19,000 --> 00:07:21,000
+Then tell them that they have been terminated.
+
+143
+00:07:21,000 --> 00:07:23,000
+Collect all company equipment.
+
+144
+00:07:23,000 --> 00:07:27,000
+Make sure you do an exit interview, letting them know all the policies that they signed to get all
+
+145
+00:07:27,000 --> 00:07:29,000
+company equipment back.
+
+146
+00:07:29,000 --> 00:07:33,000
+Transfer ownership of whatever files and folders they have to people.
+
+147
+00:07:33,000 --> 00:07:34,000
+That's probably replacing them.
+
+148
+00:07:34,000 --> 00:07:39,000
+By doing all of this, you're going to have good hiring and firing policies.
+
diff --git a/18 - Identity and Access Management (IAM)/002 Single Sign-on OB 4.6_en.srt b/18 - Identity and Access Management (IAM)/002 Single Sign-on OB 4.6_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..6b0ad4bdc32732242c3744cd68163761859af022
--- /dev/null
+++ b/18 - Identity and Access Management (IAM)/002 Single Sign-on OB 4.6_en.srt
@@ -0,0 +1,368 @@
+1
+00:00:00,000 --> 00:00:05,000
+The greatest technology that has ever been invented, in Andrew's opinion, when it comes to the world
+
+2
+00:00:05,000 --> 00:00:06,000
+of security.
+
+3
+00:00:06,000 --> 00:00:10,000
+Is this thing SS or single sign on?
+
+4
+00:00:10,000 --> 00:00:12,000
+You see, I hate passwords.
+
+5
+00:00:12,000 --> 00:00:13,000
+I hate remembering passwords.
+
+6
+00:00:13,000 --> 00:00:17,000
+I never remember passwords because my memory really sucks.
+
+7
+00:00:17,000 --> 00:00:25,000
+Single sign on is a feature where a user logs in once and gain access to multiple systems without the
+
+8
+00:00:25,000 --> 00:00:26,000
+need to reauthenticate.
+
+9
+00:00:26,000 --> 00:00:28,000
+This enhances user experience.
+
+10
+00:00:28,000 --> 00:00:29,000
+Yes it does.
+
+11
+00:00:29,000 --> 00:00:37,000
+So what this is going to do is this every single time you log into a network, basically you put your
+
+12
+00:00:37,000 --> 00:00:41,000
+username and password once and you can access tons of resources.
+
+13
+00:00:41,000 --> 00:00:47,000
+You can access files on a file server, databases, your emails, for example, you can access specific
+
+14
+00:00:47,000 --> 00:00:49,000
+intranet sites and so on.
+
+15
+00:00:49,000 --> 00:00:55,000
+Single sign on is amazing because without single sign on, I'll have to remember username and password
+
+16
+00:00:55,000 --> 00:00:56,000
+to log into my windows.
+
+17
+00:00:56,000 --> 00:01:02,000
+I'll then have to remember a password to the email password to the database, password to this intranet
+
+18
+00:01:02,000 --> 00:01:04,000
+site, and so on and drive me crazy.
+
+19
+00:01:04,000 --> 00:01:07,000
+So we want to use single sign on.
+
+20
+00:01:07,000 --> 00:01:09,000
+Single sign on has a ton of benefits.
+
+21
+00:01:09,000 --> 00:01:10,000
+Here we go.
+
+22
+00:01:11,000 --> 00:01:18,000
+Number one, like I told you so, reduces the number of passwords users must manage.
+
+23
+00:01:18,000 --> 00:01:20,000
+Guys, we can't remember all these passwords.
+
+24
+00:01:20,000 --> 00:01:23,000
+Not to mention passwords has to be complex.
+
+25
+00:01:23,000 --> 00:01:27,000
+And more and more software is making it mandatory that you memorize ten characters.
+
+26
+00:01:27,000 --> 00:01:29,000
+And it must be complex.
+
+27
+00:01:29,000 --> 00:01:33,000
+And a lot of us ends up just using the same password for everything, which is something you should
+
+28
+00:01:33,000 --> 00:01:34,000
+never do.
+
+29
+00:01:34,000 --> 00:01:39,000
+Uh, reuse very simple passwords that are long on somewhat complex.
+
+30
+00:01:39,000 --> 00:01:45,000
+This, of course, leads to bad security, so this decrease the likelihood of weak passwords.
+
+31
+00:01:45,000 --> 00:01:51,000
+Another great thing is centralized authentication provides centralized control over user access to multiple
+
+32
+00:01:51,000 --> 00:01:51,000
+systems.
+
+33
+00:01:51,000 --> 00:01:53,000
+Makes it easier to enforce security policy.
+
+34
+00:01:53,000 --> 00:01:54,000
+So.
+
+35
+00:01:55,000 --> 00:01:56,000
+For example.
+
+36
+00:01:56,000 --> 00:02:00,000
+Now we can just add you into the system, add you to a few things, and you get access to everything,
+
+37
+00:02:00,000 --> 00:02:07,000
+versus the administrator having to create a user account for the for windows user account for this website,
+
+38
+00:02:07,000 --> 00:02:13,000
+a user account for that website, a user account for the VPN, a user account for the email.
+
+39
+00:02:13,000 --> 00:02:16,000
+Now they don't need to create 500 user accounts.
+
+40
+00:02:16,000 --> 00:02:20,000
+So this of course makes it easy for it.
+
+41
+00:02:20,000 --> 00:02:26,000
+It reduces the the user account management for I for it a lot easier.
+
+42
+00:02:26,000 --> 00:02:30,000
+And of course you don't have to keep calling the help desk 500 times to reset your password.
+
+43
+00:02:30,000 --> 00:02:32,000
+One famous.
+
+44
+00:02:32,000 --> 00:02:33,000
+So technology.
+
+45
+00:02:34,000 --> 00:02:39,000
+That is utilized a lot in the world today is Ldap.
+
+46
+00:02:39,000 --> 00:02:47,000
+Now, if you have worked in corporate America today and they had a windows box and they were using Microsoft's
+
+47
+00:02:47,000 --> 00:02:52,000
+Active Directory, that was Ldap, that's the Microsoft version of it.
+
+48
+00:02:52,000 --> 00:02:57,000
+So Ldap stands for Lightweight Directory Access Protocol.
+
+49
+00:02:57,000 --> 00:03:00,000
+And this is a so example.
+
+50
+00:03:00,000 --> 00:03:03,000
+So if you say so okay I like so how do I implement it.
+
+51
+00:03:03,000 --> 00:03:09,000
+Well Ldap does this if you're if you were run in the world of Windows or Microsoft based stuff, you're
+
+52
+00:03:09,000 --> 00:03:10,000
+going to have Microsoft Active Directory.
+
+53
+00:03:10,000 --> 00:03:13,000
+If you're using pure Linux you could use Open Directory also.
+
+54
+00:03:14,000 --> 00:03:20,000
+Now it's a protocol for accessing and maintaining distributed directory information such as what but
+
+55
+00:03:20,000 --> 00:03:23,000
+like users and group details over an IP network.
+
+56
+00:03:23,000 --> 00:03:31,000
+So now we can pass user information across an entire network primarily used for directory services.
+
+57
+00:03:31,000 --> 00:03:36,000
+Commonly utilize utilize for storing credentials and groups.
+
+58
+00:03:36,000 --> 00:03:39,000
+Now once again this is Active Directory.
+
+59
+00:03:39,000 --> 00:03:43,000
+Now this course is not meant to teach you Active Directory.
+
+60
+00:03:44,000 --> 00:03:46,000
+How to set it up or anything for your exam.
+
+61
+00:03:46,000 --> 00:03:48,000
+I need you guys to know that.
+
+62
+00:03:48,000 --> 00:03:54,000
+So single sign on user logs in ones means they can gain access to everything.
+
+63
+00:03:54,000 --> 00:03:56,000
+Also remember this.
+
+64
+00:03:56,000 --> 00:03:58,000
+This reduces password.
+
+65
+00:03:58,000 --> 00:04:00,000
+People have to memorize password.
+
+66
+00:04:00,000 --> 00:04:06,000
+It makes it actually more secure because now users just have to memorize one really good strong password
+
+67
+00:04:06,000 --> 00:04:07,000
+to access the network.
+
+68
+00:04:07,000 --> 00:04:09,000
+So it reduces it workload.
+
+69
+00:04:09,000 --> 00:04:12,000
+So it doesn't have to make a bunch of user accounts.
+
+70
+00:04:12,000 --> 00:04:14,000
+One good example of it was Ldap.
+
+71
+00:04:14,000 --> 00:04:17,000
+Now remember Active Directory is based on Ldap.
+
+72
+00:04:17,000 --> 00:04:20,000
+It's used to store user accounts and the information associated with them.
+
+73
+00:04:20,000 --> 00:04:25,000
+Now one of the things that we want to discuss before we leave is what's negative about Ldap.
+
+74
+00:04:25,000 --> 00:04:28,000
+What's one of the bad things about Ldap or so?
+
+75
+00:04:28,000 --> 00:04:31,000
+What's one of the bad things with CISOs.
+
+76
+00:04:31,000 --> 00:04:41,000
+Well, its biggest negative is if one user account is compromised, it compromises all the system.
+
+77
+00:04:41,000 --> 00:04:48,000
+The reason is because you see, when you have one account that accesses all the data and all systems,
+
+78
+00:04:48,000 --> 00:04:54,000
+if that user account is lost, whoever gets it can then access everything on the network.
+
+79
+00:04:54,000 --> 00:04:58,000
+Think about this if you have one user account that accesses your your computer, like your Active Directory
+
+80
+00:04:58,000 --> 00:05:01,000
+account, you can use this to log in to to windows.
+
+81
+00:05:02,000 --> 00:05:06,000
+You can use check your email your database company's intranet site.
+
+82
+00:05:06,000 --> 00:05:12,000
+But if you lose that account and that password, oh well, whoever gets it now has access to everything
+
+83
+00:05:12,000 --> 00:05:15,000
+on the network that you did, so that's its downfall.
+
+84
+00:05:15,000 --> 00:05:23,000
+But in this situation, the benefit of not having to remember 7000 password outweighs that risk of that
+
+85
+00:05:23,000 --> 00:05:24,000
+single point of failure.
+
+86
+00:05:24,000 --> 00:05:28,000
+And that's what it is, because that single account becomes a failure on the network.
+
+87
+00:05:28,000 --> 00:05:31,000
+Basically they just compromise one account.
+
+88
+00:05:31,000 --> 00:05:32,000
+They have access to everything.
+
+89
+00:05:32,000 --> 00:05:40,000
+So in this particular one, the benefit here outweighs the risk of the actual, uh, problem with.
+
+90
+00:05:40,000 --> 00:05:46,000
+So now we do implement so across all networks today because almost everybody uses Microsoft Active Directory.
+
+91
+00:05:46,000 --> 00:05:51,000
+If you have if you have windows and if you use a variety of websites, you can also implement it with
+
+92
+00:05:51,000 --> 00:05:53,000
+Federation coming next.
+
diff --git a/18 - Identity and Access Management (IAM)/003 Federation and SAML OB 4.6_en.srt b/18 - Identity and Access Management (IAM)/003 Federation and SAML OB 4.6_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..e1b5975ba621548131084f92c0a512dbe414b189
--- /dev/null
+++ b/18 - Identity and Access Management (IAM)/003 Federation and SAML OB 4.6_en.srt
@@ -0,0 +1,664 @@
+1
+00:00:00,000 --> 00:00:05,000
+When it comes to using the internet, there's nothing more annoying than forgetting your password to
+
+2
+00:00:05,000 --> 00:00:06,000
+a particular website.
+
+3
+00:00:06,000 --> 00:00:07,000
+How many?
+
+4
+00:00:07,000 --> 00:00:08,000
+How many of you guys hate that?
+
+5
+00:00:08,000 --> 00:00:14,000
+I can't stand using the internet today for the simple fact that every single website you go to that
+
+6
+00:00:14,000 --> 00:00:17,000
+needs anything, you have to create a user account.
+
+7
+00:00:17,000 --> 00:00:18,000
+You have to remember the password.
+
+8
+00:00:19,000 --> 00:00:21,000
+It's not easy to do this.
+
+9
+00:00:21,000 --> 00:00:26,000
+So here's what I do every time I go to a website and it's like, create an account.
+
+10
+00:00:26,000 --> 00:00:28,000
+For whatever reason, I got to create an account.
+
+11
+00:00:28,000 --> 00:00:31,000
+So I create an account and then it says, would you like to use your Gmail to log in here?
+
+12
+00:00:31,000 --> 00:00:34,000
+And I'm like, oh yeah, let's do that.
+
+13
+00:00:34,000 --> 00:00:39,000
+If you've ever done that, you have used a technology we referred to as what's called Federation.
+
+14
+00:00:40,000 --> 00:00:43,000
+Now this you want to know this terms for your exam.
+
+15
+00:00:44,000 --> 00:00:44,000
+Federation is.
+
+16
+00:00:44,000 --> 00:00:51,000
+Cybersecurity is the process of linking and managing identities across different systems and organizational
+
+17
+00:00:51,000 --> 00:00:52,000
+boundaries.
+
+18
+00:00:52,000 --> 00:00:57,000
+Basically, it's going to enable users to use the same identity or set of credentials across multiple
+
+19
+00:00:57,000 --> 00:00:59,000
+applications and services.
+
+20
+00:00:59,000 --> 00:01:01,000
+Basically, federation is.
+
+21
+00:01:01,000 --> 00:01:06,000
+So for websites, that's what that's what you need to know for your exam.
+
+22
+00:01:06,000 --> 00:01:10,000
+This allows you to log in to one website and then you can then log in.
+
+23
+00:01:10,000 --> 00:01:12,000
+Basically go to other websites.
+
+24
+00:01:12,000 --> 00:01:16,000
+And that login credential will stay with you throughout the others.
+
+25
+00:01:16,000 --> 00:01:21,000
+It allows for single sign on and streamline access management to enhance user experience.
+
+26
+00:01:21,000 --> 00:01:22,000
+Remember that.
+
+27
+00:01:22,000 --> 00:01:23,000
+What exactly is Federation?
+
+28
+00:01:23,000 --> 00:01:27,000
+Well, Federation allows me to log in to this particular website.
+
+29
+00:01:28,000 --> 00:01:32,000
+And then I can go to all the different all the web sites that trust is that site.
+
+30
+00:01:33,000 --> 00:01:34,000
+It's one of the things we have to remember.
+
+31
+00:01:34,000 --> 00:01:38,000
+And then we basically we don't need to log in 100 times anymore.
+
+32
+00:01:39,000 --> 00:01:46,000
+Federation makes the internet a lot easier to use because it's bringing it's bringing single sign on
+
+33
+00:01:46,000 --> 00:01:48,000
+to websites.
+
+34
+00:01:48,000 --> 00:01:53,000
+Now, Federation involves identity providers, service providers and all kinds of protocols that goes
+
+35
+00:01:53,000 --> 00:01:54,000
+along with it.
+
+36
+00:01:54,000 --> 00:01:57,000
+And in this video we want to talk about some of those.
+
+37
+00:01:57,000 --> 00:02:05,000
+One of the most famous protocol that we have for Federation on the internet today is something we call
+
+38
+00:02:05,000 --> 00:02:06,000
+Saml.
+
+39
+00:02:06,000 --> 00:02:08,000
+Saml is security.
+
+40
+00:02:09,000 --> 00:02:11,000
+Assertion Markup Language.
+
+41
+00:02:11,000 --> 00:02:14,000
+Yeah, my my pronunciation of complex words is not the best.
+
+42
+00:02:14,000 --> 00:02:15,000
+Sorry about that guys.
+
+43
+00:02:15,000 --> 00:02:17,000
+This is basically an open standard.
+
+44
+00:02:17,000 --> 00:02:18,000
+And you guys to listen carefully.
+
+45
+00:02:18,000 --> 00:02:27,000
+Exchange in authentication and authorization data between parties, specifically an identity provider
+
+46
+00:02:27,000 --> 00:02:28,000
+and a service provider.
+
+47
+00:02:28,000 --> 00:02:31,000
+Now I have a diagram that I'm going to show you about Saml in a minute.
+
+48
+00:02:31,000 --> 00:02:37,000
+But I want to talk about the difference between authentication and authorization.
+
+49
+00:02:37,000 --> 00:02:39,000
+It's really important to understand this.
+
+50
+00:02:40,000 --> 00:02:43,000
+So authentication is this.
+
+51
+00:02:43,000 --> 00:02:49,000
+If you have a if you log in to one website you can then transfer that authentication to another.
+
+52
+00:02:49,000 --> 00:02:51,000
+So let's say you have a website A and website B.
+
+53
+00:02:52,000 --> 00:02:57,000
+Now let's say you authenticate to website A, but because website A trust this website B because you're
+
+54
+00:02:57,000 --> 00:03:00,000
+logged in to A, you automatically logged in to B.
+
+55
+00:03:01,000 --> 00:03:02,000
+That's all it is.
+
+56
+00:03:02,000 --> 00:03:05,000
+But authentication is not authorization.
+
+57
+00:03:05,000 --> 00:03:09,000
+Authorization is telling people what you have access to.
+
+58
+00:03:09,000 --> 00:03:12,000
+Authentication is proving your identity to a system.
+
+59
+00:03:13,000 --> 00:03:16,000
+Authorization is what can you access?
+
+60
+00:03:16,000 --> 00:03:21,000
+For example, I can log in to this box, but I'm not authorized to access anything.
+
+61
+00:03:21,000 --> 00:03:23,000
+Everything I double click says access denied.
+
+62
+00:03:24,000 --> 00:03:26,000
+But there's a folder on the desktop that I could access.
+
+63
+00:03:26,000 --> 00:03:29,000
+When I double click on that, I opens it and I can add files to it.
+
+64
+00:03:30,000 --> 00:03:31,000
+That's authorization.
+
+65
+00:03:31,000 --> 00:03:36,000
+So Samuel passes both authentication and authorization.
+
+66
+00:03:36,000 --> 00:03:41,000
+So for example, if there's website A and B when you log in to this one you're already logged in to
+
+67
+00:03:41,000 --> 00:03:43,000
+this one that's authentication.
+
+68
+00:03:43,000 --> 00:03:49,000
+But because you can access certain files and folders or certain web pages on this site.
+
+69
+00:03:49,000 --> 00:03:52,000
+Now Samuel is able to pass over that authorization to the other site.
+
+70
+00:03:52,000 --> 00:03:57,000
+And now you can also access certain files and folders or pages on this site, both A and B, that's
+
+71
+00:03:57,000 --> 00:03:58,000
+authorization.
+
+72
+00:03:59,000 --> 00:04:02,000
+This is one of the most widely used so for the internet.
+
+73
+00:04:02,000 --> 00:04:06,000
+Now Samuel does use what's called XML.
+
+74
+00:04:06,000 --> 00:04:08,000
+That is a type of a format.
+
+75
+00:04:08,000 --> 00:04:10,000
+That's how it's able to transfer data.
+
+76
+00:04:10,000 --> 00:04:16,000
+Think of think of XML or Extensible Markup Language as the format that it used to transfer information
+
+77
+00:04:16,000 --> 00:04:22,000
+between one to the other for data exchange, and it focuses on both authentication and authorization.
+
+78
+00:04:22,000 --> 00:04:25,000
+Now XML has two main components.
+
+79
+00:04:25,000 --> 00:04:31,000
+We want to talk about what's called the identity provider and what's called the service provider the
+
+80
+00:04:31,000 --> 00:04:32,000
+identity provider.
+
+81
+00:04:33,000 --> 00:04:37,000
+Is basically the services that authenticate users and provide identity.
+
+82
+00:04:37,000 --> 00:04:43,000
+This is going to be things like Microsoft Azure or for example, using your Gmail at Google Identity.
+
+83
+00:04:43,000 --> 00:04:49,000
+What identity providers are doing notice terms for your exam is attestation.
+
+84
+00:04:49,000 --> 00:04:53,000
+This basically is a form of verification that something is true.
+
+85
+00:04:53,000 --> 00:04:56,000
+It's done with the identity providers.
+
+86
+00:04:56,000 --> 00:04:59,000
+They attest that this user is who they claim to be.
+
+87
+00:04:59,000 --> 00:05:00,000
+Stay with me.
+
+88
+00:05:00,000 --> 00:05:02,000
+I know this doesn't make sense yet, but I'm gonna have a diagram.
+
+89
+00:05:02,000 --> 00:05:03,000
+It's going to make you make sense of this.
+
+90
+00:05:03,000 --> 00:05:10,000
+The service provider is the application or service that they rely that that you're going to rely on
+
+91
+00:05:10,000 --> 00:05:14,000
+for information from the identity provider.
+
+92
+00:05:14,000 --> 00:05:18,000
+So basically the service provider is what is who you're going to.
+
+93
+00:05:18,000 --> 00:05:23,000
+For example, let's say you use your Gmail to log in to BestBuy.
+
+94
+00:05:23,000 --> 00:05:25,000
+I don't know if BestBuy allows it, but let's say you do.
+
+95
+00:05:26,000 --> 00:05:32,000
+If you're using your Gmail to log in to BestBuy, then Gmail is the identity provider.
+
+96
+00:05:32,000 --> 00:05:36,000
+But who's providing you the service of buying tech stuff at Best Buy?
+
+97
+00:05:36,000 --> 00:05:37,000
+So they're the service provider.
+
+98
+00:05:37,000 --> 00:05:43,000
+The service provider relies on the identity provider for the identifying information.
+
+99
+00:05:44,000 --> 00:05:49,000
+Now, there is a great diagram here that I want to review with you.
+
+100
+00:05:49,000 --> 00:05:50,000
+Shows you how Saml works.
+
+101
+00:05:50,000 --> 00:05:52,000
+Here are the steps to Saml.
+
+102
+00:05:52,000 --> 00:05:55,000
+So this is you.
+
+103
+00:05:55,000 --> 00:05:59,000
+You're a user and you have a mobile device.
+
+104
+00:05:59,000 --> 00:06:03,000
+Now the service provider let's say is Best Buy.
+
+105
+00:06:04,000 --> 00:06:07,000
+The identity provider is going to be like Google.
+
+106
+00:06:07,000 --> 00:06:10,000
+Let's say you're using like your Gmail to log in somewhere else.
+
+107
+00:06:10,000 --> 00:06:11,000
+Let's see what happens.
+
+108
+00:06:11,000 --> 00:06:14,000
+So you go to the service provider.
+
+109
+00:06:14,000 --> 00:06:16,000
+You request access to a resource.
+
+110
+00:06:17,000 --> 00:06:25,000
+The second step, the service provider then goes to the identity provider and says unattended unauthenticated
+
+111
+00:06:25,000 --> 00:06:25,000
+request.
+
+112
+00:06:25,000 --> 00:06:29,000
+He basically sends a Saml request saying, hey, do you know this guy?
+
+113
+00:06:30,000 --> 00:06:34,000
+Google then displays a login page on your phone.
+
+114
+00:06:34,000 --> 00:06:38,000
+You get a login, you try to click, and Google is like, hey, you need to log in with this username
+
+115
+00:06:38,000 --> 00:06:40,000
+and password to Google, not to Best Buy.
+
+116
+00:06:40,000 --> 00:06:45,000
+You put in your username and password and you send it back to their database.
+
+117
+00:06:45,000 --> 00:06:48,000
+Google's database credentials sends for verification.
+
+118
+00:06:49,000 --> 00:06:56,000
+Google then authenticates your credential and then sends a verification back to Google's Saml server
+
+119
+00:06:56,000 --> 00:06:58,000
+or their identity provider.
+
+120
+00:06:58,000 --> 00:07:05,000
+The Saml ID provider then sends a request back to Best Buy saying, hey, yeah, log them in, they're
+
+121
+00:07:05,000 --> 00:07:05,000
+all good.
+
+122
+00:07:05,000 --> 00:07:09,000
+And then you request access to whatever resources that you want on Best Buy.
+
+123
+00:07:11,000 --> 00:07:11,000
+Okay.
+
+124
+00:07:11,000 --> 00:07:13,000
+This exam is not going to go in depth into this.
+
+125
+00:07:13,000 --> 00:07:19,000
+I just wanted to show you guys know identity providers and know what service providers are.
+
+126
+00:07:19,000 --> 00:07:23,000
+Service providers are the folks that you are going to.
+
+127
+00:07:23,000 --> 00:07:27,000
+They're providing the internet service you want, whether it's buying tech stuff or reading some kind
+
+128
+00:07:27,000 --> 00:07:29,000
+of article or something like that.
+
+129
+00:07:29,000 --> 00:07:33,000
+Basically, the website you're visiting and the identity providers who you're using to log in to that
+
+130
+00:07:33,000 --> 00:07:35,000
+website to, such as Google.
+
+131
+00:07:35,000 --> 00:07:36,000
+I think you could use Facebook and stuff like that.
+
+132
+00:07:39,000 --> 00:07:39,000
+All right.
+
+133
+00:07:39,000 --> 00:07:44,000
+Now there are some other so based federation technology that you should be familiar with.
+
+134
+00:07:44,000 --> 00:07:48,000
+There is OAuth and this stands for open authorization.
+
+135
+00:07:48,000 --> 00:07:51,000
+This is open standard for access delegation.
+
+136
+00:07:51,000 --> 00:07:56,000
+It's used to grant websites or applications access to their information on other websites without giving
+
+137
+00:07:56,000 --> 00:07:57,000
+them a password.
+
+138
+00:07:57,000 --> 00:08:02,000
+Commonly used for authorizing third party applications to access a user data.
+
+139
+00:08:02,000 --> 00:08:04,000
+Now here's the thing with OAuth.
+
+140
+00:08:04,000 --> 00:08:08,000
+OAuth does not do basically authentication.
+
+141
+00:08:08,000 --> 00:08:12,000
+That's not what it does a lot only does authorization.
+
+142
+00:08:12,000 --> 00:08:19,000
+So if you have, for example, a particular application that needs access to this particular website,
+
+143
+00:08:19,000 --> 00:08:21,000
+then you can use OAuth for this.
+
+144
+00:08:21,000 --> 00:08:26,000
+It doesn't need the user, it doesn't need the user to authenticate, but just a particular application.
+
+145
+00:08:26,000 --> 00:08:33,000
+So remember for your exam OAuth is basically authorization only not authentication and authorization.
+
+146
+00:08:33,000 --> 00:08:41,000
+Now, if you're looking to do, uh, to add to OAuth, you want to add that authentication part, then
+
+147
+00:08:41,000 --> 00:08:43,000
+you can use OpenID connect.
+
+148
+00:08:43,000 --> 00:08:48,000
+Basically, it's an identity layer on top of a 2.0 that allows client to verify the identity of the
+
+149
+00:08:48,000 --> 00:08:53,000
+end user, um, on the authentication performed by the authorization.
+
+150
+00:08:53,000 --> 00:08:59,000
+So it's primarily used for for authentication in modern applications, especially on mobile sites.
+
+151
+00:09:00,000 --> 00:09:04,000
+Now the thing with these kinds of systems are, you know, some people are going to say, so, Andrew,
+
+152
+00:09:04,000 --> 00:09:07,000
+why should I, should I use OAuth or Saml for your exam?
+
+153
+00:09:07,000 --> 00:09:08,000
+Don't worry about that.
+
+154
+00:09:08,000 --> 00:09:12,000
+I just need I need you guys to know the technology.
+
+155
+00:09:12,000 --> 00:09:17,000
+For example, when it comes to Federation, one of the most popular implementation of federation is
+
+156
+00:09:17,000 --> 00:09:18,000
+Saml.
+
+157
+00:09:18,000 --> 00:09:19,000
+Samuel has two main components.
+
+158
+00:09:19,000 --> 00:09:21,000
+They have a identity provider.
+
+159
+00:09:22,000 --> 00:09:26,000
+And a service provider and identity provider is basically who holds your username and password and who's
+
+160
+00:09:26,000 --> 00:09:27,000
+going to verify you.
+
+161
+00:09:27,000 --> 00:09:33,000
+And the service provider is the folks that you the website that you've been to to get a particular service,
+
+162
+00:09:33,000 --> 00:09:35,000
+such as buying stuff at Best Buy.
+
+163
+00:09:35,000 --> 00:09:42,000
+And don't forget, OAuth is open authorization that only provides authorization if you want to add authentication
+
+164
+00:09:42,000 --> 00:09:45,000
+on top of what you use OpenID connect.
+
+165
+00:09:45,000 --> 00:09:45,000
+All right.
+
+166
+00:09:45,000 --> 00:09:51,000
+Just note that these technologies are basically all that's used with Federation.
+
diff --git a/18 - Identity and Access Management (IAM)/004 Access Control Models OB 4.6_en.srt b/18 - Identity and Access Management (IAM)/004 Access Control Models OB 4.6_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..fe3ccfd6619d54f11f95c050a09b799974d64c3e
--- /dev/null
+++ b/18 - Identity and Access Management (IAM)/004 Access Control Models OB 4.6_en.srt
@@ -0,0 +1,508 @@
+1
+00:00:00,000 --> 00:00:05,000
+When you log into a computer, what kind of access do you have to that machine?
+
+2
+00:00:05,000 --> 00:00:10,000
+Can you just make files and folders and share it as you like to anyone on the network?
+
+3
+00:00:10,000 --> 00:00:11,000
+Or could you not?
+
+4
+00:00:11,000 --> 00:00:17,000
+Could you access anything on the network or anything on the computer, or is there certain restrictions?
+
+5
+00:00:17,000 --> 00:00:19,000
+You see, this comes down to access control.
+
+6
+00:00:19,000 --> 00:00:26,000
+And there are a set of access controls that we need to know for our exam and work in, in real life.
+
+7
+00:00:26,000 --> 00:00:33,000
+So access controls are are basically mechanisms and policies used to manage and restrict access to resources
+
+8
+00:00:33,000 --> 00:00:34,000
+in an entire network.
+
+9
+00:00:34,000 --> 00:00:37,000
+It could be individual systems or the entire network.
+
+10
+00:00:37,000 --> 00:00:43,000
+Now there is a bunch we want to talk about from discretionary access control, mandatory access control
+
+11
+00:00:43,000 --> 00:00:49,000
+role and rule based access control and attribute based access control for your exam, you're going to
+
+12
+00:00:49,000 --> 00:00:51,000
+want to know the difference between them.
+
+13
+00:00:51,000 --> 00:00:55,000
+This particular topic has been a very popular topic on your exam.
+
+14
+00:00:56,000 --> 00:01:01,000
+The effective implementation of access control is require balance and security and complexity and usability.
+
+15
+00:01:01,000 --> 00:01:02,000
+Why?
+
+16
+00:01:02,000 --> 00:01:08,000
+You see, it's all about balance and security and complexity, because some of these access controls
+
+17
+00:01:08,000 --> 00:01:11,000
+are super restrictive, like mandatory access control.
+
+18
+00:01:11,000 --> 00:01:15,000
+And some of them are pretty loose, like discretionary access control.
+
+19
+00:01:15,000 --> 00:01:17,000
+Let's get into it and see these kinds of access controls.
+
+20
+00:01:17,000 --> 00:01:23,000
+The first one I want to talk about is the most restrictive access control out there, which is called
+
+21
+00:01:23,000 --> 00:01:25,000
+mandatory access control.
+
+22
+00:01:25,000 --> 00:01:30,000
+First of all, I want to start out by saying that mandatory access control is only really used in the
+
+23
+00:01:30,000 --> 00:01:35,000
+government and military, where classification of the information is needed.
+
+24
+00:01:35,000 --> 00:01:43,000
+Now mandatory access control utilizes a variety of system labels in order to keep the system secure.
+
+25
+00:01:43,000 --> 00:01:44,000
+But what exactly is it?
+
+26
+00:01:44,000 --> 00:01:50,000
+It's a security model in which access rights are regulated by central authority, based on different
+
+27
+00:01:50,000 --> 00:01:51,000
+levels of security clearance.
+
+28
+00:01:51,000 --> 00:01:55,000
+Now, it does utilize a particular security clearance and a security label.
+
+29
+00:01:55,000 --> 00:01:57,000
+The scope of that is beyond your exam.
+
+30
+00:01:57,000 --> 00:02:01,000
+But I'm going to give you guys, uh, a couple a couple examples in a minute.
+
+31
+00:02:02,000 --> 00:02:02,000
+Key aspect.
+
+32
+00:02:02,000 --> 00:02:06,000
+Users cannot change access permissions they are set enforce by the administrator.
+
+33
+00:02:06,000 --> 00:02:14,000
+So basically on windows, which is basically based on a DAC system, on a mandatory access control system.
+
+34
+00:02:14,000 --> 00:02:16,000
+And I'm not talking Mac here, by the way.
+
+35
+00:02:16,000 --> 00:02:17,000
+Like Apple.
+
+36
+00:02:17,000 --> 00:02:17,000
+I just thought of that.
+
+37
+00:02:17,000 --> 00:02:18,000
+I'm not talking.
+
+38
+00:02:18,000 --> 00:02:19,000
+That's a completely different thing.
+
+39
+00:02:20,000 --> 00:02:25,000
+What we're talking about here is a system that when you log, when you create a user account and they
+
+40
+00:02:25,000 --> 00:02:28,000
+log in, they have permission basically to nothing.
+
+41
+00:02:28,000 --> 00:02:29,000
+And they can't change anything.
+
+42
+00:02:29,000 --> 00:02:32,000
+They can access only what the administrator.
+
+43
+00:02:32,000 --> 00:02:35,000
+It's not like they could make a folder and then they can change the permission.
+
+44
+00:02:35,000 --> 00:02:40,000
+You see in discretionary access control devices, when you make a folder, you own it.
+
+45
+00:02:40,000 --> 00:02:42,000
+You can change whatever you like about it.
+
+46
+00:02:42,000 --> 00:02:43,000
+And discretionary tour.
+
+47
+00:02:43,000 --> 00:02:45,000
+When you make a folder, it changes.
+
+48
+00:02:46,000 --> 00:02:52,000
+But when you make a folder, the folder actually will stay with the system and get the system permission.
+
+49
+00:02:52,000 --> 00:02:56,000
+You see, one of the things we got to remember with mandatory access control in the government, the
+
+50
+00:02:56,000 --> 00:02:59,000
+government uses what's called security clearances.
+
+51
+00:02:59,000 --> 00:03:09,000
+And this is important, you see, for you to gain access to something you just cannot, uh, double
+
+52
+00:03:09,000 --> 00:03:13,000
+click and access it if you have a certain clearance, let's say a top secret, it doesn't mean you can
+
+53
+00:03:13,000 --> 00:03:16,000
+access all top secret data.
+
+54
+00:03:16,000 --> 00:03:19,000
+So you got to have rights by the owner.
+
+55
+00:03:19,000 --> 00:03:23,000
+Basically, you got to have a need to know, and you got to have a certain set of clearance in order
+
+56
+00:03:23,000 --> 00:03:24,000
+to access the data.
+
+57
+00:03:24,000 --> 00:03:25,000
+Let me explain.
+
+58
+00:03:25,000 --> 00:03:33,000
+In the military, you're going to have top secret and secret now, not some like in windows where like
+
+59
+00:03:33,000 --> 00:03:35,000
+you're an administrator, you get access to everything.
+
+60
+00:03:35,000 --> 00:03:35,000
+No.
+
+61
+00:03:35,000 --> 00:03:39,000
+If you have a top secret clearance, you can't access all top secret data.
+
+62
+00:03:39,000 --> 00:03:42,000
+You have to have what's called a need to know.
+
+63
+00:03:42,000 --> 00:03:47,000
+Now, these kinds of systems will implement that need to know and the clearance, and it utilizes security
+
+64
+00:03:47,000 --> 00:03:49,000
+labels to do it.
+
+65
+00:03:49,000 --> 00:03:56,000
+The operating system that does this is an operating system known as Linux SE or SE Linux Secure Enhanced
+
+66
+00:03:56,000 --> 00:03:57,000
+Linux.
+
+67
+00:03:57,000 --> 00:04:00,000
+They do this with kernel patches and different kinds of things.
+
+68
+00:04:00,000 --> 00:04:02,000
+In Red Hat Linux.
+
+69
+00:04:02,000 --> 00:04:07,000
+And you can actually download this next thing up we have is discretionary access control.
+
+70
+00:04:07,000 --> 00:04:10,000
+The resource owner decides on the access level.
+
+71
+00:04:10,000 --> 00:04:12,000
+It's the most flexible of all the access control.
+
+72
+00:04:13,000 --> 00:04:19,000
+Using environments where users need control over resources they own, like setting file permissions.
+
+73
+00:04:19,000 --> 00:04:22,000
+Now this is normal windows.
+
+74
+00:04:22,000 --> 00:04:25,000
+If you have or Mac that you're I'm talking not Mac like this.
+
+75
+00:04:25,000 --> 00:04:32,000
+I'm talking like you're if you have a MacBook air or MacBook Pro or whatever you're using, you'll log
+
+76
+00:04:32,000 --> 00:04:33,000
+into it.
+
+77
+00:04:33,000 --> 00:04:36,000
+You create a folder on the desktop, you can set the permissions.
+
+78
+00:04:36,000 --> 00:04:41,000
+Anybody can access any file on it because you said this have a risk because you're giving users access
+
+79
+00:04:41,000 --> 00:04:42,000
+over that.
+
+80
+00:04:42,000 --> 00:04:50,000
+In order to be a little bit more restrictive, let's implement one of the most widely used access control
+
+81
+00:04:50,000 --> 00:04:55,000
+in the entire world is called role based access control.
+
+82
+00:04:55,000 --> 00:04:59,000
+This assigns permissions based on a user's role within the business.
+
+83
+00:04:59,000 --> 00:05:04,000
+Now, this is common in corporate environments where the roles defined the job function.
+
+84
+00:05:05,000 --> 00:05:12,000
+So basically they set up roles which in Active Directory or if you manage users would be groups.
+
+85
+00:05:12,000 --> 00:05:18,000
+You're going to have accounting, sales, finance, management, it and so on.
+
+86
+00:05:18,000 --> 00:05:24,000
+And basically you don't assign individual users to resources.
+
+87
+00:05:24,000 --> 00:05:26,000
+Basically you assign them to a group.
+
+88
+00:05:26,000 --> 00:05:28,000
+The group then gives them access to the resource.
+
+89
+00:05:28,000 --> 00:05:32,000
+So if they're not in the role, they can't get access to the resource.
+
+90
+00:05:32,000 --> 00:05:37,000
+This streamlines access in the business, making it a lot easier to manage them.
+
+91
+00:05:37,000 --> 00:05:40,000
+Now there are two others that you want to be familiar with.
+
+92
+00:05:40,000 --> 00:05:46,000
+That's called rule based access control and attribute based rule based access control is decision are
+
+93
+00:05:46,000 --> 00:05:52,000
+based on a set of rules defined by an administrator, useful in environments where stringent access
+
+94
+00:05:52,000 --> 00:05:53,000
+control is needed.
+
+95
+00:05:53,000 --> 00:05:57,000
+Now rule based access control I showed you this when I showed you firewalls.
+
+96
+00:05:57,000 --> 00:06:02,000
+If you watch a video with me setting up a configuring a firewall, that's a rule based access control.
+
+97
+00:06:02,000 --> 00:06:07,000
+Basically, configuring a firewall and setting up its rules is a rule based access control.
+
+98
+00:06:07,000 --> 00:06:11,000
+The only thing here that's going to be using rule based access control is basically routers with their
+
+99
+00:06:11,000 --> 00:06:12,000
+access lists.
+
+100
+00:06:12,000 --> 00:06:13,000
+And of course firewalls.
+
+101
+00:06:13,000 --> 00:06:16,000
+The other one is attribute based access control.
+
+102
+00:06:16,000 --> 00:06:22,000
+This one is incredibly popular today, and you have probably have been using this without your knowledge.
+
+103
+00:06:23,000 --> 00:06:28,000
+Uses policies that evaluate attributes or characteristics of a user.
+
+104
+00:06:28,000 --> 00:06:35,000
+Effective and complex environments with diverse and dynamic user attributes provides fine grained control,
+
+105
+00:06:35,000 --> 00:06:39,000
+allowing for multiple decisions before you give access.
+
+106
+00:06:39,000 --> 00:06:41,000
+Now, let me give you a bunch of examples of this.
+
+107
+00:06:41,000 --> 00:06:43,000
+So you use Netflix, right?
+
+108
+00:06:43,000 --> 00:06:44,000
+Who does it right.
+
+109
+00:06:44,000 --> 00:06:45,000
+You log in to Netflix.
+
+110
+00:06:45,000 --> 00:06:50,000
+And did you know based on your IP addresses, the content you're going to see?
+
+111
+00:06:51,000 --> 00:06:55,000
+Did you guys know that if you have a European IP, you see this, if you have a United States IP, you
+
+112
+00:06:55,000 --> 00:06:58,000
+see this and people even try to get around with VPNs.
+
+113
+00:06:59,000 --> 00:07:07,000
+Um, basically, if you the attribute based access control utilizes many attributes to determine what
+
+114
+00:07:07,000 --> 00:07:08,000
+you can access.
+
+115
+00:07:08,000 --> 00:07:12,000
+For example, if you log in with a mobile browser because the browser screen is small, you can only
+
+116
+00:07:12,000 --> 00:07:17,000
+access this content if you log in that's an attribute, the browser or the screen size.
+
+117
+00:07:17,000 --> 00:07:19,000
+Another attribute could be things like day.
+
+118
+00:07:19,000 --> 00:07:23,000
+Maybe at a certain time you can access this versus a certain time you can't.
+
+119
+00:07:23,000 --> 00:07:26,000
+It could be an IP address or a location.
+
+120
+00:07:26,000 --> 00:07:27,000
+Those are all attributes.
+
+121
+00:07:27,000 --> 00:07:32,000
+Basically, you're utilizing multiple attributes in order to determine what they can access.
+
+122
+00:07:33,000 --> 00:07:38,000
+Now you want to make sure that you really know the you want to make sure that you really know.
+
+123
+00:07:39,000 --> 00:07:47,000
+Uh, these kinds of access control, these terms mandatory access control, discretionary role based,
+
+124
+00:07:47,000 --> 00:07:49,000
+be the most popular, one rule based.
+
+125
+00:07:49,000 --> 00:07:53,000
+And of course, the last one we talked about attribute based access control.
+
+126
+00:07:53,000 --> 00:07:55,000
+Rewatch this video a few times.
+
+127
+00:07:55,000 --> 00:07:57,000
+Make sure you really understand them before taking your test.
+
diff --git a/18 - Identity and Access Management (IAM)/005 Multifactor Authentication OB 4.6_en.srt b/18 - Identity and Access Management (IAM)/005 Multifactor Authentication OB 4.6_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..626ec1de63daf4aff8d46a9f305ce9eeb7e22218
--- /dev/null
+++ b/18 - Identity and Access Management (IAM)/005 Multifactor Authentication OB 4.6_en.srt
@@ -0,0 +1,220 @@
+1
+00:00:00,000 --> 00:00:01,000
+When it comes to it.
+
+2
+00:00:01,000 --> 00:00:01,000
+Security.
+
+3
+00:00:01,000 --> 00:00:08,000
+One of the most important thing we have to secure or have secured is our authentication information.
+
+4
+00:00:08,000 --> 00:00:12,000
+Authentication is basically proven our identity to a machine.
+
+5
+00:00:12,000 --> 00:00:17,000
+Now we covered, uh, authentication a little bit.
+
+6
+00:00:17,000 --> 00:00:21,000
+Or we briefly covered it when we spoke about authentication right at the beginning of the course.
+
+7
+00:00:21,000 --> 00:00:27,000
+In this section we're going to go more in depth into things like tokens, passwords and biometric.
+
+8
+00:00:27,000 --> 00:00:30,000
+But before we do that, let's do a quick review.
+
+9
+00:00:30,000 --> 00:00:32,000
+When it comes to authentication, authentication is proven.
+
+10
+00:00:32,000 --> 00:00:34,000
+Identification.
+
+11
+00:00:34,000 --> 00:00:37,000
+The way you would do that is most people know is with a password.
+
+12
+00:00:37,000 --> 00:00:42,000
+Now in particularly in this section we're looking at multi-factor authentication.
+
+13
+00:00:42,000 --> 00:00:49,000
+MFA is a security system that requires more than one method to authenticate while we use things such
+
+14
+00:00:49,000 --> 00:00:50,000
+as just a password.
+
+15
+00:00:50,000 --> 00:00:52,000
+That would just be a single factor.
+
+16
+00:00:52,000 --> 00:00:55,000
+In this section, we want to look at other factors more than just a password.
+
+17
+00:00:55,000 --> 00:01:01,000
+So it requires more than one method to authenticate from an independent category of credential to verify
+
+18
+00:01:01,000 --> 00:01:03,000
+a user's identity for a login.
+
+19
+00:01:03,000 --> 00:01:07,000
+This combined uses two or more distinctive factors.
+
+20
+00:01:07,000 --> 00:01:13,000
+Now, when it comes to the different factors, we have to look that the factors are going to fall into
+
+21
+00:01:13,000 --> 00:01:16,000
+one of these four main categories.
+
+22
+00:01:16,000 --> 00:01:19,000
+So the first one up is what we are all familiar with.
+
+23
+00:01:19,000 --> 00:01:20,000
+It's what we're all used.
+
+24
+00:01:20,000 --> 00:01:21,000
+It's password.
+
+25
+00:01:21,000 --> 00:01:25,000
+It's something you know commonly used but is vulnerable to theft.
+
+26
+00:01:25,000 --> 00:01:31,000
+People can steal your passwords or guess and or even brute force attack where they can try every combination.
+
+27
+00:01:31,000 --> 00:01:35,000
+Now you got to remember, pins and passwords are going to be this.
+
+28
+00:01:35,000 --> 00:01:40,000
+Now, if you have something like your cell phone and it takes four digits to get in, that's 10,000
+
+29
+00:01:40,000 --> 00:01:41,000
+combinations.
+
+30
+00:01:41,000 --> 00:01:43,000
+That's subject to brute force attack.
+
+31
+00:01:43,000 --> 00:01:46,000
+Or maybe the password on your cell, maybe the.
+
+32
+00:01:47,000 --> 00:01:49,000
+The log into your cell phone.
+
+33
+00:01:49,000 --> 00:01:53,000
+If it's four digits and it's just a Pin, a lot of people put their birthday, for example.
+
+34
+00:01:53,000 --> 00:01:55,000
+That would be me guessing it.
+
+35
+00:01:55,000 --> 00:02:00,000
+Okay, the other thing here is going to be something you have, which adds a layer of security by requiring
+
+36
+00:02:00,000 --> 00:02:05,000
+some kind of physical device that's going to be done either with a hard token or an app on your phone.
+
+37
+00:02:05,000 --> 00:02:10,000
+So you got to have either some you got to have your mobile phone with you, some kind of security token,
+
+38
+00:02:10,000 --> 00:02:12,000
+or even a smart card.
+
+39
+00:02:12,000 --> 00:02:16,000
+The other thing here is going to be something you are, which is going to be biometrics.
+
+40
+00:02:16,000 --> 00:02:20,000
+Now, we do have a big discussion and a whole presentation on biometrics.
+
+41
+00:02:20,000 --> 00:02:25,000
+This one is highly secure, but implementation is generally going to be more expensive than all of this.
+
+42
+00:02:25,000 --> 00:02:31,000
+This is going to be used in things either an iris scanner or a thumbprint, facial, facial recognition,
+
+43
+00:02:31,000 --> 00:02:35,000
+hand geometry, and many others we'll discuss in another video.
+
+44
+00:02:35,000 --> 00:02:37,000
+The other one here is called location based.
+
+45
+00:02:37,000 --> 00:02:38,000
+This is.
+
+46
+00:02:38,000 --> 00:02:40,000
+Somewhere you are.
+
+47
+00:02:40,000 --> 00:02:44,000
+This adds contextual security by restricting to a specific IP address.
+
+48
+00:02:44,000 --> 00:02:48,000
+And basically that IP address is going to look into your location.
+
+49
+00:02:48,000 --> 00:02:51,000
+So for example, you can't log in if you're not in the United States.
+
+50
+00:02:51,000 --> 00:02:55,000
+So they may restrict the application to just United States login.
+
+51
+00:02:55,000 --> 00:02:56,000
+All right.
+
+52
+00:02:56,000 --> 00:02:59,000
+So this is going to be multi-factor authentication.
+
+53
+00:02:59,000 --> 00:03:00,000
+This was a review.
+
+54
+00:03:00,000 --> 00:03:01,000
+We did cover this at the beginning of the course.
+
+55
+00:03:01,000 --> 00:03:05,000
+Let's get more in depth into things other than just passwords.
+
diff --git a/18 - Identity and Access Management (IAM)/006 Authentication tokens OB 4.6_en.srt b/18 - Identity and Access Management (IAM)/006 Authentication tokens OB 4.6_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..5aae688ae975aa770fa30cf5d3b617ae9538fcff
--- /dev/null
+++ b/18 - Identity and Access Management (IAM)/006 Authentication tokens OB 4.6_en.srt
@@ -0,0 +1,268 @@
+1
+00:00:00,000 --> 00:00:05,000
+When it comes to multi-factor authentication, keep in mind that you have to use two of the four possible
+
+2
+00:00:05,000 --> 00:00:07,000
+factors that we outlined.
+
+3
+00:00:07,000 --> 00:00:13,000
+If you remember the four factors something you know something you have, some something you are and
+
+4
+00:00:13,000 --> 00:00:14,000
+some where you are.
+
+5
+00:00:14,000 --> 00:00:19,000
+So for example, you can use something you know, which would be like a password and something you have
+
+6
+00:00:19,000 --> 00:00:22,000
+like an RSA token, like I'm about to show you now.
+
+7
+00:00:22,000 --> 00:00:27,000
+Or you can use a password and a thumbprint, or you could use a security key and a thumbprint, something
+
+8
+00:00:27,000 --> 00:00:28,000
+like that.
+
+9
+00:00:28,000 --> 00:00:31,000
+So you're going to have to use at least two of those.
+
+10
+00:00:31,000 --> 00:00:33,000
+Now for your exam.
+
+11
+00:00:33,000 --> 00:00:34,000
+I want you guys to remember.
+
+12
+00:00:35,000 --> 00:00:39,000
+The most the most secure way is multi factor.
+
+13
+00:00:39,000 --> 00:00:43,000
+So if they say something, if they give you a question where they were like well here is uh what's,
+
+14
+00:00:43,000 --> 00:00:49,000
+what's more secure and a 20 digit password, then they say a bank card and a and a four digit Pin.
+
+15
+00:00:49,000 --> 00:00:51,000
+The answer is a bank card and a four digit Pin.
+
+16
+00:00:51,000 --> 00:00:57,000
+If they give you if they give you three choices, such as a really long, complex 20 digit password,
+
+17
+00:00:57,000 --> 00:00:59,000
+bank card and Pin and iris scan.
+
+18
+00:00:59,000 --> 00:01:04,000
+You still do bank card and Pin, because a bank card and a Pin is two factors.
+
+19
+00:01:04,000 --> 00:01:07,000
+It's something you know, the Pin and something you have is the is the card.
+
+20
+00:01:07,000 --> 00:01:13,000
+Now in this video I want you guys to I want to concentrate on the something you have.
+
+21
+00:01:13,000 --> 00:01:18,000
+So there's basically going to uh, it's basically going to give us three things.
+
+22
+00:01:18,000 --> 00:01:22,000
+Number one is going to be some kind of a token.
+
+23
+00:01:22,000 --> 00:01:25,000
+And I want to show you guys this in the first one.
+
+24
+00:01:25,000 --> 00:01:33,000
+So one of the most popular, uh, authentication devices of something you have is this thing here.
+
+25
+00:01:33,000 --> 00:01:34,000
+This is a hard token.
+
+26
+00:01:34,000 --> 00:01:38,000
+So hard tokens are physical devices, key fobs or smart cards.
+
+27
+00:01:38,000 --> 00:01:42,000
+So this is going to be a key fab used to generate secure codes.
+
+28
+00:01:42,000 --> 00:01:47,000
+Now these things these RSA tokens the way this would be this would be paired to your system.
+
+29
+00:01:47,000 --> 00:01:50,000
+And when you want to log in it's going to say give me the code.
+
+30
+00:01:50,000 --> 00:01:54,000
+Now the thing is the the codes on this device changes all the time.
+
+31
+00:01:54,000 --> 00:01:55,000
+All right.
+
+32
+00:01:55,000 --> 00:01:55,000
+It continues.
+
+33
+00:01:55,000 --> 00:01:58,000
+It consistently changes changes changes.
+
+34
+00:01:58,000 --> 00:02:04,000
+The other thing they have is something called a soft token software, uh, software based approaches
+
+35
+00:02:04,000 --> 00:02:06,000
+to generate a secure code on the user device.
+
+36
+00:02:06,000 --> 00:02:11,000
+Now, a soft token is when you have a software.
+
+37
+00:02:11,000 --> 00:02:18,000
+Now there is a software in RSA, Securid software that you can get that has that sends a code to the
+
+38
+00:02:18,000 --> 00:02:20,000
+actual soft device on your phone.
+
+39
+00:02:20,000 --> 00:02:27,000
+So you still need your phone to log in versus using this, using this physical device to log in.
+
+40
+00:02:28,000 --> 00:02:34,000
+Now these both are used to provide real time sensitive passcode as an additional authentication factor,
+
+41
+00:02:34,000 --> 00:02:35,000
+which work well.
+
+42
+00:02:35,000 --> 00:02:38,000
+Now you see this quite a lot being implemented.
+
+43
+00:02:38,000 --> 00:02:42,000
+Also, generally when you try to log into a website, it may send a code to your phone.
+
+44
+00:02:42,000 --> 00:02:45,000
+I see that a lot, especially when I'm trying to log into Google.
+
+45
+00:02:45,000 --> 00:02:50,000
+That is a type of something you have, because you must have the phone that is linked to that particular
+
+46
+00:02:50,000 --> 00:02:51,000
+phone number.
+
+47
+00:02:51,000 --> 00:02:55,000
+The other thing I want to mention is something very secure is called a security key.
+
+48
+00:02:55,000 --> 00:03:01,000
+This is a physical hardware device used for verifying a user's identity, uses part of a multi-factor
+
+49
+00:03:01,000 --> 00:03:05,000
+such as you're more than likely going to have to put in a password, and then you have to plug the key
+
+50
+00:03:05,000 --> 00:03:05,000
+in.
+
+51
+00:03:05,000 --> 00:03:07,000
+So you must have this key.
+
+52
+00:03:07,000 --> 00:03:12,000
+Now, unlike hard tokens, which generate a passcode, the key usually doesn't work like that.
+
+53
+00:03:12,000 --> 00:03:15,000
+All it has to be is just plugged in to the actual network.
+
+54
+00:03:15,000 --> 00:03:19,000
+Now, I used to use this for a particular software.
+
+55
+00:03:19,000 --> 00:03:22,000
+In order to make the software start, you would.
+
+56
+00:03:22,000 --> 00:03:24,000
+You'd have to push the USB key in.
+
+57
+00:03:24,000 --> 00:03:27,000
+The key had a code that would then allow the software to start.
+
+58
+00:03:27,000 --> 00:03:29,000
+So I did use this at one point.
+
+59
+00:03:29,000 --> 00:03:31,000
+Now these things do use protocols.
+
+60
+00:03:31,000 --> 00:03:34,000
+Uh, there's one called Universal Second factor.
+
+61
+00:03:34,000 --> 00:03:36,000
+Uh, that's one of the most popular one.
+
+62
+00:03:37,000 --> 00:03:39,000
+And again, you just have to push the key in.
+
+63
+00:03:39,000 --> 00:03:40,000
+And there's a variety of different ones.
+
+64
+00:03:40,000 --> 00:03:42,000
+Here is one of them.
+
+65
+00:03:42,000 --> 00:03:45,000
+There's also a famous one from Google Titan okay.
+
+66
+00:03:46,000 --> 00:03:54,000
+So those are going to be some of the things that falls into the category of something you have.
+
+67
+00:03:54,000 --> 00:03:58,000
+Keep in mind that something you have and something you know is a combination of multifactor.
+
diff --git a/18 - Identity and Access Management (IAM)/007 Biometric OB 4.6_en.srt b/18 - Identity and Access Management (IAM)/007 Biometric OB 4.6_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..6aa9f158e8878f6dbe37d5a1f2467c6e7eae9e4b
--- /dev/null
+++ b/18 - Identity and Access Management (IAM)/007 Biometric OB 4.6_en.srt
@@ -0,0 +1,680 @@
+1
+00:00:00,000 --> 00:00:02,000
+When it comes to logging into a computer.
+
+2
+00:00:02,000 --> 00:00:07,000
+My most favorite one to use if the device supports is going to be biometrics.
+
+3
+00:00:07,000 --> 00:00:09,000
+I use biometrics to log into everything.
+
+4
+00:00:09,000 --> 00:00:14,000
+When it comes to my cell phone, I'll use a fingerprint and also my windows.
+
+5
+00:00:14,000 --> 00:00:18,000
+My my windows laptop has a biometrics reader on it again, a fingerprint.
+
+6
+00:00:18,000 --> 00:00:20,000
+Now biometrics is great.
+
+7
+00:00:20,000 --> 00:00:26,000
+Biometrics is based on a unique physical attribute or a behavior that the user is going to do.
+
+8
+00:00:26,000 --> 00:00:30,000
+Now in this video, I want to go through all of the different types of biometrics that are out there.
+
+9
+00:00:31,000 --> 00:00:33,000
+And which one is accurate.
+
+10
+00:00:33,000 --> 00:00:37,000
+We'll also take a look at what makes them accurate and how exactly is a process they work.
+
+11
+00:00:37,000 --> 00:00:44,000
+So biometric authentication is a type of system that relies on the unique biological characteristics
+
+12
+00:00:44,000 --> 00:00:44,000
+of you.
+
+13
+00:00:45,000 --> 00:00:45,000
+All right.
+
+14
+00:00:45,000 --> 00:00:50,000
+It's sophisticated, but it's generally always going to be more expensive than implementing passwords.
+
+15
+00:00:50,000 --> 00:00:51,000
+Let's go down the list here.
+
+16
+00:00:51,000 --> 00:00:54,000
+And there's quite a few of them of different biometrics.
+
+17
+00:00:54,000 --> 00:01:02,000
+You can use the first one up that most people no are familiar with in today's world is fingerprint and
+
+18
+00:01:02,000 --> 00:01:03,000
+face scans.
+
+19
+00:01:03,000 --> 00:01:04,000
+Okay.
+
+20
+00:01:04,000 --> 00:01:04,000
+Why?
+
+21
+00:01:04,000 --> 00:01:09,000
+Because the iPhone supports one and a lot of androids uses the thumbprint.
+
+22
+00:01:09,000 --> 00:01:10,000
+So fingerprints.
+
+23
+00:01:10,000 --> 00:01:14,000
+Uh, this here is going to be the visible patterns on your fingers, on your thumb.
+
+24
+00:01:14,000 --> 00:01:17,000
+Everybody does have a unique fingerprint.
+
+25
+00:01:17,000 --> 00:01:23,000
+Face scans or facial recognition will look for the geometrical patterns of your actual face.
+
+26
+00:01:24,000 --> 00:01:26,000
+Uh, now, there's two of them that confuses folks.
+
+27
+00:01:26,000 --> 00:01:28,000
+It's called retina and iris.
+
+28
+00:01:28,000 --> 00:01:31,000
+Now, both of these here will scan your eye.
+
+29
+00:01:31,000 --> 00:01:37,000
+So retina scanners focuses on patterns of blood vessels at the back of the eyes.
+
+30
+00:01:37,000 --> 00:01:42,000
+This is considered the most accurate, but least acceptable.
+
+31
+00:01:43,000 --> 00:01:45,000
+The this thing also has a problem.
+
+32
+00:01:45,000 --> 00:01:48,000
+It could reveal high blood pressure and pregnancy.
+
+33
+00:01:48,000 --> 00:01:57,000
+So remember for your exam, retina scanners is the most accurate biometric, uh, biometric authentication.
+
+34
+00:01:57,000 --> 00:01:58,000
+But it has a problem.
+
+35
+00:01:58,000 --> 00:02:07,000
+You see, this thing here could reveal health issues with people making it an invasion of health, privacy
+
+36
+00:02:07,000 --> 00:02:08,000
+or privacy in general.
+
+37
+00:02:08,000 --> 00:02:12,000
+So this is probably not the most acceptable one out there.
+
+38
+00:02:12,000 --> 00:02:18,000
+Iris scanners focuses on the colored area around the pupil, not the back of the eye around the pupil.
+
+39
+00:02:18,000 --> 00:02:22,000
+Second most accurate, uh, longer authentication lifespan.
+
+40
+00:02:22,000 --> 00:02:25,000
+The reason is because, uh, this one doesn't degrade over time.
+
+41
+00:02:25,000 --> 00:02:27,000
+A lot of times your thumbprint may degrade over time.
+
+42
+00:02:27,000 --> 00:02:29,000
+Your face patterns may change.
+
+43
+00:02:29,000 --> 00:02:31,000
+Palm scans, scans.
+
+44
+00:02:31,000 --> 00:02:33,000
+The Prom uses infrared light to measure.
+
+45
+00:02:33,000 --> 00:02:39,000
+So palm scans measures the vein patterns in your arm.
+
+46
+00:02:39,000 --> 00:02:46,000
+Now, I remember doing this because when you go to Pearson Vue or Vue to take your exam in person,
+
+47
+00:02:46,000 --> 00:02:53,000
+if you do that, if you do take this exam in person, um, like a CISSP or CISSP exam that's in person,
+
+48
+00:02:53,000 --> 00:02:56,000
+but CompTIA exams, you can do it at home any which way you go.
+
+49
+00:02:56,000 --> 00:03:02,000
+And you put it over a box, this v shaped box, and it actually sends a light to your hands and it measures
+
+50
+00:03:02,000 --> 00:03:04,000
+the vein pattern in your hands.
+
+51
+00:03:04,000 --> 00:03:08,000
+Now hand geometry is different than than what I just mentioned.
+
+52
+00:03:08,000 --> 00:03:13,000
+This recognizes the physical dimensions of the hand, including the width and length, so that one is
+
+53
+00:03:13,000 --> 00:03:18,000
+looking for the physical dimensions, how long your fingers are, how wide your hand is, something
+
+54
+00:03:18,000 --> 00:03:19,000
+that a lot of people.
+
+55
+00:03:20,000 --> 00:03:22,000
+Don't believe that exists, but it does.
+
+56
+00:03:22,000 --> 00:03:24,000
+It's not actually a primary.
+
+57
+00:03:24,000 --> 00:03:25,000
+It's a secondary.
+
+58
+00:03:25,000 --> 00:03:30,000
+It's called heart pattern, often employed as a secondary biometric to support another.
+
+59
+00:03:30,000 --> 00:03:32,000
+Now if you're wondering it measures the pulse.
+
+60
+00:03:32,000 --> 00:03:32,000
+Yes.
+
+61
+00:03:32,000 --> 00:03:35,000
+It measures to see if you're alive basically.
+
+62
+00:03:35,000 --> 00:03:41,000
+In other words in high military systems, for example, uh, they may use a retina scanner and then
+
+63
+00:03:41,000 --> 00:03:42,000
+use a heart pulse.
+
+64
+00:03:42,000 --> 00:03:46,000
+That way you're trying to get into a secure facility.
+
+65
+00:03:46,000 --> 00:03:52,000
+You don't cut off the guy's head and put his eye there, take his eyeball out and try to authenticate
+
+66
+00:03:52,000 --> 00:03:55,000
+to the machine because the machine is going to see, hey, this guy alive or what?
+
+67
+00:03:55,000 --> 00:03:58,000
+Sounds it sounds funny, but it's true.
+
+68
+00:03:58,000 --> 00:03:59,000
+All right.
+
+69
+00:03:59,000 --> 00:04:00,000
+Uh, voice pattern.
+
+70
+00:04:00,000 --> 00:04:05,000
+This year will relies on the characteristics of how the person's sound signature dynamics.
+
+71
+00:04:06,000 --> 00:04:07,000
+This is how you write.
+
+72
+00:04:07,000 --> 00:04:13,000
+It looks for the pressure on how you apply the pen, how you do certain stroke, and how fast.
+
+73
+00:04:13,000 --> 00:04:19,000
+And basically you write something, uh, keystroke patterns, of course, how fast you type.
+
+74
+00:04:19,000 --> 00:04:19,000
+All right.
+
+75
+00:04:19,000 --> 00:04:24,000
+So this one is going to look at how long you particularly like hold a key down when you're typing.
+
+76
+00:04:24,000 --> 00:04:25,000
+Okay.
+
+77
+00:04:25,000 --> 00:04:28,000
+So these are going to be some popular biometrics out there.
+
+78
+00:04:28,000 --> 00:04:32,000
+Let's take a look though at what's called biometrics error rating.
+
+79
+00:04:32,000 --> 00:04:34,000
+Now you need to know this for your exam.
+
+80
+00:04:34,000 --> 00:04:40,000
+This is there's two error rating that you should be familiar with what's called type one and type two
+
+81
+00:04:40,000 --> 00:04:41,000
+errors.
+
+82
+00:04:41,000 --> 00:04:44,000
+So type one error occurs when a subject is not authenticated.
+
+83
+00:04:45,000 --> 00:04:50,000
+So when a valid subject is not authenticated, this is the more common of the device when it's set to
+
+84
+00:04:50,000 --> 00:04:51,000
+sensitive.
+
+85
+00:04:51,000 --> 00:04:54,000
+Now type one is this okay.
+
+86
+00:04:54,000 --> 00:04:58,000
+Type one is when I, I go and I put my thumbprint and it did it didn't log me on.
+
+87
+00:04:58,000 --> 00:05:00,000
+All right let me show you a type one log.
+
+88
+00:05:00,000 --> 00:05:03,000
+Type one I'm going to put my thumbprint here.
+
+89
+00:05:03,000 --> 00:05:06,000
+And I'm going to uh, didn't log me in.
+
+90
+00:05:06,000 --> 00:05:08,000
+Uh, didn't, uh, doesn't like me.
+
+91
+00:05:08,000 --> 00:05:08,000
+Nope.
+
+92
+00:05:08,000 --> 00:05:08,000
+Doesn't like me.
+
+93
+00:05:09,000 --> 00:05:10,000
+That's a type one.
+
+94
+00:05:10,000 --> 00:05:11,000
+Annoying.
+
+95
+00:05:11,000 --> 00:05:12,000
+Doesn't doesn't log me in.
+
+96
+00:05:13,000 --> 00:05:18,000
+Now, type one errors are known as false rejection rate.
+
+97
+00:05:18,000 --> 00:05:20,000
+This is when the device is generally set to sensitive.
+
+98
+00:05:21,000 --> 00:05:22,000
+Now.
+
+99
+00:05:22,000 --> 00:05:27,000
+Type one errors are not bad in terms of security.
+
+100
+00:05:27,000 --> 00:05:30,000
+In other words, they're not going to allow bad guys to get in.
+
+101
+00:05:30,000 --> 00:05:31,000
+But type two is.
+
+102
+00:05:31,000 --> 00:05:34,000
+Type two occurs when an invalid subject is authenticated.
+
+103
+00:05:34,000 --> 00:05:39,000
+This is when there's somebody named Bob that's built similarly to me.
+
+104
+00:05:39,000 --> 00:05:42,000
+Um, and he probably lets you using hand geometry.
+
+105
+00:05:42,000 --> 00:05:47,000
+And he puts his hand, I put my hand and it logs me in because he's built similarly to me.
+
+106
+00:05:47,000 --> 00:05:51,000
+He puts his hand logs in as a logs him in as me.
+
+107
+00:05:51,000 --> 00:05:53,000
+This is when, um.
+
+108
+00:05:54,000 --> 00:05:57,000
+Invalid subject is authenticated.
+
+109
+00:05:57,000 --> 00:05:59,000
+So now Bob is basically logging in as me.
+
+110
+00:05:59,000 --> 00:06:02,000
+More common when the device is not sensitive enough.
+
+111
+00:06:02,000 --> 00:06:05,000
+So the device allows a wide variety of logins.
+
+112
+00:06:05,000 --> 00:06:07,000
+This is known as a false acceptance rate.
+
+113
+00:06:07,000 --> 00:06:13,000
+Now, in order to make the device good, you want to make sure you do what's called a crossover error
+
+114
+00:06:13,000 --> 00:06:14,000
+rate or an equal error rate.
+
+115
+00:06:14,000 --> 00:06:17,000
+Now for your exam, the lower this percentage is better.
+
+116
+00:06:17,000 --> 00:06:23,000
+In other words, they look at the device and see well how much type one error does it generate and how
+
+117
+00:06:23,000 --> 00:06:24,000
+much type two error is it generate.
+
+118
+00:06:24,000 --> 00:06:30,000
+Now, if you think about it, the least amount of type one, the better the device, the least amount
+
+119
+00:06:30,000 --> 00:06:31,000
+of type two, the better the device.
+
+120
+00:06:31,000 --> 00:06:36,000
+So what they do is they plotted on a graph and they're like, well, at this point here, it seems like
+
+121
+00:06:36,000 --> 00:06:38,000
+that's when we get the lowest type one and type two.
+
+122
+00:06:38,000 --> 00:06:44,000
+Now for your exam, if they give you some percentages you go with the lowest percentage.
+
+123
+00:06:44,000 --> 00:06:45,000
+All right.
+
+124
+00:06:45,000 --> 00:06:48,000
+So if there's a percentage of 4567 go with four.
+
+125
+00:06:48,000 --> 00:06:50,000
+That's going to be the lowest number.
+
+126
+00:06:50,000 --> 00:06:52,000
+So the crossover error rate the lower the better.
+
+127
+00:06:52,000 --> 00:06:54,000
+This is also known as the equal error rate.
+
+128
+00:06:54,000 --> 00:06:56,000
+How does biometrics actually work.
+
+129
+00:06:56,000 --> 00:06:59,000
+Now I do have a chart here that I want to go over.
+
+130
+00:06:59,000 --> 00:07:04,000
+So when you want to set up biometrics generally on some kind of computer system, the first thing has
+
+131
+00:07:04,000 --> 00:07:06,000
+to have is an enrollment process.
+
+132
+00:07:06,000 --> 00:07:10,000
+This extracts and stores the unique features of that person.
+
+133
+00:07:10,000 --> 00:07:14,000
+So if you're enrolling for the thumbprint, you're gonna have to put their thumbprint quite a few times
+
+134
+00:07:14,000 --> 00:07:16,000
+to create what's known as a reference template.
+
+135
+00:07:17,000 --> 00:07:19,000
+Comparison.
+
+136
+00:07:19,000 --> 00:07:21,000
+Real time comparison of the user templates.
+
+137
+00:07:21,000 --> 00:07:22,000
+So when you put your thumbprint.
+
+138
+00:07:23,000 --> 00:07:27,000
+Uh, what starts to happen is going to start to compare to what it has in its database.
+
+139
+00:07:28,000 --> 00:07:29,000
+Is it match or does it match?
+
+140
+00:07:29,000 --> 00:07:33,000
+Now keep in mind that it's generally should do this in one second or less.
+
+141
+00:07:33,000 --> 00:07:38,000
+Now, I do want to point out that biometrics can be 1 to 1 for authentication.
+
+142
+00:07:39,000 --> 00:07:41,000
+A one to many for identification also.
+
+143
+00:07:42,000 --> 00:07:43,000
+Here's what I mean by that.
+
+144
+00:07:43,000 --> 00:07:51,000
+So there's some biometrics machine where you have to put in a number, like I used to work at a place
+
+145
+00:07:51,000 --> 00:07:56,000
+where the, the clock in, you know, you have to clock in to go to when you go to work, you have to
+
+146
+00:07:56,000 --> 00:07:58,000
+clock in in the morning, clock out in the afternoon.
+
+147
+00:07:58,000 --> 00:08:03,000
+So you had a code, a four digit code you put in your code and then you put your hand.
+
+148
+00:08:03,000 --> 00:08:06,000
+So this was a hand geometry machine and would measure the size of your hand.
+
+149
+00:08:06,000 --> 00:08:08,000
+That was a 1 to 1.
+
+150
+00:08:08,000 --> 00:08:10,000
+In other words it's matching.
+
+151
+00:08:10,000 --> 00:08:13,000
+It knows the user and it's matching this one.
+
+152
+00:08:13,000 --> 00:08:19,000
+The handprint against that user template versus your phone is more of a one to many.
+
+153
+00:08:19,000 --> 00:08:24,000
+So what that means is this when you put your thumbprint, it takes and it has to match it against many
+
+154
+00:08:24,000 --> 00:08:25,000
+profiles it has.
+
+155
+00:08:25,000 --> 00:08:27,000
+And see whichever one matches up log you in.
+
+156
+00:08:28,000 --> 00:08:28,000
+Okay.
+
+157
+00:08:28,000 --> 00:08:30,000
+Keep in mind guys, biometrics.
+
+158
+00:08:30,000 --> 00:08:34,000
+Yes, biometrics is easier to use than passwords.
+
+159
+00:08:34,000 --> 00:08:37,000
+And, uh, what do you call hard tokens or soft tokens?
+
+160
+00:08:37,000 --> 00:08:42,000
+Something you have and something you know on your exam.
+
+161
+00:08:42,000 --> 00:08:46,000
+They might give you a question where they say which one of these is more secure.
+
+162
+00:08:46,000 --> 00:08:47,000
+And I've mentioned this before.
+
+163
+00:08:47,000 --> 00:08:53,000
+I mentioned in a previous video they're going to give you choice a ten digit password choice B uh,
+
+164
+00:08:53,000 --> 00:09:00,000
+retina scanner choice C, fingerprint choice D bank card and Pin or something very simple.
+
+165
+00:09:00,000 --> 00:09:02,000
+And the answer is, of course, a bank card and a Pin.
+
+166
+00:09:02,000 --> 00:09:05,000
+I mentioned this earlier because that is considered multi-factor.
+
+167
+00:09:05,000 --> 00:09:07,000
+While the single factor the bet.
+
+168
+00:09:07,000 --> 00:09:11,000
+The best answer here though, would be something like a password or a thumbprint.
+
+169
+00:09:11,000 --> 00:09:17,000
+That's one of the best combinations because something, you know, complex password and something you
+
+170
+00:09:17,000 --> 00:09:18,000
+are biometric.
+
diff --git a/18 - Identity and Access Management (IAM)/008 Password Management OB 4.6_en.srt b/18 - Identity and Access Management (IAM)/008 Password Management OB 4.6_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..9d84b204a3dcadeb3c23e7f8eaae263a218039eb
--- /dev/null
+++ b/18 - Identity and Access Management (IAM)/008 Password Management OB 4.6_en.srt
@@ -0,0 +1,476 @@
+1
+00:00:00,000 --> 00:00:02,000
+When it comes to IT security.
+
+2
+00:00:02,000 --> 00:00:09,000
+Unfortunately, the least secure way to log into a system is the most used way.
+
+3
+00:00:09,000 --> 00:00:11,000
+And of course, I'm talking about passwords.
+
+4
+00:00:12,000 --> 00:00:12,000
+All right.
+
+5
+00:00:12,000 --> 00:00:19,000
+Passwords is what we use to log into almost every system out there that does support things like biometrics
+
+6
+00:00:19,000 --> 00:00:24,000
+or something you have will also support passwords and many systems will only utilize passwords.
+
+7
+00:00:24,000 --> 00:00:28,000
+So let's see in this video let's learn more about passwords.
+
+8
+00:00:28,000 --> 00:00:29,000
+Let's go through it.
+
+9
+00:00:29,000 --> 00:00:35,000
+So when it comes to password uh let's go through some best practices.
+
+10
+00:00:35,000 --> 00:00:36,000
+When it comes to password.
+
+11
+00:00:36,000 --> 00:00:39,000
+The longer the password the more secure it is.
+
+12
+00:00:39,000 --> 00:00:42,000
+This prevents against brute force attacks against those passwords.
+
+13
+00:00:42,000 --> 00:00:48,000
+Now when it comes to different attacks against a password, brute force attack, if the password is
+
+14
+00:00:48,000 --> 00:00:52,000
+very small, can potentially guess every single combination.
+
+15
+00:00:52,000 --> 00:00:54,000
+At eight, it's somewhat secure.
+
+16
+00:00:54,000 --> 00:00:58,000
+And around 10 or 12 it becomes very secure now.
+
+17
+00:00:59,000 --> 00:01:04,000
+Also, you never want your password to just be, uh, lowercase letters or something.
+
+18
+00:01:04,000 --> 00:01:10,000
+That is a normal word in a dictionary because they basically run dictionaries against your prompt for
+
+19
+00:01:10,000 --> 00:01:11,000
+dictionary attacks.
+
+20
+00:01:11,000 --> 00:01:17,000
+So password should include a mix of uppercase, lowercase letters, numbers, and special characters
+
+21
+00:01:17,000 --> 00:01:19,000
+to resist brute force attack.
+
+22
+00:01:20,000 --> 00:01:21,000
+Now.
+
+23
+00:01:21,000 --> 00:01:23,000
+You don't want passwords to be reused.
+
+24
+00:01:23,000 --> 00:01:25,000
+Never reuse passwords.
+
+25
+00:01:25,000 --> 00:01:31,000
+Avoid using the same password, uh, across multiple accounts.
+
+26
+00:01:31,000 --> 00:01:31,000
+Right?
+
+27
+00:01:31,000 --> 00:01:36,000
+This is something that people are very guilty of doing that way, if I guess one of your password,
+
+28
+00:01:36,000 --> 00:01:41,000
+I can then use that password to log into many other accounts.
+
+29
+00:01:41,000 --> 00:01:42,000
+The other thing is expiration.
+
+30
+00:01:42,000 --> 00:01:46,000
+You should be changing your password about every 90 days.
+
+31
+00:01:46,000 --> 00:01:49,000
+Some organizations are going to say every 60 days to change your password.
+
+32
+00:01:49,000 --> 00:01:54,000
+That way if your password was ever compromised, maybe because its length was small and it wasn't complex
+
+33
+00:01:54,000 --> 00:01:56,000
+enough, at least you changed it.
+
+34
+00:01:56,000 --> 00:01:58,000
+Another thing is password age.
+
+35
+00:01:58,000 --> 00:02:03,000
+How often do you have to update your password?
+
+36
+00:02:04,000 --> 00:02:06,000
+Monitoring the age of the passengers to enforce the update.
+
+37
+00:02:06,000 --> 00:02:14,000
+You see, it's important with password age because what people do is their password expires and then
+
+38
+00:02:14,000 --> 00:02:18,000
+they change the password to the same password they had.
+
+39
+00:02:18,000 --> 00:02:20,000
+So password age says what?
+
+40
+00:02:20,000 --> 00:02:21,000
+You can't reuse that.
+
+41
+00:02:21,000 --> 00:02:24,000
+Basically you can't reuse that password over and over.
+
+42
+00:02:24,000 --> 00:02:28,000
+Now I know managing a password is complex.
+
+43
+00:02:28,000 --> 00:02:34,000
+So and because you have passwords for everything is there's a billion sites and you can't remember them
+
+44
+00:02:34,000 --> 00:02:35,000
+all.
+
+45
+00:02:35,000 --> 00:02:39,000
+Uh, especially if you try to make complex passwords that are really long.
+
+46
+00:02:39,000 --> 00:02:45,000
+Like for me, all my passwords and all my websites are probably touching 20 characters.
+
+47
+00:02:45,000 --> 00:02:50,000
+They are incredibly complex, and I don't memorize any of them because I like to use a password manager.
+
+48
+00:02:50,000 --> 00:02:58,000
+And there are tons of password manager such as Dashlane, which is a really good one, or LastPass.
+
+49
+00:02:58,000 --> 00:02:59,000
+That one is okay too.
+
+50
+00:02:59,000 --> 00:03:01,000
+So these are password managers.
+
+51
+00:03:01,000 --> 00:03:06,000
+These are software that you can download some of them are free, or they have free versions of them
+
+52
+00:03:06,000 --> 00:03:11,000
+that basically they store passwords for you, and some of them can even retype it on the website, so
+
+53
+00:03:11,000 --> 00:03:13,000
+you never need to memorize it like I do.
+
+54
+00:03:13,000 --> 00:03:18,000
+I don't memorize passwords at all because I'm too old to to memorize those complex things.
+
+55
+00:03:18,000 --> 00:03:23,000
+Now it's encouraged for managing large number of complex password password managers store and encrypt
+
+56
+00:03:23,000 --> 00:03:24,000
+passwords for you.
+
+57
+00:03:24,000 --> 00:03:27,000
+You only have to remember one strong master password.
+
+58
+00:03:27,000 --> 00:03:32,000
+And yes, my master password is incredibly complex and no one knows it.
+
+59
+00:03:33,000 --> 00:03:41,000
+Now we are moving into the world of passwordless authentication.
+
+60
+00:03:41,000 --> 00:03:43,000
+This is a new trend, and this is you're going to find more.
+
+61
+00:03:43,000 --> 00:03:48,000
+They're being replaced with alternative methods like biometric security keys at one time.
+
+62
+00:03:48,000 --> 00:03:50,000
+Have you guys gone to a website lately?
+
+63
+00:03:50,000 --> 00:03:57,000
+And you try to log in and it's like, well, you just put your username and you press enter and it says,
+
+64
+00:03:57,000 --> 00:04:04,000
+hey, you have your phone, let me send you a one time key or token to your, to your phone, and you
+
+65
+00:04:04,000 --> 00:04:06,000
+get the code to type it in and boom, it logs you in.
+
+66
+00:04:06,000 --> 00:04:07,000
+I know quite a few websites are doing that.
+
+67
+00:04:07,000 --> 00:04:11,000
+This is known as passwordless authentication.
+
+68
+00:04:12,000 --> 00:04:17,000
+This enhances security by eliminating the risk associated with weaker compromise password.
+
+69
+00:04:18,000 --> 00:04:24,000
+Another thing that we can use when it comes to managing users and passwords is something we call Pam,
+
+70
+00:04:24,000 --> 00:04:28,000
+or privileged access management tools, and this is something you want to implement on your network.
+
+71
+00:04:28,000 --> 00:04:35,000
+These are things that used to control, manage and monitor access to critical systems within the business.
+
+72
+00:04:35,000 --> 00:04:39,000
+They focus on people basically as good or privileged users in the network.
+
+73
+00:04:39,000 --> 00:04:40,000
+Now.
+
+74
+00:04:40,000 --> 00:04:42,000
+They do have.
+
+75
+00:04:42,000 --> 00:04:46,000
+Pam itself is going to give us three technology, what's called just in time.
+
+76
+00:04:46,000 --> 00:04:54,000
+We can use uh, basically for time limited access password vault in to store our credentials and what's
+
+77
+00:04:54,000 --> 00:04:55,000
+called a ephemeral credential.
+
+78
+00:04:55,000 --> 00:04:56,000
+Let's get into it.
+
+79
+00:04:56,000 --> 00:05:00,000
+So the first one up I want to mention is something called Just in time.
+
+80
+00:05:00,000 --> 00:05:07,000
+Just in time is when permissions are granted, uh, permissions granted privilege access on an as needed
+
+81
+00:05:07,000 --> 00:05:07,000
+basis.
+
+82
+00:05:07,000 --> 00:05:12,000
+So basically you log in, you need a certain amount of permissions to access a file.
+
+83
+00:05:12,000 --> 00:05:13,000
+Just in time.
+
+84
+00:05:13,000 --> 00:05:16,000
+We'll give you just that permission just when you need it.
+
+85
+00:05:17,000 --> 00:05:20,000
+And when you're done, it removes the credentials away from you.
+
+86
+00:05:20,000 --> 00:05:27,000
+So this reduces the risk of privilege abuse by ensuring privileges are only granted when they are needed.
+
+87
+00:05:27,000 --> 00:05:31,000
+So, for example, ideal for situations where users need temporary elevated access.
+
+88
+00:05:31,000 --> 00:05:36,000
+So let's say you're working in a network today and you're working in the accounting department.
+
+89
+00:05:36,000 --> 00:05:39,000
+But you need to do some bank reconciliation because Mary is not in.
+
+90
+00:05:39,000 --> 00:05:40,000
+But that's not your job.
+
+91
+00:05:40,000 --> 00:05:43,000
+So just in time they grant you that access to do that.
+
+92
+00:05:43,000 --> 00:05:46,000
+And then when you come back the next day it's gone.
+
+93
+00:05:46,000 --> 00:05:48,000
+The privilege to do that is gone.
+
+94
+00:05:49,000 --> 00:05:52,000
+In big companies, we're going to need to store those passwords.
+
+95
+00:05:52,000 --> 00:05:54,000
+So we're going to use what's called password vault in.
+
+96
+00:05:54,000 --> 00:06:00,000
+This is securely storing and managing credentials for privileged accounts in a central repository.
+
+97
+00:06:00,000 --> 00:06:05,000
+Now the good thing here is that this allows you to check in and check out the credentials when they
+
+98
+00:06:05,000 --> 00:06:05,000
+need.
+
+99
+00:06:05,000 --> 00:06:09,000
+The vault automatically manages and rotates and update passwords as needed.
+
+100
+00:06:09,000 --> 00:06:13,000
+That way, you could know if a credential is being used in your network, and the other one here is
+
+101
+00:06:13,000 --> 00:06:15,000
+called ephemeral credentials.
+
+102
+00:06:15,000 --> 00:06:18,000
+Now what this does, this is good technology that comes with the Pam.
+
+103
+00:06:18,000 --> 00:06:20,000
+Because what this does is this is able to.
+
+104
+00:06:22,000 --> 00:06:25,000
+These are temporary credentials that are generated on demand and expire.
+
+105
+00:06:25,000 --> 00:06:29,000
+So this is an entire username and password is generated when you need it.
+
+106
+00:06:29,000 --> 00:06:33,000
+It's only for a short period of time and then boom, it's gone forever.
+
+107
+00:06:33,000 --> 00:06:39,000
+So enhance the security by ensuring credentials are only valid for a short period of time.
+
+108
+00:06:39,000 --> 00:06:41,000
+Now you're going to specify what that is.
+
+109
+00:06:41,000 --> 00:06:45,000
+This is using dynamic environments like cloud, where credentials are needed for a short period of time
+
+110
+00:06:45,000 --> 00:06:47,000
+to complete a certain task, and then it's gone.
+
+111
+00:06:48,000 --> 00:06:48,000
+All right.
+
+112
+00:06:48,000 --> 00:06:50,000
+So when it comes to Pam.
+
+113
+00:06:50,000 --> 00:06:56,000
+Pam is really good to manage and credentials, uh, on a network, pushing up privileges when needed,
+
+114
+00:06:56,000 --> 00:07:02,000
+like with just in time or just giving out username and passwords, uh, like with ephemeral credentials.
+
+115
+00:07:02,000 --> 00:07:04,000
+But also we covered passwords.
+
+116
+00:07:04,000 --> 00:07:07,000
+Keep in mind passwords should be moderately long 8 to 12 characters.
+
+117
+00:07:07,000 --> 00:07:09,000
+Change your password at least every 90 days.
+
+118
+00:07:09,000 --> 00:07:16,000
+Keep it complex uppercase, lowercase numbers and symbols in your password and make sure don't reuse
+
+119
+00:07:16,000 --> 00:07:18,000
+the same password over and over.
+
diff --git a/18 - Identity and Access Management (IAM)/009 Quick Quiz.html b/18 - Identity and Access Management (IAM)/009 Quick Quiz.html
new file mode 100644
index 0000000000000000000000000000000000000000..455aa698669b63ef0e5cbd82e3bd0b97abecaf7d
--- /dev/null
+++ b/18 - Identity and Access Management (IAM)/009 Quick Quiz.html
@@ -0,0 +1,479 @@
+
+
+
+
+
+
+ Quiz
+
+
+
+
+
+
+
+
+ Score: 999 of
+ 999%
+
+ Correct: 999
+ Incorrect: 999
+
+
+
+
+
+
+
+
+
+
diff --git a/19 - Incident Response/001 Incident Response Steps OB 4.8_en.srt b/19 - Incident Response/001 Incident Response Steps OB 4.8_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..c7cb8877ab55a56eecc0dcf0b45e68753ef1ef59
--- /dev/null
+++ b/19 - Incident Response/001 Incident Response Steps OB 4.8_en.srt
@@ -0,0 +1,544 @@
+1
+00:00:00,000 --> 00:00:06,000
+When you work in cybersecurity, you should expect to get a security incident almost on a daily basis.
+
+2
+00:00:06,000 --> 00:00:10,000
+If not, you're going to have multiple security incidents every single day.
+
+3
+00:00:10,000 --> 00:00:14,000
+Depending on your organization, some security incidents are going to be really small, and some of
+
+4
+00:00:14,000 --> 00:00:16,000
+them are going to be really big.
+
+5
+00:00:16,000 --> 00:00:18,000
+That needs to be responded to right away.
+
+6
+00:00:18,000 --> 00:00:24,000
+In this video, I want to talk about what exactly is a security incident, what is the definition of
+
+7
+00:00:24,000 --> 00:00:25,000
+a security incident.
+
+8
+00:00:25,000 --> 00:00:31,000
+And of course, we want to go through the security incident steps that you need to know for your exam.
+
+9
+00:00:31,000 --> 00:00:32,000
+So let's get started.
+
+10
+00:00:33,000 --> 00:00:37,000
+First of all, what exactly is a security incident?
+
+11
+00:00:37,000 --> 00:00:39,000
+How do you define a security incident?
+
+12
+00:00:39,000 --> 00:00:46,000
+Well, by definition, a security incident is an event that that compromises the confidentiality, integrity
+
+13
+00:00:46,000 --> 00:00:48,000
+or availability of information assets.
+
+14
+00:00:48,000 --> 00:00:54,000
+Now, basically anything that affects CIA is considered a security incident.
+
+15
+00:00:54,000 --> 00:00:55,000
+Let me give you a few examples.
+
+16
+00:00:55,000 --> 00:00:58,000
+Obviously, a hacker stealing data, that's confidentiality.
+
+17
+00:00:58,000 --> 00:01:03,000
+It's affecting confidential de DDoS against your server.
+
+18
+00:01:03,000 --> 00:01:05,000
+Well, that's affecting availability.
+
+19
+00:01:05,000 --> 00:01:08,000
+Hacker changing data or bad people changing your information.
+
+20
+00:01:08,000 --> 00:01:10,000
+That's against integrity.
+
+21
+00:01:10,000 --> 00:01:12,000
+Now it just doesn't include that.
+
+22
+00:01:12,000 --> 00:01:15,000
+But what about a printer drop in server going offline.
+
+23
+00:01:15,000 --> 00:01:18,000
+Those are both against availability within the network.
+
+24
+00:01:18,000 --> 00:01:20,000
+What if a user workstation crashes?
+
+25
+00:01:20,000 --> 00:01:22,000
+That again is availability.
+
+26
+00:01:22,000 --> 00:01:24,000
+What if a user gets a virus on their computer?
+
+27
+00:01:24,000 --> 00:01:28,000
+Potential confidentiality, integrity and availability that's getting hit.
+
+28
+00:01:28,000 --> 00:01:32,000
+So security incidents are pretty broad.
+
+29
+00:01:32,000 --> 00:01:35,000
+In other words, it's not just hacker coming in.
+
+30
+00:01:35,000 --> 00:01:41,000
+In fact, 90% of security incidents comes happens because of internal users doing things.
+
+31
+00:01:41,000 --> 00:01:46,000
+For example, a user may open an email link, a user station may die.
+
+32
+00:01:47,000 --> 00:01:52,000
+Don't think all your security incidents are coming from outside that you have to remove from your mind.
+
+33
+00:01:52,000 --> 00:01:56,000
+Most of the security incidents occurs with the people who have access to the information.
+
+34
+00:01:56,000 --> 00:01:58,000
+Now that you have it, you got to have a process.
+
+35
+00:01:58,000 --> 00:02:03,000
+You got to have a process and steps in order to deal with this incident.
+
+36
+00:02:03,000 --> 00:02:09,000
+It is super important that you memorize this in the order that you see it in.
+
+37
+00:02:09,000 --> 00:02:18,000
+So we have to prepare, detect, analyze, contain, eradicate, recover and then do our lesson learn.
+
+38
+00:02:18,000 --> 00:02:19,000
+Let's get started on this.
+
+39
+00:02:19,000 --> 00:02:21,000
+So the first step.
+
+40
+00:02:22,000 --> 00:02:25,000
+When it comes to security incident is preparation.
+
+41
+00:02:25,000 --> 00:02:33,000
+This is where the organization develops the incident response plans, establishes the response teams,
+
+42
+00:02:33,000 --> 00:02:35,000
+set up the tools and communication channel.
+
+43
+00:02:35,000 --> 00:02:40,000
+So listen, before you respond to any incident, you have to build a team.
+
+44
+00:02:40,000 --> 00:02:42,000
+You have to come up with plans okay.
+
+45
+00:02:42,000 --> 00:02:44,000
+When this happens we do this.
+
+46
+00:02:44,000 --> 00:02:46,000
+You have to know who's going to be on the team.
+
+47
+00:02:46,000 --> 00:02:48,000
+You have to train the team.
+
+48
+00:02:48,000 --> 00:02:50,000
+You have to train the people when they're doing this.
+
+49
+00:02:50,000 --> 00:02:53,000
+They just can't go and respond to incidents if they weren't trained on this.
+
+50
+00:02:53,000 --> 00:02:59,000
+So this includes training people, conducting regular security assessments within the business and ensuring
+
+51
+00:02:59,000 --> 00:03:00,000
+that the team have the right resources.
+
+52
+00:03:00,000 --> 00:03:03,000
+So do this before you respond to any incident.
+
+53
+00:03:03,000 --> 00:03:10,000
+Now let's say let's play a, uh, let's come up with a scenario.
+
+54
+00:03:10,000 --> 00:03:14,000
+So the scenario is a user workstation was potentially hacked.
+
+55
+00:03:14,000 --> 00:03:23,000
+The user called in and said the workstation, uh, is is showing a message that the data is encrypted
+
+56
+00:03:23,000 --> 00:03:25,000
+and they want $10,000 to get the data back.
+
+57
+00:03:25,000 --> 00:03:27,000
+So this is a kind of a ransomware.
+
+58
+00:03:27,000 --> 00:03:29,000
+So this is what the user sees on the screen.
+
+59
+00:03:29,000 --> 00:03:32,000
+The first thing up is we have to detect this ransomware.
+
+60
+00:03:32,000 --> 00:03:35,000
+So detection involves identifying the security incidents.
+
+61
+00:03:35,000 --> 00:03:41,000
+This can be achieved through various means network monitoring intrusion detection system regular security
+
+62
+00:03:41,000 --> 00:03:42,000
+scans.
+
+63
+00:03:42,000 --> 00:03:48,000
+So something like this could have been detected with the user's endpoint security or antivirus software.
+
+64
+00:03:48,000 --> 00:03:52,000
+It could have been detected by the IDs system on the user's machine also.
+
+65
+00:03:53,000 --> 00:03:59,000
+Or it if it was a different kind of incident, something on a server, maybe a security audit by auditors
+
+66
+00:03:59,000 --> 00:03:59,000
+would have done.
+
+67
+00:03:59,000 --> 00:04:00,000
+So.
+
+68
+00:04:00,000 --> 00:04:05,000
+The first thing is to quickly I, uh, detect it.
+
+69
+00:04:05,000 --> 00:04:07,000
+If you don't detect it, you'll never respond to it.
+
+70
+00:04:07,000 --> 00:04:12,000
+The quicker you detect it means the faster you can respond.
+
+71
+00:04:12,000 --> 00:04:13,000
+Now analysis.
+
+72
+00:04:13,000 --> 00:04:14,000
+So now that we.
+
+73
+00:04:14,000 --> 00:04:16,000
+Okay, there's an incident we have to detect.
+
+74
+00:04:16,000 --> 00:04:19,000
+There's an incident on Mary's workstation.
+
+75
+00:04:19,000 --> 00:04:21,000
+Let's go analyze the incident.
+
+76
+00:04:21,000 --> 00:04:26,000
+Once the potential is is detected, it must be analyzed.
+
+77
+00:04:27,000 --> 00:04:27,000
+One.
+
+78
+00:04:27,000 --> 00:04:29,000
+We want to understand its nature.
+
+79
+00:04:29,000 --> 00:04:31,000
+Like what exactly is it doing?
+
+80
+00:04:31,000 --> 00:04:31,000
+Like what?
+
+81
+00:04:31,000 --> 00:04:33,000
+What is it that it wants?
+
+82
+00:04:33,000 --> 00:04:34,000
+Is it?
+
+83
+00:04:34,000 --> 00:04:39,000
+Well, in our case, we know it's a ransomware and it wants money, but has it stolen the data?
+
+84
+00:04:39,000 --> 00:04:40,000
+Is it modifying data?
+
+85
+00:04:40,000 --> 00:04:42,000
+Is it bringing down the system?
+
+86
+00:04:42,000 --> 00:04:46,000
+This involves determining the type of attack the system is affected.
+
+87
+00:04:46,000 --> 00:04:48,000
+Is data compromise.
+
+88
+00:04:48,000 --> 00:04:51,000
+This analysis is really important.
+
+89
+00:04:52,000 --> 00:04:55,000
+Because from here we can know what steps to take in order to fix it.
+
+90
+00:04:56,000 --> 00:05:00,000
+Now, one of the things we should be doing, depending on what the incident is we have to contain that
+
+91
+00:05:00,000 --> 00:05:01,000
+incident.
+
+92
+00:05:01,000 --> 00:05:06,000
+Containing the incident is to ensure the incident doesn't spread to limit the scope and magnitude.
+
+93
+00:05:06,000 --> 00:05:09,000
+This involves isolating systems, blocking malicious traffic.
+
+94
+00:05:09,000 --> 00:05:11,000
+The best thing here we can do, we go, we see.
+
+95
+00:05:11,000 --> 00:05:12,000
+Oh boy.
+
+96
+00:05:12,000 --> 00:05:13,000
+That's ransomware okay.
+
+97
+00:05:13,000 --> 00:05:14,000
+Unplug it.
+
+98
+00:05:14,000 --> 00:05:15,000
+Take it off the network.
+
+99
+00:05:15,000 --> 00:05:20,000
+So if it is a worm or some kind of malware that can spread, it doesn't spread that way.
+
+100
+00:05:20,000 --> 00:05:24,000
+It doesn't, uh, doesn't produce further damage on your network.
+
+101
+00:05:24,000 --> 00:05:25,000
+Eradicate it.
+
+102
+00:05:26,000 --> 00:05:27,000
+After the incident.
+
+103
+00:05:27,000 --> 00:05:30,000
+We have to get it off the entire system.
+
+104
+00:05:30,000 --> 00:05:32,000
+Eradication.
+
+105
+00:05:32,000 --> 00:05:34,000
+Uh, looks for that root cause, you know.
+
+106
+00:05:34,000 --> 00:05:36,000
+You know what is causing that?
+
+107
+00:05:36,000 --> 00:05:40,000
+This involves removing the malware, closing the security gap, restoring the system.
+
+108
+00:05:40,000 --> 00:05:42,000
+For example, something like this.
+
+109
+00:05:42,000 --> 00:05:43,000
+Like this ransomware.
+
+110
+00:05:43,000 --> 00:05:48,000
+The best thing here we can do is just reimage windows, reinstall windows, reinstall all the applications,
+
+111
+00:05:48,000 --> 00:05:50,000
+and hopefully no data was lost.
+
+112
+00:05:51,000 --> 00:05:52,000
+Recovery.
+
+113
+00:05:53,000 --> 00:05:57,000
+You want to restore the system, restore it to normal.
+
+114
+00:05:57,000 --> 00:05:59,000
+This includes ensuring that all systems are clean.
+
+115
+00:05:59,000 --> 00:06:01,000
+You want to make sure we reinstall windows.
+
+116
+00:06:01,000 --> 00:06:02,000
+You got to put it back on the network.
+
+117
+00:06:02,000 --> 00:06:03,000
+You got to put back all the applications.
+
+118
+00:06:03,000 --> 00:06:04,000
+You got to get the data.
+
+119
+00:06:05,000 --> 00:06:10,000
+And we got to make sure that the system is functioning just as she had it the day before.
+
+120
+00:06:10,000 --> 00:06:15,000
+Monitoring and then connecting to it and making sure that this malware does not come back.
+
+121
+00:06:15,000 --> 00:06:19,000
+Finally, lesson learned after the incident.
+
+122
+00:06:19,000 --> 00:06:19,000
+Resolve.
+
+123
+00:06:19,000 --> 00:06:25,000
+It's important to conduct a post incident review analyzing what happened, how it was handled, what
+
+124
+00:06:25,000 --> 00:06:26,000
+could have been done.
+
+125
+00:06:26,000 --> 00:06:34,000
+Now, keep in mind the lesson learned is more of, uh, the process, the incident response process.
+
+126
+00:06:34,000 --> 00:06:35,000
+Like a faster response.
+
+127
+00:06:35,000 --> 00:06:38,000
+Did we contain it right or wrong?
+
+128
+00:06:38,000 --> 00:06:40,000
+What could we have done better the next time?
+
+129
+00:06:41,000 --> 00:06:46,000
+So let's learn about more about the process of the actual incident response now.
+
+130
+00:06:47,000 --> 00:06:50,000
+These are steps that you're going to know for your exam.
+
+131
+00:06:50,000 --> 00:06:52,000
+Know these steps in the order.
+
+132
+00:06:52,000 --> 00:06:55,000
+Be prepared for questions where they're going to say, okay, they did this.
+
+133
+00:06:55,000 --> 00:06:57,000
+And then what should they do next?
+
+134
+00:06:57,000 --> 00:07:00,000
+Make sure to know these steps for your tests.
+
+135
+00:07:00,000 --> 00:07:05,000
+Now keep in mind that different organizations may have different steps, but these are the ones you
+
+136
+00:07:05,000 --> 00:07:07,000
+need to know for your exam.
+
diff --git a/19 - Incident Response/002 Incident Response Training OB 4.8_en.srt b/19 - Incident Response/002 Incident Response Training OB 4.8_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..9ec15d97b14faace57c32e6bd5610e2922a72364
--- /dev/null
+++ b/19 - Incident Response/002 Incident Response Training OB 4.8_en.srt
@@ -0,0 +1,488 @@
+1
+00:00:00,000 --> 00:00:07,000
+If you're working in cybersecurity and you're working on the incident response team, there are some
+
+2
+00:00:07,000 --> 00:00:08,000
+things that you should be familiar with.
+
+3
+00:00:08,000 --> 00:00:10,000
+So in this video, let's take a look at that.
+
+4
+00:00:10,000 --> 00:00:15,000
+First of all, if you're working on an incident response team, you have to have the appropriate training
+
+5
+00:00:15,000 --> 00:00:17,000
+in the right incident response activity.
+
+6
+00:00:17,000 --> 00:00:25,000
+You see, incident response is a very important or a critical process in IT security because it's not
+
+7
+00:00:25,000 --> 00:00:28,000
+if we're going to have an incident, it's just when we're going to have an incident and we're going
+
+8
+00:00:28,000 --> 00:00:32,000
+to have the right people to know what to do ASAP.
+
+9
+00:00:32,000 --> 00:00:37,000
+The longer incidents are out there or the longer incidents stays open or not responded to, or at least
+
+10
+00:00:37,000 --> 00:00:42,000
+not contained, the more data could be stolen modified.
+
+11
+00:00:42,000 --> 00:00:46,000
+Basically, the longer the systems are vulnerable or the more damage is happening.
+
+12
+00:00:46,000 --> 00:00:50,000
+So we want to make sure that we train our users correctly.
+
+13
+00:00:50,000 --> 00:00:57,000
+So training focuses on the educational and the skill based skills needed for preparing individuals and
+
+14
+00:00:57,000 --> 00:00:59,000
+teams to respond effectively.
+
+15
+00:00:59,000 --> 00:01:02,000
+Now the training is going to be a wide variety.
+
+16
+00:01:02,000 --> 00:01:04,000
+Good incident response.
+
+17
+00:01:04,000 --> 00:01:11,000
+Folks should have good skills and knowledge of different kinds of systems, networking and all kinds
+
+18
+00:01:11,000 --> 00:01:13,000
+of IT security tools.
+
+19
+00:01:13,000 --> 00:01:20,000
+You can't be an incident response person that has never worked on windows, or never worked on a windows
+
+20
+00:01:20,000 --> 00:01:26,000
+server, or don't understand how networking works or don't know IP addressing, you know, basic networking.
+
+21
+00:01:26,000 --> 00:01:31,000
+Because the simple fact is, you wouldn't understand the scope of how an incident affect a system if
+
+22
+00:01:31,000 --> 00:01:34,000
+you really don't know how that system works.
+
+23
+00:01:34,000 --> 00:01:39,000
+Now, also, when it comes to working an incident response and we come up with our incident response
+
+24
+00:01:39,000 --> 00:01:46,000
+process procedures of actually responding to an incident or fixing incidents, we have to have ways
+
+25
+00:01:46,000 --> 00:01:50,000
+of testing those responses or testing our process.
+
+26
+00:01:50,000 --> 00:01:53,000
+So what is testing is about?
+
+27
+00:01:53,000 --> 00:01:58,000
+Well, how prepared are we and how, you know, what's our capabilities in doing this.
+
+28
+00:01:58,000 --> 00:02:03,000
+So there's two kinds of tests I want to talk about table top tests and simulations.
+
+29
+00:02:03,000 --> 00:02:06,000
+So the first one up is a tabletop exercise.
+
+30
+00:02:06,000 --> 00:02:11,000
+Let's say your organization comes up with their own incident response process.
+
+31
+00:02:11,000 --> 00:02:16,000
+We're going to do this if an incident happened here's how we're going to detect it.
+
+32
+00:02:16,000 --> 00:02:19,000
+Here's how we're going to respond to it.
+
+33
+00:02:19,000 --> 00:02:23,000
+Here's how we're going to eradicate it now contain it and so on and so on.
+
+34
+00:02:24,000 --> 00:02:29,000
+So one of the first things they should be doing is what's called a tabletop exercise.
+
+35
+00:02:29,000 --> 00:02:36,000
+Remember, for your exam, tabletop exercise is a discussion based session where team members walk through
+
+36
+00:02:36,000 --> 00:02:37,000
+various incidents.
+
+37
+00:02:37,000 --> 00:02:42,000
+Scenario it is they're sitting at a table and they're discussing it.
+
+38
+00:02:42,000 --> 00:02:50,000
+For example, they're going to say, well, if there if a computer gets a virus and then they talk,
+
+39
+00:02:50,000 --> 00:02:55,000
+they go around and they talk about what they're going to do, how are they going to respond to this
+
+40
+00:02:55,000 --> 00:02:57,000
+computer that gets a virus?
+
+41
+00:02:57,000 --> 00:03:03,000
+The purpose of this is to assess the effectiveness of the incident response plan and the team's understanding.
+
+42
+00:03:03,000 --> 00:03:08,000
+So they're going to go around, they're going to say, Bob is going to say, well, I'm the one that.
+
+43
+00:03:08,000 --> 00:03:10,000
+Recovers the system.
+
+44
+00:03:10,000 --> 00:03:13,000
+Mary is going to say, well, before you do that, Bob, I got to contain the system.
+
+45
+00:03:13,000 --> 00:03:14,000
+Here is how I'm going to do that.
+
+46
+00:03:14,000 --> 00:03:20,000
+So they're basically understanding their roles and they're understanding exactly what they're going
+
+47
+00:03:20,000 --> 00:03:20,000
+to be doing.
+
+48
+00:03:20,000 --> 00:03:23,000
+Now, the thing is, they're not actually doing it.
+
+49
+00:03:24,000 --> 00:03:30,000
+You're not going to get up and do hands on of containing a, you know, containing a computer, for
+
+50
+00:03:30,000 --> 00:03:39,000
+example, that simulations, these are more hands on and involved in creating a realistic cyber incident
+
+51
+00:03:39,000 --> 00:03:40,000
+environment.
+
+52
+00:03:40,000 --> 00:03:43,000
+We're the response team can practice responding.
+
+53
+00:03:43,000 --> 00:03:46,000
+This includes the use of real tools and systems.
+
+54
+00:03:46,000 --> 00:03:48,000
+So if they're going to be.
+
+55
+00:03:49,000 --> 00:03:54,000
+Are contained in the system by taking it off the Vlan or taking it off the network.
+
+56
+00:03:54,000 --> 00:03:55,000
+You can actually go and do that.
+
+57
+00:03:55,000 --> 00:03:59,000
+They're going to go and maybe disable the Nic card or remove the cable from there.
+
+58
+00:03:59,000 --> 00:04:06,000
+If it involves utilizing certain malware, software anti-malware to clean the infection, then use that
+
+59
+00:04:06,000 --> 00:04:07,000
+tool.
+
+60
+00:04:07,000 --> 00:04:13,000
+This is going to give them a more realistic handling of the tools and to respond to incidents.
+
+61
+00:04:13,000 --> 00:04:16,000
+So this is a better test now.
+
+62
+00:04:17,000 --> 00:04:21,000
+When you manage an incident, you got to really look at the root cause of the incident.
+
+63
+00:04:21,000 --> 00:04:29,000
+This involves exploring systematic processes to identify the underlying reasons why a security incident
+
+64
+00:04:29,000 --> 00:04:29,000
+occurred.
+
+65
+00:04:29,000 --> 00:04:32,000
+RCA is critical, helps prevent future incidents.
+
+66
+00:04:32,000 --> 00:04:39,000
+So let's say you get, uh, somebody that gets, um.
+
+67
+00:04:40,000 --> 00:04:47,000
+Ransomware on their computer and you guys go, you do your incident response process, you respond to
+
+68
+00:04:47,000 --> 00:04:49,000
+it, you clean it up.
+
+69
+00:04:50,000 --> 00:04:53,000
+Three days later they got the same thing again.
+
+70
+00:04:53,000 --> 00:04:55,000
+And you go, you go, you clean it up.
+
+71
+00:04:55,000 --> 00:04:57,000
+But you got to keep asking yourself.
+
+72
+00:04:58,000 --> 00:05:00,000
+Why exactly is this happening?
+
+73
+00:05:00,000 --> 00:05:04,000
+What's the root cause of this person always getting malware?
+
+74
+00:05:04,000 --> 00:05:11,000
+After doing some digging, you came to understand that this person failed to attend the user awareness
+
+75
+00:05:11,000 --> 00:05:12,000
+training sessions.
+
+76
+00:05:13,000 --> 00:05:15,000
+That's why this user was not trained.
+
+77
+00:05:15,000 --> 00:05:19,000
+This user just kept clicking on things that says that they're going to be a millionaire if they click
+
+78
+00:05:19,000 --> 00:05:20,000
+on this.
+
+79
+00:05:21,000 --> 00:05:24,000
+So they kept falling for the same trick over and over.
+
+80
+00:05:24,000 --> 00:05:28,000
+Root cause analysis is when you're looking for the main cause.
+
+81
+00:05:28,000 --> 00:05:30,000
+Why is this incident happening?
+
+82
+00:05:30,000 --> 00:05:34,000
+By doing this, you are able to eradicate many incidents in your network.
+
+83
+00:05:34,000 --> 00:05:40,000
+So remember what root cause analysis is looking at the deep end like the deep, deep, deep end.
+
+84
+00:05:40,000 --> 00:05:41,000
+Why is this happening?
+
+85
+00:05:43,000 --> 00:05:48,000
+One other thing you might be doing when it comes to working on incident response is knowing who your
+
+86
+00:05:48,000 --> 00:05:49,000
+threats are.
+
+87
+00:05:49,000 --> 00:05:54,000
+Threat hunting is a whole different thing than working just in IT security.
+
+88
+00:05:54,000 --> 00:05:55,000
+So.
+
+89
+00:05:56,000 --> 00:06:03,000
+It involves exploring the proactive and iterative approach to detecting and isolating advanced threats
+
+90
+00:06:03,000 --> 00:06:05,000
+that evade security solution.
+
+91
+00:06:06,000 --> 00:06:09,000
+Critical components of a good security program.
+
+92
+00:06:09,000 --> 00:06:11,000
+Identifying mitigating sophisticated cyber threats.
+
+93
+00:06:11,000 --> 00:06:13,000
+Now, here's here's what threat hunting is.
+
+94
+00:06:13,000 --> 00:06:16,000
+You see in traditional cyber security.
+
+95
+00:06:18,000 --> 00:06:26,000
+We put in all the great practices to keep our system secure firewalls, IDs, all kinds of updates.
+
+96
+00:06:26,000 --> 00:06:30,000
+We trained our users multi layers of firewalls and so on.
+
+97
+00:06:30,000 --> 00:06:32,000
+Now here's the problem.
+
+98
+00:06:33,000 --> 00:06:36,000
+We then we sat back and we waited for the threat to come.
+
+99
+00:06:36,000 --> 00:06:37,000
+The threat come.
+
+100
+00:06:37,000 --> 00:06:38,000
+And it got in.
+
+101
+00:06:38,000 --> 00:06:41,000
+But we respond like we talked about in this section.
+
+102
+00:06:41,000 --> 00:06:43,000
+How about if we go after the threat.
+
+103
+00:06:43,000 --> 00:06:48,000
+How about if we proactively go after the threat?
+
+104
+00:06:48,000 --> 00:06:51,000
+Like this says exploring the proactive iterative approach to detecting.
+
+105
+00:06:51,000 --> 00:06:53,000
+How about if we go after?
+
+106
+00:06:53,000 --> 00:06:56,000
+How about if we go to the dark web and see what threats are coming?
+
+107
+00:06:56,000 --> 00:07:03,000
+How about if we learn about cyber threats that are out there that hasn't actually affected us yet,
+
+108
+00:07:03,000 --> 00:07:07,000
+and then build our systems proactively to stop those things?
+
+109
+00:07:07,000 --> 00:07:13,000
+So let's say there is malware a circulating the world right now, but it hasn't affected us.
+
+110
+00:07:14,000 --> 00:07:16,000
+How about if we go and we learn about malware?
+
+111
+00:07:16,000 --> 00:07:20,000
+A we explore what it is and now we hunt the threat.
+
+112
+00:07:20,000 --> 00:07:21,000
+We don't let the threat hunt us.
+
+113
+00:07:21,000 --> 00:07:23,000
+That was our whole methodology.
+
+114
+00:07:23,000 --> 00:07:27,000
+We just we built a fortress and we just waited for the threat to come.
+
+115
+00:07:27,000 --> 00:07:29,000
+Now we're going to build a fortress.
+
+116
+00:07:29,000 --> 00:07:30,000
+Now we're going to go and hunt the threat.
+
+117
+00:07:30,000 --> 00:07:35,000
+Now we're going to go and see who's coming after us, and then we can build our fortress even better.
+
+118
+00:07:35,000 --> 00:07:39,000
+So if it does come, it's not going to get us it's threat hunting.
+
+119
+00:07:39,000 --> 00:07:41,000
+So this takes a different approach to it.
+
+120
+00:07:41,000 --> 00:07:45,000
+Keep in mind that working on IT security at as many aspects of IT security.
+
+121
+00:07:45,000 --> 00:07:48,000
+But in this particular one, you got to understand the different threats out there.
+
+122
+00:07:48,000 --> 00:07:54,000
+And working on an incident response team is is a critical part of keeping your network secure.
+
diff --git a/19 - Incident Response/003 Digital Forensics OB 4.8_en.srt b/19 - Incident Response/003 Digital Forensics OB 4.8_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..a36fa4e4cc4bfa41d77e70826acb7aa1a3cce8f6
--- /dev/null
+++ b/19 - Incident Response/003 Digital Forensics OB 4.8_en.srt
@@ -0,0 +1,748 @@
+1
+00:00:00,000 --> 00:00:08,000
+When it comes to crime in modern society, most of it is going to be using a computer at some point,
+
+2
+00:00:08,000 --> 00:00:11,000
+either to do the crime or help to get the crime done.
+
+3
+00:00:11,000 --> 00:00:12,000
+Here's what I mean.
+
+4
+00:00:13,000 --> 00:00:17,000
+In the world of crime, there's two kinds of crime.
+
+5
+00:00:17,000 --> 00:00:21,000
+Crime where the computer helps you, or crime against the computer.
+
+6
+00:00:21,000 --> 00:00:24,000
+So crime, for example, let's say you want to kill someone.
+
+7
+00:00:24,000 --> 00:00:26,000
+I know it's an extreme example.
+
+8
+00:00:26,000 --> 00:00:31,000
+I know you want to kill someone, and you're not sure how to dispose of a body or the quickest way to
+
+9
+00:00:31,000 --> 00:00:31,000
+kill them.
+
+10
+00:00:31,000 --> 00:00:34,000
+So you go to Google and you type in, how do I kill someone?
+
+11
+00:00:34,000 --> 00:00:36,000
+How do I dispose of a body?
+
+12
+00:00:36,000 --> 00:00:39,000
+Well, that's where the computer is helping you do the crime.
+
+13
+00:00:39,000 --> 00:00:43,000
+Maybe you want to rob a bank and you're like, well, how does bank, how are bank secure?
+
+14
+00:00:43,000 --> 00:00:44,000
+Same thing.
+
+15
+00:00:44,000 --> 00:00:46,000
+But then there are crimes against the computer.
+
+16
+00:00:46,000 --> 00:00:53,000
+This is going to be like when you utilize malware to steal data, or like when you're doing a DDoS attack
+
+17
+00:00:53,000 --> 00:00:58,000
+to take out an entire system any which way, if you're ever caught, and hopefully you are, if that's
+
+18
+00:00:58,000 --> 00:01:02,000
+what you're doing, all those criminals, hopefully they get caught.
+
+19
+00:01:02,000 --> 00:01:04,000
+We are going to now need to.
+
+20
+00:01:06,000 --> 00:01:08,000
+Get the evidence to prosecute them.
+
+21
+00:01:08,000 --> 00:01:11,000
+And this brings me to this topic of digital forensics.
+
+22
+00:01:12,000 --> 00:01:19,000
+This is going to go into the methodologies and principles applied in the investigation of cyber incidents,
+
+23
+00:01:19,000 --> 00:01:24,000
+specifically focused identification, collection, examination and preservation of digital evidence.
+
+24
+00:01:24,000 --> 00:01:30,000
+So now remember this one here is talking about cyber, uh, cyber incidents.
+
+25
+00:01:30,000 --> 00:01:37,000
+But the things I'm talking about here applies to not just, uh, crimes against the computer, but crimes
+
+26
+00:01:37,000 --> 00:01:41,000
+that are utilized, crimes that utilize the computer as part of it.
+
+27
+00:01:42,000 --> 00:01:47,000
+It underscores the need for a good ethical handling of the digital evidence.
+
+28
+00:01:47,000 --> 00:01:49,000
+Now you want to remember something.
+
+29
+00:01:49,000 --> 00:01:56,000
+If digital evidence is, for example, like the Google search the criminal did to how to rob a bank,
+
+30
+00:01:56,000 --> 00:01:58,000
+that's digital evidence.
+
+31
+00:01:58,000 --> 00:02:02,000
+The problem with digital evidence versus physical evidence, like a murder body or murder weapon, is
+
+32
+00:02:02,000 --> 00:02:05,000
+that it can easily be manipulated and change.
+
+33
+00:02:05,000 --> 00:02:07,000
+So we have to know how to handle that.
+
+34
+00:02:07,000 --> 00:02:11,000
+So there are a couple of things here in this section of the course that I want to go over.
+
+35
+00:02:11,000 --> 00:02:15,000
+Keep in mind, I'm just going to tell you what you need to know for your exam.
+
+36
+00:02:15,000 --> 00:02:21,000
+Digital forensics is an entire industry within it that if you're interested in working for law enforcement,
+
+37
+00:02:21,000 --> 00:02:24,000
+please explore their certifications in it.
+
+38
+00:02:24,000 --> 00:02:29,000
+They're specialized tools like EnCase or Access Data Forensics Toolkit or the Fctc.
+
+39
+00:02:30,000 --> 00:02:34,000
+There are many tools, many you know, there's a whole industry on this.
+
+40
+00:02:34,000 --> 00:02:37,000
+Let's just go into what you need to know for your exam.
+
+41
+00:02:37,000 --> 00:02:39,000
+The first thing I want to mention is something called a legal hold.
+
+42
+00:02:39,000 --> 00:02:43,000
+This is a firm that means, um, we're potentially relevant.
+
+43
+00:02:43,000 --> 00:02:47,000
+Data is preserved for legal and investigative purpose.
+
+44
+00:02:47,000 --> 00:02:50,000
+This involves ensuring that such data is not altered, delete or destroyed.
+
+45
+00:02:50,000 --> 00:02:57,000
+So first of all, let's say somebody within an organization was stealing money out of the company.
+
+46
+00:02:58,000 --> 00:02:58,000
+All right.
+
+47
+00:02:58,000 --> 00:03:03,000
+And the we call the police and reported them to police, arrested the person.
+
+48
+00:03:03,000 --> 00:03:07,000
+The investigators are going to come in and say, we need a legal hold on all the data from our systems,
+
+49
+00:03:07,000 --> 00:03:14,000
+because that data and the system she was using is now going to be used as part of evidence to prosecute
+
+50
+00:03:14,000 --> 00:03:14,000
+her.
+
+51
+00:03:15,000 --> 00:03:18,000
+So they put a legal hold on it.
+
+52
+00:03:18,000 --> 00:03:26,000
+That means that such data is not altered, deleted, destroyed during the course of the investigation.
+
+53
+00:03:26,000 --> 00:03:27,000
+So they say it's a legal hold.
+
+54
+00:03:27,000 --> 00:03:29,000
+That means nobody can touch it.
+
+55
+00:03:29,000 --> 00:03:29,000
+All right.
+
+56
+00:03:29,000 --> 00:03:31,000
+That's for them to use.
+
+57
+00:03:31,000 --> 00:03:35,000
+Now, a hot topic for your exam is going to be this firm called the Chain of Custody.
+
+58
+00:03:35,000 --> 00:03:41,000
+This referred to the documentation of paper trail that records or other records control, transfer,
+
+59
+00:03:41,000 --> 00:03:44,000
+analysis and disposition of physical or electronic evidence.
+
+60
+00:03:44,000 --> 00:03:45,000
+Here's what it is.
+
+61
+00:03:46,000 --> 00:03:48,000
+When evidence is collected.
+
+62
+00:03:49,000 --> 00:03:54,000
+Who took it, when they took it, how they took it, where they took it to, what method it was used
+
+63
+00:03:54,000 --> 00:03:59,000
+to, to collect it, where they put it, how long it was there, who had access to it, when did they
+
+64
+00:03:59,000 --> 00:04:00,000
+take it?
+
+65
+00:04:00,000 --> 00:04:01,000
+What did they do with it?
+
+66
+00:04:01,000 --> 00:04:03,000
+Basically, it's like the life of the evidence.
+
+67
+00:04:03,000 --> 00:04:06,000
+It's a step by step life of the evidence.
+
+68
+00:04:06,000 --> 00:04:11,000
+It talks of things like it's a sequence of, you know, who had it, what did they do with it?
+
+69
+00:04:11,000 --> 00:04:13,000
+Who did they give it to transfer?
+
+70
+00:04:13,000 --> 00:04:15,000
+How did they analyze it?
+
+71
+00:04:15,000 --> 00:04:17,000
+How did they maybe gave it back?
+
+72
+00:04:18,000 --> 00:04:21,000
+And it's both for physical and electronic evidence.
+
+73
+00:04:21,000 --> 00:04:22,000
+You have to understand something.
+
+74
+00:04:22,000 --> 00:04:24,000
+The key word is integrity.
+
+75
+00:04:24,000 --> 00:04:30,000
+You see, how many times have you guys ever heard of court cases where they say something like, well,
+
+76
+00:04:30,000 --> 00:04:33,000
+the evidence was thrown out because the evidence was tampered with.
+
+77
+00:04:33,000 --> 00:04:34,000
+All right.
+
+78
+00:04:34,000 --> 00:04:35,000
+The evidence was tampered with.
+
+79
+00:04:35,000 --> 00:04:36,000
+So the evidence was no good.
+
+80
+00:04:36,000 --> 00:04:43,000
+The chain of custody ensures that the evidence was never tampered with in a way that makes the evidence
+
+81
+00:04:43,000 --> 00:04:44,000
+invalid.
+
+82
+00:04:44,000 --> 00:04:45,000
+So remember what it does.
+
+83
+00:04:45,000 --> 00:04:49,000
+Who took it when they took it, how they took it, what they did with it, where they put it, who accessed
+
+84
+00:04:49,000 --> 00:04:49,000
+it, and so on.
+
+85
+00:04:49,000 --> 00:04:52,000
+And it continues for the life of the evidence that way.
+
+86
+00:04:52,000 --> 00:04:57,000
+Let's say the prosecution is using this that way the defense can't look at it and say, well, this
+
+87
+00:04:57,000 --> 00:05:01,000
+evidence was tampered with in a way that that that corrupted it.
+
+88
+00:05:01,000 --> 00:05:02,000
+That way.
+
+89
+00:05:02,000 --> 00:05:06,000
+When the defense does look at it, defense can say, okay, well, this guy reanalyzed it.
+
+90
+00:05:06,000 --> 00:05:07,000
+You know, he's really smart.
+
+91
+00:05:07,000 --> 00:05:09,000
+So I guess it was it was the right.
+
+92
+00:05:09,000 --> 00:05:10,000
+It was the right analysis.
+
+93
+00:05:12,000 --> 00:05:14,000
+Acquiring digital evidence.
+
+94
+00:05:14,000 --> 00:05:18,000
+All right, is the process of collecting digital evidence while ensuring the data is.
+
+95
+00:05:18,000 --> 00:05:19,000
+Now this is the big thing.
+
+96
+00:05:19,000 --> 00:05:22,000
+I mentioned this when we talk digital evidence.
+
+97
+00:05:22,000 --> 00:05:24,000
+The big thing is manipulation.
+
+98
+00:05:24,000 --> 00:05:28,000
+The integrity of the evidence is important during the process.
+
+99
+00:05:28,000 --> 00:05:34,000
+This involves creating exact copies of hard drives, memory or other storage media, uh, using specialized
+
+100
+00:05:34,000 --> 00:05:34,000
+tools.
+
+101
+00:05:34,000 --> 00:05:39,000
+Now, I want to talk about this a little bit when it comes to digital evidence.
+
+102
+00:05:39,000 --> 00:05:43,000
+When we take, for example, all of those evidence are going to be stored on hard drive.
+
+103
+00:05:43,000 --> 00:05:48,000
+One of the things you want to do is you want to do what's called a bit by bit duplication of the drive.
+
+104
+00:05:48,000 --> 00:05:49,000
+So.
+
+105
+00:05:50,000 --> 00:05:53,000
+Here's how they collect digital evidence.
+
+106
+00:05:53,000 --> 00:05:56,000
+So let's say we had an employee at the company.
+
+107
+00:05:56,000 --> 00:05:57,000
+His name is Bob.
+
+108
+00:05:57,000 --> 00:05:59,000
+And Bob was stealing data.
+
+109
+00:05:59,000 --> 00:06:03,000
+So this computer that we had, we took we took Bob's hard drive out.
+
+110
+00:06:03,000 --> 00:06:05,000
+Now here's what we should do.
+
+111
+00:06:06,000 --> 00:06:11,000
+We're going to take the hard drive and we are going to duplicate.
+
+112
+00:06:11,000 --> 00:06:14,000
+This is the hard, hard drive.
+
+113
+00:06:14,000 --> 00:06:15,000
+This is the original one.
+
+114
+00:06:15,000 --> 00:06:17,000
+What we're going to do is we're going to make a copy.
+
+115
+00:06:18,000 --> 00:06:20,000
+To to analyze.
+
+116
+00:06:21,000 --> 00:06:22,000
+All right.
+
+117
+00:06:22,000 --> 00:06:23,000
+That's going to be one.
+
+118
+00:06:23,000 --> 00:06:24,000
+Copy.
+
+119
+00:06:24,000 --> 00:06:31,000
+Now, what we should do is you're going to make maybe not one, maybe two copies to analyze what we
+
+120
+00:06:31,000 --> 00:06:33,000
+should do with this original one is put it away.
+
+121
+00:06:33,000 --> 00:06:36,000
+This one should never be analyzed, should not be tampered with.
+
+122
+00:06:36,000 --> 00:06:37,000
+Now.
+
+123
+00:06:39,000 --> 00:06:44,000
+You don't want to just do a normal duplication of the original hard drive.
+
+124
+00:06:45,000 --> 00:06:45,000
+All right.
+
+125
+00:06:45,000 --> 00:06:53,000
+What we want to do is we want to do what's called a bit by bit duplicator.
+
+126
+00:06:53,000 --> 00:06:58,000
+This means that it's going to duplicate the drive every single sector you see.
+
+127
+00:06:58,000 --> 00:07:03,000
+If you just do a normal duplication or copy of the drive, it only copies just the just the data that's
+
+128
+00:07:03,000 --> 00:07:03,000
+there.
+
+129
+00:07:03,000 --> 00:07:05,000
+It doesn't copy all the data that was deleted.
+
+130
+00:07:05,000 --> 00:07:12,000
+You want to when you take this drive, when when you analyze it, you want to get all the blank spaces,
+
+131
+00:07:12,000 --> 00:07:15,000
+all the spaces that there is no data there, even though there is data there.
+
+132
+00:07:15,000 --> 00:07:17,000
+So do what's called a bit by bit duplication.
+
+133
+00:07:17,000 --> 00:07:19,000
+So you're going to want to take out the drive.
+
+134
+00:07:19,000 --> 00:07:21,000
+You're going to want to make a couple of copies of it.
+
+135
+00:07:23,000 --> 00:07:29,000
+And one copy that you should be making before I leave here is going to be is another duplication.
+
+136
+00:07:29,000 --> 00:07:29,000
+Copy.
+
+137
+00:07:30,000 --> 00:07:30,000
+Duplicate.
+
+138
+00:07:30,000 --> 00:07:31,000
+Hard drive.
+
+139
+00:07:31,000 --> 00:07:31,000
+Copy.
+
+140
+00:07:31,000 --> 00:07:32,000
+We'll call this.
+
+141
+00:07:32,000 --> 00:07:38,000
+What this is is this is an additional this is the drive you're going to use to make even more copies.
+
+142
+00:07:39,000 --> 00:07:40,000
+These means analyze drives.
+
+143
+00:07:40,000 --> 00:07:43,000
+So you make a couple of them but at least have one.
+
+144
+00:07:43,000 --> 00:07:45,000
+And then this drive here can be put into a vault.
+
+145
+00:07:45,000 --> 00:07:49,000
+This drive here can be put in stored away that no one has access to it.
+
+146
+00:07:49,000 --> 00:07:52,000
+No one is modifying or troubling it.
+
+147
+00:07:53,000 --> 00:07:54,000
+All right.
+
+148
+00:07:56,000 --> 00:07:57,000
+Reporting.
+
+149
+00:07:57,000 --> 00:08:01,000
+So report involves documenting the finding of the forensics.
+
+150
+00:08:01,000 --> 00:08:02,000
+What did you find?
+
+151
+00:08:02,000 --> 00:08:06,000
+Forensics tools like the access data forensics or the forensics toolkit.
+
+152
+00:08:06,000 --> 00:08:11,000
+Or in case, uh, in case these are all forensic software.
+
+153
+00:08:11,000 --> 00:08:13,000
+How was the evidence collected, analyzed and preserved?
+
+154
+00:08:13,000 --> 00:08:16,000
+And what conclusion can be drawn when you analyze the evidence?
+
+155
+00:08:16,000 --> 00:08:17,000
+Did he do the crime?
+
+156
+00:08:17,000 --> 00:08:18,000
+Did he not do the crime?
+
+157
+00:08:18,000 --> 00:08:21,000
+So you have to come up with a good reporting on this.
+
+158
+00:08:21,000 --> 00:08:23,000
+Preservation is the big thing.
+
+159
+00:08:25,000 --> 00:08:29,000
+Digital forensics refers to the process of protecting and maintaining the integrity.
+
+160
+00:08:29,000 --> 00:08:30,000
+The digital.
+
+161
+00:08:30,000 --> 00:08:32,000
+The main word is the integrity, right?
+
+162
+00:08:32,000 --> 00:08:35,000
+Because we said that it is important.
+
+163
+00:08:36,000 --> 00:08:39,000
+That you keep things the same.
+
+164
+00:08:39,000 --> 00:08:42,000
+If the evidence is ever modified, they're going to throw it out.
+
+165
+00:08:42,000 --> 00:08:47,000
+Storing the evidence in a secure environment, ensuring that is protected from alteration, tampering
+
+166
+00:08:47,000 --> 00:08:48,000
+or degradation.
+
+167
+00:08:48,000 --> 00:08:51,000
+You also, when I got here you see this hard drive.
+
+168
+00:08:51,000 --> 00:08:52,000
+The best thing to do is make a hash of it.
+
+169
+00:08:52,000 --> 00:08:55,000
+If you hash the entire drive, it was any modification.
+
+170
+00:08:55,000 --> 00:08:56,000
+You can detect that.
+
+171
+00:08:58,000 --> 00:08:59,000
+E-Discovery.
+
+172
+00:08:59,000 --> 00:09:01,000
+If you've ever heard of this firm e-discovery.
+
+173
+00:09:01,000 --> 00:09:07,000
+This is the process of identifying, collecting and producing electronically stored information.
+
+174
+00:09:07,000 --> 00:09:12,000
+So ESI in in response to a request for production legal case.
+
+175
+00:09:12,000 --> 00:09:17,000
+So e-discovery is identifying and collecting.
+
+176
+00:09:19,000 --> 00:09:21,000
+Electronic evidence emails.
+
+177
+00:09:22,000 --> 00:09:25,000
+Documents, databases, audio files, and video files.
+
+178
+00:09:25,000 --> 00:09:32,000
+So when you heard a storm eDiscovery, remember it's basically they're looking for electronic evidence,
+
+179
+00:09:32,000 --> 00:09:32,000
+right?
+
+180
+00:09:32,000 --> 00:09:33,000
+They're looking for.
+
+181
+00:09:34,000 --> 00:09:41,000
+That web page, that audio file, that video, that email that proves some kind of thing in a case where
+
+182
+00:09:41,000 --> 00:09:43,000
+it's proven the guy guilty or not guilty.
+
+183
+00:09:43,000 --> 00:09:43,000
+All right.
+
+184
+00:09:43,000 --> 00:09:48,000
+These are some terms here that you want to be familiar with when it comes to digital forensics.
+
+185
+00:09:48,000 --> 00:09:52,000
+Keep in mind this is an entire industry by itself.
+
+186
+00:09:52,000 --> 00:09:56,000
+It does require specialized training, but this is a good introduction to it if you ever want to give
+
+187
+00:09:56,000 --> 00:09:58,000
+it a shot in real life.
+
diff --git a/19 - Incident Response/004 Types of logs OB 4.9_en.srt b/19 - Incident Response/004 Types of logs OB 4.9_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..29bf04cf6874f0d2cb45ee968f90d2f9f3928361
--- /dev/null
+++ b/19 - Incident Response/004 Types of logs OB 4.9_en.srt
@@ -0,0 +1,456 @@
+1
+00:00:00,000 --> 00:00:05,000
+One of the most important things in IT security is log files.
+
+2
+00:00:05,000 --> 00:00:10,000
+Keep in mind that log files tells you all the activities happen in your network.
+
+3
+00:00:10,000 --> 00:00:16,000
+In fact, there are tons of different log files and firewall logs, application logs, network logs,
+
+4
+00:00:16,000 --> 00:00:17,000
+IDs, logs.
+
+5
+00:00:17,000 --> 00:00:19,000
+Everything has log files.
+
+6
+00:00:19,000 --> 00:00:24,000
+Let's do a quick review of some of these kinds of log files and where they come from in this video.
+
+7
+00:00:24,000 --> 00:00:26,000
+Now this is not an all end video.
+
+8
+00:00:26,000 --> 00:00:27,000
+Every device has log files.
+
+9
+00:00:27,000 --> 00:00:31,000
+And I just want to go through some of the most common log files that you're going to encounter.
+
+10
+00:00:31,000 --> 00:00:36,000
+Now, I do want to keep in mind that it is probably impossible to read all these log files.
+
+11
+00:00:36,000 --> 00:00:41,000
+That's why you're going to have a Siem system, Siem systems or security information and event management
+
+12
+00:00:41,000 --> 00:00:43,000
+is able to correlate.
+
+13
+00:00:43,000 --> 00:00:47,000
+Grab these log files for you and then read them for you.
+
+14
+00:00:47,000 --> 00:00:51,000
+And based on their algorithms, they can do alerts and tell you if there's any issues.
+
+15
+00:00:51,000 --> 00:00:54,000
+Let's go through some of the most common log files and where we get them from.
+
+16
+00:00:54,000 --> 00:01:03,000
+So when it comes to IT security, the first device that comes to my mind is actually this device, which
+
+17
+00:01:03,000 --> 00:01:04,000
+is your firewall.
+
+18
+00:01:04,000 --> 00:01:07,000
+Your firewall is going to come with a ton of log file.
+
+19
+00:01:07,000 --> 00:01:12,000
+In fact, if I log in here, there's a ton of log files that says all the traffic coming in and out,
+
+20
+00:01:12,000 --> 00:01:14,000
+what was denied, what was not denied.
+
+21
+00:01:14,000 --> 00:01:17,000
+So this is going to be included.
+
+22
+00:01:17,000 --> 00:01:19,000
+Attempted and blocked connections.
+
+23
+00:01:19,000 --> 00:01:20,000
+What was allowed?
+
+24
+00:01:20,000 --> 00:01:24,000
+Was there any did anybody modify this thing logged into it changes anything.
+
+25
+00:01:24,000 --> 00:01:28,000
+Unauthorized attempt, potential breaches is all going to be within the log files.
+
+26
+00:01:28,000 --> 00:01:32,000
+Thousands and thousands of entries every day for firewall logs.
+
+27
+00:01:32,000 --> 00:01:34,000
+Application log.
+
+28
+00:01:34,000 --> 00:01:39,000
+This is going to be logs that record events from specific application.
+
+29
+00:01:39,000 --> 00:01:44,000
+Think like Microsoft Word or a custom application you may have at crash did open it.
+
+30
+00:01:44,000 --> 00:01:46,000
+It corrupted data.
+
+31
+00:01:46,000 --> 00:01:48,000
+This includes information about its performance.
+
+32
+00:01:48,000 --> 00:01:56,000
+Maybe it keeps crashing how users or when users used it, any errors that might be generated on any
+
+33
+00:01:56,000 --> 00:01:56,000
+security events.
+
+34
+00:01:56,000 --> 00:01:59,000
+Maybe there's detection in there.
+
+35
+00:01:59,000 --> 00:02:04,000
+Maybe there's abnormal behavior with people using the application endpoint logs.
+
+36
+00:02:04,000 --> 00:02:09,000
+These are going to be generated by endpoint devices, laptops, desktop mobile devices.
+
+37
+00:02:09,000 --> 00:02:13,000
+Now you could have endpoint security software installed generating these logs too.
+
+38
+00:02:13,000 --> 00:02:15,000
+They contain information or operation.
+
+39
+00:02:15,000 --> 00:02:19,000
+But the activity on the device such as was there any changes on the device.
+
+40
+00:02:19,000 --> 00:02:21,000
+What are users using the device?
+
+41
+00:02:21,000 --> 00:02:27,000
+Is there any antivirus alerts such as the system infected with malware this is going to use to help
+
+42
+00:02:27,000 --> 00:02:28,000
+detect malware?
+
+43
+00:02:28,000 --> 00:02:32,000
+This is going to use to detect if there's any unattempted unauthorized access to these devices in the
+
+44
+00:02:32,000 --> 00:02:33,000
+first place.
+
+45
+00:02:34,000 --> 00:02:38,000
+Operating system specific security log.
+
+46
+00:02:38,000 --> 00:02:43,000
+Now the operating system, like windows, is going to have something called a system log that says any
+
+47
+00:02:43,000 --> 00:02:46,000
+problems and issues that happens with windows.
+
+48
+00:02:46,000 --> 00:02:49,000
+But there is in windows something called a security log.
+
+49
+00:02:49,000 --> 00:02:56,000
+This tells us specific things, such as when users are logging on and off, is there any errors, policy
+
+50
+00:02:56,000 --> 00:03:00,000
+changes, or even somebody manipulated things like group policies on it?
+
+51
+00:03:00,000 --> 00:03:03,000
+Now this is going to be within the operating system itself.
+
+52
+00:03:03,000 --> 00:03:07,000
+IDs, IPS, IDs helps to detect intrusions.
+
+53
+00:03:07,000 --> 00:03:13,000
+IPS can prevent intrusions such as shutting off connections or disabling connections.
+
+54
+00:03:13,000 --> 00:03:18,000
+Of course, anything that comes through these systems are going to be recorded and logged.
+
+55
+00:03:18,000 --> 00:03:23,000
+And this is going to give you log in information about network traffic and security threats.
+
+56
+00:03:24,000 --> 00:03:29,000
+They have to identify suspicious activity policy violations within your network.
+
+57
+00:03:29,000 --> 00:03:31,000
+Network logs.
+
+58
+00:03:31,000 --> 00:03:33,000
+Now this is going to come from your network devices.
+
+59
+00:03:33,000 --> 00:03:39,000
+Record data about the activities within a network including traffic flows, connectivity, even network
+
+60
+00:03:39,000 --> 00:03:40,000
+errors.
+
+61
+00:03:40,000 --> 00:03:41,000
+Maybe there's corruption of the data.
+
+62
+00:03:41,000 --> 00:03:43,000
+Maybe the data is taken too long.
+
+63
+00:03:43,000 --> 00:03:49,000
+Maybe there's rejection of the data from certain devices on the stand and the baseline activity.
+
+64
+00:03:49,000 --> 00:03:55,000
+So you should know what is the baseline network activity, especially the flow of traffic.
+
+65
+00:03:55,000 --> 00:04:01,000
+And if there's any variation, network logs can tell you that there's a worm you want to be familiar
+
+66
+00:04:01,000 --> 00:04:04,000
+with that is going to give you a ton of info.
+
+67
+00:04:04,000 --> 00:04:05,000
+It's called metadata.
+
+68
+00:04:05,000 --> 00:04:08,000
+Metadata refers to data about data.
+
+69
+00:04:08,000 --> 00:04:13,000
+For example, in cybersecurity, like like a file contains data.
+
+70
+00:04:13,000 --> 00:04:15,000
+But what is data about that data?
+
+71
+00:04:15,000 --> 00:04:21,000
+Well, things like file creation when it was created, when it was modified, who had access to it,
+
+72
+00:04:21,000 --> 00:04:22,000
+what did they do with it?
+
+73
+00:04:22,000 --> 00:04:24,000
+Did they send it in an email?
+
+74
+00:04:24,000 --> 00:04:25,000
+Where is it located?
+
+75
+00:04:25,000 --> 00:04:31,000
+So metadata are used to trace activities and look at patterns of what's happening with that data.
+
+76
+00:04:31,000 --> 00:04:34,000
+Now where are we getting these log files from right.
+
+77
+00:04:34,000 --> 00:04:38,000
+Where are the sources that you're going to get information about your network from?
+
+78
+00:04:38,000 --> 00:04:46,000
+Well, the most common way that you're going to find information about potential impacts or potential
+
+79
+00:04:46,000 --> 00:04:52,000
+vulnerabilities or potential holes or malware is going to be in a vulnerability scan.
+
+80
+00:04:52,000 --> 00:04:59,000
+There's going to be automated tools that you're going to use to scan systems across the network.
+
+81
+00:04:59,000 --> 00:05:05,000
+And the application security weakness vulnerability scanners, like the Nexus security scanner will
+
+82
+00:05:05,000 --> 00:05:08,000
+be able to tell you that that machine over there is not patched.
+
+83
+00:05:08,000 --> 00:05:09,000
+It has a weak password.
+
+84
+00:05:09,000 --> 00:05:13,000
+Also, they give you detailed information about each system.
+
+85
+00:05:15,000 --> 00:05:16,000
+Automated reports.
+
+86
+00:05:16,000 --> 00:05:19,000
+So you're going to have a variety of security tools and systems.
+
+87
+00:05:19,000 --> 00:05:23,000
+Think of like IPS systems Siem systems.
+
+88
+00:05:23,000 --> 00:05:26,000
+That's going to generate all kinds of automated reports.
+
+89
+00:05:26,000 --> 00:05:28,000
+That's going to give you a ton of information about your network.
+
+90
+00:05:28,000 --> 00:05:33,000
+First of all, a high level overview of your security posture, like, hey, how secure really is your
+
+91
+00:05:33,000 --> 00:05:33,000
+network?
+
+92
+00:05:33,000 --> 00:05:39,000
+And then it's going to go into different patterns that shows whether you are being more secure or you're
+
+93
+00:05:39,000 --> 00:05:39,000
+not.
+
+94
+00:05:40,000 --> 00:05:41,000
+Dashboard.
+
+95
+00:05:42,000 --> 00:05:45,000
+In things like seem systems and software like Splunk.
+
+96
+00:05:45,000 --> 00:05:50,000
+They have dashboards that does a real time overview of the organization, security status, the aggregate
+
+97
+00:05:50,000 --> 00:05:55,000
+data from multiple log files or multiple sources in a single interface.
+
+98
+00:05:55,000 --> 00:05:57,000
+They can even give you alerts.
+
+99
+00:05:57,000 --> 00:06:01,000
+Dashboards are good for monitoring your systems in real time.
+
+100
+00:06:01,000 --> 00:06:06,000
+Now, if you monitor a network, you're going to have what's you're going to be doing packet capture.
+
+101
+00:06:06,000 --> 00:06:11,000
+Packet captures is when you utilize software like Wireshark.
+
+102
+00:06:11,000 --> 00:06:16,000
+This records network traffic and analyze the traffic that traverse across your network.
+
+103
+00:06:16,000 --> 00:06:22,000
+The Wireshark allows you to capture that network traffic, and then you're going to have to analyze
+
+104
+00:06:22,000 --> 00:06:22,000
+it.
+
+105
+00:06:22,000 --> 00:06:27,000
+And if you have the good skills, you can know, okay, this is abnormal traffic or this is normal traffic.
+
+106
+00:06:27,000 --> 00:06:30,000
+And but it's going to give you a good understand the nature of the network.
+
+107
+00:06:30,000 --> 00:06:36,000
+Now when you analyze it you can see is data being sent away from your network.
+
+108
+00:06:36,000 --> 00:06:40,000
+Is there a communications between attackers and normal systems?
+
+109
+00:06:41,000 --> 00:06:46,000
+Uh, if you haven't played around with packet capture and tools such as Wireshark, I strongly suggest
+
+110
+00:06:46,000 --> 00:06:47,000
+that you do.
+
+111
+00:06:47,000 --> 00:06:52,000
+Keep in mind this is just a quick overview of some common log files or common places we're going to
+
+112
+00:06:52,000 --> 00:06:53,000
+learn about our network.
+
+113
+00:06:53,000 --> 00:06:59,000
+Keep in mind, every device and every application on the network has log files, and I know reading
+
+114
+00:06:59,000 --> 00:07:04,000
+them is impossible, but that's why you have Siem systems to make it a lot easier.
+
diff --git a/19 - Incident Response/005 Quick Quiz.html b/19 - Incident Response/005 Quick Quiz.html
new file mode 100644
index 0000000000000000000000000000000000000000..160eb538e2db4a5be682cc4ea8e2ea1c20464496
--- /dev/null
+++ b/19 - Incident Response/005 Quick Quiz.html
@@ -0,0 +1,479 @@
+
+
+
+
+
+
+ Quiz
+
+
+
+
+
+
+
+
+ Score: 999 of
+ 999%
+
+ Correct: 999
+ Incorrect: 999
+
+
+
+
+
+
+
+
+
+
diff --git a/20 - Security Governance and Privacy/001 Security Polices, Standards, Guidelines and Procedures OB 5.1_en.srt b/20 - Security Governance and Privacy/001 Security Polices, Standards, Guidelines and Procedures OB 5.1_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..1f2a80d29ec28faa849842dd71f7ad2470b398bf
--- /dev/null
+++ b/20 - Security Governance and Privacy/001 Security Polices, Standards, Guidelines and Procedures OB 5.1_en.srt
@@ -0,0 +1,1200 @@
+1
+00:00:00,000 --> 00:00:06,000
+When it comes to building a good security program and ensuring that you have support from senior management
+
+2
+00:00:06,000 --> 00:00:11,000
+to build programs, that's going to stop threats and protect your asset.
+
+3
+00:00:11,000 --> 00:00:15,000
+It is critical that we have what's called security governance.
+
+4
+00:00:15,000 --> 00:00:20,000
+Now, before I get into all of this great terminologies here, I want to talk about the word governance.
+
+5
+00:00:20,000 --> 00:00:26,000
+You see, in an organization, most people have probably heard of what's called corporate governance.
+
+6
+00:00:26,000 --> 00:00:34,000
+Corporate governance are all the steps that management takes in order to run the business.
+
+7
+00:00:34,000 --> 00:00:38,000
+Corporate governance is about accomplishing the mission of the business.
+
+8
+00:00:38,000 --> 00:00:41,000
+It's about accomplishing goals of the business.
+
+9
+00:00:41,000 --> 00:00:44,000
+So the business has a particular plan.
+
+10
+00:00:44,000 --> 00:00:47,000
+That said, increase revenue by 30% over the next one year.
+
+11
+00:00:47,000 --> 00:00:49,000
+Corporate governance would step in that.
+
+12
+00:00:49,000 --> 00:00:52,000
+Now a subset of corporate governance is IT governance.
+
+13
+00:00:52,000 --> 00:00:55,000
+And then a subset of that is IT security governance.
+
+14
+00:00:55,000 --> 00:01:01,000
+Now in recent years, security governance has started to branch away and just become a standalone thing
+
+15
+00:01:01,000 --> 00:01:07,000
+as security is now not just a function of just pure it, but it's basically has become its own department
+
+16
+00:01:07,000 --> 00:01:08,000
+now.
+
+17
+00:01:08,000 --> 00:01:12,000
+So depending on the structure you you follow in a business security governance, what we're going to
+
+18
+00:01:12,000 --> 00:01:17,000
+be covering could be a standalone thing, or it could be part of an IT department.
+
+19
+00:01:17,000 --> 00:01:22,000
+But keep in mind, whether it's IT or it's security, IT governance or just security governance, they're
+
+20
+00:01:22,000 --> 00:01:26,000
+all going to be a subset of corporate governance.
+
+21
+00:01:26,000 --> 00:01:28,000
+So in this course obviously we're talking about security.
+
+22
+00:01:28,000 --> 00:01:30,000
+So let's stick with security governance.
+
+23
+00:01:31,000 --> 00:01:35,000
+When you think of governance I want you guys to think of what the word manage.
+
+24
+00:01:35,000 --> 00:01:41,000
+It's basically what are we going to be doing or what are we going to be managing in order to accomplish
+
+25
+00:01:41,000 --> 00:01:45,000
+the goal of the IT security or the security department?
+
+26
+00:01:45,000 --> 00:01:52,000
+So it's a collection of practices for supporting, evaluating, defining and directing the security
+
+27
+00:01:52,000 --> 00:01:52,000
+efforts.
+
+28
+00:01:52,000 --> 00:01:54,000
+So what are we doing?
+
+29
+00:01:54,000 --> 00:01:55,000
+What are we going to support the security efforts.
+
+30
+00:01:55,000 --> 00:01:56,000
+We're going to evaluate it.
+
+31
+00:01:56,000 --> 00:01:58,000
+We're going to define it and we're going to direct it.
+
+32
+00:01:58,000 --> 00:02:01,000
+But you got to understand this word.
+
+33
+00:02:01,000 --> 00:02:03,000
+What exactly is security efforts.
+
+34
+00:02:03,000 --> 00:02:10,000
+Security efforts is defined as the activities that we do in the security department to protect our assets.
+
+35
+00:02:10,000 --> 00:02:16,000
+So whether you're configuring a firewall, updating an IDs, install an anti-malware on a computer,
+
+36
+00:02:16,000 --> 00:02:19,000
+those are all considered security efforts.
+
+37
+00:02:19,000 --> 00:02:23,000
+Now, if you have good security governance or good security management, because that's really what
+
+38
+00:02:23,000 --> 00:02:23,000
+this is saying.
+
+39
+00:02:23,000 --> 00:02:28,000
+Security management, if you have good security management, what are what are we going to try to get
+
+40
+00:02:28,000 --> 00:02:28,000
+out of it?
+
+41
+00:02:28,000 --> 00:02:33,000
+Well, these things we're going to try to establish and sustain a culture of security.
+
+42
+00:02:34,000 --> 00:02:39,000
+Within the within the company's culture, we're going to establish and maintain a framework to provide
+
+43
+00:02:39,000 --> 00:02:43,000
+assurance that information security aligns with business objectives.
+
+44
+00:02:43,000 --> 00:02:48,000
+Now, this particular, uh, second bulleted point is the main one.
+
+45
+00:02:49,000 --> 00:02:54,000
+Is security aligned with the company's objectives now?
+
+46
+00:02:55,000 --> 00:02:58,000
+I've always said this about organizations.
+
+47
+00:02:58,000 --> 00:03:00,000
+It is not the organization.
+
+48
+00:03:00,000 --> 00:03:06,000
+It is not the security department to dictate the direction of the business.
+
+49
+00:03:06,000 --> 00:03:09,000
+The direction of the business is dictated by the senior management.
+
+50
+00:03:10,000 --> 00:03:11,000
+I'll give you guys an example.
+
+51
+00:03:11,000 --> 00:03:15,000
+Let's say we go to Penn Station where we catch the Amtrak from New York.
+
+52
+00:03:15,000 --> 00:03:18,000
+The Amtrak is a train that goes all over the country.
+
+53
+00:03:18,000 --> 00:03:24,000
+It is not the security folks that dictates which Amtrak we're going to take.
+
+54
+00:03:24,000 --> 00:03:27,000
+We could take an Amtrak to go north to Boston.
+
+55
+00:03:27,000 --> 00:03:29,000
+We could take one to go to Florida.
+
+56
+00:03:30,000 --> 00:03:32,000
+We can even take one to go to California.
+
+57
+00:03:32,000 --> 00:03:38,000
+That is not the objectives of the actual IT department or the security department.
+
+58
+00:03:38,000 --> 00:03:40,000
+That's senior management.
+
+59
+00:03:40,000 --> 00:03:42,000
+They determined that they want to go to Boston.
+
+60
+00:03:42,000 --> 00:03:45,000
+It's our job to make sure the train don't fall off the track, if you know what I mean.
+
+61
+00:03:45,000 --> 00:03:47,000
+It's our job to make sure people don't fall off the train.
+
+62
+00:03:47,000 --> 00:03:50,000
+It's our job to keep that train on the track and keep it secure.
+
+63
+00:03:50,000 --> 00:03:55,000
+We need to make sure that what we do as security folks is aligned with the business to ensure the business
+
+64
+00:03:55,000 --> 00:04:00,000
+accomplishes its goal safely and within reasonable expenses.
+
+65
+00:04:00,000 --> 00:04:04,000
+We don't want to spend too much money and then go way off of the actual goal.
+
+66
+00:04:05,000 --> 00:04:10,000
+Ensure that security is consistent with the laws and regulations, and there is a lot that we have to
+
+67
+00:04:10,000 --> 00:04:10,000
+follow.
+
+68
+00:04:10,000 --> 00:04:15,000
+We want to assess the emerging threats and provide good security leadership.
+
+69
+00:04:15,000 --> 00:04:19,000
+Now, there are a couple of things here that I need you guys to know.
+
+70
+00:04:20,000 --> 00:04:29,000
+When you're talking security governance, you should develop policies, standards, guidelines and procedures.
+
+71
+00:04:29,000 --> 00:04:36,000
+In this section, I want you guys to know these four terms policies, standards, guidelines and procedures.
+
+72
+00:04:36,000 --> 00:04:44,000
+I'm going to go through these four things and I'll give you some examples of policies or different procedures
+
+73
+00:04:44,000 --> 00:04:44,000
+and so on.
+
+74
+00:04:44,000 --> 00:04:45,000
+So let's take a look.
+
+75
+00:04:46,000 --> 00:04:47,000
+Policies.
+
+76
+00:04:47,000 --> 00:04:49,000
+What exactly are policies?
+
+77
+00:04:49,000 --> 00:04:51,000
+What policies are critical component?
+
+78
+00:04:51,000 --> 00:04:55,000
+They provide a framework for the consistent and secure operations.
+
+79
+00:04:55,000 --> 00:04:56,000
+So what are policies?
+
+80
+00:04:56,000 --> 00:05:02,000
+Policies are basically framework for consistent and secure operations across the entire business.
+
+81
+00:05:02,000 --> 00:05:05,000
+Now in particularly we're talking security policies here.
+
+82
+00:05:06,000 --> 00:05:10,000
+They formed a foundation of how an organization's assets are secure.
+
+83
+00:05:11,000 --> 00:05:17,000
+Effective governance relies on the development, implementation and enforcement of these policies.
+
+84
+00:05:17,000 --> 00:05:21,000
+Now, every business that you work for should have policies in place.
+
+85
+00:05:22,000 --> 00:05:27,000
+Every business that you go and you sign up for during your employment, you probably got that employee
+
+86
+00:05:27,000 --> 00:05:32,000
+handbook that has tons of policies in it, whether it was an acceptable use policy, for example.
+
+87
+00:05:33,000 --> 00:05:37,000
+Uh, most people look at like vacation policies and time off policies, but in this one we really want
+
+88
+00:05:37,000 --> 00:05:39,000
+to look at security policies.
+
+89
+00:05:39,000 --> 00:05:40,000
+If you ask them, well, where do they come from?
+
+90
+00:05:41,000 --> 00:05:49,000
+In a good approach, policies should be developed by management or at least a supporting of the development
+
+91
+00:05:49,000 --> 00:05:50,000
+by management.
+
+92
+00:05:50,000 --> 00:05:56,000
+Policies should be developed using what's called a top down approach, which means policies comes from
+
+93
+00:05:56,000 --> 00:05:56,000
+management.
+
+94
+00:05:57,000 --> 00:05:58,000
+For your exam.
+
+95
+00:05:58,000 --> 00:06:04,000
+And in real life, the most important concept of a policy senior management support.
+
+96
+00:06:04,000 --> 00:06:07,000
+If senior management does not support the policy.
+
+97
+00:06:08,000 --> 00:06:09,000
+No one is going to follow it.
+
+98
+00:06:10,000 --> 00:06:11,000
+No one is going to read it.
+
+99
+00:06:11,000 --> 00:06:12,000
+No one is going to abide by it.
+
+100
+00:06:12,000 --> 00:06:17,000
+If senior management breaks the policy on a consistent basis, trust me, that policy has no way of
+
+101
+00:06:17,000 --> 00:06:19,000
+being being actually implemented.
+
+102
+00:06:20,000 --> 00:06:24,000
+So we want to make sure that the policy is top down, which means that policies comes from management
+
+103
+00:06:24,000 --> 00:06:25,000
+and is pushed down.
+
+104
+00:06:25,000 --> 00:06:30,000
+Policies is management way of telling what they want in the organization.
+
+105
+00:06:31,000 --> 00:06:34,000
+Now, what exactly are some policies?
+
+106
+00:06:34,000 --> 00:06:38,000
+Well, the first one up we have is what's called an acceptable use policy.
+
+107
+00:06:38,000 --> 00:06:43,000
+This defines the acceptable ways in which network or systems should be used.
+
+108
+00:06:43,000 --> 00:06:49,000
+For example, acceptable use policy will say the desktops and the laptops and the mobile phones should
+
+109
+00:06:49,000 --> 00:06:56,000
+only be used when accessing company resources, and no other time they're going to do this for all kinds
+
+110
+00:06:56,000 --> 00:07:00,000
+of things, from whether it's your desktop to your internet usage, like your email should only be used
+
+111
+00:07:00,000 --> 00:07:02,000
+for business purposes.
+
+112
+00:07:02,000 --> 00:07:05,000
+This, of course, is to protect the organization and resources.
+
+113
+00:07:05,000 --> 00:07:09,000
+Another policy is, of course going to be our information security policy.
+
+114
+00:07:09,000 --> 00:07:14,000
+This is now this is a broad range of different guidelines that we're going to be implementing to protect
+
+115
+00:07:14,000 --> 00:07:15,000
+the CIA.
+
+116
+00:07:15,000 --> 00:07:20,000
+It's going to cover things like data classification, access control, cryptography and even physical
+
+117
+00:07:20,000 --> 00:07:21,000
+security.
+
+118
+00:07:22,000 --> 00:07:29,000
+Now business continuity and disaster recovery policies now understand what business continuity is.
+
+119
+00:07:30,000 --> 00:07:34,000
+Business continuity is what we're going to do.
+
+120
+00:07:34,000 --> 00:07:38,000
+All right is what we're going to do after there is a disaster.
+
+121
+00:07:38,000 --> 00:07:40,000
+How do we continue to function?
+
+122
+00:07:40,000 --> 00:07:42,000
+How do we continue to function?
+
+123
+00:07:42,000 --> 00:07:49,000
+Uh, if there is a disaster such as a data center falling out, this includes essential functions during
+
+124
+00:07:49,000 --> 00:07:51,000
+and after a major disruption.
+
+125
+00:07:51,000 --> 00:07:56,000
+So let's say a major disaster has occurred.
+
+126
+00:07:56,000 --> 00:07:58,000
+One of the data centers is down.
+
+127
+00:07:58,000 --> 00:08:00,000
+50% of the business is not functioning.
+
+128
+00:08:00,000 --> 00:08:05,000
+What is your organization going to do while that data center is being rebuilt?
+
+129
+00:08:05,000 --> 00:08:07,000
+So that's business continuity.
+
+130
+00:08:07,000 --> 00:08:09,000
+The other one is called disaster recovery.
+
+131
+00:08:09,000 --> 00:08:12,000
+Disaster recovery is what you do to recover from the disaster.
+
+132
+00:08:12,000 --> 00:08:15,000
+So the data center dropped okay.
+
+133
+00:08:15,000 --> 00:08:20,000
+The business continuity was moved all of the processing to the cloud.
+
+134
+00:08:20,000 --> 00:08:25,000
+Now we have to repair that data center that that actually blew up like kind of like this picture.
+
+135
+00:08:26,000 --> 00:08:31,000
+But that's going to include things like data backup recover and systems knowing what roles and responsibilities
+
+136
+00:08:31,000 --> 00:08:32,000
+and who to do what.
+
+137
+00:08:32,000 --> 00:08:34,000
+So that's disaster recovery.
+
+138
+00:08:34,000 --> 00:08:39,000
+How do we recover from that particular disaster incident response policy?
+
+139
+00:08:39,000 --> 00:08:44,000
+Earlier in the course, we talked about an incident response plan or steps that you should know for
+
+140
+00:08:44,000 --> 00:08:45,000
+your exam.
+
+141
+00:08:45,000 --> 00:08:50,000
+Now, we want to have a policy in place that provides a structured approach for managing all kinds of
+
+142
+00:08:50,000 --> 00:08:53,000
+incidents and breaches, such as defining roles.
+
+143
+00:08:53,000 --> 00:08:57,000
+We talked about the processes that they want you to know and the communication strategy.
+
+144
+00:08:57,000 --> 00:09:03,000
+We want to minimize the impact of all of those particular security incidents.
+
+145
+00:09:03,000 --> 00:09:06,000
+Software development, life cycle policy.
+
+146
+00:09:06,000 --> 00:09:06,000
+What is this?
+
+147
+00:09:06,000 --> 00:09:13,000
+Well, most organizations, especially big organizations, are going to be developing their own software.
+
+148
+00:09:13,000 --> 00:09:17,000
+And if they're developing, deploying and maintaining their software, they have to have a policy that
+
+149
+00:09:17,000 --> 00:09:20,000
+states, how are they going to be doing these particular things?
+
+150
+00:09:20,000 --> 00:09:25,000
+What is management expected for when it comes to developing and deploying and maintaining their own
+
+151
+00:09:25,000 --> 00:09:25,000
+software?
+
+152
+00:09:25,000 --> 00:09:30,000
+What's the security in every stage of the software development life cycle?
+
+153
+00:09:31,000 --> 00:09:34,000
+Change will happen in every business.
+
+154
+00:09:34,000 --> 00:09:38,000
+We need a policy that dictates how are we going to be doing changes right?
+
+155
+00:09:38,000 --> 00:09:41,000
+What is critical about change management?
+
+156
+00:09:41,000 --> 00:09:46,000
+Well, you see, when it comes to change management, lots of errors can go wrong.
+
+157
+00:09:46,000 --> 00:09:50,000
+If there's one thing that we know is when something breaks in it, the first thing people say is, hey,
+
+158
+00:09:50,000 --> 00:09:51,000
+who changed what?
+
+159
+00:09:51,000 --> 00:09:57,000
+So we need a good procedures to make sure that changes are evaluated, approved and documented.
+
+160
+00:09:57,000 --> 00:10:02,000
+We don't want people just going and making unauthorized modification because they feel something needs
+
+161
+00:10:02,000 --> 00:10:03,000
+to change in a system.
+
+162
+00:10:04,000 --> 00:10:06,000
+So those were policies.
+
+163
+00:10:07,000 --> 00:10:10,000
+Under under policy, something a little bit more detail.
+
+164
+00:10:10,000 --> 00:10:11,000
+It's going to be a standard.
+
+165
+00:10:12,000 --> 00:10:19,000
+Standards are established benchmarks or sets of criteria against which security generally are measured
+
+166
+00:10:19,000 --> 00:10:20,000
+and designed.
+
+167
+00:10:20,000 --> 00:10:24,000
+They guide organizations in implementing the policies.
+
+168
+00:10:24,000 --> 00:10:29,000
+So while a policy is generally going to be more high level, a standard is going to be something much
+
+169
+00:10:29,000 --> 00:10:30,000
+more specific.
+
+170
+00:10:30,000 --> 00:10:33,000
+Let me give you a couple of examples of standards, like a password standard.
+
+171
+00:10:33,000 --> 00:10:38,000
+Password standards define the criteria for creating and for example managing passwords.
+
+172
+00:10:38,000 --> 00:10:42,000
+So your organization should have a password standard like what are the standards for passwords that
+
+173
+00:10:42,000 --> 00:10:43,000
+you guys follow.
+
+174
+00:10:43,000 --> 00:10:45,000
+What is the length that you guys.
+
+175
+00:10:45,000 --> 00:10:46,000
+Some people do eight, some people do ten.
+
+176
+00:10:47,000 --> 00:10:50,000
+The what's the complexity requirement?
+
+177
+00:10:50,000 --> 00:10:53,000
+How frequently does your company want to change passwords?
+
+178
+00:10:53,000 --> 00:10:55,000
+Access control standards.
+
+179
+00:10:55,000 --> 00:10:59,000
+How do you guys in your organization or the companies that you're going to work for?
+
+180
+00:10:59,000 --> 00:11:04,000
+How are you guys going to give access to the information systems and the data on them?
+
+181
+00:11:04,000 --> 00:11:12,000
+Is there a particular, uh, set of procedures or I should say, step by step things of doing this?
+
+182
+00:11:12,000 --> 00:11:14,000
+The standards can help dictate this.
+
+183
+00:11:14,000 --> 00:11:20,000
+So they're going to be guidelines for user authentication authentication, authorization levels.
+
+184
+00:11:20,000 --> 00:11:26,000
+These standards ensure that users have only the necessary resources, access to the necessary resources
+
+185
+00:11:26,000 --> 00:11:28,000
+they need to get their job done.
+
+186
+00:11:28,000 --> 00:11:34,000
+Physical security standards what standards do you guys follow to physically secure physical assets such
+
+187
+00:11:34,000 --> 00:11:39,000
+as tables, chairs, furniture, fixtures, computers, laptops, servers, and so on?
+
+188
+00:11:39,000 --> 00:11:45,000
+Address the protection of hardware, software, network and data from physical events.
+
+189
+00:11:45,000 --> 00:11:50,000
+This is going to include standards for securing our facilities, controlling physical access.
+
+190
+00:11:50,000 --> 00:11:54,000
+In the physical security section, we talked about all the different things we can do to physically
+
+191
+00:11:54,000 --> 00:11:55,000
+secure our network.
+
+192
+00:11:55,000 --> 00:11:58,000
+These are the standards that we're going to follow to do those things.
+
+193
+00:12:00,000 --> 00:12:01,000
+Encryption standards.
+
+194
+00:12:01,000 --> 00:12:06,000
+Every organization needs to follow some kind of standard when it comes to encryption.
+
+195
+00:12:06,000 --> 00:12:11,000
+For example, what bit strength, what algorithm do we want to use when it comes to securing our data.
+
+196
+00:12:11,000 --> 00:12:15,000
+So this is going to outline the requirements for encrypting data.
+
+197
+00:12:15,000 --> 00:12:19,000
+Remember encryption is data at rest and data in transit.
+
+198
+00:12:19,000 --> 00:12:22,000
+The coveted use of encryption algorithms key management and encryption protocols.
+
+199
+00:12:23,000 --> 00:12:25,000
+Now what are guidelines?
+
+200
+00:12:25,000 --> 00:12:28,000
+Guidelines are all throughout the industry.
+
+201
+00:12:28,000 --> 00:12:32,000
+Guidelines are best practices and cybersecurity.
+
+202
+00:12:32,000 --> 00:12:37,000
+Essential sets of recommendations and best practices that help shapes the organization posture.
+
+203
+00:12:37,000 --> 00:12:43,000
+They provide the roadmap for organizations in developing, implementing, and maintaining robust security
+
+204
+00:12:43,000 --> 00:12:43,000
+practices.
+
+205
+00:12:43,000 --> 00:12:44,000
+So.
+
+206
+00:12:45,000 --> 00:12:48,000
+How does guidelines influence standard standards you see?
+
+207
+00:12:48,000 --> 00:12:50,000
+Guidelines are best practices.
+
+208
+00:12:50,000 --> 00:12:55,000
+Basically, the industry said that we should have ten characters.
+
+209
+00:12:55,000 --> 00:12:56,000
+Let's say that's the new guideline.
+
+210
+00:12:57,000 --> 00:13:02,000
+Then your standard is going to say, well, we have ten character passwords, so where are we pulling
+
+211
+00:13:02,000 --> 00:13:03,000
+those standards from?
+
+212
+00:13:03,000 --> 00:13:04,000
+Where are we getting those standards from?
+
+213
+00:13:04,000 --> 00:13:06,000
+Generally from the guidelines.
+
+214
+00:13:06,000 --> 00:13:10,000
+Now we can't forget about what's called procedures.
+
+215
+00:13:10,000 --> 00:13:11,000
+So what are procedures?
+
+216
+00:13:11,000 --> 00:13:19,000
+Well, in the world of cybersecurity, governance procedures are the most detailed operational level
+
+217
+00:13:19,000 --> 00:13:22,000
+instructions that guide listen carefully day to day activities.
+
+218
+00:13:22,000 --> 00:13:31,000
+They are the actionable step by step, uh, they're basically the step by steps that operationalize
+
+219
+00:13:31,000 --> 00:13:32,000
+security policy standards.
+
+220
+00:13:32,000 --> 00:13:34,000
+Insurance security governance is implemented.
+
+221
+00:13:35,000 --> 00:13:39,000
+How do we implement that policy?
+
+222
+00:13:40,000 --> 00:13:44,000
+Well, review the standard to see the specifics of the policy.
+
+223
+00:13:44,000 --> 00:13:47,000
+Well, how do we how do we get that standard done?
+
+224
+00:13:47,000 --> 00:13:49,000
+Well, the procedures is it.
+
+225
+00:13:49,000 --> 00:13:50,000
+Let me give you an example.
+
+226
+00:13:50,000 --> 00:13:54,000
+So senior management I'm going to give you an example of a policy.
+
+227
+00:13:55,000 --> 00:13:57,000
+Uh, a policy, a standard.
+
+228
+00:13:58,000 --> 00:14:00,000
+A guideline and a procedure.
+
+229
+00:14:00,000 --> 00:14:01,000
+All for.
+
+230
+00:14:01,000 --> 00:14:02,000
+Let me use an example.
+
+231
+00:14:02,000 --> 00:14:04,000
+So senior management is going to write.
+
+232
+00:14:04,000 --> 00:14:06,000
+They're going to create a pass.
+
+233
+00:14:06,000 --> 00:14:08,000
+They're going to create an authentication policy.
+
+234
+00:14:08,000 --> 00:14:11,000
+The policy is going to be very generic because policies are high level.
+
+235
+00:14:11,000 --> 00:14:17,000
+They're going to say that all logins to the computers should be secured.
+
+236
+00:14:17,000 --> 00:14:19,000
+That's really it's going to say it's not going to go much.
+
+237
+00:14:19,000 --> 00:14:21,000
+It shouldn't be very detailed.
+
+238
+00:14:21,000 --> 00:14:26,000
+Now they're going to review the guidelines and say, well, in order to have secure logins they need
+
+239
+00:14:26,000 --> 00:14:28,000
+passwords with ten characters.
+
+240
+00:14:28,000 --> 00:14:30,000
+So the standard is going to come out.
+
+241
+00:14:30,000 --> 00:14:31,000
+The standard is going to be written.
+
+242
+00:14:31,000 --> 00:14:35,000
+The password standard is going to say ten characters change every 60 days.
+
+243
+00:14:36,000 --> 00:14:37,000
+But what's the procedure?
+
+244
+00:14:37,000 --> 00:14:40,000
+The procedure is how do we implement that?
+
+245
+00:14:40,000 --> 00:14:45,000
+What are we going to do to implement this secure authentication policy?
+
+246
+00:14:45,000 --> 00:14:51,000
+Well, the procedure is going to say something that goes like, well, go to Windows Server, go to
+
+247
+00:14:51,000 --> 00:14:53,000
+a Windows Server, that's a domain controller.
+
+248
+00:14:53,000 --> 00:14:55,000
+Click on the windows button.
+
+249
+00:14:55,000 --> 00:15:02,000
+Open up server manager, go to Active Directory users and computers and then administer the domain.
+
+250
+00:15:02,000 --> 00:15:06,000
+Change the domain policy to up to ten characters because by default it's eight.
+
+251
+00:15:06,000 --> 00:15:08,000
+Notice this is a step by step thing.
+
+252
+00:15:08,000 --> 00:15:14,000
+This is where you're clicking to implement that particular thing that gives you your policy.
+
+253
+00:15:14,000 --> 00:15:21,000
+Now you should have procedures for many things within your organization, not just one.
+
+254
+00:15:22,000 --> 00:15:26,000
+You can't implement a policy without a procedure.
+
+255
+00:15:26,000 --> 00:15:31,000
+The procedure is the step by step actions to implement that particular policy.
+
+256
+00:15:31,000 --> 00:15:33,000
+So something like change management procedures.
+
+257
+00:15:33,000 --> 00:15:34,000
+What is this.
+
+258
+00:15:34,000 --> 00:15:39,000
+Well these are procedures are critical to ensuring all IT system stays secure.
+
+259
+00:15:39,000 --> 00:15:40,000
+Why.
+
+260
+00:15:40,000 --> 00:15:44,000
+Because you see we need a step by step.
+
+261
+00:15:44,000 --> 00:15:46,000
+How do we request a change.
+
+262
+00:15:46,000 --> 00:15:48,000
+How do we review a change.
+
+263
+00:15:48,000 --> 00:15:49,000
+How do we approve a change.
+
+264
+00:15:49,000 --> 00:15:50,000
+How do we implement the change.
+
+265
+00:15:50,000 --> 00:15:52,000
+How do we document a change.
+
+266
+00:15:52,000 --> 00:15:56,000
+This is going to be a systematic way to manage changes.
+
+267
+00:15:57,000 --> 00:16:07,000
+What is the step by step actions we need to onboard people into the business and release people from
+
+268
+00:16:07,000 --> 00:16:07,000
+the business.
+
+269
+00:16:08,000 --> 00:16:10,000
+What is the steps for when we get a new employee?
+
+270
+00:16:10,000 --> 00:16:12,000
+How do we prove their identity?
+
+271
+00:16:12,000 --> 00:16:14,000
+How do we create that user account?
+
+272
+00:16:14,000 --> 00:16:16,000
+How do we add it to the group?
+
+273
+00:16:16,000 --> 00:16:18,000
+How do we ensure that they get the right access?
+
+274
+00:16:18,000 --> 00:16:21,000
+That's going to be onboarding when they're terminated?
+
+275
+00:16:21,000 --> 00:16:23,000
+What exactly are those steps?
+
+276
+00:16:23,000 --> 00:16:28,000
+How do we remove access to systems and data that they had access to?
+
+277
+00:16:29,000 --> 00:16:36,000
+Now playbook playbook is important in the world of IT security incidents.
+
+278
+00:16:36,000 --> 00:16:37,000
+You have to have a playbook.
+
+279
+00:16:37,000 --> 00:16:41,000
+When there is an incident, you basically play the book.
+
+280
+00:16:41,000 --> 00:16:46,000
+In other words, you open up a book that's going to have a bunch of procedures that you need to follow
+
+281
+00:16:46,000 --> 00:16:48,000
+when there is this incident.
+
+282
+00:16:48,000 --> 00:16:54,000
+So a playbook is a set of procedures that detail the steps to be taken in response to a particular incident.
+
+283
+00:16:54,000 --> 00:16:57,000
+So the moment there is an incident, we're going to basically run the playbook.
+
+284
+00:16:57,000 --> 00:17:03,000
+The playbook is going to give us all the steps we should be taking when managing that particular incident.
+
+285
+00:17:03,000 --> 00:17:04,000
+Security incident.
+
+286
+00:17:04,000 --> 00:17:09,000
+There's basically it's basically a predefined set of actions to follow, basically ensuring that consistent
+
+287
+00:17:09,000 --> 00:17:14,000
+and effective response to these particular incident, they cover a wide range of scenarios from data
+
+288
+00:17:14,000 --> 00:17:16,000
+breaches all the way to DDoS attack.
+
+289
+00:17:16,000 --> 00:17:17,000
+Okay.
+
+290
+00:17:17,000 --> 00:17:22,000
+Very important in this particular video, what was security governance?
+
+291
+00:17:22,000 --> 00:17:29,000
+Security governance is basically the management of all of IT security to keep our assets secure and
+
+292
+00:17:29,000 --> 00:17:35,000
+to ensure we align the security actions with business objectives.
+
+293
+00:17:35,000 --> 00:17:41,000
+When we're managing or when we are implementing security governance, we need to make sure we have policies
+
+294
+00:17:41,000 --> 00:17:42,000
+that are top down.
+
+295
+00:17:42,000 --> 00:17:47,000
+They're coming from senior management policies, are high level documents that implements the wishes
+
+296
+00:17:47,000 --> 00:17:49,000
+or desires of senior management.
+
+297
+00:17:49,000 --> 00:17:51,000
+Underneath that, you can have a standard.
+
+298
+00:17:52,000 --> 00:17:57,000
+Standards are basically more detailed information about those particular policies.
+
+299
+00:17:57,000 --> 00:18:02,000
+Where are we going to get a lot of the standards from guidelines or best practices in the industry,
+
+300
+00:18:02,000 --> 00:18:08,000
+and the step by step things or actions we need to implement those policies are in the procedures.
+
diff --git a/20 - Security Governance and Privacy/002 Security Governance Considerations and Revisions OB 5.1_en.srt b/20 - Security Governance and Privacy/002 Security Governance Considerations and Revisions OB 5.1_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..01731c1d52a0183abfe3622b837535e6324f2acf
--- /dev/null
+++ b/20 - Security Governance and Privacy/002 Security Governance Considerations and Revisions OB 5.1_en.srt
@@ -0,0 +1,332 @@
+1
+00:00:00,000 --> 00:00:06,000
+When you are developing a good security governance program and making all of your standards, guidelines,
+
+2
+00:00:06,000 --> 00:00:11,000
+procedures and policies, there's a couple of things to think about and that's going to be external
+
+3
+00:00:11,000 --> 00:00:17,000
+considerations, things external to your business that's going to influence the development of those
+
+4
+00:00:17,000 --> 00:00:18,000
+particular documents.
+
+5
+00:00:18,000 --> 00:00:20,000
+So let's get started with this.
+
+6
+00:00:21,000 --> 00:00:22,000
+Things that you should consider?
+
+7
+00:00:22,000 --> 00:00:23,000
+I should say so.
+
+8
+00:00:23,000 --> 00:00:29,000
+These considerations is going to shape and often mandate aspects of security governance making them
+
+9
+00:00:29,000 --> 00:00:30,000
+critical.
+
+10
+00:00:30,000 --> 00:00:35,000
+Right now every organization is generally different in the way they're structured.
+
+11
+00:00:35,000 --> 00:00:40,000
+But if you are in a particular industry, for example, there's going to be specific laws that you're
+
+12
+00:00:40,000 --> 00:00:41,000
+going to be following.
+
+13
+00:00:41,000 --> 00:00:47,000
+So this is going to highlight the need for organization to be aware of and compliant with diverse range
+
+14
+00:00:47,000 --> 00:00:54,000
+of external factors such as legal and regulatory, technological, society changes, industry changes
+
+15
+00:00:54,000 --> 00:00:56,000
+or industry consideration.
+
+16
+00:00:56,000 --> 00:00:59,000
+Let's take a look at a few of these considerations.
+
+17
+00:00:59,000 --> 00:01:04,000
+The first thing up is going to be national regulatory and legal consideration.
+
+18
+00:01:04,000 --> 00:01:10,000
+Any time an organization builds a security governance program, keep in mind that all the different
+
+19
+00:01:10,000 --> 00:01:14,000
+laws and regulations that that company is going to have to follow.
+
+20
+00:01:14,000 --> 00:01:20,000
+For example, if the organization is located or does business in the European Union, they're going
+
+21
+00:01:20,000 --> 00:01:26,000
+to have to protect the privacy of your European Union citizens or EU citizens with GDPR.
+
+22
+00:01:27,000 --> 00:01:31,000
+Now, if you're in the United States and you're managing health records, you're going to have to follow
+
+23
+00:01:31,000 --> 00:01:32,000
+HIPAA.
+
+24
+00:01:32,000 --> 00:01:37,000
+If you are in the United States, you're managing credit card information, you're collecting credit
+
+25
+00:01:37,000 --> 00:01:37,000
+cards.
+
+26
+00:01:37,000 --> 00:01:41,000
+You're going to have to secure that using the PCI standard.
+
+27
+00:01:41,000 --> 00:01:46,000
+So these are some of the regulatory and regulations that you have to consider.
+
+28
+00:01:46,000 --> 00:01:50,000
+Now the other thing is that just don't think about things.
+
+29
+00:01:50,000 --> 00:01:56,000
+All the different regulatory laws that are like national, but they might be local or regional considerations
+
+30
+00:01:56,000 --> 00:01:58,000
+that you may have to follow.
+
+31
+00:01:58,000 --> 00:02:03,000
+Laws can be can affect an organization's security governance, for example, local governance law.
+
+32
+00:02:03,000 --> 00:02:06,000
+Maybe you doing physical security and the local.
+
+33
+00:02:07,000 --> 00:02:13,000
+Uh, city that you're in has laws on how structures has to be built, how much entries they have to
+
+34
+00:02:13,000 --> 00:02:15,000
+have, where cameras can be placed, and so on.
+
+35
+00:02:15,000 --> 00:02:21,000
+So this is state or other regional laws that you may have to be familiar with.
+
+36
+00:02:21,000 --> 00:02:23,000
+Another thing is going to be global consideration.
+
+37
+00:02:23,000 --> 00:02:30,000
+Now if your organization is a global entity there's a lot of things to think about.
+
+38
+00:02:31,000 --> 00:02:37,000
+Now this is going to include understanding and compliant with cybersecurity laws and regulations of
+
+39
+00:02:37,000 --> 00:02:38,000
+all the countries that you operate.
+
+40
+00:02:38,000 --> 00:02:44,000
+So if you're a global business and you take money from all of the countries in the world, be prepared
+
+41
+00:02:44,000 --> 00:02:49,000
+to manage a massive legal department, because now you have to know all the laws and regulations and
+
+42
+00:02:49,000 --> 00:02:52,000
+protecting the users data, following the laws that they're in.
+
+43
+00:02:53,000 --> 00:02:56,000
+So this of course could be very large scale.
+
+44
+00:02:56,000 --> 00:03:00,000
+Global consideration also involves dealing with cross border data transfer.
+
+45
+00:03:00,000 --> 00:03:05,000
+If you're collecting data on the EU citizens and you transfer and store in the United States, what
+
+46
+00:03:05,000 --> 00:03:06,000
+laws do you have to follow?
+
+47
+00:03:06,000 --> 00:03:08,000
+Industry considerations.
+
+48
+00:03:08,000 --> 00:03:11,000
+Different industries have unique cybersecurity challenges.
+
+49
+00:03:11,000 --> 00:03:13,000
+I give you guys a good example.
+
+50
+00:03:13,000 --> 00:03:15,000
+It's the cyber financial sector.
+
+51
+00:03:16,000 --> 00:03:23,000
+They might have some of the most stringent requirements because they carry some of the most the most
+
+52
+00:03:23,000 --> 00:03:27,000
+open data or the most confidential data, because they have all your credit card information, all your
+
+53
+00:03:27,000 --> 00:03:28,000
+banking information.
+
+54
+00:03:28,000 --> 00:03:31,000
+Another industry is going to be things like health care information.
+
+55
+00:03:31,000 --> 00:03:37,000
+So just because you're in that industry, be prepared for more cyber attacks than someone that's not.
+
+56
+00:03:37,000 --> 00:03:43,000
+So they're going to have a lot of stringent requirements when it comes to data encryption, for example,
+
+57
+00:03:43,000 --> 00:03:45,000
+in transaction security.
+
+58
+00:03:46,000 --> 00:03:54,000
+All right, so when you're making your, um, your policies, your procedures, you're creating that
+
+59
+00:03:54,000 --> 00:03:58,000
+entire program, you have to keep in mind all of these considerations.
+
+60
+00:03:58,000 --> 00:03:59,000
+Now.
+
+61
+00:04:00,000 --> 00:04:04,000
+I want you guys to keep in mind that it's not just.
+
+62
+00:04:05,000 --> 00:04:10,000
+Making all these policies and procedures and being familiar with some of these things, like laws and
+
+63
+00:04:10,000 --> 00:04:12,000
+regulations that you have to follow.
+
+64
+00:04:13,000 --> 00:04:20,000
+A good security governance program will need to be consistently updated, changed and revised.
+
+65
+00:04:20,000 --> 00:04:27,000
+And that's this last thing here that I want to just briefly mention and something that you should always
+
+66
+00:04:27,000 --> 00:04:27,000
+understand.
+
+67
+00:04:27,000 --> 00:04:35,000
+The world changes, laws changes, technology changes, people change, management change, CEO change.
+
+68
+00:04:35,000 --> 00:04:37,000
+Things change all the time.
+
+69
+00:04:38,000 --> 00:04:40,000
+So what is what are we going to be doing?
+
+70
+00:04:40,000 --> 00:04:45,000
+Well, keep in mind that those policies and procedures from yesterday may not be valid today.
+
+71
+00:04:45,000 --> 00:04:52,000
+So this involves understanding the ongoing process of overseeing security operations and making adjustment
+
+72
+00:04:52,000 --> 00:04:53,000
+keyword.
+
+73
+00:04:53,000 --> 00:04:57,000
+Make an adjustment because it's not just monitoring and keeping an eye on it.
+
+74
+00:04:57,000 --> 00:05:00,000
+It's about revising it for the current times.
+
+75
+00:05:00,000 --> 00:05:05,000
+As threats get more technical, threats becomes more difficult.
+
+76
+00:05:05,000 --> 00:05:08,000
+The program has to evolve to match the threats.
+
+77
+00:05:08,000 --> 00:05:09,000
+Security.
+
+78
+00:05:09,000 --> 00:05:15,000
+Governance requires not only the implementation of a good security measures, but also ongoing evaluation
+
+79
+00:05:15,000 --> 00:05:17,000
+and adapt to security changes.
+
+80
+00:05:18,000 --> 00:05:22,000
+All right, don't think that just creating a security program is just about making a few policies and
+
+81
+00:05:22,000 --> 00:05:22,000
+putting them in place.
+
+82
+00:05:22,000 --> 00:05:28,000
+No, it's about considering all the things that can affect those policies and consider how the environment
+
+83
+00:05:28,000 --> 00:05:32,000
+is consistently changed so you can keep it updated.
+
diff --git a/20 - Security Governance and Privacy/003 Security Governance Structures OB 5.1_en.srt b/20 - Security Governance and Privacy/003 Security Governance Structures OB 5.1_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..8b0f338c3e2cdf62c2195e17b29242251569fcd5
--- /dev/null
+++ b/20 - Security Governance and Privacy/003 Security Governance Structures OB 5.1_en.srt
@@ -0,0 +1,400 @@
+1
+00:00:00,000 --> 00:00:06,000
+When it comes to building a good security governance program, be prepared to deal with a lot of different
+
+2
+00:00:06,000 --> 00:00:11,000
+folks from different levels of the organization also outside the organization.
+
+3
+00:00:11,000 --> 00:00:16,000
+So let's take a look at some of these different governance structures that you're basically going to
+
+4
+00:00:16,000 --> 00:00:17,000
+be dealing with.
+
+5
+00:00:17,000 --> 00:00:19,000
+These structures have different sais.
+
+6
+00:00:19,000 --> 00:00:24,000
+They also have different opinions or different leverage over your governance program.
+
+7
+00:00:24,000 --> 00:00:30,000
+For example, government entities that sets regulations have a big part or a big say in your governance
+
+8
+00:00:30,000 --> 00:00:33,000
+program because you have to meet their laws.
+
+9
+00:00:33,000 --> 00:00:35,000
+While the board may dictate where we're going with this.
+
+10
+00:00:35,000 --> 00:00:39,000
+So let's go through these five basic entities here.
+
+11
+00:00:39,000 --> 00:00:40,000
+The first one that we want to mention is the board.
+
+12
+00:00:40,000 --> 00:00:47,000
+So when you're working in an organization, the top, top, top of the organization is the board of
+
+13
+00:00:47,000 --> 00:00:47,000
+directors.
+
+14
+00:00:47,000 --> 00:00:53,000
+The board of directors generally hires the CEO, who then hires almost all the staff underneath that,
+
+15
+00:00:53,000 --> 00:00:55,000
+underneath that person.
+
+16
+00:00:55,000 --> 00:00:56,000
+So board of directors are a similar.
+
+17
+00:00:56,000 --> 00:01:00,000
+Governance has the ultimate responsibility for cybersecurity governance.
+
+18
+00:01:00,000 --> 00:01:01,000
+Now you're probably saying.
+
+19
+00:01:02,000 --> 00:01:03,000
+Hmm.
+
+20
+00:01:04,000 --> 00:01:05,000
+They have the responsibility.
+
+21
+00:01:05,000 --> 00:01:06,000
+Yes.
+
+22
+00:01:06,000 --> 00:01:13,000
+I want you guys to remember, the senior management has the ultimate responsibility for security in
+
+23
+00:01:13,000 --> 00:01:14,000
+an organization.
+
+24
+00:01:14,000 --> 00:01:19,000
+You see, senior management sets the tone for security in the business.
+
+25
+00:01:19,000 --> 00:01:23,000
+When there are security breaches and security hacks, who takes the brunt of the blame?
+
+26
+00:01:23,000 --> 00:01:24,000
+Senior management.
+
+27
+00:01:24,000 --> 00:01:27,000
+And they don't get more senior than the board.
+
+28
+00:01:27,000 --> 00:01:33,000
+The board sets the tone at the top, establishes strategic priorities and ensure that cyber risks are
+
+29
+00:01:33,000 --> 00:01:35,000
+adequately covered in the overall organization.
+
+30
+00:01:35,000 --> 00:01:36,000
+Risk management.
+
+31
+00:01:36,000 --> 00:01:39,000
+I want you guys to remember something for your exam senior management.
+
+32
+00:01:40,000 --> 00:01:46,000
+Such as the board will support, will help to fund security activities.
+
+33
+00:01:46,000 --> 00:01:50,000
+They're going to support the creation of things like policies, but they don't actually do it.
+
+34
+00:01:50,000 --> 00:01:56,000
+If you ever see a question on your exam, such as senior management, editing policy, change in policies
+
+35
+00:01:56,000 --> 00:01:58,000
+or conduct an assessment, they don't do that.
+
+36
+00:01:58,000 --> 00:02:05,000
+The big job of the board or senior management is going to be to support the security governance program.
+
+37
+00:02:05,000 --> 00:02:10,000
+Remember something if they don't support it and the program is never implemented and the company's hacked,
+
+38
+00:02:10,000 --> 00:02:12,000
+they're going to take the brunt of that blame.
+
+39
+00:02:12,000 --> 00:02:16,000
+So remember who's ultimately responsible for security in a business exam.
+
+40
+00:02:16,000 --> 00:02:19,000
+Senior management.
+
+41
+00:02:19,000 --> 00:02:24,000
+Now within a business you're going to have different types of committees that are out there.
+
+42
+00:02:24,000 --> 00:02:31,000
+Cybersecurity committees often compromises of cross-functional members from various departments.
+
+43
+00:02:31,000 --> 00:02:32,000
+This include.
+
+44
+00:02:33,000 --> 00:02:38,000
+These may include cybersecurity steering committee A steering committee basically dictates the direction
+
+45
+00:02:39,000 --> 00:02:40,000
+of somebody's steering a car.
+
+46
+00:02:40,000 --> 00:02:44,000
+They're basically going to set the tone of where we want to go, what technology we should be using,
+
+47
+00:02:44,000 --> 00:02:49,000
+what actions or steps we should be taking to keep our system secure.
+
+48
+00:02:49,000 --> 00:02:50,000
+IT risk commuter.
+
+49
+00:02:50,000 --> 00:02:55,000
+Even Data Privacy Committee committees have one or more specialization and responsible for seeing the
+
+50
+00:02:55,000 --> 00:02:58,000
+implementation of things such as policies.
+
+51
+00:02:58,000 --> 00:03:03,000
+Keep in mind there's all going to be all kinds of different committees within the business, and committees
+
+52
+00:03:03,000 --> 00:03:05,000
+should never be made up of just one set of folks.
+
+53
+00:03:05,000 --> 00:03:11,000
+For example, the cybersecurity steering committee should just, you know, it shouldn't just be, uh,
+
+54
+00:03:11,000 --> 00:03:13,000
+IT security folks.
+
+55
+00:03:13,000 --> 00:03:16,000
+How would a cyber breach affect the accounting department?
+
+56
+00:03:16,000 --> 00:03:17,000
+Well, I don't know.
+
+57
+00:03:17,000 --> 00:03:18,000
+I don't work in accounting.
+
+58
+00:03:18,000 --> 00:03:21,000
+Maybe we should have an accounting person on this committee.
+
+59
+00:03:21,000 --> 00:03:22,000
+See what I mean?
+
+60
+00:03:22,000 --> 00:03:26,000
+You want to make sure your committee has a diverse set of folks?
+
+61
+00:03:26,000 --> 00:03:30,000
+Well, not not much to say here except government entities.
+
+62
+00:03:30,000 --> 00:03:35,000
+When you're developing any kind of security governance program, you better be prepared to deal with
+
+63
+00:03:35,000 --> 00:03:41,000
+a lot of government regulators, especially if you work in certain industries like the financial sector,
+
+64
+00:03:41,000 --> 00:03:43,000
+health care sector.
+
+65
+00:03:44,000 --> 00:03:49,000
+So government entities and regulatory bodies will play a critical role in your governance program,
+
+66
+00:03:49,000 --> 00:03:54,000
+because they're going to define all the legal and regulatory frameworks that you better follow or you
+
+67
+00:03:54,000 --> 00:03:55,000
+have to follow.
+
+68
+00:03:55,000 --> 00:03:56,000
+All right.
+
+69
+00:03:56,000 --> 00:03:59,000
+These entities set standards and regulations such as GDPR.
+
+70
+00:03:59,000 --> 00:04:05,000
+Now centralized governance versus decentralized governance.
+
+71
+00:04:05,000 --> 00:04:07,000
+This is going to be up to your business.
+
+72
+00:04:07,000 --> 00:04:11,000
+So a centralized not government I'm talking governance.
+
+73
+00:04:11,000 --> 00:04:18,000
+So governance in a centralized governance structures, cybersecurity policies and decision making are
+
+74
+00:04:18,000 --> 00:04:22,000
+consolidated with one central entity or generally group.
+
+75
+00:04:22,000 --> 00:04:28,000
+This is usually under under the leadership of the CIO or the CISO.
+
+76
+00:04:29,000 --> 00:04:35,000
+Now if the organization has a CIO underneath the CIO chief information officer, you might have a CISO
+
+77
+00:04:35,000 --> 00:04:37,000
+or the IT director.
+
+78
+00:04:37,000 --> 00:04:38,000
+It depends on how the company is.
+
+79
+00:04:38,000 --> 00:04:41,000
+Sometimes this is the, uh, work of the CIO.
+
+80
+00:04:41,000 --> 00:04:43,000
+Also, it depends how the company is structured.
+
+81
+00:04:43,000 --> 00:04:49,000
+Centralized governance is good because it allows for uniform, in other words, pretty standard policies
+
+82
+00:04:49,000 --> 00:04:56,000
+and enforcement across the business now versus a decentralized governance structure.
+
+83
+00:04:56,000 --> 00:05:00,000
+Cybersecurity governance are distributed to various departments or even units.
+
+84
+00:05:00,000 --> 00:05:06,000
+So every unit or department may have their own um, IT steering committee.
+
+85
+00:05:06,000 --> 00:05:10,000
+They may have their own way of managing security or governance programs.
+
+86
+00:05:11,000 --> 00:05:19,000
+Um, this makes it greater specialization and may even align more with those departments and their security
+
+87
+00:05:19,000 --> 00:05:19,000
+needs.
+
+88
+00:05:19,000 --> 00:05:25,000
+Because if you think about it, if you go back to a centralized governance program, it may not have
+
+89
+00:05:25,000 --> 00:05:31,000
+the flexibility and it may apply too much security to departments that just doesn't deal with things
+
+90
+00:05:31,000 --> 00:05:36,000
+that are super secure and needs a level of security that the financial department needs.
+
+91
+00:05:36,000 --> 00:05:41,000
+For example, a lot of things that the salespeople work on is generally public knowledge versus a almost
+
+92
+00:05:41,000 --> 00:05:47,000
+everything the research and development or the financial department does is very needs more security
+
+93
+00:05:47,000 --> 00:05:48,000
+or is more secret.
+
+94
+00:05:48,000 --> 00:05:55,000
+So maybe in a decentralized environment this may be better as every department can pretty much set their
+
+95
+00:05:55,000 --> 00:05:56,000
+own policies.
+
+96
+00:05:56,000 --> 00:05:58,000
+Now, there's no right or wrong way.
+
+97
+00:05:58,000 --> 00:06:04,000
+I'm not going to tell you guys that there is a good way, or there is a correct way of doing this that's
+
+98
+00:06:04,000 --> 00:06:06,000
+going to be dependent on your organization.
+
+99
+00:06:06,000 --> 00:06:13,000
+But just keep in mind that these different structures exist and they will influence the way you manage
+
+100
+00:06:13,000 --> 00:06:14,000
+your security governance.
+
diff --git a/20 - Security Governance and Privacy/004 Security Governance Roles OB 5.1_en.srt b/20 - Security Governance and Privacy/004 Security Governance Roles OB 5.1_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..b53b6a0165707eb647f22e942197a57b385e44a4
--- /dev/null
+++ b/20 - Security Governance and Privacy/004 Security Governance Roles OB 5.1_en.srt
@@ -0,0 +1,368 @@
+1
+00:00:00,000 --> 00:00:05,000
+When it comes to implementing a security governance program, there are a few roles that you want to
+
+2
+00:00:05,000 --> 00:00:10,000
+be familiar with to ensure that they are assigned to ensure a perfect or good implementation.
+
+3
+00:00:10,000 --> 00:00:16,000
+Now those two, there's two roles here that is mandatory, and depending on the laws and regulations
+
+4
+00:00:16,000 --> 00:00:18,000
+you follow, you may have the other two.
+
+5
+00:00:18,000 --> 00:00:24,000
+So the two roles that you should have in every single governance program is going to be owners and custodians
+
+6
+00:00:24,000 --> 00:00:25,000
+or stewards.
+
+7
+00:00:25,000 --> 00:00:29,000
+Now, depending on the laws and regulations you follow, like if you're following the general data protection,
+
+8
+00:00:29,000 --> 00:00:35,000
+which is GDPR and the European Union, you may have things that controllers and processors.
+
+9
+00:00:35,000 --> 00:00:37,000
+So let's go into these roles here.
+
+10
+00:00:37,000 --> 00:00:42,000
+The first one up I want to mention is going to be an owner data owner system owner is how you would
+
+11
+00:00:42,000 --> 00:00:43,000
+see this show up.
+
+12
+00:00:43,000 --> 00:00:46,000
+So what exactly is an owner.
+
+13
+00:00:46,000 --> 00:00:52,000
+Well owners are generally senior management or members of departmental heads who have overall accountability
+
+14
+00:00:52,000 --> 00:00:54,000
+for specific information assets.
+
+15
+00:00:54,000 --> 00:01:01,000
+They're responsible for ensuring that proper controls are in place to protect the data and making strategic
+
+16
+00:01:01,000 --> 00:01:02,000
+decisions.
+
+17
+00:01:02,000 --> 00:01:06,000
+Owners define the classification of the data and approve access control.
+
+18
+00:01:06,000 --> 00:01:08,000
+Let me give you guys a whole bunch of examples.
+
+19
+00:01:08,000 --> 00:01:10,000
+The data owners for example.
+
+20
+00:01:11,000 --> 00:01:14,000
+Is generally the people at the head of the department.
+
+21
+00:01:14,000 --> 00:01:16,000
+Data has to be broken down by department.
+
+22
+00:01:16,000 --> 00:01:19,000
+So let's say you work in a company and is the head of the accounting department.
+
+23
+00:01:19,000 --> 00:01:24,000
+The person who heads that accounting department is generally the data owner of the account in data.
+
+24
+00:01:24,000 --> 00:01:31,000
+That person is generally going to be responsible for determining who has access to the data and what
+
+25
+00:01:31,000 --> 00:01:32,000
+type of access they need.
+
+26
+00:01:32,000 --> 00:01:38,000
+For example, let's say the head of the accounting department is Mary, and Mary is the data owner.
+
+27
+00:01:38,000 --> 00:01:45,000
+For all the accounting data, Mary can dictate that Bob can only have access to this accounting data.
+
+28
+00:01:45,000 --> 00:01:48,000
+He can read to this and he can write to that.
+
+29
+00:01:48,000 --> 00:01:48,000
+He can't.
+
+30
+00:01:48,000 --> 00:01:50,000
+He can't read and he can't.
+
+31
+00:01:50,000 --> 00:01:53,000
+He doesn't have full control over any of the data.
+
+32
+00:01:53,000 --> 00:01:57,000
+Mary can also dictate that Peter can only read to this and nothing more.
+
+33
+00:01:57,000 --> 00:02:01,000
+So notice Mary is determining the access control.
+
+34
+00:02:01,000 --> 00:02:03,000
+Mary is determining who can access this data.
+
+35
+00:02:03,000 --> 00:02:09,000
+Mary can determine whether you know where in the level of data classification does this data rank.
+
+36
+00:02:09,000 --> 00:02:13,000
+Mary has to ensure that the proper controls are in place.
+
+37
+00:02:13,000 --> 00:02:15,000
+Mary should dictate things like when this.
+
+38
+00:02:15,000 --> 00:02:17,000
+When should this data be backed up?
+
+39
+00:02:17,000 --> 00:02:19,000
+What type of encryption does it need?
+
+40
+00:02:19,000 --> 00:02:24,000
+So the data owner sets a lot of parameters about the particular data.
+
+41
+00:02:24,000 --> 00:02:29,000
+The other famous firm that you may see on your exam is going to be what's known as a custodian.
+
+42
+00:02:29,000 --> 00:02:30,000
+That's us.
+
+43
+00:02:30,000 --> 00:02:32,000
+We are the tech folks.
+
+44
+00:02:32,000 --> 00:02:39,000
+Custodians are data stewards are responsible for the technical and protection of the data.
+
+45
+00:02:39,000 --> 00:02:45,000
+So technical management, the implement security measures, manage access control and ensure proper
+
+46
+00:02:45,000 --> 00:02:47,000
+operations of that system.
+
+47
+00:02:47,000 --> 00:02:51,000
+Now where are they going to get what type of measures.
+
+48
+00:02:51,000 --> 00:02:52,000
+Where are they going to get?
+
+49
+00:02:52,000 --> 00:02:54,000
+What type of access controller?
+
+50
+00:02:54,000 --> 00:02:55,000
+Who should have access.
+
+51
+00:02:55,000 --> 00:02:56,000
+Right.
+
+52
+00:02:56,000 --> 00:02:58,000
+We're going to where are they going to get that from the data owner.
+
+53
+00:02:58,000 --> 00:03:04,000
+The data owner is going to say, well, the data should be backed up every Monday, Wednesday and Friday
+
+54
+00:03:04,000 --> 00:03:05,000
+at seven in the night.
+
+55
+00:03:05,000 --> 00:03:07,000
+You know who's going to do the backup?
+
+56
+00:03:07,000 --> 00:03:08,000
+Not the owner.
+
+57
+00:03:08,000 --> 00:03:15,000
+This guy, the custodian, the steward is going to be the one that's doing the actual backup.
+
+58
+00:03:15,000 --> 00:03:20,000
+Custodians handle the day to day management of the data and ensuring the CIA here.
+
+59
+00:03:20,000 --> 00:03:27,000
+Now, if you're following things like GDPR, you're going to have additional terms such as controllers
+
+60
+00:03:27,000 --> 00:03:28,000
+and processors.
+
+61
+00:03:28,000 --> 00:03:36,000
+Now, in the context of data protection, regulations like GDPR, controllers are entities that determine
+
+62
+00:03:36,000 --> 00:03:39,000
+the purpose and means of processing personal data.
+
+63
+00:03:39,000 --> 00:03:43,000
+So they're going to determine, wait, why do we need this data?
+
+64
+00:03:43,000 --> 00:03:46,000
+They have to be able to justify this to regulators.
+
+65
+00:03:46,000 --> 00:03:49,000
+And how are we going to process people's private data.
+
+66
+00:03:49,000 --> 00:03:53,000
+They make decisions about the data processing activity and they have to make sure.
+
+67
+00:03:53,000 --> 00:03:59,000
+So the data processor is the person that's going to report to the regulators within those countries.
+
+68
+00:03:59,000 --> 00:04:06,000
+So they're going to have to ensure that the right security measures are implemented to ensure the data
+
+69
+00:04:06,000 --> 00:04:06,000
+is protected.
+
+70
+00:04:06,000 --> 00:04:13,000
+And they're generally the general point of contact or the primary point of contact for regulatory officers.
+
+71
+00:04:13,000 --> 00:04:19,000
+So, for example, if you follow things like GDPR, because you your company does business in the EU
+
+72
+00:04:20,000 --> 00:04:25,000
+or the European Union, you're going to have generally a person as assigned as the controller.
+
+73
+00:04:25,000 --> 00:04:28,000
+This controller is the one that is the bridge between.
+
+74
+00:04:29,000 --> 00:04:33,000
+The regulators, the GDPR law and the data that we're collecting in the IT department.
+
+75
+00:04:33,000 --> 00:04:37,000
+This person has to ensure that the data is collected for a reason.
+
+76
+00:04:37,000 --> 00:04:42,000
+The data is processed within the confines of the law, and they're going to ensure that when regulators
+
+77
+00:04:42,000 --> 00:04:45,000
+come, they're the one that they're going to be talking to.
+
+78
+00:04:46,000 --> 00:04:48,000
+Also related to this is going to be processors.
+
+79
+00:04:48,000 --> 00:04:53,000
+Processors are entities that process data on behalf of the controllers.
+
+80
+00:04:53,000 --> 00:05:00,000
+This could be things like third party service providers or internal departments that handles data.
+
+81
+00:05:00,000 --> 00:05:05,000
+They're responsible including processing data securely as the controllers instructions and ensure that
+
+82
+00:05:05,000 --> 00:05:06,000
+they comply with all laws.
+
+83
+00:05:06,000 --> 00:05:09,000
+So the controller is going to work with the processor.
+
+84
+00:05:09,000 --> 00:05:11,000
+Wait, whatever we're doing with the data, how are we analyzing the data?
+
+85
+00:05:11,000 --> 00:05:14,000
+Where is the data being analyzed that we're collecting.
+
+86
+00:05:14,000 --> 00:05:16,000
+That's what the processor is going to be doing, the analyzing the data.
+
+87
+00:05:16,000 --> 00:05:22,000
+But they better make sure they follow the laws that the controller had specified because the controller
+
+88
+00:05:22,000 --> 00:05:24,000
+reports back to the regulators.
+
+89
+00:05:25,000 --> 00:05:25,000
+Okay.
+
+90
+00:05:25,000 --> 00:05:32,000
+So, uh, just for quick roles that you're going to see appearing on your exam, make sure you know
+
+91
+00:05:32,000 --> 00:05:33,000
+what they are.
+
+92
+00:05:34,000 --> 00:05:38,000
+Um, because more than likely, you're probably going to get a few questions on this particular topic.
+
diff --git a/20 - Security Governance and Privacy/005 Compliance Reporting OB 5.4_en.srt b/20 - Security Governance and Privacy/005 Compliance Reporting OB 5.4_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..47e3aebd7c762de1a919caa92f2835353f8efa8f
--- /dev/null
+++ b/20 - Security Governance and Privacy/005 Compliance Reporting OB 5.4_en.srt
@@ -0,0 +1,736 @@
+1
+00:00:00,000 --> 00:00:07,000
+When it comes to working in the world of technology, be prepared to deal with tons of different regulations.
+
+2
+00:00:07,000 --> 00:00:14,000
+Regulations are laws passed by government entities that we have to follow, and they dictate many of
+
+3
+00:00:14,000 --> 00:00:20,000
+the different aspects of it, such as how should we secure this phone to not lose private data?
+
+4
+00:00:20,000 --> 00:00:24,000
+How should we set up this firewall to ensure data is encrypted?
+
+5
+00:00:24,000 --> 00:00:29,000
+How should we configure the access points to ensure no unauthorized access and encryption of wireless
+
+6
+00:00:29,000 --> 00:00:30,000
+data?
+
+7
+00:00:30,000 --> 00:00:37,000
+These these kinds of regulations will affect many, many, if not all aspects of what we do in it.
+
+8
+00:00:37,000 --> 00:00:42,000
+Now, in this video, we're not going to go into the different laws that we have to follow, but we
+
+9
+00:00:42,000 --> 00:00:47,000
+want to talk about what's called compliance reporting and what happens if you're not in compliance to
+
+10
+00:00:47,000 --> 00:00:49,000
+the different regulations you have to follow.
+
+11
+00:00:49,000 --> 00:00:52,000
+Let's start out by talking about compliance reporting.
+
+12
+00:00:52,000 --> 00:00:53,000
+What exactly is this?
+
+13
+00:00:53,000 --> 00:01:00,000
+This is refers to the processes of documenting and convey an organization's adherence to various various
+
+14
+00:01:00,000 --> 00:01:03,000
+cybersecurity regulations, standards, and policies.
+
+15
+00:01:03,000 --> 00:01:07,000
+For example, maybe your organization deals with medical records.
+
+16
+00:01:07,000 --> 00:01:13,000
+Maybe you're a hospital or clinic, and you get a lot of folks medical records, such as their insurance
+
+17
+00:01:13,000 --> 00:01:17,000
+information, illnesses they may have or different medications they take.
+
+18
+00:01:18,000 --> 00:01:25,000
+You're going to follow what's known as HIPAA compliance, high HIPAA compliance.
+
+19
+00:01:25,000 --> 00:01:28,000
+That is a kind of regulation that you have to follow.
+
+20
+00:01:28,000 --> 00:01:33,000
+If you collect credit cards, for example, you're going to follow what's called PCI Compliance Payment
+
+21
+00:01:33,000 --> 00:01:38,000
+card industry, what's known as PCI, DSS Payment Card Industry Data Security Standard PCI.
+
+22
+00:01:38,000 --> 00:01:44,000
+If you collect credit cards, PCI compliance says that you have to follow a standard in order to ensure
+
+23
+00:01:44,000 --> 00:01:45,000
+that data is secure.
+
+24
+00:01:45,000 --> 00:01:51,000
+Now, when it comes to these kinds of compliance reporting, you're basically going to be doing two
+
+25
+00:01:51,000 --> 00:01:52,000
+kinds of reporting.
+
+26
+00:01:52,000 --> 00:01:56,000
+You're going to be reporting it internal reporting and external reporting.
+
+27
+00:01:56,000 --> 00:02:02,000
+So internal reporting involves generating reports for use within the organization.
+
+28
+00:02:02,000 --> 00:02:08,000
+Typically for folks like management internal audit teams or your IT security department.
+
+29
+00:02:08,000 --> 00:02:13,000
+Why would you, uh, report internal audits.
+
+30
+00:02:13,000 --> 00:02:14,000
+Right.
+
+31
+00:02:14,000 --> 00:02:17,000
+Why would you report internally to management?
+
+32
+00:02:17,000 --> 00:02:26,000
+Well, when you do a security assessment within the organization to see are we meeting a certain regulation?
+
+33
+00:02:26,000 --> 00:02:30,000
+What you're basically doing is you're doing what's known as self evaluation.
+
+34
+00:02:30,000 --> 00:02:36,000
+The organization basically does a self evaluation to see are we in compliance to HIPAA regulation.
+
+35
+00:02:36,000 --> 00:02:39,000
+Are we in compliance to the PCI standards.
+
+36
+00:02:40,000 --> 00:02:42,000
+And what they're looking for is areas for improvement.
+
+37
+00:02:42,000 --> 00:02:44,000
+So they identify areas for improvement.
+
+38
+00:02:44,000 --> 00:02:49,000
+They may say well we are 99% in compliance but we're missing this particular aspect.
+
+39
+00:02:49,000 --> 00:02:51,000
+So we need to now need to fix that.
+
+40
+00:02:51,000 --> 00:02:54,000
+This is internal compliance external compliance.
+
+41
+00:02:54,000 --> 00:03:00,000
+So you could imagine it's going to go outside outside entities regulatory bodies clients or third party
+
+42
+00:03:00,000 --> 00:03:01,000
+auditors.
+
+43
+00:03:01,000 --> 00:03:02,000
+Let me give you an example.
+
+44
+00:03:03,000 --> 00:03:09,000
+If you process tons of credit cards through your e-commerce website and you're using a bank, let's
+
+45
+00:03:09,000 --> 00:03:14,000
+say you're using Bank of America to process as your credit card processors.
+
+46
+00:03:14,000 --> 00:03:18,000
+Those are the people that's going to actually run the card for you.
+
+47
+00:03:18,000 --> 00:03:22,000
+Bank of America makes it mandatory that you follow PCI compliance.
+
+48
+00:03:22,000 --> 00:03:28,000
+So what happens is you're going to have to report to Bank of America, how are you staying with PCI.
+
+49
+00:03:28,000 --> 00:03:33,000
+So they're you're going to have to report to this third party entity of Bank of America.
+
+50
+00:03:33,000 --> 00:03:38,000
+So this type of report reporting demonstrates compliance with external security standards.
+
+51
+00:03:38,000 --> 00:03:41,000
+Uh, there's a bunch here, whether it's ISO standard.
+
+52
+00:03:41,000 --> 00:03:45,000
+Maybe you're following this to show how good of a security system you have.
+
+53
+00:03:45,000 --> 00:03:50,000
+Nice GDPR, HIPAA, GDPR is a European privacy law.
+
+54
+00:03:50,000 --> 00:03:54,000
+HIPAA is going to be an American medical records law.
+
+55
+00:03:55,000 --> 00:04:01,000
+Now external reporting might require specific might be required periodically or in response to a specific
+
+56
+00:04:01,000 --> 00:04:02,000
+compliance audit.
+
+57
+00:04:02,000 --> 00:04:04,000
+For example PCI compliance.
+
+58
+00:04:04,000 --> 00:04:12,000
+You may have to report PCI, um standard requirements or how you are in requirements sometimes on a
+
+59
+00:04:12,000 --> 00:04:14,000
+monthly, quarterly, or even yearly basis.
+
+60
+00:04:14,000 --> 00:04:17,000
+So remember what external it's for outside entities.
+
+61
+00:04:17,000 --> 00:04:24,000
+The other thing we want to talk about is what happens if you are not in compliance.
+
+62
+00:04:24,000 --> 00:04:25,000
+What is the consequences of compliance.
+
+63
+00:04:25,000 --> 00:04:26,000
+Let's go through this quickly.
+
+64
+00:04:26,000 --> 00:04:29,000
+Conformance of noncompliance.
+
+65
+00:04:29,000 --> 00:04:35,000
+It's going to be some kind of adverse effect that the organization would fail if you fail to meet certain
+
+66
+00:04:35,000 --> 00:04:37,000
+regulations or standards.
+
+67
+00:04:37,000 --> 00:04:41,000
+Let's go through some of them here that I have fine sanctions, all these different things here.
+
+68
+00:04:42,000 --> 00:04:43,000
+Let's go through some of them.
+
+69
+00:04:43,000 --> 00:04:44,000
+The first one is fine.
+
+70
+00:04:44,000 --> 00:04:48,000
+If you don't meet a certain compliance, be prepared to be fine.
+
+71
+00:04:48,000 --> 00:04:50,000
+This is a standard thing.
+
+72
+00:04:50,000 --> 00:04:57,000
+If you don't meet a certain, uh, regulations such as HIPAA regulation, if you don't meet certain
+
+73
+00:04:57,000 --> 00:04:59,000
+GDPR, especially GDPR.
+
+74
+00:05:00,000 --> 00:05:02,000
+Um, this is general data protection.
+
+75
+00:05:03,000 --> 00:05:05,000
+So this is going to be a European privacy law.
+
+76
+00:05:05,000 --> 00:05:07,000
+If you don't meet it, you're going to get fined.
+
+77
+00:05:07,000 --> 00:05:10,000
+The fines and penalty could be substantive.
+
+78
+00:05:10,000 --> 00:05:13,000
+It could really affect your organization.
+
+79
+00:05:13,000 --> 00:05:17,000
+So another reason why you want to get it is to make sure that you don't pay any hefty fees.
+
+80
+00:05:18,000 --> 00:05:20,000
+Another one here you have is going to be sanctions.
+
+81
+00:05:20,000 --> 00:05:24,000
+This is when not just formal penalties, but they could restrict you.
+
+82
+00:05:24,000 --> 00:05:29,000
+They may sanction your organization and restrict you from doing certain kinds of businesses.
+
+83
+00:05:29,000 --> 00:05:33,000
+They may restrict you for selling a certain product or doing business in a certain country.
+
+84
+00:05:33,000 --> 00:05:37,000
+So make sure once again you stay in compliance.
+
+85
+00:05:38,000 --> 00:05:43,000
+If you fall out of compliance, your reputation may take a hit.
+
+86
+00:05:44,000 --> 00:05:51,000
+Non-compliance can lead to significant reputation damages, the public disclosure of compliance failures,
+
+87
+00:05:51,000 --> 00:05:54,000
+especially those that compromises consumer data.
+
+88
+00:05:54,000 --> 00:06:01,000
+For example, let's say you didn't encrypt a customer's data when you should have, uh, the data was
+
+89
+00:06:01,000 --> 00:06:07,000
+stolen and it was all in clear text that leaks out or auditors release it.
+
+90
+00:06:07,000 --> 00:06:10,000
+That company A has lost the customer's data.
+
+91
+00:06:10,000 --> 00:06:15,000
+You better best believe your customers may not want to do business with you anymore because you lose
+
+92
+00:06:15,000 --> 00:06:19,000
+their data all the time, so your reputation will take a hit.
+
+93
+00:06:19,000 --> 00:06:20,000
+They're not going to trust you anymore.
+
+94
+00:06:20,000 --> 00:06:25,000
+Their confidence is going to decline, not just with your customers, but partners also.
+
+95
+00:06:25,000 --> 00:06:28,000
+So B be ready for that.
+
+96
+00:06:29,000 --> 00:06:35,000
+If you don't manage regulations and you work in a business that needs certain licenses, like in finance
+
+97
+00:06:35,000 --> 00:06:40,000
+or in health care, and you don't have and you don't meet certain compliance, you may lose the license
+
+98
+00:06:40,000 --> 00:06:42,000
+to continue working.
+
+99
+00:06:42,000 --> 00:06:46,000
+Some organizations, like we own medical schools in the state of New York.
+
+100
+00:06:46,000 --> 00:06:53,000
+Tia is the owner of big medical schools, and those medical schools require a license to stay open if
+
+101
+00:06:53,000 --> 00:06:59,000
+you don't meet certain regulations, whether it's safety regulations for our students or licensure regulations
+
+102
+00:06:59,000 --> 00:07:01,000
+for our instructors.
+
+103
+00:07:01,000 --> 00:07:04,000
+The school will lose its license and its ability to operate.
+
+104
+00:07:04,000 --> 00:07:09,000
+So if our license is revoked, we could be shut down.
+
+105
+00:07:10,000 --> 00:07:16,000
+Contractual impacts well, failure to comply with cybersecurity clauses and contracts could lead to
+
+106
+00:07:16,000 --> 00:07:17,000
+a contract breach.
+
+107
+00:07:17,000 --> 00:07:24,000
+This can lead to legal disputes, which means, uh, you and a vendor in court, you can even lose contracts.
+
+108
+00:07:25,000 --> 00:07:34,000
+Or the contract may have financial penalties associated with failure to meet certain kinds of regulations.
+
+109
+00:07:34,000 --> 00:07:40,000
+For example, let's say you're working with a vendor, and that vendor has to stay in PCI compliance
+
+110
+00:07:40,000 --> 00:07:41,000
+because they're processing your credit card.
+
+111
+00:07:41,000 --> 00:07:43,000
+They don't want managing your website.
+
+112
+00:07:43,000 --> 00:07:43,000
+Well.
+
+113
+00:07:43,000 --> 00:07:48,000
+If that vendor fails PCI compliance or fails to meet it, you might terminate the contract with them,
+
+114
+00:07:48,000 --> 00:07:50,000
+which would generally be a good idea.
+
+115
+00:07:51,000 --> 00:07:52,000
+This is especially significant.
+
+116
+00:07:52,000 --> 00:07:58,000
+B2B means business to business where, uh, cybersecurity compliance is mandatory.
+
+117
+00:07:58,000 --> 00:08:03,000
+Now you want to continuously monitor this compliance.
+
+118
+00:08:03,000 --> 00:08:05,000
+Monitoring is an ongoing thing.
+
+119
+00:08:06,000 --> 00:08:08,000
+I've said this before in security.
+
+120
+00:08:08,000 --> 00:08:14,000
+When it comes to security, what happens is basically what's happening today.
+
+121
+00:08:14,000 --> 00:08:16,000
+What's it's what's happening today is just today.
+
+122
+00:08:17,000 --> 00:08:18,000
+New things happen tomorrow.
+
+123
+00:08:18,000 --> 00:08:20,000
+New viruses comes out.
+
+124
+00:08:20,000 --> 00:08:27,000
+Tomorrow, new vulnerabilities are discovered tomorrow new hackers are coming on the market tomorrow.
+
+125
+00:08:27,000 --> 00:08:33,000
+Tonight there's some guy contemplating should I, should I, should I bring this system down.
+
+126
+00:08:33,000 --> 00:08:35,000
+Should I try this right now.
+
+127
+00:08:35,000 --> 00:08:37,000
+And he's probably going to say yes.
+
+128
+00:08:37,000 --> 00:08:39,000
+So the world changes all the time.
+
+129
+00:08:39,000 --> 00:08:40,000
+And the same thing with compliance.
+
+130
+00:08:40,000 --> 00:08:43,000
+You're in compliance today doesn't mean you're in compliance tomorrow.
+
+131
+00:08:43,000 --> 00:08:45,000
+So you have to continuously do this.
+
+132
+00:08:45,000 --> 00:08:51,000
+It's an ongoing process of ensuring that an organization consistently meet the needs.
+
+133
+00:08:51,000 --> 00:08:52,000
+If not.
+
+134
+00:08:53,000 --> 00:08:56,000
+You're going to, you're going to suffer some of the consequences.
+
+135
+00:08:56,000 --> 00:08:59,000
+Now due diligence and due care.
+
+136
+00:08:59,000 --> 00:09:07,000
+So due diligence in compliance monitoring is the effort of is involves a continuous effort to ensure
+
+137
+00:09:07,000 --> 00:09:13,000
+that all cybersecurity practices policies are in controls, are in line with the latest and regulatory
+
+138
+00:09:13,000 --> 00:09:15,000
+requirements for due care.
+
+139
+00:09:15,000 --> 00:09:21,000
+This is the ongoing management and upkeep of these practices, demonstrating that the organization is
+
+140
+00:09:21,000 --> 00:09:24,000
+actively maintaining its cybersecurity posture.
+
+141
+00:09:24,000 --> 00:09:26,000
+Now, let me give you a couple of examples.
+
+142
+00:09:26,000 --> 00:09:30,000
+When it comes to due diligence, due diligence is doing a lot of research.
+
+143
+00:09:30,000 --> 00:09:35,000
+It's seeing what are the different practices, what is the different policies, what is the different
+
+144
+00:09:35,000 --> 00:09:43,000
+regulations that we need to be involved in to be good in order to stay in compliance?
+
+145
+00:09:43,000 --> 00:09:47,000
+And then due care is actual following those things.
+
+146
+00:09:47,000 --> 00:09:48,000
+Are we following those things?
+
+147
+00:09:48,000 --> 00:09:52,000
+Are we showing that we're following those things?
+
+148
+00:09:53,000 --> 00:09:55,000
+Now a couple of words here.
+
+149
+00:09:56,000 --> 00:10:03,000
+Attestation could never get that word right involves formal verification confirming data organization
+
+150
+00:10:03,000 --> 00:10:04,000
+cybersecurity controls.
+
+151
+00:10:04,000 --> 00:10:13,000
+So at attestation is when the organization assesses that we follow these particular policies or we aren't
+
+152
+00:10:13,000 --> 00:10:18,000
+compliant to something in certain regulations, especially like in PCI compliance.
+
+153
+00:10:18,000 --> 00:10:22,000
+What happens is if you're really small, you don't process many credit cards.
+
+154
+00:10:22,000 --> 00:10:26,000
+You can the organization can just attest that they are without a formal audit.
+
+155
+00:10:28,000 --> 00:10:36,000
+An acknowledgement refers to the organization's recognition and acceptance of its cyber security responsibilities.
+
+156
+00:10:37,000 --> 00:10:41,000
+Now, how do we acknowledge that we are going to follow these things?
+
+157
+00:10:42,000 --> 00:10:44,000
+How do we acknowledge, okay, we are going to be held responsible for this?
+
+158
+00:10:44,000 --> 00:10:48,000
+Well, that's going to be the different policies that you follow in your business.
+
+159
+00:10:48,000 --> 00:10:53,000
+Now internal and external monitoring.
+
+160
+00:10:53,000 --> 00:10:58,000
+So internal monitoring is activities conducted within the business to ensure compliance.
+
+161
+00:10:58,000 --> 00:11:03,000
+This is when you're going to do internal audits regular audits reviews and assessments.
+
+162
+00:11:03,000 --> 00:11:07,000
+External monitoring is generally done by an external parties.
+
+163
+00:11:07,000 --> 00:11:11,000
+This is going to be external auditors or external compliance folks.
+
+164
+00:11:11,000 --> 00:11:13,000
+You are going to be monitored by both.
+
+165
+00:11:13,000 --> 00:11:16,000
+You're going to be doing internal monitoring.
+
+166
+00:11:16,000 --> 00:11:19,000
+The internal monitoring is going to lead to internal reporting.
+
+167
+00:11:19,000 --> 00:11:22,000
+External monitoring could lead to external reporting.
+
+168
+00:11:24,000 --> 00:11:28,000
+When it comes to compliance, one of the best things we can do is automation.
+
+169
+00:11:28,000 --> 00:11:34,000
+Automation and compliance is the use of different kinds of software, tools and technology to continuously
+
+170
+00:11:34,000 --> 00:11:35,000
+monitor compliance.
+
+171
+00:11:35,000 --> 00:11:43,000
+Remember, compliance may stay the same, that rule may stay the same, but your environment doesn't
+
+172
+00:11:43,000 --> 00:11:44,000
+stay the same.
+
+173
+00:11:44,000 --> 00:11:49,000
+And if there's changes in the environment, new malware and new hackers, new vulnerabilities, and
+
+174
+00:11:49,000 --> 00:11:51,000
+so on, how do you check it on?
+
+175
+00:11:51,000 --> 00:11:56,000
+You can't say if you have automated systems like a CRM system or a SIM system.
+
+176
+00:11:56,000 --> 00:12:02,000
+These types of systems like Splunk, which we covered already, remember Siem systems, security information,
+
+177
+00:12:02,000 --> 00:12:07,000
+event management, these are systems that is consistently checking all your log files to see if you
+
+178
+00:12:07,000 --> 00:12:11,000
+are out of compliance or if there's something wrong within the organization.
+
+179
+00:12:11,000 --> 00:12:14,000
+This is going to be an automated system to do that because you can't do it all.
+
+180
+00:12:15,000 --> 00:12:18,000
+The contract changes in regulatory requirements.
+
+181
+00:12:18,000 --> 00:12:21,000
+Monitor security in real time and give you good alerts.
+
+182
+00:12:21,000 --> 00:12:26,000
+Okay, so keep in mind, guys, when it comes to compliance, if we are out of compliance, there's
+
+183
+00:12:26,000 --> 00:12:31,000
+tons of consequences that can happen, whether it's fines or basically losing your business.
+
+184
+00:12:31,000 --> 00:12:35,000
+So if those are some of the consequences, make sure your organization stays in compliance.
+