Tan115 commited on
Commit
e888468
·
verified ·
1 Parent(s): 06ac39f

Add files using upload-large-folder tool

Browse files
This view is limited to 50 files because it contains too many changes.   See raw diff
Files changed (50) hide show
  1. .gitattributes +33 -0
  2. 08 - Social Engineering/005 Spear Phishing OB 2.2.mp4 +3 -0
  3. 08 - Social Engineering/007 Impersonation OB 2.2.mp4 +3 -0
  4. 08 - Social Engineering/008 Business Email Compromise OB 2.2.mp4 +3 -0
  5. 08 - Social Engineering/009 Pretexting OB 2.2.mp4 +3 -0
  6. 08 - Social Engineering/010 Watering Hole OB 2.2.mp4 +3 -0
  7. 08 - Social Engineering/011 Brand Impersonation OB 2.2.mp4 +3 -0
  8. 08 - Social Engineering/012 Typosquatting OB 2.2.mp4 +3 -0
  9. 08 - Social Engineering/013 Training against Phishing OB 5.6.mp4 +3 -0
  10. 08 - Social Engineering/014 Security Awareness Program OB 5.6.mp4 +3 -0
  11. 09 - Securing IT Assets/001 Segmentation OB 2.5.mp4 +3 -0
  12. 09 - Securing IT Assets/002 Isolation OB 2.5.mp4 +3 -0
  13. 09 - Securing IT Assets/003 Access Control OB 2.5.mp4 +3 -0
  14. 09 - Securing IT Assets/004 Principles of Least Privilege OB 2.5.mp4 +3 -0
  15. 09 - Securing IT Assets/005 Access Control List OB 2.5.mp4 +3 -0
  16. 09 - Securing IT Assets/006 Filesystem Permissions OB 2.5.mp4 +3 -0
  17. 09 - Securing IT Assets/007 Application Allow List OB 2.5.mp4 +3 -0
  18. 09 - Securing IT Assets/008 Patching OB 2.5.mp4 +3 -0
  19. 09 - Securing IT Assets/009 Configuration Enforcement OB 2.5.mp4 +3 -0
  20. 09 - Securing IT Assets/010 Decommissioning OB 2.5.mp4 +3 -0
  21. 09 - Securing IT Assets/011 Monitoring OB 2.5.mp4 +3 -0
  22. 09 - Securing IT Assets/012 Hardening Techniques OB 2.5.mp4 +3 -0
  23. 10 - Security Architecture/001 Cloud OB 3.1.mp4 +3 -0
  24. 10 - Security Architecture/002 Infrastructure as Code OB 3.1.mp4 +3 -0
  25. 10 - Security Architecture/003 Serverless Architecture OB 3.1.mp4 +3 -0
  26. 10 - Security Architecture/004 Microservices OB 3.1.mp4 +3 -0
  27. 10 - Security Architecture/005 Air Gapped OB 3.1.mp4 +3 -0
  28. 10 - Security Architecture/006 Software-Defined Networking OB 3.1.mp4 +3 -0
  29. 10 - Security Architecture/007 On-Premises OB 3.1.mp4 +3 -0
  30. 10 - Security Architecture/008 Centralized vs. Decentralized OB 3.1.mp4 +3 -0
  31. 10 - Security Architecture/009 Virtualization OB 3.1.mp4 +3 -0
  32. 10 - Security Architecture/010 Containerization OB 3.1.mp4 +3 -0
  33. 10 - Security Architecture/011 High Availability OB 3.1.mp4 +3 -0
  34. 10 - Security Architecture/013 ICS OB 3.1.mp4 +3 -0
  35. 20 - Security Governance and Privacy/006 Privacy OB 5.4_en.srt +552 -0
  36. 20 - Security Governance and Privacy/007 Quick Quiz.html +479 -0
  37. 21 - Risk Management/001 Risk Terms OB 5.2_en.srt +416 -0
  38. 21 - Risk Management/002 Risk Identification and Assessment Times OB 5.2_en.srt +340 -0
  39. 21 - Risk Management/003 Quantitative and Qualitive Risk Assessment OB 5.2_en.srt +784 -0
  40. 21 - Risk Management/004 Risk Register OB 5.2_en.srt +424 -0
  41. 21 - Risk Management/005 Risk Appetite OB 5.2_en.srt +324 -0
  42. 21 - Risk Management/006 Risk Response OB 5.2_en.srt +424 -0
  43. 21 - Risk Management/007 Business Impact Assessment OB 5.2_en.srt +352 -0
  44. 21 - Risk Management/008 Quick Quiz.html +479 -0
  45. 22 - Vendor Management/001 Vendor Assessment and Selection OB 5.3_en.srt +888 -0
  46. 22 - Vendor Management/002 Vendor Agreements OB 5.3_en.srt +484 -0
  47. 22 - Vendor Management/003 Quick Quiz.html +479 -0
  48. 23 - Physical Security/001 Physical Security OB 1.2_en.srt +640 -0
  49. 23 - Physical Security/002 Quick Quiz.html +479 -0
  50. 24 - Change Management/001 Change management OB 1.3_en.srt +824 -0
.gitattributes CHANGED
@@ -133,3 +133,36 @@ saved_model/**/* filter=lfs diff=lfs merge=lfs -text
133
  08[[:space:]]-[[:space:]]Social[[:space:]]Engineering/003[[:space:]]Vishing[[:space:]]OB[[:space:]]2.2.mp4 filter=lfs diff=lfs merge=lfs -text
134
  08[[:space:]]-[[:space:]]Social[[:space:]]Engineering/002[[:space:]]Phishing[[:space:]]OB[[:space:]]2.2.mp4 filter=lfs diff=lfs merge=lfs -text
135
  08[[:space:]]-[[:space:]]Social[[:space:]]Engineering/006[[:space:]]Misinformation[[:space:]]and[[:space:]]Disinformation[[:space:]]OB[[:space:]]2.2.mp4 filter=lfs diff=lfs merge=lfs -text
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
133
  08[[:space:]]-[[:space:]]Social[[:space:]]Engineering/003[[:space:]]Vishing[[:space:]]OB[[:space:]]2.2.mp4 filter=lfs diff=lfs merge=lfs -text
134
  08[[:space:]]-[[:space:]]Social[[:space:]]Engineering/002[[:space:]]Phishing[[:space:]]OB[[:space:]]2.2.mp4 filter=lfs diff=lfs merge=lfs -text
135
  08[[:space:]]-[[:space:]]Social[[:space:]]Engineering/006[[:space:]]Misinformation[[:space:]]and[[:space:]]Disinformation[[:space:]]OB[[:space:]]2.2.mp4 filter=lfs diff=lfs merge=lfs -text
136
+ 08[[:space:]]-[[:space:]]Social[[:space:]]Engineering/005[[:space:]]Spear[[:space:]]Phishing[[:space:]]OB[[:space:]]2.2.mp4 filter=lfs diff=lfs merge=lfs -text
137
+ 08[[:space:]]-[[:space:]]Social[[:space:]]Engineering/007[[:space:]]Impersonation[[:space:]]OB[[:space:]]2.2.mp4 filter=lfs diff=lfs merge=lfs -text
138
+ 08[[:space:]]-[[:space:]]Social[[:space:]]Engineering/008[[:space:]]Business[[:space:]]Email[[:space:]]Compromise[[:space:]]OB[[:space:]]2.2.mp4 filter=lfs diff=lfs merge=lfs -text
139
+ 08[[:space:]]-[[:space:]]Social[[:space:]]Engineering/010[[:space:]]Watering[[:space:]]Hole[[:space:]]OB[[:space:]]2.2.mp4 filter=lfs diff=lfs merge=lfs -text
140
+ 08[[:space:]]-[[:space:]]Social[[:space:]]Engineering/009[[:space:]]Pretexting[[:space:]]OB[[:space:]]2.2.mp4 filter=lfs diff=lfs merge=lfs -text
141
+ 08[[:space:]]-[[:space:]]Social[[:space:]]Engineering/011[[:space:]]Brand[[:space:]]Impersonation[[:space:]]OB[[:space:]]2.2.mp4 filter=lfs diff=lfs merge=lfs -text
142
+ 08[[:space:]]-[[:space:]]Social[[:space:]]Engineering/012[[:space:]]Typosquatting[[:space:]]OB[[:space:]]2.2.mp4 filter=lfs diff=lfs merge=lfs -text
143
+ 08[[:space:]]-[[:space:]]Social[[:space:]]Engineering/013[[:space:]]Training[[:space:]]against[[:space:]]Phishing[[:space:]]OB[[:space:]]5.6.mp4 filter=lfs diff=lfs merge=lfs -text
144
+ 08[[:space:]]-[[:space:]]Social[[:space:]]Engineering/014[[:space:]]Security[[:space:]]Awareness[[:space:]]Program[[:space:]]OB[[:space:]]5.6.mp4 filter=lfs diff=lfs merge=lfs -text
145
+ 09[[:space:]]-[[:space:]]Securing[[:space:]]IT[[:space:]]Assets/001[[:space:]]Segmentation[[:space:]]OB[[:space:]]2.5.mp4 filter=lfs diff=lfs merge=lfs -text
146
+ 09[[:space:]]-[[:space:]]Securing[[:space:]]IT[[:space:]]Assets/002[[:space:]]Isolation[[:space:]]OB[[:space:]]2.5.mp4 filter=lfs diff=lfs merge=lfs -text
147
+ 09[[:space:]]-[[:space:]]Securing[[:space:]]IT[[:space:]]Assets/003[[:space:]]Access[[:space:]]Control[[:space:]]OB[[:space:]]2.5.mp4 filter=lfs diff=lfs merge=lfs -text
148
+ 09[[:space:]]-[[:space:]]Securing[[:space:]]IT[[:space:]]Assets/005[[:space:]]Access[[:space:]]Control[[:space:]]List[[:space:]]OB[[:space:]]2.5.mp4 filter=lfs diff=lfs merge=lfs -text
149
+ 09[[:space:]]-[[:space:]]Securing[[:space:]]IT[[:space:]]Assets/004[[:space:]]Principles[[:space:]]of[[:space:]]Least[[:space:]]Privilege[[:space:]]OB[[:space:]]2.5.mp4 filter=lfs diff=lfs merge=lfs -text
150
+ 09[[:space:]]-[[:space:]]Securing[[:space:]]IT[[:space:]]Assets/007[[:space:]]Application[[:space:]]Allow[[:space:]]List[[:space:]]OB[[:space:]]2.5.mp4 filter=lfs diff=lfs merge=lfs -text
151
+ 09[[:space:]]-[[:space:]]Securing[[:space:]]IT[[:space:]]Assets/006[[:space:]]Filesystem[[:space:]]Permissions[[:space:]]OB[[:space:]]2.5.mp4 filter=lfs diff=lfs merge=lfs -text
152
+ 09[[:space:]]-[[:space:]]Securing[[:space:]]IT[[:space:]]Assets/009[[:space:]]Configuration[[:space:]]Enforcement[[:space:]]OB[[:space:]]2.5.mp4 filter=lfs diff=lfs merge=lfs -text
153
+ 09[[:space:]]-[[:space:]]Securing[[:space:]]IT[[:space:]]Assets/008[[:space:]]Patching[[:space:]]OB[[:space:]]2.5.mp4 filter=lfs diff=lfs merge=lfs -text
154
+ 09[[:space:]]-[[:space:]]Securing[[:space:]]IT[[:space:]]Assets/010[[:space:]]Decommissioning[[:space:]]OB[[:space:]]2.5.mp4 filter=lfs diff=lfs merge=lfs -text
155
+ 09[[:space:]]-[[:space:]]Securing[[:space:]]IT[[:space:]]Assets/011[[:space:]]Monitoring[[:space:]]OB[[:space:]]2.5.mp4 filter=lfs diff=lfs merge=lfs -text
156
+ 09[[:space:]]-[[:space:]]Securing[[:space:]]IT[[:space:]]Assets/012[[:space:]]Hardening[[:space:]]Techniques[[:space:]]OB[[:space:]]2.5.mp4 filter=lfs diff=lfs merge=lfs -text
157
+ 10[[:space:]]-[[:space:]]Security[[:space:]]Architecture/001[[:space:]]Cloud[[:space:]]OB[[:space:]]3.1.mp4 filter=lfs diff=lfs merge=lfs -text
158
+ 10[[:space:]]-[[:space:]]Security[[:space:]]Architecture/003[[:space:]]Serverless[[:space:]]Architecture[[:space:]]OB[[:space:]]3.1.mp4 filter=lfs diff=lfs merge=lfs -text
159
+ 10[[:space:]]-[[:space:]]Security[[:space:]]Architecture/002[[:space:]]Infrastructure[[:space:]]as[[:space:]]Code[[:space:]]OB[[:space:]]3.1.mp4 filter=lfs diff=lfs merge=lfs -text
160
+ 10[[:space:]]-[[:space:]]Security[[:space:]]Architecture/004[[:space:]]Microservices[[:space:]]OB[[:space:]]3.1.mp4 filter=lfs diff=lfs merge=lfs -text
161
+ 10[[:space:]]-[[:space:]]Security[[:space:]]Architecture/005[[:space:]]Air[[:space:]]Gapped[[:space:]]OB[[:space:]]3.1.mp4 filter=lfs diff=lfs merge=lfs -text
162
+ 10[[:space:]]-[[:space:]]Security[[:space:]]Architecture/007[[:space:]]On-Premises[[:space:]]OB[[:space:]]3.1.mp4 filter=lfs diff=lfs merge=lfs -text
163
+ 10[[:space:]]-[[:space:]]Security[[:space:]]Architecture/006[[:space:]]Software-Defined[[:space:]]Networking[[:space:]]OB[[:space:]]3.1.mp4 filter=lfs diff=lfs merge=lfs -text
164
+ 10[[:space:]]-[[:space:]]Security[[:space:]]Architecture/008[[:space:]]Centralized[[:space:]]vs.[[:space:]]Decentralized[[:space:]]OB[[:space:]]3.1.mp4 filter=lfs diff=lfs merge=lfs -text
165
+ 10[[:space:]]-[[:space:]]Security[[:space:]]Architecture/009[[:space:]]Virtualization[[:space:]]OB[[:space:]]3.1.mp4 filter=lfs diff=lfs merge=lfs -text
166
+ 10[[:space:]]-[[:space:]]Security[[:space:]]Architecture/010[[:space:]]Containerization[[:space:]]OB[[:space:]]3.1.mp4 filter=lfs diff=lfs merge=lfs -text
167
+ 10[[:space:]]-[[:space:]]Security[[:space:]]Architecture/011[[:space:]]High[[:space:]]Availability[[:space:]]OB[[:space:]]3.1.mp4 filter=lfs diff=lfs merge=lfs -text
168
+ 10[[:space:]]-[[:space:]]Security[[:space:]]Architecture/013[[:space:]]ICS[[:space:]]OB[[:space:]]3.1.mp4 filter=lfs diff=lfs merge=lfs -text
08 - Social Engineering/005 Spear Phishing OB 2.2.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:33817e9440664590d364c3a5ac0457d1cf3d4344e5d8cc06bfe9310c469ff374
3
+ size 243728707
08 - Social Engineering/007 Impersonation OB 2.2.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:84500dfa8248e7c3a4520c043defab68eb4ba9fb0f53b426dedf291d087224ab
3
+ size 146609459
08 - Social Engineering/008 Business Email Compromise OB 2.2.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:86ba65fdbf0c8c98c8ff6bf7198c06b7b1de50bffc997dd4807b93094894a639
3
+ size 146064157
08 - Social Engineering/009 Pretexting OB 2.2.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:06d638ed3ad9abd537b9848a1a0a28b8c3d9ec3ada49703b4e22f4bc823e7eab
3
+ size 208963164
08 - Social Engineering/010 Watering Hole OB 2.2.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:74a70cafc05e7560b7fc660c19784f49e64de7a38f4df7bc959a67eb334d07ee
3
+ size 191350680
08 - Social Engineering/011 Brand Impersonation OB 2.2.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:fd07516b14d370c2fbd49d8d1cb75f02149b2359c549c644cb2e3c6a568cf1cc
3
+ size 120682958
08 - Social Engineering/012 Typosquatting OB 2.2.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:b7e3c1ab4603f980f199544225b39aacf69b307452b72162828d0e81cae5e353
3
+ size 226674750
08 - Social Engineering/013 Training against Phishing OB 5.6.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:174997c17366cbd07ceae687d00d495cfd0f5b81187086e9b01a8859e3ed3f7b
3
+ size 213174958
08 - Social Engineering/014 Security Awareness Program OB 5.6.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:22641fc1822b5ba9c357ec85938ff4031ad8cfc2952f5852a0a031d277de0cfe
3
+ size 223183545
09 - Securing IT Assets/001 Segmentation OB 2.5.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:0c4f0f6b27eb1c75c27b8d0cf7bd392a00150adec3217b880431c14906a8adc1
3
+ size 229078501
09 - Securing IT Assets/002 Isolation OB 2.5.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:32dd560740f2a381ee6807c0ed3e8463e651f003f6ee16539f6bc847d92494df
3
+ size 255600569
09 - Securing IT Assets/003 Access Control OB 2.5.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:a634e9b68f524e2eabc5361ca815d4032ea3098ef22c2a734b40cca6bead6c74
3
+ size 130346468
09 - Securing IT Assets/004 Principles of Least Privilege OB 2.5.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:451cfb0122fcb168220044a2b8dd37ff06aefba2d4a156502c82b654fea2e6b7
3
+ size 140483198
09 - Securing IT Assets/005 Access Control List OB 2.5.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:1f46f459cecf28e2209ae38d75ab9673c356e21034aa5a0b11e56af3ccb62748
3
+ size 80763470
09 - Securing IT Assets/006 Filesystem Permissions OB 2.5.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:6dd5822f232a8da329ab4e45723fc5425a5df7d9e114a5c04a322dd959f0ab5e
3
+ size 207582053
09 - Securing IT Assets/007 Application Allow List OB 2.5.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:ef792351b3328095cb67971f74195f7b0326bde581213dc6f68df24318ac8418
3
+ size 77594987
09 - Securing IT Assets/008 Patching OB 2.5.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:ff10141ae450dd7e6237aebfc8658aedfb2ec596420bee9e5069d696ee59f5fe
3
+ size 164696270
09 - Securing IT Assets/009 Configuration Enforcement OB 2.5.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:0efce9153d54b004f221be25bc49323bc299d2708ef090b3c75ae3586a2692d0
3
+ size 101018118
09 - Securing IT Assets/010 Decommissioning OB 2.5.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:c1c63c118e4b9e3c876fcf1647d8ba6cb101f2721a3d09bd7f6512d84f28642d
3
+ size 166973644
09 - Securing IT Assets/011 Monitoring OB 2.5.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:9feb3619ba2c6ee323898656074bd5dd441f7d72d1498b0ae89a10df24ad856b
3
+ size 129115103
09 - Securing IT Assets/012 Hardening Techniques OB 2.5.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:c9e1777edb1557bcbfe8732868839e0326f403154a2950c2f022f6ba12bafe1d
3
+ size 440558615
10 - Security Architecture/001 Cloud OB 3.1.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:d97d150bda22e1f679687878dcc9dbd8d5e575ca6e2b92e5c2f0c032b3728abb
3
+ size 511591304
10 - Security Architecture/002 Infrastructure as Code OB 3.1.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:976a3b50ba018c8bb63c1f35b400aa4597909971dc359f0370bd1471e098419d
3
+ size 153103708
10 - Security Architecture/003 Serverless Architecture OB 3.1.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:7f753ffd503baecf5d5073246ceeaf302dcf73709cb234a7f40cfed362ace493
3
+ size 97395474
10 - Security Architecture/004 Microservices OB 3.1.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:eb69f2536bc8a9a6b9e54e4de52291302518639303028f4c3b69b3e179891df6
3
+ size 135693215
10 - Security Architecture/005 Air Gapped OB 3.1.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:ab7b3f8ae4af31020d8dee0752882f7e2140201c0f6ea3d2b7001dc0d34f8e0b
3
+ size 99208855
10 - Security Architecture/006 Software-Defined Networking OB 3.1.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:38ff5c09641718366c45565821aaf767dbae05488e80840b8c16befcfc129f5d
3
+ size 219936591
10 - Security Architecture/007 On-Premises OB 3.1.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:b4e92596402ff78bdb273f7e3f3d752bc1e859ab7348c6ee0c4a98942328afd9
3
+ size 53459965
10 - Security Architecture/008 Centralized vs. Decentralized OB 3.1.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:7b69fff1ae23a2ae3f0de9286cf3ffd92fa111b02a2b82084f8234a8a5a18658
3
+ size 178712004
10 - Security Architecture/009 Virtualization OB 3.1.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:8bb61d45846d6513739bbeb3ace86ac2a86f1980a437e56e77ec08cd887c8993
3
+ size 301783477
10 - Security Architecture/010 Containerization OB 3.1.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:894f74391eee91494c903790eeae243fea3068ce0840cb08bc3c69e71de019cc
3
+ size 220510089
10 - Security Architecture/011 High Availability OB 3.1.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:5a93f0a1eb6b93a13f3b7bb16a8c12bb8c9372b74b956a5453ac0544cfa99ed7
3
+ size 186692724
10 - Security Architecture/013 ICS OB 3.1.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:5305d91a5764667386e2f0cdc270b3bbc5d8a5609e1200f1de342c1180bd1b90
3
+ size 204975036
20 - Security Governance and Privacy/006 Privacy OB 5.4_en.srt ADDED
@@ -0,0 +1,552 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ 1
2
+ 00:00:00,000 --> 00:00:04,000
3
+ The hottest topic in the world of cybersecurity right now is privacy.
4
+
5
+ 2
6
+ 00:00:04,000 --> 00:00:07,000
7
+ Did you guess that privacy is a big thing nowadays?
8
+
9
+ 3
10
+ 00:00:08,000 --> 00:00:13,000
11
+ Almost anytime you hear malware gets into an organization and steals the data, or hackers steals the
12
+
13
+ 4
14
+ 00:00:13,000 --> 00:00:18,000
15
+ data, or disgruntled employee steals the data, it's always about the loss of private data.
16
+
17
+ 5
18
+ 00:00:19,000 --> 00:00:22,000
19
+ So in this video, let's take a look at privacy.
20
+
21
+ 6
22
+ 00:00:22,000 --> 00:00:25,000
23
+ Just the entire topic of privacy.
24
+
25
+ 7
26
+ 00:00:25,000 --> 00:00:28,000
27
+ And there's a couple of terms that I want you guys to be familiar with.
28
+
29
+ 8
30
+ 00:00:28,000 --> 00:00:30,000
31
+ So if you see on your exam you're familiar with it.
32
+
33
+ 9
34
+ 00:00:30,000 --> 00:00:37,000
35
+ Privacy refers to the practices, policies, and legal requirements surrounding the protection of personal
36
+
37
+ 10
38
+ 00:00:37,000 --> 00:00:38,000
39
+ and sensitive data.
40
+
41
+ 11
42
+ 00:00:38,000 --> 00:00:40,000
43
+ Now, what data are we talking about?
44
+
45
+ 12
46
+ 00:00:40,000 --> 00:00:41,000
47
+ What is it that we're secure?
48
+
49
+ 13
50
+ 00:00:41,000 --> 00:00:45,000
51
+ Well, privacy information falls into two things.
52
+
53
+ 14
54
+ 00:00:45,000 --> 00:00:47,000
55
+ What's known as PII information.
56
+
57
+ 15
58
+ 00:00:49,000 --> 00:00:55,000
59
+ Are known as personal identifiable info and protected health, also known as personal health info.
60
+
61
+ 16
62
+ 00:00:55,000 --> 00:00:57,000
63
+ So PII and Phi.
64
+
65
+ 17
66
+ 00:00:57,000 --> 00:00:59,000
67
+ So what exactly is PII?
68
+
69
+ 18
70
+ 00:00:59,000 --> 00:01:05,000
71
+ Well, it's information that when used alone or with other relevant data, can identify the individual.
72
+
73
+ 19
74
+ 00:01:06,000 --> 00:01:08,000
75
+ And then there's Phi.
76
+
77
+ 20
78
+ 00:01:08,000 --> 00:01:15,000
79
+ Now this is the demographic information, medical history, tests and laboratory results, mental health
80
+
81
+ 21
82
+ 00:01:15,000 --> 00:01:22,000
83
+ conditions, insurance information or other information is generally collected to care for a person.
84
+
85
+ 22
86
+ 00:01:22,000 --> 00:01:25,000
87
+ Let me give you a couple of examples of what PII and Phi.
88
+
89
+ 23
90
+ 00:01:25,000 --> 00:01:26,000
91
+ So.
92
+
93
+ 24
94
+ 00:01:27,000 --> 00:01:34,000
95
+ Your address, your, uh, your email address, physical address, email, your phone number, your
96
+
97
+ 25
98
+ 00:01:34,000 --> 00:01:35,000
99
+ credit card information.
100
+
101
+ 26
102
+ 00:01:35,000 --> 00:01:41,000
103
+ That's going to be PII, what medication you're taking, what illnesses you have, what what was your
104
+
105
+ 27
106
+ 00:01:41,000 --> 00:01:43,000
107
+ recent blood tests and things like that.
108
+
109
+ 28
110
+ 00:01:43,000 --> 00:01:44,000
111
+ That would be Fi.
112
+
113
+ 29
114
+ 00:01:44,000 --> 00:01:49,000
115
+ These are both considered private information that falls under the terms of privacy, and they need
116
+
117
+ 30
118
+ 00:01:49,000 --> 00:01:50,000
119
+ to be protected.
120
+
121
+ 31
122
+ 00:01:50,000 --> 00:01:54,000
123
+ Privacy is a critical thing when it comes to the world of security.
124
+
125
+ 32
126
+ 00:01:54,000 --> 00:02:01,000
127
+ Now, if there's one thing we know about privacy is that it's heavily regulated, not just locally.
128
+
129
+ 33
130
+ 00:02:02,000 --> 00:02:05,000
131
+ But sometimes regionally, nationally and globally.
132
+
133
+ 34
134
+ 00:02:05,000 --> 00:02:11,000
135
+ Laws like GDPR in Europe, CcpA, which is done in California, which is similar to GDPR.
136
+
137
+ 35
138
+ 00:02:11,000 --> 00:02:18,000
139
+ Basically, these are privacy laws that is out there to secure people's private information PII and
140
+
141
+ 36
142
+ 00:02:19,000 --> 00:02:20,000
143
+ Phi.
144
+
145
+ 37
146
+ 00:02:20,000 --> 00:02:25,000
147
+ Now, the first thing we want to talk about is that you're going to have local or regional laws that
148
+
149
+ 38
150
+ 00:02:25,000 --> 00:02:27,000
151
+ you have to follow.
152
+
153
+ 39
154
+ 00:02:27,000 --> 00:02:31,000
155
+ These are going to address specific things in a smaller geographic community.
156
+
157
+ 40
158
+ 00:02:31,000 --> 00:02:34,000
159
+ These laws can be very detailed or stricter.
160
+
161
+ 41
162
+ 00:02:34,000 --> 00:02:40,000
163
+ For example, in a town they may have a certain way that private data should be stored.
164
+
165
+ 42
166
+ 00:02:40,000 --> 00:02:44,000
167
+ Or if you want to do business in this town, you have to secure the private data.
168
+
169
+ 43
170
+ 00:02:44,000 --> 00:02:47,000
171
+ This is where you have to store it in a certain pattern.
172
+
173
+ 44
174
+ 00:02:47,000 --> 00:02:53,000
175
+ Now, you know that's local legal ramifications or local legal laws.
176
+
177
+ 45
178
+ 00:02:53,000 --> 00:02:58,000
179
+ Then you have national laws that are broader in scope that the entire country has to follow.
180
+
181
+ 46
182
+ 00:02:59,000 --> 00:03:02,000
183
+ This is how organizations across an entire country is going to have to follow.
184
+
185
+ 47
186
+ 00:03:02,000 --> 00:03:08,000
187
+ Things like this is going to include like HIPAA compliance, which is every single clinic and hospital
188
+
189
+ 48
190
+ 00:03:08,000 --> 00:03:10,000
191
+ within the United States have to follow.
192
+
193
+ 49
194
+ 00:03:12,000 --> 00:03:18,000
195
+ Then you can have global laws that anybody wants to do business in this country.
196
+
197
+ 50
198
+ 00:03:18,000 --> 00:03:19,000
199
+ They got to follow it.
200
+
201
+ 51
202
+ 00:03:19,000 --> 00:03:25,000
203
+ Now this is especially organizations that falls into operating internationally.
204
+
205
+ 52
206
+ 00:03:25,000 --> 00:03:28,000
207
+ You're dealing with data across national borders.
208
+
209
+ 53
210
+ 00:03:28,000 --> 00:03:34,000
211
+ So for example with with GDPR which is a general data protection.
212
+
213
+ 54
214
+ 00:03:34,000 --> 00:03:43,000
215
+ This particular regulation is done to protect the privacy data of the EU citizens, now EU citizens.
216
+
217
+ 55
218
+ 00:03:44,000 --> 00:03:49,000
219
+ Doesn't matter what country they're in, their data needs to be protected by GDPR.
220
+
221
+ 56
222
+ 00:03:49,000 --> 00:03:53,000
223
+ Doesn't matter what country your organization is in, you need to follow GDPR.
224
+
225
+ 57
226
+ 00:03:53,000 --> 00:04:01,000
227
+ So if you work in a company that follows or works in multiple countries, that company needs to follow
228
+
229
+ 58
230
+ 00:04:01,000 --> 00:04:03,000
231
+ all these laws across all these different countries.
232
+
233
+ 59
234
+ 00:04:03,000 --> 00:04:07,000
235
+ And that, of course, is very complex to do.
236
+
237
+ 60
238
+ 00:04:07,000 --> 00:04:11,000
239
+ Now, there are some terms when it comes to processing private data.
240
+
241
+ 61
242
+ 00:04:12,000 --> 00:04:13,000
243
+ A couple of terms.
244
+
245
+ 62
246
+ 00:04:13,000 --> 00:04:14,000
247
+ What's called the data subject.
248
+
249
+ 63
250
+ 00:04:15,000 --> 00:04:18,000
251
+ Data controllers and data processor.
252
+
253
+ 64
254
+ 00:04:18,000 --> 00:04:19,000
255
+ So let's go through this.
256
+
257
+ 65
258
+ 00:04:19,000 --> 00:04:24,000
259
+ A data subject is an individual whose personal data is processed by an organization.
260
+
261
+ 66
262
+ 00:04:24,000 --> 00:04:28,000
263
+ You have to protect the rights and privacy of the data subjects.
264
+
265
+ 67
266
+ 00:04:28,000 --> 00:04:36,000
267
+ This includes ensuring consistent, uh, consistency for the data, uh, making sure you get consent
268
+
269
+ 68
270
+ 00:04:36,000 --> 00:04:41,000
271
+ for the data and processing and allowing the data to be processed correctly.
272
+
273
+ 69
274
+ 00:04:41,000 --> 00:04:46,000
275
+ Now, keep in mind the data subject is just a user to the website.
276
+
277
+ 70
278
+ 00:04:46,000 --> 00:04:51,000
279
+ If you're going to Facebook right now, you're the data subject on a website.
280
+
281
+ 71
282
+ 00:04:51,000 --> 00:04:54,000
283
+ You're going to have what's called a controller and a processor.
284
+
285
+ 72
286
+ 00:04:54,000 --> 00:05:00,000
287
+ In privacy terms, a controller is an entity that determines the purpose and means of person processing.
288
+
289
+ 73
290
+ 00:05:00,000 --> 00:05:09,000
291
+ Personal data A processor is an entity that the that processes the data on behalf of the controller.
292
+
293
+ 74
294
+ 00:05:09,000 --> 00:05:09,000
295
+ Let me explain.
296
+
297
+ 75
298
+ 00:05:09,000 --> 00:05:11,000
299
+ I'll give you guys a couple of examples of this.
300
+
301
+ 76
302
+ 00:05:11,000 --> 00:05:14,000
303
+ So you have a data subject a controller and a processor.
304
+
305
+ 77
306
+ 00:05:14,000 --> 00:05:16,000
307
+ Let's say you have a website.
308
+
309
+ 78
310
+ 00:05:17,000 --> 00:05:23,000
311
+ And you own a website, you're going to determine what data we collect.
312
+
313
+ 79
314
+ 00:05:23,000 --> 00:05:29,000
315
+ You're going to then determine how you're going to store that data, why you need to collect the data.
316
+
317
+ 80
318
+ 00:05:29,000 --> 00:05:30,000
319
+ Then you have a website user.
320
+
321
+ 81
322
+ 00:05:30,000 --> 00:05:34,000
323
+ So the website user is just coming to browse what you have on your website.
324
+
325
+ 82
326
+ 00:05:34,000 --> 00:05:36,000
327
+ Then you have something like Google Analytics.
328
+
329
+ 83
330
+ 00:05:36,000 --> 00:05:38,000
331
+ Now Google Analytics is just Google.
332
+
333
+ 84
334
+ 00:05:38,000 --> 00:05:43,000
335
+ And all they're doing is they're processing all the data on your website to see how many visitors you
336
+
337
+ 85
338
+ 00:05:43,000 --> 00:05:45,000
339
+ had and how long they stayed on your website.
340
+
341
+ 86
342
+ 00:05:46,000 --> 00:05:52,000
343
+ So let's go through the three, the three terms the data subject, controller and processor.
344
+
345
+ 87
346
+ 00:05:52,000 --> 00:05:55,000
347
+ So the data subject is just users.
348
+
349
+ 88
350
+ 00:05:55,000 --> 00:06:01,000
351
+ The data controller is you, the data controller is who's going to determine, okay, why do we need
352
+
353
+ 89
354
+ 00:06:01,000 --> 00:06:02,000
355
+ this data.
356
+
357
+ 90
358
+ 00:06:02,000 --> 00:06:04,000
359
+ Why where are we going to store this data.
360
+
361
+ 91
362
+ 00:06:06,000 --> 00:06:07,000
363
+ What are we going to do with this data.
364
+
365
+ 92
366
+ 00:06:08,000 --> 00:06:16,000
367
+ Now who's getting the data are processing the data and coming out with specific outputs.
368
+
369
+ 93
370
+ 00:06:16,000 --> 00:06:17,000
371
+ Google analytics.
372
+
373
+ 94
374
+ 00:06:17,000 --> 00:06:20,000
375
+ So Google is going to be the processor.
376
+
377
+ 95
378
+ 00:06:20,000 --> 00:06:22,000
379
+ You are the data controller.
380
+
381
+ 96
382
+ 00:06:22,000 --> 00:06:25,000
383
+ And then the person using a website is the subject.
384
+
385
+ 97
386
+ 00:06:26,000 --> 00:06:30,000
387
+ Another time you want to be, uh, familiar with is what's called ownership.
388
+
389
+ 98
390
+ 00:06:30,000 --> 00:06:33,000
391
+ Data ownership refers to the rights and control of the data.
392
+
393
+ 99
394
+ 00:06:33,000 --> 00:06:38,000
395
+ Like who owns the data, who's controlling the data, what they determine what you should do with the
396
+
397
+ 100
398
+ 00:06:38,000 --> 00:06:39,000
399
+ data.
400
+
401
+ 101
402
+ 00:06:40,000 --> 00:06:46,000
403
+ It relates to the ownership of personal data by data subjects and the organizations responsibility.
404
+
405
+ 102
406
+ 00:06:46,000 --> 00:06:47,000
407
+ Now.
408
+
409
+ 103
410
+ 00:06:47,000 --> 00:06:52,000
411
+ One thing an organization should always do is have data inventory.
412
+
413
+ 104
414
+ 00:06:52,000 --> 00:06:54,000
415
+ What exactly is that?
416
+
417
+ 105
418
+ 00:06:54,000 --> 00:07:00,000
419
+ Well, an organization, and I believe every company should do this, is to go and make an inventory
420
+
421
+ 106
422
+ 00:07:00,000 --> 00:07:03,000
423
+ of all the different data that they have collected.
424
+
425
+ 107
426
+ 00:07:03,000 --> 00:07:08,000
427
+ Sometimes organizations are very surprised to see what they have collected.
428
+
429
+ 108
430
+ 00:07:08,000 --> 00:07:10,000
431
+ What exactly have they hold?
432
+
433
+ 109
434
+ 00:07:10,000 --> 00:07:11,000
435
+ Where is it stored?
436
+
437
+ 110
438
+ 00:07:11,000 --> 00:07:14,000
439
+ How long have they had it?
440
+
441
+ 111
442
+ 00:07:15,000 --> 00:07:17,000
443
+ How is it being used?
444
+
445
+ 112
446
+ 00:07:17,000 --> 00:07:22,000
447
+ So you want to make sure that you do this data inventory to see basically what data do you have.
448
+
449
+ 113
450
+ 00:07:22,000 --> 00:07:28,000
451
+ And then the other thing is certain regulations will dictate how long you can hold certain data for.
452
+
453
+ 114
454
+ 00:07:28,000 --> 00:07:32,000
455
+ So data retention policies must align with legal requirements.
456
+
457
+ 115
458
+ 00:07:32,000 --> 00:07:36,000
459
+ For example, one law may specify that you need to hold the data for eight years.
460
+
461
+ 116
462
+ 00:07:36,000 --> 00:07:38,000
463
+ Another law may say you need to hold it for 20 years.
464
+
465
+ 117
466
+ 00:07:38,000 --> 00:07:40,000
467
+ So make sure you know the laws.
468
+
469
+ 118
470
+ 00:07:41,000 --> 00:07:44,000
471
+ Here's a firm you're probably going to see on your exam.
472
+
473
+ 119
474
+ 00:07:44,000 --> 00:07:50,000
475
+ It's called right to be forgotten and this is something that you're probably familiar with right now.
476
+
477
+ 120
478
+ 00:07:50,000 --> 00:07:56,000
479
+ Do you guys know you can go and tell Facebook to delete your data and your profile and Google also.
480
+
481
+ 121
482
+ 00:07:57,000 --> 00:08:01,000
483
+ Just Google the steps of how to do that, but that's a right to be forgotten.
484
+
485
+ 122
486
+ 00:08:01,000 --> 00:08:08,000
487
+ We now have to give this right, and GDPR makes it pretty much mandatory that there is a right to be
488
+
489
+ 123
490
+ 00:08:08,000 --> 00:08:09,000
491
+ forgotten.
492
+
493
+ 124
494
+ 00:08:09,000 --> 00:08:17,000
495
+ Now, it's also known the right to erasure is a principle that allows individuals to request a deletion
496
+
497
+ 125
498
+ 00:08:17,000 --> 00:08:21,000
499
+ of their personal data when there's no compelling reason for it to be continued processing.
500
+
501
+ 126
502
+ 00:08:22,000 --> 00:08:25,000
503
+ For example, maybe you don't use Facebook anymore.
504
+
505
+ 127
506
+ 00:08:25,000 --> 00:08:28,000
507
+ Maybe you never logged in in the last two years and you don't plan to.
508
+
509
+ 128
510
+ 00:08:28,000 --> 00:08:31,000
511
+ So you can go to Facebook and you could say, well, you know what?
512
+
513
+ 129
514
+ 00:08:31,000 --> 00:08:33,000
515
+ I don't want my data stored here anymore.
516
+
517
+ 130
518
+ 00:08:34,000 --> 00:08:37,000
519
+ So that's known as a right to be forgotten.
520
+
521
+ 131
522
+ 00:08:37,000 --> 00:08:40,000
523
+ And what they're going to do is they're going to delete your profile and all of your data that they
524
+
525
+ 132
526
+ 00:08:40,000 --> 00:08:43,000
527
+ have on their systems that have they ever hacked or anything like that.
528
+
529
+ 133
530
+ 00:08:43,000 --> 00:08:45,000
531
+ They can't get your data.
532
+
533
+ 134
534
+ 00:08:45,000 --> 00:08:45,000
535
+ Okay.
536
+
537
+ 135
538
+ 00:08:45,000 --> 00:08:48,000
539
+ Make sure you understand that privacy is a very serious subject.
540
+
541
+ 136
542
+ 00:08:48,000 --> 00:08:55,000
543
+ And although most of the time what we do with privacy and how we manage privacy is going to be managed
544
+
545
+ 137
546
+ 00:08:55,000 --> 00:09:02,000
547
+ by regulations or dictated by different regulations, keep in mind that even if it's not, it's something
548
+
549
+ 138
550
+ 00:09:02,000 --> 00:09:07,000
551
+ that you have to follow all the time because it is super important to protect our customers information.
552
+
20 - Security Governance and Privacy/007 Quick Quiz.html ADDED
@@ -0,0 +1,479 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ <!DOCTYPE html>
2
+ <html lang="en">
3
+ <head>
4
+ <meta charset="UTF-8" />
5
+ <meta http-equiv="X-UA-Compatible" content="IE=edge" />
6
+ <meta name="viewport" content="width=device-width, initial-scale=1.0" />
7
+ <title>Quiz</title>
8
+ <style>
9
+ * {
10
+ font-family: system-ui, -apple-system, BlinkMacSystemFont, "Segoe UI", Roboto, Oxygen, Ubuntu, Cantarell,
11
+ "Open Sans", "Helvetica Neue", sans-serif;
12
+ margin: 0;
13
+ padding: 0;
14
+ box-sizing: border-box;
15
+ font-size: 16px;
16
+ }
17
+
18
+ main {
19
+ padding-top: 48px;
20
+ }
21
+
22
+ :root {
23
+ --large-device-width: 850px;
24
+ --primary-color: #0f172a;
25
+ --secondary-color: #020617;
26
+ --primary-text-color: #c7d1dd;
27
+ --secondary-text-color: #061602;
28
+ --success-background: hsl(159, 82%, 24%);
29
+ --success-foreground: hsl(164, 86%, 16%);
30
+ --success: hsl(160, 84%, 39%);
31
+ --danger: #ef4444;
32
+ --warning: #f59e0b;
33
+ --info-background: hsl(218, 81%, 8%);
34
+ --info-foreground: hsl(217, 91%, 85%);
35
+ --border-color: #d1d7dc;
36
+ --check-box-size: 20px;
37
+ /* control the size */
38
+ --check-box-color: var(--info-foreground);
39
+ /* the active color */
40
+ }
41
+
42
+ body {
43
+ position: relative;
44
+ background-color: #020617;
45
+ color: var(--primary-text-color);
46
+ }
47
+
48
+ #score-stats-container {
49
+ position: fixed;
50
+ z-index: 10;
51
+ top: 0;
52
+ height: 40px;
53
+ width: 100%;
54
+ background-color: var(--info-background);
55
+
56
+ padding: 0px 16px;
57
+ color: var(--info-foreground);
58
+ font-weight: 600;
59
+ display: flex;
60
+ align-items: center;
61
+ justify-content: space-between;
62
+ }
63
+
64
+ #quiz-container {
65
+ border-radius: 8px;
66
+ display: flex;
67
+ gap: 16px;
68
+ flex-direction: column;
69
+ }
70
+
71
+ input[type="radio"] {
72
+ height: var(--check-box-size);
73
+ aspect-ratio: 1;
74
+ border: calc(var(--check-box-size) / 8) solid #939393;
75
+ padding: calc(var(--check-box-size) / 8);
76
+ background: radial-gradient(farthest-side, var(--check-box-color) 94%, #0000) 50%/0 0 no-repeat
77
+ content-box;
78
+ border-radius: 50%;
79
+ outline-offset: calc(var(--check-box-size) / 10);
80
+ -webkit-appearance: none;
81
+ -moz-appearance: none;
82
+ appearance: none;
83
+ cursor: pointer;
84
+ font-size: inherit;
85
+ transition: 0.3s;
86
+ }
87
+
88
+ input[type="radio"]:checked {
89
+ border-color: var(--check-box-color);
90
+ background-size: 100% 100%;
91
+ }
92
+
93
+ input[type="radio"]:disabled {
94
+ background: linear-gradient(#939393 0 0) 50%/100% 20% no-repeat content-box;
95
+ opacity: 0.5;
96
+ cursor: not-allowed;
97
+ }
98
+
99
+ label {
100
+ display: inline-flex;
101
+ align-items: center;
102
+ gap: 10px;
103
+ cursor: pointer;
104
+ padding: 4px 6px;
105
+ border-radius: 4px;
106
+ }
107
+
108
+ @media (max-width: 767px) {
109
+ input[type="radio"],
110
+ label {
111
+ cursor: default;
112
+ }
113
+
114
+ #quiz-container {
115
+ margin-left: 8px;
116
+ margin-right: 8px;
117
+ }
118
+ }
119
+
120
+ /* PC (Desktop devices) */
121
+ @media (min-width: 768px) {
122
+ body {
123
+ display: flex;
124
+ justify-content: center;
125
+ }
126
+
127
+ main {
128
+ max-width: var(--large-device-width);
129
+ }
130
+
131
+ #score-stats-container {
132
+ max-width: var(--large-device-width);
133
+ }
134
+
135
+ dialog {
136
+ max-width: var(--large-device-width);
137
+ }
138
+ }
139
+
140
+ @media print {
141
+ input[type="radio"] {
142
+ background: none !important;
143
+ border-color: #939393 !important;
144
+ }
145
+
146
+ input[type="radio"]:checked {
147
+ border-color: #939393 !important;
148
+ }
149
+ }
150
+
151
+ .question-lable {
152
+ display: flex;
153
+ align-items: center;
154
+ gap: 8px;
155
+ }
156
+
157
+ button {
158
+ -webkit-tap-highlight-color: transparent;
159
+ -webkit-touch-callout: none;
160
+ -webkit-user-select: none;
161
+ user-select: none;
162
+ outline: none;
163
+ position: relative;
164
+ overflow: hidden;
165
+ cursor: pointer;
166
+ }
167
+
168
+ .button {
169
+ background-color: var(--success-background);
170
+ border: none;
171
+ color: #f4f5f7;
172
+ opacity: 0.8;
173
+ font-size: 18px;
174
+ flex-grow: 1;
175
+ padding: 8px 16px;
176
+ border-radius: 8px;
177
+ }
178
+
179
+ .button:hover {
180
+ opacity: 1;
181
+ }
182
+
183
+ .explanation-btn {
184
+ border: none;
185
+ color: var(--success);
186
+ background-color: transparent;
187
+ }
188
+
189
+ #submit-button:active::after {
190
+ background-color: #ef4444;
191
+ }
192
+
193
+ .single-question-container {
194
+ background-color: var(--primary-color);
195
+ display: flex;
196
+ flex-direction: column;
197
+ gap: 8px;
198
+ padding: 16px;
199
+ border-radius: 8px;
200
+ }
201
+
202
+ #modal-content {
203
+ padding: 16px;
204
+ line-height: 24px;
205
+ }
206
+
207
+ dialog::backdrop {
208
+ background: rgba(0, 0, 0, 0.5);
209
+ }
210
+
211
+ dialog {
212
+ position: fixed;
213
+ border: 1px solid var(--border-color);
214
+ background-color: var(--primary-color);
215
+ color: rgb(240, 241, 248);
216
+ padding: 16px;
217
+ border-radius: 8px;
218
+ width: 80vw;
219
+ max-height: 80vh;
220
+ overflow: auto;
221
+ top: 50%;
222
+ left: 50%;
223
+ -webkit-transform: translateX(-50%) translateY(-50%);
224
+ -moz-transform: translateX(-50%) translateY(-50%);
225
+ -ms-transform: translateX(-50%) translateY(-50%);
226
+ transform: translateX(-50%) translateY(-50%);
227
+ }
228
+
229
+ #close-modal-btn {
230
+ position: absolute;
231
+ top: 4px;
232
+ right: 4px;
233
+ padding: 2px 8px;
234
+ border-radius: 2px;
235
+ border: none;
236
+ background-color: var(--danger);
237
+ }
238
+
239
+ .correct-answer label {
240
+ border: 2px solid var(--success);
241
+ width: 100%;
242
+ }
243
+
244
+ .incorrect-answer label {
245
+ border: 2px solid var(--danger);
246
+ width: 100%;
247
+ }
248
+
249
+ .options-container {
250
+ display: flex;
251
+ flex-direction: column;
252
+ gap: 4px;
253
+ }
254
+
255
+ #quiz-meta-container {
256
+ border-radius: 8px;
257
+ background-color: var(--primary-color);
258
+ margin-bottom: 12px;
259
+ padding: 8px;
260
+ }
261
+
262
+ #quiz-title {
263
+ text-align: center;
264
+ font-size: 24px;
265
+ margin-bottom: 8px;
266
+ }
267
+
268
+ #quiz-description {
269
+ line-height: 1.5;
270
+ padding: 2px 6px;
271
+ }
272
+ </style>
273
+ </head>
274
+
275
+ <body onload="main()">
276
+ <main>
277
+ <section id="quiz-meta-container">
278
+ <h1 id="quiz-title"></h1>
279
+ <p id="quiz-description"></p>
280
+ </section>
281
+ <section id="score-stats-container">
282
+ <div id="score-card">
283
+ Score: <span id="current-score">999</span> of
284
+ <span id="pass-percent">999%</span>
285
+ </div>
286
+ <div>Correct: <span id="correct-answers">999</span></div>
287
+ <div>Incorrect: <span id="wrong-answers">999</span></div>
288
+ </section>
289
+
290
+ <section id="quiz-container"></section>
291
+
292
+ <dialog id="modal" class="modal-container">
293
+ <div id="modal-content">
294
+ <p id="modal-text"></p>
295
+ </div>
296
+ </dialog>
297
+ </main>
298
+
299
+ <script>
300
+ const quizData = {"quiz_id": 6180176, "quiz_description": null, "quiz_title": "Quick Quiz", "pass_percent": null, "questions": [{"_class": "assessment", "id": 74731142, "assessment_type": "multiple-choice", "prompt": {"question": "<p>A corporation is revising its security policies to align with current best practices. Which policy should they prioritize updating to ensure compliance with data protection laws?</p>", "relatedLectureIds": "", "feedbacks": ["", "Updating the Information Security Policy should be a priority for the corporation to ensure compliance with current data protection laws. This policy forms the backbone of the organization's security posture, outlining the standards, guidelines, and procedures for protecting sensitive data. While AUP, Business Continuity, and Disaster Recovery plans are important, the Information Security Policy directly addresses the comprehensive security measures and practices that align with legal requirements for data protection.", "", ""], "answers": ["<p>Acceptable Use Policy (AUP)</p>", "<p>Information Security Policy</p>", "<p>Business Continuity Plan</p>", "<p>Disaster Recovery Plan</p>"]}, "correct_response": ["b"], "section": "", "question_plain": "A corporation is revising its security policies to align with current best practices. Which policy should they prioritize updating to ensure compliance with data protection laws?", "related_lectures": []}, {"_class": "assessment", "id": 74731540, "assessment_type": "multiple-choice", "prompt": {"question": "<p>An e-commerce company is expanding globally and needs to ensure compliance with various privacy laws. What aspect of privacy governance should they focus on?</p>", "relatedLectureIds": "", "feedbacks": ["As the e-commerce company expands globally, implementing a robust Data Inventory and Retention policy is critical to comply with various international privacy laws. This policy should address how data is collected, stored, used, and retained, ensuring compliance with regulations like GDPR, which includes provisions like the right to be forgotten. Additionally, it should consider the legal implications and requirements in different regions. ", "", "", ""], "answers": ["<p>Implementing a robust Data Inventory and Retention policy</p>", "<p>Reviewing Physical Security Procedures</p>", "<p>Updating their Change Management Playbook</p>", "<p>Modifying their Access Control Procedures</p>"]}, "correct_response": ["a"], "section": "", "question_plain": "An e-commerce company is expanding globally and needs to ensure compliance with various privacy laws. What aspect of privacy governance should they focus on?", "related_lectures": []}, {"_class": "assessment", "id": 74731548, "assessment_type": "multiple-choice", "prompt": {"question": "<p>A multinational corporation is reviewing its compliance reporting mechanisms. What approach should they prioritize to effectively manage compliance across different regions?</p>", "relatedLectureIds": "", "feedbacks": ["Centralizing the compliance reporting structure is a strategic approach for a multinational corporation to manage compliance effectively across different regions. This approach allows for a unified view of compliance status, enabling better oversight, consistency, and coordination of compliance efforts across various jurisdictions. It helps in identifying and addressing compliance gaps and streamlines the reporting process. While decentralization can offer local flexibility, it may lack the cohesive overview provided by a centralized approach. ", "", "", ""], "answers": ["<p>Centralizing their compliance reporting structure</p>", "<p>Decentralizing their compliance reporting structure</p>", "<p>Focusing solely on internal compliance reporting</p>", "<p>Implementing automated compliance monitoring</p>"]}, "correct_response": ["a"], "section": "", "question_plain": "A multinational corporation is reviewing its compliance reporting mechanisms. What approach should they prioritize to effectively manage compliance across different regions?", "related_lectures": []}, {"_class": "assessment", "id": 74731554, "assessment_type": "multiple-choice", "prompt": {"question": "<p>A tech company is facing fines and reputational damage due to non-compliance with industry standards. What should they implement to prevent future non-compliance?</p>", "relatedLectureIds": "", "feedbacks": ["", "Conducting more thorough Due Diligence and Compliance Monitoring is crucial for the tech company to prevent future non-compliance issues. This involves regularly reviewing and assessing the company\u2019s adherence to relevant industry standards and regulations. Through diligent compliance monitoring, the company can identify and rectify potential compliance issues proactively, thus avoiding fines and protecting its reputation. ", "", ""], "answers": ["<p>Enhancing their Disaster Recovery Plan</p>", "<p>Conducting more thorough Due Diligence and Compliance Monitoring</p>", "<p>Focusing on updating their Business Continuity Plan</p>", "<p>Revising their Physical Security Procedures</p>"]}, "correct_response": ["b"], "section": "", "question_plain": "A tech company is facing fines and reputational damage due to non-compliance with industry standards. What should they implement to prevent future non-compliance?", "related_lectures": []}, {"_class": "assessment", "id": 74731572, "assessment_type": "multiple-choice", "prompt": {"question": "<p>A healthcare organization needs to manage the access and processing of sensitive patient data. What roles should they define to ensure proper data governance?</p>", "relatedLectureIds": "", "feedbacks": ["Defining roles such as Data Owners and Data Processors is critical in a healthcare organization for proper governance of sensitive patient data. Data Owners are responsible for defining the purposes and means of data processing, while Data Processors handle the actual processing of data as per the owners' instructions. ", "", "", ""], "answers": ["<p>Data Owners and Processors</p>", "<p>Centralized IT Committee members</p>", "<p>Decentralized Department Heads</p>", "<p>External Compliance Auditors</p>"]}, "correct_response": ["a"], "section": "", "question_plain": "A healthcare organization needs to manage the access and processing of sensitive patient data. What roles should they define to ensure proper data governance?", "related_lectures": []}]};
301
+ let correct = new Set();
302
+ let incorrect = new Set();
303
+ let totalNumberOfQuestions = 0;
304
+ const quizTitle = quizData.quiz_title;
305
+ const quizDescription = quizData.quiz_description;
306
+ const questionData = quizData.questions;
307
+ const passPercent = quizData.pass_percent;
308
+ const modalTextElement = document.getElementById("modal-text");
309
+ const quizContainerElement = document.getElementById("quiz-container");
310
+
311
+ const dialog = document.querySelector("dialog");
312
+ const showButton = document.getElementById("view-explanatin");
313
+ const closeButton = document.getElementById("close-modal-btn");
314
+ const quizTitleElement = document.getElementById("quiz-title");
315
+ const quizDescriptionElement = document.getElementById("quiz-description");
316
+
317
+ function main() {
318
+ // update quiz meta data
319
+ document.title = quizTitle;
320
+ quizTitleElement.innerHTML = quizTitle;
321
+ quizDescriptionElement.innerHTML = quizDescription;
322
+
323
+ const passPercentElement = document.getElementById("pass-percent");
324
+ passPercentElement.innerHTML = passPercent + "%";
325
+ totalNumberOfQuestions = questionData.length;
326
+ // shuffle the questionData to randomize the order of the questions
327
+ for (let i = questionData.length - 1; i > 0; i--) {
328
+ const j = Math.floor(Math.random() * (i + 1));
329
+ [questionData[i], questionData[j]] = [questionData[j], questionData[i]];
330
+ }
331
+
332
+ let formattedQuestions = questionData.map(formatSingleQuestionData);
333
+ updateScore();
334
+ // display the formattedQuestions
335
+ formattedQuestions.forEach((question, idx) => {
336
+ renderSingleQuestion(question, idx + 1);
337
+ });
338
+ }
339
+
340
+ /**
341
+ * Formats the question data from the given QuizData object.
342
+ *
343
+ * @param {Object} singleQuizData - The singleQuizData object containing prompt and correct_response.
344
+ * @return {Object} The formatted question object with the following properties:
345
+ * - id: The ID of the question.
346
+ * - question: The text of the question.
347
+ * - answers: The array of answer options.
348
+ * - correctAnswer: The text of the correct answer.
349
+ * - explanation: The explanation of the correct answer.
350
+ */
351
+ function formatSingleQuestionData(singleQuizData = null) {
352
+ const { prompt, correct_response, id } = singleQuizData;
353
+ const questionText = prompt.question;
354
+ const answers = prompt.answers;
355
+ const correctAnswer = correct_response[0];
356
+ const correctAnswerText = answers[correctAnswer.toLowerCase().charCodeAt(0) - 97];
357
+ const questionObj = {
358
+ id: id,
359
+ question: questionText,
360
+ answers: answers,
361
+ correctAnswer: correctAnswerText,
362
+ explanation: prompt?.explanation || "",
363
+ };
364
+ return questionObj;
365
+ }
366
+
367
+ /**
368
+ * Renders a single question with its options and submit button.
369
+ *
370
+ * @param {Object} singleQuestionData - The data of the question to render.
371
+ * @param {number} rootIndex - The index of the question in the quiz.
372
+ * @return {void} return nothing.
373
+ */
374
+
375
+ const renderSingleQuestion = (singleQuestionData = {}, rootIndex = 1) => {
376
+ const { id, explanation, answers, correctAnswer, question } = singleQuestionData;
377
+ // shuffle the answers to randomize the order of the answers
378
+ for (let i = answers.length - 1; i > 0; i--) {
379
+ const j = Math.floor(Math.random() * (i + 1));
380
+ [answers[i], answers[j]] = [answers[j], answers[i]];
381
+ }
382
+ const optionsHTML = answers
383
+ .map((option, index) => {
384
+ const optionId = `${id}_${index}`;
385
+
386
+ return `
387
+ <div class="question-lable">
388
+ <input type="radio" id="${optionId}" name="${"answer"}" value="${option}" />
389
+ <label for="${optionId}">${option}</label>
390
+ </div>
391
+ `;
392
+ })
393
+
394
+ .join("");
395
+
396
+ const container = document.createElement("div");
397
+ container.innerHTML = `
398
+ <form data-correct-answer="${correctAnswer}" data-question-id="${id}" class="single-question-container" onsubmit="submitButtonListener(event)">
399
+ <div style="display: flex;justify-content: space-between;">
400
+ <p style="font-weight: 600">Question ${rootIndex}:</p>
401
+ <button type="button" onclick="renderExplanation(event)" id="${`explanation-${id}`}" data-explanation="${explanation}" class="explanation-btn">View Explanation</button>
402
+ </div>
403
+ <p style="margin-bottom: 8px;line-height: 1.5">${question}</p>
404
+ <div class="options-container">
405
+ ${optionsHTML}
406
+ </div>
407
+ <div style="display: flex; gap: 8px;">
408
+ <button type="submit" id="submit-button" class="button">Submit</button>
409
+ </div>
410
+ </form>
411
+ `;
412
+ quizContainerElement.appendChild(container);
413
+ };
414
+
415
+ /**
416
+ * Updates the score on the page based on the number of correct and incorrect answers.
417
+ *
418
+ * @return {void} This function does not return a value.
419
+ */
420
+ function updateScore() {
421
+ const currentParcentageElement = document.getElementById("current-score");
422
+ const correctAnswerElement = document.getElementById("correct-answers");
423
+ const wrongAnswerElement = document.getElementById("wrong-answers");
424
+ correctAnswerElement.innerHTML = correct.size;
425
+ wrongAnswerElement.innerHTML = incorrect.size;
426
+ const score = Number((correct.size / totalNumberOfQuestions) * 100).toFixed(2);
427
+ currentParcentageElement.innerHTML = score;
428
+ }
429
+
430
+ /**
431
+ * Handles the event when the submit button is clicked.
432
+ *
433
+ * @param {Event} e - The event object.
434
+ * @return {void} This function does not return anything.
435
+ */
436
+ const submitButtonListener = (e) => {
437
+ e.preventDefault();
438
+ const formData = new FormData(e.target);
439
+ const form = e.target;
440
+ const selectedOption = e.target.querySelector('input[type="radio"]:checked');
441
+ if (!selectedOption) {
442
+ alert("Please select an answer!");
443
+ return;
444
+ }
445
+
446
+ let isCorrect = false;
447
+ const { answer: userAnswer } = Object.fromEntries(formData.entries());
448
+ const correctAnswer = e.target.dataset.correctAnswer;
449
+ const questionId = e.target.dataset.questionId;
450
+ if (userAnswer == correctAnswer) {
451
+ correct.add(questionId);
452
+ incorrect.delete(questionId);
453
+ isCorrect = true;
454
+ } else {
455
+ incorrect.add(e.target.dataset.questionId);
456
+ correct.delete(questionId);
457
+ }
458
+ updateScore();
459
+
460
+ const resultClass = isCorrect ? "correct-answer" : "incorrect-answer";
461
+
462
+ form.querySelectorAll(".question-lable").forEach((label) => {
463
+ label.classList.remove("correct-answer", "incorrect-answer");
464
+ });
465
+ selectedOption.closest(".question-lable").classList.add(resultClass);
466
+ };
467
+
468
+ function renderExplanation(ev) {
469
+ modalTextElement.innerHTML = ev.target.dataset?.explanation || "no explanation found";
470
+ dialog.showModal();
471
+ dialog.addEventListener("click", (event) => {
472
+ if (event.target === dialog) {
473
+ dialog.close();
474
+ }
475
+ });
476
+ }
477
+ </script>
478
+ </body>
479
+ </html>
21 - Risk Management/001 Risk Terms OB 5.2_en.srt ADDED
@@ -0,0 +1,416 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ 1
2
+ 00:00:00,000 --> 00:00:03,000
3
+ Everything we do in life has risks.
4
+
5
+ 2
6
+ 00:00:03,000 --> 00:00:05,000
7
+ Now, what exactly is risk?
8
+
9
+ 3
10
+ 00:00:05,000 --> 00:00:08,000
11
+ Well, in this section I want to define risk.
12
+
13
+ 4
14
+ 00:00:08,000 --> 00:00:12,000
15
+ And I want to go through some terms with you guys that you should be familiar with.
16
+
17
+ 5
18
+ 00:00:12,000 --> 00:00:14,000
19
+ So first of all, what exactly is risk.
20
+
21
+ 6
22
+ 00:00:14,000 --> 00:00:19,000
23
+ Well, risk is the probability of a threat exploiting a vulnerability.
24
+
25
+ 7
26
+ 00:00:19,000 --> 00:00:22,000
27
+ That's a generic definition of risk.
28
+
29
+ 8
30
+ 00:00:22,000 --> 00:00:28,000
31
+ The first thing we want to talk about is risk is is probable risk is not guaranteed to happen if something
32
+
33
+ 9
34
+ 00:00:28,000 --> 00:00:29,000
35
+ is considered to be a risk.
36
+
37
+ 10
38
+ 00:00:29,000 --> 00:00:34,000
39
+ We're basically we're saying that this thing might or might not happen.
40
+
41
+ 11
42
+ 00:00:34,000 --> 00:00:37,000
43
+ If it's 100% sure it's going to happen, it's not considered a risk.
44
+
45
+ 12
46
+ 00:00:37,000 --> 00:00:40,000
47
+ Now, if it's probable, it's going to be a risk.
48
+
49
+ 13
50
+ 00:00:40,000 --> 00:00:41,000
51
+ But what exactly is a risk?
52
+
53
+ 14
54
+ 00:00:41,000 --> 00:00:46,000
55
+ Well, basically a risk is basically a threat exploiting a vulnerability.
56
+
57
+ 15
58
+ 00:00:47,000 --> 00:00:49,000
59
+ This looks like a formula.
60
+
61
+ 16
62
+ 00:00:49,000 --> 00:00:53,000
63
+ And it is, but it's not really a numerical formula.
64
+
65
+ 17
66
+ 00:00:53,000 --> 00:00:56,000
67
+ It's just more of a formula that tells you how to calculate risk.
68
+
69
+ 18
70
+ 00:00:56,000 --> 00:01:03,000
71
+ For example, if there is a particular threat like a hacker and there is a vulnerability because you
72
+
73
+ 19
74
+ 00:01:03,000 --> 00:01:08,000
75
+ don't have firewalls on your network and there's a hacker that wants to exploit your network, well,
76
+
77
+ 20
78
+ 00:01:08,000 --> 00:01:10,000
79
+ that's a high threat.
80
+
81
+ 21
82
+ 00:01:10,000 --> 00:01:11,000
83
+ That's a big vulnerability.
84
+
85
+ 22
86
+ 00:01:11,000 --> 00:01:13,000
87
+ There's a very high risk.
88
+
89
+ 23
90
+ 00:01:13,000 --> 00:01:19,000
91
+ But what if the hacker exploits a particular hole on your network and you patch up that particular hole?
92
+
93
+ 24
94
+ 00:01:20,000 --> 00:01:22,000
95
+ Well, the hacker still exists.
96
+
97
+ 25
98
+ 00:01:22,000 --> 00:01:25,000
99
+ There's still a threat, but there's no vulnerability.
100
+
101
+ 26
102
+ 00:01:25,000 --> 00:01:27,000
103
+ And anything times zero is basically zero.
104
+
105
+ 27
106
+ 00:01:27,000 --> 00:01:29,000
107
+ So basically this risk may not exist.
108
+
109
+ 28
110
+ 00:01:29,000 --> 00:01:36,000
111
+ In other words, the risk of him coming through port 21 is no more because you put a firewall on it,
112
+
113
+ 29
114
+ 00:01:36,000 --> 00:01:37,000
115
+ blocked that particular port.
116
+
117
+ 30
118
+ 00:01:37,000 --> 00:01:44,000
119
+ So when it comes to risk management, we have to ensure that we manage the threats and the vulnerabilities
120
+
121
+ 31
122
+ 00:01:44,000 --> 00:01:46,000
123
+ in order to reduce or eliminate risks.
124
+
125
+ 32
126
+ 00:01:46,000 --> 00:01:50,000
127
+ Now security is known to be risk based.
128
+
129
+ 33
130
+ 00:01:50,000 --> 00:01:57,000
131
+ You see, all the actions we take in security should be done from a risk based approach.
132
+
133
+ 34
134
+ 00:01:57,000 --> 00:01:58,000
135
+ What does that mean?
136
+
137
+ 35
138
+ 00:01:58,000 --> 00:02:05,000
139
+ You see a risk based approach to security is that the controls we implement is going to be selected
140
+
141
+ 36
142
+ 00:02:05,000 --> 00:02:06,000
143
+ based on a risk assessment.
144
+
145
+ 37
146
+ 00:02:06,000 --> 00:02:08,000
147
+ Let me just tell you guys something.
148
+
149
+ 38
150
+ 00:02:08,000 --> 00:02:12,000
151
+ You can't spend $10 protecting $5.
152
+
153
+ 39
154
+ 00:02:12,000 --> 00:02:17,000
155
+ Every control that we implement in IT security is probably going to cost money.
156
+
157
+ 40
158
+ 00:02:17,000 --> 00:02:22,000
159
+ And we have to ensure that what we're spending is protecting the asset, that it's actually worth it.
160
+
161
+ 41
162
+ 00:02:22,000 --> 00:02:26,000
163
+ In other words, is the $10 that we're spending worth protecting $5?
164
+
165
+ 42
166
+ 00:02:26,000 --> 00:02:28,000
167
+ How do we even come up with the value of the asset?
168
+
169
+ 43
170
+ 00:02:28,000 --> 00:02:32,000
171
+ So risks of itself, risk assessment can get complex.
172
+
173
+ 44
174
+ 00:02:32,000 --> 00:02:34,000
175
+ That's what this whole section is about.
176
+
177
+ 45
178
+ 00:02:34,000 --> 00:02:41,000
179
+ Now, before we get into all the different risk assessments and how to respond to it, I want to cover
180
+
181
+ 46
182
+ 00:02:41,000 --> 00:02:43,000
183
+ some terms that we're going to be using later.
184
+
185
+ 47
186
+ 00:02:43,000 --> 00:02:44,000
187
+ The first thing up we have is an asset.
188
+
189
+ 48
190
+ 00:02:44,000 --> 00:02:47,000
191
+ This is anything an environment that needs to be protected.
192
+
193
+ 49
194
+ 00:02:47,000 --> 00:02:49,000
195
+ It's anything in the environment that generally has a value.
196
+
197
+ 50
198
+ 00:02:49,000 --> 00:02:53,000
199
+ Of course, the most important asset in it is human life.
200
+
201
+ 51
202
+ 00:02:53,000 --> 00:02:54,000
203
+ That's correct.
204
+
205
+ 52
206
+ 00:02:54,000 --> 00:02:58,000
207
+ If you said that second most important is probably going to be data, then you have things like physical
208
+
209
+ 53
210
+ 00:02:58,000 --> 00:03:02,000
211
+ structures like servers, computers, physical buildings and so on.
212
+
213
+ 54
214
+ 00:03:02,000 --> 00:03:06,000
215
+ The asset valuation, this is something that you have to calculate.
216
+
217
+ 55
218
+ 00:03:06,000 --> 00:03:10,000
219
+ Well, you can't really do a risk assessment if you don't know the value of the asset.
220
+
221
+ 56
222
+ 00:03:10,000 --> 00:03:17,000
223
+ Once again, if you don't know the asset is worth $5, how are you doing an assessment to then go and
224
+
225
+ 57
226
+ 00:03:17,000 --> 00:03:20,000
227
+ spend $1,020 protecting this $5 asset.
228
+
229
+ 58
230
+ 00:03:20,000 --> 00:03:22,000
231
+ So you have to know the value of the asset.
232
+
233
+ 59
234
+ 00:03:22,000 --> 00:03:28,000
235
+ This is a dollar value assigned to an asset based on the actual cost and non-monetary expenses.
236
+
237
+ 60
238
+ 00:03:28,000 --> 00:03:32,000
239
+ In the world of risk, you have to know your threats.
240
+
241
+ 61
242
+ 00:03:32,000 --> 00:03:35,000
243
+ Any potential occurrence that may harm the asset.
244
+
245
+ 62
246
+ 00:03:35,000 --> 00:03:42,000
247
+ Threats can be not just people think hackers and viruses, but threats can also be things like physical
248
+
249
+ 63
250
+ 00:03:42,000 --> 00:03:46,000
251
+ things, physical threats like a hurricane or a flood.
252
+
253
+ 64
254
+ 00:03:47,000 --> 00:03:49,000
255
+ Threat agents and threat actors.
256
+
257
+ 65
258
+ 00:03:49,000 --> 00:03:53,000
259
+ Those are people programs, hardware systems that uses threats to cause harm.
260
+
261
+ 66
262
+ 00:03:53,000 --> 00:03:57,000
263
+ So a threat agent or an actor is basically a hacker.
264
+
265
+ 67
266
+ 00:03:57,000 --> 00:04:01,000
267
+ The threat event are occurrences that lead to the exploitation.
268
+
269
+ 68
270
+ 00:04:01,000 --> 00:04:05,000
271
+ So them hacking your system is considered a threat event.
272
+
273
+ 69
274
+ 00:04:05,000 --> 00:04:06,000
275
+ What's a threat vector?
276
+
277
+ 70
278
+ 00:04:06,000 --> 00:04:08,000
279
+ Well, how did they hack your system?
280
+
281
+ 71
282
+ 00:04:08,000 --> 00:04:10,000
283
+ What vector did they use?
284
+
285
+ 72
286
+ 00:04:10,000 --> 00:04:14,000
287
+ Well, that's the path or means by which the attacker can gain access.
288
+
289
+ 73
290
+ 00:04:14,000 --> 00:04:18,000
291
+ So a threat vector for example is going to be like an internet line.
292
+
293
+ 74
294
+ 00:04:20,000 --> 00:04:24,000
295
+ Vulnerability is a weakness in the asset or the absence of the weakness.
296
+
297
+ 75
298
+ 00:04:25,000 --> 00:04:29,000
299
+ Uh, or the absent or the weakness of a safeguard or countermeasure.
300
+
301
+ 76
302
+ 00:04:29,000 --> 00:04:30,000
303
+ So what is the vulnerability?
304
+
305
+ 77
306
+ 00:04:30,000 --> 00:04:31,000
307
+ It's a hole in your system.
308
+
309
+ 78
310
+ 00:04:31,000 --> 00:04:33,000
311
+ It's a weakness in your system.
312
+
313
+ 79
314
+ 00:04:33,000 --> 00:04:35,000
315
+ It's the absence of a safeguard in your system.
316
+
317
+ 80
318
+ 00:04:35,000 --> 00:04:41,000
319
+ For example, not have an antivirus, not having a firewall, uh, not training your users.
320
+
321
+ 81
322
+ 00:04:41,000 --> 00:04:45,000
323
+ Those are going to be absence of a particular safeguard.
324
+
325
+ 82
326
+ 00:04:46,000 --> 00:04:50,000
327
+ Exposure that is the actual or anticipated damage.
328
+
329
+ 83
330
+ 00:04:50,000 --> 00:04:54,000
331
+ So, for example, when the threat exploits the vulnerability, when a hacker comes in, when the malware
332
+
333
+ 84
334
+ 00:04:54,000 --> 00:04:56,000
335
+ comes in, how much is lost?
336
+
337
+ 85
338
+ 00:04:56,000 --> 00:04:58,000
339
+ That's your exposure.
340
+
341
+ 86
342
+ 00:04:58,000 --> 00:05:01,000
343
+ Safeguard is what we put in place to reduce the risk or eliminate the risk.
344
+
345
+ 87
346
+ 00:05:01,000 --> 00:05:05,000
347
+ This is going to be like putting an antivirus or training your user.
348
+
349
+ 88
350
+ 00:05:05,000 --> 00:05:10,000
351
+ The attack is when the threat attempts to exploit the vulnerability and if they're successful, it's
352
+
353
+ 89
354
+ 00:05:10,000 --> 00:05:11,000
355
+ called a breach.
356
+
357
+ 90
358
+ 00:05:11,000 --> 00:05:17,000
359
+ Now I want you guys to know the difference breach is the occurrence of a security mechanism being bypassed.
360
+
361
+ 91
362
+ 00:05:17,000 --> 00:05:24,000
363
+ So if an attacker, a hacker, tries to break into your network, that's called the attack where they
364
+
365
+ 92
366
+ 00:05:24,000 --> 00:05:25,000
367
+ successful.
368
+
369
+ 93
370
+ 00:05:25,000 --> 00:05:26,000
371
+ Maybe.
372
+
373
+ 94
374
+ 00:05:26,000 --> 00:05:27,000
375
+ Maybe not.
376
+
377
+ 95
378
+ 00:05:27,000 --> 00:05:28,000
379
+ If they are, it's considered a breach.
380
+
381
+ 96
382
+ 00:05:28,000 --> 00:05:32,000
383
+ So when we say security breach, that is generally a successful attack.
384
+
385
+ 97
386
+ 00:05:32,000 --> 00:05:38,000
387
+ Now keep in mind once again guys, everything we do in IT security is a risk based thing.
388
+
389
+ 98
390
+ 00:05:38,000 --> 00:05:40,000
391
+ We should not be doing anything in IT security.
392
+
393
+ 99
394
+ 00:05:40,000 --> 00:05:43,000
395
+ If we haven't done a risk assessment, we can't.
396
+
397
+ 100
398
+ 00:05:43,000 --> 00:05:45,000
399
+ We shouldn't select controls.
400
+
401
+ 101
402
+ 00:05:45,000 --> 00:05:47,000
403
+ If we haven't done a risk assessment.
404
+
405
+ 102
406
+ 00:05:47,000 --> 00:05:51,000
407
+ Without the risk assessment, we may be spending money protecting things that just don't need it or
408
+
409
+ 103
410
+ 00:05:51,000 --> 00:05:53,000
411
+ it just doesn't have any value.
412
+
413
+ 104
414
+ 00:05:53,000 --> 00:05:55,000
415
+ So let's get started with these risk assessments.
416
+
21 - Risk Management/002 Risk Identification and Assessment Times OB 5.2_en.srt ADDED
@@ -0,0 +1,340 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ 1
2
+ 00:00:00,000 --> 00:00:04,000
3
+ When it comes to risk management, one of the first things you're going to be doing is, of course,
4
+
5
+ 2
6
+ 00:00:04,000 --> 00:00:07,000
7
+ identifying the risks that can affect your network.
8
+
9
+ 3
10
+ 00:00:07,000 --> 00:00:14,000
11
+ Now, risk identification is understanding the initial phase of risk management where the potential
12
+
13
+ 4
14
+ 00:00:14,000 --> 00:00:17,000
15
+ security risks are recognized and described.
16
+
17
+ 5
18
+ 00:00:17,000 --> 00:00:18,000
19
+ Now I want to just point out something.
20
+
21
+ 6
22
+ 00:00:18,000 --> 00:00:22,000
23
+ Risk identification is not something that's a solo activity.
24
+
25
+ 7
26
+ 00:00:22,000 --> 00:00:27,000
27
+ Risk identification should be done by all members of the IT department, or most members of the IT department
28
+
29
+ 8
30
+ 00:00:27,000 --> 00:00:29,000
31
+ and other departments.
32
+
33
+ 9
34
+ 00:00:29,000 --> 00:00:34,000
35
+ The more people involved in it, the more perspectives you get.
36
+
37
+ 10
38
+ 00:00:34,000 --> 00:00:40,000
39
+ Generally speaking, IT folks may be able to identify risks related to the IT department, but they're
40
+
41
+ 11
42
+ 00:00:40,000 --> 00:00:45,000
43
+ probably not going to be able to identify certain risks that can affect the accounting department or
44
+
45
+ 12
46
+ 00:00:45,000 --> 00:00:47,000
47
+ the sales department.
48
+
49
+ 13
50
+ 00:00:47,000 --> 00:00:47,000
51
+ Why?
52
+
53
+ 14
54
+ 00:00:47,000 --> 00:00:49,000
55
+ Because the IT folks generally don't work there.
56
+
57
+ 15
58
+ 00:00:49,000 --> 00:00:55,000
59
+ So the more people that gets involved, the more likely your risk identification is going to be more
60
+
61
+ 16
62
+ 00:00:55,000 --> 00:00:56,000
63
+ comprehensive.
64
+
65
+ 17
66
+ 00:00:56,000 --> 00:01:02,000
67
+ So the whole point of risk identification is just coming up with a list of risks that can affect us.
68
+
69
+ 18
70
+ 00:01:02,000 --> 00:01:03,000
71
+ Like what?
72
+
73
+ 19
74
+ 00:01:03,000 --> 00:01:08,000
75
+ Well, we can already think of most risks, such as hackers hacking into the network and stealing our
76
+
77
+ 20
78
+ 00:01:08,000 --> 00:01:08,000
79
+ data.
80
+
81
+ 21
82
+ 00:01:08,000 --> 00:01:13,000
83
+ Ransomware, uh, modifying and encrypting the data.
84
+
85
+ 22
86
+ 00:01:13,000 --> 00:01:16,000
87
+ But what about regulatory risks, like being out of compliance?
88
+
89
+ 23
90
+ 00:01:16,000 --> 00:01:18,000
91
+ The risk of being out of compliance?
92
+
93
+ 24
94
+ 00:01:18,000 --> 00:01:24,000
95
+ What about risks to the supply chain of a of a vendor going away or a vendor going down?
96
+
97
+ 25
98
+ 00:01:24,000 --> 00:01:29,000
99
+ What about physical security risks such as the drop of infrastructure such as not having power?
100
+
101
+ 26
102
+ 00:01:29,000 --> 00:01:34,000
103
+ Those are all different kinds of risks that needs to identify needs to be identified.
104
+
105
+ 27
106
+ 00:01:34,000 --> 00:01:39,000
107
+ This is critical for establishing a baseline from which risk analysis, assessment and strategies are
108
+
109
+ 28
110
+ 00:01:39,000 --> 00:01:39,000
111
+ done.
112
+
113
+ 29
114
+ 00:01:40,000 --> 00:01:46,000
115
+ Now, when it comes to risk assessment themselves, there are a few different ways of doing it.
116
+
117
+ 30
118
+ 00:01:46,000 --> 00:01:51,000
119
+ One kind of risk assessment is called an ad hoc risk assessment.
120
+
121
+ 31
122
+ 00:01:51,000 --> 00:01:53,000
123
+ This is performed as needed.
124
+
125
+ 32
126
+ 00:01:53,000 --> 00:01:57,000
127
+ Generally responds to a specific event or change in the environment.
128
+
129
+ 33
130
+ 00:01:57,000 --> 00:02:03,000
131
+ For example, it might be conducted after a major security breach, or it could be conducted after a
132
+
133
+ 34
134
+ 00:02:03,000 --> 00:02:05,000
135
+ natural disaster that no one thought about.
136
+
137
+ 35
138
+ 00:02:05,000 --> 00:02:10,000
139
+ For example, there was a major flood next to a data center or a particular office that no one ever
140
+
141
+ 36
142
+ 00:02:10,000 --> 00:02:12,000
143
+ taught, that that area ever gets flooded.
144
+
145
+ 37
146
+ 00:02:12,000 --> 00:02:14,000
147
+ So you could come out and just do an ad hoc assessment.
148
+
149
+ 38
150
+ 00:02:14,000 --> 00:02:16,000
151
+ Basically, there's no plan for it.
152
+
153
+ 39
154
+ 00:02:16,000 --> 00:02:18,000
155
+ You just do it when it's needed.
156
+
157
+ 40
158
+ 00:02:19,000 --> 00:02:24,000
159
+ Now, most companies have what's called reoccurring risk assessments.
160
+
161
+ 41
162
+ 00:02:24,000 --> 00:02:29,000
163
+ This is the kind of assessment is conducted at regular intervals, for example, monthly or quarterly
164
+
165
+ 42
166
+ 00:02:29,000 --> 00:02:30,000
167
+ or annually.
168
+
169
+ 43
170
+ 00:02:30,000 --> 00:02:35,000
171
+ At a minimum, risk assessment should be done once a year at a minimum.
172
+
173
+ 44
174
+ 00:02:35,000 --> 00:02:41,000
175
+ Reoccurring risk assessment are generally part of a good systematic approach to managing risks.
176
+
177
+ 45
178
+ 00:02:41,000 --> 00:02:44,000
179
+ Now this one here is a good way of doing it.
180
+
181
+ 46
182
+ 00:02:45,000 --> 00:02:46,000
183
+ Yearly, at a minimum.
184
+
185
+ 47
186
+ 00:02:46,000 --> 00:02:47,000
187
+ Quarterly.
188
+
189
+ 48
190
+ 00:02:47,000 --> 00:02:49,000
191
+ Monthly sounds better.
192
+
193
+ 49
194
+ 00:02:49,000 --> 00:02:53,000
195
+ There are times when you're just going to do a one time risk assessment.
196
+
197
+ 50
198
+ 00:02:53,000 --> 00:02:58,000
199
+ This is generally conducted for specific scenarios, such as if you're launching like a brand new IT
200
+
201
+ 51
202
+ 00:02:58,000 --> 00:03:02,000
203
+ product, you may just do this one time thing because you're not going to launch that product again
204
+
205
+ 52
206
+ 00:03:02,000 --> 00:03:04,000
207
+ because it's just going to stay in the marketplace.
208
+
209
+ 53
210
+ 00:03:04,000 --> 00:03:08,000
211
+ So for example, when implementing a new system or releasing a new product.
212
+
213
+ 54
214
+ 00:03:08,000 --> 00:03:13,000
215
+ Now this is one thing we got to keep in mind is that risk assessment is continuous.
216
+
217
+ 55
218
+ 00:03:13,000 --> 00:03:15,000
219
+ It's never something you stop.
220
+
221
+ 56
222
+ 00:03:15,000 --> 00:03:17,000
223
+ You continuously do it over and over.
224
+
225
+ 57
226
+ 00:03:17,000 --> 00:03:18,000
227
+ Why?
228
+
229
+ 58
230
+ 00:03:18,000 --> 00:03:21,000
231
+ Because the world changes and there's new risk every day.
232
+
233
+ 59
234
+ 00:03:21,000 --> 00:03:25,000
235
+ Every single day you wake up, there's a new risk that can take your life away.
236
+
237
+ 60
238
+ 00:03:25,000 --> 00:03:28,000
239
+ There's a new risk that can bring your company down.
240
+
241
+ 61
242
+ 00:03:28,000 --> 00:03:31,000
243
+ So we have to consistently keep doing risk assessment.
244
+
245
+ 62
246
+ 00:03:31,000 --> 00:03:35,000
247
+ So remember the first step in that assessment is going to be identifying those risks.
248
+
249
+ 63
250
+ 00:03:35,000 --> 00:03:40,000
251
+ Then we have to analyze those risks which will take a look at in the next video.
252
+
253
+ 64
254
+ 00:03:41,000 --> 00:03:45,000
255
+ So ongoing monitoring and analysis and analysis of risks.
256
+
257
+ 65
258
+ 00:03:45,000 --> 00:03:46,000
259
+ This approach.
260
+
261
+ 66
262
+ 00:03:46,000 --> 00:03:49,000
263
+ This approach will use real time data and automated tools.
264
+
265
+ 67
266
+ 00:03:49,000 --> 00:03:52,000
267
+ Continuous assessment are becoming increasingly important.
268
+
269
+ 68
270
+ 00:03:52,000 --> 00:03:52,000
271
+ Why?
272
+
273
+ 69
274
+ 00:03:52,000 --> 00:03:53,000
275
+ Because.
276
+
277
+ 70
278
+ 00:03:54,000 --> 00:03:54,000
279
+ It.
280
+
281
+ 71
282
+ 00:03:54,000 --> 00:03:56,000
283
+ Security is dynamic.
284
+
285
+ 72
286
+ 00:03:56,000 --> 00:03:56,000
287
+ All right.
288
+
289
+ 73
290
+ 00:03:56,000 --> 00:03:58,000
291
+ What we do in this world is dynamic.
292
+
293
+ 74
294
+ 00:03:58,000 --> 00:03:59,000
295
+ Everything changes.
296
+
297
+ 75
298
+ 00:03:59,000 --> 00:04:06,000
299
+ New threats, new technology, new management, new people, new laws, new governments on a consistent
300
+
301
+ 76
302
+ 00:04:06,000 --> 00:04:07,000
303
+ basis.
304
+
305
+ 77
306
+ 00:04:07,000 --> 00:04:09,000
307
+ The world is not static.
308
+
309
+ 78
310
+ 00:04:09,000 --> 00:04:12,000
311
+ So your assessment can't be static.
312
+
313
+ 79
314
+ 00:04:12,000 --> 00:04:13,000
315
+ All right, keep that in mind.
316
+
317
+ 80
318
+ 00:04:14,000 --> 00:04:18,000
319
+ Keep that in mind that you're going to be doing risk assessment on a continuous basis.
320
+
321
+ 81
322
+ 00:04:18,000 --> 00:04:22,000
323
+ There are times when you might do a one time assessment for a particular launch of a new product.
324
+
325
+ 82
326
+ 00:04:22,000 --> 00:04:27,000
327
+ Keep in mind that it's continuous and it probably should be done every quarterly in my opinion, or
328
+
329
+ 83
330
+ 00:04:27,000 --> 00:04:30,000
331
+ monthly, but at least do it every yearly.
332
+
333
+ 84
334
+ 00:04:31,000 --> 00:04:32,000
335
+ Uh, you know why?
336
+
337
+ 85
338
+ 00:04:32,000 --> 00:04:35,000
339
+ Because risk is something that changes all the time.
340
+
21 - Risk Management/003 Quantitative and Qualitive Risk Assessment OB 5.2_en.srt ADDED
@@ -0,0 +1,784 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ 1
2
+ 00:00:00,000 --> 00:00:05,000
3
+ When you conduct a risk assessment, you're either going to be doing what's called a quantitative assessment
4
+
5
+ 2
6
+ 00:00:05,000 --> 00:00:07,000
7
+ or a qualitative assessment.
8
+
9
+ 3
10
+ 00:00:07,000 --> 00:00:13,000
11
+ Quantitative assessment is when you numerically analyze risk and you run a series of formulas for that
12
+
13
+ 4
14
+ 00:00:13,000 --> 00:00:18,000
15
+ versus quantitative assessment is a more subjective kind of a risk assessment, in which case you're
16
+
17
+ 5
18
+ 00:00:18,000 --> 00:00:23,000
19
+ going to be using things such as high, medium, low or verbally describing risks.
20
+
21
+ 6
22
+ 00:00:23,000 --> 00:00:30,000
23
+ So quantitative assessment is when you're going to use numbers, actual hard numbers in order to do
24
+
25
+ 7
26
+ 00:00:30,000 --> 00:00:32,000
27
+ your risk assessment.
28
+
29
+ 8
30
+ 00:00:32,000 --> 00:00:33,000
31
+ Let me give you an example.
32
+
33
+ 9
34
+ 00:00:33,000 --> 00:00:37,000
35
+ In the world of risk assessment, an earthquake in New York City, what's the probability?
36
+
37
+ 10
38
+ 00:00:37,000 --> 00:00:43,000
39
+ Well, for quantitative, you might say the probability of an earthquake or a major earthquake in New
40
+
41
+ 11
42
+ 00:00:43,000 --> 00:00:49,000
43
+ York City is low versus in a quantitative assessment, you're going to say, well, it's a 1% every
44
+
45
+ 12
46
+ 00:00:49,000 --> 00:00:50,000
47
+ year.
48
+
49
+ 13
50
+ 00:00:50,000 --> 00:00:54,000
51
+ If you actually look it up, it's actually one out of a one out of 100 chance.
52
+
53
+ 14
54
+ 00:00:54,000 --> 00:00:56,000
55
+ You get an earthquake every year.
56
+
57
+ 15
58
+ 00:00:56,000 --> 00:00:57,000
59
+ Major earthquake in New York City.
60
+
61
+ 16
62
+ 00:00:57,000 --> 00:01:01,000
63
+ If you say, well, what's the impact of a major earthquake in New York City?
64
+
65
+ 17
66
+ 00:01:01,000 --> 00:01:06,000
67
+ Qualitative assessment is going to say something like, well, it's a high impact versus quantitative
68
+
69
+ 18
70
+ 00:01:06,000 --> 00:01:12,000
71
+ assessment is going to be, well, it's going to cost $50 billion in damages.
72
+
73
+ 19
74
+ 00:01:12,000 --> 00:01:15,000
75
+ You notice one is more objective based.
76
+
77
+ 20
78
+ 00:01:15,000 --> 00:01:20,000
79
+ That's going to be the quantitative assessment versus one is very subjective based.
80
+
81
+ 21
82
+ 00:01:20,000 --> 00:01:22,000
83
+ That's going to be the qualitative assessment.
84
+
85
+ 22
86
+ 00:01:22,000 --> 00:01:27,000
87
+ One needs massive amounts of data and computation and calculations.
88
+
89
+ 23
90
+ 00:01:27,000 --> 00:01:30,000
91
+ That's going to be quantitative assessment because of the numbers.
92
+
93
+ 24
94
+ 00:01:30,000 --> 00:01:33,000
95
+ You're going to have to go and grab data from all kinds of sources.
96
+
97
+ 25
98
+ 00:01:33,000 --> 00:01:41,000
99
+ And that makes it very, very objective versus something where we just use people's opinion and their
100
+
101
+ 26
102
+ 00:01:41,000 --> 00:01:41,000
103
+ experience.
104
+
105
+ 27
106
+ 00:01:41,000 --> 00:01:45,000
107
+ That's going to be more subjective, like qualitative assessment.
108
+
109
+ 28
110
+ 00:01:45,000 --> 00:01:50,000
111
+ Now, I do recommend to watch this video twice because when it comes to quantitative assessment, there's
112
+
113
+ 29
114
+ 00:01:50,000 --> 00:01:53,000
115
+ a series of formulas that you're going to need to know for your exam.
116
+
117
+ 30
118
+ 00:01:53,000 --> 00:01:54,000
119
+ So let's take a look.
120
+
121
+ 31
122
+ 00:01:54,000 --> 00:01:57,000
123
+ So here is a series of formulas.
124
+
125
+ 32
126
+ 00:01:57,000 --> 00:02:03,000
127
+ And it's basically only two formulas Excel and Ali I'll come to this one value to safeguard coming up
128
+
129
+ 33
130
+ 00:02:03,000 --> 00:02:03,000
131
+ later.
132
+
133
+ 34
134
+ 00:02:04,000 --> 00:02:11,000
135
+ But I want to point out something before I get started with this, uh, asset value exposure factor.
136
+
137
+ 35
138
+ 00:02:11,000 --> 00:02:16,000
139
+ An annual rate of occurrence of the Aro are not numbers that you can calculate.
140
+
141
+ 36
142
+ 00:02:16,000 --> 00:02:19,000
143
+ This has to be given to you in a question.
144
+
145
+ 37
146
+ 00:02:19,000 --> 00:02:23,000
147
+ And then you can calculate the SL and the Ala.
148
+
149
+ 38
150
+ 00:02:24,000 --> 00:02:24,000
151
+ All right.
152
+
153
+ 39
154
+ 00:02:24,000 --> 00:02:25,000
155
+ So keep that in mind.
156
+
157
+ 40
158
+ 00:02:26,000 --> 00:02:27,000
159
+ Okay.
160
+
161
+ 41
162
+ 00:02:27,000 --> 00:02:28,000
163
+ So let's go through this.
164
+
165
+ 42
166
+ 00:02:28,000 --> 00:02:30,000
167
+ I'm going to come up with a scenario.
168
+
169
+ 43
170
+ 00:02:30,000 --> 00:02:32,000
171
+ Now don't worry too much about the numbers in this scenario.
172
+
173
+ 44
174
+ 00:02:32,000 --> 00:02:36,000
175
+ All I need you to do is to be able to calculate the formulas for your exam.
176
+
177
+ 45
178
+ 00:02:36,000 --> 00:02:37,000
179
+ So let's get started.
180
+
181
+ 46
182
+ 00:02:37,000 --> 00:02:42,000
183
+ So remember quantitative analysis is all about numerical analysis.
184
+
185
+ 47
186
+ 00:02:42,000 --> 00:02:44,000
187
+ It's all about numerically analyzing risk.
188
+
189
+ 48
190
+ 00:02:44,000 --> 00:02:47,000
191
+ It's about putting a dollar value on the risk.
192
+
193
+ 49
194
+ 00:02:47,000 --> 00:02:48,000
195
+ So let's get started.
196
+
197
+ 50
198
+ 00:02:48,000 --> 00:02:52,000
199
+ So let's say you have an asset and that asset has to have a value.
200
+
201
+ 51
202
+ 00:02:52,000 --> 00:02:56,000
203
+ So your first thing you have to do in risk assessment is you have to know the value of the asset.
204
+
205
+ 52
206
+ 00:02:56,000 --> 00:02:58,000
207
+ Let's say the asset is data.
208
+
209
+ 53
210
+ 00:02:58,000 --> 00:03:03,000
211
+ And your data is worth, uh, $1 million.
212
+
213
+ 54
214
+ 00:03:03,000 --> 00:03:04,000
215
+ All right.
216
+
217
+ 55
218
+ 00:03:04,000 --> 00:03:05,000
219
+ So $1 million.
220
+
221
+ 56
222
+ 00:03:06,000 --> 00:03:06,000
223
+ All right.
224
+
225
+ 57
226
+ 00:03:06,000 --> 00:03:08,000
227
+ Don't ask me where I get the number from.
228
+
229
+ 58
230
+ 00:03:08,000 --> 00:03:10,000
231
+ Remember, this number has to be given to you on the exam.
232
+
233
+ 59
234
+ 00:03:10,000 --> 00:03:12,000
235
+ You can't make it up.
236
+
237
+ 60
238
+ 00:03:12,000 --> 00:03:14,000
239
+ So it's it's $1 million asset.
240
+
241
+ 61
242
+ 00:03:14,000 --> 00:03:16,000
243
+ Now the exposure factor.
244
+
245
+ 62
246
+ 00:03:16,000 --> 00:03:17,000
247
+ Notice terme.
248
+
249
+ 63
250
+ 00:03:17,000 --> 00:03:24,000
251
+ The exposure factor is a percentage of loss that an organization would experience if a specific asset
252
+
253
+ 64
254
+ 00:03:24,000 --> 00:03:26,000
255
+ were violated by a risk.
256
+
257
+ 65
258
+ 00:03:26,000 --> 00:03:28,000
259
+ So it's a percentage.
260
+
261
+ 66
262
+ 00:03:28,000 --> 00:03:32,000
263
+ If I come in here and I put 100%.
264
+
265
+ 67
266
+ 00:03:33,000 --> 00:03:41,000
267
+ What that means is that if this risk, know, the risk we're talking about is malware to data.
268
+
269
+ 68
270
+ 00:03:41,000 --> 00:03:43,000
271
+ So malware infecting data is the risk.
272
+
273
+ 69
274
+ 00:03:43,000 --> 00:03:51,000
275
+ So if the malware infects your data, how much of or percentage of the data would be lost?
276
+
277
+ 70
278
+ 00:03:51,000 --> 00:03:53,000
279
+ I'm saying it's 100%.
280
+
281
+ 71
282
+ 00:03:53,000 --> 00:03:57,000
283
+ In other words, if you get infected with malware, all your data is gone.
284
+
285
+ 72
286
+ 00:03:57,000 --> 00:04:01,000
287
+ This exposure factor can change though.
288
+
289
+ 73
290
+ 00:04:01,000 --> 00:04:08,000
291
+ For example, if you had a data center that's worth or a build and worth $1 million and a category five
292
+
293
+ 74
294
+ 00:04:08,000 --> 00:04:16,000
295
+ hurricane would destroy 50% of it, so then a 50% loss so your exposure factor wouldn't be 150%.
296
+
297
+ 75
298
+ 00:04:16,000 --> 00:04:18,000
299
+ And then how much of the building would you lose?
300
+
301
+ 76
302
+ 00:04:18,000 --> 00:04:23,000
303
+ Well, if it's worth $1 million and you and you're going to lose 50%, then it's worth 500,000.
304
+
305
+ 77
306
+ 00:04:23,000 --> 00:04:24,000
307
+ And that's called the SLA.
308
+
309
+ 78
310
+ 00:04:25,000 --> 00:04:32,000
311
+ The SLA is the cost associated with every single realized risk against an asset.
312
+
313
+ 79
314
+ 00:04:32,000 --> 00:04:41,000
315
+ So the SLA is equal to the asset value, which we have is 1 million times the actual 100%.
316
+
317
+ 80
318
+ 00:04:41,000 --> 00:04:48,000
319
+ So if we know 1 million times, 100% is basically 100% is one, so it would be equal to 1 million.
320
+
321
+ 81
322
+ 00:04:48,000 --> 00:04:56,000
323
+ We're saying is that every single, every single time you get hit with malware, you're going to lose
324
+
325
+ 82
326
+ 00:04:56,000 --> 00:04:57,000
327
+ $1 million.
328
+
329
+ 83
330
+ 00:04:57,000 --> 00:05:04,000
331
+ You're going to lose all your data versus if you had a build in that was worth a million and a hurricane
332
+
333
+ 84
334
+ 00:05:04,000 --> 00:05:07,000
335
+ is going to destroy 50%, it'll be 500 for you.
336
+
337
+ 85
338
+ 00:05:07,000 --> 00:05:13,000
339
+ Now, the next thing is, how often is this going to happen, right?
340
+
341
+ 86
342
+ 00:05:13,000 --> 00:05:20,000
343
+ How many times every single year are you going to get hit with a particular virus?
344
+
345
+ 87
346
+ 00:05:20,000 --> 00:05:25,000
347
+ Now, technically, you should do this before the virus protection is implemented.
348
+
349
+ 88
350
+ 00:05:25,000 --> 00:05:28,000
351
+ And after, let's say you have no virus protection.
352
+
353
+ 89
354
+ 00:05:28,000 --> 00:05:35,000
355
+ Let's say you don't have any antivirus, no user training, anti-malware, firewall, nothing.
356
+
357
+ 90
358
+ 00:05:35,000 --> 00:05:37,000
359
+ You don't have anything.
360
+
361
+ 91
362
+ 00:05:37,000 --> 00:05:39,000
363
+ How many times a year are you going to get a virus?
364
+
365
+ 92
366
+ 00:05:40,000 --> 00:05:45,000
367
+ Let's say you get a virus at least once a week, 50 times a year.
368
+
369
+ 93
370
+ 00:05:45,000 --> 00:05:45,000
371
+ All right.
372
+
373
+ 94
374
+ 00:05:45,000 --> 00:05:47,000
375
+ Because you don't have any protection you're going to get.
376
+
377
+ 95
378
+ 00:05:47,000 --> 00:05:49,000
379
+ At least I'm going to go with a minimum.
380
+
381
+ 96
382
+ 00:05:49,000 --> 00:05:50,000
383
+ I'm going to say 50.
384
+
385
+ 97
386
+ 00:05:50,000 --> 00:05:54,000
387
+ You guys are probably saying, well, it's like every day, let's just go with 50 for now.
388
+
389
+ 98
390
+ 00:05:54,000 --> 00:05:54,000
391
+ Okay.
392
+
393
+ 99
394
+ 00:05:54,000 --> 00:06:00,000
395
+ So we're saying that, hey, you're going to get at least 50 infection a year.
396
+
397
+ 100
398
+ 00:06:00,000 --> 00:06:02,000
399
+ So how much are you going to lose every year.
400
+
401
+ 101
402
+ 00:06:02,000 --> 00:06:04,000
403
+ Well that's the annualized loss expectancy.
404
+
405
+ 102
406
+ 00:06:04,000 --> 00:06:12,000
407
+ This is a formula is equal to the SLA which is 1 million times the R0.
408
+
409
+ 103
410
+ 00:06:12,000 --> 00:06:14,000
411
+ So the R0 is 50 right.
412
+
413
+ 104
414
+ 00:06:14,000 --> 00:06:15,000
415
+ So 1 million times 50.
416
+
417
+ 105
418
+ 00:06:16,000 --> 00:06:18,000
419
+ This is $50 million.
420
+
421
+ 106
422
+ 00:06:18,000 --> 00:06:22,000
423
+ So we know that we're going to lose 50 million every year.
424
+
425
+ 107
426
+ 00:06:22,000 --> 00:06:28,000
427
+ Another way to calculate the SLA is basically you know SLA is equal to AV times F.
428
+
429
+ 108
430
+ 00:06:28,000 --> 00:06:33,000
431
+ So they're just uh uh, spelling that out for you.
432
+
433
+ 109
434
+ 00:06:33,000 --> 00:06:38,000
435
+ You can say AV times F times R0, but the real form is SLA, times R0 gives you the same thing.
436
+
437
+ 110
438
+ 00:06:38,000 --> 00:06:39,000
439
+ So it's $50 million.
440
+
441
+ 111
442
+ 00:06:39,000 --> 00:06:41,000
443
+ What is this number mean.
444
+
445
+ 112
446
+ 00:06:41,000 --> 00:06:51,000
447
+ Well that $50 million means that every single year you're going to lose $50 million, right?
448
+
449
+ 113
450
+ 00:06:52,000 --> 00:06:54,000
451
+ You're going to lose 50 million bucks.
452
+
453
+ 114
454
+ 00:06:54,000 --> 00:06:55,000
455
+ Why?
456
+
457
+ 115
458
+ 00:06:55,000 --> 00:06:57,000
459
+ Because you have no anti-virus protection.
460
+
461
+ 116
462
+ 00:06:57,000 --> 00:07:00,000
463
+ Now, this are the formulas.
464
+
465
+ 117
466
+ 00:07:00,000 --> 00:07:01,000
467
+ So the asset.
468
+
469
+ 118
470
+ 00:07:01,000 --> 00:07:02,000
471
+ Let's do a quick review.
472
+
473
+ 119
474
+ 00:07:02,000 --> 00:07:04,000
475
+ The asset value is a number that's given to you.
476
+
477
+ 120
478
+ 00:07:04,000 --> 00:07:05,000
479
+ You can't calculate it.
480
+
481
+ 121
482
+ 00:07:05,000 --> 00:07:12,000
483
+ So whatever the asset is worth to the business the exposure factor is a percentage of loss when or and
484
+
485
+ 122
486
+ 00:07:12,000 --> 00:07:17,000
487
+ when if a risk materializes, how much of the asset is lost in percentage.
488
+
489
+ 123
490
+ 00:07:17,000 --> 00:07:23,000
491
+ Single loss expectancy is the asset value times the exposure factor.
492
+
493
+ 124
494
+ 00:07:23,000 --> 00:07:26,000
495
+ Then how many times a year would a potential thing occur?
496
+
497
+ 125
498
+ 00:07:26,000 --> 00:07:28,000
499
+ That's going to be the R0.
500
+
501
+ 126
502
+ 00:07:28,000 --> 00:07:30,000
503
+ So in our ones we have 50.
504
+
505
+ 127
506
+ 00:07:30,000 --> 00:07:33,000
507
+ Then the annualized loss expectancy is the asset times the R0.
508
+
509
+ 128
510
+ 00:07:34,000 --> 00:07:38,000
511
+ Now I have something at the bottom the annual cost of the safeguard.
512
+
513
+ 129
514
+ 00:07:38,000 --> 00:07:40,000
515
+ We have to calculate.
516
+
517
+ 130
518
+ 00:07:40,000 --> 00:07:45,000
519
+ Well you go to management and you tell management well we're going to lose $50 million a year.
520
+
521
+ 131
522
+ 00:07:45,000 --> 00:07:47,000
523
+ And management says, oh that's a lot of money.
524
+
525
+ 132
526
+ 00:07:47,000 --> 00:07:53,000
527
+ Okay, let's go and spend some money and protect our protect those data.
528
+
529
+ 133
530
+ 00:07:53,000 --> 00:07:59,000
531
+ So management we come out and we need antivirus user training and firewall.
532
+
533
+ 134
534
+ 00:07:59,000 --> 00:08:03,000
535
+ So the annual cost of the safeguard is not a number you can calculate.
536
+
537
+ 135
538
+ 00:08:03,000 --> 00:08:05,000
539
+ This is going to be let's say 10 million.
540
+
541
+ 136
542
+ 00:08:05,000 --> 00:08:08,000
543
+ So 10 million.
544
+
545
+ 137
546
+ 00:08:08,000 --> 00:08:16,000
547
+ Now, when you get the actual, uh, value of the safeguard, now you can recalculate your ale.
548
+
549
+ 138
550
+ 00:08:16,000 --> 00:08:19,000
551
+ You see, if you recalculate.
552
+
553
+ 139
554
+ 00:08:19,000 --> 00:08:24,000
555
+ Remember when we did this, we said we had no protection in place.
556
+
557
+ 140
558
+ 00:08:24,000 --> 00:08:28,000
559
+ Remember that with no protection, you're getting 50 infections.
560
+
561
+ 141
562
+ 00:08:28,000 --> 00:08:30,000
563
+ Now, what happens if you do protection?
564
+
565
+ 142
566
+ 00:08:30,000 --> 00:08:30,000
567
+ Well.
568
+
569
+ 143
570
+ 00:08:31,000 --> 00:08:35,000
571
+ Let's recalculate all these numbers because now we have a protection.
572
+
573
+ 144
574
+ 00:08:35,000 --> 00:08:37,000
575
+ Now we have antivirus user training.
576
+
577
+ 145
578
+ 00:08:37,000 --> 00:08:38,000
579
+ Now what is it going to be.
580
+
581
+ 146
582
+ 00:08:38,000 --> 00:08:42,000
583
+ Well by putting an antivirus doesn't change the value of the data does it.
584
+
585
+ 147
586
+ 00:08:42,000 --> 00:08:45,000
587
+ It's still a million bucks if you get infected.
588
+
589
+ 148
590
+ 00:08:45,000 --> 00:08:50,000
591
+ Even if you have antivirus and you get infected and it bypasses your antivirus, you're still going
592
+
593
+ 149
594
+ 00:08:50,000 --> 00:08:51,000
595
+ to lose 100%.
596
+
597
+ 150
598
+ 00:08:52,000 --> 00:08:58,000
599
+ So in this one, I'm going to leave the cell as 1 million because it's AV 1 million.
600
+
601
+ 151
602
+ 00:08:59,000 --> 00:09:02,000
603
+ Times the single loss expectancy of 100.
604
+
605
+ 152
606
+ 00:09:02,000 --> 00:09:07,000
607
+ So it's going to be there's 100% 1 million.
608
+
609
+ 153
610
+ 00:09:07,000 --> 00:09:09,000
611
+ Now here's the thing.
612
+
613
+ 154
614
+ 00:09:09,000 --> 00:09:13,000
615
+ By implementing all the how many infections are you going to have a year that's going to take out all
616
+
617
+ 155
618
+ 00:09:13,000 --> 00:09:14,000
619
+ the data.
620
+
621
+ 156
622
+ 00:09:14,000 --> 00:09:19,000
623
+ Let's say you bring that number down to, let's say, two infections a year.
624
+
625
+ 157
626
+ 00:09:19,000 --> 00:09:25,000
627
+ That means that your L is equal to 1 million times two.
628
+
629
+ 158
630
+ 00:09:25,000 --> 00:09:29,000
631
+ So you only losing $2 million every single year.
632
+
633
+ 159
634
+ 00:09:30,000 --> 00:09:34,000
635
+ So by you implementing the safeguard, what is it worth to you?
636
+
637
+ 160
638
+ 00:09:35,000 --> 00:09:35,000
639
+ Right.
640
+
641
+ 161
642
+ 00:09:35,000 --> 00:09:38,000
643
+ What is what is the value the organization is getting out of this.
644
+
645
+ 162
646
+ 00:09:38,000 --> 00:09:39,000
647
+ And that's this last number.
648
+
649
+ 163
650
+ 00:09:40,000 --> 00:09:44,000
651
+ So the value is equal to the al before the safeguard we know is 50 million.
652
+
653
+ 164
654
+ 00:09:45,000 --> 00:09:48,000
655
+ After minus the L after the safeguard.
656
+
657
+ 165
658
+ 00:09:48,000 --> 00:09:50,000
659
+ So we know we're losing 2 million.
660
+
661
+ 166
662
+ 00:09:50,000 --> 00:09:52,000
663
+ Even though you put in a safeguard guide, you're still losing 2 million.
664
+
665
+ 167
666
+ 00:09:52,000 --> 00:09:54,000
667
+ So -2 million.
668
+
669
+ 168
670
+ 00:09:54,000 --> 00:09:57,000
671
+ And then the actual cost of the safeguard is 10 million.
672
+
673
+ 169
674
+ 00:09:58,000 --> 00:10:01,000
675
+ So let's do 50 minus two is 48.
676
+
677
+ 170
678
+ 00:10:01,000 --> 00:10:04,000
679
+ Minus ten is 38 million.
680
+
681
+ 171
682
+ 00:10:05,000 --> 00:10:07,000
683
+ This is what the organization is gaining.
684
+
685
+ 172
686
+ 00:10:07,000 --> 00:10:14,000
687
+ This is like their value that they're gaining because of the antivirus protection or the malware protection.
688
+
689
+ 173
690
+ 00:10:14,000 --> 00:10:16,000
691
+ You see guys, that's what you need.
692
+
693
+ 174
694
+ 00:10:16,000 --> 00:10:17,000
695
+ Antivirus.
696
+
697
+ 175
698
+ 00:10:17,000 --> 00:10:18,000
699
+ Okay.
700
+
701
+ 176
702
+ 00:10:18,000 --> 00:10:20,000
703
+ Replay this video a couple of times.
704
+
705
+ 177
706
+ 00:10:20,000 --> 00:10:22,000
707
+ Make sure you really understand these formulas.
708
+
709
+ 178
710
+ 00:10:22,000 --> 00:10:27,000
711
+ Now the last thing I want to mention uh is going to be uh qualitative assessment.
712
+
713
+ 179
714
+ 00:10:27,000 --> 00:10:34,000
715
+ So qualitative assessment is assessing risk based on subjective criteria such as expert opinions uh
716
+
717
+ 180
718
+ 00:10:34,000 --> 00:10:39,000
719
+ scenario analysis and generally all kinds of industry best practices.
720
+
721
+ 181
722
+ 00:10:39,000 --> 00:10:41,000
723
+ It'll categorize risk into high, medium or low.
724
+
725
+ 182
726
+ 00:10:42,000 --> 00:10:44,000
727
+ It just it does not use numbers.
728
+
729
+ 183
730
+ 00:10:44,000 --> 00:10:49,000
731
+ You see in order to do this you got to go out and you got to grab numbers, man.
732
+
733
+ 184
734
+ 00:10:49,000 --> 00:10:51,000
735
+ You got to go and do all the research.
736
+
737
+ 185
738
+ 00:10:51,000 --> 00:10:57,000
739
+ For example, when I told you guys that there is a 1% chance of getting an earthquake in New York City,
740
+
741
+ 186
742
+ 00:10:57,000 --> 00:10:58,000
743
+ that is an actual number.
744
+
745
+ 187
746
+ 00:10:58,000 --> 00:11:02,000
747
+ I had to research that for a project that was working on a while back.
748
+
749
+ 188
750
+ 00:11:02,000 --> 00:11:07,000
751
+ Now, this approach is useful for understanding the general magnitude of risks.
752
+
753
+ 189
754
+ 00:11:07,000 --> 00:11:12,000
755
+ So keep in mind qualitative analysis is very subjective.
756
+
757
+ 190
758
+ 00:11:12,000 --> 00:11:13,000
759
+ All right.
760
+
761
+ 191
762
+ 00:11:13,000 --> 00:11:15,000
763
+ It's done by people's opinion.
764
+
765
+ 192
766
+ 00:11:15,000 --> 00:11:18,000
767
+ It uses rankings such as high, medium or low.
768
+
769
+ 193
770
+ 00:11:18,000 --> 00:11:22,000
771
+ It's quick and it's easy to do and it doesn't require a ton of data.
772
+
773
+ 194
774
+ 00:11:23,000 --> 00:11:28,000
775
+ Quantitative assessment is more objective, requires a ton of data, takes a lot of time.
776
+
777
+ 195
778
+ 00:11:28,000 --> 00:11:32,000
779
+ And of course it's going to be more expensive because it does require a lot more time.
780
+
781
+ 196
782
+ 00:11:32,000 --> 00:11:35,000
783
+ So keep that in mind when taking your exam.
784
+
21 - Risk Management/004 Risk Register OB 5.2_en.srt ADDED
@@ -0,0 +1,424 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ 1
2
+ 00:00:00,000 --> 00:00:05,000
3
+ When you do your risk assessment, such as your qualitative and quantitative, and you identify your
4
+
5
+ 2
6
+ 00:00:05,000 --> 00:00:07,000
7
+ risks, you have to store this somewhere.
8
+
9
+ 3
10
+ 00:00:07,000 --> 00:00:09,000
11
+ You have to store this in a particular document.
12
+
13
+ 4
14
+ 00:00:09,000 --> 00:00:11,000
15
+ We're going to call the risk register.
16
+
17
+ 5
18
+ 00:00:11,000 --> 00:00:17,000
19
+ So the risk register is basically a component of good risk management because it serves as the central
20
+
21
+ 6
22
+ 00:00:17,000 --> 00:00:21,000
23
+ repository for all the risk in it.
24
+
25
+ 7
26
+ 00:00:21,000 --> 00:00:23,000
27
+ Now I do have a sample of it here.
28
+
29
+ 8
30
+ 00:00:23,000 --> 00:00:26,000
31
+ Every risk register can be different in every organization.
32
+
33
+ 9
34
+ 00:00:26,000 --> 00:00:30,000
35
+ This is a sample that I got from a risk register template here on this website.
36
+
37
+ 10
38
+ 00:00:30,000 --> 00:00:33,000
39
+ At a minimum it's going to have the identified risks.
40
+
41
+ 11
42
+ 00:00:33,000 --> 00:00:39,000
43
+ The assessments on them, such as the description and the potential actions that we want to take against
44
+
45
+ 12
46
+ 00:00:39,000 --> 00:00:39,000
47
+ them.
48
+
49
+ 13
50
+ 00:00:39,000 --> 00:00:44,000
51
+ Notice in this risk register I know it's hard to see, but you can expand it on the you know, when
52
+
53
+ 14
54
+ 00:00:44,000 --> 00:00:45,000
55
+ you see the slide, it'll be easier.
56
+
57
+ 15
58
+ 00:00:45,000 --> 00:00:50,000
59
+ Uh the description notice they have an impact description, the level, how it's going to impact.
60
+
61
+ 16
62
+ 00:00:50,000 --> 00:00:51,000
63
+ It's a high medium or low.
64
+
65
+ 17
66
+ 00:00:51,000 --> 00:00:53,000
67
+ Um, they have a priority.
68
+
69
+ 18
70
+ 00:00:53,000 --> 00:00:56,000
71
+ They also have a mitigation note like what are we going to do to reduce this risk.
72
+
73
+ 19
74
+ 00:00:56,000 --> 00:01:00,000
75
+ So at a minimum, a risk register should have a description of the risk.
76
+
77
+ 20
78
+ 00:01:00,000 --> 00:01:03,000
79
+ Like what exactly is the risk in the world of it.
80
+
81
+ 21
82
+ 00:01:04,000 --> 00:01:06,000
83
+ We can have ransomware.
84
+
85
+ 22
86
+ 00:01:06,000 --> 00:01:07,000
87
+ That's a risk.
88
+
89
+ 23
90
+ 00:01:07,000 --> 00:01:08,000
91
+ What's the description of it.
92
+
93
+ 24
94
+ 00:01:08,000 --> 00:01:13,000
95
+ Well ransomware can encrypt the data and then hold us hostage by making us want to pay to get the data
96
+
97
+ 25
98
+ 00:01:13,000 --> 00:01:14,000
99
+ back.
100
+
101
+ 26
102
+ 00:01:14,000 --> 00:01:21,000
103
+ So we want a nice detail risk register with a nice detailed description of each individual risk.
104
+
105
+ 27
106
+ 00:01:21,000 --> 00:01:26,000
107
+ If you have a risk with hurricane floods, power outages describe how you know how is that going to
108
+
109
+ 28
110
+ 00:01:26,000 --> 00:01:28,000
111
+ affect the actual business.
112
+
113
+ 29
114
+ 00:01:28,000 --> 00:01:33,000
115
+ So describe the risks, the assets that are affected, the consequences.
116
+
117
+ 30
118
+ 00:01:33,000 --> 00:01:38,000
119
+ For example, if there's a power outage at a major data center, you can see that this can bring the
120
+
121
+ 31
122
+ 00:01:38,000 --> 00:01:41,000
123
+ data center down for extended periods of time, causing the organization a lot of money.
124
+
125
+ 32
126
+ 00:01:43,000 --> 00:01:49,000
127
+ Another thing here you're going to want to have on your risk register is what's called your Chris or
128
+
129
+ 33
130
+ 00:01:49,000 --> 00:01:51,000
131
+ your key risk indicators.
132
+
133
+ 34
134
+ 00:01:51,000 --> 00:01:56,000
135
+ These are metrics you're going to use to measure and monitor the likelihood and impact of a risk.
136
+
137
+ 35
138
+ 00:01:56,000 --> 00:02:00,000
139
+ They provide early warnings that a risk may be increasing or decreasing.
140
+
141
+ 36
142
+ 00:02:00,000 --> 00:02:05,000
143
+ For example, in a high number of failed login this may be a cry for unauthorized access.
144
+
145
+ 37
146
+ 00:02:05,000 --> 00:02:07,000
147
+ So think about this.
148
+
149
+ 38
150
+ 00:02:07,000 --> 00:02:15,000
151
+ At what point do you look at and say, well, this risk is most likely to happen, right?
152
+
153
+ 39
154
+ 00:02:15,000 --> 00:02:16,000
155
+ Like what's that?
156
+
157
+ 40
158
+ 00:02:16,000 --> 00:02:18,000
159
+ What's that number?
160
+
161
+ 41
162
+ 00:02:18,000 --> 00:02:24,000
163
+ Like, what does that look like to you when you say, well, okay, this is risk is probably going to
164
+
165
+ 42
166
+ 00:02:24,000 --> 00:02:24,000
167
+ take place.
168
+
169
+ 43
170
+ 00:02:24,000 --> 00:02:26,000
171
+ For example, like they're saying here.
172
+
173
+ 44
174
+ 00:02:26,000 --> 00:02:31,000
175
+ Well there's going to be a high this ten failed logins.
176
+
177
+ 45
178
+ 00:02:31,000 --> 00:02:33,000
179
+ Is that is that a good number for you.
180
+
181
+ 46
182
+ 00:02:33,000 --> 00:02:34,000
183
+ But you see ten fail.
184
+
185
+ 47
186
+ 00:02:34,000 --> 00:02:35,000
187
+ Log on from that.
188
+
189
+ 48
190
+ 00:02:35,000 --> 00:02:37,000
191
+ Users did this user account is under attack.
192
+
193
+ 49
194
+ 00:02:37,000 --> 00:02:40,000
195
+ The risk is starting to materialize itself.
196
+
197
+ 50
198
+ 00:02:41,000 --> 00:02:48,000
199
+ So you have to come up with KPIs that can give you basically early warning signs that a risk is happening.
200
+
201
+ 51
202
+ 00:02:48,000 --> 00:02:57,000
203
+ Another example, let's say a system has generated, uh, ten different error that the operating system
204
+
205
+ 52
206
+ 00:02:57,000 --> 00:03:00,000
207
+ is getting corrupted or the operating system stopped responding.
208
+
209
+ 53
210
+ 00:03:00,000 --> 00:03:06,000
211
+ How many of those errors do you need to see before you go in and say, okay, let's reinstall the operating
212
+
213
+ 54
214
+ 00:03:06,000 --> 00:03:09,000
215
+ system before the whole thing crashes and produces a massive failure.
216
+
217
+ 55
218
+ 00:03:09,000 --> 00:03:11,000
219
+ You need to come up with those numbers.
220
+
221
+ 56
222
+ 00:03:11,000 --> 00:03:12,000
223
+ Every organization is different.
224
+
225
+ 57
226
+ 00:03:13,000 --> 00:03:15,000
227
+ You want to assign a risk owner.
228
+
229
+ 58
230
+ 00:03:15,000 --> 00:03:19,000
231
+ A risk owner is someone who's held responsible for managing and mitigating that risk.
232
+
233
+ 59
234
+ 00:03:19,000 --> 00:03:23,000
235
+ So you can go through the risk register and say, well, this risk is owned by this person.
236
+
237
+ 60
238
+ 00:03:23,000 --> 00:03:28,000
239
+ That way this person takes ownership of it and build a team to help secure against this risk.
240
+
241
+ 61
242
+ 00:03:28,000 --> 00:03:33,000
243
+ Now there's generally someone who's going to be in a manager owner management role and has the authority
244
+
245
+ 62
246
+ 00:03:33,000 --> 00:03:37,000
247
+ and knowledge to come up with the right responses now.
248
+
249
+ 63
250
+ 00:03:38,000 --> 00:03:42,000
251
+ What exactly is the threshold for the level of action?
252
+
253
+ 64
254
+ 00:03:42,000 --> 00:03:42,000
255
+ All right.
256
+
257
+ 65
258
+ 00:03:42,000 --> 00:03:47,000
259
+ Threshold refers to the level of risk that the organization is willing to accept.
260
+
261
+ 66
262
+ 00:03:47,000 --> 00:03:51,000
263
+ Risks that fall below the threshold is probably you're just going to watch it.
264
+
265
+ 67
266
+ 00:03:51,000 --> 00:03:52,000
267
+ You're going to accept it.
268
+
269
+ 68
270
+ 00:03:52,000 --> 00:03:53,000
271
+ You're going to monitor it.
272
+
273
+ 69
274
+ 00:03:53,000 --> 00:03:59,000
275
+ Anything above it will require an activation notice will require activation of mitigation.
276
+
277
+ 70
278
+ 00:03:59,000 --> 00:04:02,000
279
+ So let's say you're watching the operating system.
280
+
281
+ 71
282
+ 00:04:02,000 --> 00:04:03,000
283
+ You're watching the operating.
284
+
285
+ 72
286
+ 00:04:03,000 --> 00:04:08,000
287
+ You're seeing that the hard drive is getting filled very quickly because it's a backup machine.
288
+
289
+ 73
290
+ 00:04:09,000 --> 00:04:11,000
291
+ What is the threshold that we increase the storage.
292
+
293
+ 74
294
+ 00:04:11,000 --> 00:04:13,000
295
+ We're going to run out of storage.
296
+
297
+ 75
298
+ 00:04:13,000 --> 00:04:15,000
299
+ Is it when it's 80% filled?
300
+
301
+ 76
302
+ 00:04:15,000 --> 00:04:16,000
303
+ Is it when it's 90% filled.
304
+
305
+ 77
306
+ 00:04:16,000 --> 00:04:19,000
307
+ That's something you have to determine.
308
+
309
+ 78
310
+ 00:04:19,000 --> 00:04:20,000
311
+ So that's the risk threshold.
312
+
313
+ 79
314
+ 00:04:20,000 --> 00:04:21,000
315
+ All right.
316
+
317
+ 80
318
+ 00:04:21,000 --> 00:04:25,000
319
+ Don't forget guys make sure you understand what exactly is a risk register.
320
+
321
+ 81
322
+ 00:04:25,000 --> 00:04:29,000
323
+ A risk register is a document that you're going to put all your risk on.
324
+
325
+ 82
326
+ 00:04:29,000 --> 00:04:30,000
327
+ You're going to describe them.
328
+
329
+ 83
330
+ 00:04:30,000 --> 00:04:34,000
331
+ You're going to have risk owners risk thresholds you're going to put on there.
332
+
333
+ 84
334
+ 00:04:35,000 --> 00:04:36,000
335
+ And now risk indicators.
336
+
337
+ 85
338
+ 00:04:36,000 --> 00:04:40,000
339
+ Also you're going to have if you're wondering, hey Andrew, what's in between that indicator and the
340
+
341
+ 86
342
+ 00:04:40,000 --> 00:04:41,000
343
+ threshold?
344
+
345
+ 87
346
+ 00:04:41,000 --> 00:04:45,000
347
+ Well, remember indicator is the early warning sign that the risk is happening.
348
+
349
+ 88
350
+ 00:04:45,000 --> 00:04:46,000
351
+ The risk threshold is okay.
352
+
353
+ 89
354
+ 00:04:46,000 --> 00:04:47,000
355
+ It crossed this.
356
+
357
+ 90
358
+ 00:04:47,000 --> 00:04:48,000
359
+ It needs to be fixed.
360
+
361
+ 91
362
+ 00:04:48,000 --> 00:04:50,000
363
+ Remember indicators are early warning signs.
364
+
365
+ 92
366
+ 00:04:50,000 --> 00:04:53,000
367
+ For example, if you go back to the server backup.
368
+
369
+ 93
370
+ 00:04:53,000 --> 00:05:00,000
371
+ Well, if the server backups start to exceed, let's say the maximum, you're willing to lose 80%.
372
+
373
+ 94
374
+ 00:05:00,000 --> 00:05:06,000
375
+ If the backup drives are more than 80% filled, you've got to up the storage before you run out of space
376
+
377
+ 95
378
+ 00:05:06,000 --> 00:05:08,000
379
+ and then the risk of no backup.
380
+
381
+ 96
382
+ 00:05:08,000 --> 00:05:12,000
383
+ So the risk indicators like 70% okay, it's an early warning sign.
384
+
385
+ 97
386
+ 00:05:12,000 --> 00:05:12,000
387
+ Okay.
388
+
389
+ 98
390
+ 00:05:12,000 --> 00:05:14,000
391
+ This risk is probably going to happen.
392
+
393
+ 99
394
+ 00:05:14,000 --> 00:05:16,000
395
+ So you start looking at it looking at it.
396
+
397
+ 100
398
+ 00:05:16,000 --> 00:05:19,000
399
+ And then now you have the threshold okay.
400
+
401
+ 101
402
+ 00:05:19,000 --> 00:05:20,000
403
+ Now we crossed with 81%.
404
+
405
+ 102
406
+ 00:05:20,000 --> 00:05:21,000
407
+ Boom.
408
+
409
+ 103
410
+ 00:05:21,000 --> 00:05:25,000
411
+ Implement the mitigation strategy of up in the drive space.
412
+
413
+ 104
414
+ 00:05:25,000 --> 00:05:25,000
415
+ All right.
416
+
417
+ 105
418
+ 00:05:25,000 --> 00:05:26,000
419
+ Make sure you know these terms.
420
+
421
+ 106
422
+ 00:05:26,000 --> 00:05:29,000
423
+ More than likely you'll see some of them on your test.
424
+
21 - Risk Management/005 Risk Appetite OB 5.2_en.srt ADDED
@@ -0,0 +1,324 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ 1
2
+ 00:00:00,000 --> 00:00:04,000
3
+ In order to do something in life, you have to be willing to take risks.
4
+
5
+ 2
6
+ 00:00:04,000 --> 00:00:11,000
7
+ You see, every thing that we do in life, every action that we take in life has risks.
8
+
9
+ 3
10
+ 00:00:11,000 --> 00:00:14,000
11
+ There is a risk of me standing here.
12
+
13
+ 4
14
+ 00:00:14,000 --> 00:00:17,000
15
+ I mean, the ceiling can fall on top of me, the desk can fall over.
16
+
17
+ 5
18
+ 00:00:17,000 --> 00:00:19,000
19
+ There's all kinds of risks that can happen.
20
+
21
+ 6
22
+ 00:00:19,000 --> 00:00:20,000
23
+ Now.
24
+
25
+ 7
26
+ 00:00:20,000 --> 00:00:25,000
27
+ I have to be willing to take a certain number of risks in order to do a particular task.
28
+
29
+ 8
30
+ 00:00:25,000 --> 00:00:30,000
31
+ For example, if you go out and you drive to go to the supermarket, one of the most dangerous things
32
+
33
+ 9
34
+ 00:00:30,000 --> 00:00:32,000
35
+ a human can ever do is drive.
36
+
37
+ 10
38
+ 00:00:32,000 --> 00:00:35,000
39
+ You have to be willing to take those risks.
40
+
41
+ 11
42
+ 00:00:35,000 --> 00:00:39,000
43
+ The risk of getting into a car accident or the risk of death in a car accident.
44
+
45
+ 12
46
+ 00:00:39,000 --> 00:00:42,000
47
+ Now, this brings me to a particular terme that we want to be familiar with.
48
+
49
+ 13
50
+ 00:00:42,000 --> 00:00:44,000
51
+ It's called the risk appetite.
52
+
53
+ 14
54
+ 00:00:44,000 --> 00:00:50,000
55
+ This refers to the risk that an organization is prepared to pursue, retain, or take in its operation.
56
+
57
+ 15
58
+ 00:00:50,000 --> 00:00:55,000
59
+ So what kind of risk is the organization willing to take?
60
+
61
+ 16
62
+ 00:00:55,000 --> 00:00:55,000
63
+ Now?
64
+
65
+ 17
66
+ 00:00:56,000 --> 00:01:01,000
67
+ The organization is going to have to know the risk that they're willing to take in order to do, to
68
+
69
+ 18
70
+ 00:01:01,000 --> 00:01:04,000
71
+ build a particular product or a particular service.
72
+
73
+ 19
74
+ 00:01:04,000 --> 00:01:10,000
75
+ In fact, in businesses today, it's all about risk because they're willing to spend money to create
76
+
77
+ 20
78
+ 00:01:10,000 --> 00:01:15,000
79
+ this product or service, and they don't know if it's going to be sold or not, reflects the organization
80
+
81
+ 21
82
+ 00:01:15,000 --> 00:01:17,000
83
+ attitude towards its risk.
84
+
85
+ 22
86
+ 00:01:17,000 --> 00:01:21,000
87
+ Now, what's going to influence the risk appetite?
88
+
89
+ 23
90
+ 00:01:21,000 --> 00:01:26,000
91
+ So the risk appetite is going to be influenced by its culture, the goals, market conditions and so
92
+
93
+ 24
94
+ 00:01:26,000 --> 00:01:26,000
95
+ on.
96
+
97
+ 25
98
+ 00:01:26,000 --> 00:01:29,000
99
+ Another time you might see is the risk tolerance.
100
+
101
+ 26
102
+ 00:01:29,000 --> 00:01:34,000
103
+ This is the amount of the risk that the organization is willing to take or to withstand.
104
+
105
+ 27
106
+ 00:01:34,000 --> 00:01:35,000
107
+ Let me explain.
108
+
109
+ 28
110
+ 00:01:35,000 --> 00:01:41,000
111
+ So the risk appetite, well, I'm willing to to take this much.
112
+
113
+ 29
114
+ 00:01:41,000 --> 00:01:42,000
115
+ You know, I'm willing to take this risk.
116
+
117
+ 30
118
+ 00:01:42,000 --> 00:01:44,000
119
+ But how much of that risk are you willing to take?
120
+
121
+ 31
122
+ 00:01:44,000 --> 00:01:47,000
123
+ At what point does that risk becomes too much?
124
+
125
+ 32
126
+ 00:01:47,000 --> 00:01:52,000
127
+ You know, one of the best examples of appetite versus tolerance is like speed limit.
128
+
129
+ 33
130
+ 00:01:53,000 --> 00:01:59,000
131
+ So a highway can have a speed limit of 60 miles an hour, or let's say 65 miles an hour.
132
+
133
+ 34
134
+ 00:01:59,000 --> 00:02:01,000
135
+ So that's the risk.
136
+
137
+ 35
138
+ 00:02:01,000 --> 00:02:03,000
139
+ You know, that's the maximum speed.
140
+
141
+ 36
142
+ 00:02:03,000 --> 00:02:05,000
143
+ So what is the risk of driving on a highway?
144
+
145
+ 37
146
+ 00:02:05,000 --> 00:02:10,000
147
+ Well, you know, crashes are dying of course getting injured and so on.
148
+
149
+ 38
150
+ 00:02:10,000 --> 00:02:13,000
151
+ So those are all the risks that's there.
152
+
153
+ 39
154
+ 00:02:13,000 --> 00:02:15,000
155
+ Now the tolerance.
156
+
157
+ 40
158
+ 00:02:15,000 --> 00:02:15,000
159
+ Well.
160
+
161
+ 41
162
+ 00:02:16,000 --> 00:02:19,000
163
+ At what point are you not going to drive that highway?
164
+
165
+ 42
166
+ 00:02:19,000 --> 00:02:20,000
167
+ At what point are you going to get pulled over?
168
+
169
+ 43
170
+ 00:02:20,000 --> 00:02:25,000
171
+ So, for example, the police on the highway is going to say, well, if they drive at 65, they're
172
+
173
+ 44
174
+ 00:02:25,000 --> 00:02:26,000
175
+ okay.
176
+
177
+ 45
178
+ 00:02:26,000 --> 00:02:27,000
179
+ If they go up to 70, they're fine.
180
+
181
+ 46
182
+ 00:02:27,000 --> 00:02:30,000
183
+ But after 70, we're not willing to take that anymore.
184
+
185
+ 47
186
+ 00:02:30,000 --> 00:02:33,000
187
+ Anybody that goes over 70 miles, we're going to stop them.
188
+
189
+ 48
190
+ 00:02:33,000 --> 00:02:38,000
191
+ So the amount of risk, like how much of that risk are you actually willing to take?
192
+
193
+ 49
194
+ 00:02:38,000 --> 00:02:39,000
195
+ That's the risk tolerance.
196
+
197
+ 50
198
+ 00:02:39,000 --> 00:02:41,000
199
+ So you have to know that also.
200
+
201
+ 51
202
+ 00:02:41,000 --> 00:02:47,000
203
+ Now when it comes to risk appetite there is expansionary risk appetite.
204
+
205
+ 52
206
+ 00:02:47,000 --> 00:02:54,000
207
+ In other words, your risk appetite may be expanding over time to accommodate more risk or higher higher
208
+
209
+ 53
210
+ 00:02:54,000 --> 00:02:56,000
211
+ levels of risk in pursuit of a greater reward.
212
+
213
+ 54
214
+ 00:02:56,000 --> 00:03:01,000
215
+ Generally, the more risk, the bigger the reward in the world of business, right?
216
+
217
+ 55
218
+ 00:03:01,000 --> 00:03:07,000
219
+ Generally, people can pursue things that can give them a great payback, but there's a high risk of
220
+
221
+ 56
222
+ 00:03:07,000 --> 00:03:07,000
223
+ failure.
224
+
225
+ 57
226
+ 00:03:07,000 --> 00:03:11,000
227
+ For example, purchasing a stock in a brand new company that just started.
228
+
229
+ 58
230
+ 00:03:11,000 --> 00:03:13,000
231
+ Yeah, the stock price is cheap.
232
+
233
+ 59
234
+ 00:03:13,000 --> 00:03:18,000
235
+ And there's a if the company does well and make a ton of money, think of like investing in Tesla when
236
+
237
+ 60
238
+ 00:03:18,000 --> 00:03:19,000
239
+ it first started.
240
+
241
+ 61
242
+ 00:03:19,000 --> 00:03:20,000
243
+ So.
244
+
245
+ 62
246
+ 00:03:21,000 --> 00:03:27,000
247
+ Companies that does this are often in growth phases, seeking competitive advantage and willing to invest
248
+
249
+ 63
250
+ 00:03:27,000 --> 00:03:29,000
251
+ in the opportunity of a higher risk.
252
+
253
+ 64
254
+ 00:03:29,000 --> 00:03:31,000
255
+ But remember, these things will carry higher risks.
256
+
257
+ 65
258
+ 00:03:31,000 --> 00:03:37,000
259
+ Now, some companies are more conservative towards it and implies a preference for lower risk and focus
260
+
261
+ 66
262
+ 00:03:37,000 --> 00:03:39,000
263
+ on more stability.
264
+
265
+ 67
266
+ 00:03:39,000 --> 00:03:43,000
267
+ Organizations with a conservative appetite, uh, prioritize.
268
+
269
+ 68
270
+ 00:03:43,000 --> 00:03:46,000
271
+ Protect an asset and minimizing potential losses.
272
+
273
+ 69
274
+ 00:03:46,000 --> 00:03:50,000
275
+ And then the other one here we have is a neutral risk appetite.
276
+
277
+ 70
278
+ 00:03:50,000 --> 00:03:51,000
279
+ They just go with the market.
280
+
281
+ 71
282
+ 00:03:51,000 --> 00:03:54,000
283
+ Strikes a balance between the two of them.
284
+
285
+ 72
286
+ 00:03:54,000 --> 00:03:59,000
287
+ Organizations with a neutral are willing to accept some level of risk for a reasonable return, but
288
+
289
+ 73
290
+ 00:03:59,000 --> 00:04:01,000
291
+ not inclined to pursue high level risks.
292
+
293
+ 74
294
+ 00:04:01,000 --> 00:04:04,000
295
+ So if your company is right in the middle, in other words, it's not too conservative.
296
+
297
+ 75
298
+ 00:04:04,000 --> 00:04:11,000
299
+ It doesn't take a lot of risk versus your your company takes a ton of risk to get higher rewards.
300
+
301
+ 76
302
+ 00:04:11,000 --> 00:04:15,000
303
+ Most of us are probably going to be somewhere here.
304
+
305
+ 77
306
+ 00:04:15,000 --> 00:04:16,000
307
+ All right.
308
+
309
+ 78
310
+ 00:04:16,000 --> 00:04:21,000
311
+ Just remember, uh, when it comes to risk management, remember what risk appetite is.
312
+
313
+ 79
314
+ 00:04:21,000 --> 00:04:25,000
315
+ It's all the risk that you're willing to take on in order to pursue a particular goal.
316
+
317
+ 80
318
+ 00:04:25,000 --> 00:04:29,000
319
+ And then how much of that risk can you actually withstand is your risk tolerance?
320
+
321
+ 81
322
+ 00:04:29,000 --> 00:04:32,000
323
+ Keep that in mind if you see these terms on your exam.
324
+
21 - Risk Management/006 Risk Response OB 5.2_en.srt ADDED
@@ -0,0 +1,424 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ 1
2
+ 00:00:00,000 --> 00:00:05,000
3
+ When you have identified a risk and know how that risk is going to impact your organization, the next
4
+
5
+ 2
6
+ 00:00:05,000 --> 00:00:10,000
7
+ step is going to do is to come up with potential ways to respond to that risk.
8
+
9
+ 3
10
+ 00:00:10,000 --> 00:00:15,000
11
+ In this video, I want to go through some of the different ways that organizations can respond to resources.
12
+
13
+ 4
14
+ 00:00:15,000 --> 00:00:22,000
15
+ In particularly it's known are the responses are avoidance, mitigate, transfer and accept.
16
+
17
+ 5
18
+ 00:00:22,000 --> 00:00:24,000
19
+ So let's go into these here.
20
+
21
+ 6
22
+ 00:00:24,000 --> 00:00:28,000
23
+ So the first one up that I want to talk about is going to be risk avoidance.
24
+
25
+ 7
26
+ 00:00:28,000 --> 00:00:37,000
27
+ Now risk avoidance involves changing plans or procedures to eliminate the risk or to remove the organization's
28
+
29
+ 8
30
+ 00:00:37,000 --> 00:00:38,000
31
+ exposure to it.
32
+
33
+ 9
34
+ 00:00:38,000 --> 00:00:40,000
35
+ This means not this.
36
+
37
+ 10
38
+ 00:00:40,000 --> 00:00:44,000
39
+ This might mean not implementing a certain system or technology.
40
+
41
+ 11
42
+ 00:00:44,000 --> 00:00:51,000
43
+ So avoidance is the process of eliminating completely removing the risk.
44
+
45
+ 12
46
+ 00:00:51,000 --> 00:00:52,000
47
+ Let me give you an example.
48
+
49
+ 13
50
+ 00:00:53,000 --> 00:00:58,000
51
+ Let's say there is a risk that virus A can infect a windows server.
52
+
53
+ 14
54
+ 00:00:58,000 --> 00:01:00,000
55
+ How do you avoid this risk.
56
+
57
+ 15
58
+ 00:01:00,000 --> 00:01:02,000
59
+ Well don't use windows right?
60
+
61
+ 16
62
+ 00:01:02,000 --> 00:01:03,000
63
+ Use a Linux server.
64
+
65
+ 17
66
+ 00:01:03,000 --> 00:01:05,000
67
+ Virus A only infects windows.
68
+
69
+ 18
70
+ 00:01:05,000 --> 00:01:11,000
71
+ So you have effectively avoided virus a risk to your organization.
72
+
73
+ 19
74
+ 00:01:11,000 --> 00:01:17,000
75
+ So risk avoidance is some kind of action that you're going to take that that results in the risk completely
76
+
77
+ 20
78
+ 00:01:17,000 --> 00:01:19,000
79
+ being gone 100% gone.
80
+
81
+ 21
82
+ 00:01:20,000 --> 00:01:25,000
83
+ Now the other one that confuses folks with avoidance is mitigation.
84
+
85
+ 22
86
+ 00:01:25,000 --> 00:01:31,000
87
+ Now, a lot of times when people say mitigation, they they mean all four of the different responses.
88
+
89
+ 23
90
+ 00:01:31,000 --> 00:01:33,000
91
+ But mitigation is a very particular thing.
92
+
93
+ 24
94
+ 00:01:33,000 --> 00:01:37,000
95
+ It refers to taking steps to reduce the likelihood or impact of a risk.
96
+
97
+ 25
98
+ 00:01:37,000 --> 00:01:42,000
99
+ This is going to be things like implementing security controls, updating your software, user training,
100
+
101
+ 26
102
+ 00:01:42,000 --> 00:01:46,000
103
+ monitoring systems, even things such as implementing antivirus.
104
+
105
+ 27
106
+ 00:01:46,000 --> 00:01:52,000
107
+ Remember something mitigation doesn't remove the risk 100% like it's completely gone.
108
+
109
+ 28
110
+ 00:01:52,000 --> 00:01:57,000
111
+ So in the case with virus A in a windows server, what you're going to do is you're going to patch it,
112
+
113
+ 29
114
+ 00:01:57,000 --> 00:02:01,000
115
+ you're going to update it, you're going to do user training, you're going to put malware detection
116
+
117
+ 30
118
+ 00:02:01,000 --> 00:02:02,000
119
+ and removal software on it.
120
+
121
+ 31
122
+ 00:02:02,000 --> 00:02:06,000
123
+ So the risk of getting the virus is still there.
124
+
125
+ 32
126
+ 00:02:06,000 --> 00:02:11,000
127
+ It's just that its impact and or probability has been drastically reduced.
128
+
129
+ 33
130
+ 00:02:11,000 --> 00:02:18,000
131
+ So remember that for your exam avoidance completely eliminates the risk versus mitigation reduces the
132
+
133
+ 34
134
+ 00:02:18,000 --> 00:02:19,000
135
+ risk.
136
+
137
+ 35
138
+ 00:02:19,000 --> 00:02:27,000
139
+ Risk transfer is given away to risk to a third party, shifting the impact to a third party.
140
+
141
+ 36
142
+ 00:02:27,000 --> 00:02:30,000
143
+ This is generally done by purchasing insurance.
144
+
145
+ 37
146
+ 00:02:30,000 --> 00:02:31,000
147
+ All right.
148
+
149
+ 38
150
+ 00:02:31,000 --> 00:02:37,000
151
+ So if you buy insurance policies for example, there's a risk that a fire can bring down your entire
152
+
153
+ 39
154
+ 00:02:37,000 --> 00:02:38,000
155
+ infrastructure.
156
+
157
+ 40
158
+ 00:02:38,000 --> 00:02:43,000
159
+ Well in order to transfer that risk you buy fire insurance.
160
+
161
+ 41
162
+ 00:02:43,000 --> 00:02:47,000
163
+ If there is a fire, then the insurance company is going to have to take care of it.
164
+
165
+ 42
166
+ 00:02:47,000 --> 00:02:51,000
167
+ So this transfer is a financial risk to the insurance provider through outsourcing the risks.
168
+
169
+ 43
170
+ 00:02:51,000 --> 00:02:59,000
171
+ Remember, anytime you see the word insurance, think transfer risk acceptance is when you do absolutely
172
+
173
+ 44
174
+ 00:02:59,000 --> 00:02:59,000
175
+ nothing.
176
+
177
+ 45
178
+ 00:02:59,000 --> 00:03:04,000
179
+ It's a decision to not take any action against a risk.
180
+
181
+ 46
182
+ 00:03:04,000 --> 00:03:06,000
183
+ In other words, you're not eliminating it.
184
+
185
+ 47
186
+ 00:03:06,000 --> 00:03:10,000
187
+ You're not giving it away to somebody else like an insurance company, and you're not taking steps to
188
+
189
+ 48
190
+ 00:03:10,000 --> 00:03:11,000
191
+ reduce it.
192
+
193
+ 49
194
+ 00:03:11,000 --> 00:03:12,000
195
+ You're just leaving it alone.
196
+
197
+ 50
198
+ 00:03:12,000 --> 00:03:13,000
199
+ If it happens, it happens.
200
+
201
+ 51
202
+ 00:03:13,000 --> 00:03:17,000
203
+ Now you're probably saying, well, why would you do that?
204
+
205
+ 52
206
+ 00:03:17,000 --> 00:03:20,000
207
+ Well, a couple of different couple different reasons.
208
+
209
+ 53
210
+ 00:03:20,000 --> 00:03:25,000
211
+ Number one, sometimes the cost of mitigating the risk is greater than the potential loss.
212
+
213
+ 54
214
+ 00:03:25,000 --> 00:03:33,000
215
+ For example, let's say you bought a car for $500 and the cheapest alarm system is $2,000, the cheapest
216
+
217
+ 55
218
+ 00:03:33,000 --> 00:03:34,000
219
+ one.
220
+
221
+ 56
222
+ 00:03:34,000 --> 00:03:38,000
223
+ So your car is 500 and the cheapest alarm is 2000.
224
+
225
+ 57
226
+ 00:03:38,000 --> 00:03:40,000
227
+ Would you buy it an alarm system?
228
+
229
+ 58
230
+ 00:03:40,000 --> 00:03:42,000
231
+ Would you spend $2,000 protecting 500?
232
+
233
+ 59
234
+ 00:03:43,000 --> 00:03:46,000
235
+ You'd say, you know what, if the car gets stolen, it gets stolen.
236
+
237
+ 60
238
+ 00:03:46,000 --> 00:03:48,000
239
+ I'm just going to leave it alone.
240
+
241
+ 61
242
+ 00:03:48,000 --> 00:03:50,000
243
+ Another time is sometimes the risk.
244
+
245
+ 62
246
+ 00:03:50,000 --> 00:03:52,000
247
+ Sometimes the likelihood is way too low.
248
+
249
+ 63
250
+ 00:03:54,000 --> 00:03:55,000
251
+ Earthquake in New York City.
252
+
253
+ 64
254
+ 00:03:55,000 --> 00:03:56,000
255
+ I live in New York City.
256
+
257
+ 65
258
+ 00:03:56,000 --> 00:04:03,000
259
+ Do I have earthquake insurance, earthquake proof housing or earthquake response plan?
260
+
261
+ 66
262
+ 00:04:03,000 --> 00:04:03,000
263
+ Nope.
264
+
265
+ 67
266
+ 00:04:04,000 --> 00:04:05,000
267
+ If it happens, it happens.
268
+
269
+ 68
270
+ 00:04:05,000 --> 00:04:07,000
271
+ I haven't made any plan for it.
272
+
273
+ 69
274
+ 00:04:07,000 --> 00:04:11,000
275
+ I don't have any insurance for it because its probability is too low for me to worry about it.
276
+
277
+ 70
278
+ 00:04:11,000 --> 00:04:15,000
279
+ Now you're probably asking yourself, well, when are times we want to accept the risk?
280
+
281
+ 71
282
+ 00:04:15,000 --> 00:04:19,000
283
+ Sometimes it could be an exemption or an exception.
284
+
285
+ 72
286
+ 00:04:19,000 --> 00:04:20,000
287
+ So an exemption is specific.
288
+
289
+ 73
290
+ 00:04:20,000 --> 00:04:24,000
291
+ Risk might be exempt from mitigation due to the nature.
292
+
293
+ 74
294
+ 00:04:24,000 --> 00:04:29,000
295
+ For example, you might decide not to install antivirus on a particular machine.
296
+
297
+ 75
298
+ 00:04:29,000 --> 00:04:31,000
299
+ And you can exempt that one from antivirus.
300
+
301
+ 76
302
+ 00:04:31,000 --> 00:04:34,000
303
+ And the reason is because the machine will never touch the internet.
304
+
305
+ 77
306
+ 00:04:34,000 --> 00:04:38,000
307
+ The machine is only going to be connected to a particular piece of equipment, so it's exempt from a
308
+
309
+ 78
310
+ 00:04:38,000 --> 00:04:40,000
311
+ particular strategy of risk.
312
+
313
+ 79
314
+ 00:04:40,000 --> 00:04:44,000
315
+ An exception is similar to an exemption.
316
+
317
+ 80
318
+ 00:04:45,000 --> 00:04:47,000
319
+ Generally it's going to be a temporary thing.
320
+
321
+ 81
322
+ 00:04:47,000 --> 00:04:52,000
323
+ Now the other thing that we want to know is risk exploitation.
324
+
325
+ 82
326
+ 00:04:52,000 --> 00:04:54,000
327
+ Not all risk are going to be negative.
328
+
329
+ 83
330
+ 00:04:54,000 --> 00:04:56,000
331
+ In fact there is a thing like positive risk.
332
+
333
+ 84
334
+ 00:04:56,000 --> 00:04:59,000
335
+ So sometimes you want the risk to happen.
336
+
337
+ 85
338
+ 00:04:59,000 --> 00:05:01,000
339
+ See negative risk increases cost.
340
+
341
+ 86
342
+ 00:05:01,000 --> 00:05:03,000
343
+ Reduces functionality.
344
+
345
+ 87
346
+ 00:05:04,000 --> 00:05:05,000
347
+ Brings your system down.
348
+
349
+ 88
350
+ 00:05:05,000 --> 00:05:11,000
351
+ Sometimes you want to take advantage of potential positive impact of certain risks that could produce
352
+
353
+ 89
354
+ 00:05:11,000 --> 00:05:13,000
355
+ a positive result.
356
+
357
+ 90
358
+ 00:05:13,000 --> 00:05:18,000
359
+ So while this is less common in cybersecurity, it's common in project management, though less common
360
+
361
+ 91
362
+ 00:05:18,000 --> 00:05:19,000
363
+ in cybersecurity.
364
+
365
+ 92
366
+ 00:05:19,000 --> 00:05:26,000
367
+ Sometimes certain technological or certain technology can increase functionality if happens.
368
+
369
+ 93
370
+ 00:05:26,000 --> 00:05:30,000
371
+ Now, when it comes to all of this, you're going to want to make sure you do a good risk reporting.
372
+
373
+ 94
374
+ 00:05:31,000 --> 00:05:37,000
375
+ This involves understanding the process of communicating information about risks, their identified
376
+
377
+ 95
378
+ 00:05:37,000 --> 00:05:39,000
379
+ risks, their analysis and mitigation to stakeholders.
380
+
381
+ 96
382
+ 00:05:39,000 --> 00:05:47,000
383
+ Stakeholders within the organisation should know what you plan to do about certain risks, that potential
384
+
385
+ 97
386
+ 00:05:47,000 --> 00:05:47,000
387
+ risk register.
388
+
389
+ 98
390
+ 00:05:47,000 --> 00:05:49,000
391
+ This is going to be a critical element.
392
+
393
+ 99
394
+ 00:05:49,000 --> 00:05:53,000
395
+ It ensures transparency and ongoing management of risk management.
396
+
397
+ 100
398
+ 00:05:53,000 --> 00:05:54,000
399
+ Okay.
400
+
401
+ 101
402
+ 00:05:54,000 --> 00:05:57,000
403
+ Be familiar with the four different ways of managing risk.
404
+
405
+ 102
406
+ 00:05:57,000 --> 00:06:02,000
407
+ Remember something avoidance is an action taken to completely eliminate the risk.
408
+
409
+ 103
410
+ 00:06:03,000 --> 00:06:06,000
411
+ Mitigation is an action taken to reduce the risk.
412
+
413
+ 104
414
+ 00:06:06,000 --> 00:06:13,000
415
+ Transfer is to give away the risk to a third party by an insurance, and acceptance means to do absolutely
416
+
417
+ 105
418
+ 00:06:13,000 --> 00:06:14,000
419
+ nothing about the risk.
420
+
421
+ 106
422
+ 00:06:14,000 --> 00:06:16,000
423
+ Remember those four strategies for your exam?
424
+
21 - Risk Management/007 Business Impact Assessment OB 5.2_en.srt ADDED
@@ -0,0 +1,352 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ 1
2
+ 00:00:00,000 --> 00:00:06,000
3
+ When it comes to a disaster, every business has to understand how certain disasters can affect their
4
+
5
+ 2
6
+ 00:00:06,000 --> 00:00:07,000
7
+ business.
8
+
9
+ 3
10
+ 00:00:07,000 --> 00:00:13,000
11
+ This particular exercise of how you go through how different disasters can affect your business is called
12
+
13
+ 4
14
+ 00:00:13,000 --> 00:00:17,000
15
+ a business impact analysis, and it basically is.
16
+
17
+ 5
18
+ 00:00:17,000 --> 00:00:24,000
19
+ When it's done in business continuity, it helps identify and evaluate the potential effects of interruptions
20
+
21
+ 6
22
+ 00:00:24,000 --> 00:00:27,000
23
+ to critical business operations.
24
+
25
+ 7
26
+ 00:00:27,000 --> 00:00:32,000
27
+ For example, let's say there's a disaster like a power outage, or let's say there's a disaster of
28
+
29
+ 8
30
+ 00:00:33,000 --> 00:00:36,000
31
+ a hurricane or a DDoS attacks against your server.
32
+
33
+ 9
34
+ 00:00:36,000 --> 00:00:40,000
35
+ The question is exactly how does that affect your operations?
36
+
37
+ 10
38
+ 00:00:40,000 --> 00:00:46,000
39
+ So a business impact analysis looks in to how is the business going to be affected?
40
+
41
+ 11
42
+ 00:00:46,000 --> 00:00:48,000
43
+ How long is it going to bring down systems.
44
+
45
+ 12
46
+ 00:00:48,000 --> 00:00:51,000
47
+ How long is the data center going to be offline for example.
48
+
49
+ 13
50
+ 00:00:52,000 --> 00:00:59,000
51
+ So BIA is proactive measure that aids in crafting effective business continuity and disaster recovery
52
+
53
+ 14
54
+ 00:00:59,000 --> 00:00:59,000
55
+ strategies.
56
+
57
+ 15
58
+ 00:00:59,000 --> 00:01:01,000
59
+ Now remember this.
60
+
61
+ 16
62
+ 00:01:01,000 --> 00:01:06,000
63
+ The BIA shows how a potential disaster is going to impact a business.
64
+
65
+ 17
66
+ 00:01:06,000 --> 00:01:09,000
67
+ Now there are some terms that we want to review.
68
+
69
+ 18
70
+ 00:01:11,000 --> 00:01:15,000
71
+ The first thing we want to talk are terms that's going to deal with what's called recovery time.
72
+
73
+ 19
74
+ 00:01:15,000 --> 00:01:18,000
75
+ I have three terms here that you need to know for your exam.
76
+
77
+ 20
78
+ 00:01:18,000 --> 00:01:21,000
79
+ The first one is called a maximum tolerable downtime.
80
+
81
+ 21
82
+ 00:01:21,000 --> 00:01:28,000
83
+ This defines the amount of time a business function can be inoperable without causing keyword, without
84
+
85
+ 22
86
+ 00:01:28,000 --> 00:01:31,000
87
+ causing irreparable harm to the business.
88
+
89
+ 23
90
+ 00:01:31,000 --> 00:01:34,000
91
+ This is known sometimes as the maximum tolerable outage.
92
+
93
+ 24
94
+ 00:01:34,000 --> 00:01:36,000
95
+ Now take for example.
96
+
97
+ 25
98
+ 00:01:36,000 --> 00:01:41,000
99
+ Let's say you're running a website and hackers are against you and they want to bring down your website.
100
+
101
+ 26
102
+ 00:01:42,000 --> 00:01:50,000
103
+ Well, if your website does go down, how long can it go down before you start to have harm done to
104
+
105
+ 27
106
+ 00:01:50,000 --> 00:01:53,000
107
+ your business that you can never recover from?
108
+
109
+ 28
110
+ 00:01:53,000 --> 00:01:53,000
111
+ Right.
112
+
113
+ 29
114
+ 00:01:53,000 --> 00:02:01,000
115
+ So let's say if your website goes down for up to an hour, anything that you lose, you can always recover
116
+
117
+ 30
118
+ 00:02:01,000 --> 00:02:02,000
119
+ the sales.
120
+
121
+ 31
122
+ 00:02:02,000 --> 00:02:05,000
123
+ But anything after an hour, let's say you're an e-commerce site.
124
+
125
+ 32
126
+ 00:02:05,000 --> 00:02:07,000
127
+ Yeah, that means those sales are gone forever.
128
+
129
+ 33
130
+ 00:02:07,000 --> 00:02:11,000
131
+ That's harm that you'll never be able to get back, or those sales.
132
+
133
+ 34
134
+ 00:02:11,000 --> 00:02:12,000
135
+ You'll never be able to make that money back.
136
+
137
+ 35
138
+ 00:02:13,000 --> 00:02:18,000
139
+ So your maximum tolerable downtime for that website is one hour.
140
+
141
+ 36
142
+ 00:02:18,000 --> 00:02:23,000
143
+ The question is, if your website does go down, how long will it take to fix it?
144
+
145
+ 37
146
+ 00:02:23,000 --> 00:02:25,000
147
+ That's called the recovery time objectives.
148
+
149
+ 38
150
+ 00:02:25,000 --> 00:02:29,000
151
+ It's the amount of time to recover a function in the event of a disaster.
152
+
153
+ 39
154
+ 00:02:29,000 --> 00:02:35,000
155
+ So let's say it takes 30 minutes to recover your website up to 45 minutes.
156
+
157
+ 40
158
+ 00:02:35,000 --> 00:02:36,000
159
+ Well, you're doing great.
160
+
161
+ 41
162
+ 00:02:36,000 --> 00:02:42,000
163
+ In fact, the whole point of disaster recovery is to keep your toes less than your mtdz if your maximum
164
+
165
+ 42
166
+ 00:02:42,000 --> 00:02:43,000
167
+ is one hour.
168
+
169
+ 43
170
+ 00:02:44,000 --> 00:02:46,000
171
+ And you could bring it back up in war in 30 minutes.
172
+
173
+ 44
174
+ 00:02:46,000 --> 00:02:47,000
175
+ Great.
176
+
177
+ 45
178
+ 00:02:47,000 --> 00:02:51,000
179
+ You'll never suffer what's called irreparable harm.
180
+
181
+ 46
182
+ 00:02:51,000 --> 00:02:54,000
183
+ In other words, you'll never suffer harm that you can't recover from.
184
+
185
+ 47
186
+ 00:02:55,000 --> 00:02:57,000
187
+ Another time you want to know is what we call a recovery point.
188
+
189
+ 48
190
+ 00:02:57,000 --> 00:02:58,000
191
+ Objectives.
192
+
193
+ 49
194
+ 00:02:58,000 --> 00:03:04,000
195
+ You got to listen to this one defines the point in time before data loss during the outage will leave
196
+
197
+ 50
198
+ 00:03:04,000 --> 00:03:05,000
199
+ the business function unrecoverable.
200
+
201
+ 51
202
+ 00:03:05,000 --> 00:03:07,000
203
+ At what point?
204
+
205
+ 52
206
+ 00:03:07,000 --> 00:03:08,000
207
+ Point is a key word?
208
+
209
+ 53
210
+ 00:03:08,000 --> 00:03:10,000
211
+ At what point do we lose so much data?
212
+
213
+ 54
214
+ 00:03:10,000 --> 00:03:15,000
215
+ Like how much data are we willing to lose before we fix this thing?
216
+
217
+ 55
218
+ 00:03:15,000 --> 00:03:18,000
219
+ So this this deals with data loss.
220
+
221
+ 56
222
+ 00:03:18,000 --> 00:03:26,000
223
+ Now when it comes to other terms there, when you look at when system fails, every system fails, every
224
+
225
+ 57
226
+ 00:03:26,000 --> 00:03:31,000
227
+ router fails, every single server fails, every switch fails, every component will fail.
228
+
229
+ 58
230
+ 00:03:31,000 --> 00:03:35,000
231
+ There's a couple of terms we need to know with regard to with regard to failure time.
232
+
233
+ 59
234
+ 00:03:35,000 --> 00:03:42,000
235
+ The first thing is mean time to repair is the average time taken to repair a failed component and return
236
+
237
+ 60
238
+ 00:03:42,000 --> 00:03:44,000
239
+ it back to operational status.
240
+
241
+ 61
242
+ 00:03:44,000 --> 00:03:47,000
243
+ The other one is mean time between failure.
244
+
245
+ 62
246
+ 00:03:47,000 --> 00:03:53,000
247
+ It's a measure of reliability and stability, indicating the average time between failure of a system.
248
+
249
+ 63
250
+ 00:03:53,000 --> 00:03:54,000
251
+ Let me give you a couple of examples.
252
+
253
+ 64
254
+ 00:03:55,000 --> 00:03:59,000
255
+ So let's say my sonicwall once again.
256
+
257
+ 65
258
+ 00:04:01,000 --> 00:04:07,000
259
+ Now when this thing fails, let's say it's common for the for the memory chip to fail.
260
+
261
+ 66
262
+ 00:04:07,000 --> 00:04:10,000
263
+ If the memory chips fail, how long will it take to repair it?
264
+
265
+ 67
266
+ 00:04:10,000 --> 00:04:15,000
267
+ Well, it takes about two hours to take it out, reprogram it, reflash it, put the memory chip back
268
+
269
+ 68
270
+ 00:04:15,000 --> 00:04:15,000
271
+ in.
272
+
273
+ 69
274
+ 00:04:15,000 --> 00:04:20,000
275
+ So the mean time to repair for this device is two hours.
276
+
277
+ 70
278
+ 00:04:20,000 --> 00:04:23,000
279
+ Now, how often does this device fail?
280
+
281
+ 71
282
+ 00:04:23,000 --> 00:04:27,000
283
+ Let's say in a normal work environment, it fails every two years.
284
+
285
+ 72
286
+ 00:04:27,000 --> 00:04:33,000
287
+ So the mean time between failure would be two years and the mean time to repair would be two hours.
288
+
289
+ 73
290
+ 00:04:33,000 --> 00:04:34,000
291
+ All right.
292
+
293
+ 74
294
+ 00:04:34,000 --> 00:04:41,000
295
+ So between the failures, how long versus how long does it take to fix it.
296
+
297
+ 75
298
+ 00:04:41,000 --> 00:04:42,000
299
+ All right.
300
+
301
+ 76
302
+ 00:04:42,000 --> 00:04:45,000
303
+ These were some important terms you want to be familiar with for your exam.
304
+
305
+ 77
306
+ 00:04:45,000 --> 00:04:48,000
307
+ They're really famous and asking you these kinds of terms.
308
+
309
+ 78
310
+ 00:04:48,000 --> 00:04:53,000
311
+ Just remember that a business impact analysis is about seeing how different disasters can affect your
312
+
313
+ 79
314
+ 00:04:53,000 --> 00:04:54,000
315
+ business.
316
+
317
+ 80
318
+ 00:04:54,000 --> 00:05:01,000
319
+ How long will a certain disaster take out your business for maximum tolerable outage or maximum tolerable
320
+
321
+ 81
322
+ 00:05:01,000 --> 00:05:02,000
323
+ downtime?
324
+
325
+ 82
326
+ 00:05:02,000 --> 00:05:07,000
327
+ MTD is how long your business can go down from a particular disaster.
328
+
329
+ 83
330
+ 00:05:07,000 --> 00:05:12,000
331
+ How long will it or could it stay down before irreparable harm?
332
+
333
+ 84
334
+ 00:05:12,000 --> 00:05:15,000
335
+ Now remember, you don't want to stay down.
336
+
337
+ 85
338
+ 00:05:15,000 --> 00:05:17,000
339
+ You want to be able to repair it then.
340
+
341
+ 86
342
+ 00:05:17,000 --> 00:05:20,000
343
+ So you want to make sure that.
344
+
345
+ 87
346
+ 00:05:20,000 --> 00:05:28,000
347
+ Your RPOs RTO recovery time objective, which is how fast you can fix things, is less than your MTD.
348
+
349
+ 88
350
+ 00:05:28,000 --> 00:05:30,000
351
+ Remember those terms for your tests.
352
+
21 - Risk Management/008 Quick Quiz.html ADDED
@@ -0,0 +1,479 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ <!DOCTYPE html>
2
+ <html lang="en">
3
+ <head>
4
+ <meta charset="UTF-8" />
5
+ <meta http-equiv="X-UA-Compatible" content="IE=edge" />
6
+ <meta name="viewport" content="width=device-width, initial-scale=1.0" />
7
+ <title>Quiz</title>
8
+ <style>
9
+ * {
10
+ font-family: system-ui, -apple-system, BlinkMacSystemFont, "Segoe UI", Roboto, Oxygen, Ubuntu, Cantarell,
11
+ "Open Sans", "Helvetica Neue", sans-serif;
12
+ margin: 0;
13
+ padding: 0;
14
+ box-sizing: border-box;
15
+ font-size: 16px;
16
+ }
17
+
18
+ main {
19
+ padding-top: 48px;
20
+ }
21
+
22
+ :root {
23
+ --large-device-width: 850px;
24
+ --primary-color: #0f172a;
25
+ --secondary-color: #020617;
26
+ --primary-text-color: #c7d1dd;
27
+ --secondary-text-color: #061602;
28
+ --success-background: hsl(159, 82%, 24%);
29
+ --success-foreground: hsl(164, 86%, 16%);
30
+ --success: hsl(160, 84%, 39%);
31
+ --danger: #ef4444;
32
+ --warning: #f59e0b;
33
+ --info-background: hsl(218, 81%, 8%);
34
+ --info-foreground: hsl(217, 91%, 85%);
35
+ --border-color: #d1d7dc;
36
+ --check-box-size: 20px;
37
+ /* control the size */
38
+ --check-box-color: var(--info-foreground);
39
+ /* the active color */
40
+ }
41
+
42
+ body {
43
+ position: relative;
44
+ background-color: #020617;
45
+ color: var(--primary-text-color);
46
+ }
47
+
48
+ #score-stats-container {
49
+ position: fixed;
50
+ z-index: 10;
51
+ top: 0;
52
+ height: 40px;
53
+ width: 100%;
54
+ background-color: var(--info-background);
55
+
56
+ padding: 0px 16px;
57
+ color: var(--info-foreground);
58
+ font-weight: 600;
59
+ display: flex;
60
+ align-items: center;
61
+ justify-content: space-between;
62
+ }
63
+
64
+ #quiz-container {
65
+ border-radius: 8px;
66
+ display: flex;
67
+ gap: 16px;
68
+ flex-direction: column;
69
+ }
70
+
71
+ input[type="radio"] {
72
+ height: var(--check-box-size);
73
+ aspect-ratio: 1;
74
+ border: calc(var(--check-box-size) / 8) solid #939393;
75
+ padding: calc(var(--check-box-size) / 8);
76
+ background: radial-gradient(farthest-side, var(--check-box-color) 94%, #0000) 50%/0 0 no-repeat
77
+ content-box;
78
+ border-radius: 50%;
79
+ outline-offset: calc(var(--check-box-size) / 10);
80
+ -webkit-appearance: none;
81
+ -moz-appearance: none;
82
+ appearance: none;
83
+ cursor: pointer;
84
+ font-size: inherit;
85
+ transition: 0.3s;
86
+ }
87
+
88
+ input[type="radio"]:checked {
89
+ border-color: var(--check-box-color);
90
+ background-size: 100% 100%;
91
+ }
92
+
93
+ input[type="radio"]:disabled {
94
+ background: linear-gradient(#939393 0 0) 50%/100% 20% no-repeat content-box;
95
+ opacity: 0.5;
96
+ cursor: not-allowed;
97
+ }
98
+
99
+ label {
100
+ display: inline-flex;
101
+ align-items: center;
102
+ gap: 10px;
103
+ cursor: pointer;
104
+ padding: 4px 6px;
105
+ border-radius: 4px;
106
+ }
107
+
108
+ @media (max-width: 767px) {
109
+ input[type="radio"],
110
+ label {
111
+ cursor: default;
112
+ }
113
+
114
+ #quiz-container {
115
+ margin-left: 8px;
116
+ margin-right: 8px;
117
+ }
118
+ }
119
+
120
+ /* PC (Desktop devices) */
121
+ @media (min-width: 768px) {
122
+ body {
123
+ display: flex;
124
+ justify-content: center;
125
+ }
126
+
127
+ main {
128
+ max-width: var(--large-device-width);
129
+ }
130
+
131
+ #score-stats-container {
132
+ max-width: var(--large-device-width);
133
+ }
134
+
135
+ dialog {
136
+ max-width: var(--large-device-width);
137
+ }
138
+ }
139
+
140
+ @media print {
141
+ input[type="radio"] {
142
+ background: none !important;
143
+ border-color: #939393 !important;
144
+ }
145
+
146
+ input[type="radio"]:checked {
147
+ border-color: #939393 !important;
148
+ }
149
+ }
150
+
151
+ .question-lable {
152
+ display: flex;
153
+ align-items: center;
154
+ gap: 8px;
155
+ }
156
+
157
+ button {
158
+ -webkit-tap-highlight-color: transparent;
159
+ -webkit-touch-callout: none;
160
+ -webkit-user-select: none;
161
+ user-select: none;
162
+ outline: none;
163
+ position: relative;
164
+ overflow: hidden;
165
+ cursor: pointer;
166
+ }
167
+
168
+ .button {
169
+ background-color: var(--success-background);
170
+ border: none;
171
+ color: #f4f5f7;
172
+ opacity: 0.8;
173
+ font-size: 18px;
174
+ flex-grow: 1;
175
+ padding: 8px 16px;
176
+ border-radius: 8px;
177
+ }
178
+
179
+ .button:hover {
180
+ opacity: 1;
181
+ }
182
+
183
+ .explanation-btn {
184
+ border: none;
185
+ color: var(--success);
186
+ background-color: transparent;
187
+ }
188
+
189
+ #submit-button:active::after {
190
+ background-color: #ef4444;
191
+ }
192
+
193
+ .single-question-container {
194
+ background-color: var(--primary-color);
195
+ display: flex;
196
+ flex-direction: column;
197
+ gap: 8px;
198
+ padding: 16px;
199
+ border-radius: 8px;
200
+ }
201
+
202
+ #modal-content {
203
+ padding: 16px;
204
+ line-height: 24px;
205
+ }
206
+
207
+ dialog::backdrop {
208
+ background: rgba(0, 0, 0, 0.5);
209
+ }
210
+
211
+ dialog {
212
+ position: fixed;
213
+ border: 1px solid var(--border-color);
214
+ background-color: var(--primary-color);
215
+ color: rgb(240, 241, 248);
216
+ padding: 16px;
217
+ border-radius: 8px;
218
+ width: 80vw;
219
+ max-height: 80vh;
220
+ overflow: auto;
221
+ top: 50%;
222
+ left: 50%;
223
+ -webkit-transform: translateX(-50%) translateY(-50%);
224
+ -moz-transform: translateX(-50%) translateY(-50%);
225
+ -ms-transform: translateX(-50%) translateY(-50%);
226
+ transform: translateX(-50%) translateY(-50%);
227
+ }
228
+
229
+ #close-modal-btn {
230
+ position: absolute;
231
+ top: 4px;
232
+ right: 4px;
233
+ padding: 2px 8px;
234
+ border-radius: 2px;
235
+ border: none;
236
+ background-color: var(--danger);
237
+ }
238
+
239
+ .correct-answer label {
240
+ border: 2px solid var(--success);
241
+ width: 100%;
242
+ }
243
+
244
+ .incorrect-answer label {
245
+ border: 2px solid var(--danger);
246
+ width: 100%;
247
+ }
248
+
249
+ .options-container {
250
+ display: flex;
251
+ flex-direction: column;
252
+ gap: 4px;
253
+ }
254
+
255
+ #quiz-meta-container {
256
+ border-radius: 8px;
257
+ background-color: var(--primary-color);
258
+ margin-bottom: 12px;
259
+ padding: 8px;
260
+ }
261
+
262
+ #quiz-title {
263
+ text-align: center;
264
+ font-size: 24px;
265
+ margin-bottom: 8px;
266
+ }
267
+
268
+ #quiz-description {
269
+ line-height: 1.5;
270
+ padding: 2px 6px;
271
+ }
272
+ </style>
273
+ </head>
274
+
275
+ <body onload="main()">
276
+ <main>
277
+ <section id="quiz-meta-container">
278
+ <h1 id="quiz-title"></h1>
279
+ <p id="quiz-description"></p>
280
+ </section>
281
+ <section id="score-stats-container">
282
+ <div id="score-card">
283
+ Score: <span id="current-score">999</span> of
284
+ <span id="pass-percent">999%</span>
285
+ </div>
286
+ <div>Correct: <span id="correct-answers">999</span></div>
287
+ <div>Incorrect: <span id="wrong-answers">999</span></div>
288
+ </section>
289
+
290
+ <section id="quiz-container"></section>
291
+
292
+ <dialog id="modal" class="modal-container">
293
+ <div id="modal-content">
294
+ <p id="modal-text"></p>
295
+ </div>
296
+ </dialog>
297
+ </main>
298
+
299
+ <script>
300
+ const quizData = {"quiz_id": 6180184, "quiz_description": null, "quiz_title": "Quick Quiz", "pass_percent": null, "questions": [{"_class": "assessment", "id": 74731596, "assessment_type": "multiple-choice", "prompt": {"question": "<p>A newly established e-commerce platform needs to identify potential risks to its operations. What should be their first step in the risk management process?</p>", "relatedLectureIds": "", "feedbacks": ["", "", "The first step for the e-commerce platform in the risk management process should be Risk Identification. This involves recognizing potential risks that could negatively impact their operations, such as cybersecurity threats, data breaches, or system failures. By identifying these risks upfront, the platform can better prepare and manage them. While Business Impact Analysis, setting up a Risk Register, and developing Risk Management Strategies are important, they follow after the initial identification of risks.", ""], "answers": ["<p>Conducting a Business Impact Analysis</p>", "<p>Setting up a Risk Register</p>", "<p>Performing Risk Identification</p>", "<p>Developing Risk Management Strategies</p>"]}, "correct_response": ["c"], "section": "", "question_plain": "A newly established e-commerce platform needs to identify potential risks to its operations. What should be their first step in the risk management process?", "related_lectures": []}, {"_class": "assessment", "id": 74731604, "assessment_type": "multiple-choice", "prompt": {"question": "<p>A small business is establishing a risk management process and wants to record and monitor identified risks. What tool should they prioritize setting up?</p>", "relatedLectureIds": "", "feedbacks": ["The small business should prioritize setting up a Risk Register. A Risk Register is a tool used to record identified risks, along with information such as key risk indicators, risk owners, and risk thresholds. It serves as a central repository for tracking and monitoring risks, which is essential for any risk management process. Business Impact Analysis, Risk Tolerance, and Risk Appetite are important but are separate elements of the risk management process and do not substitute for a centralized risk recording and monitoring tool.", "", "", ""], "answers": ["<p>Risk Register</p>", "<p>Business Impact Analysis Report</p>", "<p>Risk Tolerance Policy</p>", "<p>Risk Appetite Statement</p>"]}, "correct_response": ["a"], "section": "", "question_plain": "A small business is establishing a risk management process and wants to record and monitor identified risks. What tool should they prioritize setting up?", "related_lectures": []}, {"_class": "assessment", "id": 74731606, "assessment_type": "multiple-choice", "prompt": {"question": "<p>A software development firm needs to decide how to handle the risk of potential litigation due to copyright infringement. Which risk management strategy would be most appropriate?</p>", "relatedLectureIds": "", "feedbacks": ["", "", "The most appropriate risk management strategy for the software development firm in this case would be Risk Transfer. This could involve purchasing insurance to cover potential litigation costs related to copyright infringement. Risk Transfer shifts the financial burden of a risk to a third party, reducing the company's direct exposure. Risk Acceptance would involve tolerating the risk without action, Risk Avoidance would mean changing practices to eliminate the risk (which might not be feasible), and Risk Mitigation would involve reducing the risk's impact or likelihood but not transferring it", ""], "answers": ["<p>Risk Acceptance</p>", "<p>Risk Avoidance</p>", "<p>Risk Transfer</p>", "<p>Risk Mitigation</p>"]}, "correct_response": ["c"], "section": "", "question_plain": "A software development firm needs to decide how to handle the risk of potential litigation due to copyright infringement. Which risk management strategy would be most appropriate?", "related_lectures": []}, {"_class": "assessment", "id": 74731614, "assessment_type": "multiple-choice", "prompt": {"question": "<p>An online retailer is conducting a Business Impact Analysis. What are they likely focusing on to ensure business continuity?</p>", "relatedLectureIds": "", "feedbacks": ["In conducting a Business Impact Analysis, the online retailer is likely focusing on Recovery Time Objective (RTO) and Recovery Point Objective (RPO). RTO is the time within which business functions must be restored after a disruption to avoid unacceptable consequences, and RPO is the maximum age of files that must be recovered from backup storage for normal operations to resume. These objectives are crucial in planning for business continuity and disaster recovery. ARO and Probability relate to risk analysis, while Risk Tolerance and Risk Appetite pertain to how much risk the business is willi", "", "", ""], "answers": ["<p>Recovery Time Objective (RTO) and Recovery Point Objective (RPO)</p>", "<p>Annualized Rate of Occurrence (ARO) and Probability</p>", "<p>Risk Tolerance and Risk Appetite</p>", "<p>Risk Register Updates</p>"]}, "correct_response": ["a"], "section": "", "question_plain": "An online retailer is conducting a Business Impact Analysis. What are they likely focusing on to ensure business continuity?", "related_lectures": []}, {"_class": "assessment", "id": 74731624, "assessment_type": "multiple-choice", "prompt": {"question": "<p>A cloud service provider is evaluating the potential impacts of various risks on their service availability. What method of risk analysis should they use to assess the potential frequency of these risks?</p>", "relatedLectureIds": "", "feedbacks": ["", "", "The cloud service provider should use the method of assessing the Annualized Rate of Occurrence (ARO) to evaluate the potential frequency of various risks. ARO is a quantitative risk analysis tool that estimates how often a specific risk is expected to occur within a year. This assessment will help the provider understand the likelihood of different risks, which is crucial for planning mitigation strategies and ensuring reliable service availability. ", ""], "answers": ["<p>Qualitative Risk Analysis</p>", "<p>Quantitative Risk Analysis</p>", "<p>Assessing the Annualized Rate of Occurrence (ARO)</p>", "<p>Conducting a Risk Tolerance Evaluation</p>"]}, "correct_response": ["c"], "section": "", "question_plain": "A cloud service provider is evaluating the potential impacts of various risks on their service availability. What method of risk analysis should they use to assess the potential frequency of these risks?", "related_lectures": []}]};
301
+ let correct = new Set();
302
+ let incorrect = new Set();
303
+ let totalNumberOfQuestions = 0;
304
+ const quizTitle = quizData.quiz_title;
305
+ const quizDescription = quizData.quiz_description;
306
+ const questionData = quizData.questions;
307
+ const passPercent = quizData.pass_percent;
308
+ const modalTextElement = document.getElementById("modal-text");
309
+ const quizContainerElement = document.getElementById("quiz-container");
310
+
311
+ const dialog = document.querySelector("dialog");
312
+ const showButton = document.getElementById("view-explanatin");
313
+ const closeButton = document.getElementById("close-modal-btn");
314
+ const quizTitleElement = document.getElementById("quiz-title");
315
+ const quizDescriptionElement = document.getElementById("quiz-description");
316
+
317
+ function main() {
318
+ // update quiz meta data
319
+ document.title = quizTitle;
320
+ quizTitleElement.innerHTML = quizTitle;
321
+ quizDescriptionElement.innerHTML = quizDescription;
322
+
323
+ const passPercentElement = document.getElementById("pass-percent");
324
+ passPercentElement.innerHTML = passPercent + "%";
325
+ totalNumberOfQuestions = questionData.length;
326
+ // shuffle the questionData to randomize the order of the questions
327
+ for (let i = questionData.length - 1; i > 0; i--) {
328
+ const j = Math.floor(Math.random() * (i + 1));
329
+ [questionData[i], questionData[j]] = [questionData[j], questionData[i]];
330
+ }
331
+
332
+ let formattedQuestions = questionData.map(formatSingleQuestionData);
333
+ updateScore();
334
+ // display the formattedQuestions
335
+ formattedQuestions.forEach((question, idx) => {
336
+ renderSingleQuestion(question, idx + 1);
337
+ });
338
+ }
339
+
340
+ /**
341
+ * Formats the question data from the given QuizData object.
342
+ *
343
+ * @param {Object} singleQuizData - The singleQuizData object containing prompt and correct_response.
344
+ * @return {Object} The formatted question object with the following properties:
345
+ * - id: The ID of the question.
346
+ * - question: The text of the question.
347
+ * - answers: The array of answer options.
348
+ * - correctAnswer: The text of the correct answer.
349
+ * - explanation: The explanation of the correct answer.
350
+ */
351
+ function formatSingleQuestionData(singleQuizData = null) {
352
+ const { prompt, correct_response, id } = singleQuizData;
353
+ const questionText = prompt.question;
354
+ const answers = prompt.answers;
355
+ const correctAnswer = correct_response[0];
356
+ const correctAnswerText = answers[correctAnswer.toLowerCase().charCodeAt(0) - 97];
357
+ const questionObj = {
358
+ id: id,
359
+ question: questionText,
360
+ answers: answers,
361
+ correctAnswer: correctAnswerText,
362
+ explanation: prompt?.explanation || "",
363
+ };
364
+ return questionObj;
365
+ }
366
+
367
+ /**
368
+ * Renders a single question with its options and submit button.
369
+ *
370
+ * @param {Object} singleQuestionData - The data of the question to render.
371
+ * @param {number} rootIndex - The index of the question in the quiz.
372
+ * @return {void} return nothing.
373
+ */
374
+
375
+ const renderSingleQuestion = (singleQuestionData = {}, rootIndex = 1) => {
376
+ const { id, explanation, answers, correctAnswer, question } = singleQuestionData;
377
+ // shuffle the answers to randomize the order of the answers
378
+ for (let i = answers.length - 1; i > 0; i--) {
379
+ const j = Math.floor(Math.random() * (i + 1));
380
+ [answers[i], answers[j]] = [answers[j], answers[i]];
381
+ }
382
+ const optionsHTML = answers
383
+ .map((option, index) => {
384
+ const optionId = `${id}_${index}`;
385
+
386
+ return `
387
+ <div class="question-lable">
388
+ <input type="radio" id="${optionId}" name="${"answer"}" value="${option}" />
389
+ <label for="${optionId}">${option}</label>
390
+ </div>
391
+ `;
392
+ })
393
+
394
+ .join("");
395
+
396
+ const container = document.createElement("div");
397
+ container.innerHTML = `
398
+ <form data-correct-answer="${correctAnswer}" data-question-id="${id}" class="single-question-container" onsubmit="submitButtonListener(event)">
399
+ <div style="display: flex;justify-content: space-between;">
400
+ <p style="font-weight: 600">Question ${rootIndex}:</p>
401
+ <button type="button" onclick="renderExplanation(event)" id="${`explanation-${id}`}" data-explanation="${explanation}" class="explanation-btn">View Explanation</button>
402
+ </div>
403
+ <p style="margin-bottom: 8px;line-height: 1.5">${question}</p>
404
+ <div class="options-container">
405
+ ${optionsHTML}
406
+ </div>
407
+ <div style="display: flex; gap: 8px;">
408
+ <button type="submit" id="submit-button" class="button">Submit</button>
409
+ </div>
410
+ </form>
411
+ `;
412
+ quizContainerElement.appendChild(container);
413
+ };
414
+
415
+ /**
416
+ * Updates the score on the page based on the number of correct and incorrect answers.
417
+ *
418
+ * @return {void} This function does not return a value.
419
+ */
420
+ function updateScore() {
421
+ const currentParcentageElement = document.getElementById("current-score");
422
+ const correctAnswerElement = document.getElementById("correct-answers");
423
+ const wrongAnswerElement = document.getElementById("wrong-answers");
424
+ correctAnswerElement.innerHTML = correct.size;
425
+ wrongAnswerElement.innerHTML = incorrect.size;
426
+ const score = Number((correct.size / totalNumberOfQuestions) * 100).toFixed(2);
427
+ currentParcentageElement.innerHTML = score;
428
+ }
429
+
430
+ /**
431
+ * Handles the event when the submit button is clicked.
432
+ *
433
+ * @param {Event} e - The event object.
434
+ * @return {void} This function does not return anything.
435
+ */
436
+ const submitButtonListener = (e) => {
437
+ e.preventDefault();
438
+ const formData = new FormData(e.target);
439
+ const form = e.target;
440
+ const selectedOption = e.target.querySelector('input[type="radio"]:checked');
441
+ if (!selectedOption) {
442
+ alert("Please select an answer!");
443
+ return;
444
+ }
445
+
446
+ let isCorrect = false;
447
+ const { answer: userAnswer } = Object.fromEntries(formData.entries());
448
+ const correctAnswer = e.target.dataset.correctAnswer;
449
+ const questionId = e.target.dataset.questionId;
450
+ if (userAnswer == correctAnswer) {
451
+ correct.add(questionId);
452
+ incorrect.delete(questionId);
453
+ isCorrect = true;
454
+ } else {
455
+ incorrect.add(e.target.dataset.questionId);
456
+ correct.delete(questionId);
457
+ }
458
+ updateScore();
459
+
460
+ const resultClass = isCorrect ? "correct-answer" : "incorrect-answer";
461
+
462
+ form.querySelectorAll(".question-lable").forEach((label) => {
463
+ label.classList.remove("correct-answer", "incorrect-answer");
464
+ });
465
+ selectedOption.closest(".question-lable").classList.add(resultClass);
466
+ };
467
+
468
+ function renderExplanation(ev) {
469
+ modalTextElement.innerHTML = ev.target.dataset?.explanation || "no explanation found";
470
+ dialog.showModal();
471
+ dialog.addEventListener("click", (event) => {
472
+ if (event.target === dialog) {
473
+ dialog.close();
474
+ }
475
+ });
476
+ }
477
+ </script>
478
+ </body>
479
+ </html>
22 - Vendor Management/001 Vendor Assessment and Selection OB 5.3_en.srt ADDED
@@ -0,0 +1,888 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ 1
2
+ 00:00:00,000 --> 00:00:05,000
3
+ When it comes to working in information technology, you are going to be dealing with a lot of vendors
4
+
5
+ 2
6
+ 00:00:05,000 --> 00:00:07,000
7
+ when I mean a ton of vendors, I mean a lot.
8
+
9
+ 3
10
+ 00:00:07,000 --> 00:00:12,000
11
+ You see, in the world of it, we really don't make firewalls, right?
12
+
13
+ 4
14
+ 00:00:12,000 --> 00:00:18,000
15
+ I've never met an organization that produces their own firewall or their own antivirus software or their
16
+
17
+ 5
18
+ 00:00:18,000 --> 00:00:20,000
19
+ own operating system.
20
+
21
+ 6
22
+ 00:00:20,000 --> 00:00:22,000
23
+ So we're going to be dealing with a lot of vendors.
24
+
25
+ 7
26
+ 00:00:22,000 --> 00:00:24,000
27
+ For example, I have the Sonicwall student on my desk.
28
+
29
+ 8
30
+ 00:00:24,000 --> 00:00:29,000
31
+ This was bought from Dell, or now Sonicwall, or I should say Dell owned Sonicwall.
32
+
33
+ 9
34
+ 00:00:30,000 --> 00:00:32,000
35
+ So this is a vendor.
36
+
37
+ 10
38
+ 00:00:32,000 --> 00:00:35,000
39
+ Our laptops are purchased from Lenovo, for example.
40
+
41
+ 11
42
+ 00:00:35,000 --> 00:00:40,000
43
+ So in the world of technology, you're going to be dealing with a lot of vendors, whether that's a
44
+
45
+ 12
46
+ 00:00:40,000 --> 00:00:45,000
47
+ third party vendor such as Dell, that you purchase your hardware from Microsoft, where you're going
48
+
49
+ 13
50
+ 00:00:45,000 --> 00:00:51,000
51
+ to get your operating systems from, uh, Symantec's or Broadcom, or you're going to get your, your
52
+
53
+ 14
54
+ 00:00:51,000 --> 00:00:56,000
55
+ security software from tons and tons of vendors, then you're going to have vendors coming into your
56
+
57
+ 15
58
+ 00:00:56,000 --> 00:01:00,000
59
+ organization to repair some of these devices, and of course, to update your software.
60
+
61
+ 16
62
+ 00:01:00,000 --> 00:01:06,000
63
+ So in this video, let's take a look at what should we be doing or what should we be looking at when
64
+
65
+ 17
66
+ 00:01:06,000 --> 00:01:12,000
67
+ we are going to be assessing a particular vendor, things that we want to look for, how are we going
68
+
69
+ 18
70
+ 00:01:12,000 --> 00:01:13,000
71
+ to keep them monitored?
72
+
73
+ 19
74
+ 00:01:13,000 --> 00:01:17,000
75
+ And of course, in the end, part of this section will take a look at different agreements that we can
76
+
77
+ 20
78
+ 00:01:17,000 --> 00:01:18,000
79
+ have with vendors.
80
+
81
+ 21
82
+ 00:01:18,000 --> 00:01:20,000
83
+ Let's go through this pretty quickly.
84
+
85
+ 22
86
+ 00:01:20,000 --> 00:01:22,000
87
+ So the first thing up is vendor assessment.
88
+
89
+ 23
90
+ 00:01:22,000 --> 00:01:25,000
91
+ What exactly is this concept of assessing vendor.
92
+
93
+ 24
94
+ 00:01:26,000 --> 00:01:33,000
95
+ Well, it's about evaluating and monitoring the security risks associated with third party providers
96
+
97
+ 25
98
+ 00:01:33,000 --> 00:01:34,000
99
+ in your network.
100
+
101
+ 26
102
+ 00:01:34,000 --> 00:01:36,000
103
+ You control all aspects of it.
104
+
105
+ 27
106
+ 00:01:36,000 --> 00:01:42,000
107
+ But the moment you go and you introduce a third party device into your network, this device could bring
108
+
109
+ 28
110
+ 00:01:42,000 --> 00:01:43,000
111
+ problems.
112
+
113
+ 29
114
+ 00:01:43,000 --> 00:01:48,000
115
+ If this device is compromised and shipped to you in a compromised state, it already has malware on
116
+
117
+ 30
118
+ 00:01:48,000 --> 00:01:53,000
119
+ it or some kind of monitoring legal software, and you install this into your organization.
120
+
121
+ 31
122
+ 00:01:53,000 --> 00:01:56,000
123
+ You just got compromised by bringing in somebody else's software.
124
+
125
+ 32
126
+ 00:01:56,000 --> 00:01:58,000
127
+ So obviously you don't want that.
128
+
129
+ 33
130
+ 00:01:58,000 --> 00:02:01,000
131
+ So in this particular one, what is the security risk?
132
+
133
+ 34
134
+ 00:02:01,000 --> 00:02:06,000
135
+ Well, the security risk is like I mentioned, put in compromised devices in your network.
136
+
137
+ 35
138
+ 00:02:06,000 --> 00:02:11,000
139
+ It involves scrutinizing vendors cybersecurity practices, policies and compliance.
140
+
141
+ 36
142
+ 00:02:11,000 --> 00:02:17,000
143
+ Listen, when I purchase software, I really don't purchase software and or hardware from small vendors.
144
+
145
+ 37
146
+ 00:02:17,000 --> 00:02:19,000
147
+ I like going with the bigger vendors.
148
+
149
+ 38
150
+ 00:02:19,000 --> 00:02:26,000
151
+ That's more scrutinized by all kinds of regulations they have to follow, or all kinds of different
152
+
153
+ 39
154
+ 00:02:26,000 --> 00:02:27,000
155
+ financial audits that they may have.
156
+
157
+ 40
158
+ 00:02:29,000 --> 00:02:34,000
159
+ Bigger vendors, in my opinion, will probably have better practices, more policies, and they're going
160
+
161
+ 41
162
+ 00:02:34,000 --> 00:02:36,000
163
+ to have to be more in compliance.
164
+
165
+ 42
166
+ 00:02:36,000 --> 00:02:39,000
167
+ Maybe they have things like penetration testing done on their networks.
168
+
169
+ 43
170
+ 00:02:39,000 --> 00:02:44,000
171
+ Maybe they have particular audit reports, maybe they have particular way they handle data and maintain
172
+
173
+ 44
174
+ 00:02:44,000 --> 00:02:45,000
175
+ privacy.
176
+
177
+ 45
178
+ 00:02:45,000 --> 00:02:53,000
179
+ Now the goal here is to ensure that the vendors security posture aligns with your organization's security
180
+
181
+ 46
182
+ 00:02:53,000 --> 00:02:58,000
183
+ requirements and that risk management strategies and anything that's going to be done to minimize risks
184
+
185
+ 47
186
+ 00:02:58,000 --> 00:03:00,000
187
+ to our systems and data.
188
+
189
+ 48
190
+ 00:03:00,000 --> 00:03:08,000
191
+ Now, security posture is this you can't have an amazing security organization with great policies,
192
+
193
+ 49
194
+ 00:03:08,000 --> 00:03:11,000
195
+ but then the vendors you deal with actually don't.
196
+
197
+ 50
198
+ 00:03:11,000 --> 00:03:14,000
199
+ In other words, they don't follow good security practices.
200
+
201
+ 51
202
+ 00:03:14,000 --> 00:03:15,000
203
+ So what happens?
204
+
205
+ 52
206
+ 00:03:15,000 --> 00:03:19,000
207
+ You end up bringing in poor security practices into your company.
208
+
209
+ 53
210
+ 00:03:19,000 --> 00:03:22,000
211
+ Now there are some things here that we want to review.
212
+
213
+ 54
214
+ 00:03:23,000 --> 00:03:26,000
215
+ When you are getting vendors, okay.
216
+
217
+ 55
218
+ 00:03:26,000 --> 00:03:32,000
219
+ When it comes to seeing how well their security issues are managed, there is this concept of penetration
220
+
221
+ 56
222
+ 00:03:32,000 --> 00:03:33,000
223
+ testing.
224
+
225
+ 57
226
+ 00:03:33,000 --> 00:03:38,000
227
+ So did the vendor get a penetration test against their system?
228
+
229
+ 58
230
+ 00:03:38,000 --> 00:03:42,000
231
+ Now keep in mind that you can also hire vendors to penetrate your systems.
232
+
233
+ 59
234
+ 00:03:42,000 --> 00:03:48,000
235
+ When you hire a third party to get penetration testing done against you, but vendors should have a
236
+
237
+ 60
238
+ 00:03:48,000 --> 00:03:50,000
239
+ pen test done against their system.
240
+
241
+ 61
242
+ 00:03:50,000 --> 00:03:56,000
243
+ Think about this if this vendor is holding your private data, maybe it's a type of a cloud service
244
+
245
+ 62
246
+ 00:03:56,000 --> 00:03:58,000
247
+ that they're going to be storing your information.
248
+
249
+ 63
250
+ 00:03:59,000 --> 00:04:03,000
251
+ Uh, maybe it's a company that processes certain medical records because you deal in medical.
252
+
253
+ 64
254
+ 00:04:03,000 --> 00:04:05,000
255
+ They're going to have your patient's information.
256
+
257
+ 65
258
+ 00:04:05,000 --> 00:04:10,000
259
+ Did they have a pen test done against their system to test their security policy?
260
+
261
+ 66
262
+ 00:04:10,000 --> 00:04:15,000
263
+ So this involves simulating cyber attacks against the vendor system to assess the security.
264
+
265
+ 67
266
+ 00:04:15,000 --> 00:04:21,000
267
+ This particularly important for vendors handling sensitive or critical data because once again how do
268
+
269
+ 68
270
+ 00:04:21,000 --> 00:04:24,000
271
+ we know if they're systems is actually secure.
272
+
273
+ 69
274
+ 00:04:24,000 --> 00:04:29,000
275
+ Well, a pen test can tell us if there's any vulnerability and what those vulnerabilities are.
276
+
277
+ 70
278
+ 00:04:29,000 --> 00:04:35,000
279
+ Results from this test can reveal any kind of vulnerabilities that poses a risk to that organization.
280
+
281
+ 71
282
+ 00:04:35,000 --> 00:04:41,000
283
+ Another thing you may want to ask your vendors about is a right to audit clause.
284
+
285
+ 72
286
+ 00:04:41,000 --> 00:04:47,000
287
+ This involves, and you're usually going to put this in your contracts that grants you the organization,
288
+
289
+ 73
290
+ 00:04:47,000 --> 00:04:54,000
291
+ the right to conduct or have conducted on its behalf an audit of the vendor security practices.
292
+
293
+ 74
294
+ 00:04:54,000 --> 00:04:59,000
295
+ Now, when it comes to large organizations, this is something not easy to get.
296
+
297
+ 75
298
+ 00:04:59,000 --> 00:05:05,000
299
+ This is when you have something in a contract that states that you have the ability to audit them or
300
+
301
+ 76
302
+ 00:05:05,000 --> 00:05:10,000
303
+ have a third party company, maybe of your choice, audit their security practices.
304
+
305
+ 77
306
+ 00:05:10,000 --> 00:05:11,000
307
+ Not so much.
308
+
309
+ 78
310
+ 00:05:11,000 --> 00:05:14,000
311
+ So in large organizations like large third party vendors.
312
+
313
+ 79
314
+ 00:05:14,000 --> 00:05:21,000
315
+ But for example, I'm not I might not have that on a contract with Dell, but Dell generally gets a
316
+
317
+ 80
318
+ 00:05:21,000 --> 00:05:25,000
319
+ lot of different third party and external audits done.
320
+
321
+ 81
322
+ 00:05:25,000 --> 00:05:30,000
323
+ This can include reviewing security policies, all their different controls that they have applied.
324
+
325
+ 82
326
+ 00:05:30,000 --> 00:05:34,000
327
+ And do they have any type of compliance that they have to stay with now?
328
+
329
+ 83
330
+ 00:05:34,000 --> 00:05:36,000
331
+ Evidence of internal audits.
332
+
333
+ 84
334
+ 00:05:36,000 --> 00:05:40,000
335
+ Every organization should be doing some kind of internal audit.
336
+
337
+ 85
338
+ 00:05:40,000 --> 00:05:45,000
339
+ Internal audits is when their own auditors inside of their organization.
340
+
341
+ 86
342
+ 00:05:45,000 --> 00:05:51,000
343
+ Now I spent about a year, I believe, or a little less than a year, being an internal auditor before
344
+
345
+ 87
346
+ 00:05:51,000 --> 00:05:52,000
347
+ it became a pentester.
348
+
349
+ 88
350
+ 00:05:52,000 --> 00:06:00,000
351
+ And basically you just reviewing the internal security policies, procedures and findings within the
352
+
353
+ 89
354
+ 00:06:00,000 --> 00:06:01,000
355
+ organization.
356
+
357
+ 90
358
+ 00:06:01,000 --> 00:06:05,000
359
+ For example, if there is a policy that says secure passwords, do we actually have that?
360
+
361
+ 91
362
+ 00:06:05,000 --> 00:06:12,000
363
+ So internal audits is something that the company does on a regular basis with their own internal employees.
364
+
365
+ 92
366
+ 00:06:12,000 --> 00:06:20,000
367
+ Does the vendor have evidence of these regular internal audits of their security processes and their
368
+
369
+ 93
370
+ 00:06:20,000 --> 00:06:20,000
371
+ controls?
372
+
373
+ 94
374
+ 00:06:20,000 --> 00:06:23,000
375
+ Maybe they can show you audit reports.
376
+
377
+ 95
378
+ 00:06:23,000 --> 00:06:28,000
379
+ Maybe they can do a summary of different findings that they found and how they fixed it.
380
+
381
+ 96
382
+ 00:06:28,000 --> 00:06:32,000
383
+ And what what was the remediation against those findings.
384
+
385
+ 97
386
+ 00:06:33,000 --> 00:06:39,000
387
+ Now, a lot of times, one of the best things that I believe that we can get is an independent assessment.
388
+
389
+ 98
390
+ 00:06:39,000 --> 00:06:44,000
391
+ I don't want the order the third party vendor to come and say, like, Dell is going to tell me, yeah,
392
+
393
+ 99
394
+ 00:06:44,000 --> 00:06:45,000
395
+ we are super secure.
396
+
397
+ 100
398
+ 00:06:45,000 --> 00:06:48,000
399
+ You telling me that is the same way?
400
+
401
+ 101
402
+ 00:06:48,000 --> 00:06:52,000
403
+ Me telling you that I am the smartest man in the world, in my opinion.
404
+
405
+ 102
406
+ 00:06:52,000 --> 00:06:53,000
407
+ So.
408
+
409
+ 103
410
+ 00:06:53,000 --> 00:06:59,000
411
+ But if you can get a third party evaluator to evaluate you and tell me that you have good security controls,
412
+
413
+ 104
414
+ 00:06:59,000 --> 00:07:01,000
415
+ that gives me a good peace of mind.
416
+
417
+ 105
418
+ 00:07:01,000 --> 00:07:03,000
419
+ So that's an independent assessment.
420
+
421
+ 106
422
+ 00:07:03,000 --> 00:07:07,000
423
+ It's generally done by third party and sometimes it involves a certification.
424
+
425
+ 107
426
+ 00:07:07,000 --> 00:07:13,000
427
+ There's what's called ISO certification or ISO 27,000 which produces an information security management
428
+
429
+ 108
430
+ 00:07:13,000 --> 00:07:13,000
431
+ system.
432
+
433
+ 109
434
+ 00:07:13,000 --> 00:07:15,000
435
+ There's also what's called SoC audits.
436
+
437
+ 110
438
+ 00:07:15,000 --> 00:07:20,000
439
+ These are going to be audits to test for different security controls against the CIA.
440
+
441
+ 111
442
+ 00:07:20,000 --> 00:07:23,000
443
+ These provides more of an objective evaluation.
444
+
445
+ 112
446
+ 00:07:23,000 --> 00:07:27,000
447
+ An objective means something that is very detailed.
448
+
449
+ 113
450
+ 00:07:27,000 --> 00:07:30,000
451
+ It's not subjective like you can question it.
452
+
453
+ 114
454
+ 00:07:30,000 --> 00:07:35,000
455
+ The critical for verifying that the vendor heeds the good industry practices.
456
+
457
+ 115
458
+ 00:07:35,000 --> 00:07:38,000
459
+ So if you want to know, does your vendor follow good security practices?
460
+
461
+ 116
462
+ 00:07:38,000 --> 00:07:42,000
463
+ A good third party independent assessment is important.
464
+
465
+ 117
466
+ 00:07:42,000 --> 00:07:46,000
467
+ Another thing you're going to want to ask your vendors about is going to be what's called supply chain
468
+
469
+ 118
470
+ 00:07:46,000 --> 00:07:47,000
471
+ analysis.
472
+
473
+ 119
474
+ 00:07:47,000 --> 00:07:48,000
475
+ Supply chain.
476
+
477
+ 120
478
+ 00:07:48,000 --> 00:07:49,000
479
+ What exactly is supply chain.
480
+
481
+ 121
482
+ 00:07:49,000 --> 00:07:56,000
483
+ Well, how do we take oil out of the ground and turn it into something like this?
484
+
485
+ 122
486
+ 00:07:56,000 --> 00:07:56,000
487
+ Right.
488
+
489
+ 123
490
+ 00:07:56,000 --> 00:08:00,000
491
+ How do we get steel out of the ground and oil out of the ground so we can develop silicone.
492
+
493
+ 124
494
+ 00:08:00,000 --> 00:08:04,000
495
+ We can develop all the parts that comes together and then ship it to me.
496
+
497
+ 125
498
+ 00:08:05,000 --> 00:08:11,000
499
+ So the supply chain is all the things that it goes through, from raw materials to a finished product
500
+
501
+ 126
502
+ 00:08:11,000 --> 00:08:14,000
503
+ that we use as consumers of these products.
504
+
505
+ 127
506
+ 00:08:14,000 --> 00:08:21,000
507
+ Supply chain could be damaged, for example, if they're using a supplier in a part of the world that
508
+
509
+ 128
510
+ 00:08:21,000 --> 00:08:27,000
511
+ is subject to floods or hurricanes and stuff like that, then the supply chain can easily be affected.
512
+
513
+ 129
514
+ 00:08:27,000 --> 00:08:32,000
515
+ Does the vendor have multiple supply chains or supply routes that they can get raw materials from?
516
+
517
+ 130
518
+ 00:08:32,000 --> 00:08:37,000
519
+ So examining the security of the vendor supply chain has vulnerabilities in the chain can directly impact
520
+
521
+ 131
522
+ 00:08:37,000 --> 00:08:39,000
523
+ the security of the products or services.
524
+
525
+ 132
526
+ 00:08:39,000 --> 00:08:42,000
527
+ For example, what if they're getting a microchips?
528
+
529
+ 133
530
+ 00:08:43,000 --> 00:08:50,000
531
+ From a country that is that doesn't like the United States, that can then embed malware in those microchips
532
+
533
+ 134
534
+ 00:08:50,000 --> 00:08:52,000
535
+ and then ship it to me.
536
+
537
+ 135
538
+ 00:08:52,000 --> 00:08:57,000
539
+ Like, for example, what if this thing has what if this sonicwall has chips from a country that doesn't
540
+
541
+ 136
542
+ 00:08:57,000 --> 00:09:02,000
543
+ like the United States, that has malware embedded to it to spy on United States companies?
544
+
545
+ 137
546
+ 00:09:02,000 --> 00:09:08,000
547
+ So the analysis should assess the security practices of not only the primary vendor, but all of their
548
+
549
+ 138
550
+ 00:09:08,000 --> 00:09:10,000
551
+ suppliers that they have.
552
+
553
+ 139
554
+ 00:09:10,000 --> 00:09:12,000
555
+ Now, another thing you want.
556
+
557
+ 140
558
+ 00:09:12,000 --> 00:09:13,000
559
+ How are you going to get this done.
560
+
561
+ 141
562
+ 00:09:13,000 --> 00:09:16,000
563
+ But questionnaires you got to question the vendor.
564
+
565
+ 142
566
+ 00:09:16,000 --> 00:09:18,000
567
+ This question is a critical tool.
568
+
569
+ 143
570
+ 00:09:18,000 --> 00:09:24,000
571
+ You're going to gather information, question them about their practices, their policies and how how
572
+
573
+ 144
574
+ 00:09:24,000 --> 00:09:26,000
575
+ are they going to stay in compliance.
576
+
577
+ 145
578
+ 00:09:26,000 --> 00:09:26,000
579
+ Right.
580
+
581
+ 146
582
+ 00:09:26,000 --> 00:09:33,000
583
+ So the question just literally asking them questions like what practices you follow, what kind of policies
584
+
585
+ 147
586
+ 00:09:33,000 --> 00:09:37,000
587
+ you have, this is really going to assess the risks that they may bring to us.
588
+
589
+ 148
590
+ 00:09:38,000 --> 00:09:43,000
591
+ Now, another thing you're going to want to talk about with them is the rules of engagement.
592
+
593
+ 149
594
+ 00:09:43,000 --> 00:09:46,000
595
+ This is something that you may want to outline in the contract.
596
+
597
+ 150
598
+ 00:09:46,000 --> 00:09:51,000
599
+ The rules of engagement refers to the set of guidelines or protocols that outline how an organization's
600
+
601
+ 151
602
+ 00:09:51,000 --> 00:09:54,000
603
+ interact and cooperate with third party vendors.
604
+
605
+ 152
606
+ 00:09:54,000 --> 00:09:58,000
607
+ So how are we going to deal with that third party vendor?
608
+
609
+ 153
610
+ 00:09:58,000 --> 00:10:00,000
611
+ How are we going to onboard them?
612
+
613
+ 154
614
+ 00:10:00,000 --> 00:10:01,000
615
+ Can we do this?
616
+
617
+ 155
618
+ 00:10:01,000 --> 00:10:02,000
619
+ Can we not do that with them?
620
+
621
+ 156
622
+ 00:10:03,000 --> 00:10:09,000
623
+ Um, this is going to set a good baseline of what we should be expecting of them.
624
+
625
+ 157
626
+ 00:10:09,000 --> 00:10:12,000
627
+ Maybe they got to have a yearly third party assessment done.
628
+
629
+ 158
630
+ 00:10:12,000 --> 00:10:14,000
631
+ What's the responsibilities?
632
+
633
+ 159
634
+ 00:10:14,000 --> 00:10:16,000
635
+ What's the boundaries set between them.
636
+
637
+ 160
638
+ 00:10:16,000 --> 00:10:20,000
639
+ Now when it comes to assessing them, we went through a few things there.
640
+
641
+ 161
642
+ 00:10:20,000 --> 00:10:22,000
643
+ At some point you got to select a vendor.
644
+
645
+ 162
646
+ 00:10:22,000 --> 00:10:25,000
647
+ So this is going to be evaluated.
648
+
649
+ 163
650
+ 00:10:25,000 --> 00:10:27,000
651
+ And choosing the best third party provider.
652
+
653
+ 164
654
+ 00:10:27,000 --> 00:10:36,000
655
+ Like what's or who we should say is the vendor that meets your security posture or that meets the way
656
+
657
+ 165
658
+ 00:10:36,000 --> 00:10:43,000
659
+ you want to do security, meets your recommendations or wants in terms of third party assessments.
660
+
661
+ 166
662
+ 00:10:43,000 --> 00:10:45,000
663
+ Now, there's a couple of things that we want to mention.
664
+
665
+ 167
666
+ 00:10:45,000 --> 00:10:49,000
667
+ The first thing you want to do before selecting any vendor is do your due diligence.
668
+
669
+ 168
670
+ 00:10:49,000 --> 00:10:50,000
671
+ What is due diligence?
672
+
673
+ 169
674
+ 00:10:50,000 --> 00:10:58,000
675
+ Well, it's basically a really comprehensive appraisal or evaluation of the vendors practices focusing
676
+
677
+ 170
678
+ 00:10:58,000 --> 00:11:00,000
679
+ on cybersecurity policies, procedures.
680
+
681
+ 171
682
+ 00:11:00,000 --> 00:11:04,000
683
+ So do do your due diligence.
684
+
685
+ 172
686
+ 00:11:04,000 --> 00:11:08,000
687
+ Due diligence is doing all your homework, all your background information.
688
+
689
+ 173
690
+ 00:11:08,000 --> 00:11:12,000
691
+ Check in things such as did they have some kind of third party compliance?
692
+
693
+ 174
694
+ 00:11:13,000 --> 00:11:14,000
695
+ Are they ISO certified?
696
+
697
+ 175
698
+ 00:11:14,000 --> 00:11:16,000
699
+ Did they have Soc2 reports.
700
+
701
+ 176
702
+ 00:11:16,000 --> 00:11:19,000
703
+ These are going to be audits done by external organizations.
704
+
705
+ 177
706
+ 00:11:19,000 --> 00:11:23,000
707
+ Did they get any past cyber cyber breach?
708
+
709
+ 178
710
+ 00:11:23,000 --> 00:11:25,000
711
+ Is their reputation any good.
712
+
713
+ 179
714
+ 00:11:26,000 --> 00:11:28,000
715
+ Go back ten years.
716
+
717
+ 180
718
+ 00:11:28,000 --> 00:11:30,000
719
+ Did they get hacked at any point?
720
+
721
+ 181
722
+ 00:11:30,000 --> 00:11:32,000
723
+ What was the what was the remediation?
724
+
725
+ 182
726
+ 00:11:32,000 --> 00:11:35,000
727
+ How many times has this organization been hacked?
728
+
729
+ 183
730
+ 00:11:35,000 --> 00:11:39,000
731
+ For example, what is the public's perception of this organization?
732
+
733
+ 184
734
+ 00:11:39,000 --> 00:11:41,000
735
+ This is going to be your due diligence.
736
+
737
+ 185
738
+ 00:11:41,000 --> 00:11:46,000
739
+ Uncover any potential security vulnerabilities and weaknesses before you're selecting them.
740
+
741
+ 186
742
+ 00:11:46,000 --> 00:11:51,000
743
+ Now, one thing that you're going to want to keep in mind is this thing called conflict of interest.
744
+
745
+ 187
746
+ 00:11:51,000 --> 00:11:52,000
747
+ What is it?
748
+
749
+ 188
750
+ 00:11:52,000 --> 00:11:57,000
751
+ Well, this is going to be identifying and managing any conflict of interest.
752
+
753
+ 189
754
+ 00:11:57,000 --> 00:12:03,000
755
+ It's arise when a vendor has listened carefully, competing interests that can influence your ability
756
+
757
+ 190
758
+ 00:12:03,000 --> 00:12:07,000
759
+ to objectively and securely provide security services.
760
+
761
+ 191
762
+ 00:12:07,000 --> 00:12:15,000
763
+ For example, let's say you hire an organization to do pen tests to do a pen test for you.
764
+
765
+ 192
766
+ 00:12:15,000 --> 00:12:19,000
767
+ It's a third party vendor that you're going to be using to do a pen test.
768
+
769
+ 193
770
+ 00:12:19,000 --> 00:12:28,000
771
+ But then you came to realize that the vendors, the vendor, their CEO, their let's say their owner
772
+
773
+ 194
774
+ 00:12:28,000 --> 00:12:35,000
775
+ owns shares or owns a majority shares in a company that directly competes with you.
776
+
777
+ 195
778
+ 00:12:35,000 --> 00:12:41,000
779
+ So your competitor is actually owned by the guy that's doing the pen test for you.
780
+
781
+ 196
782
+ 00:12:41,000 --> 00:12:47,000
783
+ That's something that you want to know now, it's not illegal for them to own, you know, for anybody
784
+
785
+ 197
786
+ 00:12:47,000 --> 00:12:48,000
787
+ to own a business.
788
+
789
+ 198
790
+ 00:12:48,000 --> 00:12:54,000
791
+ But that is called a conflict of interest because can they really objectively analyze your organization?
792
+
793
+ 199
794
+ 00:12:54,000 --> 00:12:57,000
795
+ Are they going to look for things that are going to steal your information?
796
+
797
+ 200
798
+ 00:12:57,000 --> 00:13:05,000
799
+ So keep in mind these kinds of things do occur, and you have to do your due diligence to find out.
800
+
801
+ 201
802
+ 00:13:05,000 --> 00:13:12,000
803
+ Is there any kind of conflict of interest you want to ensure transparency in any kind of impartial ability
804
+
805
+ 202
806
+ 00:13:12,000 --> 00:13:14,000
807
+ with this now?
808
+
809
+ 203
810
+ 00:13:15,000 --> 00:13:20,000
811
+ When you select your vendor, you have to monitor the vendor consistent monitoring of the vendor.
812
+
813
+ 204
814
+ 00:13:21,000 --> 00:13:24,000
815
+ Continuous process assessing and overseeing third party.
816
+
817
+ 205
818
+ 00:13:24,000 --> 00:13:25,000
819
+ Always keep an eye on the vendor.
820
+
821
+ 206
822
+ 00:13:25,000 --> 00:13:26,000
823
+ Look at the news.
824
+
825
+ 207
826
+ 00:13:26,000 --> 00:13:29,000
827
+ Look at all the problems and issues that arise with the vendor.
828
+
829
+ 208
830
+ 00:13:29,000 --> 00:13:36,000
831
+ This includes regular evaluations of the security practices, incident capabilities, and making sure
832
+
833
+ 209
834
+ 00:13:36,000 --> 00:13:40,000
835
+ that they stay relevant on the industry, industry compliance or regulation.
836
+
837
+ 210
838
+ 00:13:41,000 --> 00:13:45,000
839
+ Now you want to proactively identify and manage potential security risks.
840
+
841
+ 211
842
+ 00:13:45,000 --> 00:13:48,000
843
+ Because remember, the world of technology changes every day.
844
+
845
+ 212
846
+ 00:13:48,000 --> 00:13:52,000
847
+ Keep in mind that today there's no problems with the vendor.
848
+
849
+ 213
850
+ 00:13:52,000 --> 00:13:55,000
851
+ The vendor has great security practices.
852
+
853
+ 214
854
+ 00:13:55,000 --> 00:14:00,000
855
+ He's in compliance right now to different kinds of certifications that they had to get, or different
856
+
857
+ 215
858
+ 00:14:00,000 --> 00:14:02,000
859
+ kinds of third party audits.
860
+
861
+ 216
862
+ 00:14:02,000 --> 00:14:06,000
863
+ But tomorrow there, they could be a new audit and the guy fails.
864
+
865
+ 217
866
+ 00:14:06,000 --> 00:14:10,000
867
+ They could be a new, uh, pen test against them and they fail it.
868
+
869
+ 218
870
+ 00:14:10,000 --> 00:14:12,000
871
+ They could be a new hack, and they lost all your data.
872
+
873
+ 219
874
+ 00:14:13,000 --> 00:14:18,000
875
+ Remember, security is is basically an -- of, like, right now type thing.
876
+
877
+ 220
878
+ 00:14:18,000 --> 00:14:21,000
879
+ You could be secured today and insecure tomorrow.
880
+
881
+ 221
882
+ 00:14:21,000 --> 00:14:26,000
883
+ Let's keep that in mind when managing vendors because of the you know, one of the last things we want
884
+
885
+ 222
886
+ 00:14:26,000 --> 00:14:30,000
887
+ is to bring security problems to our organization.
888
+
22 - Vendor Management/002 Vendor Agreements OB 5.3_en.srt ADDED
@@ -0,0 +1,484 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ 1
2
+ 00:00:00,000 --> 00:00:06,000
3
+ When it comes to managing the relationship between you and a vendor, you must have some kind of a contract.
4
+
5
+ 2
6
+ 00:00:06,000 --> 00:00:13,000
7
+ Never manage a relationship between you and a third party vendor with just a handshake, or just talking
8
+
9
+ 3
10
+ 00:00:13,000 --> 00:00:14,000
11
+ over the phone.
12
+
13
+ 4
14
+ 00:00:14,000 --> 00:00:17,000
15
+ Just don't do it by words as they say.
16
+
17
+ 5
18
+ 00:00:17,000 --> 00:00:18,000
19
+ Put it on paper.
20
+
21
+ 6
22
+ 00:00:18,000 --> 00:00:19,000
23
+ Put it in writing.
24
+
25
+ 7
26
+ 00:00:19,000 --> 00:00:24,000
27
+ So in this video, let's take a look at some different kinds of contractual agreements that we want
28
+
29
+ 8
30
+ 00:00:24,000 --> 00:00:25,000
31
+ to be familiar with for our exam.
32
+
33
+ 9
34
+ 00:00:25,000 --> 00:00:27,000
35
+ And what is it that they're going to have in them.
36
+
37
+ 10
38
+ 00:00:27,000 --> 00:00:29,000
39
+ So what exactly are we talking about?
40
+
41
+ 11
42
+ 00:00:29,000 --> 00:00:35,000
43
+ Well, when you select vendors, you must consider how well you're going to manage these vendors due
44
+
45
+ 12
46
+ 00:00:35,000 --> 00:00:39,000
47
+ to contractual terms, such as having an SLA with them, which we'll cover in a minute.
48
+
49
+ 13
50
+ 00:00:39,000 --> 00:00:44,000
51
+ Does these SLAs align with the organization's security expectations?
52
+
53
+ 14
54
+ 00:00:44,000 --> 00:00:49,000
55
+ Things we're going to want to look for data protection, incident response, security audits, right
56
+
57
+ 15
58
+ 00:00:49,000 --> 00:00:57,000
59
+ to audit clauses, all of these things here we can include in our um, in our different types of contracts.
60
+
61
+ 16
62
+ 00:00:57,000 --> 00:01:03,000
63
+ So let's go see some different types of contracts that we're going to want to have with our vendors.
64
+
65
+ 17
66
+ 00:01:03,000 --> 00:01:07,000
67
+ So the first one up I want to mention is one of the most popular ones you're going to have with a third
68
+
69
+ 18
70
+ 00:01:07,000 --> 00:01:08,000
71
+ party vendor.
72
+
73
+ 19
74
+ 00:01:08,000 --> 00:01:11,000
75
+ And that's going to be a service level agreement or SLA.
76
+
77
+ 20
78
+ 00:01:11,000 --> 00:01:15,000
79
+ Now, this is a contract between a service provider and a client that specifies, quote unquote, the
80
+
81
+ 21
82
+ 00:01:15,000 --> 00:01:21,000
83
+ level of service, hence the name service level agreement expected during the terms of the agreement.
84
+
85
+ 22
86
+ 00:01:21,000 --> 00:01:27,000
87
+ This generally includes things like system uptime, response time or support requests and security measures.
88
+
89
+ 23
90
+ 00:01:27,000 --> 00:01:28,000
91
+ Let me give you a bunch of examples.
92
+
93
+ 24
94
+ 00:01:29,000 --> 00:01:31,000
95
+ When you get when you get a vendor.
96
+
97
+ 25
98
+ 00:01:31,000 --> 00:01:37,000
99
+ For example, let's say you go to Verizon and you get a Verizon Internet line.
100
+
101
+ 26
102
+ 00:01:37,000 --> 00:01:45,000
103
+ They're vendor, they're providing the service of internet, but you need your internet to be up 99.999%
104
+
105
+ 27
106
+ 00:01:45,000 --> 00:01:46,000
107
+ of the time.
108
+
109
+ 28
110
+ 00:01:46,000 --> 00:01:47,000
111
+ It's called the five nines.
112
+
113
+ 29
114
+ 00:01:47,000 --> 00:01:52,000
115
+ 99.999% of the time is a very high uptime.
116
+
117
+ 30
118
+ 00:01:52,000 --> 00:01:58,000
119
+ So you could put in a contract if Verizon can say, well, our SLA is 99.999%.
120
+
121
+ 31
122
+ 00:01:58,000 --> 00:02:01,000
123
+ In other words, their systems go down very little.
124
+
125
+ 32
126
+ 00:02:01,000 --> 00:02:03,000
127
+ So you can put that in the SLA.
128
+
129
+ 33
130
+ 00:02:03,000 --> 00:02:09,000
131
+ So the SLA is going to be 99.99% of the time, even incident response times, for example, if there
132
+
133
+ 34
134
+ 00:02:09,000 --> 00:02:15,000
135
+ is a security incident or for example, if the internet line does go down, Verizon will fix it within
136
+
137
+ 35
138
+ 00:02:15,000 --> 00:02:19,000
139
+ four hours, 2 hours or 24 hours, depending on what's in your SLA.
140
+
141
+ 36
142
+ 00:02:19,000 --> 00:02:27,000
143
+ So the SLA is generally going to be some kind of level in the name service level that the organization,
144
+
145
+ 37
146
+ 00:02:27,000 --> 00:02:31,000
147
+ the vendor in particular has to meet to keep that agreement active.
148
+
149
+ 38
150
+ 00:02:31,000 --> 00:02:32,000
151
+ And what if they don't meet it?
152
+
153
+ 39
154
+ 00:02:32,000 --> 00:02:37,000
155
+ Like, what if Verizon say they're going to fix all internet issues within four hours, but then it
156
+
157
+ 40
158
+ 00:02:37,000 --> 00:02:38,000
159
+ actually took six hours?
160
+
161
+ 41
162
+ 00:02:38,000 --> 00:02:43,000
163
+ Well, the SLA can actually specify penalties for the for the particular vendor.
164
+
165
+ 42
166
+ 00:02:43,000 --> 00:02:47,000
167
+ The vendor may have to give you back service credits or refunds on future bills.
168
+
169
+ 43
170
+ 00:02:47,000 --> 00:02:52,000
171
+ So this is going to be critical because if you're a manager in a server and it's basically managing
172
+
173
+ 44
174
+ 00:02:52,000 --> 00:02:57,000
175
+ your own web server and you need a high uptime on on the internet line, make sure that your SLA is
176
+
177
+ 45
178
+ 00:02:57,000 --> 00:02:58,000
179
+ a 99 point.
180
+
181
+ 46
182
+ 00:02:58,000 --> 00:03:00,000
183
+ You never get 100%.
184
+
185
+ 47
186
+ 00:03:01,000 --> 00:03:04,000
187
+ You know, they say the only thing that's 100% in this world is debt.
188
+
189
+ 48
190
+ 00:03:04,000 --> 00:03:06,000
191
+ So you're not going to get 100%.
192
+
193
+ 49
194
+ 00:03:06,000 --> 00:03:08,000
195
+ But all those nines is close enough.
196
+
197
+ 50
198
+ 00:03:08,000 --> 00:03:13,000
199
+ So SLA is a critical for establishing performance benchmarks and consequences.
200
+
201
+ 51
202
+ 00:03:13,000 --> 00:03:19,000
203
+ So it will have consequences, like I said, like if they don't meet it, it may they may have to give
204
+
205
+ 52
206
+ 00:03:19,000 --> 00:03:21,000
207
+ you back some kind of service credit.
208
+
209
+ 53
210
+ 00:03:21,000 --> 00:03:27,000
211
+ Another thing you have is an MOA or memo of agreement.
212
+
213
+ 54
214
+ 00:03:27,000 --> 00:03:32,000
215
+ An MOA is a formal document outlining an agreement between two or more parties.
216
+
217
+ 55
218
+ 00:03:32,000 --> 00:03:38,000
219
+ It's used to establish some kind of cooperative relationship, detailing the terms and scope of the
220
+
221
+ 56
222
+ 00:03:38,000 --> 00:03:38,000
223
+ agreement.
224
+
225
+ 57
226
+ 00:03:38,000 --> 00:03:42,000
227
+ Now, when it comes to cyber security, it's basically set out.
228
+
229
+ 58
230
+ 00:03:43,000 --> 00:03:48,000
231
+ A joint initiative for information sharing and collaborative development of security protocols.
232
+
233
+ 59
234
+ 00:03:48,000 --> 00:03:55,000
235
+ So a lot of times we're going to have memo of agreement with other organizations to sometimes work on
236
+
237
+ 60
238
+ 00:03:55,000 --> 00:03:57,000
239
+ a joint project together.
240
+
241
+ 61
242
+ 00:03:57,000 --> 00:03:59,000
243
+ That's very common when we do these things.
244
+
245
+ 62
246
+ 00:03:59,000 --> 00:04:03,000
247
+ Hey, we're going to have this agreement that says, here's how we're going to share information, here's
248
+
249
+ 63
250
+ 00:04:03,000 --> 00:04:06,000
251
+ how we're going to work together to finish a particular project.
252
+
253
+ 64
254
+ 00:04:07,000 --> 00:04:13,000
255
+ Take for example, vendor A and vendor B, combining together to develop a new security product.
256
+
257
+ 65
258
+ 00:04:13,000 --> 00:04:15,000
259
+ This is how they're going to share information.
260
+
261
+ 66
262
+ 00:04:15,000 --> 00:04:18,000
263
+ These are this is what this one should do versus another.
264
+
265
+ 67
266
+ 00:04:18,000 --> 00:04:25,000
267
+ Another thing you have is something that's less formal is what we just have a memo of understanding
268
+
269
+ 68
270
+ 00:04:25,000 --> 00:04:26,000
271
+ our MOU.
272
+
273
+ 69
274
+ 00:04:26,000 --> 00:04:33,000
275
+ Now it's typically used to outline a mutual agreement or a shared goal without keyword legal obligation.
276
+
277
+ 70
278
+ 00:04:33,000 --> 00:04:37,000
279
+ So this is going to be more of when they outline, hey, this is how we're going to work together,
280
+
281
+ 71
282
+ 00:04:37,000 --> 00:04:41,000
283
+ but they actually don't go in to the specifics.
284
+
285
+ 72
286
+ 00:04:41,000 --> 00:04:45,000
287
+ And it's not something that if one wants to walk away from the other, one can take the other one to
288
+
289
+ 73
290
+ 00:04:45,000 --> 00:04:46,000
291
+ court.
292
+
293
+ 74
294
+ 00:04:46,000 --> 00:04:50,000
295
+ Now, it does facilitate information sharing, research, research, collaboration.
296
+
297
+ 75
298
+ 00:04:50,000 --> 00:04:56,000
299
+ So it's really something that's less formal than an MOA.
300
+
301
+ 76
302
+ 00:04:57,000 --> 00:05:03,000
303
+ Now, one of the main ones you're going to want to get is what's called a master service agreement.
304
+
305
+ 77
306
+ 00:05:03,000 --> 00:05:05,000
307
+ This is a more comprehensive contract.
308
+
309
+ 78
310
+ 00:05:05,000 --> 00:05:11,000
311
+ These sets the general terms governing future of transactions in all agreements between you and that
312
+
313
+ 79
314
+ 00:05:11,000 --> 00:05:13,000
315
+ vendor can streamline future agreements.
316
+
317
+ 80
318
+ 00:05:13,000 --> 00:05:17,000
319
+ And it often will include how are they going to protect the CIA.
320
+
321
+ 81
322
+ 00:05:17,000 --> 00:05:22,000
323
+ So confidentiality, integrity and availability, any kind of disputes that may show up or any kind
324
+
325
+ 82
326
+ 00:05:22,000 --> 00:05:23,000
327
+ of data security standard.
328
+
329
+ 83
330
+ 00:05:23,000 --> 00:05:30,000
331
+ So the Master Service agreement is exactly how it's the big agreement that really dictates how the relationship
332
+
333
+ 84
334
+ 00:05:30,000 --> 00:05:33,000
335
+ between you and the vendor will be managed.
336
+
337
+ 85
338
+ 00:05:33,000 --> 00:05:35,000
339
+ Now to outline the specific work.
340
+
341
+ 86
342
+ 00:05:35,000 --> 00:05:38,000
343
+ This is going to be called a work order or statement of work.
344
+
345
+ 87
346
+ 00:05:38,000 --> 00:05:42,000
347
+ This is a document that specific details about the work to be performed.
348
+
349
+ 88
350
+ 00:05:42,000 --> 00:05:47,000
351
+ So if you hire a vendor to work on a particular project or get particular task done for you, you're
352
+
353
+ 89
354
+ 00:05:47,000 --> 00:05:48,000
355
+ going to want to make sure you add this in.
356
+
357
+ 90
358
+ 00:05:48,000 --> 00:05:52,000
359
+ It must be detailed, like what is it that they're going to have to deliver?
360
+
361
+ 91
362
+ 00:05:52,000 --> 00:05:56,000
363
+ When are timelines, specific tasks and the responsibilities?
364
+
365
+ 92
366
+ 00:05:56,000 --> 00:05:59,000
367
+ For example, let's say you hire somebody to build a website.
368
+
369
+ 93
370
+ 00:05:59,000 --> 00:06:01,000
371
+ You should have a statement of work for them.
372
+
373
+ 94
374
+ 00:06:01,000 --> 00:06:02,000
375
+ This is what you want.
376
+
377
+ 95
378
+ 00:06:02,000 --> 00:06:03,000
379
+ These are the pages.
380
+
381
+ 96
382
+ 00:06:03,000 --> 00:06:08,000
383
+ This is what should be on the pages if it's in terms of security.
384
+
385
+ 97
386
+ 00:06:08,000 --> 00:06:13,000
387
+ If it's particularly like if it's a security project, what should be configured, how should be configured,
388
+
389
+ 98
390
+ 00:06:13,000 --> 00:06:17,000
391
+ what type of audits or tests or implementations we need to get done.
392
+
393
+ 99
394
+ 00:06:18,000 --> 00:06:19,000
395
+ A non-disclosure.
396
+
397
+ 100
398
+ 00:06:19,000 --> 00:06:24,000
399
+ Any time you work with a vendor, you should always have a non-disclosure agreement.
400
+
401
+ 101
402
+ 00:06:24,000 --> 00:06:30,000
403
+ This is a legal binding contract that establishes that confidential relationship now.
404
+
405
+ 102
406
+ 00:06:30,000 --> 00:06:39,000
407
+ Basically it's a it's an agreement that says no one is to disclose information covered by the agreement,
408
+
409
+ 103
410
+ 00:06:39,000 --> 00:06:40,000
411
+ which is critical.
412
+
413
+ 104
414
+ 00:06:40,000 --> 00:06:45,000
415
+ For example, if you're dealing with a vendor and that vendor comes into your organization, they may
416
+
417
+ 105
418
+ 00:06:45,000 --> 00:06:45,000
419
+ find.
420
+
421
+ 106
422
+ 00:06:46,000 --> 00:06:52,000
423
+ Private information about your customers, maybe even secret projects that you're working on, maybe
424
+
425
+ 107
426
+ 00:06:52,000 --> 00:06:55,000
427
+ specific way you deal your business or business secrets.
428
+
429
+ 108
430
+ 00:06:56,000 --> 00:07:03,000
431
+ They can technically share that information with anyone, but if they sign an NDA, they're not supposed
432
+
433
+ 109
434
+ 00:07:03,000 --> 00:07:04,000
435
+ to disclose that information to anyone.
436
+
437
+ 110
438
+ 00:07:04,000 --> 00:07:07,000
439
+ So this becomes a legal contract that says, you know what?
440
+
441
+ 111
442
+ 00:07:07,000 --> 00:07:11,000
443
+ Whatever I find in this organization, I can't disclose it.
444
+
445
+ 112
446
+ 00:07:11,000 --> 00:07:13,000
447
+ So that's why this is important.
448
+
449
+ 113
450
+ 00:07:13,000 --> 00:07:18,000
451
+ So it's critical for protecting sensitive data, especially proprietary information.
452
+
453
+ 114
454
+ 00:07:19,000 --> 00:07:23,000
455
+ Now another agreement you may see is a business partners agreement.
456
+
457
+ 115
458
+ 00:07:23,000 --> 00:07:28,000
459
+ This is going to be when business people combine together, share resources, joint ventures or work
460
+
461
+ 116
462
+ 00:07:28,000 --> 00:07:30,000
463
+ on different types of projects.
464
+
465
+ 117
466
+ 00:07:30,000 --> 00:07:35,000
467
+ Together they're going to sign a business partner agreement to say, here, let's combine together to
468
+
469
+ 118
470
+ 00:07:35,000 --> 00:07:39,000
471
+ develop certain security products, software, hardware and so on.
472
+
473
+ 119
474
+ 00:07:39,000 --> 00:07:42,000
475
+ Okay, just be familiar with some of these agreements.
476
+
477
+ 120
478
+ 00:07:42,000 --> 00:07:44,000
479
+ You might see them, they show up on your exam.
480
+
481
+ 121
482
+ 00:07:44,000 --> 00:07:51,000
483
+ But keep in mind, never manage a vendor without having the correct agreement or contract in place.
484
+
22 - Vendor Management/003 Quick Quiz.html ADDED
@@ -0,0 +1,479 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ <!DOCTYPE html>
2
+ <html lang="en">
3
+ <head>
4
+ <meta charset="UTF-8" />
5
+ <meta http-equiv="X-UA-Compatible" content="IE=edge" />
6
+ <meta name="viewport" content="width=device-width, initial-scale=1.0" />
7
+ <title>Quiz</title>
8
+ <style>
9
+ * {
10
+ font-family: system-ui, -apple-system, BlinkMacSystemFont, "Segoe UI", Roboto, Oxygen, Ubuntu, Cantarell,
11
+ "Open Sans", "Helvetica Neue", sans-serif;
12
+ margin: 0;
13
+ padding: 0;
14
+ box-sizing: border-box;
15
+ font-size: 16px;
16
+ }
17
+
18
+ main {
19
+ padding-top: 48px;
20
+ }
21
+
22
+ :root {
23
+ --large-device-width: 850px;
24
+ --primary-color: #0f172a;
25
+ --secondary-color: #020617;
26
+ --primary-text-color: #c7d1dd;
27
+ --secondary-text-color: #061602;
28
+ --success-background: hsl(159, 82%, 24%);
29
+ --success-foreground: hsl(164, 86%, 16%);
30
+ --success: hsl(160, 84%, 39%);
31
+ --danger: #ef4444;
32
+ --warning: #f59e0b;
33
+ --info-background: hsl(218, 81%, 8%);
34
+ --info-foreground: hsl(217, 91%, 85%);
35
+ --border-color: #d1d7dc;
36
+ --check-box-size: 20px;
37
+ /* control the size */
38
+ --check-box-color: var(--info-foreground);
39
+ /* the active color */
40
+ }
41
+
42
+ body {
43
+ position: relative;
44
+ background-color: #020617;
45
+ color: var(--primary-text-color);
46
+ }
47
+
48
+ #score-stats-container {
49
+ position: fixed;
50
+ z-index: 10;
51
+ top: 0;
52
+ height: 40px;
53
+ width: 100%;
54
+ background-color: var(--info-background);
55
+
56
+ padding: 0px 16px;
57
+ color: var(--info-foreground);
58
+ font-weight: 600;
59
+ display: flex;
60
+ align-items: center;
61
+ justify-content: space-between;
62
+ }
63
+
64
+ #quiz-container {
65
+ border-radius: 8px;
66
+ display: flex;
67
+ gap: 16px;
68
+ flex-direction: column;
69
+ }
70
+
71
+ input[type="radio"] {
72
+ height: var(--check-box-size);
73
+ aspect-ratio: 1;
74
+ border: calc(var(--check-box-size) / 8) solid #939393;
75
+ padding: calc(var(--check-box-size) / 8);
76
+ background: radial-gradient(farthest-side, var(--check-box-color) 94%, #0000) 50%/0 0 no-repeat
77
+ content-box;
78
+ border-radius: 50%;
79
+ outline-offset: calc(var(--check-box-size) / 10);
80
+ -webkit-appearance: none;
81
+ -moz-appearance: none;
82
+ appearance: none;
83
+ cursor: pointer;
84
+ font-size: inherit;
85
+ transition: 0.3s;
86
+ }
87
+
88
+ input[type="radio"]:checked {
89
+ border-color: var(--check-box-color);
90
+ background-size: 100% 100%;
91
+ }
92
+
93
+ input[type="radio"]:disabled {
94
+ background: linear-gradient(#939393 0 0) 50%/100% 20% no-repeat content-box;
95
+ opacity: 0.5;
96
+ cursor: not-allowed;
97
+ }
98
+
99
+ label {
100
+ display: inline-flex;
101
+ align-items: center;
102
+ gap: 10px;
103
+ cursor: pointer;
104
+ padding: 4px 6px;
105
+ border-radius: 4px;
106
+ }
107
+
108
+ @media (max-width: 767px) {
109
+ input[type="radio"],
110
+ label {
111
+ cursor: default;
112
+ }
113
+
114
+ #quiz-container {
115
+ margin-left: 8px;
116
+ margin-right: 8px;
117
+ }
118
+ }
119
+
120
+ /* PC (Desktop devices) */
121
+ @media (min-width: 768px) {
122
+ body {
123
+ display: flex;
124
+ justify-content: center;
125
+ }
126
+
127
+ main {
128
+ max-width: var(--large-device-width);
129
+ }
130
+
131
+ #score-stats-container {
132
+ max-width: var(--large-device-width);
133
+ }
134
+
135
+ dialog {
136
+ max-width: var(--large-device-width);
137
+ }
138
+ }
139
+
140
+ @media print {
141
+ input[type="radio"] {
142
+ background: none !important;
143
+ border-color: #939393 !important;
144
+ }
145
+
146
+ input[type="radio"]:checked {
147
+ border-color: #939393 !important;
148
+ }
149
+ }
150
+
151
+ .question-lable {
152
+ display: flex;
153
+ align-items: center;
154
+ gap: 8px;
155
+ }
156
+
157
+ button {
158
+ -webkit-tap-highlight-color: transparent;
159
+ -webkit-touch-callout: none;
160
+ -webkit-user-select: none;
161
+ user-select: none;
162
+ outline: none;
163
+ position: relative;
164
+ overflow: hidden;
165
+ cursor: pointer;
166
+ }
167
+
168
+ .button {
169
+ background-color: var(--success-background);
170
+ border: none;
171
+ color: #f4f5f7;
172
+ opacity: 0.8;
173
+ font-size: 18px;
174
+ flex-grow: 1;
175
+ padding: 8px 16px;
176
+ border-radius: 8px;
177
+ }
178
+
179
+ .button:hover {
180
+ opacity: 1;
181
+ }
182
+
183
+ .explanation-btn {
184
+ border: none;
185
+ color: var(--success);
186
+ background-color: transparent;
187
+ }
188
+
189
+ #submit-button:active::after {
190
+ background-color: #ef4444;
191
+ }
192
+
193
+ .single-question-container {
194
+ background-color: var(--primary-color);
195
+ display: flex;
196
+ flex-direction: column;
197
+ gap: 8px;
198
+ padding: 16px;
199
+ border-radius: 8px;
200
+ }
201
+
202
+ #modal-content {
203
+ padding: 16px;
204
+ line-height: 24px;
205
+ }
206
+
207
+ dialog::backdrop {
208
+ background: rgba(0, 0, 0, 0.5);
209
+ }
210
+
211
+ dialog {
212
+ position: fixed;
213
+ border: 1px solid var(--border-color);
214
+ background-color: var(--primary-color);
215
+ color: rgb(240, 241, 248);
216
+ padding: 16px;
217
+ border-radius: 8px;
218
+ width: 80vw;
219
+ max-height: 80vh;
220
+ overflow: auto;
221
+ top: 50%;
222
+ left: 50%;
223
+ -webkit-transform: translateX(-50%) translateY(-50%);
224
+ -moz-transform: translateX(-50%) translateY(-50%);
225
+ -ms-transform: translateX(-50%) translateY(-50%);
226
+ transform: translateX(-50%) translateY(-50%);
227
+ }
228
+
229
+ #close-modal-btn {
230
+ position: absolute;
231
+ top: 4px;
232
+ right: 4px;
233
+ padding: 2px 8px;
234
+ border-radius: 2px;
235
+ border: none;
236
+ background-color: var(--danger);
237
+ }
238
+
239
+ .correct-answer label {
240
+ border: 2px solid var(--success);
241
+ width: 100%;
242
+ }
243
+
244
+ .incorrect-answer label {
245
+ border: 2px solid var(--danger);
246
+ width: 100%;
247
+ }
248
+
249
+ .options-container {
250
+ display: flex;
251
+ flex-direction: column;
252
+ gap: 4px;
253
+ }
254
+
255
+ #quiz-meta-container {
256
+ border-radius: 8px;
257
+ background-color: var(--primary-color);
258
+ margin-bottom: 12px;
259
+ padding: 8px;
260
+ }
261
+
262
+ #quiz-title {
263
+ text-align: center;
264
+ font-size: 24px;
265
+ margin-bottom: 8px;
266
+ }
267
+
268
+ #quiz-description {
269
+ line-height: 1.5;
270
+ padding: 2px 6px;
271
+ }
272
+ </style>
273
+ </head>
274
+
275
+ <body onload="main()">
276
+ <main>
277
+ <section id="quiz-meta-container">
278
+ <h1 id="quiz-title"></h1>
279
+ <p id="quiz-description"></p>
280
+ </section>
281
+ <section id="score-stats-container">
282
+ <div id="score-card">
283
+ Score: <span id="current-score">999</span> of
284
+ <span id="pass-percent">999%</span>
285
+ </div>
286
+ <div>Correct: <span id="correct-answers">999</span></div>
287
+ <div>Incorrect: <span id="wrong-answers">999</span></div>
288
+ </section>
289
+
290
+ <section id="quiz-container"></section>
291
+
292
+ <dialog id="modal" class="modal-container">
293
+ <div id="modal-content">
294
+ <p id="modal-text"></p>
295
+ </div>
296
+ </dialog>
297
+ </main>
298
+
299
+ <script>
300
+ const quizData = {"quiz_id": 6180190, "quiz_description": null, "quiz_title": "Quick Quiz", "pass_percent": null, "questions": [{"_class": "assessment", "id": 74731654, "assessment_type": "multiple-choice", "prompt": {"question": "<p>A corporation is planning to hire a third-party IT service provider. What is the initial step they should take to ensure the provider meets their security requirements?</p>", "relatedLectureIds": "", "feedbacks": ["", "The initial step for the corporation should be conducting a Vendor Assessment. This process involves evaluating the potential vendor's security measures, which might include penetration testing results, evidence of their internal audits, independent assessments, and supply chain analysis. This assessment helps in understanding if the vendor can meet the corporation's security requirements. ", "", ""], "answers": ["<p>Signing a Non-disclosure Agreement (NDA)</p>", "<p>Conducting a Vendor Assessment</p>", "<p>Establishing a Service-Level Agreement (SLA)</p>", "<p>Preparing a Work Order (WO)/Statement of Work (SOW)</p>"]}, "correct_response": ["b"], "section": "", "question_plain": "A corporation is planning to hire a third-party IT service provider. What is the initial step they should take to ensure the provider meets their security requirements?", "related_lectures": []}, {"_class": "assessment", "id": 74731658, "assessment_type": "multiple-choice", "prompt": {"question": "<p>A financial institution is selecting a new software vendor for its transaction processing system. What process should they prioritize to avoid conflicts of interest and ensure the vendor aligns with their operational needs?</p>", "relatedLectureIds": "", "feedbacks": ["", "", "The financial institution should prioritize performing Due Diligence in the Vendor Selection process. Due diligence involves a comprehensive evaluation of the vendor\u2019s capabilities, financial stability, reputation, and compliance with regulations, ensuring that there are no conflicts of interest and that the vendor aligns with the institution's operational needs and standards. ", ""], "answers": ["<p>Implementing Vendor Monitoring</p>", "<p>Executing a Memorandum of Understanding (MOU)</p>", "<p>Performing Due Diligence in Vendor Selection</p>", "<p>Drafting a Business Partners Agreement (BPA)</p>"]}, "correct_response": ["c"], "section": "", "question_plain": "A financial institution is selecting a new software vendor for its transaction processing system. What process should they prioritize to avoid conflicts of interest and ensure the vendor aligns with their operational needs?", "related_lectures": []}, {"_class": "assessment", "id": 74731670, "assessment_type": "multiple-choice", "prompt": {"question": "<p>A technology company is evaluating several vendors for a new project. What tool should they use to gather detailed information about the vendors' policies, practices, and capabilities?</p>", "relatedLectureIds": "", "feedbacks": ["The technology company should use Vendor Questionnaires as a tool to gather detailed information about the vendors' policies, practices, and capabilities. These questionnaires are designed to extract specific information that helps in evaluating the vendors' qualifications, security measures, compliance with industry standards, and overall suitability for the project. ", "", "", ""], "answers": ["<p>Vendor Questionnaires</p>", "<p>Service-Level Agreements (SLAs)</p>", "<p>Memorandum of Understanding (MOU)</p>", "<p>Business Partners Agreement (BPA)</p>"]}, "correct_response": ["a"], "section": "", "question_plain": "A technology company is evaluating several vendors for a new project. What tool should they use to gather detailed information about the vendors' policies, practices, and capabilities?", "related_lectures": []}, {"_class": "assessment", "id": 74731800, "assessment_type": "multiple-choice", "prompt": {"question": "<p>A multinational corporation is drafting agreements with multiple vendors for a series of international projects. What type of agreement is essential to protect confidential information shared during vendor interactions?</p>", "relatedLectureIds": "", "feedbacks": ["For the multinational corporation, a Non-disclosure Agreement (NDA) is essential in their agreements with vendors, especially to protect confidential information. NDAs legally bind the vendors to confidentiality, ensuring that sensitive information shared during negotiations, project planning, and execution is not disclosed to unauthorized parties. ", "", "", ""], "answers": ["<p>Non-disclosure Agreement (NDA)</p>", "<p>Service-level Agreement (SLA)</p>", "<p>Memorandum of Understanding (MOU)</p>", "<p>Master Service Agreement (MSA)</p>"]}, "correct_response": ["a"], "section": "", "question_plain": "A multinational corporation is drafting agreements with multiple vendors for a series of international projects. What type of agreement is essential to protect confidential information shared during vendor interactions?", "related_lectures": []}, {"_class": "assessment", "id": 74731872, "assessment_type": "multiple-choice", "prompt": {"question": "<p>A manufacturing company is outsourcing part of its production to a third-party vendor. To maintain quality control and manage potential supply chain risks, what strategy should they employ in their agreement with the vendor?</p>", "relatedLectureIds": "", "feedbacks": ["For the manufacturing company outsourcing production, including a Right-to-Audit clause in the agreement with the third-party vendor is a critical strategy to maintain quality control and manage supply chain risks. This clause allows the company to conduct periodic audits of the vendor's processes, ensuring that they adhere to agreed-upon quality standards and production timelines.", "", "", ""], "answers": ["<p>Including a Right-to-Audit clause in the agreement</p>", "<p>Focusing on the financial terms in the Service-Level Agreement (SLA)</p>", "<p>Establishing a Memorandum of Understanding (MOU) for shared objectives</p>", "<p>Drafting a detailed Work Order (WO)/Statement of Work (SOW)</p>"]}, "correct_response": ["a"], "section": "", "question_plain": "A manufacturing company is outsourcing part of its production to a third-party vendor. To maintain quality control and manage potential supply chain risks, what strategy should they employ in their agreement with the vendor?", "related_lectures": []}]};
301
+ let correct = new Set();
302
+ let incorrect = new Set();
303
+ let totalNumberOfQuestions = 0;
304
+ const quizTitle = quizData.quiz_title;
305
+ const quizDescription = quizData.quiz_description;
306
+ const questionData = quizData.questions;
307
+ const passPercent = quizData.pass_percent;
308
+ const modalTextElement = document.getElementById("modal-text");
309
+ const quizContainerElement = document.getElementById("quiz-container");
310
+
311
+ const dialog = document.querySelector("dialog");
312
+ const showButton = document.getElementById("view-explanatin");
313
+ const closeButton = document.getElementById("close-modal-btn");
314
+ const quizTitleElement = document.getElementById("quiz-title");
315
+ const quizDescriptionElement = document.getElementById("quiz-description");
316
+
317
+ function main() {
318
+ // update quiz meta data
319
+ document.title = quizTitle;
320
+ quizTitleElement.innerHTML = quizTitle;
321
+ quizDescriptionElement.innerHTML = quizDescription;
322
+
323
+ const passPercentElement = document.getElementById("pass-percent");
324
+ passPercentElement.innerHTML = passPercent + "%";
325
+ totalNumberOfQuestions = questionData.length;
326
+ // shuffle the questionData to randomize the order of the questions
327
+ for (let i = questionData.length - 1; i > 0; i--) {
328
+ const j = Math.floor(Math.random() * (i + 1));
329
+ [questionData[i], questionData[j]] = [questionData[j], questionData[i]];
330
+ }
331
+
332
+ let formattedQuestions = questionData.map(formatSingleQuestionData);
333
+ updateScore();
334
+ // display the formattedQuestions
335
+ formattedQuestions.forEach((question, idx) => {
336
+ renderSingleQuestion(question, idx + 1);
337
+ });
338
+ }
339
+
340
+ /**
341
+ * Formats the question data from the given QuizData object.
342
+ *
343
+ * @param {Object} singleQuizData - The singleQuizData object containing prompt and correct_response.
344
+ * @return {Object} The formatted question object with the following properties:
345
+ * - id: The ID of the question.
346
+ * - question: The text of the question.
347
+ * - answers: The array of answer options.
348
+ * - correctAnswer: The text of the correct answer.
349
+ * - explanation: The explanation of the correct answer.
350
+ */
351
+ function formatSingleQuestionData(singleQuizData = null) {
352
+ const { prompt, correct_response, id } = singleQuizData;
353
+ const questionText = prompt.question;
354
+ const answers = prompt.answers;
355
+ const correctAnswer = correct_response[0];
356
+ const correctAnswerText = answers[correctAnswer.toLowerCase().charCodeAt(0) - 97];
357
+ const questionObj = {
358
+ id: id,
359
+ question: questionText,
360
+ answers: answers,
361
+ correctAnswer: correctAnswerText,
362
+ explanation: prompt?.explanation || "",
363
+ };
364
+ return questionObj;
365
+ }
366
+
367
+ /**
368
+ * Renders a single question with its options and submit button.
369
+ *
370
+ * @param {Object} singleQuestionData - The data of the question to render.
371
+ * @param {number} rootIndex - The index of the question in the quiz.
372
+ * @return {void} return nothing.
373
+ */
374
+
375
+ const renderSingleQuestion = (singleQuestionData = {}, rootIndex = 1) => {
376
+ const { id, explanation, answers, correctAnswer, question } = singleQuestionData;
377
+ // shuffle the answers to randomize the order of the answers
378
+ for (let i = answers.length - 1; i > 0; i--) {
379
+ const j = Math.floor(Math.random() * (i + 1));
380
+ [answers[i], answers[j]] = [answers[j], answers[i]];
381
+ }
382
+ const optionsHTML = answers
383
+ .map((option, index) => {
384
+ const optionId = `${id}_${index}`;
385
+
386
+ return `
387
+ <div class="question-lable">
388
+ <input type="radio" id="${optionId}" name="${"answer"}" value="${option}" />
389
+ <label for="${optionId}">${option}</label>
390
+ </div>
391
+ `;
392
+ })
393
+
394
+ .join("");
395
+
396
+ const container = document.createElement("div");
397
+ container.innerHTML = `
398
+ <form data-correct-answer="${correctAnswer}" data-question-id="${id}" class="single-question-container" onsubmit="submitButtonListener(event)">
399
+ <div style="display: flex;justify-content: space-between;">
400
+ <p style="font-weight: 600">Question ${rootIndex}:</p>
401
+ <button type="button" onclick="renderExplanation(event)" id="${`explanation-${id}`}" data-explanation="${explanation}" class="explanation-btn">View Explanation</button>
402
+ </div>
403
+ <p style="margin-bottom: 8px;line-height: 1.5">${question}</p>
404
+ <div class="options-container">
405
+ ${optionsHTML}
406
+ </div>
407
+ <div style="display: flex; gap: 8px;">
408
+ <button type="submit" id="submit-button" class="button">Submit</button>
409
+ </div>
410
+ </form>
411
+ `;
412
+ quizContainerElement.appendChild(container);
413
+ };
414
+
415
+ /**
416
+ * Updates the score on the page based on the number of correct and incorrect answers.
417
+ *
418
+ * @return {void} This function does not return a value.
419
+ */
420
+ function updateScore() {
421
+ const currentParcentageElement = document.getElementById("current-score");
422
+ const correctAnswerElement = document.getElementById("correct-answers");
423
+ const wrongAnswerElement = document.getElementById("wrong-answers");
424
+ correctAnswerElement.innerHTML = correct.size;
425
+ wrongAnswerElement.innerHTML = incorrect.size;
426
+ const score = Number((correct.size / totalNumberOfQuestions) * 100).toFixed(2);
427
+ currentParcentageElement.innerHTML = score;
428
+ }
429
+
430
+ /**
431
+ * Handles the event when the submit button is clicked.
432
+ *
433
+ * @param {Event} e - The event object.
434
+ * @return {void} This function does not return anything.
435
+ */
436
+ const submitButtonListener = (e) => {
437
+ e.preventDefault();
438
+ const formData = new FormData(e.target);
439
+ const form = e.target;
440
+ const selectedOption = e.target.querySelector('input[type="radio"]:checked');
441
+ if (!selectedOption) {
442
+ alert("Please select an answer!");
443
+ return;
444
+ }
445
+
446
+ let isCorrect = false;
447
+ const { answer: userAnswer } = Object.fromEntries(formData.entries());
448
+ const correctAnswer = e.target.dataset.correctAnswer;
449
+ const questionId = e.target.dataset.questionId;
450
+ if (userAnswer == correctAnswer) {
451
+ correct.add(questionId);
452
+ incorrect.delete(questionId);
453
+ isCorrect = true;
454
+ } else {
455
+ incorrect.add(e.target.dataset.questionId);
456
+ correct.delete(questionId);
457
+ }
458
+ updateScore();
459
+
460
+ const resultClass = isCorrect ? "correct-answer" : "incorrect-answer";
461
+
462
+ form.querySelectorAll(".question-lable").forEach((label) => {
463
+ label.classList.remove("correct-answer", "incorrect-answer");
464
+ });
465
+ selectedOption.closest(".question-lable").classList.add(resultClass);
466
+ };
467
+
468
+ function renderExplanation(ev) {
469
+ modalTextElement.innerHTML = ev.target.dataset?.explanation || "no explanation found";
470
+ dialog.showModal();
471
+ dialog.addEventListener("click", (event) => {
472
+ if (event.target === dialog) {
473
+ dialog.close();
474
+ }
475
+ });
476
+ }
477
+ </script>
478
+ </body>
479
+ </html>
23 - Physical Security/001 Physical Security OB 1.2_en.srt ADDED
@@ -0,0 +1,640 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ 1
2
+ 00:00:00,000 --> 00:00:08,000
3
+ IT security professionals mostly think about how do we secure our data from technical attacks such as
4
+
5
+ 2
6
+ 00:00:08,000 --> 00:00:09,000
7
+ hackers.
8
+
9
+ 3
10
+ 00:00:09,000 --> 00:00:16,000
11
+ But reality says this it doesn't matter how much technical controls you put in place, such as you can
12
+
13
+ 4
14
+ 00:00:16,000 --> 00:00:22,000
15
+ have great firewalls, encryption, anti-malware, intrusion prevention systems, and all the other
16
+
17
+ 5
18
+ 00:00:22,000 --> 00:00:24,000
19
+ things that we're going to talk about later in this course.
20
+
21
+ 6
22
+ 00:00:24,000 --> 00:00:29,000
23
+ See, it doesn't matter how much technical security you have, if I have the ability just to walk into
24
+
25
+ 7
26
+ 00:00:29,000 --> 00:00:34,000
27
+ your organization, pick up your server and walk back out, you really don't have much security, do
28
+
29
+ 8
30
+ 00:00:34,000 --> 00:00:35,000
31
+ you?
32
+
33
+ 9
34
+ 00:00:36,000 --> 00:00:39,000
35
+ You see, the topic in this video is called physical security.
36
+
37
+ 10
38
+ 00:00:39,000 --> 00:00:46,000
39
+ And when we protect our organization, just don't protect it from theft of digital data, protect it
40
+
41
+ 11
42
+ 00:00:46,000 --> 00:00:50,000
43
+ from the theft of the physical server that stores the data.
44
+
45
+ 12
46
+ 00:00:50,000 --> 00:00:52,000
47
+ So let's get more into physical security.
48
+
49
+ 13
50
+ 00:00:52,000 --> 00:00:57,000
51
+ And also in this video I want to go through some different controls within physical security.
52
+
53
+ 14
54
+ 00:00:57,000 --> 00:00:59,000
55
+ You want to be familiar with for your exam.
56
+
57
+ 15
58
+ 00:00:59,000 --> 00:01:01,000
59
+ So the first thing up what exactly is this.
60
+
61
+ 16
62
+ 00:01:01,000 --> 00:01:06,000
63
+ Well it's a critical aspect that focuses on protecting an organization's assets.
64
+
65
+ 17
66
+ 00:01:06,000 --> 00:01:08,000
67
+ And it's mostly going to be physical assets.
68
+
69
+ 18
70
+ 00:01:08,000 --> 00:01:14,000
71
+ Think building equipment and personnel from physical actions and events that can cause serious loss
72
+
73
+ 19
74
+ 00:01:14,000 --> 00:01:15,000
75
+ or damage.
76
+
77
+ 20
78
+ 00:01:15,000 --> 00:01:16,000
79
+ Now I want to point out something.
80
+
81
+ 21
82
+ 00:01:17,000 --> 00:01:21,000
83
+ One of the most important assets that you're going to be protecting in physical security is going to
84
+
85
+ 22
86
+ 00:01:21,000 --> 00:01:22,000
87
+ be people's lives.
88
+
89
+ 23
90
+ 00:01:22,000 --> 00:01:25,000
91
+ Because when you think physical security, don't think of just theft.
92
+
93
+ 24
94
+ 00:01:25,000 --> 00:01:29,000
95
+ Most people think, well, it's a thief coming in to steal a server.
96
+
97
+ 25
98
+ 00:01:29,000 --> 00:01:30,000
99
+ Not particularly.
100
+
101
+ 26
102
+ 00:01:30,000 --> 00:01:34,000
103
+ Remember, physical security protects against a wide variety of things like fire.
104
+
105
+ 27
106
+ 00:01:34,000 --> 00:01:40,000
107
+ Not only can that destroy, that can take lives, flood, natural disasters like hurricanes, earthquakes,
108
+
109
+ 28
110
+ 00:01:40,000 --> 00:01:42,000
111
+ burglary, theft, vandalism, and even terrorism.
112
+
113
+ 29
114
+ 00:01:42,000 --> 00:01:44,000
115
+ Always remember something.
116
+
117
+ 30
118
+ 00:01:44,000 --> 00:01:49,000
119
+ It doesn't matter how sophisticated your IT security is or your technical security is.
120
+
121
+ 31
122
+ 00:01:49,000 --> 00:01:54,000
123
+ Keep in mind that it could be rendered ineffective if your physical security is compromised.
124
+
125
+ 32
126
+ 00:01:54,000 --> 00:01:59,000
127
+ Now I'm going to go through some physical security controls in this video with you.
128
+
129
+ 33
130
+ 00:01:59,000 --> 00:02:02,000
131
+ I want you to understand what these things are for your exam.
132
+
133
+ 34
134
+ 00:02:02,000 --> 00:02:03,000
135
+ Don't go in depth into them.
136
+
137
+ 35
138
+ 00:02:03,000 --> 00:02:06,000
139
+ Your exam won't, but just know what these controls are.
140
+
141
+ 36
142
+ 00:02:06,000 --> 00:02:07,000
143
+ So let's get started.
144
+
145
+ 37
146
+ 00:02:07,000 --> 00:02:08,000
147
+ Now.
148
+
149
+ 38
150
+ 00:02:08,000 --> 00:02:11,000
151
+ They're not in any particular order per se that you need to have this.
152
+
153
+ 39
154
+ 00:02:11,000 --> 00:02:14,000
155
+ Just know that these things exist and know what they do.
156
+
157
+ 40
158
+ 00:02:14,000 --> 00:02:19,000
159
+ The first one up is something that you've probably seen many times, and these are going to be this
160
+
161
+ 41
162
+ 00:02:19,000 --> 00:02:22,000
163
+ big post that you see, like this one here, the silver one.
164
+
165
+ 42
166
+ 00:02:22,000 --> 00:02:24,000
167
+ This is going to be like the one in front of a building.
168
+
169
+ 43
170
+ 00:02:25,000 --> 00:02:28,000
171
+ This yellow one is going to be like the one that you see in the parking lot.
172
+
173
+ 44
174
+ 00:02:28,000 --> 00:02:32,000
175
+ Now what these things are, they're basically called bollards.
176
+
177
+ 45
178
+ 00:02:33,000 --> 00:02:38,000
179
+ Now bollards are basically sturdy vertical posts, and they're designed to prevent car based attacks
180
+
181
+ 46
182
+ 00:02:38,000 --> 00:02:41,000
183
+ on buildings or to control access to sensitive areas.
184
+
185
+ 47
186
+ 00:02:41,000 --> 00:02:47,000
187
+ So basically, if you put this in front of your building, somebody can't run a car directly into your
188
+
189
+ 48
190
+ 00:02:47,000 --> 00:02:48,000
191
+ building or a truck.
192
+
193
+ 49
194
+ 00:02:48,000 --> 00:02:53,000
195
+ These things will withstand the force of a car going many miles per hour.
196
+
197
+ 50
198
+ 00:02:53,000 --> 00:03:00,000
199
+ Another thing here we're going to have is something we call an access control vestibule.
200
+
201
+ 51
202
+ 00:03:00,000 --> 00:03:03,000
203
+ Now, depending on what you read in, this thing used to be called a mantrap.
204
+
205
+ 52
206
+ 00:03:03,000 --> 00:03:06,000
207
+ If you ever read old security texts used to be called that.
208
+
209
+ 53
210
+ 00:03:06,000 --> 00:03:09,000
211
+ Now it's called an access control vestibule.
212
+
213
+ 54
214
+ 00:03:09,000 --> 00:03:16,000
215
+ This is a secure area between two sets of doors used to manage and control access into a secure area.
216
+
217
+ 55
218
+ 00:03:17,000 --> 00:03:19,000
219
+ Here's how it works, by the way.
220
+
221
+ 56
222
+ 00:03:19,000 --> 00:03:20,000
223
+ Here's a picture of it.
224
+
225
+ 57
226
+ 00:03:20,000 --> 00:03:21,000
227
+ Here's how it works.
228
+
229
+ 58
230
+ 00:03:21,000 --> 00:03:24,000
231
+ Let's say you want to get into and these are famous.
232
+
233
+ 59
234
+ 00:03:24,000 --> 00:03:26,000
235
+ You see these in like prison movies.
236
+
237
+ 60
238
+ 00:03:26,000 --> 00:03:27,000
239
+ You want to get into a prison.
240
+
241
+ 61
242
+ 00:03:27,000 --> 00:03:29,000
243
+ So there's going to be two doors.
244
+
245
+ 62
246
+ 00:03:29,000 --> 00:03:29,000
247
+ Okay.
248
+
249
+ 63
250
+ 00:03:29,000 --> 00:03:37,000
251
+ So let's say you enter from this door and in, and when you enter from this door, there's a pathway
252
+
253
+ 64
254
+ 00:03:37,000 --> 00:03:38,000
255
+ to the next door.
256
+
257
+ 65
258
+ 00:03:38,000 --> 00:03:44,000
259
+ And in order for the second door to open, because the second door is what takes you to the secure area,
260
+
261
+ 66
262
+ 00:03:44,000 --> 00:03:45,000
263
+ you first have to enter this door.
264
+
265
+ 67
266
+ 00:03:45,000 --> 00:03:49,000
267
+ And then there's some kind of authentication between the two doors.
268
+
269
+ 68
270
+ 00:03:49,000 --> 00:03:54,000
271
+ For example, in a prison, the authentication between the two doors is generally a security guard or
272
+
273
+ 69
274
+ 00:03:54,000 --> 00:03:58,000
275
+ somebody checking your ID, or it could be checking to see if you have any kind of weapons or something.
276
+
277
+ 70
278
+ 00:03:59,000 --> 00:04:05,000
279
+ So you open this door, you go in, you're checked to make sure that you're you match the correct identification.
280
+
281
+ 71
282
+ 00:04:05,000 --> 00:04:07,000
283
+ Maybe you check to see if you have any kind of weapons.
284
+
285
+ 72
286
+ 00:04:07,000 --> 00:04:09,000
287
+ Then the second door opens.
288
+
289
+ 73
290
+ 00:04:09,000 --> 00:04:11,000
291
+ Then you can go in to the secure area.
292
+
293
+ 74
294
+ 00:04:12,000 --> 00:04:17,000
295
+ Now it's not just used in prison, but they're used in a wide variety of places in it.
296
+
297
+ 75
298
+ 00:04:17,000 --> 00:04:19,000
299
+ For example, in data centers.
300
+
301
+ 76
302
+ 00:04:19,000 --> 00:04:21,000
303
+ You're going to find this quite often.
304
+
305
+ 77
306
+ 00:04:21,000 --> 00:04:27,000
307
+ Now it's generally equipped with some kind of biometric scanners, metal detectors and other security
308
+
309
+ 78
310
+ 00:04:27,000 --> 00:04:31,000
311
+ measures that only authorized individuals will gain access to.
312
+
313
+ 79
314
+ 00:04:32,000 --> 00:04:34,000
315
+ Now, the other one here you have is FinCEN.
316
+
317
+ 80
318
+ 00:04:34,000 --> 00:04:35,000
319
+ Now, you're pretty much familiar with FinCEN.
320
+
321
+ 81
322
+ 00:04:35,000 --> 00:04:40,000
323
+ As you can see in this picture here, fences are used to secure perimeters of a property.
324
+
325
+ 82
326
+ 00:04:40,000 --> 00:04:45,000
327
+ Now high security fences are going to be topped with barbed wire and other deterrents to prevent unauthorized
328
+
329
+ 83
330
+ 00:04:45,000 --> 00:04:45,000
331
+ entry.
332
+
333
+ 84
334
+ 00:04:45,000 --> 00:04:51,000
335
+ Remember something a fence is good to secure perimeter and show where where the perimeter of a building
336
+
337
+ 85
338
+ 00:04:51,000 --> 00:04:51,000
339
+ is.
340
+
341
+ 86
342
+ 00:04:52,000 --> 00:04:53,000
343
+ Video surveillance.
344
+
345
+ 87
346
+ 00:04:53,000 --> 00:04:58,000
347
+ Security guards don't have eyes to see an entire space all around.
348
+
349
+ 88
350
+ 00:04:58,000 --> 00:04:59,000
351
+ But if you have.
352
+
353
+ 89
354
+ 00:04:59,000 --> 00:05:00,000
355
+ Good video surveillance.
356
+
357
+ 90
358
+ 00:05:00,000 --> 00:05:02,000
359
+ And I'm talking cameras as we have in this picture.
360
+
361
+ 91
362
+ 00:05:03,000 --> 00:05:11,000
363
+ This can allow one basically one guard or one person and nowadays even software to watch large plots
364
+
365
+ 92
366
+ 00:05:11,000 --> 00:05:12,000
367
+ of areas.
368
+
369
+ 93
370
+ 00:05:12,000 --> 00:05:17,000
371
+ So they're able to monitor activities in and around a facility.
372
+
373
+ 94
374
+ 00:05:17,000 --> 00:05:22,000
375
+ Now the good thing about cameras is they act as a good deterrent to prevent unauthorized actions and
376
+
377
+ 95
378
+ 00:05:22,000 --> 00:05:27,000
379
+ can provide vulnerable evidence so people are less likely to steal things.
380
+
381
+ 96
382
+ 00:05:27,000 --> 00:05:31,000
383
+ Or it might be deter to steal something or break in if they see, oh, look at that.
384
+
385
+ 97
386
+ 00:05:31,000 --> 00:05:32,000
387
+ That camera is watching me.
388
+
389
+ 98
390
+ 00:05:32,000 --> 00:05:36,000
391
+ So they might say, you know what, I don't want to do that because I don't want to get caught.
392
+
393
+ 99
394
+ 00:05:36,000 --> 00:05:40,000
395
+ And if I do get caught, they're going to have the evidence in the camera footage.
396
+
397
+ 100
398
+ 00:05:41,000 --> 00:05:45,000
399
+ Now sometimes you just need a person there.
400
+
401
+ 101
402
+ 00:05:45,000 --> 00:05:52,000
403
+ If there's any kind of discretionary or discretion that has to be made, something that needs to be
404
+
405
+ 102
406
+ 00:05:52,000 --> 00:05:52,000
407
+ checked.
408
+
409
+ 103
410
+ 00:05:52,000 --> 00:05:54,000
411
+ Software is generally not the most reliable.
412
+
413
+ 104
414
+ 00:05:54,000 --> 00:05:56,000
415
+ Sometimes you need that physical security guard.
416
+
417
+ 105
418
+ 00:05:56,000 --> 00:06:01,000
419
+ Unfortunately, we don't have robots that can restrain or physically stop people, but a security guard
420
+
421
+ 106
422
+ 00:06:01,000 --> 00:06:02,000
423
+ could.
424
+
425
+ 107
426
+ 00:06:02,000 --> 00:06:06,000
427
+ So security guard is that human presence is a critical component of physical security.
428
+
429
+ 108
430
+ 00:06:06,000 --> 00:06:13,000
431
+ Remember, we really don't have basically robots that can get up and catch someone running or somebody
432
+
433
+ 109
434
+ 00:06:13,000 --> 00:06:16,000
435
+ that can physically stop someone from entering a building.
436
+
437
+ 110
438
+ 00:06:16,000 --> 00:06:19,000
439
+ That's what human personnel are for until robots come along.
440
+
441
+ 111
442
+ 00:06:19,000 --> 00:06:20,000
443
+ But that's not yet.
444
+
445
+ 112
446
+ 00:06:20,000 --> 00:06:25,000
447
+ So guard they can monitor, they conduct patrols, they respond to incidents, and they're going to
448
+
449
+ 113
450
+ 00:06:25,000 --> 00:06:26,000
451
+ control access.
452
+
453
+ 114
454
+ 00:06:26,000 --> 00:06:28,000
455
+ You're allowed in and you're not allowed in.
456
+
457
+ 115
458
+ 00:06:29,000 --> 00:06:34,000
459
+ Generally, it's pretty common within organizations today for people to be given one of these things
460
+
461
+ 116
462
+ 00:06:34,000 --> 00:06:37,000
463
+ that shows the company name, your name, and your title.
464
+
465
+ 117
466
+ 00:06:37,000 --> 00:06:42,000
467
+ Sometimes they're embedded with what's called an RFID chip or radio frequency ID chips.
468
+
469
+ 118
470
+ 00:06:42,000 --> 00:06:47,000
471
+ So what these are badges are going to be used to identify personnel and will contain some kind of magnetic
472
+
473
+ 119
474
+ 00:06:47,000 --> 00:06:47,000
475
+ strip.
476
+
477
+ 120
478
+ 00:06:47,000 --> 00:06:53,000
479
+ A lot of times these badges are going to be used to enter certain rooms that only these people should
480
+
481
+ 121
482
+ 00:06:53,000 --> 00:06:54,000
483
+ have access to.
484
+
485
+ 122
486
+ 00:06:55,000 --> 00:06:56,000
487
+ Leiden.
488
+
489
+ 123
490
+ 00:06:57,000 --> 00:07:02,000
491
+ Cameras can detect, uh, if it's dark or if it's completely black.
492
+
493
+ 124
494
+ 00:07:02,000 --> 00:07:05,000
495
+ You want to make sure that you have adequate lighting.
496
+
497
+ 125
498
+ 00:07:05,000 --> 00:07:10,000
499
+ It's going to be important for security, especially in outdoor areas, because when the sun goes down,
500
+
501
+ 126
502
+ 00:07:10,000 --> 00:07:13,000
503
+ you're not going to be able to see the entire perimeter.
504
+
505
+ 127
506
+ 00:07:13,000 --> 00:07:20,000
507
+ So make sure the perimeter is well lit and enhances visibility, acting as a deterrent to trespassers,
508
+
509
+ 128
510
+ 00:07:20,000 --> 00:07:22,000
511
+ aiding in the effectiveness of video surveillance.
512
+
513
+ 129
514
+ 00:07:22,000 --> 00:07:27,000
515
+ You see, if it goes dark and the area is completely black, people can just dressed in black and run
516
+
517
+ 130
518
+ 00:07:27,000 --> 00:07:32,000
519
+ through the space, run through the yard, run through the big open ground.
520
+
521
+ 131
522
+ 00:07:32,000 --> 00:07:40,000
523
+ That's because run through the big open ground, because it's relatively easy for them to go through,
524
+
525
+ 132
526
+ 00:07:40,000 --> 00:07:42,000
527
+ and the camera can't detect them because it's all black.
528
+
529
+ 133
530
+ 00:07:42,000 --> 00:07:46,000
531
+ Remember, the camera needs light sensors.
532
+
533
+ 134
534
+ 00:07:46,000 --> 00:07:50,000
535
+ Now you're going to have a variety of motion detectors.
536
+
537
+ 135
538
+ 00:07:50,000 --> 00:07:56,000
539
+ Now these kinds of motion detectors is going to be able to detect motion in around your ground.
540
+
541
+ 136
542
+ 00:07:56,000 --> 00:07:57,000
543
+ There's a few different ones.
544
+
545
+ 137
546
+ 00:07:57,000 --> 00:07:59,000
547
+ The first one is going to be infrared sensors.
548
+
549
+ 138
550
+ 00:07:59,000 --> 00:08:03,000
551
+ These are going to detect heat often used in an intrusion detection system.
552
+
553
+ 139
554
+ 00:08:03,000 --> 00:08:05,000
555
+ These are really good because basically.
556
+
557
+ 140
558
+ 00:08:06,000 --> 00:08:12,000
559
+ These are going to be really used to detect if there's heat in the space and if there's movement within
560
+
561
+ 141
562
+ 00:08:12,000 --> 00:08:13,000
563
+ that space of that heat.
564
+
565
+ 142
566
+ 00:08:13,000 --> 00:08:15,000
567
+ Heat signals the infrared sensors.
568
+
569
+ 143
570
+ 00:08:15,000 --> 00:08:17,000
571
+ The problem is they're not going to be able to do a white space.
572
+
573
+ 144
574
+ 00:08:17,000 --> 00:08:19,000
575
+ The other one you have is a pressure sensor.
576
+
577
+ 145
578
+ 00:08:19,000 --> 00:08:22,000
579
+ These detect changes in pressure like weight.
580
+
581
+ 146
582
+ 00:08:22,000 --> 00:08:25,000
583
+ These are these are going to put on things like secure flooring or windows.
584
+
585
+ 147
586
+ 00:08:25,000 --> 00:08:30,000
587
+ So if anybody like for example steps on the flooring, it's going to know the weight has changed or
588
+
589
+ 148
590
+ 00:08:30,000 --> 00:08:32,000
591
+ the pressure has changed and it's going to set off an alarm.
592
+
593
+ 149
594
+ 00:08:32,000 --> 00:08:36,000
595
+ Now, if you have something like a big perimeter or a big ground that you want to secure, you're going
596
+
597
+ 150
598
+ 00:08:36,000 --> 00:08:37,000
599
+ to use what's called microwave sensors.
600
+
601
+ 151
602
+ 00:08:37,000 --> 00:08:40,000
603
+ These are going to be able to detect movement in a much larger area.
604
+
605
+ 152
606
+ 00:08:41,000 --> 00:08:46,000
607
+ Now, the other one you have, and some of the later technology is going to be that ultrasonic.
608
+
609
+ 153
610
+ 00:08:46,000 --> 00:08:50,000
611
+ These emit ultrasonic wave and measure the reflection off the objects.
612
+
613
+ 154
614
+ 00:08:50,000 --> 00:08:55,000
615
+ These are going to basically use in a lot of different motion detection systems that we have out there.
616
+
617
+ 155
618
+ 00:08:56,000 --> 00:08:56,000
619
+ Okay.
620
+
621
+ 156
622
+ 00:08:56,000 --> 00:08:59,000
623
+ These are going to be some of the things here that you might see on your exam.
624
+
625
+ 157
626
+ 00:08:59,000 --> 00:09:04,000
627
+ When it comes to physical security, the best thing is make sure you understand them, understand what
628
+
629
+ 158
630
+ 00:09:04,000 --> 00:09:05,000
631
+ these things are when you see them.
632
+
633
+ 159
634
+ 00:09:05,000 --> 00:09:13,000
635
+ Now keep in mind, guys, don't forget it doesn't matter how good your technical security is, it's
636
+
637
+ 160
638
+ 00:09:13,000 --> 00:09:17,000
639
+ going to be rendered ineffective if you don't have good physical security.
640
+
23 - Physical Security/002 Quick Quiz.html ADDED
@@ -0,0 +1,479 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ <!DOCTYPE html>
2
+ <html lang="en">
3
+ <head>
4
+ <meta charset="UTF-8" />
5
+ <meta http-equiv="X-UA-Compatible" content="IE=edge" />
6
+ <meta name="viewport" content="width=device-width, initial-scale=1.0" />
7
+ <title>Quiz</title>
8
+ <style>
9
+ * {
10
+ font-family: system-ui, -apple-system, BlinkMacSystemFont, "Segoe UI", Roboto, Oxygen, Ubuntu, Cantarell,
11
+ "Open Sans", "Helvetica Neue", sans-serif;
12
+ margin: 0;
13
+ padding: 0;
14
+ box-sizing: border-box;
15
+ font-size: 16px;
16
+ }
17
+
18
+ main {
19
+ padding-top: 48px;
20
+ }
21
+
22
+ :root {
23
+ --large-device-width: 850px;
24
+ --primary-color: #0f172a;
25
+ --secondary-color: #020617;
26
+ --primary-text-color: #c7d1dd;
27
+ --secondary-text-color: #061602;
28
+ --success-background: hsl(159, 82%, 24%);
29
+ --success-foreground: hsl(164, 86%, 16%);
30
+ --success: hsl(160, 84%, 39%);
31
+ --danger: #ef4444;
32
+ --warning: #f59e0b;
33
+ --info-background: hsl(218, 81%, 8%);
34
+ --info-foreground: hsl(217, 91%, 85%);
35
+ --border-color: #d1d7dc;
36
+ --check-box-size: 20px;
37
+ /* control the size */
38
+ --check-box-color: var(--info-foreground);
39
+ /* the active color */
40
+ }
41
+
42
+ body {
43
+ position: relative;
44
+ background-color: #020617;
45
+ color: var(--primary-text-color);
46
+ }
47
+
48
+ #score-stats-container {
49
+ position: fixed;
50
+ z-index: 10;
51
+ top: 0;
52
+ height: 40px;
53
+ width: 100%;
54
+ background-color: var(--info-background);
55
+
56
+ padding: 0px 16px;
57
+ color: var(--info-foreground);
58
+ font-weight: 600;
59
+ display: flex;
60
+ align-items: center;
61
+ justify-content: space-between;
62
+ }
63
+
64
+ #quiz-container {
65
+ border-radius: 8px;
66
+ display: flex;
67
+ gap: 16px;
68
+ flex-direction: column;
69
+ }
70
+
71
+ input[type="radio"] {
72
+ height: var(--check-box-size);
73
+ aspect-ratio: 1;
74
+ border: calc(var(--check-box-size) / 8) solid #939393;
75
+ padding: calc(var(--check-box-size) / 8);
76
+ background: radial-gradient(farthest-side, var(--check-box-color) 94%, #0000) 50%/0 0 no-repeat
77
+ content-box;
78
+ border-radius: 50%;
79
+ outline-offset: calc(var(--check-box-size) / 10);
80
+ -webkit-appearance: none;
81
+ -moz-appearance: none;
82
+ appearance: none;
83
+ cursor: pointer;
84
+ font-size: inherit;
85
+ transition: 0.3s;
86
+ }
87
+
88
+ input[type="radio"]:checked {
89
+ border-color: var(--check-box-color);
90
+ background-size: 100% 100%;
91
+ }
92
+
93
+ input[type="radio"]:disabled {
94
+ background: linear-gradient(#939393 0 0) 50%/100% 20% no-repeat content-box;
95
+ opacity: 0.5;
96
+ cursor: not-allowed;
97
+ }
98
+
99
+ label {
100
+ display: inline-flex;
101
+ align-items: center;
102
+ gap: 10px;
103
+ cursor: pointer;
104
+ padding: 4px 6px;
105
+ border-radius: 4px;
106
+ }
107
+
108
+ @media (max-width: 767px) {
109
+ input[type="radio"],
110
+ label {
111
+ cursor: default;
112
+ }
113
+
114
+ #quiz-container {
115
+ margin-left: 8px;
116
+ margin-right: 8px;
117
+ }
118
+ }
119
+
120
+ /* PC (Desktop devices) */
121
+ @media (min-width: 768px) {
122
+ body {
123
+ display: flex;
124
+ justify-content: center;
125
+ }
126
+
127
+ main {
128
+ max-width: var(--large-device-width);
129
+ }
130
+
131
+ #score-stats-container {
132
+ max-width: var(--large-device-width);
133
+ }
134
+
135
+ dialog {
136
+ max-width: var(--large-device-width);
137
+ }
138
+ }
139
+
140
+ @media print {
141
+ input[type="radio"] {
142
+ background: none !important;
143
+ border-color: #939393 !important;
144
+ }
145
+
146
+ input[type="radio"]:checked {
147
+ border-color: #939393 !important;
148
+ }
149
+ }
150
+
151
+ .question-lable {
152
+ display: flex;
153
+ align-items: center;
154
+ gap: 8px;
155
+ }
156
+
157
+ button {
158
+ -webkit-tap-highlight-color: transparent;
159
+ -webkit-touch-callout: none;
160
+ -webkit-user-select: none;
161
+ user-select: none;
162
+ outline: none;
163
+ position: relative;
164
+ overflow: hidden;
165
+ cursor: pointer;
166
+ }
167
+
168
+ .button {
169
+ background-color: var(--success-background);
170
+ border: none;
171
+ color: #f4f5f7;
172
+ opacity: 0.8;
173
+ font-size: 18px;
174
+ flex-grow: 1;
175
+ padding: 8px 16px;
176
+ border-radius: 8px;
177
+ }
178
+
179
+ .button:hover {
180
+ opacity: 1;
181
+ }
182
+
183
+ .explanation-btn {
184
+ border: none;
185
+ color: var(--success);
186
+ background-color: transparent;
187
+ }
188
+
189
+ #submit-button:active::after {
190
+ background-color: #ef4444;
191
+ }
192
+
193
+ .single-question-container {
194
+ background-color: var(--primary-color);
195
+ display: flex;
196
+ flex-direction: column;
197
+ gap: 8px;
198
+ padding: 16px;
199
+ border-radius: 8px;
200
+ }
201
+
202
+ #modal-content {
203
+ padding: 16px;
204
+ line-height: 24px;
205
+ }
206
+
207
+ dialog::backdrop {
208
+ background: rgba(0, 0, 0, 0.5);
209
+ }
210
+
211
+ dialog {
212
+ position: fixed;
213
+ border: 1px solid var(--border-color);
214
+ background-color: var(--primary-color);
215
+ color: rgb(240, 241, 248);
216
+ padding: 16px;
217
+ border-radius: 8px;
218
+ width: 80vw;
219
+ max-height: 80vh;
220
+ overflow: auto;
221
+ top: 50%;
222
+ left: 50%;
223
+ -webkit-transform: translateX(-50%) translateY(-50%);
224
+ -moz-transform: translateX(-50%) translateY(-50%);
225
+ -ms-transform: translateX(-50%) translateY(-50%);
226
+ transform: translateX(-50%) translateY(-50%);
227
+ }
228
+
229
+ #close-modal-btn {
230
+ position: absolute;
231
+ top: 4px;
232
+ right: 4px;
233
+ padding: 2px 8px;
234
+ border-radius: 2px;
235
+ border: none;
236
+ background-color: var(--danger);
237
+ }
238
+
239
+ .correct-answer label {
240
+ border: 2px solid var(--success);
241
+ width: 100%;
242
+ }
243
+
244
+ .incorrect-answer label {
245
+ border: 2px solid var(--danger);
246
+ width: 100%;
247
+ }
248
+
249
+ .options-container {
250
+ display: flex;
251
+ flex-direction: column;
252
+ gap: 4px;
253
+ }
254
+
255
+ #quiz-meta-container {
256
+ border-radius: 8px;
257
+ background-color: var(--primary-color);
258
+ margin-bottom: 12px;
259
+ padding: 8px;
260
+ }
261
+
262
+ #quiz-title {
263
+ text-align: center;
264
+ font-size: 24px;
265
+ margin-bottom: 8px;
266
+ }
267
+
268
+ #quiz-description {
269
+ line-height: 1.5;
270
+ padding: 2px 6px;
271
+ }
272
+ </style>
273
+ </head>
274
+
275
+ <body onload="main()">
276
+ <main>
277
+ <section id="quiz-meta-container">
278
+ <h1 id="quiz-title"></h1>
279
+ <p id="quiz-description"></p>
280
+ </section>
281
+ <section id="score-stats-container">
282
+ <div id="score-card">
283
+ Score: <span id="current-score">999</span> of
284
+ <span id="pass-percent">999%</span>
285
+ </div>
286
+ <div>Correct: <span id="correct-answers">999</span></div>
287
+ <div>Incorrect: <span id="wrong-answers">999</span></div>
288
+ </section>
289
+
290
+ <section id="quiz-container"></section>
291
+
292
+ <dialog id="modal" class="modal-container">
293
+ <div id="modal-content">
294
+ <p id="modal-text"></p>
295
+ </div>
296
+ </dialog>
297
+ </main>
298
+
299
+ <script>
300
+ const quizData = {"quiz_id": 6180104, "quiz_description": null, "quiz_title": "Quick Quiz", "pass_percent": null, "questions": [{"_class": "assessment", "id": 74728190, "assessment_type": "multiple-choice", "prompt": {"question": "<p>To monitor activities at all times, especially in low-light conditions, which security feature should a business install?</p>", "relatedLectureIds": "", "feedbacks": ["", "", "Video surveillance is the most comprehensive option for monitoring activities, and it often includes capabilities for low-light conditions. Lighting improves visibility but does not record or monitor. Access badges control access but do not monitor wide areas. Infrared sensors detect heat and movement but do not provide visual monitoring.", ""], "answers": ["<p>Lighting</p>", "<p>Access badge</p>", "<p>Video surveillance</p>", "<p>Infrared sensors</p>"]}, "correct_response": ["c"], "section": "", "question_plain": "To monitor activities at all times, especially in low-light conditions, which security feature should a business install?", "related_lectures": []}, {"_class": "assessment", "id": 74728198, "assessment_type": "multiple-choice", "prompt": {"question": "<p>In a museum, which security feature is most effective for protecting exhibits from touch or close proximity by visitors?</p>", "relatedLectureIds": "", "feedbacks": ["", "", "Infrared sensors can be set up around exhibits to detect and alert staff if visitors get too close, making them ideal for protecting exhibits. Pressure sensors are more for detecting weight changes, not proximity. Security guards provide general surveillance but can't monitor all exhibits simultaneously. Access badges control access but don't protect specific items.", ""], "answers": ["<p>Pressure sensors</p>", "<p>Security guard</p>", "<p>Infrared sensors</p>", "<p>Access badge</p>"]}, "correct_response": ["c"], "section": "", "question_plain": "In a museum, which security feature is most effective for protecting exhibits from touch or close proximity by visitors?", "related_lectures": []}, {"_class": "assessment", "id": 74728200, "assessment_type": "multiple-choice", "prompt": {"question": "<p>For a high-security data center, which of the following would most effectively control access to server rooms?</p>", "relatedLectureIds": "", "feedbacks": ["", "An access badge system can specifically control and monitor individual access to sensitive areas like server rooms in a data center. Bollards and fencing are more suited to external security. Ultrasonic sensors detect presence but don't control access.", "", ""], "answers": ["<p>Bollards</p>", "<p>Access badge system</p>", "<p>Fencing</p>", "<p>Ultrasonic sensors</p>"]}, "correct_response": ["b"], "section": "", "question_plain": "For a high-security data center, which of the following would most effectively control access to server rooms?", "related_lectures": []}]};
301
+ let correct = new Set();
302
+ let incorrect = new Set();
303
+ let totalNumberOfQuestions = 0;
304
+ const quizTitle = quizData.quiz_title;
305
+ const quizDescription = quizData.quiz_description;
306
+ const questionData = quizData.questions;
307
+ const passPercent = quizData.pass_percent;
308
+ const modalTextElement = document.getElementById("modal-text");
309
+ const quizContainerElement = document.getElementById("quiz-container");
310
+
311
+ const dialog = document.querySelector("dialog");
312
+ const showButton = document.getElementById("view-explanatin");
313
+ const closeButton = document.getElementById("close-modal-btn");
314
+ const quizTitleElement = document.getElementById("quiz-title");
315
+ const quizDescriptionElement = document.getElementById("quiz-description");
316
+
317
+ function main() {
318
+ // update quiz meta data
319
+ document.title = quizTitle;
320
+ quizTitleElement.innerHTML = quizTitle;
321
+ quizDescriptionElement.innerHTML = quizDescription;
322
+
323
+ const passPercentElement = document.getElementById("pass-percent");
324
+ passPercentElement.innerHTML = passPercent + "%";
325
+ totalNumberOfQuestions = questionData.length;
326
+ // shuffle the questionData to randomize the order of the questions
327
+ for (let i = questionData.length - 1; i > 0; i--) {
328
+ const j = Math.floor(Math.random() * (i + 1));
329
+ [questionData[i], questionData[j]] = [questionData[j], questionData[i]];
330
+ }
331
+
332
+ let formattedQuestions = questionData.map(formatSingleQuestionData);
333
+ updateScore();
334
+ // display the formattedQuestions
335
+ formattedQuestions.forEach((question, idx) => {
336
+ renderSingleQuestion(question, idx + 1);
337
+ });
338
+ }
339
+
340
+ /**
341
+ * Formats the question data from the given QuizData object.
342
+ *
343
+ * @param {Object} singleQuizData - The singleQuizData object containing prompt and correct_response.
344
+ * @return {Object} The formatted question object with the following properties:
345
+ * - id: The ID of the question.
346
+ * - question: The text of the question.
347
+ * - answers: The array of answer options.
348
+ * - correctAnswer: The text of the correct answer.
349
+ * - explanation: The explanation of the correct answer.
350
+ */
351
+ function formatSingleQuestionData(singleQuizData = null) {
352
+ const { prompt, correct_response, id } = singleQuizData;
353
+ const questionText = prompt.question;
354
+ const answers = prompt.answers;
355
+ const correctAnswer = correct_response[0];
356
+ const correctAnswerText = answers[correctAnswer.toLowerCase().charCodeAt(0) - 97];
357
+ const questionObj = {
358
+ id: id,
359
+ question: questionText,
360
+ answers: answers,
361
+ correctAnswer: correctAnswerText,
362
+ explanation: prompt?.explanation || "",
363
+ };
364
+ return questionObj;
365
+ }
366
+
367
+ /**
368
+ * Renders a single question with its options and submit button.
369
+ *
370
+ * @param {Object} singleQuestionData - The data of the question to render.
371
+ * @param {number} rootIndex - The index of the question in the quiz.
372
+ * @return {void} return nothing.
373
+ */
374
+
375
+ const renderSingleQuestion = (singleQuestionData = {}, rootIndex = 1) => {
376
+ const { id, explanation, answers, correctAnswer, question } = singleQuestionData;
377
+ // shuffle the answers to randomize the order of the answers
378
+ for (let i = answers.length - 1; i > 0; i--) {
379
+ const j = Math.floor(Math.random() * (i + 1));
380
+ [answers[i], answers[j]] = [answers[j], answers[i]];
381
+ }
382
+ const optionsHTML = answers
383
+ .map((option, index) => {
384
+ const optionId = `${id}_${index}`;
385
+
386
+ return `
387
+ <div class="question-lable">
388
+ <input type="radio" id="${optionId}" name="${"answer"}" value="${option}" />
389
+ <label for="${optionId}">${option}</label>
390
+ </div>
391
+ `;
392
+ })
393
+
394
+ .join("");
395
+
396
+ const container = document.createElement("div");
397
+ container.innerHTML = `
398
+ <form data-correct-answer="${correctAnswer}" data-question-id="${id}" class="single-question-container" onsubmit="submitButtonListener(event)">
399
+ <div style="display: flex;justify-content: space-between;">
400
+ <p style="font-weight: 600">Question ${rootIndex}:</p>
401
+ <button type="button" onclick="renderExplanation(event)" id="${`explanation-${id}`}" data-explanation="${explanation}" class="explanation-btn">View Explanation</button>
402
+ </div>
403
+ <p style="margin-bottom: 8px;line-height: 1.5">${question}</p>
404
+ <div class="options-container">
405
+ ${optionsHTML}
406
+ </div>
407
+ <div style="display: flex; gap: 8px;">
408
+ <button type="submit" id="submit-button" class="button">Submit</button>
409
+ </div>
410
+ </form>
411
+ `;
412
+ quizContainerElement.appendChild(container);
413
+ };
414
+
415
+ /**
416
+ * Updates the score on the page based on the number of correct and incorrect answers.
417
+ *
418
+ * @return {void} This function does not return a value.
419
+ */
420
+ function updateScore() {
421
+ const currentParcentageElement = document.getElementById("current-score");
422
+ const correctAnswerElement = document.getElementById("correct-answers");
423
+ const wrongAnswerElement = document.getElementById("wrong-answers");
424
+ correctAnswerElement.innerHTML = correct.size;
425
+ wrongAnswerElement.innerHTML = incorrect.size;
426
+ const score = Number((correct.size / totalNumberOfQuestions) * 100).toFixed(2);
427
+ currentParcentageElement.innerHTML = score;
428
+ }
429
+
430
+ /**
431
+ * Handles the event when the submit button is clicked.
432
+ *
433
+ * @param {Event} e - The event object.
434
+ * @return {void} This function does not return anything.
435
+ */
436
+ const submitButtonListener = (e) => {
437
+ e.preventDefault();
438
+ const formData = new FormData(e.target);
439
+ const form = e.target;
440
+ const selectedOption = e.target.querySelector('input[type="radio"]:checked');
441
+ if (!selectedOption) {
442
+ alert("Please select an answer!");
443
+ return;
444
+ }
445
+
446
+ let isCorrect = false;
447
+ const { answer: userAnswer } = Object.fromEntries(formData.entries());
448
+ const correctAnswer = e.target.dataset.correctAnswer;
449
+ const questionId = e.target.dataset.questionId;
450
+ if (userAnswer == correctAnswer) {
451
+ correct.add(questionId);
452
+ incorrect.delete(questionId);
453
+ isCorrect = true;
454
+ } else {
455
+ incorrect.add(e.target.dataset.questionId);
456
+ correct.delete(questionId);
457
+ }
458
+ updateScore();
459
+
460
+ const resultClass = isCorrect ? "correct-answer" : "incorrect-answer";
461
+
462
+ form.querySelectorAll(".question-lable").forEach((label) => {
463
+ label.classList.remove("correct-answer", "incorrect-answer");
464
+ });
465
+ selectedOption.closest(".question-lable").classList.add(resultClass);
466
+ };
467
+
468
+ function renderExplanation(ev) {
469
+ modalTextElement.innerHTML = ev.target.dataset?.explanation || "no explanation found";
470
+ dialog.showModal();
471
+ dialog.addEventListener("click", (event) => {
472
+ if (event.target === dialog) {
473
+ dialog.close();
474
+ }
475
+ });
476
+ }
477
+ </script>
478
+ </body>
479
+ </html>
24 - Change Management/001 Change management OB 1.3_en.srt ADDED
@@ -0,0 +1,824 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ 1
2
+ 00:00:00,000 --> 00:00:02,000
3
+ As an IT security person.
4
+
5
+ 2
6
+ 00:00:02,000 --> 00:00:06,000
7
+ Anytime something breaks within an organization or there's some kind of security incident, the first
8
+
9
+ 3
10
+ 00:00:06,000 --> 00:00:09,000
11
+ thing that comes to my mind is what changed?
12
+
13
+ 4
14
+ 00:00:09,000 --> 00:00:10,000
15
+ Who changed what?
16
+
17
+ 5
18
+ 00:00:10,000 --> 00:00:13,000
19
+ Now I want to point out something to you guys.
20
+
21
+ 6
22
+ 00:00:13,000 --> 00:00:17,000
23
+ You could build the greatest and most secure system.
24
+
25
+ 7
26
+ 00:00:18,000 --> 00:00:24,000
27
+ Great firewalls, a good configuration on firewalls, just good selection of configuration of switches,
28
+
29
+ 8
30
+ 00:00:24,000 --> 00:00:30,000
31
+ routers, access points, anti-malware software, intrusion detection and prevention systems, and so
32
+
33
+ 9
34
+ 00:00:30,000 --> 00:00:30,000
35
+ on.
36
+
37
+ 10
38
+ 00:00:31,000 --> 00:00:36,000
39
+ And then it just takes somebody to go and do an unauthorized change or change that you didn't authorize
40
+
41
+ 11
42
+ 00:00:36,000 --> 00:00:37,000
43
+ or didn't know about.
44
+
45
+ 12
46
+ 00:00:37,000 --> 00:00:40,000
47
+ And all your security just goes right down the drain.
48
+
49
+ 13
50
+ 00:00:40,000 --> 00:00:44,000
51
+ Maybe because they punch a hole in the firewall, they change the level of authentication that allows
52
+
53
+ 14
54
+ 00:00:44,000 --> 00:00:46,000
55
+ easy passwords or something.
56
+
57
+ 15
58
+ 00:00:46,000 --> 00:00:50,000
59
+ Change management is critical for IT security.
60
+
61
+ 16
62
+ 00:00:50,000 --> 00:00:57,000
63
+ We want to make sure that any changes within the organization is done in a secure way, and it doesn't
64
+
65
+ 17
66
+ 00:00:57,000 --> 00:01:01,000
67
+ reduce the security in the organization if it increases it, great.
68
+
69
+ 18
70
+ 00:01:01,000 --> 00:01:04,000
71
+ Now you got to keep in mind that change will happen in a company.
72
+
73
+ 19
74
+ 00:01:04,000 --> 00:01:08,000
75
+ If a company is around long enough, they're going to change from Windows 10 to Windows 11.
76
+
77
+ 20
78
+ 00:01:08,000 --> 00:01:09,000
79
+ They're going to change a router.
80
+
81
+ 21
82
+ 00:01:09,000 --> 00:01:10,000
83
+ They're going to change a switch.
84
+
85
+ 22
86
+ 00:01:10,000 --> 00:01:12,000
87
+ They're going to change an access point.
88
+
89
+ 23
90
+ 00:01:12,000 --> 00:01:14,000
91
+ They're going to change people.
92
+
93
+ 24
94
+ 00:01:14,000 --> 00:01:16,000
95
+ Changes will happen.
96
+
97
+ 25
98
+ 00:01:16,000 --> 00:01:18,000
99
+ Business processes and procedure changes.
100
+
101
+ 26
102
+ 00:01:18,000 --> 00:01:19,000
103
+ So changes will happen.
104
+
105
+ 27
106
+ 00:01:20,000 --> 00:01:25,000
107
+ So in this video I want to talk about change management and some of the things we should be expecting
108
+
109
+ 28
110
+ 00:01:25,000 --> 00:01:28,000
111
+ when managing changes across the entire company.
112
+
113
+ 29
114
+ 00:01:28,000 --> 00:01:35,000
115
+ So in cybersecurity, change management is a structured approach to transitioning individuals, teams
116
+
117
+ 30
118
+ 00:01:35,000 --> 00:01:41,000
119
+ and the organization from the current state to a future state or desired future state, while ensuring
120
+
121
+ 31
122
+ 00:01:41,000 --> 00:01:45,000
123
+ now keep in mind the security, the confidentiality, integrity and availability of information.
124
+
125
+ 32
126
+ 00:01:45,000 --> 00:01:46,000
127
+ So that's important.
128
+
129
+ 33
130
+ 00:01:47,000 --> 00:01:48,000
131
+ Remember something.
132
+
133
+ 34
134
+ 00:01:49,000 --> 00:01:55,000
135
+ For us to go from where we are right now, our current state to where we want to be a desired state.
136
+
137
+ 35
138
+ 00:01:55,000 --> 00:01:57,000
139
+ Something needs to change.
140
+
141
+ 36
142
+ 00:01:57,000 --> 00:01:59,000
143
+ I'm £215.
144
+
145
+ 37
146
+ 00:01:59,000 --> 00:01:59,000
147
+ All right.
148
+
149
+ 38
150
+ 00:01:59,000 --> 00:02:05,000
151
+ The doctor and my wife and everybody keeps telling me, Andrew, you need to be £190.
152
+
153
+ 39
154
+ 00:02:05,000 --> 00:02:12,000
155
+ Well, in order for me to go from the current 215 to the desired 190.
156
+
157
+ 40
158
+ 00:02:12,000 --> 00:02:15,000
159
+ Well, I got to do what I got to change, right?
160
+
161
+ 41
162
+ 00:02:15,000 --> 00:02:19,000
163
+ Maybe I got to give up that eating that Burger King twice a week or that McDonald's a couple of times
164
+
165
+ 42
166
+ 00:02:19,000 --> 00:02:20,000
167
+ a week.
168
+
169
+ 43
170
+ 00:02:20,000 --> 00:02:21,000
171
+ Maybe I got to give up that couple of beers.
172
+
173
+ 44
174
+ 00:02:21,000 --> 00:02:23,000
175
+ In other words, I have to change something.
176
+
177
+ 45
178
+ 00:02:23,000 --> 00:02:29,000
179
+ So changes must occur from for an organization to go from a current state to a desired state, your
180
+
181
+ 46
182
+ 00:02:29,000 --> 00:02:34,000
183
+ job is going to be to ensure that all the changes that the organization is going to be going through
184
+
185
+ 47
186
+ 00:02:34,000 --> 00:02:35,000
187
+ is done in a secure way.
188
+
189
+ 48
190
+ 00:02:35,000 --> 00:02:39,000
191
+ Now there are going to be security changes.
192
+
193
+ 49
194
+ 00:02:39,000 --> 00:02:41,000
195
+ Now what are security changes?
196
+
197
+ 50
198
+ 00:02:41,000 --> 00:02:44,000
199
+ Well, for example, you configure this firewall and it's working all good.
200
+
201
+ 51
202
+ 00:02:44,000 --> 00:02:47,000
203
+ Now you want to change a configuration on the firewall.
204
+
205
+ 52
206
+ 00:02:47,000 --> 00:02:48,000
207
+ You want to change a rule on it.
208
+
209
+ 53
210
+ 00:02:48,000 --> 00:02:50,000
211
+ You want to update a rule.
212
+
213
+ 54
214
+ 00:02:50,000 --> 00:02:52,000
215
+ You want to remove a rule on a firewall.
216
+
217
+ 55
218
+ 00:02:52,000 --> 00:02:53,000
219
+ Anti-Malware software.
220
+
221
+ 56
222
+ 00:02:53,000 --> 00:02:57,000
223
+ Maybe you want to change the anti-malware software or add a new configuration.
224
+
225
+ 57
226
+ 00:02:57,000 --> 00:03:01,000
227
+ So let's go through some things that we want to keep in mind when managing changes.
228
+
229
+ 58
230
+ 00:03:02,000 --> 00:03:07,000
231
+ Now business process impacting security operation.
232
+
233
+ 59
234
+ 00:03:07,000 --> 00:03:09,000
235
+ Now we got to understand something.
236
+
237
+ 60
238
+ 00:03:09,000 --> 00:03:14,000
239
+ Business process is what they're going to be doing to produce the deliverables or produce the products
240
+
241
+ 61
242
+ 00:03:14,000 --> 00:03:15,000
243
+ and services that they sell.
244
+
245
+ 62
246
+ 00:03:15,000 --> 00:03:17,000
247
+ This will have an impact on security.
248
+
249
+ 63
250
+ 00:03:17,000 --> 00:03:23,000
251
+ In general, understanding business processes impacting security operations involve knowing how these
252
+
253
+ 64
254
+ 00:03:23,000 --> 00:03:28,000
255
+ processes work together to manage changes in a way that minimize risk, and ensuring security and stability
256
+
257
+ 65
258
+ 00:03:28,000 --> 00:03:29,000
259
+ of the environment.
260
+
261
+ 66
262
+ 00:03:29,000 --> 00:03:33,000
263
+ When you go out and you change something, how is that going to impact?
264
+
265
+ 67
266
+ 00:03:34,000 --> 00:03:36,000
267
+ The business processes that's happening.
268
+
269
+ 68
270
+ 00:03:36,000 --> 00:03:43,000
271
+ For example, let's say you go and you modify, uh, you implement a new version of windows across everybody's
272
+
273
+ 69
274
+ 00:03:43,000 --> 00:03:47,000
275
+ machine, put Windows 11 that you all had, Windows 10, that can have massive disruption to business
276
+
277
+ 70
278
+ 00:03:47,000 --> 00:03:51,000
279
+ operation because people may may not know how to use it very well.
280
+
281
+ 71
282
+ 00:03:51,000 --> 00:03:56,000
283
+ So you've got to make sure and understand how does these changes impact business operation.
284
+
285
+ 72
286
+ 00:03:56,000 --> 00:04:02,000
287
+ Every change management procedure in a business needs to have some kind of an approval process.
288
+
289
+ 73
290
+ 00:04:02,000 --> 00:04:04,000
291
+ This is going to be different for every business.
292
+
293
+ 74
294
+ 00:04:04,000 --> 00:04:07,000
295
+ Just understand for now that there has to be one.
296
+
297
+ 75
298
+ 00:04:07,000 --> 00:04:09,000
299
+ It's a structured approval process.
300
+
301
+ 76
302
+ 00:04:10,000 --> 00:04:15,000
303
+ Ensure that any changes, especially those affect on IT systems and security, are reviewed and approved
304
+
305
+ 77
306
+ 00:04:15,000 --> 00:04:17,000
307
+ by an authorized personnel.
308
+
309
+ 78
310
+ 00:04:17,000 --> 00:04:19,000
311
+ Who is authorized personnel.
312
+
313
+ 79
314
+ 00:04:19,000 --> 00:04:26,000
315
+ Depending on the type of change, it may be a lower level IT manager, a higher mid-level IT manager.
316
+
317
+ 80
318
+ 00:04:26,000 --> 00:04:30,000
319
+ It may be the CIO that needs to approve of a certain change.
320
+
321
+ 81
322
+ 00:04:30,000 --> 00:04:37,000
323
+ For example, a small change to desktop computers may be done by the Helpdesk Help help desk manager,
324
+
325
+ 82
326
+ 00:04:37,000 --> 00:04:43,000
327
+ a major change that somebody wants to implement, like, uh, new configuration or firewall may be done
328
+
329
+ 83
330
+ 00:04:43,000 --> 00:04:46,000
331
+ by the CISO or the chief information security officer.
332
+
333
+ 84
334
+ 00:04:46,000 --> 00:04:52,000
335
+ But change in massive technology, like all the desktops to win for windows uh, 10 to 11 might need
336
+
337
+ 85
338
+ 00:04:52,000 --> 00:04:53,000
339
+ the CIO approval.
340
+
341
+ 86
342
+ 00:04:53,000 --> 00:04:57,000
343
+ So think of that approval process.
344
+
345
+ 87
346
+ 00:04:57,000 --> 00:04:59,000
347
+ It's going to be different for every single organization.
348
+
349
+ 88
350
+ 00:04:59,000 --> 00:05:04,000
351
+ This is going to help to mitigate risk associated with unauthorized or poorly planned changes.
352
+
353
+ 89
354
+ 00:05:04,000 --> 00:05:06,000
355
+ So you got to have some kind of an approval process.
356
+
357
+ 90
358
+ 00:05:06,000 --> 00:05:06,000
359
+ Why?
360
+
361
+ 91
362
+ 00:05:06,000 --> 00:05:12,000
363
+ Because then people are going to know, well, I can't implement the change without having the approval.
364
+
365
+ 92
366
+ 00:05:12,000 --> 00:05:14,000
367
+ Next thing we want to look at is ownership.
368
+
369
+ 93
370
+ 00:05:14,000 --> 00:05:15,000
371
+ Who owns the change?
372
+
373
+ 94
374
+ 00:05:16,000 --> 00:05:20,000
375
+ Ownership refers to identify who's responsible for overseeing the change process.
376
+
377
+ 95
378
+ 00:05:20,000 --> 00:05:26,000
379
+ So this can go many ways because you can have a person owning the change management process.
380
+
381
+ 96
382
+ 00:05:26,000 --> 00:05:32,000
383
+ Or you can have a team doing this, or you can have ownership of the of a specific change itself.
384
+
385
+ 97
386
+ 00:05:32,000 --> 00:05:39,000
387
+ When you're when there's ownership of changes, that person or team is going to be responsible for planning,
388
+
389
+ 98
390
+ 00:05:39,000 --> 00:05:41,000
391
+ executing and follow up to the change.
392
+
393
+ 99
394
+ 00:05:41,000 --> 00:05:48,000
395
+ This ensures accountability and that the appropriate security consideration are integrated into them.
396
+
397
+ 100
398
+ 00:05:48,000 --> 00:05:52,000
399
+ The next thing is when we implement the change who's it?
400
+
401
+ 101
402
+ 00:05:52,000 --> 00:05:53,000
403
+ Who's this change affected?
404
+
405
+ 102
406
+ 00:05:54,000 --> 00:05:59,000
407
+ If you implement a firewall change to allow remote workers, well, then the stakeholders are going
408
+
409
+ 103
410
+ 00:05:59,000 --> 00:06:02,000
411
+ to be only people that are working remotely.
412
+
413
+ 104
414
+ 00:06:02,000 --> 00:06:06,000
415
+ And of course the IT security department and some infrastructure department.
416
+
417
+ 105
418
+ 00:06:06,000 --> 00:06:11,000
419
+ If it's a change like going from Windows 10 to Windows 11, that's a change that's going to impact every
420
+
421
+ 106
422
+ 00:06:11,000 --> 00:06:12,000
423
+ single user in the business.
424
+
425
+ 107
426
+ 00:06:12,000 --> 00:06:15,000
427
+ These are called stakeholders in change management.
428
+
429
+ 108
430
+ 00:06:15,000 --> 00:06:20,000
431
+ Anyone who may be affected or who has influence over the process.
432
+
433
+ 109
434
+ 00:06:20,000 --> 00:06:24,000
435
+ So if someone might be affected or is affected, they're going to be considered a stakeholder of the
436
+
437
+ 110
438
+ 00:06:24,000 --> 00:06:25,000
439
+ change.
440
+
441
+ 111
442
+ 00:06:25,000 --> 00:06:29,000
443
+ This includes IT staff, security teams, management and of course end users.
444
+
445
+ 112
446
+ 00:06:29,000 --> 00:06:32,000
447
+ You want to communicate well with them, communicate what the change is.
448
+
449
+ 113
450
+ 00:06:32,000 --> 00:06:33,000
451
+ When are they going to get the change?
452
+
453
+ 114
454
+ 00:06:33,000 --> 00:06:35,000
455
+ Why is the change needed?
456
+
457
+ 115
458
+ 00:06:35,000 --> 00:06:39,000
459
+ So effective communication involves many stakeholders are going to be key for good implementation.
460
+
461
+ 116
462
+ 00:06:40,000 --> 00:06:42,000
463
+ I can't emphasize this part enough.
464
+
465
+ 117
466
+ 00:06:42,000 --> 00:06:44,000
467
+ You must have good impact analysis.
468
+
469
+ 118
470
+ 00:06:45,000 --> 00:06:45,000
471
+ What is that?
472
+
473
+ 119
474
+ 00:06:45,000 --> 00:06:54,000
475
+ Well, don't ever implement the change if you don't know how that change is going to affect systems.
476
+
477
+ 120
478
+ 00:06:54,000 --> 00:07:00,000
479
+ Way too often there's people implement the change not understanding the impact and it brings system
480
+
481
+ 121
482
+ 00:07:00,000 --> 00:07:01,000
483
+ down.
484
+
485
+ 122
486
+ 00:07:02,000 --> 00:07:02,000
487
+ Oh man.
488
+
489
+ 123
490
+ 00:07:02,000 --> 00:07:03,000
491
+ Why is the server offline?
492
+
493
+ 124
494
+ 00:07:03,000 --> 00:07:08,000
495
+ Well Bob put in a change and he didn't realize it would have taken that server off or shut off a particular
496
+
497
+ 125
498
+ 00:07:08,000 --> 00:07:09,000
499
+ service.
500
+
501
+ 126
502
+ 00:07:09,000 --> 00:07:13,000
503
+ So before implementing the change, it's critical to analyze its potential impact on the organization
504
+
505
+ 127
506
+ 00:07:13,000 --> 00:07:14,000
507
+ posture.
508
+
509
+ 128
510
+ 00:07:14,000 --> 00:07:20,000
511
+ This includes evaluating the risk and benefits of the change, how it might affect existing security
512
+
513
+ 129
514
+ 00:07:20,000 --> 00:07:23,000
515
+ controls, and what new risk it might prevent present to you.
516
+
517
+ 130
518
+ 00:07:24,000 --> 00:07:29,000
519
+ Now, understand how it's going to impact and then test your change.
520
+
521
+ 131
522
+ 00:07:29,000 --> 00:07:33,000
523
+ Testing changes in a controlled environment for implementation is critical.
524
+
525
+ 132
526
+ 00:07:33,000 --> 00:07:39,000
527
+ One of the things I always say, and when something breaks in a change, you're going to say, did you
528
+
529
+ 133
530
+ 00:07:39,000 --> 00:07:41,000
531
+ did you test that change?
532
+
533
+ 134
534
+ 00:07:41,000 --> 00:07:44,000
535
+ Did you verify that that was going to do what it says?
536
+
537
+ 135
538
+ 00:07:44,000 --> 00:07:46,000
539
+ Because that could just brought down the whole system.
540
+
541
+ 136
542
+ 00:07:46,000 --> 00:07:49,000
543
+ This helps to identify any unforeseen issues.
544
+
545
+ 137
546
+ 00:07:49,000 --> 00:07:56,000
547
+ And then documenting the test, documenting the test results allows the organization to use them to
548
+
549
+ 138
550
+ 00:07:56,000 --> 00:08:00,000
551
+ refine if there is any security problems and maybe enhance it in the future.
552
+
553
+ 139
554
+ 00:08:01,000 --> 00:08:04,000
555
+ Now you can plan all you want.
556
+
557
+ 140
558
+ 00:08:04,000 --> 00:08:09,000
559
+ You can look at the impact you can implement good, uh, good testing environment.
560
+
561
+ 141
562
+ 00:08:10,000 --> 00:08:11,000
563
+ And then you go and you implement the change.
564
+
565
+ 142
566
+ 00:08:11,000 --> 00:08:14,000
567
+ And before you know it, the old system crashes or the whole place crash.
568
+
569
+ 143
570
+ 00:08:16,000 --> 00:08:17,000
571
+ Well, what are you going to do?
572
+
573
+ 144
574
+ 00:08:17,000 --> 00:08:19,000
575
+ Well, you got to go back to where you are.
576
+
577
+ 145
578
+ 00:08:19,000 --> 00:08:21,000
579
+ This is called a back out plan.
580
+
581
+ 146
582
+ 00:08:21,000 --> 00:08:28,000
583
+ It's a contingency plan that can be active if the changes introduces unacceptable risks or causes unforeseen.
584
+
585
+ 147
586
+ 00:08:28,000 --> 00:08:33,000
587
+ It outlines the steps to revert the system to their state before the changes minimize the impact.
588
+
589
+ 148
590
+ 00:08:33,000 --> 00:08:36,000
591
+ So let's say you send all your users home.
592
+
593
+ 149
594
+ 00:08:36,000 --> 00:08:40,000
595
+ You're going to be rolling out a brand new anti-malware software to all the computers.
596
+
597
+ 150
598
+ 00:08:40,000 --> 00:08:45,000
599
+ You send them all home, you start rolling it out and you realize.
600
+
601
+ 151
602
+ 00:08:46,000 --> 00:08:49,000
603
+ After half the machine's been installed.
604
+
605
+ 152
606
+ 00:08:49,000 --> 00:08:50,000
607
+ It's crashing the machine.
608
+
609
+ 153
610
+ 00:08:50,000 --> 00:08:51,000
611
+ It's not compatible.
612
+
613
+ 154
614
+ 00:08:51,000 --> 00:08:55,000
615
+ You didn't realize some of the Nic cards are not going to function with it.
616
+
617
+ 155
618
+ 00:08:55,000 --> 00:08:58,000
619
+ Some of the operating system don't have the right patches and so on to make this thing work.
620
+
621
+ 156
622
+ 00:08:58,000 --> 00:09:02,000
623
+ And you only got four hours before the users come back in.
624
+
625
+ 157
626
+ 00:09:02,000 --> 00:09:03,000
627
+ But what do you do?
628
+
629
+ 158
630
+ 00:09:03,000 --> 00:09:04,000
631
+ Well, the best thing here.
632
+
633
+ 159
634
+ 00:09:04,000 --> 00:09:09,000
635
+ Do you have a backup plan, a roll back procedure that we can use to revert the system back quickly
636
+
637
+ 160
638
+ 00:09:09,000 --> 00:09:12,000
639
+ to the old one, because we can't have the entire network down.
640
+
641
+ 161
642
+ 00:09:12,000 --> 00:09:18,000
643
+ It's always good to have a good backup plan, also known as a roll back plan maintenance window.
644
+
645
+ 162
646
+ 00:09:18,000 --> 00:09:22,000
647
+ Well, you got to ask yourself, when are you going to be doing these changes?
648
+
649
+ 163
650
+ 00:09:22,000 --> 00:09:25,000
651
+ This is a predetermined period during which changes are implemented.
652
+
653
+ 164
654
+ 00:09:25,000 --> 00:09:27,000
655
+ So we have to have a good maintenance window.
656
+
657
+ 165
658
+ 00:09:27,000 --> 00:09:34,000
659
+ In other words, we want to be doing it in a time where it is not going to be affecting users.
660
+
661
+ 166
662
+ 00:09:34,000 --> 00:09:35,000
663
+ Scheduling changes.
664
+
665
+ 167
666
+ 00:09:35,000 --> 00:09:40,000
667
+ The maintenance windows helps in reducing the impact on users, allows for more controlled and secure
668
+
669
+ 168
670
+ 00:09:40,000 --> 00:09:43,000
671
+ implementation guys if you want.
672
+
673
+ 169
674
+ 00:09:43,000 --> 00:09:47,000
675
+ If you work in it, be prepared to work on weekends.
676
+
677
+ 170
678
+ 00:09:47,000 --> 00:09:49,000
679
+ Late, late nights.
680
+
681
+ 171
682
+ 00:09:49,000 --> 00:09:54,000
683
+ I'm talking two in the morning, uh, because that's when we roll out many of the changes, especially
684
+
685
+ 172
686
+ 00:09:54,000 --> 00:09:59,000
687
+ weekends, Saturday night at 2:00 when all your friends are going to be out at the bar having fun.
688
+
689
+ 173
690
+ 00:09:59,000 --> 00:10:03,000
691
+ You're going to be installing some kind of software on a on a desktop.
692
+
693
+ 174
694
+ 00:10:03,000 --> 00:10:04,000
695
+ That's your maintenance window.
696
+
697
+ 175
698
+ 00:10:04,000 --> 00:10:09,000
699
+ At that time, you have the least amount of users on the network, so the least impact to them.
700
+
701
+ 176
702
+ 00:10:10,000 --> 00:10:17,000
703
+ Now keep in mind what SOPs are standard operating procedures are detailed written instructions to achieve
704
+
705
+ 177
706
+ 00:10:17,000 --> 00:10:20,000
707
+ something uniformly in the performance of a specific function.
708
+
709
+ 178
710
+ 00:10:20,000 --> 00:10:21,000
711
+ So what exactly is this.
712
+
713
+ 179
714
+ 00:10:21,000 --> 00:10:24,000
715
+ So company set up standard operating procedures.
716
+
717
+ 180
718
+ 00:10:24,000 --> 00:10:30,000
719
+ So standard operating procedure are the SOPs are basically here's a series of steps of how to configure
720
+
721
+ 181
722
+ 00:10:30,000 --> 00:10:32,000
723
+ something how to do something.
724
+
725
+ 182
726
+ 00:10:32,000 --> 00:10:33,000
727
+ How to produce.
728
+
729
+ 183
730
+ 00:10:33,000 --> 00:10:35,000
731
+ So you can have an SOP to configure this firewall.
732
+
733
+ 184
734
+ 00:10:35,000 --> 00:10:38,000
735
+ And in it let's say a company has 30 of these things.
736
+
737
+ 185
738
+ 00:10:39,000 --> 00:10:40,000
739
+ You have 30 locations.
740
+
741
+ 186
742
+ 00:10:40,000 --> 00:10:43,000
743
+ You can have an SOP that says, here's how you take this thing out of the box.
744
+
745
+ 187
746
+ 00:10:43,000 --> 00:10:45,000
747
+ Here's how you configure it step by step.
748
+
749
+ 188
750
+ 00:10:45,000 --> 00:10:46,000
751
+ Log into the device.
752
+
753
+ 189
754
+ 00:10:46,000 --> 00:10:47,000
755
+ Go to this tab.
756
+
757
+ 190
758
+ 00:10:47,000 --> 00:10:49,000
759
+ Implement this username configure here.
760
+
761
+ 191
762
+ 00:10:49,000 --> 00:10:50,000
763
+ Add this.
764
+
765
+ 192
766
+ 00:10:50,000 --> 00:10:51,000
767
+ Update this.
768
+
769
+ 193
770
+ 00:10:51,000 --> 00:10:52,000
771
+ Configure this rule.
772
+
773
+ 194
774
+ 00:10:52,000 --> 00:10:52,000
775
+ Remove this rule.
776
+
777
+ 195
778
+ 00:10:52,000 --> 00:10:53,000
779
+ That's an SOP.
780
+
781
+ 196
782
+ 00:10:53,000 --> 00:10:57,000
783
+ Now when you do changes they're going to affect these SOPs.
784
+
785
+ 197
786
+ 00:10:57,000 --> 00:11:03,000
787
+ In change management SOPs is kind of a change manager SOPs ensure that changes are implemented consistently
788
+
789
+ 198
790
+ 00:11:03,000 --> 00:11:05,000
791
+ and securely and eat into the best practices.
792
+
793
+ 199
794
+ 00:11:05,000 --> 00:11:12,000
795
+ Do you have good SOPs for change management or is your changes affecting the SOPs that you already have?
796
+
797
+ 200
798
+ 00:11:12,000 --> 00:11:13,000
799
+ You need both.
800
+
801
+ 201
802
+ 00:11:13,000 --> 00:11:18,000
803
+ So we're going to have good procedures to manage the changes, and you're going to have and you're going
804
+
805
+ 202
806
+ 00:11:18,000 --> 00:11:21,000
807
+ to want to make sure that the changes you implement update existing SOPs.
808
+
809
+ 203
810
+ 00:11:23,000 --> 00:11:26,000
811
+ Change management is critical in every organization.
812
+
813
+ 204
814
+ 00:11:26,000 --> 00:11:30,000
815
+ Every organization that wants to grow and which one doesn't is going to have to go through some kind
816
+
817
+ 205
818
+ 00:11:30,000 --> 00:11:31,000
819
+ of change.
820
+
821
+ 206
822
+ 00:11:31,000 --> 00:11:36,000
823
+ And you want to make sure that you allow these changes in a secure manner.
824
+