1
1

00:00:00,450  -->  00:00:02,370
<v Instructor>SIEM dashboards.</v>
2

2

00:00:02,370  -->  00:00:03,840
Now, in the previous sections,
3

3

00:00:03,840  -->  00:00:06,210
I showed you a couple of different SIEM solutions
4

4

00:00:06,210  -->  00:00:07,950
and the related dashboards.
5

5

00:00:07,950  -->  00:00:10,760
In this section, we're going to dive a little deeper into SIEMs
6

6

00:00:10,760  -->  00:00:13,440
and learn how we can analyze and query logs
7

7

00:00:13,440  -->  00:00:15,210
and SIEM data within them.
8

8

00:00:15,210  -->  00:00:16,560
In this particular lesson,
9

9

00:00:16,560  -->  00:00:18,000
we're going to start with another look
10

10

00:00:18,000  -->  00:00:19,659
at those SIEM dashboards.
11

11

00:00:19,659  -->  00:00:22,710
Now, cybersecurity analysts are usually going to work
12

12

00:00:22,710  -->  00:00:24,600
in a SOC or a CSIRT
13

13

00:00:24,600  -->  00:00:26,637
and they're going to perform a lot of different functions.
14

14

00:00:26,637  -->  00:00:28,620
These functions include things
15

15

00:00:28,620  -->  00:00:30,600
like performing triage on alerts,
16

16

00:00:30,600  -->  00:00:32,760
being able to escalate true positives for instant response
17

17

00:00:32,760  -->  00:00:35,610
and dismissing away the false positives.
18

18

00:00:35,610  -->  00:00:37,619
They're also going to review security data sources
19

19

00:00:37,619  -->  00:00:39,360
and check that log collection
20

20

00:00:39,360  -->  00:00:42,300
and information feeds are functioning as they're supposed to
21

21

00:00:42,300  -->  00:00:44,856
to make sure all that data is getting into the SIEM.
22

22

00:00:44,856  -->  00:00:46,170
Additionally,
23

23

00:00:46,170  -->  00:00:48,570
they're going to review cyber threat intelligence.
24

24

00:00:48,570  -->  00:00:50,940
This way they can identify what the priorities are
25

25

00:00:50,940  -->  00:00:52,500
or the potential impacts
26

26

00:00:52,500  -->  00:00:54,090
from different events that are happening
27

27

00:00:54,090  -->  00:00:57,000
across their network and across their company.
28

28

00:00:57,000  -->  00:00:58,290
Another thing they're going to work on
29

29

00:00:58,290  -->  00:01:00,000
is performing vulnerability scanning
30

30

00:01:00,000  -->  00:01:01,740
and vulnerability management.
31

31

00:01:01,740  -->  00:01:04,260
This way they can understand their vulnerability posture
32

32

00:01:04,260  -->  00:01:06,210
within the organization and what threats
33

33

00:01:06,210  -->  00:01:08,819
outside the organization may try to attack them.
34

34

00:01:08,819  -->  00:01:11,277
Also, they're going to identify opportunities
35

35

00:01:11,277  -->  00:01:12,780
for threat hunting.
36

36

00:01:12,780  -->  00:01:14,130
As they're going through their SIEM,
37

37

00:01:14,130  -->  00:01:15,420
they're going to be able to start seeing
38

38

00:01:15,420  -->  00:01:17,370
different opportunities for threat hunting
39

39

00:01:17,370  -->  00:01:19,230
based on different cyber threat intelligence
40

40

00:01:19,230  -->  00:01:21,480
and overall alerts and incidence status
41

41

00:01:21,480  -->  00:01:23,190
that they're going to be identifying.
42

42

00:01:23,190  -->  00:01:25,530
As they start seeing what alerts are being triggered,
43

43

00:01:25,530  -->  00:01:27,570
they can also see what patterns there are.
44

44

00:01:27,570  -->  00:01:29,256
And based on that, they can find opportunities
45

45

00:01:29,256  -->  00:01:32,259
for going after those patterns by using threat hunting.
46

46

00:01:32,259  -->  00:01:34,290
Now, one of the big things you have to remember
47

47

00:01:34,290  -->  00:01:36,600
with security incidents is that they are identified
48

48

00:01:36,600  -->  00:01:38,100
and interpreted differently
49

49

00:01:38,100  -->  00:01:40,200
based on the overall threat level.
50

50

00:01:40,200  -->  00:01:41,215
Every organization is different
51

51

00:01:41,215  -->  00:01:43,650
and the overall threat level is different
52

52

00:01:43,650  -->  00:01:45,139
based on your organization.
53

53

00:01:45,139  -->  00:01:48,030
For example, if you work in the Department of Defense
54

54

00:01:48,030  -->  00:01:49,294
and you work for the US military,
55

55

00:01:49,294  -->  00:01:51,176
you might have top secret information.
56

56

00:01:51,176  -->  00:01:52,856
That is a much bigger area
57

57

00:01:52,856  -->  00:01:55,277
that has a bigger threat base going towards it
58

58

00:01:55,277  -->  00:01:57,207
than say, my small company.
59

59

00:01:57,207  -->  00:01:58,920
Now, alternatively,
60

60

00:01:58,920  -->  00:02:00,960
my small company may have some other threats
61

61

00:02:00,960  -->  00:02:02,040
that we are vulnerable to
62

62

00:02:02,040  -->  00:02:03,690
that they're not vulnerable to,
63

63

00:02:03,690  -->  00:02:05,550
and so depending on these type of things
64

64

00:02:05,550  -->  00:02:07,950
are going to change your overall threat level,
65

65

00:02:07,950  -->  00:02:09,510
and that is going to have to be identified
66

66

00:02:09,510  -->  00:02:11,720
and interpreted based on the events you're seeing
67

67

00:02:11,720  -->  00:02:14,014
and the threats to your organization.
68

68

00:02:14,014  -->  00:02:16,140
Now, another great example of this
69

69

00:02:16,140  -->  00:02:17,880
is the open SSL vulnerability
70

70

00:02:17,880  -->  00:02:19,320
that happened a couple years ago.
71

71

00:02:19,320  -->  00:02:21,330
This was known as Heartbleed.
72

72

00:02:21,330  -->  00:02:23,100
Now, this was a zero day vulnerability
73

73

00:02:23,100  -->  00:02:27,000
that affected everybody's websites if they used open SSL
74

74

00:02:27,000  -->  00:02:28,560
to do their encryption.
75

75

00:02:28,560  -->  00:02:30,036
Now, if you're an e-commerce site,
76

76

00:02:30,036  -->  00:02:32,220
you're going to have a really high threat level with that
77

77

00:02:32,220  -->  00:02:35,070
because that means your e-commerce is vulnerable.
78

78

00:02:35,070  -->  00:02:37,294
If you were just running a site for your personal amusement,
79

79

00:02:37,294  -->  00:02:39,930
well, you might not have been as worried about it
80

80

00:02:39,930  -->  00:02:41,939
because you weren't transmitting information back and forth
81

81

00:02:41,939  -->  00:02:44,700
to the server over an SSL connection.
82

82

00:02:44,700  -->  00:02:47,400
And so based on whether or not you are vulnerable to this,
83

83

00:02:47,400  -->  00:02:50,254
whether or not you had a business case that relied on SSL,
84

84

00:02:50,254  -->  00:02:52,860
all these things are going to go into your analysis
85

85

00:02:52,860  -->  00:02:54,780
and to determine how you're going to interpret
86

86

00:02:54,780  -->  00:02:57,870
that security incident and what you should do about it.
87

87

00:02:57,870  -->  00:02:59,400
Now, the reason we're talking about all of this
88

88

00:02:59,400  -->  00:03:01,140
is because when you build out your dashboard,
89

89

00:03:01,140  -->  00:03:02,899
you're going to build it to present information.
90

90

00:03:02,899  -->  00:03:04,920
When we talk about a SIEM dashboard,
91

91

00:03:04,920  -->  00:03:06,955
this is a console that presents selected information
92

92

00:03:06,955  -->  00:03:11,280
in an easily digestible format, such as using visualization.
93

93

00:03:11,280  -->  00:03:12,680
Now, when we talk about visualization,
94

94

00:03:12,680  -->  00:03:14,400
this is where you can take a widget
95

95

00:03:14,400  -->  00:03:15,750
and it can show you different records
96

96

00:03:15,750  -->  00:03:17,700
or metrics in a visual format,
97

97

00:03:17,700  -->  00:03:19,379
such as a graph or a table.
98

98

00:03:19,379  -->  00:03:21,416
For example, on your dashboard,
99

99

00:03:21,416  -->  00:03:25,320
you can have all sorts of different kinds of visualizations.
100

100

00:03:25,320  -->  00:03:27,896
Here's an example from an elastic stack dashboard.
101

101

00:03:27,896  -->  00:03:30,280
Now here you can see it's running on top of security onion
102

102

00:03:30,280  -->  00:03:32,199
and we have all sorts of different data
103

103

00:03:32,199  -->  00:03:34,814
that is relevant to this particular use case.
104

104

00:03:34,814  -->  00:03:36,150
Now, inside here,
105

105

00:03:36,150  -->  00:03:38,397
we can see on the bottom right we have a pie chart.
106

106

00:03:38,397  -->  00:03:40,920
Inside that pie chart, we can see the relative balance
107

107

00:03:40,920  -->  00:03:42,330
of the different classifications,
108

108

00:03:42,330  -->  00:03:44,220
without seeing the overall level.
109

109

00:03:44,220  -->  00:03:46,500
So for example, I see there's a lot of red there.
110

110

00:03:46,500  -->  00:03:48,339
In fact, it's over 75% red,
111

111

00:03:48,339  -->  00:03:49,830
and as I look up to the legend,
112

112

00:03:49,830  -->  00:03:52,200
I see that is a classification of 2.
113

113

00:03:52,200  -->  00:03:54,750
And so that tells me that this is a 2 severity level
114

114

00:03:54,750  -->  00:03:57,390
and that's where we're seeing most of our activity.
115

115

00:03:57,390  -->  00:03:59,640
Next, we also have things like line graphs
116

116

00:03:59,640  -->  00:04:01,470
and line graphs are going to show the level
117

117

00:04:01,470  -->  00:04:02,776
over a given time period.
118

118

00:04:02,776  -->  00:04:04,920
So here on the top, you can see the counts,
119

119

00:04:04,920  -->  00:04:06,930
the number of log counts over time
120

120

00:04:06,930  -->  00:04:08,360
as we went throughout the day.
121

121

00:04:08,360  -->  00:04:11,130
Now, pie charts and line graphs aren't the only ways
122

122

00:04:11,130  -->  00:04:12,510
that we can display information.
123

123

00:04:12,510  -->  00:04:14,499
For instance, if I go over to my Splunk dashboard
124

124

00:04:14,499  -->  00:04:16,717
I can see many different formats.
125

125

00:04:16,717  -->  00:04:19,080
Here, for example, I have a bar graph
126

126

00:04:19,080  -->  00:04:20,520
and this is going to compare the levels
127

127

00:04:20,520  -->  00:04:22,410
between different classifications.
128

128

00:04:22,410  -->  00:04:25,110
You can see here the critical, the high, the medium
129

129

00:04:25,110  -->  00:04:28,380
and the low urgency, and the number of counts going across.
130

130

00:04:28,380  -->  00:04:31,290
This shows me that my medium emergency is the most common
131

131

00:04:31,290  -->  00:04:32,820
that I'm using.
132

132

00:04:32,820  -->  00:04:35,130
In addition to that, I might have gauges.
133

133

00:04:35,130  -->  00:04:37,440
Now, these gauges can be done in lots of different ways.
134

134

00:04:37,440  -->  00:04:39,214
I've seen a lot of them that look like speedometers,
135

135

00:04:39,214  -->  00:04:40,650
or in the case of Splunk,
136

136

00:04:40,650  -->  00:04:42,240
they like to use these trending graphs
137

137

00:04:42,240  -->  00:04:45,150
with the up and down arrows and a big number there.
138

138

00:04:45,150  -->  00:04:46,470
These gauges show you the level
139

139

00:04:46,470  -->  00:04:48,330
that has defined limits with it.
140

140

00:04:48,330  -->  00:04:50,190
So in this case, we have a different thing
141

141

00:04:50,190  -->  00:04:53,730
like access notables, endpoint notables, network notables
142

142

00:04:53,730  -->  00:04:57,240
identity notables, audit notables, threat notables
143

143

00:04:57,240  -->  00:04:58,830
and EUBA notables.
144

144

00:04:58,830  -->  00:05:00,717
And all these have a number associated with it
145

145

00:05:00,717  -->  00:05:02,340
and a trend over time
146

146

00:05:02,340  -->  00:05:04,680
that can be very quickly looked at and observed.
147

147

00:05:04,680  -->  00:05:07,320
The final thing you'll see on a lot of dashboards is tables
148

148

00:05:07,320  -->  00:05:10,770
and tables are going to give you a lot more information.
149

149

00:05:10,770  -->  00:05:12,810
A lot of times these will be the top events
150

150

00:05:12,810  -->  00:05:14,070
or the bottom events.
151

151

00:05:14,070  -->  00:05:16,410
In this case, you can see these are the top 10 events
152

152

00:05:16,410  -->  00:05:19,410
that are being displayed across our entire Splunk system
153

153

00:05:19,410  -->  00:05:21,016
which is acting as our SIEM.
154

154

00:05:21,016  -->  00:05:23,970
Now, all these dashboards have something in common.
155

155

00:05:23,970  -->  00:05:25,500
They display metrics,
156

156

00:05:25,500  -->  00:05:27,750
and it's important for you to select the right metrics
157

157

00:05:27,750  -->  00:05:28,890
for your dashboard.
158

158

00:05:28,890  -->  00:05:30,150
This is critical
159

159

00:05:30,150  -->  00:05:31,619
because if you're selecting the wrong information
160

160

00:05:31,619  -->  00:05:33,757
you're not really presenting what you want
161

161

00:05:33,757  -->  00:05:35,880
and it's not going to be useful to your analyst
162

162

00:05:35,880  -->  00:05:38,970
or to your manager or whoever's looking at this dashboard.
163

163

00:05:38,970  -->  00:05:39,960
Now, speaking of that,
164

164

00:05:39,960  -->  00:05:42,510
one of the big things we have to think about is metrics
165

165

00:05:42,510  -->  00:05:45,360
and metrics are also known as key performance indicators
166

166

00:05:45,360  -->  00:05:46,950
or KPIs.
167

167

00:05:46,950  -->  00:05:48,570
Now, this is a quantifiable measure
168

168

00:05:48,570  -->  00:05:50,856
that's used to evaluate the success of an organization,
169

169

00:05:50,856  -->  00:05:52,740
an employee or other element
170

170

00:05:52,740  -->  00:05:54,780
in meeting objectives for performance.
171

171

00:05:54,780  -->  00:05:56,670
Now, this is a generic business definition,
172

172

00:05:56,670  -->  00:05:57,810
but when we we start looking at it
173

173

00:05:57,810  -->  00:06:00,780
in terms of our systems, we have KPIs too.
174

174

00:06:00,780  -->  00:06:02,739
For instance, we have key performance indicators
175

175

00:06:02,739  -->  00:06:05,430
for the processor utilization on your server.
176

176

00:06:05,430  -->  00:06:07,620
We have it based on the disk space that's being used.
177

177

00:06:07,620  -->  00:06:09,660
We may have it on the bandwidth that's being used.
178

178

00:06:09,660  -->  00:06:11,190
There are lots of different measures
179

179

00:06:11,190  -->  00:06:12,420
and metrics that we can create
180

180

00:06:12,420  -->  00:06:14,250
for all these different numbers.
181

181

00:06:14,250  -->  00:06:15,619
Now, we're not going to go into a ton of detail
182

182

00:06:15,619  -->  00:06:17,640
in the terms of metrics here,
183

183

00:06:17,640  -->  00:06:18,720
because as an analyst,
184

184

00:06:18,720  -->  00:06:21,360
it's not our job to define those metrics.
185

185

00:06:21,360  -->  00:06:23,214
Instead, that's the cybersecurity engineers
186

186

00:06:23,214  -->  00:06:25,400
and the cybersecurity architect's job,
187

187

00:06:25,400  -->  00:06:27,080
to figure out what we should be measuring.
188

188

00:06:27,080  -->  00:06:29,940
That is something that is done at the management level,
189

189

00:06:29,940  -->  00:06:31,720
the executive level and at that engineering
190

190

00:06:31,720  -->  00:06:33,750
and architecture level.
191

191

00:06:33,750  -->  00:06:35,070
Our job as an analyst is to be able
192

192

00:06:35,070  -->  00:06:38,120
to understand these numbers and use them in the real world.
193

193

00:06:38,120  -->  00:06:41,310
Now, if you're interested to go beyond the CYSA plus exam
194

194

00:06:41,310  -->  00:06:42,920
and learn more about measures and metrics,
195

195

00:06:42,920  -->  00:06:46,560
I have a course dedicated just to measures and metrics
196

196

00:06:46,560  -->  00:06:48,090
which is for my service management students
197

197

00:06:48,090  -->  00:06:51,270
because it plays such a big important key in their world.
198

198

00:06:51,270  -->  00:06:52,500
But for the rest of this lesson,
199

199

00:06:52,500  -->  00:06:54,480
we are going to talk about measures and metrics,
200

200

00:06:54,480  -->  00:06:55,890
and it is important for you to understand
201

201

00:06:55,890  -->  00:06:57,450
the basics of them.
202

202

00:06:57,450  -->  00:06:59,250
Now, when we talk about measures and metrics
203

203

00:06:59,250  -->  00:07:01,080
what kind of things should we be measuring?
204

204

00:07:01,080  -->  00:07:04,276
Well, we might want to measure the number of vulnerabilities.
205

205

00:07:04,276  -->  00:07:06,510
By measuring the number of vulnerabilities,
206

206

00:07:06,510  -->  00:07:08,796
we might know what type of service was being affected
207

207

00:07:08,796  -->  00:07:10,680
and when these things were discovered
208

208

00:07:10,680  -->  00:07:12,330
and remediated over time.
209

209

00:07:12,330  -->  00:07:14,160
We also might want to be able to capture the number
210

210

00:07:14,160  -->  00:07:15,270
of failed log ons
211

211

00:07:15,270  -->  00:07:16,770
because if we have failed log ons
212

212

00:07:16,770  -->  00:07:18,136
or unauthorized access attempts,
213

213

00:07:18,136  -->  00:07:19,410
that could be an indicator
214

214

00:07:19,410  -->  00:07:21,090
of somebody trying to break into our network
215

215

00:07:21,090  -->  00:07:22,890
by trying to do password guessing,
216

216

00:07:22,890  -->  00:07:25,470
brute force attack or something like that.
217

217

00:07:25,470  -->  00:07:26,910
We also might want to capture the number
218

218

00:07:26,910  -->  00:07:28,050
of vulnerable systems.
219

219

00:07:28,050  -->  00:07:29,610
When you do your vulnerability assessments
220

220

00:07:29,610  -->  00:07:31,830
across your network and you scan a host
221

221

00:07:31,830  -->  00:07:33,660
and you figure out that it is missing a bunch
222

222

00:07:33,660  -->  00:07:36,360
of critical patches, what do you do with that information?
223

223

00:07:36,360  -->  00:07:38,250
Well, if you know the number of vulnerable systems,
224

224

00:07:38,250  -->  00:07:39,510
we can remediate those
225

225

00:07:39,510  -->  00:07:41,460
and figure out which systems are in compliance
226

226

00:07:41,460  -->  00:07:43,500
and which ones are out of compliance.
227

227

00:07:43,500  -->  00:07:45,120
Then we might want to also capture the number
228

228

00:07:45,120  -->  00:07:46,500
of security incidents.
229

229

00:07:46,500  -->  00:07:48,030
How many incidents do we have?
230

230

00:07:48,030  -->  00:07:50,100
How many are reported in a given period of time,
231

231

00:07:50,100  -->  00:07:53,070
maybe in the last week, the last month, or the last year?
232

232

00:07:53,070  -->  00:07:55,500
Are we on an upward trend or a downward trend?
233

233

00:07:55,500  -->  00:07:57,420
Are things getting better or are they getting worse?
234

234

00:07:57,420  -->  00:07:58,800
If you don't capture these numbers,
235

235

00:07:58,800  -->  00:08:00,157
you'll never be able to know.
236

236

00:08:00,157  -->  00:08:03,030
Then we'll also want to think about the average response time.
237

237

00:08:03,030  -->  00:08:04,335
When we identify a security incident,
238

238

00:08:04,335  -->  00:08:07,080
how long does it take for us to fix that problem?
239

239

00:08:07,080  -->  00:08:09,840
How long does it take for us to re-image that machine?
240

240

00:08:09,840  -->  00:08:12,030
How long does it take for us to get that employee back
241

241

00:08:12,030  -->  00:08:14,790
to working order and back to a known good state?
242

242

00:08:14,790  -->  00:08:16,317
These are all things we want to capture.
243

243

00:08:16,317  -->  00:08:18,750
We also might want to capture the average time
244

244

00:08:18,750  -->  00:08:20,040
to resolve a ticket.
245

245

00:08:20,040  -->  00:08:22,254
Now, this might sound more like a service management issue
246

246

00:08:22,254  -->  00:08:25,356
but it does affect the cybersecurity world too
247

247

00:08:25,356  -->  00:08:27,270
because if we have a help desk ticket
248

248

00:08:27,270  -->  00:08:28,740
and it's not being resolved,
249

249

00:08:28,740  -->  00:08:31,500
a lot of times our users are going to find a workaround
250

250

00:08:31,500  -->  00:08:32,734
to get their job done.
251

251

00:08:32,734  -->  00:08:35,400
For instance, in one organization I was in,
252

252

00:08:35,400  -->  00:08:37,560
we had a closed network and an open network.
253

253

00:08:37,560  -->  00:08:39,930
The open network connected to the internet.
254

254

00:08:39,930  -->  00:08:41,460
The closed network did not.
255

255

00:08:41,460  -->  00:08:43,560
And if we wanted to get information from the open network
256

256

00:08:43,560  -->  00:08:45,030
to the closed network,
257

257

00:08:45,030  -->  00:08:47,160
we had to put in a ticket with the help desk.
258

258

00:08:47,160  -->  00:08:49,080
Then a technician would take that information,
259

259

00:08:49,080  -->  00:08:51,539
burn it to a cd, move it over to the closed network
260

260

00:08:51,539  -->  00:08:53,139
and then allow us to use it.
261

261

00:08:53,139  -->  00:08:55,590
Now, if they weren't going to do do that for us,
262

262

00:08:55,590  -->  00:08:57,060
and it took them three weeks to do that,
263

263

00:08:57,060  -->  00:08:59,036
and I have a presentation to make in three hours,
264

264

00:08:59,036  -->  00:09:00,720
that can become a problem.
265

265

00:09:00,720  -->  00:09:02,370
And so your average time to resolve tickets
266

266

00:09:02,370  -->  00:09:04,957
does affect your security, so keep that in mind.
267

267

00:09:04,957  -->  00:09:06,600
Another metric we might look at
268

268

00:09:06,600  -->  00:09:08,400
is the number of outstanding issues.
269

269

00:09:08,400  -->  00:09:09,990
How many things are sitting in queue
270

270

00:09:09,990  -->  00:09:11,130
that haven't been done yet?
271

271

00:09:11,130  -->  00:09:13,197
Again, people will find a way to get the work done.
272

272

00:09:13,197  -->  00:09:15,180
So if you have an access request
273

273

00:09:15,180  -->  00:09:17,454
or you have a port open request or something like that
274

274

00:09:17,454  -->  00:09:20,280
and it sits in queue for 6 months or 12 months,
275

275

00:09:20,280  -->  00:09:22,200
people will find a way to get their job done
276

276

00:09:22,200  -->  00:09:24,180
and that may break your security.
277

277

00:09:24,180  -->  00:09:25,530
Another thing we might look at is the number
278

278

00:09:25,530  -->  00:09:27,360
of employees who are trained.
279

279

00:09:27,360  -->  00:09:28,193
For instance,
280

280

00:09:28,193  -->  00:09:30,630
does your organization do annual security training?
281

281

00:09:30,630  -->  00:09:31,770
Do they learn about threats?
282

282

00:09:31,770  -->  00:09:32,970
Do they learn about vulnerabilities?
283

283

00:09:32,970  -->  00:09:35,670
Do they learn about how to have long, strong passwords?
284

284

00:09:35,670  -->  00:09:37,500
Do they learn about two-factor authentication?
285

285

00:09:37,500  -->  00:09:40,170
Do they learn about phishing attacks and what to look for?
286

286

00:09:40,170  -->  00:09:41,370
All of these things are things
287

287

00:09:41,370  -->  00:09:42,390
that can be part of your training,
288

288

00:09:42,390  -->  00:09:44,460
and if you know the number of employees who are trained,
289

289

00:09:44,460  -->  00:09:46,200
you know you have a better security posture,
290

290

00:09:46,200  -->  00:09:48,330
so tracking that might be useful as well.
291

291

00:09:48,330  -->  00:09:50,296
And finally, we might also want to capture the percentage
292

292

00:09:50,296  -->  00:09:51,896
of testing completed.
293

293

00:09:51,896  -->  00:09:53,790
When you build a new application,
294

294

00:09:53,790  -->  00:09:55,320
does it get put online immediately
295

295

00:09:55,320  -->  00:09:56,760
or does it go through testing first?
296

296

00:09:56,760  -->  00:09:59,010
Well, if it should go through testing first,
297

297

00:09:59,010  -->  00:09:59,843
and if it does,
298

298

00:09:59,843  -->  00:10:01,860
you should be tracking that as it's going through.
299

299

00:10:01,860  -->  00:10:03,480
This way, you know how many applications you have,
300

300

00:10:03,480  -->  00:10:06,330
how may have been tested, and how may have been released.
301

301

00:10:06,330  -->  00:10:07,680
All of these are just some metrics
302

302

00:10:07,680  -->  00:10:10,110
that you can think about and there can be a lot more.
303

303

00:10:10,110  -->  00:10:11,970
This is not an exhaustive list.
304

304

00:10:11,970  -->  00:10:13,320
This is just something to get you started
305

305

00:10:13,320  -->  00:10:14,610
in thinking about it.
306

306

00:10:14,610  -->  00:10:15,780
Now, one of the important things
307

307

00:10:15,780  -->  00:10:17,610
is when you're configuring your dashboard,
308

308

00:10:17,610  -->  00:10:19,299
you need to display the needed information
309

309

00:10:19,299  -->  00:10:20,877
based on that user's role.
310

310

00:10:20,877  -->  00:10:23,550
For example, if I'm an analyst,
311

311

00:10:23,550  -->  00:10:26,120
do I care as much about the number of employees trained?
312

312

00:10:26,120  -->  00:10:27,178
Probably not.
313

313

00:10:27,178  -->  00:10:28,920
But if I'm the manager who's in charge
314

314

00:10:28,920  -->  00:10:30,570
of training the entire staff
315

315

00:10:30,570  -->  00:10:33,037
to minimize our vulnerabilities, I probably do care.
316

316

00:10:33,037  -->  00:10:35,319
And so the great thing is with a lot of these dashboards,
317

317

00:10:35,319  -->  00:10:38,516
they use widgets to pull that information in from the SIEM.
318

318

00:10:38,516  -->  00:10:41,640
Now, by doing that, you can put in different dashboards
319

319

00:10:41,640  -->  00:10:43,200
and create different dashboards
320

320

00:10:43,200  -->  00:10:45,000
based on the employee who's looking at it.
321

321

00:10:45,000  -->  00:10:47,557
In my company, we have several different dashboards
322

322

00:10:47,557  -->  00:10:49,699
and based on your position in the company,
323

323

00:10:49,699  -->  00:10:53,357
you have access to some, all or none of those
324

324

00:10:53,357  -->  00:10:55,230
depending on what you need.
325

325

00:10:55,230  -->  00:10:57,120
For instance, I own the company,
326

326

00:10:57,120  -->  00:10:59,101
and I have access to every single dashboard.
327

327

00:10:59,101  -->  00:11:00,750
That doesn't mean I look at every one
328

328

00:11:00,750  -->  00:11:01,980
on a daily basis though.
329

329

00:11:01,980  -->  00:11:02,813
For instance,
330

330

00:11:02,813  -->  00:11:05,100
I don't look at the dashboard for our ITSM system
331

331

00:11:05,100  -->  00:11:06,870
which is where we get all of our support tickets
332

332

00:11:06,870  -->  00:11:07,890
in from our students
333

333

00:11:07,890  -->  00:11:09,476
and seeing what the resolution times are.
334

334

00:11:09,476  -->  00:11:11,160
I look at that once a week
335

335

00:11:11,160  -->  00:11:13,258
to make sure my customer service manager is doing her job
336

336

00:11:13,258  -->  00:11:15,080
but I don't look at it every single day,
337

337

00:11:15,080  -->  00:11:17,040
because I have somebody who does that.
338

338

00:11:17,040  -->  00:11:18,240
That's her role.
339

339

00:11:18,240  -->  00:11:19,073
Now, on the other hand,
340

340

00:11:19,073  -->  00:11:20,970
I do look at our security dashboard every day
341

341

00:11:20,970  -->  00:11:23,370
with my tech team because I'm a technical guy
342

342

00:11:23,370  -->  00:11:25,830
and I care about that information, and so does my tech team
343

343

00:11:25,830  -->  00:11:27,630
and I actually lead up my tech team.
344

344

00:11:27,630  -->  00:11:29,181
So in my role as the tech team lead,
345

345

00:11:29,181  -->  00:11:31,560
I'm going to be looking at that information.
346

346

00:11:31,560  -->  00:11:33,420
So you want to make sure you're building your dashboards
347

347

00:11:33,420  -->  00:11:34,830
based on the user's role
348

348

00:11:34,830  -->  00:11:37,260
and only bringing the information that they need to see.
349

349

00:11:37,260  -->  00:11:39,150
Otherwise, it's useless information
350

350

00:11:39,150  -->  00:11:41,050
and it's just distracting to the user.
