1
1

00:00:00,360  -->  00:00:02,160
<v Instructor>Training and testing.</v>
2

2

00:00:03,030  -->  00:00:05,670
The last thing we have to focus on in our preparation
3

3

00:00:05,670  -->  00:00:07,440
is training and testing.
4

4

00:00:07,440  -->  00:00:09,960
And there is a difference between those two things.
5

5

00:00:09,960  -->  00:00:12,030
First, let's talk about training.
6

6

00:00:12,030  -->  00:00:14,520
Training is education to ensure employees
7

7

00:00:14,520  -->  00:00:17,340
and staff understand your processes, procedures
8

8

00:00:17,340  -->  00:00:20,130
and priorities during an incident response.
9

9

00:00:20,130  -->  00:00:21,450
By conducting training,
10

10

00:00:21,450  -->  00:00:23,940
you're going to make sure that your people are ready to respond
11

11

00:00:23,940  -->  00:00:25,800
when something bad happens.
12

12

00:00:25,800  -->  00:00:27,810
Training should be provided to all employees
13

13

00:00:27,810  -->  00:00:31,650
with a relevant perspective and focus based on their needs
14

14

00:00:31,650  -->  00:00:34,710
because not everyone is going to get the same training.
15

15

00:00:34,710  -->  00:00:36,960
For example, if you're a responder,
16

16

00:00:36,960  -->  00:00:39,120
you need training in a technical capacity.
17

17

00:00:39,120  -->  00:00:40,950
What are the procedures you're going to follow?
18

18

00:00:40,950  -->  00:00:42,630
How do you re-image a machine?
19

19

00:00:42,630  -->  00:00:44,010
How do you remove malware?
20

20

00:00:44,010  -->  00:00:46,080
How do you change configuration settings?
21

21

00:00:46,080  -->  00:00:49,170
All of that stuff is part of your responding training.
22

22

00:00:49,170  -->  00:00:51,000
Now, if you're a manager or an executive,
23

23

00:00:51,000  -->  00:00:52,770
you're going to have different training requirements.
24

24

00:00:52,770  -->  00:00:55,470
You're going to be focused more on risk versus reward.
25

25

00:00:55,470  -->  00:00:57,900
You're going to be focused more on managerial decision making
26

26

00:00:57,900  -->  00:01:00,390
and communication across the organization
27

27

00:01:00,390  -->  00:01:02,280
and outside the organization
28

28

00:01:02,280  -->  00:01:04,860
with law enforcement and the media as well.
29

29

00:01:04,860  -->  00:01:06,630
And finally, we have our end users.
30

30

00:01:06,630  -->  00:01:08,850
And our end users need to be trained as well.
31

31

00:01:08,850  -->  00:01:10,650
They need to be trained on the way to report
32

32

00:01:10,650  -->  00:01:12,900
if they suspect an incident is occurring.
33

33

00:01:12,900  -->  00:01:14,280
For instance, as an end user,
34

34

00:01:14,280  -->  00:01:17,220
if I open up my email and I see a phishing campaign,
35

35

00:01:17,220  -->  00:01:19,530
how do I report that to the service desk?
36

36

00:01:19,530  -->  00:01:21,510
If I went and clicked on one of those links,
37

37

00:01:21,510  -->  00:01:23,430
I'm going to need remedial training to know
38

38

00:01:23,430  -->  00:01:25,050
how to identify that in the future
39

39

00:01:25,050  -->  00:01:27,330
and make sure I don't fall for that again.
40

40

00:01:27,330  -->  00:01:29,310
This is the idea of your end user training.
41

41

00:01:29,310  -->  00:01:31,740
They need training on how to be a better user
42

42

00:01:31,740  -->  00:01:32,790
and how to prevent incidents
43

43

00:01:32,790  -->  00:01:34,710
from occurring in the first place.
44

44

00:01:34,710  -->  00:01:36,420
Now, when you're providing training,
45

45

00:01:36,420  -->  00:01:38,490
one of the things you want to make sure you're capturing
46

46

00:01:38,490  -->  00:01:40,770
is lessons learned from previous incidents,
47

47

00:01:40,770  -->  00:01:43,020
and you want to bring those back up during training.
48

48

00:01:43,020  -->  00:01:44,970
Because when you have a lessons learned
49

49

00:01:44,970  -->  00:01:47,070
that means it's something that went wrong in the past.
50

50

00:01:47,070  -->  00:01:48,480
And how we can do it better in the future
51

51

00:01:48,480  -->  00:01:51,480
is by training people on those lessons learned.
52

52

00:01:51,480  -->  00:01:53,190
If we just write down those lessons learned
53

53

00:01:53,190  -->  00:01:55,620
and nobody reads it again and nobody gets training on it,
54

54

00:01:55,620  -->  00:01:57,510
then we're going to be doomed to repeat those things.
55

55

00:01:57,510  -->  00:01:59,580
And so we want to make sure we're preventing that.
56

56

00:01:59,580  -->  00:02:01,290
Remember, when you're doing training,
57

57

00:02:01,290  -->  00:02:03,480
it's not just about technical skill here.
58

58

00:02:03,480  -->  00:02:05,310
You also need to include soft skills
59

59

00:02:05,310  -->  00:02:07,680
and relationship building within your teams,
60

60

00:02:07,680  -->  00:02:09,150
because that is important as well
61

61

00:02:09,150  -->  00:02:11,730
if you want a high functioning CSIRT.
62

62

00:02:11,730  -->  00:02:13,710
Next, let's talk about testing.
63

63

00:02:13,710  -->  00:02:15,750
Now, testing is the practical exercising
64

64

00:02:15,750  -->  00:02:17,790
of incident response procedures.
65

65

00:02:17,790  -->  00:02:20,430
With training, we're going to teach you what to do,
66

66

00:02:20,430  -->  00:02:23,400
in testing, we're going to make sure you know how to do it.
67

67

00:02:23,400  -->  00:02:24,570
Now, when we're dealing with testing,
68

68

00:02:24,570  -->  00:02:25,860
we'll often conduct a test
69

69

00:02:25,860  -->  00:02:27,990
to simulate a significant incident.
70

70

00:02:27,990  -->  00:02:30,630
Now, the challenge with this is doing this is very costly
71

71

00:02:30,630  -->  00:02:32,760
and it can be a complex event.
72

72

00:02:32,760  -->  00:02:34,140
For example, I've been involved
73

73

00:02:34,140  -->  00:02:36,330
with a lot of testing over the years.
74

74

00:02:36,330  -->  00:02:39,060
One such test was a full scale exercise
75

75

00:02:39,060  -->  00:02:40,800
that showed exactly what we would do
76

76

00:02:40,800  -->  00:02:43,830
in the event that we had a large scale data breach.
77

77

00:02:43,830  -->  00:02:47,070
Now, this went across multiple sites around the world
78

78

00:02:47,070  -->  00:02:50,310
and it cost us hundreds of thousands of dollars to do,
79

79

00:02:50,310  -->  00:02:52,770
but it made sure everyone knew what they were doing
80

80

00:02:52,770  -->  00:02:55,050
and that we could actually go through those actions
81

81

00:02:55,050  -->  00:02:57,540
and get a bad guy out of our systems.
82

82

00:02:57,540  -->  00:02:59,100
Now, when you're designing your test,
83

83

00:02:59,100  -->  00:03:01,530
you can do it in one of two major ways.
84

84

00:03:01,530  -->  00:03:02,940
The first is a tabletop
85

85

00:03:02,940  -->  00:03:05,160
and the second is a penetration test.
86

86

00:03:05,160  -->  00:03:06,900
Let's talk about both of these.
87

87

00:03:06,900  -->  00:03:09,960
When we're dealing with a tabletop exercise or a TTX,
88

88

00:03:09,960  -->  00:03:12,810
this is an exercise that uses an instant response scenario
89

89

00:03:12,810  -->  00:03:15,900
against a framework of controls or a red team.
90

90

00:03:15,900  -->  00:03:17,880
Now, the reason we call it a tabletop exercise
91

91

00:03:17,880  -->  00:03:20,070
is because we're doing it on a tabletop
92

92

00:03:20,070  -->  00:03:22,560
and we're not physically doing it in our networks.
93

93

00:03:22,560  -->  00:03:25,650
In a tabletop, we might gather experts around the table
94

94

00:03:25,650  -->  00:03:27,330
and we'll start presenting scenarios.
95

95

00:03:27,330  -->  00:03:30,060
For instance, if I was leading the tabletop, we could say,
96

96

00:03:30,060  -->  00:03:32,220
you have an indication of a data breach.
97

97

00:03:32,220  -->  00:03:34,470
It's occurring on this database server.
98

98

00:03:34,470  -->  00:03:35,310
What do you do?
99

99

00:03:35,310  -->  00:03:36,720
And then the defenders would start saying
100

100

00:03:36,720  -->  00:03:39,000
what they're going to do, and they would each take turns,
101

101

00:03:39,000  -->  00:03:40,530
almost like they're role-playing,
102

102

00:03:40,530  -->  00:03:43,320
what they would do in the case of this particular scenario
103

103

00:03:43,320  -->  00:03:45,300
as they work through that event.
104

104

00:03:45,300  -->  00:03:47,070
Now, the benefit of doing a tabletop is
105

105

00:03:47,070  -->  00:03:50,130
it's a lot less expensive than a full-blown exercise,
106

106

00:03:50,130  -->  00:03:52,710
but there are some negatives to it in the fact
107

107

00:03:52,710  -->  00:03:54,780
that you can't get this hands-on experience
108

108

00:03:54,780  -->  00:03:57,000
because you're not physically doing the things
109

109

00:03:57,000  -->  00:04:00,360
on the keyboard and making actions happen on the network.
110

110

00:04:00,360  -->  00:04:03,390
So it's really more of a theoretical exercise here.
111

111

00:04:03,390  -->  00:04:04,740
Now, another way you can do this
112

112

00:04:04,740  -->  00:04:07,830
is you can break people up into red teams and blue teams.
113

113

00:04:07,830  -->  00:04:09,630
Now the red teams are the attackers
114

114

00:04:09,630  -->  00:04:11,550
and the blue teams are the defenders.
115

115

00:04:11,550  -->  00:04:13,020
And so you can actually take turns saying,
116

116

00:04:13,020  -->  00:04:14,640
okay, here's a scenario,
117

117

00:04:14,640  -->  00:04:16,920
blue team this is what you detect, what do you do?
118

118

00:04:16,920  -->  00:04:18,330
And then based on what they say
119

119

00:04:18,330  -->  00:04:19,290
the red team then says,
120

120

00:04:19,290  -->  00:04:21,570
okay, we would then do X, Y, and Z.
121

121

00:04:21,570  -->  00:04:22,590
And then the blue team would say,
122

122

00:04:22,590  -->  00:04:26,100
well, then we would see this and respond in A, B, and C.
123

123

00:04:26,100  -->  00:04:27,210
And they'll go back and forth
124

124

00:04:27,210  -->  00:04:30,600
through several rounds to hit and attack and defend
125

125

00:04:30,600  -->  00:04:34,050
and go back and forth until we can see what the effects are.
126

126

00:04:34,050  -->  00:04:35,820
The benefits of doing it as a red team
127

127

00:04:35,820  -->  00:04:37,650
versus blue team type scenario
128

128

00:04:37,650  -->  00:04:39,900
is that you're going to get live people thinking
129

129

00:04:39,900  -->  00:04:41,490
through both the attacker side
130

130

00:04:41,490  -->  00:04:43,530
and the defender side to help you come up
131

131

00:04:43,530  -->  00:04:44,520
with a better solution
132

132

00:04:44,520  -->  00:04:46,320
and how you can figure out better controls
133

133

00:04:46,320  -->  00:04:48,060
to protect your network.
134

134

00:04:48,060  -->  00:04:49,350
Now, another way you can do this
135

135

00:04:49,350  -->  00:04:51,810
is by actually getting people on the network.
136

136

00:04:51,810  -->  00:04:54,240
And this is done through a penetration test.
137

137

00:04:54,240  -->  00:04:55,680
Now, a penetration test occurs
138

138

00:04:55,680  -->  00:04:57,690
when a red team attempts to conduct an intrusion
139

139

00:04:57,690  -->  00:05:00,840
onto the network using a specific scenario based
140

140

00:05:00,840  -->  00:05:02,250
on threat modeling.
141

141

00:05:02,250  -->  00:05:03,900
Now, this is an important concept here
142

142

00:05:03,900  -->  00:05:05,910
when we're talking about penetration testing,
143

143

00:05:05,910  -->  00:05:08,460
because we're not just doing something against the network
144

144

00:05:08,460  -->  00:05:10,530
to see what we can do to get in.
145

145

00:05:10,530  -->  00:05:12,840
We have a specific goal in mind.
146

146

00:05:12,840  -->  00:05:15,420
So, if my goal is to go after the database server,
147

147

00:05:15,420  -->  00:05:17,910
I'm not going to throw a distributed denial of service attack
148

148

00:05:17,910  -->  00:05:18,743
at you.
149

149

00:05:18,743  -->  00:05:20,370
That wouldn't be a valid pen-test.
150

150

00:05:20,370  -->  00:05:22,470
So instead, we have a specific scenario based
151

151

00:05:22,470  -->  00:05:23,640
on threat modeling,
152

152

00:05:23,640  -->  00:05:26,340
meaning we know what a regular adversary would do,
153

153

00:05:26,340  -->  00:05:28,590
and we're going to base our actions on that.
154

154

00:05:28,590  -->  00:05:30,360
Now, when you're dealing with a penetration test,
155

155

00:05:30,360  -->  00:05:33,000
you always have to agree on a clear methodology
156

156

00:05:33,000  -->  00:05:35,700
and rules of engagement before that penetration test
157

157

00:05:35,700  -->  00:05:36,750
is performed.
158

158

00:05:36,750  -->  00:05:38,010
This is critically important
159

159

00:05:38,010  -->  00:05:40,230
because there are rules to these things.
160

160

00:05:40,230  -->  00:05:41,820
Like I said, I'm not just going to throw
161

161

00:05:41,820  -->  00:05:44,040
a distributed denial of service attack at you
162

162

00:05:44,040  -->  00:05:45,450
because that would probably be against
163

163

00:05:45,450  -->  00:05:46,740
the rules of engagement.
164

164

00:05:46,740  -->  00:05:48,300
Now, if they're in my rules of engagement,
165

165

00:05:48,300  -->  00:05:50,430
then that would be fair game, but in most cases,
166

166

00:05:50,430  -->  00:05:52,170
that's not going to be in there.
167

167

00:05:52,170  -->  00:05:55,410
Now, penetration testing is covered in much more depth
168

168

00:05:55,410  -->  00:05:58,200
if you take the CompTIA pen-test plus exam.
169

169

00:05:58,200  -->  00:05:59,160
The reason for this is
170

170

00:05:59,160  -->  00:06:01,830
that certification is all about red teaming.
171

171

00:06:01,830  -->  00:06:04,470
It is all about being a penetration tester.
172

172

00:06:04,470  -->  00:06:08,070
Whereas here in CySA, we are more focused on defense.
173

173

00:06:08,070  -->  00:06:09,990
But as a defender, you should be familiar
174

174

00:06:09,990  -->  00:06:11,310
with at least a couple of tools
175

175

00:06:11,310  -->  00:06:13,140
that are used by pen-testers.
176

176

00:06:13,140  -->  00:06:14,760
Some of the most common ones you're going to see
177

177

00:06:14,760  -->  00:06:18,600
are things like Metasploit, Cobalt Strike, Kali Linux,
178

178

00:06:18,600  -->  00:06:21,270
ParrotOS and Commando OS.
179

179

00:06:21,270  -->  00:06:23,340
As a defender, if you ever see these tools
180

180

00:06:23,340  -->  00:06:26,640
or operating systems on your network, you should be thinking
181

181

00:06:26,640  -->  00:06:29,040
about the fact that they are penetration testing tools
182

182

00:06:29,040  -->  00:06:31,410
which could be used as part of a penetration test
183

183

00:06:31,410  -->  00:06:33,720
or even worse by an attacker,
184

184

00:06:33,720  -->  00:06:35,970
because most of these are open source tools
185

185

00:06:35,970  -->  00:06:37,893
that anyone can download and use.
