1
1

00:00:00,780  -->  00:00:02,880
<v Trainer>Communicating risk.</v>
2

2

00:00:02,880  -->  00:00:05,910
Now, one of your jobs as a cybersecurity analyst
3

3

00:00:05,910  -->  00:00:08,190
is to make sure you can explain risk
4

4

00:00:08,190  -->  00:00:10,590
in plain and simple language.
5

5

00:00:10,590  -->  00:00:12,300
Now, what do I mean by that?
6

6

00:00:12,300  -->  00:00:15,660
Well, let's take the example of a denial of service attack.
7

7

00:00:15,660  -->  00:00:17,070
Let's pretend you went into a meeting,
8

8

00:00:17,070  -->  00:00:19,530
and there was a room with a bunch of executives in it,
9

9

00:00:19,530  -->  00:00:20,363
and they look and you say,
10

10

00:00:20,363  -->  00:00:22,657
"Hey, I heard you're a new cybersecurity analyst.
11

11

00:00:22,657  -->  00:00:24,697
"Tell me, I heard there's a big threat out there
12

12

00:00:24,697  -->  00:00:26,077
"of denial of service attacks.
13

13

00:00:26,077  -->  00:00:28,650
"What exactly is that and how are we affected?"
14

14

00:00:28,650  -->  00:00:30,667
Well, if you started saying the answer something like this,
15

15

00:00:30,667  -->  00:00:33,697
"Well, a denial of service attack is a type of cyber attack,
16

16

00:00:33,697  -->  00:00:36,037
"which is used to overwhelm a computer, a service,
17

17

00:00:36,037  -->  00:00:38,977
"or a resource by providing extraneous information requests
18

18

00:00:38,977  -->  00:00:40,897
"in a limited duration of time."
19

19

00:00:40,897  -->  00:00:42,877
"Now, for example, during a SYN flood,
20

20

00:00:42,877  -->  00:00:44,107
"there's this three-way handshake
21

21

00:00:44,107  -->  00:00:45,877
"that's compromised by an attacker
22

22

00:00:45,877  -->  00:00:48,487
"after initiating the handshake by sending a SYN request.
23

23

00:00:48,487  -->  00:00:50,287
"but they never return the ACK request,
24

24

00:00:50,287  -->  00:00:51,127
"and this doesn't allow
25

25

00:00:51,127  -->  00:00:53,850
"a completed requested connection to occur."
26

26

00:00:53,850  -->  00:00:55,080
Is that really simple?
27

27

00:00:55,080  -->  00:00:56,130
Well, not really.
28

28

00:00:56,130  -->  00:00:57,990
Instead, if you're talking to a bunch of executives,
29

29

00:00:57,990  -->  00:00:59,910
you need to change it into something more simple,
30

30

00:00:59,910  -->  00:01:01,297
something like this.
31

31

00:01:01,297  -->  00:01:02,707
"A denial of service attack
32

32

00:01:02,707  -->  00:01:04,447
"is a result of malicious activity
33

33

00:01:04,447  -->  00:01:05,947
"against our public website.
34

34

00:01:05,947  -->  00:01:07,507
"The site could become overloaded,
35

35

00:01:07,507  -->  00:01:09,817
"it could prevent customers from accessing their accounts,
36

36

00:01:09,817  -->  00:01:11,377
"and this could result in a loss of sales
37

37

00:01:11,377  -->  00:01:13,237
"for up to two hours where we're dealing with it
38

38

00:01:13,237  -->  00:01:15,937
"and a potential loss of revenue of up to $25,000
39

39

00:01:15,937  -->  00:01:18,420
"based on our average daily sales volume."
40

40

00:01:18,420  -->  00:01:20,040
Which one do you think is going to get you
41

41

00:01:20,040  -->  00:01:22,410
more money and more budget for your cybersecurity
42

42

00:01:22,410  -->  00:01:24,780
to be able to prevent a DoS attack?
43

43

00:01:24,780  -->  00:01:26,070
Probably the second one, right?
44

44

00:01:26,070  -->  00:01:28,110
Because the executives can understand that.
45

45

00:01:28,110  -->  00:01:29,970
You put it in terms they understand.
46

46

00:01:29,970  -->  00:01:32,610
It's this technical thing that you have now dumbed down,
47

47

00:01:32,610  -->  00:01:33,840
for lack of a better term,
48

48

00:01:33,840  -->  00:01:35,857
into simple things that affect them.
49

49

00:01:35,857  -->  00:01:37,747
"It's when your site becomes overloaded.
50

50

00:01:37,747  -->  00:01:39,787
"This prevents your customers from accessing their account.
51

51

00:01:39,787  -->  00:01:40,927
"They can't give you money,
52

52

00:01:40,927  -->  00:01:42,247
"and we're going to lose money, boss.
53

53

00:01:42,247  -->  00:01:43,987
"Therefore, you need to give me money,
54

54

00:01:43,987  -->  00:01:44,887
"so that we can go ahead
55

55

00:01:44,887  -->  00:01:47,010
"and prevent these DoSes from occurring."
56

56

00:01:47,010  -->  00:01:48,990
This is one of the main roles that you have
57

57

00:01:48,990  -->  00:01:51,930
is to communicate risk in simple language,
58

58

00:01:51,930  -->  00:01:54,060
so that your bosses and their executives
59

59

00:01:54,060  -->  00:01:55,410
can understand what they're funding
60

60

00:01:55,410  -->  00:01:57,780
because this communication is key.
61

61

00:01:57,780  -->  00:01:58,650
When you communicate,
62

62

00:01:58,650  -->  00:01:59,640
you need to think about
63

63

00:01:59,640  -->  00:02:01,980
who the receiver of that communication is.
64

64

00:02:01,980  -->  00:02:03,630
If you're talking to another technician,
65

65

00:02:03,630  -->  00:02:05,610
the first answer was probably fine,
66

66

00:02:05,610  -->  00:02:07,710
but if you're talking to executives and managers,
67

67

00:02:07,710  -->  00:02:10,230
the second answer is much, much better.
68

68

00:02:10,230  -->  00:02:11,640
Now, another way that we communicate
69

69

00:02:11,640  -->  00:02:14,310
is using something known as a risk register.
70

70

00:02:14,310  -->  00:02:16,140
A risk register is a document
71

71

00:02:16,140  -->  00:02:18,270
that highlights the results of risk assessments
72

72

00:02:18,270  -->  00:02:20,820
in easily comprehensible format.
73

73

00:02:20,820  -->  00:02:22,140
Inside of this risk register,
74

74

00:02:22,140  -->  00:02:23,220
you're going to document things like
75

75

00:02:23,220  -->  00:02:24,870
the impact and likelihood ratings,
76

76

00:02:24,870  -->  00:02:26,850
those high, medium and lows we talked about,
77

77

00:02:26,850  -->  00:02:28,740
the date you identified the risk,
78

78

00:02:28,740  -->  00:02:30,300
the description of the risk,
79

79

00:02:30,300  -->  00:02:32,280
the countermeasures and controls,
80

80

00:02:32,280  -->  00:02:33,480
who is the risk owner,
81

81

00:02:33,480  -->  00:02:34,620
and how are they going to decide,
82

82

00:02:34,620  -->  00:02:36,840
if we're going to accept, mitigate,
83

83

00:02:36,840  -->  00:02:38,880
transfer, or avoid the risk.
84

84

00:02:38,880  -->  00:02:40,500
And then we also need to think about the status.
85

85

00:02:40,500  -->  00:02:43,200
Which of those are we doing and what is the plan of action?
86

86

00:02:43,200  -->  00:02:46,080
If it's a mitigation, what controls are we putting in place?
87

87

00:02:46,080  -->  00:02:47,610
All of these are things you're going to document
88

88

00:02:47,610  -->  00:02:49,230
inside that risk register.
89

89

00:02:49,230  -->  00:02:51,120
And the risk register really is a document
90

90

00:02:51,120  -->  00:02:53,100
for management and executives to look over
91

91

00:02:53,100  -->  00:02:55,320
and understand what their risk posture is
92

92

00:02:55,320  -->  00:02:56,850
across the organization.
93

93

00:02:56,850  -->  00:02:59,010
Now, this risk register needs to be shared
94

94

00:02:59,010  -->  00:03:00,600
between the different stakeholders,
95

95

00:03:00,600  -->  00:03:02,580
so they can understand what risks are associated
96

96

00:03:02,580  -->  00:03:04,740
with the different workflows that they manage.
97

97

00:03:04,740  -->  00:03:05,573
Like I said,
98

98

00:03:05,573  -->  00:03:07,410
this is made for the managers and the executives.
99

99

00:03:07,410  -->  00:03:08,940
It's not something you're going to create
100

100

00:03:08,940  -->  00:03:10,680
and keep inside your own work group.
101

101

00:03:10,680  -->  00:03:12,870
You need to make sure this is widely understood
102

102

00:03:12,870  -->  00:03:14,010
where your risks are,
103

103

00:03:14,010  -->  00:03:16,320
so they understand what risks they're taking on.
104

104

00:03:16,320  -->  00:03:17,700
Any risk that's being accepted,
105

105

00:03:17,700  -->  00:03:19,950
they need to understand what that is
106

106

00:03:19,950  -->  00:03:21,840
'cause this is important for them.
107

107

00:03:21,840  -->  00:03:23,190
Now, another thing we want to document
108

108

00:03:23,190  -->  00:03:25,650
and communicate is our compensating controls.
109

109

00:03:25,650  -->  00:03:27,720
Now, what is a compensating control?
110

110

00:03:27,720  -->  00:03:29,460
Well, this is a type of security control
111

111

00:03:29,460  -->  00:03:32,160
that acts as a substitute for a principal control.
112

112

00:03:32,160  -->  00:03:34,470
Now, a principal control is just a primary control.
113

113

00:03:34,470  -->  00:03:36,210
When dealing with a compensating control,
114

114

00:03:36,210  -->  00:03:37,043
they're going to provide you
115

115

00:03:37,043  -->  00:03:39,120
with the same or better level of protection,
116

116

00:03:39,120  -->  00:03:42,300
but they're going to use a different methodology or technology.
117

117

00:03:42,300  -->  00:03:44,700
For example, if your risk management framework states
118

118

00:03:44,700  -->  00:03:46,290
that you have to install antivirus
119

119

00:03:46,290  -->  00:03:47,820
on all of your workstations,
120

120

00:03:47,820  -->  00:03:50,550
but for some reason, you can't install it on one of those,
121

121

00:03:50,550  -->  00:03:53,400
you might choose to install an anti-malware solution instead
122

122

00:03:53,400  -->  00:03:56,070
because anti-malware also includes antivirus.
123

123

00:03:56,070  -->  00:03:57,870
And this would then be compensating control
124

124

00:03:57,870  -->  00:03:59,190
because it meets or exceeds
125

125

00:03:59,190  -->  00:04:01,080
the requirement having antivirus,
126

126

00:04:01,080  -->  00:04:02,970
although you're using a different technology,
127

127

00:04:02,970  -->  00:04:05,850
anti-malware in this particular situation.
128

128

00:04:05,850  -->  00:04:07,410
Another good example of this might be,
129

129

00:04:07,410  -->  00:04:09,840
if you wanted to have long strong passwords
130

130

00:04:09,840  -->  00:04:10,980
for all of your systems,
131

131

00:04:10,980  -->  00:04:12,690
that is what your requirement is going to say.
132

132

00:04:12,690  -->  00:04:16,680
Everyone must have a 16 character long, strong password.
133

133

00:04:16,680  -->  00:04:20,310
Well, that's great, except some devices, like SCADA and ICS,
134

134

00:04:20,310  -->  00:04:22,350
might only support an eight character password,
135

135

00:04:22,350  -->  00:04:25,350
so you can't get a long strong password on that system.
136

136

00:04:25,350  -->  00:04:27,840
But maybe you're able to set up two-factor authentication
137

137

00:04:27,840  -->  00:04:30,660
using a smart card and pin, and if you can,
138

138

00:04:30,660  -->  00:04:32,400
that would be a compensating control
139

139

00:04:32,400  -->  00:04:33,960
because a compensating control here
140

140

00:04:33,960  -->  00:04:36,780
would be having two-factor or multi-factor authentication.
141

141

00:04:36,780  -->  00:04:38,790
That is stronger than just using a password,
142

142

00:04:38,790  -->  00:04:40,620
but we're using a different technology,
143

143

00:04:40,620  -->  00:04:43,050
but we're still getting what we need out of the system.
144

144

00:04:43,050  -->  00:04:45,330
Now, the third thing we need to consider is exceptions.
145

145

00:04:45,330  -->  00:04:46,500
When we talk about exceptions,
146

146

00:04:46,500  -->  00:04:48,870
we need to think about exception management.
147

147

00:04:48,870  -->  00:04:51,060
When you're dealing with all your policies and procedures,
148

148

00:04:51,060  -->  00:04:53,010
they're going to say you need to do certain things,
149

149

00:04:53,010  -->  00:04:54,990
and sometimes, you simply can't.
150

150

00:04:54,990  -->  00:04:57,330
These are going to be listed as an exception.
151

151

00:04:57,330  -->  00:04:59,550
Exception management is a formal process
152

152

00:04:59,550  -->  00:05:01,200
that's used to document each case
153

153

00:05:01,200  -->  00:05:03,540
where a function or asset is non-compliant
154

154

00:05:03,540  -->  00:05:06,270
with the written policy and procedural controls.
155

155

00:05:06,270  -->  00:05:08,640
For example, you might have business processes
156

156

00:05:08,640  -->  00:05:09,870
and assets that are affected.
157

157

00:05:09,870  -->  00:05:11,280
You want to document that.
158

158

00:05:11,280  -->  00:05:12,480
If I have this exception,
159

159

00:05:12,480  -->  00:05:14,730
where this thing can't use a long strong password,
160

160

00:05:14,730  -->  00:05:16,590
what is being affected by that?
161

161

00:05:16,590  -->  00:05:18,840
Then I might think about what personnel are involved.
162

162

00:05:18,840  -->  00:05:20,670
Because I don't have a long strong password,
163

163

00:05:20,670  -->  00:05:22,830
we're going to end up changing it every 30 days
164

164

00:05:22,830  -->  00:05:24,990
instead of every 60 days, because that way,
165

165

00:05:24,990  -->  00:05:27,300
it gives us at least a little bit of a compensation.
166

166

00:05:27,300  -->  00:05:29,430
We might think about the reason for the exception.
167

167

00:05:29,430  -->  00:05:31,320
We have to have an exception for this system,
168

168

00:05:31,320  -->  00:05:33,690
because it's an old ICS SCADA system,
169

169

00:05:33,690  -->  00:05:35,730
and it can't support a long, strong password,
170

170

00:05:35,730  -->  00:05:38,040
and it can't support two-factor authentication,
171

171

00:05:38,040  -->  00:05:40,290
so we have to have an exception for it.
172

172

00:05:40,290  -->  00:05:41,123
Somebody might ask,
173

173

00:05:41,123  -->  00:05:42,690
"Why can't you just take the system offline?"
174

174

00:05:42,690  -->  00:05:45,030
Well, this particular ICS SCADA system
175

175

00:05:45,030  -->  00:05:47,520
might be running our entire manufacturing floor,
176

176

00:05:47,520  -->  00:05:48,600
and if we take it offline,
177

177

00:05:48,600  -->  00:05:50,640
we lose $1,000,000 a day in productivity,
178

178

00:05:50,640  -->  00:05:51,870
so we're going to live with the fact
179

179

00:05:51,870  -->  00:05:54,150
that it only has an eight character password.
180

180

00:05:54,150  -->  00:05:54,983
These are the kind of things
181

181

00:05:54,983  -->  00:05:56,400
you have to think about in the real world.
182

182

00:05:56,400  -->  00:05:58,110
We're then going to look at a risk assessment.
183

183

00:05:58,110  -->  00:05:59,407
We're going to look at that system and say,
184

184

00:05:59,407  -->  00:06:01,897
"How bad is it by not having this one control?
185

185

00:06:01,897  -->  00:06:04,500
"Do I have enough other controls that might mitigate it?"
186

186

00:06:04,500  -->  00:06:06,150
Maybe I took that ICS SCADA system,
187

187

00:06:06,150  -->  00:06:07,470
and I put it on its own VLAN,
188

188

00:06:07,470  -->  00:06:09,540
and it's only accessible from the local network,
189

189

00:06:09,540  -->  00:06:10,620
not from the internet,
190

190

00:06:10,620  -->  00:06:12,570
and I put additional compensations in place.
191

191

00:06:12,570  -->  00:06:14,130
And when I do a risk assessment for it,
192

192

00:06:14,130  -->  00:06:15,570
I find out that this brings me down
193

193

00:06:15,570  -->  00:06:16,830
to a lower level of risk,
194

194

00:06:16,830  -->  00:06:18,810
and I'm willing to grant an exception.
195

195

00:06:18,810  -->  00:06:20,460
I might think about compensating controls
196

196

00:06:20,460  -->  00:06:21,420
that are being utilized.
197

197

00:06:21,420  -->  00:06:24,540
Again, because I couldn't access the long strong password,
198

198

00:06:24,540  -->  00:06:26,700
I put it on its own isolated network,
199

199

00:06:26,700  -->  00:06:29,250
so nobody else can access that system directly.
200

200

00:06:29,250  -->  00:06:31,350
Next, we have the duration of the exception.
201

201

00:06:31,350  -->  00:06:34,590
How long are we going to exist in this accepted state?
202

202

00:06:34,590  -->  00:06:36,450
In the case of this ICS SCADA system,
203

203

00:06:36,450  -->  00:06:38,850
maybe we decide that we're going to give them 12 months,
204

204

00:06:38,850  -->  00:06:41,100
because in that 12 months, we're going to have enough money,
205

205

00:06:41,100  -->  00:06:42,150
and we have an upgrade coming
206

206

00:06:42,150  -->  00:06:43,380
and that system's going to get replaced
207

207

00:06:43,380  -->  00:06:45,630
with this newer system that has better security.
208

208

00:06:45,630  -->  00:06:47,190
That's the idea here with the duration.
209

209

00:06:47,190  -->  00:06:49,140
We don't want to let this run on indefinitely,
210

210

00:06:49,140  -->  00:06:50,580
but it has to be a reasonable amount of time,
211

211

00:06:50,580  -->  00:06:53,310
so they can get the money and get the system replaced.
212

212

00:06:53,310  -->  00:06:56,340
And finally, what steps are needed to achieve compliance?
213

213

00:06:56,340  -->  00:06:59,070
In the case of my fictitious ICS SCADA example,
214

214

00:06:59,070  -->  00:07:02,130
we might need to upgrade from version two to version three,
215

215

00:07:02,130  -->  00:07:04,290
and that costs us $1,000,000 for the new system,
216

216

00:07:04,290  -->  00:07:05,910
and it takes six months to install.
217

217

00:07:05,910  -->  00:07:06,750
So here's all the things,
218

218

00:07:06,750  -->  00:07:08,130
we need to have budgeting in place,
219

219

00:07:08,130  -->  00:07:09,690
we need to have approval in place.
220

220

00:07:09,690  -->  00:07:10,980
We need to start ordering these things,
221

221

00:07:10,980  -->  00:07:12,180
and there's this amount of lead time,
222

222

00:07:12,180  -->  00:07:14,250
and we can start going through all of those things.
223

223

00:07:14,250  -->  00:07:15,540
All of these are things you have to consider
224

224

00:07:15,540  -->  00:07:17,820
as you're thinking about your exception management.
225

225

00:07:17,820  -->  00:07:19,110
Now, the final thing to think about,
226

226

00:07:19,110  -->  00:07:20,460
when you're talking about exception management,
227

227

00:07:20,460  -->  00:07:22,950
is that if you have a certain policy or procedure
228

228

00:07:22,950  -->  00:07:25,470
that's generating a lot of exception requests,
229

229

00:07:25,470  -->  00:07:27,660
you need to step back and start thinking about,
230

230

00:07:27,660  -->  00:07:30,750
do you need to redesign or reconsider that policy?
231

231

00:07:30,750  -->  00:07:32,460
Sometimes somebody has a great idea
232

232

00:07:32,460  -->  00:07:34,177
for a policy or procedure, they say,
233

233

00:07:34,177  -->  00:07:37,387
"This is going to save us time, this is going to save us money,
234

234

00:07:37,387  -->  00:07:40,140
"this is going to make us more secure," whatever it is.
235

235

00:07:40,140  -->  00:07:41,430
But when you start putting it into practice,
236

236

00:07:41,430  -->  00:07:43,530
you find out that your systems can't support it.
237

237

00:07:43,530  -->  00:07:45,840
You don't have the capability, you don't have the knowledge,
238

238

00:07:45,840  -->  00:07:48,300
you don't have the money or the resources, whatever it is,
239

239

00:07:48,300  -->  00:07:50,490
and so people start putting in exception requests.
240

240

00:07:50,490  -->  00:07:52,890
If you get one or two requests, that's probably okay,
241

241

00:07:52,890  -->  00:07:54,030
we can work with those.
242

242

00:07:54,030  -->  00:07:55,530
If you're getting hundreds or thousands
243

243

00:07:55,530  -->  00:07:57,330
of requests across your organization,
244

244

00:07:57,330  -->  00:07:59,910
this probably means it's a bad or stupid policy.
245

245

00:07:59,910  -->  00:08:02,370
So go back and look at it, and if possible,
246

246

00:08:02,370  -->  00:08:03,870
you might want to redesign that.
