1
1

00:00:00,360  -->  00:00:02,580
<v Instructor>Prescriptive frameworks.</v>
2

2

00:00:02,580  -->  00:00:04,770
In the last lesson, we brought up the concept
3

3

00:00:04,770  -->  00:00:06,540
of a framework and how it fits
4

4

00:00:06,540  -->  00:00:10,170
inside the world of IT governance and IT service management.
5

5

00:00:10,170  -->  00:00:11,070
In this lesson,
6

6

00:00:11,070  -->  00:00:14,580
we're going to focus specifically on prescriptive frameworks.
7

7

00:00:14,580  -->  00:00:16,530
Now, when I talk about a prescriptive framework,
8

8

00:00:16,530  -->  00:00:18,060
this is a framework that stipulates
9

9

00:00:18,060  -->  00:00:20,460
control selection and deployment.
10

10

00:00:20,460  -->  00:00:22,440
This is something that is going to be mandatory.
11

11

00:00:22,440  -->  00:00:24,240
That's why it is prescriptive.
12

12

00:00:24,240  -->  00:00:26,430
A lot of times when you see prescriptive frameworks,
13

13

00:00:26,430  -->  00:00:29,550
they're going to be driven by regulatory compliance.
14

14

00:00:29,550  -->  00:00:31,080
As I mentioned in the last lesson,
15

15

00:00:31,080  -->  00:00:32,550
if you're a healthcare provider
16

16

00:00:32,550  -->  00:00:34,530
you're going to be focused on meeting the requirements
17

17

00:00:34,530  -->  00:00:37,332
for regulatory compliance of HIPAA, and, therefore,
18

18

00:00:37,332  -->  00:00:39,270
you might want to use a prescriptive framework
19

19

00:00:39,270  -->  00:00:40,800
to help you meet that.
20

20

00:00:40,800  -->  00:00:43,050
Now, there are lots of different frameworks out there.
21

21

00:00:43,050  -->  00:00:44,790
As I mentioned before, for instance,
22

22

00:00:44,790  -->  00:00:48,450
we have ITIL and COBIT and ISO 27001,
23

23

00:00:48,450  -->  00:00:52,740
which is an information security framework, or PCI DSS.
24

24

00:00:52,740  -->  00:00:55,080
Now, all of these different frameworks could be chosen,
25

25

00:00:55,080  -->  00:00:57,180
depending on what your needs are, and, again,
26

26

00:00:57,180  -->  00:01:00,450
that's going to go back to your IT governance structure.
27

27

00:01:00,450  -->  00:01:01,980
Depending on which one you're using,
28

28

00:01:01,980  -->  00:01:03,720
that's going to have different requirements that you,
29

29

00:01:03,720  -->  00:01:05,485
as a cybersecurity analyst, are going to have to fill.
30

30

00:01:05,485  -->  00:01:09,360
For the exam, you don't need to know the specifics of that,
31

31

00:01:09,360  -->  00:01:11,700
but in the real world, if your company is using
32

32

00:01:11,700  -->  00:01:12,960
one of these frameworks,
33

33

00:01:12,960  -->  00:01:15,000
you want to start learning about it so you can make sure
34

34

00:01:15,000  -->  00:01:16,260
that you're meeting the requirements
35

35

00:01:16,260  -->  00:01:18,150
of that framework inside
36

36

00:01:18,150  -->  00:01:20,460
of the prescriptive framework itself.
37

37

00:01:20,460  -->  00:01:21,870
Now, inside of these frameworks,
38

38

00:01:21,870  -->  00:01:24,420
we often use what's known as a maturity model.
39

39

00:01:24,420  -->  00:01:26,250
Now, a maturity model is a component
40

40

00:01:26,250  -->  00:01:28,890
of an enterprise security architecture framework
41

41

00:01:28,890  -->  00:01:30,570
that's used to assess the formality
42

42

00:01:30,570  -->  00:01:34,140
and optimization of security, control selection and usage
43

43

00:01:34,140  -->  00:01:36,750
and it addresses any gaps that you may have.
44

44

00:01:36,750  -->  00:01:39,210
Essentially, we're going to take our organization
45

45

00:01:39,210  -->  00:01:41,154
and we're going to do a baseline to figure out where we are
46

46

00:01:41,154  -->  00:01:44,130
and then we can place it onto this maturity model
47

47

00:01:44,130  -->  00:01:47,040
and say we're a level one, two, three, four
48

48

00:01:47,040  -->  00:01:48,630
or five organization
49

49

00:01:48,630  -->  00:01:50,130
and if we want to get to a higher level,
50

50

00:01:50,130  -->  00:01:52,350
there are certain things we have to do.
51

51

00:01:52,350  -->  00:01:54,150
Now, when we start out with a maturity model,
52

52

00:01:54,150  -->  00:01:57,360
generally, most organizations start at tier one,
53

53

00:01:57,360  -->  00:01:59,850
and this is a very reactive posture.
54

54

00:01:59,850  -->  00:02:01,230
Now, what we want to do is get
55

55

00:02:01,230  -->  00:02:02,340
out of this reactive mode
56

56

00:02:02,340  -->  00:02:04,590
where we're not firefighting all the time.
57

57

00:02:04,590  -->  00:02:06,060
If you ever worked in a new company,
58

58

00:02:06,060  -->  00:02:08,520
and they're very immature, things are just happening
59

59

00:02:08,520  -->  00:02:10,770
and you're reacting to them as they're happening.
60

60

00:02:10,770  -->  00:02:12,780
You're not ever getting ahead of the game.
61

61

00:02:12,780  -->  00:02:15,600
What we want to do is move ourself from this reactive posture
62

62

00:02:15,600  -->  00:02:17,910
into a proactive posture, and as you go
63

63

00:02:17,910  -->  00:02:20,010
up the maturity model scale, you'll get more
64

64

00:02:20,010  -->  00:02:21,750
and more proactive.
65

65

00:02:21,750  -->  00:02:24,330
One of the most common models looks something like this.
66

66

00:02:24,330  -->  00:02:26,610
This is a five-tier approach, and we're going to start
67

67

00:02:26,610  -->  00:02:27,960
at level one.
68

68

00:02:27,960  -->  00:02:30,120
Level one is our initial maturity.
69

69

00:02:30,120  -->  00:02:32,100
This is where we first start out, and this is where
70

70

00:02:32,100  -->  00:02:34,170
we are highly reactive in nature.
71

71

00:02:34,170  -->  00:02:36,690
Then as we get a little bit more mature, we become managed.
72

72

00:02:36,690  -->  00:02:39,570
This is level two, and in level two, we're going to prepare
73

73

00:02:39,570  -->  00:02:42,300
to mitigate through risk assessments to be able to figure
74

74

00:02:42,300  -->  00:02:44,100
out what risks are out there, and we can try
75

75

00:02:44,100  -->  00:02:46,320
to get ahead of the game at least a little bit.
76

76

00:02:46,320  -->  00:02:49,260
Once we get into level three, we start being defined.
77

77

00:02:49,260  -->  00:02:51,360
Now, this is where we have defined policies and procedures
78

78

00:02:51,360  -->  00:02:54,510
for lots of different things across our organization,
79

79

00:02:54,510  -->  00:02:55,770
but we're still not perfect.
80

80

00:02:55,770  -->  00:02:58,140
We're still reacting a lot of the time.
81

81

00:02:58,140  -->  00:02:59,610
When we get into level four,
82

82

00:02:59,610  -->  00:03:02,460
we're starting to do quantitative management here.
83

83

00:03:02,460  -->  00:03:04,170
This is where we have management oversight
84

84

00:03:04,170  -->  00:03:05,400
of all of our risks.
85

85

00:03:05,400  -->  00:03:07,140
We've captured them in our risk register,
86

86

00:03:07,140  -->  00:03:08,370
we know what risks exist
87

87

00:03:08,370  -->  00:03:10,440
and we know what we're going to do to fix those things,
88

88

00:03:10,440  -->  00:03:12,540
but, again, there are still some things that pop up
89

89

00:03:12,540  -->  00:03:13,740
that we didn't think of,
90

90

00:03:13,740  -->  00:03:16,680
so we're still only a level four organization.
91

91

00:03:16,680  -->  00:03:19,650
Once we get to level five, this is where we're optimizing.
92

92

00:03:19,650  -->  00:03:21,960
We are fully proactive at this point.
93

93

00:03:21,960  -->  00:03:23,940
We're using risk-driven approaches to figure out
94

94

00:03:23,940  -->  00:03:26,280
what type of risk exists and what we can do about 'em.
95

95

00:03:26,280  -->  00:03:28,140
We are completely being proactive here
96

96

00:03:28,140  -->  00:03:30,300
and trying to stop all risks that we can
97

97

00:03:30,300  -->  00:03:32,970
and mitigate them down to an acceptable level.
98

98

00:03:32,970  -->  00:03:34,770
Now, when you look at these maturity models,
99

99

00:03:34,770  -->  00:03:36,720
they're going to help you review your organization
100

100

00:03:36,720  -->  00:03:38,043
against the expected goals
101

101

00:03:38,043  -->  00:03:40,800
for that level of organization that you want to meet.
102

102

00:03:40,800  -->  00:03:42,330
This will help you determine the level of risk
103

103

00:03:42,330  -->  00:03:45,600
that the organization is exposed to based on those goals.
104

104

00:03:45,600  -->  00:03:47,490
If you're a level five, that means you're exposed
105

105

00:03:47,490  -->  00:03:49,800
to less risk than if you're a level one.
106

106

00:03:49,800  -->  00:03:52,200
Now, does that mean that we all want to be level fives?
107

107

00:03:52,200  -->  00:03:53,280
Well, no.
108

108

00:03:53,280  -->  00:03:55,800
You may not need to be a level five organization.
109

109

00:03:55,800  -->  00:03:58,290
This again goes back to your IT governance.
110

110

00:03:58,290  -->  00:04:00,540
What is our risk appetite that our shareholders
111

111

00:04:00,540  -->  00:04:03,810
and stakeholders have developed for us in terms of risk?
112

112

00:04:03,810  -->  00:04:05,707
In my organization, we usually aim
113

113

00:04:05,707  -->  00:04:08,220
for a level three or a level four.
114

114

00:04:08,220  -->  00:04:09,870
We don't need to be fully proactive
115

115

00:04:09,870  -->  00:04:13,050
because the cost associated with doing that is so excessive
116

116

00:04:13,050  -->  00:04:15,330
that it doesn't make sense for our business model.
117

117

00:04:15,330  -->  00:04:17,760
But, if we're at a level three or a level four,
118

118

00:04:17,760  -->  00:04:20,160
that's good enough to be able to keep a lot of the risk
119

119

00:04:20,160  -->  00:04:23,400
down to a low enough level that we can accept the risk based
120

120

00:04:23,400  -->  00:04:24,453
on our risk appetite.
