1
1

00:00:00,570  -->  00:00:02,910
<v Jason>Risk-Based Frameworks.</v>
2

2

00:00:02,910  -->  00:00:04,620
Now, the other type of framework we have
3

3

00:00:04,620  -->  00:00:07,260
is what's known as a risk-based framework.
4

4

00:00:07,260  -->  00:00:09,030
When we're dealing with a prescriptive framework
5

5

00:00:09,030  -->  00:00:10,890
like we talked about in the last lesson,
6

6

00:00:10,890  -->  00:00:12,870
this can actually make it more difficult for us
7

7

00:00:12,870  -->  00:00:14,850
because the framework can't keep pace
8

8

00:00:14,850  -->  00:00:17,490
with continually evolving threat landscapes.
9

9

00:00:17,490  -->  00:00:20,430
Prescriptive frameworks tend to be very matter-of-fact
10

10

00:00:20,430  -->  00:00:21,990
and very checklist-driven,
11

11

00:00:21,990  -->  00:00:23,670
and so we may start doing things
12

12

00:00:23,670  -->  00:00:26,190
to be able to meet those prescriptive frameworks,
13

13

00:00:26,190  -->  00:00:28,470
that doesn't really help us in the real world.
14

14

00:00:28,470  -->  00:00:30,000
Let me give you an example of this.
15

15

00:00:30,000  -->  00:00:31,717
You might have a prescriptive framework that says,
16

16

00:00:31,717  -->  00:00:35,370
"You need to have ongoing monitoring done through a SIEM."
17

17

00:00:35,370  -->  00:00:37,290
And you think, "Well, that's a great thing, right, Jason?"
18

18

00:00:37,290  -->  00:00:40,080
And I would agree, having a SIEM is a good thing,
19

19

00:00:40,080  -->  00:00:42,720
but if we start putting everything into the SIEM,
20

20

00:00:42,720  -->  00:00:45,150
we can create a situation where the SIEM starts raising
21

21

00:00:45,150  -->  00:00:46,830
hundreds of alerts every day,
22

22

00:00:46,830  -->  00:00:48,870
and that can start overwhelming our analysts
23

23

00:00:48,870  -->  00:00:51,240
because a lot of those might be false positives.
24

24

00:00:51,240  -->  00:00:52,590
That would be a big issue for us.
25

25

00:00:52,590  -->  00:00:53,790
And if we're only doing it
26

26

00:00:53,790  -->  00:00:55,770
to meet the prescriptive framework requirements,
27

27

00:00:55,770  -->  00:00:57,960
and not doing it because we have a real risk
28

28

00:00:57,960  -->  00:00:59,880
that we're trying to address with that SIEM,
29

29

00:00:59,880  -->  00:01:01,740
then we're wasting our time.
30

30

00:01:01,740  -->  00:01:03,690
And so, we want to be thinking about these things
31

31

00:01:03,690  -->  00:01:04,897
as we're figuring out,
32

32

00:01:04,897  -->  00:01:06,120
"Is this going to be something we're doing
33

33

00:01:06,120  -->  00:01:08,550
because we're told to because it's prescriptive?
34

34

00:01:08,550  -->  00:01:11,640
Or, are we doing it based on a risk that really exists?"
35

35

00:01:11,640  -->  00:01:13,650
Well, when we deal with a risk-based framework
36

36

00:01:13,650  -->  00:01:15,990
we are dealing with a framework that uses risk assessment
37

37

00:01:15,990  -->  00:01:19,380
to prioritize security control selection and investment.
38

38

00:01:19,380  -->  00:01:22,650
So maybe having that SIEM is a good thing, maybe it's not,
39

39

00:01:22,650  -->  00:01:24,510
but we'll be able to make an intelligent decision,
40

40

00:01:24,510  -->  00:01:27,270
and not do it just because we're being told to.
41

41

00:01:27,270  -->  00:01:30,480
Now, all of this comes down to regulatory compliance, right?
42

42

00:01:30,480  -->  00:01:32,310
When we're dealing with regulatory compliance,
43

43

00:01:32,310  -->  00:01:34,380
we are told things that we must do.
44

44

00:01:34,380  -->  00:01:36,120
So those things are going to be falling
45

45

00:01:36,120  -->  00:01:38,460
much more in the prescriptive category.
46

46

00:01:38,460  -->  00:01:40,507
If I'm running an organization and HIPAA says,
47

47

00:01:40,507  -->  00:01:43,290
"You must have a SIEM," then I better have a SIEM, right?
48

48

00:01:43,290  -->  00:01:45,960
Because I need to be within the constraints of that law.
49

49

00:01:45,960  -->  00:01:48,630
But if I'm not barred into this regulatory compliance
50

50

00:01:48,630  -->  00:01:49,950
because I'm an organization
51

51

00:01:49,950  -->  00:01:52,140
that doesn't fall into one of those categories,
52

52

00:01:52,140  -->  00:01:55,260
then it's much better to use a risk-based framework.
53

53

00:01:55,260  -->  00:01:56,880
By using a risk-based framework,
54

54

00:01:56,880  -->  00:01:57,930
this can allow businesses
55

55

00:01:57,930  -->  00:01:59,640
to develop their own way of doing things
56

56

00:01:59,640  -->  00:02:01,380
while minimizing risk.
57

57

00:02:01,380  -->  00:02:02,760
In my organization,
58

58

00:02:02,760  -->  00:02:05,730
we don't have a lot of regulatory compliance requirements.
59

59

00:02:05,730  -->  00:02:08,100
The only ones we really have is PCI DSS
60

60

00:02:08,100  -->  00:02:09,750
for our credit card payments.
61

61

00:02:09,750  -->  00:02:11,400
Everything else, we can really do
62

62

00:02:11,400  -->  00:02:12,690
under a risk-based framework,
63

63

00:02:12,690  -->  00:02:14,160
and that is what we do.
64

64

00:02:14,160  -->  00:02:15,750
We think about what risks exist
65

65

00:02:15,750  -->  00:02:17,460
and then we put mitigations in place
66

66

00:02:17,460  -->  00:02:20,880
based on the prioritization to help us meet our needs.
67

67

00:02:20,880  -->  00:02:22,350
Now, one of the best ways to do this
68

68

00:02:22,350  -->  00:02:23,790
is by using something known as
69

69

00:02:23,790  -->  00:02:26,040
the NIST Cybersecurity Framework.
70

70

00:02:26,040  -->  00:02:27,660
This is a relatively new framework
71

71

00:02:27,660  -->  00:02:29,730
that's come out in the last couple of years.
72

72

00:02:29,730  -->  00:02:32,550
The NIST Cybersecurity Framework is a risk-based framework
73

73

00:02:32,550  -->  00:02:36,660
that's focused on IT security over IT service provisioning,
74

74

00:02:36,660  -->  00:02:39,060
and this framework covers three core areas.
75

75

00:02:39,060  -->  00:02:41,910
There's the framework core, the implementation tiers,
76

76

00:02:41,910  -->  00:02:43,860
and the framework profiles.
77

77

00:02:43,860  -->  00:02:45,810
Now, when we talk about the framework core,
78

78

00:02:45,810  -->  00:02:48,660
this is going to identify the five cybersecurity functions,
79

79

00:02:48,660  -->  00:02:53,190
which are, identify, protect, detect, respond, and recover.
80

80

00:02:53,190  -->  00:02:54,930
And then for each of these five functions,
81

81

00:02:54,930  -->  00:02:58,230
they can then be divided into categories and subcategories.
82

82

00:02:58,230  -->  00:03:00,390
This makes up the core of the framework,
83

83

00:03:00,390  -->  00:03:01,950
and it gives you lots of different controls
84

84

00:03:01,950  -->  00:03:04,890
that you can pick from under these five categories.
85

85

00:03:04,890  -->  00:03:06,810
When we look at the implementation tiers,
86

86

00:03:06,810  -->  00:03:09,210
this is going to assess how closely those core functions,
87

87

00:03:09,210  -->  00:03:10,410
those five areas
88

88

00:03:10,410  -->  00:03:12,120
are integrated into the organization's
89

89

00:03:12,120  -->  00:03:14,160
overall risk management process.
90

90

00:03:14,160  -->  00:03:15,510
And for each of those tiers,
91

91

00:03:15,510  -->  00:03:16,560
they're going to be categorized
92

92

00:03:16,560  -->  00:03:20,580
as partial, risk-informed, repeatable, or adaptive.
93

93

00:03:20,580  -->  00:03:23,190
Now, if you're partial, that's low on the scale.
94

94

00:03:23,190  -->  00:03:25,560
If you're adaptive, that's very high on the scale,
95

95

00:03:25,560  -->  00:03:27,360
and so you want to try to get higher on the scale
96

96

00:03:27,360  -->  00:03:29,700
as you start getting more and more of this
97

97

00:03:29,700  -->  00:03:31,080
integrated into your organization
98

98

00:03:31,080  -->  00:03:32,850
and the way you do business.
99

99

00:03:32,850  -->  00:03:34,140
And then the final thing we're going to look at
100

100

00:03:34,140  -->  00:03:36,000
is our framework profiles.
101

101

00:03:36,000  -->  00:03:37,560
These are used to supply statements
102

102

00:03:37,560  -->  00:03:39,270
of current cybersecurity outcomes
103

103

00:03:39,270  -->  00:03:41,160
and target cybersecurity outcomes
104

104

00:03:41,160  -->  00:03:43,740
to identify investments that will be the most productive
105

105

00:03:43,740  -->  00:03:46,470
in closing the gap in cybersecurity capabilities,
106

106

00:03:46,470  -->  00:03:47,670
shown by the comparison
107

107

00:03:47,670  -->  00:03:50,070
of the current and the target profiles.
108

108

00:03:50,070  -->  00:03:52,500
Now, that is a lot of words to say this.
109

109

00:03:52,500  -->  00:03:54,690
Essentially, you want to look at your organization,
110

110

00:03:54,690  -->  00:03:56,430
and you want to capture a baseline
111

111

00:03:56,430  -->  00:03:59,550
of where you are in terms of the framework right now.
112

112

00:03:59,550  -->  00:04:01,800
Are you at a very high quality or low quality?
113

113

00:04:01,800  -->  00:04:03,300
Now, if you're at a low quality,
114

114

00:04:03,300  -->  00:04:04,950
and you want to get to a high quality,
115

115

00:04:04,950  -->  00:04:06,960
that is your target cybersecurity outcome.
116

116

00:04:06,960  -->  00:04:08,880
You want to be at this higher level,
117

117

00:04:08,880  -->  00:04:10,770
so what things do you need to do?
118

118

00:04:10,770  -->  00:04:13,680
You can identify those things based on the profiles
119

119

00:04:13,680  -->  00:04:16,110
so you can then start adding those things over time
120

120

00:04:16,110  -->  00:04:18,390
and getting your organization to that higher level.
121

121

00:04:18,390  -->  00:04:19,650
That's the idea here.
122

122

00:04:19,650  -->  00:04:22,320
And again, all of this is risk-informed.
123

123

00:04:22,320  -->  00:04:23,850
This is a risk-based framework
124

124

00:04:23,850  -->  00:04:26,693
when you're dealing with the NIST Cybersecurity Framework.
