1
1

00:00:00,120  -->  00:00:01,080
<v Instructor>In this lesson,</v>
2

2

00:00:01,080  -->  00:00:03,120
we're going to discuss industry frameworks
3

3

00:00:03,120  -->  00:00:06,180
that you may come across in the cybersecurity industry.
4

4

00:00:06,180  -->  00:00:08,547
This includes PCI DSS,
5

5

00:00:08,547  -->  00:00:13,547
CIS, OWASP, ISO 27000 and OSS TMM.
6

6

00:00:14,460  -->  00:00:17,580
First we have PCI DSS, also known as
7

7

00:00:17,580  -->  00:00:20,850
the Payment Card Industry Digital Security Standard.
8

8

00:00:20,850  -->  00:00:23,550
Now the Payment Card Industry Data Security Standard
9

9

00:00:23,550  -->  00:00:25,440
is a set of security standards created by
10

10

00:00:25,440  -->  00:00:27,030
major credit card companies
11

11

00:00:27,030  -->  00:00:29,670
to help protect the sensitive payment card information
12

12

00:00:29,670  -->  00:00:31,560
from fraud and data breaches.
13

13

00:00:31,560  -->  00:00:33,630
This standard applies to all organizations
14

14

00:00:33,630  -->  00:00:37,050
that process, store or transmit payment card information
15

15

00:00:37,050  -->  00:00:39,240
and is designed to ensure that these organizations
16

16

00:00:39,240  -->  00:00:40,530
maintain a secure environment
17

17

00:00:40,530  -->  00:00:42,600
to protect cardholder data.
18

18

00:00:42,600  -->  00:00:46,320
The PCI DSS standard is divided into six main categories
19

19

00:00:46,320  -->  00:00:48,030
or control objectives.
20

20

00:00:48,030  -->  00:00:50,880
First, build and maintain a secure network.
21

21

00:00:50,880  -->  00:00:52,980
This means that organizations must maintain
22

22

00:00:52,980  -->  00:00:56,190
a firewall configuration to better protect cardholder data
23

23

00:00:56,190  -->  00:00:59,280
and regularly update and test their security systems.
24

24

00:00:59,280  -->  00:01:01,800
Second, protect cardholder data.
25

25

00:01:01,800  -->  00:01:04,530
Organizations must protect stored cardholder data
26

26

00:01:04,530  -->  00:01:06,630
and encrypt transmission of cardholder data
27

27

00:01:06,630  -->  00:01:08,940
across open, public networks.
28

28

00:01:08,940  -->  00:01:12,240
Third, maintain a vulnerability management program.
29

29

00:01:12,240  -->  00:01:14,850
Organizations have to use antivirus software,
30

30

00:01:14,850  -->  00:01:16,680
regularly update their security systems
31

31

00:01:16,680  -->  00:01:18,960
and implement vulnerability scanning and patching
32

32

00:01:18,960  -->  00:01:20,730
within their organization.
33

33

00:01:20,730  -->  00:01:24,000
Fourth, implement strong access control measures.
34

34

00:01:24,000  -->  00:01:26,790
Organizations have to limit access to cardholder data
35

35

00:01:26,790  -->  00:01:27,900
to only those who need it
36

36

00:01:27,900  -->  00:01:30,720
and regularly monitor and test access control systems
37

37

00:01:30,720  -->  00:01:32,220
to ensure nobody's accessing it
38

38

00:01:32,220  -->  00:01:34,170
that shouldn't be accessing it.
39

39

00:01:34,170  -->  00:01:37,260
Fifth, regularly monitor and test networks.
40

40

00:01:37,260  -->  00:01:39,780
Organizations have to track and monitor all access
41

41

00:01:39,780  -->  00:01:42,180
to network resources and cardholder data,
42

42

00:01:42,180  -->  00:01:44,130
as well as regularly test their security systems
43

43

00:01:44,130  -->  00:01:45,390
and processes.
44

44

00:01:45,390  -->  00:01:47,430
This includes doing vulnerability scanning
45

45

00:01:47,430  -->  00:01:49,740
as well as doing penetration testing.
46

46

00:01:49,740  -->  00:01:53,100
Sixth, maintain an information security policy.
47

47

00:01:53,100  -->  00:01:55,230
Organizations must maintain a policy
48

48

00:01:55,230  -->  00:01:57,090
that addresses information security
49

49

00:01:57,090  -->  00:01:59,130
and ensures that all employees are aware of
50

50

00:01:59,130  -->  00:02:01,410
and understand this policy.
51

51

00:02:01,410  -->  00:02:04,050
Now compliance with the PCI DSS standard
52

52

00:02:04,050  -->  00:02:06,750
is considered mandatory for all organizations
53

53

00:02:06,750  -->  00:02:10,650
that process, store or transmit payment card information.
54

54

00:02:10,650  -->  00:02:12,540
Now when I talk about payment card information,
55

55

00:02:12,540  -->  00:02:14,340
I'm really talking about things like credit cards
56

56

00:02:14,340  -->  00:02:15,990
and debit cards here.
57

57

00:02:15,990  -->  00:02:17,970
Organizations also have to be audited
58

58

00:02:17,970  -->  00:02:19,800
by a qualified security assessor,
59

59

00:02:19,800  -->  00:02:23,250
known as a QSA and pass regular security screens
60

60

00:02:23,250  -->  00:02:26,520
to ensure compliance with the PCI DSS standard.
61

61

00:02:26,520  -->  00:02:27,900
In addition to all of this,
62

62

00:02:27,900  -->  00:02:30,180
organizations also have to maintain documentation
63

63

00:02:30,180  -->  00:02:32,460
and evidence of compliance with the standard
64

64

00:02:32,460  -->  00:02:35,370
and make it available to credit card companies upon request
65

65

00:02:35,370  -->  00:02:37,560
as part of traditional audits.
66

66

00:02:37,560  -->  00:02:39,240
Now cybersecurity analysts are going to play
67

67

00:02:39,240  -->  00:02:41,790
a critical role in helping organizations comply
68

68

00:02:41,790  -->  00:02:43,980
with the PCI DSS standard.
69

69

00:02:43,980  -->  00:02:45,540
As a cybersecurity analyst,
70

70

00:02:45,540  -->  00:02:47,280
you're going to be responsible for analyzing
71

71

00:02:47,280  -->  00:02:48,990
the organization's security systems
72

72

00:02:48,990  -->  00:02:51,420
and identifying vulnerabilities that could compromise
73

73

00:02:51,420  -->  00:02:53,760
any cardholder data they're processing.
74

74

00:02:53,760  -->  00:02:55,080
You're also going to be responsible
75

75

00:02:55,080  -->  00:02:57,120
for helping to implement the control objectives
76

76

00:02:57,120  -->  00:02:59,790
of the standard such as configuring your firewalls,
77

77

00:02:59,790  -->  00:03:00,810
encrypting the data
78

78

00:03:00,810  -->  00:03:03,480
and implementing strong access control measures.
79

79

00:03:03,480  -->  00:03:04,830
In addition to all of that,
80

80

00:03:04,830  -->  00:03:06,000
as a cybersecurity analyst,
81

81

00:03:06,000  -->  00:03:07,590
you're also responsible for monitoring
82

82

00:03:07,590  -->  00:03:09,840
and testing the organization's security systems,
83

83

00:03:09,840  -->  00:03:11,640
to ensure that they're functioning properly
84

84

00:03:11,640  -->  00:03:14,220
and that any vulnerabilities are identified and addressed
85

85

00:03:14,220  -->  00:03:15,750
in a timely manner.
86

86

00:03:15,750  -->  00:03:17,250
Now one of the most critical aspects
87

87

00:03:17,250  -->  00:03:18,510
for a cybersecurity analyst
88

88

00:03:18,510  -->  00:03:21,000
who's working with PCI DSS is to ensure
89

89

00:03:21,000  -->  00:03:23,790
that the security controls are being implemented correctly
90

90

00:03:23,790  -->  00:03:25,440
and are tested regularly.
91

91

00:03:25,440  -->  00:03:26,370
This includes ensuring
92

92

00:03:26,370  -->  00:03:28,920
that regular vulnerability scans are being performed
93

93

00:03:28,920  -->  00:03:31,020
and those vulnerabilities are tracked
94

94

00:03:31,020  -->  00:03:33,360
and properly patched and remediated.
95

95

00:03:33,360  -->  00:03:35,430
Compliance with the PCI DSS standard
96

96

00:03:35,430  -->  00:03:37,680
is also considered an ongoing process
97

97

00:03:37,680  -->  00:03:39,030
and as a cybersecurity analyst,
98

98

00:03:39,030  -->  00:03:41,640
you have to stay up to date on the late security threats
99

99

00:03:41,640  -->  00:03:42,570
and technologies
100

100

00:03:42,570  -->  00:03:44,580
to ensure your organization's security systems
101

101

00:03:44,580  -->  00:03:47,550
continue to meet the PCI DSS standard.
102

102

00:03:47,550  -->  00:03:49,920
Now whenever you hear PCI DSS,
103

103

00:03:49,920  -->  00:03:51,090
I want you to remember,
104

104

00:03:51,090  -->  00:03:52,530
this has to do with credit cards
105

105

00:03:52,530  -->  00:03:54,450
and sensitive cardholder data
106

106

00:03:54,450  -->  00:03:56,430
that has to be protected.
107

107

00:03:56,430  -->  00:03:58,710
Second, we're going to cover CIS
108

108

00:03:58,710  -->  00:04:00,870
or the Center for Internet Security.
109

109

00:04:00,870  -->  00:04:03,600
Now CIS, or the Center for Internet Security
110

110

00:04:03,600  -->  00:04:05,550
is a nonprofit organization
111

111

00:04:05,550  -->  00:04:07,650
that provides a set of best practice guidelines
112

112

00:04:07,650  -->  00:04:10,500
and security controls for organizations to utilize
113

113

00:04:10,500  -->  00:04:12,900
in order to secure their IT systems.
114

114

00:04:12,900  -->  00:04:15,537
Now CIS controls are a set
115

115

00:04:15,537  -->  00:04:16,620
of 20 different security controls
116

116

00:04:16,620  -->  00:04:19,050
that are organized into three categories.
117

117

00:04:19,050  -->  00:04:22,320
These are basic, foundational and organizational.
118

118

00:04:22,320  -->  00:04:24,780
The basic controls are the first line of defense
119

119

00:04:24,780  -->  00:04:27,000
and they include things like inventorying your hardware
120

120

00:04:27,000  -->  00:04:30,180
and software and maintaining an incident response plan.
121

121

00:04:30,180  -->  00:04:32,220
The foundational controls are going to build
122

122

00:04:32,220  -->  00:04:33,600
on those basic controls
123

123

00:04:33,600  -->  00:04:34,620
and they include activities
124

124

00:04:34,620  -->  00:04:36,900
such as configuring security settings and devices
125

125

00:04:36,900  -->  00:04:38,910
and applying security updates.
126

126

00:04:38,910  -->  00:04:41,910
The organizational controls are the final layer of defense
127

127

00:04:41,910  -->  00:04:43,620
and they include items such as implementing
128

128

00:04:43,620  -->  00:04:45,090
security training programs
129

129

00:04:45,090  -->  00:04:47,640
and conducting regular risk assessments.
130

130

00:04:47,640  -->  00:04:49,740
Now the Center for Internet Security's controls
131

131

00:04:49,740  -->  00:04:52,200
are going to be used by cybersecurity analysts like you,
132

132

00:04:52,200  -->  00:04:53,940
to provide a framework for identifying
133

133

00:04:53,940  -->  00:04:55,500
and addressing potential security risks
134

134

00:04:55,500  -->  00:04:57,240
within your organization.
135

135

00:04:57,240  -->  00:04:59,370
This is a structured approach to security
136

136

00:04:59,370  -->  00:05:00,900
and allows analysts to evaluate
137

137

00:05:00,900  -->  00:05:02,910
the organization's current security posture
138

138

00:05:02,910  -->  00:05:05,250
and identify areas that need improvement.
139

139

00:05:05,250  -->  00:05:06,570
The controls are going to be designed
140

140

00:05:06,570  -->  00:05:08,610
to easily be understood and implemented,
141

141

00:05:08,610  -->  00:05:10,500
and they can be tailored to fit specific needs
142

142

00:05:10,500  -->  00:05:12,030
of your organization.
143

143

00:05:12,030  -->  00:05:14,160
By utilizing the CIS controls,
144

144

00:05:14,160  -->  00:05:16,170
a cybersecurity analyst can better understand
145

145

00:05:16,170  -->  00:05:18,420
the organization's current security posture,
146

146

00:05:18,420  -->  00:05:20,010
develop a security strategy
147

147

00:05:20,010  -->  00:05:21,810
and implement security controls
148

148

00:05:21,810  -->  00:05:23,820
to mitigate potential risks.
149

149

00:05:23,820  -->  00:05:26,760
Now one of the main benefits of using the CIS controls
150

150

00:05:26,760  -->  00:05:28,260
is that they have been developed and tested
151

151

00:05:28,260  -->  00:05:31,320
by security experts from a variety of different industries.
152

152

00:05:31,320  -->  00:05:33,674
Including the government, healthcare and finance.
153

153

00:05:33,674  -->  00:05:36,930
As a result, the controls have been proven to be effective
154

154

00:05:36,930  -->  00:05:39,270
in identifying and mitigating security risks
155

155

00:05:39,270  -->  00:05:41,760
in a variety of different types of organizations.
156

156

00:05:41,760  -->  00:05:43,110
They're also widely recognized
157

157

00:05:43,110  -->  00:05:44,730
as one of the sets of best practices
158

158

00:05:44,730  -->  00:05:46,980
in the field of cybersecurity and they are supported
159

159

00:05:46,980  -->  00:05:48,510
by various government agencies
160

160

00:05:48,510  -->  00:05:50,490
and private sector organizations.
161

161

00:05:50,490  -->  00:05:53,100
So, you may find that you're using the CIS controls
162

162

00:05:53,100  -->  00:05:55,290
in your own organization too.
163

163

00:05:55,290  -->  00:05:57,480
Now when you're analyzing your CIS controls,
164

164

00:05:57,480  -->  00:05:59,910
you're trying to determine your current security posture
165

165

00:05:59,910  -->  00:06:02,880
and then evaluate your adherence to those controls.
166

166

00:06:02,880  -->  00:06:05,130
This allows you to compare the organization's practices
167

167

00:06:05,130  -->  00:06:07,890
and procedures to the recommended CIS controls
168

168

00:06:07,890  -->  00:06:10,200
and determine whether or not your internal processes
169

169

00:06:10,200  -->  00:06:11,430
are adequate.
170

170

00:06:11,430  -->  00:06:12,900
Based on your evaluation,
171

171

00:06:12,900  -->  00:06:14,580
you can then develop a security strategy
172

172

00:06:14,580  -->  00:06:17,130
that's tailored to your specific organizational needs
173

173

00:06:17,130  -->  00:06:19,920
and addresses the vulnerabilities you've identified.
174

174

00:06:19,920  -->  00:06:22,110
Now once you've developed your security strategy,
175

175

00:06:22,110  -->  00:06:24,210
you're then going to begin implementing security controls
176

176

00:06:24,210  -->  00:06:26,760
to mitigate the potential risks you've identified.
177

177

00:06:26,760  -->  00:06:28,590
This may include making recommended changes
178

178

00:06:28,590  -->  00:06:30,780
to your organization's existing security practices
179

179

00:06:30,780  -->  00:06:31,800
and procedures,
180

180

00:06:31,800  -->  00:06:34,320
or you may implement new security controls
181

181

00:06:34,320  -->  00:06:36,450
in addition to what you're already doing.
182

182

00:06:36,450  -->  00:06:38,490
For example, an analyst might recommend
183

183

00:06:38,490  -->  00:06:40,350
that an organization implements a firewall
184

184

00:06:40,350  -->  00:06:42,930
to protect its network from unauthorized access
185

185

00:06:42,930  -->  00:06:44,910
or you might want to encrypt your data
186

186

00:06:44,910  -->  00:06:46,260
to protect it from being intercepted
187

187

00:06:46,260  -->  00:06:47,880
by unauthorized parties.
188

188

00:06:47,880  -->  00:06:49,470
The implementation of these controls
189

189

00:06:49,470  -->  00:06:51,990
is an ongoing process and you as an analyst
190

190

00:06:51,990  -->  00:06:53,880
are going to need to monitor and evaluate them
191

191

00:06:53,880  -->  00:06:56,100
to ensure they're continually being effective
192

192

00:06:56,100  -->  00:06:58,620
in protecting your organization's systems.
193

193

00:06:58,620  -->  00:07:02,010
Now the third thing we need to talk about OWASP
194

194

00:07:02,010  -->  00:07:03,630
which is said as O-WASP
195

195

00:07:03,630  -->  00:07:06,840
or the Open Web Application Security Project.
196

196

00:07:06,840  -->  00:07:09,450
Now OWASP is a nonprofit organization
197

197

00:07:09,450  -->  00:07:12,720
that aims to promote and improve web application security.
198

198

00:07:12,720  -->  00:07:14,160
One of the ways it does this
199

199

00:07:14,160  -->  00:07:15,780
is providing a set of guidelines,
200

200

00:07:15,780  -->  00:07:19,230
tools and best practices for secure software development.
201

201

00:07:19,230  -->  00:07:22,050
These guidelines are known as the OWASP top 10
202

202

00:07:22,050  -->  00:07:24,240
and they're designed to help organizations identify
203

203

00:07:24,240  -->  00:07:25,641
and mitigate
204

204

00:07:25,641  -->  00:07:27,630
the most critical web application security risks.
205

205

00:07:27,630  -->  00:07:29,310
The OWASP top 10 is a list
206

206

00:07:29,310  -->  00:07:32,070
of the 10 most critical web application security risks
207

207

00:07:32,070  -->  00:07:35,340
as identified by the OWASP organization.
208

208

00:07:35,340  -->  00:07:37,680
Now this list is updated every three years
209

209

00:07:37,680  -->  00:07:42,630
and it was updated in 2017 and 2021 and again in 2024.
210

210

00:07:42,630  -->  00:07:44,580
Now even though it is updated every three years,
211

211

00:07:44,580  -->  00:07:47,190
based on the current state of web application security,
212

212

00:07:47,190  -->  00:07:48,780
I can tell you that in general,
213

213

00:07:48,780  -->  00:07:51,570
about 90% of it doesn't change from year to year
214

214

00:07:51,570  -->  00:07:52,770
because most of these things
215

215

00:07:52,770  -->  00:07:54,420
are the same things we've been dealing with
216

216

00:07:54,420  -->  00:07:56,550
for lots and lots of years.
217

217

00:07:56,550  -->  00:07:58,260
Let's take a look at a couple of these.
218

218

00:07:58,260  -->  00:07:59,520
Injection attacks,
219

219

00:07:59,520  -->  00:08:01,890
broken authentication and session management,
220

220

00:08:01,890  -->  00:08:04,830
cross-site scripting, broken access control,
221

221

00:08:04,830  -->  00:08:08,280
security misconfiguration, sensitive data exposure,
222

222

00:08:08,280  -->  00:08:09,990
insufficient cryptography,
223

223

00:08:09,990  -->  00:08:11,760
insufficient security testing,
224

224

00:08:11,760  -->  00:08:15,570
improper error handling, lack of infrastructure security,
225

225

00:08:15,570  -->  00:08:18,030
all of these are things that are very generic in nature
226

226

00:08:18,030  -->  00:08:20,790
and that's why it doesn't change much from year to year.
227

227

00:08:20,790  -->  00:08:22,320
Now as a cybersecurity analyst,
228

228

00:08:22,320  -->  00:08:25,020
you play a critical role in helping your organization
229

229

00:08:25,020  -->  00:08:27,240
address all these different risks.
230

230

00:08:27,240  -->  00:08:28,073
These are things
231

231

00:08:28,073  -->  00:08:29,790
that we're going to be responsible for analyzing
232

232

00:08:29,790  -->  00:08:31,140
to ensure that our organization's
233

233

00:08:31,140  -->  00:08:32,940
custom-built web applications
234

234

00:08:32,940  -->  00:08:35,220
aren't vulnerable to these types of attacks.
235

235

00:08:35,220  -->  00:08:36,630
As a cybersecurity analyst,
236

236

00:08:36,630  -->  00:08:38,790
you're also going to be responsible to help implement controls
237

237

00:08:38,790  -->  00:08:40,473
to mitigate all of these risks.
238

238

00:08:41,393  -->  00:08:42,540
For instance, you'll want to make sure you're doing things
239

239

00:08:42,540  -->  00:08:45,570
like input validation, encryption, access control,
240

240

00:08:45,570  -->  00:08:48,870
implementing web application firewalls and things like that.
241

241

00:08:48,870  -->  00:08:50,070
In addition to all of that,
242

242

00:08:50,070  -->  00:08:52,230
a cybersecurity analyst is also responsible
243

243

00:08:52,230  -->  00:08:54,330
for monitoring and testing web applications
244

244

00:08:54,330  -->  00:08:56,490
to ensure that the vulnerabilities that were identified
245

245

00:08:56,490  -->  00:08:58,470
are addressed in a timely manner.
246

246

00:08:58,470  -->  00:08:59,370
They're also going to make sure
247

247

00:08:59,370  -->  00:09:01,200
we're ensuring the web application security
248

248

00:09:01,200  -->  00:09:02,844
is considered throughout
249

249

00:09:02,844  -->  00:09:04,200
the entire software development life cycle,
250

250

00:09:04,200  -->  00:09:06,330
known as the SDLC.
251

251

00:09:06,330  -->  00:09:08,580
Another important aspect for a cybersecurity analyst
252

252

00:09:08,580  -->  00:09:09,780
working with OWASP,
253

253

00:09:09,780  -->  00:09:11,810
is it ensure that they are aware
254

254

00:09:11,810  -->  00:09:12,643
of all of the latest vulnerabilities
255

255

00:09:12,643  -->  00:09:14,790
and attack trends because this helps you to identify
256

256

00:09:14,790  -->  00:09:16,950
potential threats and come up with a strategy
257

257

00:09:16,950  -->  00:09:19,170
to prevent those threats from being realized
258

258

00:09:19,170  -->  00:09:20,880
in your organization.
259

259

00:09:20,880  -->  00:09:22,680
Security testing and penetration testing
260

260

00:09:22,680  -->  00:09:25,470
are also critical roles to help an analyst identify
261

261

00:09:25,470  -->  00:09:27,450
those vulnerabilities and then track them
262

262

00:09:27,450  -->  00:09:29,340
until they're fully remediated.
263

263

00:09:29,340  -->  00:09:32,730
Now fourth, we have ISO 27000.
264

264

00:09:32,730  -->  00:09:35,760
Now the ISO 27000 series of standards
265

265

00:09:35,760  -->  00:09:37,151
was created
266

266

00:09:37,151  -->  00:09:39,800
by the International Organization for Standardization,
267

267

00:09:39,800  -->  00:09:41,340
known as ISO and it's used to provide
268

268

00:09:41,340  -->  00:09:44,070
a framework for managing information security.
269

269

00:09:44,070  -->  00:09:46,553
This standard provides guidelines and general practices
270

270

00:09:46,553  -->  00:09:48,330
for initiating, implementing,
271

271

00:09:48,330  -->  00:09:51,060
maintaining and improving information security management
272

272

00:09:51,060  -->  00:09:52,503
within your organization.
273

273

00:09:53,697  -->  00:09:55,230
It also is used to provide a set of best practices
274

274

00:09:55,230  -->  00:09:57,269
for establishing and maintaining
275

275

00:09:57,269  -->  00:09:58,800
and information security management system.
276

276

00:09:58,800  -->  00:10:02,400
Now the main standard inside the ISO 27000 family
277

277

00:10:02,400  -->  00:10:06,900
is called the ISO/IEC 27001.
278

278

00:10:06,900  -->  00:10:09,300
And this is a standard that specifies the requirements
279

279

00:10:09,300  -->  00:10:11,520
for an information security management system
280

280

00:10:11,520  -->  00:10:13,230
and it's designed to be used in conjunction
281

281

00:10:13,230  -->  00:10:17,100
with other standards inside that ISO 27000 series.
282

282

00:10:17,100  -->  00:10:20,730
Such as the ISO/IEC 27002
283

283

00:10:20,730  -->  00:10:22,140
which provides a code of practice
284

284

00:10:22,140  -->  00:10:24,300
for information security management.
285

285

00:10:24,300  -->  00:10:28,650
Now the ISO/IEC 27001 specifies the requirements
286

286

00:10:28,650  -->  00:10:30,990
for an information security management system
287

287

00:10:30,990  -->  00:10:32,580
in three main areas.
288

288

00:10:32,580  -->  00:10:34,890
Policies, procedures and responsibilities
289

289

00:10:34,890  -->  00:10:37,740
and organizational structure and management.
290

290

00:10:37,740  -->  00:10:39,210
Now organizations are required
291

291

00:10:39,210  -->  00:10:40,770
to establish a set of policies
292

292

00:10:40,770  -->  00:10:42,600
that outline the objectives and principles
293

293

00:10:42,600  -->  00:10:45,000
of their information security management system.
294

294

00:10:45,000  -->  00:10:47,460
Then, they need to define the roles and responsibilities
295

295

00:10:47,460  -->  00:10:49,860
of those involved in the system and finally,
296

296

00:10:49,860  -->  00:10:51,150
they need to describe the procedures
297

297

00:10:51,150  -->  00:10:52,620
that must be followed to implement
298

298

00:10:52,620  -->  00:10:54,540
and maintain that system.
299

299

00:10:54,540  -->  00:10:57,030
This standard also requires organizations to implement
300

300

00:10:57,030  -->  00:11:00,150
a set of controls to protect their information assets.
301

301

00:11:00,150  -->  00:11:03,060
These controls are divided into two main categories,
302

302

00:11:03,060  -->  00:11:05,130
technical and organizational.
303

303

00:11:05,130  -->  00:11:07,860
Now technical controls include measures such as encryption
304

304

00:11:07,860  -->  00:11:08,760
and firewalls,
305

305

00:11:08,760  -->  00:11:10,860
while organizational controls include measures
306

306

00:11:10,860  -->  00:11:13,620
such as access controls and incident management.
307

307

00:11:13,620  -->  00:11:15,210
Now one of the most important aspects
308

308

00:11:15,210  -->  00:11:17,640
that you as a cybersecurity analyst may be working with
309

309

00:11:17,640  -->  00:11:20,250
inside of the ISO 2700 is to ensure
310

310

00:11:20,250  -->  00:11:21,360
that the organization has
311

311

00:11:21,360  -->  00:11:23,970
a robust incident management process in place
312

312

00:11:23,970  -->  00:11:26,610
and this ensures that in case of a security incident,
313

313

00:11:26,610  -->  00:11:29,160
your organization is going to be able to identify,
314

314

00:11:29,160  -->  00:11:30,660
contain and recover from it
315

315

00:11:30,660  -->  00:11:32,790
in a timely and effective manner.
316

316

00:11:32,790  -->  00:11:35,790
Now compliance with the ISO 27000 series
317

317

00:11:35,790  -->  00:11:37,410
does require organizations to keep
318

318

00:11:37,410  -->  00:11:39,390
a lot of documentation which can be used
319

319

00:11:39,390  -->  00:11:42,060
to show evidence of compliance during an audit.
320

320

00:11:42,060  -->  00:11:43,890
Cybersecurity analysts will also need to work
321

321

00:11:43,890  -->  00:11:45,690
with other departments to ensure they can meet
322

322

00:11:45,690  -->  00:11:47,310
any of those compliance requirements
323

323

00:11:47,310  -->  00:11:48,720
and document that you're following
324

324

00:11:48,720  -->  00:11:50,550
those compliance requirements.
325

325

00:11:50,550  -->  00:11:54,150
Our fifth framework we're going to cover is the OSS TMM
326

326

00:11:54,150  -->  00:11:57,480
or the Open Source Software Testing Maturity Model.
327

327

00:11:57,480  -->  00:12:00,030
Now the Open Source Software Testing Maturity Model
328

328

00:12:00,030  -->  00:12:01,440
is a framework for evaluating
329

329

00:12:01,440  -->  00:12:04,080
and improving the quality of open source software
330

330

00:12:04,080  -->  00:12:05,940
and its testing processes.
331

331

00:12:05,940  -->  00:12:07,590
This was developed by OWASP,
332

332

00:12:07,590  -->  00:12:09,930
the Open Web Application Security Project
333

333

00:12:09,930  -->  00:12:12,394
and it provides a set of best practices
334

334

00:12:12,394  -->  00:12:13,350
for testing open source software
335

335

00:12:13,350  -->  00:12:15,480
for security vulnerabilities.
336

336

00:12:15,480  -->  00:12:16,830
Now the Open Source Software
337

337

00:12:16,830  -->  00:12:18,570
Testing Maturity Model framework
338

338

00:12:18,570  -->  00:12:20,550
is designed to help organizations understand
339

339

00:12:20,550  -->  00:12:23,430
their current level of open source software testing maturity
340

340

00:12:23,430  -->  00:12:24,510
and to identify areas
341

341

00:12:24,510  -->  00:12:26,880
where they can improve their testing processes.
342

342

00:12:26,880  -->  00:12:29,700
The framework defines five levels of testing maturity,
343

343

00:12:29,700  -->  00:12:32,460
each with its own set of goals and best practices.
344

344

00:12:32,460  -->  00:12:35,850
These levels are initial, managed, defined,
345

345

00:12:35,850  -->  00:12:38,640
quantitatively managed and optimizing.
346

346

00:12:38,640  -->  00:12:40,290
Initial means that the organization
347

347

00:12:40,290  -->  00:12:42,810
is just starting to use the open source software
348

348

00:12:42,810  -->  00:12:45,660
and has no established testing processes in place.
349

349

00:12:45,660  -->  00:12:47,790
Managed means the organization has established
350

350

00:12:47,790  -->  00:12:50,700
basic testing processes for the open source software
351

351

00:12:50,700  -->  00:12:52,470
but they're not yet formalized
352

352

00:12:52,470  -->  00:12:55,440
or fully integrated into their development processes.
353

353

00:12:55,440  -->  00:12:57,270
Defined means that the organization
354

354

00:12:57,270  -->  00:13:00,120
has formalized testing processes for open source software
355

355

00:13:00,120  -->  00:13:02,310
that are integrated into the development process
356

356

00:13:02,310  -->  00:13:05,340
but they're not yet consistently applied.
357

357

00:13:05,340  -->  00:13:06,810
Quantitatively managed
358

358

00:13:06,810  -->  00:13:08,790
means the organization consistently applies
359

359

00:13:08,790  -->  00:13:11,550
formalized testing processes for open source software
360

360

00:13:11,550  -->  00:13:13,800
and uses metrics to measure the effectiveness
361

361

00:13:13,800  -->  00:13:17,250
of that testing process and finally, optimizing.
362

362

00:13:17,250  -->  00:13:19,470
This means that organization continually improves
363

363

00:13:19,470  -->  00:13:21,750
its open source software testing processes
364

364

00:13:21,750  -->  00:13:24,030
based on metrics and other data.
365

365

00:13:24,030  -->  00:13:25,920
Now as a cybersecurity analyst,
366

366

00:13:25,920  -->  00:13:29,100
your job here is to help organizations reach higher levels
367

367

00:13:29,100  -->  00:13:31,560
of open source software testing maturity.
368

368

00:13:31,560  -->  00:13:32,940
We're responsible for analyzing
369

369

00:13:32,940  -->  00:13:35,637
the organization's open source software testing process
370

370

00:13:35,637  -->  00:13:38,640
and identifying areas where improvements could be made.
371

371

00:13:38,640  -->  00:13:40,590
You'll also be responsible to help implement
372

372

00:13:40,590  -->  00:13:41,970
the best practices outlined
373

373

00:13:41,970  -->  00:13:45,330
in the open source software testing maturity model framework
374

374

00:13:45,330  -->  00:13:47,400
such as formalizing testing processes,
375

375

00:13:47,400  -->  00:13:49,620
integrating testing into the development process
376

376

00:13:49,620  -->  00:13:51,600
and using metrics to measure the effectiveness
377

377

00:13:51,600  -->  00:13:53,280
of the testing process.
378

378

00:13:53,280  -->  00:13:54,570
In addition to all of that,
379

379

00:13:54,570  -->  00:13:56,250
you'll also be responsible for monitoring
380

380

00:13:56,250  -->  00:13:57,930
and testing open source software
381

381

00:13:57,930  -->  00:13:59,760
to ensure that vulnerabilities are identified
382

382

00:13:59,760  -->  00:14:01,890
and addressed in a timely manner.
383

383

00:14:01,890  -->  00:14:03,270
Now the open source software
384

384

00:14:03,270  -->  00:14:05,910
testing maturity model framework is really important
385

385

00:14:05,910  -->  00:14:07,830
for cybersecurity analysts because it provides us
386

386

00:14:07,830  -->  00:14:10,170
with a clear set of goals and best practices
387

387

00:14:10,170  -->  00:14:12,120
for testing this open source software
388

388

00:14:12,120  -->  00:14:14,130
for different security vulnerabilities.
389

389

00:14:14,130  -->  00:14:15,450
By following the framework,
390

390

00:14:15,450  -->  00:14:16,980
we can ensure that our organizations
391

391

00:14:16,980  -->  00:14:19,350
are applying best practices for software testing
392

392

00:14:19,350  -->  00:14:21,480
and if they're identifying and mitigating vulnerabilities
393

393

00:14:21,480  -->  00:14:23,250
in a more timely manner.
394

394

00:14:23,250  -->  00:14:24,300
This is really important,
395

395

00:14:24,300  -->  00:14:27,030
given the rapid growing use of open source software
396

396

00:14:27,030  -->  00:14:29,070
in many of our organizations.
397

397

00:14:29,070  -->  00:14:31,680
With the increasing reliance on open source software,
398

398

00:14:31,680  -->  00:14:33,060
organizations can be exposed
399

399

00:14:33,060  -->  00:14:34,770
to more risks and vulnerabilities
400

400

00:14:34,770  -->  00:14:36,090
and so the open source software
401

401

00:14:36,090  -->  00:14:37,740
testing maturity model framework
402

402

00:14:37,740  -->  00:14:39,060
is going to help our organizations
403

403

00:14:39,060  -->  00:14:41,250
to test their open source software libraries
404

404

00:14:41,250  -->  00:14:43,920
for more vulnerabilities and then validate the software
405

405

00:14:43,920  -->  00:14:46,890
is secure for usage inside of our organizations.
406

406

00:14:46,890  -->  00:14:49,446
Now I know that was a lot of information we just discussed
407

407

00:14:49,446  -->  00:14:51,870
about the five different industry frameworks
408

408

00:14:51,870  -->  00:14:56,390
including PCI DSS, CIS, OWASP, ISO 27000
409

409

00:14:56,390  -->  00:14:59,400
and the OSS TMM frameworks.
410

410

00:14:59,400  -->  00:15:00,330
Now for the exam,
411

411

00:15:00,330  -->  00:15:01,163
you do not need to know
412

412

00:15:01,163  -->  00:15:03,180
these five industry frameworks in depth,
413

413

00:15:03,180  -->  00:15:05,880
but you should be aware of the basics for each one
414

414

00:15:05,880  -->  00:15:06,870
and how they're related to
415

415

00:15:06,870  -->  00:15:08,400
your vulnerability management program
416

416

00:15:08,400  -->  00:15:09,963
inside of an organization.
