1
1

00:00:00,450  -->  00:00:02,880
<v Instructor>Continuous monitoring.</v>
2

2

00:00:02,880  -->  00:00:06,270
Now, in every organization, we do some kind of monitoring.
3

3

00:00:06,270  -->  00:00:09,660
Unfortunately, not all of us do continuous monitoring.
4

4

00:00:09,660  -->  00:00:12,960
Oftentimes, an organization may take weekly measurements
5

5

00:00:12,960  -->  00:00:14,190
or monthly measurements,
6

6

00:00:14,190  -->  00:00:16,500
or they'll rely on assessment once a year.
7

7

00:00:16,500  -->  00:00:18,600
That is not continuous monitoring,
8

8

00:00:18,600  -->  00:00:20,640
that is monitoring over time,
9

9

00:00:20,640  -->  00:00:22,530
and it's not nearly as effective.
10

10

00:00:22,530  -->  00:00:25,620
So instead, we want to focus on doing continuous monitoring.
11

11

00:00:25,620  -->  00:00:27,690
This is the technique of constantly evaluating
12

12

00:00:27,690  -->  00:00:29,400
an environment for changes.
13

13

00:00:29,400  -->  00:00:32,040
That way new risk can be more quickly detected
14

14

00:00:32,040  -->  00:00:34,980
and business operations can be improved upon.
15

15

00:00:34,980  -->  00:00:36,330
By doing continuous monitoring,
16

16

00:00:36,330  -->  00:00:38,190
we are constantly looking at our systems
17

17

00:00:38,190  -->  00:00:40,230
and figuring out exactly what they're doing
18

18

00:00:40,230  -->  00:00:42,240
and what they're reporting to us.
19

19

00:00:42,240  -->  00:00:44,610
Now, continuous monitoring is an ongoing effort
20

20

00:00:44,610  -->  00:00:47,190
to obtain information that is vital in managing risk
21

21

00:00:47,190  -->  00:00:48,960
within your organization.
22

22

00:00:48,960  -->  00:00:50,760
It has a lot of benefits.
23

23

00:00:50,760  -->  00:00:53,010
For instance, by doing continuous monitoring
24

24

00:00:53,010  -->  00:00:55,320
you're going to gain more situational awareness.
25

25

00:00:55,320  -->  00:00:57,060
You'll know what systems are in use,
26

26

00:00:57,060  -->  00:00:58,380
what systems are having issues
27

27

00:00:58,380  -->  00:01:00,570
and how you can act on those quicker.
28

28

00:01:00,570  -->  00:01:02,460
Another benefit of continuous monitoring
29

29

00:01:02,460  -->  00:01:05,130
is you have the ability to do routine audits
30

30

00:01:05,130  -->  00:01:06,180
because you don't have to wait
31

31

00:01:06,180  -->  00:01:08,430
for a quarterly or an annual assessment.
32

32

00:01:08,430  -->  00:01:10,470
You can do an audit whenever you need to.
33

33

00:01:10,470  -->  00:01:12,600
You can pull out the logs from that system.
34

34

00:01:12,600  -->  00:01:14,730
You can generate automated logs in that system
35

35

00:01:14,730  -->  00:01:16,050
and pull out that information
36

36

00:01:16,050  -->  00:01:18,570
and do the audit anytime you want.
37

37

00:01:18,570  -->  00:01:21,090
Additionally, you can have realtime analysis
38

38

00:01:21,090  -->  00:01:22,710
by doing continuous monitoring.
39

39

00:01:22,710  -->  00:01:24,750
By continually monitoring those systems,
40

40

00:01:24,750  -->  00:01:26,850
you're going to be able to do that realtime analysis
41

41

00:01:26,850  -->  00:01:29,220
and see those alerts when things happen.
42

42

00:01:29,220  -->  00:01:31,560
Instead of looking back a week, two weeks,
43

43

00:01:31,560  -->  00:01:33,540
a month or even six months later,
44

44

00:01:33,540  -->  00:01:36,090
you're getting realtime analysis when things happen
45

45

00:01:36,090  -->  00:01:38,940
and that helps minimize your risk posture too.
46

46

00:01:38,940  -->  00:01:40,110
Now, continuous monitoring
47

47

00:01:40,110  -->  00:01:42,480
can help transform your organization
48

48

00:01:42,480  -->  00:01:46,350
from using reactive processes into proactive processes.
49

49

00:01:46,350  -->  00:01:48,930
This way, you can get out ahead of these incidents
50

50

00:01:48,930  -->  00:01:51,930
and you can figure out what's going on much more quickly.
51

51

00:01:51,930  -->  00:01:54,090
Now, one of the things I see a lot of organizations do
52

52

00:01:54,090  -->  00:01:56,640
with continuous monitoring that is a bad thing
53

53

00:01:56,640  -->  00:01:58,920
is they rely way too much on metrics
54

54

00:01:58,920  -->  00:02:01,500
and don't have the metrics properly defined.
55

55

00:02:01,500  -->  00:02:02,910
When you're looking at metrics
56

56

00:02:02,910  -->  00:02:05,070
and you start setting up things like a SIEM,
57

57

00:02:05,070  -->  00:02:07,290
that can have lots of different information
58

58

00:02:07,290  -->  00:02:08,400
being sent into it,
59

59

00:02:08,400  -->  00:02:10,380
but it's not necessarily a continuous monitoring
60

60

00:02:10,380  -->  00:02:12,390
if nobody's looking at that data.
61

61

00:02:12,390  -->  00:02:15,390
So a lot of organizations will set up a dashboard.
62

62

00:02:15,390  -->  00:02:16,620
If you're going to do that,
63

63

00:02:16,620  -->  00:02:18,660
you need to make sure that data is being sent in
64

64

00:02:18,660  -->  00:02:20,880
and it's being analyzed and assessed.
65

65

00:02:20,880  -->  00:02:23,070
This way, you can create actionable metrics
66

66

00:02:23,070  -->  00:02:25,950
that represent your risk to your organization.
67

67

00:02:25,950  -->  00:02:28,410
Because certain metrics might be easy to collect,
68

68

00:02:28,410  -->  00:02:30,540
but they may not actually tell you anything valuable
69

69

00:02:30,540  -->  00:02:32,430
about the security of your network.
70

70

00:02:32,430  -->  00:02:34,170
So you want to make sure whatever you're using
71

71

00:02:34,170  -->  00:02:36,600
is your metrics, these are things you've thought about
72

72

00:02:36,600  -->  00:02:39,360
and they're actually going to have benefit to your organization
73

73

00:02:39,360  -->  00:02:41,640
because if you're collecting data just to collect data
74

74

00:02:41,640  -->  00:02:44,190
you're really not doing continuous monitoring.
75

75

00:02:44,190  -->  00:02:45,870
Now, an effective implementation
76

76

00:02:45,870  -->  00:02:47,970
and maintenance of a continuous modern capability
77

77

00:02:47,970  -->  00:02:50,400
is complex and time consuming,
78

78

00:02:50,400  -->  00:02:52,500
and that's why a lot of people don't do it.
79

79

00:02:52,500  -->  00:02:53,333
For instance,
80

80

00:02:53,333  -->  00:02:56,130
if you want to have 24/7 coverage of your system,
81

81

00:02:56,130  -->  00:02:59,280
that means you have to have people who are working 24/7
82

82

00:02:59,280  -->  00:03:00,600
and that costs money.
83

83

00:03:00,600  -->  00:03:02,130
And so these are things you have to think about
84

84

00:03:02,130  -->  00:03:05,280
in your organization is do you need continuous monitoring?
85

85

00:03:05,280  -->  00:03:07,380
And if so, how many hours a day
86

86

00:03:07,380  -->  00:03:09,570
are you continuously going to be monitoring?
87

87

00:03:09,570  -->  00:03:11,610
If you're only going to have people there from nine to five
88

88

00:03:11,610  -->  00:03:13,200
that's only eight hours a day,
89

89

00:03:13,200  -->  00:03:15,420
you're missing 16 hours a day, so you're really
90

90

00:03:15,420  -->  00:03:17,580
not doing continuous monitoring in that case.
91

91

00:03:17,580  -->  00:03:20,250
But if your organization determines that's okay
92

92

00:03:20,250  -->  00:03:21,840
and you're willing to accept that risk
93

93

00:03:21,840  -->  00:03:23,340
because of your risk appetite,
94

94

00:03:23,340  -->  00:03:24,780
that is something you can consider.
95

95

00:03:24,780  -->  00:03:26,220
So these are the things you have to weigh
96

96

00:03:26,220  -->  00:03:28,470
and it's all a risk management decision.
97

97

00:03:28,470  -->  00:03:29,490
Now, one of the things that's come
98

98

00:03:29,490  -->  00:03:31,860
out recently from the US Department of Homeland Security
99

99

00:03:31,860  -->  00:03:34,170
is a program known as CDM.
100

100

00:03:34,170  -->  00:03:37,380
This stands for the Continuous Diagnostics and Mitigation.
101

101

00:03:37,380  -->  00:03:39,540
Now, it is required by the US government
102

102

00:03:39,540  -->  00:03:42,030
that governmental agencies adopt a program
103

103

00:03:42,030  -->  00:03:44,160
of continuous security monitoring,
104

104

00:03:44,160  -->  00:03:46,440
and to do that a lot of them are using CDM.
105

105

00:03:46,440  -->  00:03:48,540
So it's important for you to understand this.
106

106

00:03:48,540  -->  00:03:50,130
A lot of us who work in cybersecurity
107

107

00:03:50,130  -->  00:03:52,770
do work for the government or for a government contractor
108

108

00:03:52,770  -->  00:03:56,370
and so you may be using CDM in the real world as well.
109

109

00:03:56,370  -->  00:03:58,980
Now, CDM is going to provide us government agencies
110

110

00:03:58,980  -->  00:04:01,080
and departments with capabilities and tools
111

111

00:04:01,080  -->  00:04:04,590
to identify cybersecurity risks on an ongoing basis.
112

112

00:04:04,590  -->  00:04:06,060
They're then going to prioritize these risks
113

113

00:04:06,060  -->  00:04:07,650
based on the potential impacts
114

114

00:04:07,650  -->  00:04:09,360
and enable cybersecurity personnel
115

115

00:04:09,360  -->  00:04:12,300
to mitigate the most significant problems first,
116

116

00:04:12,300  -->  00:04:14,313
that is the whole concept of CDM.
117

117

00:04:15,210  -->  00:04:17,070
Now, if you log in to look at CDM
118

118

00:04:17,070  -->  00:04:19,980
normally the first thing you're going to see is a dashboard.
119

119

00:04:19,980  -->  00:04:22,410
This dashboard is going to aggregate data
120

120

00:04:22,410  -->  00:04:25,080
and display it in a way that is useful for people
121

121

00:04:25,080  -->  00:04:27,630
at the agency and federal levels to make sense of.
122

122

00:04:27,630  -->  00:04:29,310
This gives them that situational awareness
123

123

00:04:29,310  -->  00:04:30,570
we're talking about.
124

124

00:04:30,570  -->  00:04:32,910
Then inside of that, we have different tiers.
125

125

00:04:32,910  -->  00:04:34,830
Underneath that we have asset management.
126

126

00:04:34,830  -->  00:04:37,290
This helps answer the question, what is on our network?
127

127

00:04:37,290  -->  00:04:38,550
We have to know what's on the network
128

128

00:04:38,550  -->  00:04:40,230
so we can secure it, right?
129

129

00:04:40,230  -->  00:04:42,870
Then inside of that, we have who is on the network?
130

130

00:04:42,870  -->  00:04:45,330
Which is identity and access management.
131

131

00:04:45,330  -->  00:04:46,290
Then we start thinking about
132

132

00:04:46,290  -->  00:04:47,730
what is happening on the network?
133

133

00:04:47,730  -->  00:04:49,830
And that's network security management.
134

134

00:04:49,830  -->  00:04:51,210
And then finally, we start thinking
135

135

00:04:51,210  -->  00:04:52,950
about how is our data protected?
136

136

00:04:52,950  -->  00:04:55,530
And that is done through data protection management.
137

137

00:04:55,530  -->  00:04:56,850
Each of these circles
138

138

00:04:56,850  -->  00:04:59,460
is comprised of different systems and sensors
139

139

00:04:59,460  -->  00:05:00,840
that aggregate data together
140

140

00:05:00,840  -->  00:05:03,990
and then roll that up into this overall dashboard
141

141

00:05:03,990  -->  00:05:06,870
so that managers, analysts and executives
142

142

00:05:06,870  -->  00:05:08,160
can look at that information
143

143

00:05:08,160  -->  00:05:10,060
and know the status of their networks.
