1
1

00:00:00,360  -->  00:00:02,400
<v Narrator>Scanning workflow.</v>
2

2

00:00:02,400  -->  00:00:04,050
In this lesson, we're going to talk
3

3

00:00:04,050  -->  00:00:07,080
about the basic assessment scan workflow.
4

4

00:00:07,080  -->  00:00:09,570
Now, before you start doing your assessment scans
5

5

00:00:09,570  -->  00:00:10,403
there are lots
6

6

00:00:10,403  -->  00:00:12,240
of different questions that you have to answer
7

7

00:00:12,240  -->  00:00:13,800
and this will make sure you're ready to conduct
8

8

00:00:13,800  -->  00:00:15,540
that vulnerability scan.
9

9

00:00:15,540  -->  00:00:17,940
These are things like who is going to conduct the scan?
10

10

00:00:17,940  -->  00:00:20,100
Because you need to know which person's going to do it.
11

11

00:00:20,100  -->  00:00:21,690
Is it going to be assistant administrator,
12

12

00:00:21,690  -->  00:00:22,860
an internal employee,
13

13

00:00:22,860  -->  00:00:25,500
an external employee, who's going to do it?
14

14

00:00:25,500  -->  00:00:28,290
Then you need to answer when will the scan be performed?
15

15

00:00:28,290  -->  00:00:31,290
Because you can't just conduct the scan anytime you want.
16

16

00:00:31,290  -->  00:00:32,160
When you do a scan
17

17

00:00:32,160  -->  00:00:34,200
it puts additional load on the network
18

18

00:00:34,200  -->  00:00:35,850
and on the resources that you're targeting
19

19

00:00:35,850  -->  00:00:37,943
as part of your scan. And so if you do this
20

20

00:00:37,943  -->  00:00:40,080
at the primetime during the middle of the day
21

21

00:00:40,080  -->  00:00:42,540
you can actually crash your own network by doing it.
22

22

00:00:42,540  -->  00:00:43,710
So you have to make sure you figure out
23

23

00:00:43,710  -->  00:00:46,110
when is the right time to perform that scan.
24

24

00:00:46,110  -->  00:00:48,840
Also, which systems are going to be scanned?
25

25

00:00:48,840  -->  00:00:50,880
Are you going to scan everything on the network
26

26

00:00:50,880  -->  00:00:52,290
and are you going to do 'em all equally
27

27

00:00:52,290  -->  00:00:55,140
or are you going to divide this up into smaller pieces?
28

28

00:00:55,140  -->  00:00:57,300
This is an important question for you to answer.
29

29

00:00:57,300  -->  00:00:59,040
Another question you have to ask yourself is
30

30

00:00:59,040  -->  00:01:01,560
how will scanning impact the systems?
31

31

00:01:01,560  -->  00:01:04,140
As I just said, when you scan these systems
32

32

00:01:04,140  -->  00:01:06,660
some of them are going to have additional load placed on them
33

33

00:01:06,660  -->  00:01:09,840
by these scans, and if you're doing a very in-depth scan
34

34

00:01:09,840  -->  00:01:11,340
you can actually put additional load
35

35

00:01:11,340  -->  00:01:14,790
on those systems that eats up memory or processor resources
36

36

00:01:14,790  -->  00:01:16,380
and that can crash those systems.
37

37

00:01:16,380  -->  00:01:19,080
So you need to be careful when doing scanning as well.
38

38

00:01:19,080  -->  00:01:20,760
Another question we want to ask ourself is
39

39

00:01:20,760  -->  00:01:24,060
does the system need to be isolated during the scanning?
40

40

00:01:24,060  -->  00:01:26,010
Now, why is this important to ask?
41

41

00:01:26,010  -->  00:01:27,990
Well, again, because you have to know how
42

42

00:01:27,990  -->  00:01:30,900
the system is going to respond when you do these scans.
43

43

00:01:30,900  -->  00:01:33,030
When I ask about should I isolate the system
44

44

00:01:33,030  -->  00:01:34,470
the question here is really
45

45

00:01:34,470  -->  00:01:36,330
can I scan it while it's in production?
46

46

00:01:36,330  -->  00:01:37,470
Or do I need to take it off
47

47

00:01:37,470  -->  00:01:40,170
of doing a real world job so I can scan it
48

48

00:01:40,170  -->  00:01:42,720
and then put it back into the real world environment?
49

49

00:01:42,720  -->  00:01:44,250
This is an important thing to consider because
50

50

00:01:44,250  -->  00:01:47,310
it's going to have real world consequences to those actions.
51

51

00:01:47,310  -->  00:01:50,070
And finally, who can assist you with scanning?
52

52

00:01:50,070  -->  00:01:52,320
Now, I don't mean who's going to be your assistant here,
53

53

00:01:52,320  -->  00:01:53,940
but if you start scanning a system
54

54

00:01:53,940  -->  00:01:56,010
and you start seeing things that look unusual
55

55

00:01:56,010  -->  00:01:57,570
who are you going to ask for help?
56

56

00:01:57,570  -->  00:01:58,950
If I'm scanning the web server
57

57

00:01:58,950  -->  00:02:00,810
I probably want to talk to the web developer.
58

58

00:02:00,810  -->  00:02:02,160
If I'm scanning a database
59

59

00:02:02,160  -->  00:02:04,080
I might want to ask the database administrator.
60

60

00:02:04,080  -->  00:02:05,700
This is the idea of who can assist you
61

61

00:02:05,700  -->  00:02:07,890
if you have problems during scanning.
62

62

00:02:07,890  -->  00:02:09,450
Now, all of this then allows us to
63

63

00:02:09,450  -->  00:02:12,180
start creating what will be our workflow.
64

64

00:02:12,180  -->  00:02:14,040
As we start thinking about our workflow
65

65

00:02:14,040  -->  00:02:15,870
and we have the answers from these questions
66

66

00:02:15,870  -->  00:02:18,240
we can develop our own processes.
67

67

00:02:18,240  -->  00:02:20,466
Now, for example, here is going to be a simple
68

68

00:02:20,466  -->  00:02:22,770
seven step process that we're going to walk through
69

69

00:02:22,770  -->  00:02:24,000
in this lesson.
70

70

00:02:24,000  -->  00:02:26,130
You don't have to follow this step by step though.
71

71

00:02:26,130  -->  00:02:29,220
This does not mean that this is the only way to do scanning.
72

72

00:02:29,220  -->  00:02:31,740
This is just an example for you to consider.
73

73

00:02:31,740  -->  00:02:33,720
First, we want to install the software
74

74

00:02:33,720  -->  00:02:36,330
and patches to establish a baseline system.
75

75

00:02:36,330  -->  00:02:37,890
So I have a brand new server.
76

76

00:02:37,890  -->  00:02:39,300
I installed the operating system,
77

77

00:02:39,300  -->  00:02:41,670
I installed the antivirus, I configured it.
78

78

00:02:41,670  -->  00:02:43,680
I installed all the software patches and updates,
79

79

00:02:43,680  -->  00:02:46,200
and now that system is what I think
80

80

00:02:46,200  -->  00:02:47,820
a good system should look like.
81

81

00:02:47,820  -->  00:02:49,920
At this point, I should move into my second step
82

82

00:02:49,920  -->  00:02:53,010
which is to perform an initial scan of that target system.
83

83

00:02:53,010  -->  00:02:54,240
So I have this brand new system
84

84

00:02:54,240  -->  00:02:56,220
with everything I just installed and patched
85

85

00:02:56,220  -->  00:02:59,520
I'm going to run a scan and that creates my baseline for me.
86

86

00:02:59,520  -->  00:03:00,690
Everything else will be compared
87

87

00:03:00,690  -->  00:03:02,760
against this baseline moving forward.
88

88

00:03:02,760  -->  00:03:04,560
Now, the third step I'm going to do is analyze
89

89

00:03:04,560  -->  00:03:05,940
the assessment reports based
90

90

00:03:05,940  -->  00:03:07,800
on that baseline I just created.
91

91

00:03:07,800  -->  00:03:11,220
So I installed all the software, I scanned that target
92

92

00:03:11,220  -->  00:03:12,360
and now I'm going to go
93

93

00:03:12,360  -->  00:03:14,790
through the report and see what the findings were.
94

94

00:03:14,790  -->  00:03:16,500
Was everything installed properly?
95

95

00:03:16,500  -->  00:03:17,400
Did I miss something?
96

96

00:03:17,400  -->  00:03:19,800
Are there still vulnerabilities that I'm not aware of?
97

97

00:03:19,800  -->  00:03:21,570
If so, we'll go into step four
98

98

00:03:21,570  -->  00:03:23,256
where we're going to perform corrective actions based
99

99

00:03:23,256  -->  00:03:25,140
on the reported findings.
100

100

00:03:25,140  -->  00:03:27,390
So let's say I scan this new window system
101

101

00:03:27,390  -->  00:03:29,070
that I just installed and I found out
102

102

00:03:29,070  -->  00:03:31,740
that I'm running a vulnerable version of IIS,
103

103

00:03:31,740  -->  00:03:33,900
well, I need to go to Microsoft update
104

104

00:03:33,900  -->  00:03:36,450
and get the updates to patch that system
105

105

00:03:36,450  -->  00:03:38,640
because I want to make sure I don't have vulnerabilities
106

106

00:03:38,640  -->  00:03:39,930
in my system.
107

107

00:03:39,930  -->  00:03:41,820
And then I move into number five
108

108

00:03:41,820  -->  00:03:44,940
I'm going to perform another vulnerability scan and assessment.
109

109

00:03:44,940  -->  00:03:47,430
So I've now installed this new system,
110

110

00:03:47,430  -->  00:03:50,280
I've scanned this new system, I've analyzed the report,
111

111

00:03:50,280  -->  00:03:53,280
I've patched things, and now I'm going to scan again.
112

112

00:03:53,280  -->  00:03:54,113
Why?
113

113

00:03:54,113  -->  00:03:56,400
Because now I want to make sure the fixes I put in
114

114

00:03:56,400  -->  00:03:57,810
actually took place
115

115

00:03:57,810  -->  00:04:00,150
and those things are actually solving the problem.
116

116

00:04:00,150  -->  00:04:03,660
Now, after I do this, I'm now going to go into step six.
117

117

00:04:03,660  -->  00:04:05,160
I'm going to document any findings
118

118

00:04:05,160  -->  00:04:07,800
and create reports for my relevant stakeholders.
119

119

00:04:07,800  -->  00:04:10,440
So now that I have this baseline, I've patched it,
120

120

00:04:10,440  -->  00:04:12,750
I've fixed it, I've scanned it, I've fixed it
121

121

00:04:12,750  -->  00:04:14,100
and I've done that a couple of times
122

122

00:04:14,100  -->  00:04:15,517
I can now create a report and say,
123

123

00:04:15,517  -->  00:04:18,360
"Stakeholders, here is the remaining vulnerabilities.
124

124

00:04:18,360  -->  00:04:20,550
This is the risk that you're going to be accepting
125

125

00:04:20,550  -->  00:04:22,680
if we put this device on the network."
126

126

00:04:22,680  -->  00:04:23,580
And by doing that
127

127

00:04:23,580  -->  00:04:26,400
I'm giving my stakeholders a chance to accept that risk
128

128

00:04:26,400  -->  00:04:28,920
with knowledge of what that risk actually is.
129

129

00:04:28,920  -->  00:04:30,630
I'm not just saying I'm putting the server on
130

130

00:04:30,630  -->  00:04:32,160
but I'm putting the server on,
131

131

00:04:32,160  -->  00:04:35,790
and here are the five or 10 vulnerabilities we can't fix yet
132

132

00:04:35,790  -->  00:04:37,740
but here's the mitigations we've put in place
133

133

00:04:37,740  -->  00:04:39,390
to minimize the risk from that.
134

134

00:04:39,390  -->  00:04:41,370
And then that gets us to number seven, which is
135

135

00:04:41,370  -->  00:04:44,850
conducting ongoing scanning to ensure continual remediation.
136

136

00:04:44,850  -->  00:04:46,860
Now, this is a really important point
137

137

00:04:46,860  -->  00:04:49,740
because when you do a scan and you take a vulnerability scan
138

138

00:04:49,740  -->  00:04:51,900
across your network or across the target,
139

139

00:04:51,900  -->  00:04:54,090
that is a point in time assessment.
140

140

00:04:54,090  -->  00:04:57,240
Now what I mean is if I do that today, and today is Thursday
141

141

00:04:57,240  -->  00:05:00,990
as I'm recording this and I go and I take a scan today
142

142

00:05:00,990  -->  00:05:03,690
and then next Wednesday we get hacked
143

143

00:05:03,690  -->  00:05:05,460
because there's some zero day that came out
144

144

00:05:05,460  -->  00:05:06,480
and we didn't know about it.
145

145

00:05:06,480  -->  00:05:09,630
Well, if we only scanned it last Thursday today
146

146

00:05:09,630  -->  00:05:11,550
and Wednesday, the new vulnerability came out
147

147

00:05:11,550  -->  00:05:12,750
and somebody could exploit it.
148

148

00:05:12,750  -->  00:05:13,860
Well, again, they can do that
149

149

00:05:13,860  -->  00:05:15,780
because it's a point in time assessment.
150

150

00:05:15,780  -->  00:05:17,520
We always need to make sure we're continually
151

151

00:05:17,520  -->  00:05:18,720
checking our systems.
152

152

00:05:18,720  -->  00:05:19,980
Now, does that mean
153

153

00:05:19,980  -->  00:05:22,260
that we're going to scan our systems every day?
154

154

00:05:22,260  -->  00:05:24,090
Maybe, maybe not.
155

155

00:05:24,090  -->  00:05:25,050
It'd be really uncommon
156

156

00:05:25,050  -->  00:05:26,550
for you to scan your systems every day, though
157

157

00:05:26,550  -->  00:05:27,660
I'll tell you that.
158

158

00:05:27,660  -->  00:05:30,120
But we are going to cover more about scan frequency later.
159

159

00:05:30,120  -->  00:05:32,760
But the idea here is that this is not a one and done.
160

160

00:05:32,760  -->  00:05:34,620
I don't do it once when I install the system
161

161

00:05:34,620  -->  00:05:35,970
and never touch it again.
162

162

00:05:35,970  -->  00:05:38,730
I need to conduct ongoing scanning, whether that's weekly,
163

163

00:05:38,730  -->  00:05:41,430
whether that's monthly, quarterly, or yearly,
164

164

00:05:41,430  -->  00:05:44,280
whatever that frequency is based on your risk profile
165

165

00:05:44,280  -->  00:05:47,190
you are going to conduct ongoing scanning and patching.
166

166

00:05:47,190  -->  00:05:49,590
Which brings us to the mantra of IT.
167

167

00:05:49,590  -->  00:05:51,450
Whenever you are stuck on the exam
168

168

00:05:51,450  -->  00:05:53,760
and you start talking about vulnerability assessments
169

169

00:05:53,760  -->  00:05:55,440
I want you to remember these three words,
170

170

00:05:55,440  -->  00:05:57,990
scan, patch, scan.
171

171

00:05:57,990  -->  00:05:59,130
Now what does that mean?
172

172

00:05:59,130  -->  00:06:01,170
Well, that's really the workflow I just described.
173

173

00:06:01,170  -->  00:06:03,060
We have a system, we scanned it,
174

174

00:06:03,060  -->  00:06:05,400
we found some vulnerabilities, we patched them
175

175

00:06:05,400  -->  00:06:07,500
and then we scanned it again to make sure
176

176

00:06:07,500  -->  00:06:10,050
that the patches we put in place actually worked.
177

177

00:06:10,050  -->  00:06:11,760
And we're going to continue to do that over
178

178

00:06:11,760  -->  00:06:13,110
and over and over again.
179

179

00:06:13,110  -->  00:06:15,210
If you do weekly scans in your organization
180

180

00:06:15,210  -->  00:06:17,040
you should also be doing weekly patches.
181

181

00:06:17,040  -->  00:06:18,240
If you're doing monthly patches
182

182

00:06:18,240  -->  00:06:20,490
but weekly scans, then guess what?
183

183

00:06:20,490  -->  00:06:22,890
You're going to find the same vulnerabilities four times
184

184

00:06:22,890  -->  00:06:25,440
in a row until somebody gets around to patching 'em.
185

185

00:06:25,440  -->  00:06:27,300
That's not going to be very effective for you.
186

186

00:06:27,300  -->  00:06:29,160
So instead, you want to make sure your scanning cycle
187

187

00:06:29,160  -->  00:06:31,230
and your patching cycle line up.
188

188

00:06:31,230  -->  00:06:33,510
You want to scan something, find all the problems,
189

189

00:06:33,510  -->  00:06:34,530
patch all the problems
190

190

00:06:34,530  -->  00:06:37,560
and then scan again to make sure those are all been fixed.
191

191

00:06:37,560  -->  00:06:38,970
And then we'll scan again next week
192

192

00:06:38,970  -->  00:06:41,970
or next month or next quarter or whatever your frequency is.
