1
1

00:00:00,240  -->  00:00:02,610
<v Narrator>Scheduling and constraints.</v>
2

2

00:00:02,610  -->  00:00:03,443
In this lesson
3

3

00:00:03,443  -->  00:00:06,150
we're going to talk about scheduling and constraints.
4

4

00:00:06,150  -->  00:00:07,260
So the first question I have
5

5

00:00:07,260  -->  00:00:09,570
for you is how often should you scan?
6

6

00:00:09,570  -->  00:00:11,520
Well, this is going to be determined based
7

7

00:00:11,520  -->  00:00:13,380
on your internal risk management decisions
8

8

00:00:13,380  -->  00:00:14,820
of your organization.
9

9

00:00:14,820  -->  00:00:16,470
If you have a larger risk appetite
10

10

00:00:16,470  -->  00:00:18,150
you're going to have more time in between scans
11

11

00:00:18,150  -->  00:00:20,700
and you might go towards rarely or sometimes.
12

12

00:00:20,700  -->  00:00:22,500
If you have a very low risk appetite
13

13

00:00:22,500  -->  00:00:24,720
you may do it very often or often.
14

14

00:00:24,720  -->  00:00:27,540
This is going to depend on you and your organization.
15

15

00:00:27,540  -->  00:00:30,780
Remember, a scan is a point-in-time assessment.
16

16

00:00:30,780  -->  00:00:34,350
One organization I worked with did scans every six months.
17

17

00:00:34,350  -->  00:00:36,180
Now that seems like an awfully long time
18

18

00:00:36,180  -->  00:00:37,980
to me to wait between scans
19

19

00:00:37,980  -->  00:00:40,650
and they're assuming a ton of risk because they did that.
20

20

00:00:40,650  -->  00:00:43,380
Another organization I worked with did it every month
21

21

00:00:43,380  -->  00:00:45,270
yet others do it every week.
22

22

00:00:45,270  -->  00:00:46,980
Again, it really depends on you
23

23

00:00:46,980  -->  00:00:49,110
and how quickly you want to get those results
24

24

00:00:49,110  -->  00:00:50,610
and see what vulnerabilities exist
25

25

00:00:50,610  -->  00:00:52,500
so you can start mitigating them.
26

26

00:00:52,500  -->  00:00:54,660
Remember, vulnerability scans are really
27

27

00:00:54,660  -->  00:00:55,950
up to your organization
28

28

00:00:55,950  -->  00:00:58,830
but my personal recommendation is they should be done
29

29

00:00:58,830  -->  00:01:00,360
at least weekly.
30

30

00:01:00,360  -->  00:01:02,010
Now, this isn't something that comes from your book,
31

31

00:01:02,010  -->  00:01:04,260
this is just from my professional experience.
32

32

00:01:04,260  -->  00:01:06,930
I think if you don't do it at least weekly
33

33

00:01:06,930  -->  00:01:08,520
you are going to be missing a lot
34

34

00:01:08,520  -->  00:01:10,170
and there's just way too much stuff that goes
35

35

00:01:10,170  -->  00:01:11,760
on in a seven day cycle
36

36

00:01:11,760  -->  00:01:14,430
that you should be at least scanning once a week.
37

37

00:01:14,430  -->  00:01:16,950
Now, when we start talking about scans, there are lots
38

38

00:01:16,950  -->  00:01:18,660
of different things we have to consider when we think
39

39

00:01:18,660  -->  00:01:20,640
about when we should schedule them.
40

40

00:01:20,640  -->  00:01:21,840
Some of them include things like,
41

41

00:01:21,840  -->  00:01:24,330
when we deploy a new or updated system.
42

42

00:01:24,330  -->  00:01:26,850
If I'm going to install some new piece of gear onto my network
43

43

00:01:26,850  -->  00:01:28,260
I want to make sure it's been scanned
44

44

00:01:28,260  -->  00:01:29,970
and I know what vulnerabilities exist.
45

45

00:01:29,970  -->  00:01:31,200
And so that's my first time I think
46

46

00:01:31,200  -->  00:01:32,880
about when I should scan something.
47

47

00:01:32,880  -->  00:01:34,110
Another time I think about it is
48

48

00:01:34,110  -->  00:01:36,420
when new vulnerabilities have been identified.
49

49

00:01:36,420  -->  00:01:37,710
Now, this can be identified
50

50

00:01:37,710  -->  00:01:40,260
in your network or just identified at large.
51

51

00:01:40,260  -->  00:01:41,910
For instance, you might be reading the newspaper
52

52

00:01:41,910  -->  00:01:44,370
and find out about this new thing called WannaCry.
53

53

00:01:44,370  -->  00:01:46,650
If this was 2017, that's when it came out,
54

54

00:01:46,650  -->  00:01:47,857
it hit the newspapers and everybody goes
55

55

00:01:47,857  -->  00:01:50,130
"Oh my goodness, what is WannaCry?"
56

56

00:01:50,130  -->  00:01:52,080
And you could actually find there was a vulnerability
57

57

00:01:52,080  -->  00:01:54,150
associated with it and you could scan for that.
58

58

00:01:54,150  -->  00:01:55,710
If I see something like that in the news,
59

59

00:01:55,710  -->  00:01:57,930
I immediately want to make sure I'm scanning my network
60

60

00:01:57,930  -->  00:01:59,610
to see if I'm vulnerable.
61

61

00:01:59,610  -->  00:02:00,840
The next thing you want to think about
62

62

00:02:00,840  -->  00:02:02,550
is whenever there's a security breach.
63

63

00:02:02,550  -->  00:02:04,500
If you've had a security breach in your network
64

64

00:02:04,500  -->  00:02:05,790
you want to scan your network
65

65

00:02:05,790  -->  00:02:08,520
and make sure you find all your vulnerabilities.
66

66

00:02:08,520  -->  00:02:10,950
Just because they got in one way doesn't mean they're
67

67

00:02:10,950  -->  00:02:12,390
going to come back in that same way.
68

68

00:02:12,390  -->  00:02:14,460
So you can't just patch the one way they got in.
69

69

00:02:14,460  -->  00:02:16,140
This isn't a penetration test.
70

70

00:02:16,140  -->  00:02:18,360
If they got in, you need to start making sure you lock
71

71

00:02:18,360  -->  00:02:21,090
down everything, because generally what we've seen is when
72

72

00:02:21,090  -->  00:02:22,530
an attacker gets in one way,
73

73

00:02:22,530  -->  00:02:25,140
they come back to re-attack you again and again.
74

74

00:02:25,140  -->  00:02:26,550
So if you had a security breach,
75

75

00:02:26,550  -->  00:02:29,460
you need to make sure you follow up and do another scan.
76

76

00:02:29,460  -->  00:02:31,650
Another reason to do it is when you have regulatory
77

77

00:02:31,650  -->  00:02:33,030
or oversight requirements.
78

78

00:02:33,030  -->  00:02:35,220
For instance, if you deal with PCIDSS
79

79

00:02:35,220  -->  00:02:37,920
with credit card data, you have to do a scan once
80

80

00:02:37,920  -->  00:02:39,810
a quarter that's required to be compliant
81

81

00:02:39,810  -->  00:02:41,370
with PCIDSS requirements.
82

82

00:02:41,370  -->  00:02:43,320
So if you have a regulatory oversight requirement
83

83

00:02:43,320  -->  00:02:45,450
you'll do it based on their scan schedule.
84

84

00:02:45,450  -->  00:02:47,820
And then the other one you're going to do it for is anytime
85

85

00:02:47,820  -->  00:02:48,990
it's regularly scheduled.
86

86

00:02:48,990  -->  00:02:51,450
Now, what I mean by that, in my organization
87

87

00:02:51,450  -->  00:02:52,890
we do weekly scans.
88

88

00:02:52,890  -->  00:02:55,710
So every week we make sure we do a full scan of our servers
89

89

00:02:55,710  -->  00:02:57,300
and we make sure that everything is good.
90

90

00:02:57,300  -->  00:02:59,010
If you do that, you'll know exactly
91

91

00:02:59,010  -->  00:03:00,330
where you are every single week
92

92

00:03:00,330  -->  00:03:02,640
and what your vulnerability posture is.
93

93

00:03:02,640  -->  00:03:06,090
So why doesn't an organization just scan continuously
94

94

00:03:06,090  -->  00:03:07,410
all day every day?
95

95

00:03:07,410  -->  00:03:08,430
I should just run my scanners
96

96

00:03:08,430  -->  00:03:10,260
over and over and over again to check.
97

97

00:03:10,260  -->  00:03:12,900
Well, because vulnerabilities don't show up that way.
98

98

00:03:12,900  -->  00:03:14,580
It's not the way things work.
99

99

00:03:14,580  -->  00:03:15,413
There are a lot
100

100

00:03:15,413  -->  00:03:17,070
of technical constraints here that would preclude you
101

101

00:03:17,070  -->  00:03:19,230
from being able to do scans continuously over
102

102

00:03:19,230  -->  00:03:20,670
and over and over again.
103

103

00:03:20,670  -->  00:03:22,200
One of the big things is your feeds
104

104

00:03:22,200  -->  00:03:23,670
are only updated so often.
105

105

00:03:23,670  -->  00:03:25,500
Think about like antivirus signatures.
106

106

00:03:25,500  -->  00:03:27,660
If you haven't gotten new antivirus signatures
107

107

00:03:27,660  -->  00:03:30,030
then you're not going to be able to detect anything new, right?
108

108

00:03:30,030  -->  00:03:31,740
That's the same concept here.
109

109

00:03:31,740  -->  00:03:33,180
But really the biggest limitation
110

110

00:03:33,180  -->  00:03:34,980
is your technical constraints.
111

111

00:03:34,980  -->  00:03:36,810
Technical constraints can limit your ability
112

112

00:03:36,810  -->  00:03:39,810
to conduct scans more frequently than you'd like.
113

113

00:03:39,810  -->  00:03:41,340
When you start scanning your network
114

114

00:03:41,340  -->  00:03:43,770
you're going to start causing processor utilization
115

115

00:03:43,770  -->  00:03:45,360
and memory utilization.
116

116

00:03:45,360  -->  00:03:48,210
For instance, here you can see exactly when the scan started
117

117

00:03:48,210  -->  00:03:49,740
and when the scan stopped.
118

118

00:03:49,740  -->  00:03:52,380
Notice the processor usage was at like five to 6%
119

119

00:03:52,380  -->  00:03:54,630
and then it shot up to almost a hundred percent.
120

120

00:03:54,630  -->  00:03:55,950
That's because this computer was
121

121

00:03:55,950  -->  00:03:57,750
in the middle of doing a scan.
122

122

00:03:57,750  -->  00:03:58,800
Now, this consumes a lot
123

123

00:03:58,800  -->  00:04:01,380
of network bandwidth as well as significant processing
124

124

00:04:01,380  -->  00:04:04,920
and memory usage on the target and from the scanning system.
125

125

00:04:04,920  -->  00:04:06,390
And if you're using agent based scans
126

126

00:04:06,390  -->  00:04:08,550
like this particular system was, you're going to see
127

127

00:04:08,550  -->  00:04:11,850
on that system how the CPU can spike up during that time.
128

128

00:04:11,850  -->  00:04:14,190
So you need to make sure you're timing your scans right
129

129

00:04:14,190  -->  00:04:16,140
so they don't have an effect on your end user.
130

130

00:04:16,140  -->  00:04:17,520
And you need to make sure
131

131

00:04:17,520  -->  00:04:19,080
that you're not overburdening these systems
132

132

00:04:19,080  -->  00:04:21,960
by trying to do continuous scans, because if you do that
133

133

00:04:21,960  -->  00:04:23,580
your systems can become useless
134

134

00:04:23,580  -->  00:04:25,650
because they won't get any work done.
135

135

00:04:25,650  -->  00:04:28,560
Another constraint you're to consider is cost.
136

136

00:04:28,560  -->  00:04:31,470
Each time you scan that has a cost associated with it.
137

137

00:04:31,470  -->  00:04:33,690
Now your corporate policy is going to dictate how
138

138

00:04:33,690  -->  00:04:35,550
much risk you're willing to assume.
139

139

00:04:35,550  -->  00:04:36,540
And again, this comes down
140

140

00:04:36,540  -->  00:04:39,570
to a cost situation because the more scans I do
141

141

00:04:39,570  -->  00:04:42,720
the more people hours I have to use to do those scans
142

142

00:04:42,720  -->  00:04:44,130
and people to read those scans
143

143

00:04:44,130  -->  00:04:46,890
and people to analyze those scans and all of that stuff,
144

144

00:04:46,890  -->  00:04:49,110
let alone the processing power and the network bandwidth
145

145

00:04:49,110  -->  00:04:50,580
and all the other things that go into that.
146

146

00:04:50,580  -->  00:04:52,260
So all of that has additional cost
147

147

00:04:52,260  -->  00:04:54,397
and so there's going to be a risk appetite of,
148

148

00:04:54,397  -->  00:04:58,290
"Hey if I can do this once a week versus once a day
149

149

00:04:58,290  -->  00:04:59,790
is that still good enough?"
150

150

00:04:59,790  -->  00:05:01,500
If I do this once an hour
151

151

00:05:01,500  -->  00:05:03,720
versus once a day, which one is better?
152

152

00:05:03,720  -->  00:05:04,860
And you're going to weigh that based
153

153

00:05:04,860  -->  00:05:05,970
on how much it's going to cost you
154

154

00:05:05,970  -->  00:05:07,800
and what benefit you're really going to get.
155

155

00:05:07,800  -->  00:05:10,260
As I said, I tend to lean on the side of about
156

156

00:05:10,260  -->  00:05:12,750
once a week is a good scan frequency,
157

157

00:05:12,750  -->  00:05:15,300
but again, you get to choose this in your own organization.
158

158

00:05:15,300  -->  00:05:16,320
As you start looking at this
159

159

00:05:16,320  -->  00:05:17,970
in your overall threat intelligence,
160

160

00:05:17,970  -->  00:05:19,440
you're going to see how much of a threat there is
161

161

00:05:19,440  -->  00:05:22,140
against your organization and how often new code
162

162

00:05:22,140  -->  00:05:23,580
and exploits are coming out.
163

163

00:05:23,580  -->  00:05:26,010
Generally, we see from Microsoft once a week,
164

164

00:05:26,010  -->  00:05:26,970
we get patches right?
165

165

00:05:26,970  -->  00:05:28,500
We get 'em on patch Tuesday,
166

166

00:05:28,500  -->  00:05:30,540
and so if we have 'em coming out on patch Tuesday
167

167

00:05:30,540  -->  00:05:32,640
that's a good frequency for us once a week
168

168

00:05:32,640  -->  00:05:34,830
to be able to scan, patch, scan and make sure
169

169

00:05:34,830  -->  00:05:37,140
that we're getting up to date with the latest patches.
170

170

00:05:37,140  -->  00:05:39,420
Now, your scanning frequency and technique will be
171

171

00:05:39,420  -->  00:05:42,300
affected also by the data type that's being processed
172

172

00:05:42,300  -->  00:05:43,530
by the target.
173

173

00:05:43,530  -->  00:05:46,020
Now, what I mean by this is what's being processed
174

174

00:05:46,020  -->  00:05:48,900
by the server will help you determine how many times
175

175

00:05:48,900  -->  00:05:51,270
you need to scan this thing and how often.
176

176

00:05:51,270  -->  00:05:53,820
For example, if you have a server that contains confidential
177

177

00:05:53,820  -->  00:05:56,130
or top secret or sensitive information,
178

178

00:05:56,130  -->  00:05:58,500
it should be scanned more frequently than a computer
179

179

00:05:58,500  -->  00:06:00,480
that's being used by the mail room
180

180

00:06:00,480  -->  00:06:02,310
because that's maybe not as important.
181

181

00:06:02,310  -->  00:06:04,290
And so you're going to have to make those decisions.
182

182

00:06:04,290  -->  00:06:06,570
Conversely, you're going to want to make sure the system
183

183

00:06:06,570  -->  00:06:08,460
is scanned using a credentialed scan instead
184

184

00:06:08,460  -->  00:06:10,920
of a non-credentialed scan if you're dealing with something
185

185

00:06:10,920  -->  00:06:14,310
like secret or top secret or confidential data, right?
186

186

00:06:14,310  -->  00:06:15,390
Because this is important stuff
187

187

00:06:15,390  -->  00:06:17,760
we want to find all the vulnerabilities.
188

188

00:06:17,760  -->  00:06:20,640
Now, again, this becomes tricky though because as I said
189

189

00:06:20,640  -->  00:06:23,100
once the scan administrator has to do a credential scan
190

190

00:06:23,100  -->  00:06:25,020
that means they need to have administrative credentials
191

191

00:06:25,020  -->  00:06:27,030
on that sensitive target, which again
192

192

00:06:27,030  -->  00:06:28,440
could lead to an insider threat.
193

193

00:06:28,440  -->  00:06:31,470
So all these things are things that have to be balanced
194

194

00:06:31,470  -->  00:06:33,120
and you have to weigh that risk.
195

195

00:06:33,120  -->  00:06:35,610
This is why CYSA is a much harder exam
196

196

00:06:35,610  -->  00:06:37,500
than some of the earlier exams you may have taken
197

197

00:06:37,500  -->  00:06:40,200
because there's not a clear cut answer all of the time.
198

198

00:06:40,200  -->  00:06:42,030
A lot of these things are risk decisions
199

199

00:06:42,030  -->  00:06:42,870
that we have to weigh
200

200

00:06:42,870  -->  00:06:44,880
and based on the different circumstances
201

201

00:06:44,880  -->  00:06:46,830
we are going to choose different answers.
202

202

00:06:46,830  -->  00:06:49,380
It's not always going to be A, sometimes it's going to be B
203

203

00:06:49,380  -->  00:06:51,840
or C or D based on the circumstances.
204

204

00:06:51,840  -->  00:06:53,760
And so you have to think these things through
205

205

00:06:53,760  -->  00:06:55,080
and put on your manager hat
206

206

00:06:55,080  -->  00:06:57,150
and your risk management hat as you start thinking
207

207

00:06:57,150  -->  00:06:59,820
about these things and what you're going to do.
208

208

00:06:59,820  -->  00:07:02,100
Now, one way to mitigate the risk of giving
209

209

00:07:02,100  -->  00:07:04,380
out administrator credentials and still being able to
210

210

00:07:04,380  -->  00:07:07,260
do a credentialed scan is to use what's called a PAM,
211

211

00:07:07,260  -->  00:07:09,690
a privileged access management solution.
212

212

00:07:09,690  -->  00:07:11,640
Now, a PAM allows you to mitigate this risk
213

213

00:07:11,640  -->  00:07:12,930
of the insider threat.
214

214

00:07:12,930  -->  00:07:15,420
Essentially, this is a technology that you can use.
215

215

00:07:15,420  -->  00:07:17,550
So the scanning software goes to this server
216

216

00:07:17,550  -->  00:07:18,750
the PAM server,
217

217

00:07:18,750  -->  00:07:19,583
and it'll actually get
218

218

00:07:19,583  -->  00:07:21,420
the privileged credentials from there.
219

219

00:07:21,420  -->  00:07:23,370
These are actually one time used credentials.
220

220

00:07:23,370  -->  00:07:26,160
So what happens is the PAM server will actually go
221

221

00:07:26,160  -->  00:07:28,080
to the target that you're trying to scan.
222

222

00:07:28,080  -->  00:07:30,810
It will change the password to some random thing,
223

223

00:07:30,810  -->  00:07:33,300
give that random thing over to the scanning server.
224

224

00:07:33,300  -->  00:07:35,340
The scanning server will finish its scan.
225

225

00:07:35,340  -->  00:07:37,890
Once it's done, it tells the PAM server, "Hey, I'm done."
226

226

00:07:37,890  -->  00:07:38,850
And the PAM server goes
227

227

00:07:38,850  -->  00:07:41,700
and rechanges that password to something else entirely.
228

228

00:07:41,700  -->  00:07:43,110
So you only have the password
229

229

00:07:43,110  -->  00:07:45,240
or the administrative credentials for the time of the scan
230

230

00:07:45,240  -->  00:07:46,860
and then they're taken away from you again.
231

231

00:07:46,860  -->  00:07:48,510
That's how these PAM solutions work,
232

232

00:07:48,510  -->  00:07:50,160
these privileged access management solutions.
233

233

00:07:50,160  -->  00:07:52,350
So if you are in a big organization
234

234

00:07:52,350  -->  00:07:53,910
and you really want to do these credentialed scans
235

235

00:07:53,910  -->  00:07:56,220
which I do recommend, then you really do want to
236

236

00:07:56,220  -->  00:07:58,260
get yourself a privileged access management solution
237

237

00:07:58,260  -->  00:08:00,780
because it'll help you mitigate this insider threat.
238

238

00:08:00,780  -->  00:08:03,390
Now, unfortunately, these PAM solutions do cost money
239

239

00:08:03,390  -->  00:08:05,370
and sometimes you don't have the budget for it.
240

240

00:08:05,370  -->  00:08:06,300
So what can you do
241

241

00:08:06,300  -->  00:08:08,490
if you don't have the budget for a PAM solution?
242

242

00:08:08,490  -->  00:08:10,440
Well, you can do the next best thing.
243

243

00:08:10,440  -->  00:08:12,390
You can create restricted log on hours
244

244

00:08:12,390  -->  00:08:14,910
for a specific period of time, that only allows scanning
245

245

00:08:14,910  -->  00:08:17,520
during that time using those administrative credentials.
246

246

00:08:17,520  -->  00:08:19,710
So we might say we're only going to allow scanning
247

247

00:08:19,710  -->  00:08:21,240
from midnight to 2:00 AM.
248

248

00:08:21,240  -->  00:08:23,910
So if somebody tries to log on at three in the afternoon
249

249

00:08:23,910  -->  00:08:25,890
when the administrator's actually there,
250

250

00:08:25,890  -->  00:08:27,660
then we would know that's an insider threat
251

251

00:08:27,660  -->  00:08:29,040
and we'd have to think about that, right?
252

252

00:08:29,040  -->  00:08:30,990
And look into that and see what's going on.
253

253

00:08:30,990  -->  00:08:33,570
This way that privilege account can only be used
254

254

00:08:33,570  -->  00:08:35,760
to do the scanning between midnight and 2:00 AM
255

255

00:08:35,760  -->  00:08:37,560
which is the time the server will do it
256

256

00:08:37,560  -->  00:08:39,960
on its own without the scan administrator there
257

257

00:08:39,960  -->  00:08:42,300
so they don't have access to those credentials as well.
258

258

00:08:42,300  -->  00:08:44,580
So this is just another mitigation you can use, but again
259

259

00:08:44,580  -->  00:08:46,050
the privilege access management solution
260

260

00:08:46,050  -->  00:08:48,663
is a much better option, and one I highly recommend.
