1
1

00:00:00,510  -->  00:00:02,030
<v Instructor>Scan Reports.</v>
2

2

00:00:02,030  -->  00:00:04,110
In this lesson, we're going to start looking
3

3

00:00:04,110  -->  00:00:05,580
at some scan reports
4

4

00:00:05,580  -->  00:00:08,250
from our different vulnerability assessment tools.
5

5

00:00:08,250  -->  00:00:10,200
Now, these scan reports are going to contain
6

6

00:00:10,200  -->  00:00:13,680
color-coded vulnerabilities in terms of their criticality.
7

7

00:00:13,680  -->  00:00:15,720
This allows you to very quickly identify
8

8

00:00:15,720  -->  00:00:17,700
what is the most important things
9

9

00:00:17,700  -->  00:00:19,560
that need to draw your attention.
10

10

00:00:19,560  -->  00:00:22,590
For example, here on the screen, you can see a list
11

11

00:00:22,590  -->  00:00:24,390
of several different vulnerabilities
12

12

00:00:24,390  -->  00:00:25,890
that are being displayed.
13

13

00:00:25,890  -->  00:00:27,990
Here are just the first six vulnerabilities
14

14

00:00:27,990  -->  00:00:30,750
we're going to look at, and you can see the severity of them.
15

15

00:00:30,750  -->  00:00:32,730
These are all classified as high
16

16

00:00:32,730  -->  00:00:36,030
because they have a 10.0 or 9.3 rating
17

17

00:00:36,030  -->  00:00:38,070
as far as criticality is concerned.
18

18

00:00:38,070  -->  00:00:40,680
Now, if I clicked on that specific vulnerability,
19

19

00:00:40,680  -->  00:00:42,450
it will actually give me additional details
20

20

00:00:42,450  -->  00:00:45,420
about that vulnerability, such as how it's detected,
21

21

00:00:45,420  -->  00:00:46,620
what can be done to fix it,
22

22

00:00:46,620  -->  00:00:48,750
and what could be used to exploit it.
23

23

00:00:48,750  -->  00:00:50,430
All of this is valid information
24

24

00:00:50,430  -->  00:00:51,780
that you should be reviewing,
25

25

00:00:51,780  -->  00:00:53,070
so you can make a determination
26

26

00:00:53,070  -->  00:00:56,040
of what you're going to do to mitigate this risk.
27

27

00:00:56,040  -->  00:00:57,450
Now, at any time if you want to look
28

28

00:00:57,450  -->  00:00:58,830
at your previous scan reports,
29

29

00:00:58,830  -->  00:01:01,260
you can do that by going back through your dashboard
30

30

00:01:01,260  -->  00:01:03,450
of your vulnerability assessment tool.
31

31

00:01:03,450  -->  00:01:05,790
Now again, these reports should be treated
32

32

00:01:05,790  -->  00:01:07,350
as highly confidential,
33

33

00:01:07,350  -->  00:01:09,060
and you should limit the access to them
34

34

00:01:09,060  -->  00:01:10,950
to a specific group of administrators
35

35

00:01:10,950  -->  00:01:12,480
that have the rights to look at them
36

36

00:01:12,480  -->  00:01:14,940
because these are the keys to the kingdom.
37

37

00:01:14,940  -->  00:01:17,460
These scans have now already told the attacker
38

38

00:01:17,460  -->  00:01:19,800
what is on your network that is vulnerable.
39

39

00:01:19,800  -->  00:01:22,680
So if an attacker got their hands on this scan report,
40

40

00:01:22,680  -->  00:01:24,360
they would know exactly what to attack
41

41

00:01:24,360  -->  00:01:26,970
and how easily to get into your network.
42

42

00:01:26,970  -->  00:01:28,980
Now, one of the things I see a lot of people do
43

43

00:01:28,980  -->  00:01:32,280
is they try to use automation for everything in the network.
44

44

00:01:32,280  -->  00:01:34,230
Now, automation is a great thing to use
45

45

00:01:34,230  -->  00:01:36,750
and it can really free up a lot of your analyst time,
46

46

00:01:36,750  -->  00:01:40,530
but automation by itself cannot do everything for you.
47

47

00:01:40,530  -->  00:01:43,260
For example, one of the things I see commonly done
48

48

00:01:43,260  -->  00:01:44,610
is that people will set up these tools
49

49

00:01:44,610  -->  00:01:47,190
to automatically scan the network, which is a good thing,
50

50

00:01:47,190  -->  00:01:49,290
and then automatically send out those reports
51

51

00:01:49,290  -->  00:01:52,920
via email or send an alert via email or text message
52

52

00:01:52,920  -->  00:01:55,650
if the scan finds some non-compliant item.
53

53

00:01:55,650  -->  00:01:58,140
Now, this is a good thing to do in theory,
54

54

00:01:58,140  -->  00:01:59,940
but you have to be careful here
55

55

00:01:59,940  -->  00:02:02,610
because this automatic distribution of these scan results
56

56

00:02:02,610  -->  00:02:05,490
does make it harder for you to preserve confidentiality.
57

57

00:02:05,490  -->  00:02:07,170
It's harder to maintain control
58

58

00:02:07,170  -->  00:02:08,490
over all of those scan reports
59

59

00:02:08,490  -->  00:02:10,530
when you start sending them out to everyone,
60

60

00:02:10,530  -->  00:02:11,460
and so you want to make sure
61

61

00:02:11,460  -->  00:02:13,140
that if you're using automation,
62

62

00:02:13,140  -->  00:02:15,240
you really think through who's getting that,
63

63

00:02:15,240  -->  00:02:16,230
how you're protecting it,
64

64

00:02:16,230  -->  00:02:17,790
and are you encrypting that data
65

65

00:02:17,790  -->  00:02:19,500
as you start sending it out.
66

66

00:02:19,500  -->  00:02:21,720
For this reason, a lot of organizations
67

67

00:02:21,720  -->  00:02:23,640
will do automated scans,
68

68

00:02:23,640  -->  00:02:26,700
but those reports will stay in a centralized location
69

69

00:02:26,700  -->  00:02:28,440
and then will have to be looked at manually
70

70

00:02:28,440  -->  00:02:31,200
and those will be sent out additionally to the right people
71

71

00:02:31,200  -->  00:02:33,900
in a secure method so they can look at them.
72

72

00:02:33,900  -->  00:02:36,450
Now, this brings us to the idea of manual distribution.
73

73

00:02:36,450  -->  00:02:38,430
When you're dealing with manual distribution reports,
74

74

00:02:38,430  -->  00:02:40,080
this can allow you to have better control
75

75

00:02:40,080  -->  00:02:42,000
over the contents of those reports
76

76

00:02:42,000  -->  00:02:43,860
because you're making sure only what you want
77

77

00:02:43,860  -->  00:02:46,500
is being seen by others, and in addition to that,
78

78

00:02:46,500  -->  00:02:49,560
it gives your analysts a chance to explain the results.
79

79

00:02:49,560  -->  00:02:51,780
Now, what I mean by this is you can take that report
80

80

00:02:51,780  -->  00:02:54,270
and you can go brief it up to the senior leadership.
81

81

00:02:54,270  -->  00:02:56,640
This might be your executives or your managers
82

82

00:02:56,640  -->  00:02:58,440
or whoever it is that you need to brief.
83

83

00:02:58,440  -->  00:03:00,030
Now, instead of just giving them a report
84

84

00:03:00,030  -->  00:03:02,257
with facts and figures, you can explain to them,
85

85

00:03:02,257  -->  00:03:04,260
"Yes, there is this vulnerability.
86

86

00:03:04,260  -->  00:03:06,660
It affects 50% of our systems
87

87

00:03:06,660  -->  00:03:09,240
and it's really critical because of this reason
88

88

00:03:09,240  -->  00:03:11,520
and here's what I recommend we do to fix it."
89

89

00:03:11,520  -->  00:03:13,950
This gives you a chance to start getting that narrative
90

90

00:03:13,950  -->  00:03:16,260
and be able to control exactly what's going to be done
91

91

00:03:16,260  -->  00:03:18,060
as you move forward into the future.
