1
1

00:00:00,360  -->  00:00:02,583
<v Narrator>Remediation and mitigation.</v>
2

2

00:00:03,450  -->  00:00:04,650
Now, in this lesson,
3

3

00:00:04,650  -->  00:00:07,800
we are going to talk about remediation and mitigation,
4

4

00:00:07,800  -->  00:00:08,970
and this is really important
5

5

00:00:08,970  -->  00:00:10,470
because as we've mentioned before,
6

6

00:00:10,470  -->  00:00:12,960
you can't get risk down to zero.
7

7

00:00:12,960  -->  00:00:15,270
Instead, we need to mitigate that risk
8

8

00:00:15,270  -->  00:00:18,030
and we do that through a process of remediation.
9

9

00:00:18,030  -->  00:00:19,440
Now, when we have a vulnerability,
10

10

00:00:19,440  -->  00:00:23,400
this vulnerability must be prioritized and then remediated
11

11

00:00:23,400  -->  00:00:25,620
because we have limited resources.
12

12

00:00:25,620  -->  00:00:28,410
The way we usually do this is by looking at the risk.
13

13

00:00:28,410  -->  00:00:29,790
If it's a critical risk,
14

14

00:00:29,790  -->  00:00:31,950
then we're going to try to prioritize that higher.
15

15

00:00:31,950  -->  00:00:34,650
If it's a high risk, it'll be a little less high than that.
16

16

00:00:34,650  -->  00:00:35,820
If we go to medium or low,
17

17

00:00:35,820  -->  00:00:37,620
it's going to be further down the list.
18

18

00:00:37,620  -->  00:00:40,500
And eventually, we're going to have this one to N list
19

19

00:00:40,500  -->  00:00:42,990
with one being the highest, most critical priority
20

20

00:00:42,990  -->  00:00:46,290
and N being the 1258th priority
21

21

00:00:46,290  -->  00:00:49,650
that we're going to get to sometime at some point.
22

22

00:00:49,650  -->  00:00:52,200
And that's the idea of taking these vulnerabilities.
23

23

00:00:52,200  -->  00:00:53,940
Now, once we have prioritized them,
24

24

00:00:53,940  -->  00:00:55,890
we then start remediation.
25

25

00:00:55,890  -->  00:00:57,330
When we talk about remediation,
26

26

00:00:57,330  -->  00:01:00,630
remediation is the overall process of reducing exposure
27

27

00:01:00,630  -->  00:01:03,060
to the effects of risk factors.
28

28

00:01:03,060  -->  00:01:06,420
So remediation can be done lots of different ways.
29

29

00:01:06,420  -->  00:01:09,480
If you patch of vulnerability, that's a form of remediation.
30

30

00:01:09,480  -->  00:01:11,460
If you put in a compensating control,
31

31

00:01:11,460  -->  00:01:13,080
that's a form of remediation.
32

32

00:01:13,080  -->  00:01:14,700
If I isolate something from the network
33

33

00:01:14,700  -->  00:01:16,440
because it's really, really dangerous,
34

34

00:01:16,440  -->  00:01:18,480
that's a form of remediation too.
35

35

00:01:18,480  -->  00:01:21,000
Remediation can take lots of different forms,
36

36

00:01:21,000  -->  00:01:23,640
but the goal here is to reduce the exposure
37

37

00:01:23,640  -->  00:01:26,490
to minimize the leftover residual risk.
38

38

00:01:26,490  -->  00:01:29,250
Now, when we do our vulnerability management scans,
39

39

00:01:29,250  -->  00:01:31,470
we are going to come back with a vulnerability report
40

40

00:01:31,470  -->  00:01:33,750
and this report is going to offer recommendations
41

41

00:01:33,750  -->  00:01:37,410
for mitigations and fixes to the various security problems.
42

42

00:01:37,410  -->  00:01:39,900
They might say that for this particular vulnerability,
43

43

00:01:39,900  -->  00:01:41,220
there's a patch available.
44

44

00:01:41,220  -->  00:01:42,240
For this other one,
45

45

00:01:42,240  -->  00:01:44,400
you need to use this configuration setting.
46

46

00:01:44,400  -->  00:01:46,530
Whatever those things are, they're going to be included
47

47

00:01:46,530  -->  00:01:48,810
in those vulnerability reports when you're using a tool
48

48

00:01:48,810  -->  00:01:51,810
like Nessus or Qualys or OpenVAS.
49

49

00:01:51,810  -->  00:01:53,610
Now, when we go to do our mitigation,
50

50

00:01:53,610  -->  00:01:56,550
what is the goal when we conduct that mitigation?
51

51

00:01:56,550  -->  00:01:58,920
Well, our goal is not to erase risk entirely
52

52

00:01:58,920  -->  00:02:00,900
because that's just not possible.
53

53

00:02:00,900  -->  00:02:03,180
There will always be some risk in our networks.
54

54

00:02:03,180  -->  00:02:05,310
Instead, our goal is remediation
55

55

00:02:05,310  -->  00:02:08,130
because remediation is going to mitigate risk exposure
56

56

00:02:08,130  -->  00:02:09,690
down to an acceptable level
57

57

00:02:09,690  -->  00:02:12,360
based on your organizational risk appetite.
58

58

00:02:12,360  -->  00:02:14,040
Now, there are lots of different questions
59

59

00:02:14,040  -->  00:02:15,000
you have to think about
60

60

00:02:15,000  -->  00:02:16,890
when you start doing your mitigations here
61

61

00:02:16,890  -->  00:02:18,210
and your remediations.
62

62

00:02:18,210  -->  00:02:21,000
First, you're going to figure out how critical is the system.
63

63

00:02:21,000  -->  00:02:22,440
If it's a really critical system,
64

64

00:02:22,440  -->  00:02:24,720
that's going to determine what type of mitigations
65

65

00:02:24,720  -->  00:02:26,460
or remediations you can do.
66

66

00:02:26,460  -->  00:02:28,500
If it's a critical system to business operations,
67

67

00:02:28,500  -->  00:02:31,110
I can't isolate it from the network and turn it off
68

68

00:02:31,110  -->  00:02:32,880
even though that would solve the risk
69

69

00:02:32,880  -->  00:02:34,950
because that thing is critical to my operation,
70

70

00:02:34,950  -->  00:02:36,270
so I can't do that.
71

71

00:02:36,270  -->  00:02:38,670
I also have to think about how difficult is remediation.
72

72

00:02:38,670  -->  00:02:40,890
Is it as simple as changing a configuration setting
73

73

00:02:40,890  -->  00:02:42,120
or installing a patch,
74

74

00:02:42,120  -->  00:02:43,950
or do I need to completely overhaul
75

75

00:02:43,950  -->  00:02:45,720
the entire configuration of this system?
76

76

00:02:45,720  -->  00:02:47,310
Based on how difficult it is,
77

77

00:02:47,310  -->  00:02:49,860
that's going to factor into when we remediate it
78

78

00:02:49,860  -->  00:02:52,800
and how much money and resources we're going to put into it.
79

79

00:02:52,800  -->  00:02:53,970
And the last thing we have to think about
80

80

00:02:53,970  -->  00:02:55,980
is how risky is the issue?
81

81

00:02:55,980  -->  00:02:59,010
Now, just because a thing says it's a critical issue
82

82

00:02:59,010  -->  00:03:01,650
that depends on where it sits in your network.
83

83

00:03:01,650  -->  00:03:04,920
When you get a CVSS score and it looks like 10.0
84

84

00:03:04,920  -->  00:03:06,390
and it's something that's connected to the internet,
85

85

00:03:06,390  -->  00:03:08,190
that might be a critical issue.
86

86

00:03:08,190  -->  00:03:09,930
But if it's on an internal LAN
87

87

00:03:09,930  -->  00:03:11,850
that has no external network connectivity
88

88

00:03:11,850  -->  00:03:14,310
in a trusted enclave in a secure facility,
89

89

00:03:14,310  -->  00:03:15,600
that's not nearly as risky
90

90

00:03:15,600  -->  00:03:19,020
even though the CVSS would still say it has a 10.0
91

91

00:03:19,020  -->  00:03:22,320
because it is what is standard for that particular risk.
92

92

00:03:22,320  -->  00:03:24,270
So you have to look at each issue individually
93

93

00:03:24,270  -->  00:03:26,400
and figure out exactly how risky is it.
94

94

00:03:26,400  -->  00:03:29,820
Remember, our whole goal here is to reduce risk.
95

95

00:03:29,820  -->  00:03:31,500
We're not going to eliminate risk.
96

96

00:03:31,500  -->  00:03:33,300
We are going to reduce risk.
97

97

00:03:33,300  -->  00:03:35,130
Now, as we try to reduce risk,
98

98

00:03:35,130  -->  00:03:38,190
one of the most important things we use is change control.
99

99

00:03:38,190  -->  00:03:40,530
This is an important part of risk mitigation.
100

100

00:03:40,530  -->  00:03:41,730
Now, why is that?
101

101

00:03:41,730  -->  00:03:44,190
Because so many of the risks that we're trying to mitigate
102

102

00:03:44,190  -->  00:03:47,520
or remediate require us to make a change to a configuration
103

103

00:03:47,520  -->  00:03:50,040
or install an update to a piece of software.
104

104

00:03:50,040  -->  00:03:52,080
These are security patches, for instance.
105

105

00:03:52,080  -->  00:03:54,690
All of this needs to go through your change control process
106

106

00:03:54,690  -->  00:03:56,550
because if you just start installing things everywhere,
107

107

00:03:56,550  -->  00:03:58,020
you're actually going to be adding more risk
108

108

00:03:58,020  -->  00:03:59,610
to your network, not less.
109

109

00:03:59,610  -->  00:04:00,443
So you want to make sure
110

110

00:04:00,443  -->  00:04:02,400
there is an appropriate process that you're going to use
111

111

00:04:02,400  -->  00:04:05,010
and it is going through the proper change control process.
112

112

00:04:05,010  -->  00:04:06,540
Now, another thing we have to think about here
113

113

00:04:06,540  -->  00:04:09,270
is risk acceptance, because there is going to be
114

114

00:04:09,270  -->  00:04:11,610
some amount of risk that you just have to accept in life.
115

115

00:04:11,610  -->  00:04:13,560
You cannot eliminate all risk.
116

116

00:04:13,560  -->  00:04:15,150
And so when I talk about risk acceptance,
117

117

00:04:15,150  -->  00:04:17,130
we're talking about that there is no countermeasure
118

118

00:04:17,130  -->  00:04:18,180
that's put in place
119

119

00:04:18,180  -->  00:04:20,130
because the level of risk is low enough
120

120

00:04:20,130  -->  00:04:22,380
or the risk doesn't justify the cost
121

121

00:04:22,380  -->  00:04:24,240
to mitigate the associated risk.
122

122

00:04:24,240  -->  00:04:25,680
And I've mentioned this before,
123

123

00:04:25,680  -->  00:04:27,420
if I have a piece of software
124

124

00:04:27,420  -->  00:04:28,710
that might have a vulnerability
125

125

00:04:28,710  -->  00:04:31,590
that relates to something like $10,000 per year,
126

126

00:04:31,590  -->  00:04:34,290
but it would cost me a million dollars to remediate it,
127

127

00:04:34,290  -->  00:04:35,430
that wouldn't be worth it
128

128

00:04:35,430  -->  00:04:38,640
because I'm going to spend a million dollars to save $10,000.
129

129

00:04:38,640  -->  00:04:39,660
I wouldn't do that.
130

130

00:04:39,660  -->  00:04:41,730
We would simply accept that risk.
131

131

00:04:41,730  -->  00:04:43,560
Similarly, if it's a very low level risk,
132

132

00:04:43,560  -->  00:04:45,540
it may not justify spending any money
133

133

00:04:45,540  -->  00:04:48,540
or any time or any resources on fixing that.
134

134

00:04:48,540  -->  00:04:50,790
And so we have to think about these things.
135

135

00:04:50,790  -->  00:04:52,410
Now, when you accept a risk,
136

136

00:04:52,410  -->  00:04:54,870
you can't just say, "I accept it," and move on.
137

137

00:04:54,870  -->  00:04:56,520
There's something you have to do.
138

138

00:04:56,520  -->  00:04:57,960
When you accept a risk,
139

139

00:04:57,960  -->  00:05:01,110
you need to make sure that risk is still being monitored.
140

140

00:05:01,110  -->  00:05:02,580
Now, how do you do this?
141

141

00:05:02,580  -->  00:05:05,010
Generally, you're going to put it on your risk register.
142

142

00:05:05,010  -->  00:05:07,320
So you're still going to know that risk exists,
143

143

00:05:07,320  -->  00:05:08,317
but you notated,
144

144

00:05:08,317  -->  00:05:10,050
"I understand there's this amount of risk there
145

145

00:05:10,050  -->  00:05:11,790
and I'm going to accept it."
146

146

00:05:11,790  -->  00:05:13,170
That way, as we go through
147

147

00:05:13,170  -->  00:05:15,210
and do our further on risk management later on
148

148

00:05:15,210  -->  00:05:17,700
and we do more vulnerability scans and people identify this,
149

149

00:05:17,700  -->  00:05:20,010
you can go, "No, I understand there's that risk there.
150

150

00:05:20,010  -->  00:05:22,080
I've already accepted it. It was a low risk.
151

151

00:05:22,080  -->  00:05:23,127
We've gone through that process
152

152

00:05:23,127  -->  00:05:25,350
and we made the intelligent decision here."
153

153

00:05:25,350  -->  00:05:27,420
Now, once you do your risk mitigations,
154

154

00:05:27,420  -->  00:05:31,110
the last thing you need to do is go back and scan again.
155

155

00:05:31,110  -->  00:05:33,690
This way, your vulnerability should be re-scanned
156

156

00:05:33,690  -->  00:05:36,930
and verified against the mitigation that was put in place
157

157

00:05:36,930  -->  00:05:39,810
to verify what residual risk sits there.
158

158

00:05:39,810  -->  00:05:42,390
So if I had a server and there was 100 vulnerabilities
159

159

00:05:42,390  -->  00:05:45,180
and I patched 50 of them and accepted the other 50,
160

160

00:05:45,180  -->  00:05:47,700
I should then go through and scan it again
161

161

00:05:47,700  -->  00:05:48,930
and that should come back showing me
162

162

00:05:48,930  -->  00:05:51,060
that there's only 50 vulnerabilities left.
163

163

00:05:51,060  -->  00:05:52,680
Now, based on those 50 vulnerabilities,
164

164

00:05:52,680  -->  00:05:55,350
if they're all low or mediums, I can accept that risk.
165

165

00:05:55,350  -->  00:05:57,660
If they're highs and criticals, I might not,
166

166

00:05:57,660  -->  00:05:59,820
and I'd want to go back and do more patching.
167

167

00:05:59,820  -->  00:06:01,320
That's the idea here when we start dealing
168

168

00:06:01,320  -->  00:06:04,260
with verification of risk because after all,
169

169

00:06:04,260  -->  00:06:05,790
just because you installed a patch
170

170

00:06:05,790  -->  00:06:07,740
doesn't mean it actually solved the problem.
171

171

00:06:07,740  -->  00:06:09,960
Sometimes you're going to install a patch
172

172

00:06:09,960  -->  00:06:11,640
and that's going to fix one risk,
173

173

00:06:11,640  -->  00:06:13,860
but it introduce two or three new risks.
174

174

00:06:13,860  -->  00:06:16,050
So it's always important whenever you do a patch,
175

175

00:06:16,050  -->  00:06:18,900
you go back and you verify it by doing another scan
176

176

00:06:18,900  -->  00:06:20,160
and go through your results again
177

177

00:06:20,160  -->  00:06:22,800
and verify what is the residual that's left over
178

178

00:06:22,800  -->  00:06:24,700
because that is what you're accepting.
