1
1

00:00:00,092  -->  00:00:03,090
<v Educator>Identity and Access Management.</v>
2

2

00:00:03,090  -->  00:00:05,026
In this lesson, we're going to start to examine
3

3

00:00:05,026  -->  00:00:08,280
the idea of identity and access management.
4

4

00:00:08,280  -->  00:00:10,440
When I talk about identity and access management,
5

5

00:00:10,440  -->  00:00:11,943
this is also called IAM.
6

6

00:00:13,110  -->  00:00:16,110
This is a security process that provides the identification,
7

7

00:00:16,110  -->  00:00:18,510
authentication, and authorization mechanisms
8

8

00:00:18,510  -->  00:00:20,776
for users, computers, and other entities
9

9

00:00:20,776  -->  00:00:23,910
to work with organizational assets like networks,
10

10

00:00:23,910  -->  00:00:26,160
operating systems, and applications.
11

11

00:00:26,160  -->  00:00:28,500
Essentially, when you log onto your computer,
12

12

00:00:28,500  -->  00:00:31,890
you're taking place inside of the IAM process
13

13

00:00:31,890  -->  00:00:34,410
because you're presenting a username and a password,
14

14

00:00:34,410  -->  00:00:36,060
and that's going to authenticate you,
15

15

00:00:36,060  -->  00:00:37,380
and that gives you authorization
16

16

00:00:37,380  -->  00:00:39,780
to certain things within your network.
17

17

00:00:39,780  -->  00:00:42,146
Now, every unique subject in the organization
18

18

00:00:42,146  -->  00:00:45,137
is identified and associated with an account.
19

19

00:00:45,137  -->  00:00:48,090
Now, when I talk about the term, a unique subject,
20

20

00:00:48,090  -->  00:00:49,590
what does that really mean?
21

21

00:00:49,590  -->  00:00:51,840
Well, a unique subject could be personnel,
22

22

00:00:51,840  -->  00:00:54,090
it could be endpoints, it could be servers,
23

23

00:00:54,090  -->  00:00:56,610
it could be softwares, or it could be roles.
24

24

00:00:56,610  -->  00:00:57,870
When I'm talking about personnel,
25

25

00:00:57,870  -->  00:01:00,687
this is the most common type of IAM that's defined.
26

26

00:01:00,687  -->  00:01:02,574
This is people and employees,
27

27

00:01:02,574  -->  00:01:03,754
those who have user accounts
28

28

00:01:03,754  -->  00:01:06,498
and log onto the system to do stuff with them.
29

29

00:01:06,498  -->  00:01:07,890
Now, this is really important
30

30

00:01:07,890  -->  00:01:11,250
because most computers aren't there just to be a computer.
31

31

00:01:11,250  -->  00:01:13,380
They're there to get some kind of value from it.
32

32

00:01:13,380  -->  00:01:15,039
And to get that value from the computer,
33

33

00:01:15,039  -->  00:01:17,040
you need people to use it.
34

34

00:01:17,040  -->  00:01:19,530
When my computer is just sitting here, it's a paperweight,
35

35

00:01:19,530  -->  00:01:20,970
but when I log onto my computer
36

36

00:01:20,970  -->  00:01:23,340
and I access the internet to answer your questions,
37

37

00:01:23,340  -->  00:01:24,870
I'm providing value.
38

38

00:01:24,870  -->  00:01:28,890
And that's why personnel are so important in terms of IAM.
39

39

00:01:28,890  -->  00:01:30,000
Now, another thing you have to think about
40

40

00:01:30,000  -->  00:01:31,470
when you're talking about personnel with IAM
41

41

00:01:31,470  -->  00:01:33,750
is that personnel is also a huge risk area
42

42

00:01:33,750  -->  00:01:36,060
because people write down their usernames and passwords,
43

43

00:01:36,060  -->  00:01:37,230
and that's a risk.
44

44

00:01:37,230  -->  00:01:38,970
People log into places carelessly
45

45

00:01:38,970  -->  00:01:41,105
and let their credentials get out, and that's a risk.
46

46

00:01:41,105  -->  00:01:43,410
So these are things you have to think about.
47

47

00:01:43,410  -->  00:01:46,320
The next area we want to talk about for IAM is endpoints.
48

48

00:01:46,320  -->  00:01:47,310
Now, we talk about endpoints,
49

49

00:01:47,310  -->  00:01:50,131
these are desktops and laptops and tablets and cell phones,
50

50

00:01:50,131  -->  00:01:51,910
and all of these things are endpoints.
51

51

00:01:51,910  -->  00:01:54,367
They're devices that people use to gain access
52

52

00:01:54,367  -->  00:01:57,374
to a network and be able to do their job.
53

53

00:01:57,374  -->  00:01:59,460
So, the personnel is going to have credentials
54

54

00:01:59,460  -->  00:02:00,614
to log onto the computer,
55

55

00:02:00,614  -->  00:02:02,275
and that computer is going to have credentials
56

56

00:02:02,275  -->  00:02:04,140
to log onto the network.
57

57

00:02:04,140  -->  00:02:05,172
And sometimes those are the same credentials
58

58

00:02:05,172  -->  00:02:07,950
but it's still different from an IAM perspective.
59

59

00:02:07,950  -->  00:02:09,870
Because the computer has its own set.
60

60

00:02:09,870  -->  00:02:12,812
Because it is a unique subject in the case of IAM.
61

61

00:02:12,812  -->  00:02:15,046
Now, the next area we're going to talk about is servers.
62

62

00:02:15,046  -->  00:02:17,414
Now, servers are a little bit different than endpoints.
63

63

00:02:17,414  -->  00:02:20,340
Endpoints are devices that users are going to log onto,
64

64

00:02:20,340  -->  00:02:22,110
but servers are sitting in the back,
65

65

00:02:22,110  -->  00:02:23,250
and a lot of times,
66

66

00:02:23,250  -->  00:02:26,010
servers are there for machine to machine communication.
67

67

00:02:26,010  -->  00:02:26,892
So each server also
68

68

00:02:26,892  -->  00:02:29,757
is going to have its own IAM credentials.
69

69

00:02:29,757  -->  00:02:32,190
These servers might have mission critical systems
70

70

00:02:32,190  -->  00:02:33,420
and encryption schemes
71

71

00:02:33,420  -->  00:02:35,220
and other things that are all going on,
72

72

00:02:35,220  -->  00:02:37,147
and all of that trust and identity that happens
73

73

00:02:37,147  -->  00:02:39,840
behind the scenes happens on these servers.
74

74

00:02:39,840  -->  00:02:42,097
So servers are another big part of IAM.
75

75

00:02:42,097  -->  00:02:45,330
Another area we have to think about with IAM is software.
76

76

00:02:45,330  -->  00:02:47,253
Just like servers, there are different applications
77

77

00:02:47,253  -->  00:02:50,373
that can take and feed requests to and from users,
78

78

00:02:50,373  -->  00:02:52,620
and that's going to require IAM.
79

79

00:02:52,620  -->  00:02:54,636
And so, software can also be a subject
80

80

00:02:54,636  -->  00:02:56,430
that has its own unique way,
81

81

00:02:56,430  -->  00:02:58,710
and usually this is going to be done using certificates
82

82

00:02:58,710  -->  00:03:00,983
like digital certificates to be able to allow
83

83

00:03:00,983  -->  00:03:03,192
or disallow a client from doing certain things
84

84

00:03:03,192  -->  00:03:05,370
with a certain piece of software.
85

85

00:03:05,370  -->  00:03:06,960
And finally, we have roles.
86

86

00:03:06,960  -->  00:03:09,450
This is the fifth type of unique subject.
87

87

00:03:09,450  -->  00:03:11,798
Roles are going to support the identities of various assets
88

88

00:03:11,798  -->  00:03:15,540
by defining the resources an asset has permission to access
89

89

00:03:15,540  -->  00:03:18,690
based on the function that the asset is going to fulfill.
90

90

00:03:18,690  -->  00:03:19,997
So, when we talk about roles,
91

91

00:03:19,997  -->  00:03:22,449
these roles can actually be assigned to servers
92

92

00:03:22,449  -->  00:03:25,044
or to people or to endpoints,
93

93

00:03:25,044  -->  00:03:26,790
and based on those roles,
94

94

00:03:26,790  -->  00:03:28,920
they're going to have different permission sets.
95

95

00:03:28,920  -->  00:03:30,264
Now, the great thing here with roles
96

96

00:03:30,264  -->  00:03:32,370
is that they're not limited to just people
97

97

00:03:32,370  -->  00:03:35,370
or just servers or just endpoints or just software.
98

98

00:03:35,370  -->  00:03:36,870
All of those can be roles.
99

99

00:03:36,870  -->  00:03:38,678
So while we have those other four categories,
100

100

00:03:38,678  -->  00:03:41,166
they can all be rolled down into roles as well
101

101

00:03:41,166  -->  00:03:43,710
if we configure ourself that way.
102

102

00:03:43,710  -->  00:03:44,687
Now, when you're dealing with roles,
103

103

00:03:44,687  -->  00:03:47,190
a lot of times we're going to do this inside of Windows
104

104

00:03:47,190  -->  00:03:48,690
by assigning people to different groups
105

105

00:03:48,690  -->  00:03:50,610
and then give those groups permissions.
106

106

00:03:50,610  -->  00:03:53,036
That's what you probably learned in A+ or Security+.
107

107

00:03:53,036  -->  00:03:54,688
So just keep that in mind when we talk about roles,
108

108

00:03:54,688  -->  00:03:57,001
that's usually the way things are going to be done.
109

109

00:03:57,001  -->  00:03:59,008
Now, when we talk about IAM tasks,
110

110

00:03:59,008  -->  00:04:01,498
there's lotsa different tasks that the system is going to do.
111

111

00:04:01,498  -->  00:04:04,290
Your roles is that they're not limited to just people
112

112

00:04:04,290  -->  00:04:07,230
or just servers or just endpoints or just software.
113

113

00:04:07,230  -->  00:04:09,930
IAM system is going to contain technical components,
114

114

00:04:09,930  -->  00:04:12,420
like directory services and repositories,
115

115

00:04:12,420  -->  00:04:13,253
access management tools,
116

116

00:04:13,253  -->  00:04:15,090
and systems that are going to do auditing
117

117

00:04:15,090  -->  00:04:17,481
and reporting on ID management capabilities.
118

118

00:04:17,481  -->  00:04:20,250
All of these things contain tasks that need to be done
119

119

00:04:20,250  -->  00:04:23,340
for an IAM system to function properly.
120

120

00:04:23,340  -->  00:04:24,510
Now, in addition to that,
121

121

00:04:24,510  -->  00:04:25,898
a lot of different things that might happen
122

122

00:04:25,898  -->  00:04:27,506
as part of the IAM system
123

123

00:04:27,506  -->  00:04:30,450
is things like creating and deprovisioning accounts.
124

124

00:04:30,450  -->  00:04:31,938
So if I'm going to create a new user,
125

125

00:04:31,938  -->  00:04:34,379
that's a creation or provisioning of an account.
126

126

00:04:34,379  -->  00:04:36,510
If I'm going to disable or delete a user,
127

127

00:04:36,510  -->  00:04:37,588
that's deprovisioning.
128

128

00:04:37,588  -->  00:04:39,360
When I talk about managing accounts,
129

129

00:04:39,360  -->  00:04:41,321
this includes things like resetting somebody's passwords,
130

130

00:04:41,321  -->  00:04:42,823
updating their digital certificates,
131

131

00:04:42,823  -->  00:04:45,240
managing their permissions and their authorizations,
132

132

00:04:45,240  -->  00:04:46,490
and other things of that nature.
133

133

00:04:46,490  -->  00:04:47,826
When I talk about auditing accounts,
134

134

00:04:47,826  -->  00:04:49,224
this is when I start looking at the activity
135

135

00:04:49,224  -->  00:04:51,893
that that account has done through the different logs
136

136

00:04:51,893  -->  00:04:54,450
and figure out was that legitimate or not?
137

137

00:04:54,450  -->  00:04:55,283
This is a big function
138

138

00:04:55,283  -->  00:04:57,570
inside the cybersecurity analyst role.
139

139

00:04:57,570  -->  00:04:59,550
You're going to do a lot of account auditing
140

140

00:04:59,550  -->  00:05:00,840
as you go through those systems,
141

141

00:05:00,840  -->  00:05:03,660
and this is going to be a big part of your IAM management.
142

142

00:05:03,660  -->  00:05:04,800
Another thing we're going to do
143

143

00:05:04,800  -->  00:05:06,661
is evaluate identity-based threats.
144

144

00:05:06,661  -->  00:05:08,130
Now what this means is we're going to do
145

145

00:05:08,130  -->  00:05:09,862
a lot of different things to identify any threats
146

146

00:05:09,862  -->  00:05:12,491
as a cybersecurity analyst to our IAM systems.
147

147

00:05:12,491  -->  00:05:13,410
For instance,
148

148

00:05:13,410  -->  00:05:15,458
you might run password checks across your network
149

149

00:05:15,458  -->  00:05:17,580
to see if there's any weak passwords.
150

150

00:05:17,580  -->  00:05:18,529
That is evaluating the security
151

151

00:05:18,529  -->  00:05:20,520
of your identity-based threats.
152

152

00:05:20,520  -->  00:05:22,290
You want to make sure those passwords are strong
153

153

00:05:22,290  -->  00:05:24,210
and so an attacker can't break into them.
154

154

00:05:24,210  -->  00:05:26,970
And the last thing we do is we want to maintain compliance.
155

155

00:05:26,970  -->  00:05:27,960
And to maintain compliance,
156

156

00:05:27,960  -->  00:05:29,536
we're going to go through checks and balances,
157

157

00:05:29,536  -->  00:05:30,667
we're going to go through audits,
158

158

00:05:30,667  -->  00:05:32,520
and we're going to make sure that we're meeting
159

159

00:05:32,520  -->  00:05:33,353
the requirements that we have set up
160

160

00:05:33,353  -->  00:05:35,700
for our system to run securely.
161

161

00:05:35,700  -->  00:05:37,200
And in the final part of this lesson,
162

162

00:05:37,200  -->  00:05:38,700
I want to talk about risk.
163

163

00:05:38,700  -->  00:05:40,932
What risks exist within IAM?
164

164

00:05:40,932  -->  00:05:42,727
Well, the biggest risk is really the risk
165

165

00:05:42,727  -->  00:05:44,329
caused by our accounts.
166

166

00:05:44,329  -->  00:05:45,430
And there are three main types
167

167

00:05:45,430  -->  00:05:47,142
of accounts that we're going to cover.
168

168

00:05:47,142  -->  00:05:48,480
There are user accounts,
169

169

00:05:48,480  -->  00:05:49,770
and these are your standard accounts
170

170

00:05:49,770  -->  00:05:51,630
that all your users are going to have.
171

171

00:05:51,630  -->  00:05:52,977
Now, these are the least risky for us
172

172

00:05:52,977  -->  00:05:55,560
because they just have basic user permissions,
173

173

00:05:55,560  -->  00:05:56,998
but they are still a risk.
174

174

00:05:56,998  -->  00:05:59,700
The second type of account we have are privileged accounts,
175

175

00:05:59,700  -->  00:06:01,138
and this is even more risky.
176

176

00:06:01,138  -->  00:06:02,225
The reason it's more risky
177

177

00:06:02,225  -->  00:06:05,250
is because this type of account has more permissions.
178

178

00:06:05,250  -->  00:06:06,240
As a privileged account,
179

179

00:06:06,240  -->  00:06:08,986
this is an administrator, a root user, or a super user.
180

180

00:06:08,986  -->  00:06:10,766
And so, they have permission to install software
181

181

00:06:10,766  -->  00:06:12,422
and uninstall software,
182

182

00:06:12,422  -->  00:06:14,730
and they can change passwords on other users,
183

183

00:06:14,730  -->  00:06:16,200
and they can create new accounts,
184

184

00:06:16,200  -->  00:06:19,620
and do all sorts of things making it a much more risky area,
185

185

00:06:19,620  -->  00:06:21,357
so it's an area you want to have additional auditing
186

186

00:06:21,357  -->  00:06:23,220
and additional compliance checks
187

187

00:06:23,220  -->  00:06:25,140
to make sure those accounts are safe.
188

188

00:06:25,140  -->  00:06:26,981
And finally, we have shared accounts.
189

189

00:06:26,981  -->  00:06:28,643
Now, shared accounts are typically used
190

190

00:06:28,643  -->  00:06:31,247
in small office, home office environments.
191

191

00:06:31,247  -->  00:06:32,820
You may have one account
192

192

00:06:32,820  -->  00:06:36,330
that everybody uses to log in to do some certain function.
193

193

00:06:36,330  -->  00:06:37,605
Now, this is a really dangerous practice
194

194

00:06:37,605  -->  00:06:40,290
because everybody has that shared password,
195

195

00:06:40,290  -->  00:06:41,790
and so you lose the ability to audit
196

196

00:06:41,790  -->  00:06:43,350
who actually did something
197

197

00:06:43,350  -->  00:06:44,926
because everybody's logging in as that user.
198

198

00:06:44,926  -->  00:06:46,507
I can't just go to the logs and say,
199

199

00:06:46,507  -->  00:06:49,044
"Ah, the shared account was on this system at this time.
200

200

00:06:49,044  -->  00:06:50,370
They must have done it."
201

201

00:06:50,370  -->  00:06:51,553
Well, who was the shared account?
202

202

00:06:51,553  -->  00:06:53,308
It could've been any of 10 different employees.
203

203

00:06:53,308  -->  00:06:54,269
We don't know.
204

204

00:06:54,269  -->  00:06:56,430
And so this is another area that's very risky,
205

205

00:06:56,430  -->  00:06:58,320
so it's not recommended to use shared accounts.
206

206

00:06:58,320  -->  00:07:01,080
Instead, you should have people using user accounts
207

207

00:07:01,080  -->  00:07:03,420
and put them into a role-based permissions group
208

208

00:07:03,420  -->  00:07:05,620
to allow them to do the functions they need.
