1
1

00:00:00,360  -->  00:00:02,760
<v Instructor>Asset and change management.</v>
2

2

00:00:02,760  -->  00:00:04,500
In this lesson, we're going to focus
3

3

00:00:04,500  -->  00:00:06,510
on asset and change management,
4

4

00:00:06,510  -->  00:00:09,660
and why this is important to the security of your networks.
5

5

00:00:09,660  -->  00:00:11,160
Now, if you're like most people,
6

6

00:00:11,160  -->  00:00:14,340
you might go, "Jason, why does asset and change management
7

7

00:00:14,340  -->  00:00:16,020
affect the security of my networks?
8

8

00:00:16,020  -->  00:00:17,340
After all, that's something
9

9

00:00:17,340  -->  00:00:19,200
that those service management folks do.
10

10

00:00:19,200  -->  00:00:22,170
I'm an information security, I'm a cybersecurity person.
11

11

00:00:22,170  -->  00:00:23,760
I don't have to worry about that."
12

12

00:00:23,760  -->  00:00:25,440
Well, it is really important for us
13

13

00:00:25,440  -->  00:00:26,910
to know what is on our network
14

14

00:00:26,910  -->  00:00:28,830
because if we don't know what's on our network,
15

15

00:00:28,830  -->  00:00:30,390
how are we going to defend it?
16

16

00:00:30,390  -->  00:00:32,180
And that's why asset and change management
17

17

00:00:32,180  -->  00:00:33,450
is so important to us.
18

18

00:00:33,450  -->  00:00:36,240
So we're going to briefly talk about these two topics.
19

19

00:00:36,240  -->  00:00:37,950
We're going to talk about asset tagging
20

20

00:00:37,950  -->  00:00:40,320
and we're going to talk about change management.
21

21

00:00:40,320  -->  00:00:43,110
When I talk about asset tags, what are those?
22

22

00:00:43,110  -->  00:00:45,420
Well, if you've ever worked in a large corporate network,
23

23

00:00:45,420  -->  00:00:47,280
you've probably seen an asset tag.
24

24

00:00:47,280  -->  00:00:50,310
This is the practice of assigning an ID to an asset,
25

25

00:00:50,310  -->  00:00:52,140
and then associating that ID
26

26

00:00:52,140  -->  00:00:55,140
with those entries inside an inventory database.
27

27

00:00:55,140  -->  00:00:57,690
This way, I can know how many computers I have,
28

28

00:00:57,690  -->  00:01:00,900
how many mins I have, how many desktops I have,
29

29

00:01:00,900  -->  00:01:02,070
how many servers I have,
30

30

00:01:02,070  -->  00:01:04,170
and they're all tracked in a database.
31

31

00:01:04,170  -->  00:01:05,820
So if you go up to your computer at work
32

32

00:01:05,820  -->  00:01:06,653
and you look under,
33

33

00:01:06,653  -->  00:01:09,330
there might be a barcode and it just says Asset ID.
34

34

00:01:09,330  -->  00:01:11,100
Now, this can be something that can be a barcode
35

35

00:01:11,100  -->  00:01:12,180
that can be scanned,
36

36

00:01:12,180  -->  00:01:15,330
or it can be something like a radio frequency ID tag
37

37

00:01:15,330  -->  00:01:16,890
that's attached to the device.
38

38

00:01:16,890  -->  00:01:18,060
Either way is acceptable.
39

39

00:01:18,060  -->  00:01:20,970
It just depends on how your organization wants to do it.
40

40

00:01:20,970  -->  00:01:22,530
Either of these methods will work,
41

41

00:01:22,530  -->  00:01:24,720
and it just gives you a way to inventory those assets.
42

42

00:01:24,720  -->  00:01:26,370
Because if I have a computer
43

43

00:01:26,370  -->  00:01:28,350
and I downloaded a bunch of information to it,
44

44

00:01:28,350  -->  00:01:29,970
and now that computer is missing,
45

45

00:01:29,970  -->  00:01:30,870
that's an issue.
46

46

00:01:30,870  -->  00:01:32,580
And that's really an inventory issue,
47

47

00:01:32,580  -->  00:01:34,920
but it could have cybersecurity effects to us,
48

48

00:01:34,920  -->  00:01:36,810
because somebody can now access that data
49

49

00:01:36,810  -->  00:01:40,110
or use that lost laptop to connect to our network.
50

50

00:01:40,110  -->  00:01:41,100
And so we want to make sure
51

51

00:01:41,100  -->  00:01:43,110
we're tracking all of our things.
52

52

00:01:43,110  -->  00:01:44,820
Now, when we have these asset tags,
53

53

00:01:44,820  -->  00:01:47,040
they're going to correlate with the asset records
54

54

00:01:47,040  -->  00:01:48,780
for that particular thing.
55

55

00:01:48,780  -->  00:01:49,950
So if I have a laptop,
56

56

00:01:49,950  -->  00:01:52,620
it might contain things like vendor documentation,
57

57

00:01:52,620  -->  00:01:55,470
configuration information, and warranty information
58

58

00:01:55,470  -->  00:01:57,000
for that asset.
59

59

00:01:57,000  -->  00:01:59,010
And that's why these things are so important
60

60

00:01:59,010  -->  00:02:00,660
and so helpful to us.
61

61

00:02:00,660  -->  00:02:02,250
Now, we want to take it a step further though
62

62

00:02:02,250  -->  00:02:03,990
because just knowing what is out there
63

63

00:02:03,990  -->  00:02:06,450
and owned by the organization isn't enough.
64

64

00:02:06,450  -->  00:02:09,120
We also want to make sure we control that information
65

65

00:02:09,120  -->  00:02:11,340
and we control what those assets look like
66

66

00:02:11,340  -->  00:02:12,750
and how they're configured.
67

67

00:02:12,750  -->  00:02:15,180
And that's when we get into change management.
68

68

00:02:15,180  -->  00:02:17,010
Now, change management is the process
69

69

00:02:17,010  -->  00:02:19,080
through which changes to the configuration
70

70

00:02:19,080  -->  00:02:22,230
of information systems are monitored and controlled
71

71

00:02:22,230  -->  00:02:23,640
as part of your organization's
72

72

00:02:23,640  -->  00:02:26,130
overall configuration management efforts.
73

73

00:02:26,130  -->  00:02:28,590
Now, this is important because as you have a device
74

74

00:02:28,590  -->  00:02:30,960
and you have a new laptop and you've scanned it in,
75

75

00:02:30,960  -->  00:02:33,150
and you've tagged it, and you've put it on the network,
76

76

00:02:33,150  -->  00:02:35,040
you now know what that state is.
77

77

00:02:35,040  -->  00:02:36,660
That is the initial state of it.
78

78

00:02:36,660  -->  00:02:39,570
But over time, we're going to change the status of that device
79

79

00:02:39,570  -->  00:02:41,520
because we're going to install new software,
80

80

00:02:41,520  -->  00:02:42,900
we're going to change configurations,
81

81

00:02:42,900  -->  00:02:45,000
we're going to install patches and things like that.
82

82

00:02:45,000  -->  00:02:47,250
And all of that needs to be documented.
83

83

00:02:47,250  -->  00:02:50,220
Each individual component should have a separate document
84

84

00:02:50,220  -->  00:02:53,010
or a database record that describes its initial state
85

85

00:02:53,010  -->  00:02:55,470
and all of those subsequent changes.
86

86

00:02:55,470  -->  00:02:56,880
This way, we know exactly
87

87

00:02:56,880  -->  00:02:58,890
what any asset on the network looks like
88

88

00:02:58,890  -->  00:03:01,020
and how it's properly configured.
89

89

00:03:01,020  -->  00:03:02,840
Now, as you start looking at this information
90

90

00:03:02,840  -->  00:03:05,790
in change management, what are we going to really focus on?
91

91

00:03:05,790  -->  00:03:06,690
Well, we're going to focus
92

92

00:03:06,690  -->  00:03:08,520
on a lot of different pieces of information,
93

93

00:03:08,520  -->  00:03:10,650
including the configuration information,
94

94

00:03:10,650  -->  00:03:12,150
the patches that are installed,
95

95

00:03:12,150  -->  00:03:14,070
the backup records for that asset,
96

96

00:03:14,070  -->  00:03:16,080
and any incident reports or issues
97

97

00:03:16,080  -->  00:03:17,310
that may have been reported.
98

98

00:03:17,310  -->  00:03:19,800
Because again, that could all be information that we can use
99

99

00:03:19,800  -->  00:03:21,150
as part of our investigation
100

100

00:03:21,150  -->  00:03:24,300
and to know the state of that particular asset.
101

101

00:03:24,300  -->  00:03:26,130
Change management is going to ensure
102

102

00:03:26,130  -->  00:03:27,600
that all of the changes that we do
103

103

00:03:27,600  -->  00:03:29,460
are planned and controlled.
104

104

00:03:29,460  -->  00:03:31,710
We do this because it helps us minimize risk
105

105

00:03:31,710  -->  00:03:33,840
of causing a service disruption.
106

106

00:03:33,840  -->  00:03:35,705
So if I know that this particular server
107

107

00:03:35,705  -->  00:03:37,740
has two power supplies in it
108

108

00:03:37,740  -->  00:03:39,780
and one of them has failed three months ago
109

109

00:03:39,780  -->  00:03:42,840
and this server is four years old, what does that tell me?
110

110

00:03:42,840  -->  00:03:44,970
It's possible that we might need to change
111

111

00:03:44,970  -->  00:03:46,380
and replace that other power supply
112

112

00:03:46,380  -->  00:03:47,970
because it could fail too.
113

113

00:03:47,970  -->  00:03:49,470
And so we can keep track of this stuff
114

114

00:03:49,470  -->  00:03:52,470
as part of our asset management and our change management.
115

115

00:03:52,470  -->  00:03:55,080
In addition to that, anytime we want to do a change,
116

116

00:03:55,080  -->  00:03:57,090
we need to schedule that change.
117

117

00:03:57,090  -->  00:03:58,380
And that's why change management
118

118

00:03:58,380  -->  00:04:00,660
helps us get the approvals we need.
119

119

00:04:00,660  -->  00:04:02,190
Now, if we're going to deal with a change,
120

120

00:04:02,190  -->  00:04:04,140
they have to be categorized in some way.
121

121

00:04:04,140  -->  00:04:05,850
And normally, they're going to be categorized
122

122

00:04:05,850  -->  00:04:07,440
according to the potential impact
123

123

00:04:07,440  -->  00:04:09,330
and level of risk they could cause.
124

124

00:04:09,330  -->  00:04:11,280
We have changes that are major changes,
125

125

00:04:11,280  -->  00:04:13,710
or significant changes, or minor changes,
126

126

00:04:13,710  -->  00:04:15,270
or even normal changes.
127

127

00:04:15,270  -->  00:04:17,430
And based on which of these categories it is,
128

128

00:04:17,430  -->  00:04:19,920
it's going to require a different level of approval.
129

129

00:04:19,920  -->  00:04:23,250
For instance, if it's a normal change or a minor change,
130

130

00:04:23,250  -->  00:04:26,100
you might just do that through a supervisory approval.
131

131

00:04:26,100  -->  00:04:26,933
If you're going to do something
132

132

00:04:26,933  -->  00:04:28,230
that's a significant or major change,
133

133

00:04:28,230  -->  00:04:30,690
it might need to go higher up in the organization.
134

134

00:04:30,690  -->  00:04:32,490
Now, how do you request a change?
135

135

00:04:32,490  -->  00:04:35,040
Well, we have this thing called an RFC.
136

136

00:04:35,040  -->  00:04:37,320
An RFC is a request for change.
137

137

00:04:37,320  -->  00:04:39,990
Now, an RFC is essentially just a document,
138

138

00:04:39,990  -->  00:04:42,420
and this document is going to list the reason for a change
139

139

00:04:42,420  -->  00:04:44,880
and the procedures to implement that change.
140

140

00:04:44,880  -->  00:04:47,940
So if I want to install Windows 2016
141

141

00:04:47,940  -->  00:04:50,280
on this old Windows 2012 server,
142

142

00:04:50,280  -->  00:04:51,750
I'm going to list that we need to do it
143

143

00:04:51,750  -->  00:04:54,030
because 2012 is now end of life
144

144

00:04:54,030  -->  00:04:55,350
and we want to move to something newer.
145

145

00:04:55,350  -->  00:04:57,390
So we're going to move to Windows 2016
146

146

00:04:57,390  -->  00:04:59,010
or even something newer than that.
147

147

00:04:59,010  -->  00:05:00,600
We'll tell that's the reason for the change.
148

148

00:05:00,600  -->  00:05:02,910
Then what are the procedures to implement that change?
149

149

00:05:02,910  -->  00:05:05,370
Well, here are the 15 steps that we're going to take,
150

150

00:05:05,370  -->  00:05:07,020
and this is the amount of downtime we're going to need,
151

151

00:05:07,020  -->  00:05:08,730
and here's our plan that if something goes wrong,
152

152

00:05:08,730  -->  00:05:09,840
how we're going to roll back.
153

153

00:05:09,840  -->  00:05:11,370
And all of those things will be incorporated
154

154

00:05:11,370  -->  00:05:13,080
into this request for change.
155

155

00:05:13,080  -->  00:05:14,880
Now, again, if it's a small change,
156

156

00:05:14,880  -->  00:05:17,400
that might be a normal or a minor change,
157

157

00:05:17,400  -->  00:05:18,330
those can be approved
158

158

00:05:18,330  -->  00:05:20,190
at very low levels in the organization.
159

159

00:05:20,190  -->  00:05:22,620
But when you get up to a major or a significant change,
160

160

00:05:22,620  -->  00:05:24,060
these are going to require approval
161

161

00:05:24,060  -->  00:05:27,720
from your Change Advisory Board, known as the CAB.
162

162

00:05:27,720  -->  00:05:28,920
Now, a Change Advisory Board
163

163

00:05:28,920  -->  00:05:31,830
is essentially a group of leaders in the organization
164

164

00:05:31,830  -->  00:05:33,930
that have the technical and management know-how
165

165

00:05:33,930  -->  00:05:35,160
to look at these changes
166

166

00:05:35,160  -->  00:05:38,130
and decide when they're going to occur, based on the schedule,
167

167

00:05:38,130  -->  00:05:41,010
and if they should occur, based on the risk.
168

168

00:05:41,010  -->  00:05:43,020
Now, the risk isn't just cybersecurity though,
169

169

00:05:43,020  -->  00:05:44,327
the risk is also business.
170

170

00:05:44,327  -->  00:05:46,800
And so we have to weigh the business impact
171

171

00:05:46,800  -->  00:05:48,690
versus the risk to the systems.
172

172

00:05:48,690  -->  00:05:50,550
And based on that, we'll determine when
173

173

00:05:50,550  -->  00:05:53,310
and if those changes will get approved.
174

174

00:05:53,310  -->  00:05:55,440
Now, this is all part of change management,
175

175

00:05:55,440  -->  00:05:56,910
and that's what we're talking about here
176

176

00:05:56,910  -->  00:06:00,030
because all of these things have to be coordinated.
177

177

00:06:00,030  -->  00:06:01,110
When we have a change,
178

178

00:06:01,110  -->  00:06:02,850
we want to engage with our stakeholders.
179

179

00:06:02,850  -->  00:06:04,177
We want to talk with them and say,
180

180

00:06:04,177  -->  00:06:05,790
"Why do you need this change?"
181

181

00:06:05,790  -->  00:06:07,560
And see if there's a good reason for it.
182

182

00:06:07,560  -->  00:06:08,940
If they have a good change reason,
183

183

00:06:08,940  -->  00:06:10,650
then we're going to plan for that change.
184

184

00:06:10,650  -->  00:06:11,940
We're going to make sure we're improving
185

185

00:06:11,940  -->  00:06:13,440
that change process over time
186

186

00:06:13,440  -->  00:06:15,510
to make it faster and more resilient.
187

187

00:06:15,510  -->  00:06:17,340
We're also going to make sure we have the right team on board,
188

188

00:06:17,340  -->  00:06:20,130
and we're going to execute those changes in a methodical way.
189

189

00:06:20,130  -->  00:06:22,290
And as we do that, we're going to measure all of that.
190

190

00:06:22,290  -->  00:06:23,123
Why?
191

191

00:06:23,123  -->  00:06:23,956
Because we want to make sure
192

192

00:06:23,956  -->  00:06:25,350
we're meeting the goals that we set out.
193

193

00:06:25,350  -->  00:06:26,250
If we said this change
194

194

00:06:26,250  -->  00:06:27,810
was going to take five minutes to implement
195

195

00:06:27,810  -->  00:06:30,150
and it took us five hours, we need to know that
196

196

00:06:30,150  -->  00:06:31,620
because that's going to affect our planning
197

197

00:06:31,620  -->  00:06:33,150
for future iterations.
198

198

00:06:33,150  -->  00:06:35,310
And so change management is crucial for us
199

199

00:06:35,310  -->  00:06:37,530
to be able to have good security in our network.
200

200

00:06:37,530  -->  00:06:40,350
Now, anytime you're going to submit a change like an RFC,
201

201

00:06:40,350  -->  00:06:41,520
you need to accompany that
202

202

00:06:41,520  -->  00:06:43,740
with a rollback or remediation plan.
203

203

00:06:43,740  -->  00:06:44,850
Now, what are these?
204

204

00:06:44,850  -->  00:06:47,370
Well, this says that if something goes wrong,
205

205

00:06:47,370  -->  00:06:49,170
can we go back to the way we were
206

206

00:06:49,170  -->  00:06:50,850
and get back to the old good state?
207

207

00:06:50,850  -->  00:06:52,710
Because we know before we made the change,
208

208

00:06:52,710  -->  00:06:54,120
things were working fine.
209

209

00:06:54,120  -->  00:06:55,860
And so if I went and tried to upgrade something
210

210

00:06:55,860  -->  00:06:58,140
or install a patch and it broke something,
211

211

00:06:58,140  -->  00:07:01,140
can I roll back to the pre-patched state?
212

212

00:07:01,140  -->  00:07:02,070
I can do that.
213

213

00:07:02,070  -->  00:07:03,480
That means we can then get there,
214

214

00:07:03,480  -->  00:07:05,010
think about how we're going to fix this problem,
215

215

00:07:05,010  -->  00:07:06,750
and then we can move forward with the change again
216

216

00:07:06,750  -->  00:07:08,430
during the next window.
217

217

00:07:08,430  -->  00:07:09,750
Now, that brings another idea up,
218

218

00:07:09,750  -->  00:07:11,670
which is called a maintenance window.
219

219

00:07:11,670  -->  00:07:14,460
Now, many networks have scheduled maintenance windows
220

220

00:07:14,460  -->  00:07:16,530
and they use these for authorized downtime.
221

221

00:07:16,530  -->  00:07:18,420
So most companies will have something
222

222

00:07:18,420  -->  00:07:20,490
that looks like a Saturday night window,
223

223

00:07:20,490  -->  00:07:21,810
from midnight to 4:00 AM,
224

224

00:07:21,810  -->  00:07:24,570
because most companies are closed on Saturdays, right?
225

225

00:07:24,570  -->  00:07:25,710
And so if you're closed,
226

226

00:07:25,710  -->  00:07:27,150
you're not going to affect the business
227

227

00:07:27,150  -->  00:07:28,800
if you shut down that network.
228

228

00:07:28,800  -->  00:07:30,810
So they'll use that as a maintenance window.
229

229

00:07:30,810  -->  00:07:32,280
And that's the time that you're going to schedule
230

230

00:07:32,280  -->  00:07:34,470
all of the changes that need to be done.
231

231

00:07:34,470  -->  00:07:36,030
Now, this is great for the business folks,
232

232

00:07:36,030  -->  00:07:37,500
but it kind of stinks for us IT folks,
233

233

00:07:37,500  -->  00:07:39,750
'cause a lot of us end up having to work overnight shifts
234

234

00:07:39,750  -->  00:07:41,580
to be as part of these maintenance windows.
235

235

00:07:41,580  -->  00:07:43,860
But again, that's just part of the job.
236

236

00:07:43,860  -->  00:07:45,990
So when you have these maintenance windows,
237

237

00:07:45,990  -->  00:07:48,090
there's might be four hours that we know we have
238

238

00:07:48,090  -->  00:07:49,380
that we can have downtime.
239

239

00:07:49,380  -->  00:07:51,360
So part of the CAB's job is to schedule
240

240

00:07:51,360  -->  00:07:54,180
what changes will happen during that four-hour window.
241

241

00:07:54,180  -->  00:07:56,220
And that's why knowing how long something's going to take
242

242

00:07:56,220  -->  00:07:58,110
is really important as well.
243

243

00:07:58,110  -->  00:08:01,470
Now, for the exam, let me give you a couple of quick tips.
244

244

00:08:01,470  -->  00:08:04,140
You need to think through how you might install a patch
245

245

00:08:04,140  -->  00:08:05,610
or other type of change,
246

246

00:08:05,610  -->  00:08:08,040
and this comes down to change management.
247

247

00:08:08,040  -->  00:08:10,800
For example, if there's a brand new critical vulnerability
248

248

00:08:10,800  -->  00:08:13,260
that just came out today at 11:00 AM,
249

249

00:08:13,260  -->  00:08:15,000
are you going to cause a disruption to the network
250

250

00:08:15,000  -->  00:08:17,670
if you stop everything and install it right now?
251

251

00:08:17,670  -->  00:08:19,320
Or are you going to stop and analyze
252

252

00:08:19,320  -->  00:08:21,000
the risk to your business and your network,
253

253

00:08:21,000  -->  00:08:22,980
and then decide, "Hey, we should wait
254

254

00:08:22,980  -->  00:08:24,363
for an emergency maintenance window,
255

255

00:08:24,363  -->  00:08:25,740
that we might be able to get approved
256

256

00:08:25,740  -->  00:08:27,690
for tonight at nine o'clock."
257

257

00:08:27,690  -->  00:08:29,490
Or do you say, "You know what? Forget it.
258

258

00:08:29,490  -->  00:08:30,390
We'll just wait till Saturday
259

259

00:08:30,390  -->  00:08:32,730
for our regularly scheduled maintenance window."
260

260

00:08:32,730  -->  00:08:35,040
Now, all three of these may be the right answer.
261

261

00:08:35,040  -->  00:08:36,180
It really does depend though,
262

262

00:08:36,180  -->  00:08:38,250
because this is all about risk management.
263

263

00:08:38,250  -->  00:08:40,950
In general though, if you're dealing with a critical risk,
264

264

00:08:40,950  -->  00:08:42,930
you're going to want to get that fixed sooner,
265

265

00:08:42,930  -->  00:08:45,870
but you also don't want to cause business interruption.
266

266

00:08:45,870  -->  00:08:47,460
So you're going to have to get approval
267

267

00:08:47,460  -->  00:08:50,040
for something like a special emergency window.
268

268

00:08:50,040  -->  00:08:52,440
Now, that's actually going to be probably the best plan here.
269

269

00:08:52,440  -->  00:08:53,273
Why?
270

270

00:08:53,273  -->  00:08:55,770
Because that's going to give you today to plan the change,
271

271

00:08:55,770  -->  00:08:58,560
to get everybody on board, to get the team members together,
272

272

00:08:58,560  -->  00:09:00,930
to have a rollback plan in case something goes wrong,
273

273

00:09:00,930  -->  00:09:02,370
and even test that patch
274

274

00:09:02,370  -->  00:09:04,470
in a staging or test environment first.
275

275

00:09:04,470  -->  00:09:05,400
Then when people come in
276

276

00:09:05,400  -->  00:09:06,780
for the emergency maintenance window,
277

277

00:09:06,780  -->  00:09:08,670
we know we have the patch, we know it works,
278

278

00:09:08,670  -->  00:09:10,320
and we know what our rollback plan is.
279

279

00:09:10,320  -->  00:09:12,870
So that is balancing the risk versus reward.
280

280

00:09:12,870  -->  00:09:14,010
Now, for the exam,
281

281

00:09:14,010  -->  00:09:16,890
I always want you to think about measuring risk.
282

282

00:09:16,890  -->  00:09:19,440
Don't jump to conclusions and immediately patch things
283

283

00:09:19,440  -->  00:09:22,230
just because a critical patch was available from the vendor.
284

284

00:09:22,230  -->  00:09:25,290
You have to weigh the benefits of a more secure network now
285

285

00:09:25,290  -->  00:09:27,450
versus the loss of productivity that you might face
286

286

00:09:27,450  -->  00:09:29,310
if you take down the network to patch it.
287

287

00:09:29,310  -->  00:09:31,830
And so by balancing that and going, "You know what?
288

288

00:09:31,830  -->  00:09:33,360
it's already 11 o'clock.
289

289

00:09:33,360  -->  00:09:35,310
I can afford to wait till nine o'clock at night.
290

290

00:09:35,310  -->  00:09:36,150
And in the meantime,
291

291

00:09:36,150  -->  00:09:37,860
we're going to set up some additional monitoring
292

292

00:09:37,860  -->  00:09:39,360
and we're going to make sure we're protecting the network
293

293

00:09:39,360  -->  00:09:41,070
and see if anybody's trying to exploit
294

294

00:09:41,070  -->  00:09:42,630
this particular vulnerability.
295

295

00:09:42,630  -->  00:09:44,610
Then at nine o'clock when everybody's gone home,
296

296

00:09:44,610  -->  00:09:46,740
that's a good time for us to take down the network,
297

297

00:09:46,740  -->  00:09:48,900
run those patches, and bring it back up."
298

298

00:09:48,900  -->  00:09:50,670
So these are the kind of things you have to think through.
299

299

00:09:50,670  -->  00:09:52,957
It's not just clear cut and dry of,
300

300

00:09:52,957  -->  00:09:55,050
"There's a critical vulnerability, let's patch it."
301

301

00:09:55,050  -->  00:09:56,850
That's not always the right answer.
302

302

00:09:56,850  -->  00:09:58,200
So keep that in mind for the exam
303

303

00:09:58,200  -->  00:09:59,280
because these are the type of things
304

304

00:09:59,280  -->  00:10:01,440
I see students get tripped up on on the exam
305

305

00:10:01,440  -->  00:10:02,373
and lose points.
