1
1

00:00:00,300  -->  00:00:01,230
<v Instructor>In this lesson,</v>
2

2

00:00:01,230  -->  00:00:03,330
we're going to talk about deperimeterization
3

3

00:00:03,330  -->  00:00:05,220
and the need to implement zero trust
4

4

00:00:05,220  -->  00:00:07,080
in order to secure your networks.
5

5

00:00:07,080  -->  00:00:09,500
First, what is deperimeterization?
6

6

00:00:09,500  -->  00:00:12,570
Now, deperimeterization is the removal of a boundary
7

7

00:00:12,570  -->  00:00:15,240
between an organization and the outside world.
8

8

00:00:15,240  -->  00:00:16,950
In the old days of computer networks,
9

9

00:00:16,950  -->  00:00:19,770
we would have all of our laptops, desktops, servers,
10

10

00:00:19,770  -->  00:00:21,270
and network devices contained
11

11

00:00:21,270  -->  00:00:23,280
within our own office buildings.
12

12

00:00:23,280  -->  00:00:24,960
Over time though, we added things
13

13

00:00:24,960  -->  00:00:27,480
like personal digital assistants and smartphones,
14

14

00:00:27,480  -->  00:00:29,610
and this allowed our networks to expand beyond the walls
15

15

00:00:29,610  -->  00:00:31,020
of our own buildings.
16

16

00:00:31,020  -->  00:00:33,810
These days, we cannot trust that all of our devices
17

17

00:00:33,810  -->  00:00:35,460
are going to be connecting to our networks
18

18

00:00:35,460  -->  00:00:37,680
from within our trusted office spaces.
19

19

00:00:37,680  -->  00:00:40,740
This is known as the deperimeterization of our networks.
20

20

00:00:40,740  -->  00:00:42,090
Now because of this,
21

21

00:00:42,090  -->  00:00:44,700
we cannot rely solely on perimeter-based defenses
22

22

00:00:44,700  -->  00:00:47,160
like firewalls, intrusion prevention systems,
23

23

00:00:47,160  -->  00:00:48,870
and other network appliances.
24

24

00:00:48,870  -->  00:00:50,970
Instead, we must protect our systems
25

25

00:00:50,970  -->  00:00:53,400
and data using multiple levels of encryption,
26

26

00:00:53,400  -->  00:00:55,980
secure protocols, data level authentication,
27

27

00:00:55,980  -->  00:00:58,440
and other host-based protection mechanisms.
28

28

00:00:58,440  -->  00:01:00,750
Now, deperimeterization is a wonderful thing
29

29

00:01:00,750  -->  00:01:02,550
from an operational perspective.
30

30

00:01:02,550  -->  00:01:04,260
It allows us to reduce our cost,
31

31

00:01:04,260  -->  00:01:05,880
conduct business to business transactions
32

32

00:01:05,880  -->  00:01:07,110
from anywhere in the world
33

33

00:01:07,110  -->  00:01:09,270
and become a more agile organization.
34

34

00:01:09,270  -->  00:01:12,090
The move to the cloud has rapidly increased our ability
35

35

00:01:12,090  -->  00:01:13,530
to conduct secure operations
36

36

00:01:13,530  -->  00:01:16,140
within a deperimeterization architecture.
37

37

00:01:16,140  -->  00:01:18,360
But deperimeterization has occurred
38

38

00:01:18,360  -->  00:01:20,220
due to the migration into the cloud,
39

39

00:01:20,220  -->  00:01:21,720
this increase in remote work,
40

40

00:01:21,720  -->  00:01:23,490
and the embracing of mobile technologies,
41

41

00:01:23,490  -->  00:01:24,990
and the use of wireless networks,
42

42

00:01:24,990  -->  00:01:27,600
as well as a move to outsourcing and contracting.
43

43

00:01:27,600  -->  00:01:31,290
But it does bring a lot of risk to us if we're not careful.
44

44

00:01:31,290  -->  00:01:33,420
Let's start by looking at mobile devices.
45

45

00:01:33,420  -->  00:01:36,690
When I began working in the IT field nearly two decades ago,
46

46

00:01:36,690  -->  00:01:39,330
networks were mostly comprised of servers, desktops,
47

47

00:01:39,330  -->  00:01:41,700
and a few laptops thrown in here and there.
48

48

00:01:41,700  -->  00:01:43,290
Over the past 10 years though,
49

49

00:01:43,290  -->  00:01:45,300
the type of devices that make up our networks
50

50

00:01:45,300  -->  00:01:48,270
have expanded to include mobile devices such as tablets,
51

51

00:01:48,270  -->  00:01:50,400
smartphones, and countless other devices
52

52

00:01:50,400  -->  00:01:52,281
that make up the internet of things.
53

53

00:01:52,281  -->  00:01:54,600
Due to this ever-increasing scope of devices
54

54

00:01:54,600  -->  00:01:56,850
on our networks, it's become very important
55

55

00:01:56,850  -->  00:01:58,770
to consider the unique challenges each
56

56

00:01:58,770  -->  00:02:01,410
of these devices bring into our organizations.
57

57

00:02:01,410  -->  00:02:02,839
Our organization must first consider
58

58

00:02:02,839  -->  00:02:05,850
if it's going to allow these devices to connect to the network,
59

59

00:02:05,850  -->  00:02:09,660
and if so, what security policies will reduce the risk
60

60

00:02:09,660  -->  00:02:12,570
that these various devices are going to introduce?
61

61

00:02:12,570  -->  00:02:14,580
Each device can connect to multiple networks,
62

62

00:02:14,580  -->  00:02:16,830
including our organizational wireless networks,
63

63

00:02:16,830  -->  00:02:18,870
the untrusted internet over cellular,
64

64

00:02:18,870  -->  00:02:20,370
the user's own home network,
65

65

00:02:20,370  -->  00:02:22,710
and even hotel or coffee shop's wireless networks
66

66

00:02:22,710  -->  00:02:24,870
when our employees are traveling for business.
67

67

00:02:24,870  -->  00:02:27,000
While we can't control all of these networks,
68

68

00:02:27,000  -->  00:02:30,000
each one of them introduces security risks into the devices,
69

69

00:02:30,000  -->  00:02:31,860
which in turn introduces them back
70

70

00:02:31,860  -->  00:02:33,810
into our organizational networks.
71

71

00:02:33,810  -->  00:02:35,670
So with the move to the cloud,
72

72

00:02:35,670  -->  00:02:38,280
many organizations are placing their critical data
73

73

00:02:38,280  -->  00:02:41,280
either in public cloud offerings like AWS, Azure,
74

74

00:02:41,280  -->  00:02:42,840
or Google Cloud's platform,
75

75

00:02:42,840  -->  00:02:44,910
or they're putting that data into software
76

76

00:02:44,910  -->  00:02:46,350
as a service offerings.
77

77

00:02:46,350  -->  00:02:48,660
Either way, the data now goes beyond the perimeter
78

78

00:02:48,660  -->  00:02:49,493
of your network,
79

79

00:02:49,493  -->  00:02:52,890
and this, too, is considered a form of deperimeterization.
80

80

00:02:52,890  -->  00:02:55,560
Increasingly, our employees are working remotely
81

81

00:02:55,560  -->  00:02:57,870
whether that's from their home, from a hotel room,
82

82

00:02:57,870  -->  00:02:59,640
or from a co-working space.
83

83

00:02:59,640  -->  00:03:01,170
Because of this increase in the number
84

84

00:03:01,170  -->  00:03:02,880
and type of locations being used,
85

85

00:03:02,880  -->  00:03:04,800
these employees and their data
86

86

00:03:04,800  -->  00:03:07,020
are also outside our traditional perimeters
87

87

00:03:07,020  -->  00:03:08,820
of the corporate network.
88

88

00:03:08,820  -->  00:03:11,130
When they're working outside of our corporate offices,
89

89

00:03:11,130  -->  00:03:13,050
our employees may also be using different types
90

90

00:03:13,050  -->  00:03:14,689
of connections back into our networks.
91

91

00:03:14,689  -->  00:03:17,100
For example, when they're working from a hotel
92

92

00:03:17,100  -->  00:03:18,210
or their home office,
93

93

00:03:18,210  -->  00:03:20,940
they might be using a wireless network, a cellular modem,
94

94

00:03:20,940  -->  00:03:23,490
or being directly cabled to an ethernet connection
95

95

00:03:23,490  -->  00:03:25,890
over a Cat 5 or Cat 6 cable.
96

96

00:03:25,890  -->  00:03:27,630
As the owner of the office network,
97

97

00:03:27,630  -->  00:03:29,190
you really won't have much control
98

98

00:03:29,190  -->  00:03:30,900
over which type of network they're connecting
99

99

00:03:30,900  -->  00:03:31,980
back to you over.
100

100

00:03:31,980  -->  00:03:33,801
So it's always the best practice
101

101

00:03:33,801  -->  00:03:36,600
to implement a concept known as zero trust
102

102

00:03:36,600  -->  00:03:38,459
to ensure the security of your corporate network
103

103

00:03:38,459  -->  00:03:40,440
and your corporate data.
104

104

00:03:40,440  -->  00:03:42,480
Now you see, in traditional networks,
105

105

00:03:42,480  -->  00:03:44,070
we used to believe that our networks
106

106

00:03:44,070  -->  00:03:45,476
and our users were trusted
107

107

00:03:45,476  -->  00:03:47,880
because we gave them access to our data,
108

108

00:03:47,880  -->  00:03:51,360
but under a zero trust model, that is not the case,
109

109

00:03:51,360  -->  00:03:54,140
and that is considered a good thing in a modern world.
110

110

00:03:54,140  -->  00:03:56,640
Zero trust is a security concept
111

111

00:03:56,640  -->  00:03:58,530
that's centered on the belief that organizations
112

112

00:03:58,530  -->  00:04:00,870
should not automatically trust anything inside
113

113

00:04:00,870  -->  00:04:02,970
or outside of its perimeters,
114

114

00:04:02,970  -->  00:04:05,462
and instead it must verify anything and everything
115

115

00:04:05,462  -->  00:04:07,410
that's trying to connect to its systems
116

116

00:04:07,410  -->  00:04:09,420
before granting them access.
117

117

00:04:09,420  -->  00:04:12,960
This all comes down to the fact that everyone is suspicious.
118

118

00:04:12,960  -->  00:04:14,935
Just because someone's using a username and password
119

119

00:04:14,935  -->  00:04:17,100
that was assigned to one of your users,
120

120

00:04:17,100  -->  00:04:20,010
you really don't know if that user is who they say they are
121

121

00:04:20,010  -->  00:04:21,539
and if they can be trusted.
122

122

00:04:21,539  -->  00:04:23,790
Zero trust is a strategic initiative
123

123

00:04:23,790  -->  00:04:26,070
that helps prevent successful data breaches
124

124

00:04:26,070  -->  00:04:27,870
by eliminating the concept of trust
125

125

00:04:27,870  -->  00:04:30,420
from an organization's network architecture.
126

126

00:04:30,420  -->  00:04:32,580
Instead zero trust can be used
127

127

00:04:32,580  -->  00:04:34,500
to protect modern digital environments
128

128

00:04:34,500  -->  00:04:36,390
by leveraging network segmentation,
129

129

00:04:36,390  -->  00:04:37,770
preventing lateral movement,
130

130

00:04:37,770  -->  00:04:39,870
providing layer 7 threat prevention,
131

131

00:04:39,870  -->  00:04:43,020
and simplifying granular user access control.
132

132

00:04:43,020  -->  00:04:45,467
Now, by using the concepts of microsegmentation,
133

133

00:04:45,467  -->  00:04:48,386
we can create microperimeters within our networks.
134

134

00:04:48,386  -->  00:04:50,558
Every time somebody tries to cross that perimeter
135

135

00:04:50,558  -->  00:04:52,470
either inbound or outbound,
136

136

00:04:52,470  -->  00:04:53,760
they're going to be checked again
137

137

00:04:53,760  -->  00:04:55,920
to see if they have the right access.
138

138

00:04:55,920  -->  00:04:57,510
These checks are not focused simply
139

139

00:04:57,510  -->  00:04:58,740
on authentication though,
140

140

00:04:58,740  -->  00:05:00,660
which is who is conducting the action,
141

141

00:05:00,660  -->  00:05:02,850
but it's also checking the what they want to do,
142

142

00:05:02,850  -->  00:05:05,370
where they're doing it from, why they're doing it,
143

143

00:05:05,370  -->  00:05:06,561
and how they're doing it.
144

144

00:05:06,561  -->  00:05:09,180
This policy of zero trust will determine
145

145

00:05:09,180  -->  00:05:10,830
who can transit the microperimeter
146

146

00:05:10,830  -->  00:05:12,480
at any given point in time,
147

147

00:05:12,480  -->  00:05:14,850
and this prevents access to your protected area
148

148

00:05:14,850  -->  00:05:16,800
by unauthorized users and prevents them
149

149

00:05:16,800  -->  00:05:19,320
from exfiltrating sensitive data from your network
150

150

00:05:19,320  -->  00:05:22,590
and other services, regardless of their actual location.
151

151

00:05:22,590  -->  00:05:23,760
The final consideration
152

152

00:05:23,760  -->  00:05:25,167
in this move to deperimeterization
153

153

00:05:25,167  -->  00:05:27,510
and the implementation of zero trust revolves
154

154

00:05:27,510  -->  00:05:29,880
around the world of outsourcing and contracting,
155

155

00:05:29,880  -->  00:05:33,330
which is ever on the increase inside modern organizations.
156

156

00:05:33,330  -->  00:05:35,910
You see, when we outsource functions within our company
157

157

00:05:35,910  -->  00:05:38,460
to a contractor, we're also going to be including methods
158

158

00:05:38,460  -->  00:05:41,460
for them to authenticate back into our network too.
159

159

00:05:41,460  -->  00:05:44,070
For example, I have a video editor on my staff,
160

160

00:05:44,070  -->  00:05:45,690
but I have additional video editors
161

161

00:05:45,690  -->  00:05:47,190
that I contract work out to
162

162

00:05:47,190  -->  00:05:50,400
whenever we're producing a lot of courses at the same time.
163

163

00:05:50,400  -->  00:05:52,620
Now, both of these video editors though need
164

164

00:05:52,620  -->  00:05:54,000
to access our file servers
165

165

00:05:54,000  -->  00:05:55,890
to access the videos that I recorded
166

166

00:05:55,890  -->  00:05:57,090
so they can do their job
167

167

00:05:57,090  -->  00:05:59,370
and make the final video that you're going to see.
168

168

00:05:59,370  -->  00:06:01,740
My on staff video editor can simply access it
169

169

00:06:01,740  -->  00:06:03,240
from our local internet,
170

170

00:06:03,240  -->  00:06:05,880
but my contracted video editor can't do that
171

171

00:06:05,880  -->  00:06:08,610
because they're not located in or near our offices.
172

172

00:06:08,610  -->  00:06:10,740
Instead, we have to implement the concept
173

173

00:06:10,740  -->  00:06:12,330
surrounding deperimeterization
174

174

00:06:12,330  -->  00:06:15,420
to allow them to securely access cloud-based file shares
175

175

00:06:15,420  -->  00:06:17,220
under our zero trust policy
176

176

00:06:17,220  -->  00:06:18,720
so they can access those files
177

177

00:06:18,720  -->  00:06:21,270
and perform their necessary job functions.
178

178

00:06:21,270  -->  00:06:23,940
As you begin to work with outsourcing and contractors,
179

179

00:06:23,940  -->  00:06:24,810
it's always important
180

180

00:06:24,810  -->  00:06:26,877
to identify what data they need access to,
181

181

00:06:26,877  -->  00:06:28,770
where it is currently being stored
182

182

00:06:28,770  -->  00:06:31,110
and how you're going to move that across the perimeter
183

183

00:06:31,110  -->  00:06:33,933
to give them access to the data while keeping it secure.
