1
1

00:00:00,090  -->  00:00:01,680
<v Narrator>In this lesson, we're going to discuss</v>
2

2

00:00:01,680  -->  00:00:04,410
a concept known as a single pane of glass.
3

3

00:00:04,410  -->  00:00:07,110
Now, a single pane of glass is a central point of access
4

4

00:00:07,110  -->  00:00:09,540
for all the information, tools and systems,
5

5

00:00:09,540  -->  00:00:12,390
the security team needs to effectively monitor, manage,
6

6

00:00:12,390  -->  00:00:15,540
and use to secure an organization's IT environment.
7

7

00:00:15,540  -->  00:00:17,720
A single pane of glass allows the security teams
8

8

00:00:17,720  -->  00:00:20,370
to have a unified view of their security posture
9

9

00:00:20,370  -->  00:00:22,560
and to quickly and easily access the information
10

10

00:00:22,560  -->  00:00:25,290
they need to make informed decisions.
11

11

00:00:25,290  -->  00:00:27,090
When using a single pane of glass,
12

12

00:00:27,090  -->  00:00:28,980
security teams can see all of their security
13

13

00:00:28,980  -->  00:00:31,710
related information, including things like logs,
14

14

00:00:31,710  -->  00:00:34,410
alerts, and reports in one place.
15

15

00:00:34,410  -->  00:00:36,960
This eliminates the need to log into multiple systems
16

16

00:00:36,960  -->  00:00:38,670
and reduces the time and effort required
17

17

00:00:38,670  -->  00:00:41,070
to manage your security operations.
18

18

00:00:41,070  -->  00:00:43,830
One of the main benefits of using a single pane of glass
19

19

00:00:43,830  -->  00:00:46,530
is that it simplifies the management of security operations
20

20

00:00:46,530  -->  00:00:48,000
by providing this unified view
21

21

00:00:48,000  -->  00:00:49,770
of security related information,
22

22

00:00:49,770  -->  00:00:51,660
that makes it easier for security teams
23

23

00:00:51,660  -->  00:00:53,670
to detect and respond to threats.
24

24

00:00:53,670  -->  00:00:55,980
Security teams can use a single pane of glass
25

25

00:00:55,980  -->  00:00:57,630
to monitor their environment for signs
26

26

00:00:57,630  -->  00:01:00,630
of suspicious activity such as unusual traffic patterns
27

27

00:01:00,630  -->  00:01:02,430
or failed login attempts.
28

28

00:01:02,430  -->  00:01:04,200
They can also use it to track the progress
29

29

00:01:04,200  -->  00:01:05,850
of incident response activities
30

30

00:01:05,850  -->  00:01:07,560
and to ensure that all necessary steps
31

31

00:01:07,560  -->  00:01:09,990
are being taken to resolve an incident.
32

32

00:01:09,990  -->  00:01:11,880
A single pane of glass also can improve
33

33

00:01:11,880  -->  00:01:14,310
the efficiency of your security operations center
34

34

00:01:14,310  -->  00:01:15,960
by automating many of the repetitive
35

35

00:01:15,960  -->  00:01:17,460
and time-consuming tasks
36

36

00:01:17,460  -->  00:01:19,890
that most security teams have to perform.
37

37

00:01:19,890  -->  00:01:23,100
For example, security teams can use the single pane of glass
38

38

00:01:23,100  -->  00:01:25,890
to automate the collection and analysis of log data,
39

39

00:01:25,890  -->  00:01:27,510
reducing the time and effort required
40

40

00:01:27,510  -->  00:01:29,610
to identify those potential threats.
41

41

00:01:29,610  -->  00:01:31,110
This allows the security team
42

42

00:01:31,110  -->  00:01:33,150
to then focus on more important tasks
43

43

00:01:33,150  -->  00:01:35,790
such as instant responses and threat hunting.
44

44

00:01:35,790  -->  00:01:37,890
Another benefit of a single pane of glass,
45

45

00:01:37,890  -->  00:01:39,510
is that it improves collaboration
46

46

00:01:39,510  -->  00:01:42,060
and communication within the security teams.
47

47

00:01:42,060  -->  00:01:44,670
With a single pane of glass, security teams can easily
48

48

00:01:44,670  -->  00:01:46,890
share information and coordinate their efforts
49

49

00:01:46,890  -->  00:01:48,690
when they're responding to a threat.
50

50

00:01:48,690  -->  00:01:50,850
This helps to improve the overall security posture
51

51

00:01:50,850  -->  00:01:53,370
of the organization, as security teams are able to
52

52

00:01:53,370  -->  00:01:55,650
work together more efficiently and effectively
53

53

00:01:55,650  -->  00:01:58,350
to identify and respond to the given threat.
54

54

00:01:58,350  -->  00:02:00,030
In addition to all of these other benefits,
55

55

00:02:00,030  -->  00:02:02,160
a single pane of glass can also make it easier
56

56

00:02:02,160  -->  00:02:04,590
for your security team to comply with regulatory
57

57

00:02:04,590  -->  00:02:06,360
and compliance requirements.
58

58

00:02:06,360  -->  00:02:08,820
Many regulations and standards will require
59

59

00:02:08,820  -->  00:02:10,830
your organization to maintain detailed logs
60

60

00:02:10,830  -->  00:02:13,740
and reports of your security related activities.
61

61

00:02:13,740  -->  00:02:15,930
And a single pane of glass makes it much easier
62

62

00:02:15,930  -->  00:02:17,940
to generate these reports and logs
63

63

00:02:17,940  -->  00:02:20,730
by providing the documentation that the organization needs
64

64

00:02:20,730  -->  00:02:23,130
to be able to demonstrate compliance with the regulatory
65

65

00:02:23,130  -->  00:02:26,400
and compliance requirements that are being levied upon them.
66

66

00:02:26,400  -->  00:02:28,410
Now, a single pane of glass can be implemented
67

67

00:02:28,410  -->  00:02:31,590
as software or hardware, but most of the time
68

68

00:02:31,590  -->  00:02:33,870
it is going to be a software based solution
69

69

00:02:33,870  -->  00:02:36,150
because it's more flexible in terms of the types of data
70

70

00:02:36,150  -->  00:02:38,250
sources that can be integrated into it
71

71

00:02:38,250  -->  00:02:40,830
than a hardware based solution might have.
72

72

00:02:40,830  -->  00:02:42,900
Now, there are five main steps to implementing
73

73

00:02:42,900  -->  00:02:45,270
a single pane of glass inside of your organization's
74

74

00:02:45,270  -->  00:02:47,010
security operations center.
75

75

00:02:47,010  -->  00:02:48,810
First, defining the requirements.
76

76

00:02:48,810  -->  00:02:51,660
Second, identifying and integrating data sources.
77

77

00:02:51,660  -->  00:02:53,760
Third, customizing the interface.
78

78

00:02:53,760  -->  00:02:56,070
Fourth, developing standard operating procedures
79

79

00:02:56,070  -->  00:02:57,990
and documentation and fifth,
80

80

00:02:57,990  -->  00:03:00,990
continuously monitoring and maintaining the solution.
81

81

00:03:00,990  -->  00:03:03,600
Now, the first step in implementing a single pane of glass
82

82

00:03:03,600  -->  00:03:05,700
is to define your requirements.
83

83

00:03:05,700  -->  00:03:08,220
This involves identifying the information, tools
84

84

00:03:08,220  -->  00:03:10,560
and systems that your security teams are going to need
85

85

00:03:10,560  -->  00:03:12,720
to effectively monitor, manage and secure
86

86

00:03:12,720  -->  00:03:15,150
the organization's IT environment.
87

87

00:03:15,150  -->  00:03:16,440
This should include the types of data
88

88

00:03:16,440  -->  00:03:18,090
that need to be collected and analyzed
89

89

00:03:18,090  -->  00:03:20,340
such as logs, alerts, and reports,
90

90

00:03:20,340  -->  00:03:22,500
as well as any other tools that need to be integrated
91

91

00:03:22,500  -->  00:03:24,150
such as intrusion detection systems
92

92

00:03:24,150  -->  00:03:26,580
and incident response platforms.
93

93

00:03:26,580  -->  00:03:28,380
Once the requirements have been defined,
94

94

00:03:28,380  -->  00:03:30,060
our second step is to identify
95

95

00:03:30,060  -->  00:03:31,920
and integrate the data sources.
96

96

00:03:31,920  -->  00:03:33,810
This involves identifying the data sources
97

97

00:03:33,810  -->  00:03:35,670
that your security team needs to access
98

98

00:03:35,670  -->  00:03:38,520
including your log servers and intrusion detection systems
99

99

00:03:38,520  -->  00:03:39,690
and then integrating those into
100

100

00:03:39,690  -->  00:03:41,790
the single pane of glass solution.
101

101

00:03:41,790  -->  00:03:44,700
This can be done using APIs, web hooks, plugins
102

102

00:03:44,700  -->  00:03:47,250
or connectors to allow your single pane of glass
103

103

00:03:47,250  -->  00:03:48,660
to collect and analyze data
104

104

00:03:48,660  -->  00:03:50,880
from all your various data sources.
105

105

00:03:50,880  -->  00:03:52,530
It's also important to consider the data
106

106

00:03:52,530  -->  00:03:54,330
in terms of format and location
107

107

00:03:54,330  -->  00:03:55,980
and to make sure it's all correlated
108

108

00:03:55,980  -->  00:03:57,240
so you can properly integrate it
109

109

00:03:57,240  -->  00:03:59,970
and analyze it inside of your solution.
110

110

00:03:59,970  -->  00:04:02,220
The third step is to customize your interface
111

111

00:04:02,220  -->  00:04:03,750
of your single pane of glass,
112

112

00:04:03,750  -->  00:04:05,010
to make sure it's meeting the needs
113

113

00:04:05,010  -->  00:04:07,170
of your security operations team.
114

114

00:04:07,170  -->  00:04:09,090
This includes designing the user interface
115

115

00:04:09,090  -->  00:04:11,010
and configuring the different panels and views
116

116

00:04:11,010  -->  00:04:13,710
that are going to be used to display information and data.
117

117

00:04:13,710  -->  00:04:14,910
It's also important to have a clear
118

118

00:04:14,910  -->  00:04:17,070
and organized layout that'll help the security team
119

119

00:04:17,070  -->  00:04:18,360
navigate through the data
120

120

00:04:18,360  -->  00:04:20,610
and make informed decisions quicker.
121

121

00:04:20,610  -->  00:04:23,190
The fourth step in the implementation is to develop
122

122

00:04:23,190  -->  00:04:25,620
the standard operating procedures or SOPs
123

123

00:04:25,620  -->  00:04:27,060
and associate documentation
124

124

00:04:27,060  -->  00:04:29,400
for your single pane of glass solution.
125

125

00:04:29,400  -->  00:04:31,110
This ensures that the security teams
126

126

00:04:31,110  -->  00:04:33,000
know how to use the single pane of glass
127

127

00:04:33,000  -->  00:04:34,890
and understand the processes and procedures
128

128

00:04:34,890  -->  00:04:37,650
that are being used to manage security operations.
129

129

00:04:37,650  -->  00:04:39,600
It also helps to ensure consistency
130

130

00:04:39,600  -->  00:04:43,140
and repeatability in the management of security operations.
131

131

00:04:43,140  -->  00:04:45,720
The fifth and final step, is to continually monitoring
132

132

00:04:45,720  -->  00:04:48,210
and maintaining your single pane of glass solution.
133

133

00:04:48,210  -->  00:04:50,070
This includes regularly reviewing the data
134

134

00:04:50,070  -->  00:04:51,720
and information that's being collected,
135

135

00:04:51,720  -->  00:04:53,970
as well as making adjustments as necessary
136

136

00:04:53,970  -->  00:04:56,250
to ensure the single pane of glass is meeting the needs
137

137

00:04:56,250  -->  00:04:59,640
of your security team and your security operation center.
138

138

00:04:59,640  -->  00:05:02,160
It's always important to ensure the single pane of glass
139

139

00:05:02,160  -->  00:05:04,350
is properly being configured and secured
140

140

00:05:04,350  -->  00:05:06,780
to protect against unauthorized access as well
141

141

00:05:06,780  -->  00:05:10,020
because it holds all of your critical data inside of it.
142

142

00:05:10,020  -->  00:05:11,940
Now as I said, there are many benefits
143

143

00:05:11,940  -->  00:05:13,920
to implementing a single pane of glass.
144

144

00:05:13,920  -->  00:05:15,480
This includes simplifying the management
145

145

00:05:15,480  -->  00:05:18,480
of security operations, making it easier for security teams
146

146

00:05:18,480  -->  00:05:20,220
to detect and respond to threats.
147

147

00:05:20,220  -->  00:05:22,530
Improving the efficiency of security operations
148

148

00:05:22,530  -->  00:05:24,120
by automating many of the repetitive
149

149

00:05:24,120  -->  00:05:25,410
and time-consuming tasks
150

150

00:05:25,410  -->  00:05:27,330
that your security team needs to perform.
151

151

00:05:27,330  -->  00:05:29,100
Improving collaboration and communication
152

152

00:05:29,100  -->  00:05:31,050
within your security teams to allow them
153

153

00:05:31,050  -->  00:05:32,460
to work together more effectively
154

154

00:05:32,460  -->  00:05:34,380
to identify and respond to threats,
155

155

00:05:34,380  -->  00:05:36,930
as well as to make it easier for organizations to comply
156

156

00:05:36,930  -->  00:05:39,090
with regulatory and compliance requirements
157

157

00:05:39,090  -->  00:05:40,860
by providing the necessary documentation
158

158

00:05:40,860  -->  00:05:42,750
to demonstrate their compliance.
159

159

00:05:42,750  -->  00:05:46,099
So remember, when you're utilizing a single pane of glass
160

160

00:05:46,099  -->  00:05:47,430
in your security operations center,
161

161

00:05:47,430  -->  00:05:50,370
it can really help to simplify the management of your SOC,
162

162

00:05:50,370  -->  00:05:52,410
improve the efficiency of your security teams
163

163

00:05:52,410  -->  00:05:54,660
and improve your overall security posture
164

164

00:05:54,660  -->  00:05:55,893
in your organization.
