1
1

00:00:00,310  -->  00:00:01,840
<v ->Asset Disposal.</v>
2

2

00:00:01,840  -->  00:00:04,600
In this lesson, we're going to talk about asset disposal,
3

3

00:00:04,600  -->  00:00:06,940
which is critical to the physical security of your devices
4

4

00:00:06,940  -->  00:00:08,700
and the data they process.
5

5

00:00:08,700  -->  00:00:11,610
Asset disposal occurs whenever a system is no longer needed
6

6

00:00:11,610  -->  00:00:13,160
by an organization.
7

7

00:00:13,160  -->  00:00:15,520
Now, once you're done using a device like a router,
8

8

00:00:15,520  -->  00:00:16,940
or a switch, or a firewall,
9

9

00:00:16,940  -->  00:00:18,720
and you replace it with a newer version,
10

10

00:00:18,720  -->  00:00:20,820
what are you going to do with that old device?
11

11

00:00:20,820  -->  00:00:22,180
Are you simply going to take it out of the rack
12

12

00:00:22,180  -->  00:00:23,360
and throw it in the corner?
13

13

00:00:23,360  -->  00:00:24,740
Are you going to give it to another organization
14

14

00:00:24,740  -->  00:00:25,573
like a charity,
15

15

00:00:25,573  -->  00:00:27,210
or are you going to throw it away?
16

16

00:00:27,210  -->  00:00:29,790
Well, this is really a question you have to think about
17

17

00:00:29,790  -->  00:00:31,050
in terms of risk tolerance
18

18

00:00:31,050  -->  00:00:33,870
and how your organization views it's security posture.
19

19

00:00:33,870  -->  00:00:36,010
Which method you decide is going to be documented
20

20

00:00:36,010  -->  00:00:38,400
inside your organization's disposal policy
21

21

00:00:38,400  -->  00:00:40,850
and it's something you need to think through.
22

22

00:00:40,850  -->  00:00:43,200
Now, regardless of which method you choose to use,
23

23

00:00:43,200  -->  00:00:44,780
you should first make sure that you're following
24

24

00:00:44,780  -->  00:00:47,810
your organization's policies for proper asset disposal,
25

25

00:00:47,810  -->  00:00:50,990
because these devices may still contain valuable information
26

26

00:00:50,990  -->  00:00:52,660
in the hands of an attacker.
27

27

00:00:52,660  -->  00:00:54,940
For example, if you're disposing of a switch,
28

28

00:00:54,940  -->  00:00:56,180
router or a firewall,
29

29

00:00:56,180  -->  00:00:58,260
your old configurations may still be located
30

30

00:00:58,260  -->  00:00:59,820
in the storage of that device.
31

31

00:00:59,820  -->  00:01:00,930
If you throw it in the dumpster
32

32

00:01:00,930  -->  00:01:03,240
and an attacker grabs it as part of dumpster diving,
33

33

00:01:03,240  -->  00:01:05,390
then they're going to see every single access control rule
34

34

00:01:05,390  -->  00:01:06,400
you have in that device
35

35

00:01:06,400  -->  00:01:08,580
and essentially, they can map out their attacks
36

36

00:01:08,580  -->  00:01:10,260
around your protections.
37

37

00:01:10,260  -->  00:01:12,870
So, when it comes time to dispose of an asset,
38

38

00:01:12,870  -->  00:01:15,300
it's important that we perform a factory reset,
39

39

00:01:15,300  -->  00:01:19,320
wipe the configuration, or sanitize the device for disposal.
40

40

00:01:19,320  -->  00:01:21,270
Now, many of our other network appliances
41

41

00:01:21,270  -->  00:01:23,340
are essentially just going to be Linux servers
42

42

00:01:23,340  -->  00:01:24,860
running specialized software.
43

43

00:01:24,860  -->  00:01:27,040
So even our old intrusion detection systems
44

44

00:01:27,040  -->  00:01:28,630
or intrusion protection systems,
45

45

00:01:28,630  -->  00:01:30,000
data loss prevention systems,
46

46

00:01:30,000  -->  00:01:31,670
and unified threat management systems
47

47

00:01:31,670  -->  00:01:33,780
will still need to properly be disposed of
48

48

00:01:33,780  -->  00:01:35,550
to ensure we don't let critical information
49

49

00:01:35,550  -->  00:01:37,130
fall into the wrong hands.
50

50

00:01:37,130  -->  00:01:39,650
For the rest of this lesson, I am going to talk specifically
51

51

00:01:39,650  -->  00:01:41,820
about proper disposal of networking equipment
52

52

00:01:41,820  -->  00:01:43,130
like routers and switches,
53

53

00:01:43,130  -->  00:01:45,360
but similar processes and procedures are available
54

54

00:01:45,360  -->  00:01:48,910
for all devices, appliances, and servers on your network.
55

55

00:01:48,910  -->  00:01:50,340
Now, the quickest and easiest way
56

56

00:01:50,340  -->  00:01:52,010
to prepare your devices for retirement
57

57

00:01:52,010  -->  00:01:54,140
is to perform a factory reset.
58

58

00:01:54,140  -->  00:01:55,690
A factory reset is a procedure
59

59

00:01:55,690  -->  00:01:57,890
that will remove all the customer-specific data
60

60

00:01:57,890  -->  00:01:59,420
that's been added to that network device
61

61

00:01:59,420  -->  00:02:01,660
since the time it was shipped from the manufacturer.
62

62

00:02:01,660  -->  00:02:04,360
This includes your IOS images, your boot images,
63

63

00:02:04,360  -->  00:02:08,220
configurations, log files, boot variables, core files,
64

64

00:02:08,220  -->  00:02:11,080
FIPS-related security keys, and credentials.
65

65

00:02:11,080  -->  00:02:13,960
To perform a factory reset on a Cisco device, for example,
66

66

00:02:13,960  -->  00:02:15,860
you simply need to enter the enable command
67

67

00:02:15,860  -->  00:02:17,350
from the command line interface
68

68

00:02:17,350  -->  00:02:19,380
to enter the privilege execution mode,
69

69

00:02:19,380  -->  00:02:22,980
then enter the command factory_reset all.
70

70

00:02:22,980  -->  00:02:25,120
Within a few minutes, you'll have a freshly-formatted
71

71

00:02:25,120  -->  00:02:27,920
and ready to retire Cisco router or switch.
72

72

00:02:27,920  -->  00:02:28,753
Now, on the other hand,
73

73

00:02:28,753  -->  00:02:31,170
if you only need to perform a wipe of your configurations,
74

74

00:02:31,170  -->  00:02:32,800
you can do this on a Cisco device
75

75

00:02:32,800  -->  00:02:34,580
using the write erase command.
76

76

00:02:34,580  -->  00:02:36,850
This will raise the NVRAM file system,
77

77

00:02:36,850  -->  00:02:38,100
and will remove both the running
78

78

00:02:38,100  -->  00:02:40,040
and startup configuration files.
79

79

00:02:40,040  -->  00:02:42,280
But when you use either of these two options,
80

80

00:02:42,280  -->  00:02:44,350
you're essentially just running a format command
81

81

00:02:44,350  -->  00:02:46,010
on the storage of these switches.
82

82

00:02:46,010  -->  00:02:47,300
If you're a bit more paranoid
83

83

00:02:47,300  -->  00:02:49,300
or you're dealing with a high security environment,
84

84

00:02:49,300  -->  00:02:50,650
you should take the extra step
85

85

00:02:50,650  -->  00:02:53,060
of sanitizing your devices for disposal.
86

86

00:02:53,060  -->  00:02:55,500
Now, the challenge is that sensitization procedures
87

87

00:02:55,500  -->  00:02:57,200
usually involve conducting a format
88

88

00:02:57,200  -->  00:03:00,100
and overwriting the non-volatile memory or storage
89

89

00:03:00,100  -->  00:03:03,180
with a series of randomized ones or zeros multiple times
90

90

00:03:03,180  -->  00:03:05,760
in order to prevent any reconstruction of the data remnants
91

91

00:03:05,760  -->  00:03:07,390
from the storage devices.
92

92

00:03:07,390  -->  00:03:09,070
So if you're using a network appliance
93

93

00:03:09,070  -->  00:03:10,850
that's essentially a Linux workstation,
94

94

00:03:10,850  -->  00:03:13,050
you can follow the standard overwrite procedures
95

95

00:03:13,050  -->  00:03:15,720
for sanitization of hard drives and solid state drives
96

96

00:03:15,720  -->  00:03:17,570
that you learned back in A+.
97

97

00:03:17,570  -->  00:03:20,230
But unfortunately, if you're using a router or a switch,
98

98

00:03:20,230  -->  00:03:21,830
this may not be possible.
99

99

00:03:21,830  -->  00:03:24,270
In those cases, you have to resort to the removal
100

100

00:03:24,270  -->  00:03:28,320
and physical destruction of the NVRAM and the flash modules
101

101

00:03:28,320  -->  00:03:29,600
from these devices.
102

102

00:03:29,600  -->  00:03:32,330
The NVRAM module stores your configuration files
103

103

00:03:32,330  -->  00:03:35,110
and the flash module stores the Cisco IOS,
104

104

00:03:35,110  -->  00:03:36,490
both of these are removable
105

105

00:03:36,490  -->  00:03:38,330
on most Cisco routers and switches.
106

106

00:03:38,330  -->  00:03:40,420
So you can take them out and destroy them.
107

107

00:03:40,420  -->  00:03:42,360
If you happen to work for the government or the military
108

108

00:03:42,360  -->  00:03:43,690
on a classified system,
109

109

00:03:43,690  -->  00:03:45,510
they will usually go to this level of effort
110

110

00:03:45,510  -->  00:03:48,620
to sanitize and destroy the NVRAM and flash modules
111

111

00:03:48,620  -->  00:03:51,090
prior to disposal, recycling or destruction
112

112

00:03:51,090  -->  00:03:53,950
of their secret and top secret routers and switches.
113

113

00:03:53,950  -->  00:03:56,160
That said, most businesses and organizations
114

114

00:03:56,160  -->  00:03:58,280
are instead going to rely on a factory reset
115

115

00:03:58,280  -->  00:04:00,030
or simply wiping the configurations
116

116

00:04:00,030  -->  00:04:02,150
prior to disposing of the devices.
117

117

00:04:02,150  -->  00:04:04,070
Now, when it comes to disposing of the information
118

118

00:04:04,070  -->  00:04:04,950
from our systems,
119

119

00:04:04,950  -->  00:04:07,180
we have some other methods that we can use as well.
120

120

00:04:07,180  -->  00:04:09,180
For example, if you have a bunch of backup tapes
121

121

00:04:09,180  -->  00:04:10,340
that need to be disposed of,
122

122

00:04:10,340  -->  00:04:11,690
you can actually shred those tapes
123

123

00:04:11,690  -->  00:04:13,900
by pulling the magnetic ribbons out of the casing,
124

124

00:04:13,900  -->  00:04:15,650
and then you can put them through the shredder,
125

125

00:04:15,650  -->  00:04:17,170
or you can even burn them
126

126

00:04:17,170  -->  00:04:19,100
as a method of physical destruction.
127

127

00:04:19,100  -->  00:04:21,450
If your organization is using hard drives for storage,
128

128

00:04:21,450  -->  00:04:24,140
these can be destroyed using a degaussing process.
129

129

00:04:24,140  -->  00:04:26,070
Degaussing is going to expose the hard disk
130

130

00:04:26,070  -->  00:04:27,660
to a powerful magnetic field
131

131

00:04:27,660  -->  00:04:29,480
and this causes the previously written data
132

132

00:04:29,480  -->  00:04:30,680
to be wiped from the drive
133

133

00:04:30,680  -->  00:04:33,500
and the drive becomes a blank slate once again.
134

134

00:04:33,500  -->  00:04:35,020
Now, I've also seen organizations
135

135

00:04:35,020  -->  00:04:36,340
that take this a step further
136

136

00:04:36,340  -->  00:04:38,140
and they physically destroy those hard drives
137

137

00:04:38,140  -->  00:04:39,970
to prevent the data from being exposed.
138

138

00:04:39,970  -->  00:04:42,080
And they do this by hitting them with axes,
139

139

00:04:42,080  -->  00:04:43,300
smashing them with hammers,
140

140

00:04:43,300  -->  00:04:45,020
or even using industrial shredders
141

141

00:04:45,020  -->  00:04:47,760
to turn that hard disk into tiny little pieces.
142

142

00:04:47,760  -->  00:04:50,170
Now, if all that sounds a little too violent for you,
143

143

00:04:50,170  -->  00:04:51,003
that's okay,
144

144

00:04:51,003  -->  00:04:53,310
there's electronic mechanisms to do this as well.
145

145

00:04:53,310  -->  00:04:56,270
This is known as purging or sanitizing.
146

146

00:04:56,270  -->  00:04:59,090
Now purging or sanitizing is the act of removing data
147

147

00:04:59,090  -->  00:05:01,500
in such a way that it can not be reconstructed
148

148

00:05:01,500  -->  00:05:03,710
using any known forensic techniques.
149

149

00:05:03,710  -->  00:05:06,640
This includes using special bit by bit erasing software
150

150

00:05:06,640  -->  00:05:09,370
that can allow you to rewrite the hard drive many times over
151

151

00:05:09,370  -->  00:05:11,130
with a series of ones and zeros.
152

152

00:05:11,130  -->  00:05:13,420
If you do this seven times or 35 times
153

153

00:05:13,420  -->  00:05:15,250
for really high security applications,
154

154

00:05:15,250  -->  00:05:18,170
you can actually erase that drive and reuse it again.
155

155

00:05:18,170  -->  00:05:20,900
Another technique you can use is to encrypt the drive.
156

156

00:05:20,900  -->  00:05:22,460
And if you destroy the encryption key,
157

157

00:05:22,460  -->  00:05:25,390
this again makes the data on that drive impossible to read,
158

158

00:05:25,390  -->  00:05:28,190
that's another way to basically sanitize your drive.
159

159

00:05:28,190  -->  00:05:30,160
Now, if you want to reuse that old hard drive
160

160

00:05:30,160  -->  00:05:31,240
more easily, though,
161

161

00:05:31,240  -->  00:05:33,520
you would instead use a clearing technique.
162

162

00:05:33,520  -->  00:05:35,640
Now, a clearing technique is the removal of data
163

163

00:05:35,640  -->  00:05:37,100
with a certain amount of assurance
164

164

00:05:37,100  -->  00:05:38,660
that it can't be reconstructed.
165

165

00:05:38,660  -->  00:05:39,493
For example,
166

166

00:05:39,493  -->  00:05:41,400
if you delete a file or folder from your hard disk,
167

167

00:05:41,400  -->  00:05:43,240
and then you replace that area that it was stored on
168

168

00:05:43,240  -->  00:05:46,350
with a series of zeros, this would constitute clearing.
169

169

00:05:46,350  -->  00:05:48,810
This is also used to do a secure erase function
170

170

00:05:48,810  -->  00:05:50,570
inside of some operating systems.
171

171

00:05:50,570  -->  00:05:52,830
Now, unfortunately, clearing is not foolproof
172

172

00:05:52,830  -->  00:05:55,340
and with special forensic techniques and procedures,
173

173

00:05:55,340  -->  00:05:57,160
you can actually recover that data,
174

174

00:05:57,160  -->  00:05:59,620
but again, it's a very low likelihood.
175

175

00:05:59,620  -->  00:06:01,220
Also, if you want to conduct something
176

176

00:06:01,220  -->  00:06:03,190
like a low level format of a hard disk,
177

177

00:06:03,190  -->  00:06:05,120
this could be considered clearing as well.
178

178

00:06:05,120  -->  00:06:06,180
The bottom line is,
179

179

00:06:06,180  -->  00:06:08,150
if you're working in a high security environment,
180

180

00:06:08,150  -->  00:06:09,940
you really shouldn't be using clearing.
181

181

00:06:09,940  -->  00:06:13,270
Instead, you should opt for purging or physical destruction.
182

182

00:06:13,270  -->  00:06:14,730
Now, when it comes down to it,
183

183

00:06:14,730  -->  00:06:16,850
the major security concern here that we're dealing with
184

184

00:06:16,850  -->  00:06:18,320
is data remnants.
185

185

00:06:18,320  -->  00:06:20,070
These are the leftover pieces of the data
186

186

00:06:20,070  -->  00:06:23,040
that may exist on the hard drive that we no longer needed.
187

187

00:06:23,040  -->  00:06:25,340
For example, let's say I took an old network appliance
188

188

00:06:25,340  -->  00:06:26,850
that runs on a Linux server,
189

189

00:06:26,850  -->  00:06:28,640
and I want to sell it to another person,
190

190

00:06:28,640  -->  00:06:31,030
I would want to ensure that they can't access any of the data
191

191

00:06:31,030  -->  00:06:32,930
that was previously stored on there, right?
192

192

00:06:32,930  -->  00:06:35,300
Well, to do that, I can remove the hard drive,
193

193

00:06:35,300  -->  00:06:37,050
but this would make that network appliance
194

194

00:06:37,050  -->  00:06:39,330
essentially unusable or unsellable.
195

195

00:06:39,330  -->  00:06:42,010
So instead, I can purge it or sanitize it
196

196

00:06:42,010  -->  00:06:44,290
by going through and using the overwrite procedures
197

197

00:06:44,290  -->  00:06:46,160
and then re-install the operating system
198

198

00:06:46,160  -->  00:06:48,290
for this appliance and all of the software
199

199

00:06:48,290  -->  00:06:50,590
as if I just received it from the factory again.
200

200

00:06:50,590  -->  00:06:52,540
As long as I overwrote every single sector
201

201

00:06:52,540  -->  00:06:54,530
of that hard drive multiple times,
202

202

00:06:54,530  -->  00:06:57,320
the fear of the data being recovered would be mitigated.
203

203

00:06:57,320  -->  00:06:59,130
Now, there is no right or wrong answer
204

204

00:06:59,130  -->  00:07:00,070
when it comes to deciding
205

205

00:07:00,070  -->  00:07:02,940
if an asset should be physically destroyed or reused.
206

206

00:07:02,940  -->  00:07:04,510
This is a decision you have to make
207

207

00:07:04,510  -->  00:07:07,110
as a cybersecurity professional based on the cost,
208

208

00:07:07,110  -->  00:07:09,200
the business case and the security issues
209

209

00:07:09,200  -->  00:07:10,890
that are involved in your organization
210

210

00:07:10,890  -->  00:07:13,253
and based on its asset disposal policies.
211

211

00:07:14,378  -->  00:07:16,655
(gentle electronic music)
