1
1

00:00:00,480  -->  00:00:01,860
<v ->Risk Management.</v>
2

2

00:00:01,860  -->  00:00:04,770
In this lesson we're going to talk about risk management.
3

3

00:00:04,770  -->  00:00:07,650
In every network we have threats and vulnerabilities
4

4

00:00:07,650  -->  00:00:09,240
and when these two are combined,
5

5

00:00:09,240  -->  00:00:12,060
this is where risk is going to exist within our networks.
6

6

00:00:12,060  -->  00:00:13,550
Let's consider a simple example
7

7

00:00:13,550  -->  00:00:15,760
you probably deal with every day in your own life.
8

8

00:00:15,760  -->  00:00:17,200
When you're ready to go to bed at night
9

9

00:00:17,200  -->  00:00:18,950
do you lock the doors to your house?
10

10

00:00:18,950  -->  00:00:21,090
Well this little question each and every evening
11

11

00:00:21,090  -->  00:00:22,980
is going to be answered by your actions
12

12

00:00:22,980  -->  00:00:25,070
after you conduct a quick risk assessment
13

13

00:00:25,070  -->  00:00:27,340
as part of your ability to manage the risk to your home,
14

14

00:00:27,340  -->  00:00:29,180
its contents and your family.
15

15

00:00:29,180  -->  00:00:30,730
First you consider the threats.
16

16

00:00:30,730  -->  00:00:32,590
There might be a burglar who wants to get inside
17

17

00:00:32,590  -->  00:00:33,930
and steal all your valuables,
18

18

00:00:33,930  -->  00:00:36,260
or maybe you live in an area that's pretty windy,
19

19

00:00:36,260  -->  00:00:38,710
and this could result in the door being pushed open at night
20

20

00:00:38,710  -->  00:00:41,290
and the elements like the wind and the rain getting inside
21

21

00:00:41,290  -->  00:00:42,880
and ruining all your stuff.
22

22

00:00:42,880  -->  00:00:44,700
Next, you're going to consider the vulnerabilities
23

23

00:00:44,700  -->  00:00:45,600
that could exist.
24

24

00:00:45,600  -->  00:00:48,280
In this case, maybe you have a front door and a back door
25

25

00:00:48,280  -->  00:00:50,494
and a garage door that leads into your home.
26

26

00:00:50,494  -->  00:00:52,810
Now each of these represents a vulnerability
27

27

00:00:52,810  -->  00:00:54,769
if you don't lock it before you go to bed at night.
28

28

00:00:54,769  -->  00:00:56,773
Now should you lock these doors?
29

29

00:00:56,773  -->  00:01:00,180
Well, that depends on your assessment of the situation.
30

30

00:01:00,180  -->  00:01:01,510
If I was worried about a burglar,
31

31

00:01:01,510  -->  00:01:03,800
I probably would lock all three of these doors.
32

32

00:01:03,800  -->  00:01:04,880
But on the other hand
33

33

00:01:04,880  -->  00:01:06,000
if I'm trying to mitigate the threat
34

34

00:01:06,000  -->  00:01:07,340
of wind opening my door
35

35

00:01:07,340  -->  00:01:10,030
I may only need to lock the front door and the back door
36

36

00:01:10,030  -->  00:01:11,750
because the door leading into my garage
37

37

00:01:11,750  -->  00:01:13,120
is already protected from the wind
38

38

00:01:13,120  -->  00:01:15,180
because I have a large garage door there as well
39

39

00:01:15,180  -->  00:01:16,630
that's already in the closed position
40

40

00:01:16,630  -->  00:01:18,630
and it blocks the wind from entering my home.
41

41

00:01:18,630  -->  00:01:21,210
Now I know this is a pretty silly example but at its core,
42

42

00:01:21,210  -->  00:01:23,140
this is the basics of risk management.
43

43

00:01:23,140  -->  00:01:24,650
Risk management is the identification,
44

44

00:01:24,650  -->  00:01:27,380
evaluation, and prioritization of risks
45

45

00:01:27,380  -->  00:01:29,300
followed by the allocation of resources
46

46

00:01:29,300  -->  00:01:31,640
to minimize, monitor and control the probability
47

47

00:01:31,640  -->  00:01:35,160
or impact of a vulnerability being exploited by a threat.
48

48

00:01:35,160  -->  00:01:36,860
In order to conduct risk management
49

49

00:01:36,860  -->  00:01:39,060
we often conduct risk assessments.
50

50

00:01:39,060  -->  00:01:40,670
Now a risk assessment is a process
51

51

00:01:40,670  -->  00:01:42,090
to identify potential hazards
52

52

00:01:42,090  -->  00:01:44,760
and analyze what could happen if a hazard occurs.
53

53

00:01:44,760  -->  00:01:46,240
Simply put a risk assessment
54

54

00:01:46,240  -->  00:01:47,660
to determine its possible incidents,
55

55

00:01:47,660  -->  00:01:49,240
their likelihood and consequences,
56

56

00:01:49,240  -->  00:01:52,380
and your organization's tolerance for such events occurring.
57

57

00:01:52,380  -->  00:01:54,630
To conduct risk management within our organizations
58

58

00:01:54,630  -->  00:01:57,440
we usually use two different types of risk assessments;
59

59

00:01:57,440  -->  00:01:59,440
these are known as security risk assessments
60

60

00:01:59,440  -->  00:02:01,240
and business risk assessments.
61

61

00:02:01,240  -->  00:02:03,850
Now a security risk assessment is used to identify,
62

62

00:02:03,850  -->  00:02:06,160
assess, and implement key security controls
63

63

00:02:06,160  -->  00:02:08,700
within an application system or network.
64

64

00:02:08,700  -->  00:02:10,770
Security risk assessments may be conducted
65

65

00:02:10,770  -->  00:02:13,180
as a threat assessment, a vulnerability assessment,
66

66

00:02:13,180  -->  00:02:15,860
a penetration test, or a posture assessment.
67

67

00:02:15,860  -->  00:02:17,090
Now in a threat assessment
68

68

00:02:17,090  -->  00:02:18,740
we're going to focus on the identification
69

69

00:02:18,740  -->  00:02:20,840
of the different threats that may wish to attack
70

70

00:02:20,840  -->  00:02:23,040
or cause harm to our systems or networks.
71

71

00:02:23,040  -->  00:02:24,970
A common tool that we use to do this is known
72

72

00:02:24,970  -->  00:02:26,680
as the MITRE ATT&amp;CK framework.
73

73

00:02:26,680  -->  00:02:28,070
Now the MITRE ATT&amp;CK framework
74

74

00:02:28,070  -->  00:02:29,970
is a globally accessible knowledge base
75

75

00:02:29,970  -->  00:02:31,940
of adversary tactics and techniques
76

76

00:02:31,940  -->  00:02:34,240
based on real-world observations from the field
77

77

00:02:34,240  -->  00:02:35,950
and it lets an administrator or analyst
78

78

00:02:35,950  -->  00:02:37,760
walk through the typical methodologies
79

79

00:02:37,760  -->  00:02:40,100
that are used by different threats to harm your networks
80

80

00:02:40,100  -->  00:02:41,958
and identify where you should focus your resources
81

81

00:02:41,958  -->  00:02:43,970
to better protect yourself.
82

82

00:02:43,970  -->  00:02:46,020
Now a vulnerability assessment on the other hand
83

83

00:02:46,020  -->  00:02:48,060
is focused on identifying, quantifying,
84

84

00:02:48,060  -->  00:02:50,140
and prioritizing the risks and vulnerabilities
85

85

00:02:50,140  -->  00:02:51,640
in a system or network.
86

86

00:02:51,640  -->  00:02:53,370
To conduct a vulnerability assessment
87

87

00:02:53,370  -->  00:02:55,760
a technician will normally use a vulnerability scanner,
88

88

00:02:55,760  -->  00:02:58,660
something like Nessus or QualysGuard or OpenVAS
89

89

00:02:58,660  -->  00:03:01,350
to enumerate each system or machine on that network
90

90

00:03:01,350  -->  00:03:03,550
and identify the versions of every piece of hardware
91

91

00:03:03,550  -->  00:03:05,370
and software that's being used.
92

92

00:03:05,370  -->  00:03:08,330
And then it can create a summarized report of which systems
93

93

00:03:08,330  -->  00:03:09,520
have open vulnerabilities
94

94

00:03:09,520  -->  00:03:11,510
and which ones need to be remediated.
95

95

00:03:11,510  -->  00:03:13,060
Now the big difference between these two
96

96

00:03:13,060  -->  00:03:14,680
is whether you're looking at the target network
97

97

00:03:14,680  -->  00:03:17,830
through the eyes of the attacker or the eyes of a defender.
98

98

00:03:17,830  -->  00:03:20,560
Remember a threat is controlled by the attacker or an event.
99

99

00:03:20,560  -->  00:03:23,089
They get to determine how and when it could be occurring.
100

100

00:03:23,089  -->  00:03:24,857
Now a vulnerability on the other hand
101

101

00:03:24,857  -->  00:03:26,798
is usually going to be within your control.
102

102

00:03:26,798  -->  00:03:29,470
After all if you have an unpatched network router,
103

103

00:03:29,470  -->  00:03:30,650
that's a vulnerability,
104

104

00:03:30,650  -->  00:03:32,440
but you could remove that vulnerability
105

105

00:03:32,440  -->  00:03:35,340
by patching the system or replacing that router.
106

106

00:03:35,340  -->  00:03:36,860
Sure there are some vulnerabilities
107

107

00:03:36,860  -->  00:03:38,270
that you can't remove completely
108

108

00:03:38,270  -->  00:03:40,380
like the vulnerability of the network losing power,
109

109

00:03:40,380  -->  00:03:42,330
but you can't can add additional controls
110

110

00:03:42,330  -->  00:03:44,680
to help mitigate it and reduce that risk.
111

111

00:03:44,680  -->  00:03:46,240
You can do this by adding battery backups
112

112

00:03:46,240  -->  00:03:47,670
or diesel generators, for example,
113

113

00:03:47,670  -->  00:03:49,740
to provide secondary and tertiary backup power
114

114

00:03:49,740  -->  00:03:51,320
to your systems and your networks.
115

115

00:03:51,320  -->  00:03:53,450
In some security risk assessments
116

116

00:03:53,450  -->  00:03:55,090
they'll also combine a threat assessment
117

117

00:03:55,090  -->  00:03:57,840
and a vulnerability assessment into one single threat
118

118

00:03:57,840  -->  00:03:59,140
and vulnerability assessment
119

119

00:03:59,140  -->  00:04:01,270
to provide a more holistic perspective of your network
120

120

00:04:01,270  -->  00:04:02,460
and its security.
121

121

00:04:02,460  -->  00:04:04,400
The third kind of security risk assessment we have
122

122

00:04:04,400  -->  00:04:05,970
is a penetration test.
123

123

00:04:05,970  -->  00:04:07,570
Now a penetration test is an attempt
124

124

00:04:07,570  -->  00:04:09,669
to evaluate the security of an IT infrastructure
125

125

00:04:09,669  -->  00:04:11,760
by safely trying to exploit vulnerabilities
126

126

00:04:11,760  -->  00:04:13,282
within the system or networks.
127

127

00:04:13,282  -->  00:04:15,120
Penetration tests are also useful
128

128

00:04:15,120  -->  00:04:16,500
in validating the effectiveness
129

129

00:04:16,500  -->  00:04:17,950
of your defensive mechanisms,
130

130

00:04:17,950  -->  00:04:19,708
as well as the adherence of your security policies
131

131

00:04:19,708  -->  00:04:21,221
by your end users.
132

132

00:04:21,221  -->  00:04:23,611
Now a penetration test is a technical assessment
133

133

00:04:23,611  -->  00:04:25,742
where ethical hackers within your organization
134

134

00:04:25,742  -->  00:04:28,940
have permission to attempt to break into the network
135

135

00:04:28,940  -->  00:04:30,500
to validate your security controls
136

136

00:04:30,500  -->  00:04:32,654
and identify where improvements could be made.
137

137

00:04:32,654  -->  00:04:35,300
Now the fourth type of security risk assessment we have
138

138

00:04:35,300  -->  00:04:37,180
is known as a posture assessment.
139

139

00:04:37,180  -->  00:04:38,870
A posture assessment is used to assess
140

140

00:04:38,870  -->  00:04:40,720
your organization's attack surface
141

141

00:04:40,720  -->  00:04:41,950
in order for you to better understanding
142

142

00:04:41,950  -->  00:04:44,540
your cyber risk posture and exposure to threats
143

143

00:04:44,540  -->  00:04:47,430
that are caused by misconfigurations and patching delays.
144

144

00:04:47,430  -->  00:04:50,280
A posture assessment will often include four main steps:
145

145

00:04:50,280  -->  00:04:52,710
First define your mission-critical components,
146

146

00:04:52,710  -->  00:04:54,980
second, identify strengths, weaknesses,
147

147

00:04:54,980  -->  00:04:56,230
and security issues.
148

148

00:04:56,230  -->  00:04:57,990
Third, strengthen your position
149

149

00:04:57,990  -->  00:05:00,130
and fourth stay in control.
150

150

00:05:00,130  -->  00:05:01,710
By conducting a posture assessment,
151

151

00:05:01,710  -->  00:05:03,260
you will ensure you're always up to date
152

152

00:05:03,260  -->  00:05:05,080
on the status of your system security
153

153

00:05:05,080  -->  00:05:08,120
and to ensure you always understand the healthier systems.
154

154

00:05:08,120  -->  00:05:10,260
Often you'll combine this posture assessment
155

155

00:05:10,260  -->  00:05:12,680
with a threat and vulnerability assessment as well.
156

156

00:05:12,680  -->  00:05:15,210
Now, in addition to conducting security risk assessments
157

157

00:05:15,210  -->  00:05:16,970
your organization may also conduct
158

158

00:05:16,970  -->  00:05:18,470
business risk assessments.
159

159

00:05:18,470  -->  00:05:19,850
Now a business risk assessment
160

160

00:05:19,850  -->  00:05:20,990
is the process of identifying,
161

161

00:05:20,990  -->  00:05:23,213
understanding and evaluating potential hazards
162

162

00:05:23,213  -->  00:05:25,560
in the workplace concerning the day-to-day
163

163

00:05:25,560  -->  00:05:26,850
running of your company.
164

164

00:05:26,850  -->  00:05:29,710
Now there are two main types of business risk assessments,
165

165

00:05:29,710  -->  00:05:32,180
process assessments, and vendor assessments.
166

166

00:05:32,180  -->  00:05:33,250
A process assessment
167

167

00:05:33,250  -->  00:05:35,164
is the discipline examination of the processes
168

168

00:05:35,164  -->  00:05:38,200
used by your organization against a set of criteria
169

169

00:05:38,200  -->  00:05:40,170
to determine the capability of these processes
170

170

00:05:40,170  -->  00:05:43,158
to perform within the quality, cost, and schedule goals.
171

171

00:05:43,158  -->  00:05:45,670
Basically that's a lot of words to say
172

172

00:05:45,670  -->  00:05:47,080
this method is used to determine
173

173

00:05:47,080  -->  00:05:48,340
if you're doing the right things
174

174

00:05:48,340  -->  00:05:50,840
and if you're doing those things the correct way.
175

175

00:05:50,840  -->  00:05:53,130
Now maybe you have a process in your organization
176

176

00:05:53,130  -->  00:05:55,340
for the creation of a new user account on the network.
177

177

00:05:55,340  -->  00:05:57,900
This process may have eight steps to creating the account
178

178

00:05:57,900  -->  00:05:59,220
and then the entire process
179

179

00:05:59,220  -->  00:06:01,240
should take less than one work day to complete
180

180

00:06:01,240  -->  00:06:03,300
from the time the submitted request is received.
181

181

00:06:03,300  -->  00:06:05,180
This is the basis of your process.
182

182

00:06:05,180  -->  00:06:07,330
So during your process assessment
183

183

00:06:07,330  -->  00:06:09,490
the auditor might watch you perform this process
184

184

00:06:09,490  -->  00:06:11,050
and they'll see all the steps you do
185

185

00:06:11,050  -->  00:06:12,160
to make sure they make sense
186

186

00:06:12,160  -->  00:06:13,980
and to make sure you're doing them properly
187

187

00:06:13,980  -->  00:06:15,076
and within the proper timeframes
188

188

00:06:15,076  -->  00:06:16,670
to ensure it's all being done
189

189

00:06:16,670  -->  00:06:18,450
within the requirements you've set.
190

190

00:06:18,450  -->  00:06:19,730
Now after the assessment
191

191

00:06:19,730  -->  00:06:20,930
there may be some recommendations
192

192

00:06:20,930  -->  00:06:22,390
on how you could speed up the process
193

193

00:06:22,390  -->  00:06:24,270
or take some steps out, or refine it
194

194

00:06:24,270  -->  00:06:25,800
to get a better higher level of quality
195

195

00:06:25,800  -->  00:06:27,211
within some sort of the process.
196

196

00:06:27,211  -->  00:06:28,660
All of these are things that can come out
197

197

00:06:28,660  -->  00:06:30,270
of a process assessment.
198

198

00:06:30,270  -->  00:06:32,130
Now the second type of business risk assessment
199

199

00:06:32,130  -->  00:06:33,740
is known as a vendor assessment.
200

200

00:06:33,740  -->  00:06:35,010
A vendor assessment is defined
201

201

00:06:35,010  -->  00:06:37,521
as the assessment or evaluation of prospective vendor
202

202

00:06:37,521  -->  00:06:40,050
to determine if they can effectively meet the obligations
203

203

00:06:40,050  -->  00:06:42,460
and the needs of the business regarding the product.
204

204

00:06:42,460  -->  00:06:44,270
Now by conducting a vendor assessment
205

205

00:06:44,270  -->  00:06:46,538
we can assess the suppliers and contractors ability
206

206

00:06:46,538  -->  00:06:48,260
to ensure they're implementing and maintaining
207

207

00:06:48,260  -->  00:06:50,160
the appropriate security controls.
208

208

00:06:50,160  -->  00:06:51,740
This is also used to mitigate the threat
209

209

00:06:51,740  -->  00:06:53,750
of a supply chain vulnerability.
210

210

00:06:53,750  -->  00:06:55,410
For example, a few years ago,
211

211

00:06:55,410  -->  00:06:57,890
there was a big issue with counterfeit Cisco devices,
212

212

00:06:57,890  -->  00:06:59,150
these were routers and switches
213

213

00:06:59,150  -->  00:07:00,830
that were being sold to other businesses.
214

214

00:07:00,830  -->  00:07:03,190
Now these devices were being sold by third-party vendors,
215

215

00:07:03,190  -->  00:07:04,380
not Cisco directly.
216

216

00:07:04,380  -->  00:07:06,480
And these vendors themselves didn't even realize
217

217

00:07:06,480  -->  00:07:07,981
that they were selling counterfeit devices.
218

218

00:07:07,981  -->  00:07:10,560
The problem is that introduced new vulnerabilities
219

219

00:07:10,560  -->  00:07:12,770
into the business networks all over the world
220

220

00:07:12,770  -->  00:07:14,200
because these counterfeit Cisco devices
221

221

00:07:14,200  -->  00:07:16,070
had malware installed in their firmware,
222

222

00:07:16,070  -->  00:07:18,440
effectively giving the threat actors a backdoor
223

223

00:07:18,440  -->  00:07:20,920
into various business networks all over the globe.
224

224

00:07:20,920  -->  00:07:22,080
For reasons such as this,
225

225

00:07:22,080  -->  00:07:23,910
it is really important to vet your vendors
226

226

00:07:23,910  -->  00:07:25,890
and your suppliers to make sure they understand
227

227

00:07:25,890  -->  00:07:27,370
what their supply chain looks like
228

228

00:07:27,370  -->  00:07:29,350
and this way you can minimize your risk
229

229

00:07:29,350  -->  00:07:30,670
of supply chain issues.
230

230

00:07:30,670  -->  00:07:32,580
Also, you want to make sure that they won't fail
231

231

00:07:32,580  -->  00:07:34,400
to deliver on their contractual obligations
232

232

00:07:34,400  -->  00:07:37,050
and doing a vendor assessment can help with that too.
