1
1

00:00:00,450  -->  00:00:01,960
<v ->Network policies.</v>
2

2

00:00:01,960  -->  00:00:03,140
In this section of the course,
3

3

00:00:03,140  -->  00:00:05,183
we're going to talk about network policies.
4

4

00:00:05,183  -->  00:00:08,250
When we discuss policies, we're not talking specifically
5

5

00:00:08,250  -->  00:00:09,880
about technical controls anymore
6

6

00:00:09,880  -->  00:00:12,870
like adding access control lists to our firewalls or routers
7

7

00:00:12,870  -->  00:00:15,840
or enabling Mac filtering or even enforcing encryption
8

8

00:00:15,840  -->  00:00:16,943
and all the other things like that,
9

9

00:00:16,943  -->  00:00:19,200
that we do to better secure our networks.
10

10

00:00:19,200  -->  00:00:21,620
No, those are considered technical controls,
11

11

00:00:21,620  -->  00:00:24,220
and they're not the only way for us to secure our networks.
12

12

00:00:24,220  -->  00:00:26,350
In fact, there are a lot of network protections
13

13

00:00:26,350  -->  00:00:28,700
that will come in the form of administrative controls
14

14

00:00:28,700  -->  00:00:30,160
such as policies.
15

15

00:00:30,160  -->  00:00:31,630
So when we talk about policies,
16

16

00:00:31,630  -->  00:00:34,730
remember that policies are one part of a larger concept
17

17

00:00:34,730  -->  00:00:36,494
known as IT governance.
18

18

00:00:36,494  -->  00:00:38,010
IT governance is used to provide us
19

19

00:00:38,010  -->  00:00:40,300
with a comprehensive security management framework
20

20

00:00:40,300  -->  00:00:43,440
for the organization, and that way we can build upon it.
21

21

00:00:43,440  -->  00:00:45,820
Now this is done using policies, standards,
22

22

00:00:45,820  -->  00:00:48,460
baselines, guidelines, and procedures.
23

23

00:00:48,460  -->  00:00:50,870
Policies are going to be used to define the role of security
24

24

00:00:50,870  -->  00:00:52,350
inside of an organization
25

25

00:00:52,350  -->  00:00:54,070
and establishes the desired end state
26

26

00:00:54,070  -->  00:00:55,810
for that security program.
27

27

00:00:55,810  -->  00:00:58,320
This is usually going to be provided by senior management
28

28

00:00:58,320  -->  00:00:59,380
and it's going to clarify
29

29

00:00:59,380  -->  00:01:01,830
the level in which the organization enforces security
30

30

00:01:01,830  -->  00:01:04,360
and how the organization will categorize the controls
31

31

00:01:04,360  -->  00:01:05,920
that are going to be applied.
32

32

00:01:05,920  -->  00:01:07,600
Policies tend to be very broad
33

33

00:01:07,600  -->  00:01:09,180
and they provide the basic foundation
34

34

00:01:09,180  -->  00:01:12,670
upon which standards, baselines, guidelines, and procedures
35

35

00:01:12,670  -->  00:01:14,020
are going to be built.
36

36

00:01:14,020  -->  00:01:17,090
Security policies are going to be divided into three levels.
37

37

00:01:17,090  -->  00:01:20,820
This is organizational, system-specific, and issue-specific.
38

38

00:01:20,820  -->  00:01:22,400
Organizational security policies
39

39

00:01:22,400  -->  00:01:24,640
are going to provide direction and goals.
40

40

00:01:24,640  -->  00:01:25,830
They're going to give you a framework
41

41

00:01:25,830  -->  00:01:26,930
to meet the business goals
42

42

00:01:26,930  -->  00:01:29,530
and define the roles, responsibilities, and terms
43

43

00:01:29,530  -->  00:01:30,700
that are associated with it.
44

44

00:01:30,700  -->  00:01:33,330
System-specific policies are going to address the security
45

45

00:01:33,330  -->  00:01:36,020
of a specific technology, application, network,
46

46

00:01:36,020  -->  00:01:37,400
or computer system.
47

47

00:01:37,400  -->  00:01:39,070
These system-specific policies
48

48

00:01:39,070  -->  00:01:40,490
tend to be much more technical
49

49

00:01:40,490  -->  00:01:43,140
and they focus on protecting a certain piece of the system
50

50

00:01:43,140  -->  00:01:45,360
or a certain piece of technology.
51

51

00:01:45,360  -->  00:01:46,640
Issue-specific policies
52

52

00:01:46,640  -->  00:01:48,980
are built to address a specific security issue,
53

53

00:01:48,980  -->  00:01:52,060
such as email privacy, employee termination procedures,
54

54

00:01:52,060  -->  00:01:53,760
and other specific issues.
55

55

00:01:53,760  -->  00:01:55,140
As we move beyond policies,
56

56

00:01:55,140  -->  00:01:57,400
we begin to enter the world of standards.
57

57

00:01:57,400  -->  00:01:59,340
Now, standards are used to implement a policy
58

58

00:01:59,340  -->  00:02:00,810
within an organization.
59

59

00:02:00,810  -->  00:02:02,990
These are going to include things like mandatory actions,
60

60

00:02:02,990  -->  00:02:04,820
steps or rules that are needed
61

61

00:02:04,820  -->  00:02:07,210
to achieve the desired level of security.
62

62

00:02:07,210  -->  00:02:09,400
After standards, we have baselines.
63

63

00:02:09,400  -->  00:02:11,670
And baselines are going to be used to create a reference point
64

64

00:02:11,670  -->  00:02:13,960
in our network architecture and design.
65

65

00:02:13,960  -->  00:02:16,750
These baselines are used to document any kind of system
66

66

00:02:16,750  -->  00:02:19,290
so we can go back later and compare it for analysis
67

67

00:02:19,290  -->  00:02:20,870
against that baseline.
68

68

00:02:20,870  -->  00:02:23,220
For example, we may have a baseline configuration
69

69

00:02:23,220  -->  00:02:24,410
for our network switches,
70

70

00:02:24,410  -->  00:02:27,140
and we can compare the running configuration on any switch
71

71

00:02:27,140  -->  00:02:28,600
to our baseline at any time
72

72

00:02:28,600  -->  00:02:30,940
to see what changes have been made by our administrators
73

73

00:02:30,940  -->  00:02:32,780
or a possible attacker.
74

74

00:02:32,780  -->  00:02:34,570
Next, we have guidelines.
75

75

00:02:34,570  -->  00:02:37,110
Guidelines are not required or mandatory actions,
76

76

00:02:37,110  -->  00:02:39,810
but instead, they're simply recommended actions.
77

77

00:02:39,810  -->  00:02:41,670
Guidelines tend to be flexible in nature,
78

78

00:02:41,670  -->  00:02:43,530
and they allow exceptions and allowances
79

79

00:02:43,530  -->  00:02:45,780
when a unique situation is going to occur.
80

80

00:02:45,780  -->  00:02:47,840
For example, let's pretend I have a guideline
81

81

00:02:47,840  -->  00:02:49,890
that every employee gets one terabyte of storage
82

82

00:02:49,890  -->  00:02:51,200
on our cloud servers.
83

83

00:02:51,200  -->  00:02:53,600
That might be fine for most of the people who work here.
84

84

00:02:53,600  -->  00:02:55,350
Now, our salespeople, and our accountants,
85

85

00:02:55,350  -->  00:02:56,450
and human resources,
86

86

00:02:56,450  -->  00:02:57,400
all of those folks
87

87

00:02:57,400  -->  00:02:59,460
would have no problem fitting all of their documents
88

88

00:02:59,460  -->  00:03:01,220
into that one terabyte of space
89

89

00:03:01,220  -->  00:03:03,600
because most of what they do is text files.
90

90

00:03:03,600  -->  00:03:05,670
Those users will have lots of space here.
91

91

00:03:05,670  -->  00:03:08,177
But my video editor, she might come up and say,
92

92

00:03:08,177  -->  00:03:09,550
"Hey, I'm running out of space.
93

93

00:03:09,550  -->  00:03:11,770
I need at least five terabytes of storage."
94

94

00:03:11,770  -->  00:03:14,110
Well, based on our storage size limitations,
95

95

00:03:14,110  -->  00:03:15,700
if they're based on a guideline,
96

96

00:03:15,700  -->  00:03:17,020
I can make an exception to that
97

97

00:03:17,020  -->  00:03:19,050
and allow her to have five terabytes
98

98

00:03:19,050  -->  00:03:20,270
instead of one terabyte,
99

99

00:03:20,270  -->  00:03:22,800
because it meets the needs of her specific job role
100

100

00:03:22,800  -->  00:03:25,530
because she's dealing with large video files all day long.
101

101

00:03:25,530  -->  00:03:26,910
That's the idea of a guideline.
102

102

00:03:26,910  -->  00:03:29,070
It's something that can be changed on the fly
103

103

00:03:29,070  -->  00:03:31,020
and an exception can be quickly made.
104

104

00:03:31,020  -->  00:03:32,640
Next, we have procedures.
105

105

00:03:32,640  -->  00:03:35,330
Now, procedures are detailed step-by-step instructions
106

106

00:03:35,330  -->  00:03:36,163
that are created
107

107

00:03:36,163  -->  00:03:37,810
to ensure personnel can perform a given task
108

108

00:03:37,810  -->  00:03:39,240
or series of actions.
109

109

00:03:39,240  -->  00:03:41,620
These procedures are where those high-level policies
110

110

00:03:41,620  -->  00:03:43,010
are transferred all the way down
111

111

00:03:43,010  -->  00:03:45,930
through those standards and guidelines into actionable steps
112

112

00:03:45,930  -->  00:03:47,720
that can be followed by a technician.
113

113

00:03:47,720  -->  00:03:50,400
For example, your service desk probably has a procedure
114

114

00:03:50,400  -->  00:03:52,290
on how to create a new user account.
115

115

00:03:52,290  -->  00:03:53,520
This procedure encompasses
116

116

00:03:53,520  -->  00:03:55,340
all of the security-related policies,
117

117

00:03:55,340  -->  00:03:58,220
standards and guidelines to allow your frontline employees
118

118

00:03:58,220  -->  00:04:00,060
to be able to follow the step-by-step actions
119

119

00:04:00,060  -->  00:04:01,690
necessary to create a new account
120

120

00:04:01,690  -->  00:04:03,610
and give that account the proper permissions,
121

121

00:04:03,610  -->  00:04:04,780
the correct password strength,
122

122

00:04:04,780  -->  00:04:06,560
and all of those types of things.
123

123

00:04:06,560  -->  00:04:08,020
For the exam, I want you to remember
124

124

00:04:08,020  -->  00:04:09,570
all the different types of policies we have
125

125

00:04:09,570  -->  00:04:11,800
inside of our governance as we work our way down
126

126

00:04:11,800  -->  00:04:13,890
from the more generic to the more specific.
127

127

00:04:13,890  -->  00:04:16,750
This includes our policies, our standards, our baselines,
128

128

00:04:16,750  -->  00:04:18,760
our guidelines, and our procedures.
129

129

00:04:18,760  -->  00:04:20,200
Now, in this section of the course,
130

130

00:04:20,200  -->  00:04:23,080
we're going to focus on Domain 3: Network Operations,
131

131

00:04:23,080  -->  00:04:25,460
specifically in Objective 3.2.
132

132

00:04:25,460  -->  00:04:26,840
Objective 3.2 states
133

133

00:04:26,840  -->  00:04:28,490
that you must be able to explain the purpose
134

134

00:04:28,490  -->  00:04:30,950
of organizational documents and policies.
135

135

00:04:30,950  -->  00:04:32,460
So let's get started talking
136

136

00:04:32,460  -->  00:04:35,270
all about the different policies and plans and procedures,
137

137

00:04:35,270  -->  00:04:37,800
hardening and security policies and common agreements
138

138

00:04:37,800  -->  00:04:40,550
that you're going to find inside your enterprise networks.
139

139

00:04:41,593  -->  00:04:43,971
(upbeat music)
