1
1

00:00:00,210  -->  00:00:02,139
<v ->Hardening and security policies.</v>
2

2

00:00:02,139  -->  00:00:04,070
In this video, we're going to talk about
3

3

00:00:04,070  -->  00:00:06,160
the various hardening and security policies
4

4

00:00:06,160  -->  00:00:08,580
that are used in securing your enterprise networks.
5

5

00:00:08,580  -->  00:00:11,610
This includes password policies, acceptable use policies,
6

6

00:00:11,610  -->  00:00:14,490
bring your own device policies, remote access policies,
7

7

00:00:14,490  -->  00:00:17,160
onboarding and off-boarding policies, security policies,
8

8

00:00:17,160  -->  00:00:19,140
and data loss prevention policies.
9

9

00:00:19,140  -->  00:00:21,500
First, we have password policies.
10

10

00:00:21,500  -->  00:00:24,040
Now a password policy is a set of rules created
11

11

00:00:24,040  -->  00:00:26,730
to improve computer security by motivating users
12

12

00:00:26,730  -->  00:00:29,040
to create dependable, secure passwords,
13

13

00:00:29,040  -->  00:00:31,380
and then store and utilize them properly.
14

14

00:00:31,380  -->  00:00:33,650
This document will promote strong passwords
15

15

00:00:33,650  -->  00:00:35,560
by specifying a minimum password length,
16

16

00:00:35,560  -->  00:00:38,810
a complexity requirement requiring periodic password changes
17

17

00:00:38,810  -->  00:00:41,390
and placing limits on the reuse of passwords.
18

18

00:00:41,390  -->  00:00:43,250
Once you create your password policy,
19

19

00:00:43,250  -->  00:00:45,840
it's important to educate your end users on the requirements
20

20

00:00:45,840  -->  00:00:47,870
that are set forth in this policy.
21

21

00:00:47,870  -->  00:00:50,240
Also, you want to create guidelines and standards
22

22

00:00:50,240  -->  00:00:53,170
within your organization based on your password policy
23

23

00:00:53,170  -->  00:00:55,470
and use those to implement the technical controls
24

24

00:00:55,470  -->  00:00:57,230
that will enforce the requirements set forth
25

25

00:00:57,230  -->  00:00:59,080
in your password policy.
26

26

00:00:59,080  -->  00:01:01,550
Next, we have acceptable use policies.
27

27

00:01:01,550  -->  00:01:04,010
An acceptable use policy or AUP
28

28

00:01:04,010  -->  00:01:06,220
is a set of rules applied by the owner, creator
29

29

00:01:06,220  -->  00:01:09,050
or administrator of a network website or service
30

30

00:01:09,050  -->  00:01:11,220
that restricts the ways in which the network website
31

31

00:01:11,220  -->  00:01:13,590
or system may be used and sets guidelines
32

32

00:01:13,590  -->  00:01:15,550
as to how it should be used.
33

33

00:01:15,550  -->  00:01:17,650
Now, essentially, this is a policy that governs
34

34

00:01:17,650  -->  00:01:20,430
the use of the company equipment and its internet services
35

35

00:01:20,430  -->  00:01:21,760
by its employees.
36

36

00:01:21,760  -->  00:01:24,900
So what kind of things might you find in an AUP?
37

37

00:01:24,900  -->  00:01:27,130
Well, this is really going to depend on your organization
38

38

00:01:27,130  -->  00:01:28,510
and its requirements.
39

39

00:01:28,510  -->  00:01:30,860
At one of the large organizations I used to work for,
40

40

00:01:30,860  -->  00:01:32,520
they had restrictions that prevented employees
41

41

00:01:32,520  -->  00:01:34,380
from accessing websites like eBay,
42

42

00:01:34,380  -->  00:01:36,020
because you shouldn't be buying and selling things
43

43

00:01:36,020  -->  00:01:37,030
while you're at work.
44

44

00:01:37,030  -->  00:01:39,140
They also prevented employees from accessing pornography
45

45

00:01:39,140  -->  00:01:40,730
or gambling websites.
46

46

00:01:40,730  -->  00:01:42,660
Another organization I worked at restricted,
47

47

00:01:42,660  -->  00:01:44,090
the use of Facebook while at work,
48

48

00:01:44,090  -->  00:01:45,660
because they didn't want people spending their time
49

49

00:01:45,660  -->  00:01:47,520
on social media during the workday.
50

50

00:01:47,520  -->  00:01:48,920
But like I said,
51

51

00:01:48,920  -->  00:01:51,400
this is really going to depend on your organization.
52

52

00:01:51,400  -->  00:01:53,530
In my company, I don't block Facebook
53

53

00:01:53,530  -->  00:01:55,170
because I want my team members there
54

54

00:01:55,170  -->  00:01:56,900
because I want them to be in our Facebook group
55

55

00:01:56,900  -->  00:01:58,410
and interacting with our students
56

56

00:01:58,410  -->  00:02:00,470
in the Dion training Facebook group.
57

57

00:02:00,470  -->  00:02:02,560
As you can see, there's really no one size
58

58

00:02:02,560  -->  00:02:03,760
fits all answer here,
59

59

00:02:03,760  -->  00:02:06,020
but for the exam, if you start seeing things
60

60

00:02:06,020  -->  00:02:08,850
that talk about what things an employee can and cannot do,
61

61

00:02:08,850  -->  00:02:10,570
what they're allowed to do with company equipment
62

62

00:02:10,570  -->  00:02:11,700
and internet services,
63

63

00:02:11,700  -->  00:02:14,590
your correct answer should be unacceptable use policy
64

64

00:02:14,590  -->  00:02:15,980
or AUP.
65

65

00:02:15,980  -->  00:02:18,510
Next we have bring your own device policies.
66

66

00:02:18,510  -->  00:02:21,620
Bring your own device or BYOD is going to allow,
67

67

00:02:21,620  -->  00:02:24,380
or sometimes encourage employees to access enterprise
68

68

00:02:24,380  -->  00:02:27,220
networks and systems using personal mobile devices,
69

69

00:02:27,220  -->  00:02:29,860
such as smartphones, tablets, and laptops.
70

70

00:02:29,860  -->  00:02:32,220
Some organizations are fully embracing a culture
71

71

00:02:32,220  -->  00:02:33,640
of bringing your own device
72

72

00:02:33,640  -->  00:02:35,560
while others have rejected it completely
73

73

00:02:35,560  -->  00:02:38,070
because it does bring up different security risks
74

74

00:02:38,070  -->  00:02:39,520
that you have to think about.
75

75

00:02:39,520  -->  00:02:42,130
After all, let's say I'm able to bring my laptop to work
76

76

00:02:42,130  -->  00:02:43,550
and connect it to your network.
77

77

00:02:43,550  -->  00:02:46,020
Now, any malware issues I have on my device
78

78

00:02:46,020  -->  00:02:48,140
are now going to be a part of your network too,
79

79

00:02:48,140  -->  00:02:49,460
and it can spread.
80

80

00:02:49,460  -->  00:02:51,890
BYOD also has a lot of challenges with maintaining
81

81

00:02:51,890  -->  00:02:53,880
a proper configuration baseline too,
82

82

00:02:53,880  -->  00:02:56,650
because the company doesn't technically own that device
83

83

00:02:56,650  -->  00:02:58,960
and therefore they can't patch them or upgrade them
84

84

00:02:58,960  -->  00:03:01,410
automatically using their patch management processes
85

85

00:03:01,410  -->  00:03:03,950
because the employee owns that device.
86

86

00:03:03,950  -->  00:03:04,870
Now, on the other hand,
87

87

00:03:04,870  -->  00:03:07,360
a lot of companies really love BYOD
88

88

00:03:07,360  -->  00:03:09,590
and this bring your own device policy because it means
89

89

00:03:09,590  -->  00:03:11,640
they don't have to buy you a laptop or a cell phone
90

90

00:03:11,640  -->  00:03:14,160
or a tablet because you as an employee are simply going to
91

91

00:03:14,160  -->  00:03:17,030
bring your own personal device and do your work on it.
92

92

00:03:17,030  -->  00:03:18,970
This will save the company money in the short term,
93

93

00:03:18,970  -->  00:03:21,520
but again, there's a lot of security concerns here
94

94

00:03:21,520  -->  00:03:22,870
you have to worry about.
95

95

00:03:22,870  -->  00:03:24,770
When the data goes onto that device,
96

96

00:03:24,770  -->  00:03:25,910
whose data is it?
97

97

00:03:25,910  -->  00:03:28,750
Is it the company's data or is it the employee's data?
98

98

00:03:28,750  -->  00:03:30,150
Who has the rights to it?
99

99

00:03:30,150  -->  00:03:32,180
Where do you draw the line between what personal data
100

100

00:03:32,180  -->  00:03:34,720
can be on that laptop and what is going to be business data
101

101

00:03:34,720  -->  00:03:36,390
that has to be properly secured.
102

102

00:03:36,390  -->  00:03:38,430
These are all things you have to think about, right?
103

103

00:03:38,430  -->  00:03:39,480
If there's going to be an incident,
104

104

00:03:39,480  -->  00:03:41,890
can the company take your personal devices as evidence
105

105

00:03:41,890  -->  00:03:43,280
during the investigation?
106

106

00:03:43,280  -->  00:03:45,260
Can they require you to reformat and purge
107

107

00:03:45,260  -->  00:03:47,110
all your information from your smartphone,
108

108

00:03:47,110  -->  00:03:49,170
including all the pictures of your kids?
109

109

00:03:49,170  -->  00:03:50,830
That is something you have to think about.
110

110

00:03:50,830  -->  00:03:52,820
As you can see, there are a lot of questions
111

111

00:03:52,820  -->  00:03:55,140
that come up when you start using a bring your own device
112

112

00:03:55,140  -->  00:03:56,900
or BYOD policy.
113

113

00:03:56,900  -->  00:04:00,530
In general, I recommend against using a BYOB policy
114

114

00:04:00,530  -->  00:04:01,780
in enterprise networks.
115

115

00:04:01,780  -->  00:04:04,780
But if you are going to embrace a BYOD policy,
116

116

00:04:04,780  -->  00:04:06,950
then I suggest you create a segmented network
117

117

00:04:06,950  -->  00:04:10,120
where your BYOD devices can connect directly to the internet
118

118

00:04:10,120  -->  00:04:12,230
and then use cloud hosted resources,
119

119

00:04:12,230  -->  00:04:14,764
instead of going into your local network directly.
120

120

00:04:14,764  -->  00:04:17,440
Next, we have remote access policies.
121

121

00:04:17,440  -->  00:04:20,190
Now a remote access policy is a document that outlines
122

122

00:04:20,190  -->  00:04:22,980
and defines acceptable methods of remotely connecting
123

123

00:04:22,980  -->  00:04:24,430
to the internal network.
124

124

00:04:24,430  -->  00:04:26,820
For example, are your employees allowed to be connected
125

125

00:04:26,820  -->  00:04:29,710
to internal network resources such as your email server
126

126

00:04:29,710  -->  00:04:31,460
directly over the internet?
127

127

00:04:31,460  -->  00:04:32,560
Now, in most cases,
128

128

00:04:32,560  -->  00:04:34,120
you're not going to configure your email server
129

129

00:04:34,120  -->  00:04:36,220
to allow this to happen because it opens you up
130

130

00:04:36,220  -->  00:04:38,110
to a whole bunch of vulnerabilities.
131

131

00:04:38,110  -->  00:04:41,070
Instead, you may choose to enable a web mail server
132

132

00:04:41,070  -->  00:04:43,510
that sits in a screen sub-net or a DMZ,
133

133

00:04:43,510  -->  00:04:45,500
and then allow your employees to connect to that,
134

134

00:04:45,500  -->  00:04:47,520
and it will be used essentially as a jump box
135

135

00:04:47,520  -->  00:04:49,250
into the exchange server.
136

136

00:04:49,250  -->  00:04:52,440
Or your remote access policy might decide that you're going to
137

137

00:04:52,440  -->  00:04:54,670
allow employees to use their corporate laptops,
138

138

00:04:54,670  -->  00:04:57,920
to connect to the internet over a VPN connection.
139

139

00:04:57,920  -->  00:05:00,350
This way, they're going to be connecting to your network,
140

140

00:05:00,350  -->  00:05:03,320
using a trusted device, that corporate laptop using your
141

141

00:05:03,320  -->  00:05:05,610
standard baseline configuration security protocols,
142

142

00:05:05,610  -->  00:05:07,590
and they can validate their identity using whatever
143

143

00:05:07,590  -->  00:05:09,570
authentication and authorization procedures
144

144

00:05:09,570  -->  00:05:12,550
you have to ensure the security of your network.
145

145

00:05:12,550  -->  00:05:15,030
This again goes into your remote access policy.
146

146

00:05:15,030  -->  00:05:18,110
What type of services, whether they're VPNs or other things,
147

147

00:05:18,110  -->  00:05:20,240
are you going to allow your employees to use?
148

148

00:05:20,240  -->  00:05:23,590
Again, as you start creating your remote access policy,
149

149

00:05:23,590  -->  00:05:25,620
it's really going to be based on your risk tolerance
150

150

00:05:25,620  -->  00:05:26,920
and your operational needs,
151

151

00:05:26,920  -->  00:05:29,870
and it is going to be dependent on your organization.
152

152

00:05:29,870  -->  00:05:32,730
Next, we have onboarding and offboarding policies.
153

153

00:05:32,730  -->  00:05:35,290
Now an onboarding policy is a documented policy
154

154

00:05:35,290  -->  00:05:36,600
that describes all the requirements
155

155

00:05:36,600  -->  00:05:38,960
for integrating a new employee into the company
156

156

00:05:38,960  -->  00:05:40,700
and its cultures, as well as getting
157

157

00:05:40,700  -->  00:05:43,300
that new hire all the tools and information they need
158

158

00:05:43,300  -->  00:05:45,590
to be able to do their job successfully.
159

159

00:05:45,590  -->  00:05:48,350
Now, an offboarding policy is a documented policy
160

160

00:05:48,350  -->  00:05:49,970
that covers all the steps necessary
161

161

00:05:49,970  -->  00:05:51,950
to successfully part ways with an employee
162

162

00:05:51,950  -->  00:05:54,380
following their resignation or termination.
163

163

00:05:54,380  -->  00:05:57,110
When you do this well, a clear off-boarding process
164

164

00:05:57,110  -->  00:05:59,680
will ensure a smooth transition for both your company
165

165

00:05:59,680  -->  00:06:01,370
and the departing employee.
166

166

00:06:01,370  -->  00:06:04,410
Now a good onboarding and offboarding policy needs to extend
167

167

00:06:04,410  -->  00:06:06,370
beyond the information technology realm.
168

168

00:06:06,370  -->  00:06:08,820
But for our purposes, we're focusing really
169

169

00:06:08,820  -->  00:06:10,560
on the IT side of things.
170

170

00:06:10,560  -->  00:06:12,500
For example, when somebody is hired,
171

171

00:06:12,500  -->  00:06:15,160
how is that new employee going to get their account created?
172

172

00:06:15,160  -->  00:06:16,710
How are they going to be issued a new laptop
173

173

00:06:16,710  -->  00:06:18,130
or smartphone or tablet?
174

174

00:06:18,130  -->  00:06:19,290
How are they going to be given access
175

175

00:06:19,290  -->  00:06:20,600
to different network resources
176

176

00:06:20,600  -->  00:06:22,200
like the company shared drive?
177

177

00:06:22,200  -->  00:06:23,900
All of these are things that need to be documented
178

178

00:06:23,900  -->  00:06:27,020
within the onboarding policy and it's associated procedures.
179

179

00:06:27,020  -->  00:06:27,853
On the other hand,
180

180

00:06:27,853  -->  00:06:29,850
when an employee resigns or is terminated,
181

181

00:06:29,850  -->  00:06:31,710
how are you going to remove them from all their accounts
182

182

00:06:31,710  -->  00:06:32,830
and accesses?
183

183

00:06:32,830  -->  00:06:35,310
How long do they have before their accounts can be deleted
184

184

00:06:35,310  -->  00:06:36,730
once they transfer?
185

185

00:06:36,730  -->  00:06:39,080
Do you need to archive their data for historical purposes
186

186

00:06:39,080  -->  00:06:41,320
and record-keeping, or can you delete it all?
187

187

00:06:41,320  -->  00:06:43,240
Do you need to take back equipment like a laptop
188

188

00:06:43,240  -->  00:06:44,830
or a smartphone or a tablet?
189

189

00:06:44,830  -->  00:06:46,730
How are you going to refurbish it so it's ready to be issued
190

190

00:06:46,730  -->  00:06:49,490
to the next employee who's hired into that position?
191

191

00:06:49,490  -->  00:06:50,960
All of these are things you need to cover
192

192

00:06:50,960  -->  00:06:53,180
inside your offboarding policy.
193

193

00:06:53,180  -->  00:06:55,360
Next, we have security policies.
194

194

00:06:55,360  -->  00:06:57,750
Now a security policy is a document that outlines
195

195

00:06:57,750  -->  00:06:59,710
how to protect the organization systems,
196

196

00:06:59,710  -->  00:07:01,490
networks and data from threats,
197

197

00:07:01,490  -->  00:07:03,280
including computer security threats,
198

198

00:07:03,280  -->  00:07:06,410
and how to handle situations when they do occur.
199

199

00:07:06,410  -->  00:07:08,150
A security policy is going to identify
200

200

00:07:08,150  -->  00:07:10,960
all of a company's assets as well as the potential threats
201

201

00:07:10,960  -->  00:07:12,440
to those assets.
202

202

00:07:12,440  -->  00:07:13,950
Now, in many organizations
203

203

00:07:13,950  -->  00:07:16,530
there may be a single overarching security policy,
204

204

00:07:16,530  -->  00:07:18,780
that's going to contain all the other security policies
205

205

00:07:18,780  -->  00:07:19,650
underneath it.
206

206

00:07:19,650  -->  00:07:22,230
Things like the AUP, the BYOD,
207

207

00:07:22,230  -->  00:07:24,400
the password policy, the onboarding policy,
208

208

00:07:24,400  -->  00:07:26,910
the offboarding policy and many others.
209

209

00:07:26,910  -->  00:07:29,400
In other organizations, they prefer to break apart
210

210

00:07:29,400  -->  00:07:30,840
the larger security policy
211

211

00:07:30,840  -->  00:07:32,720
into smaller individual policies
212

212

00:07:32,720  -->  00:07:34,660
for use within the organization.
213

213

00:07:34,660  -->  00:07:37,550
Finally, we have our data loss prevention policy.
214

214

00:07:37,550  -->  00:07:39,880
Now a data loss prevention policy is a document
215

215

00:07:39,880  -->  00:07:43,290
that defines how organizations can share and protect data.
216

216

00:07:43,290  -->  00:07:45,900
It's going to guide how data can be used in decision-making
217

217

00:07:45,900  -->  00:07:47,420
without it being exposed to anyone
218

218

00:07:47,420  -->  00:07:49,260
who should not have access to it.
219

219

00:07:49,260  -->  00:07:51,470
Now, the goal of a data loss prevention policy
220

220

00:07:51,470  -->  00:07:54,600
is to minimize accidental or malicious data loss.
221

221

00:07:54,600  -->  00:07:57,050
These policies need to cover the entire network,
222

222

00:07:57,050  -->  00:07:59,810
not just your file servers or your email servers.
223

223

00:07:59,810  -->  00:08:01,030
In my organization,
224

224

00:08:01,030  -->  00:08:02,940
we use a data loss prevention system
225

225

00:08:02,940  -->  00:08:05,640
based on our organizational DLP policies.
226

226

00:08:05,640  -->  00:08:07,570
Our DLP system goes through our network
227

227

00:08:07,570  -->  00:08:10,130
and inspects any data being sent or received.
228

228

00:08:10,130  -->  00:08:12,020
For example, if our system detects that
229

229

00:08:12,020  -->  00:08:14,340
a large amount of data is being sent out of our network
230

230

00:08:14,340  -->  00:08:16,700
to a site like Google drive or Dropbox,
231

231

00:08:16,700  -->  00:08:19,200
it can create an alert and tell our system administrators
232

232

00:08:19,200  -->  00:08:20,900
that we need to investigate that.
233

233

00:08:20,900  -->  00:08:23,350
This way we can look at, what particular employee
234

234

00:08:23,350  -->  00:08:25,290
was sending, what particular documents
235

235

00:08:25,290  -->  00:08:27,600
and decide is that legitimate or not.
236

236

00:08:27,600  -->  00:08:29,570
In some cases, an employee might need to send
237

237

00:08:29,570  -->  00:08:32,070
a large amount of data, but in others they shouldn't
238

238

00:08:32,070  -->  00:08:33,520
be sending large data files.
239

239

00:08:33,520  -->  00:08:36,250
And that may be them trynna steal data from our systems.
240

240

00:08:36,250  -->  00:08:37,083
For example,
241

241

00:08:37,083  -->  00:08:39,540
let's say that my DLP system created an alert
242

242

00:08:39,540  -->  00:08:41,350
because one of my employees was uploading
243

243

00:08:41,350  -->  00:08:43,260
all the video content from this course
244

244

00:08:43,260  -->  00:08:44,570
into one of our video servers
245

245

00:08:44,570  -->  00:08:47,000
or to one of our video distribution partners.
246

246

00:08:47,000  -->  00:08:48,580
That might be 50, a hundred
247

247

00:08:48,580  -->  00:08:50,960
or 200 gigabytes of data or more.
248

248

00:08:50,960  -->  00:08:53,190
I guarantee that our data loss prevention system
249

249

00:08:53,190  -->  00:08:55,090
is going to flag on that amount of data,
250

250

00:08:55,090  -->  00:08:57,030
leaving our network from a single user
251

251

00:08:57,030  -->  00:08:58,430
or a single workstation,
252

252

00:08:58,430  -->  00:09:00,790
because this is typically an indicator of a compromise
253

253

00:09:00,790  -->  00:09:03,540
for a data breach or data exfiltration attack.
254

254

00:09:03,540  -->  00:09:05,820
My DLP will flag this data transfer
255

255

00:09:05,820  -->  00:09:07,080
and based on our policies,
256

256

00:09:07,080  -->  00:09:09,740
it may even block this data transfer from occurring.
257

257

00:09:09,740  -->  00:09:12,390
Now our administrator can review that flagged alert
258

258

00:09:12,390  -->  00:09:14,240
and look at the content and determine
259

259

00:09:14,240  -->  00:09:16,380
is this somebody who is stealing from us
260

260

00:09:16,380  -->  00:09:18,140
or is it someone doing their job
261

261

00:09:18,140  -->  00:09:20,070
and they have a legitimate reason to do this?
262

262

00:09:20,070  -->  00:09:22,430
For example, if I have my video editor,
263

263

00:09:22,430  -->  00:09:25,030
we might see that she just uploaded this brand new course
264

264

00:09:25,030  -->  00:09:26,460
to one of our distribution partners.
265

265

00:09:26,460  -->  00:09:28,450
And she did it all in a one day period.
266

266

00:09:28,450  -->  00:09:31,560
So she had to upload two or 300 gigabytes of data
267

267

00:09:31,560  -->  00:09:33,490
so we can prepare to publish this course.
268

268

00:09:33,490  -->  00:09:34,323
That would be fine.
269

269

00:09:34,323  -->  00:09:36,520
We'd mark the alert as normal and acceptable,
270

270

00:09:36,520  -->  00:09:38,100
and we'd move on with our day.
271

271

00:09:38,100  -->  00:09:39,650
But again, this is all going to be dependent
272

272

00:09:39,650  -->  00:09:41,480
on your data loss prevention policies.
273

273

00:09:41,480  -->  00:09:43,840
And what's going to trigger inside your company.
274

274

00:09:43,840  -->  00:09:45,910
In your company, if you had a single person
275

275

00:09:45,910  -->  00:09:48,130
sending 50 or a hundred gigabytes of data,
276

276

00:09:48,130  -->  00:09:51,470
that would probably be extremely suspicious in most cases
277

277

00:09:51,470  -->  00:09:53,490
and needs to be investigated further.
278

278

00:09:53,490  -->  00:09:56,030
As part of your DLP policy, it's always important
279

279

00:09:56,030  -->  00:09:57,760
to set proper thresholds.
280

280

00:09:57,760  -->  00:09:59,750
When is your DLP going to alarm?
281

281

00:09:59,750  -->  00:10:02,300
What is the amount of data transfer or the file types
282

282

00:10:02,300  -->  00:10:05,440
that it's going to consider acceptable or out of baseline?
283

283

00:10:05,440  -->  00:10:07,460
What file formats are you going to be able to transfer?
284

284

00:10:07,460  -->  00:10:09,080
And which ones are going to be blocked?
285

285

00:10:09,080  -->  00:10:11,380
Are you going to allow people to transfer database files
286

286

00:10:11,380  -->  00:10:13,640
or zip files or PowerPoint files?
287

287

00:10:13,640  -->  00:10:16,020
All of these are things that DLP can block
288

288

00:10:16,020  -->  00:10:18,360
or alert on depending on how you configure it.
289

289

00:10:18,360  -->  00:10:20,210
So as you look at all these different things,
290

290

00:10:20,210  -->  00:10:23,440
you need to define that in your data loss prevention policy.
291

291

00:10:23,440  -->  00:10:26,370
Now, remember when it comes to securing your networks,
292

292

00:10:26,370  -->  00:10:28,170
there are lots of different hardening techniques
293

293

00:10:28,170  -->  00:10:30,670
and security policies that you may come across.
294

294

00:10:30,670  -->  00:10:32,440
We cover just a few in this lesson
295

295

00:10:32,440  -->  00:10:34,290
that you may get asked about on the exam,
296

296

00:10:34,290  -->  00:10:36,050
but in the real world there are tons
297

297

00:10:36,050  -->  00:10:37,440
of other ones out there.
298

298

00:10:37,440  -->  00:10:39,280
For the exam, I want you to remember
299

299

00:10:39,280  -->  00:10:41,080
that we have things like password policies,
300

300

00:10:41,080  -->  00:10:42,600
acceptable use policies,
301

301

00:10:42,600  -->  00:10:44,000
bring your own device policies,
302

302

00:10:44,000  -->  00:10:45,220
remote access policies,
303

303

00:10:45,220  -->  00:10:47,010
onboarding and offboarding policies,
304

304

00:10:47,010  -->  00:10:48,000
security policies,
305

305

00:10:48,000  -->  00:10:49,590
and data loss prevention policies,
306

306

00:10:49,590  -->  00:10:51,093
and what each one is used for.
