1
00:00:00,050 --> 00:00:01,350
In this section of the course,

2
00:00:01,350 --> 00:00:04,110
we're going to be focused on the fundamentals of security.

3
00:00:04,110 --> 00:00:05,220
Now, before we can dive deep

4
00:00:05,220 --> 00:00:07,800
into any technical discussions around SQL injections

5
00:00:07,800 --> 00:00:10,470
or password cracking or securing your enterprise systems

6
00:00:10,470 --> 00:00:13,080
by configuring your firewalls, we need to first cover

7
00:00:13,080 --> 00:00:15,900
some basics that you simply must understand.

8
00:00:15,900 --> 00:00:18,210
Now, as a cybersecurity professional, you're going to find

9
00:00:18,210 --> 00:00:19,980
that it is really hard to ensure the security

10
00:00:19,980 --> 00:00:21,720
of your networks and systems.

11
00:00:21,720 --> 00:00:24,000
Now, this is hard, not just because we have bad actors

12
00:00:24,000 --> 00:00:25,890
out there who are trying to hack into our networks

13
00:00:25,890 --> 00:00:27,540
and steal our confidential data,

14
00:00:27,540 --> 00:00:30,390
but also, it's hard because we have internal threats too

15
00:00:30,390 --> 00:00:32,759
like our end users who often try to bypass

16
00:00:32,759 --> 00:00:35,130
our internal security controls as well.

17
00:00:35,130 --> 00:00:37,230
Why, well, because there's always going to be

18
00:00:37,230 --> 00:00:39,660
a friction that exists between the security of the network

19
00:00:39,660 --> 00:00:42,510
and the usability or convenience of that network.

20
00:00:42,510 --> 00:00:44,040
Now, let me give you a quick example here

21
00:00:44,040 --> 00:00:45,510
so you can probably relate to it.

22
00:00:45,510 --> 00:00:47,910
Now, at your house, you probably have an internet connection

23
00:00:47,910 --> 00:00:50,010
from your cable provider, your phone company,

24
00:00:50,010 --> 00:00:52,170
or some third party internet service provider.

25
00:00:52,170 --> 00:00:53,610
Regardless of which one you have,

26
00:00:53,610 --> 00:00:55,740
most of these companies send you a single device

27
00:00:55,740 --> 00:00:58,980
that contains the modem as well as a router inside of it

28
00:00:58,980 --> 00:01:01,200
that provides wireless access throughout your house

29
00:01:01,200 --> 00:01:03,360
so you can have a Wi-Fi access point there.

30
00:01:03,360 --> 00:01:05,910
Now, by default, the internet service provider will give you

31
00:01:05,910 --> 00:01:08,370
a preset password that's pretty long and complicated

32
00:01:08,370 --> 00:01:09,660
in most cases.

33
00:01:09,660 --> 00:01:11,430
On the front of my device, for example,

34
00:01:11,430 --> 00:01:12,690
the company is a sticker that says

35
00:01:12,690 --> 00:01:15,030
the name of the wireless network and the password

36
00:01:15,030 --> 00:01:17,530
such as Wireless Network: ATT142DFE

37
00:01:19,470 --> 00:01:24,470
and a long strong password of 3%1WT&!92#SXH.

38
00:01:27,840 --> 00:01:28,890
Now, I don't know about you,

39
00:01:28,890 --> 00:01:31,650
but that's a pretty long and complicated looking password.

40
00:01:31,650 --> 00:01:33,810
Now, most users will simply change this password

41
00:01:33,810 --> 00:01:35,040
to something easier to remember.

42
00:01:35,040 --> 00:01:40,040
Like magic2912 or cupcake#1 or something like that.

43
00:01:40,440 --> 00:01:43,110
Now, while this is great for convenience and usability,

44
00:01:43,110 --> 00:01:45,600
it really does decrease the level of security you have

45
00:01:45,600 --> 00:01:47,280
because it's easier for a cyber attacker

46
00:01:47,280 --> 00:01:49,710
to crack that password because it is short

47
00:01:49,710 --> 00:01:51,810
and it uses dictionary words inside of it,

48
00:01:51,810 --> 00:01:54,150
but that longer, more complex password,

49
00:01:54,150 --> 00:01:55,650
which is normally more secure

50
00:01:55,650 --> 00:01:57,900
is actually really difficult to memorize

51
00:01:57,900 --> 00:02:00,570
and this also brings another critical weakness to it,

52
00:02:00,570 --> 00:02:02,520
which is the fact that it's printed right on the front

53
00:02:02,520 --> 00:02:04,800
of the modem for anybody who walks by to see it

54
00:02:04,800 --> 00:02:06,060
and write it down.

55
00:02:06,060 --> 00:02:07,050
Now, the truth of the matter

56
00:02:07,050 --> 00:02:09,000
is that with security and usability,

57
00:02:09,000 --> 00:02:11,250
we're always going to have these two things at odds.

58
00:02:11,250 --> 00:02:13,590
Even if you create the most secure system in the world,

59
00:02:13,590 --> 00:02:16,260
your end users will try to bypass those restrictions you put

60
00:02:16,260 --> 00:02:18,240
in place because it's making their day job

61
00:02:18,240 --> 00:02:20,070
much more difficult to complete.

62
00:02:20,070 --> 00:02:22,470
So remember, our end users are people,

63
00:02:22,470 --> 00:02:25,440
and people want things easy, they want them convenient,

64
00:02:25,440 --> 00:02:27,480
but as we give them more convenience,

65
00:02:27,480 --> 00:02:29,760
we're usually going to have to loosen up our security posture

66
00:02:29,760 --> 00:02:31,410
a little bit and conversely,

67
00:02:31,410 --> 00:02:33,300
if we try to increase security too much,

68
00:02:33,300 --> 00:02:36,030
we're going to make things so challenging and so difficult

69
00:02:36,030 --> 00:02:38,130
for our users that they're actually going to take away

70
00:02:38,130 --> 00:02:40,470
all that convenience level and they'll try to find ways

71
00:02:40,470 --> 00:02:42,180
around what we've done.

72
00:02:42,180 --> 00:02:43,920
Now, as a cybersecurity professional,

73
00:02:43,920 --> 00:02:45,810
this is a delicate operational balance

74
00:02:45,810 --> 00:02:48,690
that we're always dealing with inside of our organizations.

75
00:02:48,690 --> 00:02:51,180
Our organizations are having to fight this challenge

76
00:02:51,180 --> 00:02:53,550
all the time to be able to support the convenience

77
00:02:53,550 --> 00:02:56,790
that our users want while giving them more security

78
00:02:56,790 --> 00:02:58,470
and this is one of the reasons why we continue

79
00:02:58,470 --> 00:03:01,080
to have cyber attacks and data breaches to this day

80
00:03:01,080 --> 00:03:02,970
because as we give them more convenience,

81
00:03:02,970 --> 00:03:04,710
we loosen up our security.

82
00:03:04,710 --> 00:03:07,680
Now, in 2022, the average major company that had

83
00:03:07,680 --> 00:03:12,090
a data breach spent $4.35 million per data breach.

84
00:03:12,090 --> 00:03:14,730
That is an amazing and large figure,

85
00:03:14,730 --> 00:03:16,560
but the reason it is is because we have

86
00:03:16,560 --> 00:03:19,380
a security versus convenience trade off that's happening

87
00:03:19,380 --> 00:03:22,140
and people have chosen the wrong things to trade off.

88
00:03:22,140 --> 00:03:24,330
Now, we can make things easier for our users

89
00:03:24,330 --> 00:03:26,340
for them to be able get their work done on a daily basis,

90
00:03:26,340 --> 00:03:28,440
but still making sure it's challenging enough

91
00:03:28,440 --> 00:03:30,000
that our threat actors can't hack their way

92
00:03:30,000 --> 00:03:32,760
into our networks, and that right there is the dream,

93
00:03:32,760 --> 00:03:35,040
that's the sweet spot we're trying to obtain.

94
00:03:35,040 --> 00:03:36,750
So in this section of the course,

95
00:03:36,750 --> 00:03:37,800
we're going to start out by covering

96
00:03:37,800 --> 00:03:40,470
the fundamentals of security and before we do that,

97
00:03:40,470 --> 00:03:43,020
we need to cover two important definitions.

98
00:03:43,020 --> 00:03:43,950
Now, whenever you're working

99
00:03:43,950 --> 00:03:45,420
as a cybersecurity professional,

100
00:03:45,420 --> 00:03:47,850
you're going to hear people talk about two key terms

101
00:03:47,850 --> 00:03:49,410
when we're talking about security.

102
00:03:49,410 --> 00:03:51,630
We talk about these as information security

103
00:03:51,630 --> 00:03:53,670
and information system security.

104
00:03:53,670 --> 00:03:55,020
Now, it's important to know the difference

105
00:03:55,020 --> 00:03:57,120
because these are two different terms.

106
00:03:57,120 --> 00:03:59,340
Information security is the act of protecting

107
00:03:59,340 --> 00:04:02,070
the data and information from unauthorized access,

108
00:04:02,070 --> 00:04:04,110
unlawful modification and disruption,

109
00:04:04,110 --> 00:04:06,720
disclosure or corruption, and destruction.

110
00:04:06,720 --> 00:04:09,480
Simply put, when we talk about information security,

111
00:04:09,480 --> 00:04:12,090
we are talking about the data that the systems are holding,

112
00:04:12,090 --> 00:04:14,010
not the systems themself.

113
00:04:14,010 --> 00:04:16,920
Now, on the other hand, we have information system security,

114
00:04:16,920 --> 00:04:18,839
which is the act of protecting the systems

115
00:04:18,839 --> 00:04:21,240
that hold and process our critical data.

116
00:04:21,240 --> 00:04:23,730
That can be a computer, a server, a network device,

117
00:04:23,730 --> 00:04:24,990
or even your smartphone.

118
00:04:24,990 --> 00:04:26,160
Remember, if somebody's talking

119
00:04:26,160 --> 00:04:27,690
about protecting the data itself,

120
00:04:27,690 --> 00:04:29,820
they are talking about information security,

121
00:04:29,820 --> 00:04:32,280
but if they're talking about the devices that hold the data,

122
00:04:32,280 --> 00:04:35,340
now, we're talking about information system security.

123
00:04:35,340 --> 00:04:37,200
Now, in this section, we're going to be focused

124
00:04:37,200 --> 00:04:39,850
on domain 1 and specifically, objectives 1.1 and 1.2.

125
00:04:41,430 --> 00:04:44,040
Objective 1.1 states that you must be able to compare

126
00:04:44,040 --> 00:04:46,320
and contrast various types of security controls

127
00:04:46,320 --> 00:04:48,480
and objective 1.2 states that you must be able

128
00:04:48,480 --> 00:04:51,150
to summarize fundamental security concepts,

129
00:04:51,150 --> 00:04:53,370
and this is what I was talking about when I mentioned

130
00:04:53,370 --> 00:04:55,650
that they don't always put the objectives in the right order

131
00:04:55,650 --> 00:04:57,150
because the thing we need to learn first

132
00:04:57,150 --> 00:05:00,900
is actually objective 1.2 before we can cover 1.1

133
00:05:00,900 --> 00:05:03,330
and that's exactly what we're going to do in this section.

134
00:05:03,330 --> 00:05:04,710
So as we kick off this section,

135
00:05:04,710 --> 00:05:05,970
we're going to start with objective 1.2

136
00:05:05,970 --> 00:05:09,540
and we'll first start out by covering the C.I.A triad.

137
00:05:09,540 --> 00:05:11,010
Now, the C.I.A triad stands

138
00:05:11,010 --> 00:05:13,800
for confidentiality, integrity, and availability,

139
00:05:13,800 --> 00:05:16,410
and these are the three pillars of security.

140
00:05:16,410 --> 00:05:19,320
Confidentiality ensures that information is only accessible

141
00:05:19,320 --> 00:05:21,360
to those with the appropriate authorization.

142
00:05:21,360 --> 00:05:23,520
For example, if you encrypt sensitive files

143
00:05:23,520 --> 00:05:26,310
to only authorize people can read them and decrypt them,

144
00:05:26,310 --> 00:05:28,170
that is confidentiality.

145
00:05:28,170 --> 00:05:30,780
Now, integrity is going to ensure that data remains accurate

146
00:05:30,780 --> 00:05:33,750
and unaltered unless modification is required.

147
00:05:33,750 --> 00:05:36,000
For example, checksums can be used to verify

148
00:05:36,000 --> 00:05:38,190
that a file has not been changed or corrupted

149
00:05:38,190 --> 00:05:41,160
as it moves along our network during a data transfer.

150
00:05:41,160 --> 00:05:43,530
Availability ensures that information resources

151
00:05:43,530 --> 00:05:45,690
are accessible and functional when needed

152
00:05:45,690 --> 00:05:47,100
by authorized users.

153
00:05:47,100 --> 00:05:49,950
So a good example of availability would be your website

154
00:05:49,950 --> 00:05:51,750
when you implement redundancy measures

155
00:05:51,750 --> 00:05:54,240
to ensure it remains online and up anytime

156
00:05:54,240 --> 00:05:56,370
regardless of how much traffic it's receiving.

157
00:05:56,370 --> 00:05:58,230
So even if you have a period of high traffic,

158
00:05:58,230 --> 00:06:00,300
it'll be able to handle that due to your redundancy

159
00:06:00,300 --> 00:06:02,460
and this gives you good availability.

160
00:06:02,460 --> 00:06:05,520
Next, we're going to cover the concept of non-repudiation.

161
00:06:05,520 --> 00:06:08,310
Non-repudiation means guaranteeing that a specific action

162
00:06:08,310 --> 00:06:10,710
or event has taken place and can not be denied

163
00:06:10,710 --> 00:06:12,120
by the parties involved.

164
00:06:12,120 --> 00:06:15,390
For example, if I send you an email and I digitally sign it,

165
00:06:15,390 --> 00:06:17,880
that's going to ensure that I can not deny sending you

166
00:06:17,880 --> 00:06:20,280
that particular message because my digital signature

167
00:06:20,280 --> 00:06:21,450
is attached to it.

168
00:06:21,450 --> 00:06:24,030
Now, in the old days, we as cybersecurity professionals

169
00:06:24,030 --> 00:06:27,690
always talked about the C.I.A triad, but in recent years,

170
00:06:27,690 --> 00:06:31,080
we have now added two new things to it, an N and an A,

171
00:06:31,080 --> 00:06:33,720
and that's non-repudiation and authentication.

172
00:06:33,720 --> 00:06:37,290
This essentially makes it a pentagon more so than a triad

173
00:06:37,290 --> 00:06:40,740
because now, we have C.I.A.N.A, which is five letters

174
00:06:40,740 --> 00:06:43,140
and a five-sided shape is a pentagon.

175
00:06:43,140 --> 00:06:45,360
Now, with the introduction of this authentication

176
00:06:45,360 --> 00:06:48,330
into C.I.A.N.A, we now move into this area

177
00:06:48,330 --> 00:06:50,310
of the AAAs of security,

178
00:06:50,310 --> 00:06:54,060
which we call authentication, authorization, and accounting.

179
00:06:54,060 --> 00:06:56,280
Now, authentication is the process of verifying

180
00:06:56,280 --> 00:06:58,260
the identity of a user or system.

181
00:06:58,260 --> 00:07:01,140
For example, when you try to log in to get to your email,

182
00:07:01,140 --> 00:07:02,970
your username and password is being checked

183
00:07:02,970 --> 00:07:05,850
against a stored version to confirm your identity.

184
00:07:05,850 --> 00:07:08,340
Now, once you've been authenticated based on your identity,

185
00:07:08,340 --> 00:07:10,140
we then move into authorization,

186
00:07:10,140 --> 00:07:13,170
and authorization determines what actions or resources

187
00:07:13,170 --> 00:07:16,230
an authenticated user has permissions to perform.

188
00:07:16,230 --> 00:07:18,360
For example, in a company database,

189
00:07:18,360 --> 00:07:20,370
you as an employee may have the authorization

190
00:07:20,370 --> 00:07:22,830
to view records, but you may not be authorized

191
00:07:22,830 --> 00:07:24,030
to actually edit them.

192
00:07:24,030 --> 00:07:25,410
So you have read permissions,

193
00:07:25,410 --> 00:07:27,420
but not write or edit permissions.

194
00:07:27,420 --> 00:07:29,670
Now, the third area we have is what's known as accounting,

195
00:07:29,670 --> 00:07:32,130
and accounting is the act of tracking your user activities

196
00:07:32,130 --> 00:07:34,620
and resource utilization and typically, we do this

197
00:07:34,620 --> 00:07:36,540
for auditing or billing purposes.

198
00:07:36,540 --> 00:07:38,520
So when you log into your computer,

199
00:07:38,520 --> 00:07:40,320
we're actually logging what you do.

200
00:07:40,320 --> 00:07:42,960
All those user activities on the network are being logged

201
00:07:42,960 --> 00:07:44,430
to be able to monitor them for unusual

202
00:07:44,430 --> 00:07:46,230
or unauthorized behavior and that would be

203
00:07:46,230 --> 00:07:48,150
a good example of accounting.

204
00:07:48,150 --> 00:07:49,530
After that, we're going to cover

205
00:07:49,530 --> 00:07:52,110
the different security control categories and types.

206
00:07:52,110 --> 00:07:54,480
Now, security controls are measures or mechanisms

207
00:07:54,480 --> 00:07:56,040
that are put in place to mitigate risks

208
00:07:56,040 --> 00:07:58,140
and protect the confidentiality, integrity,

209
00:07:58,140 --> 00:08:01,500
and availability of information systems and their data.

210
00:08:01,500 --> 00:08:04,080
These security controls can be grouped into categories,

211
00:08:04,080 --> 00:08:06,480
like technical, managerial, operational,

212
00:08:06,480 --> 00:08:09,240
and physical controls, but we can also discuss

213
00:08:09,240 --> 00:08:11,160
the different types of security controls we have,

214
00:08:11,160 --> 00:08:14,730
like preventative, deterrent, detective, corrective,

215
00:08:14,730 --> 00:08:17,070
compensating, and directive controls.

216
00:08:17,070 --> 00:08:20,280
Then we'll discuss this concept known as zero trust.

217
00:08:20,280 --> 00:08:22,980
Now, zero trust is a newer security model that operates

218
00:08:22,980 --> 00:08:24,450
on the principle that no one,

219
00:08:24,450 --> 00:08:26,910
whether inside or outside of your organization,

220
00:08:26,910 --> 00:08:29,430
should be trusted by default and verification

221
00:08:29,430 --> 00:08:31,230
is going to be required from everybody

222
00:08:31,230 --> 00:08:33,870
who's trying to gain access to your system's resources.

223
00:08:33,870 --> 00:08:35,460
Now, in order to achieve zero trust,

224
00:08:35,460 --> 00:08:38,070
we have to use a control plane and a data plane.

225
00:08:38,070 --> 00:08:40,740
The control plane consists of the adaptive identity,

226
00:08:40,740 --> 00:08:43,679
threat scope reduction, policy driven access controls,

227
00:08:43,679 --> 00:08:44,970
and secured zones.

228
00:08:44,970 --> 00:08:46,410
The data plan, on the other hand,

229
00:08:46,410 --> 00:08:48,510
is going to be focused on the subject and system,

230
00:08:48,510 --> 00:08:50,640
the policy engine, the policy administrator,

231
00:08:50,640 --> 00:08:52,980
and establishing policy enforcement points.

232
00:08:52,980 --> 00:08:54,840
Finally, we're going to take a short quiz to see

233
00:08:54,840 --> 00:08:56,550
what you learned during this section of the course

234
00:08:56,550 --> 00:08:58,530
and review each of those quiz questions fully

235
00:08:58,530 --> 00:09:00,420
to ensure that you can explain each question

236
00:09:00,420 --> 00:09:02,160
and why the right answer was right.

237
00:09:02,160 --> 00:09:03,750
So let's get started diving

238
00:09:03,750 --> 00:09:05,100
into the fundamentals of security

239
00:09:05,100 --> 00:09:06,600
in this section of the course.

