1
00:00:00,090 --> 00:00:03,270
In this lesson, we're going to cover confidentiality.

2
00:00:03,270 --> 00:00:05,760
Now, confidentiality is a foundational concept

3
00:00:05,760 --> 00:00:07,620
in the world of information security,

4
00:00:07,620 --> 00:00:09,660
and it refers to the protection of information

5
00:00:09,660 --> 00:00:12,330
from unauthorized access and disclosure.

6
00:00:12,330 --> 00:00:14,130
Confidentiality is used to ensure

7
00:00:14,130 --> 00:00:15,840
that private or sensitive information

8
00:00:15,840 --> 00:00:17,580
is not available or disclosed to

9
00:00:17,580 --> 00:00:21,090
an unauthorized individual, entity, or process.

10
00:00:21,090 --> 00:00:23,010
Imagine you just walked into your local bank

11
00:00:23,010 --> 00:00:25,170
and saw a stack of personal loan applications

12
00:00:25,170 --> 00:00:27,810
being left out in the open for anybody to see.

13
00:00:27,810 --> 00:00:30,330
Each application contains lots of sensitive data,

14
00:00:30,330 --> 00:00:32,790
including the bank customer's names, their addresses,

15
00:00:32,790 --> 00:00:34,890
their social security number, their work history,

16
00:00:34,890 --> 00:00:37,320
their income, and all sorts of things like that.

17
00:00:37,320 --> 00:00:39,000
If I saw that, I'd be pretty alarmed

18
00:00:39,000 --> 00:00:41,100
and I'm pretty sure you would be too.

19
00:00:41,100 --> 00:00:43,410
That's because most of us have an expectation

20
00:00:43,410 --> 00:00:45,990
that our sensitive banking details will be kept secret

21
00:00:45,990 --> 00:00:48,450
and only revealed to people who are authorized to see it,

22
00:00:48,450 --> 00:00:50,820
such as the bank tellers or the bank managers.

23
00:00:50,820 --> 00:00:52,470
Well, the same expectation occurs

24
00:00:52,470 --> 00:00:54,900
for most of us inside of our computer networks.

25
00:00:54,900 --> 00:00:57,480
We expect that confidentiality is going to occur

26
00:00:57,480 --> 00:00:58,710
and that people aren't randomly

27
00:00:58,710 --> 00:01:01,140
accessing data or information from our laptops,

28
00:01:01,140 --> 00:01:02,460
smartphones, or tablets

29
00:01:02,460 --> 00:01:05,040
without our knowledge, consent, or approval.

30
00:01:05,040 --> 00:01:07,290
After all, confidentiality is all about

31
00:01:07,290 --> 00:01:10,260
keeping your information secret and safe from prying eyes

32
00:01:10,260 --> 00:01:12,600
while at the same time allowing authorized people

33
00:01:12,600 --> 00:01:14,790
to access that data that they need.

34
00:01:14,790 --> 00:01:17,610
So why is confidentiality so important?

35
00:01:17,610 --> 00:01:20,970
Well, confidentiality is important for three main reasons.

36
00:01:20,970 --> 00:01:22,980
This is to protect your personal privacy,

37
00:01:22,980 --> 00:01:24,450
to maintain a business advantage,

38
00:01:24,450 --> 00:01:26,730
and to achieve regulatory compliance.

39
00:01:26,730 --> 00:01:29,010
Now, the first reason that confidentiality is important

40
00:01:29,010 --> 00:01:31,800
is for you to be able to protect your personal privacy.

41
00:01:31,800 --> 00:01:32,640
Just as you wouldn't want

42
00:01:32,640 --> 00:01:34,500
your personal letters read by strangers,

43
00:01:34,500 --> 00:01:36,960
most individuals don't want their personal data,

44
00:01:36,960 --> 00:01:39,390
including their health records or financial details,

45
00:01:39,390 --> 00:01:41,250
being shared without their consent.

46
00:01:41,250 --> 00:01:44,130
So as cybersecurity professionals, we seek to ensure

47
00:01:44,130 --> 00:01:46,200
that our data remains safe from prying eyes

48
00:01:46,200 --> 00:01:49,470
in order to maintain the confidentiality of that data.

49
00:01:49,470 --> 00:01:51,780
The second reason that confidentiality is important

50
00:01:51,780 --> 00:01:53,550
is to maintain a business advantage.

51
00:01:53,550 --> 00:01:55,620
Now, most businesses have proprietary data

52
00:01:55,620 --> 00:01:57,420
that's used in their daily operations

53
00:01:57,420 --> 00:01:59,760
including information about their products, their clients,

54
00:01:59,760 --> 00:02:01,710
and their overall business strategy.

55
00:02:01,710 --> 00:02:03,930
Keeping this information confidential is crucial

56
00:02:03,930 --> 00:02:07,020
for maintaining a competitive edge within your industry.

57
00:02:07,020 --> 00:02:09,330
And the third reason that confidentiality is important

58
00:02:09,330 --> 00:02:11,430
is to achieve regulatory compliance.

59
00:02:11,430 --> 00:02:13,230
Now, many industries have regulations

60
00:02:13,230 --> 00:02:15,690
that mandate the protection of certain types of data,

61
00:02:15,690 --> 00:02:18,810
like personally identifiable information, or PII,

62
00:02:18,810 --> 00:02:21,060
protected health information, or PHI,

63
00:02:21,060 --> 00:02:24,480
financial data, and various other types of data too.

64
00:02:24,480 --> 00:02:25,934
If you fail to maintain confidentiality

65
00:02:25,934 --> 00:02:27,570
of these types of data,

66
00:02:27,570 --> 00:02:30,150
your organization could be levied a fine against it

67
00:02:30,150 --> 00:02:32,520
and pay a large penalty for non-compliance;

68
00:02:32,520 --> 00:02:35,160
so it's important to follow all the mandatory regulations

69
00:02:35,160 --> 00:02:36,810
within your industry.

70
00:02:36,810 --> 00:02:38,850
Now, in order to ensure confidentiality,

71
00:02:38,850 --> 00:02:41,160
we're going to use five basic methods:

72
00:02:41,160 --> 00:02:44,100
encryption, access controls, data masking,

73
00:02:44,100 --> 00:02:47,190
physical security measures, and training & awareness.

74
00:02:47,190 --> 00:02:48,930
First, we have encryption.

75
00:02:48,930 --> 00:02:51,076
Encryption is a process of converting data into code

76
00:02:51,076 --> 00:02:53,310
to prevent unauthorized access.

77
00:02:53,310 --> 00:02:55,170
Even if somebody intercepts the data,

78
00:02:55,170 --> 00:02:56,100
they won't understand it

79
00:02:56,100 --> 00:02:57,870
unless they have the decryption key.

80
00:02:57,870 --> 00:02:59,400
Essentially, with encryption,

81
00:02:59,400 --> 00:03:00,888
we're scrambling up the plain text data

82
00:03:00,888 --> 00:03:02,910
into an indecipherable jumble

83
00:03:02,910 --> 00:03:05,100
until the right decryption key is provided,

84
00:03:05,100 --> 00:03:08,280
in which case the scrambled data, which we call ciphertext,

85
00:03:08,280 --> 00:03:09,840
can then be quickly presented again

86
00:03:09,840 --> 00:03:11,850
in its plain text format.

87
00:03:11,850 --> 00:03:14,280
Second, we have access controls.

88
00:03:14,280 --> 00:03:16,140
By setting up strong user permissions,

89
00:03:16,140 --> 00:03:17,040
you're going to be able to ensure

90
00:03:17,040 --> 00:03:18,990
that only authorized personnel can access

91
00:03:18,990 --> 00:03:20,400
certain types of data.

92
00:03:20,400 --> 00:03:21,780
Access controls can be set up

93
00:03:21,780 --> 00:03:23,580
by creating password-protected files,

94
00:03:23,580 --> 00:03:25,290
or securing access to a database

95
00:03:25,290 --> 00:03:26,760
by using a username and password

96
00:03:26,760 --> 00:03:28,410
or other types of credentials.

97
00:03:28,410 --> 00:03:30,450
For example, your boss might want you

98
00:03:30,450 --> 00:03:33,120
to save your personnel record on the company's shared drive,

99
00:03:33,120 --> 00:03:35,550
but they only want themselves to be able to access it.

100
00:03:35,550 --> 00:03:38,010
In this case, they can set permissions for that record

101
00:03:38,010 --> 00:03:40,290
so they have full access to read and write information

102
00:03:40,290 --> 00:03:42,840
to that file, but nobody else can.

103
00:03:42,840 --> 00:03:44,910
Third, we have data masking.

104
00:03:44,910 --> 00:03:46,860
Now, data masking is a method that involves

105
00:03:46,860 --> 00:03:49,230
obscuring specific data within a database

106
00:03:49,230 --> 00:03:51,630
to make it inaccessible for unauthorized users

107
00:03:51,630 --> 00:03:53,261
while retaining the real data's authenticity

108
00:03:53,261 --> 00:03:55,560
and use for authorized users.

109
00:03:55,560 --> 00:03:57,720
For example, if your customer service system

110
00:03:57,720 --> 00:03:59,700
stores your user's credit card number,

111
00:03:59,700 --> 00:04:01,020
you could use data masking

112
00:04:01,020 --> 00:04:04,470
so the first 12 digits of the 16-digit number is masked

113
00:04:04,470 --> 00:04:07,140
and only the final 4 digits of the customer's credit card

114
00:04:07,140 --> 00:04:09,600
is going to be displayed to your support agents.

115
00:04:09,600 --> 00:04:11,730
This type of confidentiality helps to prevent

116
00:04:11,730 --> 00:04:14,190
accidental disclosures of the sensitive information,

117
00:04:14,190 --> 00:04:15,210
and in this case, that would be

118
00:04:15,210 --> 00:04:17,519
the entire 16-digit credit card number

119
00:04:17,519 --> 00:04:18,930
while still allowing some portion of it

120
00:04:18,930 --> 00:04:21,540
to be viewed for identification purposes.

121
00:04:21,540 --> 00:04:24,030
Fourth, we have physical security measures.

122
00:04:24,030 --> 00:04:25,800
Now, physical security measures are used

123
00:04:25,800 --> 00:04:28,590
to ensure confidentiality for both physical types of data,

124
00:04:28,590 --> 00:04:30,807
such as paper records stored in a filing cabinet,

125
00:04:30,807 --> 00:04:32,640
and for digital information that's contained

126
00:04:32,640 --> 00:04:34,380
on servers and workstations.

127
00:04:34,380 --> 00:04:36,690
To protect data using physical security controls,

128
00:04:36,690 --> 00:04:38,220
we can lock our filing cabinets,

129
00:04:38,220 --> 00:04:41,010
install biometric security locks on the server room door,

130
00:04:41,010 --> 00:04:42,450
install security cameras to detect

131
00:04:42,450 --> 00:04:43,950
any physical data breaches

132
00:04:43,950 --> 00:04:45,780
or other types of physical security controls

133
00:04:45,780 --> 00:04:47,430
that we might want to use.

134
00:04:47,430 --> 00:04:49,740
Fifth, we have training and awareness.

135
00:04:49,740 --> 00:04:52,410
Often, breaches in confidentiality are going to occur

136
00:04:52,410 --> 00:04:55,650
due to human error, negligence, or malicious intent.

137
00:04:55,650 --> 00:04:57,660
To help prevent human error and negligence,

138
00:04:57,660 --> 00:04:58,950
you should conduct regular training

139
00:04:58,950 --> 00:05:00,930
on the security awareness best practices

140
00:05:00,930 --> 00:05:02,430
that employees can use to protect

141
00:05:02,430 --> 00:05:04,560
their organization's sensitive data.

142
00:05:04,560 --> 00:05:06,750
So remember, confidentiality is the principle

143
00:05:06,750 --> 00:05:09,360
of ensuring that information is only accessible

144
00:05:09,360 --> 00:05:11,370
to those who have the right to access it

145
00:05:11,370 --> 00:05:14,010
whether through encryption, access controls, data masking,

146
00:05:14,010 --> 00:05:16,830
physical security measures, or training and awareness,

147
00:05:16,830 --> 00:05:18,001
our goal is going to be to protect

148
00:05:18,001 --> 00:05:21,270
our organization's sensitive data from prying eyes.

149
00:05:21,270 --> 00:05:23,460
Anytime you're asked about confidentiality,

150
00:05:23,460 --> 00:05:25,020
your answer should always have something to do

151
00:05:25,020 --> 00:05:28,290
with protecting data from being seen by unauthorized users.

152
00:05:28,290 --> 00:05:30,750
Most commonly, we do this using encryption,

153
00:05:30,750 --> 00:05:32,070
so I really want you to link the words

154
00:05:32,070 --> 00:05:34,890
confidentiality and encryption in your mind.

155
00:05:34,890 --> 00:05:37,620
In a digital age where information is our digital currency,

156
00:05:37,620 --> 00:05:40,470
maintaining the confidentiality of our organizational data

157
00:05:40,470 --> 00:05:41,900
is really important and critical

158
00:05:41,900 --> 00:05:44,610
to ensuring that we can maintain our customer's trust,

159
00:05:44,610 --> 00:05:46,440
meet our regulatory compliance requirements,

160
00:05:46,440 --> 00:05:48,600
and achieve continuous business operations

161
00:05:48,600 --> 00:05:50,433
inside of our enterprise networks.

