1
00:00:00,020 --> 00:00:01,350
In this section of the course,

2
00:00:01,350 --> 00:00:04,230
we're going to be focused on asset and change management.

3
00:00:04,230 --> 00:00:06,900
Now, asset management refers to the systematic process

4
00:00:06,900 --> 00:00:10,140
of developing, operating, maintaining, and selling assets

5
00:00:10,140 --> 00:00:11,850
in a cost-effective manner.

6
00:00:11,850 --> 00:00:13,560
Now, change management, on the other hand,

7
00:00:13,560 --> 00:00:15,900
is a structured approach to transitioning individuals,

8
00:00:15,900 --> 00:00:18,390
teams, and organizations from a current state

9
00:00:18,390 --> 00:00:20,130
to a desired future state.

10
00:00:20,130 --> 00:00:22,140
Now, in cybersecurity, asset management

11
00:00:22,140 --> 00:00:24,510
and change management are two of the critical pillars

12
00:00:24,510 --> 00:00:25,343
that are used to safeguard

13
00:00:25,343 --> 00:00:27,750
an organization's data and infrastructure.

14
00:00:27,750 --> 00:00:29,220
Asset management is going to ensure

15
00:00:29,220 --> 00:00:30,750
that all of our digital assets,

16
00:00:30,750 --> 00:00:33,360
ranging from hardware devices to software applications,

17
00:00:33,360 --> 00:00:35,970
have been identified, cataloged, and monitored,

18
00:00:35,970 --> 00:00:37,410
and therefore this helps us

19
00:00:37,410 --> 00:00:38,910
to reduce potential vulnerabilities

20
00:00:38,910 --> 00:00:40,530
and to ensure that the security protocols

21
00:00:40,530 --> 00:00:43,860
are consistently being applied across all of our assets.

22
00:00:43,860 --> 00:00:46,350
Meanwhile, change management is used to guarantee

23
00:00:46,350 --> 00:00:48,300
that any modifications to our systems,

24
00:00:48,300 --> 00:00:49,770
whether they're to software updates

25
00:00:49,770 --> 00:00:51,600
or to new technology implementations,

26
00:00:51,600 --> 00:00:54,090
are being done in a controlled and secure manner,

27
00:00:54,090 --> 00:00:55,950
and this prevents unforeseen security gaps

28
00:00:55,950 --> 00:00:57,990
or misconfigurations from occurring.

29
00:00:57,990 --> 00:00:59,820
Together, these practices provide us

30
00:00:59,820 --> 00:01:02,070
with a structured framework to prevent, detect,

31
00:01:02,070 --> 00:01:03,630
and respond to cyber threats

32
00:01:03,630 --> 00:01:05,970
to ensure that an organization's digital resources

33
00:01:05,970 --> 00:01:09,060
remain secure amidst an evolving threat landscape.

34
00:01:09,060 --> 00:01:10,650
Now, in this section of the course,

35
00:01:10,650 --> 00:01:13,170
we're going to be focused on Domain 1 and Domain 4,

36
00:01:13,170 --> 00:01:16,095
and we'll specifically be looking at objectives 1.3,

37
00:01:16,095 --> 00:01:17,820
4.1, and 4.2.

38
00:01:17,820 --> 00:01:20,040
Objective 1.3 states that you must be able

39
00:01:20,040 --> 00:01:22,470
to explain the importance of change management processes

40
00:01:22,470 --> 00:01:24,150
and the impact to security.

41
00:01:24,150 --> 00:01:26,790
Objective 4.1 states that given a scenario,

42
00:01:26,790 --> 00:01:29,070
you must be able to apply common security techniques

43
00:01:29,070 --> 00:01:30,600
to computing resources,

44
00:01:30,600 --> 00:01:32,880
and Objective 4.2 states that you must be able

45
00:01:32,880 --> 00:01:35,640
to explain security implications of proper hardware,

46
00:01:35,640 --> 00:01:38,070
software, and data asset management.

47
00:01:38,070 --> 00:01:40,050
Now, as we begin this section, we're going to start out

48
00:01:40,050 --> 00:01:43,080
by covering the concepts of acquisition and procurement.

49
00:01:43,080 --> 00:01:45,180
Now, acquisition and procurement in cybersecurity

50
00:01:45,180 --> 00:01:47,940
involve the structured process of sourcing, vetting,

51
00:01:47,940 --> 00:01:50,400
and obtaining security technologies and services

52
00:01:50,400 --> 00:01:53,640
to bolster organizations' defenses against cyber threats.

53
00:01:53,640 --> 00:01:55,170
Next, we're going to cover the concepts

54
00:01:55,170 --> 00:01:56,580
of mobile asset deployments,

55
00:01:56,580 --> 00:02:01,200
including BYOD, COPE, CYOD, and other deployment models

56
00:02:01,200 --> 00:02:02,730
that are pivotal to cybersecurity,

57
00:02:02,730 --> 00:02:05,130
as they determine how personal and company owned devices

58
00:02:05,130 --> 00:02:06,660
will be managed and integrated

59
00:02:06,660 --> 00:02:08,340
within your organization's networks

60
00:02:08,340 --> 00:02:09,870
to ensure that the most suitable model

61
00:02:09,870 --> 00:02:12,480
is being chosen based on your business's unique needs

62
00:02:12,480 --> 00:02:14,490
and desired security posture.

63
00:02:14,490 --> 00:02:17,250
Then, we're going to dive into the asset management world.

64
00:02:17,250 --> 00:02:19,110
We're going to be talking about assignment and accounting

65
00:02:19,110 --> 00:02:21,870
and monitoring and asset tracking inside of cybersecurity,

66
00:02:21,870 --> 00:02:24,360
and how it revolves around a clear definition of ownership

67
00:02:24,360 --> 00:02:26,490
and classification of each asset.

68
00:02:26,490 --> 00:02:28,170
This will help us to ensure a rigorous system

69
00:02:28,170 --> 00:02:29,430
of monitoring of our assets

70
00:02:29,430 --> 00:02:31,740
is occurring through inventory checks, enumeration,

71
00:02:31,740 --> 00:02:33,540
and leveraging tools like MDM

72
00:02:33,540 --> 00:02:36,000
or mobile device management solutions in order to maintain

73
00:02:36,000 --> 00:02:38,400
an organized and secure digital environment.

74
00:02:38,400 --> 00:02:40,620
After that, we'll discuss asset disposal

75
00:02:40,620 --> 00:02:41,820
and decommissioning.

76
00:02:41,820 --> 00:02:44,400
This includes things like sanitization, destruction,

77
00:02:44,400 --> 00:02:46,650
certification, and data retention policies

78
00:02:46,650 --> 00:02:49,200
that will all play vital roles in ensuring that our assets,

79
00:02:49,200 --> 00:02:50,880
that can range from data to hardware,

80
00:02:50,880 --> 00:02:52,890
are all safely discarded or repurposed

81
00:02:52,890 --> 00:02:54,300
at the end of their useful life

82
00:02:54,300 --> 00:02:56,520
in order to minimize the risk of unauthorized access

83
00:02:56,520 --> 00:02:58,380
or data breaches from occurring.

84
00:02:58,380 --> 00:03:00,975
Next, we're going to focus on change management,

85
00:03:00,975 --> 00:03:01,890
and we're going to be talking about the importance

86
00:03:01,890 --> 00:03:03,750
of change management in cybersecurity

87
00:03:03,750 --> 00:03:05,970
because this simply cannot be overstated.

88
00:03:05,970 --> 00:03:08,580
Every change, whether it's a minor or major change,

89
00:03:08,580 --> 00:03:10,740
should undergo a strict approval process

90
00:03:10,740 --> 00:03:12,810
while considering a lot of different aspects,

91
00:03:12,810 --> 00:03:15,060
including the change advisory board's insights,

92
00:03:15,060 --> 00:03:16,290
the ownership of the change,

93
00:03:16,290 --> 00:03:17,790
the stakeholder involvement of the change,

94
00:03:17,790 --> 00:03:20,940
and a thorough impact analysis for the proposed change.

95
00:03:20,940 --> 00:03:22,890
Then, we'll explore the intricate details

96
00:03:22,890 --> 00:03:24,810
of the change management processes.

97
00:03:24,810 --> 00:03:27,000
In the constantly evolving realm of cybersecurity,

98
00:03:27,000 --> 00:03:29,160
it is imperative to schedule maintenance windows,

99
00:03:29,160 --> 00:03:31,020
possess a well-thought-out backup plan,

100
00:03:31,020 --> 00:03:32,370
and consistently test results

101
00:03:32,370 --> 00:03:34,110
after implementing your changes.

102
00:03:34,110 --> 00:03:35,640
This will ensure that all of your changes

103
00:03:35,640 --> 00:03:37,530
are aligned with the standard operating procedures

104
00:03:37,530 --> 00:03:40,590
while maintain the integrity and security of your systems.

105
00:03:40,590 --> 00:03:41,790
After that, we're going to dive

106
00:03:41,790 --> 00:03:43,890
into the technical implications of changes,

107
00:03:43,890 --> 00:03:46,830
and it's essential to be aware of and to manage elements

108
00:03:46,830 --> 00:03:48,810
like allow lists and deny lists,

109
00:03:48,810 --> 00:03:51,210
understanding the nuances of restricted activities,

110
00:03:51,210 --> 00:03:52,710
managing downtime efficiently,

111
00:03:52,710 --> 00:03:55,470
and handling service or application restarts.

112
00:03:55,470 --> 00:03:57,480
In addition to all of that, we also need to consider

113
00:03:57,480 --> 00:03:59,400
the complexities of legacy applications

114
00:03:59,400 --> 00:04:01,230
and their dependencies in order to be able

115
00:04:01,230 --> 00:04:02,610
to avoid potential vulnerabilities

116
00:04:02,610 --> 00:04:05,010
or system clashes that may occur.

117
00:04:05,010 --> 00:04:08,130
Next, we'll address the importance of documenting changes.

118
00:04:08,130 --> 00:04:09,600
Now, in the world of cybersecurity,

119
00:04:09,600 --> 00:04:11,520
version controlling all of your changes

120
00:04:11,520 --> 00:04:15,030
through documentation is considered a non-negotiable thing.

121
00:04:15,030 --> 00:04:17,190
This involves regularly updating your diagrams,

122
00:04:17,190 --> 00:04:18,810
revising your policies and procedures

123
00:04:18,810 --> 00:04:20,610
if a change doesn't yield the desired result

124
00:04:20,610 --> 00:04:23,130
that you expected, and updating change requests

125
00:04:23,130 --> 00:04:25,410
or trouble tickets post-implementation,

126
00:04:25,410 --> 00:04:27,750
as well as ensuring transparency and accountability

127
00:04:27,750 --> 00:04:29,550
throughout the entire process.

128
00:04:29,550 --> 00:04:31,200
Finally, we're going to take a short quiz

129
00:04:31,200 --> 00:04:33,150
to see what you learned during this section of the course

130
00:04:33,150 --> 00:04:34,980
and review each of those quiz questions fully

131
00:04:34,980 --> 00:04:37,650
to ensure you can explain why each answer was right.

132
00:04:37,650 --> 00:04:39,090
Now, let's jump into our coverage

133
00:04:39,090 --> 00:04:40,350
of asset and change management

134
00:04:40,350 --> 00:04:41,850
in this section of the course.

