1
00:00:00,000 --> 00:00:01,680
In this section of the course, we're going

2
00:00:01,680 --> 00:00:04,230
to talk about audits and assessments.

3
00:00:04,230 --> 00:00:06,660
Audits and assessments play an important role in ensuring

4
00:00:06,660 --> 00:00:10,020
the robustness and reliability of organization's security

5
00:00:10,020 --> 00:00:12,630
and infrastructure, and these processes are the key

6
00:00:12,630 --> 00:00:14,280
to identifying vulnerabilities,

7
00:00:14,280 --> 00:00:15,630
validating security measures,

8
00:00:15,630 --> 00:00:19,110
and maintaining compliance with regulatory standards.

9
00:00:19,110 --> 00:00:21,300
First, we have audits.

10
00:00:21,300 --> 00:00:23,220
Audits are a systematic evaluation

11
00:00:23,220 --> 00:00:25,920
of organizational information systems, applications,

12
00:00:25,920 --> 00:00:26,880
and security controls

13
00:00:26,880 --> 00:00:30,330
to ascertain their efficiency and effectiveness.

14
00:00:30,330 --> 00:00:33,510
They are typically conducted by an independent entity

15
00:00:33,510 --> 00:00:35,460
to provide an unbiased view

16
00:00:35,460 --> 00:00:37,560
of the organization's security posture.

17
00:00:37,560 --> 00:00:39,120
Now, audits can be an internal

18
00:00:39,120 --> 00:00:42,630
or external, depending on the source of the audit.

19
00:00:42,630 --> 00:00:44,610
Now, internal audits are conducted

20
00:00:44,610 --> 00:00:46,230
by the organization's own audit team,

21
00:00:46,230 --> 00:00:49,950
while external audits are performed by third party entities.

22
00:00:49,950 --> 00:00:53,070
An example of an internal audit would be an organization's

23
00:00:53,070 --> 00:00:55,260
internal audit team, conducting a review

24
00:00:55,260 --> 00:00:57,600
of the company's data protection policy.

25
00:00:57,600 --> 00:01:00,240
They will check whether the policies are up to date,

26
00:01:00,240 --> 00:01:01,590
comprehensive, and in line

27
00:01:01,590 --> 00:01:03,480
with the latest regulatory requirements.

28
00:01:03,480 --> 00:01:05,910
They also verify if these policies are being followed

29
00:01:05,910 --> 00:01:08,460
correctly by all employees.

30
00:01:08,460 --> 00:01:11,430
An example of an external audit would be a third party

31
00:01:11,430 --> 00:01:12,540
auditor being hired

32
00:01:12,540 --> 00:01:14,910
to evaluate an e-commerce company's compliance

33
00:01:14,910 --> 00:01:16,660
with PCI DSS

34
00:01:17,579 --> 00:01:20,010
or Payment Card Industry Data Security Standard.

35
00:01:20,010 --> 00:01:22,560
The auditor checks the company's network security,

36
00:01:22,560 --> 00:01:25,590
data encryption methods, and access control mechanisms

37
00:01:25,590 --> 00:01:27,480
to ensure that credit card information

38
00:01:27,480 --> 00:01:29,370
is being handled securely.

39
00:01:29,370 --> 00:01:31,710
Audits are crucial for identifying gaps in security

40
00:01:31,710 --> 00:01:34,260
policies, procedures, and controls.

41
00:01:34,260 --> 00:01:36,480
They also help in ensuring compliance

42
00:01:36,480 --> 00:01:39,240
with various regulatory standards like the General Data

43
00:01:39,240 --> 00:01:43,020
Protection or GDPR, Health Insurance Portability

44
00:01:43,020 --> 00:01:45,480
and Accountability Act, or HIPAA

45
00:01:45,480 --> 00:01:48,180
and the Payment Card Industry Data Security Standard,

46
00:01:48,180 --> 00:01:50,760
or PCI DSS.

47
00:01:50,760 --> 00:01:52,770
Second, we have assessments.

48
00:01:52,770 --> 00:01:55,740
Assessments are about performing a detailed analysis

49
00:01:55,740 --> 00:01:57,450
of a security organization's systems

50
00:01:57,450 --> 00:01:59,880
to identify vulnerabilities and risks.

51
00:01:59,880 --> 00:02:03,090
They're often performed before implementing any new system

52
00:02:03,090 --> 00:02:06,090
or making significant changes to an existing ones.

53
00:02:06,090 --> 00:02:09,600
The goal of assessment is to understand the potential risk

54
00:02:09,600 --> 00:02:12,270
and threats to an organization's information system

55
00:02:12,270 --> 00:02:14,460
and propose mitigation strategies

56
00:02:14,460 --> 00:02:16,413
to address these vulnerabilities.

57
00:02:17,250 --> 00:02:20,040
Assessments can be categorized into risk assessments,

58
00:02:20,040 --> 00:02:22,950
vulnerability assessments, and threat assessments.

59
00:02:22,950 --> 00:02:25,890
Each type of these assessments focus on a different aspect

60
00:02:25,890 --> 00:02:28,410
of security and provides valuable insight

61
00:02:28,410 --> 00:02:31,620
to help strengthen the organization's security posture.

62
00:02:31,620 --> 00:02:33,420
So in this section of the course,

63
00:02:33,420 --> 00:02:35,790
we'll be focusing solely on domain five,

64
00:02:35,790 --> 00:02:38,130
specifically objective 5.5, which states

65
00:02:38,130 --> 00:02:40,530
that you must be able to explain types

66
00:02:40,530 --> 00:02:43,350
and purposes of audits and assessments.

67
00:02:43,350 --> 00:02:44,340
First off, again,

68
00:02:44,340 --> 00:02:47,130
we'll cover internal audits and assessments.

69
00:02:47,130 --> 00:02:49,770
Internal audits and assessments are evaluations conducted

70
00:02:49,770 --> 00:02:52,950
within an organization to review its processes, controls,

71
00:02:52,950 --> 00:02:56,040
and compliance to ensure operational effectiveness

72
00:02:56,040 --> 00:02:58,740
and adherent to internal policies.

73
00:02:58,740 --> 00:03:00,750
Then we're going to jump right into the demo on how

74
00:03:00,750 --> 00:03:03,420
to perform an internal assessment so that we can show you

75
00:03:03,420 --> 00:03:05,940
how to review an organization's processes, controls,

76
00:03:05,940 --> 00:03:08,430
and compliance within its internal policies.

77
00:03:08,430 --> 00:03:09,810
After that, we're going to talk about

78
00:03:09,810 --> 00:03:11,700
external audits and assessments.

79
00:03:11,700 --> 00:03:14,490
External audits and assessments are independent evaluations

80
00:03:14,490 --> 00:03:17,490
performed by external parties to verify organization's

81
00:03:17,490 --> 00:03:19,230
financial statements, compliant

82
00:03:19,230 --> 00:03:21,180
and operational practices against

83
00:03:21,180 --> 00:03:23,850
established standards and regulations.

84
00:03:23,850 --> 00:03:26,190
Then we're going to go back to another demo

85
00:03:26,190 --> 00:03:28,650
and perform an external assessment so that you can see

86
00:03:28,650 --> 00:03:30,810
how a third party or independent auditor

87
00:03:30,810 --> 00:03:35,160
or assessor can review the organization's security posture.

88
00:03:35,160 --> 00:03:38,070
Following that, we're going to discuss penetration testing.

89
00:03:38,070 --> 00:03:40,890
Now, penetration testing often referred to as a pen test

90
00:03:40,890 --> 00:03:42,270
or ethical hacking,

91
00:03:42,270 --> 00:03:45,330
is a simulated cyber attack against a computer system,

92
00:03:45,330 --> 00:03:48,570
network or web application to identify vulnerabilities

93
00:03:48,570 --> 00:03:50,580
that could be exploited by attackers.

94
00:03:50,580 --> 00:03:53,670
Then we'll take a look at reconnaissance and pen testing.

95
00:03:53,670 --> 00:03:55,560
In this lesson, we're going to discuss the need

96
00:03:55,560 --> 00:03:57,660
for reconnaissance based on the type of pen test

97
00:03:57,660 --> 00:04:00,540
and the environment, including known environments,

98
00:04:00,540 --> 00:04:03,450
partially known environments, unknown environments,

99
00:04:03,450 --> 00:04:05,520
and we're also going to discuss different types

100
00:04:05,520 --> 00:04:08,164
of reconnaissance, which are passive and active.

101
00:04:08,164 --> 00:04:11,070
Next, we'll dive into a quick demo showing how

102
00:04:11,070 --> 00:04:14,900
to perform a basic pen test by using tools like Nmap

103
00:04:14,900 --> 00:04:17,459
and Metasploit to scan a network for a vulnerable machine,

104
00:04:17,459 --> 00:04:19,560
and then how to exploit that vulnerability

105
00:04:19,560 --> 00:04:21,600
to gain full administrative access over

106
00:04:21,600 --> 00:04:23,370
the targeted machine.

107
00:04:23,370 --> 00:04:26,310
After that, we'll cover attestation of findings.

108
00:04:26,310 --> 00:04:27,900
Now, attestations of findings

109
00:04:27,900 --> 00:04:29,520
is a formal written declaration

110
00:04:29,520 --> 00:04:31,350
or confirmation of the results

111
00:04:31,350 --> 00:04:34,140
or outcomes of an audit or assessment.

112
00:04:34,140 --> 00:04:36,390
And finally, we're going to take a short quiz just to see

113
00:04:36,390 --> 00:04:38,250
what you learned during this section of the course,

114
00:04:38,250 --> 00:04:40,800
and review each of those quiz questions fully to ensure

115
00:04:40,800 --> 00:04:44,130
that you can explain why the right answers were right.

116
00:04:44,130 --> 00:04:46,590
So let's dive into our coverage of audits

117
00:04:46,590 --> 00:04:48,890
and assessments in this section of the course.

