1
00:00:00,750 --> 00:00:01,583
In this lesson,

2
00:00:01,583 --> 00:00:04,560
we will cover external audits and assessments.

3
00:00:04,560 --> 00:00:07,530
External audits and assessments serve as critical tools

4
00:00:07,530 --> 00:00:10,830
for organizations to maintain a robust security posture

5
00:00:10,830 --> 00:00:14,160
and ensure compliance with regulatory standard.

6
00:00:14,160 --> 00:00:16,140
These evaluations are often conducted

7
00:00:16,140 --> 00:00:17,640
by independent third parties

8
00:00:17,640 --> 00:00:19,650
that provide an unbiased view

9
00:00:19,650 --> 00:00:21,810
of an organization's security infrastructure,

10
00:00:21,810 --> 00:00:23,850
identify potential vulnerabilities,

11
00:00:23,850 --> 00:00:27,180
and validate the effectiveness of security controls.

12
00:00:27,180 --> 00:00:29,610
External audits are systematic evaluations

13
00:00:29,610 --> 00:00:31,710
conducted by independent entities

14
00:00:31,710 --> 00:00:34,410
to assess an organization's information systems,

15
00:00:34,410 --> 00:00:36,690
applications, and security controls.

16
00:00:36,690 --> 00:00:38,070
Unlike internal audits,

17
00:00:38,070 --> 00:00:38,903
which are performed

18
00:00:38,903 --> 00:00:41,880
by an organization's own internal audit team,

19
00:00:41,880 --> 00:00:44,550
external audits provide an objective perspective

20
00:00:44,550 --> 00:00:47,430
on an organization's true security posture.

21
00:00:47,430 --> 00:00:50,160
External audits can cover a wide range of areas,

22
00:00:50,160 --> 00:00:52,740
including data protection, network security,

23
00:00:52,740 --> 00:00:55,980
access controls, and incident response procedures.

24
00:00:55,980 --> 00:00:59,190
The goal of an external audit is to identify gaps

25
00:00:59,190 --> 00:01:01,920
in security policies, procedures, and controls

26
00:01:01,920 --> 00:01:04,319
to ensure compliance with various regulatory standards

27
00:01:04,319 --> 00:01:06,720
like the General Data Protection Regulation,

28
00:01:06,720 --> 00:01:08,700
also known as GDPR,

29
00:01:08,700 --> 00:01:10,290
and the Healthcare Insurance

30
00:01:10,290 --> 00:01:13,920
Portability and Accountability Act, also known as HIPAA.

31
00:01:13,920 --> 00:01:14,753
And lastly,

32
00:01:14,753 --> 00:01:17,280
the Payment Card Industry Data Security Standard,

33
00:01:17,280 --> 00:01:20,550
also known as PCI DSS.

34
00:01:20,550 --> 00:01:22,710
For example, a financial institution

35
00:01:22,710 --> 00:01:24,630
might hire an external auditor

36
00:01:24,630 --> 00:01:28,020
to evaluate its compliance with the PCI DSS

37
00:01:28,020 --> 00:01:30,270
once per quarter or once per year.

38
00:01:30,270 --> 00:01:32,310
The external auditor would then review

39
00:01:32,310 --> 00:01:34,590
the institution's card holder data environment

40
00:01:34,590 --> 00:01:36,420
and examine its security measures,

41
00:01:36,420 --> 00:01:40,020
such as firewalls, encryption methods, and access controls

42
00:01:40,020 --> 00:01:41,640
to ensure that they meet the requirements

43
00:01:41,640 --> 00:01:43,912
of the PCI DSS standard.

44
00:01:43,912 --> 00:01:46,320
In addition to external audits,

45
00:01:46,320 --> 00:01:48,360
we can also have external assessments

46
00:01:48,360 --> 00:01:51,360
conducted on our organization's enterprise network.

47
00:01:51,360 --> 00:01:53,550
An external assessment is a detailed analysis

48
00:01:53,550 --> 00:01:57,180
that's conducted by an independent entity or entities

49
00:01:57,180 --> 00:01:59,520
to identify vulnerabilities and risks

50
00:01:59,520 --> 00:02:01,470
in an organization's security system.

51
00:02:01,470 --> 00:02:05,100
This external assessment often involves a combination

52
00:02:05,100 --> 00:02:08,280
of automated scanning tools and manual testing techniques

53
00:02:08,280 --> 00:02:09,840
to provide a comprehensive view

54
00:02:09,840 --> 00:02:12,930
of the organization's security vulnerabilities.

55
00:02:12,930 --> 00:02:15,210
External assessments can take various forms,

56
00:02:15,210 --> 00:02:17,970
including risk assessments, vulnerability assessments,

57
00:02:17,970 --> 00:02:19,680
and threat assessments.

58
00:02:19,680 --> 00:02:21,480
Each type of external assessment

59
00:02:21,480 --> 00:02:23,880
will focus on different aspects of security

60
00:02:23,880 --> 00:02:26,040
and provide us with some valuable insights

61
00:02:26,040 --> 00:02:26,940
that can help strengthen

62
00:02:26,940 --> 00:02:28,860
our organization's security posture.

63
00:02:28,860 --> 00:02:31,200
For example, a healthcare organization

64
00:02:31,200 --> 00:02:33,360
might engage a cybersecurity firm

65
00:02:33,360 --> 00:02:35,130
to conduct a vulnerability assessment

66
00:02:35,130 --> 00:02:37,200
of its electronic health record system

67
00:02:37,200 --> 00:02:38,520
to ensure that it's compliant

68
00:02:38,520 --> 00:02:40,860
with the HIPAA regulatory requirements.

69
00:02:40,860 --> 00:02:42,810
The external assessment firm

70
00:02:42,810 --> 00:02:45,270
would then use specialized tools to scan the system

71
00:02:45,270 --> 00:02:46,500
for known vulnerabilities,

72
00:02:46,500 --> 00:02:49,500
such as outdated software or misconfigured settings,

73
00:02:49,500 --> 00:02:52,650
and then provide a report detailing these vulnerabilities

74
00:02:52,650 --> 00:02:54,990
and recommend the mitigation strategies

75
00:02:54,990 --> 00:02:57,330
that the organization should implement.

76
00:02:57,330 --> 00:03:00,299
Next, we have regulatory compliance.

77
00:03:00,299 --> 00:03:03,090
Regulatory compliance refers to the goal

78
00:03:03,090 --> 00:03:04,980
that organizations aspire to achieve

79
00:03:04,980 --> 00:03:06,030
in their efforts

80
00:03:06,030 --> 00:03:09,570
to assure that they are aware of and take steps to comply

81
00:03:09,570 --> 00:03:12,510
with relevant laws, policies, and regulations.

82
00:03:12,510 --> 00:03:14,910
Due to the increasing number of regulations

83
00:03:14,910 --> 00:03:17,580
and the need for operational transparency,

84
00:03:17,580 --> 00:03:19,830
organizations are increasingly adopting the use

85
00:03:19,830 --> 00:03:23,760
of consolidated and harmonized set of compliance controls

86
00:03:23,760 --> 00:03:25,860
to achieve their regulatory compliance,

87
00:03:25,860 --> 00:03:28,320
such as using NIST Cybersecurity Framework

88
00:03:28,320 --> 00:03:31,020
as their main regulatory compliance mechanisms

89
00:03:31,020 --> 00:03:33,000
while allowing the implementation

90
00:03:33,000 --> 00:03:35,970
of each individual regulatory set of controls

91
00:03:35,970 --> 00:03:39,780
within the larger NIST Cybersecurity Framework.

92
00:03:39,780 --> 00:03:41,370
Regulatory compliance involves

93
00:03:41,370 --> 00:03:43,350
adhering to laws and regulations

94
00:03:43,350 --> 00:03:46,230
that dictate how organizations must manage the security

95
00:03:46,230 --> 00:03:49,260
of their information technology systems and data.

96
00:03:49,260 --> 00:03:51,360
These regulations can include rules

97
00:03:51,360 --> 00:03:53,250
that are specific to certain industries,

98
00:03:53,250 --> 00:03:54,660
such as HIPAA for healthcare

99
00:03:54,660 --> 00:03:56,760
and PCI DSS for organizations

100
00:03:56,760 --> 00:03:58,530
that handle credit card information

101
00:03:58,530 --> 00:04:00,150
as well as more generalized types of,

102
00:04:00,150 --> 00:04:02,130
like the General Data Protection Regulation,

103
00:04:02,130 --> 00:04:03,660
also known as GDPR,

104
00:04:03,660 --> 00:04:07,440
that applies to organizations across all industries.

105
00:04:07,440 --> 00:04:09,540
To achieve compliance with these regulations,

106
00:04:09,540 --> 00:04:10,710
organizations will often

107
00:04:10,710 --> 00:04:13,230
implement specific security controls,

108
00:04:13,230 --> 00:04:15,360
maintain certain policies and procedures,

109
00:04:15,360 --> 00:04:17,490
and regularly audit and assess

110
00:04:17,490 --> 00:04:19,589
their organization's security posture.

111
00:04:19,589 --> 00:04:22,950
Next thing that we have to consider is examinations.

112
00:04:22,950 --> 00:04:25,590
Examinations are detailed inspections

113
00:04:25,590 --> 00:04:27,750
of an organization's security infrastructure

114
00:04:27,750 --> 00:04:29,400
that are conducted externally,

115
00:04:29,400 --> 00:04:31,470
and they can cover a wide range of areas

116
00:04:31,470 --> 00:04:35,310
from network security to data protection to access controls.

117
00:04:35,310 --> 00:04:37,710
In addition to this part of the examination,

118
00:04:37,710 --> 00:04:39,800
which acts very much like an assessment,

119
00:04:39,800 --> 00:04:42,780
an examination may also include some testing

120
00:04:42,780 --> 00:04:46,200
of your key personnel using standardized testing,

121
00:04:46,200 --> 00:04:49,170
checking if their certifications are current and up-to-date,

122
00:04:49,170 --> 00:04:50,820
and things like that.

123
00:04:50,820 --> 00:04:52,320
For example, if you work for

124
00:04:52,320 --> 00:04:55,110
a nuclear power generation facility or power plant,

125
00:04:55,110 --> 00:04:58,050
these organizations are subject to examinations

126
00:04:58,050 --> 00:04:59,790
every one to five years.

127
00:04:59,790 --> 00:05:02,730
During the examination, their computer network systems,

128
00:05:02,730 --> 00:05:04,260
ICS and SCADA equipment,

129
00:05:04,260 --> 00:05:08,640
and other operational procedures are assessed and examined.

130
00:05:08,640 --> 00:05:10,830
Additionally, all of the employees of the facility

131
00:05:10,830 --> 00:05:12,930
are examined based on their work roles

132
00:05:12,930 --> 00:05:16,200
to ensure that they can complete knowledge-based exams

133
00:05:16,200 --> 00:05:17,670
in order to maintain their authority

134
00:05:17,670 --> 00:05:20,610
to operate at the given power plant.

135
00:05:20,610 --> 00:05:23,010
Examinations also involve a review

136
00:05:23,010 --> 00:05:26,100
of the organization's policies, procedures, and controls

137
00:05:26,100 --> 00:05:28,050
to ensure that they meet requirements

138
00:05:28,050 --> 00:05:30,000
of their relevant regulation.

139
00:05:30,000 --> 00:05:31,680
Examinations are a crucial part

140
00:05:31,680 --> 00:05:33,810
of maintaining a strong security posture

141
00:05:33,810 --> 00:05:35,850
and ensuring regulatory compliance.

142
00:05:35,850 --> 00:05:37,530
They can help identify potential weakness

143
00:05:37,530 --> 00:05:39,570
in the organization's security infrastructure

144
00:05:39,570 --> 00:05:43,320
and provide a roadmap for making necessary improvements.

145
00:05:43,320 --> 00:05:45,120
Many cybersecurity professionals

146
00:05:45,120 --> 00:05:47,310
will never experience this kind of examination,

147
00:05:47,310 --> 00:05:51,000
and instead, most will simply undergo a typical assessment.

148
00:05:51,000 --> 00:05:53,880
But depending on the industry that you work for

149
00:05:53,880 --> 00:05:55,920
and the regulations that apply to your industry,

150
00:05:55,920 --> 00:05:57,540
you may be subject to an examination

151
00:05:57,540 --> 00:05:59,400
at some point in your career.

152
00:05:59,400 --> 00:06:02,520
Finally, we have independent third-party audits.

153
00:06:02,520 --> 00:06:05,640
Independent third-party audits are a crucial component

154
00:06:05,640 --> 00:06:07,680
of an organization's cybersecurity strategy

155
00:06:07,680 --> 00:06:10,260
that are used to provide an unbiased perspective

156
00:06:10,260 --> 00:06:12,000
of the organization's security posture

157
00:06:12,000 --> 00:06:14,190
that helps to identify potential weaknesses

158
00:06:14,190 --> 00:06:17,520
that might be overlooked in internal audits or assessments.

159
00:06:17,520 --> 00:06:20,910
These independent third-party audits can provide validation

160
00:06:20,910 --> 00:06:22,680
of an organization's security measures

161
00:06:22,680 --> 00:06:24,690
that can help build trust with customers,

162
00:06:24,690 --> 00:06:27,150
stakeholders, and regulatory bodies.

163
00:06:27,150 --> 00:06:31,650
Many regulations include GDPR and PCI DSS,

164
00:06:31,650 --> 00:06:32,640
require organizations

165
00:06:32,640 --> 00:06:35,640
to undergo regular independent third-party audits

166
00:06:35,640 --> 00:06:38,070
as part of their compliance requirements.

167
00:06:38,070 --> 00:06:41,400
So remember, external audits and assessments

168
00:06:41,400 --> 00:06:42,390
are essential tools

169
00:06:42,390 --> 00:06:44,940
for maintaining a robust cybersecurity posture

170
00:06:44,940 --> 00:06:47,760
and ensuring compliance with regulatory standards.

171
00:06:47,760 --> 00:06:49,860
By providing an unbiased view

172
00:06:49,860 --> 00:06:51,930
of an organization security infrastructure,

173
00:06:51,930 --> 00:06:53,370
these evaluations can help

174
00:06:53,370 --> 00:06:55,194
identify potential vulnerabilities,

175
00:06:55,194 --> 00:06:58,050
validate the effectiveness of security controls,

176
00:06:58,050 --> 00:07:00,540
and build trust with stakeholders.

177
00:07:00,540 --> 00:07:02,430
Regular external audits and assessments

178
00:07:02,430 --> 00:07:04,380
conducted by independent third parties

179
00:07:04,380 --> 00:07:05,460
should be a key component

180
00:07:05,460 --> 00:07:07,893
of any organization's cybersecurity strategy.

