1
00:00:00,020 --> 00:00:00,853
In this lesson,

2
00:00:00,853 --> 00:00:03,337
we will discuss the attestation of findings.

3
00:00:03,337 --> 00:00:06,450
Attestation is a process that involves the formal validation

4
00:00:06,450 --> 00:00:08,760
or confirmation provided by an entity

5
00:00:08,760 --> 00:00:10,650
that is used to assert the accuracy

6
00:00:10,650 --> 00:00:14,010
and authenticity of specific information.

7
00:00:14,010 --> 00:00:16,710
This process is crucial in various contexts,

8
00:00:16,710 --> 00:00:20,430
particularly in conducting both internal and external audits

9
00:00:20,430 --> 00:00:22,890
where it serves as a foundation for asserting

10
00:00:22,890 --> 00:00:25,080
the reliability and integrity of data,

11
00:00:25,080 --> 00:00:26,790
systems, and processes.

12
00:00:26,790 --> 00:00:30,210
Now, attestation of findings is essentially a way to prove

13
00:00:30,210 --> 00:00:32,640
that the penetration test actually occurred

14
00:00:32,640 --> 00:00:35,730
and it signifies that the findings are actually valid

15
00:00:35,730 --> 00:00:37,470
based on the evidence you presented.

16
00:00:37,470 --> 00:00:40,380
These attestations of the findings is something required,

17
00:00:40,380 --> 00:00:42,150
depending on an organization's reason

18
00:00:42,150 --> 00:00:43,950
for conducting a penetration test.

19
00:00:43,950 --> 00:00:45,990
If you conducted a penetration test simply

20
00:00:45,990 --> 00:00:47,640
because the organization wanted it,

21
00:00:47,640 --> 00:00:49,370
then you might not be required to provide

22
00:00:49,370 --> 00:00:51,180
an attestation of your findings.

23
00:00:51,180 --> 00:00:52,950
But if they're doing it for compliance

24
00:00:52,950 --> 00:00:55,290
or regulatory reasons like making sure they're compliant

25
00:00:55,290 --> 00:01:00,290
with the GLBA, HIPAA, Sarbanes and Oxley, or PCI DSS,

26
00:01:00,660 --> 00:01:03,807
then the organization may require a letter of attestation

27
00:01:03,807 --> 00:01:05,790
from your penetration testing firm to show

28
00:01:05,790 --> 00:01:07,290
that this is an official record

29
00:01:07,290 --> 00:01:09,630
that the penetration test was completed.

30
00:01:09,630 --> 00:01:11,846
If you're asked to provide a letter of attestation

31
00:01:11,846 --> 00:01:13,770
or attestation of your findings,

32
00:01:13,770 --> 00:01:15,600
then you want to make sure that you include

33
00:01:15,600 --> 00:01:17,790
a summary of the findings as well as proof

34
00:01:17,790 --> 00:01:19,800
that you have conducted the security assessment

35
00:01:19,800 --> 00:01:22,620
during a given period of time for the organization.

36
00:01:22,620 --> 00:01:24,690
This way, the organization can take the letter

37
00:01:24,690 --> 00:01:26,460
and show it as proof to a third party

38
00:01:26,460 --> 00:01:29,040
to show that they have conducted a security assessment

39
00:01:29,040 --> 00:01:31,260
by using the firm for the penetration test.

40
00:01:31,260 --> 00:01:33,420
Now, often, we get asked,

41
00:01:33,420 --> 00:01:35,940
what's the difference between the attestation of findings

42
00:01:35,940 --> 00:01:38,490
and the report that a penetration tester may deliver

43
00:01:38,490 --> 00:01:40,770
to the organization at the end of engagement?

44
00:01:40,770 --> 00:01:42,180
Well, the big difference

45
00:01:42,180 --> 00:01:45,570
is the attestation of findings also includes evidence.

46
00:01:45,570 --> 00:01:48,450
So, for example, if you provided a finding

47
00:01:48,450 --> 00:01:50,940
that said they were not using multi-factor authentication

48
00:01:50,940 --> 00:01:53,250
and you're able to bypass their system

49
00:01:53,250 --> 00:01:55,200
by using standard username and password,

50
00:01:55,200 --> 00:01:58,050
now you're going to provide them evidence to show

51
00:01:58,050 --> 00:01:59,790
that exploit actually happened

52
00:01:59,790 --> 00:02:02,130
and they're not just taking your word for it.

53
00:02:02,130 --> 00:02:04,560
This might be a thing where you're going to sit down

54
00:02:04,560 --> 00:02:07,110
with them and go over all the details from the report

55
00:02:07,110 --> 00:02:09,449
and pull out your evidence to show them what you did

56
00:02:09,449 --> 00:02:10,889
and how you did it.

57
00:02:10,889 --> 00:02:13,380
This might include bringing out detailed reports,

58
00:02:13,380 --> 00:02:17,160
data, logs, explanations, or even some of your exploit code

59
00:02:17,160 --> 00:02:19,200
to show them the risk that they have

60
00:02:19,200 --> 00:02:21,630
and how you are able to go about exploiting them.

61
00:02:21,630 --> 00:02:23,130
When it comes to attestation though,

62
00:02:23,130 --> 00:02:25,410
sometimes you will not leave the evidence

63
00:02:25,410 --> 00:02:26,730
with the organization.

64
00:02:26,730 --> 00:02:29,580
For example, if you show them some of your custom code

65
00:02:29,580 --> 00:02:32,250
that you use to be able to exploit that network,

66
00:02:32,250 --> 00:02:34,860
you do not have to leave a copy of that with them,

67
00:02:34,860 --> 00:02:36,180
but you will show it to them

68
00:02:36,180 --> 00:02:37,800
during your attestation meeting.

69
00:02:37,800 --> 00:02:39,720
This is in contrast to the report

70
00:02:39,720 --> 00:02:41,250
that you actually delivered

71
00:02:41,250 --> 00:02:42,630
that will show them the findings

72
00:02:42,630 --> 00:02:44,400
and a remediation that you recommend,

73
00:02:44,400 --> 00:02:45,630
but not necessarily

74
00:02:45,630 --> 00:02:47,670
the way you exploited that vulnerability.

75
00:02:47,670 --> 00:02:48,960
This is a key difference

76
00:02:48,960 --> 00:02:50,820
when you're talking about attestation.

77
00:02:50,820 --> 00:02:53,250
Now, normally, you're going to hear people talk about

78
00:02:53,250 --> 00:02:55,680
a letter of attestation when it comes to the attestation

79
00:02:55,680 --> 00:02:56,700
of your findings.

80
00:02:56,700 --> 00:02:58,920
This may be more about the fact that you can prove

81
00:02:58,920 --> 00:03:01,230
that the penetration test actually happened

82
00:03:01,230 --> 00:03:04,140
and prove that to a third party who may be interested

83
00:03:04,140 --> 00:03:06,720
in the security of the network of the organization

84
00:03:06,720 --> 00:03:09,720
that you are hired to target in your penetration test.

85
00:03:09,720 --> 00:03:12,120
But that is really going to depend on a target organization

86
00:03:12,120 --> 00:03:13,950
that you're doing a penetration test for

87
00:03:13,950 --> 00:03:16,290
and why they hire you to conduct a penetration test

88
00:03:16,290 --> 00:03:17,460
in the first place.

89
00:03:17,460 --> 00:03:19,890
Now, you may also hear about attestation

90
00:03:19,890 --> 00:03:22,590
in terms of software attestation, hardware attestation,

91
00:03:22,590 --> 00:03:24,480
and system attestation as well.

92
00:03:24,480 --> 00:03:26,490
But these are more for integrity checking

93
00:03:26,490 --> 00:03:27,750
of your organization

94
00:03:27,750 --> 00:03:30,390
than what is usually conducted during a penetration test.

95
00:03:30,390 --> 00:03:33,120
Software attestation involves validating the integrity

96
00:03:33,120 --> 00:03:35,460
of software by checking that it hasn't been tampered with

97
00:03:35,460 --> 00:03:37,410
or altered maliciously.

98
00:03:37,410 --> 00:03:39,870
For instance, by installing a software update,

99
00:03:39,870 --> 00:03:41,790
a system might use cryptographic techniques

100
00:03:41,790 --> 00:03:44,610
to verify the update's digital signature.

101
00:03:44,610 --> 00:03:46,020
If the signature is valid,

102
00:03:46,020 --> 00:03:48,420
it attests that the update is authentic

103
00:03:48,420 --> 00:03:50,340
and hasn't been tampered with since it was signed

104
00:03:50,340 --> 00:03:52,080
by the software vendor.

105
00:03:52,080 --> 00:03:54,930
Hardware attestation involves validating the integrity

106
00:03:54,930 --> 00:03:56,250
of hardware components.

107
00:03:56,250 --> 00:03:59,640
For example, a Trusted Platform Module, or TPM,

108
00:03:59,640 --> 00:04:00,870
can be used to attest

109
00:04:00,870 --> 00:04:03,000
that a computer hasn't been tampered with.

110
00:04:03,000 --> 00:04:05,520
The trusted platform module can store measurements

111
00:04:05,520 --> 00:04:08,280
of the computer's hardware and firmware configurations,

112
00:04:08,280 --> 00:04:10,680
and these measurements can be checked at boot time

113
00:04:10,680 --> 00:04:13,309
to ensure that they haven't changed unexpectedly.

114
00:04:13,309 --> 00:04:15,180
System attestation involves validating

115
00:04:15,180 --> 00:04:17,100
the security posture of a system.

116
00:04:17,100 --> 00:04:18,990
For instance, a cloud service provider

117
00:04:18,990 --> 00:04:20,579
might provide attestation

118
00:04:20,579 --> 00:04:23,250
that its services meet certain security standards,

119
00:04:23,250 --> 00:04:27,180
such as being ISO 27001 or SOC 2 compliant.

120
00:04:27,180 --> 00:04:29,820
This attestation gives customers confidence

121
00:04:29,820 --> 00:04:31,950
that their data is being handled securely.

122
00:04:31,950 --> 00:04:34,740
An internal audit's attestation plays a significant role

123
00:04:34,740 --> 00:04:36,840
in evaluating organizational compliance

124
00:04:36,840 --> 00:04:39,180
and the effectiveness of the internal controls.

125
00:04:39,180 --> 00:04:42,480
For instance, the internal auditor may provide attestation

126
00:04:42,480 --> 00:04:44,460
on the accuracy of financial records,

127
00:04:44,460 --> 00:04:46,440
the effectiveness of risk management strategies,

128
00:04:46,440 --> 00:04:49,350
or adherence to internal policies and procedures.

129
00:04:49,350 --> 00:04:51,960
This process helps to ensure that the organization

130
00:04:51,960 --> 00:04:54,060
is operating effectively and efficiently,

131
00:04:54,060 --> 00:04:56,370
and that is compliant with all the relevant laws,

132
00:04:56,370 --> 00:04:57,720
regulations, and standards.

133
00:04:57,720 --> 00:04:59,580
External audits, on the other hand,

134
00:04:59,580 --> 00:05:02,370
are conducted by an independent third party entity.

135
00:05:02,370 --> 00:05:05,070
These external audits often involve the attestation

136
00:05:05,070 --> 00:05:07,350
of financial statements, regulatory adherence,

137
00:05:07,350 --> 00:05:08,850
and operational efficiency

138
00:05:08,850 --> 00:05:11,400
by the trusted third party assessor.

139
00:05:11,400 --> 00:05:13,560
For example, if an external auditor

140
00:05:13,560 --> 00:05:14,850
may provide attestation

141
00:05:14,850 --> 00:05:16,950
on a company's annual financial statements

142
00:05:16,950 --> 00:05:19,440
to confirm that they present a true and fair view

143
00:05:19,440 --> 00:05:21,450
of the company's financial position,

144
00:05:21,450 --> 00:05:24,000
this attestation is crucial for stakeholders,

145
00:05:24,000 --> 00:05:25,770
such as investors, creditors,

146
00:05:25,770 --> 00:05:28,020
and regulators who rely on these statements

147
00:05:28,020 --> 00:05:29,850
to make informed decisions.

148
00:05:29,850 --> 00:05:32,310
Regardless of the type of audit being conducted,

149
00:05:32,310 --> 00:05:35,940
attestation remains a big component in strengthening trust,

150
00:05:35,940 --> 00:05:38,820
enhancing transparency, and ensuring accountability

151
00:05:38,820 --> 00:05:40,230
within an organization.

152
00:05:40,230 --> 00:05:42,210
By providing a formal validation

153
00:05:42,210 --> 00:05:45,360
of accuracy and authenticity of information,

154
00:05:45,360 --> 00:05:48,570
attestation helps to build confidence among stakeholders,

155
00:05:48,570 --> 00:05:51,000
promote transparency in business operations,

156
00:05:51,000 --> 00:05:53,730
and ensure that the organization is held accountable

157
00:05:53,730 --> 00:05:54,930
for its actions.

158
00:05:54,930 --> 00:05:58,920
So remember, attestation is a formal validation process

159
00:05:58,920 --> 00:06:00,390
that asserts the accuracy

160
00:06:00,390 --> 00:06:02,790
and authenticity of specific information

161
00:06:02,790 --> 00:06:03,990
and it plays a crucial role

162
00:06:03,990 --> 00:06:06,120
in both internal and external audits,

163
00:06:06,120 --> 00:06:09,150
serving as a foundation for asserting the reliability

164
00:06:09,150 --> 00:06:12,360
and integrity of data, systems, and processes.

165
00:06:12,360 --> 00:06:14,100
Regardless of the audit type,

166
00:06:14,100 --> 00:06:16,380
attestation is key in strengthening trust,

167
00:06:16,380 --> 00:06:17,760
enhancing transparency,

168
00:06:17,760 --> 00:06:20,550
and ensuring accountability within the organization.

169
00:06:20,550 --> 00:06:22,440
It builds confidence among stakeholders,

170
00:06:22,440 --> 00:06:24,540
promotes transparency in operations,

171
00:06:24,540 --> 00:06:27,393
and ensures organizational accountability.

