1
00:00:00,120 --> 00:00:01,290
In this section of the course,

2
00:00:01,290 --> 00:00:03,660
we're going to cover security architecture.

3
00:00:03,660 --> 00:00:05,250
Now, security architecture refers

4
00:00:05,250 --> 00:00:07,410
to the design, structure and behavior

5
00:00:07,410 --> 00:00:10,290
of an organization's information security environment.

6
00:00:10,290 --> 00:00:12,840
It encompasses various components such as hardware,

7
00:00:12,840 --> 00:00:14,970
software, processes and people,

8
00:00:14,970 --> 00:00:17,700
to protect the organization's information assets.

9
00:00:17,700 --> 00:00:19,350
So in this section of the course,

10
00:00:19,350 --> 00:00:21,720
we'll be covering Domain 3 and Domain 4,

11
00:00:21,720 --> 00:00:25,830
specifically focused on objective 3.1 and objective 4.1.

12
00:00:25,830 --> 00:00:27,870
Objective 3.1 states that you must be able

13
00:00:27,870 --> 00:00:29,820
to compare and contrast security implications

14
00:00:29,820 --> 00:00:31,620
of different architecture models.

15
00:00:31,620 --> 00:00:33,150
And objective 4.1 states

16
00:00:33,150 --> 00:00:35,070
that given a scenario you must be able

17
00:00:35,070 --> 00:00:38,670
to apply common security techniques to computing resources.

18
00:00:38,670 --> 00:00:40,740
Now, first we're going to cover on-premise

19
00:00:40,740 --> 00:00:42,330
versus cloud deployments.

20
00:00:42,330 --> 00:00:44,370
On-premise refers to the traditional method

21
00:00:44,370 --> 00:00:46,620
of setting up infrastructure and services locally

22
00:00:46,620 --> 00:00:49,050
within an organization's own premises.

23
00:00:49,050 --> 00:00:50,280
Now this includes servers,

24
00:00:50,280 --> 00:00:52,260
data centers and related hardware.

25
00:00:52,260 --> 00:00:53,760
Cloud computing, on the other hand,

26
00:00:53,760 --> 00:00:56,460
involves delivering computing services over the internet.

27
00:00:56,460 --> 00:00:58,140
This includes your servers, your storage,

28
00:00:58,140 --> 00:01:00,270
your database, your networking, your software,

29
00:01:00,270 --> 00:01:02,130
your analytics and much more.

30
00:01:02,130 --> 00:01:04,950
Next we're going to jump into a discussion on cloud security

31
00:01:04,950 --> 00:01:05,850
and in that lesson,

32
00:01:05,850 --> 00:01:07,980
we'll be covering all the security considerations

33
00:01:07,980 --> 00:01:09,240
when utilizing the cloud

34
00:01:09,240 --> 00:01:11,520
including shared physical server vulnerabilities,

35
00:01:11,520 --> 00:01:13,620
inadequate virtual environment security,

36
00:01:13,620 --> 00:01:15,090
user access management,

37
00:01:15,090 --> 00:01:16,920
lack of up-to-date security measures,

38
00:01:16,920 --> 00:01:18,270
single points of failure,

39
00:01:18,270 --> 00:01:20,550
weak authentication and encryption practices,

40
00:01:20,550 --> 00:01:22,860
unclear policies and data remnants.

41
00:01:22,860 --> 00:01:24,780
Then, we're going to talk about virtualization

42
00:01:24,780 --> 00:01:26,040
and containerization.

43
00:01:26,040 --> 00:01:28,320
And we'll be discussing different virtualization types,

44
00:01:28,320 --> 00:01:31,350
containerization, the benefits and risks of utilizing both,

45
00:01:31,350 --> 00:01:33,540
and we'll also go over some of the vulnerabilities

46
00:01:33,540 --> 00:01:36,030
like VM escape and resource reuse.

47
00:01:36,030 --> 00:01:38,550
After that, we're going to be discussing serverless.

48
00:01:38,550 --> 00:01:40,110
Now, serverless computing is a model

49
00:01:40,110 --> 00:01:42,870
where the cloud provider dynamically manages the allocation

50
00:01:42,870 --> 00:01:44,730
and provisioning of your servers.

51
00:01:44,730 --> 00:01:46,800
Developers don't need to worry about the server management

52
00:01:46,800 --> 00:01:48,210
and the capacity planning.

53
00:01:48,210 --> 00:01:51,060
Instead, they just focus on writing their code.

54
00:01:51,060 --> 00:01:53,430
Next, we'll discuss microservices.

55
00:01:53,430 --> 00:01:55,830
And microservices are an architectural style

56
00:01:55,830 --> 00:01:57,720
that structures an application as a collection

57
00:01:57,720 --> 00:01:59,550
of small autonomous services,

58
00:01:59,550 --> 00:02:02,460
and each one performs a specific business function.

59
00:02:02,460 --> 00:02:04,890
Then, we'll take a look at network architecture

60
00:02:04,890 --> 00:02:06,630
and we'll go over the use of physical separation

61
00:02:06,630 --> 00:02:08,729
like air gaps versus logical separation

62
00:02:08,729 --> 00:02:11,310
and things like that, as well as subnetting.

63
00:02:11,310 --> 00:02:14,010
After that, we'll dive into the software-defined networking

64
00:02:14,010 --> 00:02:16,170
space covering SDNs.

65
00:02:16,170 --> 00:02:18,510
Now, SDNs are an approach to network management

66
00:02:18,510 --> 00:02:20,010
that allows dynamic, programmatic,

67
00:02:20,010 --> 00:02:22,050
efficient network configurations in order

68
00:02:22,050 --> 00:02:24,450
to improve network performance and monitoring.

69
00:02:24,450 --> 00:02:28,290
Next, we're going to go over infrastructure as code or IaC.

70
00:02:28,290 --> 00:02:31,290
Now, IaC is a type of IT setup wherein developers

71
00:02:31,290 --> 00:02:33,600
or operations teams can automatically manage

72
00:02:33,600 --> 00:02:36,030
and provision the technology stack for an application

73
00:02:36,030 --> 00:02:38,760
through software rather than using a manual process

74
00:02:38,760 --> 00:02:40,530
to configure discrete hardware devices

75
00:02:40,530 --> 00:02:42,120
and operating systems.

76
00:02:42,120 --> 00:02:44,070
Then, we'll talk about centralized

77
00:02:44,070 --> 00:02:46,020
versus decentralized architectures

78
00:02:46,020 --> 00:02:47,640
by discussing the benefits and risks

79
00:02:47,640 --> 00:02:50,280
of centralized and decentralized architectures.

80
00:02:50,280 --> 00:02:52,500
After that, we'll go over the internet of things,

81
00:02:52,500 --> 00:02:53,880
known as IoT.

82
00:02:53,880 --> 00:02:55,950
Now the internet of things refers to networks

83
00:02:55,950 --> 00:02:58,260
of physical devices, vehicles, appliances

84
00:02:58,260 --> 00:02:59,640
and other items that are embedded

85
00:02:59,640 --> 00:03:02,070
with sensors, software and network connectivity

86
00:03:02,070 --> 00:03:03,870
that enables these objects to connect

87
00:03:03,870 --> 00:03:06,330
and exchange data in near real time.

88
00:03:06,330 --> 00:03:08,880
Next, we'll talk about ICS and SCADA.

89
00:03:08,880 --> 00:03:11,460
Now ICS stands for the industrial control systems

90
00:03:11,460 --> 00:03:13,050
and they're types of control systems

91
00:03:13,050 --> 00:03:15,840
used in industrial production including manufacturing,

92
00:03:15,840 --> 00:03:18,360
transportation, energy and utilities.

93
00:03:18,360 --> 00:03:19,620
SCADA on the other hand,

94
00:03:19,620 --> 00:03:22,500
stands for the supervisory control and data acquisition,

95
00:03:22,500 --> 00:03:24,420
and it's a subset of ICS.

96
00:03:24,420 --> 00:03:26,280
SCADA systems are used to control

97
00:03:26,280 --> 00:03:28,350
and monitor physical processes such as

98
00:03:28,350 --> 00:03:30,960
electricity transmission, gas transportation,

99
00:03:30,960 --> 00:03:33,780
water distribution and wastewater collection.

100
00:03:33,780 --> 00:03:36,030
Then, we'll cover embedded systems.

101
00:03:36,030 --> 00:03:38,520
Now an embedded system is a dedicated computer system

102
00:03:38,520 --> 00:03:41,100
that's designed for one or two specific functions.

103
00:03:41,100 --> 00:03:44,220
This system is embedded as part of a complete device system

104
00:03:44,220 --> 00:03:46,020
that includes hardware such as electrical

105
00:03:46,020 --> 00:03:47,790
and mechanical components too.

106
00:03:47,790 --> 00:03:49,410
And finally, we'll take a short quiz

107
00:03:49,410 --> 00:03:51,390
to see what you learned during this section of the course

108
00:03:51,390 --> 00:03:53,250
and review each of those quiz questions fully

109
00:03:53,250 --> 00:03:56,040
to ensure you can explain why each right answer was right.

110
00:03:56,040 --> 00:03:57,210
So let's go ahead

111
00:03:57,210 --> 00:03:59,100
and jump into the security architecture section

112
00:03:59,100 --> 00:04:00,033
of this course.

