1
00:00:00,090 --> 00:00:00,960
In this lesson,

2
00:00:00,960 --> 00:00:02,250
we're going to focus on selecting

3
00:00:02,250 --> 00:00:05,430
infrastructure controls for our enterprise infrastructure.

4
00:00:05,430 --> 00:00:07,890
Now, our networks and infrastructure security is created

5
00:00:07,890 --> 00:00:09,504
by a large number of different decisions

6
00:00:09,504 --> 00:00:11,700
that we have made over the years.

7
00:00:11,700 --> 00:00:13,320
Each decision to install a new piece

8
00:00:13,320 --> 00:00:14,520
of hardware or software,

9
00:00:14,520 --> 00:00:15,990
will introduce new vulnerabilities

10
00:00:15,990 --> 00:00:17,820
into our enterprise infrastructure,

11
00:00:17,820 --> 00:00:19,905
but we can also strategically select different controls

12
00:00:19,905 --> 00:00:22,080
to effectively mitigate the risks presented

13
00:00:22,080 --> 00:00:24,570
by these new vulnerabilities and weaknesses.

14
00:00:24,570 --> 00:00:26,160
As a cybersecurity professional,

15
00:00:26,160 --> 00:00:27,360
you're going to spend a lot of time

16
00:00:27,360 --> 00:00:29,820
selecting or recommending various controls

17
00:00:29,820 --> 00:00:31,470
that you can use to effectively secure

18
00:00:31,470 --> 00:00:33,965
and protect your network and the data it contains.

19
00:00:33,965 --> 00:00:35,580
Now, a control is a measure

20
00:00:35,580 --> 00:00:38,370
or safeguard that's implemented to mitigate potential risks

21
00:00:38,370 --> 00:00:40,259
and to protect an organization's assets.

22
00:00:40,259 --> 00:00:42,510
Selecting effective controls ensures

23
00:00:42,510 --> 00:00:43,590
that we can prevent breaches

24
00:00:43,590 --> 00:00:45,660
and to minimize vulnerabilities while ensuring

25
00:00:45,660 --> 00:00:48,360
that our resources are being used efficiently.

26
00:00:48,360 --> 00:00:50,640
Effective control selections can also help us

27
00:00:50,640 --> 00:00:53,130
to foster trust among our stakeholders by demonstrating

28
00:00:53,130 --> 00:00:54,270
that we have a proactive approach

29
00:00:54,270 --> 00:00:56,780
to our organization security and compliance postures.

30
00:00:56,780 --> 00:00:58,830
So in this lesson,

31
00:00:58,830 --> 00:01:00,420
we're going to go through some key principles,

32
00:01:00,420 --> 00:01:03,060
methodologies, and best practices that you can use

33
00:01:03,060 --> 00:01:05,250
to make more informed decisions when you're selecting

34
00:01:05,250 --> 00:01:07,410
effective controls inside of your organization's

35
00:01:07,410 --> 00:01:09,060
network infrastructure.

36
00:01:09,060 --> 00:01:11,820
Now, first, let's talk about some key principles

37
00:01:11,820 --> 00:01:13,950
when it comes to selecting effective controls.

38
00:01:13,950 --> 00:01:15,450
We should consider the key principles

39
00:01:15,450 --> 00:01:17,610
of least privilege, defense in depth,

40
00:01:17,610 --> 00:01:18,995
utilizing a risk-based approach,

41
00:01:18,995 --> 00:01:20,880
conducting lifecycle management,

42
00:01:20,880 --> 00:01:23,310
and focusing on open design principles

43
00:01:23,310 --> 00:01:25,110
to secure our infrastructure.

44
00:01:25,110 --> 00:01:27,750
Now, the principle of least privilege mandates that a user

45
00:01:27,750 --> 00:01:30,025
or system should only have the necessary access rights

46
00:01:30,025 --> 00:01:32,015
that they need to perform their duties.

47
00:01:32,015 --> 00:01:34,410
Selecting and implementing controls associated

48
00:01:34,410 --> 00:01:36,570
with the principle of least privilege really does help

49
00:01:36,570 --> 00:01:39,015
to reduce the potential attack surface of your network.

50
00:01:39,015 --> 00:01:40,980
Another key principle to use

51
00:01:40,980 --> 00:01:43,020
is the concept of defense in depth.

52
00:01:43,020 --> 00:01:45,600
Now, the defense in depth approach emphasizes the use

53
00:01:45,600 --> 00:01:47,550
of multiple layers of security to ensure

54
00:01:47,550 --> 00:01:48,455
that if one control fails,

55
00:01:48,455 --> 00:01:50,105
that our other controls will still be ready

56
00:01:50,105 --> 00:01:52,710
to stop a potential threat from successfully

57
00:01:52,710 --> 00:01:54,810
exploiting our infrastructure.

58
00:01:54,810 --> 00:01:57,330
Now, a risk-based approach is another good idea for you

59
00:01:57,330 --> 00:01:59,310
to implement because it underscores the need

60
00:01:59,310 --> 00:02:01,920
for the prioritization of controls based on the potential

61
00:02:01,920 --> 00:02:03,870
risks and vulnerabilities that are specific

62
00:02:03,870 --> 00:02:05,675
to your organization's infrastructure.

63
00:02:05,675 --> 00:02:08,685
After all, no organization has enough people time

64
00:02:08,685 --> 00:02:12,030
or money to completely mitigate every single potential

65
00:02:12,030 --> 00:02:13,980
threat or vulnerability that's out there.

66
00:02:13,980 --> 00:02:16,405
So we have to prioritize them using a risk-based approach

67
00:02:16,405 --> 00:02:18,900
to more effectively use our limited resources

68
00:02:18,900 --> 00:02:22,050
while giving us the best protection for our infrastructure.

69
00:02:22,050 --> 00:02:24,060
Additionally, the principle of lifecycle

70
00:02:24,060 --> 00:02:26,100
management will be used to focus on the importance

71
00:02:26,100 --> 00:02:27,930
of regularly reviewing, updating,

72
00:02:27,930 --> 00:02:29,940
and retiring our controls that align

73
00:02:29,940 --> 00:02:31,200
with the always changing threat

74
00:02:31,200 --> 00:02:32,715
landscape that we're experiencing.

75
00:02:32,715 --> 00:02:34,470
After all, we don't select

76
00:02:34,470 --> 00:02:36,060
and implement our controls one time

77
00:02:36,060 --> 00:02:37,410
and then expect that our network will be

78
00:02:37,410 --> 00:02:39,300
well protected for the rest of time.

79
00:02:39,300 --> 00:02:41,700
So we need to conduct proper lifecycle management for all

80
00:02:41,700 --> 00:02:44,285
of our controls as our networks evolve over the years.

81
00:02:44,285 --> 00:02:47,085
Now, the final key principle we need to utilize is one known

82
00:02:47,085 --> 00:02:49,380
as the open design principle.

83
00:02:49,380 --> 00:02:51,510
The open design principle is focused on creating

84
00:02:51,510 --> 00:02:53,880
transparency and accountability by ensuring

85
00:02:53,880 --> 00:02:56,640
that our infrastructure and our controls undergo rigorous

86
00:02:56,640 --> 00:02:58,860
testing and scrutiny to ensure they're effective

87
00:02:58,860 --> 00:03:00,810
and being implemented securely.

88
00:03:00,810 --> 00:03:03,390
By deeply understanding and integrating these key principles

89
00:03:03,390 --> 00:03:05,760
into the selection of your infrastructure's controls,

90
00:03:05,760 --> 00:03:07,260
you can ensure that you have a more robust,

91
00:03:07,260 --> 00:03:10,105
resilient and responsive enterprise infrastructure.

92
00:03:10,105 --> 00:03:12,205
Second, let's take a look at the methodology

93
00:03:12,205 --> 00:03:14,665
that you can use to select some effective controls.

94
00:03:14,665 --> 00:03:16,925
Now, the basic methodology that I recommend is

95
00:03:16,925 --> 00:03:18,600
to assess the current state,

96
00:03:18,600 --> 00:03:21,300
conduct a gap analysis, set clear objectives,

97
00:03:21,300 --> 00:03:24,390
conduct benchmarking, conduct a cost benefit analysis,

98
00:03:24,390 --> 00:03:25,920
ensure stakeholder involvement,

99
00:03:25,920 --> 00:03:27,300
and then implement monitoring

100
00:03:27,300 --> 00:03:29,760
and feedback loops into your organization.

101
00:03:29,760 --> 00:03:31,595
So remember that when you're examining methodologies,

102
00:03:31,595 --> 00:03:33,325
it's always important that you adopt a structured

103
00:03:33,325 --> 00:03:35,185
and systematic approach to ensure the security

104
00:03:35,185 --> 00:03:37,860
of your infrastructure remains intact.

105
00:03:37,860 --> 00:03:38,910
Now, you should always start out

106
00:03:38,910 --> 00:03:40,745
by assessing the current state of your security

107
00:03:40,745 --> 00:03:43,350
and the controls that you already have in place.

108
00:03:43,350 --> 00:03:44,580
You must have a clear understanding

109
00:03:44,580 --> 00:03:47,220
of your current infrastructure set up its vulnerabilities,

110
00:03:47,220 --> 00:03:49,380
and its existing controls, if any,

111
00:03:49,380 --> 00:03:51,395
before you start adding any kind of new controls.

112
00:03:51,395 --> 00:03:53,225
Once you understand your baseline,

113
00:03:53,225 --> 00:03:55,165
you should then utilize a gap analysis

114
00:03:55,165 --> 00:03:56,685
to identify any discrepancies

115
00:03:56,685 --> 00:03:58,385
between your current security posture

116
00:03:58,385 --> 00:04:00,930
and your desired security posture that you want to achieve

117
00:04:00,930 --> 00:04:03,180
inside your organization's network.

118
00:04:03,180 --> 00:04:05,310
Then once you have this information,

119
00:04:05,310 --> 00:04:07,260
you can set clear objectives for what you're hoping

120
00:04:07,260 --> 00:04:09,035
to achieve as you add additional controls,

121
00:04:09,035 --> 00:04:11,640
whether you want to safeguard specific data,

122
00:04:11,640 --> 00:04:12,480
ensure uptime,

123
00:04:12,480 --> 00:04:14,315
or maintain compliance with laws and regulations.

124
00:04:14,315 --> 00:04:16,805
Setting up clear objectives is going to help you do this

125
00:04:16,805 --> 00:04:19,440
during your control selection process.

126
00:04:19,440 --> 00:04:20,910
Once your objectives have been set,

127
00:04:20,910 --> 00:04:22,110
you can conduct benchmarking

128
00:04:22,110 --> 00:04:23,940
to compare your organization's processes,

129
00:04:23,940 --> 00:04:25,740
performance, and security metrics

130
00:04:25,740 --> 00:04:27,384
against your industry's best practices

131
00:04:27,384 --> 00:04:29,790
to determine how you compare to your competitors

132
00:04:29,790 --> 00:04:31,560
and others in your industry.

133
00:04:31,560 --> 00:04:34,620
Next, you should consider performing a cost benefit analysis

134
00:04:34,620 --> 00:04:36,930
before you start implementing your new controls.

135
00:04:36,930 --> 00:04:38,375
While we want the best controls in place,

136
00:04:38,375 --> 00:04:40,980
these controls also need to be cost effective.

137
00:04:40,980 --> 00:04:42,405
So it's important to find the right balance

138
00:04:42,405 --> 00:04:43,800
between the level of security

139
00:04:43,800 --> 00:04:45,645
that you want to achieve versus the amount of financial

140
00:04:45,645 --> 00:04:47,765
and other resources that are going to have to be invested

141
00:04:47,765 --> 00:04:49,955
to achieve that level of security.

142
00:04:49,955 --> 00:04:52,380
Stakeholder involvement is also important

143
00:04:52,380 --> 00:04:54,180
during this process because it's going to help you

144
00:04:54,180 --> 00:04:56,520
to ensure the controls you choose are going to be adopted

145
00:04:56,520 --> 00:04:58,080
by your users, and they're going to work

146
00:04:58,080 --> 00:04:59,850
in the business context of your current

147
00:04:59,850 --> 00:05:01,710
and ongoing operations.

148
00:05:01,710 --> 00:05:03,420
Finally, we need to create monitoring

149
00:05:03,420 --> 00:05:05,550
and feedback loops so that we can ensure our controls

150
00:05:05,550 --> 00:05:06,960
remain effective over time.

151
00:05:06,960 --> 00:05:09,630
Because the cyber threat landscape is constantly changing

152
00:05:09,630 --> 00:05:12,510
and evolving by regularly revisiting your control selection

153
00:05:12,510 --> 00:05:14,310
methodology to ensure it remains relevant

154
00:05:14,310 --> 00:05:15,900
and adjusting it as required,

155
00:05:15,900 --> 00:05:16,800
we're going to be able to ensure

156
00:05:16,800 --> 00:05:19,020
that our enterprise infrastructure remains agile

157
00:05:19,020 --> 00:05:21,175
in the face of continually evolving threats.

158
00:05:21,175 --> 00:05:23,445
Third, let's consider some best practices to use

159
00:05:23,445 --> 00:05:25,125
during the selection of various controls

160
00:05:25,125 --> 00:05:26,905
for your enterprise networks.

161
00:05:26,905 --> 00:05:28,980
Now, when you're determining the best controls

162
00:05:28,980 --> 00:05:30,570
for your enterprise infrastructure,

163
00:05:30,570 --> 00:05:33,300
you must first conduct a comprehensive risk assessment

164
00:05:33,300 --> 00:05:34,530
to better understand the threats

165
00:05:34,530 --> 00:05:37,275
and vulnerabilities that are specific to your organization.

166
00:05:37,275 --> 00:05:39,000
This will provide us with a foundation

167
00:05:39,000 --> 00:05:41,130
for every subsequent decision that we're going to be asked

168
00:05:41,130 --> 00:05:43,650
to make during the control selection process.

169
00:05:43,650 --> 00:05:45,690
Also, a risk assessment should not be

170
00:05:45,690 --> 00:05:47,310
considered a one-time thing,

171
00:05:47,310 --> 00:05:48,945
but instead, it should be a recurring process

172
00:05:48,945 --> 00:05:51,360
that's going to be repeated and updated anytime

173
00:05:51,360 --> 00:05:52,500
there's a significant change

174
00:05:52,500 --> 00:05:54,150
in your enterprise infrastructure

175
00:05:54,150 --> 00:05:56,160
or your business' operations.

176
00:05:56,160 --> 00:05:58,290
Next, you need to align your control selection

177
00:05:58,290 --> 00:06:00,690
to a well-established framework or standard.

178
00:06:00,690 --> 00:06:02,970
For example, the National Institute of Standards

179
00:06:02,970 --> 00:06:04,355
and Technology known as NIST

180
00:06:04,355 --> 00:06:06,785
and the International Organization for Standardization,

181
00:06:06,785 --> 00:06:08,370
known as ISO,

182
00:06:08,370 --> 00:06:09,455
both have published guidelines

183
00:06:09,455 --> 00:06:11,635
that have been vetted and refined over time.

184
00:06:11,635 --> 00:06:13,500
By adhering to these frameworks,

185
00:06:13,500 --> 00:06:15,690
you can be assured that your approach is comprehensive

186
00:06:15,690 --> 00:06:18,180
and based on tried and tested methodologies.

187
00:06:18,180 --> 00:06:19,650
For example, I personally like

188
00:06:19,650 --> 00:06:21,480
to use the NIST Cybersecurity framework

189
00:06:21,480 --> 00:06:23,700
and the NIST Risk Management framework when I'm working

190
00:06:23,700 --> 00:06:24,695
as a cybersecurity consultant,

191
00:06:24,695 --> 00:06:26,460
because they're both very in-depth

192
00:06:26,460 --> 00:06:27,535
and well-regarded frameworks

193
00:06:27,535 --> 00:06:29,605
that we can rely on during our engagements.

194
00:06:29,605 --> 00:06:31,975
Another best practice is to perform customization

195
00:06:31,975 --> 00:06:34,170
of the frameworks for your own usage

196
00:06:34,170 --> 00:06:36,210
to meet your specific use cases.

197
00:06:36,210 --> 00:06:37,615
Here, customization is key

198
00:06:37,615 --> 00:06:39,390
because while these frameworks provide

199
00:06:39,390 --> 00:06:40,860
a robust starting point,

200
00:06:40,860 --> 00:06:42,510
you can also tailor their controls

201
00:06:42,510 --> 00:06:44,790
to the unique aspects of your organization's business

202
00:06:44,790 --> 00:06:46,560
operations and its infrastructure's

203
00:06:46,560 --> 00:06:48,005
own specific risk profile.

204
00:06:48,005 --> 00:06:50,735
Finally, I cannot overemphasize the importance

205
00:06:50,735 --> 00:06:52,710
of conducting stakeholder engagement

206
00:06:52,710 --> 00:06:53,850
and training as part

207
00:06:53,850 --> 00:06:55,885
of your effective control selection process.

208
00:06:55,885 --> 00:06:58,920
Your security controls are only going to be as effective

209
00:06:58,920 --> 00:06:59,970
as the people who are asked

210
00:06:59,970 --> 00:07:01,725
to implement them and monitor them.

211
00:07:01,725 --> 00:07:04,770
Therefore, you have to engage all relevant stakeholders

212
00:07:04,770 --> 00:07:06,184
in the decision making processes

213
00:07:06,184 --> 00:07:08,250
to ensure that they understand the rationale

214
00:07:08,250 --> 00:07:10,350
behind each control that was being selected,

215
00:07:10,350 --> 00:07:11,970
and it's rolling your organization's

216
00:07:11,970 --> 00:07:13,325
broader security strategy.

217
00:07:13,325 --> 00:07:16,110
Regular training sessions should also be conducted

218
00:07:16,110 --> 00:07:18,360
to keep everyone up to date on the latest threats,

219
00:07:18,360 --> 00:07:20,235
the purpose of the security controls we have in place,

220
00:07:20,235 --> 00:07:23,045
and the best ways to utilize those control measures.

221
00:07:23,045 --> 00:07:25,500
When it comes to implementing effective security controls

222
00:07:25,500 --> 00:07:26,640
in your organization,

223
00:07:26,640 --> 00:07:28,590
you really will have to rely on a knowledgeable

224
00:07:28,590 --> 00:07:30,780
and engaged workforce to achieve a higher level

225
00:07:30,780 --> 00:07:32,790
of security for your infrastructure.

226
00:07:32,790 --> 00:07:34,650
So remember, a control is a measure

227
00:07:34,650 --> 00:07:37,350
or safeguard that's implemented to mitigate potential risks

228
00:07:37,350 --> 00:07:39,085
and protect an organization's assets.

229
00:07:39,085 --> 00:07:41,460
Selecting effective controls will ensure

230
00:07:41,460 --> 00:07:42,630
that we can prevent breaches

231
00:07:42,630 --> 00:07:44,815
and minimize vulnerabilities while ensuring our resources

232
00:07:44,815 --> 00:07:47,130
are being utilized efficiently.

233
00:07:47,130 --> 00:07:48,480
To select your controls,

234
00:07:48,480 --> 00:07:50,190
you should use a structured methodology

235
00:07:50,190 --> 00:07:51,930
like the basic methodology I presented

236
00:07:51,930 --> 00:07:53,880
that includes an assessment of the current state,

237
00:07:53,880 --> 00:07:55,890
a gap analysis, clear objectives,

238
00:07:55,890 --> 00:07:58,140
benchmarking, a cost benefit analysis,

239
00:07:58,140 --> 00:07:59,100
stakeholder involvement,

240
00:07:59,100 --> 00:08:01,170
and monitoring and feedback loops.

241
00:08:01,170 --> 00:08:02,910
Also, that control selection

242
00:08:02,910 --> 00:08:04,710
is not going to be a one-time event,

243
00:08:04,710 --> 00:08:05,910
but instead it's something that we need

244
00:08:05,910 --> 00:08:07,680
to practice time and time again,

245
00:08:07,680 --> 00:08:09,750
and I recommend that you do this either annually

246
00:08:09,750 --> 00:08:11,670
or quarterly based on your business

247
00:08:11,670 --> 00:08:14,470
to ensure your enterprise infrastructure remains secure.

