1
00:00:00,000 --> 00:00:00,960
In this lesson,

2
00:00:00,960 --> 00:00:03,330
we're going to discuss secure baselines.

3
00:00:03,330 --> 00:00:04,920
Now, in the cybersecurity industry,

4
00:00:04,920 --> 00:00:07,770
a secure baseline refers to a standard set of configurations

5
00:00:07,770 --> 00:00:10,320
and controls that are applied to a system, network,

6
00:00:10,320 --> 00:00:13,770
or application to ensure a minimum level of security.

7
00:00:13,770 --> 00:00:16,350
Establishing a secure baseline helps organizations

8
00:00:16,350 --> 00:00:18,210
to maintain consistent security postures

9
00:00:18,210 --> 00:00:20,400
and mitigate common vulnerabilities across all

10
00:00:20,400 --> 00:00:22,560
of our organization's digital assets.

11
00:00:22,560 --> 00:00:23,970
So, let's take a moment and discuss

12
00:00:23,970 --> 00:00:26,310
how a secure baseline is established, deployed,

13
00:00:26,310 --> 00:00:28,620
and maintained in our organizations.

14
00:00:28,620 --> 00:00:31,440
Now, the first stage is to establish a secure baseline.

15
00:00:31,440 --> 00:00:32,850
And a secure baseline is established

16
00:00:32,850 --> 00:00:35,370
by conducting a thorough assessment of your system, network,

17
00:00:35,370 --> 00:00:37,320
or application that needs protection,

18
00:00:37,320 --> 00:00:39,810
in order to identify the type of data being handled,

19
00:00:39,810 --> 00:00:41,520
to understand the data's workflow,

20
00:00:41,520 --> 00:00:44,670
and to evaluate any potential vulnerabilities and threats,

21
00:00:44,670 --> 00:00:46,500
best practices, industry standards,

22
00:00:46,500 --> 00:00:47,760
and compliance requirements

23
00:00:47,760 --> 00:00:51,390
such as those outlined in frameworks like the ISO 27001

24
00:00:51,390 --> 00:00:54,270
or the NIST Special Publication 800-53

25
00:00:54,270 --> 00:00:55,860
are often used as our starting points

26
00:00:55,860 --> 00:00:57,930
for defining a secure baseline.

27
00:00:57,930 --> 00:01:00,390
Now, to establish a secure baseline configuration

28
00:01:00,390 --> 00:01:01,650
for a given type of system,

29
00:01:01,650 --> 00:01:04,170
like a specific laptop model that our organization uses

30
00:01:04,170 --> 00:01:05,550
for all of our end users,

31
00:01:05,550 --> 00:01:07,860
we're going to first get a copy of that brand new laptop

32
00:01:07,860 --> 00:01:09,060
to use as our template.

33
00:01:09,060 --> 00:01:12,420
Then, we're going to format it, install the operating system,

34
00:01:12,420 --> 00:01:14,940
update it, configure it, and properly secure it,

35
00:01:14,940 --> 00:01:16,710
all on that one laptop.

36
00:01:16,710 --> 00:01:19,140
Once this is done, this laptop will now be checked

37
00:01:19,140 --> 00:01:21,060
against our baseline configuration guidance

38
00:01:21,060 --> 00:01:22,080
and scanned for any known

39
00:01:22,080 --> 00:01:24,150
vulnerabilities or misconfigurations.

40
00:01:24,150 --> 00:01:25,620
Now, once this is completed,

41
00:01:25,620 --> 00:01:27,330
we now have a very secure laptop,

42
00:01:27,330 --> 00:01:29,550
but it doesn't have any of the different programs

43
00:01:29,550 --> 00:01:32,280
that our average users are going to need to perform their job.

44
00:01:32,280 --> 00:01:34,440
So, we can now install all the applications

45
00:01:34,440 --> 00:01:35,910
that are needed by our employees,

46
00:01:35,910 --> 00:01:37,800
including things like an office suite,

47
00:01:37,800 --> 00:01:40,380
endpoint detection response agent, a web browser,

48
00:01:40,380 --> 00:01:41,700
and other tools like that,

49
00:01:41,700 --> 00:01:43,680
based on their specific job roles.

50
00:01:43,680 --> 00:01:45,840
Once all these tools are installed and configured,

51
00:01:45,840 --> 00:01:47,160
we'll then scan the system again

52
00:01:47,160 --> 00:01:50,160
for any known vulnerabilities and remediate those too.

53
00:01:50,160 --> 00:01:51,840
Now, this may have taken us several hours

54
00:01:51,840 --> 00:01:54,060
to create this new laptop and fully secure it,

55
00:01:54,060 --> 00:01:55,800
so we don't want to have to do this each and every time

56
00:01:55,800 --> 00:01:57,240
we hire a new employee.

57
00:01:57,240 --> 00:01:59,640
So instead, we're going to create an image of this machine

58
00:01:59,640 --> 00:02:02,310
and use that as our known good and secure baseline

59
00:02:02,310 --> 00:02:05,100
for any new laptops that match this configuration

60
00:02:05,100 --> 00:02:07,350
that we need to be able to set up for our employees.

61
00:02:07,350 --> 00:02:10,139
This baseline will then be continually refined and secured

62
00:02:10,139 --> 00:02:11,130
so it remains up to date

63
00:02:11,130 --> 00:02:13,800
with the latest security patches, hotfixes, updates,

64
00:02:13,800 --> 00:02:14,820
and service packs,

65
00:02:14,820 --> 00:02:17,370
as the threat environment continues to evolve.

66
00:02:17,370 --> 00:02:19,080
Now, in addition to creating the secure image

67
00:02:19,080 --> 00:02:20,340
for new installations,

68
00:02:20,340 --> 00:02:22,590
we also need to keep track of any group policies

69
00:02:22,590 --> 00:02:24,660
and other configurations that we're going to create

70
00:02:24,660 --> 00:02:26,460
and ensure they're validated and secured

71
00:02:26,460 --> 00:02:28,950
before we deploy them to all of our other assets.

72
00:02:28,950 --> 00:02:31,650
And so now that we have a secure baseline established,

73
00:02:31,650 --> 00:02:32,490
we can now deploy it

74
00:02:32,490 --> 00:02:35,190
across all of our organization's digital assets.

75
00:02:35,190 --> 00:02:37,290
Deployment can involve configuring firewalls,

76
00:02:37,290 --> 00:02:38,670
setting up user permissions,

77
00:02:38,670 --> 00:02:40,200
implementing encryption protocols,

78
00:02:40,200 --> 00:02:42,540
ensuring that anti-virus and antimalware solutions

79
00:02:42,540 --> 00:02:44,490
are properly installed and updated.

80
00:02:44,490 --> 00:02:46,830
Automated tools and scripts can be employed to ensure

81
00:02:46,830 --> 00:02:49,440
that the secure baseline is going to be uniformly applied

82
00:02:49,440 --> 00:02:51,210
across all your devices and systems

83
00:02:51,210 --> 00:02:53,040
that are not installed using the disk image

84
00:02:53,040 --> 00:02:54,990
that we created back in the first step.

85
00:02:54,990 --> 00:02:57,660
So instead, we're going to be able to compare these assets

86
00:02:57,660 --> 00:02:59,460
against our known good configurations,

87
00:02:59,460 --> 00:03:01,920
ensure they all receive the proper configurations needed

88
00:03:01,920 --> 00:03:03,720
to make sure they're secure and up to date

89
00:03:03,720 --> 00:03:06,120
with all the latest configurations we've created.

90
00:03:06,120 --> 00:03:08,550
For example, in a Windows domain environment,

91
00:03:08,550 --> 00:03:11,760
administrators can use group policy objects known as GPOs

92
00:03:11,760 --> 00:03:13,260
to apply a secure baseline

93
00:03:13,260 --> 00:03:16,170
that dictates different policies like password policies,

94
00:03:16,170 --> 00:03:18,210
user rights assignments, and audit settings,

95
00:03:18,210 --> 00:03:20,670
across all the computers in a given domain.

96
00:03:20,670 --> 00:03:23,010
Similarly, if you're working in a cloud-based environment

97
00:03:23,010 --> 00:03:27,000
like AWS, organizations can utilize services like AWS Config

98
00:03:27,000 --> 00:03:28,920
to define and deploy secure configurations

99
00:03:28,920 --> 00:03:31,590
across all of their cloud-based resources.

100
00:03:31,590 --> 00:03:33,870
Next, we need to maintain the secure baseline

101
00:03:33,870 --> 00:03:35,370
on all of our assets.

102
00:03:35,370 --> 00:03:37,440
Now, this is done by locking down our systems

103
00:03:37,440 --> 00:03:39,840
so that our users can't install additional software

104
00:03:39,840 --> 00:03:42,240
or modify our existing configurations.

105
00:03:42,240 --> 00:03:43,590
Additionally, we're going to find

106
00:03:43,590 --> 00:03:44,820
that maintaining a secure baseline

107
00:03:44,820 --> 00:03:46,680
becomes an ongoing process.

108
00:03:46,680 --> 00:03:48,780
We're going to conduct regular audits and monitoring,

109
00:03:48,780 --> 00:03:50,970
and this is going to ensure that the baseline remains effective

110
00:03:50,970 --> 00:03:53,400
and up to date with the latest threats and vulnerabilities

111
00:03:53,400 --> 00:03:55,500
that we're seeing out in the marketplace.

112
00:03:55,500 --> 00:03:57,960
This type of continuous monitoring can be done by tools

113
00:03:57,960 --> 00:04:00,540
that will help us to identify deviations from the baseline,

114
00:04:00,540 --> 00:04:02,700
and then trigger alerts for immediate remediation

115
00:04:02,700 --> 00:04:05,040
by our security operations center team.

116
00:04:05,040 --> 00:04:07,380
Over time, you're going to need to periodically review

117
00:04:07,380 --> 00:04:09,030
and update your secure baseline

118
00:04:09,030 --> 00:04:11,490
to align with changes in the organizational infrastructure,

119
00:04:11,490 --> 00:04:14,520
business needs, and evolving threat landscapes too.

120
00:04:14,520 --> 00:04:16,680
Now, to aid in maintaining your secure baseline,

121
00:04:16,680 --> 00:04:18,329
you should also conduct training and awareness

122
00:04:18,329 --> 00:04:19,529
with all of your employees

123
00:04:19,529 --> 00:04:21,300
to ensure they understand the importance of adhering

124
00:04:21,300 --> 00:04:23,430
to the secure baseline configurations.

125
00:04:23,430 --> 00:04:25,320
Employees should be made aware of the potential risks

126
00:04:25,320 --> 00:04:26,790
of deviating from the baseline,

127
00:04:26,790 --> 00:04:27,630
and they should be encouraged

128
00:04:27,630 --> 00:04:29,400
to report any suspicious activities

129
00:04:29,400 --> 00:04:32,220
that they may notice when they're utilizing their systems.

130
00:04:32,220 --> 00:04:34,920
So remember, the establishment, deployment, and maintenance

131
00:04:34,920 --> 00:04:37,200
of a secure baseline is a critical practice

132
00:04:37,200 --> 00:04:38,850
within the cybersecurity industry

133
00:04:38,850 --> 00:04:40,980
that protects your organization's networks.

134
00:04:40,980 --> 00:04:42,570
Secure baselines help to ensure

135
00:04:42,570 --> 00:04:44,310
that an organization's digital assets

136
00:04:44,310 --> 00:04:46,560
are consistently configured to resist attacks

137
00:04:46,560 --> 00:04:49,530
and to mitigate known vulnerabilities and misconfigurations.

138
00:04:49,530 --> 00:04:51,090
By continuously monitoring and updating

139
00:04:51,090 --> 00:04:52,290
our secure baselines,

140
00:04:52,290 --> 00:04:54,780
our organizations can enhance their security posture

141
00:04:54,780 --> 00:04:56,970
and protect their valuable data and resources

142
00:04:56,970 --> 00:04:58,533
from potential data breaches.

