1
00:00:00,000 --> 00:00:01,830
In this lesson, we'll be learning about

2
00:00:01,830 --> 00:00:03,719
analyzing vulnerabilities.

3
00:00:03,719 --> 00:00:05,820
Analyzing vulnerabilities is a critical step

4
00:00:05,820 --> 00:00:06,900
that we must perform

5
00:00:06,900 --> 00:00:09,300
to help strengthen our cybersecurity defenses.

6
00:00:09,300 --> 00:00:10,650
As we move through this lesson,

7
00:00:10,650 --> 00:00:12,150
we're going to explore the various concepts

8
00:00:12,150 --> 00:00:13,830
related to analyzing vulnerabilities,

9
00:00:13,830 --> 00:00:16,020
including confirming the vulnerabilities exist,

10
00:00:16,020 --> 00:00:17,520
prioritizing the vulnerabilities,

11
00:00:17,520 --> 00:00:19,020
classifying the vulnerabilities,

12
00:00:19,020 --> 00:00:21,210
the organizational impact of those vulnerabilities,

13
00:00:21,210 --> 00:00:22,860
the exposure factor of the vulnerabilities,

14
00:00:22,860 --> 00:00:25,260
and how all of this compares to the risk tolerance

15
00:00:25,260 --> 00:00:26,730
in your organization.

16
00:00:26,730 --> 00:00:29,970
Now, first, let's start out with vulnerability confirmation.

17
00:00:29,970 --> 00:00:32,070
When you run a vulnerability scan of your network,

18
00:00:32,070 --> 00:00:34,560
numerous vulnerabilities are going to be detected.

19
00:00:34,560 --> 00:00:36,630
Now, some of these vulnerabilities are going to be real,

20
00:00:36,630 --> 00:00:38,910
and some of these are really not an issue for us.

21
00:00:38,910 --> 00:00:41,160
So a part of our vulnerability management process

22
00:00:41,160 --> 00:00:43,500
is that we have to analyze each alert or finding

23
00:00:43,500 --> 00:00:45,150
to determine if it's a true positive,

24
00:00:45,150 --> 00:00:46,080
false positive,

25
00:00:46,080 --> 00:00:46,913
true negative,

26
00:00:46,913 --> 00:00:48,180
or false negative.

27
00:00:48,180 --> 00:00:49,680
Now, a true positive occurs

28
00:00:49,680 --> 00:00:51,270
when there is a real and exploitable vulnerability

29
00:00:51,270 --> 00:00:53,100
that has been correctly identified

30
00:00:53,100 --> 00:00:54,840
by your vulnerability scanner.

31
00:00:54,840 --> 00:00:57,090
Basically, our systems say that we're vulnerable

32
00:00:57,090 --> 00:00:58,230
and we analyze the finding,

33
00:00:58,230 --> 00:00:59,610
and we agree the vulnerability

34
00:00:59,610 --> 00:01:01,680
does exist inside of our system.

35
00:01:01,680 --> 00:01:04,680
For example, if we perform a vulnerability scan on a system

36
00:01:04,680 --> 00:01:06,870
and it detects or missing a critical security patch

37
00:01:06,870 --> 00:01:09,720
like Microsoft 17-010,

38
00:01:09,720 --> 00:01:10,830
and we look at that system

39
00:01:10,830 --> 00:01:12,900
and we agree that patch was never installed,

40
00:01:12,900 --> 00:01:14,730
this is known as a true positive.

41
00:01:14,730 --> 00:01:17,130
Because that system is indeed vulnerable to attacks

42
00:01:17,130 --> 00:01:18,510
against this known vulnerability

43
00:01:18,510 --> 00:01:21,510
because the patch to mitigate that has not been installed.

44
00:01:21,510 --> 00:01:23,250
Now, a false positive is going to occur

45
00:01:23,250 --> 00:01:24,660
when the system incorrectly states

46
00:01:24,660 --> 00:01:26,520
that a vulnerability exists on the system,

47
00:01:26,520 --> 00:01:29,130
but that vulnerability actually doesn't exist.

48
00:01:29,130 --> 00:01:30,720
For example, I've had cases

49
00:01:30,720 --> 00:01:32,070
where I've scanned a Linux system

50
00:01:32,070 --> 00:01:33,930
and the vulnerability scanning report comes back

51
00:01:33,930 --> 00:01:35,400
stating that the system is missing

52
00:01:35,400 --> 00:01:37,110
a critical Windows security patch

53
00:01:37,110 --> 00:01:38,610
and is therefore vulnerable.

54
00:01:38,610 --> 00:01:41,010
But because I'm using a Linux machine or server,

55
00:01:41,010 --> 00:01:43,740
it's actually not vulnerable to any Windows-based exploit.

56
00:01:43,740 --> 00:01:46,140
So this would be considered a false positive

57
00:01:46,140 --> 00:01:48,240
because Windows patches are not going to be required

58
00:01:48,240 --> 00:01:50,010
on a Linux-based system.

59
00:01:50,010 --> 00:01:51,690
Now, a true negative, on the other hand,

60
00:01:51,690 --> 00:01:53,850
is going to occur when the system correctly identifies

61
00:01:53,850 --> 00:01:56,490
that there is no vulnerability present on the system.

62
00:01:56,490 --> 00:01:58,530
For example, if I scan my laptop

63
00:01:58,530 --> 00:01:59,850
and it states I have correctly installed

64
00:01:59,850 --> 00:02:02,220
all the security patches and updates from my system,

65
00:02:02,220 --> 00:02:04,020
it is reporting a true negative

66
00:02:04,020 --> 00:02:05,880
because it's stating that my system is secure

67
00:02:05,880 --> 00:02:06,990
from known vulnerabilities

68
00:02:06,990 --> 00:02:08,789
inside of the scanning engine's database,

69
00:02:08,789 --> 00:02:10,080
and that is actually the true state

70
00:02:10,080 --> 00:02:11,910
because I am not vulnerable.

71
00:02:11,910 --> 00:02:13,200
Now, a false negative

72
00:02:13,200 --> 00:02:15,780
is actually one of the most serious findings you can have.

73
00:02:15,780 --> 00:02:16,980
With a false negative,

74
00:02:16,980 --> 00:02:18,030
the vulnerability scanner

75
00:02:18,030 --> 00:02:20,520
does not detect a known vulnerability on the system,

76
00:02:20,520 --> 00:02:21,840
even though that vulnerability

77
00:02:21,840 --> 00:02:23,910
does actually exist on the system.

78
00:02:23,910 --> 00:02:25,980
Now, the reason I consider this to be the most dangerous

79
00:02:25,980 --> 00:02:28,230
is because you think you are well-protected and secure

80
00:02:28,230 --> 00:02:30,900
because your scans are not detecting a known vulnerability,

81
00:02:30,900 --> 00:02:34,050
but those vulnerabilities are still there on your system.

82
00:02:34,050 --> 00:02:34,890
This often occurs

83
00:02:34,890 --> 00:02:36,630
because you forgot to update the scanner's rules

84
00:02:36,630 --> 00:02:37,530
or definitions.

85
00:02:37,530 --> 00:02:39,480
So the scanner is unaware of a newer exploit

86
00:02:39,480 --> 00:02:40,320
that's available

87
00:02:40,320 --> 00:02:42,840
that is now attacking a known vulnerability.

88
00:02:42,840 --> 00:02:45,810
Second, we need to prioritize our vulnerabilities.

89
00:02:45,810 --> 00:02:47,790
Now, when we're prioritizing our vulnerabilities,

90
00:02:47,790 --> 00:02:49,860
we need to rank our identified vulnerabilities

91
00:02:49,860 --> 00:02:51,120
in the order of their severity

92
00:02:51,120 --> 00:02:53,250
and potential impact on the organization

93
00:02:53,250 --> 00:02:54,900
to ensure that we can allocate resources

94
00:02:54,900 --> 00:02:57,630
that address the most critical security threats first.

95
00:02:57,630 --> 00:02:59,250
Several factors are going to come into play

96
00:02:59,250 --> 00:03:00,360
during this process,

97
00:03:00,360 --> 00:03:02,100
including the ease of exploitation,

98
00:03:02,100 --> 00:03:03,630
the magnitude of potential damage,

99
00:03:03,630 --> 00:03:05,490
and the importance of the affected system

100
00:03:05,490 --> 00:03:07,530
to the organization's operations.

101
00:03:07,530 --> 00:03:08,430
For example,

102
00:03:08,430 --> 00:03:09,630
if a vulnerability is found

103
00:03:09,630 --> 00:03:10,980
in a mission-critical application

104
00:03:10,980 --> 00:03:12,780
that could lead to significant data breaches,

105
00:03:12,780 --> 00:03:13,980
if it was exploited,

106
00:03:13,980 --> 00:03:16,470
this is probably going to be prioritized a lot higher

107
00:03:16,470 --> 00:03:19,320
than a minor flaw in a less significant system.

108
00:03:19,320 --> 00:03:20,910
Now, to assist in this process,

109
00:03:20,910 --> 00:03:23,490
security professionals often employ a scoring system

110
00:03:23,490 --> 00:03:27,180
like the Common Vulnerability Scoring System, or CVSS.

111
00:03:27,180 --> 00:03:29,160
Now, the Common Vulnerability Scoring System

112
00:03:29,160 --> 00:03:30,930
is going to provide us with a standardized framework

113
00:03:30,930 --> 00:03:32,850
for assessing the severity of a vulnerability,

114
00:03:32,850 --> 00:03:35,040
and then assign a score based on metrics

115
00:03:35,040 --> 00:03:36,900
such as the attack vector being used,

116
00:03:36,900 --> 00:03:40,080
the impact, and the exploitability of that vulnerability.

117
00:03:40,080 --> 00:03:41,970
By utilizing a CVSS score

118
00:03:41,970 --> 00:03:44,010
and considering our organizational context,

119
00:03:44,010 --> 00:03:45,090
our security teams

120
00:03:45,090 --> 00:03:47,400
can systematically prioritize our vulnerabilities

121
00:03:47,400 --> 00:03:48,780
to ensure that our efforts are being focused

122
00:03:48,780 --> 00:03:49,800
where they're needed most,

123
00:03:49,800 --> 00:03:52,200
and that the risk is being effectively managed.

124
00:03:52,200 --> 00:03:54,870
Third, we need to classify our vulnerabilities.

125
00:03:54,870 --> 00:03:56,100
Now, classification involves

126
00:03:56,100 --> 00:03:58,140
categorizing the identified vulnerabilities

127
00:03:58,140 --> 00:04:00,060
based on factors like the type of threat,

128
00:04:00,060 --> 00:04:01,950
the potential impact on the organization,

129
00:04:01,950 --> 00:04:04,410
and the systems or data that may be affected.

130
00:04:04,410 --> 00:04:05,400
By doing so,

131
00:04:05,400 --> 00:04:06,870
organizations can better understand

132
00:04:06,870 --> 00:04:08,160
the nature of the vulnerabilities

133
00:04:08,160 --> 00:04:10,560
and align the remediation efforts accordingly.

134
00:04:10,560 --> 00:04:11,430
For example,

135
00:04:11,430 --> 00:04:13,590
vulnerabilities might be classified into categories

136
00:04:13,590 --> 00:04:14,670
like software flaws,

137
00:04:14,670 --> 00:04:15,630
configuration errors,

138
00:04:15,630 --> 00:04:17,370
or security policy gaps.

139
00:04:17,370 --> 00:04:18,720
Within each of these categories,

140
00:04:18,720 --> 00:04:20,670
we can further sub-classify these things

141
00:04:20,670 --> 00:04:22,050
like buffer overflows,

142
00:04:22,050 --> 00:04:22,980
privilege escalation,

143
00:04:22,980 --> 00:04:25,140
or insecure default settings.

144
00:04:25,140 --> 00:04:26,580
Another way for us to gain information

145
00:04:26,580 --> 00:04:27,510
about our vulnerabilities

146
00:04:27,510 --> 00:04:29,100
that we can use to aid in the classification

147
00:04:29,100 --> 00:04:30,150
of our vulnerabilities

148
00:04:30,150 --> 00:04:32,130
is something known as a CVE,

149
00:04:32,130 --> 00:04:35,130
or a Common Vulnerabilities and Exposures.

150
00:04:35,130 --> 00:04:37,410
Now, the Common Vulnerabilities and Exposures system

151
00:04:37,410 --> 00:04:38,880
is going to contain a large database

152
00:04:38,880 --> 00:04:41,550
of every known vulnerability in the world.

153
00:04:41,550 --> 00:04:45,030
Each vulnerability will be assigned a specific CVE number,

154
00:04:45,030 --> 00:04:47,010
and this can be used to look up the relevant information

155
00:04:47,010 --> 00:04:49,260
about that vulnerability at the website

156
00:04:49,260 --> 00:04:52,680
cve.mitre.org.

157
00:04:55,440 --> 00:04:58,260
Now, this CVE database serves as a valuable reference

158
00:04:58,260 --> 00:04:59,730
for cybersecurity professionals

159
00:04:59,730 --> 00:05:01,500
to provide us with a detailed description,

160
00:05:01,500 --> 00:05:02,460
potential impact,

161
00:05:02,460 --> 00:05:04,530
and references to solutions or workarounds

162
00:05:04,530 --> 00:05:06,780
for each vulnerability that's been identified.

163
00:05:06,780 --> 00:05:08,880
By cross-referencing your detective vulnerabilities

164
00:05:08,880 --> 00:05:10,440
with the CVE database,

165
00:05:10,440 --> 00:05:12,120
organizations can gain deeper insights

166
00:05:12,120 --> 00:05:13,980
into the nature and characteristics of the threats

167
00:05:13,980 --> 00:05:14,910
that they're facing.

168
00:05:14,910 --> 00:05:16,260
They can make more informed decisions

169
00:05:16,260 --> 00:05:18,510
during the vulnerability management process.

170
00:05:18,510 --> 00:05:20,220
Also, by using the CVEs

171
00:05:20,220 --> 00:05:21,960
to help classify your vulnerabilities,

172
00:05:21,960 --> 00:05:23,190
you're going to be able to systematically

173
00:05:23,190 --> 00:05:24,870
evaluate your security posture

174
00:05:24,870 --> 00:05:26,310
in order to make informed decisions

175
00:05:26,310 --> 00:05:29,130
about prioritizing and addressing your vulnerabilities.

176
00:05:29,130 --> 00:05:31,110
By having a clear classification system,

177
00:05:31,110 --> 00:05:33,180
security teams can streamline their workflows

178
00:05:33,180 --> 00:05:34,770
and ensure they're dealing with these vulnerabilities

179
00:05:34,770 --> 00:05:37,140
in a strategic and organized manner.

180
00:05:37,140 --> 00:05:39,330
Fourth, we have the organizational impact

181
00:05:39,330 --> 00:05:40,680
of the vulnerabilities.

182
00:05:40,680 --> 00:05:41,820
Now, it's important to understand

183
00:05:41,820 --> 00:05:43,920
the potential impact on your organization

184
00:05:43,920 --> 00:05:46,950
in order to properly prioritize your remediation efforts.

185
00:05:46,950 --> 00:05:48,780
The vulnerabilities impact can be assessed

186
00:05:48,780 --> 00:05:50,190
in terms of its confidentiality,

187
00:05:50,190 --> 00:05:51,840
integrity, or availability

188
00:05:51,840 --> 00:05:53,370
of your different data and services

189
00:05:53,370 --> 00:05:54,720
that are going to be affected.

190
00:05:54,720 --> 00:05:56,520
A vulnerability that could lead to the exposure

191
00:05:56,520 --> 00:05:58,470
of sensitive customer data, for example,

192
00:05:58,470 --> 00:05:59,820
would have a significant impact

193
00:05:59,820 --> 00:06:01,530
on your organization's reputation

194
00:06:01,530 --> 00:06:03,330
and could even result in regulatory fines

195
00:06:03,330 --> 00:06:05,310
being imposed upon your company.

196
00:06:05,310 --> 00:06:06,660
Similarly, a vulnerability

197
00:06:06,660 --> 00:06:08,820
that affects the availability of a critical service

198
00:06:08,820 --> 00:06:10,080
would've serious consequences

199
00:06:10,080 --> 00:06:11,610
for your business continuity plans.

200
00:06:11,610 --> 00:06:14,010
So you may give that a higher prioritization level

201
00:06:14,010 --> 00:06:17,010
based on this increased impact to your overall business.

202
00:06:17,010 --> 00:06:19,380
The vulnerabilities impact on your organization

203
00:06:19,380 --> 00:06:21,180
can also be assessed based on the industry

204
00:06:21,180 --> 00:06:23,250
that the organization is operating within.

205
00:06:23,250 --> 00:06:24,120
For example,

206
00:06:24,120 --> 00:06:25,920
vulnerabilities in a healthcare organization

207
00:06:25,920 --> 00:06:27,990
could risk patient data and safety

208
00:06:27,990 --> 00:06:30,090
while vulnerabilities at a financial institution

209
00:06:30,090 --> 00:06:31,380
could lead to monetary losses

210
00:06:31,380 --> 00:06:33,150
and increase scrutiny by regulators.

211
00:06:33,150 --> 00:06:34,380
And in both of these cases,

212
00:06:34,380 --> 00:06:37,020
you would prioritize those vulnerabilities higher up

213
00:06:37,020 --> 00:06:39,630
than you might for something at a small local store.

214
00:06:39,630 --> 00:06:40,950
Now, by considering the specifics

215
00:06:40,950 --> 00:06:42,960
around your organization and your industry,

216
00:06:42,960 --> 00:06:44,910
your cybersecurity team can better understand

217
00:06:44,910 --> 00:06:47,670
how a vulnerability might affect your day-to-day operations,

218
00:06:47,670 --> 00:06:48,660
your legal compliance,

219
00:06:48,660 --> 00:06:50,910
and overall level of customer trust.

220
00:06:50,910 --> 00:06:52,770
Fifth, we have exposure factor

221
00:06:52,770 --> 00:06:54,480
of the vulnerability to consider.

222
00:06:54,480 --> 00:06:56,460
Now, the exposure factor or EF

223
00:06:56,460 --> 00:06:58,230
is used as a quantifiable metric

224
00:06:58,230 --> 00:06:59,520
to help a cybersecurity professional

225
00:06:59,520 --> 00:07:01,770
understand the exact percentage of an asset

226
00:07:01,770 --> 00:07:03,570
that is likely to be damaged or affected

227
00:07:03,570 --> 00:07:06,450
if a particular vulnerability is going to be exploited.

228
00:07:06,450 --> 00:07:07,290
At its core,

229
00:07:07,290 --> 00:07:10,110
the exposure factor is an estimation of the amount of loss

230
00:07:10,110 --> 00:07:12,870
that a vulnerability might cause to your organization.

231
00:07:12,870 --> 00:07:13,740
For example,

232
00:07:13,740 --> 00:07:16,200
if a critical database contains sensitive customer data

233
00:07:16,200 --> 00:07:17,400
and it was compromised,

234
00:07:17,400 --> 00:07:19,950
the exposure factor would be considered pretty high,

235
00:07:19,950 --> 00:07:22,860
as a large portion or potentially the entire database

236
00:07:22,860 --> 00:07:25,020
and that asset could be put at risk.

237
00:07:25,020 --> 00:07:25,853
On the other hand,

238
00:07:25,853 --> 00:07:28,680
if the vulnerability only exposes non-critical information,

239
00:07:28,680 --> 00:07:29,880
the exposure factor there

240
00:07:29,880 --> 00:07:31,470
would actually be assigned much lower

241
00:07:31,470 --> 00:07:33,780
because it's affecting a much less significant portion

242
00:07:33,780 --> 00:07:35,940
of our business or that asset.

243
00:07:35,940 --> 00:07:38,610
Now, organizations need to understand the exposure factor

244
00:07:38,610 --> 00:07:39,540
because it's used heavily

245
00:07:39,540 --> 00:07:41,640
when you're conducting a qualitative risk management

246
00:07:41,640 --> 00:07:43,200
inside your organization.

247
00:07:43,200 --> 00:07:44,700
By evaluating the exposure factor

248
00:07:44,700 --> 00:07:45,930
along with other variables

249
00:07:45,930 --> 00:07:48,210
like the threat likelihood and the asset value,

250
00:07:48,210 --> 00:07:50,310
your organization will truly be able to understand

251
00:07:50,310 --> 00:07:51,480
the potential impact

252
00:07:51,480 --> 00:07:53,940
of a successful exploit in mathematical terms,

253
00:07:53,940 --> 00:07:55,950
so they can properly allocate time, money,

254
00:07:55,950 --> 00:07:58,380
and other resources to mitigating the vulnerabilities,

255
00:07:58,380 --> 00:07:59,490
which pose the greatest risk

256
00:07:59,490 --> 00:08:01,710
to your operations and your objectives.

257
00:08:01,710 --> 00:08:03,300
And sixth, we need to understand

258
00:08:03,300 --> 00:08:04,710
our organization's risk tolerance

259
00:08:04,710 --> 00:08:06,570
as we analyze vulnerabilities.

260
00:08:06,570 --> 00:08:08,460
Risk tolerance refers to the level of risk

261
00:08:08,460 --> 00:08:10,260
that an organization is willing to accept

262
00:08:10,260 --> 00:08:11,700
in the pursuit of its objectives

263
00:08:11,700 --> 00:08:14,910
before action is deemed necessary to mitigate that risk.

264
00:08:14,910 --> 00:08:17,100
By understanding our organization's risk tolerance,

265
00:08:17,100 --> 00:08:19,050
we can ensure that we align our organization's approach

266
00:08:19,050 --> 00:08:20,250
to vulnerability management

267
00:08:20,250 --> 00:08:22,440
with its broader risk management strategy.

268
00:08:22,440 --> 00:08:23,273
After all,

269
00:08:23,273 --> 00:08:25,290
some organizations might be more risk-averse

270
00:08:25,290 --> 00:08:27,330
and will prioritize more stringent security measures

271
00:08:27,330 --> 00:08:29,460
that require dedicating a lot more resources

272
00:08:29,460 --> 00:08:31,770
to address even the most minor vulnerabilities.

273
00:08:31,770 --> 00:08:34,230
While other organizations may have a higher risk tolerance,

274
00:08:34,230 --> 00:08:35,429
so they're going to be more willing

275
00:08:35,429 --> 00:08:37,289
to accept a certain level of exposure

276
00:08:37,289 --> 00:08:38,130
while they're focusing

277
00:08:38,130 --> 00:08:40,409
on more pressing aspects of their business.

278
00:08:40,409 --> 00:08:43,440
Basically, if your organization has a low risk tolerance,

279
00:08:43,440 --> 00:08:46,260
even vulnerabilities with a minor or moderate impact

280
00:08:46,260 --> 00:08:48,270
will need to be remediated more quickly.

281
00:08:48,270 --> 00:08:50,100
Conversely, if you work for an organization

282
00:08:50,100 --> 00:08:51,540
with a higher risk tolerance,

283
00:08:51,540 --> 00:08:53,130
your organization might decide

284
00:08:53,130 --> 00:08:55,050
to simply monitor certain vulnerabilities

285
00:08:55,050 --> 00:08:57,420
while they're focusing their remediation efforts and money

286
00:08:57,420 --> 00:08:59,130
to secure more severe vulnerabilities

287
00:08:59,130 --> 00:09:00,750
or those with a higher likelihood

288
00:09:00,750 --> 00:09:02,760
of being exploited by a threat actor.

289
00:09:02,760 --> 00:09:03,600
In either case,

290
00:09:03,600 --> 00:09:05,610
aligning your vulnerability management practices

291
00:09:05,610 --> 00:09:07,410
with the organization's risk tolerance

292
00:09:07,410 --> 00:09:09,180
is going to ensure that your security efforts

293
00:09:09,180 --> 00:09:10,170
are going to remain consistent

294
00:09:10,170 --> 00:09:12,840
with your overall business strategies and objectives.

295
00:09:12,840 --> 00:09:13,740
So remember,

296
00:09:13,740 --> 00:09:15,780
analyzing vulnerabilities is a critical step

297
00:09:15,780 --> 00:09:16,740
that we have to perform

298
00:09:16,740 --> 00:09:18,840
to strengthen our cybersecurity defenses.

299
00:09:18,840 --> 00:09:20,070
Confirming vulnerabilities

300
00:09:20,070 --> 00:09:21,600
involves determining the accuracy

301
00:09:21,600 --> 00:09:23,610
of an identified potential security weakness

302
00:09:23,610 --> 00:09:25,470
by verifying whether it's a true positive,

303
00:09:25,470 --> 00:09:26,340
false positive,

304
00:09:26,340 --> 00:09:28,260
true negative, or false negative.

305
00:09:28,260 --> 00:09:29,640
Prioritizing vulnerabilities

306
00:09:29,640 --> 00:09:32,190
entails assessing and ranking security vulnerabilities

307
00:09:32,190 --> 00:09:33,510
based on several factors,

308
00:09:33,510 --> 00:09:35,580
including their severity, potential impact,

309
00:09:35,580 --> 00:09:37,440
and likelihood of exploitation,

310
00:09:37,440 --> 00:09:40,080
so your organization can properly allocate resources

311
00:09:40,080 --> 00:09:42,600
to remediate your vulnerabilities more effectively.

312
00:09:42,600 --> 00:09:43,980
Classifying vulnerabilities

313
00:09:43,980 --> 00:09:45,090
means that we're going to categorize

314
00:09:45,090 --> 00:09:47,550
identified security weaknesses into different groups

315
00:09:47,550 --> 00:09:48,690
based on their characteristics,

316
00:09:48,690 --> 00:09:49,830
like the type of threat,

317
00:09:49,830 --> 00:09:50,700
the affected system,

318
00:09:50,700 --> 00:09:51,750
and the potential impact

319
00:09:51,750 --> 00:09:54,360
to streamline our management and response efforts.

320
00:09:54,360 --> 00:09:57,090
The exposure factor is going to refer to the percentage of loss

321
00:09:57,090 --> 00:09:58,650
that an organization will experience

322
00:09:58,650 --> 00:09:59,850
if a specific vulnerability

323
00:09:59,850 --> 00:10:01,950
was exploited on a given resource.

324
00:10:01,950 --> 00:10:03,630
And your organization's risk tolerance

325
00:10:03,630 --> 00:10:04,950
is going to refer to the level of risk

326
00:10:04,950 --> 00:10:07,620
that an organization is willing to accept or mitigate

327
00:10:07,620 --> 00:10:10,320
in pursuit of its objectives and operations.

328
00:10:10,320 --> 00:10:12,330
By systematically analyzing, confirming,

329
00:10:12,330 --> 00:10:14,580
classifying, and prioritizing vulnerabilities,

330
00:10:14,580 --> 00:10:16,140
understanding the exposure factor,

331
00:10:16,140 --> 00:10:17,430
and aligning these processes

332
00:10:17,430 --> 00:10:19,200
with the organization's risk tolerance,

333
00:10:19,200 --> 00:10:21,120
we're going to be better able to equip ourself

334
00:10:21,120 --> 00:10:22,740
to build a more secure, resilient,

335
00:10:22,740 --> 00:10:24,940
and responsive cybersecurity infrastructure.

