1
00:00:00,000 --> 00:00:00,960
In this lesson,

2
00:00:00,960 --> 00:00:02,670
we're going to cover vulnerability response

3
00:00:02,670 --> 00:00:04,350
and remediation options.

4
00:00:04,350 --> 00:00:06,120
Vulnerability response and remediation

5
00:00:06,120 --> 00:00:09,000
refers to the strategies and actions taken to identify,

6
00:00:09,000 --> 00:00:11,910
assess, and address vulnerabilities in a system or network

7
00:00:11,910 --> 00:00:13,500
by aiming to mitigate risks associated

8
00:00:13,500 --> 00:00:14,940
with those known vulnerabilities

9
00:00:14,940 --> 00:00:15,773
so that you can strengthen

10
00:00:15,773 --> 00:00:17,670
your organization's security posture.

11
00:00:17,670 --> 00:00:20,430
When a vulnerability is identified within an organization,

12
00:00:20,430 --> 00:00:22,170
it's imperative to respond effectively

13
00:00:22,170 --> 00:00:24,840
and efficiently to mitigate or completely neutralize

14
00:00:24,840 --> 00:00:25,890
that threat.

15
00:00:25,890 --> 00:00:28,260
The process of vulnerability response and remediation

16
00:00:28,260 --> 00:00:31,020
is going to encompass a range of options including patching,

17
00:00:31,020 --> 00:00:33,120
insurance, network segmentation,

18
00:00:33,120 --> 00:00:34,710
implementing compensating controls,

19
00:00:34,710 --> 00:00:36,900
and granting exceptions and exemptions.

20
00:00:36,900 --> 00:00:38,580
Now, let's take a look at each of these options

21
00:00:38,580 --> 00:00:40,230
and how they contribute to an organization's

22
00:00:40,230 --> 00:00:42,360
overall cybersecurity strategy.

23
00:00:42,360 --> 00:00:44,430
Now, our first option for response and remediation

24
00:00:44,430 --> 00:00:45,930
is the use of patching.

25
00:00:45,930 --> 00:00:48,030
Patching refers to the process of applying updates

26
00:00:48,030 --> 00:00:50,040
to software, systems or applications

27
00:00:50,040 --> 00:00:51,870
in order to fix security vulnerabilities

28
00:00:51,870 --> 00:00:53,490
or to improve performance.

29
00:00:53,490 --> 00:00:55,650
Patches are typically released by software vendors

30
00:00:55,650 --> 00:00:57,810
to fix known vulnerabilities that could be exploited

31
00:00:57,810 --> 00:00:59,010
by a threat actor.

32
00:00:59,010 --> 00:01:01,170
For example, if a software company has identified

33
00:01:01,170 --> 00:01:03,840
a vulnerability in its word processing software application

34
00:01:03,840 --> 00:01:05,940
that would allow a threat actor to gain unauthorized access

35
00:01:05,940 --> 00:01:08,820
to your sensitive data, that company should quickly develop

36
00:01:08,820 --> 00:01:10,650
and release a security patch or hotfix

37
00:01:10,650 --> 00:01:12,900
to mitigate this known vulnerability.

38
00:01:12,900 --> 00:01:14,340
Now that the patch is released,

39
00:01:14,340 --> 00:01:16,590
it's going to be up to our end users to update their software

40
00:01:16,590 --> 00:01:19,350
to the latest version that includes this new security patch,

41
00:01:19,350 --> 00:01:21,810
so that vulnerability in their system can be mitigated

42
00:01:21,810 --> 00:01:23,220
and that the threat actor can no longer

43
00:01:23,220 --> 00:01:24,690
exploit their system.

44
00:01:24,690 --> 00:01:27,060
The second option we have for response to remediation

45
00:01:27,060 --> 00:01:29,100
is to purchase an insurance policy.

46
00:01:29,100 --> 00:01:31,890
Now, purchasing a cybersecurity risk insurance policy

47
00:01:31,890 --> 00:01:33,570
is going to be a risk management strategy

48
00:01:33,570 --> 00:01:36,240
where an organization is going to procure an insurance policy

49
00:01:36,240 --> 00:01:38,370
that is designed to mitigate any financial losses

50
00:01:38,370 --> 00:01:41,130
that could result from a cyber incident like a data breach,

51
00:01:41,130 --> 00:01:43,380
network outage, or business interruption.

52
00:01:43,380 --> 00:01:45,240
For example, if you're working for a small

53
00:01:45,240 --> 00:01:47,370
e-commerce company, you might opt to purchase

54
00:01:47,370 --> 00:01:49,020
a cybersecurity insurance policy.

55
00:01:49,020 --> 00:01:51,390
So that if the company does suffer from a data breach,

56
00:01:51,390 --> 00:01:54,120
the insurance policy will cover the costs for mitigation,

57
00:01:54,120 --> 00:01:56,220
remediation, and recovery that are associated

58
00:01:56,220 --> 00:01:57,150
with that incident.

59
00:01:57,150 --> 00:01:59,910
And this includes things like legal fees, new servers,

60
00:01:59,910 --> 00:02:02,640
new software, consultants, public relation efforts

61
00:02:02,640 --> 00:02:03,960
to rebuild your company's image,

62
00:02:03,960 --> 00:02:06,360
and all the costs associated with notifying your customers

63
00:02:06,360 --> 00:02:08,310
that were affected by that incident.

64
00:02:08,310 --> 00:02:10,440
Our third option for response and remediation

65
00:02:10,440 --> 00:02:12,060
is known as segmentation.

66
00:02:12,060 --> 00:02:14,730
Network segmentation involves dividing a computer network

67
00:02:14,730 --> 00:02:17,460
into smaller parts or segments to improve performance

68
00:02:17,460 --> 00:02:19,320
and security by isolating different parts

69
00:02:19,320 --> 00:02:20,820
of the network from each other.

70
00:02:20,820 --> 00:02:23,400
This way, if one segment becomes compromised,

71
00:02:23,400 --> 00:02:25,800
the threat will not be allowed to easily propagate itself

72
00:02:25,800 --> 00:02:28,620
into other parts of your organization's network as well.

73
00:02:28,620 --> 00:02:31,710
For example, a hospital might implement network segmentation

74
00:02:31,710 --> 00:02:34,680
to separate patient data from other non-critical systems.

75
00:02:34,680 --> 00:02:36,960
This way, if a malware infection occurs in one

76
00:02:36,960 --> 00:02:39,270
of the non-critical systems, the segmented network

77
00:02:39,270 --> 00:02:42,030
that's hosting that sensitive patient data will be kept safe

78
00:02:42,030 --> 00:02:43,650
from the malware that already infected

79
00:02:43,650 --> 00:02:46,770
our non-critical systems in that other network segment.

80
00:02:46,770 --> 00:02:48,960
Our fourth option for response and remediation

81
00:02:48,960 --> 00:02:51,090
is known as compensating controls.

82
00:02:51,090 --> 00:02:53,490
Compensating controls are alternative security measures

83
00:02:53,490 --> 00:02:55,890
that can be implemented when a standard security control

84
00:02:55,890 --> 00:02:58,170
cannot feasibly or effectively be implemented

85
00:02:58,170 --> 00:02:59,520
on a given system.

86
00:02:59,520 --> 00:03:01,500
These compensating controls are tailored

87
00:03:01,500 --> 00:03:03,270
to provide equivalent levels of protection

88
00:03:03,270 --> 00:03:05,280
when you're mitigating your vulnerabilities.

89
00:03:05,280 --> 00:03:07,920
For example, let's say that your organization's leadership

90
00:03:07,920 --> 00:03:10,200
decide that we're all going to use multi-factor authentication

91
00:03:10,200 --> 00:03:12,120
on all of our systems because it's considered

92
00:03:12,120 --> 00:03:14,550
the best practice for securing your user accounts.

93
00:03:14,550 --> 00:03:17,100
The problem with this is that we can't implement MFA

94
00:03:17,100 --> 00:03:18,780
on all of our servers because some of them

95
00:03:18,780 --> 00:03:22,290
are running older legacy versions of the server software.

96
00:03:22,290 --> 00:03:23,970
Now, until those servers can be replaced

97
00:03:23,970 --> 00:03:26,730
or upgrade to more modern versions of the server software,

98
00:03:26,730 --> 00:03:28,500
our company is going to have to use a series

99
00:03:28,500 --> 00:03:29,730
of compensating controls,

100
00:03:29,730 --> 00:03:31,440
such as rigorous password policies,

101
00:03:31,440 --> 00:03:33,660
account lockouts after failed login attempts,

102
00:03:33,660 --> 00:03:36,090
and regular security awareness training for our employees

103
00:03:36,090 --> 00:03:38,550
to mitigate the fact that multi-factor authentication

104
00:03:38,550 --> 00:03:41,100
simply cannot be installed on those legacy servers

105
00:03:41,100 --> 00:03:42,510
at this time.

106
00:03:42,510 --> 00:03:44,760
Now, our fifth option for response and remediation

107
00:03:44,760 --> 00:03:47,160
is to create an exception or an exemption.

108
00:03:47,160 --> 00:03:49,110
An exception in the world of vulnerability response

109
00:03:49,110 --> 00:03:51,480
refers to a situation where a certain security control

110
00:03:51,480 --> 00:03:54,780
or policy is going to be temporarily relaxed or bypassed

111
00:03:54,780 --> 00:03:57,090
because your operational business needs it to be.

112
00:03:57,090 --> 00:03:58,860
Now, when you do this, you have to understand

113
00:03:58,860 --> 00:04:01,680
and accept the associated risk of bypassing those controls.

114
00:04:01,680 --> 00:04:04,110
But when you do, this creates an exception.

115
00:04:04,110 --> 00:04:06,420
Now, for example, if an organization has a policy

116
00:04:06,420 --> 00:04:08,970
that requires all of your systems to be updated regularly,

117
00:04:08,970 --> 00:04:11,670
but you have a critical server running a legacy application

118
00:04:11,670 --> 00:04:13,710
that simply cannot be updated without breaking

119
00:04:13,710 --> 00:04:15,690
that application, well, in this case,

120
00:04:15,690 --> 00:04:17,160
you need to use an exception,

121
00:04:17,160 --> 00:04:19,230
and that exception could be made so that this server

122
00:04:19,230 --> 00:04:21,839
is being acknowledged for the risk of not being updated,

123
00:04:21,839 --> 00:04:23,700
and the rational and timeframe for that exception

124
00:04:23,700 --> 00:04:26,400
will also be documented like the scope of the exception

125
00:04:26,400 --> 00:04:28,440
and the date by which the exception will expire,

126
00:04:28,440 --> 00:04:30,450
and that server has to be replaced or upgraded

127
00:04:30,450 --> 00:04:31,890
to a more secure version,

128
00:04:31,890 --> 00:04:33,720
or be completely removed from the network

129
00:04:33,720 --> 00:04:35,280
for non-compliance.

130
00:04:35,280 --> 00:04:36,960
Now, an exemption on the other hand,

131
00:04:36,960 --> 00:04:39,300
is an instance where a security control or policy

132
00:04:39,300 --> 00:04:41,970
is permanently going to be waived for a specific reason

133
00:04:41,970 --> 00:04:43,980
such as when you're trying to use a legacy system

134
00:04:43,980 --> 00:04:46,320
that simply cannot use a modern security measure

135
00:04:46,320 --> 00:04:47,910
as one of its controls.

136
00:04:47,910 --> 00:04:49,770
For example, if you're working for a large

137
00:04:49,770 --> 00:04:51,330
university's research department

138
00:04:51,330 --> 00:04:53,400
and they have an older computer system that's necessary

139
00:04:53,400 --> 00:04:55,050
for processing historical data

140
00:04:55,050 --> 00:04:57,030
and it can't run the updated security software

141
00:04:57,030 --> 00:04:59,070
that you want to install, your university's

142
00:04:59,070 --> 00:05:01,620
chief information security officer might decide to grant

143
00:05:01,620 --> 00:05:04,410
a permanent exemption for that system so it doesn't have

144
00:05:04,410 --> 00:05:06,060
to be updated anymore in the future.

145
00:05:06,060 --> 00:05:07,770
Because this system will be physically

146
00:05:07,770 --> 00:05:09,360
and logically isolated from the rest

147
00:05:09,360 --> 00:05:10,530
of the university's network.

148
00:05:10,530 --> 00:05:12,030
And this mitigates the potential risk

149
00:05:12,030 --> 00:05:13,860
associated with making this exemption.

150
00:05:13,860 --> 00:05:15,930
And because the system is so expensive,

151
00:05:15,930 --> 00:05:17,370
it's going to take us years to replace

152
00:05:17,370 --> 00:05:19,320
because we can't afford to buy a new supercomputer,

153
00:05:19,320 --> 00:05:20,850
for example, and so we're going to have to use

154
00:05:20,850 --> 00:05:23,130
an exception instead of completely avoiding this risk

155
00:05:23,130 --> 00:05:24,720
by updating that server.

156
00:05:24,720 --> 00:05:26,670
So remember, vulnerability response

157
00:05:26,670 --> 00:05:28,530
and remediation refers to the strategies

158
00:05:28,530 --> 00:05:30,240
and actions that are taken to identify,

159
00:05:30,240 --> 00:05:33,270
assess, and address vulnerabilities in a system or network

160
00:05:33,270 --> 00:05:35,250
by aiming to mitigate risks associated with those

161
00:05:35,250 --> 00:05:37,110
known vulnerabilities so that you can strengthen

162
00:05:37,110 --> 00:05:39,120
your organization's security posture.

163
00:05:39,120 --> 00:05:40,920
Whether it's quickly applying patches,

164
00:05:40,920 --> 00:05:42,660
investing in an insurance policy,

165
00:05:42,660 --> 00:05:44,370
utilizing network segmentation,

166
00:05:44,370 --> 00:05:45,900
implementing compensating controls,

167
00:05:45,900 --> 00:05:48,030
or granting exceptions and exemptions,

168
00:05:48,030 --> 00:05:50,280
each type will offer us a different way to enhance

169
00:05:50,280 --> 00:05:52,410
the organization's cybersecurity posture.

170
00:05:52,410 --> 00:05:55,110
By understanding and effectively leveraging these options,

171
00:05:55,110 --> 00:05:57,360
your organization can fortify its defenses

172
00:05:57,360 --> 00:06:00,030
and navigate the complex landscape of cybersecurity threats

173
00:06:00,030 --> 00:06:02,253
with more confidence and more resilience.

