1
00:00:00,000 --> 00:00:00,960
In this lesson,

2
00:00:00,960 --> 00:00:03,480
we're going to discuss vulnerability reporting.

3
00:00:03,480 --> 00:00:05,880
Vulnerability reporting is the process of documenting

4
00:00:05,880 --> 00:00:08,400
and communicating details about security weaknesses

5
00:00:08,400 --> 00:00:10,770
that were identified in systems or software

6
00:00:10,770 --> 00:00:12,960
to the individuals or organizations that are responsible

7
00:00:12,960 --> 00:00:14,910
for addressing the issues to be able to ensure

8
00:00:14,910 --> 00:00:16,920
that these vulnerabilities are managed discreetly

9
00:00:16,920 --> 00:00:19,320
and effectively to prevent exploitation.

10
00:00:19,320 --> 00:00:20,610
Now, when it comes to reporting,

11
00:00:20,610 --> 00:00:23,130
it's important that these reports use clear, concise,

12
00:00:23,130 --> 00:00:24,390
and transparent language

13
00:00:24,390 --> 00:00:26,460
to ensure that the vulnerabilities can be well understood

14
00:00:26,460 --> 00:00:28,320
by all the key stakeholders.

15
00:00:28,320 --> 00:00:30,660
Now at the same time, we also need to ensure

16
00:00:30,660 --> 00:00:32,759
that communications and the reports themself

17
00:00:32,759 --> 00:00:35,700
remain confidential because they contain an exhaustive list

18
00:00:35,700 --> 00:00:36,960
of every known vulnerability

19
00:00:36,960 --> 00:00:38,910
inside of our enterprise networks.

20
00:00:38,910 --> 00:00:41,670
So as we focus on reporting vulnerabilities,

21
00:00:41,670 --> 00:00:43,950
we are going to be discussing internal reporting,

22
00:00:43,950 --> 00:00:45,000
external reporting,

23
00:00:45,000 --> 00:00:47,100
reporting as part of responsible disclosure,

24
00:00:47,100 --> 00:00:47,933
and the importance

25
00:00:47,933 --> 00:00:49,500
of keeping vulnerability reporting information

26
00:00:49,500 --> 00:00:51,960
confidential and safe from prying eyes.

27
00:00:51,960 --> 00:00:54,180
First, we have internal reporting.

28
00:00:54,180 --> 00:00:56,250
Internal reporting serves as the first line of defense

29
00:00:56,250 --> 00:00:58,410
in the vulnerability management process.

30
00:00:58,410 --> 00:01:00,690
Internal reporting involves the identification,

31
00:01:00,690 --> 00:01:02,610
documentation, and communication

32
00:01:02,610 --> 00:01:04,230
of your organization's vulnerabilities

33
00:01:04,230 --> 00:01:07,290
within the organizational structure of your organization.

34
00:01:07,290 --> 00:01:09,780
This kind of internal reporting may happen horizontally

35
00:01:09,780 --> 00:01:12,420
inside of your organization, where a cybersecurity analyst

36
00:01:12,420 --> 00:01:14,490
is providing the results of their vulnerability scans

37
00:01:14,490 --> 00:01:15,960
over to your system administrators

38
00:01:15,960 --> 00:01:18,360
so that those administrators can begin applying patches

39
00:01:18,360 --> 00:01:19,800
or reconfiguring your devices

40
00:01:19,800 --> 00:01:20,970
to remediate the vulnerabilities

41
00:01:20,970 --> 00:01:22,650
that were found by the analyst.

42
00:01:22,650 --> 00:01:25,410
Alternatively, you may also work in a vertical structure

43
00:01:25,410 --> 00:01:26,700
where you're creating a weekly report

44
00:01:26,700 --> 00:01:29,310
that's being sent upwards to your managers and executives

45
00:01:29,310 --> 00:01:31,260
so they can understand the current security posture

46
00:01:31,260 --> 00:01:32,910
of the organization's network.

47
00:01:32,910 --> 00:01:34,380
In either of these cases, though,

48
00:01:34,380 --> 00:01:36,030
the information needs to remain internal

49
00:01:36,030 --> 00:01:37,800
to your organization, and in this case,

50
00:01:37,800 --> 00:01:39,930
that makes it internal reporting.

51
00:01:39,930 --> 00:01:41,490
When you're making an internal report,

52
00:01:41,490 --> 00:01:43,020
it's important that your report provides

53
00:01:43,020 --> 00:01:44,100
the details and clarity

54
00:01:44,100 --> 00:01:45,930
about the vulnerabilities that were being discovered

55
00:01:45,930 --> 00:01:47,220
during your scans.

56
00:01:47,220 --> 00:01:48,900
Your report should also be timely

57
00:01:48,900 --> 00:01:51,000
because rapid reporting can drastically reduce

58
00:01:51,000 --> 00:01:51,833
the period of time

59
00:01:51,833 --> 00:01:53,550
that your organization is going to be exposed

60
00:01:53,550 --> 00:01:56,010
due to a known but unpatched vulnerability

61
00:01:56,010 --> 00:01:57,270
inside of your network.

62
00:01:57,270 --> 00:01:58,530
Now, another key concern

63
00:01:58,530 --> 00:02:00,030
when you're doing internal reporting

64
00:02:00,030 --> 00:02:01,440
is that you have properly established

65
00:02:01,440 --> 00:02:04,110
the communication paths and protocols that are going to be used

66
00:02:04,110 --> 00:02:05,790
when new vulnerabilities are discovered,

67
00:02:05,790 --> 00:02:07,950
and the results of a new vulnerability scan

68
00:02:07,950 --> 00:02:09,539
is going to be ready to be shared internally

69
00:02:09,539 --> 00:02:12,720
across the system administrators, managers, or executives

70
00:02:12,720 --> 00:02:14,940
through this new communication path.

71
00:02:14,940 --> 00:02:17,250
Second, we have external reporting.

72
00:02:17,250 --> 00:02:18,600
Now, external reporting occurs

73
00:02:18,600 --> 00:02:20,220
when you need to discuss your vulnerabilities

74
00:02:20,220 --> 00:02:22,680
outside of your own organization structure.

75
00:02:22,680 --> 00:02:25,050
External reporting is usually going to involve discussions

76
00:02:25,050 --> 00:02:26,520
with your vendors, your partners,

77
00:02:26,520 --> 00:02:28,650
your customers, or the public at large,

78
00:02:28,650 --> 00:02:30,180
depending on the specific vulnerability

79
00:02:30,180 --> 00:02:31,290
that we're talking about.

80
00:02:31,290 --> 00:02:32,460
Now, one of the most commonly used

81
00:02:32,460 --> 00:02:33,750
external reporting methods

82
00:02:33,750 --> 00:02:35,490
is to coordinate with your vendor.

83
00:02:35,490 --> 00:02:36,570
By engaging with the vendor

84
00:02:36,570 --> 00:02:38,610
of your vulnerable system or software first,

85
00:02:38,610 --> 00:02:40,170
you're giving them a chance to rectify

86
00:02:40,170 --> 00:02:43,050
and remediate the issue, not just for your organization,

87
00:02:43,050 --> 00:02:45,930
but for all customers who rely on this vendor's product.

88
00:02:45,930 --> 00:02:48,450
Another common form of external reporting and communication

89
00:02:48,450 --> 00:02:50,790
is going to occur when you share non-sensitive aspects

90
00:02:50,790 --> 00:02:54,000
of that vulnerability with databases like the CVE database

91
00:02:54,000 --> 00:02:56,690
or the vendor's own knowledge base or support forum

92
00:02:56,690 --> 00:02:57,523
to be able to increase

93
00:02:57,523 --> 00:02:58,800
the cybersecurity community's knowledge

94
00:02:58,800 --> 00:03:00,720
about this given vulnerability.

95
00:03:00,720 --> 00:03:03,300
Also, when you're conducting external reporting,

96
00:03:03,300 --> 00:03:05,400
it's important that you ensure that any sensitive details

97
00:03:05,400 --> 00:03:07,380
about your systems and the data they contain

98
00:03:07,380 --> 00:03:08,610
are not being disclosed

99
00:03:08,610 --> 00:03:10,560
if that could put other people at risk.

100
00:03:10,560 --> 00:03:12,480
For this reason, it's important to respect

101
00:03:12,480 --> 00:03:14,520
the privacy of your employees, your customers,

102
00:03:14,520 --> 00:03:16,140
and your vendors when you're discussing

103
00:03:16,140 --> 00:03:19,320
potential vulnerabilities with other external organizations.

104
00:03:19,320 --> 00:03:21,210
Third, we have to consider reporting

105
00:03:21,210 --> 00:03:23,130
in terms of responsible disclosures.

106
00:03:23,130 --> 00:03:24,660
Now, responsible disclosure reporting

107
00:03:24,660 --> 00:03:26,880
is the art of disclosing vulnerabilities ethically

108
00:03:26,880 --> 00:03:29,370
and judiciously to the affected stakeholders

109
00:03:29,370 --> 00:03:31,890
before making the announcement to the public at large.

110
00:03:31,890 --> 00:03:34,260
Responsible disclosures are focused on collaborating

111
00:03:34,260 --> 00:03:36,000
with the entity responsible for the vulnerability

112
00:03:36,000 --> 00:03:38,370
in the first place, such as a software developer,

113
00:03:38,370 --> 00:03:40,590
so that they can develop a hotfix or a security patch

114
00:03:40,590 --> 00:03:42,690
for the vulnerability that you discovered.

115
00:03:42,690 --> 00:03:45,300
This is often going to be done as part of a bug bounty program,

116
00:03:45,300 --> 00:03:47,550
which is a form of responsible disclosure.

117
00:03:47,550 --> 00:03:49,380
Additionally, when you work with the vendor,

118
00:03:49,380 --> 00:03:51,270
you should give them a grace period of a few weeks

119
00:03:51,270 --> 00:03:53,610
or even possibly a few months in order for them to be able

120
00:03:53,610 --> 00:03:56,070
to ensure that they can address the issue and deploy a patch

121
00:03:56,070 --> 00:03:58,170
before you make any kind of public announcement.

122
00:03:58,170 --> 00:04:00,480
Otherwise, a threat actor would hear your announcement,

123
00:04:00,480 --> 00:04:02,520
create an exploit to attack the vendor's customers

124
00:04:02,520 --> 00:04:03,353
who are now vulnerable

125
00:04:03,353 --> 00:04:04,620
to the new attack that you discovered,

126
00:04:04,620 --> 00:04:06,900
and this is going to cause all sorts of problems.

127
00:04:06,900 --> 00:04:08,820
When you're conducting responsible disclosure,

128
00:04:08,820 --> 00:04:11,010
you need to provide a detailed report to the vendor,

129
00:04:11,010 --> 00:04:13,290
including the method you use to exploit the vulnerability

130
00:04:13,290 --> 00:04:15,360
so they can reproduce your attack or exploit,

131
00:04:15,360 --> 00:04:16,920
the potential impact of the vulnerability

132
00:04:16,920 --> 00:04:17,910
if it was exploited,

133
00:04:17,910 --> 00:04:20,010
and any proposed mitigations that you would recommend

134
00:04:20,010 --> 00:04:21,899
until the vendor has time to release a patch

135
00:04:21,899 --> 00:04:23,130
for the vulnerability.

136
00:04:23,130 --> 00:04:25,710
For example, if I just discovered a new vulnerability

137
00:04:25,710 --> 00:04:27,960
in the Windows File and Printer Sharing service,

138
00:04:27,960 --> 00:04:29,970
I should first go ahead and notify Microsoft

139
00:04:29,970 --> 00:04:31,140
as part of their bug bounty

140
00:04:31,140 --> 00:04:33,150
or Responsible Disclosure Program.

141
00:04:33,150 --> 00:04:34,650
When I do that, I'm going to tell them

142
00:04:34,650 --> 00:04:37,380
about the vulnerability I discovered, what the impact is,

143
00:04:37,380 --> 00:04:39,450
and any proposed mitigations for it.

144
00:04:39,450 --> 00:04:41,910
So let's pretend that the vulnerability I discovered

145
00:04:41,910 --> 00:04:44,220
is only effective against version one and version two

146
00:04:44,220 --> 00:04:47,160
of the SMB protocol, but not version three.

147
00:04:47,160 --> 00:04:49,260
So in this case, the mitigation might be

148
00:04:49,260 --> 00:04:50,520
for Microsoft's customers

149
00:04:50,520 --> 00:04:53,970
to disable version one and version two of the SMB protocol.

150
00:04:53,970 --> 00:04:55,650
Or if this vulnerability was discovered

151
00:04:55,650 --> 00:04:57,840
to be a remote code execution vulnerability,

152
00:04:57,840 --> 00:05:00,510
we might make the recommendation that Port 445,

153
00:05:00,510 --> 00:05:02,010
which is used by SMB,

154
00:05:02,010 --> 00:05:03,990
is going to be blocked at the customer's firewall

155
00:05:03,990 --> 00:05:06,630
because that way if Port 445 is closed,

156
00:05:06,630 --> 00:05:08,610
only people internal to the organization

157
00:05:08,610 --> 00:05:09,780
will be able to use it

158
00:05:09,780 --> 00:05:11,580
and nobody from outside of the organization

159
00:05:11,580 --> 00:05:14,490
will be able to access the servers using Port 445.

160
00:05:14,490 --> 00:05:16,170
This will prevent an external threat actor

161
00:05:16,170 --> 00:05:17,400
from exploiting this vulnerability

162
00:05:17,400 --> 00:05:19,020
remotely over the Internet.

163
00:05:19,020 --> 00:05:20,640
These are just some examples of mitigations

164
00:05:20,640 --> 00:05:23,040
that could be used until the security patch to plug the hole

165
00:05:23,040 --> 00:05:24,450
would be released by Microsoft

166
00:05:24,450 --> 00:05:25,650
through the Windows Update service

167
00:05:25,650 --> 00:05:27,270
to all of their customers.

168
00:05:27,270 --> 00:05:29,640
Now, fourth and finally, we need to discuss the importance

169
00:05:29,640 --> 00:05:32,430
of confidentiality in our vulnerability reporting.

170
00:05:32,430 --> 00:05:34,230
Confidentiality in our vulnerability reports

171
00:05:34,230 --> 00:05:36,150
really is a non-negotiable matter

172
00:05:36,150 --> 00:05:38,160
because the details included in those reports

173
00:05:38,160 --> 00:05:40,560
are basically going to give the attacker everything they need

174
00:05:40,560 --> 00:05:41,520
in order to circumvent

175
00:05:41,520 --> 00:05:44,370
your organization's security appliances and defenses.

176
00:05:44,370 --> 00:05:45,660
Think about it like this.

177
00:05:45,660 --> 00:05:47,970
You just took the time to drop some blueprints of your home

178
00:05:47,970 --> 00:05:49,110
and then document exactly

179
00:05:49,110 --> 00:05:51,390
where all the valuables are in your home.

180
00:05:51,390 --> 00:05:52,290
In addition to that,

181
00:05:52,290 --> 00:05:54,360
you listed all the security cameras you have,

182
00:05:54,360 --> 00:05:56,040
which doors are locked and which ones aren't,

183
00:05:56,040 --> 00:05:57,900
which windows are open and which ones aren't,

184
00:05:57,900 --> 00:05:59,160
all that kind of stuff.

185
00:05:59,160 --> 00:06:00,090
Now as you're going to work,

186
00:06:00,090 --> 00:06:01,950
you accidentally drop that blueprint on the street,

187
00:06:01,950 --> 00:06:03,180
and I picked it up.

188
00:06:03,180 --> 00:06:04,080
Well, guess what?

189
00:06:04,080 --> 00:06:06,000
Now I know exactly how to break into your house

190
00:06:06,000 --> 00:06:08,550
and where all the valuables are located, right?

191
00:06:08,550 --> 00:06:11,250
Well, the same holds true with our vulnerability reports.

192
00:06:11,250 --> 00:06:13,140
After you conduct your vulnerability scans,

193
00:06:13,140 --> 00:06:14,340
the report is going to be generated,

194
00:06:14,340 --> 00:06:16,230
and it's going to contain a list of every vulnerability

195
00:06:16,230 --> 00:06:17,130
in your networks,

196
00:06:17,130 --> 00:06:19,500
as well as every misconfiguration it finds.

197
00:06:19,500 --> 00:06:21,690
In the hands of a threat actor, this is a map

198
00:06:21,690 --> 00:06:23,910
that will tell them exactly how to break into your networks

199
00:06:23,910 --> 00:06:26,280
and wreak havoc all across your systems.

200
00:06:26,280 --> 00:06:28,800
So when it comes to the confidentiality of your reports,

201
00:06:28,800 --> 00:06:29,850
you always want to make sure

202
00:06:29,850 --> 00:06:31,350
those reports are being encrypted,

203
00:06:31,350 --> 00:06:33,630
and you should use secure storage spaces online

204
00:06:33,630 --> 00:06:35,100
if you're going to give access to other people

205
00:06:35,100 --> 00:06:36,990
instead of just emailing it around.

206
00:06:36,990 --> 00:06:39,510
For example, I could create the report, encrypt it,

207
00:06:39,510 --> 00:06:41,520
and then upload it to a password-protected portion

208
00:06:41,520 --> 00:06:44,280
of our internal SharePoint or document repository,

209
00:06:44,280 --> 00:06:46,080
and then I can send that link by email

210
00:06:46,080 --> 00:06:47,910
to the people who need a copy of that report

211
00:06:47,910 --> 00:06:50,700
instead of emailing them the PDF of the report directly.

212
00:06:50,700 --> 00:06:52,700
This helps to ensure we have securely controlled access

213
00:06:52,700 --> 00:06:55,200
to the report instead of people forwarding that email

214
00:06:55,200 --> 00:06:57,960
internally or externally of our organization.

215
00:06:57,960 --> 00:07:00,060
Additionally, you also want to ensure that your report

216
00:07:00,060 --> 00:07:02,850
is only provided to those who have a need-to-know basis.

217
00:07:02,850 --> 00:07:04,620
Again, this is another reason why you want to put it

218
00:07:04,620 --> 00:07:06,270
on an internal SharePoint portal

219
00:07:06,270 --> 00:07:07,710
or other document repository

220
00:07:07,710 --> 00:07:09,540
that has access control rights.

221
00:07:09,540 --> 00:07:12,120
For example, an accountant who works at your organization

222
00:07:12,120 --> 00:07:13,830
probably doesn't need to see the detailed report

223
00:07:13,830 --> 00:07:16,650
of all your vulnerabilities, but your system administrators,

224
00:07:16,650 --> 00:07:17,483
they probably do

225
00:07:17,483 --> 00:07:19,470
because they're going to be patching those vulnerabilities,

226
00:07:19,470 --> 00:07:21,180
so they need to know they exist.

227
00:07:21,180 --> 00:07:23,910
On the other hand, your executives do have a vested interest

228
00:07:23,910 --> 00:07:24,743
and a need-to-know

229
00:07:24,743 --> 00:07:26,640
about the security posture of your network,

230
00:07:26,640 --> 00:07:27,840
but they probably don't need

231
00:07:27,840 --> 00:07:30,000
the fully detailed 300-page report

232
00:07:30,000 --> 00:07:32,220
of every vulnerability that exists in your network

233
00:07:32,220 --> 00:07:33,930
because they're not a system administrator

234
00:07:33,930 --> 00:07:35,460
and they're not going to be going line by line

235
00:07:35,460 --> 00:07:37,650
through the report to patch and mitigate them.

236
00:07:37,650 --> 00:07:39,990
Instead, these executives would rather have

237
00:07:39,990 --> 00:07:42,090
a three to five-page executive summary

238
00:07:42,090 --> 00:07:43,770
of your organization's vulnerabilities

239
00:07:43,770 --> 00:07:45,450
that contains much less details

240
00:07:45,450 --> 00:07:47,790
and can be shared to a slightly larger audience

241
00:07:47,790 --> 00:07:50,010
while still being much easier for them to understand

242
00:07:50,010 --> 00:07:52,410
because it relies on summarized information and graphs

243
00:07:52,410 --> 00:07:55,200
to highlight your organization's current security posture.

244
00:07:55,200 --> 00:07:57,150
Now, it is very important that your reporting

245
00:07:57,150 --> 00:07:59,340
remains confidential, otherwise,

246
00:07:59,340 --> 00:08:01,440
exploitation, reputational damage

247
00:08:01,440 --> 00:08:02,760
and even legal repercussions

248
00:08:02,760 --> 00:08:04,560
could occur for your organization.

249
00:08:04,560 --> 00:08:06,900
After all, a malicious actor could use the report

250
00:08:06,900 --> 00:08:08,640
to exploit your disclosed vulnerabilities

251
00:08:08,640 --> 00:08:10,560
before they're patched by your system administrators,

252
00:08:10,560 --> 00:08:12,900
so we want to make sure we keep those unknown.

253
00:08:12,900 --> 00:08:15,360
If your vulnerability report gets posted on social media,

254
00:08:15,360 --> 00:08:17,700
for example, this would actually damage your reputation

255
00:08:17,700 --> 00:08:19,050
and have the public lose confidence

256
00:08:19,050 --> 00:08:20,490
in your organization's ability

257
00:08:20,490 --> 00:08:22,710
to securely protect its customers' data.

258
00:08:22,710 --> 00:08:24,870
Finally, if that report does get out,

259
00:08:24,870 --> 00:08:26,760
you may be subject to legal repercussions

260
00:08:26,760 --> 00:08:29,310
due to your existing contracts, industry regulations,

261
00:08:29,310 --> 00:08:31,350
or simply being sued by one of your customers

262
00:08:31,350 --> 00:08:32,850
if their data is getting exposed

263
00:08:32,850 --> 00:08:35,760
due to your negligence release of that vulnerability report,

264
00:08:35,760 --> 00:08:37,890
especially if you're working as an external auditor

265
00:08:37,890 --> 00:08:40,409
or a cybersecurity consultant for that customer.

266
00:08:40,409 --> 00:08:43,320
So remember, vulnerability reporting is the last step,

267
00:08:43,320 --> 00:08:45,330
but a really important step inside

268
00:08:45,330 --> 00:08:48,000
of the organization's vulnerability management program.

269
00:08:48,000 --> 00:08:50,490
Vulnerability reporting is the process of documenting

270
00:08:50,490 --> 00:08:52,860
and communicating details about security weaknesses

271
00:08:52,860 --> 00:08:54,720
identified in software systems

272
00:08:54,720 --> 00:08:56,760
to the individuals or organizations responsible

273
00:08:56,760 --> 00:08:57,960
for addressing the issue

274
00:08:57,960 --> 00:08:59,190
to ensure that these vulnerabilities

275
00:08:59,190 --> 00:09:00,960
are managed discreetly and effectively

276
00:09:00,960 --> 00:09:02,640
to prevent exploitation.

277
00:09:02,640 --> 00:09:04,110
This vulnerability reporting

278
00:09:04,110 --> 00:09:06,060
can be performed internally or externally,

279
00:09:06,060 --> 00:09:09,030
as well as part of a Responsible Disclosure Program.

280
00:09:09,030 --> 00:09:09,990
Either way, though,

281
00:09:09,990 --> 00:09:12,510
your vulnerability reports must be kept encrypted

282
00:09:12,510 --> 00:09:14,070
to maintain their confidentiality,

283
00:09:14,070 --> 00:09:15,690
and they should only be shared with other people

284
00:09:15,690 --> 00:09:16,680
who have a need-to-know

285
00:09:16,680 --> 00:09:19,020
in terms of your organization's existing vulnerabilities

286
00:09:19,020 --> 00:09:20,493
and current security posture.

