1
00:00:06,510 --> 00:00:07,650
- Welcome to lesson one,

2
00:00:07,650 --> 00:00:11,100
Compare and Contrast Various
Types of Security Controls.

3
00:00:11,100 --> 00:00:15,600
In our first lesson,
1.1 Control Objectives,

4
00:00:15,600 --> 00:00:18,570
we are gonna focus 100% on controls.

5
00:00:18,570 --> 00:00:19,403
Why?

6
00:00:19,403 --> 00:00:21,210
Because as a cybersecurity practitioner,

7
00:00:21,210 --> 00:00:22,860
you're gonna be all about controls.

8
00:00:22,860 --> 00:00:24,570
You are gonna be implementing controls,

9
00:00:24,570 --> 00:00:26,940
and managing controls,
and monitoring controls.

10
00:00:26,940 --> 00:00:28,620
You'll be selecting controls.

11
00:00:28,620 --> 00:00:30,720
You will be advising others on controls,

12
00:00:30,720 --> 00:00:32,850
and you'll be educating on controls.

13
00:00:32,850 --> 00:00:33,930
So it's really important

14
00:00:33,930 --> 00:00:36,060
that you have a good grounded foundation

15
00:00:36,060 --> 00:00:38,250
in understanding how we use controls,

16
00:00:38,250 --> 00:00:39,420
why we use controls,

17
00:00:39,420 --> 00:00:41,280
what do we expect of our controls,

18
00:00:41,280 --> 00:00:44,700
as well as different control
categories and classifications.

19
00:00:44,700 --> 00:00:46,170
So let's get started.

20
00:00:46,170 --> 00:00:48,330
Before we start talking
about controls though,

21
00:00:48,330 --> 00:00:50,640
I just wanna go through a couple of terms

22
00:00:50,640 --> 00:00:52,950
some cyber basic terms
that we're gonna use

23
00:00:52,950 --> 00:00:54,360
all the way through this course,

24
00:00:54,360 --> 00:00:56,190
just to make sure that we're defining them

25
00:00:56,190 --> 00:00:57,663
in the same way, you and I.

26
00:00:58,590 --> 00:01:00,840
So starting with the
first one, vulnerability.

27
00:01:00,840 --> 00:01:03,630
A vulnerability is a weakness.

28
00:01:03,630 --> 00:01:05,400
Now, it could be a weakness in a person,

29
00:01:05,400 --> 00:01:07,950
in an infrastructure, in building,

30
00:01:07,950 --> 00:01:10,770
in software, in hardware, in a device,

31
00:01:10,770 --> 00:01:15,150
but very simply, it just
refers to a weakness.

32
00:01:15,150 --> 00:01:18,000
A threat is a potential danger,

33
00:01:18,000 --> 00:01:19,410
something that wants to harm us.

34
00:01:19,410 --> 00:01:22,020
Now, threats can be adversarial
and non-adversarial.

35
00:01:22,020 --> 00:01:24,150
Adversarial means that
we have an adversary

36
00:01:24,150 --> 00:01:25,980
who's targeting that threat.

37
00:01:25,980 --> 00:01:28,980
Non adversarial means it's
not really targeted at us.

38
00:01:28,980 --> 00:01:32,190
For example, a flood or a power outage

39
00:01:32,190 --> 00:01:33,840
or some type of weather event.

40
00:01:33,840 --> 00:01:35,913
Still a danger, but not adversarial.

41
00:01:36,990 --> 00:01:38,790
Third is a threat actor.

42
00:01:38,790 --> 00:01:40,650
A threat actor is an adversary,

43
00:01:40,650 --> 00:01:45,240
an adversary meaning an opponent
that has malicious intent.

44
00:01:45,240 --> 00:01:47,670
And lastly, is an exploit.

45
00:01:47,670 --> 00:01:49,860
An exploit is when that threat actor

46
00:01:49,860 --> 00:01:53,070
successfully takes advantage
of the vulnerability

47
00:01:53,070 --> 00:01:54,390
or of that weakness.

48
00:01:54,390 --> 00:01:55,507
So the threat actor says,

49
00:01:55,507 --> 00:01:57,240
"Okay, I know that weakness is there."

50
00:01:57,240 --> 00:01:59,520
I'm gonna take advantage of that weakness

51
00:01:59,520 --> 00:02:00,570
over that vulnerability,

52
00:02:00,570 --> 00:02:03,480
and that becomes our exploit.

53
00:02:03,480 --> 00:02:07,380
So, vulnerability, threat,
threat actor, and exploit,

54
00:02:07,380 --> 00:02:09,680
terms we're gonna use
all through this course.

55
00:02:11,310 --> 00:02:13,200
So let's start talking about controls.

56
00:02:13,200 --> 00:02:15,840
We're gonna define controls as tactics,

57
00:02:15,840 --> 00:02:17,910
mechanisms, or strategies

58
00:02:17,910 --> 00:02:19,950
that proactively minimize risk

59
00:02:19,950 --> 00:02:21,930
in one or more of the following ways.

60
00:02:21,930 --> 00:02:23,670
Now, before I share those ways with you,

61
00:02:23,670 --> 00:02:25,680
let's just dissect this
sentence a little bit.

62
00:02:25,680 --> 00:02:27,990
Proactively means we're
doing it ahead of time,

63
00:02:27,990 --> 00:02:29,670
minimize means we're gonna diminish,

64
00:02:29,670 --> 00:02:32,760
and risk just refers to
a level of uncertainty.

65
00:02:32,760 --> 00:02:35,850
So our controls or tactics,
mechanisms, or strategies

66
00:02:35,850 --> 00:02:39,870
that, ahead of time, bring
down the level of uncertainty

67
00:02:39,870 --> 00:02:42,510
in one or more of the following ways.

68
00:02:42,510 --> 00:02:46,020
It will either reduce or
eliminate a vulnerability,

69
00:02:46,020 --> 00:02:47,790
reduce or eliminate the likelihood

70
00:02:47,790 --> 00:02:49,230
that a threat actor will be able

71
00:02:49,230 --> 00:02:51,090
to exploit the vulnerability

72
00:02:51,090 --> 00:02:54,660
or reduce or eliminate
the impact of an exploit.

73
00:02:54,660 --> 00:02:56,160
Now, a control can do one of these,

74
00:02:56,160 --> 00:02:57,930
two of these, or all three,

75
00:02:57,930 --> 00:03:01,443
but it has to do at least one
to be considered a control.

76
00:03:02,940 --> 00:03:04,740
Now, you may have heard
the term countermeasure

77
00:03:04,740 --> 00:03:07,740
because very often it's used
interchangeably with control,

78
00:03:07,740 --> 00:03:09,630
but it doesn't mean the same thing.

79
00:03:09,630 --> 00:03:12,030
Countermeasures are controls
that are implemented

80
00:03:12,030 --> 00:03:14,820
to address a specific threat.

81
00:03:14,820 --> 00:03:17,700
So where our controls
were fairly broad based

82
00:03:17,700 --> 00:03:19,080
and they were proactive,

83
00:03:19,080 --> 00:03:21,450
countermeasures are generally reactive

84
00:03:21,450 --> 00:03:24,810
and they may be more effective
for that specific threat,

85
00:03:24,810 --> 00:03:27,000
but they're less broadly efficient.

86
00:03:27,000 --> 00:03:29,010
So let me give you an
example of a countermeasure.

87
00:03:29,010 --> 00:03:30,510
Perhaps in your threat intelligence,

88
00:03:30,510 --> 00:03:33,420
you learn that a particular IP address

89
00:03:33,420 --> 00:03:36,780
is distributing malicious
software or malware.

90
00:03:36,780 --> 00:03:37,980
So you block that.

91
00:03:37,980 --> 00:03:39,240
You set up a firewall rule

92
00:03:39,240 --> 00:03:41,610
to block access to that IP address.

93
00:03:41,610 --> 00:03:45,120
That would be a countermeasure
specific for that threat,

94
00:03:45,120 --> 00:03:46,920
very efficient for that threat,

95
00:03:46,920 --> 00:03:49,263
but doesn't really have
a broad application.

96
00:03:51,570 --> 00:03:55,017
And we wanna know that our controls work

97
00:03:55,017 --> 00:03:57,210
and they do what we expect them to do.

98
00:03:57,210 --> 00:03:59,610
And we summarize that as
thinking about the fact

99
00:03:59,610 --> 00:04:02,220
that our controls should be trustworthy.

100
00:04:02,220 --> 00:04:03,870
So when we're evaluating a control,

101
00:04:03,870 --> 00:04:05,820
there's a couple things we wanna look at.

102
00:04:05,820 --> 00:04:07,440
First is functionality

103
00:04:07,440 --> 00:04:10,380
and functionality is what a control does.

104
00:04:10,380 --> 00:04:12,540
And second is effectiveness.

105
00:04:12,540 --> 00:04:15,840
Effectiveness is how well a control works.

106
00:04:15,840 --> 00:04:18,960
Now, effectiveness reflects
the control's consistent,

107
00:04:18,960 --> 00:04:22,680
complete, reliable, and timely operation.

108
00:04:22,680 --> 00:04:24,840
So when we are assessing our controls,

109
00:04:24,840 --> 00:04:26,910
we're looking at both the functionality

110
00:04:26,910 --> 00:04:28,230
and the effectiveness.

111
00:04:28,230 --> 00:04:30,900
And the process of
assessing those controls

112
00:04:30,900 --> 00:04:32,730
is referred to as assurance.

113
00:04:32,730 --> 00:04:34,980
Assurance is a measure of confidence

114
00:04:34,980 --> 00:04:36,960
that the intended security controls

115
00:04:36,960 --> 00:04:39,543
are effective in their application.

116
00:04:41,970 --> 00:04:44,160
A control objective is a statement

117
00:04:44,160 --> 00:04:46,860
of desired result or
purpose to be achieved

118
00:04:46,860 --> 00:04:49,200
by implementing either a single control

119
00:04:49,200 --> 00:04:51,870
or more likely a set of controls.

120
00:04:51,870 --> 00:04:53,640
And so a control objective is,

121
00:04:53,640 --> 00:04:55,020
what am I trying to achieve

122
00:04:55,020 --> 00:04:57,090
or what am I trying to accomplish?

123
00:04:57,090 --> 00:04:58,770
Let me give you an example.

124
00:04:58,770 --> 00:05:00,307
I might have a control
objective that says,

125
00:05:00,307 --> 00:05:02,970
"I wanna protect my hosts or my endpoints

126
00:05:02,970 --> 00:05:05,160
from malware infiltration."

127
00:05:05,160 --> 00:05:06,660
How am I gonna do that?

128
00:05:06,660 --> 00:05:08,460
Well, you and I know we're not gonna do it

129
00:05:08,460 --> 00:05:09,750
with just one control.

130
00:05:09,750 --> 00:05:12,510
And so maybe there's a
whole series of controls.

131
00:05:12,510 --> 00:05:14,760
They may be related or unrelated,

132
00:05:14,760 --> 00:05:17,580
antivirus software, a host firewall,

133
00:05:17,580 --> 00:05:22,290
restricted email attachments,
URL filtering, sandboxing.

134
00:05:22,290 --> 00:05:25,410
All of those are individual,
discreet controls

135
00:05:25,410 --> 00:05:28,020
that we use to achieve
our control objective,

136
00:05:28,020 --> 00:05:31,443
in this case, to protect hosts
from malware infiltration.

137
00:05:34,110 --> 00:05:35,640
And we really wanna make sure

138
00:05:35,640 --> 00:05:37,620
that we have security control diversity,

139
00:05:37,620 --> 00:05:40,740
that we're not depending
upon just one control

140
00:05:40,740 --> 00:05:43,890
or just the same type of
control over and over again.

141
00:05:43,890 --> 00:05:44,970
So defense-in-depth,

142
00:05:44,970 --> 00:05:47,790
also known as layered
security or layered controls,

143
00:05:47,790 --> 00:05:49,920
is the design and implementation

144
00:05:49,920 --> 00:05:53,460
of multiple overlapping
layers of diverse control.

145
00:05:53,460 --> 00:05:55,080
So if one control fails,

146
00:05:55,080 --> 00:05:58,080
hopefully, the next control is successful.

147
00:05:58,080 --> 00:06:01,140
Now, control should not be
subject to a cascade effect

148
00:06:01,140 --> 00:06:04,200
and should always, always
maintain their independence.

149
00:06:04,200 --> 00:06:06,150
What do we mean by a cascade effect?

150
00:06:06,150 --> 00:06:09,150
Well, think about a bunch of
dominoes all set up in a row.

151
00:06:09,150 --> 00:06:11,160
And if you tip one over, boom,
boom, boom, boom, boom, boom

152
00:06:11,160 --> 00:06:12,540
all the dominoes fall over.

153
00:06:12,540 --> 00:06:14,400
That would be a cascade effect.

154
00:06:14,400 --> 00:06:16,320
We wanna make sure that
that doesn't happen,

155
00:06:16,320 --> 00:06:19,560
and that our controls remain
independent of each other,

156
00:06:19,560 --> 00:06:22,080
and that we wanna have
different types of controls,

157
00:06:22,080 --> 00:06:24,270
referred to as a diversity of controls,

158
00:06:24,270 --> 00:06:26,370
and we wanna use more than one vendor.

159
00:06:26,370 --> 00:06:28,560
So we wanna have diversity of controls

160
00:06:28,560 --> 00:06:30,453
and diversity of vendors.

161
00:06:33,180 --> 00:06:35,100
Now we use security control baselines

162
00:06:35,100 --> 00:06:38,823
to express the minimum standards
for a given environment.

163
00:06:38,823 --> 00:06:41,820
Now, you can develop your own
security control baselines

164
00:06:41,820 --> 00:06:44,490
or you do what most of us actually do,

165
00:06:44,490 --> 00:06:47,520
is go out and research the
security control baselines

166
00:06:47,520 --> 00:06:48,870
that are already available to us

167
00:06:48,870 --> 00:06:50,700
because there is so much work

168
00:06:50,700 --> 00:06:53,130
that's already been done in this area,

169
00:06:53,130 --> 00:06:55,380
and we're gonna talk about
some of those in just a sec,

170
00:06:55,380 --> 00:06:58,350
but let's talk a little bit
more about what a baseline does.

171
00:06:58,350 --> 00:07:00,750
Again, the baseline
expresses minimum standards

172
00:07:00,750 --> 00:07:02,700
for a given environment.

173
00:07:02,700 --> 00:07:04,890
But when you adopt a baseline,

174
00:07:04,890 --> 00:07:07,860
they should always serve
as a starting point

175
00:07:07,860 --> 00:07:08,970
and you need to make sure

176
00:07:08,970 --> 00:07:10,470
that they are strategically aligned

177
00:07:10,470 --> 00:07:12,330
with the needs of the organization,

178
00:07:12,330 --> 00:07:15,240
which is something you're gonna
hear me say a ton of times.

179
00:07:15,240 --> 00:07:18,180
We never want to adopt a control baseline,

180
00:07:18,180 --> 00:07:20,377
or a policy, or a new tool just 'cause,

181
00:07:20,377 --> 00:07:22,350
"Ooh, that sounds cool and interesting."

182
00:07:22,350 --> 00:07:23,490
Uh-uh never.

183
00:07:23,490 --> 00:07:26,400
We always wanna make sure that
whatever action we're taking,

184
00:07:26,400 --> 00:07:28,410
it is always in support
of the organization

185
00:07:28,410 --> 00:07:30,750
and it strategically aligns

186
00:07:30,750 --> 00:07:33,930
with the needs and the
strategy of the organization.

187
00:07:33,930 --> 00:07:35,910
And control baseline should also be

188
00:07:35,910 --> 00:07:37,530
proportionate to the criticality

189
00:07:37,530 --> 00:07:39,720
and the sensitivity classifications

190
00:07:39,720 --> 00:07:41,670
of the asset being protected.

191
00:07:41,670 --> 00:07:45,363
And we refer to that as the
principle of proportionality.

192
00:07:46,740 --> 00:07:49,380
There's some excellent
control guidance out there.

193
00:07:49,380 --> 00:07:52,110
NIST is the National Institute
of Standards and Technology.

194
00:07:52,110 --> 00:07:53,730
It's a US government agency,

195
00:07:53,730 --> 00:07:58,680
and they have just a compendium
of information and documents

196
00:07:58,680 --> 00:08:01,110
and standards available to you for free.

197
00:08:01,110 --> 00:08:03,780
You can freely download and adopt them.

198
00:08:03,780 --> 00:08:07,200
NIST has the NIST Special
Publication 800 -53.

199
00:08:07,200 --> 00:08:09,180
Current revision is revision five,

200
00:08:09,180 --> 00:08:11,130
which is security and privacy controls

201
00:08:11,130 --> 00:08:13,920
for information systems and organizations.

202
00:08:13,920 --> 00:08:17,400
And then NIST has three
frameworks that I just love.

203
00:08:17,400 --> 00:08:18,600
They're really fantastic.

204
00:08:18,600 --> 00:08:19,980
They have the CSF

205
00:08:19,980 --> 00:08:22,080
that's known as the
cybersecurity framework,

206
00:08:22,080 --> 00:08:23,670
the privacy framework,

207
00:08:23,670 --> 00:08:26,070
and the risk management framework

208
00:08:26,070 --> 00:08:28,140
from which you can take your controls

209
00:08:28,140 --> 00:08:29,790
and control objectives.

210
00:08:29,790 --> 00:08:31,740
Now, what's really
interesting about NIST is,

211
00:08:31,740 --> 00:08:34,260
even though it's a US government agency,

212
00:08:34,260 --> 00:08:36,120
when they do these publications

213
00:08:36,120 --> 00:08:39,270
and they design these control
sets and these frameworks,

214
00:08:39,270 --> 00:08:41,700
they're really doing it with
a bigger audience in mind.

215
00:08:41,700 --> 00:08:43,650
Matter of fact, when they developed

216
00:08:43,650 --> 00:08:45,930
the NIST Cybersecurity Framework,

217
00:08:45,930 --> 00:08:49,440
the agency actually
invited in representatives

218
00:08:49,440 --> 00:08:54,180
of industry, and academia,
and the nonprofit sector

219
00:08:54,180 --> 00:08:58,380
to really help and have input
into developing the framework.

220
00:08:58,380 --> 00:09:00,060
And because they recognize

221
00:09:00,060 --> 00:09:02,400
that they could easily be used worldwide,

222
00:09:02,400 --> 00:09:03,960
the NIST Cybersecurity framework

223
00:09:03,960 --> 00:09:06,630
has been translated
into multiple languages.

224
00:09:06,630 --> 00:09:08,310
If you're not familiar with

225
00:09:08,310 --> 00:09:10,710
the NIST special publications
or the frameworks,

226
00:09:10,710 --> 00:09:12,840
please absolutely take time to go out

227
00:09:12,840 --> 00:09:14,850
and really learn about them.

228
00:09:14,850 --> 00:09:17,970
You will not be tested
specifically on them for the exam,

229
00:09:17,970 --> 00:09:19,620
but they're an incredible resource

230
00:09:19,620 --> 00:09:22,890
for your day-to-day
cybersecurity practice.

231
00:09:22,890 --> 00:09:25,080
Now, another really good
set of controls guidance

232
00:09:25,080 --> 00:09:26,790
is published by the ISO.

233
00:09:26,790 --> 00:09:27,623
The ISO is the

234
00:09:27,623 --> 00:09:29,910
International Organization
for Standardization,

235
00:09:29,910 --> 00:09:33,570
and you can learn more
about them at iso.org.

236
00:09:33,570 --> 00:09:35,430
Now, they are globally recognized

237
00:09:35,430 --> 00:09:37,140
and their standards are adopted

238
00:09:37,140 --> 00:09:38,970
by a lot of multinational companies,

239
00:09:38,970 --> 00:09:43,560
and they have the ISO 27014:2020,

240
00:09:43,560 --> 00:09:46,440
which is the Information
Security Cybersecurity

241
00:09:46,440 --> 00:09:48,630
and Privacy Protection Standard.

242
00:09:48,630 --> 00:09:51,750
Now, the caveat with the ISO
is that it is proprietary.

243
00:09:51,750 --> 00:09:55,773
And to have access to the ISO
materials, you do need to pay.

244
00:09:58,200 --> 00:10:02,040
So once you've made a decision
about your controls baseline

245
00:10:02,040 --> 00:10:03,330
the next step is saying,

246
00:10:03,330 --> 00:10:06,540
how do I make these
just really applicable,

247
00:10:06,540 --> 00:10:08,790
really perfect for my organization?

248
00:10:08,790 --> 00:10:11,400
So we go through the process
of fine tuning the controls,

249
00:10:11,400 --> 00:10:13,200
and it's a four-step process,

250
00:10:13,200 --> 00:10:17,970
scoping, tailoring,
compensating, and supplementing.

251
00:10:17,970 --> 00:10:19,560
Scoping is eliminating

252
00:10:19,560 --> 00:10:21,630
any unnecessary baseline recommendations

253
00:10:21,630 --> 00:10:23,940
that are not applicable
to your organization.

254
00:10:23,940 --> 00:10:25,110
So it's like, "Oh, I don't need that.

255
00:10:25,110 --> 00:10:26,730
That doesn't make sense
for my organization.

256
00:10:26,730 --> 00:10:28,980
Scratch it, Get rid of it."

257
00:10:28,980 --> 00:10:32,310
Tailoring is customizing
those baseline recommendations

258
00:10:32,310 --> 00:10:35,130
to align with organizational requirements.

259
00:10:35,130 --> 00:10:38,010
It's like going to the store,
you buy a suit off the rack.

260
00:10:38,010 --> 00:10:41,850
Looks okay, but you wanted to
look great, really fit well.

261
00:10:41,850 --> 00:10:44,250
So you go to the tailor,
and the tailor takes it in,

262
00:10:44,250 --> 00:10:46,770
lets it out, whatever it needs to be done

263
00:10:46,770 --> 00:10:48,330
just to make it perfect.

264
00:10:48,330 --> 00:10:50,790
So it's customizing the
baseline recommendations

265
00:10:50,790 --> 00:10:54,000
to align with organizational requirements.

266
00:10:54,000 --> 00:10:55,620
Now, third is compensating.

267
00:10:55,620 --> 00:10:58,590
Compensating is substituting
a recommended baseline control

268
00:10:58,590 --> 00:10:59,940
with a similar control.

269
00:10:59,940 --> 00:11:01,260
Maybe there's a recommended control,

270
00:11:01,260 --> 00:11:04,290
but for whatever reason, you
can't implement that control.

271
00:11:04,290 --> 00:11:05,970
So we put in a similar one

272
00:11:05,970 --> 00:11:07,920
that would be referred to compensating.

273
00:11:07,920 --> 00:11:10,980
And lastly, supplementing
is when we augment

274
00:11:10,980 --> 00:11:13,080
or add to the baseline recommendations.

275
00:11:13,080 --> 00:11:14,790
Maybe there's something
specific in your environment

276
00:11:14,790 --> 00:11:16,350
that needs additional controls.

277
00:11:16,350 --> 00:11:18,420
You wanna add to that baseline.

278
00:11:18,420 --> 00:11:22,650
So scoping, tailoring,
compensating, and supplementing.

279
00:11:22,650 --> 00:11:25,740
So what is the baseline
modification process look like?

280
00:11:25,740 --> 00:11:28,020
Well, we start with identifying
our control baselines.

281
00:11:28,020 --> 00:11:29,220
They could be ones that we've written,

282
00:11:29,220 --> 00:11:31,470
but more likely we're gonna look at NIST,

283
00:11:31,470 --> 00:11:32,700
we're gonna look at ISO,

284
00:11:32,700 --> 00:11:35,700
or we'll look at other industry baselines.

285
00:11:35,700 --> 00:11:37,650
We'll apply the scoping considerations,

286
00:11:37,650 --> 00:11:39,540
meaning that we will say which ones

287
00:11:39,540 --> 00:11:42,750
are not applicable to my
organization, and get rid of them.

288
00:11:42,750 --> 00:11:45,840
We'll tailor or fine tune those controls.

289
00:11:45,840 --> 00:11:48,240
We will select compensating
controls if needed.

290
00:11:48,240 --> 00:11:50,340
They may not be necessary at all.

291
00:11:50,340 --> 00:11:53,310
And we'll supplement the
baseline, again, if needed.

292
00:11:53,310 --> 00:11:54,660
A baseline might be comprehensive

293
00:11:54,660 --> 00:11:56,310
and you don't need to add anything,

294
00:11:56,310 --> 00:11:57,423
or you might need to.

295
00:11:58,860 --> 00:11:59,850
Then we're gonna publish 'em.

296
00:11:59,850 --> 00:12:02,760
So everyone in our organization
knows what we're using.

297
00:12:02,760 --> 00:12:04,920
We will implement them.

298
00:12:04,920 --> 00:12:07,410
We will assess to make sure

299
00:12:07,410 --> 00:12:08,970
that they are working in the ways

300
00:12:08,970 --> 00:12:11,910
that we expect them to work,
that they're trustworthy.

301
00:12:11,910 --> 00:12:14,880
And we will continue to
monitor the control baseline

302
00:12:14,880 --> 00:12:16,710
and all the individual controls.

303
00:12:16,710 --> 00:12:18,330
Why, because things change over time,

304
00:12:18,330 --> 00:12:20,970
and we wanna make sure that
they're continuing to operate

305
00:12:20,970 --> 00:12:23,673
and function in the way we expect them to.

306
00:12:26,940 --> 00:12:28,950
We also want to make sure that our

307
00:12:28,950 --> 00:12:31,950
controls are subject to
a cost benefit analysis.

308
00:12:31,950 --> 00:12:34,050
A cost benefit analysis is really looking

309
00:12:34,050 --> 00:12:37,563
at the financial
implications of a control.

310
00:12:38,670 --> 00:12:40,230
So the cost benefit analysis,

311
00:12:40,230 --> 00:12:42,000
being the process of comparing

312
00:12:42,000 --> 00:12:44,100
the estimated costs and benefits

313
00:12:44,100 --> 00:12:45,840
to determine whether it makes sense

314
00:12:45,840 --> 00:12:48,330
to proceed from a business perspective.

315
00:12:48,330 --> 00:12:51,390
Now, if the cost of a control
is significantly lower

316
00:12:51,390 --> 00:12:53,430
than the losses without the control,

317
00:12:53,430 --> 00:12:54,570
well, that's easy, right?

318
00:12:54,570 --> 00:12:57,120
The cost of the control
is generally justified.

319
00:12:57,120 --> 00:13:00,990
Conversely, if the cost of
control is significantly higher

320
00:13:00,990 --> 00:13:02,500
than the loss without the control,

321
00:13:02,500 --> 00:13:04,530
well, the cost probably isn't justified.

322
00:13:04,530 --> 00:13:06,060
It doesn't make any sense.

323
00:13:06,060 --> 00:13:07,950
And when they're about the same,

324
00:13:07,950 --> 00:13:10,770
you're going to do a return
on investment, an ROI,

325
00:13:10,770 --> 00:13:13,350
to determine whether
the cost is justified.

326
00:13:13,350 --> 00:13:16,380
The cost certainly is
never the only determinant.

327
00:13:16,380 --> 00:13:18,960
We are also looking at reputation,

328
00:13:18,960 --> 00:13:21,330
and regulatory requirements,

329
00:13:21,330 --> 00:13:24,990
and our strategy inside our organization.

330
00:13:24,990 --> 00:13:27,600
But because we have to pay
for many of our controls,

331
00:13:27,600 --> 00:13:28,530
we always wanna make sure

332
00:13:28,530 --> 00:13:31,263
that we're looking at the
financial benefit as well.

333
00:13:33,450 --> 00:13:35,010
And that, my friends, brings us to

334
00:13:35,010 --> 00:13:36,930
our first three-second challenge.

335
00:13:36,930 --> 00:13:38,580
We're going to have a
three-second challenge

336
00:13:38,580 --> 00:13:39,720
in every sub lesson.

337
00:13:39,720 --> 00:13:41,610
And for each three second challenge,

338
00:13:41,610 --> 00:13:43,080
what I'm gonna do is I'm gonna give you

339
00:13:43,080 --> 00:13:44,760
a statement or a term,

340
00:13:44,760 --> 00:13:47,340
and I want you to shout out

341
00:13:47,340 --> 00:13:48,930
and I mean that, sitting at your computer,

342
00:13:48,930 --> 00:13:52,530
shout out what you think the
correct answer or response is.

343
00:13:52,530 --> 00:13:54,600
I'm gonna give you three
seconds for each of these.

344
00:13:54,600 --> 00:13:56,700
So let's go ahead and
do our first set, ready?

345
00:13:56,700 --> 00:13:58,050
Let's go.

346
00:13:58,050 --> 00:14:00,270
Statement of desired result to be achieved

347
00:14:00,270 --> 00:14:01,620
by implementing a control.

348
00:14:01,620 --> 00:14:02,517
I want you to tell me what that is,

349
00:14:02,517 --> 00:14:04,410
and I want you to shout
it out at your computer.

350
00:14:04,410 --> 00:14:05,760
I'm gonna give you three seconds.

351
00:14:05,760 --> 00:14:08,340
One, two, three.

352
00:14:08,340 --> 00:14:10,800
Well, hopefully you said
a control objective.

353
00:14:10,800 --> 00:14:12,060
All right, number two.

354
00:14:12,060 --> 00:14:14,760
The term used to describe multiple layers

355
00:14:14,760 --> 00:14:16,293
of diverse controls.

356
00:14:17,250 --> 00:14:19,500
One, two, three.

357
00:14:19,500 --> 00:14:20,433
Shout it out.

358
00:14:21,360 --> 00:14:24,570
Defense-in-depth or layered
security or layered controls,

359
00:14:24,570 --> 00:14:25,770
all of those would work.

360
00:14:27,000 --> 00:14:28,530
Number three,

361
00:14:28,530 --> 00:14:31,323
set of minimum controls
for a given environment.

362
00:14:32,730 --> 00:14:35,370
One, two, three.

363
00:14:35,370 --> 00:14:36,963
That's our control baseline.

364
00:14:38,670 --> 00:14:39,840
You getting the hang of it, I bet.

365
00:14:39,840 --> 00:14:42,630
Number four, the process of eliminating

366
00:14:42,630 --> 00:14:44,940
unnecessary baseline recommendations.

367
00:14:44,940 --> 00:14:47,430
Remember this is part of
that four-step process.

368
00:14:47,430 --> 00:14:49,083
One, two, three.

369
00:14:50,220 --> 00:14:51,900
That's gonna be scoping.

370
00:14:51,900 --> 00:14:53,880
And lastly, number five,

371
00:14:53,880 --> 00:14:57,903
a control implemented to
address a specific threat.

372
00:14:59,100 --> 00:15:00,360
One, two, three.

373
00:15:00,360 --> 00:15:02,850
We talked about this way at the beginning.

374
00:15:02,850 --> 00:15:04,500
That's gonna be a countermeasure.

375
00:15:06,630 --> 00:15:08,250
Also, in every sub lesson,

376
00:15:08,250 --> 00:15:10,800
we're gonna be doing a
security-in-action case study.

377
00:15:10,800 --> 00:15:13,440
Now, the objective of the
security-in-action case study

378
00:15:13,440 --> 00:15:16,350
is for you to be able
to apply your knowledge,

379
00:15:16,350 --> 00:15:19,473
what we just learned and talked
about in a practical manner.

380
00:15:20,640 --> 00:15:22,710
So in our first
security-in-action case study,

381
00:15:22,710 --> 00:15:25,470
we're gonna be talking about
adopting a control baseline.

382
00:15:25,470 --> 00:15:28,260
And what I want you to do is I want you to

383
00:15:28,260 --> 00:15:29,790
get ready to put me on pause.

384
00:15:29,790 --> 00:15:33,480
We're gonna read through the case study,

385
00:15:33,480 --> 00:15:35,310
and then there's gonna be a question

386
00:15:35,310 --> 00:15:37,290
or two that you need to answer.

387
00:15:37,290 --> 00:15:39,510
So at that point, you'll put me on pause

388
00:15:39,510 --> 00:15:41,040
you'll think about what your answer is.

389
00:15:41,040 --> 00:15:42,570
If you want, write it down.

390
00:15:42,570 --> 00:15:45,600
And then when you're
ready, take me off pause,

391
00:15:45,600 --> 00:15:48,420
come back, and we'll go
through the answer together.

392
00:15:48,420 --> 00:15:50,760
So in our first
security-in-action case study,

393
00:15:50,760 --> 00:15:52,710
adopting a control baseline,

394
00:15:52,710 --> 00:15:54,660
external auditors have recommended

395
00:15:54,660 --> 00:15:58,800
that your organization adopt the ISO 27014

396
00:15:58,800 --> 00:16:00,450
as a control baseline.

397
00:16:00,450 --> 00:16:02,610
And you concur with the recommendation

398
00:16:02,610 --> 00:16:05,550
and the management's response
is that they worry about

399
00:16:05,550 --> 00:16:08,490
the applicability and
the cost of implementing

400
00:16:08,490 --> 00:16:11,400
such a broad set of controls.

401
00:16:11,400 --> 00:16:13,230
So my question to you is,

402
00:16:13,230 --> 00:16:17,640
what would you say to them
to alleviate their concerns?

403
00:16:17,640 --> 00:16:19,020
Go ahead if you want to put me on pause,

404
00:16:19,020 --> 00:16:20,910
think about it, jot down your answer,

405
00:16:20,910 --> 00:16:22,460
come on back when you're ready.

406
00:16:25,020 --> 00:16:26,850
Well, here might be your response.

407
00:16:26,850 --> 00:16:28,680
Begin the conversation by explaining

408
00:16:28,680 --> 00:16:31,320
that control baselines
are a starting point,

409
00:16:31,320 --> 00:16:32,730
and the goal is going to be

410
00:16:32,730 --> 00:16:35,610
to strategically align the controls

411
00:16:35,610 --> 00:16:37,410
with the needs of the organization.

412
00:16:37,410 --> 00:16:40,060
So you won't be implementing
anything you don't need.

413
00:16:41,340 --> 00:16:43,680
The adoption process includes scoping,

414
00:16:43,680 --> 00:16:46,380
remember that's eliminating
unnecessary controls,

415
00:16:46,380 --> 00:16:49,140
tailoring, that was
customizing and fine tuning,

416
00:16:49,140 --> 00:16:51,960
compensating, substituting
controls if necessary,

417
00:16:51,960 --> 00:16:55,260
and supplementing, adding
controls as warranted,

418
00:16:55,260 --> 00:16:59,160
till you get that really
perfect set of controls.

419
00:16:59,160 --> 00:17:00,810
And you wanna assure them

420
00:17:00,810 --> 00:17:03,540
that a baseline can be
phased in over time.

421
00:17:03,540 --> 00:17:06,240
It's really not unusual
to phase in a baseline

422
00:17:06,240 --> 00:17:08,730
over six months, or 12
months, or 18 months,

423
00:17:08,730 --> 00:17:11,130
or even up to 36 months,

424
00:17:11,130 --> 00:17:12,900
and certainly can be in concert

425
00:17:12,900 --> 00:17:14,910
with your budget allocations.

426
00:17:14,910 --> 00:17:17,070
And being able to have this conversation,

427
00:17:17,070 --> 00:17:19,263
that, my friends, is security-in-action.

428
00:17:20,426 --> 00:17:21,630
Now, we're gonna be ending every sublesson

429
00:17:21,630 --> 00:17:23,223
with a word cloud.

430
00:17:24,060 --> 00:17:26,430
I want you to stare at this word cloud.

431
00:17:26,430 --> 00:17:28,020
Put me on pause when we're done,

432
00:17:28,020 --> 00:17:30,900
and really, really look
at this word cloud.

433
00:17:30,900 --> 00:17:33,420
And what I want you to do is go through

434
00:17:33,420 --> 00:17:35,370
each one of these terms

435
00:17:35,370 --> 00:17:37,650
and make sure that you know what it is,

436
00:17:37,650 --> 00:17:39,720
that you can speak to it,
that you can explain it.

437
00:17:39,720 --> 00:17:43,170
These are all terms that we
will have covered in the lesson.

438
00:17:43,170 --> 00:17:44,370
And if you can't,

439
00:17:44,370 --> 00:17:47,370
then go back through
the lesson till you can.

440
00:17:47,370 --> 00:17:48,660
And then when you're ready,

441
00:17:48,660 --> 00:17:49,980
come on and join me in the next lesson.

442
00:17:49,980 --> 00:17:51,780
I'll be waiting for you right there.
