1
00:00:06,644 --> 00:00:09,660
- In 11.2, we're gonna talk
about network access control

2
00:00:09,660 --> 00:00:11,700
and the devices we use

3
00:00:11,700 --> 00:00:15,363
to ensure and secure
network access control.

4
00:00:16,710 --> 00:00:17,910
So network access control,

5
00:00:17,910 --> 00:00:20,850
we're gonna define for our
purposes in this lesson

6
00:00:20,850 --> 00:00:23,220
as the process of controlling access,

7
00:00:23,220 --> 00:00:25,410
identifying suspicious behavior

8
00:00:25,410 --> 00:00:27,570
and preventing data exfiltration.

9
00:00:27,570 --> 00:00:30,750
And there is a number of
devices that we use to do that.

10
00:00:30,750 --> 00:00:33,990
We use firewalls, IDSs and IPSs,

11
00:00:33,990 --> 00:00:36,660
jump servers, proxy servers,

12
00:00:36,660 --> 00:00:39,810
NAC, network access control
devices, not to be confused

13
00:00:39,810 --> 00:00:42,090
with the generic term
network access control

14
00:00:42,090 --> 00:00:45,483
and DLP, data loss prevention solutions.

15
00:00:46,890 --> 00:00:50,040
The most basic use of a
firewall is to control

16
00:00:50,040 --> 00:00:52,170
ingress and egress traffic.

17
00:00:52,170 --> 00:00:57,170
An IDS and an IPS can both
analyze and monitor traffic

18
00:00:57,330 --> 00:01:01,140
and an IPS can actually take an action.

19
00:01:01,140 --> 00:01:03,690
We use a jump server to
provide secure access

20
00:01:03,690 --> 00:01:05,730
to another system.

21
00:01:05,730 --> 00:01:10,293
We use proxy servers to filter
and fetch or catch client.

22
00:01:11,190 --> 00:01:16,190
We use proxies to filter and
fetch or cache client requests.

23
00:01:16,980 --> 00:01:20,610
We use NAC to evaluate
endpoints for network access

24
00:01:20,610 --> 00:01:23,340
using pre-admission and
post admission policies.

25
00:01:23,340 --> 00:01:27,840
And we use DLP data loss
prevention to detect data movement

26
00:01:27,840 --> 00:01:30,870
and to prevent data exfiltration.

27
00:01:30,870 --> 00:01:34,113
So we're gonna dive deeper
into each one of these.

28
00:01:35,925 --> 00:01:38,280
Now, the primary objective
of a traditional firewall

29
00:01:38,280 --> 00:01:41,100
is to isolate network segments and traffic

30
00:01:41,100 --> 00:01:45,360
by controlling ingress incoming
and egress outgoing traffic.

31
00:01:45,360 --> 00:01:47,220
Now there's a lot to talk about firewalls

32
00:01:47,220 --> 00:01:48,690
so we're actually gonna move firewalls

33
00:01:48,690 --> 00:01:50,040
right to our next lesson.

34
00:01:50,040 --> 00:01:52,590
We'll focus on firewalls in lesson 11.3

35
00:01:52,590 --> 00:01:56,283
and have an entire lesson about
firewalls so let's move on.

36
00:01:57,810 --> 00:02:00,330
Let's talk about I IDSs and IPSs.

37
00:02:00,330 --> 00:02:03,120
An intrusion detection system or an IDS

38
00:02:03,120 --> 00:02:06,540
can analyze and monitor network traffic.

39
00:02:06,540 --> 00:02:10,290
An IPS is an intrusion prevention system,

40
00:02:10,290 --> 00:02:13,200
can analyze and monitor just like an IDS,

41
00:02:13,200 --> 00:02:14,100
but the difference is

42
00:02:14,100 --> 00:02:16,830
it can proactively deny network traffic.

43
00:02:16,830 --> 00:02:18,903
It can proactively take action.

44
00:02:20,430 --> 00:02:23,070
Now, IDSs or IPSs can be network-based

45
00:02:23,070 --> 00:02:26,160
in which case we refer
to them as NIDS and NIPS

46
00:02:26,160 --> 00:02:29,250
or they can be host-based in
which we refer to them as,

47
00:02:29,250 --> 00:02:32,160
with the H, HIDS or HIPS.

48
00:02:32,160 --> 00:02:35,100
Now in-band, when we talk
about in places in-band,

49
00:02:35,100 --> 00:02:37,920
in-band placement directly
in the flow of traffic

50
00:02:37,920 --> 00:02:40,290
and inspects every packet.

51
00:02:40,290 --> 00:02:43,230
Now, NIDS and NIPS can be in-band.

52
00:02:43,230 --> 00:02:46,290
Out of band placement
utilizes a passive tap.

53
00:02:46,290 --> 00:02:48,360
We talked about a tap in the last lesson

54
00:02:48,360 --> 00:02:50,760
that can receive a copy
of the network traffic

55
00:02:50,760 --> 00:02:52,500
and can process samples.

56
00:02:52,500 --> 00:02:55,380
Now, that only applies to a NIDS, right?

57
00:02:55,380 --> 00:02:58,350
Because NIPS would take action, right?

58
00:02:58,350 --> 00:03:02,553
So only applies to a network
IDS, not a network IPS.

59
00:03:06,600 --> 00:03:10,140
So the IDS or the IPS, same device really

60
00:03:10,140 --> 00:03:12,870
when it's making its decisions

61
00:03:12,870 --> 00:03:16,800
has to decide is this good
traffic or is this bad traffic?

62
00:03:16,800 --> 00:03:19,020
Is it normal or abnormal?

63
00:03:19,020 --> 00:03:20,760
So it has decision engines

64
00:03:20,760 --> 00:03:22,590
that allow it to make those decisions.

65
00:03:22,590 --> 00:03:25,560
And there are four primary
types of decision engines -

66
00:03:25,560 --> 00:03:27,480
pattern matching, rule-based,

67
00:03:27,480 --> 00:03:31,050
behavioral based and heuristic.

68
00:03:31,050 --> 00:03:32,970
Pattern matching decisions are based

69
00:03:32,970 --> 00:03:36,330
on established, known
patterns and signatures.

70
00:03:36,330 --> 00:03:38,730
And the signatures must
be updated frequently

71
00:03:38,730 --> 00:03:41,643
very much like the debt
files for your antivirus.

72
00:03:42,960 --> 00:03:46,890
Rule-based IDSs analyze
behavior for violation

73
00:03:46,890 --> 00:03:49,443
of a pre-configured set of rules.

74
00:03:50,550 --> 00:03:53,460
Behavioral-based IDS decision engines

75
00:03:53,460 --> 00:03:56,070
focus on identifying deviations

76
00:03:56,070 --> 00:03:58,350
from normal patterns of behavior

77
00:03:58,350 --> 00:04:02,640
rather than specific
attack signatures or rules.

78
00:04:02,640 --> 00:04:06,690
And lastly, heuristic IDSs
use a set of predefined rules

79
00:04:06,690 --> 00:04:11,130
and algorithms to identify
anomalous behavior and patterns

80
00:04:11,130 --> 00:04:14,940
which can be adapted and
can be updated over time.

81
00:04:14,940 --> 00:04:17,490
Now it's possible your IDS
only has one of these engines

82
00:04:17,490 --> 00:04:21,693
but many IDSs actually have a
combination of these engines.

83
00:04:24,660 --> 00:04:27,210
A jump server, which is
also known as a jump host

84
00:04:27,210 --> 00:04:30,420
or a bastion host, is gonna
be a hardened computer system

85
00:04:30,420 --> 00:04:33,510
or server that serves
to provide secure access

86
00:04:33,510 --> 00:04:36,780
to other computers or other
systems within your network.

87
00:04:36,780 --> 00:04:40,170
Now, jump servers are usually
deployed in a screen subnet.

88
00:04:40,170 --> 00:04:42,990
Remember, a screen subnet
was going to be a zone

89
00:04:42,990 --> 00:04:44,730
that had connections to both the trusted

90
00:04:44,730 --> 00:04:46,590
and untrusted network.

91
00:04:46,590 --> 00:04:48,750
So it's usually deployed
in a screen subnet

92
00:04:48,750 --> 00:04:51,420
to provide additional layer of security.

93
00:04:51,420 --> 00:04:53,550
The users can access the jump server

94
00:04:53,550 --> 00:04:57,180
through a secure connection
such as SSH or through a VPN,

95
00:04:57,180 --> 00:04:59,850
and then use that jump server as a gateway

96
00:04:59,850 --> 00:05:02,820
to access other systems on the network.

97
00:05:02,820 --> 00:05:04,590
The jump servers can also be used

98
00:05:04,590 --> 00:05:06,270
to enforce security policies

99
00:05:06,270 --> 00:05:09,333
and provide an audit
trail of user activity.

100
00:05:12,930 --> 00:05:16,080
A proxy server is an intermediary machine.

101
00:05:16,080 --> 00:05:18,540
It's between a client and a server.

102
00:05:18,540 --> 00:05:22,650
And it's used to either filter
requests or fetch requests

103
00:05:22,650 --> 00:05:26,190
or fetch and cache requests
that are made by the client.

104
00:05:26,190 --> 00:05:27,960
And those cache requests can be

105
00:05:27,960 --> 00:05:31,653
or those cache responses
actually can be reused.

106
00:05:33,210 --> 00:05:35,673
Now, lots of different varieties
here are proxy servers.

107
00:05:35,673 --> 00:05:37,320
They can be a single purpose,

108
00:05:37,320 --> 00:05:39,330
supporting let's say just one protocol,

109
00:05:39,330 --> 00:05:41,370
an HTTP proxy server

110
00:05:41,370 --> 00:05:44,910
or they can be multi-purpose,
supporting multiple protocols.

111
00:05:44,910 --> 00:05:48,480
And there are three primary
proxy configurations:

112
00:05:48,480 --> 00:05:53,373
a forward proxy, a transparent
proxy, and a reverse proxy.

113
00:05:56,070 --> 00:05:58,920
A forward proxy is when the clients,

114
00:05:58,920 --> 00:06:02,340
so really your browser are
configured to send your request

115
00:06:02,340 --> 00:06:04,260
to the proxy server.

116
00:06:04,260 --> 00:06:07,890
So the proxy server receives
a request, fetches the content

117
00:06:07,890 --> 00:06:10,860
and then stores a copy for future use.

118
00:06:10,860 --> 00:06:12,360
So let's say you had a proxy server

119
00:06:12,360 --> 00:06:13,800
to go out to the internet.

120
00:06:13,800 --> 00:06:18,090
So you do your request, I
wanna go to www.someplace.com.

121
00:06:18,090 --> 00:06:19,800
It goes to the proxy server.

122
00:06:19,800 --> 00:06:22,140
The proxy server on your behalf goes out

123
00:06:22,140 --> 00:06:25,530
and fetches that content
and returns it to you.

124
00:06:25,530 --> 00:06:27,360
And if the content is static,

125
00:06:27,360 --> 00:06:29,760
meaning it's not being
dynamically updated,

126
00:06:29,760 --> 00:06:31,650
it will actually keep a copy.

127
00:06:31,650 --> 00:06:34,170
So if two minutes later one
of your colleagues says,

128
00:06:34,170 --> 00:06:37,020
I wanna go to that same
place, they make the request,

129
00:06:37,020 --> 00:06:39,990
the proxy server catches it
and responds from its cache.

130
00:06:39,990 --> 00:06:41,880
It doesn't have to go
back out to the internet

131
00:06:41,880 --> 00:06:43,320
to get that information.

132
00:06:43,320 --> 00:06:46,020
Now, obviously on sites
that dynamically change

133
00:06:46,020 --> 00:06:49,743
or updating all the time, that
information can't be cached.

134
00:06:50,910 --> 00:06:52,980
Then we have a transparent proxy.

135
00:06:52,980 --> 00:06:56,370
A transparent proxy is really
the same as a forward proxy

136
00:06:56,370 --> 00:06:57,540
except the client,

137
00:06:57,540 --> 00:06:59,850
the browser doesn't need to be configured.

138
00:06:59,850 --> 00:07:01,590
In a forward proxy server,

139
00:07:01,590 --> 00:07:03,120
we actually have to tell our browser

140
00:07:03,120 --> 00:07:05,880
to go talk to the proxy server,

141
00:07:05,880 --> 00:07:07,950
but in a transparent proxy,

142
00:07:07,950 --> 00:07:09,960
we don't have to configure
the browser at all.

143
00:07:09,960 --> 00:07:13,170
The proxy server just
resides on the gateway

144
00:07:13,170 --> 00:07:16,740
and it on its own intercepts requests.

145
00:07:16,740 --> 00:07:19,110
And then we have a reverse proxy.

146
00:07:19,110 --> 00:07:21,570
Now, a reverse proxy
isn't on the client side,

147
00:07:21,570 --> 00:07:23,910
it's actually out on the web server side.

148
00:07:23,910 --> 00:07:25,980
A reverse proxy appears to the client

149
00:07:25,980 --> 00:07:28,290
just like an ordinary web server.

150
00:07:28,290 --> 00:07:31,680
But the reverse proxy
caches all static answers

151
00:07:31,680 --> 00:07:34,350
from the web server and
replies to the clients

152
00:07:34,350 --> 00:07:36,630
from its cache with the goal

153
00:07:36,630 --> 00:07:38,820
of reducing the load on the web server.

154
00:07:38,820 --> 00:07:42,150
Of course, that's also gonna
be limited by dynamic content.

155
00:07:42,150 --> 00:07:43,650
So three types of proxy servers:

156
00:07:43,650 --> 00:07:46,713
forward, transparent, and reverse.

157
00:07:49,080 --> 00:07:51,210
Next, we have a network
access control system

158
00:07:51,210 --> 00:07:52,043
or a NAC system.

159
00:07:52,043 --> 00:07:53,790
This is a pretty cool system.

160
00:07:53,790 --> 00:07:57,930
This system uses agents to
evaluate our endpoint connections

161
00:07:57,930 --> 00:08:00,960
prior to allowing them
admission onto the network

162
00:08:00,960 --> 00:08:03,300
and then enforces access privileges

163
00:08:03,300 --> 00:08:05,220
based on what's known as pre-admission

164
00:08:05,220 --> 00:08:07,470
and post admission policies.

165
00:08:07,470 --> 00:08:09,120
So I want you to imagine that you

166
00:08:09,960 --> 00:08:11,970
come into your corporate
office, you've got your laptop,

167
00:08:11,970 --> 00:08:14,670
you go to connect either
wired or wireless,

168
00:08:14,670 --> 00:08:18,060
before you're actually going
to be allowed to authenticate

169
00:08:18,060 --> 00:08:19,500
the NAC system is gonna say,

170
00:08:19,500 --> 00:08:22,110
wait a minute, I need
to evaluate your system

171
00:08:22,110 --> 00:08:25,023
and decide if we're even
gonna let you on our network.

172
00:08:26,100 --> 00:08:27,090
Now it does that first

173
00:08:27,090 --> 00:08:29,760
using what's known as
pre-admission policies.

174
00:08:29,760 --> 00:08:31,290
Pre-admission policies determine

175
00:08:31,290 --> 00:08:33,810
if a device is gonna be
allowed on the network

176
00:08:33,810 --> 00:08:38,070
and if so, what segment based
on host health compliance.

177
00:08:38,070 --> 00:08:40,680
So for example, are you running antivirus?

178
00:08:40,680 --> 00:08:42,480
Are your dev files up-to-date?

179
00:08:42,480 --> 00:08:43,560
How about your patches?

180
00:08:43,560 --> 00:08:45,090
Are you all patched up?

181
00:08:45,090 --> 00:08:46,470
Do you have a host firewall?

182
00:08:46,470 --> 00:08:48,969
Do you have an IDS?

183
00:08:48,969 --> 00:08:51,810
Or how is your system configured?

184
00:08:51,810 --> 00:08:52,950
All of those things can be

185
00:08:52,950 --> 00:08:55,410
in the pre-admission policy, right?

186
00:08:55,410 --> 00:08:58,440
And the NAC system evaluates
your system and says,

187
00:08:58,440 --> 00:09:02,640
okay, based on how you meet
those pre-admission policies

188
00:09:02,640 --> 00:09:05,100
I'm gonna determine where
you can go on the network.

189
00:09:05,100 --> 00:09:07,500
Am I gonna let you just do a
next step of authenticating

190
00:09:07,500 --> 00:09:09,060
and go wherever you can go

191
00:09:09,060 --> 00:09:11,370
by based on rights and permissions

192
00:09:11,370 --> 00:09:14,160
or maybe going to not allow
you to be on the network

193
00:09:14,160 --> 00:09:17,460
or are we going to move you
to a maybe a segmented area

194
00:09:17,460 --> 00:09:18,930
or a segregated area of the network?

195
00:09:18,930 --> 00:09:21,390
Or maybe we'll move you
to a remediation area

196
00:09:21,390 --> 00:09:23,280
where we'll update your dev files

197
00:09:23,280 --> 00:09:25,560
or we'll get you the patches you need

198
00:09:25,560 --> 00:09:28,200
before we're gonna allow
you on the network?

199
00:09:28,200 --> 00:09:30,930
And then that post admission
policies just regulate

200
00:09:30,930 --> 00:09:33,993
and restrict access once
the connection is allowed.

201
00:09:36,600 --> 00:09:38,280
Next up, we have a DLP.

202
00:09:38,280 --> 00:09:40,950
DLP stands for data loss prevention

203
00:09:40,950 --> 00:09:45,360
and DLP solutions are designed
to detect data movement

204
00:09:45,360 --> 00:09:47,577
and to prevent data exfiltration.

205
00:09:47,577 --> 00:09:50,910
The exfiltration we define as unauthorized

206
00:09:50,910 --> 00:09:54,900
or inadvertent or accidental
release or removal of data.

207
00:09:54,900 --> 00:09:57,060
So it doesn't have to
necessarily be malicious.

208
00:09:57,060 --> 00:10:00,900
Very often, data exfiltration
is really just happens

209
00:10:00,900 --> 00:10:02,430
because someone doesn't
even understand that

210
00:10:02,430 --> 00:10:04,650
they shouldn't be sending that data out.

211
00:10:04,650 --> 00:10:07,320
So exfiltration just means
that data leaves your control,

212
00:10:07,320 --> 00:10:08,670
leaves your environment.

213
00:10:08,670 --> 00:10:13,320
So the DLP says, I can look
for unauthorized or accidental

214
00:10:13,320 --> 00:10:15,843
release or removal of data.

215
00:10:18,090 --> 00:10:19,020
So how do they work?

216
00:10:19,020 --> 00:10:22,770
Well, DLP technologies, locate
and catalog sensitive data,

217
00:10:22,770 --> 00:10:25,050
of course based on
predefined rules and criteria

218
00:10:25,050 --> 00:10:26,070
that you're gonna set up.

219
00:10:26,070 --> 00:10:28,050
So maybe, one of the criteria is

220
00:10:28,050 --> 00:10:29,520
you're looking for
social security numbers.

221
00:10:29,520 --> 00:10:30,870
Well, here in the US,

222
00:10:30,870 --> 00:10:32,790
that's gonna be three numbers, a dash,

223
00:10:32,790 --> 00:10:34,800
two numbers, a dash and four numbers.

224
00:10:34,800 --> 00:10:37,560
So that's the predefined
criteria, we're looking for that.

225
00:10:37,560 --> 00:10:39,510
Maybe you're in a financial institution

226
00:10:39,510 --> 00:10:41,640
and you wanna look for account numbers

227
00:10:41,640 --> 00:10:44,250
and your account numbers
are 18 characters long

228
00:10:44,250 --> 00:10:45,600
or 18 numbers long.

229
00:10:45,600 --> 00:10:48,330
That would be the
predefined characteristics.

230
00:10:48,330 --> 00:10:50,370
Maybe we're looking for
things like date of birth

231
00:10:50,370 --> 00:10:53,820
or other type of records
that we can catalog.

232
00:10:53,820 --> 00:10:56,730
So we can either catalog
them by a sensitivity

233
00:10:56,730 --> 00:10:59,823
or have this predetermined
criteria what it might look like.

234
00:11:00,780 --> 00:11:04,560
The DLP tools can monitor
that target data in use,

235
00:11:04,560 --> 00:11:07,920
in motion and at rest.

236
00:11:07,920 --> 00:11:11,220
So DLPs might be at different
locations in your network.

237
00:11:11,220 --> 00:11:14,430
They might be network-based,
storage-based,

238
00:11:14,430 --> 00:11:17,940
endpoint based or they
could even be in the cloud.

239
00:11:17,940 --> 00:11:20,580
So a network-based DLP,
which could be hardware

240
00:11:20,580 --> 00:11:23,850
or virtual appliance
deals with data in motion.

241
00:11:23,850 --> 00:11:26,913
And it's usually located
on the network perimeter.

242
00:11:29,040 --> 00:11:31,200
Storage based, which
is going to be software

243
00:11:31,200 --> 00:11:34,503
operates on long-term
storage, like our archives.

244
00:11:35,340 --> 00:11:37,680
Endpoint based, again,
is gonna be software

245
00:11:37,680 --> 00:11:42,030
operates on a local device
and focuses on data in use.

246
00:11:42,030 --> 00:11:46,440
And then cloud-based protects
in-cloud data in use,

247
00:11:46,440 --> 00:11:49,143
in motion, and in rest.

248
00:11:50,190 --> 00:11:52,077
That was a lot of different
network appliances

249
00:11:52,077 --> 00:11:55,290
and and what they can do
to secure your enterprise.

250
00:11:55,290 --> 00:11:58,410
So that brings us to a
three second challenge.

251
00:11:58,410 --> 00:12:00,480
Five challenge questions,
three seconds each,

252
00:12:00,480 --> 00:12:01,480
you know what to do.

253
00:12:02,790 --> 00:12:06,300
This device is used to control
ingress and egress access.

254
00:12:06,300 --> 00:12:08,400
1, 2, 3. I know you know what this is.

255
00:12:08,400 --> 00:12:11,160
This is a firewall. Good work!

256
00:12:11,160 --> 00:12:13,710
Number two, this passive
device can analyze

257
00:12:13,710 --> 00:12:16,260
and monitor network traffic.

258
00:12:16,260 --> 00:12:18,273
1, 2, 3.

259
00:12:19,680 --> 00:12:22,413
That's gonna be an IDS
because it's passive.

260
00:12:24,750 --> 00:12:27,630
Number three, this server can
be used to gain secure access

261
00:12:27,630 --> 00:12:30,813
to other computers and
systems within a network.

262
00:12:31,710 --> 00:12:33,840
1, 2, 3.

263
00:12:33,840 --> 00:12:35,240
It's gonna be a jump server.

264
00:12:36,300 --> 00:12:39,990
Number four, this type of proxy
server appears to a client

265
00:12:39,990 --> 00:12:41,883
just like an ordinary web server.

266
00:12:42,720 --> 00:12:45,210
1, 2, 3.

267
00:12:45,210 --> 00:12:46,950
And that's a reverse proxy.

268
00:12:46,950 --> 00:12:48,900
And lastly, number five,

269
00:12:48,900 --> 00:12:51,210
this type of NAC policy
is used to determine

270
00:12:51,210 --> 00:12:54,033
if a device should be allowed
to connect to the network.

271
00:12:54,990 --> 00:12:57,570
1, 2, 3.

272
00:12:57,570 --> 00:13:00,840
And that's gonna be a
pre-admission policy.

273
00:13:00,840 --> 00:13:02,580
Awesome. Great work!

274
00:13:02,580 --> 00:13:05,400
So that brings us to
a security and action,

275
00:13:05,400 --> 00:13:07,740
putting your knowledge into play.

276
00:13:07,740 --> 00:13:10,230
This one's about data exfiltration.

277
00:13:10,230 --> 00:13:11,310
The buzz in your industry

278
00:13:11,310 --> 00:13:13,830
is that foreign competitors
are willing to pay big money

279
00:13:13,830 --> 00:13:15,660
for insider information.

280
00:13:15,660 --> 00:13:18,780
And your boss is concerned
that a particular employee

281
00:13:18,780 --> 00:13:21,930
might be tempted, especially,

282
00:13:21,930 --> 00:13:23,460
especially if they thought the likelihood

283
00:13:23,460 --> 00:13:25,080
of being caught was low.

284
00:13:25,080 --> 00:13:28,140
So she's come to you and she's
asked you for recommendations

285
00:13:28,140 --> 00:13:30,000
of how to mitigate this risk.

286
00:13:30,000 --> 00:13:34,050
And my question to you is,
what are your recommendations?

287
00:13:34,050 --> 00:13:37,860
Okay, so the buzz here is that
a foreign competitor, right?

288
00:13:37,860 --> 00:13:41,010
Really willing to pay big, big money

289
00:13:41,010 --> 00:13:42,900
for insider information.

290
00:13:42,900 --> 00:13:45,510
And we've got this particular employee

291
00:13:45,510 --> 00:13:47,910
who he's worried might be tempted,

292
00:13:47,910 --> 00:13:52,473
especially if the likelihood
of being caught was low.

293
00:13:53,520 --> 00:13:55,560
So come to you for recommendations,

294
00:13:55,560 --> 00:13:57,030
What are you gonna do?

295
00:13:57,030 --> 00:13:59,820
Great time to put me on
pause, write down some notes,

296
00:13:59,820 --> 00:14:01,680
tell me what your recommendations are.

297
00:14:01,680 --> 00:14:03,730
Come on back and we'll do these together.

298
00:14:06,810 --> 00:14:09,810
Well, the first thing we
wanna do is we wanna identify

299
00:14:09,810 --> 00:14:12,660
what type of information or data sets

300
00:14:12,660 --> 00:14:14,070
are being sought, right?

301
00:14:14,070 --> 00:14:16,140
So what does that foreign competitor want

302
00:14:16,140 --> 00:14:17,610
so that we can catalog them, right?

303
00:14:17,610 --> 00:14:20,433
We need to know what it is
we're trying to protect.

304
00:14:22,680 --> 00:14:26,670
Then we can assess access
rights and permissions

305
00:14:26,670 --> 00:14:28,050
to those data sets.

306
00:14:28,050 --> 00:14:29,880
So who has rights and permissions to them?

307
00:14:29,880 --> 00:14:33,150
And whenever possible,
reduce the exposure.

308
00:14:33,150 --> 00:14:35,790
That means implementing the
principle of least privilege.

309
00:14:35,790 --> 00:14:37,050
Remember least privileges,

310
00:14:37,050 --> 00:14:39,120
assigning the least rights and permissions

311
00:14:39,120 --> 00:14:40,200
to get a job done.

312
00:14:40,200 --> 00:14:42,660
So let's not give anybody any more rights

313
00:14:42,660 --> 00:14:45,423
or permissions to those
data sets than they need.

314
00:14:46,530 --> 00:14:48,810
And then we can implement a DLP,

315
00:14:48,810 --> 00:14:50,940
a data loss prevention solution

316
00:14:50,940 --> 00:14:53,310
that can monitor that target data

317
00:14:53,310 --> 00:14:58,310
while it's in use and in
motion, including email.

318
00:14:58,650 --> 00:15:00,120
But we have to start

319
00:15:00,120 --> 00:15:02,490
with identifying what the
type of information is

320
00:15:02,490 --> 00:15:04,650
'cause we don't want the DLP
to have to look at everything

321
00:15:04,650 --> 00:15:06,660
that happens and be
making decisions, right?

322
00:15:06,660 --> 00:15:09,780
We wanna really be able
to target the DLP solution

323
00:15:09,780 --> 00:15:12,420
to specifically the types of data sets

324
00:15:12,420 --> 00:15:16,413
that we think that foreign
competitor is trying to extract.

325
00:15:18,060 --> 00:15:21,150
We'll then configure the DLP to quarantine

326
00:15:21,150 --> 00:15:22,803
any suspicious activity.

327
00:15:24,300 --> 00:15:26,940
And we can also use endpoint DLP

328
00:15:26,940 --> 00:15:29,190
to restrict use of removable media.

329
00:15:29,190 --> 00:15:31,050
So we've got two things happening here.

330
00:15:31,050 --> 00:15:34,200
We're gonna configure the DLP
to quarantine or stop, right?

331
00:15:34,200 --> 00:15:36,450
So note, we're not gonna
let that file go out.

332
00:15:36,450 --> 00:15:37,650
We're gonna be look at it first

333
00:15:37,650 --> 00:15:39,270
before it's allowed to go anywhere

334
00:15:39,270 --> 00:15:41,100
or that email before it's
allowed to go anywhere,

335
00:15:41,100 --> 00:15:42,210
if it's the email based.

336
00:15:42,210 --> 00:15:44,790
And then we're gonna use
endpoint data loss protection

337
00:15:44,790 --> 00:15:46,860
to restrict the use of removable media

338
00:15:46,860 --> 00:15:48,810
because what we don't want
is that employee to say,

339
00:15:48,810 --> 00:15:51,330
okay, well I can't get it
out through the firewall.

340
00:15:51,330 --> 00:15:52,650
I can't get it out through email.

341
00:15:52,650 --> 00:15:54,540
What if I just put in a USB device?

342
00:15:54,540 --> 00:15:56,010
I plug one in and I just put it there,

343
00:15:56,010 --> 00:15:57,810
put it in my pocket and walk out.

344
00:15:57,810 --> 00:15:59,400
And we don't want that to happen either.

345
00:15:59,400 --> 00:16:02,820
So we wanna be able to restrict
the use of removable media

346
00:16:02,820 --> 00:16:05,370
and we can do that with a DLP.

347
00:16:05,370 --> 00:16:06,930
All right, how'd you do?

348
00:16:06,930 --> 00:16:09,240
Lots of, lots of great ideas here, right,

349
00:16:09,240 --> 00:16:12,240
of ways that we can really secure our data

350
00:16:12,240 --> 00:16:13,530
and keep that foreign competitor

351
00:16:13,530 --> 00:16:15,060
from getting their hands on it.

352
00:16:15,060 --> 00:16:17,847
Doing that, well, definitely
security and action.

353
00:16:17,847 --> 00:16:20,790
All right, there's your word
cloud, quite a bit, right?

354
00:16:20,790 --> 00:16:23,610
Make sure that you really
understand everything that's here.

355
00:16:23,610 --> 00:16:26,880
You can speak to it, you're
confident before you move on.

356
00:16:26,880 --> 00:16:29,430
Once you're ready, I'll
see you at the next lesson.
