1
00:00:06,540 --> 00:00:09,690
- In 12.3, we're going
to look at some specific

2
00:00:09,690 --> 00:00:12,903
data protection mechanisms and strategies.

3
00:00:13,800 --> 00:00:15,450
Now, how do we make decisions

4
00:00:15,450 --> 00:00:17,940
about our protection
mechanisms and strategies?

5
00:00:17,940 --> 00:00:20,220
Well, that's data management.

6
00:00:20,220 --> 00:00:23,760
Data management being the
planning and execution of policies

7
00:00:23,760 --> 00:00:28,170
and practices to protect data
confidentiality, integrity,

8
00:00:28,170 --> 00:00:31,380
and availability, there's
our fundamental principles,

9
00:00:31,380 --> 00:00:33,391
throughout its lifecycle.

10
00:00:33,391 --> 00:00:36,300
The data protection decisions
are generally related

11
00:00:36,300 --> 00:00:39,630
to data classification, we
talked about in the last lesson,

12
00:00:39,630 --> 00:00:42,180
the data state, meaning the point in time,

13
00:00:42,180 --> 00:00:44,910
data at rest, so for
example, persistent storage,

14
00:00:44,910 --> 00:00:48,810
disk or tape, data in use,
so data that is either in RAM

15
00:00:48,810 --> 00:00:51,060
or being processed by the CPU

16
00:00:51,060 --> 00:00:53,943
or data in transit, data
that's in transmission.

17
00:00:56,190 --> 00:00:58,290
So, who's responsible for data management?

18
00:00:58,290 --> 00:01:01,440
Well, there's an entire data
management ecosystem, right?

19
00:01:01,440 --> 00:01:03,330
The outer layer here is our directors

20
00:01:03,330 --> 00:01:05,820
and executive management, our data owners

21
00:01:05,820 --> 00:01:07,440
are gonna have specific responsibilities,

22
00:01:07,440 --> 00:01:08,940
our data custodians are gonna have

23
00:01:08,940 --> 00:01:11,130
specific responsibilities, and of course,

24
00:01:11,130 --> 00:01:15,330
our data users are going to
have specific responsibilities.

25
00:01:15,330 --> 00:01:16,590
So let's take a look little bit deeper

26
00:01:16,590 --> 00:01:19,380
about what's expected of our directors

27
00:01:19,380 --> 00:01:21,780
and executive management, our data owners,

28
00:01:21,780 --> 00:01:24,873
our data custodians, and our data users.

29
00:01:27,840 --> 00:01:30,120
So, directors and executive management

30
00:01:30,120 --> 00:01:31,740
are ultimately responsible for everything

31
00:01:31,740 --> 00:01:33,720
that happens in an organization.

32
00:01:33,720 --> 00:01:37,050
So, they're responsible for
governance and oversight.

33
00:01:37,050 --> 00:01:39,840
And from a legal and
regulatory perspective,

34
00:01:39,840 --> 00:01:42,090
they really are the
ones that are ultimately

35
00:01:42,090 --> 00:01:43,950
held responsible for the actions

36
00:01:43,950 --> 00:01:46,920
or the inactions of an organization.

37
00:01:46,920 --> 00:01:48,750
Now, are they doing any hands-on work?

38
00:01:48,750 --> 00:01:51,900
Absolutely not, in terms
of data management.

39
00:01:51,900 --> 00:01:55,170
They're doing governance work,
so policies and standards,

40
00:01:55,170 --> 00:01:58,740
making sure that that's done,
budgeting and then oversight,

41
00:01:58,740 --> 00:02:00,840
getting reports to make
sure that we're doing

42
00:02:00,840 --> 00:02:03,990
the right thing, as well
as bringing in folks

43
00:02:03,990 --> 00:02:07,230
to do assessments and audits
so that we have assurance

44
00:02:07,230 --> 00:02:08,880
that we're doing the right thing.

45
00:02:10,800 --> 00:02:13,650
The data owners, just like system owners,

46
00:02:13,650 --> 00:02:16,500
are responsible for
oversight and decisions.

47
00:02:16,500 --> 00:02:17,970
I wanna stress those two words.

48
00:02:17,970 --> 00:02:21,510
Oversight and decisions
related to classification,

49
00:02:21,510 --> 00:02:24,300
access control, and protection.

50
00:02:24,300 --> 00:02:26,880
So again, they're
responsible for oversight,

51
00:02:26,880 --> 00:02:29,910
making sure that we are
getting our data classified,

52
00:02:29,910 --> 00:02:32,550
oversight of access control and protection

53
00:02:32,550 --> 00:02:33,870
and decisions, right?

54
00:02:33,870 --> 00:02:35,160
How should this be classified?

55
00:02:35,160 --> 00:02:36,420
Who should have access?

56
00:02:36,420 --> 00:02:38,400
And how are we going to protect it?

57
00:02:38,400 --> 00:02:41,190
Now, they'll do that in concert
with the data custodians.

58
00:02:41,190 --> 00:02:43,530
Now, a little caveat here
in a mandatory environment

59
00:02:43,530 --> 00:02:46,110
that we talked about a little bit earlier,

60
00:02:46,110 --> 00:02:49,470
the owners don't have a choice
on classification, right?

61
00:02:49,470 --> 00:02:51,810
That's done by a classification officer.

62
00:02:51,810 --> 00:02:54,710
So this would be done more in
a discretionary environment.

63
00:02:55,590 --> 00:02:57,660
Our data custodians are responsible

64
00:02:57,660 --> 00:03:01,140
for advising, implementing, managing,

65
00:03:01,140 --> 00:03:04,320
and monitoring data protection controls.

66
00:03:04,320 --> 00:03:06,390
So our custodians, well,
that's you and me, right?

67
00:03:06,390 --> 00:03:07,830
The hands-on folks, right?

68
00:03:07,830 --> 00:03:09,750
We're going in, we're
advising, we're implementing,

69
00:03:09,750 --> 00:03:11,700
we're managing, we're monitoring.

70
00:03:11,700 --> 00:03:14,250
The owners ultimately
responsible for those decisions

71
00:03:14,250 --> 00:03:17,550
related to classification,
access control, and protection,

72
00:03:17,550 --> 00:03:20,523
which also means decisions
related to budgeting.

73
00:03:21,840 --> 00:03:23,400
And then we get to data users.

74
00:03:23,400 --> 00:03:25,950
And data users are
responsible for treating data

75
00:03:25,950 --> 00:03:29,370
and interacting with information
systems in accordance

76
00:03:29,370 --> 00:03:32,910
with organizational policies
and with handling standards.

77
00:03:32,910 --> 00:03:34,440
But they can't do anything

78
00:03:34,440 --> 00:03:35,820
in accordance with handling standards

79
00:03:35,820 --> 00:03:39,000
if we don't classify
and if we don't label.

80
00:03:39,000 --> 00:03:41,790
So, we have to classify our
data and label our data,

81
00:03:41,790 --> 00:03:44,940
so when our data users
interact with that data,

82
00:03:44,940 --> 00:03:46,840
they know what they're supposed to do.

83
00:03:49,290 --> 00:03:53,673
So let's look at some various
data protection strategies.

84
00:03:54,660 --> 00:03:57,780
We have geographic restrictions,
we have encryption,

85
00:03:57,780 --> 00:04:00,453
we have hashing, we have segmentation.

86
00:04:02,010 --> 00:04:03,900
Geographic restrictions are just gonna be

87
00:04:03,900 --> 00:04:06,660
global restrictions on where data

88
00:04:06,660 --> 00:04:09,033
can be stored, transmitted, and processed.

89
00:04:10,710 --> 00:04:12,210
Why do we have global restrictions?

90
00:04:12,210 --> 00:04:13,320
Well, for a couple reasons.

91
00:04:13,320 --> 00:04:15,939
One, we might have regulations that say

92
00:04:15,939 --> 00:04:18,450
your data can't be in certain places

93
00:04:18,450 --> 00:04:20,280
or can only be in certain places,

94
00:04:20,280 --> 00:04:23,760
or maybe we're concerned
about the jurisdiction

95
00:04:23,760 --> 00:04:27,300
of other places and how
what laws might apply

96
00:04:27,300 --> 00:04:29,910
or how local officials may be able

97
00:04:29,910 --> 00:04:31,953
to get access to our data.

98
00:04:33,450 --> 00:04:34,440
Encryption.

99
00:04:34,440 --> 00:04:36,150
You know all about encryption now, right?

100
00:04:36,150 --> 00:04:37,590
You know that we transform plain text

101
00:04:37,590 --> 00:04:41,310
into encrypted text that can only be read

102
00:04:41,310 --> 00:04:42,840
by the intended recipient,

103
00:04:42,840 --> 00:04:45,423
meaning only the intended
recipient can decrypt it.

104
00:04:46,260 --> 00:04:47,400
Hashing.

105
00:04:47,400 --> 00:04:48,660
You know what this is too, right?

106
00:04:48,660 --> 00:04:51,480
Creating a one way fixed
length representation

107
00:04:51,480 --> 00:04:54,000
that's used for comparative purposes.

108
00:04:54,000 --> 00:04:55,680
Really, what are we using hashing for?

109
00:04:55,680 --> 00:04:57,270
We're using hashing for integrity,

110
00:04:57,270 --> 00:05:00,210
where we used encryption
for confidentiality.

111
00:05:00,210 --> 00:05:02,640
And lastly, segmentation where we can have

112
00:05:02,640 --> 00:05:04,530
network restrictions on where data

113
00:05:04,530 --> 00:05:07,680
can be stored, processed, and transmitted.

114
00:05:07,680 --> 00:05:09,900
Now, we've talked about
all of these already,

115
00:05:09,900 --> 00:05:12,150
but let me introduce you to four new ones.

116
00:05:12,150 --> 00:05:17,150
Masking, tokenization,
obfuscation, and access controls.

117
00:05:19,740 --> 00:05:21,420
Data masking is a technique that's used

118
00:05:21,420 --> 00:05:23,880
to protect sensitive data by replacing it

119
00:05:23,880 --> 00:05:27,782
with either fictional
or de-identified data.

120
00:05:27,782 --> 00:05:29,940
The data masking techniques include

121
00:05:29,940 --> 00:05:32,760
replacing identifiable data with symbols

122
00:05:32,760 --> 00:05:35,010
like your password with
a bunch of asterisks

123
00:05:35,010 --> 00:05:38,610
or shuffling the data, or
applying data substitution methods

124
00:05:38,610 --> 00:05:41,220
that maintain the format
of the original data.

125
00:05:41,220 --> 00:05:43,050
So if you have an eight
character password,

126
00:05:43,050 --> 00:05:45,720
you still just see eight asterisks, right?

127
00:05:45,720 --> 00:05:47,730
While hiding its content.

128
00:05:47,730 --> 00:05:50,100
Now, data masking is
commonly used in industries

129
00:05:50,100 --> 00:05:53,010
that handle sensitive data
to protect the privacy

130
00:05:53,010 --> 00:05:54,750
of individuals and to comply

131
00:05:54,750 --> 00:05:57,063
with data protection regulations.

132
00:05:58,890 --> 00:06:00,930
Next up is tokenization and those of you

133
00:06:00,930 --> 00:06:04,290
who have any interaction
with having to deal

134
00:06:04,290 --> 00:06:07,320
with handling credit cards,
you're probably really familiar

135
00:06:07,320 --> 00:06:09,000
with tokenization 'cause this is where

136
00:06:09,000 --> 00:06:10,890
it just found its niche.

137
00:06:10,890 --> 00:06:15,300
Tokenization is a technique
to secure and desensitize data

138
00:06:15,300 --> 00:06:19,140
by replacing the original
data with an unrelated value

139
00:06:19,140 --> 00:06:21,273
of the same length and format.

140
00:06:22,920 --> 00:06:25,680
Now, the sensitive data
is securely captured

141
00:06:25,680 --> 00:06:28,560
and stored by a tokenization system.

142
00:06:28,560 --> 00:06:31,020
The system then generates
a token that's mapped

143
00:06:31,020 --> 00:06:34,290
to the original data and
replaces it with a token.

144
00:06:34,290 --> 00:06:38,070
And that token can be used
for processing or transmission

145
00:06:38,070 --> 00:06:41,070
because it doesn't have any
sensitive information, right?

146
00:06:41,070 --> 00:06:44,730
It just has the unrelated information

147
00:06:44,730 --> 00:06:48,000
that's replaced what the
sensitive information was.

148
00:06:48,000 --> 00:06:51,450
Now, only the tokenization
system can swap the token

149
00:06:51,450 --> 00:06:53,580
with the original value.

150
00:06:53,580 --> 00:06:57,900
Now, unlike encrypted data,
tokenized data is irreversible

151
00:06:57,900 --> 00:07:00,630
and it's really widely, widely used

152
00:07:00,630 --> 00:07:02,310
in the credit card processing

153
00:07:02,310 --> 00:07:05,010
because there are very strict
rules about how the fact

154
00:07:05,010 --> 00:07:08,970
that you can't store locally
credit card information, right?

155
00:07:08,970 --> 00:07:12,720
Credit card name, number, you know,

156
00:07:12,720 --> 00:07:16,650
the date of expiration, the security code.

157
00:07:16,650 --> 00:07:17,970
But there are a lot of organizations

158
00:07:17,970 --> 00:07:20,070
that that need to do recurring charges,

159
00:07:20,070 --> 00:07:22,710
for example, in which
case they will end up

160
00:07:22,710 --> 00:07:24,420
in a tokenized environment

161
00:07:24,420 --> 00:07:28,320
where the sensitive data
will be held, right?

162
00:07:28,320 --> 00:07:30,848
The tokenization system will
have that sensitive data,

163
00:07:30,848 --> 00:07:34,860
not the organizations
accepting the credit card

164
00:07:34,860 --> 00:07:37,020
and then they can do the swapping

165
00:07:37,020 --> 00:07:38,720
when they go to do the processing.

166
00:07:40,980 --> 00:07:44,280
The data obfuscation is
the act of making a dataset

167
00:07:44,280 --> 00:07:48,390
difficult to understand or
find by unauthorized users.

168
00:07:48,390 --> 00:07:51,840
And there's really two
kind of approaches to this.

169
00:07:51,840 --> 00:07:55,500
One is data hiding, and the
other is data abstraction.

170
00:07:55,500 --> 00:07:57,930
Now, data hiding is a
programming technique

171
00:07:57,930 --> 00:08:00,510
of hiding internal object details,

172
00:08:00,510 --> 00:08:03,420
which allow for restricted access.

173
00:08:03,420 --> 00:08:06,270
Where data abstraction
is a programming process

174
00:08:06,270 --> 00:08:08,640
of creating data types
that hides the details

175
00:08:08,640 --> 00:08:10,290
of the data representation,

176
00:08:10,290 --> 00:08:14,100
separating the interface
from the implementation.

177
00:08:14,100 --> 00:08:17,313
Often data abstraction is used
in programming environments.

178
00:08:18,510 --> 00:08:20,400
All right, my friends, that brings us to

179
00:08:20,400 --> 00:08:22,950
a three second challenge. Are you ready?

180
00:08:22,950 --> 00:08:25,560
Five challenge questions,
three seconds each.

181
00:08:25,560 --> 00:08:27,630
Let's see if we can do it.

182
00:08:27,630 --> 00:08:30,270
Number one, they're
responsible for advising,

183
00:08:30,270 --> 00:08:34,140
implementing, managing, and
monitoring data controls.

184
00:08:34,140 --> 00:08:35,190
Who is this?

185
00:08:35,190 --> 00:08:36,780
This is in our ecosystem.

186
00:08:36,780 --> 00:08:38,313
One, two, three.

187
00:08:39,330 --> 00:08:42,150
That's gonna be our data custodians.

188
00:08:42,150 --> 00:08:45,990
Number two, technique used
to protect sensitive data

189
00:08:45,990 --> 00:08:49,113
by replacing it with fictional
or de-identified data.

190
00:08:50,130 --> 00:08:51,933
One, two, three.

191
00:08:53,100 --> 00:08:54,303
That's gonna be masking.

192
00:08:56,490 --> 00:08:58,620
Number three, the act of making a dataset

193
00:08:58,620 --> 00:09:02,613
difficult to understand or
find by unauthorized users.

194
00:09:04,200 --> 00:09:06,093
One, two, three.

195
00:09:06,990 --> 00:09:08,553
That's gonna be obfuscation.

196
00:09:10,440 --> 00:09:14,010
Number four, a cryptographic
technique that creates

197
00:09:14,010 --> 00:09:17,760
a one way fixed length
representation of the data.

198
00:09:17,760 --> 00:09:19,800
I know everybody's gonna
get this right away.

199
00:09:19,800 --> 00:09:21,720
One, two, three.

200
00:09:21,720 --> 00:09:23,370
That's gonna be hashing.

201
00:09:23,370 --> 00:09:26,970
And lastly, number five,
technique to secure

202
00:09:26,970 --> 00:09:30,390
and desensitize data by
replacing the original data

203
00:09:30,390 --> 00:09:34,233
with an unrelated value of
the same length and format.

204
00:09:35,280 --> 00:09:37,620
One, two, three.

205
00:09:37,620 --> 00:09:40,290
I'll give you a hint, using
the credit card industry.

206
00:09:40,290 --> 00:09:43,890
This is a token or tokenization.

207
00:09:43,890 --> 00:09:44,723
Good work.

208
00:09:45,630 --> 00:09:47,700
All right, let's do a security in action

209
00:09:47,700 --> 00:09:49,023
about data ownership.

210
00:09:50,100 --> 00:09:52,020
It's a really short little one, isn't it?

211
00:09:52,020 --> 00:09:54,930
You've been asked to
explain to data owners

212
00:09:54,930 --> 00:09:57,630
their data protection responsibilities

213
00:09:57,630 --> 00:09:59,853
and corresponding control selection.

214
00:10:00,900 --> 00:10:02,550
Pretty straightforward, right?

215
00:10:02,550 --> 00:10:05,700
We have been asked to
explain to data owners

216
00:10:05,700 --> 00:10:08,940
what their data protection
responsibilities are

217
00:10:08,940 --> 00:10:12,663
and as well as corresponding
control selection.

218
00:10:13,834 --> 00:10:15,210
Put me on pause, jot down some notes

219
00:10:15,210 --> 00:10:16,920
about what your explanation is.

220
00:10:16,920 --> 00:10:19,720
I wanna know where you're
gonna start this conversation.

221
00:10:22,187 --> 00:10:25,950
Well, you may wanna begin by
explaining that as data owners,

222
00:10:25,950 --> 00:10:28,950
they're responsible for
oversight and decisions

223
00:10:28,950 --> 00:10:32,220
related to classification, access control,

224
00:10:32,220 --> 00:10:34,890
and data protection.

225
00:10:34,890 --> 00:10:36,960
Explain that data protection controls

226
00:10:36,960 --> 00:10:39,420
are related to the data state, right?

227
00:10:39,420 --> 00:10:42,870
Data state being, is this being processed?

228
00:10:42,870 --> 00:10:43,800
Is this at rest?

229
00:10:43,800 --> 00:10:46,320
Is this at transmission?

230
00:10:46,320 --> 00:10:48,752
Now, this would also be a really good time

231
00:10:48,752 --> 00:10:51,720
to review some recommended
data protection controls.

232
00:10:51,720 --> 00:10:54,690
access control, encryption, tokenization,

233
00:10:54,690 --> 00:10:57,300
whatever it is that really makes sense

234
00:10:57,300 --> 00:10:58,923
for your organization.

235
00:10:59,760 --> 00:11:03,090
And then you wanna
reassure the participants

236
00:11:03,090 --> 00:11:06,270
that data custodians will
be the ones to implement,

237
00:11:06,270 --> 00:11:09,480
manage, and monitor the selected controls,

238
00:11:09,480 --> 00:11:11,970
that their job as owners
is really to approach

239
00:11:11,970 --> 00:11:15,270
data management from a
business perspective.

240
00:11:15,270 --> 00:11:17,190
'Cause I would take this a
step further and tell you

241
00:11:17,190 --> 00:11:19,920
that the custodians are not
only gonna implement, manage,

242
00:11:19,920 --> 00:11:22,650
and monitor, but as custodians, right?

243
00:11:22,650 --> 00:11:25,500
We are going to advise
and educate as well.

244
00:11:25,500 --> 00:11:28,200
We will help our data owners understand

245
00:11:28,200 --> 00:11:30,810
what are the best controls, right?

246
00:11:30,810 --> 00:11:32,820
Based on strategic alignment,

247
00:11:32,820 --> 00:11:36,330
regulatory compliance,
classification levels.

248
00:11:36,330 --> 00:11:39,330
Again, having these conversations
really, really important

249
00:11:39,330 --> 00:11:43,680
because cyber and information
security is not a silo.

250
00:11:43,680 --> 00:11:47,250
It is an enterprise risk
management activity and we need

251
00:11:47,250 --> 00:11:49,950
to be able to have these
conversations with folks

252
00:11:49,950 --> 00:11:52,350
throughout our entire organization.

253
00:11:52,350 --> 00:11:55,110
Doing all that, well,
that's security in action.

254
00:11:55,110 --> 00:11:58,470
There's your word cloud,
and you know what to do.

255
00:11:58,470 --> 00:12:00,840
Don't move on until
you're really comfortable

256
00:12:00,840 --> 00:12:03,570
and confident with all
these terms and concepts.

257
00:12:03,570 --> 00:12:06,240
When you're ready, we're
gonna do a quiz together.

258
00:12:06,240 --> 00:12:07,340
So I'll see you there.
