1
00:00:06,540 --> 00:00:08,040
- Welcome to lesson 14.

2
00:00:08,040 --> 00:00:11,010
Given a scenario, apply
common security techniques

3
00:00:11,010 --> 00:00:12,810
to computing resources.

4
00:00:12,810 --> 00:00:17,100
In this lesson, our first
lesson in lesson 14, 14.1,

5
00:00:17,100 --> 00:00:19,890
we're gonna focus in on securing baselines

6
00:00:19,890 --> 00:00:21,483
and hardening targets.

7
00:00:22,440 --> 00:00:25,200
Now, a secure baseline is
gonna be a predefined set

8
00:00:25,200 --> 00:00:27,930
of security configurations and practices

9
00:00:27,930 --> 00:00:31,020
that are considered the
minimum level of protection

10
00:00:31,020 --> 00:00:33,090
for a system or a network.

11
00:00:33,090 --> 00:00:35,100
Now, the purpose of a secure baseline

12
00:00:35,100 --> 00:00:37,770
is to ensure that the
fundamental security measures

13
00:00:37,770 --> 00:00:39,330
are in place to protect against

14
00:00:39,330 --> 00:00:41,130
common threats and vulnerabilities.

15
00:00:41,130 --> 00:00:43,320
And it serves as our starting point

16
00:00:43,320 --> 00:00:45,240
for establishing a secure environment.

17
00:00:45,240 --> 00:00:48,243
And it can be used as a
foundation to build upon.

18
00:00:49,950 --> 00:00:52,590
The hardening is an ongoing activity.

19
00:00:52,590 --> 00:00:56,370
It's the ongoing process of
configuring security settings,

20
00:00:56,370 --> 00:00:58,140
applying security patches,

21
00:00:58,140 --> 00:01:00,150
and implementing least functionality,

22
00:01:00,150 --> 00:01:02,700
we've talked about the principle
of least functionality,

23
00:01:02,700 --> 00:01:05,310
in order to reduce the system footprint,

24
00:01:05,310 --> 00:01:06,990
minimize vulnerabilities

25
00:01:06,990 --> 00:01:11,040
and exposure to threats
and enhance resilience.

26
00:01:11,040 --> 00:01:12,300
Now, if you're thinking, "I can't remember

27
00:01:12,300 --> 00:01:14,640
what the principle of
least functionality is,"

28
00:01:14,640 --> 00:01:15,900
let's go through it.

29
00:01:15,900 --> 00:01:17,850
The principle of least functionality

30
00:01:17,850 --> 00:01:20,520
is that systems and devices
should be configured

31
00:01:20,520 --> 00:01:22,890
to provide only essential capabilities,

32
00:01:22,890 --> 00:01:25,800
and specifically to
prohibit or restrict the use

33
00:01:25,800 --> 00:01:29,670
of any and all unnecessary
functions, ports,

34
00:01:29,670 --> 00:01:31,983
protocols, and services.

35
00:01:33,630 --> 00:01:35,520
So let's look at some common hardening

36
00:01:35,520 --> 00:01:37,650
and ancillary measures.

37
00:01:37,650 --> 00:01:40,920
Physical, cybersecurity, redundancy,

38
00:01:40,920 --> 00:01:45,920
backup, monitoring, assessments,
testing and maintenance.

39
00:01:47,520 --> 00:01:49,860
So physical is implementing
security measures

40
00:01:49,860 --> 00:01:52,500
to protect against physical attack.

41
00:01:52,500 --> 00:01:54,630
Cybersecurity is
implementing our firewalls,

42
00:01:54,630 --> 00:01:57,090
our IDSs, our IPSs, our encryption,

43
00:01:57,090 --> 00:01:58,683
our strong authentication.

44
00:01:59,580 --> 00:02:02,700
Redundancy we just talked about
in one of our last lessons.

45
00:02:02,700 --> 00:02:07,110
Establishing redundant systems
and failover capability.

46
00:02:07,110 --> 00:02:09,720
Backup, which we talked
about just earlier as well.

47
00:02:09,720 --> 00:02:13,623
Having trustworthy copies of
data and system configurations.

48
00:02:14,580 --> 00:02:16,440
Monitoring, monitoring for threats

49
00:02:16,440 --> 00:02:19,200
and any kind of anomalous activity.

50
00:02:19,200 --> 00:02:22,020
Conducting assessments
to identify new threats

51
00:02:22,020 --> 00:02:24,060
and vulnerabilities.

52
00:02:24,060 --> 00:02:25,920
Training, absolutely important.

53
00:02:25,920 --> 00:02:27,750
Educating the user community

54
00:02:27,750 --> 00:02:30,540
about potential threats
and best practices.

55
00:02:30,540 --> 00:02:33,420
And then certainly maintenance,
which is timely maintenance

56
00:02:33,420 --> 00:02:35,940
and firmware and software updates.

57
00:02:35,940 --> 00:02:39,840
So we're gonna go through a
number of very specific type

58
00:02:39,840 --> 00:02:42,270
of hardening activities,

59
00:02:42,270 --> 00:02:44,640
two different categories of systems,

60
00:02:44,640 --> 00:02:46,743
devices, and infrastructures.

61
00:02:47,940 --> 00:02:50,460
So we're gonna start with
servers and workstations.

62
00:02:50,460 --> 00:02:53,670
So three key things for hardening
servers and workstations,

63
00:02:53,670 --> 00:02:56,940
updates and patches,
limiting admin privileges,

64
00:02:56,940 --> 00:02:59,190
and encrypting our data.

65
00:02:59,190 --> 00:03:01,500
We wanna make sure that
we're regularly updating

66
00:03:01,500 --> 00:03:05,160
the operating system,
software and the firmware,

67
00:03:05,160 --> 00:03:08,520
and we wanna apply patches
promptly in alignment

68
00:03:08,520 --> 00:03:10,230
with a severity level.

69
00:03:10,230 --> 00:03:12,030
Now, I know there's
always a lot of discussion

70
00:03:12,030 --> 00:03:14,520
about does a patch have
to go into a lab first

71
00:03:14,520 --> 00:03:16,290
or should we try it on a subset of users?

72
00:03:16,290 --> 00:03:20,130
And I think that all makes
sense, except for my money,

73
00:03:20,130 --> 00:03:21,540
when it's a critical patch,

74
00:03:21,540 --> 00:03:23,970
I want it right out the door, right away.

75
00:03:23,970 --> 00:03:26,310
I'm willing to take the other consequences

76
00:03:26,310 --> 00:03:29,193
to know that I have
patched a critical issue.

77
00:03:30,480 --> 00:03:32,820
Then we also wanna limit
administrative privileges

78
00:03:32,820 --> 00:03:35,730
to prevent unauthorized system changes

79
00:03:35,730 --> 00:03:38,970
and to minimize the potential
impact of a compromise.

80
00:03:38,970 --> 00:03:40,620
We know that an exploit, right,

81
00:03:40,620 --> 00:03:42,750
happens in the security context

82
00:03:42,750 --> 00:03:44,520
of the currently logged in user.

83
00:03:44,520 --> 00:03:47,220
So we don't want a lot of
admin privileges out there

84
00:03:47,220 --> 00:03:48,270
that could be exploited.

85
00:03:48,270 --> 00:03:51,810
And certainly, you know,
the extreme of that,

86
00:03:51,810 --> 00:03:53,580
of limiting admin privileges,

87
00:03:53,580 --> 00:03:55,893
is moving to a zero trust environment.

88
00:03:56,910 --> 00:03:58,560
And then encrypting our data.

89
00:03:58,560 --> 00:04:01,410
To implement encryption
for sensitive data at rest

90
00:04:01,410 --> 00:04:02,490
and at transit.

91
00:04:02,490 --> 00:04:03,870
And we can use FDE,

92
00:04:03,870 --> 00:04:06,930
and that's full-disk encryption
on workstations and servers

93
00:04:06,930 --> 00:04:10,023
to protect data in case of physical theft.

94
00:04:12,450 --> 00:04:14,940
Next, let's look at how
we do some hardening

95
00:04:14,940 --> 00:04:17,040
for embedded systems in IoT devices.

96
00:04:17,040 --> 00:04:19,500
And of course, an IoT device
is an embedded system,

97
00:04:19,500 --> 00:04:21,930
but it has additional characteristics.

98
00:04:21,930 --> 00:04:24,900
Physical security, which is
securing access to the device

99
00:04:24,900 --> 00:04:26,370
to prevent tampering.

100
00:04:26,370 --> 00:04:29,610
Firmware updates to regular
update embedded systems

101
00:04:29,610 --> 00:04:32,460
and IoT devices with firmware updates.

102
00:04:32,460 --> 00:04:34,950
And that's assuming that
you can update the firmware,

103
00:04:34,950 --> 00:04:38,100
just why it's so important
to do that investigation,

104
00:04:38,100 --> 00:04:40,890
that research early on
before you buy the device

105
00:04:40,890 --> 00:04:43,440
to make sure that it is upgradable.

106
00:04:43,440 --> 00:04:45,600
And then secure configuration.

107
00:04:45,600 --> 00:04:48,690
We wanna disable and remove
any unnecessary service ports

108
00:04:48,690 --> 00:04:51,600
or protocols to reduce the attack surface.

109
00:04:51,600 --> 00:04:52,433
We also wanna make sure

110
00:04:52,433 --> 00:04:54,960
that we're changing the
default credentials.

111
00:04:54,960 --> 00:04:57,180
And if we are only using passwords,

112
00:04:57,180 --> 00:04:59,520
because maybe that's all
it's allowing us to use,

113
00:04:59,520 --> 00:05:02,313
that we're using strong, unique passwords.

114
00:05:04,410 --> 00:05:06,750
For our switches and routers,
three key things to do

115
00:05:06,750 --> 00:05:08,670
is change our default credentials,

116
00:05:08,670 --> 00:05:12,660
disable unused interfaces,
and use secure protocols.

117
00:05:12,660 --> 00:05:15,390
We wanna immediately change
the default usernames

118
00:05:15,390 --> 00:05:18,330
and passwords on switches and routers.

119
00:05:18,330 --> 00:05:21,630
We've said this before, default
credentials are well known.

120
00:05:21,630 --> 00:05:23,040
They're published on the internet

121
00:05:23,040 --> 00:05:26,310
and they're easily
exploited by our attackers.

122
00:05:26,310 --> 00:05:28,830
We wanna disable any unused interfaces.

123
00:05:28,830 --> 00:05:31,230
So disable any unnecessary services

124
00:05:31,230 --> 00:05:33,870
and interfaces on our
switches and our routers,

125
00:05:33,870 --> 00:05:36,393
again, to reduce the attack surface.

126
00:05:37,350 --> 00:05:39,720
And lastly, we wanna use secure protocols.

127
00:05:39,720 --> 00:05:42,600
We wanna disable insecure
protocols such as Telnet,

128
00:05:42,600 --> 00:05:45,540
which is clear text transmission
and basic authentication,

129
00:05:45,540 --> 00:05:50,540
and use secure alternatives
like SSH, Secure Shell,

130
00:05:50,940 --> 00:05:53,793
or HTTPS for remote management.

131
00:05:55,260 --> 00:05:57,120
What about in the cloud?

132
00:05:57,120 --> 00:05:58,590
Well, there's a lot we
can do in the cloud,

133
00:05:58,590 --> 00:06:00,630
but let's just talk about three things.

134
00:06:00,630 --> 00:06:02,580
We can configure security groups

135
00:06:02,580 --> 00:06:04,950
or use network access control lists, ACLs,

136
00:06:04,950 --> 00:06:08,400
to control inbound and outbound traffic.

137
00:06:08,400 --> 00:06:10,980
We can segment our cloud and subnets

138
00:06:10,980 --> 00:06:15,300
to isolate different tiers of
resources and applications.

139
00:06:15,300 --> 00:06:17,580
And again, we're gonna
circle back to encryption.

140
00:06:17,580 --> 00:06:19,710
We wanna encrypt data at rest

141
00:06:19,710 --> 00:06:23,073
and in transit within
the cloud infrastructure.

142
00:06:24,270 --> 00:06:26,010
Okay, circling back to our ICS,

143
00:06:26,010 --> 00:06:28,530
our industrial control
systems and SCADA systems.

144
00:06:28,530 --> 00:06:30,750
What are our key hardening activities?

145
00:06:30,750 --> 00:06:33,960
Well, thinking about isolation,
secure remote access,

146
00:06:33,960 --> 00:06:36,663
and limiting end-of-life, end-of-support.

147
00:06:38,160 --> 00:06:39,060
So with isolation,

148
00:06:39,060 --> 00:06:41,430
we wanna implement strict
network segmentation

149
00:06:41,430 --> 00:06:44,730
to isolate our ICS and
our SCADA components

150
00:06:44,730 --> 00:06:46,230
from other networks.

151
00:06:46,230 --> 00:06:48,180
And we may also wanna consider air-gapping

152
00:06:48,180 --> 00:06:50,790
critical ICS and SCADA components

153
00:06:50,790 --> 00:06:53,400
from external or any untrusted network

154
00:06:53,400 --> 00:06:55,503
to provide an extra layer of security.

155
00:06:57,570 --> 00:06:58,770
For secure remote access,

156
00:06:58,770 --> 00:07:01,410
we wanna limit access and use VPN's,

157
00:07:01,410 --> 00:07:04,410
virtual private networks
with strong encryption

158
00:07:04,410 --> 00:07:09,060
and multifactor authentication,
MFA, for remote access.

159
00:07:09,060 --> 00:07:10,410
And of course, we wanna limit

160
00:07:10,410 --> 00:07:12,090
end-of-life and end-of-support.

161
00:07:12,090 --> 00:07:15,390
So we wanna maintain a
schedule to ensure compliance

162
00:07:15,390 --> 00:07:18,210
with end-of-life and end-of-support dates.

163
00:07:18,210 --> 00:07:20,400
I should have had you start
counting at the very beginning

164
00:07:20,400 --> 00:07:22,890
of this course, how many times
I was gonna say that to you.

165
00:07:22,890 --> 00:07:24,630
And I'm probably gonna
say it a couple more,

166
00:07:24,630 --> 00:07:26,583
but I can't stress how important it is.

167
00:07:27,630 --> 00:07:29,460
So there are some great
resources out there

168
00:07:29,460 --> 00:07:31,020
to help you with hardening.

169
00:07:31,020 --> 00:07:33,660
So let's go through the
resources that are available.

170
00:07:33,660 --> 00:07:35,610
From the manufacturer or developer,

171
00:07:35,610 --> 00:07:38,430
hardware manufacturers
and software developers

172
00:07:38,430 --> 00:07:41,670
often provide documentation
and security guidelines

173
00:07:41,670 --> 00:07:43,410
for their products.

174
00:07:43,410 --> 00:07:44,430
Government resources.

175
00:07:44,430 --> 00:07:47,070
We've looked at a lot
of resources from NIST,

176
00:07:47,070 --> 00:07:49,920
the National Institute of
Standards and Technology already,

177
00:07:49,920 --> 00:07:51,780
and they offer a ton more.

178
00:07:51,780 --> 00:07:53,880
They offer resources and guidelines

179
00:07:53,880 --> 00:07:56,910
related to all types of cyber
and information security

180
00:07:56,910 --> 00:07:58,620
and information technology,

181
00:07:58,620 --> 00:08:02,253
and quite a few that relate
directly to hardening security.

182
00:08:03,720 --> 00:08:05,730
Industry alliances, industry alliances

183
00:08:05,730 --> 00:08:08,430
such as the Cloud Security
Alliance, the CSA,

184
00:08:08,430 --> 00:08:12,270
and the IoT, the Internet of
Things Security Foundation,

185
00:08:12,270 --> 00:08:17,100
IoTSF, again, publish numerous
hardening recommendations.

186
00:08:17,100 --> 00:08:19,800
And then there are quite
a few online forums

187
00:08:19,800 --> 00:08:22,830
and communities that you wanna
take advantage of and join.

188
00:08:22,830 --> 00:08:26,640
Communities of cybersecurity
professionals who share, right,

189
00:08:26,640 --> 00:08:28,770
their in-the-field knowledge.

190
00:08:28,770 --> 00:08:30,690
And you wanna become a sharer as well.

191
00:08:30,690 --> 00:08:32,850
So as you gain more and
more knowledge, you know,

192
00:08:32,850 --> 00:08:35,910
participate in those online
forums and communities

193
00:08:35,910 --> 00:08:37,743
and share your knowledge.

194
00:08:38,760 --> 00:08:40,230
All right, that, my friends,

195
00:08:40,230 --> 00:08:43,020
brings us to a three-second challenge.

196
00:08:43,020 --> 00:08:43,853
Are you ready?

197
00:08:43,853 --> 00:08:46,143
Five challenge questions,
three seconds each.

198
00:08:47,190 --> 00:08:48,930
First one, number one.

199
00:08:48,930 --> 00:08:52,410
A predefined set of minimum
security configurations.

200
00:08:52,410 --> 00:08:54,273
One, two, three.

201
00:08:55,350 --> 00:08:57,150
That's gonna be our secure baseline.

202
00:08:58,080 --> 00:09:02,133
Number two, the ongoing process
of enhancing resiliency.

203
00:09:02,970 --> 00:09:06,570
One, two, three, starts with the letter H.

204
00:09:06,570 --> 00:09:08,460
That's gonna be hardening.

205
00:09:08,460 --> 00:09:11,160
Number three, the principle
that systems and devices

206
00:09:11,160 --> 00:09:14,520
should be configured to provide
only essential capabilities.

207
00:09:14,520 --> 00:09:16,770
We've talked about this
one quite a few times.

208
00:09:16,770 --> 00:09:20,973
One, two, three, this is
gonna be least functionality.

209
00:09:21,930 --> 00:09:24,450
Number four, to disallow connections

210
00:09:24,450 --> 00:09:26,070
to any untrusted network

211
00:09:26,070 --> 00:09:28,260
or any trusted network
that has connections

212
00:09:28,260 --> 00:09:30,360
to an untrusted network.

213
00:09:30,360 --> 00:09:35,220
One, two, three, of course,
that's gonna be our air-gap.

214
00:09:35,220 --> 00:09:39,060
And lastly, number five, a
secure replacement for Telnet.

215
00:09:39,060 --> 00:09:40,710
I only mentioned it in passing this time,

216
00:09:40,710 --> 00:09:42,810
but we have mentioned
it a number of times.

217
00:09:42,810 --> 00:09:44,190
Secure replacement for Telnet.

218
00:09:44,190 --> 00:09:45,810
Why do we wanna replace Telnet?

219
00:09:45,810 --> 00:09:47,880
Because Telnet is a clear text protocol

220
00:09:47,880 --> 00:09:50,160
with very basic authentication.

221
00:09:50,160 --> 00:09:51,540
So what are you gonna replace it with?

222
00:09:51,540 --> 00:09:56,540
One, two, three, and that's
gonna be Secure Shell, SSH,

223
00:09:56,730 --> 00:10:00,660
or for remote management,
you may also consider HTTPS,

224
00:10:00,660 --> 00:10:03,543
which is HTTP plus TLS.

225
00:10:04,920 --> 00:10:08,550
Hey, that brings us to
a Security-in-Action.

226
00:10:08,550 --> 00:10:10,320
Looks like a pretty
straightforward one here,

227
00:10:10,320 --> 00:10:11,850
all about hardening.

228
00:10:11,850 --> 00:10:14,310
You've been tasked with
hardening the Windows servers

229
00:10:14,310 --> 00:10:15,393
in your data center.

230
00:10:16,350 --> 00:10:17,300
Where do you begin?

231
00:10:18,240 --> 00:10:20,580
So that's a really simple question, right?

232
00:10:20,580 --> 00:10:22,860
You've been tasked with
hardening the Windows servers

233
00:10:22,860 --> 00:10:25,680
in your data center, were do you begin?

234
00:10:25,680 --> 00:10:28,500
Well, it sounds simple, but I don't know.

235
00:10:28,500 --> 00:10:30,090
Where do you start?

236
00:10:30,090 --> 00:10:32,850
Go ahead and put me on pause,
write down your approach

237
00:10:32,850 --> 00:10:35,273
and come on back and we'll
talk through it together.

238
00:10:37,290 --> 00:10:38,880
Well, first of all, we wanna determine

239
00:10:38,880 --> 00:10:42,000
if there are any secure
configuration baselines right now.

240
00:10:42,000 --> 00:10:45,270
So before we start doing new
things, let's see what we have.

241
00:10:45,270 --> 00:10:47,820
If not, your effort's
gonna need to be directed

242
00:10:47,820 --> 00:10:50,520
to developing, getting authorization

243
00:10:50,520 --> 00:10:53,610
and implementing new secure baselines.

244
00:10:53,610 --> 00:10:56,610
Now, assuming there are secure
configuration baselines,

245
00:10:56,610 --> 00:10:57,900
you wanna check to see
if there's currently

246
00:10:57,900 --> 00:11:00,900
any hardening processes
and/or documentation.

247
00:11:00,900 --> 00:11:03,060
And if not, you're
gonna wanna create them.

248
00:11:03,060 --> 00:11:05,377
And then of course, you
wanna do research and say,

249
00:11:05,377 --> 00:11:07,680
"What are the best practices out there?"

250
00:11:07,680 --> 00:11:10,170
You know, "What should
I be doing for hardening

251
00:11:10,170 --> 00:11:12,600
my Windows servers in the data center?"

252
00:11:12,600 --> 00:11:14,910
And there's some great
resources out there.

253
00:11:14,910 --> 00:11:17,670
Resources for hardening Windows
servers include Microsoft,

254
00:11:17,670 --> 00:11:19,230
go out to their site, NIST,

255
00:11:19,230 --> 00:11:21,810
the National Institute of
Standard and Technology,

256
00:11:21,810 --> 00:11:24,930
the Center for Internet
Security, that's the CIS.

257
00:11:24,930 --> 00:11:26,340
And if you haven't been there yet,

258
00:11:26,340 --> 00:11:30,210
you definitely wanna go
out to cisecurity.org.

259
00:11:30,210 --> 00:11:31,590
It's a fantastic site

260
00:11:31,590 --> 00:11:33,900
and it has all kinds
of hardening baselines,

261
00:11:33,900 --> 00:11:37,230
as well as taking advantage
of community forums.

262
00:11:37,230 --> 00:11:39,090
But if you are gonna make any changes

263
00:11:39,090 --> 00:11:42,150
to the existing secure
configuration baselines,

264
00:11:42,150 --> 00:11:44,880
make sure that you follow
the change control procedures

265
00:11:44,880 --> 00:11:45,990
in your organization.

266
00:11:45,990 --> 00:11:49,080
And then ultimately, if it's
changing configurations, right,

267
00:11:49,080 --> 00:11:51,360
we're going to have to
make some version changes

268
00:11:51,360 --> 00:11:54,360
or updates to our
configuration management.

269
00:11:54,360 --> 00:11:55,890
So knowing how to approach this

270
00:11:55,890 --> 00:11:57,750
and then how to follow
it all the way through

271
00:11:57,750 --> 00:11:59,823
that, my friends, is security in action.

272
00:12:00,990 --> 00:12:02,340
There is your word cloud.

273
00:12:02,340 --> 00:12:04,020
There's quite a bit there,

274
00:12:04,020 --> 00:12:05,940
but a lot of these aren't new topics.

275
00:12:05,940 --> 00:12:08,520
A lot of these we've talked
about a couple of times already

276
00:12:08,520 --> 00:12:11,670
just within a different context.

277
00:12:11,670 --> 00:12:13,380
But go ahead, go through all of these.

278
00:12:13,380 --> 00:12:14,520
Make sure you can speak to them,

279
00:12:14,520 --> 00:12:16,680
you're comfortable with
them, you can explain them.

280
00:12:16,680 --> 00:12:18,690
And when you're ready, head
on over to the next lesson.

281
00:12:18,690 --> 00:12:20,190
I'll be waiting for you there.
