1
00:00:06,510 --> 00:00:09,660
- Welcome to Lesson 15, Deep Dive Quiz.

2
00:00:09,660 --> 00:00:11,640
And in Lesson 15 it's all about

3
00:00:11,640 --> 00:00:14,940
explaining the security
implications of proper hardware,

4
00:00:14,940 --> 00:00:18,390
software, and data asset management.

5
00:00:18,390 --> 00:00:21,540
And we had two lessons,
15.1, Asset Management,

6
00:00:21,540 --> 00:00:24,000
where we also talked about
inventory management,

7
00:00:24,000 --> 00:00:25,410
and end of life,

8
00:00:25,410 --> 00:00:28,950
and 15.2, where we talked about deletion,

9
00:00:28,950 --> 00:00:30,750
disposal, and destruction,

10
00:00:30,750 --> 00:00:33,600
as well as archiving and retention.

11
00:00:33,600 --> 00:00:35,820
So, you ready to do a five question quiz?

12
00:00:35,820 --> 00:00:38,760
Make sure you have a pen or
pencil and a pad of paper.

13
00:00:38,760 --> 00:00:41,250
Put me on pause as often as you need to,

14
00:00:41,250 --> 00:00:43,770
so that you can take your
time and answer the questions.

15
00:00:43,770 --> 00:00:46,743
I really want this to be
an interactive experience.

16
00:00:47,970 --> 00:00:48,803
Ready?

17
00:00:48,803 --> 00:00:49,923
All right, let's start.

18
00:00:51,607 --> 00:00:55,500
"Historically, the IT group
at the nonprofit you work at

19
00:00:55,500 --> 00:00:58,080
has made the asset
classification decisions

20
00:00:58,080 --> 00:01:00,240
and there's been little oversight.

21
00:01:00,240 --> 00:01:03,570
You want to modify this
process to be in accordance

22
00:01:03,570 --> 00:01:06,360
with generally accepted best practices.

23
00:01:06,360 --> 00:01:09,450
Which group would you
recommend be responsible

24
00:01:09,450 --> 00:01:14,450
for asset classification
decisions and control oversight?

25
00:01:14,730 --> 00:01:17,460
Administrators, executives,

26
00:01:17,460 --> 00:01:21,510
asset owners, or asset custodians?"

27
00:01:21,510 --> 00:01:22,350
What do you think?

28
00:01:22,350 --> 00:01:23,780
Put me on pause if you need to,

29
00:01:23,780 --> 00:01:25,630
if you wanna read the question again.

30
00:01:27,360 --> 00:01:30,060
So what group are we gonna
recommend to be responsible

31
00:01:30,060 --> 00:01:34,533
for asset classification
decisions and control oversight?

32
00:01:35,970 --> 00:01:38,490
Well, I'm gonna choose the asset owner,

33
00:01:38,490 --> 00:01:42,780
because classification
decisions and control oversight

34
00:01:42,780 --> 00:01:45,060
really belong to that asset owner,

35
00:01:45,060 --> 00:01:48,000
with the caveat that if we're
in a mandatory environment

36
00:01:48,000 --> 00:01:51,450
where we have, you know it's
military, or national security,

37
00:01:51,450 --> 00:01:54,090
or even government, where we
have classification officers

38
00:01:54,090 --> 00:01:57,090
who do that job, but in the
environments in industry

39
00:01:57,090 --> 00:02:00,660
that most of us work in, it
would be the asset owner.

40
00:02:00,660 --> 00:02:02,100
What about the other answers?

41
00:02:02,100 --> 00:02:06,000
Well, asset custodian isn't
making the decisions, right?

42
00:02:06,000 --> 00:02:07,590
And isn't doing the oversight.

43
00:02:07,590 --> 00:02:09,690
The asset custodian is doing the managing,

44
00:02:09,690 --> 00:02:11,760
the monitoring, the implementation,

45
00:02:11,760 --> 00:02:15,330
maybe advising on those
decisions and educating.

46
00:02:15,330 --> 00:02:17,700
And if we go up, well
using an administrator

47
00:02:17,700 --> 00:02:19,380
as an asset custodian?

48
00:02:19,380 --> 00:02:22,200
Now an executive could be an asset owner,

49
00:02:22,200 --> 00:02:25,050
but an executive doesn't
have to be an asset owner.

50
00:02:25,050 --> 00:02:26,940
So asset owner is the one I like.

51
00:02:26,940 --> 00:02:27,773
You agree?

52
00:02:28,710 --> 00:02:29,580
All right, let's see.

53
00:02:29,580 --> 00:02:31,023
And that is correct.

54
00:02:32,730 --> 00:02:37,470
Question 2, "This type of
asset inventory application

55
00:02:37,470 --> 00:02:42,030
is used to discover and document
devices and characteristics

56
00:02:42,030 --> 00:02:45,567
such as services, users and groups."

57
00:02:46,710 --> 00:02:50,040
Is this a licensing tool, an audit tool,

58
00:02:50,040 --> 00:02:54,120
an enumeration tool, or a mapping tool?

59
00:02:54,120 --> 00:02:56,610
This is an asset inventory
application, right?

60
00:02:56,610 --> 00:02:57,750
And what are we trying to do?

61
00:02:57,750 --> 00:03:00,630
We're trying to discover
and document devices,

62
00:03:00,630 --> 00:03:03,600
as well as their characteristics, right?

63
00:03:03,600 --> 00:03:07,830
What services are running,
what users, what groups?

64
00:03:07,830 --> 00:03:10,380
You know, maybe even what applications?

65
00:03:10,380 --> 00:03:12,300
So we're really trying to get information

66
00:03:12,300 --> 00:03:13,800
about those devices.

67
00:03:13,800 --> 00:03:15,780
Licensing tools, audit tools,

68
00:03:15,780 --> 00:03:18,570
enumeration tools, or mapping tools?

69
00:03:18,570 --> 00:03:20,120
Put me on pause if you need to.

70
00:03:21,975 --> 00:03:24,150
Well, I'm gonna choose enumeration tools

71
00:03:24,150 --> 00:03:25,770
because we're trying to enumerate, right?

72
00:03:25,770 --> 00:03:27,240
All of those characteristics.

73
00:03:27,240 --> 00:03:29,280
List out all those characteristics.

74
00:03:29,280 --> 00:03:32,130
Licensing tools we tend to
use for software, right?

75
00:03:32,130 --> 00:03:34,260
Where we're trying to figure
out software licensing,

76
00:03:34,260 --> 00:03:37,170
audit tools have, well, lots
of different types of options.

77
00:03:37,170 --> 00:03:40,470
And a mapping tool is when
we're trying to create a map

78
00:03:40,470 --> 00:03:42,453
of our network or our infrastructure.

79
00:03:43,710 --> 00:03:44,760
Do you agree?

80
00:03:44,760 --> 00:03:46,020
Let's check.

81
00:03:46,020 --> 00:03:47,193
And that is correct.

82
00:03:49,897 --> 00:03:52,020
"As Information Security Officer,

83
00:03:52,020 --> 00:03:54,840
you've instituted a
practice that all media

84
00:03:54,840 --> 00:03:56,880
containing sensitive data be destroyed

85
00:03:56,880 --> 00:03:58,980
at the end of its useful life.

86
00:03:58,980 --> 00:04:02,250
Now, you receive a proposal
from a destruction company

87
00:04:02,250 --> 00:04:05,370
that outlines the
techniques that they use.

88
00:04:05,370 --> 00:04:08,047
Which technique would not," again,

89
00:04:08,047 --> 00:04:09,757
"Not" is the important word here.

90
00:04:09,757 --> 00:04:11,850
"Which technique would not be in keeping

91
00:04:11,850 --> 00:04:13,800
with your requirements?"

92
00:04:13,800 --> 00:04:18,800
Sanitization, pulping,
pulverizing, or shredding?

93
00:04:21,180 --> 00:04:22,380
What's your policy?

94
00:04:22,380 --> 00:04:24,030
Your policy is that all media

95
00:04:24,030 --> 00:04:27,480
containing sensitive data be destroyed,

96
00:04:27,480 --> 00:04:29,493
the media be destroyed.

97
00:04:30,960 --> 00:04:32,970
So the destruction company says, "Okay,

98
00:04:32,970 --> 00:04:35,160
here are your options, what do you want?"

99
00:04:35,160 --> 00:04:37,290
And you look at them and you say, "Well,

100
00:04:37,290 --> 00:04:39,090
that looks pretty good, but there's one

101
00:04:39,090 --> 00:04:41,850
that's definitely not in
keeping with my requirements."

102
00:04:41,850 --> 00:04:46,803
Is that sanitization, pulping,
pulverizing, or shredding?

103
00:04:48,600 --> 00:04:51,060
Well, I'm gonna choose sanitization,

104
00:04:51,060 --> 00:04:53,790
which is really another
way of saying disc wiping,

105
00:04:53,790 --> 00:04:58,050
which is when we are overriding
the disc multiple times

106
00:04:58,050 --> 00:05:01,770
with ones, or zeros, or random characters.

107
00:05:01,770 --> 00:05:06,300
The other three, pulping,
pulverizing, and shredding

108
00:05:06,300 --> 00:05:09,780
are all destruction mechanisms, agree?

109
00:05:09,780 --> 00:05:13,053
Let's check, and we are correct.

110
00:05:15,060 --> 00:05:18,420
Question 4, "One of the
business units at your company

111
00:05:18,420 --> 00:05:20,910
is using an application that was released

112
00:05:20,910 --> 00:05:23,490
on August 1st, 2011.

113
00:05:23,490 --> 00:05:25,830
The published EOL is five years,

114
00:05:25,830 --> 00:05:29,070
and the EOS is an additional five years.

115
00:05:29,070 --> 00:05:30,570
The department manager remarked

116
00:05:30,570 --> 00:05:33,480
that they've never encountered
any software issues,

117
00:05:33,480 --> 00:05:36,570
and that the software meets their needs."

118
00:05:36,570 --> 00:05:37,807
So my question to you is,

119
00:05:37,807 --> 00:05:41,047
"Would you consider
this a security issue?"

120
00:05:41,047 --> 00:05:44,490
"Yes, it is, because of
the end of life date.

121
00:05:44,490 --> 00:05:46,890
No, because the software
software's working just fine.

122
00:05:46,890 --> 00:05:48,153
It's working as intended.

123
00:05:49,140 --> 00:05:52,290
Yes, because updates and security patches

124
00:05:52,290 --> 00:05:54,750
are no longer available,"

125
00:05:54,750 --> 00:05:58,620
or, "No, no because there
appears to be no need

126
00:05:58,620 --> 00:06:00,987
for support or product maintenance."

127
00:06:02,280 --> 00:06:03,300
Go ahead, put me on pause,

128
00:06:03,300 --> 00:06:05,310
read through that situation again.

129
00:06:05,310 --> 00:06:07,380
Read through those answers.

130
00:06:07,380 --> 00:06:08,283
What do you think?

131
00:06:11,430 --> 00:06:12,780
So you know, there may be a tendency

132
00:06:12,780 --> 00:06:15,390
to get to yes, because of the EOL date,

133
00:06:15,390 --> 00:06:17,340
but you know there's really
a better answer here.

134
00:06:17,340 --> 00:06:19,830
It's not just because it's end of life.

135
00:06:19,830 --> 00:06:21,060
What else do we know?

136
00:06:21,060 --> 00:06:23,430
We said that the EOL was five years

137
00:06:23,430 --> 00:06:25,980
and the EOS was an additional five years.

138
00:06:25,980 --> 00:06:29,010
So it was released in 2011, right?

139
00:06:29,010 --> 00:06:32,070
So 2011 plus five, 2016, right?

140
00:06:32,070 --> 00:06:36,600
It's gonna be EOL, and another
five years, 2021, right?

141
00:06:36,600 --> 00:06:38,250
It reached its end of support.

142
00:06:38,250 --> 00:06:39,900
And what do we know about end of support

143
00:06:39,900 --> 00:06:41,850
that makes it so dangerous?

144
00:06:41,850 --> 00:06:45,330
Well, how about the
answer that says, "Yes,

145
00:06:45,330 --> 00:06:47,910
because updates and security patches

146
00:06:47,910 --> 00:06:49,890
are no longer available."

147
00:06:49,890 --> 00:06:51,660
So just reaching the end of life date,

148
00:06:51,660 --> 00:06:53,220
well, that is an issue, right?

149
00:06:53,220 --> 00:06:55,170
For features and functionalities,

150
00:06:55,170 --> 00:06:57,030
but it's not as much a security issue,

151
00:06:57,030 --> 00:06:59,250
because we're still getting our support,

152
00:06:59,250 --> 00:07:00,483
including our patches.

153
00:07:01,477 --> 00:07:03,450
"No, because the software's
working as intended."

154
00:07:03,450 --> 00:07:04,530
Well, it might be,

155
00:07:04,530 --> 00:07:06,720
but now that software
is vulnerable, right?

156
00:07:06,720 --> 00:07:09,900
And we have really opened
up an attack surface,

157
00:07:09,900 --> 00:07:12,150
and, "No, because there
appears to be no need

158
00:07:12,150 --> 00:07:13,530
for supportive maintenance."

159
00:07:13,530 --> 00:07:15,300
Well, the product might be working great.

160
00:07:15,300 --> 00:07:17,940
That's what the department manager said,

161
00:07:17,940 --> 00:07:20,130
but the department manager
probably doesn't realize

162
00:07:20,130 --> 00:07:23,970
the implications of
having vulnerable software

163
00:07:23,970 --> 00:07:26,010
being exposed in your environment.

164
00:07:26,010 --> 00:07:28,740
So we're going with, "Yes, because updates

165
00:07:28,740 --> 00:07:31,680
and security patches are
no longer available."

166
00:07:31,680 --> 00:07:32,880
Agree?

167
00:07:32,880 --> 00:07:34,680
All right, well, let's check it out.

168
00:07:35,520 --> 00:07:36,693
And that is correct.

169
00:07:38,220 --> 00:07:40,117
All right, our last question.

170
00:07:40,117 --> 00:07:43,350
"Your company's Revenue
Service requires tax records

171
00:07:43,350 --> 00:07:45,810
to be kept for seven years.

172
00:07:45,810 --> 00:07:48,330
How would this best be codified?

173
00:07:48,330 --> 00:07:52,170
Legal hold documentation,
a data backup policy,

174
00:07:52,170 --> 00:07:56,637
a data archiving strategy, or
a data retention strategy?"

175
00:07:58,200 --> 00:08:00,090
Your country's Revenue
Service says you've gotta

176
00:08:00,090 --> 00:08:02,313
keep tax records for seven years.

177
00:08:03,270 --> 00:08:06,900
The next line says, "How is
this best gonna be codified?"

178
00:08:06,900 --> 00:08:09,000
Now, that's important that
you read this correctly,

179
00:08:09,000 --> 00:08:12,903
because it doesn't say, how
would this best be accomplished?

180
00:08:13,770 --> 00:08:16,080
It says, "How would
this best be codified?"

181
00:08:16,080 --> 00:08:18,240
How would you document this, right?

182
00:08:18,240 --> 00:08:20,370
How would you communicate this?

183
00:08:20,370 --> 00:08:23,490
Legal hold documentation,
a data backup policy,

184
00:08:23,490 --> 00:08:27,780
a data archiving strategy,
or a data retention strategy?

185
00:08:27,780 --> 00:08:28,630
What do you like?

186
00:08:31,080 --> 00:08:33,360
Well, I'm gonna choose
data retention strategy,

187
00:08:33,360 --> 00:08:34,500
and here's why.

188
00:08:34,500 --> 00:08:37,410
A retention strategy would be our policy

189
00:08:37,410 --> 00:08:41,250
or our set of rules about
what we're going to keep,

190
00:08:41,250 --> 00:08:42,480
what we're gonna archive.

191
00:08:42,480 --> 00:08:45,390
So we would be saying, in
this case, we have a rule

192
00:08:45,390 --> 00:08:46,500
is that for seven years,

193
00:08:46,500 --> 00:08:48,660
we are going to keep our tax records.

194
00:08:48,660 --> 00:08:50,790
It wouldn't be legal hold documentation,

195
00:08:50,790 --> 00:08:53,010
because we haven't received a legal hold.

196
00:08:53,010 --> 00:08:54,750
It's not our data backup policy,

197
00:08:54,750 --> 00:08:57,720
because retention archiving
is totally different

198
00:08:57,720 --> 00:08:58,553
than data backup.

199
00:08:58,553 --> 00:09:00,300
Remember, data backup just backs up

200
00:09:00,300 --> 00:09:01,650
what's ever in production,

201
00:09:01,650 --> 00:09:04,620
so it could be backing up modified files,

202
00:09:04,620 --> 00:09:07,080
and it's not our archiving strategy.

203
00:09:07,080 --> 00:09:09,750
Our archiving strategy is how we're doing

204
00:09:09,750 --> 00:09:10,950
the archiving, right?

205
00:09:10,950 --> 00:09:12,390
How are we making that happen?

206
00:09:12,390 --> 00:09:15,120
That would really be the implementation.

207
00:09:15,120 --> 00:09:17,550
So archiving is the implementation

208
00:09:17,550 --> 00:09:19,860
of our data retention strategy.

209
00:09:19,860 --> 00:09:22,950
So I'm going with data retention strategy,

210
00:09:22,950 --> 00:09:24,750
and I'm sticking with that answer.

211
00:09:24,750 --> 00:09:25,770
You agree?

212
00:09:25,770 --> 00:09:27,480
All right, let's try it out.

213
00:09:27,480 --> 00:09:28,713
And that is correct.

214
00:09:30,060 --> 00:09:32,550
Another great job, congratulations.

215
00:09:32,550 --> 00:09:35,010
Up next, we're gonna go into Lesson 16,

216
00:09:35,010 --> 00:09:37,020
which is explain Various Activities

217
00:09:37,020 --> 00:09:39,210
Associated with Vulnerability Management.

218
00:09:39,210 --> 00:09:40,043
You ready?

219
00:09:40,043 --> 00:09:41,150
Okay, I'll see you there.
