1
00:00:06,480 --> 00:00:08,190
- Welcome to Lesson 19:

2
00:00:08,190 --> 00:00:09,240
Given a Scenario,

3
00:00:09,240 --> 00:00:13,230
Implement and Maintain
Identity and Access Management.

4
00:00:13,230 --> 00:00:15,120
In this Lesson 19.1,

5
00:00:15,120 --> 00:00:18,420
we're gonna focus in on
identity and access management,

6
00:00:18,420 --> 00:00:19,803
also known as IAM.

7
00:00:20,730 --> 00:00:23,400
Now, your identity is who you say you are.

8
00:00:23,400 --> 00:00:25,320
I say I'm Siri Green.

9
00:00:25,320 --> 00:00:28,080
Identity proofing is the process

10
00:00:28,080 --> 00:00:32,880
of verifying and validating an
individual's claimed identity

11
00:00:32,880 --> 00:00:34,950
to establish their trustworthiness

12
00:00:34,950 --> 00:00:38,043
and to ensure that they
are who they say they are.

13
00:00:39,180 --> 00:00:42,900
Now, identity proofing involves
confirming the authenticity

14
00:00:42,900 --> 00:00:45,900
and the accuracy of personal information

15
00:00:45,900 --> 00:00:49,890
provided by an individual
during the account registration

16
00:00:49,890 --> 00:00:52,410
or during the user onboarding process.

17
00:00:52,410 --> 00:00:53,970
Now, that might be a driver's license,

18
00:00:53,970 --> 00:00:55,470
that might be a passport.

19
00:00:55,470 --> 00:00:57,810
Think of all the ways
that we identify ourselves

20
00:00:57,810 --> 00:00:59,910
within the physical world.

21
00:00:59,910 --> 00:01:02,430
Identity proofing is also a component

22
00:01:02,430 --> 00:01:05,370
of fraud and identity theft prevention.

23
00:01:05,370 --> 00:01:06,783
And in some cases,

24
00:01:06,783 --> 00:01:10,323
identity proofing may be
a compliance requirement.

25
00:01:12,300 --> 00:01:15,660
Now, identity and access
management, known as IAM,

26
00:01:15,660 --> 00:01:17,310
is a business process.

27
00:01:17,310 --> 00:01:21,090
It's the business process of
enabling the right individuals

28
00:01:21,090 --> 00:01:23,250
to access the right resources

29
00:01:23,250 --> 00:01:26,553
at the right time for the right reasons.

30
00:01:28,110 --> 00:01:30,960
Now, IAM functions include provisioning,

31
00:01:30,960 --> 00:01:34,920
educating, auditing, and deprovisioning.

32
00:01:34,920 --> 00:01:36,180
Now, provisioning is a process

33
00:01:36,180 --> 00:01:38,790
of creating and managing
digital identities.

34
00:01:38,790 --> 00:01:40,530
Deprovisioning is the process

35
00:01:40,530 --> 00:01:43,950
of removing and deleting
digital identities.

36
00:01:43,950 --> 00:01:45,990
Now, IAM functions take place

37
00:01:45,990 --> 00:01:48,300
throughout the entire employee lifecycle,

38
00:01:48,300 --> 00:01:51,060
and we're gonna be taking a
look at that in just a moment.

39
00:01:51,060 --> 00:01:52,200
Now, IAM functions

40
00:01:52,200 --> 00:01:55,650
are very, very much a
shared responsibility,

41
00:01:55,650 --> 00:02:00,180
shared by managers, owners, HR, IT,

42
00:02:00,180 --> 00:02:04,353
physical security, information
security, and audit.

43
00:02:06,330 --> 00:02:09,810
So let's take a big picture
look at the identity lifecycle.

44
00:02:09,810 --> 00:02:11,850
Someone is coming into your company.

45
00:02:11,850 --> 00:02:13,860
Now, I used the term employee earlier,

46
00:02:13,860 --> 00:02:14,940
and they're probably an employee,

47
00:02:14,940 --> 00:02:17,250
but they could be a
consultant or contractor

48
00:02:17,250 --> 00:02:19,293
that's placed in your organization.

49
00:02:20,340 --> 00:02:21,600
So we have phase one,

50
00:02:21,600 --> 00:02:24,210
and that's when someone is
first joining your organization.

51
00:02:24,210 --> 00:02:26,520
So we're going through
the onboarding process,

52
00:02:26,520 --> 00:02:27,930
the account request,

53
00:02:27,930 --> 00:02:31,320
the user agreement, and
credential management.

54
00:02:31,320 --> 00:02:34,470
In phase two, this is where
they have authorization

55
00:02:34,470 --> 00:02:37,200
to access different resources.

56
00:02:37,200 --> 00:02:38,880
This is where the actual assignment

57
00:02:38,880 --> 00:02:40,650
of rights and permissions happen,

58
00:02:40,650 --> 00:02:41,483
and of course,

59
00:02:41,483 --> 00:02:43,750
we're going to continue
with our user training.

60
00:02:44,820 --> 00:02:48,480
In phase three, this is the
bulk of the identity lifecycle.

61
00:02:48,480 --> 00:02:51,270
This is where someone
is in your organization.

62
00:02:51,270 --> 00:02:53,280
They may stay at the same
job for a very long time,

63
00:02:53,280 --> 00:02:56,640
or they may change roles, so
there may be change requests,

64
00:02:56,640 --> 00:02:59,040
and this is where auditing
is going to take place,

65
00:02:59,040 --> 00:03:02,100
user account auditing
and user access auditing,

66
00:03:02,100 --> 00:03:03,300
as well as we're gonna continue

67
00:03:03,300 --> 00:03:06,090
right down the path of our user training.

68
00:03:06,090 --> 00:03:07,200
And then lastly,

69
00:03:07,200 --> 00:03:09,510
we get to the end of
the identity lifecycle,

70
00:03:09,510 --> 00:03:10,530
and this is when

71
00:03:10,530 --> 00:03:12,720
someone is going to be
leaving your organization.

72
00:03:12,720 --> 00:03:15,120
So they're terminating, could
be friendly or unfriendly,

73
00:03:15,120 --> 00:03:17,010
and we're going to offboard them,

74
00:03:17,010 --> 00:03:19,020
and we're going to have to
do all of the activities

75
00:03:19,020 --> 00:03:24,020
to kind of reclaim any access
that we had had given to them.

76
00:03:24,750 --> 00:03:26,040
So we're gonna go a little bit deeper

77
00:03:26,040 --> 00:03:27,630
into each one of these phases,

78
00:03:27,630 --> 00:03:31,023
phase one, phase two, phase
three, and phase four.

79
00:03:32,490 --> 00:03:34,980
So in phase one, we said the
key tasks were onboarding,

80
00:03:34,980 --> 00:03:37,740
account request, user agreement,
and credential management,

81
00:03:37,740 --> 00:03:39,240
so what does that all mean?

82
00:03:39,240 --> 00:03:41,220
Well, first, we have an
account creation request.

83
00:03:41,220 --> 00:03:43,260
We've brought somebody
into our organization

84
00:03:43,260 --> 00:03:45,210
and we have to say we
need accounts for them,

85
00:03:45,210 --> 00:03:47,580
and that request may come from HR

86
00:03:47,580 --> 00:03:49,770
or it may come from a business unit.

87
00:03:49,770 --> 00:03:51,570
Then there are going to be user agreements

88
00:03:51,570 --> 00:03:52,470
that need to be signed

89
00:03:52,470 --> 00:03:54,930
before they have access to our systems.

90
00:03:54,930 --> 00:03:56,940
Probably an acceptable
use policy agreement,

91
00:03:56,940 --> 00:03:59,460
and perhaps an NDA
Confidentiality agreement,

92
00:03:59,460 --> 00:04:01,770
and we'll talk more about
both of those agreements

93
00:04:01,770 --> 00:04:03,270
a little bit later on.

94
00:04:03,270 --> 00:04:04,560
User accounts are created

95
00:04:04,560 --> 00:04:07,350
and group or role
membership is established.

96
00:04:07,350 --> 00:04:08,550
What groups do they need to be in

97
00:04:08,550 --> 00:04:10,530
or what roles do they need to be in?

98
00:04:10,530 --> 00:04:12,240
Credentials will be assigned

99
00:04:12,240 --> 00:04:14,640
and security clearance, if appropriate,

100
00:04:14,640 --> 00:04:17,820
and then authentication
assets will be distributed.

101
00:04:17,820 --> 00:04:21,120
Now, that could be a token,
a smart card, a certificate,

102
00:04:21,120 --> 00:04:23,220
could be biometric enrollment.

103
00:04:23,220 --> 00:04:25,410
And then we're gonna have
orientation training.

104
00:04:25,410 --> 00:04:27,660
Now, orientation training
will go hand in hand

105
00:04:27,660 --> 00:04:29,100
with these user agreements,

106
00:04:29,100 --> 00:04:31,500
so they understand what they're signing

107
00:04:31,500 --> 00:04:33,480
and what the expectations are.

108
00:04:33,480 --> 00:04:35,040
But in my experience,

109
00:04:35,040 --> 00:04:38,100
orientation training
doesn't stick with anybody.

110
00:04:38,100 --> 00:04:40,230
First couple of days
that somebody's on a job,

111
00:04:40,230 --> 00:04:41,190
they're really just busy

112
00:04:41,190 --> 00:04:43,260
kind of remembering everybody's name

113
00:04:43,260 --> 00:04:44,970
and where the restrooms are,

114
00:04:44,970 --> 00:04:46,920
and figuring out when payday is.

115
00:04:46,920 --> 00:04:48,960
So what you tell someone
during orientation,

116
00:04:48,960 --> 00:04:51,010
never assume that they're gonna remember.

117
00:04:52,890 --> 00:04:54,420
Then we get into phase two

118
00:04:54,420 --> 00:04:56,730
in our key tasks for authorization,

119
00:04:56,730 --> 00:04:58,530
assignment of rights and permissions

120
00:04:58,530 --> 00:05:00,210
and user training again.

121
00:05:00,210 --> 00:05:02,310
Now, authorization is going to be granted

122
00:05:02,310 --> 00:05:04,980
by a data or resource owners,

123
00:05:04,980 --> 00:05:06,120
or in some cases,

124
00:05:06,120 --> 00:05:08,850
we'll have to have need
to know being established.

125
00:05:08,850 --> 00:05:11,220
Now, rights and permissions are assigned

126
00:05:11,220 --> 00:05:13,800
by the data or the resource custodian.

127
00:05:13,800 --> 00:05:15,990
Remember, custodians are those who manage,

128
00:05:15,990 --> 00:05:19,830
monitor, implement, advise, educate,

129
00:05:19,830 --> 00:05:22,620
but the custodians aren't
making the decisions

130
00:05:22,620 --> 00:05:24,360
about rights and permissions, right?

131
00:05:24,360 --> 00:05:27,960
Rights and permissions came
from the data or resource owner,

132
00:05:27,960 --> 00:05:29,940
or in terms of need to know,

133
00:05:29,940 --> 00:05:31,800
if you were in a MAC environment.

134
00:05:31,800 --> 00:05:34,440
And then we're gonna continue
with our user training,

135
00:05:34,440 --> 00:05:36,090
and here we're gonna wanna repeat

136
00:05:36,090 --> 00:05:37,980
everything we said in orientation,

137
00:05:37,980 --> 00:05:41,490
plus, we're really going to
wanna get them to understand

138
00:05:41,490 --> 00:05:45,693
our security and privacy
requirements and expectations.

139
00:05:47,940 --> 00:05:49,470
So then we get to phase three,

140
00:05:49,470 --> 00:05:51,810
and our key tasks are
user account auditing,

141
00:05:51,810 --> 00:05:55,350
user access auditing,
change request submissions,

142
00:05:55,350 --> 00:05:59,010
change request auditing,
and user training.

143
00:05:59,010 --> 00:06:00,000
So in this phase,

144
00:06:00,000 --> 00:06:02,730
this is where user accounts
are going to be audited

145
00:06:02,730 --> 00:06:04,530
to make sure they're still valid.

146
00:06:04,530 --> 00:06:06,330
Do they still need to have an account

147
00:06:06,330 --> 00:06:09,510
for that particular operating
system or application?

148
00:06:09,510 --> 00:06:12,090
And we're not just looking
internally or on premises,

149
00:06:12,090 --> 00:06:14,400
we're also looking at do
they still need the account

150
00:06:14,400 --> 00:06:15,420
at a business partner,

151
00:06:15,420 --> 00:06:16,920
or do they still need the account

152
00:06:16,920 --> 00:06:19,320
in a cloud-based application?

153
00:06:19,320 --> 00:06:22,200
Now, if someone hasn't logged
in for a long period of time

154
00:06:22,200 --> 00:06:23,790
and we were looking through the accounts,

155
00:06:23,790 --> 00:06:26,970
we would refer to that as a stale account.

156
00:06:26,970 --> 00:06:29,940
Now, in addition to looking
at do they need an account,

157
00:06:29,940 --> 00:06:31,050
we're also gonna say,

158
00:06:31,050 --> 00:06:33,510
do they need to be a member
of a particular group still?

159
00:06:33,510 --> 00:06:36,120
Do they need to be part of a role, right?

160
00:06:36,120 --> 00:06:38,880
Do they still need these
same access permissions?

161
00:06:38,880 --> 00:06:41,370
And we wanna do this on a regular basis,

162
00:06:41,370 --> 00:06:43,260
generally at least an annual basis.

163
00:06:43,260 --> 00:06:46,380
Now, user access is also auditing.

164
00:06:46,380 --> 00:06:47,640
Now, what we're looking at here

165
00:06:47,640 --> 00:06:49,770
is what someone has permissions to do,

166
00:06:49,770 --> 00:06:51,510
but perhaps shouldn't be doing.

167
00:06:51,510 --> 00:06:53,070
Let me give you a couple of examples.

168
00:06:53,070 --> 00:06:56,640
So perhaps someone is streaming
movies during the day,

169
00:06:56,640 --> 00:06:57,570
and what we notice

170
00:06:57,570 --> 00:06:59,700
is that they're chewing
up a lot of bandwidth.

171
00:06:59,700 --> 00:07:02,070
Now, they had permission
to go to the internet,

172
00:07:02,070 --> 00:07:03,930
but certainly not to be streaming movies

173
00:07:03,930 --> 00:07:06,000
and to be chewing up bandwidth.

174
00:07:06,000 --> 00:07:08,670
Another example would be in a hospital.

175
00:07:08,670 --> 00:07:11,820
On a hospital floor, all
the clinicians have access

176
00:07:11,820 --> 00:07:14,070
to the patient records
that are on that floor.

177
00:07:14,070 --> 00:07:16,440
That's important for emergency reasons,

178
00:07:16,440 --> 00:07:18,660
but perhaps there's a
policy at the hospital

179
00:07:18,660 --> 00:07:23,660
that says if a patient is a
family member or marked as VIP,

180
00:07:24,510 --> 00:07:27,630
you can't access a record
or shouldn't access a record

181
00:07:27,630 --> 00:07:29,460
unless you're involved in direct care.

182
00:07:29,460 --> 00:07:31,020
So we could be looking
for things like that.

183
00:07:31,020 --> 00:07:34,192
Did you access a record
that you shouldn't have?

184
00:07:34,192 --> 00:07:36,540
Now, change requests are
going to be submitted

185
00:07:36,540 --> 00:07:39,000
all during the identity lifecycle

186
00:07:39,000 --> 00:07:41,040
'cause people move from one job to another

187
00:07:41,040 --> 00:07:43,140
or they need a different
set of permissions.

188
00:07:43,140 --> 00:07:46,500
So those change requests are
going to be audited as well.

189
00:07:46,500 --> 00:07:49,980
And then we're gonna continue
with our user training.

190
00:07:49,980 --> 00:07:52,920
Now, user training really falls
into one of three buckets,

191
00:07:52,920 --> 00:07:55,320
education, training, and awareness,

192
00:07:55,320 --> 00:07:58,050
and in the security world,
we refer to that as SETA,

193
00:07:58,050 --> 00:08:00,120
Security Education Training and Awareness.

194
00:08:00,120 --> 00:08:03,510
And in our very last
lesson in this course,

195
00:08:03,510 --> 00:08:05,970
we're gonna dive deep into
what do we mean by SETA,

196
00:08:05,970 --> 00:08:07,590
Security Education and Training?

197
00:08:07,590 --> 00:08:09,330
But for now, really just keep in mind

198
00:08:09,330 --> 00:08:13,080
that we wanna continue
educating and training

199
00:08:13,080 --> 00:08:15,060
and having our users aware,

200
00:08:15,060 --> 00:08:18,093
contextually aware of security threats.

201
00:08:20,137 --> 00:08:22,680
Let's talk a little bit
more about change requests.

202
00:08:22,680 --> 00:08:25,320
Now, change requests
are the formal process

203
00:08:25,320 --> 00:08:28,890
to request, to revoke, or modify access

204
00:08:28,890 --> 00:08:30,660
when a user's status changes

205
00:08:30,660 --> 00:08:34,170
through transfer,
resignation, or termination.

206
00:08:34,170 --> 00:08:38,460
So transfer to a new job,
they leave, they terminate.

207
00:08:38,460 --> 00:08:41,220
Authorization creep's
an interesting concept.

208
00:08:41,220 --> 00:08:44,130
Authorization creep is the accumulation

209
00:08:44,130 --> 00:08:48,210
of unnecessary rights and
permissions over time.

210
00:08:48,210 --> 00:08:50,040
Now, why do we have authorization creep?

211
00:08:50,040 --> 00:08:52,800
Promotions, lateral moves, cross-training,

212
00:08:52,800 --> 00:08:54,210
and temporary coverage

213
00:08:54,210 --> 00:08:56,280
all contribute to authorization creep,

214
00:08:56,280 --> 00:08:59,520
and it happens because people
move from one job to another,

215
00:08:59,520 --> 00:09:02,250
and very often, when
they move to a new job,

216
00:09:02,250 --> 00:09:04,080
they need their new
rights and permissions,

217
00:09:04,080 --> 00:09:06,840
but maybe they're still
covering the old job

218
00:09:06,840 --> 00:09:09,210
or maybe they're training
their replacement,

219
00:09:09,210 --> 00:09:12,780
so they get the new job and
the new rights and permissions,

220
00:09:12,780 --> 00:09:14,700
but they still have the
old rights and permissions,

221
00:09:14,700 --> 00:09:16,200
and then no one goes back

222
00:09:16,200 --> 00:09:18,330
and gets rid of those old
rights and permissions,

223
00:09:18,330 --> 00:09:20,100
and that continues on and on and on.

224
00:09:20,100 --> 00:09:22,710
And that's where the change
request auditing comes in,

225
00:09:22,710 --> 00:09:24,150
and says, "Okay, we can see

226
00:09:24,150 --> 00:09:26,070
you gave them the new
rights and permissions,

227
00:09:26,070 --> 00:09:27,240
but oh, look,

228
00:09:27,240 --> 00:09:29,520
you didn't take away the
old rights and permissions."

229
00:09:29,520 --> 00:09:32,943
So we're really trying not
to have authorization creep.

230
00:09:34,747 --> 00:09:37,620
Now we get to phase four,
and that's our termination.

231
00:09:37,620 --> 00:09:38,453
That's when somebody

232
00:09:38,453 --> 00:09:40,200
is going to be leaving our organization.

233
00:09:40,200 --> 00:09:42,450
That could be friendly or an unfriendly.

234
00:09:42,450 --> 00:09:44,550
It could be they could be
being fired, they could resign,

235
00:09:44,550 --> 00:09:46,650
they could be being laid off.

236
00:09:46,650 --> 00:09:49,410
You know, it could be just time to go,

237
00:09:49,410 --> 00:09:51,090
so it's termination.

238
00:09:51,090 --> 00:09:52,680
And offboarding is the process

239
00:09:52,680 --> 00:09:55,800
of having them sort of
leave our organization.

240
00:09:55,800 --> 00:09:59,400
Now, termination tasks include
reclaiming physical assets,

241
00:09:59,400 --> 00:10:00,780
like a smartphone,

242
00:10:00,780 --> 00:10:04,320
and access control assets, like a token,

243
00:10:04,320 --> 00:10:07,440
disabling and removing
accounts and access,

244
00:10:07,440 --> 00:10:09,420
both internal and external,

245
00:10:09,420 --> 00:10:10,980
and I can't stress external enough.

246
00:10:10,980 --> 00:10:14,280
We have to remember that we
need to disable those accounts

247
00:10:14,280 --> 00:10:15,600
or delete those accounts

248
00:10:15,600 --> 00:10:18,240
at partners and everywhere in the cloud

249
00:10:18,240 --> 00:10:19,410
where they may have an account

250
00:10:19,410 --> 00:10:21,900
associated with our organization.

251
00:10:21,900 --> 00:10:24,600
We want to archive any documents they had,

252
00:10:24,600 --> 00:10:29,370
maybe archive their email so
that we have them later on.

253
00:10:29,370 --> 00:10:31,560
And then off-boarding tasks include

254
00:10:31,560 --> 00:10:35,940
reassigning file and folder
permissions and ownership.

255
00:10:35,940 --> 00:10:37,860
We're going to probably
do an exit interview,

256
00:10:37,860 --> 00:10:39,810
and at the very least,
what we should be doing

257
00:10:39,810 --> 00:10:42,690
is reminding users of any agreements

258
00:10:42,690 --> 00:10:44,610
that extend beyond employment.

259
00:10:44,610 --> 00:10:46,290
So for example, confidentiality

260
00:10:46,290 --> 00:10:48,540
or non-disclosure agreement, an NDA,

261
00:10:48,540 --> 00:10:52,740
very often will extend
beyond the employment period.

262
00:10:52,740 --> 00:10:55,590
It will go on for X number of years.

263
00:10:55,590 --> 00:10:59,823
So those are the four phases
in the identity lifecycle.

264
00:11:01,440 --> 00:11:03,720
That, my friends, brings us
to a three-second challenge.

265
00:11:03,720 --> 00:11:05,760
Five challenge questions,
three seconds each.

266
00:11:05,760 --> 00:11:07,380
You know what to do.

267
00:11:07,380 --> 00:11:08,790
Challenge question one,

268
00:11:08,790 --> 00:11:12,420
the process of creating and
managing digital identities.

269
00:11:12,420 --> 00:11:14,193
One, two, three.

270
00:11:15,180 --> 00:11:17,340
That's gonna be provisioning.

271
00:11:17,340 --> 00:11:21,630
Number two, confirming the
authenticity and the accuracy

272
00:11:21,630 --> 00:11:25,950
of the personal information
provided by an individual.

273
00:11:25,950 --> 00:11:27,393
One, two, three.

274
00:11:29,610 --> 00:11:31,173
It's identity proofing.

275
00:11:32,070 --> 00:11:36,270
Number three, an account
that's no longer being used.

276
00:11:36,270 --> 00:11:37,830
What's that called?

277
00:11:37,830 --> 00:11:39,453
One, two, three.

278
00:11:40,350 --> 00:11:42,063
That's a stale account.

279
00:11:43,680 --> 00:11:46,320
Number four, the accumulation

280
00:11:46,320 --> 00:11:49,413
of unnecessary rights and
permissions over time.

281
00:11:50,400 --> 00:11:51,783
One, two, three.

282
00:11:52,950 --> 00:11:54,903
That's gonna be authorization creep.

283
00:11:56,340 --> 00:11:59,310
And number five, when management validates

284
00:11:59,310 --> 00:12:02,880
that rights and permissions
assignments are correct.

285
00:12:02,880 --> 00:12:04,680
You know, I don't think
I gave you this term,

286
00:12:04,680 --> 00:12:06,630
so I'm gonna give it to you now.

287
00:12:06,630 --> 00:12:09,480
We wanna make sure that
on an a regular basis,

288
00:12:09,480 --> 00:12:12,457
maybe an annual basis,
that management is saying,

289
00:12:12,457 --> 00:12:15,270
"Yes, those rights and
permissions are correct."

290
00:12:15,270 --> 00:12:18,060
That process is called recertification

291
00:12:18,060 --> 00:12:19,953
or access attestation.

292
00:12:21,150 --> 00:12:24,390
So recertification or access attestation.

293
00:12:24,390 --> 00:12:25,223
Now you have it.

294
00:12:26,340 --> 00:12:28,560
So let's do a security-in-action together.

295
00:12:28,560 --> 00:12:31,020
This is about IAM auditing.

296
00:12:31,020 --> 00:12:34,560
Now, a member of the Human
Resources staff was terminated

297
00:12:34,560 --> 00:12:37,650
because he accessed
management payroll records

298
00:12:37,650 --> 00:12:39,450
and then bragged about it.

299
00:12:39,450 --> 00:12:42,270
Now, obviously this is
a violation of trust.

300
00:12:42,270 --> 00:12:45,930
Management faulted the HR
Director for her lack of oversight

301
00:12:45,930 --> 00:12:48,780
and charged her with
cleaning up this mess.

302
00:12:48,780 --> 00:12:51,870
Now, her first response was
to bring in an audit team

303
00:12:51,870 --> 00:12:55,110
to review payroll
application accessibility.

304
00:12:55,110 --> 00:12:56,797
And she's come to you and said,

305
00:12:56,797 --> 00:12:58,860
"Can you help me define the audit scope?

306
00:12:58,860 --> 00:12:59,700
In other words,

307
00:12:59,700 --> 00:13:02,400
what do I need the
auditors to be looking at?"

308
00:13:02,400 --> 00:13:05,640
So the question to you
is, what did you include?

309
00:13:05,640 --> 00:13:08,940
So quick recap, we had a
member of the HR staff.

310
00:13:08,940 --> 00:13:10,290
They were terminated

311
00:13:10,290 --> 00:13:13,080
because they accessed
management payroll records

312
00:13:13,080 --> 00:13:16,530
and then for some reason
decided to brag about it.

313
00:13:16,530 --> 00:13:18,390
So HR Director gets blamed.

314
00:13:18,390 --> 00:13:21,600
She brings in audit, good idea, right,

315
00:13:21,600 --> 00:13:25,020
to review the payroll
application accessibility,

316
00:13:25,020 --> 00:13:26,160
but she wants to make sure

317
00:13:26,160 --> 00:13:28,650
that everything that should
be included is included,

318
00:13:28,650 --> 00:13:30,360
and comes to you for advice.

319
00:13:30,360 --> 00:13:32,070
What are you gonna include?

320
00:13:32,070 --> 00:13:33,750
Go ahead and put me on
pause, think about that,

321
00:13:33,750 --> 00:13:35,400
jot down some notes, and then come back,

322
00:13:35,400 --> 00:13:37,250
and we'll go through the audit scope.

323
00:13:39,450 --> 00:13:41,280
Well, the audit focus really needs to be

324
00:13:41,280 --> 00:13:44,626
on who can access the payroll application,

325
00:13:44,626 --> 00:13:48,420
what they can do, including
data exfiltration,

326
00:13:48,420 --> 00:13:50,610
and what they are doing.

327
00:13:50,610 --> 00:13:52,230
So really three parts there, right?

328
00:13:52,230 --> 00:13:56,190
Who has rights to access
it, what they can do,

329
00:13:56,190 --> 00:13:57,660
so including, right,

330
00:13:57,660 --> 00:14:01,230
being able to maybe save
things to an Excel file, right?

331
00:14:01,230 --> 00:14:04,200
Save payroll records to an Excel file

332
00:14:04,200 --> 00:14:06,270
and then maybe exfiltrate that,

333
00:14:06,270 --> 00:14:08,460
and then what they really are doing.

334
00:14:08,460 --> 00:14:10,680
Those are the three components.

335
00:14:10,680 --> 00:14:12,750
Now, the audit scope should include

336
00:14:12,750 --> 00:14:15,870
who has explicit and implicit access

337
00:14:15,870 --> 00:14:17,970
and their assigned permissions.

338
00:14:17,970 --> 00:14:19,560
So implicit and explicit.

339
00:14:19,560 --> 00:14:22,110
Either we've assigned it to them directly

340
00:14:22,110 --> 00:14:23,280
or they have an assignment

341
00:14:23,280 --> 00:14:27,330
because they are part of a
group or they are in a role,

342
00:14:27,330 --> 00:14:29,610
and what their assigned permissions are.

343
00:14:29,610 --> 00:14:32,643
And we wanna look back over
a specific period of time.

344
00:14:33,561 --> 00:14:35,910
We also wanna look at change histories,

345
00:14:35,910 --> 00:14:38,040
so what's been granted and removed,

346
00:14:38,040 --> 00:14:39,753
and has that been done correctly?

347
00:14:40,920 --> 00:14:42,540
We wanna look at the activity.

348
00:14:42,540 --> 00:14:44,490
How are they using the application?

349
00:14:44,490 --> 00:14:46,533
What are they actually doing?

350
00:14:47,760 --> 00:14:50,924
So we just do an activity sample over time

351
00:14:50,924 --> 00:14:53,670
and a review of past events.

352
00:14:53,670 --> 00:14:56,880
So if there's any suspicion,
a review of past events,

353
00:14:56,880 --> 00:14:59,280
and that would be awesome if
there's any logs available,

354
00:14:59,280 --> 00:15:03,510
to be able to go back and see
what they've done over time.

355
00:15:03,510 --> 00:15:05,850
Now, if this application can log,

356
00:15:05,850 --> 00:15:08,220
and there haven't been any logs to date,

357
00:15:08,220 --> 00:15:10,800
this is a great time to start logging.

358
00:15:10,800 --> 00:15:12,720
And that would be the audit scope

359
00:15:12,720 --> 00:15:14,700
to try to figure out what's going on

360
00:15:14,700 --> 00:15:17,970
and try to prevent this from
happening again in the future

361
00:15:17,970 --> 00:15:19,260
by having the right

362
00:15:19,260 --> 00:15:22,380
or having the correct
rights and permissions.

363
00:15:22,380 --> 00:15:24,573
Doing that, my friends,
security-in-action.

364
00:15:25,560 --> 00:15:27,390
There's your word cloud.

365
00:15:27,390 --> 00:15:28,380
You know what to do.

366
00:15:28,380 --> 00:15:30,780
When you're ready, I'll
see you the next lesson.
