1
00:00:06,420 --> 00:00:08,610
- Now, in this Lesson 19.5,

2
00:00:08,610 --> 00:00:12,573
we're gonna focus in on access
control and authorization.

3
00:00:13,410 --> 00:00:16,050
Now, access control is a security process

4
00:00:16,050 --> 00:00:18,450
that enables organizations to manage,

5
00:00:18,450 --> 00:00:21,420
well, who's authorized to
access data and resources

6
00:00:21,420 --> 00:00:23,283
and what they're allowed to do.

7
00:00:24,120 --> 00:00:25,680
Now, physical access control

8
00:00:25,680 --> 00:00:29,730
focuses on facilities,
equipment, devices, and paper,

9
00:00:29,730 --> 00:00:32,850
where logical access
control focuses on systems,

10
00:00:32,850 --> 00:00:35,523
applications, and data.

11
00:00:36,480 --> 00:00:38,940
Now, what's so interesting
over the last couple of years

12
00:00:38,940 --> 00:00:42,570
is that we've really seen an
access control convergence,

13
00:00:42,570 --> 00:00:44,640
a convergence of information security

14
00:00:44,640 --> 00:00:46,800
and physical security controls,

15
00:00:46,800 --> 00:00:50,100
because they really do have
the same primary objective,

16
00:00:50,100 --> 00:00:54,834
which is to protect organizational
assets and personnel.

17
00:00:54,834 --> 00:00:57,780
Now, often there's a a
really significant overlap

18
00:00:57,780 --> 00:01:00,120
in the technologies and in controls.

19
00:01:00,120 --> 00:01:02,850
And an example would be an access card

20
00:01:02,850 --> 00:01:04,710
that's used to both enter a building

21
00:01:04,710 --> 00:01:06,930
and to log into the network.

22
00:01:06,930 --> 00:01:09,180
So there's this emerging convergence model

23
00:01:09,180 --> 00:01:10,470
that we talked about earlier on

24
00:01:10,470 --> 00:01:12,540
when we talked about physical security

25
00:01:12,540 --> 00:01:16,500
that really demands
communication and coordination

26
00:01:16,500 --> 00:01:18,360
between the two disciplines.

27
00:01:18,360 --> 00:01:22,140
And in a best case scenario,
the departments participate

28
00:01:22,140 --> 00:01:25,650
in the same management
and reporting structure.

29
00:01:25,650 --> 00:01:28,050
So let's talk about
rights and permissions.

30
00:01:28,050 --> 00:01:28,883
You know, it's interesting.

31
00:01:28,883 --> 00:01:31,350
So often, the terms rights and permissions

32
00:01:31,350 --> 00:01:35,130
are are used interchangeably,
but they're not the same.

33
00:01:35,130 --> 00:01:36,390
So what is rights?

34
00:01:36,390 --> 00:01:39,630
Well, rights are
entitlements granted to users

35
00:01:39,630 --> 00:01:42,120
that determine their level of control

36
00:01:42,120 --> 00:01:43,830
and access within a system.

37
00:01:43,830 --> 00:01:47,280
So for example, change system
time, or create a user,

38
00:01:47,280 --> 00:01:49,203
or to be able to install software.

39
00:01:50,430 --> 00:01:53,280
Permissions are specific authorizations

40
00:01:53,280 --> 00:01:55,380
and define what a user can do

41
00:01:55,380 --> 00:01:58,740
with specific files,
directories, or system resources.

42
00:01:58,740 --> 00:02:02,700
So for example, read,
write, delete, modify.

43
00:02:02,700 --> 00:02:04,623
Those are all examples of permissions.

44
00:02:05,610 --> 00:02:06,960
Now, two other concepts

45
00:02:06,960 --> 00:02:09,300
that really relate to
rights and permissions,

46
00:02:09,300 --> 00:02:10,620
and we've talked about both these already,

47
00:02:10,620 --> 00:02:12,150
so this should be a refresher,

48
00:02:12,150 --> 00:02:15,510
is least privilege and
authorization creep.

49
00:02:15,510 --> 00:02:17,310
It's a reminder that least privilege,

50
00:02:17,310 --> 00:02:19,050
the principle of least privilege

51
00:02:19,050 --> 00:02:21,840
refers to assigning the
minimal rights and permissions

52
00:02:21,840 --> 00:02:23,700
needed to accomplish a task.

53
00:02:23,700 --> 00:02:24,533
Why?

54
00:02:24,533 --> 00:02:27,750
Because we really wanna have
as small footprint as possible,

55
00:02:27,750 --> 00:02:31,470
'cause we know that an
exploit is going to execute

56
00:02:31,470 --> 00:02:35,580
in the security context of
the locally logged in user.

57
00:02:35,580 --> 00:02:39,000
And then authorization
creep is the accumulation

58
00:02:39,000 --> 00:02:41,850
of access rights and
permissions over time,

59
00:02:41,850 --> 00:02:43,650
and we talked about that
in an earlier lesson,

60
00:02:43,650 --> 00:02:45,360
that as we move through an organization,

61
00:02:45,360 --> 00:02:48,390
we might acquire new
rights and permissions,

62
00:02:48,390 --> 00:02:50,190
but we haven't been relieved

63
00:02:50,190 --> 00:02:51,600
of our older rights and permissions.

64
00:02:51,600 --> 00:02:53,850
And sometimes for very good
reasons originally, right?

65
00:02:53,850 --> 00:02:57,060
It might be because we're
training our replacement

66
00:02:57,060 --> 00:02:59,490
or we're covering both jobs for a while.

67
00:02:59,490 --> 00:03:00,360
But it's important

68
00:03:00,360 --> 00:03:03,120
that we are always looking
at those change requests,

69
00:03:03,120 --> 00:03:04,380
we audit those change requests,

70
00:03:04,380 --> 00:03:05,430
and say, "Wait a minute.

71
00:03:05,430 --> 00:03:06,750
They've moved on.

72
00:03:06,750 --> 00:03:08,970
They no longer need those
rights and permissions,"

73
00:03:08,970 --> 00:03:11,420
so that we don't end up
with authorization creep.

74
00:03:12,390 --> 00:03:13,650
Another really important

75
00:03:13,650 --> 00:03:17,220
access control principle or approach

76
00:03:17,220 --> 00:03:19,923
is dual control and separation of duties.

77
00:03:19,923 --> 00:03:23,910
Now, dual control requires
more than one subject or key

78
00:03:23,910 --> 00:03:26,520
to complete a specific task.

79
00:03:26,520 --> 00:03:27,600
Here's an example.

80
00:03:27,600 --> 00:03:29,760
Let's say in a bank, we
wanna open the vault,

81
00:03:29,760 --> 00:03:32,730
so we need two employees
to come to the vault.

82
00:03:32,730 --> 00:03:33,870
They each have a key.

83
00:03:33,870 --> 00:03:35,340
Each put their key in and turn it, right?

84
00:03:35,340 --> 00:03:37,650
They're doing the same thing,
put a key in and turning it,

85
00:03:37,650 --> 00:03:39,090
or maybe it's not a physical key,

86
00:03:39,090 --> 00:03:42,270
maybe it's biometric or maybe
they have to put in a code,

87
00:03:42,270 --> 00:03:44,880
but they're doing the same thing, right?

88
00:03:44,880 --> 00:03:46,620
We need two of them there, right?

89
00:03:46,620 --> 00:03:50,817
In order to complete that specific task.

90
00:03:50,817 --> 00:03:52,560
Well, separation of duties

91
00:03:52,560 --> 00:03:55,920
implies breaking a task
into separate processes,

92
00:03:55,920 --> 00:03:58,440
so no one subject is in complete control

93
00:03:58,440 --> 00:04:02,190
or has overriding decision making power.

94
00:04:02,190 --> 00:04:03,810
And we talked about that one earlier,

95
00:04:03,810 --> 00:04:06,390
but let me give you the
example that we shared before.

96
00:04:06,390 --> 00:04:09,630
We talked about what if my organization

97
00:04:09,630 --> 00:04:12,120
paid vendors with wire transfers?

98
00:04:12,120 --> 00:04:12,953
I wanted to make sure

99
00:04:12,953 --> 00:04:15,480
that no one was being paid fraudulently.

100
00:04:15,480 --> 00:04:17,220
Well, let's say I have user A

101
00:04:17,220 --> 00:04:19,650
who can log into the payment program

102
00:04:19,650 --> 00:04:21,510
and just set up the vendor.

103
00:04:21,510 --> 00:04:23,460
That's all they can do.

104
00:04:23,460 --> 00:04:26,850
User two, when they log in,
they can't set up a new vendor.

105
00:04:26,850 --> 00:04:30,960
All they can do is set up a
payment for an existing vendor.

106
00:04:30,960 --> 00:04:32,100
They can just set up the payment,

107
00:04:32,100 --> 00:04:34,440
can't create one, can't authorize it.

108
00:04:34,440 --> 00:04:35,910
User three logs in.

109
00:04:35,910 --> 00:04:38,580
They can't create a new vendor,
they can't set up a payment.

110
00:04:38,580 --> 00:04:39,630
The only thing they can do

111
00:04:39,630 --> 00:04:42,270
is authorize a payment to go out the door.

112
00:04:42,270 --> 00:04:46,530
So we've separated that payment
cycle into those three tasks

113
00:04:46,530 --> 00:04:49,830
of creating the vendor,
creating the payment,

114
00:04:49,830 --> 00:04:51,600
and authorizing the payment

115
00:04:51,600 --> 00:04:53,310
as those separate processes

116
00:04:53,310 --> 00:04:56,160
so that no one subject
is in complete control

117
00:04:56,160 --> 00:04:58,743
or has overriding decision making power.

118
00:04:59,910 --> 00:05:02,310
Now, authorization is the process

119
00:05:02,310 --> 00:05:05,523
of granting subjects access to objects.

120
00:05:06,630 --> 00:05:08,850
Subjects are active entities, right?

121
00:05:08,850 --> 00:05:11,880
They're generally in the form
of a person, like you and I,

122
00:05:11,880 --> 00:05:14,940
processes or devices
that cause information

123
00:05:14,940 --> 00:05:19,110
to flow among objects or
change the system state.

124
00:05:19,110 --> 00:05:21,288
Objects are passive entities,

125
00:05:21,288 --> 00:05:23,460
often referred to as a resource,

126
00:05:23,460 --> 00:05:27,150
that contain or receive
information or instructions.

127
00:05:27,150 --> 00:05:30,420
Now, authorization can be
static, meaning it's hard-coded,

128
00:05:30,420 --> 00:05:31,620
or it can be dynamic,

129
00:05:31,620 --> 00:05:34,893
meaning that it is influenced
by situational factors.

130
00:05:36,390 --> 00:05:38,580
There are six authorization models

131
00:05:38,580 --> 00:05:39,960
you need to be familiar with,

132
00:05:39,960 --> 00:05:43,620
mandatory, known as MAC,
discretionary, known as DAC,

133
00:05:43,620 --> 00:05:45,600
role-based, RBAC,

134
00:05:45,600 --> 00:05:50,280
rule-based, attribute-based,
ABAC, and risk-based.

135
00:05:50,280 --> 00:05:51,580
So let's go through these.

136
00:05:52,980 --> 00:05:55,290
In a mandatory access control model,

137
00:05:55,290 --> 00:05:57,840
access is based on the relationship

138
00:05:57,840 --> 00:06:00,900
between the subject's clearance
and their need to know

139
00:06:00,900 --> 00:06:03,360
and the object's classification.

140
00:06:03,360 --> 00:06:05,970
So way back when, when we were
talking about classification,

141
00:06:05,970 --> 00:06:07,230
we said that we classify

142
00:06:07,230 --> 00:06:09,960
either by criticality or by sensitivity

143
00:06:09,960 --> 00:06:14,280
and that we assign clearance
levels to our subjects, right?

144
00:06:14,280 --> 00:06:16,050
That's a level of trust.

145
00:06:16,050 --> 00:06:19,140
So the relationship is based
on the subject's clearance

146
00:06:19,140 --> 00:06:23,100
plus need to know and the
object's classification level.

147
00:06:23,100 --> 00:06:26,490
So let's say someone
has a secret clearance.

148
00:06:26,490 --> 00:06:29,040
That means that they
could access secret data,

149
00:06:29,040 --> 00:06:31,320
but not everything that's
marked secret, right?

150
00:06:31,320 --> 00:06:34,830
They also have to have
a bonafide need to know.

151
00:06:34,830 --> 00:06:39,510
And DAC is the polar opposite of MAC.

152
00:06:39,510 --> 00:06:42,720
In DAC environment or a
discretionary environment,

153
00:06:42,720 --> 00:06:45,660
access is determined by the data owner.

154
00:06:45,660 --> 00:06:47,490
So the data owner gets to say

155
00:06:47,490 --> 00:06:49,770
who can have rights, who
can have permissions.

156
00:06:49,770 --> 00:06:51,963
Totally on the data owner.

157
00:06:54,120 --> 00:06:56,460
In role-based or RBAC,

158
00:06:56,460 --> 00:06:59,400
access is based on the
subject's assigned roles.

159
00:06:59,400 --> 00:07:03,120
So subjects are put into roles
and roles are given access.

160
00:07:03,120 --> 00:07:06,810
And sometimes RBAC is referred
to as non-discretionary.

161
00:07:06,810 --> 00:07:08,280
Why non-discretionary?

162
00:07:08,280 --> 00:07:09,660
Well, because what happens

163
00:07:09,660 --> 00:07:14,660
is that the owner of the
data or the system can say,

164
00:07:14,797 --> 00:07:19,170
"Okay, these roles can
access my system or my data,

165
00:07:19,170 --> 00:07:22,350
but they don't have any say
over who gets put in the roles."

166
00:07:22,350 --> 00:07:23,183
So they can say,

167
00:07:23,183 --> 00:07:25,980
"Yes, these roles can have
these rights and permissions,

168
00:07:25,980 --> 00:07:29,700
but they don't get to say who
is in the roles themselves."

169
00:07:29,700 --> 00:07:32,163
So based on the subject's assigned roles.

170
00:07:33,030 --> 00:07:36,840
Then rule-based is based on compliance

171
00:07:36,840 --> 00:07:38,550
with an established set of rules.

172
00:07:38,550 --> 00:07:41,070
Generally rules don't
care who the subject is.

173
00:07:41,070 --> 00:07:42,177
They're just a whole set of rules,

174
00:07:42,177 --> 00:07:44,700
and the best example would
be a firewall, right?

175
00:07:44,700 --> 00:07:48,090
So firewall rules are based on source IP

176
00:07:48,090 --> 00:07:51,120
and destination IP and protocol

177
00:07:51,120 --> 00:07:53,793
to have to comply with those rules.

178
00:07:55,023 --> 00:07:57,630
And we come to one that you
might be less familiar with,

179
00:07:57,630 --> 00:07:59,550
which is a really
interesting and emerging one

180
00:07:59,550 --> 00:08:02,880
called attribute-based
access control, or ABAC.

181
00:08:02,880 --> 00:08:04,980
In ABAC, access is determined

182
00:08:04,980 --> 00:08:07,410
by a combination of attributes,

183
00:08:07,410 --> 00:08:09,810
subject attributes, object attributes,

184
00:08:09,810 --> 00:08:12,060
rules, and environmental conditions,

185
00:08:12,060 --> 00:08:14,723
and we're gonna dig right
into that one in just a sec.

186
00:08:15,780 --> 00:08:17,190
And then lastly, we have risk-based,

187
00:08:17,190 --> 00:08:20,010
which is another emerging
authorization model,

188
00:08:20,010 --> 00:08:23,100
and that's influenced by dynamic factors

189
00:08:23,100 --> 00:08:25,110
and contextual data analytics.

190
00:08:25,110 --> 00:08:26,910
And we're gonna look a little bit closer

191
00:08:26,910 --> 00:08:28,500
at that one as well.

192
00:08:28,500 --> 00:08:33,500
So MAC, DAC, RBAC, rule-based,
ABAC, and risk-based.

193
00:08:33,810 --> 00:08:35,550
Make sure that you can identify

194
00:08:35,550 --> 00:08:37,473
all of these authorization models.

195
00:08:38,730 --> 00:08:41,790
Now, ABAC stands for
attribute-based access control.

196
00:08:41,790 --> 00:08:43,830
It's a logical access control model

197
00:08:43,830 --> 00:08:47,190
that controls access to
objects by evaluating rules

198
00:08:47,190 --> 00:08:51,090
against the attributes of
the subject and the object

199
00:08:51,090 --> 00:08:54,453
as well as operations and the environment.

200
00:08:56,460 --> 00:08:59,730
Now, ABAC supports very
complex Boolean rule sets

201
00:08:59,730 --> 00:09:03,300
that can evaluate just tons
of different attributes,

202
00:09:03,300 --> 00:09:07,050
and the policies that can be
implemented in an ABAC model

203
00:09:07,050 --> 00:09:09,300
are limited only by the degree imposed

204
00:09:09,300 --> 00:09:11,610
by the computational
language that you're using

205
00:09:11,610 --> 00:09:14,760
and the available attributes themselves.

206
00:09:14,760 --> 00:09:17,100
Now, an example of an
access control framework

207
00:09:17,100 --> 00:09:18,900
that is consistent with ABAC

208
00:09:18,900 --> 00:09:21,810
is Extensible Access
Control Markup Language.

209
00:09:21,810 --> 00:09:23,490
There's that word extensible, right?

210
00:09:23,490 --> 00:09:26,130
Remember the extensible
said that we can modify,

211
00:09:26,130 --> 00:09:27,930
we can freely modify something,

212
00:09:27,930 --> 00:09:30,900
but without changing sort
of the the underlying basis,

213
00:09:30,900 --> 00:09:33,330
and I said that often when
you see the word extensible,

214
00:09:33,330 --> 00:09:37,173
it will be abbreviated
with an X, so XACML.

215
00:09:38,670 --> 00:09:41,790
So here's an illustration of ABAC.

216
00:09:41,790 --> 00:09:43,770
This illustration actually
comes from a NIST,

217
00:09:43,770 --> 00:09:46,740
National Institute of Standards
and Technology publication.

218
00:09:46,740 --> 00:09:50,940
It's NIST SP 800-162, all about ABAC.

219
00:09:50,940 --> 00:09:52,110
So if you wanna learn more about ABAC,

220
00:09:52,110 --> 00:09:54,150
would be a great resource for you.

221
00:09:54,150 --> 00:09:55,740
But we've got our subject

222
00:09:55,740 --> 00:09:58,230
and our subject requests
access to the object,

223
00:09:58,230 --> 00:10:02,077
and so the access control mechanism says,

224
00:10:02,077 --> 00:10:04,650
"Okay, well let's look at
the subject attributes,

225
00:10:04,650 --> 00:10:06,900
let's look at the object attributes,

226
00:10:06,900 --> 00:10:09,270
let's look at the environmental conditions

227
00:10:09,270 --> 00:10:12,690
and any other rules in order
to compute a decision."

228
00:10:12,690 --> 00:10:15,780
And if everything is good,

229
00:10:15,780 --> 00:10:17,730
they're allowed to access that object,

230
00:10:17,730 --> 00:10:19,887
and if not, well, they
won't be allowed to.

231
00:10:19,887 --> 00:10:23,610
But I think this is a really
nice visual on how ABAC works,

232
00:10:23,610 --> 00:10:25,920
and again, I would encourage you to go out

233
00:10:25,920 --> 00:10:27,750
and look at the NIST publication

234
00:10:27,750 --> 00:10:29,673
if you wanna learn more about ABAC.

235
00:10:31,320 --> 00:10:33,750
So next I wanna share with
you some risk triggers,

236
00:10:33,750 --> 00:10:35,340
and these are actually risk triggers

237
00:10:35,340 --> 00:10:38,100
that are from the Microsoft
Cloud environment.

238
00:10:38,100 --> 00:10:40,110
Now, often, risk triggers are layered

239
00:10:40,110 --> 00:10:43,800
with another type of authorization model.

240
00:10:43,800 --> 00:10:45,990
So let's look at four risk triggers.

241
00:10:45,990 --> 00:10:49,440
Anonymous IP address,
unfamiliar sign-in properties,

242
00:10:49,440 --> 00:10:53,280
atypical travel, and impossible travel.

243
00:10:53,280 --> 00:10:55,890
Anonymous IP address indicates a sign-in

244
00:10:55,890 --> 00:10:58,860
from an anonymous IP
address, just like it sounds.

245
00:10:58,860 --> 00:11:02,340
Now that might be fine, but
that might be suspicious, right?

246
00:11:02,340 --> 00:11:05,520
Why would you be coming in
from an anonymous IP address?

247
00:11:05,520 --> 00:11:07,470
Again, it might be a legitimate reason,

248
00:11:07,470 --> 00:11:10,143
but worth exploring to get
more information there.

249
00:11:11,190 --> 00:11:15,240
Unfamiliar sign-in properties
consider past sign-in history

250
00:11:15,240 --> 00:11:18,150
to identify non-familiar properties.

251
00:11:18,150 --> 00:11:19,410
Now, examples of properties

252
00:11:19,410 --> 00:11:23,523
would be your operating
system or your browser level.

253
00:11:25,170 --> 00:11:28,620
Now, atypical travel
identifies two sign-ins

254
00:11:28,620 --> 00:11:32,040
originating from geographically
distant locations

255
00:11:32,040 --> 00:11:35,160
where at least one of the
locations is atypical,

256
00:11:35,160 --> 00:11:36,960
given past behavior.

257
00:11:36,960 --> 00:11:40,290
So if you normally sign
in from San Francisco,

258
00:11:40,290 --> 00:11:43,350
and the next day, you're
signing in from New York,

259
00:11:43,350 --> 00:11:45,270
well, that's atypical, right?

260
00:11:45,270 --> 00:11:47,040
You're usually in San Francisco.

261
00:11:47,040 --> 00:11:48,570
Now, could it be perfectly legitimate?

262
00:11:48,570 --> 00:11:50,700
Sure, you might be coming through a VPN,

263
00:11:50,700 --> 00:11:54,420
but you know, they're too
geographically distant locations

264
00:11:54,420 --> 00:11:57,540
where at least one of those is atypical.

265
00:11:57,540 --> 00:12:00,330
And then we get impossible travel.

266
00:12:00,330 --> 00:12:03,540
Impossible travel identifies
two user activities

267
00:12:03,540 --> 00:12:06,930
originating from geographically
distant locations

268
00:12:06,930 --> 00:12:09,450
within a timeframe
shorter than it would take

269
00:12:09,450 --> 00:12:12,030
to travel between the locations.

270
00:12:12,030 --> 00:12:13,950
So at noon, right?

271
00:12:13,950 --> 00:12:16,710
If I logged in from London, England,

272
00:12:16,710 --> 00:12:18,780
and you know, 10 minutes later,

273
00:12:18,780 --> 00:12:20,820
I'm logging in from Sydney, Australia,

274
00:12:20,820 --> 00:12:23,280
it's like, well, I can't
get from London to Sydney

275
00:12:23,280 --> 00:12:24,570
in 10 minutes, right?

276
00:12:24,570 --> 00:12:27,570
No matter how much I might
want to, I can't do that.

277
00:12:27,570 --> 00:12:29,520
That's impossible travel.

278
00:12:29,520 --> 00:12:32,730
So again, that's going to
be a risk-based trigger

279
00:12:32,730 --> 00:12:35,160
to say we need to get more information.

280
00:12:35,160 --> 00:12:36,600
And could it be legit?

281
00:12:36,600 --> 00:12:40,230
Sure, it could once again
be maybe a VPN, right?

282
00:12:40,230 --> 00:12:42,510
So we're showing those
different IP addresses

283
00:12:42,510 --> 00:12:45,150
when in fact maybe I haven't moved at all.

284
00:12:45,150 --> 00:12:46,590
So it's not necessarily

285
00:12:46,590 --> 00:12:49,260
that it's always going to be
wrong or always a stopper,

286
00:12:49,260 --> 00:12:52,143
but it is a trigger to get
additional information.

287
00:12:53,700 --> 00:12:56,220
And that, my friends, brings
us to a three-second challenge.

288
00:12:56,220 --> 00:12:58,230
Five challenge questions,
three seconds each.

289
00:12:58,230 --> 00:12:59,970
You know how to do it.

290
00:12:59,970 --> 00:13:01,410
Accumulation of access rights,

291
00:13:01,410 --> 00:13:04,650
permissions, and privileges over time.

292
00:13:04,650 --> 00:13:06,753
One, two, three.

293
00:13:08,340 --> 00:13:10,650
That's authorization creep.

294
00:13:10,650 --> 00:13:13,740
Number two, requiring more
than one subject or key

295
00:13:13,740 --> 00:13:16,260
to complete a specific task.

296
00:13:16,260 --> 00:13:17,883
One, two, three.

297
00:13:19,170 --> 00:13:20,910
That's dual control.

298
00:13:20,910 --> 00:13:23,850
That was the example I gave
you of the two bank employees

299
00:13:23,850 --> 00:13:25,803
going to open up the vault.

300
00:13:27,060 --> 00:13:29,580
Number three, a minimum set of permissions

301
00:13:29,580 --> 00:13:32,310
needed to perform a task.

302
00:13:32,310 --> 00:13:33,903
One, two, three.

303
00:13:34,920 --> 00:13:36,720
And that's gonna be least privilege.

304
00:13:37,620 --> 00:13:38,730
Number four,

305
00:13:38,730 --> 00:13:42,270
access is based on the
subject's assigned roles.

306
00:13:42,270 --> 00:13:43,860
This is an easy one.

307
00:13:43,860 --> 00:13:45,930
One, two, three.

308
00:13:45,930 --> 00:13:50,070
Well, that must be role-based
access control or RBAC.

309
00:13:50,070 --> 00:13:52,020
And lastly number five,

310
00:13:52,020 --> 00:13:54,420
breaking a task into separate processes

311
00:13:54,420 --> 00:13:57,330
so no one subject is in complete control.

312
00:13:57,330 --> 00:14:00,570
That's the example I gave
you about paying our vendors.

313
00:14:00,570 --> 00:14:02,910
One, two, three.

314
00:14:02,910 --> 00:14:04,713
And that's separation of duties.

315
00:14:05,880 --> 00:14:08,190
Well, that brings us to
a security in action.

316
00:14:08,190 --> 00:14:12,270
This one's about fraudulent
activity and access controls.

317
00:14:12,270 --> 00:14:14,520
The accounting department wires funds

318
00:14:14,520 --> 00:14:16,710
to suppliers all around the world,

319
00:14:16,710 --> 00:14:19,830
and it's critical that
only authorized personnel

320
00:14:19,830 --> 00:14:23,520
have the authority to initiate
and release a transfer.

321
00:14:23,520 --> 00:14:25,350
Now, several controls were put in place

322
00:14:25,350 --> 00:14:28,320
for the online wire transfer application,

323
00:14:28,320 --> 00:14:31,200
including IP address restrictions

324
00:14:31,200 --> 00:14:33,745
and biometric authentication.

325
00:14:33,745 --> 00:14:37,590
But much to everybody's surprise,
during a financial audit,

326
00:14:37,590 --> 00:14:41,340
it was discovered that the CFO,
the chief financial officer,

327
00:14:41,340 --> 00:14:44,880
had been making fraudulent wire transfers.

328
00:14:44,880 --> 00:14:46,350
So what access controls

329
00:14:46,350 --> 00:14:49,233
would have reduced the
opportunity for fraud?

330
00:14:50,550 --> 00:14:52,260
I know you know this answer right away,

331
00:14:52,260 --> 00:14:55,110
but go ahead and put me on
pause, jot down some notes,

332
00:14:55,110 --> 00:14:57,710
and come back, and we'll
talk about access controls.

333
00:15:00,065 --> 00:15:02,520
Well, access controls
that could be considered

334
00:15:02,520 --> 00:15:06,251
include dual control and
separation of duties.

335
00:15:06,251 --> 00:15:08,220
Now, implementing dual control

336
00:15:08,220 --> 00:15:11,460
would require two or more
employees to collude, right?

337
00:15:11,460 --> 00:15:14,760
So you'd need two employees
to do the same task,

338
00:15:14,760 --> 00:15:16,590
and they would have to collude,

339
00:15:16,590 --> 00:15:18,330
which would significantly reduce

340
00:15:18,330 --> 00:15:21,483
the probability of fraudulent actions.

341
00:15:22,800 --> 00:15:25,830
Implementing separation of
duties would break the task down

342
00:15:25,830 --> 00:15:28,230
into distinct processes

343
00:15:28,230 --> 00:15:31,380
so that no one subject
is in complete control

344
00:15:31,380 --> 00:15:34,350
or has overriding decision making power.

345
00:15:34,350 --> 00:15:36,150
So those would really be your options,

346
00:15:36,150 --> 00:15:39,330
dual control or separation of duties.

347
00:15:39,330 --> 00:15:42,450
Now in this situation, for
sure, separation of duties

348
00:15:42,450 --> 00:15:45,060
would be more operationally
efficient, right?

349
00:15:45,060 --> 00:15:48,120
Dual control for major
activities like this

350
00:15:48,120 --> 00:15:49,080
doesn't usually make sense,

351
00:15:49,080 --> 00:15:50,580
because then I have to have two employees

352
00:15:50,580 --> 00:15:53,820
who are effectively sitting
together side by side,

353
00:15:53,820 --> 00:15:55,980
doing the same job, right?

354
00:15:55,980 --> 00:16:00,450
But by breaking the task
into separate processes,

355
00:16:00,450 --> 00:16:02,190
and I can separate them out,

356
00:16:02,190 --> 00:16:04,260
two people, three people,
four people, five people,

357
00:16:04,260 --> 00:16:06,180
as many people as I need.

358
00:16:06,180 --> 00:16:08,400
Much more operationally efficient,

359
00:16:08,400 --> 00:16:10,200
and the more people I have,

360
00:16:10,200 --> 00:16:12,990
the more I have reduced the probability

361
00:16:12,990 --> 00:16:15,030
of collusion and fraud.

362
00:16:15,030 --> 00:16:16,050
So in this case,

363
00:16:16,050 --> 00:16:19,290
I would probably go with
separation of duties,

364
00:16:19,290 --> 00:16:20,820
but thinking through these options

365
00:16:20,820 --> 00:16:22,890
and then be able to help implement them,

366
00:16:22,890 --> 00:16:25,080
that's security in action.

367
00:16:25,080 --> 00:16:26,790
Wow, another big word cloud.

368
00:16:26,790 --> 00:16:29,730
Again, make sure that you
understand all these terms

369
00:16:29,730 --> 00:16:31,860
and that you can speak
to all of them, right?

370
00:16:31,860 --> 00:16:34,020
'Cause they're all fair game for the exam.

371
00:16:34,020 --> 00:16:36,150
So do that before you move on,

372
00:16:36,150 --> 00:16:37,860
and once you're comfortable and confident,

373
00:16:37,860 --> 00:16:40,413
move on to the next lesson,
and I'll see you there.
