1
00:00:06,540 --> 00:00:07,800
- Welcome to lesson nine,

2
00:00:07,800 --> 00:00:09,930
explain the purpose of
mitigation techniques

3
00:00:09,930 --> 00:00:12,060
used to secure the enterprise.

4
00:00:12,060 --> 00:00:14,040
In this lesson, 9.1,

5
00:00:14,040 --> 00:00:18,009
we're gonna focus in on
secure design principles.

6
00:00:18,009 --> 00:00:20,490
Now, the goal of secure design engineering

7
00:00:20,490 --> 00:00:23,880
is to develop trustworthy
and survivable systems.

8
00:00:23,880 --> 00:00:25,860
So what do we mean by survivable?

9
00:00:25,860 --> 00:00:29,100
Well, survivable or survivability
is a system property

10
00:00:29,100 --> 00:00:30,780
and refers to the system's ability

11
00:00:30,780 --> 00:00:35,010
to prevent, to mitigate and
to recover from cyber events.

12
00:00:35,010 --> 00:00:35,880
Now we're gonna be looking

13
00:00:35,880 --> 00:00:38,850
at three sets of secure design principles:

14
00:00:38,850 --> 00:00:41,040
secure design planning principles,

15
00:00:41,040 --> 00:00:43,290
secure design configuration principles,

16
00:00:43,290 --> 00:00:45,660
and secure design relationship principles.

17
00:00:45,660 --> 00:00:46,893
There's a lot here.

18
00:00:48,960 --> 00:00:52,140
So we're starting with secure
design planning principles.

19
00:00:52,140 --> 00:00:54,780
There are five principles
we're gonna talk about:

20
00:00:54,780 --> 00:00:57,150
threat modeling, keep it simple,

21
00:00:57,150 --> 00:01:01,680
default deny posture,
fail-secure, and an open design.

22
00:01:01,680 --> 00:01:03,630
Again, these are planning principles.

23
00:01:03,630 --> 00:01:06,090
So threat modeling says we
should use threat modeling

24
00:01:06,090 --> 00:01:07,770
to anticipate threats,

25
00:01:07,770 --> 00:01:10,650
and we're gonna focus on
undesirable consequences.

26
00:01:10,650 --> 00:01:12,450
Again, this is in the planning phase.

27
00:01:12,450 --> 00:01:13,470
So what are the threats?

28
00:01:13,470 --> 00:01:15,660
Remember, threat is a potential danger,

29
00:01:15,660 --> 00:01:18,330
and we're gonna focus on
those undesirable consequences

30
00:01:18,330 --> 00:01:20,010
so that when we're planning, right,

31
00:01:20,010 --> 00:01:24,990
we can minimize the risk of
that threat ever materializing.

32
00:01:24,990 --> 00:01:26,220
The second is, keep it simple.

33
00:01:26,220 --> 00:01:27,270
I love this one.

34
00:01:27,270 --> 00:01:29,130
This is that security mechanisms

35
00:01:29,130 --> 00:01:31,230
should be as simple as possible.

36
00:01:31,230 --> 00:01:33,840
Now, simplicity means that
fewer possibilities exist

37
00:01:33,840 --> 00:01:38,043
for error, and the assessment
process is much less complex.

38
00:01:38,880 --> 00:01:40,830
Third, we have default deny.

39
00:01:40,830 --> 00:01:43,620
Now, that's the idea that we're
gonna base access decisions

40
00:01:43,620 --> 00:01:46,770
on permissions rather than exclusion.

41
00:01:46,770 --> 00:01:49,860
So this means that by default,
access is gonna be denied,

42
00:01:49,860 --> 00:01:52,830
and that the protection
scheme identifies conditions

43
00:01:52,830 --> 00:01:55,230
under which access is permitted.

44
00:01:55,230 --> 00:01:56,850
So let me give you an example.

45
00:01:56,850 --> 00:02:00,750
A firewall that is configured
in default deny posture

46
00:02:00,750 --> 00:02:03,330
would not allow any
ingress or egress traffic,

47
00:02:03,330 --> 00:02:05,040
incoming or outgoing traffic,

48
00:02:05,040 --> 00:02:07,620
until we set up rules in
our access control list

49
00:02:07,620 --> 00:02:08,870
that said it was allowed.

50
00:02:09,900 --> 00:02:13,050
But a firewall that was
set up in the opposite,

51
00:02:13,050 --> 00:02:14,820
which is default allow,

52
00:02:14,820 --> 00:02:17,760
which say all ingress and
egress traffic is allowed

53
00:02:17,760 --> 00:02:19,350
until we set up a rule

54
00:02:19,350 --> 00:02:22,650
in our access control
list that disallows it.

55
00:02:22,650 --> 00:02:23,760
So what we're saying here is,

56
00:02:23,760 --> 00:02:25,440
we don't wanna use default allow.

57
00:02:25,440 --> 00:02:27,513
We do wanna use default deny.

58
00:02:28,800 --> 00:02:32,610
We also want to use the
principle of fail-secure.

59
00:02:32,610 --> 00:02:33,630
The idea of fail-secure

60
00:02:33,630 --> 00:02:36,600
is that in the event of
failure, access will be denied.

61
00:02:36,600 --> 00:02:38,580
So going back to our firewall example,

62
00:02:38,580 --> 00:02:39,900
maybe we have to go through our firewall

63
00:02:39,900 --> 00:02:41,460
to get out to the internet.

64
00:02:41,460 --> 00:02:43,860
In fail-secure, if our firewall failed,

65
00:02:43,860 --> 00:02:46,080
we wouldn't have any
access to the internet.

66
00:02:46,080 --> 00:02:48,330
Everything would be closed or shut down.

67
00:02:48,330 --> 00:02:49,860
Lastly is open design.

68
00:02:49,860 --> 00:02:51,510
And that's the planning principle

69
00:02:51,510 --> 00:02:54,060
that a security mechanism
should not depend

70
00:02:54,060 --> 00:02:55,890
upon the secrecy of the design

71
00:02:55,890 --> 00:02:58,230
or the secrecy of the implementation.

72
00:02:58,230 --> 00:03:00,090
It's really succinctly our argument

73
00:03:00,090 --> 00:03:02,340
against security through obscurity

74
00:03:02,340 --> 00:03:05,403
because ultimately everything is knowable.

75
00:03:07,200 --> 00:03:10,773
Our next set are secure design
configuration principles.

76
00:03:11,760 --> 00:03:13,440
Secure the weakest link,

77
00:03:13,440 --> 00:03:16,680
defense-in-depth, least functionality,

78
00:03:16,680 --> 00:03:18,300
appropriate disclosure,

79
00:03:18,300 --> 00:03:21,780
and sanitize data sent to other systems.

80
00:03:21,780 --> 00:03:23,880
So secure the weakest link is saying,

81
00:03:23,880 --> 00:03:25,830
when we're doing our configuration,

82
00:03:25,830 --> 00:03:28,470
identify and strengthen your weak links

83
00:03:28,470 --> 00:03:31,950
until you get to an
acceptable level of risk.

84
00:03:31,950 --> 00:03:34,440
Defense-in-depth, we've
talked about this one a lot.

85
00:03:34,440 --> 00:03:37,920
This is to utilize multiple
layers of diverse controls

86
00:03:37,920 --> 00:03:41,190
including endpoint protection,
such as a host firewall.

87
00:03:41,190 --> 00:03:44,130
The idea is multiple
layers of diverse controls.

88
00:03:44,130 --> 00:03:45,300
Remember, we'd wanna make sure

89
00:03:45,300 --> 00:03:47,220
that our controls are independent

90
00:03:47,220 --> 00:03:50,403
and that they're not subject
to any type of cascade effect.

91
00:03:51,450 --> 00:03:53,340
The principle of least functionality

92
00:03:53,340 --> 00:03:55,050
says that our systems and devices

93
00:03:55,050 --> 00:03:58,830
should be configured to provide
only essential capabilities

94
00:03:58,830 --> 00:04:01,890
and specifically prohibit or restrict

95
00:04:01,890 --> 00:04:06,660
the use of any and all
unnecessary functions, ports,

96
00:04:06,660 --> 00:04:08,823
protocols, and services.

97
00:04:09,930 --> 00:04:13,680
Appropriate disclosure is
that error and system messages

98
00:04:13,680 --> 00:04:17,250
should not include any
unnecessary information

99
00:04:17,250 --> 00:04:19,920
that may lead to a compromise of security,

100
00:04:19,920 --> 00:04:22,050
or could be used for
reconnaissance purposes.

101
00:04:22,050 --> 00:04:24,060
And we saw that in an earlier lesson

102
00:04:24,060 --> 00:04:26,160
when we looked at the
security-in-action case study

103
00:04:26,160 --> 00:04:28,110
that had the Yellow Screen of Death.

104
00:04:28,110 --> 00:04:31,710
And then lastly, sanitize
data sent to other systems.

105
00:04:31,710 --> 00:04:33,990
The idea is that we
wanna sanitize all data

106
00:04:33,990 --> 00:04:35,730
passed to complex subsystems

107
00:04:35,730 --> 00:04:38,580
such as command shells,
relational databases,

108
00:04:38,580 --> 00:04:41,550
and commercial off-the-shelf
software known as COTS.

109
00:04:41,550 --> 00:04:43,020
Why do we wanna do that?

110
00:04:43,020 --> 00:04:47,103
Because we don't necessarily
trust those other systems.

111
00:04:49,800 --> 00:04:53,910
Our third group is secure
design relationship principles.

112
00:04:53,910 --> 00:04:57,450
Our principles are zero
trust, trust but verify,

113
00:04:57,450 --> 00:05:00,120
separation of duties, least privilege,

114
00:05:00,120 --> 00:05:02,190
and psychological acceptance.

115
00:05:02,190 --> 00:05:05,280
Now, we talked at length
early on about zero trust,

116
00:05:05,280 --> 00:05:08,550
the idea that there's no
default trust or privilege,

117
00:05:08,550 --> 00:05:10,320
and that verification in the form

118
00:05:10,320 --> 00:05:12,660
of re-authentication is required

119
00:05:12,660 --> 00:05:15,003
over and over and over again for access.

120
00:05:17,010 --> 00:05:20,580
Trust but verify is that our dependencies

121
00:05:20,580 --> 00:05:22,260
are not going to be trusted

122
00:05:22,260 --> 00:05:24,870
until we prove them trustworthy.

123
00:05:24,870 --> 00:05:28,470
Separation of duties is
breaking a task into segments

124
00:05:28,470 --> 00:05:31,470
so that no one subject
is in complete control

125
00:05:31,470 --> 00:05:34,500
or has complete decision-making power.

126
00:05:34,500 --> 00:05:36,090
So let me give you an example.

127
00:05:36,090 --> 00:05:38,940
Let's say that your
company pays their vendors

128
00:05:38,940 --> 00:05:40,710
with a wire transfer.

129
00:05:40,710 --> 00:05:41,850
Well, we wanna make sure

130
00:05:41,850 --> 00:05:43,320
that we don't have just one person

131
00:05:43,320 --> 00:05:44,617
who could set up a vendor and say,

132
00:05:44,617 --> 00:05:47,730
"Here's how much we're gonna
transfer," and then transfer.

133
00:05:47,730 --> 00:05:49,560
So in the separation of duties,

134
00:05:49,560 --> 00:05:50,700
we could have user A

135
00:05:50,700 --> 00:05:52,950
who can log on to the
wire transfer program

136
00:05:52,950 --> 00:05:56,250
and the only thing they can
do is set up a new vendor.

137
00:05:56,250 --> 00:05:57,090
That's their whole job.

138
00:05:57,090 --> 00:05:58,050
They can't do anything else.

139
00:05:58,050 --> 00:05:59,910
They can set up a new vendor.

140
00:05:59,910 --> 00:06:03,720
User B, when they log in, they
can't set up a new vendor.

141
00:06:03,720 --> 00:06:06,570
What they can do is set
up a payment for a vendor.

142
00:06:06,570 --> 00:06:08,670
They can't authorize it,
they can't set one up.

143
00:06:08,670 --> 00:06:09,503
They can just say,

144
00:06:09,503 --> 00:06:12,450
"Okay, we're gonna pay
this vendor $10,000."

145
00:06:12,450 --> 00:06:14,580
User C, when they log in,

146
00:06:14,580 --> 00:06:17,970
the only thing they can
do is authorize a payment.

147
00:06:17,970 --> 00:06:21,180
They can't create the payment,
they can't create the vendor.

148
00:06:21,180 --> 00:06:22,920
So we had user A doing the vendor,

149
00:06:22,920 --> 00:06:24,510
user B doing the payment,

150
00:06:24,510 --> 00:06:27,000
user C doing the authorization.

151
00:06:27,000 --> 00:06:29,430
So we had a complete separation of duties

152
00:06:29,430 --> 00:06:31,800
so that no one subject
was in complete control

153
00:06:31,800 --> 00:06:33,993
or had complete decision-making power.

154
00:06:35,820 --> 00:06:37,680
The principle of least privilege

155
00:06:37,680 --> 00:06:40,380
is that we're going to
give a subject or a process

156
00:06:40,380 --> 00:06:41,820
only the rights and permissions

157
00:06:41,820 --> 00:06:44,130
needed to complete their assigned task.

158
00:06:44,130 --> 00:06:45,840
We're not gonna give them any rights

159
00:06:45,840 --> 00:06:48,150
and permissions that aren't necessary.

160
00:06:48,150 --> 00:06:49,320
Why do we wanna do that?

161
00:06:49,320 --> 00:06:51,750
Well, we know that an exploit will execute

162
00:06:51,750 --> 00:06:55,830
in the security context of
the locally logged in user.

163
00:06:55,830 --> 00:06:58,290
So we wanna make sure
that that security context

164
00:06:58,290 --> 00:07:01,290
is as small and tight as possible.

165
00:07:01,290 --> 00:07:05,010
And lastly is the idea of
psychological acceptance

166
00:07:05,010 --> 00:07:07,650
that the human interface
that's being designed

167
00:07:07,650 --> 00:07:10,530
should be designed for ease of use, right?

168
00:07:10,530 --> 00:07:12,180
Should be really easy to use.

169
00:07:12,180 --> 00:07:14,670
No question, because we want our users

170
00:07:14,670 --> 00:07:17,670
to routinely and automatically apply

171
00:07:17,670 --> 00:07:20,160
those protection mechanisms correctly.

172
00:07:20,160 --> 00:07:21,540
We don't want them to make errors,

173
00:07:21,540 --> 00:07:23,190
we don't want them to be confused,

174
00:07:23,190 --> 00:07:25,290
and we don't want to get them frustrated

175
00:07:25,290 --> 00:07:27,840
so that they try to
circumvent the controls.

176
00:07:27,840 --> 00:07:30,333
So that would be the
psychological acceptance.

177
00:07:32,564 --> 00:07:33,397
All right, that my friends

178
00:07:33,397 --> 00:07:35,310
brings us to our three-second challenge.

179
00:07:35,310 --> 00:07:37,350
There was a lot of information here.

180
00:07:37,350 --> 00:07:39,990
I'm gonna give you five
questions, three seconds each.

181
00:07:39,990 --> 00:07:41,073
Let's see how you do.

182
00:07:42,300 --> 00:07:45,300
In the event of failure, access is denied.

183
00:07:45,300 --> 00:07:46,620
So what principle is that?

184
00:07:46,620 --> 00:07:49,110
In the event of failure, access is denied.

185
00:07:49,110 --> 00:07:51,060
One, two, three.

186
00:07:51,060 --> 00:07:52,743
That's gonna be fail-secure.

187
00:07:54,283 --> 00:07:58,863
Question two, the opposite of
security through obscurity.

188
00:08:00,060 --> 00:08:02,490
The opposite of security
through obscurity.

189
00:08:02,490 --> 00:08:03,480
What do you think?

190
00:08:03,480 --> 00:08:04,923
One, two, three.

191
00:08:05,820 --> 00:08:07,370
That's gonna be an open design.

192
00:08:08,850 --> 00:08:12,063
Number three, no inherent privileges.

193
00:08:13,680 --> 00:08:16,200
One, two, three.

194
00:08:16,200 --> 00:08:18,333
That's gonna be zero trust.

195
00:08:19,590 --> 00:08:23,070
Number four, multiple
layers of diverse controls.

196
00:08:23,070 --> 00:08:25,110
Ah, everybody's gonna get this one right.

197
00:08:25,110 --> 00:08:26,430
Are you ready?

198
00:08:26,430 --> 00:08:27,990
One, two, three.

199
00:08:27,990 --> 00:08:29,520
That's gonna be defense-in-depth

200
00:08:29,520 --> 00:08:32,043
or layered controls or layered security.

201
00:08:33,720 --> 00:08:35,280
And number five.

202
00:08:35,280 --> 00:08:37,740
So when I just gave you the
example for breaking a task

203
00:08:37,740 --> 00:08:41,613
into segments so that no one
subject is in complete control.

204
00:08:42,570 --> 00:08:45,150
One, two, three.

205
00:08:45,150 --> 00:08:47,403
And that's gonna be separation of duties.

206
00:08:49,020 --> 00:08:50,370
So let's do a security in action.

207
00:08:50,370 --> 00:08:51,720
Let's apply our knowledge

208
00:08:51,720 --> 00:08:54,780
in terms of psychological acceptability.

209
00:08:54,780 --> 00:08:57,480
The principle of
psychological acceptability

210
00:08:57,480 --> 00:09:01,500
recognizes the human element
in computer security.

211
00:09:01,500 --> 00:09:04,770
If security-related controls
are too complicated,

212
00:09:04,770 --> 00:09:07,560
or cumbersome, or inconvenient,

213
00:09:07,560 --> 00:09:09,630
the user's either gonna ignore them

214
00:09:09,630 --> 00:09:12,240
or they're gonna find a
way to work around them.

215
00:09:12,240 --> 00:09:14,010
So you're reviewing a software design

216
00:09:14,010 --> 00:09:18,060
that prompts the users whenever
a new patch is available

217
00:09:18,060 --> 00:09:23,060
and gives them the option to
install and reboot or ignore.

218
00:09:23,460 --> 00:09:26,820
Hmm. What is your
assessment of this approach?

219
00:09:26,820 --> 00:09:29,910
Again, we wanna make sure
that whatever we're doing,

220
00:09:29,910 --> 00:09:33,810
our users don't see as being
complicated, cumbersome,

221
00:09:33,810 --> 00:09:36,033
or in this case, inconvenient.

222
00:09:37,380 --> 00:09:38,820
Go ahead and put me on pause,

223
00:09:38,820 --> 00:09:41,340
jot down your notes of
what your assessment is

224
00:09:41,340 --> 00:09:42,180
of this approach

225
00:09:42,180 --> 00:09:44,273
and then come back and
we'll do it together.

226
00:09:46,260 --> 00:09:48,210
Well, here is probably your assessment.

227
00:09:48,210 --> 00:09:50,670
Most likely, the prompt is
gonna be ignored, right?

228
00:09:50,670 --> 00:09:51,780
So we're giving them an option,

229
00:09:51,780 --> 00:09:54,780
install and reboot in the
middle of their workday,

230
00:09:54,780 --> 00:09:56,040
or ignore it.

231
00:09:56,040 --> 00:09:58,860
So what do you think 99%
of the people are gonna do?

232
00:09:58,860 --> 00:09:59,970
They're gonna ignore it, right?

233
00:09:59,970 --> 00:10:01,170
They're gonna say, "Okay,
I can do that later.

234
00:10:01,170 --> 00:10:04,137
You gave me the choice to
ignore, so I'm gonna ignore it."

235
00:10:05,010 --> 00:10:06,270
Now, a better approach

236
00:10:06,270 --> 00:10:10,230
would be to maybe include a
brief description of the patch

237
00:10:10,230 --> 00:10:11,160
and severity level.

238
00:10:11,160 --> 00:10:14,730
So the patch is doing X,
Y, Z, and it's critical.

239
00:10:14,730 --> 00:10:17,330
That might prompt the user
to take the right action.

240
00:10:18,450 --> 00:10:21,900
We may wanna give the user an
option to schedule the update

241
00:10:21,900 --> 00:10:23,640
and the reboot so they don't
have to do it right now

242
00:10:23,640 --> 00:10:24,630
'cause you're in the middle of the work.

243
00:10:24,630 --> 00:10:25,890
But do you wanna schedule it

244
00:10:25,890 --> 00:10:28,490
for maybe five o'clock when
you're done for the day?

245
00:10:29,640 --> 00:10:31,770
And if it's a critical patch,

246
00:10:31,770 --> 00:10:34,140
maybe we're gonna allow just
a very short grace period

247
00:10:34,140 --> 00:10:36,180
and then require installation.

248
00:10:36,180 --> 00:10:38,070
So we're not gonna give them an option.

249
00:10:38,070 --> 00:10:40,140
We might say, "Listen,
you have five minutes

250
00:10:40,140 --> 00:10:43,470
to save your work because
this patch must be installed.

251
00:10:43,470 --> 00:10:44,910
It is absolutely critical."

252
00:10:44,910 --> 00:10:49,110
But we wanna be sure to be
very, very clear about this.

253
00:10:49,110 --> 00:10:52,020
So the goal is that we
wanna be partners, right,

254
00:10:52,020 --> 00:10:53,100
with our user community.

255
00:10:53,100 --> 00:10:55,020
We want them to understand
what we're doing

256
00:10:55,020 --> 00:10:56,820
and we don't want them to ever feel

257
00:10:56,820 --> 00:10:58,980
like it's burdensome or inconvenient.

258
00:10:58,980 --> 00:11:00,900
And we definitely don't
want them circumventing

259
00:11:00,900 --> 00:11:02,040
our controls.

260
00:11:02,040 --> 00:11:04,200
So being able to do
this type of assessment

261
00:11:04,200 --> 00:11:06,780
and have this conversation
with your user community,

262
00:11:06,780 --> 00:11:09,840
absolutely, you know what it
is, it's security in action.

263
00:11:09,840 --> 00:11:11,730
There's your word cloud.

264
00:11:11,730 --> 00:11:12,563
There's a lot there.

265
00:11:12,563 --> 00:11:15,360
We covered a ton, a ton
of different principles

266
00:11:15,360 --> 00:11:16,350
and concepts.

267
00:11:16,350 --> 00:11:17,700
These are all really important.

268
00:11:17,700 --> 00:11:19,950
I would expect to see these on your exam.

269
00:11:19,950 --> 00:11:21,210
Well, really, just like everything else

270
00:11:21,210 --> 00:11:24,030
probably in this course, but
these are really important.

271
00:11:24,030 --> 00:11:26,070
So make sure you can speak to all of them.

272
00:11:26,070 --> 00:11:28,170
Go back to the lesson if you can't.

273
00:11:28,170 --> 00:11:30,330
And then when you're ready,
hop on over to the next lesson.

274
00:11:30,330 --> 00:11:31,830
I'll be waiting for you there.
