1
00:00:06,497 --> 00:00:09,060
- Now in this lesson
9.2, we're gonna look at

2
00:00:09,060 --> 00:00:11,370
one of the ultimate
techniques we use to secure

3
00:00:11,370 --> 00:00:15,960
the enterprise which is
segmentation and isolation.

4
00:00:15,960 --> 00:00:18,780
Segmentation or segmenting an enterprise

5
00:00:18,780 --> 00:00:21,810
into discreet security
zones is really useful

6
00:00:21,810 --> 00:00:24,720
for creating and enforcing
security policies,

7
00:00:24,720 --> 00:00:26,580
controlling information flow,

8
00:00:26,580 --> 00:00:28,743
and for securing network access.

9
00:00:29,670 --> 00:00:31,860
Now, security zones are
going to be divisions

10
00:00:31,860 --> 00:00:35,490
of a network based on
functional, performance,

11
00:00:35,490 --> 00:00:37,740
and/or security requirements.

12
00:00:37,740 --> 00:00:40,170
Now, our security zones
are going to be enforced

13
00:00:40,170 --> 00:00:42,240
by firewall ingress, its incoming,

14
00:00:42,240 --> 00:00:44,970
and egress, outgoing, access control lists

15
00:00:44,970 --> 00:00:48,303
that we refer to as ACLS or rules.

16
00:00:49,650 --> 00:00:52,653
So let's talk about some of
the most common security zones.

17
00:00:53,730 --> 00:00:56,460
We have untrusted zones,
a screened subnet,

18
00:00:56,460 --> 00:01:00,810
a trusted zone, an enclave
zone, an air gapped zone,

19
00:01:00,810 --> 00:01:04,140
a physically isolated
zone, a wireless zone,

20
00:01:04,140 --> 00:01:06,420
and a VPN, a virtual private network.

21
00:01:06,420 --> 00:01:08,160
Now these all stand in contrast

22
00:01:08,160 --> 00:01:10,200
to our discussion about zero trust.

23
00:01:10,200 --> 00:01:13,170
Remember, in zero trust we
said nothing is trusted, right?

24
00:01:13,170 --> 00:01:15,840
Everything is untrusted, and you know,

25
00:01:15,840 --> 00:01:19,230
we don't trust our devices,
we don't trust anything.

26
00:01:19,230 --> 00:01:22,470
But assuming you're not in
a zero trust environment

27
00:01:22,470 --> 00:01:25,050
and we're in sort of a more
conventional environment,

28
00:01:25,050 --> 00:01:27,000
we will probably segment our network

29
00:01:27,000 --> 00:01:28,230
into these security zones.

30
00:01:28,230 --> 00:01:30,280
So let's talk about what these zones are.

31
00:01:31,260 --> 00:01:33,030
An untrusted network is one which

32
00:01:33,030 --> 00:01:34,890
the organization has no control over.

33
00:01:34,890 --> 00:01:37,320
What's the most common
untrusted zone out there?

34
00:01:37,320 --> 00:01:38,460
You know what it is.

35
00:01:38,460 --> 00:01:40,200
It's the internet.

36
00:01:40,200 --> 00:01:43,650
A screened subnet is going to
be a zone that has connections

37
00:01:43,650 --> 00:01:47,100
to both untrusted and trusted networks.

38
00:01:47,100 --> 00:01:49,440
Now, we used to refer to that as a DMZ.

39
00:01:49,440 --> 00:01:51,660
A good example is we might
have a web server, right,

40
00:01:51,660 --> 00:01:54,600
that has connections to
an untrusted network,

41
00:01:54,600 --> 00:01:56,520
to the internet, and to a trusted network

42
00:01:56,520 --> 00:01:59,010
back into our private network.

43
00:01:59,010 --> 00:02:00,660
A trusted network is one over which

44
00:02:00,660 --> 00:02:03,513
the organization does
have complete control.

45
00:02:04,920 --> 00:02:06,540
An enclave network is gonna be

46
00:02:06,540 --> 00:02:09,600
this restricted network
within a trusted network.

47
00:02:09,600 --> 00:02:11,970
So we have a trusted network
and inside it we have

48
00:02:11,970 --> 00:02:15,060
an even more trusted network
called an enclave network.

49
00:02:15,060 --> 00:02:17,430
And maybe that's where
your database servers live

50
00:02:17,430 --> 00:02:19,323
or your authentication servers are.

51
00:02:20,190 --> 00:02:22,740
An air gapped network is
one that does not connect

52
00:02:22,740 --> 00:02:25,650
to any untrusted network or to any network

53
00:02:25,650 --> 00:02:27,270
that connects to an untrusted network

54
00:02:27,270 --> 00:02:29,523
no matter how far down
the line we wanna go.

55
00:02:30,690 --> 00:02:32,580
A physically isolated network is one that

56
00:02:32,580 --> 00:02:35,973
doesn't connect to any other
network, period, that's it.

57
00:02:37,140 --> 00:02:38,850
A wireless network, well, that's one that

58
00:02:38,850 --> 00:02:40,680
supports wireless transmissions.

59
00:02:40,680 --> 00:02:43,620
And lastly, a VPN or a
virtual private network

60
00:02:43,620 --> 00:02:46,710
is designed to facilitate
secure communications

61
00:02:46,710 --> 00:02:48,003
over a public circuit.

62
00:02:51,180 --> 00:02:55,080
Another type of segmentation
is known as micro-segmentation.

63
00:02:55,080 --> 00:02:57,150
And we tend to see micro-segmentation

64
00:02:57,150 --> 00:03:00,330
either in a data center or up
in the cloud infrastructure,

65
00:03:00,330 --> 00:03:02,130
so not apparent to the end user,

66
00:03:02,130 --> 00:03:05,280
but how the cloud is
configured and structured.

67
00:03:05,280 --> 00:03:08,070
So I wanna talk about what
micro-segmentation is.

68
00:03:08,070 --> 00:03:10,980
I wanna define east-west
and north-south traffic,

69
00:03:10,980 --> 00:03:12,840
talk about what a protect surface is,

70
00:03:12,840 --> 00:03:16,323
and then once again, circle
back to the idea of zero trust.

71
00:03:17,580 --> 00:03:20,130
So micro-segmentation
is a method of creating

72
00:03:20,130 --> 00:03:23,310
these sort of micro zones if
you will within a data center

73
00:03:23,310 --> 00:03:26,460
and cloud environments in
order to isolate workloads

74
00:03:26,460 --> 00:03:29,463
from one another and to
secure them individually.

75
00:03:31,260 --> 00:03:33,870
Now when you hear the term
north-south, we're referring to

76
00:03:33,870 --> 00:03:36,720
traffic that flows in
and out of a data center.

77
00:03:36,720 --> 00:03:38,790
And when you hear the term east-west,

78
00:03:38,790 --> 00:03:40,590
we're talking about traffic that flows

79
00:03:40,590 --> 00:03:43,590
within the data center or
within the cloud environment

80
00:03:43,590 --> 00:03:47,013
and generally through
various micro segments.

81
00:03:48,270 --> 00:03:50,490
Now, the protect service is made up

82
00:03:50,490 --> 00:03:54,900
of your network's most critical
and valuable data, assets,

83
00:03:54,900 --> 00:03:58,500
applications, and services known as DAAS,

84
00:03:58,500 --> 00:04:01,890
data, assets, applications, and services.

85
00:04:01,890 --> 00:04:03,990
And here's the thing
about the protect surface.

86
00:04:03,990 --> 00:04:05,430
It's always knowable.

87
00:04:05,430 --> 00:04:08,160
These are your most valuable
and most critical assets.

88
00:04:08,160 --> 00:04:09,510
You will always know what they are

89
00:04:09,510 --> 00:04:11,490
or should at least always
know what they are,

90
00:04:11,490 --> 00:04:14,160
which stands in stark contrast
to your entire network,

91
00:04:14,160 --> 00:04:16,020
where there may be things that

92
00:04:16,020 --> 00:04:17,190
you have no idea what they are.

93
00:04:17,190 --> 00:04:18,630
They might be things a vendor brought in,

94
00:04:18,630 --> 00:04:20,220
things that user brought in.

95
00:04:20,220 --> 00:04:22,920
The protect surface is your
network's most critical

96
00:04:22,920 --> 00:04:26,460
and valuable data, assets,
applications, and services.

97
00:04:26,460 --> 00:04:29,520
And bearing in mind it's always knowable.

98
00:04:29,520 --> 00:04:30,900
So what does that mean?

99
00:04:30,900 --> 00:04:33,510
That means that
micro-segmentation allows us

100
00:04:33,510 --> 00:04:35,580
for the implementation of what's known

101
00:04:35,580 --> 00:04:38,520
as a zero trust protect
surface environment.

102
00:04:38,520 --> 00:04:41,280
Protect surface, that was our
most valuable assets, right?

103
00:04:41,280 --> 00:04:42,150
DAAS.

104
00:04:42,150 --> 00:04:45,390
It allows us to take that area, right,

105
00:04:45,390 --> 00:04:46,590
put a boundary around it,

106
00:04:46,590 --> 00:04:50,430
and say this is going to be
a zero trust environment.

107
00:04:50,430 --> 00:04:52,410
So assuming we're not zero trust

108
00:04:52,410 --> 00:04:55,050
in our entire enterprise
or infrastructure,

109
00:04:55,050 --> 00:04:57,480
we can have a more
conventional infrastructure

110
00:04:57,480 --> 00:05:01,170
but we can say in our protect surface area

111
00:05:01,170 --> 00:05:03,660
we're putting a boundary,
right, around those assets.

112
00:05:03,660 --> 00:05:06,870
And for those, we're gonna
configure as zero trust.

113
00:05:06,870 --> 00:05:10,440
And in zero trust,
authentication is always required

114
00:05:10,440 --> 00:05:13,500
and re-authentication, and it enforces

115
00:05:13,500 --> 00:05:14,970
the least privileged access.

116
00:05:14,970 --> 00:05:16,350
So you're only gonna get access

117
00:05:16,350 --> 00:05:19,773
for what you need to do for
a limited amount of time.

118
00:05:20,610 --> 00:05:23,880
So that's a really good way
of thinking about how do we,

119
00:05:23,880 --> 00:05:27,510
in our more conventional
environments, also take advantage

120
00:05:27,510 --> 00:05:29,943
of the power of a zero trust environment.

121
00:05:32,550 --> 00:05:36,000
Now, another way to segment
is referred to as isolation.

122
00:05:36,000 --> 00:05:39,630
Isolation is when a zone
or a device or a session

123
00:05:39,630 --> 00:05:42,360
or even an individual component
needs to be segregated

124
00:05:42,360 --> 00:05:46,203
from others so as not to
cause harm or to be harmed.

125
00:05:47,280 --> 00:05:49,890
Now, there are two
different types of isolation

126
00:05:49,890 --> 00:05:50,970
I wanna introduce you to.

127
00:05:50,970 --> 00:05:53,820
Virtualization and logical.

128
00:05:53,820 --> 00:05:57,060
The virtualization technology
creates multiple environments

129
00:05:57,060 --> 00:05:59,670
from a single physical hardware system.

130
00:05:59,670 --> 00:06:01,860
And I know many of you work
in virtual environments.

131
00:06:01,860 --> 00:06:04,800
You work with virtual
machines or virtual desktops

132
00:06:04,800 --> 00:06:07,170
or virtual network devices.

133
00:06:07,170 --> 00:06:10,290
So what these virtual
devices do really is provide

134
00:06:10,290 --> 00:06:14,190
fault and security isolation
at the hardware level

135
00:06:14,190 --> 00:06:16,953
including memory and CPU access.

136
00:06:18,000 --> 00:06:20,730
Another way to do isolation
is logical isolation.

137
00:06:20,730 --> 00:06:23,670
And really the best example
of logical isolation

138
00:06:23,670 --> 00:06:26,730
would be a VLAN, a virtual
local area network,

139
00:06:26,730 --> 00:06:29,040
which divides a single existing network,

140
00:06:29,040 --> 00:06:32,700
a physical network into multiple
logical network segments

141
00:06:32,700 --> 00:06:34,440
which then can be restricted.

142
00:06:34,440 --> 00:06:36,570
And our broadcast domains are portioned

143
00:06:36,570 --> 00:06:38,973
and they're isolated
at the data link layer.

144
00:06:42,720 --> 00:06:44,340
And that, my friends, brings us

145
00:06:44,340 --> 00:06:46,470
to the end of this particular lesson.

146
00:06:46,470 --> 00:06:48,180
So you ready for a three-second challenge?

147
00:06:48,180 --> 00:06:49,013
Let's do it.

148
00:06:51,090 --> 00:06:54,630
A zone that connects to both
trusted and untrusted networks.

149
00:06:54,630 --> 00:06:55,860
What's it called?

150
00:06:55,860 --> 00:06:57,423
One, two, three.

151
00:06:59,040 --> 00:07:00,740
That's gonna be a screened subnet.

152
00:07:01,980 --> 00:07:04,350
Question two, a network that's isolated

153
00:07:04,350 --> 00:07:07,380
from any untrusted network.

154
00:07:07,380 --> 00:07:08,913
One, two, three.

155
00:07:10,020 --> 00:07:11,270
It's gonna be air gapped.

156
00:07:12,180 --> 00:07:14,370
Number three, technology that creates

157
00:07:14,370 --> 00:07:15,960
multiple isolated environments

158
00:07:15,960 --> 00:07:18,153
from a single physical hardware host.

159
00:07:19,020 --> 00:07:20,493
One, two, three.

160
00:07:21,930 --> 00:07:23,250
And that's virtualization.

161
00:07:23,250 --> 00:07:25,200
And if you're thinking, "Yeah,
we didn't spend much time

162
00:07:25,200 --> 00:07:27,810
talking about virtualization," no worries.

163
00:07:27,810 --> 00:07:30,443
We're going to be talking
about it a little bit later on.

164
00:07:31,920 --> 00:07:35,550
Question four, a method to
isolate data center workloads

165
00:07:35,550 --> 00:07:38,340
and secure them individually.

166
00:07:38,340 --> 00:07:40,590
One, two, three.

167
00:07:40,590 --> 00:07:43,260
And that's micro-segmentation.

168
00:07:43,260 --> 00:07:45,360
And lastly, number five, made up of

169
00:07:45,360 --> 00:07:48,150
the network's most critical and valuable

170
00:07:48,150 --> 00:07:53,150
data, assets, applications
and services, DAAS.

171
00:07:53,430 --> 00:07:54,870
What is that called?

172
00:07:54,870 --> 00:07:58,320
It's what allows us to implement
a zero trust environment.

173
00:07:58,320 --> 00:08:00,540
One, two, three.

174
00:08:00,540 --> 00:08:02,643
And that's gonna be our protect surface.

175
00:08:03,690 --> 00:08:04,523
Right, that brings us to

176
00:08:04,523 --> 00:08:06,813
a security-in-action about segmentation.

177
00:08:07,860 --> 00:08:10,710
So your company is considering
moving your infrastructure

178
00:08:10,710 --> 00:08:12,900
to an outsourced data center.

179
00:08:12,900 --> 00:08:16,830
Now the vision is that users
would VPN in to the data center

180
00:08:16,830 --> 00:08:19,050
from wherever they happen to be located.

181
00:08:19,050 --> 00:08:23,100
However, there is a concern
about critical system exposure.

182
00:08:23,100 --> 00:08:25,020
So you've been tasked with investigating

183
00:08:25,020 --> 00:08:28,200
various data centers in
your geographic area.

184
00:08:28,200 --> 00:08:31,200
Now on one of your tours, the guide extols

185
00:08:31,200 --> 00:08:35,190
the virtue of east-west data
center micro-segmentation

186
00:08:35,190 --> 00:08:37,920
and air gapped networking.

187
00:08:37,920 --> 00:08:39,780
So here's my question to you.

188
00:08:39,780 --> 00:08:43,080
Are these concepts applicable
to your organization?

189
00:08:43,080 --> 00:08:45,120
So you're looking to move, right,

190
00:08:45,120 --> 00:08:49,470
your infrastructure to this
outsourced data center.

191
00:08:49,470 --> 00:08:51,390
We do have users who are gonna VPN in

192
00:08:51,390 --> 00:08:54,420
from wherever they are,
but we do have a concern

193
00:08:54,420 --> 00:08:56,760
about critical system exposure.

194
00:08:56,760 --> 00:08:59,340
We wanna protect our most critical assets.

195
00:08:59,340 --> 00:09:00,277
So our tour guide says,

196
00:09:00,277 --> 00:09:02,490
"Wow, this is just a great place for you.

197
00:09:02,490 --> 00:09:06,000
We have east-west data
center micro-segmentation

198
00:09:06,000 --> 00:09:08,550
and we have air gapped networking."

199
00:09:08,550 --> 00:09:10,410
And I want you to tell me
is that gonna work for you.

200
00:09:10,410 --> 00:09:11,730
So go ahead, put me on pause,

201
00:09:11,730 --> 00:09:13,830
jot down some notes,
and then come on back,

202
00:09:13,830 --> 00:09:15,780
and we'll talk about the applicability.

203
00:09:18,810 --> 00:09:22,560
So for sure east-west
micro-segmentation is worth exploring.

204
00:09:22,560 --> 00:09:24,210
Right, an advantage to that design

205
00:09:24,210 --> 00:09:25,980
is it reduces the surface available

206
00:09:25,980 --> 00:09:29,130
for malicious activity and
it allows the implementation

207
00:09:29,130 --> 00:09:31,050
of targeted security policies.

208
00:09:31,050 --> 00:09:33,210
So for your most critical systems,

209
00:09:33,210 --> 00:09:36,120
thinking about this
east-west micro-segmentation

210
00:09:36,120 --> 00:09:38,730
really does make a lot of sense.

211
00:09:38,730 --> 00:09:40,440
But the other part, the fact that

212
00:09:40,440 --> 00:09:43,260
it's an air gapped network
doesn't work, right?

213
00:09:43,260 --> 00:09:44,940
An air gapped network is isolated

214
00:09:44,940 --> 00:09:47,700
from any wired or
wireless untrusted network

215
00:09:47,700 --> 00:09:49,200
or to any computers that connect

216
00:09:49,200 --> 00:09:51,720
to an untrusted network
or any network that

217
00:09:51,720 --> 00:09:53,550
connects to an untrusted network.

218
00:09:53,550 --> 00:09:56,340
And that design isn't gonna
work specifically, right,

219
00:09:56,340 --> 00:09:59,040
because what we're saying
here is your network

220
00:09:59,040 --> 00:10:02,820
needs to be connected to
the internet for VPN access.

221
00:10:02,820 --> 00:10:04,620
And what is the internet but really

222
00:10:04,620 --> 00:10:07,020
the ultimate untrusted network.

223
00:10:07,020 --> 00:10:09,390
So being able to kind of dissect, right,

224
00:10:09,390 --> 00:10:10,597
what someone's saying to you, it's like,

225
00:10:10,597 --> 00:10:12,150
"Oh, this is both great things."

226
00:10:12,150 --> 00:10:13,627
I want you to be able to say,

227
00:10:13,627 --> 00:10:17,010
"Well no, they're not
necessarily applicable, right?

228
00:10:17,010 --> 00:10:20,670
They don't necessarily meet
what my organization needs.

229
00:10:20,670 --> 00:10:23,610
They don't necessarily strategically align

230
00:10:23,610 --> 00:10:25,740
with the needs of my organization."

231
00:10:25,740 --> 00:10:27,330
And being able to do that, my friends,

232
00:10:27,330 --> 00:10:29,823
is without a doubt security-in-action.

233
00:10:30,840 --> 00:10:31,860
There's your word cloud.

234
00:10:31,860 --> 00:10:33,120
There's quite a bit here again.

235
00:10:33,120 --> 00:10:36,180
You know what to do, make sure
you really, really understand

236
00:10:36,180 --> 00:10:38,820
all of these terms and
concepts before moving on.

237
00:10:38,820 --> 00:10:40,590
But when you're ready, we're gonna do

238
00:10:40,590 --> 00:10:42,120
a five-question quiz together.

239
00:10:42,120 --> 00:10:43,070
I'll see you there.
