1
00:00:06,510 --> 00:00:08,280
- [Instructor] In this
closer look segment,

2
00:00:08,280 --> 00:00:11,493
we're gonna talk a bit more
about policies and standards.

3
00:00:14,111 --> 00:00:14,944
Now in the lesson,

4
00:00:14,944 --> 00:00:18,510
we looked at the entire pantheon
of governance documents:

5
00:00:18,510 --> 00:00:23,510
policies, agreements, standards,
guidelines, and procedures.

6
00:00:24,330 --> 00:00:27,150
Now agreements are used to enforce policy

7
00:00:27,150 --> 00:00:30,420
and standards are used
to implement policy.

8
00:00:30,420 --> 00:00:34,710
But what I find very often
is there's a lot of confusion

9
00:00:34,710 --> 00:00:38,160
between really what's the
difference between a policy

10
00:00:38,160 --> 00:00:41,400
and a standard and what
belongs in a policy

11
00:00:41,400 --> 00:00:43,620
and what belongs in a standard.

12
00:00:43,620 --> 00:00:45,750
They are two different documents

13
00:00:45,750 --> 00:00:48,240
but they are closely aligned.

14
00:00:48,240 --> 00:00:50,910
And then our third document
being our guideline

15
00:00:50,910 --> 00:00:53,610
that we used to help our user community

16
00:00:53,610 --> 00:00:55,080
implement our standard.

17
00:00:55,080 --> 00:00:57,810
So let's take a closer look at a policy,

18
00:00:57,810 --> 00:01:00,273
a standard, and a guideline.

19
00:01:01,920 --> 00:01:04,320
Now we define policies and
standards in the lesson

20
00:01:04,320 --> 00:01:05,970
but I wanna do it again.

21
00:01:05,970 --> 00:01:08,430
Our information security policies

22
00:01:08,430 --> 00:01:11,220
codify high-level requirements

23
00:01:11,220 --> 00:01:14,820
for protecting information
and information assets

24
00:01:14,820 --> 00:01:18,900
and ensuring confidentiality,
integrity, and availability.

25
00:01:18,900 --> 00:01:20,730
Codify high level,

26
00:01:20,730 --> 00:01:22,560
that's the thing to remember.

27
00:01:22,560 --> 00:01:24,840
Think about who approves policy.

28
00:01:24,840 --> 00:01:27,390
Policies are approved by
the board of directors

29
00:01:27,390 --> 00:01:30,390
or the board of trustees
or executive management.

30
00:01:30,390 --> 00:01:34,710
They are setting the tone,
the tenor, the direction

31
00:01:34,710 --> 00:01:36,210
for the organization,

32
00:01:36,210 --> 00:01:39,990
and they're also assigning
roles and responsibilities.

33
00:01:39,990 --> 00:01:43,170
So, that's what we expect
to see in a policy.

34
00:01:43,170 --> 00:01:46,383
We don't expect to see
nitty gritty details.

35
00:01:47,820 --> 00:01:51,210
In contrast, an information
security standard

36
00:01:51,210 --> 00:01:53,280
includes the specifications

37
00:01:53,280 --> 00:01:55,980
for the implementation of the policy

38
00:01:55,980 --> 00:01:59,580
and they dictate mandatory requirements.

39
00:01:59,580 --> 00:02:02,640
So our policies give
us to speak direction.

40
00:02:02,640 --> 00:02:05,910
Our standards say, "Okay,
based on the policy,

41
00:02:05,910 --> 00:02:08,610
this is exactly how we're going to do it

42
00:02:08,610 --> 00:02:11,310
and these are our mandatory requirements."

43
00:02:11,310 --> 00:02:14,580
Who's involved in constructing standards?

44
00:02:14,580 --> 00:02:17,190
Well, experts in the respective areas.

45
00:02:17,190 --> 00:02:19,590
Technologists for IT standard,

46
00:02:19,590 --> 00:02:22,080
trainers for education standards,

47
00:02:22,080 --> 00:02:24,210
auditors for audit standards.

48
00:02:24,210 --> 00:02:26,160
That we engage the experts that have

49
00:02:26,160 --> 00:02:29,340
that very deep knowledge in their specific

50
00:02:29,340 --> 00:02:31,290
and respective areas.

51
00:02:31,290 --> 00:02:34,293
So let's take a look at
a policy and a standard.

52
00:02:35,250 --> 00:02:37,623
This is a section from
authentication policy.

53
00:02:38,970 --> 00:02:41,850
A is all about authentication factors.

54
00:02:41,850 --> 00:02:43,410
It says that data classifications,

55
00:02:43,410 --> 00:02:44,490
regulatory requirements,

56
00:02:44,490 --> 00:02:46,830
and the impact of unauthorized access

57
00:02:46,830 --> 00:02:49,440
and the likelihood of
a threat being exercise

58
00:02:49,440 --> 00:02:52,050
must all be considered
when deciding upon the type

59
00:02:52,050 --> 00:02:55,050
and number of authentication factors.

60
00:02:55,050 --> 00:02:56,970
That the Office of Information Security

61
00:02:56,970 --> 00:02:58,290
will make this determination

62
00:02:58,290 --> 00:03:00,990
in conjunction with the
information system owner

63
00:03:00,990 --> 00:03:03,930
and that this process must be documented.

64
00:03:03,930 --> 00:03:06,810
Now, you'll notice that
we're not saying in a VPN,

65
00:03:06,810 --> 00:03:08,460
you need to have this type of factor

66
00:03:08,460 --> 00:03:10,470
and this number of factors.

67
00:03:10,470 --> 00:03:11,520
For network login,

68
00:03:11,520 --> 00:03:12,870
you need to have this type of factor

69
00:03:12,870 --> 00:03:14,880
and this many for your smartphone.

70
00:03:14,880 --> 00:03:17,160
We're not seeing any of that, right?

71
00:03:17,160 --> 00:03:19,560
What we're getting is
that here are the things

72
00:03:19,560 --> 00:03:23,160
when you're making the
decision about the standard

73
00:03:23,160 --> 00:03:25,770
that you must take into consideration.

74
00:03:25,770 --> 00:03:27,720
And there's roles and responsibilities

75
00:03:27,720 --> 00:03:29,880
that the Office of the
Information Security

76
00:03:29,880 --> 00:03:31,440
will make this determination

77
00:03:31,440 --> 00:03:33,810
in conjunction with the
information system owner

78
00:03:33,810 --> 00:03:35,820
and that we have to document this process.

79
00:03:35,820 --> 00:03:38,913
We have to make sure it's a
formal, documented process.

80
00:03:40,830 --> 00:03:43,350
Then the policy goes on to say

81
00:03:43,350 --> 00:03:45,240
that factor requirements must comply

82
00:03:45,240 --> 00:03:47,490
with the minimum requirements
or stronger detailed

83
00:03:47,490 --> 00:03:52,140
in NIST SP800-63B Digital
Identity Guidelines.

84
00:03:52,140 --> 00:03:53,400
Why we be told that?

85
00:03:53,400 --> 00:03:54,233
Because we're being told

86
00:03:54,233 --> 00:03:56,730
that the organization has made a decision

87
00:03:56,730 --> 00:03:59,640
to align with an external standard.

88
00:03:59,640 --> 00:04:01,620
So when we're creating our standards,

89
00:04:01,620 --> 00:04:03,570
we must align with those standards.

90
00:04:03,570 --> 00:04:05,130
That's what we've adopted.

91
00:04:05,130 --> 00:04:07,830
And that any changes in factor
requirements must be approved

92
00:04:07,830 --> 00:04:09,120
by the chief security officer,

93
00:04:09,120 --> 00:04:10,860
the chief information officer,

94
00:04:10,860 --> 00:04:12,720
and the chief operating officer.

95
00:04:12,720 --> 00:04:15,510
Again, another role and responsibility.

96
00:04:15,510 --> 00:04:16,770
So what are we seeing here?

97
00:04:16,770 --> 00:04:19,143
Again, high level instructions.

98
00:04:20,160 --> 00:04:22,140
We're being told about
the external standard

99
00:04:22,140 --> 00:04:23,730
that we're going to align with

100
00:04:23,730 --> 00:04:26,280
and we've got roles and responsibilities.

101
00:04:26,280 --> 00:04:28,650
That's what belongs in a policy.

102
00:04:28,650 --> 00:04:30,573
Let's compare that with a standard.

103
00:04:30,573 --> 00:04:34,170
This is a standard for a
single factor memorized secret.

104
00:04:34,170 --> 00:04:36,690
Now a memorized secret is just a fancy way

105
00:04:36,690 --> 00:04:37,680
of saying password.

106
00:04:37,680 --> 00:04:39,000
And I'm using that term

107
00:04:39,000 --> 00:04:43,260
because that's what we
actually see in NIST SP800-63.

108
00:04:43,260 --> 00:04:44,850
And I really love the term

109
00:04:44,850 --> 00:04:46,590
because our users can relate to it well.

110
00:04:46,590 --> 00:04:48,240
They understand what a secret is

111
00:04:48,240 --> 00:04:50,190
and they know what it means
to memorize something.

112
00:04:50,190 --> 00:04:52,110
So, memorized secret.

113
00:04:52,110 --> 00:04:55,260
So the construction standard
is very, very specific.

114
00:04:55,260 --> 00:04:56,670
This is for single factor

115
00:04:56,670 --> 00:04:59,370
which is what we normally
think of as a password.

116
00:04:59,370 --> 00:05:00,570
8 characters minimum,

117
00:05:00,570 --> 00:05:02,490
64 characters maximum.

118
00:05:02,490 --> 00:05:03,960
And here's what you can't have.

119
00:05:03,960 --> 00:05:07,500
Repetitive which is three or
more or sequential characters.

120
00:05:07,500 --> 00:05:08,603
AAAAA.

121
00:05:08,603 --> 00:05:09,436
1234.

122
00:05:09,436 --> 00:05:10,590
ABCD.

123
00:05:10,590 --> 00:05:13,170
You can't use a single dictionary word

124
00:05:13,170 --> 00:05:15,480
and you can't use context-specific words

125
00:05:15,480 --> 00:05:18,090
such as the name of a
user company or department

126
00:05:18,090 --> 00:05:20,070
and derivatives thereof.

127
00:05:20,070 --> 00:05:20,903
Now you might be saying,

128
00:05:20,903 --> 00:05:22,260
"Well, what about complexity?

129
00:05:22,260 --> 00:05:24,660
Aren't we gonna tell them to
use uppercase and lowercase,

130
00:05:24,660 --> 00:05:26,340
a number, and a special character?"

131
00:05:26,340 --> 00:05:28,260
And the answer is actually not.

132
00:05:28,260 --> 00:05:31,500
Because in the NIST
digital identity standard,

133
00:05:31,500 --> 00:05:32,737
they've done away with that and says,

134
00:05:32,737 --> 00:05:35,100
"You know, that just
made it really difficult

135
00:05:35,100 --> 00:05:36,690
for our user community.

136
00:05:36,690 --> 00:05:38,610
And in the end, from a
security perspective,

137
00:05:38,610 --> 00:05:41,307
it really didn't make
a lot of difference."

138
00:05:42,480 --> 00:05:45,660
So even though this
standard is fairly simple,

139
00:05:45,660 --> 00:05:47,430
it might throw our users off.

140
00:05:47,430 --> 00:05:49,380
So we are gonna have to find a way

141
00:05:49,380 --> 00:05:52,680
to help them construct their password

142
00:05:52,680 --> 00:05:54,750
in accordance with this standard.

143
00:05:54,750 --> 00:05:57,570
But you notice the standard's
very, very specific.

144
00:05:57,570 --> 00:05:59,640
It's got input probably from people

145
00:05:59,640 --> 00:06:01,580
in the information security department

146
00:06:01,580 --> 00:06:04,110
or in the IT department, right?

147
00:06:04,110 --> 00:06:07,110
And this is what is
absolutely required, right?

148
00:06:07,110 --> 00:06:09,213
These are mandatory requirements.

149
00:06:11,790 --> 00:06:13,470
Now, let's look at a guideline.

150
00:06:13,470 --> 00:06:16,080
Now, this is a guideline
that was issued by NIST.

151
00:06:16,080 --> 00:06:18,450
Now, that has three
actually guidelines in one.

152
00:06:18,450 --> 00:06:19,500
I like all three of them.

153
00:06:19,500 --> 00:06:22,650
It's number two that's really
of the biggest concern to us.

154
00:06:22,650 --> 00:06:24,870
But the first one is don't
rely on passwords alone

155
00:06:24,870 --> 00:06:26,640
to protect anything you value.

156
00:06:26,640 --> 00:06:29,100
Turn on multifactor
authentication whenever possible.

157
00:06:29,100 --> 00:06:30,450
Great advice.

158
00:06:30,450 --> 00:06:31,830
But the second one is the one I love

159
00:06:31,830 --> 00:06:34,530
in terms of this memorized secret.

160
00:06:34,530 --> 00:06:36,333
Use a phrase with multiple words

161
00:06:36,333 --> 00:06:38,490
that you can picture in your head.

162
00:06:38,490 --> 00:06:42,120
So it's difficult to guess
but easy to remember.

163
00:06:42,120 --> 00:06:45,210
And the example they give
is "sunwalkraindrive".

164
00:06:45,210 --> 00:06:46,043
I love it.

165
00:06:46,043 --> 00:06:47,670
"sunwalkraindrive".

166
00:06:47,670 --> 00:06:49,170
It's long, you know?

167
00:06:49,170 --> 00:06:51,847
But it means something
to our users, right?

168
00:06:51,847 --> 00:06:54,270
"sunwalkraindrive".

169
00:06:54,270 --> 00:06:56,070
And then number three is just protect

170
00:06:56,070 --> 00:06:58,920
your most important accounts
like banking and primary email

171
00:06:58,920 --> 00:07:01,410
by giving each a unique pass phrase.

172
00:07:01,410 --> 00:07:03,480
So one in three great advice.

173
00:07:03,480 --> 00:07:05,070
Two is the one that really aligns

174
00:07:05,070 --> 00:07:07,050
with what we're trying
to teach them right here.

175
00:07:07,050 --> 00:07:08,397
Again, "sunwalkraindrive".

176
00:07:11,730 --> 00:07:13,020
So just to recap,

177
00:07:13,020 --> 00:07:14,940
policy, high level document

178
00:07:14,940 --> 00:07:19,170
that codifies the
requirements and expectations

179
00:07:19,170 --> 00:07:22,260
for the organization as set
out by board of directors,

180
00:07:22,260 --> 00:07:24,410
board of trustees, or
executive management.

181
00:07:25,350 --> 00:07:29,010
Our standard are mandatory
implementation details.

182
00:07:29,010 --> 00:07:30,930
Our policies are generally approved

183
00:07:30,930 --> 00:07:32,880
on an annual basis, right?

184
00:07:32,880 --> 00:07:35,760
Standards, as long as
they adhere to policy,

185
00:07:35,760 --> 00:07:37,290
can be changed as necessary

186
00:07:37,290 --> 00:07:40,140
and standards generally
don't have to ever go

187
00:07:40,140 --> 00:07:43,680
to the authoritative body
like your board of directors

188
00:07:43,680 --> 00:07:45,360
for approval.

189
00:07:45,360 --> 00:07:48,600
And then guidelines are
going to be audience-specific

190
00:07:48,600 --> 00:07:50,010
and we're gonna develop our guidelines

191
00:07:50,010 --> 00:07:52,410
to help our user community comply

192
00:07:52,410 --> 00:07:54,720
with the required standard.

193
00:07:54,720 --> 00:07:57,060
And that, my friends, is a closer look

194
00:07:57,060 --> 00:07:59,943
at policies, standards, and guidelines.
