Das Video kommt von YouTube: erst beim Abspielen verbindet sich die Seite mit YouTube (Google).
2.1 Introduction to Security Within the Organization
Das Wichtigste aus dem Video
Tipp auf eine Zeit – das Video springt genau dorthin.
Transkriptautomatisch erstellt · 944 Zeilen
- Today uh we'll study this uh uh class. This is the GRC governance uh risks and compliance. This is the mostly um theoretical class and very very
- important for your cyber security uh knowledge. So today I introduced uh our new instructor. This is the name is Ciphel Motion. Basically uh he um came
- from our first batch and u uh this is the our culture we started this our culture. Alhamdulillah Allah granted us uh he joined uh us uh
- 25 from January and alhamdulillah now is September and uh we successfully landed our team and um inshallah uh 2026 middle we
- are starting this our MSP Slowly slowly we uh make our good team uh inshallah. So everyone help us and everyone um join with us. This is our new instructor
- Safil Moshid today. Uh contact this class. Uh but I am available is online. If anything problem uh Safil Moshidwai so you just study class anything uh
- problem just not me.Am Yeah, sure. Asalamaikum all. Yeah, I think I spoke with this B like other day so I don't need to reintroduce myself
- but uh let's get started then. So today the class actually we are focusing on GRC right the main whole uh 3 hours class will be GRC so cyberc introduction
- of cyber security within organization because uh GRC related with this organization and employees. So that's why this is the headline you can see.
- Are you guys hear me clear? Right? Anybody can confirm? >> Yeah. At least I can hear you. Yeah. Clearly.
- >> Perfect. Uh so uh if I go here like class objective by end of this class actually we'll be identify the uh actually the theory concrete benefit of
- healthy security culture. What does it mean healthy security culture? And then explain the responsibilities of the sweet officers and the CISO. It's
- like high management. Explain the responsibility of security department and identify the appropriate security controls uh for a given
- resource and situation. So this will be our class objective that we learn actually in going forward step by step. So security alignment with this
- organization. If you go to the next slide, this is like the example of this like the how actually organization structure. You see that here like you
- know uh in the top like chief security risks officer then enterprise chief officer head of the production. So under head of
- the uh what is call then enterprise CIO and under him like IT operation uh what is called incident response and IT security team and here enterprise
- chief security officer he's actually like managing this area chief information security uh of uh what is called uh of
- enterprise chief security officer okay under his like this is actually job title Chief information security officer and
- security standard. So it is belongs to him like reporting to him and the security architect depends on like it can be very like organization to
- organization. This is like one kind of example looks like from the larger organization but if it is smaller or medium it could be like little bit
- different but this is high level overview but our objective is today to understand actually GRC and this will be related
- with this organization you know. So if I go to the here GRC framework so here in the you see like GRC frame GRC framework is answering the following
- question. So there's a two question what asset are most important and this qu and second question what is the earthquake protection.
- So if I ask you guys like what do you mean what like what is mean by asset anybody can like you know think about like what is asset means by
- uh if you took actually non techchnical example for asset. So this is very important like these terms actually you need to understand actually in the real
- what is called uh in technical terms too in order to work in real uh environment. So if you think about asset as a nontechnical example like asset means
- for example like jewelry important documents family for tool right this is like very very valuable asset if you think about like what is called less
- important asset let's say like old magazine or any newspaper you can think about like what is called this is less important asset right
- and if you think about like what is called the asset of like in cyber security terms. So what does it mean then asset right? So asset means like
- for example the data system and the people right. So anything like you know the world actually everything like is data driven like everything depending on
- data. So ini in GRC term here like in cyber security asset we can actually define for example like customer information financial record
- intellectual property this kind of data you can consider as a like uh what is called asset also in the system like if you think about like system perspective
- your server your asset your database your asset your apps your endpoint your asset right if you think about like what is called the people like people with
- the private delayed access for example like you know who can manage actually the uh database server who can manage let's say uh networking you know so
- those kind of things in cyber security you can consider as a asset so how we can actually what is called uh identify and classify the asset
- so it's like there is in cyber security term is called CIA trade I think you guys can learn later or maybe you already knows
- like this is this will be help you actually to identify and classify the asset. So any question guide asks to hear what
- does it mean asset you know in cyber security terms no question so basically you're trying to say that
- asset means anything part of uh this program like you know part of cyber security or part of you know technologies for example data
- information or it could the admin information or as admin in a team. Right. >> Right. Because like if you lost to your
- asset, you'll be what is called lose your value or business or it can arm you. Right. So if you lose something actually if it is affected and if you
- lose something that means this is you can consider your asset and you can classify your asset you know this like it can be like higher priority less
- priority right and based on this asset priority you should be define your security so we'll be so this so how we can actually
- define the security based on actually next question >> okay so here is saying that like we so by this what we already knows what is
- mean by asset Right. So and next question what is adequate protection? So adequate protection is means actually applying the right level of security
- controls like based on value and risks. It is like uh you cannot actually make everything 100% secure. It's like impossible right? Uh but you need to
- ensure actually what is called uh uh protection balance based on your uh asset value. for example like a nontechnical example jewelry right or
- your important documents. So this is actually very valuable asset for you. So if it is valuable you need actually like let's say strong protection you you can
- uh what is you should be keep this kind of um uh asset in the safe locker right because it's valuable but for example like uh and this is nothing but adequate
- protection how you can actually define your protection based on value and then for example as I said earlier like old magazine uh maybe you can
- simply put in your glass cabinet this is enough so now what What is mean by that? Actually you don't need to actually is define actually quick protection. You
- don't need to over need to overspending for lock everything. Uh so you just need to lock or put a security that you care about right
- for uh example in like cyber security terms uh for example like what do you think about like a high level uh asset as I said like you know the data so data
- let's say your customer data or let's say your bank account or user information right so in this case you need here like you know this kind of
- strong security for example you can you should encrypt your data. You can uh apply multi-pro multiffactor authentication
- or regular what what it uh you will be learn about like I think going for CM monitoring like oh if something happening within your asset or any what
- is called um like uh malicious activities you need actually monitoring system. So that you you guys will be learn later but here we
- are trying to understand actually what kind of protection we need based on as I said uh risk uh what is called asset value
- uh lower value we can consider is like you know uh in cyber security term let's say there is a company booklet let's say once if you are joining any company
- there's a benefit booklet oh what kind of benefit you can get from this company so this is not like what is called u import very important asset you can
- consider this kind of things like lower value because if you lose you are not losing any I think what is called let's say business or something like it's not
- going to uh arm your business. So that's how actually you can define first you need to define your asset and then what is called identify the value and then
- based on value you need to actually define your production. This is nothing but called protection. Uh any question guys up to here?
- >> Um can I share something? Um so you trying to say that uh you know we need there should be nothing less or nothing more
- >> right. uh based on our assets below we need to provide the protection let's say if there is need one security for example one security guy
- >> to uh take care of building I don't need to provide two people there right >> or probably there might be there I need five of them so I need to provide five
- of them >> right >> there shouldn't be less >> yeah yeah that's true and let's say some
- building actually let's say you just actually keep your let's for example example like your what is called something like this is not you need like
- it's not valuable it's maybe not required even like you know uh security so you don't in this case you don't need like security guard so this is actually
- define how we can protect your asset >> because like uh putting security is too expensive right for everything so if you don't need security yeah but you need to
- actually definitely actually what is called secure your important asset and that's we already described like customer data for example or your
- database or the system. Second question, I'm going to taking a little bit more longer time in the beginning and then we'll move fast forward. But you need to
- understand the concept. Um this is very important actually for your interview and for any I mean like I know technical uh analysis or research.
- Second question I have like you know uh for you guys like uh what is mean by actually the framework right you know like you send the GRC framework. So what
- is mean by framework? So uh if I how you call give you the nontechnical example like framework it's is nothing but a simply structure right
- it's it's giving you the guidelines the rules and best practice how it should be proceed you can consider like a blueprint of a uh building design right
- so this is not nothing but a framework or how you can actually uh what is called build your building or if you think about like let's say for
- example a cooking recipe. So here like food recipe nothing but your framework. So you don't so it does not like this framework does not cook your meal right
- but it will tell you how to in what kind of integrant integrance uh you needs steps or order you need to follow but you can add your own let's say spicy
- right uh but the structure or guideline already there what you need to do so same thing like if you comes actually like in framework for technical terms in
- in GRC so GRC's framework work is nothing but actually a set of like policy procedures controls you know and and that designed to help organization
- to manage and reduce the risks in a structured way. So it means like you know it's enable the cons consistency
- and uh ensuring the compliance uh for example like uh you let's say your DRC team so there's a DRC team in you
- can see like you know every or IT organization and they can maybe let's say if you guys hear about like uh NISTD security framework right so they can
- maybe say hey you need to follow this framework mark let's say there's maybe two or three uh standard out there will be might be what is called set of rules
- you need to follow NIST standard you need to follow the other ISO standard so this is nothing but actually GRC like framework will be set a policy and as I
- said procedures and control that you need to follow your organization need to follow are you guys clear like you know this is very important terms for any
- framework like if people actually ask about a framework So uh it it it doesn't matter like GRC it can be like any framework let's say your working
- framework like you know if you're developer okay development framework if you are a testing framework so here we are focusing on GRC framework
- uh any question guys like frameworks is very important to understand no question Okay. So if uh so let's move in next
- steps like GRC what is mean by GRC? So GRC G means governance R means risks sorry it's called risks management and uh C means compliance.
- So it's like as I said it's a frameworks that help actually organization align with their security activities within business for example objectives
- and manage risks actually effectively and ensuring the compliance with low regulation and standard. So here you can see like it's saying
- that DRC creating managing creating management process okay and implementing security practice across the organization
- and risk management identify the organization most important asset that you learn actually so risk management team they will be identify the important
- asset and determine how they might could be compromised or might be compromised. and complied compliance team they're
- making sure actually business follow their internal security policy so if I actually what is called give you the simple example like what is mean by
- governance so is as I said it is setting a policy governance define a rule and creating a accountability of security and risk management if I refresh again
- uh it is identify Okay. Identifying your asset and m how to mitigate the security risks like for example like let's say how to mitigate uh fishing
- ransomware or insider threat. So they will be actually identify uh this and compliance as I said this team normally they are focusing on ensuring here like
- business business means like employee right uh they should be follow the uh uh what is called regulatory or industry requirements for example you guys learn
- about maybe later like HIPPA uh there's a standard name u PCIC plus C card I think it's called transaction something So there's a lot of like uh policy or
- like standard this compliance team making sure okay they are actually following this standard and this is actually very important in
- like you know to uh in cyber security to understand governance risks and compliance uh any question guys up to here.
- So if I give you like example for example like the governance if guys are not clear uh for example think about like what is called bank set a policy
- that all employee must be use like multiffactor authentication to access the customer data. So who actually define this rule actually
- governance. So they define a rules and leaders and every employee I'm repeating again like must follow for example or every
- employee must be scan their batch once they uh what is called enter to the building so they define the rule what employee or the team should does and
- risk management so they're identify actually let's say here as I said like they are defining let's say multiffactor authentication
- and risk management event they're thinking about like their asset how to protect let's say they're thinking about like a hacker can actually steal
- customer data. So in order to mitigate how to mitigate actually implement uh multiffactor authentication or detection policy for uh fishing you
- know fishing attack and comp compliance they are nothing but making sure every body actually what is called following these rules or not.
- So are you guys clear or still confused? So the third thing compliance basically focusing on both governance and risk management if they are doing their job
- you know correctly or not study >> no not risk so governance nothing but for example like let me give you the another example
- >> so governance let's say like so governance let's say government compon government organization for example it can be any organization governance means
- not government government can be any organization team names governance. So let's say there's a government organization and they set up a making a
- rule for traffic law. So government let's say US government making a rule for traffic law. So, so this department called governance whoever making a rules
- for traffic and risks management uh you know they are actually what is called um defining hey driver in order to avoid accident
- you know so they should be follow the you know the signal for example of traffic light and other thing they should be maintaining the if they don't
- maintain it's a risk right >> yes >> so compliance let's say here's a compl compliance right the compliance team
- making sure okay like whatever they defined actually they're following this here you can consider like police officer they're ensuring okay every
- every driver following traffic rules uh but yeah so I think you got >> yeah yeah yeah so it's just
- it can be like it can be applicable for like anything it's not like only for DRC not for like only for technical terms like it can be nontechnical things says
- as well as so we are talking about >> it could be implemented by any organization >> right right so if you think about
- >> that's a general idea >> right right you got it but if you think about our cyber security we are only content like security security that's
- why I give you the example like here we need to implement like let's say multiffactor authentication or other things you know or like credential
- username password you cannot should not be accessed without username password and you should be used like a strong password for example right
- >> yeah so So who are creating those uh set of rules and implementing those practice they're the part of the governance >> right right that's true that's true
- >> and yeah and the other is part of the risk management and the last one is the part of the compliance >> right right
- >> so anyone can be working in different you know uh section like govern governance risks management or compliance right
- >> right right no that's true it's like there's a different teams Normally in every organization okay this team actually set up a rules and there's a
- risk management and there's a compliment. >> So are you are we will be part of the risk management as a cyber security
- engineer. No, no, it's a different team. I see that uh it's maybe defense what is called competitive company but I see that what is called this GRC
- >> mhm >> you know totally different teams some people in GRC let's say there is a for example two people for example uh
- working on this another two people working on this and another two people working on this or like if it is pretty big organization let's say you can
- consider this is a different one team this is another team and this is another team so they are working under part of GRC but there's a three different team
- you can consider you know so normally uh you'll see like maybe like if it is media even medium size or larger it will be different different
- team for governance risk management and compliance it will be like all the independent team you know and they'll be monitoring
- everything the compliance team to making sure we are doing right So if I move if next like we defined actually important and by asking like
- important asset for example like how would security uh security compromise of this asset affect the profit of the business.
- So basically how to decide here is nothing but telling how how to decide if asset is important or not based on the business impact. So how we can define it
- actually right asset is this important not is based on your like oh if you if you if it is got a drug is this going to arm you harm you right so it depends on
- like um business impact as I said so it means like important asset like database for so like going back to the previous
- example server or website uh like those are like core things that drive your business Right? And if the asset actually compromised those kind of asset
- uh does this affect your business profit. Right? So if answer is yes so it could be impact your business profile operation and reputation. Right?
- So uh in in DRC what is it called uh DRC decision like what should be protect first like risk
- management uh for the business value for you want you want to protect first money you want to protect first trust or compliance
- so it's it's like so they will be like risk management actually what is it called or GRC team they will actually uh what is called define based on your
- asset value what you need to protect first you know >> even though all three are important but it will be decided by the GRC framework
- >> yeah so I think there's horoscope uh in coming slide we'll be getting a more idea right you know how actually you know like how we can prioritize like do
- you need to call priest I mean like uh money trust or compliance so there's an uh in coming slide we'll be learn so
- so the most significant and the loss the most important of the asset is right if you lost more than mean your asset is very important
- right uh so if you think about like for example uh what is called money loss so there's a three things we discuss like money loss like let's say there's a
- online website for e-commerce right if it is got DOT attack are you guys familiar with DOT so distribution uh uh
- distributed uh I forgot to meaning dedic meanings uh it's called uh distributed denial of
- service so distributed denial of service let's say your website. So your website means your asset, right? This is the one of
- the valuable asset. So let's say got DOS attack. So DOS attack means is going to be your let's say your website completely goes shut down or offline for
- 2 days. So they're just attacking to to down your website. So in this case what you lost actually like uh customer cannot
- stop from your website, right? and business could be business could be lost actually millions of dollar. So therefore in this case like your website
- actually very important asset but you're not actually what is called for example it's you're losing here like money right you're not losing actually
- let's say any data or any other asset you are just losing here money because your website got attacked and it's only got actually down or like offline for 2
- days but let's say attacker is not hacked yet so it just got attacked so in this case what's happened you just actually losing money right and losing
- customer trust as well as but let's say actually your database got uh attacked right customer database so it's compromised let's say your website
- actually uh your database and hacker actually steal your customer financial data so what's happen in this case is directly impact actually regulation
- right so you should be protect your customer data this is like there's a regulation it's called like um uh one example like PC uh PCI
- uh regulation like PCI DSS I think plus uh what is this called I forget actually PCI um meaning uh PCI let me Google it
- giving the actually right example so uh PCI I think >> payment payment So payment yeah payment
- card industry data security standard you know so in this case like you know yeah you got it thank you so if you lost your actually customer data right this is
- very important asset so in this case you your company will be fine because you lost because you are not actually able to maintain your customer data right so
- it's directly impact the regulatory and directly impact the customer trust right so that means actually uh like uh database compromise means
- like you can consider is a compliance impact and major financial loss. So what I'm try what is trying to explain
- here right if you lose actually like trying to give you the example like so do attack like you can lose only money but
- you are not actually losing compliance here. So just for example if it is only detach distributed denial of service means your
- uh uh what is called server or website goes down for certain period of time but your if your database got hacked in this case you are losing actually two
- things trust and compliance right so are you guys like clear on like I think pretty much like we are talking
- about like GRC only thing like targeting GRC that's why I'm taking those kind of example simple and and the trust compliance all these are things actually
- related with GRC. So if you go to actually next slide you see that here GRC framework
- we'll be study actually how GRC framework are considering as a or it's called implemented in a business by first examining the following okay so
- the executive management team is ultimate responsible it's a executive team means like higher management they are actually responsible for adherence
- and enforce the law regulation and security practice so like top management or top leadership they are nothing but managing the rules like they part of you
- can see like remember like governance thing or like the governance so here governance they are defined like executive team so this team actually
- define the rules best practice like and the laws so it's it means like for executive you can
- think about like uh CIO like CEO like board director this kind of rules you can consider as a like you know executive management team.
- So like why it's matter in GRC right? So DRC is not like a technical things as I said earlier it's like uh what is called
- businesswide governance issue if the executive actually don't support it like the policy and controls it would not be affected effective right so you need
- actually strong support in order to implement GRC from the like executive management who and executives management nothing
- but they'll be like part of the governance and you need their support right so for example like if I give you like so here
- we are talking about like implementation right how we can implement if you cannot get a support from top management nothing but who governance team you
- cannot actually implement GRC right because there's no support for example like if I take about like non-technical example let's say you are a restaurant
- owner uh and make what is kind of responsible making a like healthy healthy food, right? So even like your chef, let's say he actually cooked very
- well and and clean every day, but owner does not care about actually what is called like healthy food, right? Or hygienic policy. So if owner does not
- care about like healthy food and hygienic policy, do you think this restaurant food quality will be good? Definitely not. Right? Because owner
- owner doesn't care. So that's sort of in same thing in cyber security like if governance team nothing but executed team
- if they if you get actually they are primarily responsible to making this kind of laws rules and regulation and you and there should be support to
- implement. So this is like how actually you can implement uh like DRC in your
- organization. Are you guys uh uh clear on this like you know in this slide or do you have any question?
- No question. Okay. Next move in next slide like security management. So security management planning and identify the
- security rules development security policy. So here security management like we're thinking about like you can consider as a like executive team
- management team like so planning and defining the security rules development security policy performing risks analysis it is part of like risks
- analysis team and then let's say so you guys might be confused here right so as I said like this is part of like this this part of governance right so
- performing security analyst so so they're not governance system not performing security analyst so that is security assessment team right so in
- this case they'll be get a report so this team will be get a report from security risk team so they'll be asked hey I need a report actually security
- assessment report analyze report for this particular asset or whatever and based on this report they can actually develop the strategy
- tactical and operation plan uh are you guys clear on this slide right so this is as I said like planning ing and defining the security rules the
- GRCG like governance teams or executive team responsibility developing security policy their responsibility and so they will be what
- is called define a strategy technical and operation plan how they actually define this one based on this report and this report they can get from security
- risk analysis. So if you move actually to the next slide right so security management you see here like it's like pyramid if you
- think about like this strategic tactical and operational. So this pyramid actually what it's called divided into three categories. The first category is
- uh strategic. It's saying that developing uh strate strategic plan long-term plan like align align with your organization goals, mission and
- objective and say longterm like let's say five years and tactical it's midterm like plan that details on how to accomplish the goals. So they define a
- goals and this one actually this middle tactical this will be work how they can actually reach their goal or mission or
- objective. So, so they set up a goal and they this part actually responsible how they can reach their goal or mission right and
- operational plan actually short-term highly detailed the plan based the strategy and tactical plan for example operational like how they can actually
- operate to actually do something in order to reach this goal. So if I give you like what is called best
- what is like you know easy definition like the strategic their focus on how they are like why they are doing why they are doing this for example if you
- want to do something like you should be have you should have a clear goal mission and objective right so they the strategic team actually like they are
- focusing on why they are doing why they doing because they have like goals, mission and objectives. So they're actually defining why they are doing in
- order to reach their what is called goals and the tactical team like their their focus will be focus will be like what to
- do like for example it's a one year like for example like in 2000 next year they set a goal next year to reach their
- whatever the goal so this team actually defining or this particularly defining like how they reach to to the goal so they can defer what to do in the next
- year that so there can get like closer to the goal or they can achieve this goal. So they will be actually make a plan how they
- can reach this goal the strategy how they can reach the strategy and this the bottom one like operation plan like therefore how how to implement you know
- so implement like in uh practical so uh for example like a strategic let's say like over the over the next five
- years your company wants to become a safest retail company in the country. So this their goal. So if people actually comes here
- in their uh what is called retail website or retail store, people should be feel like uh this is the safe place to shop. So they make a strategy next
- five year okay there will be become a like number one safest retail store for example. Right? So this team will say how I can actually make like oh okay the
- store is like safe and secure. So they said okay this this part actually they actually what is called let's say okay this year we can implement let's say CC
- camera and hiring let's say five security guards to make sure like you know security is strong enough so they set a goal make a secure and they
- actually what is called defining how to reach this goal and then the operation like here let's say uh schedule like what is called uh the
- guard in like say first ship, second ship, third ship let's say they check actually their camera because they install a CC camera and their operation
- they check a camera to make sure if there's no what is uh what is called uh unethical things happening and they are making sure actually what is called
- let's store door let's say let's say it's like uh all the time for example it's a closed or it's locked actually so just for example so they are actually
- implementing real things like like what to do and they they are actually defining how to do and they are setting actually the goal.
- So this this this tactical and operation both team actually working to reach this goal. any question guys up to here
- for example like if I take another example like let's say technical example from like let's say your company like what is called planning to achieve ISO
- certification you know in the over over the next five years so in order to get actually certification or any other security
- related certification so so let's say there is actually requirements they need to employ employ what is called deploy multiffactor authentication monitoring
- system or conduct uh penetration testing. So in order to get this what is called let's say recognition let's certified company for example.
- So so if they set a goal this team will be identify what to do. So they said oh okay in order to become a ISO certified company I need to actually implement
- multiffactor authentication monitoring strong monitoring system and penetration testing. So because in penetration testing normally organization will hire
- third party what is uh consulting firm to make sure their uh what is uh uh the site or whatever asset is secure. You can do your own penetration testing but
- it's a government it's a requirements. Let's say if it is financial or any other sensitive what is called uh uh uh the website or let's say there is a
- business they're dealing with sensitive uh user data in this case it's a requirements like um to do like a for example like
- any organization you can see like there's auditing system right third party will become for auditing so same here for security third party will
- become for penetration testing to make sure okay are you really secure or not. So, so this is like let's say they'll be set up oh this kind of things okay they
- will be conducted in testing monitoring system and then multiffactor authentication and operational team let's say so how actually they support
- them so so this middle like technical team team they need actually support from here right so whoever working let's say in short term so then it will for
- example update regularly their software their monitoring like alerting system. Uh so these kind of things they can actually do in shortterm in order to
- support this and if they get a support from this operational team they can raise their strategy.
- Any question guys? No question. Uh yeah, if it is hard to understand
- guys like you know or like feel free to raise your hand so I can try to actually give you maybe like you know any other easy example but I feel like maybe you
- guys uh risk should understand whatever is discuss discussing here. So if I actually move in the next slide
- because okay security rules and responsibility exe executive rules rules existing in more what is called
- most companies it's called like executive rules like this is nothing but the leadership or we can governance uh executive rules related with the
- security department this respons responsibility of security okay responsibility of security department the structure of the security
- department it's the overview whatever we discussed already. So executive rule the core leadership here. So this is like kind of like structure give you the uh
- person or so get an idea how it could be a structure like CEO um responsible for uh binging with the overall the direct uh direction of the company the so if
- you see here like here CEO and then chief financial officer, chief operational officer, information officer uh and then security officer kind of
- like how their organization was structured and under Then there is a multiple like other uh you can consider team or
- uh different department there. So same thing here like if it's is like giving you the like what is called the responsibility of chief
- financial officer you see that the charts and monitoring for the company uh what is called financial uh titory helping ensure the comp company use the
- fin uh hor is called finance wisely. So making sure actually whatever they're spending the money they're using actually perfectly the financial officer
- and the chief operational officer to ensure the business able to function operational you know operating officer kind of like anything operation it can
- be like not only like cyber security like if you think about like operation officer so they are mainly monitoring like oh business is up and running or
- not in day-to-day you know so this is their main concern and the information security officer make manager risk to the organization data through the
- tourist life cycle. Uh are you guys familiar with this life cycle term? Like life cycle nothing but for example like you can think about
- your your life cycle like you born and then you actually uh skull uh try to learn how to walk and then try to learn how to speak and then try to learn how
- to actually lead your life and then uh one day you'll be die right. So your life is over. So everything like there's a life cycle for every product. Every
- product there is a life cycle or so this is not oh how till you start and how it will be going to be in or finished. So life cycle like uh is it depends on like
- the which area you are talking about and uh here chips uh uh what is called information officers here okay develop the IT system to support the business.
- So he's actually responsible for to develop the I uh like whatever required actually to support the business to making sure for
- example if we think about a cyber security so he will be develop a security policy or security let's say technology to making sure actually
- business is secure actually it's actually uh safe from uh safe from like attacker just for example if you think about like security
- If if you move in the next slide here see that the responsibility of the security department. So here like you see that the department
- like it could be more department right but here like highlight actually three department networking incident response and application security.
- So this is the this is like what is called the position like who is actually responsible but super so and supervise a director of
- the networking system administrative network administrator and network administrator and the physical network technical staffs. Okay. And then
- incident response like sock manager uh security analyst and incident handlers. Okay. and application security the security architect
- topically manage the security engineers and software engineer. So if I give you like you know easy easy example for example in here like there is a three
- department is talking about like network security incident response and application security. So if you think about like network security so network
- security like what they do here like the protecting protecting the infrastructure the network security department to making sure the server firewall writer
- router BPN like Wi-Fi whatever networking related those are safe you know so this is actually this team actually responsibility
- and this team like it's it's a network admin like there's a multiple roles belongs to this team. So it could be like network admin, CIS admin, network
- uh technically on or help desk help desk support. So this is actually part of this one and incident response. This department they are mainly focus like
- what is called dete detection detecting investigate investigating and you can think about like responding uh like any incidents for example like
- detecting uh fishing malware uh or deduct attacks. So let's say this team actually always like monitoring let's say oh okay this is that the sock
- analysis right they're always like monitoring is there something anything suspicious uh that could be happened there so how
- they monitor we already discussed like CM like monitoring system and it could be there's a lot of other tools out there for monitoring so this just for
- example it could be any monitoring tools CM is like in broader case it's called any other sec what is called monitoring tools integrated with this platform so
- it it will be centralized all this information so incident response team nothing but they're detecting as I said like oh is this any u fishing or malware
- or duct duct attack happening or not to make sure your um asset is secure asset means it could be a website it could be database as I said right or it could be
- your database server and epic application security here there's another team so they are focused on actually protecting the software and
- application so they don't care like here this team don't care about networking right and so because net they have a different team actually who actually
- normally doing their uh performing their responsibility but this team mainly focus but security actually what is called responsible for all we'll be
- actually discussing later slide. It's not like only like team responsibility to manage. It's your own responsibility
- to follow the horoscal standard in order to secure your asset. It's not your personality asset because if you're working for a company so your uh company
- asset you are the responsible person to protect your asset like no matter what's your responsibility will be discussed later uh in security culture there's
- this slide but here um we are talking about like main focus so application security that here this team they're protecting the software and application
- like let's say web apps APIs mobile apps uh from vulnerabilities because if they create a vulnerable software it's like uh it will be exposed for attack right
- so then to make sure actually their application whatever they developed is not actually exposed for any vulnerabilities so that's why it's like
- you know security engineer or software engineer or the architect security their responsibility how they can secure their application
- any question guys up to here. No question. We're in slide 15. Okay. Total 81. Uh, okay. So, let's move for
- the next slide here. Security and the security and the large organization. Okay. The security operation on is interact with the
- nonsecurity teams. It's saying that like security operation interact with the other nonsecurity teams means like regular employee with the organization
- right for example in organization marketing because marketing and communication team they are not actually directly responsible to manage any
- security right but we'll be discuss actually how the related later slide but it's saying that security team operation team will be interact or like
- collaborate with the other teams for example non technical or nonIT team like marketing team, communicative team to use their
- network accounts and IT what is and that IT and the networking manager. Okay, let me discuss more actually here. So if you think about
- like security operation must be collaborate with non um as I said like nonsecurity team and like those thing communication marketing you can think
- about like non technical team or it can be like HR or finance team right because all the department relay on the IT system the data and the network so
- like awareness is very important for everybody who is using those system Right? uh if I give you the example for example
- like if you're driving a car right so nowadays all this modern car actually like they're implementing self-driving right autopilot so you bought a car and
- you are driving and you say oh okay you know so this is autopilot or this is self-driving so Toyota or like Tesla they build this
- car and you don't care about care about accident but you should right because you should not You only relay like what is called with this technology. You
- should you should know how to properly use right. You should not be like uh start this system or autopilot and when to sleep right. You should know how to
- manage actually. So so this is nothing but talking about like here same thing same concept. So security team actually okay they're
- trying to like secure your environment or the system and you as employee should know how to use actually right so this is your responsibility
- so here you can think about like you know security security team because they are called interacting with this non other nontechnical team so security team
- you can think about they are enabler they are not roadblocker They don't want to block you but you might get blocked sometime. Let's say you are trying to
- actually upload there's a malicious software in your system security team will be block you in real time. So it doesn't mean they are blocking you to
- perform your job. They are nothing but try to trying to secure you you know. So they are not actually roadblock for you but they are just
- making sure whatever you are using you are actually secure your system is secure your secure and your information or your data is secure. So instead of
- just blocking security team security should security team should be helps the team work safely and effective effect effectively and most important like
- train the employee for secure security awareness. So if employee or let's say for example if you don't know how to drive if you
- don't have driver license and if you bought a car autopilot or self-driving car and you should not right because you don't know how to
- drive you don't have driver license you just bought a car and go to the freeway uh this is that doesn't make sense right so
- your responsibility as a driver you should actually know how to drive a Even if it is self-driving. So here same concept you can think about
- like security team right as I said they are interacting with the other team. So their responsibility also like you know train train the employee how to how we
- can actually use this system how we know this email actually fishing or not. So every organization LBC uh they normally what to say uh set a
- like let's say workshop or set a send the acade academy uh like video record let's say video or tutorial hey watch this to learn how to avoid like fishing
- attack or or how we can identify oh this is not a this is this is not a real email that for example so this is also security operation team responsibility
- to train the employee or train the user how they should use this system. So if employee don't know how to use the system that's the problem problem right
- so once actually using for example marketing team they are using compl company company computer so company requirements you should be use company
- network or you should be use BPN that's you are not in office you should be BPN but not you are not using let's say and in this case you should not be able to
- connect but let's say somehow you are able to connect with internet you are not using BPN. So, so in this case like you are exposed security risks. So
- that's actually you should know as employee how to actually manage security and security team as I said they are not roadblocker they are enabler. So they
- will be training or they will be infre how you can connect with the BPN. So every company you will be see once you join they'll be actually give you the
- guideline. Oh, this is the way you can actually connect with BPN or this is this is how actually you should be lock your computer or this is how you should
- be set up your password. That's how you should not be set 1 2 3 company you will be see your system will not allow you'll be the most of the website for example
- once you actually try to do like let's say 1 2 3 4 5 6 7 this kind of password it will be not taking this kind of password in this case you'll be see like
- system will tell you hey this password is not secure you use upper case lower case special character it will be guide you so sometime it can be guide but how
- to use the system kind of like it's called like uh I forget the term uh use case uh I forget actually the term what it's called but system will
- guide you guide you same thing like security team can be arranged what is called training and other things for security awareness
- any question guys up up to here and this you need actually in your real time in day-to-day activities
- so go going to the next slide actually what what other example You can think you know. So do you guys have any other example how we can secure? For example,
- if you think about this picture he's working looks like in the computer there is a copy and there is a note is reading something. So let's say if you are way
- out of your desk this case you can keep your copy here. That's fine. It's not you don't need to actually secure your copy. It's fine here. You can just
- simply keep here. But the note maybe let's say there is important data you should be lock your computer you should be keep your note in secure place and
- then go somewhere right do you have any other example guys think about like how you can secure it can be your system it can be your information
- it could be anything so if you don't have so if I go to the next slide you see there
- Security concern versus business concern. The most profitable decision is not always most secure profitable is saying that profitable
- decision. Profitable decision means like business decision. Business always think about profit. They don't care about like security. Security. Okay. Security.
- There's a security team. But business their main intention actually like profit. Then second focus other things. But their highest priority any business
- highest priority profit if if business is not profitable they don't need this business right they don't need to run this business so why don't don't they do
- care about other things so first actually is that's why it's saying that the most important profitable decision is not always more secure because first
- they're thinking about profit so security objective may be the or within the with with those business for example here I think this
- is security team manage goal like protect to the business data and so this is actually security team goals security team goals right not
- like profit primary goal ultimately like everything is related with profit any business right the we are talking about like primary goal business primary goal
- profit not security team primary goal secure your data not profit Secure your data first. So here like two
- things like security team their main goal protect your business and business main goal maximize the profit and improve efficiency.
- It's like basic things. So if you go so what so what should the security team do actually here? So if you go here you see that
- so an organizational engineering team propose innovation but insecure new. So here is saying that there's engineering team proposing innovative but insecure.
- So they propose something insecure feature uh for the flagship product. So here you can see security team would probably
- advise against a new feature due to the poor security that's actually there is innovation on new business. The security team said hey there is a poor security
- in the news new future but business might decide business to develop it anyway believing potential profit right because business always think about
- profit security teams here like what is called uh think about u security so security team viewpoints here like uh
- the the risks like it could be data leak with less security right it could be uh data data leakage or compliance issue or attack surface but lead business
- leadership viewpoint here like the growth revenue right even with some risks because they are thinking about the profit
- then sec so as a as let's say you are a security engineer right so what would you do in this scenario right any idea guys it's okay they are trying to
- implement or maybe new feature or business because it's profitable but you are seeing here there's a poor security but business want to implement
- so you as a security engineer what what's your responsibility what you supposed to be doing in this scenario any thought
- um so what I'm thinking probably we need to discuss with the business game and you know just uh minimal
- security at least like if like if we don't provide any security right >> so then we might lose our profit
- >> right right so yeah you are in right track so same thing I'm going to like you know uh I think giving the example for like you can actually clarify the
- business hey if there is no security uh It could be lose your data. You could it could be going forward in long term you'll be lose your trust customer trust
- is initially business might be profitable but if it is exposed for attack. Yeah. So you'll be and if you lose your data you'll be lose your
- customer >> and you'll be get a fine from regulatory right. >> Yes. So, so, so what you need to do as a
- security engineer like you should not be say like it's called like security team should not be like department of no you should not see everything is oh you
- cannot implement your responsibility here actually you should be guide the business so if you guide the business you are your thought then business can
- take a what is called a knowledgeable or in inform informative decision to balancing the innovation like profit security and risk tolerance right so
- based on your advice because you need to actually guide the business right so once you actually guide the business and hey this is this is the concern in this
- case they can actually balance try to balance okay oh okay okay I need actually implement security here might be I need to spend some money and then
- maybe okay I don't need to maybe security for let's say low priority as I discussed like low priority asset let's say medium priority higher priority so
- business might say okay low priority I can take risks but higher priority whatever is the customer data customer account whatever secured data I need
- actually what you call uh strong security policy or strong security security implementation
- any question guys up to here so okay we're okay so this is next slide related with this so what should do
- security team do like you know that's what our correction right >> uh uh I'm sorry if I'm just saying from the previous slide so security team
- should provide the proper guidance to the business >> what is can you repeat >> like I was saying like security team
- should provide proper guidance to the business >> right right >> not just saying oh you cannot do that
- >> right that's why yeah that's why I said like you know >> should be a balance >> right right you got so that's why uh we
- discussed earlier Security should not be say always no security should not be like blocker it should be enabler okay it should be help the business how they
- can enable this business you know you should be guide and uh what is called help them uh to make a informative decision. So related with same thing
- here like so the is telling like as a security team you should put a put in place more aggressive monitoring. So this is your advice could be hey you
- need actually monitoring system uh data server uh for the new feature and I advise the IT networking to put a uh put in place more sophisticated access
- control. So like this is that kind of like example we can actually as a security team we can say hey you need actually moni monitoring system uh
- because so like remember like you said uh like minimum at least like minimum security. So let's say okay because they can't afford maybe all these kind of
- things but they need to actually implement here you can say okay you can't implement this one but you need actually monitoring system if something
- happening you should you'll be get alert right away and you should be what is called put a strong security in the networking depending the scenario
- you know so I think we are clear here right pretty much so the Take away actually from here
- actually security team must be flexible you know and align with the business priority because if business is not profitable you will be lost your job
- definitely. So you need to actually business what is so profit is like this is important but all as as a security engineer you should be secure your
- business this is your higher priority but end of the day everything is profit right so there should be a balance so as I said like security team should be
- flexible and take a necessary action on discuss with the business and implement and trying to share with their thoughts so business can make a informative
- decision any question guys up to here I think we'll discuss a lot but if I go here
- like you know I say 100% security is not possible like not business goal like to limit spending and increase the profit business often provide only at quick
- protection remember we discussed actually at quick protection in the first slide what you need to protect how to prioritizing your protection
- based on your asset value. So this is nothing but equip protection. If if the asset value let's say company booklet so this is less priority you don't need to
- secure but the company customer data this is like higher priority you need strong security there so that's I say like like 100% security is not a
- business goal but what about the uh what is called you need to actually prioritize your security based on like adequate protection that's we learn
- actually earlier I think you guys are clear here right because we discussed a lot actually
- earlier uh regarding this 100% security do you need or not
- for if I refresh again like you know your gold diamond should be keep in your safe locker you can implement the camera uh lo jewelry like plastic things you
- don't need to actually in safeguard same thing for technical example like customer data it should be encrypted you should be implement monitor you should
- be implement multiffactor authentication biometric access for example and company as I said like uh company booklet you don't need like high security so the
- take actually here like you know security is about like risks based prioritization remember there's a risk team right they'll be prioritized is
- what is the risk and what is the high risk what is the less risks. So you need to make a decision based on your risk based prioritization
- to protect most important asset not everything. This is what actually is trying to tell. So if you go to next slide security
- versus business uh is the feature of this risk. This is like we already discussed business security versus business. Next slide. He's asking the
- question. So if you see about this slide here, security versus business in the future what this risks an organizational engineering team propose an innovative
- but insecure. We discussed it right similar concept feature for the flagship product. Okay. This organization perform a risk
- assessment. So remember like there is a new product and it was insecure that's we discussed last slide
- then you adise something you raise your concern to the business. So what business do once you raise your concern they perform a risk assessment
- right to calcul and concludes okay so whatever they're actually getting so risk assessment will
- be help you to identify like the balance or prioritizing the risks so here you see that the this is you can consider one side you see that in your this new
- feature let's so this let's think about this is balancer. So the one side is money right and other side is risks.
- So so in this new feature is saying that if you implement this new feature this new feature could be lived 25% profit
- but at the same time this feature would be risk exposing isolated uh like data server. So, oh okay this feature could could be
- also rigged as exposing an isolated data server say data service is data contact the customer um
- containing the customer okay names username and email address but no other PPI so it's saying that this server only contain uh customer name username email
- address but not other but not other PIP. PIP means personal identif identifiable information means like
- social security. You can think about your driver license. This this is called like PII sorry PII. So here they are actually performing
- what is called risk assessment the company to made a decision. So here advantage if you think about like business here once they actually
- performing this risk assessment and they find actually this uh this information here advantage is like after this risk assessment uh it's increase a quarter
- quarterly profit like business side like uh 20% revenue right and disadvantage it could be exposed the isolated data server is saying that it could be a risk
- right isolated data server with the c with that contains actually customer name, username, email address but it's not actually taking sensitive uh other
- sensitive information PII nothing but let's say social security so this is like what is called is user could be lose their username password and email
- address but is but what is called it's not actually this database not storing any other information but problem is like if user lose username and password
- uh what is called attacker can attack or what is called the other site or other database to steal this PIA information right so
- in this case it's like what is called we need to actually explain what ex could be happened actually in this scenario like what could be the impact and how we
- can actually mitigate for example like we discuss actually implementing like other monitoring system or maybe uh what is called uh multifactor authentication
- or access control. Remember like so are you guys what is called familiar with like what does it mean access control? We actually discussed in last next uh
- last slide remember here somewhere access control I said that. So are you guys familiar with access control? What does it mean?
- Like multiffactor authentication right is a >> no no access control is different multiffactor authentication like what is
- called secure your access but access control for example let's say you are a user right for example >> oh you mean let's say there admin
- >> right user >> yeah so like yeah this is called like access list privilege something in cyber security like things you don't need to
- access you should not be access let's say you should be access only like the thing you need. So you as a user you should not be get access to view the
- other uh what is called user data. >> Yes. >> You know so it depends. This is like so in this case is like we could implement
- what is called access control. So for example like uh updating something or let's say if you have a bank account
- uh so you you should be able only to read the data from the from from your bank side website or make any transaction but you should not be able
- to update any uh you should not be able to you can update your maybe transaction okay like there's a this is called like access control like if you are owner of
- this account maybe you can only read you can made a transaction or if you made any transaction you can made uh what is called update or edit this transaction.
- This is might be or cancel this transaction because you are the owner of this account but you should not be alter any other information outside of your
- account. So this is nothing but access control but if you are admin might be you are able to see other user information because you are admin and
- admin also should have like access control too for example like you know even you are admin you shouldn't be see user password so user password should be
- always encrypted so you'll be learn actually guys like what does it mean encryption decryption I think there is an uh there's a class for that so there
- is like what is called uh it's called like I think list privilege Uh so like yeah admin also should not be get like all this kind of access. For example, if
- you want to reset a password, admin should not be should not be able to share the direct password to you directly. They admin can send only the
- link hey reset your password but he should not know you what what is your password. System should be generate this password just for example. Okay. So we
- are moving actually different direction but anyway there is a different class I think but here if I go the next slide in this case the business objective of this
- achieving profit target override the risks of strategy. So what we discuss here like business targets actually they override trying to
- override the risks uh and they're uh uh what is called uh trying to achieve a profit right and we discuss also like you know how we can actually collaborate
- the business to make the profitable decision means like we are trying to hear actually what is called uh help business
- to run the business but not block the business but they need to secure their business. So in the next slide you see that here
- like pros and cons like security team objective to to secure the what it's called security team objective to the feature due due to the the like uh due
- to its insecure the here pros nothing but advantage the business decide that cost of this potential bridge of a isolated server
- Because there is a isolated server contains actually remember only username, password and uh email address not other information. So with no
- sensitive data so would be a less potential uh what is less potential profit of this feature. Okay. So here what he is trying
- to say like here business actually win right business actually like business like what does I mean like uh
- the business we're talking about like you know so business wins versus like security. So here this feature actually in secure like security this is security
- team objectives and business view actually the potential bridge is limited like isolated server no sensitive information in this server and profit
- potential is like higher than 20% 25% that's discussed. So here actually decision like you know business want to move forward accepting this li what is
- this kind of like limited risks but here like in this slide and uh next what what we actually learn what is what is the takeway this is this is the uh
- important things like security rules is like inform mitigate and the monitor not always like as I said like blocking and risk should be like qualified and
- manage. Even there is a it should be like what is for sorry quantified and managed and allowing the business to make informationative decision. That's
- what you can learn here. Any question guys up to this slide then we'll be move forward in different topics
- uh and this is important uh your day-to-day life. So here oh governance and comp okay after making this decision the business up
- business update is security practice to account for the risks it has undertaken okay and the regulatory confirm that everyone is
- following these rules. So it's nothing but actually talking about the governance and compliance. So they're making a decision right
- remember we discussed actually other governance and compliance making sure actually everybody following these rules.
- So we discussed a lot actually about this they're making a decision another team doing risk assessment and this team making sure everybody so you can think
- about this one governance think about okay US government if it is government organization like traffic department police department and the compliance
- let's the police they're making sure okay people are following traffic rules uh same thing in security like executive team could be implement meant people
- should be follow what is called scan their batch using strong password whatever and compliance team making sure okay you are using strong password once
- you enter the building you're using or scan your batch just for example so now we have activity actually here >> uh now I just send this activity in your
- slack live channel uh also I send this uh activity to uh um motion motion. >> So uh just 10 minutes everyone uh uh finishes activity. Do you have any
- question about activity? After activity we can discuss uh finally.
- So activity uh this is the uh chili ramin Abdullah can you share your screen? You finish the activity. Come here.
- Do you have any question before activity? Uh
- >> yeah, that will help you guys in your activities. If you have any doubt, you received this activity. Yeah, I got this activity. Okay, fine.
- >> Yes, having. >> Yeah, so far I understand that each company has a different department and different department has different roles
- and we as a security service how we should contribute to each department. That's the whole presentation was about
- how we play a role as our IT department. >> Uh basic based you understand question he his voice is was not clear
- but yeah >> can you hear me now? Yeah. Yeah. Yeah. >> Okay. So far I understand is that obviously every every company or a new
- company has a multiple department for whatever reason. So we as a as a cyber security the whole presentation was how we will play a role in those department
- and help them secure and make profit basically right. >> Yeah. Yeah. That's true. That's true actually. Yeah. And so in order to
- actually what is called implement or how to do their security like if you think about like today class for like GRC. So this is actually the framework actually
- will be guide you actually what you need to do and based on this framework or guideline right it's a structure and list of guidelines right you can
- implement or guide the business how to secure their um asset asset could be anything you know so yeah so >> do we have to remember anything or this
- whole thing >> no I mean like you know in security or any like or anything. So I don't suggest anything like memorize or
- remember. You just need to understand the concept. >> Yeah. >> Once you understand the concept, yeah, I
- think that's enough, right? So if you if you read something and if you can understand, that's enough. But yeah, you don't need to memorize everything. Just
- understand the concept. >> Sure.
- >> Yeah. Can you share your screen and then you start this uh just um activity >> and 10 minutes you finish this activity.
- Okay. And then we'll back again. Okay. I made to five minute break.
- Okay. [Music]
- [Music] [Music]
- What's up? Start. Okay. We are still in activity.
- Keep screenable [Music] ball.
- You would learn right mostly security recommendation.
- Oh secret. Okay. The security recommendation. So the director of the security suggested the implementing corporate BPN
- >> by the gateway. Okay. So every and then every time someone try to access uh to the internal component BPN test request should determine the coming from the
- employee. is coming from the employee. Okay. If it is requested is approve. Okay. Since the company has a growth in 300 employees, the uh director argues
- that increase the critical and ensure the confidential information remain the hidden. The BPN project would be okay. Disadvantage
- network. The director of the engineer suggested record all developer should uh use the secure shell. Okay. Uh Yeah.
- Right. [Music]
- What is the lead? Okay. What is the lead to the approval of the reduced risks to improve? So improvement
- right group outside of class. I mean,
- sorry [Music] Linux
- connect. So IP address so that uh nobody else can crack because
- IP. So um is it something similar uh to that?
- >> Could you Okay, he lost actually first first couple lines sentence. Can you repeat by again?
- Linux class IP password.
- Password. >> Right. Right. It depends on like scenario. Right. if it is server. Yeah,
- makes sense. Okay.
- record developer too. Okay. So I think Okay.
- Right. [Music]
- Right. Right. Right. Mhm. First
- server. Oh, first line. uh
- okay in this activity we will be play role security conc instruction okay whether it's lit okay what >> and have a cast
- key item also there work should be take to implement the business plan okay first line the business wants to actually give the all the developer to
- access the data uh this is request was made by the director of engineer they suggested that The free access would help
- >> yeah team to move for uh faster and then help manage >> uh cut of cost and depending okay the dire make administrative server
- accessible from the public IP address and injected the corporate subet okay topically corporate or company network
- are not publicly accessible network
- access without other authentication because you already get the network access. Uh, so
- the director of the IT argues that allowing anyone access the machine of this company network with help their administrator
- May of home work remotely to connect to the server and need to manage. Okay, they exactly the features improve retention and hope to gain the
- increase in the number of the house and employees. Your new sock analysis want to merge all the email address. Okay, blah blah. This is a lot of information.
- So director of engineering like here suggested all the developers
- should access all the data advantage they can easily access but disadvantage uh allow all developer to access the
- user data including sensitive personal information uh what is called uh that has nothing to do with their job right the developer
- should not be like act like They can develop the product but they should not be actually access use of public personal information.
- Other disadvantage to number two business should reject uh reject and reject on ground of the privacy. Okay. The director of IT suggested explos.
- So another concern the director of IT suggested the act what is called exposing administration server to the public public. So
- administrative can work actually from any computer but problem the server would not be publicly accessible uh which is uh like inacceptable if server
- would publicly access inacceptable of the private network because this is security rex. So we could recommend here actually the organizer should or the
- organization should reject this request and a BPN should be better solution. So there then like in this case we should be actually guide to use actually they
- should be used actually BPN. So I have actually this answer it's a long but you guys can actually this like
- here you guys get maybe same answer right? Yeah. So looks like you guys also got this answer right. So I guess I think
- you guys actually read actually like this can take actually like line by line but looks like you need to actually what is called recommend actually what
- business supposed to be do. You got my point guys. >> I mean there's no right or wrong answer.
- Just >> no there's no true right or wrong answer. So this is like the concept. It's not like oh like a yes or no. It's
- like a statement. That's true. There's no no right and wrong. So we can move actually the other what you call you guys can try to actually do like know
- group study know so if you actually what you call read lines 10 minutes I feel like not not enough that's happened without time too like you need actually
- more time uh to do your like research but this is nothing but actually whatever actually we did like or we actually learned today so from this
- actually our knowledge we can actually made the decision here what we supposed to be do you know what you supposed to be recommen
- And I see that you guys already get this answer here. The solution recommendation right
- secure recommendation. So same thing actually we already shared with you. This is the answer you already shared whatever I'm seeing in your screen.
- So let me share my screen actually you guys can read you guys already get this answer looks like. >> Okay. So if if you have any question
- then you guys can you know reach either we cannot you know it's almost 1 hour left it looks like let me start next slide uh let me share my screen
- uh are you guys able to see my uh slide activity slide right anybody can confirm
- no >> yes we can see Yes. >> Oh, okay. Okay. Perfect. So, this is what actually you guys just actually
- doing. So, next slide. Let's see. Uh action. Okay. So, we security culture. This is important. So, we'll be discuss actually more here in security culture.
- Uh so, let's move on next slides. So here you see that the security culture strong organization securely be uh begins with the making
- secure employee make sure employee is both both means is considered this and this. So here considering
- consider security important and understand security implication of their decision.
- So in this slide right you know the security culture it means like every employee
- uh treat like should be treat like as as I discussed earlier also like security should be their part of daily day-to-day activities day-to-day job they every
- employee they are responsible to manage uh or follow the company rules and regulation in order to maintain the security for example like if company
- trained you hey this this is the how we can actually recognize is this is this fishing email or not. So you already learn from company or from the security
- team but you don't care uh you just click actually blindly any link or replied any link right so that means you are not maintaining security culture
- whatever company teach you or guide you right you should be or whatever GRC define the rules and regulation you should be follow right
- so you you should not be think about oh security is not my concern security only like security team concern here we are talking about the culture.
- So culture is here if you learn as I said like giving the previous example if you know how to drive
- a car and you are using self-driving car and you are seeing the self-driving car or autopilot going to hit the other car you should
- not be like be quiet you should be you should not be say okay it is autopilot I don't care if it is heat on other car okay uh hit you should not be do that
- right You should be take a control right away if it is going to happen. Right? Same thing exactly same thing here security culture. If you know if you
- observe any suspicious activities for example like let's say imagine like you are a employee and you are so you
- have access in your building and you access in your building and you observe there is a suspicious visitors in your building inside the building. So
- it should be report right in the security whoever the concern person person you should not be actually ignored like so you should not be just
- rely on like security guard like you can think about oh this is if suspicious activity is not my responsibility security guard should be taken care so
- this is this means you are not maintaining security culture if you see something you should be raise your voice you should be informed so this is what
- like security culture culture. So everyone should be know they are actually affecting like like you should be feel safe right in your office. So in
- in order to feel safe in your office for you or for your colleagues you should actually help to the
- concerning person by informing them hey there is a security risks right uh so like strong like strong security is not like just about like tools and policy so
- we talking about the culture so like you should not be only relying on like tools and policy you should not be relying on like How do you call only like
- self-driving car? Oh, okay. This car actually what is called there is a technology should be drive uh you should be able to do self drive. So you you
- should not be go to for sleep while you is driving in freeway right you should you should be monitored. So this is your job. Uh even like there is a what is
- called self-driving technology. So uh it is about like the culture nothing but it's talking about like employee behavior how you will behave like you
- know so you and and your behavior should be based on the company GRC policy you know and sometime you should be use your common sense so consider like uh
- security like like what is called understanding the Security uh implification
- like know how their action and how it can be like impact you know. So if you actually observe something you should be understand if it
- is happen what should be impact if you click any suspicious link for example like you get a link and you know this looks like this is a suspicious link
- right and you should not be click but if you click you should be know like what could be happen you could be los you lose your data and attacker can uh
- actually attack the company or the your system right so this is culture nothing But people behavior how should we behave based on like uh in in it you can think
- about like GRC policy whatever we discussed earlier any question guys here so same thing like for example like your company
- always guide you should be use strong password but you don't care you always use actually weak password so you are not fit with the security culture in
- your company Right? Your company suggest you to verify the resource of the email and you are not doing actually. Let's say you get a email and you just blindly
- reply. You don't actually double check is this email came from authentic source or not. And this is your job, right? This is your job to verify is this email
- is authentic or not before you actually replied or click, right? And your company let's say uh say every company they
- how it's called they make a rule you should not be share your credential or you should not be download any unverified software but it does actually
- let's say you share your password with your other colleagues or you actually download there's a malicious software in your system so you are breaking actually
- company DRC policy that means you're breaking the security culture you know so in Next slide. Okay. Here you see security. This is definition
- actually. Security culture is the way to member of the organization. Think about approach of security. A healthy security culture. Healthy security culture. Think
- about has the employee who are the invest in this organization security and behave securely. So healthy secure culture means you are
- maintaining your security you know if you don't maintaining your GRC policy that means your uh what is called environment will not be healthy security
- culture right so this is nothing but actually give you the what is called like theory any question up to here then this is very important in real time
- security culture so here security culture actually is think discussable like two different things three different things. So how important
- employee consider how important employee consider security like is this like important in uh employee should consider the security before they're doing
- anything. Second question like you know terms like how aware like is this employee aware of this risk let's say are you aware you if
- you are click on a malicious link what could be happened right so it's talking about awareness this I'm talking about important
- if you don't consider security what could be happen so so considering the security risk how important it This and the understanding the common
- security are you aware of this right and then this this one actually like whether employee know how to actually avoid insecure behavior how you could avoid
- like how you should so you should be know it's should be know how you know like as I said like you know your you as a let's say security security team or
- security engineer you should be guide your employee how they actually identify and avoid security behavior. Security behavior is not always like
- related with like tools and technology as I said right if it is tools and technology you should be guided how to they use their tools and technology you
- know and other things something not related with like what is called always tools and technology it's like behavior how it should be actually behave so this
- is actually like so here three important things guys like important to considering the security and the awareness like understanding ing the
- security risks and here like behavior saying that like behav your behavior is very important. So here like in this slide what you
- learn actually security culture just not a policy it is not a polic that's not a policy right it's a how employee behave and think about security every day this
- could be your not only like you think about your personal life right you know like if someone actually call you and asking your personal data you should not
- be just blindly given to them right you should be verify oh is this like authentic source like the call you received from Right. So same thing like
- same behavior you should be think like your for example like your company all this asset it is you should be think about it is your asset and you you are
- the responsible person to protect your company asset and you should be you should be follow this security culture nothing but the their rules and
- regulation. So the here important things is like do the employee take security seriously or not right
- this is the very important and you should and awareness as I said here like do the employee know the common issue like fishing email social engineering
- malware attack and the behavior third one I'm repeating again do the employee know how to act securely to avoid the risks so you should know how to behave
- right to avoid the security risks. So if I give you the like what is called nontechnical example here right so let's
- say employee always lock the door right so if you always lock the door and if you don't share with your ID with the other colleagues
- or others or if you report suspicious visitors as long as you see something so then what is called you are actually actually following the security culture
- So technical example if I can repeat again like employee should like here employee should know like how to recognize the
- fishing email and they always should be used like for example like strong password like how they should be behave for example okay using strong password
- and don't install uh any unverified software and don't break the DRC policy See nothing but your this is what like security culture you can think about.
- So next slide healthy security culture required a what is called moving employee to value sec value security and the training
- train them on how to avoid the security behavior right so you as a security engineer should actually train your employee actually how should be they
- behave that's what we discuss actually any question guys up to here in security culture I think we discuss a
- So if not actually here the security culture framework framework steps right so init so in so in this case like it's talking about there's a five steps for
- the security culture like measure the goals and then innovate the right people involve the right people create a action plan execute and plan and measure
- measure the change so we'll be learn actually all five steps in the Next slide.
- So here's the definition of security culture. Actually I the problems in the organization organization secure culture and then de
- and develop a plan to solve them. Okay. So let me actually go to the next slide to in order to understand actually all these five steps. Um applying this
- framework. Okay. So this framework is talking about this framework nothing but these five steps. So employees receiving an email to their
- work account from the external source. Uh employer clicking and downloading the attach email. Okay, we discussed actually all these things. The
- organization secure security team determine them meal determine that many of these link and attachment contests malware. So we'll be
- discussing in we already discussed these things but we'll discuss more actually in order to get this clear. So let's move forward actually the first one
- here. So this is nothing but so you see the 1 2 3 4 five. So we will be going to one by one one two here you see that all these five. So this is
- first number one security management like so how we actually measure the goals. So here like you know high penetration testing this is what is
- called the example for one approach there is could be a multiple approach. So here we are taking example whatever in this slide. So it's saying that like
- hiring a penetration testing firm beginning a fishing campaign like fishing mail campaign that will send fishing email. It will be sent fishing
- mail like intentionally to the user of this company and this farm will be keep track like tra the track the user how many user actually following this
- fishing because they want to measure actually you know like employee behavior is this employee fit with security culture or
- not. So they make a plan actually here this third party penetration testing team to send an email to every employee and verify how many user
- click this link means like fall in this fishing email nothing but you are clicked you clicked you did clicked so the one way first first step to is the
- measuring and get the goals because if you if you don't know your measurement you can't set a goal right that's Oh, like everybody actually following what
- is called this rules and so rules like there is a no like what is called uh like everybody's aware of that. So in this case like looks like everybody
- knows actually what to do but let's say you're on the other side of this coin let's say nobody really knows how to recognize the fishing
- email. So based on actually let's say 100% like success or 100% fail you can set here your goal right. So measurement a goal let's say here they set a goal
- like click let's set a click rate like click rate means like penetration testing firm will be sent a fishing email right to every user so once they
- set a fishing email every user is saying that they set a goal 5% 5% user could be like click this link measure this data to determine
- what percentage of employee victim of this fishing And who employee employees specifically? So if they send actually this email to
- the every employee they'll be identified like their goal actually 5%. You know but they want to actually identify how many person actually click this link
- like victim and who is actually click this click thing. So why they need that actually? So this will be help you like how many person
- click this link they will be get an idea like how many percentage of um uh employee from this company actually don't know you know this kind of like
- fishing attack and once they actually identify who actually click this link let's say there's a 5% and they knows this
- employee they can train this employee because they don't know right so the first one actually they're actually collecting the metrics and next slide
- here involve the right people to the so inform the at let's say CEO and CIO actually and HR and the what is called the person and the person in charge of
- this internal training and communication because you cannot actually send like fishing email for training purpose something without like informing let's
- say GRC you should be informed the GRC team hey we are going to do that or so or you should be in informed the like GRC means like remember like governance
- Governance is involved by high top management right CIO H so other other so you should be informed also like the top management like executive team you
- should say hey we are going to perform this kind of operation who is performing like third party penetration testing so the second one they set up a goal and
- then they inform the company or DSC team and then second one create action plan this one so develop a training cover danger of this malware and how malware
- can spread through the fishing and fishing. So fishing and fishing to cyber security term. So once actually what is called
- get this measurement and then they inform and then after that they create action plan. Once they on they get this matrix what they do
- with this matrix right. So the matrix what we supposed to be do and the fourth one like execution plan. So once they create a okay what they do and
- then they need to execute right. So execute means their action plan they need to execute. So here then they implement the training with the goal of
- like 20% employee of each quarter. This quarter 20% next quarter 20% next quarter 20% in one year 100% team members should be trained up. So that's
- their goal. They set up a goal. They inform then create action plan and then they take action like execution. And then last you see then the last
- steps here uh measure the change. So determine success or failure. So initially their target was 5% let's say and here you see the step one they are
- actually measuring again against this matrix. So in this like uh this is uh what is called security culture framework right?
- So we are talking about security culture framework. These are five first five steps. The first step measuring the goal and identify the goal. Then informed and
- create an action plan. Then execute the action and then the compare the result. Compare the result between this and this to determine is this pass or fail.
- Right? So this is like selfexplanatory. We don't need to like how actually you can make a plan. Right? It could be like this kind of what it's called framework
- you can build for anything right how we can actually proceed. Uh so there is activity for 15 minutes and then I think break
- for security culture is here. Any question guys to wait for tamay. Uh if you guys have any question.
- So security culture. >> So security culture by whatever understood basically means as we as employee how we should follow
- them. You should it's like you should not be think about like oh my technology will
- be protecting me. You should not be thinking about my car technology will be protect me from accident. Right? The cultur is here like you should be you
- should be help your technology. you should be support your technology or you should be support the GRC team in order to implement or in order to what is
- called uh achieve your goal or company like what is whatever the uh what is called objectives like if you don't care like you just actually say okay this is
- not my responsibility this is security guard responsibility that means you are not culturally fit so you should be follow the security culture and think
- about like securityities everybody responsibility. So you if you don't know how to actually fix or solve this issue but you can report and you can actually
- what is called uh try to save your system for example like you know you should not be what is called open your door let's say you set
- up a security camera in your home so you should not be unlock your door and say okay my camera is there I don't care let's keep open my door for for like
- 24/7 and you should not be do that right even you have a technology. >> So same thing here like similar concept like security culture. So you should be
- follow company rules and regulation. You should be apply your common sense and you you should try to protect your asset. This
- is not your company asset. >> So Tanbe already shared this activity. Uh Tamri,
- >> I want to drop my wife in my brother-in-law house. >> No problem. Okay, I'm just uh continue. Okay, thank you.
- >> Yeah, so I'll be back actually after 30 minutes. So they have activities and then after that I see that they have a 15 minutes break, you know.
- >> Okay, >> so I once I back I'll be rejoin. >> Okay, thank you. >> Yeah. Yeah. Thank you. Thank you guys.
- See you then again soon. Uh so uh who uh continues this uh activity? So char uh please uh proceed
- on your uh share share your screen and [Music]
- [Music] [Music]
- Please share your screen. Okay.
- That was back. Wait.
- resolution. I see
- [Music] I can in this exercise you will play the role of a security consultant who's been
- contracted to help a local bank develop a plan to address a physical security issue that recently resulted in the breach of its financial data servers.
- Uh refer to this memo from the executive team. So I think I think uh whatever we have uh unders understood from here uh there
- was a culture that uh while entering the building uh there was a culture that um to help uh the next uh individual or the next next colleague
- they used to punch their card and allow him to get inside of the building. So this is this was a security breach and um as there are 500 employees. So if
- everybody uh follow this culture helping another person uh without scanning scanning his batch uh so uh maybe um outsider uh is getting inside the
- building and um making a security breach. So um we can uh uh for mitigating this issue um the culture can be like nobody is
- allowed to uh scans in favor of another person. So every individual should scan their own badge and get inside the building. So um the security should be
- ensuring that uh every individual is scanning their badge and getting inside. Nobody's allowed to uh get inside without scanning their badge. So that
- can be one uh major uh security uh risks uh to comply. Did you get me?
- Hello Second option describe a method for finding out
- how many people encourage tailgating and keeping track of those who do. Um extra security
- guards individually
- instruction. Right.
- [Music] Oh, hi guys. Oh, yeah. My son is sleeping actually. So, I'm going to drop
- them after 30 minutes. Please here. No.
- Uh we are doing the activities right now but but we all here >> yeah I'm saying actually uh
- so how far you are guys the activity this activity port we'll release the conible all
- local bank developer about the plan address and physical security that recently is called in the branch and the
- financial data server take a scenario. Yeah, there's a scenario actually it's explaining the
- employee has been observe the door of the others behind when accessing a building and without each employee scanning there. So looks like like you
- know employee actually here uh how it's called helping or like giving the privilege to each other accessing the building without uh what is called badge
- right so you need to actually in order to prevent you need to actually create action plan and how to actually I think prevent this one
- >> yeah so um the instructions is uh something like that we have to uh identify or uh plan three uh potential solutions
- >> for this problem. So um uh one of the u solution can be that um while accessing the building everybody uh it will be ensured that everybody is scanning their
- own batch. Nobody is uh scanning their uh helping another person to get inside the building. So if anybody is entering the building, he has to scan his patch
- and >> Right. Right. >> And uh there should be a system that u anybody uh anybody is not scanning going
- inside the building there will be alarm system that hey uh this person is getting inside. >> Oh yeah, I think this is wonderful you
- know the alarm system like monitoring something like oh this this person actually not maintaining. So you can actually later take an action or train
- him actually. Oh, you should be scanned like this, you know. >> Or biometric like a fingerprint. >> Right. Right. Right. So I think you guys
- are got got it. Yeah. Yeah. There's no 100% right or wrong answer. Right. There could be like different solution. But whatever you guys are bringing I like
- that and the answer of it maybe like whatever the recommended answer like if there will be shared along with the other if
- there are any other alternative option too. So let me share my screen and then come do you guys need break or I think the class will be over within 30 minutes
- if I continue now. What do you think? >> Then probably we don't need break. >> Yeah just
- okay. Okay. Okay. So, let me share my screen again. >> Okay. >> Yeah, sure.
- >> Okay. So, let me share. Are you guys able to see my screen here? >> Okay. So, we we discuss about like security culture, right? And that's what
- we actually discussing here and we need to actually like you know like encourage like uh what is called whatever the activity is like the employee let's say
- there is a a training or why they need to actually scan their badge is there for their own security like you know protecting their uh asset like train up
- for awareness there could be another action plan but let's move forward actually uh what is called next topic security culture framework action plan
- okay so action plan Whatever you are going doing here the activities there is a next topics looks like related with this employee receiving an email uh to
- their work uh account from external resource okay and then employee are clicking the link and download the attaching email recognize okay this is
- like previously we discussed actually like back to the security scenario so let's go through the okay contest again and coordinate with each other team
- member of so the first steps here actually security culture framework steps Uh
- so the security culture that's what we discussed actually earlier he miss X how X access assess their impact to the fishing email incidents in the rigs and
- post and post by the future campaign. Okay and then here there's a three terms in this inclusion. Okay, the assessment like
- assess assessment remember there is a five steps first steps of assessment right. So here assessment of the demand done by the previous fishing incidents
- because they send out a intentionally malicious email remember and then then they're doing assessment and then then using a pen what is called penetration
- fishing attack to show how many employee actually download malicious file like I say like 10% click this rate meaning 10% employee download malicious link like
- they send intentionally the malicious link and to make sure actually identify the metrics how many person actually click this link and then they what is
- called targeted they're setting a target click through rate the team might be decided that five okay 5% click through the rate acceptable okay so that's what
- we actually discuss first actually ident what is called uh fishing like intentionally doing fishing incidents and then identify how many person
- actually this click this link and then what you can do maybe you can actually train them this actually whatever click this link so if I go to actually here
- the steps next steps what they're doing once they get actually this metrics is CF team member uh in this case actually HR manager meet with this like
- you know here security information I forget this term like um executive to explain the the previous fishing attack like whatever they get metric they
- explain issing attacks was successful because of 8% employee downloaded unknown
- like file from unknown email address. So they identify okay they successful if nobody actually click this ident what is called fishing email. So that means okay
- they're not successful in this what is proxy uh attack right because it was proxy attack right remember intentionally so they said actually 10%
- employee actually click this link so that's actually they discuss with their executive and they request for a budget they said hey we request for budget
- carrier to plan to bring like 5% down the because they require for budget for what I think is for actually train the employee to down rate from 10% to 15%.
- So they they actually discuss or maybe let's say you as a security team member discuss with the top management team hey we need actually train to the employee
- so we can actually reduce 50% attack for example right and then here the next steps actually like what is taking action like here security culture same
- framework we are talking about and then CFO team member develop a training plan because if budget is approved they develop a training plan and for security
- awareness you know and this will be only delivered to the employee who click this malicious link after this training. So they what is called they make
- actually plan here you see that right how they do actually they actually send to the employee to the uh training and then also this plan will be only be
- delivered the employee who continue click this militia link after this training that's what we discussed actually
- already but here how they actually proceed like next steps it will be clear these steps you'll be get here so after developing this training plan Talking
- about this training plan we discuss in next this slide and next slide our last slide. After develop this training plan actually team decided intensive and
- disintensive like this will be awarded based on how many employee actually u what is called behave during
- penetration test security audit. Okay. So it's nothing but still telling you like after this security training how many employee actually fall in this
- track to click this link like the link actually they sh here to get this uh the metrics. So
- they actually decide a business plan they'll be give the intensive like $50.50 50 gift card or free discount if they don't actually if if they don't
- click actually nothing but it's saying that here uh discontinu security like conference attendance and the additional
- time okay or discontinuous security conference attend discounted security conference attend
- okay and then uh disintensive supplemented security So here actually uh they they'll be give you actually
- what is called $50 gift card or discounts like whoever actually see conference attendance whoever actually attended this training
- and the additional vacation time. Okay. So it's like a intensive like $50 gift card or vacation on time or something like PTO to encourage the employee right
- you know intensive nothing but encourage the employee to follow this actually security culture but if you don't follow if you are
- failed if you are failed they said this disintensive means they'll be send you he say there is supplement security awareness training they'll be send you
- again for training say you you are not able to follow this culture go for again training that's what is happening all the time real time so let's say there
- actually standard training something and after training there will be a quiz if you win the quiz okay you are done if you if you are failed in this quiz like
- whatever you learn there's a there will be say okay go for again for another training you know supplement additional training here there'll be supplement so
- for example like once I actually get my first time like what is traffic ticket. So they give me a full give me a ticket uh for uh whatever
- reason you know and the and I failed because of um E in E sign actually I failed to stop and I get a ticket and they say hey you you need to go for uh
- DI school uh driving school for training in order to remove your points. Same thing similar thing exactly happen like if you employee like you you get a you
- get a training and after training actually you still clicking actually you know uh the malicious link so you so in this case you'll be get a this this
- intensive for clicking link like you should be go for training like this is like business plan like you know if someone actually passed okay give them
- gift card or something if failed send for send them again for training So security first step uh here. So here like during this meeting actually HR
- explained the most reliable way to secure 100% attendance. They're trying to compare 100% over the next sale year and training 20% of this employee of
- each time. So let's what they're trying to do actually like you know the next year they're trying to four quarter right each year. So they
- were planning to do like 100% employees should be trainer and each is quarter 20%. It's talking about like you know how
- they actually approach uh to address this issue and then here collaborate with the communication developer to contain the
- information of the training. Then to collaborate with the communication developer to distribute information about the training. Okay the training
- information like catalog distribution training. And then step seven actually set up a implement training schedule. So there they're m okay like distributing
- the the training module and then schedule a training and security culture steps the same. Okay. So in this steps actually after this training actually
- every quarter like SEF actually team contracted same penetration testing firm to verify their metrics again you know because all employees already trained up
- let's say 100%. But they want to make sure actually is this like everybody following what is called now aware of this all the security culture or not. So
- they actually conducting again same kind of penetration testing like proxy email and second one actually after every test actually
- S SCF actually team is identify employee who is actually click this link again they're trying to identify and supplemental security awareness that's
- we discuss actually if they fall or if they click actually even after training they will be supplement additional security awareness training you know
- this is nothing but business plan how they actually mitigate or how they actually what is called taken action to train up or uh their employee so they
- so that they can fit with the culture. uh this is like business plan culture steps of this training the fishing email that's what we discuss
- actually like after this campaign they'll be run a fishing email campaign again to evaluate over all the training and this time actually they find let's
- say 5% lower compared to other this business plan so what the action plan here uh what is the action plan okay so when
- when when will be the plan will executed when you'll be measure the progress and how you will be quantify the progress I'm not reading I'm just explaining here
- when will be plan will be executed right uh so plan will be executed once 100% employee pinned up right remember that set a goal 20% each quarter so end of
- this year 100%. So if it 100% plan is done like plan is executed not done like executed and then after executed like all 100% trained then you need to
- measurement right so they'll be in order to measure actually they are doing again fishing campaign to make sure okay they learn actually from this training or not
- and then once they get actually run this fishing campaign again they can measure actually their success rate is this reduced like 10% % to 5% or not. Right?
- So this they looks like if it is 5% looks like they're not 100% success but they are 50% success right 5%. It's like action plan. Um so this activity will be
- do later maybe. Let me finish and then this similar will by there's almost done. So we'll be back in 59. >> Okay. Later
- >> um I can share this uh activity. Okay. Can I proceed maybe with this or wait for activities done by what you can share?
- >> Let me pro I I have a class actually 12 or 2:30 either side. >> Oh okay. So you proceed. >> Okay. So yeah then we can do maybe
- activity later. So security control I think next uh yeah this is very important security controls. What is mean by security control? Uh okay give
- me one second guys. Let me uh message my teacher. Maybe 5 minutes late. 10 minutes.
- Okay. So security control here in addition to improving the security culture over the long term the security team should be enfor security controls
- you know in so what does it mean security controls we'll be learn actually next slide a security control this is the definition security uh
- control is control is any system process or technology that protect confidentially integrity and availability remember we discussed
- actually CIA CIA CIA using like CI CIA tried is called the terms confidentiality, integrity and availability.
- So we'll learn actually in next steps more. So here security controls types but before that if I actually high level overview maybe there's a different class
- for uh confidential integrity and availability confidentiality mean like what is it called uh secure like let's say like confidential data always uh
- should be like um maintain a like let's say strong secret let's say like you should not be access any other person personal uh information. The data should
- be confidential your data or other person data. Integrity nothing but data should not be altered or changed you know whatever data and availability
- means like data should be available for the user when they need you know so this is like but we'll learn actually later in details but here this controls
- actually or is like is discussable three type of controls one is administrative tactical and uh physical. So you see that here like required
- employee to follow their training guidelines. It's like administrative action like management tactical like technical
- example required developer to use secure shell just for example or required developer to implement uh multiffactor authentication you know like technical
- side and physical like protecting building by accessing like this is a key card or other person like you know remember or fingerprint right like
- physical access so so in this slide actually nothing but what is called referring like remember like previous is called like CIA right confidential
- integrity and availability so it means actually any system process or technology like know must be pro protects confidential integrity and
- availability of a resource or of a or for a asset the purpose actually reduce the risks and protect asset from the thread that's the
- main intention right the safier um asset from the thread or attacker. So here like you know this is the like administrative. So administrative
- controls like what administrative they do does actually like they set up like procedures policies uh training the guide the people that's their
- responsibility right set up a policy training and the guide the people like for example employee must complete cyber security awareness training before What
- is called accessing company system if if you don't know how to use system you should not be access this what is called uh system so you should be learn that's
- what like there will like uh like security awareness for example like if you don't know how to drive you should not be go what is called sitting in the
- driver's seat you should be know how to drive and then sit on the driver's seat technical things like here so this is technical solution must be
- like a developer must be like as I said like you know what is called impress secure shell password to ensuring the secure authentication
- right and same thing like easy example here we already discussed so in this slide the security controls can have different goals like why you need
- security controls so previous topics was security culture we are now talking about security controls and security controls nothing but there there is The
- three core things we already pointing out like CIA remember guys very important confidentiality integrity and availability right so here the first one
- actually preventive controls so it's like differentiate the what is called define five different controls one is preventive another is uh the trends and
- then uh detective and then corrective and then compens compensation controls. Okay. So
- what does it mean here like prevent preventive action right? This is the access to the techn. So like for example see here prevent action access with
- physical or tactical barriers uh like access using key card for example like uh preventive action means like you should be stop incident before it's
- happened right like this is preventive like you are taking action before it's happened. So for example like kicker accept
- prevent unauthorized access. So you are actually taking an action before it happen and then detent control here like discourage this
- is mean like discourage the attacker for attempting to access the resource for example like how we can discourage attacker right and how we can encourage
- attacker to attack so here is talking like discourage attacker like let's say you you set up a security camera Right. So and once someone like for example
- home camera home security camera of once someone actually appear in this camera say hey you are under in camera or something like this. So if it is threat
- like attacker someone like they say oh my god is camera is on. So it will be discourage the attacker right hey okay he don't want to attack because he knows
- there is a monitoring going on. So if you don't have any monitoring in your system right so attacker there is no monitoring he'll be encouraged to attack
- if you don't have any like what is called like strong security policy like let's let's say your door is open so attacker can actually enter your room
- and steal like your valuable stuffs because you you encouraging the attack okay come come to my home and uh steal my stuffs so you should be discouraged
- how you can discourage you should be close your door right same thing you should be in cyber Security should be implement strong security. You should be
- implement uh monitoring policy that will be actually discourage attacker to attack because attacker is not like always what is
- called if attacker knows okay this company always maintaining what is called strong strong security policy let's say like casparoxy or
- whatever like the they're working for security right the security company so attack okay security component they are expert on this right so they are not
- trying to actually attack security because let's say there's other what is Mid-level company there are grown and they don't have like maintain any
- security policy because there's a lot of things actually how you can they can determine they maintain strong security or not you guys can learn in practical
- uh class like or how attacker actually uh run a let's say n map or zen map to ident identify the loopholes or identify the open port so they can attack so they
- knows actually how to identify the vulnerabilities if attacker Don't find any vulnerabilities, it will be discouraged
- attacker to attack this system, right? Because he can't find any vulnerabilities. If there is a vulnerabilities available, it will be
- encouraged attacker. So you should be discouraged. And detective nothing but actually here you should be apply the uh what is called alerting system or right
- monitoring system. If something actually happening and then like corrective action let's say fix the problem like if it is happening something right you know
- you should be actually able to fix the problem you should be let's say you are using outdated software you should be update your software right as long as
- it's available let's say you're using a known uh what is called burnable software because there's a lot of software out there and it's non
- burnability and fix is not available let's say there's a software You are using your system is using but you need the software and you knows
- there is a vulnerability out there and tomorrow they actually release their updated version to free with fixed version. So what your responsibility you
- should be update this software with in order in order to remediate this vulnerability you should not be used like old software that's actually always
- it's called like patch management or like software patch you'll be hear this term in real time and compensation control nothing but
- restore the function that compromise the system right so using like temporary let's say how we can restore let's say your server is down right uh or there is
- a detach attack. So it should be have plan here right how like let's say you can implement like temporary firewalls or back up your system to maintain your
- service if it is what is comp let's say one uh what is called server is compromised you should be have another backup server that can run your business
- so we'll be discuss actually later class uh so for example if I go to uh okay so we have more secure tools yeah so Next okay coming lecture we'll be learn
- actually more this how we can actually determine but let's move on this this slide. So here more security controls in this unit. So here is regardless of
- their types actually all security controls uh seek to restrain or respond to the access of the resource. The following
- access control determine who can access specific resource like Linux file permission. For example, a Linux f is talking about access control. What
- access control like file permission act as access control preventing user from modified file they don't own like as I gave you like other example earlier.
- So if you don't own any like you know what is called uh any asset you should not be able to actually modify or update anything because you are not owner of
- this. So this is like example. Same thing here for network firewalls control access to the network right and like incident respon monitoring system we
- already discussed actually those things you know so for example like network like firewall control and access to the network you as a company company
- employee like everybody like should not be accessing your company network only employee should be accessing the network company network because there's a lot of
- things in company employee can access without password as long as they can access their network. So this is the example like it should be actually what
- is called uh manage access control who can access your network who can access your file system for example like Linux and if something happened you should
- have like you know incident respond like monitoring system. So security control check learning learning the security control is the
- fundamental aspect of the security design framework defense in depth. So this is very important guys like here we are going to disect actually like
- what is called uh how we can defense in depth like what how we can implement a security like in multiple layer right one if one
- layer is failed how you can implement like let's say plan A plan B plan C you should have multiple plan actually to uh what is called save your system. This
- is nothing but is called like defense in depth. We will learn in next slide. So this is the definition. Defense in depth is a practice of using multiple defense
- to secure a resource. For example, let's say you have a home and you have a lock in home but you have a gate before you enter the room and then gate has a lock
- like you have a multiple layer of security for your home and you have a security camera in your home. So like multiple layer security but we'll
- discuss about like uh what is called in technical terms for example here defense in is talking about technical controls
- and then tactical and tactical controls and procedures. Okay hiding the server behind the firewall. This one example firewall. So firewall can protect this
- is like first first defense like firewall to protect your server. Another technical thing like forcing user to
- authenticate. So authentic user let's say even there is a firewall if firewall is failed user should not be what is called access your server like without
- authentication. So if firewall is failed this should be protect your server authentication or SS key whatever like password or keyless uh passwordless
- access like it's called like SSH. So defense in depth nothing but multiple layer of security. If first layer is failed, second layer should be active to
- protect you. If second layer is failed, third layer should be protective like multiple layer security. Here first layer firewall then second like
- authentication and here you see the required user to generate a new key with new strong password. So there's another one like
- user should be use strong password or is saying that every quarter and change the password every quarter right so multiple layer security think about this is
- nothing but defense in depth if firewall is failed this should be protect if you and let's say this this is also failed you somehow actually your act your
- password somehow user actually hacked but you change your password here right every because you are doing every other what is called uh quarter you are
- changing your password so even your password is hacked here let's say somehow but let's say like same day like you reset your password here right like
- every quarter so in this case there's another like oh even password is hacked like your old password may be hacked but you change your password like multiple
- layer security so there's another best practice you should not be use your same password for your lifetime right you should be change it you know
- So, so this is nothing but actually redundancy and single point of failure means single talking about single point
- of failure means if you have I'm just explaining this slide if you have like one single point of defense and if it is fail that means your entire system will
- be compromised right so that means like single point of failure should not be break your entire system you should have you see that in the
- slide side like security layer one security layer two security layer three. So if you have multiple security layer if the first layer is failed second
- layer will be protective second layer is failed third layer will be protective but if you have one layer security it in this case if it is fail
- so you'll you'll be lost everything okay so we oh looks like
- uh okay let me uh Clear this one here for uh what else we have
- now looks like it's almost going to over 781 but we have only looking forward question okay in so governance like last one but we have activity but last one is
- taking about this slide what learn with today prepare us to learn about the governments later this week. So is governance definition.
- Remember we actually discussed this with the first slide. government is is the portion of the GRC framework like Gmail's governments used or enforce
- the security standard policies and uh procedures right so governments nothing but just refresh entry in the organization follow the security
- standard policy and policy and settings rules responsibility and the oversight to make sure everybody actually following this standard so like
- governments That's nothing but will tell you what must be done and who and who is the responsible for this.
- So I think yeah today class is over guys. If you guys have any question either only activities left.
- >> So do you have any question? So thank you Mushid V for your class. So inshallah we'll take care everything.
- >> Yeah. >> Thank you for your uh cooperation and uh help. >> Thank you guys. See you then maybe next
- time.Am fair comments.
- governance risk compure. Security
- controls securityver
- Security, email security. So next class. So
- assment. Linux Linux first assignments
- will tomorrow. I we uh problem hearing your voice.
- Okay. So next class. So
- first teamwork.
- [Music] Super good.
- So important management service security service provider.
- This is the very good for um starting inshallah uh 2026 uh we are starting this uh uh project inshallah. So uh if I slowly slowly we
- can start um future. Okay. So [Music] this is a good way for us.
- Most of the people maybe citizen green card holder,000 business.
- H13 unskilled. So remote working
- EB3. Visner extraordinary. Right. Right.
- extraordinary scientist or something like that. [Music]
- Yeah. Yeah. tomorrow 5:00 p.m. Our next class inshallah.
Zum Nachlesen
ZugriffskontrolleZugriffskontrolle ist die Überwachung und Steuerung des Zugriffs auf bestimmte Ressourcen. Überwiegend wird der Begriff in Bezug auf den Zugriff auf Daten …
IT-SicherheitsauditBedrohungen für die Sicherheit können ausgehen von kriminellen Angriffen, von organisatorischen Mängeln aber auch von technischen Unfällen oder höherer Gewalt.
Security EngineeringSecurity Engineering ist ein Fachgebiet der Informatik, welches Techniken für das sichere Programmieren von Software sowie Instrumente zur Abwehr und …
InformationssicherheitInformationssicherheit ist ein Zustand von technischen oder nicht-technischen Systemen zur Informationsverarbeitung und -speicherung, der die Schutzziele …