Zum Inhalt springen
L

Das Video kommt von YouTube: erst beim Abspielen verbindet sich die Seite mit YouTube (Google).

2.1 Introduction to Security Within the Organization

Cybrbee3:02:02 51 Aufrufe veröffentlicht Auf YouTube

Das Wichtigste aus dem Video

Tipp auf eine Zeit – das Video springt genau dorthin.

Transkriptautomatisch erstellt · 944 Zeilen
Herunterladen
  1. Today uh we'll study this uh uh class. This is the GRC governance uh risks and compliance. This is the mostly um theoretical class and very very
  2. important for your cyber security uh knowledge. So today I introduced uh our new instructor. This is the name is Ciphel Motion. Basically uh he um came
  3. from our first batch and u uh this is the our culture we started this our culture. Alhamdulillah Allah granted us uh he joined uh us uh
  4. 25 from January and alhamdulillah now is September and uh we successfully landed our team and um inshallah uh 2026 middle we
  5. are starting this our MSP Slowly slowly we uh make our good team uh inshallah. So everyone help us and everyone um join with us. This is our new instructor
  6. Safil Moshid today. Uh contact this class. Uh but I am available is online. If anything problem uh Safil Moshidwai so you just study class anything uh
  7. problem just not me.Am Yeah, sure. Asalamaikum all. Yeah, I think I spoke with this B like other day so I don't need to reintroduce myself
  8. but uh let's get started then. So today the class actually we are focusing on GRC right the main whole uh 3 hours class will be GRC so cyberc introduction
  9. of cyber security within organization because uh GRC related with this organization and employees. So that's why this is the headline you can see.
  10. Are you guys hear me clear? Right? Anybody can confirm? >> Yeah. At least I can hear you. Yeah. Clearly.
  11. >> Perfect. Uh so uh if I go here like class objective by end of this class actually we'll be identify the uh actually the theory concrete benefit of
  12. healthy security culture. What does it mean healthy security culture? And then explain the responsibilities of the sweet officers and the CISO. It's
  13. like high management. Explain the responsibility of security department and identify the appropriate security controls uh for a given
  14. resource and situation. So this will be our class objective that we learn actually in going forward step by step. So security alignment with this
  15. organization. If you go to the next slide, this is like the example of this like the how actually organization structure. You see that here like you
  16. know uh in the top like chief security risks officer then enterprise chief officer head of the production. So under head of
  17. the uh what is call then enterprise CIO and under him like IT operation uh what is called incident response and IT security team and here enterprise
  18. chief security officer he's actually like managing this area chief information security uh of uh what is called uh of
  19. enterprise chief security officer okay under his like this is actually job title Chief information security officer and
  20. security standard. So it is belongs to him like reporting to him and the security architect depends on like it can be very like organization to
  21. organization. This is like one kind of example looks like from the larger organization but if it is smaller or medium it could be like little bit
  22. different but this is high level overview but our objective is today to understand actually GRC and this will be related
  23. with this organization you know. So if I go to the here GRC framework so here in the you see like GRC frame GRC framework is answering the following
  24. question. So there's a two question what asset are most important and this qu and second question what is the earthquake protection.
  25. So if I ask you guys like what do you mean what like what is mean by asset anybody can like you know think about like what is asset means by
  26. uh if you took actually non techchnical example for asset. So this is very important like these terms actually you need to understand actually in the real
  27. what is called uh in technical terms too in order to work in real uh environment. So if you think about asset as a nontechnical example like asset means
  28. for example like jewelry important documents family for tool right this is like very very valuable asset if you think about like what is called less
  29. important asset let's say like old magazine or any newspaper you can think about like what is called this is less important asset right
  30. and if you think about like what is called the asset of like in cyber security terms. So what does it mean then asset right? So asset means like
  31. for example the data system and the people right. So anything like you know the world actually everything like is data driven like everything depending on
  32. data. So ini in GRC term here like in cyber security asset we can actually define for example like customer information financial record
  33. intellectual property this kind of data you can consider as a like uh what is called asset also in the system like if you think about like system perspective
  34. your server your asset your database your asset your apps your endpoint your asset right if you think about like what is called the people like people with
  35. the private delayed access for example like you know who can manage actually the uh database server who can manage let's say uh networking you know so
  36. those kind of things in cyber security you can consider as a asset so how we can actually what is called uh identify and classify the asset
  37. so it's like there is in cyber security term is called CIA trade I think you guys can learn later or maybe you already knows
  38. like this is this will be help you actually to identify and classify the asset. So any question guide asks to hear what
  39. does it mean asset you know in cyber security terms no question so basically you're trying to say that
  40. asset means anything part of uh this program like you know part of cyber security or part of you know technologies for example data
  41. information or it could the admin information or as admin in a team. Right. >> Right. Because like if you lost to your
  42. asset, you'll be what is called lose your value or business or it can arm you. Right. So if you lose something actually if it is affected and if you
  43. lose something that means this is you can consider your asset and you can classify your asset you know this like it can be like higher priority less
  44. priority right and based on this asset priority you should be define your security so we'll be so this so how we can actually
  45. define the security based on actually next question >> okay so here is saying that like we so by this what we already knows what is
  46. mean by asset Right. So and next question what is adequate protection? So adequate protection is means actually applying the right level of security
  47. controls like based on value and risks. It is like uh you cannot actually make everything 100% secure. It's like impossible right? Uh but you need to
  48. ensure actually what is called uh uh protection balance based on your uh asset value. for example like a nontechnical example jewelry right or
  49. your important documents. So this is actually very valuable asset for you. So if it is valuable you need actually like let's say strong protection you you can
  50. uh what is you should be keep this kind of um uh asset in the safe locker right because it's valuable but for example like uh and this is nothing but adequate
  51. protection how you can actually define your protection based on value and then for example as I said earlier like old magazine uh maybe you can
  52. simply put in your glass cabinet this is enough so now what What is mean by that? Actually you don't need to actually is define actually quick protection. You
  53. don't need to over need to overspending for lock everything. Uh so you just need to lock or put a security that you care about right
  54. for uh example in like cyber security terms uh for example like what do you think about like a high level uh asset as I said like you know the data so data
  55. let's say your customer data or let's say your bank account or user information right so in this case you need here like you know this kind of
  56. strong security for example you can you should encrypt your data. You can uh apply multi-pro multiffactor authentication
  57. or regular what what it uh you will be learn about like I think going for CM monitoring like oh if something happening within your asset or any what
  58. is called um like uh malicious activities you need actually monitoring system. So that you you guys will be learn later but here we
  59. are trying to understand actually what kind of protection we need based on as I said uh risk uh what is called asset value
  60. uh lower value we can consider is like you know uh in cyber security term let's say there is a company booklet let's say once if you are joining any company
  61. there's a benefit booklet oh what kind of benefit you can get from this company so this is not like what is called u import very important asset you can
  62. consider this kind of things like lower value because if you lose you are not losing any I think what is called let's say business or something like it's not
  63. going to uh arm your business. So that's how actually you can define first you need to define your asset and then what is called identify the value and then
  64. based on value you need to actually define your production. This is nothing but called protection. Uh any question guys up to here?
  65. >> Um can I share something? Um so you trying to say that uh you know we need there should be nothing less or nothing more
  66. >> right. uh based on our assets below we need to provide the protection let's say if there is need one security for example one security guy
  67. >> to uh take care of building I don't need to provide two people there right >> or probably there might be there I need five of them so I need to provide five
  68. of them >> right >> there shouldn't be less >> yeah yeah that's true and let's say some
  69. building actually let's say you just actually keep your let's for example example like your what is called something like this is not you need like
  70. it's not valuable it's maybe not required even like you know uh security so you don't in this case you don't need like security guard so this is actually
  71. define how we can protect your asset >> because like uh putting security is too expensive right for everything so if you don't need security yeah but you need to
  72. actually definitely actually what is called secure your important asset and that's we already described like customer data for example or your
  73. database or the system. Second question, I'm going to taking a little bit more longer time in the beginning and then we'll move fast forward. But you need to
  74. understand the concept. Um this is very important actually for your interview and for any I mean like I know technical uh analysis or research.
  75. Second question I have like you know uh for you guys like uh what is mean by actually the framework right you know like you send the GRC framework. So what
  76. is mean by framework? So uh if I how you call give you the nontechnical example like framework it's is nothing but a simply structure right
  77. it's it's giving you the guidelines the rules and best practice how it should be proceed you can consider like a blueprint of a uh building design right
  78. so this is not nothing but a framework or how you can actually uh what is called build your building or if you think about like let's say for
  79. example a cooking recipe. So here like food recipe nothing but your framework. So you don't so it does not like this framework does not cook your meal right
  80. but it will tell you how to in what kind of integrant integrance uh you needs steps or order you need to follow but you can add your own let's say spicy
  81. right uh but the structure or guideline already there what you need to do so same thing like if you comes actually like in framework for technical terms in
  82. in GRC so GRC's framework work is nothing but actually a set of like policy procedures controls you know and and that designed to help organization
  83. to manage and reduce the risks in a structured way. So it means like you know it's enable the cons consistency
  84. and uh ensuring the compliance uh for example like uh you let's say your DRC team so there's a DRC team in you
  85. can see like you know every or IT organization and they can maybe let's say if you guys hear about like uh NISTD security framework right so they can
  86. maybe say hey you need to follow this framework mark let's say there's maybe two or three uh standard out there will be might be what is called set of rules
  87. you need to follow NIST standard you need to follow the other ISO standard so this is nothing but actually GRC like framework will be set a policy and as I
  88. said procedures and control that you need to follow your organization need to follow are you guys clear like you know this is very important terms for any
  89. framework like if people actually ask about a framework So uh it it it doesn't matter like GRC it can be like any framework let's say your working
  90. framework like you know if you're developer okay development framework if you are a testing framework so here we are focusing on GRC framework
  91. uh any question guys like frameworks is very important to understand no question Okay. So if uh so let's move in next
  92. steps like GRC what is mean by GRC? So GRC G means governance R means risks sorry it's called risks management and uh C means compliance.
  93. So it's like as I said it's a frameworks that help actually organization align with their security activities within business for example objectives
  94. and manage risks actually effectively and ensuring the compliance with low regulation and standard. So here you can see like it's saying
  95. that DRC creating managing creating management process okay and implementing security practice across the organization
  96. and risk management identify the organization most important asset that you learn actually so risk management team they will be identify the important
  97. asset and determine how they might could be compromised or might be compromised. and complied compliance team they're
  98. making sure actually business follow their internal security policy so if I actually what is called give you the simple example like what is mean by
  99. governance so is as I said it is setting a policy governance define a rule and creating a accountability of security and risk management if I refresh again
  100. uh it is identify Okay. Identifying your asset and m how to mitigate the security risks like for example like let's say how to mitigate uh fishing
  101. ransomware or insider threat. So they will be actually identify uh this and compliance as I said this team normally they are focusing on ensuring here like
  102. business business means like employee right uh they should be follow the uh uh what is called regulatory or industry requirements for example you guys learn
  103. about maybe later like HIPPA uh there's a standard name u PCIC plus C card I think it's called transaction something So there's a lot of like uh policy or
  104. like standard this compliance team making sure okay they are actually following this standard and this is actually very important in
  105. like you know to uh in cyber security to understand governance risks and compliance uh any question guys up to here.
  106. So if I give you like example for example like the governance if guys are not clear uh for example think about like what is called bank set a policy
  107. that all employee must be use like multiffactor authentication to access the customer data. So who actually define this rule actually
  108. governance. So they define a rules and leaders and every employee I'm repeating again like must follow for example or every
  109. employee must be scan their batch once they uh what is called enter to the building so they define the rule what employee or the team should does and
  110. risk management so they're identify actually let's say here as I said like they are defining let's say multiffactor authentication
  111. and risk management event they're thinking about like their asset how to protect let's say they're thinking about like a hacker can actually steal
  112. customer data. So in order to mitigate how to mitigate actually implement uh multiffactor authentication or detection policy for uh fishing you
  113. know fishing attack and comp compliance they are nothing but making sure every body actually what is called following these rules or not.
  114. So are you guys clear or still confused? So the third thing compliance basically focusing on both governance and risk management if they are doing their job
  115. you know correctly or not study >> no not risk so governance nothing but for example like let me give you the another example
  116. >> so governance let's say like so governance let's say government compon government organization for example it can be any organization governance means
  117. not government government can be any organization team names governance. So let's say there's a government organization and they set up a making a
  118. rule for traffic law. So government let's say US government making a rule for traffic law. So, so this department called governance whoever making a rules
  119. for traffic and risks management uh you know they are actually what is called um defining hey driver in order to avoid accident
  120. you know so they should be follow the you know the signal for example of traffic light and other thing they should be maintaining the if they don't
  121. maintain it's a risk right >> yes >> so compliance let's say here's a compl compliance right the compliance team
  122. making sure okay like whatever they defined actually they're following this here you can consider like police officer they're ensuring okay every
  123. every driver following traffic rules uh but yeah so I think you got >> yeah yeah yeah so it's just
  124. it can be like it can be applicable for like anything it's not like only for DRC not for like only for technical terms like it can be nontechnical things says
  125. as well as so we are talking about >> it could be implemented by any organization >> right right so if you think about
  126. >> that's a general idea >> right right you got it but if you think about our cyber security we are only content like security security that's
  127. why I give you the example like here we need to implement like let's say multiffactor authentication or other things you know or like credential
  128. username password you cannot should not be accessed without username password and you should be used like a strong password for example right
  129. >> yeah so So who are creating those uh set of rules and implementing those practice they're the part of the governance >> right right that's true that's true
  130. >> and yeah and the other is part of the risk management and the last one is the part of the compliance >> right right
  131. >> so anyone can be working in different you know uh section like govern governance risks management or compliance right
  132. >> right right no that's true it's like there's a different teams Normally in every organization okay this team actually set up a rules and there's a
  133. risk management and there's a compliment. >> So are you are we will be part of the risk management as a cyber security
  134. engineer. No, no, it's a different team. I see that uh it's maybe defense what is called competitive company but I see that what is called this GRC
  135. >> mhm >> you know totally different teams some people in GRC let's say there is a for example two people for example uh
  136. working on this another two people working on this and another two people working on this or like if it is pretty big organization let's say you can
  137. consider this is a different one team this is another team and this is another team so they are working under part of GRC but there's a three different team
  138. you can consider you know so normally uh you'll see like maybe like if it is media even medium size or larger it will be different different
  139. team for governance risk management and compliance it will be like all the independent team you know and they'll be monitoring
  140. everything the compliance team to making sure we are doing right So if I move if next like we defined actually important and by asking like
  141. important asset for example like how would security uh security compromise of this asset affect the profit of the business.
  142. So basically how to decide here is nothing but telling how how to decide if asset is important or not based on the business impact. So how we can define it
  143. actually right asset is this important not is based on your like oh if you if you if it is got a drug is this going to arm you harm you right so it depends on
  144. like um business impact as I said so it means like important asset like database for so like going back to the previous
  145. example server or website uh like those are like core things that drive your business Right? And if the asset actually compromised those kind of asset
  146. uh does this affect your business profit. Right? So if answer is yes so it could be impact your business profile operation and reputation. Right?
  147. So uh in in DRC what is it called uh DRC decision like what should be protect first like risk
  148. management uh for the business value for you want you want to protect first money you want to protect first trust or compliance
  149. so it's it's like so they will be like risk management actually what is it called or GRC team they will actually uh what is called define based on your
  150. asset value what you need to protect first you know >> even though all three are important but it will be decided by the GRC framework
  151. >> yeah so I think there's horoscope uh in coming slide we'll be getting a more idea right you know how actually you know like how we can prioritize like do
  152. you need to call priest I mean like uh money trust or compliance so there's an uh in coming slide we'll be learn so
  153. so the most significant and the loss the most important of the asset is right if you lost more than mean your asset is very important
  154. right uh so if you think about like for example uh what is called money loss so there's a three things we discuss like money loss like let's say there's a
  155. online website for e-commerce right if it is got DOT attack are you guys familiar with DOT so distribution uh uh
  156. distributed uh I forgot to meaning dedic meanings uh it's called uh distributed denial of
  157. service so distributed denial of service let's say your website. So your website means your asset, right? This is the one of
  158. the valuable asset. So let's say got DOS attack. So DOS attack means is going to be your let's say your website completely goes shut down or offline for
  159. 2 days. So they're just attacking to to down your website. So in this case what you lost actually like uh customer cannot
  160. stop from your website, right? and business could be business could be lost actually millions of dollar. So therefore in this case like your website
  161. actually very important asset but you're not actually what is called for example it's you're losing here like money right you're not losing actually
  162. let's say any data or any other asset you are just losing here money because your website got attacked and it's only got actually down or like offline for 2
  163. days but let's say attacker is not hacked yet so it just got attacked so in this case what's happened you just actually losing money right and losing
  164. customer trust as well as but let's say actually your database got uh attacked right customer database so it's compromised let's say your website
  165. actually uh your database and hacker actually steal your customer financial data so what's happen in this case is directly impact actually regulation
  166. right so you should be protect your customer data this is like there's a regulation it's called like um uh one example like PC uh PCI
  167. uh regulation like PCI DSS I think plus uh what is this called I forget actually PCI um meaning uh PCI let me Google it
  168. giving the actually right example so uh PCI I think >> payment payment So payment yeah payment
  169. card industry data security standard you know so in this case like you know yeah you got it thank you so if you lost your actually customer data right this is
  170. very important asset so in this case you your company will be fine because you lost because you are not actually able to maintain your customer data right so
  171. it's directly impact the regulatory and directly impact the customer trust right so that means actually uh like uh database compromise means
  172. like you can consider is a compliance impact and major financial loss. So what I'm try what is trying to explain
  173. here right if you lose actually like trying to give you the example like so do attack like you can lose only money but
  174. you are not actually losing compliance here. So just for example if it is only detach distributed denial of service means your
  175. uh uh what is called server or website goes down for certain period of time but your if your database got hacked in this case you are losing actually two
  176. things trust and compliance right so are you guys like clear on like I think pretty much like we are talking
  177. about like GRC only thing like targeting GRC that's why I'm taking those kind of example simple and and the trust compliance all these are things actually
  178. related with GRC. So if you go to actually next slide you see that here GRC framework
  179. we'll be study actually how GRC framework are considering as a or it's called implemented in a business by first examining the following okay so
  180. the executive management team is ultimate responsible it's a executive team means like higher management they are actually responsible for adherence
  181. and enforce the law regulation and security practice so like top management or top leadership they are nothing but managing the rules like they part of you
  182. can see like remember like governance thing or like the governance so here governance they are defined like executive team so this team actually
  183. define the rules best practice like and the laws so it's it means like for executive you can
  184. think about like uh CIO like CEO like board director this kind of rules you can consider as a like you know executive management team.
  185. So like why it's matter in GRC right? So DRC is not like a technical things as I said earlier it's like uh what is called
  186. businesswide governance issue if the executive actually don't support it like the policy and controls it would not be affected effective right so you need
  187. actually strong support in order to implement GRC from the like executive management who and executives management nothing
  188. but they'll be like part of the governance and you need their support right so for example like if I give you like so here
  189. we are talking about like implementation right how we can implement if you cannot get a support from top management nothing but who governance team you
  190. cannot actually implement GRC right because there's no support for example like if I take about like non-technical example let's say you are a restaurant
  191. owner uh and make what is kind of responsible making a like healthy healthy food, right? So even like your chef, let's say he actually cooked very
  192. well and and clean every day, but owner does not care about actually what is called like healthy food, right? Or hygienic policy. So if owner does not
  193. care about like healthy food and hygienic policy, do you think this restaurant food quality will be good? Definitely not. Right? Because owner
  194. owner doesn't care. So that's sort of in same thing in cyber security like if governance team nothing but executed team
  195. if they if you get actually they are primarily responsible to making this kind of laws rules and regulation and you and there should be support to
  196. implement. So this is like how actually you can implement uh like DRC in your
  197. organization. Are you guys uh uh clear on this like you know in this slide or do you have any question?
  198. No question. Okay. Next move in next slide like security management. So security management planning and identify the
  199. security rules development security policy. So here security management like we're thinking about like you can consider as a like executive team
  200. management team like so planning and defining the security rules development security policy performing risks analysis it is part of like risks
  201. analysis team and then let's say so you guys might be confused here right so as I said like this is part of like this this part of governance right so
  202. performing security analyst so so they're not governance system not performing security analyst so that is security assessment team right so in
  203. this case they'll be get a report so this team will be get a report from security risk team so they'll be asked hey I need a report actually security
  204. assessment report analyze report for this particular asset or whatever and based on this report they can actually develop the strategy
  205. tactical and operation plan uh are you guys clear on this slide right so this is as I said like planning ing and defining the security rules the
  206. GRCG like governance teams or executive team responsibility developing security policy their responsibility and so they will be what
  207. is called define a strategy technical and operation plan how they actually define this one based on this report and this report they can get from security
  208. risk analysis. So if you move actually to the next slide right so security management you see here like it's like pyramid if you
  209. think about like this strategic tactical and operational. So this pyramid actually what it's called divided into three categories. The first category is
  210. uh strategic. It's saying that developing uh strate strategic plan long-term plan like align align with your organization goals, mission and
  211. objective and say longterm like let's say five years and tactical it's midterm like plan that details on how to accomplish the goals. So they define a
  212. goals and this one actually this middle tactical this will be work how they can actually reach their goal or mission or
  213. objective. So, so they set up a goal and they this part actually responsible how they can reach their goal or mission right and
  214. operational plan actually short-term highly detailed the plan based the strategy and tactical plan for example operational like how they can actually
  215. operate to actually do something in order to reach this goal. So if I give you like what is called best
  216. what is like you know easy definition like the strategic their focus on how they are like why they are doing why they are doing this for example if you
  217. want to do something like you should be have you should have a clear goal mission and objective right so they the strategic team actually like they are
  218. focusing on why they are doing why they doing because they have like goals, mission and objectives. So they're actually defining why they are doing in
  219. order to reach their what is called goals and the tactical team like their their focus will be focus will be like what to
  220. do like for example it's a one year like for example like in 2000 next year they set a goal next year to reach their
  221. whatever the goal so this team actually defining or this particularly defining like how they reach to to the goal so they can defer what to do in the next
  222. year that so there can get like closer to the goal or they can achieve this goal. So they will be actually make a plan how they
  223. can reach this goal the strategy how they can reach the strategy and this the bottom one like operation plan like therefore how how to implement you know
  224. so implement like in uh practical so uh for example like a strategic let's say like over the over the next five
  225. years your company wants to become a safest retail company in the country. So this their goal. So if people actually comes here
  226. in their uh what is called retail website or retail store, people should be feel like uh this is the safe place to shop. So they make a strategy next
  227. five year okay there will be become a like number one safest retail store for example. Right? So this team will say how I can actually make like oh okay the
  228. store is like safe and secure. So they said okay this this part actually they actually what is called let's say okay this year we can implement let's say CC
  229. camera and hiring let's say five security guards to make sure like you know security is strong enough so they set a goal make a secure and they
  230. actually what is called defining how to reach this goal and then the operation like here let's say uh schedule like what is called uh the
  231. guard in like say first ship, second ship, third ship let's say they check actually their camera because they install a CC camera and their operation
  232. they check a camera to make sure if there's no what is uh what is called uh unethical things happening and they are making sure actually what is called
  233. let's store door let's say let's say it's like uh all the time for example it's a closed or it's locked actually so just for example so they are actually
  234. implementing real things like like what to do and they they are actually defining how to do and they are setting actually the goal.
  235. So this this this tactical and operation both team actually working to reach this goal. any question guys up to here
  236. for example like if I take another example like let's say technical example from like let's say your company like what is called planning to achieve ISO
  237. certification you know in the over over the next five years so in order to get actually certification or any other security
  238. related certification so so let's say there is actually requirements they need to employ employ what is called deploy multiffactor authentication monitoring
  239. system or conduct uh penetration testing. So in order to get this what is called let's say recognition let's certified company for example.
  240. So so if they set a goal this team will be identify what to do. So they said oh okay in order to become a ISO certified company I need to actually implement
  241. multiffactor authentication monitoring strong monitoring system and penetration testing. So because in penetration testing normally organization will hire
  242. third party what is uh consulting firm to make sure their uh what is uh uh the site or whatever asset is secure. You can do your own penetration testing but
  243. it's a government it's a requirements. Let's say if it is financial or any other sensitive what is called uh uh uh the website or let's say there is a
  244. business they're dealing with sensitive uh user data in this case it's a requirements like um to do like a for example like
  245. any organization you can see like there's auditing system right third party will become for auditing so same here for security third party will
  246. become for penetration testing to make sure okay are you really secure or not. So, so this is like let's say they'll be set up oh this kind of things okay they
  247. will be conducted in testing monitoring system and then multiffactor authentication and operational team let's say so how actually they support
  248. them so so this middle like technical team team they need actually support from here right so whoever working let's say in short term so then it will for
  249. example update regularly their software their monitoring like alerting system. Uh so these kind of things they can actually do in shortterm in order to
  250. support this and if they get a support from this operational team they can raise their strategy.
  251. Any question guys? No question. Uh yeah, if it is hard to understand
  252. guys like you know or like feel free to raise your hand so I can try to actually give you maybe like you know any other easy example but I feel like maybe you
  253. guys uh risk should understand whatever is discuss discussing here. So if I actually move in the next slide
  254. because okay security rules and responsibility exe executive rules rules existing in more what is called
  255. most companies it's called like executive rules like this is nothing but the leadership or we can governance uh executive rules related with the
  256. security department this respons responsibility of security okay responsibility of security department the structure of the security
  257. department it's the overview whatever we discussed already. So executive rule the core leadership here. So this is like kind of like structure give you the uh
  258. person or so get an idea how it could be a structure like CEO um responsible for uh binging with the overall the direct uh direction of the company the so if
  259. you see here like here CEO and then chief financial officer, chief operational officer, information officer uh and then security officer kind of
  260. like how their organization was structured and under Then there is a multiple like other uh you can consider team or
  261. uh different department there. So same thing here like if it's is like giving you the like what is called the responsibility of chief
  262. financial officer you see that the charts and monitoring for the company uh what is called financial uh titory helping ensure the comp company use the
  263. fin uh hor is called finance wisely. So making sure actually whatever they're spending the money they're using actually perfectly the financial officer
  264. and the chief operational officer to ensure the business able to function operational you know operating officer kind of like anything operation it can
  265. be like not only like cyber security like if you think about like operation officer so they are mainly monitoring like oh business is up and running or
  266. not in day-to-day you know so this is their main concern and the information security officer make manager risk to the organization data through the
  267. tourist life cycle. Uh are you guys familiar with this life cycle term? Like life cycle nothing but for example like you can think about
  268. your your life cycle like you born and then you actually uh skull uh try to learn how to walk and then try to learn how to speak and then try to learn how
  269. to actually lead your life and then uh one day you'll be die right. So your life is over. So everything like there's a life cycle for every product. Every
  270. product there is a life cycle or so this is not oh how till you start and how it will be going to be in or finished. So life cycle like uh is it depends on like
  271. the which area you are talking about and uh here chips uh uh what is called information officers here okay develop the IT system to support the business.
  272. So he's actually responsible for to develop the I uh like whatever required actually to support the business to making sure for
  273. example if we think about a cyber security so he will be develop a security policy or security let's say technology to making sure actually
  274. business is secure actually it's actually uh safe from uh safe from like attacker just for example if you think about like security
  275. If if you move in the next slide here see that the responsibility of the security department. So here like you see that the department
  276. like it could be more department right but here like highlight actually three department networking incident response and application security.
  277. So this is the this is like what is called the position like who is actually responsible but super so and supervise a director of
  278. the networking system administrative network administrator and network administrator and the physical network technical staffs. Okay. And then
  279. incident response like sock manager uh security analyst and incident handlers. Okay. and application security the security architect
  280. topically manage the security engineers and software engineer. So if I give you like you know easy easy example for example in here like there is a three
  281. department is talking about like network security incident response and application security. So if you think about like network security so network
  282. security like what they do here like the protecting protecting the infrastructure the network security department to making sure the server firewall writer
  283. router BPN like Wi-Fi whatever networking related those are safe you know so this is actually this team actually responsibility
  284. and this team like it's it's a network admin like there's a multiple roles belongs to this team. So it could be like network admin, CIS admin, network
  285. uh technically on or help desk help desk support. So this is actually part of this one and incident response. This department they are mainly focus like
  286. what is called dete detection detecting investigate investigating and you can think about like responding uh like any incidents for example like
  287. detecting uh fishing malware uh or deduct attacks. So let's say this team actually always like monitoring let's say oh okay this is that the sock
  288. analysis right they're always like monitoring is there something anything suspicious uh that could be happened there so how
  289. they monitor we already discussed like CM like monitoring system and it could be there's a lot of other tools out there for monitoring so this just for
  290. example it could be any monitoring tools CM is like in broader case it's called any other sec what is called monitoring tools integrated with this platform so
  291. it it will be centralized all this information so incident response team nothing but they're detecting as I said like oh is this any u fishing or malware
  292. or duct duct attack happening or not to make sure your um asset is secure asset means it could be a website it could be database as I said right or it could be
  293. your database server and epic application security here there's another team so they are focused on actually protecting the software and
  294. application so they don't care like here this team don't care about networking right and so because net they have a different team actually who actually
  295. normally doing their uh performing their responsibility but this team mainly focus but security actually what is called responsible for all we'll be
  296. actually discussing later slide. It's not like only like team responsibility to manage. It's your own responsibility
  297. to follow the horoscal standard in order to secure your asset. It's not your personality asset because if you're working for a company so your uh company
  298. asset you are the responsible person to protect your asset like no matter what's your responsibility will be discussed later uh in security culture there's
  299. this slide but here um we are talking about like main focus so application security that here this team they're protecting the software and application
  300. like let's say web apps APIs mobile apps uh from vulnerabilities because if they create a vulnerable software it's like uh it will be exposed for attack right
  301. so then to make sure actually their application whatever they developed is not actually exposed for any vulnerabilities so that's why it's like
  302. you know security engineer or software engineer or the architect security their responsibility how they can secure their application
  303. any question guys up to here. No question. We're in slide 15. Okay. Total 81. Uh, okay. So, let's move for
  304. the next slide here. Security and the security and the large organization. Okay. The security operation on is interact with the
  305. nonsecurity teams. It's saying that like security operation interact with the other nonsecurity teams means like regular employee with the organization
  306. right for example in organization marketing because marketing and communication team they are not actually directly responsible to manage any
  307. security right but we'll be discuss actually how the related later slide but it's saying that security team operation team will be interact or like
  308. collaborate with the other teams for example non technical or nonIT team like marketing team, communicative team to use their
  309. network accounts and IT what is and that IT and the networking manager. Okay, let me discuss more actually here. So if you think about
  310. like security operation must be collaborate with non um as I said like nonsecurity team and like those thing communication marketing you can think
  311. about like non technical team or it can be like HR or finance team right because all the department relay on the IT system the data and the network so
  312. like awareness is very important for everybody who is using those system Right? uh if I give you the example for example
  313. like if you're driving a car right so nowadays all this modern car actually like they're implementing self-driving right autopilot so you bought a car and
  314. you are driving and you say oh okay you know so this is autopilot or this is self-driving so Toyota or like Tesla they build this
  315. car and you don't care about care about accident but you should right because you should not You only relay like what is called with this technology. You
  316. should you should know how to properly use right. You should not be like uh start this system or autopilot and when to sleep right. You should know how to
  317. manage actually. So so this is nothing but talking about like here same thing same concept. So security team actually okay they're
  318. trying to like secure your environment or the system and you as employee should know how to use actually right so this is your responsibility
  319. so here you can think about like you know security security team because they are called interacting with this non other nontechnical team so security team
  320. you can think about they are enabler they are not roadblocker They don't want to block you but you might get blocked sometime. Let's say you are trying to
  321. actually upload there's a malicious software in your system security team will be block you in real time. So it doesn't mean they are blocking you to
  322. perform your job. They are nothing but try to trying to secure you you know. So they are not actually roadblock for you but they are just
  323. making sure whatever you are using you are actually secure your system is secure your secure and your information or your data is secure. So instead of
  324. just blocking security team security should security team should be helps the team work safely and effective effect effectively and most important like
  325. train the employee for secure security awareness. So if employee or let's say for example if you don't know how to drive if you
  326. don't have driver license and if you bought a car autopilot or self-driving car and you should not right because you don't know how to
  327. drive you don't have driver license you just bought a car and go to the freeway uh this is that doesn't make sense right so
  328. your responsibility as a driver you should actually know how to drive a Even if it is self-driving. So here same concept you can think about
  329. like security team right as I said they are interacting with the other team. So their responsibility also like you know train train the employee how to how we
  330. can actually use this system how we know this email actually fishing or not. So every organization LBC uh they normally what to say uh set a
  331. like let's say workshop or set a send the acade academy uh like video record let's say video or tutorial hey watch this to learn how to avoid like fishing
  332. attack or or how we can identify oh this is not a this is this is not a real email that for example so this is also security operation team responsibility
  333. to train the employee or train the user how they should use this system. So if employee don't know how to use the system that's the problem problem right
  334. so once actually using for example marketing team they are using compl company company computer so company requirements you should be use company
  335. network or you should be use BPN that's you are not in office you should be BPN but not you are not using let's say and in this case you should not be able to
  336. connect but let's say somehow you are able to connect with internet you are not using BPN. So, so in this case like you are exposed security risks. So
  337. that's actually you should know as employee how to actually manage security and security team as I said they are not roadblocker they are enabler. So they
  338. will be training or they will be infre how you can connect with the BPN. So every company you will be see once you join they'll be actually give you the
  339. guideline. Oh, this is the way you can actually connect with BPN or this is this is how actually you should be lock your computer or this is how you should
  340. be set up your password. That's how you should not be set 1 2 3 company you will be see your system will not allow you'll be the most of the website for example
  341. once you actually try to do like let's say 1 2 3 4 5 6 7 this kind of password it will be not taking this kind of password in this case you'll be see like
  342. system will tell you hey this password is not secure you use upper case lower case special character it will be guide you so sometime it can be guide but how
  343. to use the system kind of like it's called like uh I forget the term uh use case uh I forget actually the term what it's called but system will
  344. guide you guide you same thing like security team can be arranged what is called training and other things for security awareness
  345. any question guys up up to here and this you need actually in your real time in day-to-day activities
  346. so go going to the next slide actually what what other example You can think you know. So do you guys have any other example how we can secure? For example,
  347. if you think about this picture he's working looks like in the computer there is a copy and there is a note is reading something. So let's say if you are way
  348. out of your desk this case you can keep your copy here. That's fine. It's not you don't need to actually secure your copy. It's fine here. You can just
  349. simply keep here. But the note maybe let's say there is important data you should be lock your computer you should be keep your note in secure place and
  350. then go somewhere right do you have any other example guys think about like how you can secure it can be your system it can be your information
  351. it could be anything so if you don't have so if I go to the next slide you see there
  352. Security concern versus business concern. The most profitable decision is not always most secure profitable is saying that profitable
  353. decision. Profitable decision means like business decision. Business always think about profit. They don't care about like security. Security. Okay. Security.
  354. There's a security team. But business their main intention actually like profit. Then second focus other things. But their highest priority any business
  355. highest priority profit if if business is not profitable they don't need this business right they don't need to run this business so why don't don't they do
  356. care about other things so first actually is that's why it's saying that the most important profitable decision is not always more secure because first
  357. they're thinking about profit so security objective may be the or within the with with those business for example here I think this
  358. is security team manage goal like protect to the business data and so this is actually security team goals security team goals right not
  359. like profit primary goal ultimately like everything is related with profit any business right the we are talking about like primary goal business primary goal
  360. profit not security team primary goal secure your data not profit Secure your data first. So here like two
  361. things like security team their main goal protect your business and business main goal maximize the profit and improve efficiency.
  362. It's like basic things. So if you go so what so what should the security team do actually here? So if you go here you see that
  363. so an organizational engineering team propose innovation but insecure new. So here is saying that there's engineering team proposing innovative but insecure.
  364. So they propose something insecure feature uh for the flagship product. So here you can see security team would probably
  365. advise against a new feature due to the poor security that's actually there is innovation on new business. The security team said hey there is a poor security
  366. in the news new future but business might decide business to develop it anyway believing potential profit right because business always think about
  367. profit security teams here like what is called uh think about u security so security team viewpoints here like uh
  368. the the risks like it could be data leak with less security right it could be uh data data leakage or compliance issue or attack surface but lead business
  369. leadership viewpoint here like the growth revenue right even with some risks because they are thinking about the profit
  370. then sec so as a as let's say you are a security engineer right so what would you do in this scenario right any idea guys it's okay they are trying to
  371. implement or maybe new feature or business because it's profitable but you are seeing here there's a poor security but business want to implement
  372. so you as a security engineer what what's your responsibility what you supposed to be doing in this scenario any thought
  373. um so what I'm thinking probably we need to discuss with the business game and you know just uh minimal
  374. security at least like if like if we don't provide any security right >> so then we might lose our profit
  375. >> right right so yeah you are in right track so same thing I'm going to like you know uh I think giving the example for like you can actually clarify the
  376. business hey if there is no security uh It could be lose your data. You could it could be going forward in long term you'll be lose your trust customer trust
  377. is initially business might be profitable but if it is exposed for attack. Yeah. So you'll be and if you lose your data you'll be lose your
  378. customer >> and you'll be get a fine from regulatory right. >> Yes. So, so, so what you need to do as a
  379. security engineer like you should not be say like it's called like security team should not be like department of no you should not see everything is oh you
  380. cannot implement your responsibility here actually you should be guide the business so if you guide the business you are your thought then business can
  381. take a what is called a knowledgeable or in inform informative decision to balancing the innovation like profit security and risk tolerance right so
  382. based on your advice because you need to actually guide the business right so once you actually guide the business and hey this is this is the concern in this
  383. case they can actually balance try to balance okay oh okay okay I need actually implement security here might be I need to spend some money and then
  384. maybe okay I don't need to maybe security for let's say low priority as I discussed like low priority asset let's say medium priority higher priority so
  385. business might say okay low priority I can take risks but higher priority whatever is the customer data customer account whatever secured data I need
  386. actually what you call uh strong security policy or strong security security implementation
  387. any question guys up to here so okay we're okay so this is next slide related with this so what should do
  388. security team do like you know that's what our correction right >> uh uh I'm sorry if I'm just saying from the previous slide so security team
  389. should provide the proper guidance to the business >> what is can you repeat >> like I was saying like security team
  390. should provide proper guidance to the business >> right right >> not just saying oh you cannot do that
  391. >> right that's why yeah that's why I said like you know >> should be a balance >> right right you got so that's why uh we
  392. discussed earlier Security should not be say always no security should not be like blocker it should be enabler okay it should be help the business how they
  393. can enable this business you know you should be guide and uh what is called help them uh to make a informative decision. So related with same thing
  394. here like so the is telling like as a security team you should put a put in place more aggressive monitoring. So this is your advice could be hey you
  395. need actually monitoring system uh data server uh for the new feature and I advise the IT networking to put a uh put in place more sophisticated access
  396. control. So like this is that kind of like example we can actually as a security team we can say hey you need actually moni monitoring system uh
  397. because so like remember like you said uh like minimum at least like minimum security. So let's say okay because they can't afford maybe all these kind of
  398. things but they need to actually implement here you can say okay you can't implement this one but you need actually monitoring system if something
  399. happening you should you'll be get alert right away and you should be what is called put a strong security in the networking depending the scenario
  400. you know so I think we are clear here right pretty much so the Take away actually from here
  401. actually security team must be flexible you know and align with the business priority because if business is not profitable you will be lost your job
  402. definitely. So you need to actually business what is so profit is like this is important but all as as a security engineer you should be secure your
  403. business this is your higher priority but end of the day everything is profit right so there should be a balance so as I said like security team should be
  404. flexible and take a necessary action on discuss with the business and implement and trying to share with their thoughts so business can make a informative
  405. decision any question guys up to here I think we'll discuss a lot but if I go here
  406. like you know I say 100% security is not possible like not business goal like to limit spending and increase the profit business often provide only at quick
  407. protection remember we discussed actually at quick protection in the first slide what you need to protect how to prioritizing your protection
  408. based on your asset value. So this is nothing but equip protection. If if the asset value let's say company booklet so this is less priority you don't need to
  409. secure but the company customer data this is like higher priority you need strong security there so that's I say like like 100% security is not a
  410. business goal but what about the uh what is called you need to actually prioritize your security based on like adequate protection that's we learn
  411. actually earlier I think you guys are clear here right because we discussed a lot actually
  412. earlier uh regarding this 100% security do you need or not
  413. for if I refresh again like you know your gold diamond should be keep in your safe locker you can implement the camera uh lo jewelry like plastic things you
  414. don't need to actually in safeguard same thing for technical example like customer data it should be encrypted you should be implement monitor you should
  415. be implement multiffactor authentication biometric access for example and company as I said like uh company booklet you don't need like high security so the
  416. take actually here like you know security is about like risks based prioritization remember there's a risk team right they'll be prioritized is
  417. what is the risk and what is the high risk what is the less risks. So you need to make a decision based on your risk based prioritization
  418. to protect most important asset not everything. This is what actually is trying to tell. So if you go to next slide security
  419. versus business uh is the feature of this risk. This is like we already discussed business security versus business. Next slide. He's asking the
  420. question. So if you see about this slide here, security versus business in the future what this risks an organizational engineering team propose an innovative
  421. but insecure. We discussed it right similar concept feature for the flagship product. Okay. This organization perform a risk
  422. assessment. So remember like there is a new product and it was insecure that's we discussed last slide
  423. then you adise something you raise your concern to the business. So what business do once you raise your concern they perform a risk assessment
  424. right to calcul and concludes okay so whatever they're actually getting so risk assessment will
  425. be help you to identify like the balance or prioritizing the risks so here you see that the this is you can consider one side you see that in your this new
  426. feature let's so this let's think about this is balancer. So the one side is money right and other side is risks.
  427. So so in this new feature is saying that if you implement this new feature this new feature could be lived 25% profit
  428. but at the same time this feature would be risk exposing isolated uh like data server. So, oh okay this feature could could be
  429. also rigged as exposing an isolated data server say data service is data contact the customer um
  430. containing the customer okay names username and email address but no other PPI so it's saying that this server only contain uh customer name username email
  431. address but not other but not other PIP. PIP means personal identif identifiable information means like
  432. social security. You can think about your driver license. This this is called like PII sorry PII. So here they are actually performing
  433. what is called risk assessment the company to made a decision. So here advantage if you think about like business here once they actually
  434. performing this risk assessment and they find actually this uh this information here advantage is like after this risk assessment uh it's increase a quarter
  435. quarterly profit like business side like uh 20% revenue right and disadvantage it could be exposed the isolated data server is saying that it could be a risk
  436. right isolated data server with the c with that contains actually customer name, username, email address but it's not actually taking sensitive uh other
  437. sensitive information PII nothing but let's say social security so this is like what is called is user could be lose their username password and email
  438. address but is but what is called it's not actually this database not storing any other information but problem is like if user lose username and password
  439. uh what is called attacker can attack or what is called the other site or other database to steal this PIA information right so
  440. in this case it's like what is called we need to actually explain what ex could be happened actually in this scenario like what could be the impact and how we
  441. can actually mitigate for example like we discuss actually implementing like other monitoring system or maybe uh what is called uh multifactor authentication
  442. or access control. Remember like so are you guys what is called familiar with like what does it mean access control? We actually discussed in last next uh
  443. last slide remember here somewhere access control I said that. So are you guys familiar with access control? What does it mean?
  444. Like multiffactor authentication right is a >> no no access control is different multiffactor authentication like what is
  445. called secure your access but access control for example let's say you are a user right for example >> oh you mean let's say there admin
  446. >> right user >> yeah so like yeah this is called like access list privilege something in cyber security like things you don't need to
  447. access you should not be access let's say you should be access only like the thing you need. So you as a user you should not be get access to view the
  448. other uh what is called user data. >> Yes. >> You know so it depends. This is like so in this case is like we could implement
  449. what is called access control. So for example like uh updating something or let's say if you have a bank account
  450. uh so you you should be able only to read the data from the from from your bank side website or make any transaction but you should not be able
  451. to update any uh you should not be able to you can update your maybe transaction okay like there's a this is called like access control like if you are owner of
  452. this account maybe you can only read you can made a transaction or if you made any transaction you can made uh what is called update or edit this transaction.
  453. This is might be or cancel this transaction because you are the owner of this account but you should not be alter any other information outside of your
  454. account. So this is nothing but access control but if you are admin might be you are able to see other user information because you are admin and
  455. admin also should have like access control too for example like you know even you are admin you shouldn't be see user password so user password should be
  456. always encrypted so you'll be learn actually guys like what does it mean encryption decryption I think there is an uh there's a class for that so there
  457. is like what is called uh it's called like I think list privilege Uh so like yeah admin also should not be get like all this kind of access. For example, if
  458. you want to reset a password, admin should not be should not be able to share the direct password to you directly. They admin can send only the
  459. link hey reset your password but he should not know you what what is your password. System should be generate this password just for example. Okay. So we
  460. are moving actually different direction but anyway there is a different class I think but here if I go the next slide in this case the business objective of this
  461. achieving profit target override the risks of strategy. So what we discuss here like business targets actually they override trying to
  462. override the risks uh and they're uh uh what is called uh trying to achieve a profit right and we discuss also like you know how we can actually collaborate
  463. the business to make the profitable decision means like we are trying to hear actually what is called uh help business
  464. to run the business but not block the business but they need to secure their business. So in the next slide you see that here
  465. like pros and cons like security team objective to to secure the what it's called security team objective to the feature due due to the the like uh due
  466. to its insecure the here pros nothing but advantage the business decide that cost of this potential bridge of a isolated server
  467. Because there is a isolated server contains actually remember only username, password and uh email address not other information. So with no
  468. sensitive data so would be a less potential uh what is less potential profit of this feature. Okay. So here what he is trying
  469. to say like here business actually win right business actually like business like what does I mean like uh
  470. the business we're talking about like you know so business wins versus like security. So here this feature actually in secure like security this is security
  471. team objectives and business view actually the potential bridge is limited like isolated server no sensitive information in this server and profit
  472. potential is like higher than 20% 25% that's discussed. So here actually decision like you know business want to move forward accepting this li what is
  473. this kind of like limited risks but here like in this slide and uh next what what we actually learn what is what is the takeway this is this is the uh
  474. important things like security rules is like inform mitigate and the monitor not always like as I said like blocking and risk should be like qualified and
  475. manage. Even there is a it should be like what is for sorry quantified and managed and allowing the business to make informationative decision. That's
  476. what you can learn here. Any question guys up to this slide then we'll be move forward in different topics
  477. uh and this is important uh your day-to-day life. So here oh governance and comp okay after making this decision the business up
  478. business update is security practice to account for the risks it has undertaken okay and the regulatory confirm that everyone is
  479. following these rules. So it's nothing but actually talking about the governance and compliance. So they're making a decision right
  480. remember we discussed actually other governance and compliance making sure actually everybody following these rules.
  481. So we discussed a lot actually about this they're making a decision another team doing risk assessment and this team making sure everybody so you can think
  482. about this one governance think about okay US government if it is government organization like traffic department police department and the compliance
  483. let's the police they're making sure okay people are following traffic rules uh same thing in security like executive team could be implement meant people
  484. should be follow what is called scan their batch using strong password whatever and compliance team making sure okay you are using strong password once
  485. you enter the building you're using or scan your batch just for example so now we have activity actually here >> uh now I just send this activity in your
  486. slack live channel uh also I send this uh activity to uh um motion motion. >> So uh just 10 minutes everyone uh uh finishes activity. Do you have any
  487. question about activity? After activity we can discuss uh finally.
  488. So activity uh this is the uh chili ramin Abdullah can you share your screen? You finish the activity. Come here.
  489. Do you have any question before activity? Uh
  490. >> yeah, that will help you guys in your activities. If you have any doubt, you received this activity. Yeah, I got this activity. Okay, fine.
  491. >> Yes, having. >> Yeah, so far I understand that each company has a different department and different department has different roles
  492. and we as a security service how we should contribute to each department. That's the whole presentation was about
  493. how we play a role as our IT department. >> Uh basic based you understand question he his voice is was not clear
  494. but yeah >> can you hear me now? Yeah. Yeah. Yeah. >> Okay. So far I understand is that obviously every every company or a new
  495. company has a multiple department for whatever reason. So we as a as a cyber security the whole presentation was how we will play a role in those department
  496. and help them secure and make profit basically right. >> Yeah. Yeah. That's true. That's true actually. Yeah. And so in order to
  497. actually what is called implement or how to do their security like if you think about like today class for like GRC. So this is actually the framework actually
  498. will be guide you actually what you need to do and based on this framework or guideline right it's a structure and list of guidelines right you can
  499. implement or guide the business how to secure their um asset asset could be anything you know so yeah so >> do we have to remember anything or this
  500. whole thing >> no I mean like you know in security or any like or anything. So I don't suggest anything like memorize or
  501. remember. You just need to understand the concept. >> Yeah. >> Once you understand the concept, yeah, I
  502. think that's enough, right? So if you if you read something and if you can understand, that's enough. But yeah, you don't need to memorize everything. Just
  503. understand the concept. >> Sure.
  504. >> Yeah. Can you share your screen and then you start this uh just um activity >> and 10 minutes you finish this activity.
  505. Okay. And then we'll back again. Okay. I made to five minute break.
  506. Okay. [Music]
  507. [Music] [Music]
  508. What's up? Start. Okay. We are still in activity.
  509. Keep screenable [Music] ball.
  510. You would learn right mostly security recommendation.
  511. Oh secret. Okay. The security recommendation. So the director of the security suggested the implementing corporate BPN
  512. >> by the gateway. Okay. So every and then every time someone try to access uh to the internal component BPN test request should determine the coming from the
  513. employee. is coming from the employee. Okay. If it is requested is approve. Okay. Since the company has a growth in 300 employees, the uh director argues
  514. that increase the critical and ensure the confidential information remain the hidden. The BPN project would be okay. Disadvantage
  515. network. The director of the engineer suggested record all developer should uh use the secure shell. Okay. Uh Yeah.
  516. Right. [Music]
  517. What is the lead? Okay. What is the lead to the approval of the reduced risks to improve? So improvement
  518. right group outside of class. I mean,
  519. sorry [Music] Linux
  520. connect. So IP address so that uh nobody else can crack because
  521. IP. So um is it something similar uh to that?
  522. >> Could you Okay, he lost actually first first couple lines sentence. Can you repeat by again?
  523. Linux class IP password.
  524. Password. >> Right. Right. It depends on like scenario. Right. if it is server. Yeah,
  525. makes sense. Okay.
  526. record developer too. Okay. So I think Okay.
  527. Right. [Music]
  528. Right. Right. Right. Mhm. First
  529. server. Oh, first line. uh
  530. okay in this activity we will be play role security conc instruction okay whether it's lit okay what >> and have a cast
  531. key item also there work should be take to implement the business plan okay first line the business wants to actually give the all the developer to
  532. access the data uh this is request was made by the director of engineer they suggested that The free access would help
  533. >> yeah team to move for uh faster and then help manage >> uh cut of cost and depending okay the dire make administrative server
  534. accessible from the public IP address and injected the corporate subet okay topically corporate or company network
  535. are not publicly accessible network
  536. access without other authentication because you already get the network access. Uh, so
  537. the director of the IT argues that allowing anyone access the machine of this company network with help their administrator
  538. May of home work remotely to connect to the server and need to manage. Okay, they exactly the features improve retention and hope to gain the
  539. increase in the number of the house and employees. Your new sock analysis want to merge all the email address. Okay, blah blah. This is a lot of information.
  540. So director of engineering like here suggested all the developers
  541. should access all the data advantage they can easily access but disadvantage uh allow all developer to access the
  542. user data including sensitive personal information uh what is called uh that has nothing to do with their job right the developer
  543. should not be like act like They can develop the product but they should not be actually access use of public personal information.
  544. Other disadvantage to number two business should reject uh reject and reject on ground of the privacy. Okay. The director of IT suggested explos.
  545. So another concern the director of IT suggested the act what is called exposing administration server to the public public. So
  546. administrative can work actually from any computer but problem the server would not be publicly accessible uh which is uh like inacceptable if server
  547. would publicly access inacceptable of the private network because this is security rex. So we could recommend here actually the organizer should or the
  548. organization should reject this request and a BPN should be better solution. So there then like in this case we should be actually guide to use actually they
  549. should be used actually BPN. So I have actually this answer it's a long but you guys can actually this like
  550. here you guys get maybe same answer right? Yeah. So looks like you guys also got this answer right. So I guess I think
  551. you guys actually read actually like this can take actually like line by line but looks like you need to actually what is called recommend actually what
  552. business supposed to be do. You got my point guys. >> I mean there's no right or wrong answer.
  553. Just >> no there's no true right or wrong answer. So this is like the concept. It's not like oh like a yes or no. It's
  554. like a statement. That's true. There's no no right and wrong. So we can move actually the other what you call you guys can try to actually do like know
  555. group study know so if you actually what you call read lines 10 minutes I feel like not not enough that's happened without time too like you need actually
  556. more time uh to do your like research but this is nothing but actually whatever actually we did like or we actually learned today so from this
  557. actually our knowledge we can actually made the decision here what we supposed to be do you know what you supposed to be recommen
  558. And I see that you guys already get this answer here. The solution recommendation right
  559. secure recommendation. So same thing actually we already shared with you. This is the answer you already shared whatever I'm seeing in your screen.
  560. So let me share my screen actually you guys can read you guys already get this answer looks like. >> Okay. So if if you have any question
  561. then you guys can you know reach either we cannot you know it's almost 1 hour left it looks like let me start next slide uh let me share my screen
  562. uh are you guys able to see my uh slide activity slide right anybody can confirm
  563. no >> yes we can see Yes. >> Oh, okay. Okay. Perfect. So, this is what actually you guys just actually
  564. doing. So, next slide. Let's see. Uh action. Okay. So, we security culture. This is important. So, we'll be discuss actually more here in security culture.
  565. Uh so, let's move on next slides. So here you see that the security culture strong organization securely be uh begins with the making
  566. secure employee make sure employee is both both means is considered this and this. So here considering
  567. consider security important and understand security implication of their decision.
  568. So in this slide right you know the security culture it means like every employee
  569. uh treat like should be treat like as as I discussed earlier also like security should be their part of daily day-to-day activities day-to-day job they every
  570. employee they are responsible to manage uh or follow the company rules and regulation in order to maintain the security for example like if company
  571. trained you hey this this is the how we can actually recognize is this is this fishing email or not. So you already learn from company or from the security
  572. team but you don't care uh you just click actually blindly any link or replied any link right so that means you are not maintaining security culture
  573. whatever company teach you or guide you right you should be or whatever GRC define the rules and regulation you should be follow right
  574. so you you should not be think about oh security is not my concern security only like security team concern here we are talking about the culture.
  575. So culture is here if you learn as I said like giving the previous example if you know how to drive
  576. a car and you are using self-driving car and you are seeing the self-driving car or autopilot going to hit the other car you should
  577. not be like be quiet you should be you should not be say okay it is autopilot I don't care if it is heat on other car okay uh hit you should not be do that
  578. right You should be take a control right away if it is going to happen. Right? Same thing exactly same thing here security culture. If you know if you
  579. observe any suspicious activities for example like let's say imagine like you are a employee and you are so you
  580. have access in your building and you access in your building and you observe there is a suspicious visitors in your building inside the building. So
  581. it should be report right in the security whoever the concern person person you should not be actually ignored like so you should not be just
  582. rely on like security guard like you can think about oh this is if suspicious activity is not my responsibility security guard should be taken care so
  583. this is this means you are not maintaining security culture if you see something you should be raise your voice you should be informed so this is what
  584. like security culture culture. So everyone should be know they are actually affecting like like you should be feel safe right in your office. So in
  585. in order to feel safe in your office for you or for your colleagues you should actually help to the
  586. concerning person by informing them hey there is a security risks right uh so like strong like strong security is not like just about like tools and policy so
  587. we talking about the culture so like you should not be only relying on like tools and policy you should not be relying on like How do you call only like
  588. self-driving car? Oh, okay. This car actually what is called there is a technology should be drive uh you should be able to do self drive. So you you
  589. should not be go to for sleep while you is driving in freeway right you should you should be monitored. So this is your job. Uh even like there is a what is
  590. called self-driving technology. So uh it is about like the culture nothing but it's talking about like employee behavior how you will behave like you
  591. know so you and and your behavior should be based on the company GRC policy you know and sometime you should be use your common sense so consider like uh
  592. security like like what is called understanding the Security uh implification
  593. like know how their action and how it can be like impact you know. So if you actually observe something you should be understand if it
  594. is happen what should be impact if you click any suspicious link for example like you get a link and you know this looks like this is a suspicious link
  595. right and you should not be click but if you click you should be know like what could be happen you could be los you lose your data and attacker can uh
  596. actually attack the company or the your system right so this is culture nothing But people behavior how should we behave based on like uh in in it you can think
  597. about like GRC policy whatever we discussed earlier any question guys here so same thing like for example like your company
  598. always guide you should be use strong password but you don't care you always use actually weak password so you are not fit with the security culture in
  599. your company Right? Your company suggest you to verify the resource of the email and you are not doing actually. Let's say you get a email and you just blindly
  600. reply. You don't actually double check is this email came from authentic source or not. And this is your job, right? This is your job to verify is this email
  601. is authentic or not before you actually replied or click, right? And your company let's say uh say every company they
  602. how it's called they make a rule you should not be share your credential or you should not be download any unverified software but it does actually
  603. let's say you share your password with your other colleagues or you actually download there's a malicious software in your system so you are breaking actually
  604. company DRC policy that means you're breaking the security culture you know so in Next slide. Okay. Here you see security. This is definition
  605. actually. Security culture is the way to member of the organization. Think about approach of security. A healthy security culture. Healthy security culture. Think
  606. about has the employee who are the invest in this organization security and behave securely. So healthy secure culture means you are
  607. maintaining your security you know if you don't maintaining your GRC policy that means your uh what is called environment will not be healthy security
  608. culture right so this is nothing but actually give you the what is called like theory any question up to here then this is very important in real time
  609. security culture so here security culture actually is think discussable like two different things three different things. So how important
  610. employee consider how important employee consider security like is this like important in uh employee should consider the security before they're doing
  611. anything. Second question like you know terms like how aware like is this employee aware of this risk let's say are you aware you if
  612. you are click on a malicious link what could be happened right so it's talking about awareness this I'm talking about important
  613. if you don't consider security what could be happen so so considering the security risk how important it This and the understanding the common
  614. security are you aware of this right and then this this one actually like whether employee know how to actually avoid insecure behavior how you could avoid
  615. like how you should so you should be know it's should be know how you know like as I said like you know your you as a let's say security security team or
  616. security engineer you should be guide your employee how they actually identify and avoid security behavior. Security behavior is not always like
  617. related with like tools and technology as I said right if it is tools and technology you should be guided how to they use their tools and technology you
  618. know and other things something not related with like what is called always tools and technology it's like behavior how it should be actually behave so this
  619. is actually like so here three important things guys like important to considering the security and the awareness like understanding ing the
  620. security risks and here like behavior saying that like behav your behavior is very important. So here like in this slide what you
  621. learn actually security culture just not a policy it is not a polic that's not a policy right it's a how employee behave and think about security every day this
  622. could be your not only like you think about your personal life right you know like if someone actually call you and asking your personal data you should not
  623. be just blindly given to them right you should be verify oh is this like authentic source like the call you received from Right. So same thing like
  624. same behavior you should be think like your for example like your company all this asset it is you should be think about it is your asset and you you are
  625. the responsible person to protect your company asset and you should be you should be follow this security culture nothing but the their rules and
  626. regulation. So the here important things is like do the employee take security seriously or not right
  627. this is the very important and you should and awareness as I said here like do the employee know the common issue like fishing email social engineering
  628. malware attack and the behavior third one I'm repeating again do the employee know how to act securely to avoid the risks so you should know how to behave
  629. right to avoid the security risks. So if I give you the like what is called nontechnical example here right so let's
  630. say employee always lock the door right so if you always lock the door and if you don't share with your ID with the other colleagues
  631. or others or if you report suspicious visitors as long as you see something so then what is called you are actually actually following the security culture
  632. So technical example if I can repeat again like employee should like here employee should know like how to recognize the
  633. fishing email and they always should be used like for example like strong password like how they should be behave for example okay using strong password
  634. and don't install uh any unverified software and don't break the DRC policy See nothing but your this is what like security culture you can think about.
  635. So next slide healthy security culture required a what is called moving employee to value sec value security and the training
  636. train them on how to avoid the security behavior right so you as a security engineer should actually train your employee actually how should be they
  637. behave that's what we discuss actually any question guys up to here in security culture I think we discuss a
  638. So if not actually here the security culture framework framework steps right so init so in so in this case like it's talking about there's a five steps for
  639. the security culture like measure the goals and then innovate the right people involve the right people create a action plan execute and plan and measure
  640. measure the change so we'll be learn actually all five steps in the Next slide.
  641. So here's the definition of security culture. Actually I the problems in the organization organization secure culture and then de
  642. and develop a plan to solve them. Okay. So let me actually go to the next slide to in order to understand actually all these five steps. Um applying this
  643. framework. Okay. So this framework is talking about this framework nothing but these five steps. So employees receiving an email to their
  644. work account from the external source. Uh employer clicking and downloading the attach email. Okay, we discussed actually all these things. The
  645. organization secure security team determine them meal determine that many of these link and attachment contests malware. So we'll be
  646. discussing in we already discussed these things but we'll discuss more actually in order to get this clear. So let's move forward actually the first one
  647. here. So this is nothing but so you see the 1 2 3 4 five. So we will be going to one by one one two here you see that all these five. So this is
  648. first number one security management like so how we actually measure the goals. So here like you know high penetration testing this is what is
  649. called the example for one approach there is could be a multiple approach. So here we are taking example whatever in this slide. So it's saying that like
  650. hiring a penetration testing firm beginning a fishing campaign like fishing mail campaign that will send fishing email. It will be sent fishing
  651. mail like intentionally to the user of this company and this farm will be keep track like tra the track the user how many user actually following this
  652. fishing because they want to measure actually you know like employee behavior is this employee fit with security culture or
  653. not. So they make a plan actually here this third party penetration testing team to send an email to every employee and verify how many user
  654. click this link means like fall in this fishing email nothing but you are clicked you clicked you did clicked so the one way first first step to is the
  655. measuring and get the goals because if you if you don't know your measurement you can't set a goal right that's Oh, like everybody actually following what
  656. is called this rules and so rules like there is a no like what is called uh like everybody's aware of that. So in this case like looks like everybody
  657. knows actually what to do but let's say you're on the other side of this coin let's say nobody really knows how to recognize the fishing
  658. email. So based on actually let's say 100% like success or 100% fail you can set here your goal right. So measurement a goal let's say here they set a goal
  659. like click let's set a click rate like click rate means like penetration testing firm will be sent a fishing email right to every user so once they
  660. set a fishing email every user is saying that they set a goal 5% 5% user could be like click this link measure this data to determine
  661. what percentage of employee victim of this fishing And who employee employees specifically? So if they send actually this email to
  662. the every employee they'll be identified like their goal actually 5%. You know but they want to actually identify how many person actually click this link
  663. like victim and who is actually click this click thing. So why they need that actually? So this will be help you like how many person
  664. click this link they will be get an idea like how many percentage of um uh employee from this company actually don't know you know this kind of like
  665. fishing attack and once they actually identify who actually click this link let's say there's a 5% and they knows this
  666. employee they can train this employee because they don't know right so the first one actually they're actually collecting the metrics and next slide
  667. here involve the right people to the so inform the at let's say CEO and CIO actually and HR and the what is called the person and the person in charge of
  668. this internal training and communication because you cannot actually send like fishing email for training purpose something without like informing let's
  669. say GRC you should be informed the GRC team hey we are going to do that or so or you should be in informed the like GRC means like remember like governance
  670. Governance is involved by high top management right CIO H so other other so you should be informed also like the top management like executive team you
  671. should say hey we are going to perform this kind of operation who is performing like third party penetration testing so the second one they set up a goal and
  672. then they inform the company or DSC team and then second one create action plan this one so develop a training cover danger of this malware and how malware
  673. can spread through the fishing and fishing. So fishing and fishing to cyber security term. So once actually what is called
  674. get this measurement and then they inform and then after that they create action plan. Once they on they get this matrix what they do
  675. with this matrix right. So the matrix what we supposed to be do and the fourth one like execution plan. So once they create a okay what they do and
  676. then they need to execute right. So execute means their action plan they need to execute. So here then they implement the training with the goal of
  677. like 20% employee of each quarter. This quarter 20% next quarter 20% next quarter 20% in one year 100% team members should be trained up. So that's
  678. their goal. They set up a goal. They inform then create action plan and then they take action like execution. And then last you see then the last
  679. steps here uh measure the change. So determine success or failure. So initially their target was 5% let's say and here you see the step one they are
  680. actually measuring again against this matrix. So in this like uh this is uh what is called security culture framework right?
  681. So we are talking about security culture framework. These are five first five steps. The first step measuring the goal and identify the goal. Then informed and
  682. create an action plan. Then execute the action and then the compare the result. Compare the result between this and this to determine is this pass or fail.
  683. Right? So this is like selfexplanatory. We don't need to like how actually you can make a plan. Right? It could be like this kind of what it's called framework
  684. you can build for anything right how we can actually proceed. Uh so there is activity for 15 minutes and then I think break
  685. for security culture is here. Any question guys to wait for tamay. Uh if you guys have any question.
  686. So security culture. >> So security culture by whatever understood basically means as we as employee how we should follow
  687. them. You should it's like you should not be think about like oh my technology will
  688. be protecting me. You should not be thinking about my car technology will be protect me from accident. Right? The cultur is here like you should be you
  689. should be help your technology. you should be support your technology or you should be support the GRC team in order to implement or in order to what is
  690. called uh achieve your goal or company like what is whatever the uh what is called objectives like if you don't care like you just actually say okay this is
  691. not my responsibility this is security guard responsibility that means you are not culturally fit so you should be follow the security culture and think
  692. about like securityities everybody responsibility. So you if you don't know how to actually fix or solve this issue but you can report and you can actually
  693. what is called uh try to save your system for example like you know you should not be what is called open your door let's say you set
  694. up a security camera in your home so you should not be unlock your door and say okay my camera is there I don't care let's keep open my door for for like
  695. 24/7 and you should not be do that right even you have a technology. >> So same thing here like similar concept like security culture. So you should be
  696. follow company rules and regulation. You should be apply your common sense and you you should try to protect your asset. This
  697. is not your company asset. >> So Tanbe already shared this activity. Uh Tamri,
  698. >> I want to drop my wife in my brother-in-law house. >> No problem. Okay, I'm just uh continue. Okay, thank you.
  699. >> Yeah, so I'll be back actually after 30 minutes. So they have activities and then after that I see that they have a 15 minutes break, you know.
  700. >> Okay, >> so I once I back I'll be rejoin. >> Okay, thank you. >> Yeah. Yeah. Thank you. Thank you guys.
  701. See you then again soon. Uh so uh who uh continues this uh activity? So char uh please uh proceed
  702. on your uh share share your screen and [Music]
  703. [Music] [Music]
  704. Please share your screen. Okay.
  705. That was back. Wait.
  706. resolution. I see
  707. [Music] I can in this exercise you will play the role of a security consultant who's been
  708. contracted to help a local bank develop a plan to address a physical security issue that recently resulted in the breach of its financial data servers.
  709. Uh refer to this memo from the executive team. So I think I think uh whatever we have uh unders understood from here uh there
  710. was a culture that uh while entering the building uh there was a culture that um to help uh the next uh individual or the next next colleague
  711. they used to punch their card and allow him to get inside of the building. So this is this was a security breach and um as there are 500 employees. So if
  712. everybody uh follow this culture helping another person uh without scanning scanning his batch uh so uh maybe um outsider uh is getting inside the
  713. building and um making a security breach. So um we can uh uh for mitigating this issue um the culture can be like nobody is
  714. allowed to uh scans in favor of another person. So every individual should scan their own badge and get inside the building. So um the security should be
  715. ensuring that uh every individual is scanning their badge and getting inside. Nobody's allowed to uh get inside without scanning their badge. So that
  716. can be one uh major uh security uh risks uh to comply. Did you get me?
  717. Hello Second option describe a method for finding out
  718. how many people encourage tailgating and keeping track of those who do. Um extra security
  719. guards individually
  720. instruction. Right.
  721. [Music] Oh, hi guys. Oh, yeah. My son is sleeping actually. So, I'm going to drop
  722. them after 30 minutes. Please here. No.
  723. Uh we are doing the activities right now but but we all here >> yeah I'm saying actually uh
  724. so how far you are guys the activity this activity port we'll release the conible all
  725. local bank developer about the plan address and physical security that recently is called in the branch and the
  726. financial data server take a scenario. Yeah, there's a scenario actually it's explaining the
  727. employee has been observe the door of the others behind when accessing a building and without each employee scanning there. So looks like like you
  728. know employee actually here uh how it's called helping or like giving the privilege to each other accessing the building without uh what is called badge
  729. right so you need to actually in order to prevent you need to actually create action plan and how to actually I think prevent this one
  730. >> yeah so um the instructions is uh something like that we have to uh identify or uh plan three uh potential solutions
  731. >> for this problem. So um uh one of the u solution can be that um while accessing the building everybody uh it will be ensured that everybody is scanning their
  732. own batch. Nobody is uh scanning their uh helping another person to get inside the building. So if anybody is entering the building, he has to scan his patch
  733. and >> Right. Right. >> And uh there should be a system that u anybody uh anybody is not scanning going
  734. inside the building there will be alarm system that hey uh this person is getting inside. >> Oh yeah, I think this is wonderful you
  735. know the alarm system like monitoring something like oh this this person actually not maintaining. So you can actually later take an action or train
  736. him actually. Oh, you should be scanned like this, you know. >> Or biometric like a fingerprint. >> Right. Right. Right. So I think you guys
  737. are got got it. Yeah. Yeah. There's no 100% right or wrong answer. Right. There could be like different solution. But whatever you guys are bringing I like
  738. that and the answer of it maybe like whatever the recommended answer like if there will be shared along with the other if
  739. there are any other alternative option too. So let me share my screen and then come do you guys need break or I think the class will be over within 30 minutes
  740. if I continue now. What do you think? >> Then probably we don't need break. >> Yeah just
  741. okay. Okay. Okay. So, let me share my screen again. >> Okay. >> Yeah, sure.
  742. >> Okay. So, let me share. Are you guys able to see my screen here? >> Okay. So, we we discuss about like security culture, right? And that's what
  743. we actually discussing here and we need to actually like you know like encourage like uh what is called whatever the activity is like the employee let's say
  744. there is a a training or why they need to actually scan their badge is there for their own security like you know protecting their uh asset like train up
  745. for awareness there could be another action plan but let's move forward actually uh what is called next topic security culture framework action plan
  746. okay so action plan Whatever you are going doing here the activities there is a next topics looks like related with this employee receiving an email uh to
  747. their work uh account from external resource okay and then employee are clicking the link and download the attaching email recognize okay this is
  748. like previously we discussed actually like back to the security scenario so let's go through the okay contest again and coordinate with each other team
  749. member of so the first steps here actually security culture framework steps Uh
  750. so the security culture that's what we discussed actually earlier he miss X how X access assess their impact to the fishing email incidents in the rigs and
  751. post and post by the future campaign. Okay and then here there's a three terms in this inclusion. Okay, the assessment like
  752. assess assessment remember there is a five steps first steps of assessment right. So here assessment of the demand done by the previous fishing incidents
  753. because they send out a intentionally malicious email remember and then then they're doing assessment and then then using a pen what is called penetration
  754. fishing attack to show how many employee actually download malicious file like I say like 10% click this rate meaning 10% employee download malicious link like
  755. they send intentionally the malicious link and to make sure actually identify the metrics how many person actually click this link and then they what is
  756. called targeted they're setting a target click through rate the team might be decided that five okay 5% click through the rate acceptable okay so that's what
  757. we actually discuss first actually ident what is called uh fishing like intentionally doing fishing incidents and then identify how many person
  758. actually this click this link and then what you can do maybe you can actually train them this actually whatever click this link so if I go to actually here
  759. the steps next steps what they're doing once they get actually this metrics is CF team member uh in this case actually HR manager meet with this like
  760. you know here security information I forget this term like um executive to explain the the previous fishing attack like whatever they get metric they
  761. explain issing attacks was successful because of 8% employee downloaded unknown
  762. like file from unknown email address. So they identify okay they successful if nobody actually click this ident what is called fishing email. So that means okay
  763. they're not successful in this what is proxy uh attack right because it was proxy attack right remember intentionally so they said actually 10%
  764. employee actually click this link so that's actually they discuss with their executive and they request for a budget they said hey we request for budget
  765. carrier to plan to bring like 5% down the because they require for budget for what I think is for actually train the employee to down rate from 10% to 15%.
  766. So they they actually discuss or maybe let's say you as a security team member discuss with the top management team hey we need actually train to the employee
  767. so we can actually reduce 50% attack for example right and then here the next steps actually like what is taking action like here security culture same
  768. framework we are talking about and then CFO team member develop a training plan because if budget is approved they develop a training plan and for security
  769. awareness you know and this will be only delivered to the employee who click this malicious link after this training. So they what is called they make
  770. actually plan here you see that right how they do actually they actually send to the employee to the uh training and then also this plan will be only be
  771. delivered the employee who continue click this militia link after this training that's what we discussed actually
  772. already but here how they actually proceed like next steps it will be clear these steps you'll be get here so after developing this training plan Talking
  773. about this training plan we discuss in next this slide and next slide our last slide. After develop this training plan actually team decided intensive and
  774. disintensive like this will be awarded based on how many employee actually u what is called behave during
  775. penetration test security audit. Okay. So it's nothing but still telling you like after this security training how many employee actually fall in this
  776. track to click this link like the link actually they sh here to get this uh the metrics. So
  777. they actually decide a business plan they'll be give the intensive like $50.50 50 gift card or free discount if they don't actually if if they don't
  778. click actually nothing but it's saying that here uh discontinu security like conference attendance and the additional
  779. time okay or discontinuous security conference attend discounted security conference attend
  780. okay and then uh disintensive supplemented security So here actually uh they they'll be give you actually
  781. what is called $50 gift card or discounts like whoever actually see conference attendance whoever actually attended this training
  782. and the additional vacation time. Okay. So it's like a intensive like $50 gift card or vacation on time or something like PTO to encourage the employee right
  783. you know intensive nothing but encourage the employee to follow this actually security culture but if you don't follow if you are
  784. failed if you are failed they said this disintensive means they'll be send you he say there is supplement security awareness training they'll be send you
  785. again for training say you you are not able to follow this culture go for again training that's what is happening all the time real time so let's say there
  786. actually standard training something and after training there will be a quiz if you win the quiz okay you are done if you if you are failed in this quiz like
  787. whatever you learn there's a there will be say okay go for again for another training you know supplement additional training here there'll be supplement so
  788. for example like once I actually get my first time like what is traffic ticket. So they give me a full give me a ticket uh for uh whatever
  789. reason you know and the and I failed because of um E in E sign actually I failed to stop and I get a ticket and they say hey you you need to go for uh
  790. DI school uh driving school for training in order to remove your points. Same thing similar thing exactly happen like if you employee like you you get a you
  791. get a training and after training actually you still clicking actually you know uh the malicious link so you so in this case you'll be get a this this
  792. intensive for clicking link like you should be go for training like this is like business plan like you know if someone actually passed okay give them
  793. gift card or something if failed send for send them again for training So security first step uh here. So here like during this meeting actually HR
  794. explained the most reliable way to secure 100% attendance. They're trying to compare 100% over the next sale year and training 20% of this employee of
  795. each time. So let's what they're trying to do actually like you know the next year they're trying to four quarter right each year. So they
  796. were planning to do like 100% employees should be trainer and each is quarter 20%. It's talking about like you know how
  797. they actually approach uh to address this issue and then here collaborate with the communication developer to contain the
  798. information of the training. Then to collaborate with the communication developer to distribute information about the training. Okay the training
  799. information like catalog distribution training. And then step seven actually set up a implement training schedule. So there they're m okay like distributing
  800. the the training module and then schedule a training and security culture steps the same. Okay. So in this steps actually after this training actually
  801. every quarter like SEF actually team contracted same penetration testing firm to verify their metrics again you know because all employees already trained up
  802. let's say 100%. But they want to make sure actually is this like everybody following what is called now aware of this all the security culture or not. So
  803. they actually conducting again same kind of penetration testing like proxy email and second one actually after every test actually
  804. S SCF actually team is identify employee who is actually click this link again they're trying to identify and supplemental security awareness that's
  805. we discuss actually if they fall or if they click actually even after training they will be supplement additional security awareness training you know
  806. this is nothing but business plan how they actually mitigate or how they actually what is called taken action to train up or uh their employee so they
  807. so that they can fit with the culture. uh this is like business plan culture steps of this training the fishing email that's what we discuss
  808. actually like after this campaign they'll be run a fishing email campaign again to evaluate over all the training and this time actually they find let's
  809. say 5% lower compared to other this business plan so what the action plan here uh what is the action plan okay so when
  810. when when will be the plan will executed when you'll be measure the progress and how you will be quantify the progress I'm not reading I'm just explaining here
  811. when will be plan will be executed right uh so plan will be executed once 100% employee pinned up right remember that set a goal 20% each quarter so end of
  812. this year 100%. So if it 100% plan is done like plan is executed not done like executed and then after executed like all 100% trained then you need to
  813. measurement right so they'll be in order to measure actually they are doing again fishing campaign to make sure okay they learn actually from this training or not
  814. and then once they get actually run this fishing campaign again they can measure actually their success rate is this reduced like 10% % to 5% or not. Right?
  815. So this they looks like if it is 5% looks like they're not 100% success but they are 50% success right 5%. It's like action plan. Um so this activity will be
  816. do later maybe. Let me finish and then this similar will by there's almost done. So we'll be back in 59. >> Okay. Later
  817. >> um I can share this uh activity. Okay. Can I proceed maybe with this or wait for activities done by what you can share?
  818. >> Let me pro I I have a class actually 12 or 2:30 either side. >> Oh okay. So you proceed. >> Okay. So yeah then we can do maybe
  819. activity later. So security control I think next uh yeah this is very important security controls. What is mean by security control? Uh okay give
  820. me one second guys. Let me uh message my teacher. Maybe 5 minutes late. 10 minutes.
  821. Okay. So security control here in addition to improving the security culture over the long term the security team should be enfor security controls
  822. you know in so what does it mean security controls we'll be learn actually next slide a security control this is the definition security uh
  823. control is control is any system process or technology that protect confidentially integrity and availability remember we discussed
  824. actually CIA CIA CIA using like CI CIA tried is called the terms confidentiality, integrity and availability.
  825. So we'll learn actually in next steps more. So here security controls types but before that if I actually high level overview maybe there's a different class
  826. for uh confidential integrity and availability confidentiality mean like what is it called uh secure like let's say like confidential data always uh
  827. should be like um maintain a like let's say strong secret let's say like you should not be access any other person personal uh information. The data should
  828. be confidential your data or other person data. Integrity nothing but data should not be altered or changed you know whatever data and availability
  829. means like data should be available for the user when they need you know so this is like but we'll learn actually later in details but here this controls
  830. actually or is like is discussable three type of controls one is administrative tactical and uh physical. So you see that here like required
  831. employee to follow their training guidelines. It's like administrative action like management tactical like technical
  832. example required developer to use secure shell just for example or required developer to implement uh multiffactor authentication you know like technical
  833. side and physical like protecting building by accessing like this is a key card or other person like you know remember or fingerprint right like
  834. physical access so so in this slide actually nothing but what is called referring like remember like previous is called like CIA right confidential
  835. integrity and availability so it means actually any system process or technology like know must be pro protects confidential integrity and
  836. availability of a resource or of a or for a asset the purpose actually reduce the risks and protect asset from the thread that's the
  837. main intention right the safier um asset from the thread or attacker. So here like you know this is the like administrative. So administrative
  838. controls like what administrative they do does actually like they set up like procedures policies uh training the guide the people that's their
  839. responsibility right set up a policy training and the guide the people like for example employee must complete cyber security awareness training before What
  840. is called accessing company system if if you don't know how to use system you should not be access this what is called uh system so you should be learn that's
  841. what like there will like uh like security awareness for example like if you don't know how to drive you should not be go what is called sitting in the
  842. driver's seat you should be know how to drive and then sit on the driver's seat technical things like here so this is technical solution must be
  843. like a developer must be like as I said like you know what is called impress secure shell password to ensuring the secure authentication
  844. right and same thing like easy example here we already discussed so in this slide the security controls can have different goals like why you need
  845. security controls so previous topics was security culture we are now talking about security controls and security controls nothing but there there is The
  846. three core things we already pointing out like CIA remember guys very important confidentiality integrity and availability right so here the first one
  847. actually preventive controls so it's like differentiate the what is called define five different controls one is preventive another is uh the trends and
  848. then uh detective and then corrective and then compens compensation controls. Okay. So
  849. what does it mean here like prevent preventive action right? This is the access to the techn. So like for example see here prevent action access with
  850. physical or tactical barriers uh like access using key card for example like uh preventive action means like you should be stop incident before it's
  851. happened right like this is preventive like you are taking action before it's happened. So for example like kicker accept
  852. prevent unauthorized access. So you are actually taking an action before it happen and then detent control here like discourage this
  853. is mean like discourage the attacker for attempting to access the resource for example like how we can discourage attacker right and how we can encourage
  854. attacker to attack so here is talking like discourage attacker like let's say you you set up a security camera Right. So and once someone like for example
  855. home camera home security camera of once someone actually appear in this camera say hey you are under in camera or something like this. So if it is threat
  856. like attacker someone like they say oh my god is camera is on. So it will be discourage the attacker right hey okay he don't want to attack because he knows
  857. there is a monitoring going on. So if you don't have any monitoring in your system right so attacker there is no monitoring he'll be encouraged to attack
  858. if you don't have any like what is called like strong security policy like let's let's say your door is open so attacker can actually enter your room
  859. and steal like your valuable stuffs because you you encouraging the attack okay come come to my home and uh steal my stuffs so you should be discouraged
  860. how you can discourage you should be close your door right same thing you should be in cyber Security should be implement strong security. You should be
  861. implement uh monitoring policy that will be actually discourage attacker to attack because attacker is not like always what is
  862. called if attacker knows okay this company always maintaining what is called strong strong security policy let's say like casparoxy or
  863. whatever like the they're working for security right the security company so attack okay security component they are expert on this right so they are not
  864. trying to actually attack security because let's say there's other what is Mid-level company there are grown and they don't have like maintain any
  865. security policy because there's a lot of things actually how you can they can determine they maintain strong security or not you guys can learn in practical
  866. uh class like or how attacker actually uh run a let's say n map or zen map to ident identify the loopholes or identify the open port so they can attack so they
  867. knows actually how to identify the vulnerabilities if attacker Don't find any vulnerabilities, it will be discouraged
  868. attacker to attack this system, right? Because he can't find any vulnerabilities. If there is a vulnerabilities available, it will be
  869. encouraged attacker. So you should be discouraged. And detective nothing but actually here you should be apply the uh what is called alerting system or right
  870. monitoring system. If something actually happening and then like corrective action let's say fix the problem like if it is happening something right you know
  871. you should be actually able to fix the problem you should be let's say you are using outdated software you should be update your software right as long as
  872. it's available let's say you're using a known uh what is called burnable software because there's a lot of software out there and it's non
  873. burnability and fix is not available let's say there's a software You are using your system is using but you need the software and you knows
  874. there is a vulnerability out there and tomorrow they actually release their updated version to free with fixed version. So what your responsibility you
  875. should be update this software with in order in order to remediate this vulnerability you should not be used like old software that's actually always
  876. it's called like patch management or like software patch you'll be hear this term in real time and compensation control nothing but
  877. restore the function that compromise the system right so using like temporary let's say how we can restore let's say your server is down right uh or there is
  878. a detach attack. So it should be have plan here right how like let's say you can implement like temporary firewalls or back up your system to maintain your
  879. service if it is what is comp let's say one uh what is called server is compromised you should be have another backup server that can run your business
  880. so we'll be discuss actually later class uh so for example if I go to uh okay so we have more secure tools yeah so Next okay coming lecture we'll be learn
  881. actually more this how we can actually determine but let's move on this this slide. So here more security controls in this unit. So here is regardless of
  882. their types actually all security controls uh seek to restrain or respond to the access of the resource. The following
  883. access control determine who can access specific resource like Linux file permission. For example, a Linux f is talking about access control. What
  884. access control like file permission act as access control preventing user from modified file they don't own like as I gave you like other example earlier.
  885. So if you don't own any like you know what is called uh any asset you should not be able to actually modify or update anything because you are not owner of
  886. this. So this is like example. Same thing here for network firewalls control access to the network right and like incident respon monitoring system we
  887. already discussed actually those things you know so for example like network like firewall control and access to the network you as a company company
  888. employee like everybody like should not be accessing your company network only employee should be accessing the network company network because there's a lot of
  889. things in company employee can access without password as long as they can access their network. So this is the example like it should be actually what
  890. is called uh manage access control who can access your network who can access your file system for example like Linux and if something happened you should
  891. have like you know incident respond like monitoring system. So security control check learning learning the security control is the
  892. fundamental aspect of the security design framework defense in depth. So this is very important guys like here we are going to disect actually like
  893. what is called uh how we can defense in depth like what how we can implement a security like in multiple layer right one if one
  894. layer is failed how you can implement like let's say plan A plan B plan C you should have multiple plan actually to uh what is called save your system. This
  895. is nothing but is called like defense in depth. We will learn in next slide. So this is the definition. Defense in depth is a practice of using multiple defense
  896. to secure a resource. For example, let's say you have a home and you have a lock in home but you have a gate before you enter the room and then gate has a lock
  897. like you have a multiple layer of security for your home and you have a security camera in your home. So like multiple layer security but we'll
  898. discuss about like uh what is called in technical terms for example here defense in is talking about technical controls
  899. and then tactical and tactical controls and procedures. Okay hiding the server behind the firewall. This one example firewall. So firewall can protect this
  900. is like first first defense like firewall to protect your server. Another technical thing like forcing user to
  901. authenticate. So authentic user let's say even there is a firewall if firewall is failed user should not be what is called access your server like without
  902. authentication. So if firewall is failed this should be protect your server authentication or SS key whatever like password or keyless uh passwordless
  903. access like it's called like SSH. So defense in depth nothing but multiple layer of security. If first layer is failed, second layer should be active to
  904. protect you. If second layer is failed, third layer should be protective like multiple layer security. Here first layer firewall then second like
  905. authentication and here you see the required user to generate a new key with new strong password. So there's another one like
  906. user should be use strong password or is saying that every quarter and change the password every quarter right so multiple layer security think about this is
  907. nothing but defense in depth if firewall is failed this should be protect if you and let's say this this is also failed you somehow actually your act your
  908. password somehow user actually hacked but you change your password here right every because you are doing every other what is called uh quarter you are
  909. changing your password so even your password is hacked here let's say somehow but let's say like same day like you reset your password here right like
  910. every quarter so in this case there's another like oh even password is hacked like your old password may be hacked but you change your password like multiple
  911. layer security so there's another best practice you should not be use your same password for your lifetime right you should be change it you know
  912. So, so this is nothing but actually redundancy and single point of failure means single talking about single point
  913. of failure means if you have I'm just explaining this slide if you have like one single point of defense and if it is fail that means your entire system will
  914. be compromised right so that means like single point of failure should not be break your entire system you should have you see that in the
  915. slide side like security layer one security layer two security layer three. So if you have multiple security layer if the first layer is failed second
  916. layer will be protective second layer is failed third layer will be protective but if you have one layer security it in this case if it is fail
  917. so you'll you'll be lost everything okay so we oh looks like
  918. uh okay let me uh Clear this one here for uh what else we have
  919. now looks like it's almost going to over 781 but we have only looking forward question okay in so governance like last one but we have activity but last one is
  920. taking about this slide what learn with today prepare us to learn about the governments later this week. So is governance definition.
  921. Remember we actually discussed this with the first slide. government is is the portion of the GRC framework like Gmail's governments used or enforce
  922. the security standard policies and uh procedures right so governments nothing but just refresh entry in the organization follow the security
  923. standard policy and policy and settings rules responsibility and the oversight to make sure everybody actually following this standard so like
  924. governments That's nothing but will tell you what must be done and who and who is the responsible for this.
  925. So I think yeah today class is over guys. If you guys have any question either only activities left.
  926. >> So do you have any question? So thank you Mushid V for your class. So inshallah we'll take care everything.
  927. >> Yeah. >> Thank you for your uh cooperation and uh help. >> Thank you guys. See you then maybe next
  928. time.Am fair comments.
  929. governance risk compure. Security
  930. controls securityver
  931. Security, email security. So next class. So
  932. assment. Linux Linux first assignments
  933. will tomorrow. I we uh problem hearing your voice.
  934. Okay. So next class. So
  935. first teamwork.
  936. [Music] Super good.
  937. So important management service security service provider.
  938. This is the very good for um starting inshallah uh 2026 uh we are starting this uh uh project inshallah. So uh if I slowly slowly we
  939. can start um future. Okay. So [Music] this is a good way for us.
  940. Most of the people maybe citizen green card holder,000 business.
  941. H13 unskilled. So remote working
  942. EB3. Visner extraordinary. Right. Right.
  943. extraordinary scientist or something like that. [Music]
  944. Yeah. Yeah. tomorrow 5:00 p.m. Our next class inshallah.

Zum Nachlesen