Comprehensive CISSP 2022 Exam Cram: Domains, Strategies & Updates
Introduction to CISSP 2022 Exam Cram Series
- Covers all eight CISSP domains with 2021-2022 updates
- Focus on high probability, high difficulty topics
- Recommended exam preparation strategies using proven learning methods
- Exam format details including CAT (Computer Adaptive Testing) and linear exam
Exam Preparation Strategy
- Use official CISSP Study Guide 9th edition eBook for searchable content, practice questions, and flashcards
- Focus on understanding concepts, not just memorization
- Employ mnemonic devices, chunking, and spaced repetition
- Use practice exams to identify weakest domains and focus 80% of study time there
- Utilize online test banks and flashcards for self-quizzing
Thinking Like a Manager
- Understand due diligence (pre-decision research) and due care (post-decision implementation)
- Prioritize strategic risk management focusing on human safety, business continuity, and risk reduction
- Act as an advisor, not a hands-on technician
CISSP Exam Format and Updates
- CAT exam: adaptive, 3-4 hours, 100-175 questions, pass at 70%
- Linear exam: 250 questions, 6 hours
- No change in domains or experience requirements
- Incremental syllabus updates with new topics like zero trust, privacy by design, and post-quantum cryptography
Domain 1: Security and Risk Management
- Key topics: Risk analysis (quantitative and qualitative), CIA triad, professional ethics, security governance, policies
- Risk formulas: Total Risk = Threats x Vulnerabilities x Asset Value; Single Loss Expectancy (SLE), Annualized Loss Expectancy (ALE)
- Risk responses: acceptance, mitigation, transference, avoidance, deterrence
- Risk management frameworks: NIST 800-37 (primary), OCTAVE, FAIR
- Threat modeling frameworks: STRIDE, PASTA, VAST, DREAD, TRIKE
- COBIT framework basics
Domain 2: Asset Security
- Data life cycle: creation, storage, use, sharing, archiving, destruction
- Data classification levels: public/unclassified, confidential/sensitive, secret/private, top secret/proprietary
- Data ownership roles: data owner (senior management), data custodian (IT staff)
- GDPR terminology: data controller, data processor, anonymization vs pseudonymization
- Data destruction methods: erasing, clearing, purging, degaussing, physical destruction
Domain 3: Security Architecture and Engineering
- Secure design principles: zero trust, least privilege, defense in depth, privacy by design, fail securely
- Security models: Bell-LaPadula (confidentiality), Biba (integrity), Clark-Wilson (access control triple), others
- Cryptography: symmetric vs asymmetric, hashing, digital signatures, PKI, quantum-resistant algorithms
- Security evaluation criteria: Common Criteria (ISO/IEC 15408), TCSEC, ITSEC
- Trusted computing base, security kernel, covert channels
- Cloud security basics: IaaS, PaaS, SaaS, shared responsibility model
- Emerging tech: IoT, containerization, microservices, APIs, SEM/SOAR
Domain 4: Communication and Network Security
- Network architectures: micro-segmentation, SDN, SD-WAN, VXLAN
- Wireless technologies: Li-Fi, Zigbee, Bluetooth, 5G security concerns
- Network protocols: OSI model, TCP/IP stack, common ports
- Network devices: firewalls (NGFW, WAF, UTM), IDS/IPS, routers, switches, gateways
- Network attacks: DoS, DDoS, spoofing, sniffing, man-in-the-middle
- Network topologies: star, mesh, ring, bus
- Network security controls: NAT, content filtering, MAC filtering, captive portals
Domain 5: Identity and Access Management
- Authentication factors: something you know, have, are
- Authentication protocols: Kerberos, RADIUS, TACACS+, Diameter
- Access control models: DAC, MAC, RBAC, ABAC, rule-based
- Federated identity: SAML, OAuth 2.0, OpenID Connect
- Privilege management: least privilege, separation of duties, just-in-time access
- Account management: access reviews, entitlement audits
- Common access control attacks: brute force, dictionary, social engineering, phishing
Domain 6: Security Assessment and Testing
- Security assessment program design and validation
- Vulnerability assessments vs penetration testing
- Security audits: internal and external
- Software testing: static and dynamic analysis, fuzzing
- Security management oversight: policies, training, backup verification
- Incident response process: detection, response, mitigation, reporting, recovery, remediation, lessons learned
Domain 7: Security Operations
- Security operations concepts: logging, monitoring, configuration management, patch management
- Incident management and response
- Business continuity planning and disaster recovery
- Physical security controls: administrative, technical, physical
- Emerging tech: AI/ML in security, threat intelligence, user and entity behavior analytics
- Disaster recovery sites: hot, warm, cold
- Backup strategies and recovery objectives (RPO, RTO)
Domain 8: Software Development Security
- Secure software development lifecycle: waterfall, agile, spiral
- Software maturity models: SW-CMM, IDEAL
- Secure coding standards and guidelines
- Software configuration management and versioning
- Code repositories and scanning
- Continuous integration and continuous delivery (CI/CD) security
- Application security: buffer overflow, injection attacks, rootkits
- Database security: relational databases, keys, referential integrity, aggregation and inference attacks
Conclusion
- Comprehensive coverage of CISSP domains with focus on exam relevance
- Emphasis on understanding concepts, applying formulas, and mastering security principles
- Use of varied learning techniques and practice exams to optimize study time
- Encouragement to engage with instructor for questions and further resources
This summary provides a structured, detailed overview of the CISSP 2022 exam cram content, optimized for exam candidates and SEO visibility.
For further study, consider exploring Mastering General Security Concepts for Security Plus Exam 2024 for foundational security principles that are crucial for CISSP candidates.
Additionally, you may find Comprehensive Overview of Incident Response and Handling in CCNA Cyber Ops helpful for understanding incident management, a key aspect of security operations.
For those interested in practical applications, check out Unlock Your Hacking Potential: A Comprehensive Guide to Security CTFs to enhance your hands-on skills in cybersecurity.
welcome to my cissp exam cram series this is the complete course we'll call it the 2022 update we're covering all
eight domains of the cissp exam as well as my recommended exam preparation strategy incorporating multiple learning
techniques to help you prepare more quickly and effectively and as a cyber security strategist for
organizations around the world and a chief information security officer for a regional bank and an educator i can
promise you i use the knowledge i gained in the cissp exam every day more importantly for you last
year alone i helped thousands achieve cyber security certifications including the cissp all without expensive boot
camps and that is quite simply my goal to help you get further faster in your exam prep
so we'll be focusing on the key points of every topic we won't spend time speaking unnecessarily
about any topic we're going to focus on the key characteristics of each concept that will help you identify right and
wrong answers quickly on exam day this content utilizes several proven learning methods that have worked for
many candidates before you myself included to accelerate your progress and i will share the techniques that you can
apply in your study on your own i want to speak for a moment about my pace i intentionally speak at about 115
to 125 words a minute if english is not your first language this may be just right for you
if you do speak english as a first language you might find that increasing the speed to 1.25
may be better for you whatever works for you i just wanted to make you aware of that small detail
and by design i'm not focusing on every single topic that appears in the official study guide i'm focusing on
high probability exam topics high difficulty concepts frequent sources of questions from my
exam candidates and areas that require process memorization at the end of the day i want to direct your focus to the
high probability high difficulty areas so you're optimizing your prep you're making the best use of your exam study
time and this strategy has proven to work out well for exam candidates thus far and in
this update i'm simply turning the knobs a bit tuning this strategy further to make it a little bit better still
but in terms of what we're covering in this video we're going to talk about my
recommended exam prep strategy so the techniques that i suggest you use that many candidates before you have used
that i myself have used to prepare for the cissp exam more quickly and effectively we'll touch on domains one
through eight so every domain of the exam and i will also offer a few separate shorter videos to drill down on
what students report to be the most challenging areas and i will call those out at the appropriate points in this
video anywhere i can there's a table of contents in the video
description so at any point if you should want to skip ahead to a specific topic a specific domain feel free to do
that and as with all of my videos you'll find a pdf copy of this presentation
available in the video description you can click and download no sign in required
and a link to additional resources faqs exam updates and errata if there is any will be in the description beneath the
video and you can't be the first to benefit from this material but you may be the
next and i wanted to just share what a few other learners have said amongst the many testimonials we've seen
throughout the last year and while no course is perfect i wanted to give you a comprehensive study
resource and system without the hefty price tag and if we look at the eight domains of
the exam between the 2018 and the 2021 releases you'll see that the same eight domains are present in 2021 as were
there in 2018 and the weighting of these domains has changed very little as you can see here
if i were to describe the updates in the 2021 release of the cissp i would say the updates are incremental
the new syllabus is not that much different from the earlier versions you'll find there's no change in
experience requirements or the number of domains the content in subdomains of course has been expanded to keep up with
the changing times that's no surprise there's almost no change in domain weights as you saw
if you happen to live in a country where you don't get the new computer adaptive testing or
cat exam you'll find that the linear exam which is 250 questions and six hours long has not changed and there's
no change in the cat exam details which i'll touch on in just a moment and a few new topics have been
introduced in some of the domains to keep up with the changing times i will cover those topics in line as we cover
domains one through eight in this course i want to fill you in on the details of the cat exam format cat stands for
computerized adaptive testing and as of right now march 2022 the exam is three hours long with a hundred to 150
questions the number of questions depends on your performance the exam adapts based on your answer and it aims
for a 50 50 probability that you will get the answer to the next question incorrect so it's going to dial the
difficulty up and down based on your performance and the answers are final there's no going back which is why many
myself included think this makes the cat exam more difficult
you need a seventy percent to pass the exam some of the questions are not scored
they're pre-test unscored questions used for research for future exam changes nothing you can do about it don't worry
about it only pass or fail are recorded and if you fail even one domain you fail
the exam so it pays to make sure that your knowledge is above the passing bar for every single domain in the cissp
body of knowledge as you prepare for the exam i also wanted to tell you about a
recently announced change to the cat exam that's coming in june so the current exam includes 25 pre-test
meaning unscored questions 25 more items will be added to that pool bringing the total to 50 pre-test items
so the exam will then be 4 hours and 125 to 175 questions but no other changes to the
syllabus or content which means no real change in how you prepare for the exam as you are right now
and now i want to take you through my recommended strategy for preparing for the exam if you've seen this before feel
free to go to the video description and fast forward to domain one but if not we'll start with the
materials so i recommend the official exam study guide the ninth edition in its electronic form you'll have access
to a thousand practice questions online as well as a little over a thousand flash cards now and the electronic
version is easily searchable that's why i recommend you get the ebook you can buy it at amazon.com it's a touch over
40 u.s at the current time but do make sure you get the ninth edition which is the
update for the 2021 release of the cissp exam so let's start with the million dollar
question that we see frequently when we're preparing for the cissp and that is
how to think like a manager and i'm going to give you here the short version think like a manager
in five minutes or less so it starts with due diligence versus do care and it's really about knowing
our role so due diligence is practicing the activities that maintain the do care effort that's the
book definition not very helpful is it now the do care definition is doing what a reasonable person would do in a given
situation it's sometimes called the prudent man rule but what you see here right away is that
these two concepts work together that due diligence supports do care and these together will reduce senior management's
culpability their liability when a loss occurs both their liability for their own organization and those
in either direction of their supply chain i want to explain these two concepts to you a bit differently in a
way i think will resonate with you so due diligence and do care can really be looked at in the context of a
decision that line in the middle is our decision so on the left we have due diligence
this is the research the planning and the evaluation that frequently happens before the decision
not always but largely before the decision and due care includes implementation of
security controls operation and upkeep of those controls and reasonable measures to secure our organization and
its resources that's the doing after the decision so due diligence
increases understanding and reduces our risk in a given situation and do care ensures that we take those reasonable
measures as outlined in that prudent man rule so i mentioned that due diligence
happens largely but not always before do care so that evaluation process is a recurring process we need to make sure
that our reasonable measures that we put in place continue to be effective over time so we're going to come back and
reevaluate on a recurring basis through internal and sometimes external audits another way to look at due diligence and
do care that may help you remember these and keep them separate and clear in your mind for the
exam is that due diligence is about thinking before you act and do care tells us that actions
speak louder than words another way we see this labeled is due diligence is do detect the d d
and do care is do correct so one of these is about the research and evaluation and the other about taking
appropriate action so separating these into the before and after in your mind may be more helpful
so let's look at examples of due diligence we have knowledge and research of laws and regulations
industry standards and best practices and on the do care side we have delivery or
execution including reporting security incidents security awareness training and disabling access of users separating
from the company in a timely way and thinking like a manager is all about knowing your priorities so if we look at
our security planning horizons from operational to strategic so operational being short term and strategic being
longer term as a chief information security officer you really deal with risks that are
escalated to the top and you send down the objectives as you see them
in terms of their importance so your focus should really be right up here at the top of the pyramid
at the strategic level you're thinking about human safety business continuity protecting profit reducing liability and
risk and you are passing objectives down to the tactical and operational teams which they will implement in the form of
policy and planning and then actually implementing those recommendations and operating the environment on a
day-to-day basis and one more perspective that may prove helpful is assume that you are in that
organization to advise not to touch so during the exam think of yourself as an outside security consultant advising an
organization you're there to advise on strategy priorities and safety you're not doing you're not laying hands on the
keyboard this may help bring focus to process your role to due diligence and do care now if you're interested in the
long version of thinking like a manager check out my cissp mindset video it's right at half an hour it is the full
story it does also include me walking through a couple of practice questions to show you how you can use this logic
to reason your way to the best answer on exam day now let's take a look at some of those
learning techniques i promised at the beginning of this video the fact of the matter is there is no award for longest
study time whether you prepare for this exam in two weeks or two months or a year and a half
a pass is a pass and so if we can prepare effectively actually learning this content for the long term without
spending a year and a half doing so we should absolutely do that and
the number one reason that i am not a fan of those five-day boot camps where you spend two or three thousand dollars
and then go take your exam on day six is due to the length of time it takes to memorize anything to truly learn
anything i can commit facts to short-term memory you know quickly by repeating my
learning spacing my repetition out over a period of hours in fact with my fifth repetition only including a 48 hour gap
within a week i can commit facts to memory very quickly now to commit something to memory for
the long term to really onboard that for the duration of your career typically takes more time and how much time it
actually takes depends on your level of exposure and experience to these concepts but you can see if you're
starting from scratch to truly memorize anything for a long time can take repetition over a period of days weeks
and even months and there's a lot of power in repetition and i'll show you some techniques that
we can use to repeat our learning in different forms
whether we're working on those short-term intervals or the long-term intervals we call this spaced repetition
and the fact of the matter is between your sessions what you'll find from your first
study session to your second to your third is that with each successive repetition you are remembering for
longer and you are forgetting less information what you'll find is that your forgetting curve we call it becomes
shallower with each repetition using this spaced repetition technique and it's not purely about memorization
we do need to identify our weakest areas and focus our repetition on the topics where we need
work and we'll talk about how to do that in just a moment but at the end of the day our focus is
to understand these concepts not just memorize them studies have long shown that understanding a subject before you
memorize greatly improves your retention because you're not just memorizing words and the exam will assume that you
understand when and where concepts fit you need to be able to apply these concepts in the
right scenarios so one learning technique that makes memorization easier is what we call a
mnemonic device or a memory device and a common memory device is an acronym and i'll show you an example in a moment
but our mnemonic devices are best when they are simple they are relevant to the topic and
visual where we can make them visual so let's look at a couple of examples here so we'll start with a first letter
mnemonic and a good example of a first letter mnemonic is the osi model so back in the
90s i remember memorizing the osi model using a first letter mnemonic please do not throw sausage pizza away that was
layers one through seven and then in the reverse all people seem to need data processing so one could argue that we
could make this more relevant by changing the words in our mnemonic let's try please do not toss security
processes aside whatever works for you but we could argue that's more relevant another mnemonic here comes with the
incident management framework so our acronym here is drm rrl
drum roll if we pronounce it the letters don't spell it out quite right but you see i can add a visual element here as
well to make it easier still for me to remember that framework that process another technique that's useful when
we're dealing with large amounts of information is chunking it's the process of breaking information into smaller
pieces or chunks that make sense so let's take cryptography as an example we have asymmetric cryptography we have
symmetric cryptography hashes block ciphers so we could break cryptography into these chunks for
example and then i can break those categories into smaller chunks yet let's take hashes for example i'll break this
into chunks based on a unique property i find within these so let's take hash algorithms i'll take the
message digest family and i see here that for md 2 4 and 5 they each have a hash value length of 128. i see that by
and large they're not still in use with md5 there are some exceptions to that it's still used with file hashes
but in the cryptographic context not so much let's take the shaw family this is
secure hash algorithm what i notice here right away is that the hash value length matches the name i can see here that
most of these are still in use certainly all of the sha-2 family is still in use but shaw 1 is not that's a chunk
i notice here that the hash value length matches the name of the algorithm that's useful
in rounding out our exam prep strategy i want to talk you through what i call the 80 20 strategy for identifying your 20
weakest area so you can spend 80 percent of your time there so it starts with the practice exams now
whether you get the practice exams from the official study guide or elsewhere doesn't matter so much i'm going to show
you how to use the exams in the official study guide to drill down to your weakest areas on a per domain basis and
that's really the important question here is how can i best use these practice quizzes to assess my exam
readiness because the fact of the matter is if you get to exam day and you ask yourself am i ready if you don't know
the answer to that question then the answer is no and the way i suggest you do this is by
looking at how the book is organized per domain so chapters 1 to 4 in the book for example
map to domain 1 security and risk management chapter 5 maps to asset security
chapters 13 and 14 mapped to domain 5 identity and access management so if we use
the quizzes at the end of these chapters we can focus our learning to find our weak areas in that domain
and one of the more common questions i receive is how do i get access to those online resources that are promised in
the book so if i just go to the electronic copy of the book i'm going to search for test
bank one word and that will bring me to the section here that describes the interactive online learning environment
and test bank and you're instructed to go register at wiley.com you'll be prompted with a challenge you can only
answer if you've purchased the latest copy of that book and once you sign in to the website
you'll be presented with a page similar to this i'll find the cissp i'll
log in there and ultimately i come to a page that looks just like this it's efficientlearning.com
and when i log in here i've gone through the process of registering
i'll see the products that are available to me and i can go to the test bank so what you need to know here is that
with these 1000 questions they are divided into exams in the quiz builder
but we can customize entirely so what i'll do is uncheck question topic so i've unchecked all questions and if i go
into those chapters i can select specific chapters to create a custom quiz so for example chapters
one through four i mentioned were domain one i will select just those four chapters
i'll scroll to the bottom and here i can tell the wizard the number of questions i'd like
so i want all 80 questions and now i can take a quiz that is only focused on domain 1 which is covered in chapters 1
through 4. and on that same screen where i selected the
test bank the practice quizzes you'll also see an option to select the flash cards
but i commonly find candidates get into the test bank here and they can't quite figure out how do i take a quiz that
shows me my weaknesses in a particular domain well that's how you do it you map the chapters out as you see here and
again you can download this as a pdf so you'll have this information at your fingertips
so moving through the 80 20 strategy as we go through that spaced repetition we have our practice exams that will help
us understand our weak areas which will spur some targeted reading we'll go read a little more on those topics where we
have weakness to better understand the material we'll come back and review the powerpoint in this video and some of the
other targeted drill down videos i have we'll look at live quiz or flash cards
so the flash cards are great if you don't have a partner to help quiz you for example my spouse my wife helped
quiz me as i was preparing but if you don't have a partner then you can use those flash cards to quiz yourself
on those topics but at the end of the day research has proven that we all function best when we learn using a
variety of techniques so variety is the spice of life and it is very effective in learning subjects more quickly
and there you have it that's my system which means it's time for domain one which is security and
risk management now a few key areas you'll be expected to know for domain one include risk and risk analysis
you'll be expected to know the quantitative risk analysis formulas and how to apply them
threat modeling concepts and processes and the frameworks that go with that compliance legal regulatory and privacy
you'll be expected to have some summary knowledge of particular u.s laws and in the case of the eu gdpr a european law
that applies to u.s companies professional ethics you'll need to know the isc squared code of ethics by heart
security governance principles like itil and finally security policies standards procedures
and guidelines you'll need to know the difference between these four including which are suggested and which are
mandatory in terms of what's new in domain 1 in 2021 when we break down the
exam syllabus 1.1 is now understand adhere to and promote professional ethics i would say generally speaking
this is a non-event there's fundamentally no change from 2018 in terms of what you'll be expected to know
for domain one so i mentioned you're going to need to know
the cia triad by hearts the cia stands for confidentiality integrity and availability you'll sometimes see this
expressed visually in the form of a triangle with confidentiality being the first followed by integrity and
availability so confidentiality is about secrecy or privacy and in the technology context
that means access controls that help ensure only authorized subjects be those people or services can access objects
whether that object is data or a system so integrity ensures that our data or system
configurations are not modified without authorization if a threat actor modifies data without
authorization we've now lost integrity that data is now no longer true and reliable
and confidentiality and integrity don't matter if we don't have availability so authorized requests for objects those
systems that data must be granted to subjects within a reasonable amount of time
the cia triad is covered in chapter one of the official cissp study guide you'll want to know cia very well for the exam
definitely going to come up i mentioned the cissp code of ethics i'm not going to read you the full
code here but at a high level it covers protecting society infrastructure the commonwealth acting
in a manner that is honest and responsible and legal providing competent
service to others and to advance and protect the
profession the code of ethics itself is much longer than this you want to give the whole thing a quick read and
personally i find most of what's in here is common sense but but you'll want to have some
familiarity with the terminology they use in here in case it comes up on a question
so i want to shift gears and talk about security policy development so at a top tier security policy is your document
that defines the scope of security that's needed by your organization the assets that need to be protected and to
the extent we should go to to protect them but there are four levels of security policy
development so it starts with acceptable use policy which is designed to assign roles within an organization and to tie
responsibility to those roles then we have security baselines which define a minimum level of security that every
system in the organization needs to meet then we have security guidelines which offer
recommendations on how standards and baselines should be implemented and these provide operational guidance for
both our security professionals and our users and then finally we have procedures
which are those detailed step-by-step documents that describe the exact actions that are necessary to implement
a specific security mechanism a control or a solution in protecting our data or infrastructure
so tidbit for the exam when you're developing new safeguards you're establishing a new baseline a new
security baseline which means that maintaining compliance with existing baselines is not a valid consideration
point now let's move on to risk management and risk analysis and i want to start with risk category so a
category is a group of potential causes of risk so at a high level you have damage which results in physical loss of
an asset or an inability to access that asset and then when it comes to information we have disclosure and
disclosing critical information regardless of where or how it was disclosed if this was a malicious act as
a result of a threat actor or unintentional on the part of a well-meaning user
and we have losses so losses might be permanent or temporary which could include altered data or inaccessible
data so data altered without authorization affects integrity if we think about it from a cia perspective
and then if you think of an attack like ransomware for example which renders data inaccessible
and permanently inaccessible unless we can recover and then we have risk factors and risk
factors factors are something that increase risk or susceptibility to loss
so in the realm of risk factors we have physical damage natural disasters power loss vandalism we have malfunctions so
whether that's a failure of a system or a network or a peripheral or the hvac system we have attacks now these are
purposeful acts of of a threat actor whether that's from the inside to the outside like unauthorized disclosure for
example so continuing on risk factors human errors now these are usually considered
accidental incidents where attacks are generally purposeful incidents then finally we have application errors which
would be failures of the application including potentially the operating system
now security planning may come up on the exam and there are three types of plans you need to be familiar with the first
is the strategic plan this is the long-term plan that's fairly stable it should generally include a risk
assessment and the strategic plan typically has a five-year horizon and you'll update it annually this helps to
align the goals of the security function with the organization's missions and objectives
the next one is the tactical plan this is a midterm plan it's developed to provide a little more details on the
goals of the strategic plan this is typically going to have a horizon of about one year the tactical plan gives
us a little more flexibility we can make some ad hoc adjustments here when circumstances dictate and the final plan
of the three is the operational plan so this is a short-term highly detailed plan that drills down on the strategic
and the tactical plans and by short term we're typically talking about monthly or quarterly the
operational plan will have budgetary figures staffing assignments scheduling and typically step-by-step
implementation procedures so now let's talk about response to risk so we have several ways we can respond
to risk the first is risk acceptance and and that means simply doing nothing we simply accept the risk
and the potential loss if the threat occurs and if the safeguards or counter
measures outweigh the potential loss in terms of their cost then just simply accepting a risk might make sense
the next option is risk mitigation or sometimes you'll hear this called risk reduction and when we mitigate risk we
implement uh countermeasure and we accept the residual risk that's the risk that's left over
once our safeguards our security controls are in place
now in risk assignment this is also called risk transference we're transferring or assigning that
risk to a third party like in purchasing insurance against damage and outsourcing to companies with
specific expertise is another way we commonly see risk assigned or transferred
so next is risk avoidance so when the cost of mitigating or accepting a risk are higher than the benefits of the
service itself then avoidance is a good idea so for example
i might decide to locate a business in kansas instead of florida to avoid hurricanes if i decide that the cost of
mitigating the risk of hurricane damage to my business is too great so continuing down this road risk
deterrence is another potential response and implementing deterrence to would-be violators of security and and policy
is a pretty common response in the real world and deterrence would include things like
implementing an audit policy to deter folks from malicious behavior for example in the
i.t department security cameras are security guards to defer deter
unauthorized entry onto our premises or even something as simple as warning signage
and then finally we have risk rejection and i want to point out this is generally considered an
unacceptable response it's a possibility but it's not acceptable this means to simply
reject or or ignore the risk just treat it as it doesn't exist
obviously never a good idea to just bury our head in the sand because problems don't just go away
but remember handling risk is not a one-time process this is an area you're going to have to revisit on a recurring
basis and refresh your responses to risks and to determine if the nature of these risks has shifted in
some way and require changes on your part let's talk about
risk management frameworks now the primary risk management framework referenced on the cissp exam
is the nist 800-37 framework and that's currently in revision 2.
if you'd like to read it end to end i'll have a link to 800-37 in its latest revision down in
the description for this video now you'll also hear some other risk management frameworks mentioned but i
want to point something out here so from the cissp study guide it says consider the following risk management frameworks
for use in the real world so the key there is for use in the real world so they mention octave and fair
and tara and the fact that they say consider these for use in the real world while mentioning
that nist 800-37 is the primary framework that tells me i'm not going to worry much about these i'm going to
focus on nist 800-37 now this nist framework establishes a
process steps and you with any process in cissp you need to make sure you know these steps in order and really it's
depicted by some as a preparatory step followed by six main steps i'm going to just give you the
seven steps so when we talk about that preparatory step uh preparing to execute
the risk management framework is that preparatory step so so if you ever see nist 837 presented as six steps it's
because they leave the prepare off so second step is categorizing your information systems
and we're looking at the information process stored and transmitted by the system based on analysis of the
potential impact for loss next is selecting security control so we need an initial set of controls for the
system and to tailor those controls to our reality to reduce risk to an acceptable level
based on our risk assessment step four we implement security controls and we describe or document how those
controls are employed within our systems and our environment and then we're going to assess those controls to determine if
they're implemented correctly if they're operating as we intended in our environment and most importantly are
they producing the desired outcomes are they meeting our security and privacy requirements and expectations
so next we authorize the system and by that i mean we authorize the system to operate in a normal
environment and at that point the organization is accepting the risk formally
for the system and because this is not a one-time event your risk management is a
process uh step seven is monitoring our security controls
periodically assessing that our controls are effective documenting any changes to the system and
conducting risk assessments periodically as necessary and remember i mentioned this is a
process right for any process in cissp we need to know those steps we want to know them in order some folks will use
a mnemonic device or a memory device that's called using the first letters of these steps in the framework
so for example for for these letters for pcs i am i could use the mnemonic device people can see i am always monitoring
so at test time if i'm a little foggy on nist 800-37 i can at least get the first letter of each of these seven steps by
remembering my mnemonic device people can see i am always monitoring that was something we did very commonly
with the osi model back in the day and we'll talk about that in a later domain in this series
and a few other things for the exam so do remember when you're talking about risk management and and risk analysis
not every risk can be mitigated that's just a fact and it's management's job to decide how
that risk is handled so when you hear me talk about thinking like a manager when you're taking the
cissp exam remember it's the role of a security professional to be a risk advisor to advise the decision maker who
is the manager and also when multiple priorities are present always remember human safety is
the most important i bring that up now that it may not even come up as a part of this domain but it's an important
point so i wanted to just mention it early on here left i i forget
remember to prioritize human safety when you're presented with many options and remember when legal issues are involved
calling an attorney is a valid choice it might not seem like a valid choice because it's technical folks
you may want to solve every problem but when we put our manager hat on calling an attorney is a great
example of risk transference right or or assignment we're
outsourcing our problem to an expert so let's talk for a moment about types of risk so residual inherent and total
are three types of risk
so we have residual risk which is the risk that remains even when
all our conceivable safeguards are in place that's the risk we can't get rid of
and at that point the risk management function has chosen to accept rather than to to mitigate or transfer or
assign that residual risk sometimes there's a bit of risk there we just can't shake
so we're accepting then there's inherent risk newly identified risk not yet addressed
with risk management strategies so another way of saying that is its inherent risk is risk that exists in the
absence of controls and this is one that that you don't really see in every cissp text i bring
it up because i've seen it a time or two and it's worthy of mentioning but total risk is the other that you want to be
very familiar with and that's the amount of risk an organization would face if no safeguards were implemented so
to say it another way if we just look at those three types of risk residual risk is after
controls are implemented that's the risk that remains inherent risk is risk that exists before we've implemented our
safeguards and then total risks would be the risk present without any safeguard so for the
exam you really want to focus on residual risk and total risk these are going to come up in a formula
and this is the first time i've mentioned formulas but formulas are very much a thing when we talk about
risk analysis and management on the cissp exam so a few tidbits for the exam
so be able to explain total risk residual risk and the controls gap which is the amount of risk that's
reduced by implementing safeguards we'll see controls gap in a formula and talk about that a bit more a little
later in this installment so to calculate total risk know this formula threats times vulnerabilities
times asset value equals total risk and we'll look at some of these formulas later in this installment because you
will need to understand the several formulas as they relate to to risk
and how to use them to arrive at good decisions so we can also express risk itself
as a formula and risk can be defined as as threat times vulnerability so yes you know threat and vulnerability are
expressed as numeric values as probabilities so stick with me to the end of the video
we'll we'll see more formulas here and we'll we'll look at a couple of examples to help you get the ball rolling
and if when we're done if maybe you'd like to see a video dedicated to nothing but the formulas that are going to come
up for you on the cissp exam just leave me a comment and
i can make that happen so i want to shift gears now from risk to risk analysis so so there are two
ways at the highest level to evaluate risk to our assets there's qualitative risk analysis and quantitative risk
analysis so quantitative assigns a dollar value to evaluate the effectiveness of our
countermeasures quantitative risk analysis uh really is the more labor-intensive of the two
methodologies it employs typically a lot of data collection and analysis using cost benefit analysis
it results in specific values that we're really what we're doing is removing guesswork
and opinions from the process it's really if if i were to describe quantitative risk analysis in one word
it's objective it requires a lot of information and effort typically but at the end of the
day it's going to assign a tangible dollar value so we can evaluate the effectiveness of our
response to risk so let's look at the risk analysis steps involved in quantitative risk analysis
so this is specific to quantitative risk analysis we're going to talk about qualitative in a moment
so step one is inventorying your assets and assigning a value and you might be asking yourself what's
that out what's that text out there in red i'm putting some some terms and some acronyms out here because these are
going to come up in formulas that we discuss later in this module so these are going to be important you'll wind up
revisiting this slide to to perhaps think think again through
these steps and and what the outputs of the step are so step two we're identifying threats
we're going to research our assets we're going to produce a list of all the possible threats to each asset
and here we're going to calculate ef which is the exposure factor and the sle which is the single loss
expectancy we're going to get to what these mean in just a moment i just want to set the stage for you so you know
what some of these outputs are and this will all come together when we talk about the formulas
step three you'll perform a threat analysis to calculate the likelihood of each threat being realized within a
single calendar year you're calculating the annualized rate of occurrence again that acronym is going to show up in a
formula here momentarily step four we're going to estimate the potential loss by calculating the annualized loss
expectancy and the fact that the word annual or the concept of yearly is coming up here
should tell you that this process is an ongoing process right this is a recurring process we're going to
revisit periodically within our organization it's not a one-time exercise step five we're going to
research counter measures for each threat and then we're going to calculate changes to the annualized rate of
occurrence so in other words how often is is this event going to occur
and what is our annualized loss expectancy based on the counter measures that we've applied
so if we've done our job right the the annualized rate of occurrence and the annualized lost expectancy are going to
be lower than when we started in step six we're going to perform a
cost benefit analysis of each of our countermeasures for each threat for each asset
to determine in a very dollars and sense fashion if we've made good decisions in our selection of countermeasures
so let's talk about qualitative risk analysis so qualitative risk analysis uses a scoring system to rank threats
and the effectiveness of our countermeasures relative to the system and the
environment it requires guesswork and estimation it definitely uses opinions however
it does provide meaningful results if i if i could summarize qualitative risk analysis in one word it would be object
subjective because it involves opinions and while it's going to tend to be less accurate it is a quick way we can make
some estimations that we can then use to guide our efforts in the deeper quantitative risk analysis so so a lot
of times qualitative risk analysis can serve as that way we take a five minute rough cut at the problems we're dealing
with i can rank impacts as low medium high i can throw out some percentages
to just get to a point that i know what i'm dealing with in terms of the probability and impact of of the threats
we're working with of the the risk we're trying to to deal with uh you should be familiar
with the delphi technique for the exam as well so in qual qualitative risk analysis this is uh basically anonymous
feedback and response used to arrive at a consensus a couple of other considerations when it
comes to risk analysis uh there's lost potential so so what would be lost if the threat agent is successful in
exploiting a vulnerability and then delayed loss and this is the amount of
loss that can occur over time because the reality is you don't lose
everything all at once in certain situations for example if an exploit
takes down your firewall and from in front of your web farm and your web farm is unavailable you
lose money over time as customers can't reach your website that's delayed loss and i mentioned threat agents here the
threat agents are what cause the threats by exploiting vulnerabilities the vulnerabilities are
the weaknesses in your assets or in your safeguards for that matter so i promised you we would talk about
those important formulas and that time has come so we're going to talk about the relevant
terms and the formulas that we use to calculate their results
so we have exposure factor single loss expectancy annualized rate of occurrence
annualized loss expectancy and safeguard evaluation so these all factor into
some key formulas that are definitely going to show up on the cissp exam so let's dig into these terms and the
formulas that go along with them so we'll start with exposure factor ef this is the percentage of loss that an
organization would experience if a specific asset were violated
by a realized risk so this is a percentage of loss so so ef or exposure factor is expressed as a percentage
single loss expectancy or sle so this represents the cost associated with a
single realized risk against a specific asset so this gives us
a one-time loss figure so the formula for single loss
expectancy is the asset value times the exposure factor so the asset
value is going to be a number a dollar figure the exposure factor will be a percentage which is expressed as a
decimal when we're doing the math so let's look at a sample here so if i
have an asset value on the left here of a hundred thousand dollars and a tornado is estimated to do thirty percent damage
to my asset so that's going to be point three my exposure factor is thirty percent
uh and my single loss expectancy then would be 30 000 or the asset value times
the exposure factor okay this is just the tip of the iceberg so let's keep going here
so annualized rate of occurrence or aro so this is the expected frequency with which a specific threat or risk will
occur within a single year so the annual rate of occurrence is an
important input for this next item
and that is annualized loss expectancy so this is the possible yearly cost of all instances of a
specific realized threat against a specific asset
so we look at that in a formula the the annualized lost expectancy the
ale is the single loss expectancy
times the annual rate of occurrence so so the sle is the one time uh loss
and then we take that times the annualized rate of occurrence so if we have an sle of 50 000
and we have an annualized rate of occurrence of say 0.5 because a particular threat only
occurs once every two years 50 000 times 0.5 is 25 000. so i've explained that simply there but
i started with an sle we'd already calculated let me take you through an end-to-end example of annualized loss
expectancy so we have an office building that's worth two hundred thousand dollars
and we estimate that hurricane damage uh would be fifty percent uh of the value of this building
and hurricane probability is one every ten years so ten percent or point one okay so we have to start by calculating
the single loss expectancy right so the single loss expectancy is the two hundred thousand dollar building times
the damage estimate of fifty percent or point five so our sle
is one hundred thousand dollars now we're going to take that sle and that factors into
our ale equation so we'll carry that hundred thousand dollars into the next equation here and that is the
single loss expectancy of a hundred thousand dollars times
the annualized rate of a current or aro and our hurricane probability is one
every 10 years so the annualized rate of occurrence is 0.1 so so if a hurricane probability was one
every single year that would be one even right but one every ten years means point
one so we take that hundred thousand times point ten and our annualized loss expectancy
is ten thousand dollars so what this tells us is that the safeguards we put in place
better not cost more than ten thousand dollars a year or we're spending more to protect this building than we're
essentially going to save so that gives us the the value of the safeguard so while
we're on that subject that that gives you a dollars and cents answer right so while we're on that subject let's
talk about how the value of the safeguard is expressed then so we call that
safeguard evaluation so good security controls will mitigate risk they're transparent
to users they're difficult to bypass but the last one here they're also cost effective so in our previous example we
saw that the safeguard shouldn't cost us more than ten thousand dollars a year or we were spending too much
relative to the reduction in loss so so safeguard evaluation has a formula so
it's the annualized loss expectancy before the safeguard minus the
annualized loss expectancy after the safeguard minus the annual cost of the safeguard
that gives us the value of the safeguard so we're really trying to answer the
question is the safeguard cost effective if we're spending more to protect an asset
than we're saving in ale then we don't have a cost effective answer there so there's your formula
expressed a little more simply so ale before the safeguard minus ale after the
safeguard minus the annual cost of
the safeguard so again i hope these examples have been helpful if you need more help with formulas if we need to do
a video with just the formulas go down to the comments drop me a note let me know we can make it happen
so the amount of risk reduced by implementing safeguards is known as the controls gap
and to see control's gap in a formula we can look at residual risk then so residual risk is total risk so
the risk and absence of controls minus the control's gap gives us that remaining
or residual risk so if total risk is a hundred thousand dollars the
controls gap is fifty thousand dollars our residual then is fifty thousand dollars
and the expectation that you know all of these formulas and how to use them make quantitative risk analysis one of the
most difficult topics on the cissp exam so one of the most important videos you can watch is my quantitative risk
analysis just the formulas video where i walk you through a real world example where we apply
those formulas to a realistic use case you'll find a link in the video description
the cissp exam will also test your knowledge of applying risk-based management concepts to the supply chain
so today most services are delivered through a chain of multiple entities that is to say
one product like a car for example really you know while it has a car company's
label on it likely includes components from multiple companies and certainly
may be transported by multiple companies to the dealership so a secure supply chain includes
vendors who are secure they're reliable they're trustworthy they're reputable and
you need to evaluate the vendors in your supply chain to ensure that's true so when evaluating third parties in the
chain you want to consider methodologies like on-site assessment visiting an organization interviewing personnel and
observing their operating habits to ensure they are as safe as they claim to be
document exchange and review and this means to investigate the means by which this organization
exchanges data sets and documentation as well as the formal processes by which they perform assessments and reviews
there's processor policy review so requesting copies of their security policies their
processes or procedures and you could finally
opt for a third-party audit so having an independent auditor provide an unbiased review of an entity security
infrastructure our next topic is one where i suspect you'll have some memorization ahead in
order to be prepared for exam day and that is threat modeling which can be proactive or reactive but the
goals are are to eliminate or or at least reduce threats significantly and your threat modeling approaches
can take one of three common forms they can focus on assets where asset valuation
is is used to identify threats to valuable assets we want to to focus our our spending on assets that
have value to the business right focusing on attackers is another common approach where
the the process is focusing on the attacker's goals and then finally
focused on software where considerations center on potential threat against the software the
organization develops or implements so let's talk through a few of these models remembering that they can focus on
assets attackers or software so one of the
more common threat modeling frameworks and it's mentioned in the cissp is stride which was actually developed by
microsoft so so remember that in case it gets called out as a detail in a question
so the stride model focuses on the the potential threat so spoofing
tampering repudiation information disclosure
denial of service and elevation of privilege so because these were developed by
microsoft we see this as a software focus right it's focused on potential threats
to to software and i believe most of these are going to be pretty well known to you repudiation
might be a term that you're not super familiar with and that's the ability of a user or an attacker to deny having
performed an action or an activity and that often takes the form of the attacker staging the situation to
blame someone else and then there's spoofing that involves falsified identity tampering which is
data manipulation you know restaurant transit but remember stride is developed by
microsoft and remember the terms there that uh that map to the acronym right all right so moving on in the threat
modeling discussion let's talk about pasta which focuses on developing counter measures based on asset value
and there are seven stages of pasta but the key here it's a
threat modeling approach that focuses on asset value which really gets to the heart of the
matter right because when we're dealing with with risk management it really comes down to
implementing cost effective control so when we're modeling threats focusing on asset man
on asset value is a great idea okay moving on there's the vast threat modeling approach which
stands for visual agile simple threat so this is based on agile project management principles
so the bottom line goal of vast is to integrate threat management into an agile
programming environment so next up is
the dread model which is based on the answers to five questions so damage potential so how severe is the
damage likely to be of the threats realized reproducibility so how complicated is it
for attackers to actually reproduce to implement the exploit exploitability so how
difficult is it to perform the attack affected users this is really about headcount right how many
users are likely to be affected by the attack as a percentage and that could mean
internal users and that could mean you pay the bills users your customers
and then discoverability so how difficult is it for an attacker to discover this
weakness because a significant weakness five or six layers deep in our defense and depth
may not be such a big problem for us so certainly something we might want to
address but maybe we'll will push it down the priority list so rounding out our our threat modeling
discussion is the trike model which focuses on acceptable risk it's an open source threat modeling process that
implements a requirements model that essentially ensures the assigned level of risk for each asset as acceptable to
stakeholders so remembering that trike is risk focused and it implements a requirements model
should cover you if it comes up on the exam and to round out domain one i want to talk to you about
cobit which stands for control objectives for information and related technology it's
not a great mapping to the cobit acronym frankly and this is a security control framework sometimes
described as a framework for i.t management and governance it's based on five principles so meeting stakeholder
needs covering the enterprise end to end so treating our our enterprise
as as the full scope of our focus applying a single integrated framework
so so continuity of a centralized coordinated approach enabling a holistic approach
and separating governance from management so holistic approach and separating governance from management
are key concepts or i think and we're expecting to see little or no coverage
on the cissp exam in fact the official study guide mentions it only briefly and goes on to promise that there's
going to be no real depth of coverage on the cissp exam so this should get you through with the basics around
cobit an important aspect of threat modeling you may not be acquainted with yet is
diagramming potential attacks so determining potential attack concepts is achieved
through visualizing your infrastructure and identifying threats
or identifying potential vulnerabilities that may be exploited so let me just sketch out a simple
example for you here so let's diagram some potential attack so i have users
that come through my perimeter my user web server boundary we'll call it so they hit my web service here
and i have a database back here a sql server where we'll pull some data from a database
so my user starts by logging in to the web service at some point they may make a request
that then causes that web service to go back and retrieve data from my sql database
i'd imagine there's uh you know maybe even a different authentication process here from
a service principal or an entity down to that database versus the user logging in manually here and i can perceive
different threads here because i'm visualizing so just right off the cuff i can imagine that on a login form
brute force password attacks dictionary attacks might be common if attackers wanted to just guess
at user names and passwords and if they were to register for our service maybe they
could get an idea of the username requirements and then just start you know as i mentioned a
dictionary attack now if i think about a web service talking to a database the first thing that always comes to mind is
sql injection so as an attacker i could try to exploit
maybe some poor value handling on a web form to perform a sql injection attack
and i'm out of space here but and i could go quite a bit further as you can see but this gives you an idea of that
diagramming process at a basic level so let's talk about reduction
analysis in threat modeling so in reduction analysis i'm going to break a system down into its uh its parts which
makes it much easier to identify the essential components of each element and take notice of where we might have
vulnerabilities and and you know likely points of attack so
just to go through this i could look at trust boundaries so any location where the level of trust or security changes
so a trust boundary in your application from say a an access control perspective would be
where a specific role or privilege is required to access a resource or an operation that would be a change in
trust data flow path so looking at the movement of data between locations
and what exposures there are that might allow attackers opportunity to to capture or breach that data input
points locations where external input is received so in our our diagramming example uh a web form where we're
logging in or a web form or we're submitting a request that that calls back to sql that's going to be
an area that would be most likely
a possibility for attack a likely target perhaps privileged operation so any activity
that requires greater privileges than that of a standard user account that's going to be a red flag area
an area will want to give special attention then finally details about security
stance and approach so so essentially just the our declaration of security policies foundations are our assumptions
in a given scenario for for a service or infrastructure so after we go through that
deconstruction and documentation process then we want to rank or rate the threats we can use the dread methodology we just
talked about or a high medium low rating for example so i want to clarify a few things around
security control so your security controls are the measures for countering or minimizing loss or unavailability
of your assets your services your apps etc and
you'll hear the term safeguards and counter measures we've used those quite a bit today and they may seem to be used
interchangeably at the end of the day the main difference between a safeguard and a
countermeasure is safeguards tend to be proactive and counter measures tend to be reactive
let's talk about the categories of controls there are three categories of security controls they're technical or
logical or sometimes called which involves the hardware or software mechanisms used to manage access and
then you have administrative controls which are policies and procedures that are designed
by the org security policy or other regulations and requirements administrative controls for example
might include hiring practices background checks data classifications and labeling security awareness and
training methods and then you have physical uh control so the physical category are
items you can physically touch so there we're talking about guards fences motion detectors lock
doors seals sealed windows lights laptop locks etc so be familiar with these control
categories and be able to name off a few in each category as i just did for you now
so next let's dig into security control types so you have deterrent
control so these are deployed to discourage violation of security policies
deterrent controls could include uh you know audit policies security awareness training locks fences security badges
they're designed to discourage violation and then we have
preventative controls these could be
technical controls like firewalls or intrusion detection systems or it could be a physical control like a
fence or a gate or a man trap and technically there could be some overlap between deterrent controls and
preventative controls the main difference here is deterrent controls really rely on on somebody making a
decision to not do something where preventative controls are really designed to actively stop the unwanted
behavior and we have detective controls which are deployed to discover or detect unwanted
activity so defining characteristic of detective controls as they really detect the activity after the fact right
they detect something in progress motion detectors cctv cameras audit trails honey pots
and you'll find some surprising elements listed as detective controls like
mandatory vacations for example job rotation because if you're rotating people across
jobs or in and out on vacations you're going to be able to establish some patterns there that will allow you to
detect behavior based on the presence or absence of certain individuals or circumstances
then we have compensating controls compensating controls provide options to other existing controls to aid in
enforcement of the gulf so for example let's say your organization requires that personally identifiable information
is encrypted in the database and in fact it is encrypted in the database but someone discovers then that the
the uh pii data is being transferred across the network in clear text so a compensating control
would be for example an additional control to encrypt that data in transit to support the
requirement and you want to make sure on the exam that you you understand
the key element that defines that control type and you know a few examples off the top of your head so you can you
can pick those out uh should you see them in a question so we're actually not done with control types let's keep going
here so so we have corrective controls
corrective controls can range from antivirus that removes uh malicious files to backup software
that automatically restores missing files to policy-based configuration management
that returns a system to its desired configuration after a breach
next up we have recovery controls which are much like corrective controls but they tend to have more advanced
capabilities good examples here would include server clustering vm shadowing hot sites warm sites alternate
processing facilities and finally we have a directive control which is intended to confine or control
the actions of the subject to force or encourage compliance with security policies
good examples of a directive control would be security policy requirement posted notifications
escape route exit signs just to name a few so again make sure you understand the defining
characteristic and you can rattle off a few examples before you walk into the exam
now we're going to talk legal and regulatory which is an area of the cissp exam that requires a lot of memorization
i'm going to try to help you focus that in so at a high level the topics here include cyber crimes and data breaches
transborder data flow licensing and intellectual property requirements things like trademarks
patents we'll talk about that in just a moment privacy is very important quite a few
laws related to privacy and then import export controls which we'll cover also
so let's start by talking about types of law so you have three types you have criminal law which is just what you
think it is it covers areas like assault robbery arson murder you have
civil law which covers more business disputes contract disputes real estate transactions employment estate
the high dollar lawsuit type of law then you have administrative law which relates to government agencies they have
some leeway to enact administrative law that can cover important topics or areas as mundane as requirements when
procuring a phone for an office desk the the cissp exam focuses on security related generalities you're not going to
get into the nitty-gritty details of the law but when a question comes up around health care related information customer
health care information you'd need to know that high tech and hipaa are are laws related to that topic
for example so let's talk about some of the the laws that are likely to come up on the exam
so the computer fraud and abuse act i think the the most significant thing about cfaa was it was the first piece of
u.s cyber crime specific legislation you have federal sentencing guidelines which are laid out to provide punishment
guidelines to help federal judges interpret computer crime laws the federal information security
management act better known as fisma uh had some requirements around formal
information security operations uh for for federal government uh the copyright and digital millennium
copyright act say that three times fast covers literary musical and dramatic work so that that's really helpful for
artists let's talk intellectual property and licensing so you have trademarks which
cover words slogans logos you use to identify a company in its products or services you want to protect your
company name you apply for a trademark patents protect the intellectual property rights of inventors and trade
secrets cover intellectual property that is absolutely critical to a business and must not be disclosed for the health of
that business and then there are four types of licensing you should be familiar with
and that's contractual shrink wrap click through and cloud services
there are some regulations around encryption and privacy that you'll want to be familiar with
so u.s companies cannot export computer technology to certain countries and those include cuba iran north korea
sudan and syria there are also restrictions laid out by the department of commerce that detail
limitations on the export of encryption products outside the us the basis for privacy rights in the u.s
is the fourth amendment to the u.s constitution and gdpr is a law you want to be
familiar with it is not a u.s law it comes from the european union but it is very likely to be mentioned for one very
good reason and that is because it applies to any company with customers in the eu
the us included you're going to hear me mention this a couple of times that's because i do expect it will be on the
exam now let's talk about other u.s privacy laws so you've so when it comes to
health care you have uh health care insurance portability and accountability act better known as hipaa
you have the health info technology for economic and critical health uh better known as high tech
we have graham leech bliley which applies to financial institutions if you see a
question on the exam related to law and financial institutions i'd bet it's going to be graham leach blighly
the children online privacy protection app better known as coppa and the electronic communications
privacy act or ecpa and that's one of two laws related to electronic communications that i might
expect you'd see on the cissp exam the other being the communications assistant for law enforcement act
i think i'd be familiar with both of those as well now notice that i've put the acronyms here i find memorizing
these acronyms makes everything easier because memorizing all those words is a lot of work but if i memorize hipaa when
i see health insurance portability and accountability act i can pick out the h-i-p-a-a right so memorizing those
acronyms is going to make this a lot easier for you and you notice how i talked about just the very basic focus
of these laws you're really going to be dealing with generalities as i mentioned and that's straight from
the official cissp exam prep guide and matches right up lines right up with my experience in taking this exam
so you're going to be expected to be familiar with the business continuity planning process and issues that pertain
to information security in in bcp around things like strategy development processes
plan approval plan implementation training and education so so important you understand the steps
of the process but know that the bcp topics are going to cover you know information security related angles
you're not expected to be a certified business continuity planner here by any means
i'll give you that same warning i give you for any process when you're looking at a process make sure you you know the
steps in order personally i don't think you're going to see a lot about bcp on the the exam it'll be limited
i want to talk through a couple of business continuity planning related definitions worth knowing just to
increase your comprehension of this topic as we prepare for the exam so the business continuity plan is the overall
organizational plan for how to continue business the disaster recovery plan is the plan
for recovering from a disaster impacting it and returning the i.t infrastructure to
operation which of course supports the business and there's a continuity of operations
plan this is the plan for continuing to do business until the i.t infrastructure can be restored i'm not expecting you'll
hear about continuity of operations planned on the exam but it's
it is a thing so i wanted to mention it but let's talk about the difference between business continuity planning
and disaster recovery planning so what exactly is the difference here well business continuity planning focuses on
the whole business it focuses on getting back to doing business where disaster recovery focuses more on
the technical aspects of recovery so bcp will cover communications and process more broadly another way to think of it
is business continuity planning as an umbrella policy and disaster recovery planning falls under that umbrella as
part of the broader plan you want to be familiar with education so security awareness
education and training so the methods and the techniques for different audiences
periodic content reviews evaluating your program effectiveness and
and you can see a variety of questions here that talk about everything from you know simple user security awareness
training to you know what's the the deepest form of training so covering things like classroom training all the
way to degree programs but security awareness training is that topic that is ubiquitous when it comes
to information security so let's start with the consequences of privacy and data breaches the first
being reputational damage when we have a security breach it can certainly result in a loss of customer
trust and ultimately a loss of revenue and the effects may last for years if the situation is not handled correctly
identity theft which involves someone using a person's private information to impersonate that individual
usually for financial gain and if that breach results in data exfiltration were potentially exposing
many people to identity theft if we're losing customer data and if a business experiences
intellectual property theft as a consequence of a data breach they can lose customers credit ratings brand
reputation and they can even forfeit first to market advantage loss of profitability and they might even lose
an entire line of business to competitors or counterfeiters fines so failing to report a breach can
result in fines that can reach into the millions of dollars in fact gdpr outlines fines of up to four percent of
a company's annual global revenues or 20 million euros for failing to report a breach and it may lead to
lawsuits but remember any company with a customer in the eu is subject to gdpr
and let's talk notifications of breaches so if a data breach occurs failing to report that breach as i just mentioned
can result in fines into the millions of dollars the eu sets their standard in gdpr and notification of data
breaches must be reported within 72 hours now escalations to external sources like law enforcement or outside
experts to stop or investigate a breach may well be necessary other countries have their own reporting
time scale and delays may sometimes be allowed for criminal investigation
but we're talking about laws so when in doubt we get the legal department involved
and that brings us to the end of domain one up next is domain 2
asset security i want to touch briefly on what's new in domain 2 because we can expect those new
topics those new areas of focus in 2021 are more likely to come up on the exam we do find certification exams tend to
focus a bit more on what's shiny and new and relevant and here we see 2.3 provision resources securely 2.4
managing the data lifecycle and 2.6 determining data security controls and compliant requirements
drm casbi and dlp those were covered in the 2018 material clearly they've been elevated to some degree
here and in in a world of identity uh focused security and zero trust it's it's not
surprising right our network perimeter doesn't exist as it used to and you're going to hear uh provisioning resources
securely in various capacities through the eight domains managing the data life cycle is the the item i want to call
attention to in domain two so it was mentioned in a phrase in in 2018 it's clearly going to get a little more
attention so here is the data life cycle and you see it begins with creation then story use
share archive and destroy now i want to call your attention to
a similar life cycle that existed in 2018 and it exists in the 2021 version of the course in domain seven in
security operations we have the information life cycle and what you're going to see here are some commonalities
so you'll notice creation you'll notice archival and destruction
use usage and storage what's different here is you notice classification so so the information life cycle it focuses a
bit more on information protection because you don't see classification called out explicitly in the data life
cycle right so another item called out in in domain seven around the information life cycle that's important
for you to remember is there isn't a consistent standard used to identify each stage or phase of
a data life cycle so conceptually speaking what i would suggest you know for the exam is that immediately after
creation it's very important that we classify data because classification tells us the requirements for protection
and the other key elements that i want you to notice here is that each of these cycles includes
archival and destruction right so archival is important because certain regulatory requirements will demand that
we have data that we keep around for a period of time in a retrievable state it could be
a year it could be seven years and data destruction is important because data that remains around longer than is
necessary creates risk and it creates liability it can be stolen it can be called as evidence it can be discovered
as evidence for for legal actions so more than remembering the steps here i want you to remember those key
elements of of the data life cycle of the information life cycle the information life cycle is covered both
in domain 7 and it's also covered in the processes and frameworks video in depth but knowing these will serve you well
but you want to know those you want to be familiar with those practical elements
of of the data life cycle and later here in domain 2 we'll talk about data classification you'll see
this chart so you want to pay attention because data classification is going to have relevance in multiple domains in
the cissp let's start with data security control so
marking labeling handling and classification may well come up on the exam
classification being the most important of these and we'll talk about data classifications in just a moment
uh data handling shipping chain of custody you know remembering don't open boxes
and with data retention comes data destruction we'll talk through some data redestruction methods like erasing
clearing overwriting more on that in a moment and with record retention uh we always need to remember
that that data destruction if the retention policy is one year that data should be destroyed when it ages out so
when it ages beyond one year uh you may even see something related to tape backup this you know this feels like a
legacy concept but it may come up because it exists in the real world and and tape backup security having a secure
facility tapes labeled will ensure that you know everybody understands the classification of the data which really
kind of comes back to that first concept of marking labeling and handling
so let's talk about data destruction methods and you'll definitely want to understand
the difference between these so at a basic level erasing data which is just performing a
delete operation so with erasing you'll want to remember that data is typically recoverable using
traditional data recovery tools now clearing or overriding prepares media for reuse and ensures that data cannot
be recovered using traditional recovery tools so purging
is a more intense form of clearing and it's used in less secure environments
so why do i highlight less secure environments that's because for example the us government doesn't consider any
form of purging as an acceptable data destruction method for top secret data degaussing is a process that uses a
device called a degausser to create a strong magnetic field that erases data on on some media so so physical media
obviously and then destruction is the final stage in the life cycle of media and it's the
most secure method of sanitizing data methods of data destruction include operations like incineration crushing
shredding dissolving using a caustic or a acidic compound
and before we step away from data security controls i want to mention one other concept which is a security
control baseline which provides according to the the cissp exam guide a listing of controls that an organization
can apply as a baseline so listing of controls on a baseline it feels a little repetitive another way i might say this
is a baseline is a group of controls that can be applied as a base standard or a starting point that we work from
not unlike a configuration based line that you'd uh work with as a starting point for securing your endpoints for
example so for the exam do be familiar with record retention and data destruction i
mentioned that you know keeping data around for longer than necessary can can be a problem
what it can do is present unnecessary legal issues and in fact if memory serves the cissp
exam prep guide outlines a story with uh with a big aeronautical company that had a big lawsuit uh that they settled for a
lot more money than necessary because they kept data around for longer than necessary
so when it comes to data protection confidentiality is often protected through encryption this is mentioned
only briefly in domain two this is really more a topic for domain three so we'll cover encryption in lesson three
so let's move on to defining sensitive data through data classification so we're going to look at
the four levels of data classification for government or non-government or sometimes called
public data so we have class 0 which in government terms would be unclassified
or public data so no damage occurs if this sort of data is revealed
outside the organization class one is data that would be confidential or in the non-government space sensitive
so this is data that could cause damage to the organization if unintentionally disclosed
or intentionally disclosed for that matter but but disclosed without authorization so class two we have
secret data and private data data that can cause serious damage to the organization if disclosed and
then at the highest level in class three we have top secret data or confidential or proprietary data in
the uh the public space which is data that can cause exceptionally grave damage if revealed
so you'll notice some commonalities here the word serious and and then exceptionally
grave so you have these juxtaposed standards for government and non-government i would be familiar with
both of these uh briefly in domain three we'll actually talk about sensitive uh but unclassified data in uh when we're
talking cryptography but generally speaking i think much less likely to come up
on the the exam itself so when it comes to asset classifications asset
classification should typically match data classifications and when it comes to sensitive data
there are two types of data you want to be very familiar with and this is sensitive data that isn't public or
unclassified there's personally identifiable information or pii data pii data refers to any information
that can identify an individual so these would be uh data elements like their name social security number uh
birthplace or birth date biometric records uh you know thumb prints retina scans
and you'll also want to be familiar with protected health information or phi which is health related information that
can be related to a specific person this is covered by hipaa which we talked about in domain one
so let's talk about data ownership for a moment so know these two roles i think if if we you know think about what are
the roles most likely to come up on the exam data owner
which is someone who can delegate some day-to-day responsibility for for data handling and security and then there's
the data custodian so this is someone who doesn't decide what controls are needed but they do
implement those controls on behalf of the data owner so just a quick tip if the
question mentions day to day they're typically talking about the duties of the custodian and another sort of
delineating factor here the data owner is usually a member of senior management the data custodian is typically going to
be somebody in the it department so that's another way you can potentially pick out
which would be the the most appropriate answer so i want to talk to you about some
other roles and then gdpr in particular which which is you're relatively new in the world
of regulatory standards but i think more and more important all the time because it does apply to a lot of u.s companies
so let's talk about some of the other roles so do be prepared to answer questions on
some of these other roles so data administrators responsible for granting appropriate access to personnel often
via role-based access control a user refers to any person who accesses data via a computing system to accomplish
their work tasks and we have business or mission owners and this role can actually overlap responsibilities with
the system owner sometimes even be the same role and then finally asset owners this is
the person who owns the asset or the system that processes sensitive data and the associated security plans
i think the key there is associated security plans uh so let's talk about gdpr because gdpr
calls out some specific terminology relative to gdpr and they treat one or two terms a little bit differently than
you'll see elsewhere so definitely know your gdpr terminology and
requirements i think this is quite likely to come up on the exam so gdpr defines a data processor
which is the entity that processes data on behalf of a data controller that data processor can be a person an authority
an agency or another body it's but it's the person it's the entity processing the data on behalf of the data
controller who is that person or entity that controls processing
of the data and then data transfer know that gdpr restricts data transfer to countries
outside the eu okay continuing down this road so there
is some discussion in domain two around reducing your gdpr requirements or exposure so there are a couple of ways
you can approach this the first is anonymization which is the process of removing all
relevant data so it's impossible to identify the original subject or person so if done effectively gdpr is no longer
relevant for the anonymized data now it's important to note here the word remove the words removing an impossible
because this is only going to be good if you don't need the data because it will be impossible to identify the original
subject or person so i think that's one of the keys if this method comes up on
the exam so if you need the data there is another way to handle this and that's through
pseudonymization that's a big one so i'll say it one more time pseudonymization which is the
process of using pseudonyms or aliases to represent other data so you use this in scenarios where
you need that information but you want to mask the identity of the user or subject to which the data belongs
but you definitely need the data so an example of this would be creating a patient number to tie back to the data
which then masks the the name of the patient at that point but bearing in mind that you know this will potentially
reduce your exposure it will result in less stringent requirements than otherwise
would apply under gdpr but bearing in mind that if that pseudonym is ever revealed if that patient number is ever
tied back and revealed to the patient name then the pseudonym is no longer effective the alias doesn't
work anymore so it's a great concept but execution matters is my point uh so if you but you
but if you need the data and you want to reduce exposure pseudonymization is going to be the
method you'll use versus anonymization and for the exam i would make sure i'm familiar with the gdpr terminology the
data roles and the security controls and don't worry i'll mention these in more than one spot
in this course so you'll definitely hear this again and you want to be aware that the
notification of data breach timeline in gdpr is 72 hours and we'll see this again but just
remember gdpr applies to any company with customers in the eu
and that's a wrap for domain two moving on to domain three security architecture and engineering
let's take a look at the official exam outline and then we'll talk about what's actually new in domain 3 in the 2021
release of the exam 3.1 is research implement and manage engineering processes using secure
design principles 3.2 understand the fundamental concepts of
security models so we'll touch on models like biba the star model bella padula this is a big area of memorization this
is a common area of confusion and i have a full 2022 update i've recorded for you
here to address the many questions i've received about security models over the last year
3.3 select controls based on system security requirements so matching controls to requirements
understand security capabilities of information systems we'll touch on a number of concepts here including
items like tpm and encryption and decryption 3.5 assess and mitigate the
vulnerabilities of security architectures designs and solution elements
3.6 select and determine cryptographic solutions and then 3.7 understand methods of cryptanalytic
attack so this tells us that cryptography is really front and center in domain 3 just based on what we see in
3.6 and 7. 3.8 apply security principles to site and facility design an area very few
folks have much experience so an area you'll want to put some focus on for the exam
and finally design site and facility security controls so what's actually new in the 2021
release well domain 3 is a big domain and there are several changes here so
under item 3.1 which is research implement and manage engineering processes using secure design principles
we see several concepts here called out that were present in the 2018 exam threat modeling lease privilege defense
and depth secure defaults fail securely separation of duties however we see several net new concepts here as well
keep it simple zero trust privacy by design trust but verify and shared responsibility i'm going to
cover these for you now okay i'm going to cover these for you in
a minute because first i want to want to point out the other syllabus line item in domain 3 that is
new and that is 3.7 understand methods of cryptanalytic attacks and again
quite a large number of attacks mentioned most of these existed in the 2018
version of the exam it's clearly a topic that's getting more attention these are covered these attacks are covered in the
attacks and counter measures supplemental lesson they are also covered
in line in their specific domains uh where they were applicable and what do i mean by in the domains
where applicable well for example uh domain five is identity and access management we'll talk about access
control attacks in domain five but if you'd like to go through attacks and counter measures all in one setting
go check out that supplemental lesson and that will serve you well in fact there's the thumbnail you want
to look for on on that supplemental video in the playlist so let's get into some of those new
concepts that i mentioned are present in domain three we'll start with zero trust security which which is a strategy an
approach that addresses the limitations of the legacy network perimeter-based security model where the firewall was
the perimeter right so with with work from home mobile devices our users are everywhere right so really
xero trust security typically treats the user identity as the control plane so you'll hear it in in marketing documents
they'll say the identity is the new perimeter uh xero trust assumes compromise or breach in
verifying every request so basically no entity is trusted by default we're verifying identity managing
devices managing apps and protecting data in all phases of operation
so in that category of secure design principles secure default is called out in 2021 so this simply means default
configuration represents a restrictive and secure configuration and this should apply not only in your
own configurations within your organization but you should expect the same
of of your hardware software and and service vendors that their service their device their software is
is secure by default it's a reasonable expectation in 2021. fail securely which simply means that
when a component fails it should fail in a state that denies access rather than granting access
these two concepts are actually taken from from nist sp 800 800-160 trust but verify is a principle that
depends on an initial authentication process to gain access to the internal secured environment and then relies on
generic access control methods so due to changes in the threat landscape today this is no longer considered sufficient
and has largely given way to zero trust security so privacy by design comes up so making
privacy an integral part of every system your policies your design process the the best
guidance i can give you here comes from the international association of privacy professionals
who have published seven principles of privacy so privacy as a proactive
approach something we consider from the moment we are envisioning a new
service or product privacy is the default setting right it's not something that uh that has to be opted opted in
it's something you would you would want to to have folks opt out of so privacy is the default uh privacy should be
embedded in the design not bolted on later so it should be considered from the design phase uh principle number
four is that privacy should be a positive sum approach not a zero zom sum approach and you might be asking well
what the heck is is a positive sum approach a positive sum occurs
when an approach is formulated where the needs of everybody involved
are are met so so when we implement privacy in our design we as an organization
create a more effective more secure service and our customers benefit because we have considered their
privacy from the beginning so so another way of saying positive sum i i would say is that you're creating a win-win
scenario end-to-end full life cycle data protection right we talked about about
data life cycle so protecting our sensitive data making sure that after data is created it's
classified and protected super important visibility and and transparency there are many ways to facilitate
visibility and transparency for example if i'm a software company i have a privacy policy that explains to a user
what data i am collecting from that user and what i am doing with that data so so transparency can be communicated through
policy and implemented in features of of a service or software what have you and keeping privacy
user centric uh you know when i think about user-centric privacy i think about gdpr
so gdpr is the is the general data protection regulation it's the eu's uh data protection lawn and in gdpr
the user has the right to instruct me as a company to forget them so in gdpr regulations i do have to be
transparent in my privacy policies the user has the right to request all data that i have collected
about them and they have the right to tell me as an organization to forget them to
basically lose their information lose my number and again i think from a cyber security
perspective these are just sensible principles anyway so applying these principles and implementing a layered
defense defense in depth we'd call it as part of a zero trust strategy just ensures
uh privacy end to end so i think these are good principles that help you help you onboard
the concept of privacy by design keep it simple is not a new concept this is a concept that's been around for a
very long time and it applies to much more than just cyber security so bruce schneier
mentioned uh once upon a time that complexity is the worst enemy of security complexity
is the worst enemy of of many things and a simple design is the best design we justify uh the addition of complexity so
in the world of cloud and hybrid security services that leverage you know ai in the cloud machine learning a best
and sweet over best in breed approach is generally considered uh the best way to simplify defense in depth because the
security suites from the various uh cloud you know cloud focused security vendors
will incorporate layers of intelligence that
together are better in securing your environment and this simplicity also helps to avoid configuration mistakes it
means that your layers are going to be integrated better
uh it means that your overall solution is generally speaking going to be smarter it does not mean that you're
going to have only one security vendor it means that you will likely have fewer security vendors but you will have you
know some sort of suite that will serve as the foundation
for your organization and whether your foundation is based on on microsoft or google or cisco
or amazon that that's not so important as the concept in this case but this enables
organizations to move forward you know incrementally rather than demanding perfection it's really a a fresh
application of the classic keep it simple silly principle that's that's the the kiss principle that they taught us
when we were kids honestly when i was a kid it was keep it simple stupid but but we're we're more
polite now and so we we don't we don't say stupid but when i think about maintaining
simplicity in in designing a cyber security strategy
these are some tips that i think you'll find helpful but really never underestimate
the value of incremental improvement rather than demanding perfection out of the box because when we choose a best in
breed strategy and we try to go find the best vendor at every layer we spend a lot of time shopping we spend a lot of
time trying to determine how well those solutions integrate with one another becomes a lot of work a lot of expense
and a lot of complexity so security as a service uh this is a cloud provider concept where the
security is provided to an organization through or by an online entity this definition would be applicable to
all of those providers that i mentioned just a moment ago internet of things so these are a class
of devices connected to the internet to provide automation remote control ai processing in a home or business setting
we all have iot devices
plugs thermostats assistance speakers
you name it so so more scenarios involving iot devices are likely to appear on the 2021 exam uh smart devices
mobile devices that offer customization typically through installing apps and might use you know on device or in the
cloud ai processing there are all sorts of devices that can be considered
smart devices from smart phones to smart thermostats to doorbells to sensors used in manufacturing
scenarios to predict device failure before
a device fails and one would think generally speaking on the cissp exam
the context the examples around smart devices and iot will be more business focused than they would be
focused on home scenarios so next we're going to talk about sim and soar so sem is security information event
management so think of a sem solution as a system that's going to collect data from many sources within your network
it's going to take sign in logs for identity and access management it's going to take syslog and
common event format data from your network devices it's going to take event logs from your endpoint it's going to
take various bits of telemetry from security solutions within your environment and it's going to provide
real-time monitoring and analysis typically using ai and machine learning and and
yuba user entity behavioral and analytics and and to
give you uh notification of potential attacks so soar security orchestration
automation and response is centralized alert and response automation generally with threat specific playbooks and what
i mean by threat specific playbooks is the form of automation may be very different from different
vendors but the automation will be threat specific generally speaking
because specific threats require specific responses whether that's a particular type of of script or
automation tool and the response might be fully automated or sometimes you'll see these solutions come semi-automated
out of the box where where essentially the potential
attack is is identified and then the sore solution gives you the
you know click here to remediate sort of response and i soar is actually mentioned in
domain eight so why am i talking about it here well i'm talking about it here because sem and sore uh nowadays are
very commonly delivered together as components in a single solution so i wanted to talk about them in context
because the sem part of the equation is going to be doing the the monitoring the analysis and the
notification the soar is the response automation whether automated or fully automated or partially automated but i
wanted to bring this up earlier in the discussion because uh in terms of context it fits here better than in
domain 8 in my opinion so so you know on the exam you know you're not taking the the questions aren't
coming to you domain at a time so functionally speaking i just wanted to get this out in the open here now but
these solutions today are often going to use ai and ml and threat intelligence to uh
to come to their conclusions to it to aid in their analysis uh we'll talk about threat intelligence in just a
moment so micro services and service oriented architecture soa may come up on the exam
in 2021 so soa is the creation of discrete services that that can be accessed by users in a black box fashion
so basically we don't know what's going on under the hood soa is a concept that's a few years old you don't hear
near as much about it anymore it's really been superseded by microservices which are
fine-grained services with a discrete function i think of of microservices as a more modern adaptation of soa
that's better oriented to cloud computing many times you'll find micro services are built
in a fashion that they are containerized so they can run on a container platform like docker and
kubernetes and it's important that we we identify code level
vulnerabilities early in the development life cycle so before software is released
you can do this with a combination of static code analysis and dynamic testing basically early in your
integration and delivery process so we can identify deficiencies before the release so so another way to say static
code analysis is static application security testing
we're going to talk about that in the changes that come in domain 8 and dynamic testing also
dynamic application security testing so so we'll touch on those two in domain 8 in in greater
depth so containerization may come up on the exam and and this is really talking about technologies like docker and
kubernetes kubernetes really being the de facto industry standard now when it comes to
containerization so this is a lightweight granular and portable way to package applications for multiple
platforms and it's going to reduce the overhead of server virtualization by allowing a containerized app
to run on a shared os kernel so we can have multiple applications that are
containerized running on the same virtual machines containers don't have their own operating system
they are sharing the operating system of the container host on which they run which is going to be you know a linux
server typically or sometimes occasionally a windows server linux being the the more common uh container
host uh now when we get into that more granular level of
sharing an operating system we still have many of the same concerns we have around server virtualization in that we
need isolation for our applications you know at a host level at a process level at a network level at a storage level
and you can imagine in shared environments we might not be comfortable running
containerized applications in the same clusters and so you'll hear discussions around
not just logical separation but but physical isolation as well
and you know really devops security can is is really going to focus on the
container level we think about application level security so author authentication and authorization
we'll talk more about these as we move along here so application programming interfaces or
apis may come up on the exam with rest being the the modern standard for api development soap was the standard in
years past but an api is a set of exposed interfaces that allows for programmatic
interaction between services back in the early days of amazon
jeff bezos laid down a standard for his his technology groups that when they built a service they had to package that
service and make it available for other other teams of the products business units etc for for their consumption as
well so rest the modern standard i mentioned uses the https protocol for for web
communications to offer those api endpoints all your communication between client and server should be encrypted
and your access should be limited with api keys which means you also need to ensure that storage distribution and
transmission of those access keys is done in a secure fashion because that's effectively a secret if you've never
played around with an api you could go sign up for a developer account on twitter for example or facebook and
and get into an example of working with an api embedded systems another potential exam
topic uh coming uh about through the rise of the internet of things so so an embedded system is a technology
component of an iot device think of it as a full computer system embedded inside another larger system a
good example of this printers typically have embedded systems gps drones
semi-autonomous vehicles they have a full computer system that's embedded inside that larger
system and with embedded devices you'll need to consider authentication practices to
ensure they meet with security best practices you want to avoid implied trust
so high performance computing another potential exam topic so so this is an alternative to client server computing
for compute intensive operations with large data sets that typically require large-scale parallel processing the seti
project the search for extraterrestrial intelligence is a good example of high performance computing where individuals
can volunteer their compute time to help process data so grid computing which we which is
high performance computing we often see in a business setting employs a centralized controller that makes
computing assignments to grid members and in a grid computing example we have some security concerns particularly
around that grid controller making sure that that grid controller is safe from bad actors or that the grid can't be
used for illicit activities which means there needs to be some governance built in as to how
assignments are made and and what compute tasks can be assigned so edge computing may come up and and
edge computing really speaks to operations that require processing activities to occur locally
far from from the cloud so this is really common in iot scenarios the agricultural space science science and
space military i even see it in retail scenarios
fog computing places a gateway device in in the field to collect and correlate uh data
centrally at the edge so fog computing is kind of a nuanced version of edge computing
you know i can think of of an edge computing scenario like in uh watering plant in a field i have sensors iot
sensors that will uh you know sense the uh the moisture level and automate
watering so for for those types of operations to happen in a timely way i might need that to happen at the edge i
can think of retail scenarios where you go visit a kiosk in a drug store for example to order
uh you know especially uh you know crafted cards or photos right there at a kiosk edge
processing could be very important in a good user experience so with large you know network device
counts and varied locations you want to think about data encryption spoofing protection and authentication
to avoid bigger security problems because a large number of unsecured iot
devices can become somebody's bot army for distributed denial of service attacks
right now we're going to shift gears and we're going to talk about cloud computing which will definitely receive
more attention on the 2021 version of the exam so we'll talk about infrastructure as a service platform as
a service software as a service so i as pas and sas and we'll talk about private hybrid and public cloud
and we will talk about the shared responsibility model this is
going to be key for the exam so let's talk about shared responsibility so when we are on prem
responsibility for security is a hundred percent ours right all the way down to the wire in our data center we are
responsible now when we begin to consume services in a public cloud scenario
who's responsible for which components shifts and some of our responsibility is for security is shifted to the csp the
cloud service provider so in an is scenario infrastructure as a service think server virtualization running
virtual machines the the csp is responsible from the wire up to uh that virtualization host we are
really deploying virtual machines and configuring and consuming at that level we will have some responsibility for
specific types of configurations to ensure availability to ensure slas kick in
but but you see there some responsibility has shifted when we look at platform as a service
we see that we're giving up more responsibilities to the csp here as well think of
cloud database models if i'm hosting a database in the cloud
where i'm not responsible for the service that runs it you know beyond some some simple configuration of
my my database uh if i'm thinking about web applications or or functions that are hosted in a service
you'll notice here all the way up to the runtime belongs to the cloud service provider and in a database scenario i'm
responsible for my my data and the applications that are talking to my data if we think about software as a service
you know we're giving away more responsibility yet we're really just responsible for using and consuming the
service uh office 365 is a great example of this uh service now the uh the itsm platform great responsibility so you
notice as we move into the cloud we're handing over some of that responsibility for security and management to the csp
which is a good thing for us so just some examples here and some some details to help you cement the the shared
responsibility model so in the is scenario the csp the cloud service provider is providing the building
blocks like the networking the storage the compute they manage
the staff and the hardware and the data center for us right so so good examples of this azure virtual machines amazon
ec2 google cloud platform compute engine pass platform as a service the customer
is responsible for deployment and management of the app so that's we are the customer in that scenario
the csp manages the provisioning the configuration the hardware the operating system you know even more underlying
details good examples here azure sql databases azure api management azure app service which which is running web apps
again in a fashion where we're not worried about servers
so before we move on to software as a service i want to touch for a moment on the difference in responsibility and
functionality between serverless and platform as a service so so serverless may also be called function as a service
so so let's take a web application when i deploy a web application let's say i'm a restaurant and i have a web
application that has a menu function and an ordering function for example uh in in a a pass scenario i'm going to deploy
that application into the service i'm typically going to have to pick a service tier now in its paths it's
platform as a service so i'm not worried about servers or any of that but i'll have to decide if i want dedicated
environment i'll have to pick you know some service tier that gives me an idea of
scale now function as a service allows us to break this down one level even more granular
i'd say so let's say if i want to move my my
restaurant application into function as a service i might break that menu out as
as one function and then i break the ordering function out separately and i send that code to my function as a
service provider they handle the provisioning uh and they handle the scale so what it would do is allow the
individual components of my my application in that scenario to scale independently but in a function as a
service scenario i'm not worried at all about the scale the platform is handling that
behind the scenes for me so function as a service allows me to to make even fewer decisions around around
service tier and scale and so forth it's giving me a more granular way to to break that up
versus platform as a service which is a a level more granular than and less responsibility than infrastructure as a
service where we were handling virtual machines so different platforms have different
names for it so so microsoft for example in azure they call it uh it's azure functions in
aws on the amazon platform it's aws lambda i believe but but what they are both is event
driven serverless computing platforms all right so let's talk about software as a service so so in the
software as a service scenario we're handing even more responsibility over to the csp so in this case you know we as
the customer just config we just configure features right the csp is responsible for management
operation and availability of the service so good examples of of software as a service that you'd be familiar with
would include office 365 service now and and salesforce all right now i want to shift gears and
talk about cloud models for a moment and i just want to acquaint you with the differences between
uh public private and hybrid cloud models so we'll start with public cloud this is where everything runs
on the cloud provider's hardware so the advantages here would
include scalability we can scale infinitely in the cloud at least in theory right
greater agility because we don't have to make capital purchases
in order to deploy new infrastructure we can push a few buttons and deploy new
infrastructure in the cloud and what you're doing in a public cloud scenario is trading some
capital expense you know which would be investment in your data center for what we call operational expense so just
paying as we go for for services in the cloud for
infrastructure in the cloud so that that pay for what you consume model and
it allows us to to scale more easily more quickly less
maintenance and it lowers the skills bar because we don't have to have maybe quite
the same server expertise and network expertise in our organization so this is a great equalizer for smaller
organizations private cloud so this is a cloud environment in your own data center so
server clusters virtualization clusters you know maybe running vmware or hyper-v for example
the advantages here include that we have legacy support we have control over that environment we can establish
the conditions for regulatory compliance so really in private cloud if i had to put it in in a word it's really
controlled there because we when we're working in a a public cloud model you know typically you're working
on the latest version of a service in a private cloud scenario we can control the pace of versioning we can control
configurations to establish compliance for specific scenarios so when legacy comes up you know private cloud is a
good answer so hybrid cloud combines these two so it allows us to have the best of of both worlds so we can run our
applications in the right location if we need to support legacy for a time we can have a private cloud where we run those
applications if we have modern apps that we've containerized or that can run in a path or a serverless environment we can
run those in the public cloud and quite often you will find that the the private cloud in the data center
is connected to the the public cloud in some respects perhaps with with some sort of vpn
uh or or private network connectivity that connects the two
the two entities so you can have communication between them for example if you have
applications in the public cloud that need to talk to services in your private cloud so the hybrid
cloud allows you to move into cloud computing into public cloud at your own pace
so there i'm really speaking to the advantages the the main advantage is flexibility in in running our legacy
scenarios and dealing with specific compliance and scalability scenarios we can we can move it around pace which
allows us to to take on that additional work whether that work is migrating an app or recoding an app
we can take on that additional work at our convenience
so a cloud access security broker or casbi for short may come up on the exam this was a topic in
the 2018 study materials i expect it gets more attention in 2021 due to the rise of cloud computing so
a casby is a security policy enforcement solution uh so we can enforce policies like ensuring
that users only use the approved applications we have in place we can prevent
information sensitive information from being shared externally from being stored in
cloud storage repositories that we don't approve casbis very widely in their
functionality the casby industry came about to solve one problem and that is the problem of shadow i.t
uh the the scenario where organizations business units within organizations would would go out and
find they would work around the i.t department to find applications or
services to help them get their job done and they would they would purchase those on their corporate cards for example and
have a whole new way of doing things in some cases that the i.t department didn't
have any control over any any governance over or knowledge of but but when you're thinking about casbi think security
policy enforcement and think shadow it prevention so word has it the 2021 version of the cissp exam may bring
questions about post-quantum cryptography and quantum resistant algorithms so what is post-quantum
cryptography exactly well it's the development of new kinds of cryptographic approaches that can be
implemented using today's conventional computers but
that will be resistant to attacks from tomorrow's quantum computers so first two questions that come to mind are
which algorithms are susceptible and which algorithms are resistant well let's start by
looking at the two classes but first let me give you a quick disclaimer here so number one i am not a professional
cryptographer nor am i a professional cryptologist however i'm
providing you information from solid authoritative sources including the likes of bruce schneier who you may know
as a well-known public cyber security figure he also happens to be the creator of the blowfish in two fish
cryptographic algorithms and joel allen who's a pretty widely published cryptographer who who put some
focus in the area of quantum and i'll have links to to both of their articles in the video description if
you're interested in reading further but moving forward how well do current encryption
algorithms hold up to the power of quantum computing so let's take our our two major types here
symmetric which is which is shared key cryptography and then asymmetric or public key so symmetric the shared key
is what we use for bulk encryption of data and asymmetric has uses like key
exchange and digital signatures so symmetric holds up fairly well to quantum computing and we'll we'll
explore that more in just a moment where quantum poses more immediate threats to asymmetric so let's unpack
symmetric first so grover's algorithm shows that a
quantum computer speeds up attacks to effectively have the key length grover's algorithm is a quantum
algorithm for unstructured search that basically with a very high probability can identify the unique input for a
given output and basically that would mean that a 256-bit key is as strong against a
quantum computer as a 128-bit key is against a conventional computer and so you may ask
yourself wait a minute uh i'm a quantum computer is only twice as powerful as a conventional no a
256-bit key is not twice as strong as 128 bit the 256 bit key is 2 to the 128 times as
strong because doubling your length increases the possible combinations
exponentially so let's talk about asymmetric so public key cryptography so on this side we have
shores algorithm which is a quantum algorithm for integer factorization can easily break all of the commonly
used public key algorithms based on both factoring which means rsa is vulnerable because
that rsa depends on factoring of large primes and the discrete logarithm problem which
means that elliptic curve is vulnerable because that's the problem it's based on so schneier points out that doubling the
key length in the asymmetric scenario increases the difficulty to break by a factor of eight which is not a
sustainable advantage so the good news uh for the future here is that lattice offers some resistance and some real
promise for quantum resistant algorithms so it's based on different types of problems the the shortest vector problem
and the closest vector problem uh and and according to allen
uh it potentially enables us to replace essentially all of our currently endangered cryptographic schemes
and lattice-based cryptographic schemes make up the lion's share of scientific publications on post-quantum
cryptography and this bit of information comes from from nist's post-quantum cryptography
competition which they announced in 2016 and in july of 2020 so last year nist announced uh round three
finalists and the bulk of the finalists are in the of the lattice type
and that is to say your research selection and standards development is is ongoing
and you might ask yourself what exactly is a lattice well a lattice is a three-dimensional array of regularly
spaced points an example of a lattice is the the image you see right there so for the exam if you see a question
asking for which types of public key algorithms are quantum resistant the answer is lattice so that's it for
domain three quite a lot of potential uplift there in prepping for the 2021 version of the the cissp
so now we'll get into the rest of domain three so let's
talk cryptography so codes versus cipher so code are are systems of symbols
that sometimes uh imply secret but don't always have to be secret they don't always
provide confidentiality ciphers on the other hand are meant to hide
the true meaning of a message so codes are sometimes secret but don't always provide confidentiality
ciphers are always secret confidentiality is always going to be implied there
so you do need to know the types of ciphers that are out there so
stream cipher number one a symmetric key cipher
in a stream cipher your your plain text digit is encrypted one at a time it's a stream so to speak because it's not a
block of data so where a stream cipher goes one character at a time a block cipher will apply the key in algorithm
to a block of data like 64 contiguous bits for example so basically as a group rather than one bit at a time so that's
the fundamental difference between a stream cipher and a block cipher a substitution cipher uses the algorithm
to replace each character or bit of the plain text message with a different character
this might be as simple as just shifting the letters of the alphabet so one letter represents another letter i could
shift characters three to one direction so the letter d
represents the letter a for example julius caesar actually developed one of the earliest ciphers of this type that's
now known as the caesar cipher transposition uses an encryption algorithm to rearrange the letters of a
plain text message forming the ciphertext message and the initialization vector iv is a
random bit string that's xored with the message reducing predictability and repeatability now the size of this
initialization vector varies by algorithm but it's normally the same length as the block size of the cipher
or as large as the encryption key really what this is is the cryptographic
version of a random number that's injected into the process prior to the xor
so caesar vigenere and one time pad are three very similar stream ciphers and the main difference between these
ciphers is key length so caesar shift cipher uses a key length of one
vigenere uses a longer key usually a word or a sentence and the key length in a one-time pad is the same length as the
message itself now we need to talk a bit more about one-time pad i do expect you're
going to see at least a question on this on the exam so
for a one-time pad to be successful the key must be generated randomly without any known pattern
and it has to be at least as long as the message to be encrypted because remember that's what what differentiates one time
pad from visionaire and caesar so the the key is the same size as the message itself and
the pads must be protected against physical disclosure you can't give away the secret right
and each pad must be used only one time and then discarded because repetition could reveal
the answer right so basically all of these must be true for a one-time pad to be successful
so a concept here zero knowledge proof so this is a communication concept and and basically
zero knowledge proof is a specific type of information that's exchanged but no
data is is actually transferred this is true with digital signatures and digital certificates
so what the heck does that mean let me give it to you in plain english to just put it simply
zero knowledge proof enables one to prove knowledge of a fact without revealing the fact itself so
that's in effect what digital signatures and certificates allow us to do split knowledge
so split knowledge means that the information or the privilege required to perform an operation is divided amongst
multiple users that makes sense right splitting the knowledge amongst multiple people
so this ensures that no single person has sufficient privileges to compromise the security of the environment it's
it's separation of of the knowledge of the privilege i kind of think of of split knowledge as
role separation of a fashion really we talk about role separation in the workplace
so one person doesn't have too much privilege that they can carry out some sort of internal threat all on
their own another concept work function sometimes called work factor
so this is a way to measure the strength of a cryptography system by measuring the effort in terms of cost and or time
to decrypt the message so that the the cost or time to decrypt the message speaks to the value of the
function so usually the time and effort required to perform a complete brute force attack against an
encryption system is what a work function rating represents so
so the security and protection offered by the system is directly proportional to the
value of the work function or or factor would you like that in plain english i
hear you it's the time and effort required to break a protective measure that's that's
the work factor so when you hear work work function or work factor think time and effort required to break
a protective measure so the importance of key security so cryptographic keys
provide a necessary element of secrecy and uh modern systems utilize keys that are
at least 128 bits long to provide adequate security and that number is going to increase over time in fact when
we see the rise of of quantum computing as a mainstream capability uh that's going to change everything
about cryptography we're going to see a a massive shift in this space
but know that 128 bits is our low water mark so to speak when it comes to key length in
modern cryptography so symmetric versus asymmetric
cryptography so symmetric relies on the use of a shared key so a shared key
versus asymmetric where we have public private key pairs for communication between
parties so the difference between the two number one symmetric key lack support for scalability it's it's not
easy to distribute the key because we only have one key how do you transmit that key
secretly you know confidentially between two two people and we don't have a way to implement
non-repudiation there so we can't guarantee the the source of the message now
asymmetric on the other hand basically gives us that capability to implement a
solution that guarantees we know who that message came from but it also makes it easy to distribute that key amongst
many parties because we have private and public key pairs to to work with
stick with me and here in about five minutes we'll actually walk through an asymmetric example so you can see how
the public private key pairs are used in a scenario to
implement non-repudiation but also to transmit data confidentially
but symmetric cryptography is going to be faster since we have that shared key asymmetric is
going to be stronger and and more scalable generally speaking
so so when you think symmetric that's single shared key and it's faster and asymmetric is a private public key pair
that's going to be stronger than asymmetric so to speak so
confidentiality integrity and non-repudiation of three concepts you'll definitely need to know for the exam so
confidentiality is really focused on the secrecy of data
both you know while it's in rest or while it's in transit
integrity basically provides a recipient with an assurance that the data wasn't altered
that the integrity of the data remains that the data we received is the data that was sent in other words
and non-repudiation gives us undeniable proof that the sender of a message
is the one who actually authored it it basically prevents the sender from subsequently denying that they sent the
original message which is fantastic in certain circumstances so you need to be able to explain the
five basic operational modes of data encryption standard des and triple desks so i'm going to cover these for you in a
way that i hope is is easier for you to remember because just looking at them on the surface they're not
just super super easy to remember they don't stand out so the first is electronic code book mode so this is
the least secure of the lot and with code book mode it processes a 64-bit block the problem is
if it encounters the same block multiple times it produces the same encrypted block which makes it easy to break so i
like to say this code book is pretty easy reading cipher block chaining and in cipher
block chaining each block of encrypted text is exhored with the block of ciphertext immediately proceeding so the
previous link in the chain so to speak cipher feedback
is basically cipher block chaining in a streaming version it's going to work on the data in real time in memory but but
do remember when chaining is involved errors will propagate that's that's a key factor to associate with cipher
block chaining and cipher feedback is when they use chaining errors propagate but cipher feedback is basically
cipher block chaining in a streaming version working in memory buffers now the next one output feedback works a
lot like cipher feedback but it exerts the plain text with a seed value which means we're not using chaining anymore
it's using a seed value instead of that immediately preceding ciphertex so no no chaining means errors don't propagate in
this case and then another variation of that is is counter which uses an incrementing
counter instead of a seat and again you know using that increment encounter is pretty pretty easy
to uh to tie to that fifth mode and then uh how is triple dez different well triple
des uh runs dez three times with uh with two or three keys different keys to increase
the effective key size to 112 or 168 bits respectively so let's talk about exclusive or xor i
said we'd get to this here we are so so this is a concept that's used pretty heavily in cryptology it's a lot
more complicated than it sounds it's actually just a flipping of bits in a pretty simple systematic fashion so
you're looking at my table here you have the original value the key value and the cipher value what you're looking at here
is when the the binary values match so when the
original and the key value match you get a zero when they don't match original and key value don't match we get a one
simple as that so that's xor exclusive or so key clustering is a weakness in
cryptography where a plain text message generates identical ciphertext messages using the
same algorithm but using different keys i'll tell you how i remember this one i think of key cluster as being similar to
collisions in hashing so hashes have a collision when two different strings produce the same hash
collisions are exact exactly why md5 isn't used as a hashing algorithm anymore so with key clustering
basically it's when two different keys using the same algorithm produce the same ciphertext so it's similar to
collision in that respect so now we're going to talk asymmetric cryptography or public key cryptography
so on the asymmetric side of cryptography of public keys that are going to be shared
amongst communicating parties so if you and i are going to communicate and share secrets you can
see my you have access to my public key and i have access to yours my private key
is secret only i know my private key and in your case only you know yours and
in terms of data to encrypt a message you each can use the recipient's public key so i can use your public key
to encrypt a message and then you can decrypt it using your own private key
and with a digital signature to sign a message you're going to use your own private key
which gives us non-repudiation it ensures that if i sign a digitally signed a message
with my private key it ensures that it was sent by
me and to validate a signature you'll use my public key
so asymmetric and symmetric can work together in the sense that remember symmetric
cryptography is is fast right so we can use asymmetric cryptography to securely transmit the shared key we're
going to use in symmetric cryptography so essentially asymmetric
solves three problems one of which is distribution of of a secret and with symmetric that's
that's a problem right sharing that key amongst many parties on the symmetric side would be really difficult so that's
where asymmetric can help out so just remember each party has both a private and public key
so let's look at a simple example we have franco and maria so franco sends a request to maria requesting her public
key maria sends her public key back to franco remember your public key is
shared with all and franco is going to encrypt his message using maria's public key and she's going to decrypt the
message using her private key as simple as that and the contents of that message could be anything including but not
limited to a key a shared key to be used in a symmetric crypto function
so hash function so a good hash function has five requirements has to allow input of any length
and it has to provide fixed length output that is to say no matter how long the input the output must always be the
same length the hash must always be the same length it has to make it relatively easy to
compute the hash function for any input so it needs to be relatively fast in that respect it has to provide a one-way
functionality in other words it can't be reversed or a hash function that's easily reversed a two-way functionality
would not be so simple and it has to be collision free
collisions are exactly why the md5 protocol is not why md5 is no longer used as
a hashing algorithm so a collision in hashing means that we could put two different inputs through a hash function
and it would generate the same output meaning we can't then determine reliably what the original
value was that's exactly why md5 is not used anymore let's talk about cryptographic
salts so attackers may use something called a rainbow table it's a table of
pre-computed values to to try to identify commonly used passwords and a salt is random data that's used as an
additional input to a one-way function that hashes data password passphrase whatever
and and because we're injecting random data adding salts to passwords before hashing them reduces the
effectiveness of of the rainbow table attacks because the attacker doesn't know what
additional random data has been injected before the hash so digital signature standard
so dss uses sha one shot two shot three message digest function functions uh it used to use sha-1 generally speaking
shot 2 is going to be more common now the sha-2 is approved with dss and it works in conjunction with
one of three encryption algorithms so it would work with a digital signature algorithm or dsa
an rsa algorithm or elliptic curve dsa so public key infrastructure so this is
the certificate server that you'd see commonly in an enterprise environment so certificate authorities are sometimes
called certification authorities generate digital certificates that contain public keys of system users
every certificate has a public key and a private key to be clear and the users can distribute the
certificates to people with whom they want to communicate and the recipients verify a certificate
using the ca's public key so so that's how one can establish a chain of trust back to the issuing certificate
authority so it all goes all the way back to the the root certification authority so
in pki you'll sometimes have tiers of servers and you'll have an issuing authority
but you'll have a root authority at the at the base of the the infrastructure oftentimes
that root authority is is maintained offline but it's using uh asymmetric in that case certs are
used for web network and email security pretty commonly so in fact let's talk about web network and email security so
an email pretty common standards for encrypted messages include s mime and pretty good privacy
on the website of the house the de facto standard is is http over tls transport layer security which has largely
replaced the older ssl standard that was in use for a lot of years then on the network side i the ipsec
protocol is is pretty pretty standard framework used for encrypting network traffic uh you may actually see a bit uh
uh additional uh in terms of questions on on ipsec so let's talk about ipsec at
some greater depth here so ipsec is a security architecture that supports frame secure communications
over ip and it establishes a channel in one of two modes transport mode or tunnel mode
and it can be used to establish direct communication with computers over or over a vpn so i've seen ipsec used
between computers without a vpn vpn is a very common use of ipsec though
the windows operating system has has capability to do uh you know ipsec between computers without a vpn but you
can also establish a vpn and it uses one or two protocols authentication header and encapsulating security payload
all right common cryptographic attacks just a couple here you should be familiar with for sure from uh from
domain three brute force attacks which are attempts to randomly find the correct cryptographic
key so it's just using brute force of of computing power
with known plain text and chosen cipher text to but it requires the attacker to have
some extra information there's a meet in the middle attack which exploits protocols that use
two rounds of encryption so it's going to exploit some weaker protocols and it require requires the attacker to know
something somewhere around at least eight bytes
of uh of a message so so if uh an attacker knew the parties involved and weaker
protocols were in play here i mean the middle attack might be possible but but it uses
looking for those two rounds of encryption would be the key i'd remember for the exam in case this comes up man
in the middle attack you'll hear a lot more about this this fools both parties into communicating with the attacker in
the middle instead of directly with one another so each side actually thinks they're communicating with one another
but instead they're communicating with the man in the middle and a birthday attack is an attempt to find collisions
in hash functions and and remember a collision in a hash
function is when a hash function can receive two different values but
generates the same output that's a collision then a replay attack is an attempt to
reuse authentication requests so basically to get uh the uh the
the the hashed um output of the the authentication request and to present that um so that's
actually uh pretty pretty common so digital rights management you hear
this a lot in the entertainment world so it allows content owners to enforce restrictions
on the use of their content by others so this used to be a a big deal in the entertainment world with uh with
music back in the day it's occasionally found in the enterprise protecting sensitive information stored in in
documents but the entertainment content is where where drm was always a big discussion
and nobody was ever very happy about it so let's talk about symmetric algorithms if you haven't watched my my
video on memorization techniques for cissp you get a taste of them here so so i like to break my cryptography down in
a process called chunking so i start by breaking it down to the types of algorithms i need to remember because
this is the most uh technical topic on the cissp exam and it's a big topic so let's look at
symmetric algorithms here so you need to remember these you need to know the block size
i'd try to remember the key size as well and and remember you know symmetric from asymmetric so so
looking at this table i see i have a big chunk of of algorithms here that have a 64-bit block size
including blowfish the uh the the des family the uh
rc two through five so one of the tricks i use here so i i tied
blowfish and skipjack together i remember that they're both 64-bit because blowfish
and skipjack are both fish okay you're asking what the heck is a skipjack
this is a skipjack it's a tuna i i've lived near the coast many times so i happen to to know that
and because i know blowfish and skipjack are both the 64-bit block size remembering two fish is easy for me
because one fish times two is two fish right so that's 128 so two fish is going to be
a little more advanced in that respect and i know that aes is used commonly in the enterprise so that's advanced as
well so i just kind of tie those together that the advanced family has a 128-bit
block size uh and rc-5 has
three different options there but but i remember that the the greatest is the the 128 so then you just half that and
then half again to get your three rc5 algorithms and then streaming you know doesn't have the
block size right it's doing it piece at a time as it streams okay hash algorithms we've talked about
these a lot today right so these are easy to break down so i break the md5 family down so that's message digest
mdmd24 and five all have a hash value of 128. also notice that none of those are still in
use remember i mentioned md5 which is the the newest of the three you see there
none of those are still in use they were replaced by multiple other functions and then you have the shaw family and
the shaw family is easy to remember here because uh the and these are this is secure hash
algorithm so you'll notice that with the shaw family that the name maps to the uh the hash value link so so all of
those shaw 224 through 512 these are these are sha-2 variants and uh and essentially
the the hash value shows up in the name and and shaw one's not really in use anymore but the sha-2 family are still
actively used so make sure you you're going to break out md the md family and the shaw families and remember those
the three major public key crypto systems so you have
rsa which is probably the most famous it was it was developed by three folks back in the 1970s
you have elgamal which is actually an extension of diffie-hellman key exchange and it depends on modular
arithmetic so with rsa i tie rsa back to the uh to prime numbers so rsa involves the
difficulty of factoring the product of prime numbers diffie diffie-hellman relies on modular arithmetic
it's less common than rsa in the last few years but elgamal is based on diffie-hellman and then elliptic curve
depends on the elliptic curve discrete logarithm problem and it's going to provide
more security than other algorithms when both keys are of the same length
but but rsa i think is the the most famous of these and the most likely to come up on the exam but try try to kind
of tie some of these key facts about these three into your head so you can pick the right one out should a question
come up so digital signatures so digital signatures rely on public key
cryptography and hashing functions so so digital signatures have to use shot two nowadays
and there are three currently approved encryption algorithms for digital signatures you've got dsa
you've got rsa and you've got elliptic curve dsa and here's the table of asymmetric
algorithms we just covered i don't have any memory devices for you here because this is a fairly short table so you have
rsa diffie-hellman elgamal and elliptic curve remembering that elgamal is based on diffie-hellman key
exchange so as you're preparing for the exam i'd suggest you just chunk these out and focus on asymmetric and then
symmetric and hash each separately and it'll be a little easier i think to get those organized in your mind for game
day now we're going to talk through security models and this is an area i expect
you'll need to spend a fair bit of time and study and memorization before you take the exam it's certainly a frequent
source of questions from exam candidates this is my 2022 approach to security models in an effort to answer some of
those questions proactively so i hope it's helpful we'll start with the million dollar question what is a
security model well security models are used to determine how security will be implemented what subjects can access the
system and what objects they will have access to so remembering that subjects think of
those as the people and objects as the resources they will access and where do security models fit in the
big picture well they are a way to formalize security policy as you see in the visualization
to the right there they're typically implemented by enforcing integrity
confidentiality or other controls so you'll see these models focus on one of those three typically
and each of these models lays out broad guidelines they're not specific in nature
it's up to the developer to decide how these models will be used and integrated into specific designs as you can see in
the visualization on the right so to state it another way briefly here
what is the purpose of the security model it provides a way for designers to map abstract statements into a security
policy again it determines how security will be implemented what subjects can access the
system and what objects what resources they will have access to so the state machine model
describes a system that is always secure no matter what state it's in it's based on the computer science
definition of a finite state machine a state is a snapshot of a system at a specific
moment in time all state transitions must be evaluated and if each possible state transition
results in another secure state the system can be called a secure state machine
an information flow model focuses on the flow of information and information flow models are based on
a state machine model so biba and bellapadula are both information flow models these are two
security models we'll talk about in just a moment below padula focuses on preventing
information flow from a high security level to a low security level whereas biba
focuses on flow in the opposite direction from low to high you'll find that biba and bella padula are opposite
in their characteristics in a couple of respects the non-interference model is loosely
based on the information flow model it's concerned with how actions of a subject at a higher security level affect the
system state or the actions of a subject at a lower security level
it ensures that the actions of different objects and subjects aren't seen by and don't interfere with other objects and
subjects on the same system and a lattice-based model is based on the interaction between any combination
of objects like resources computers and applications and subjects such as individuals groups
or organizations lattice-based models are used to define the levels of security that an object
may have and a subject may have access to and you'll see lattice-based models in
bella padula and biba which we'll touch on in just a moment so three properties that will be
mentioned repeatedly when talking about security models are the simple security property which
describes rules for read operations the star security property which describes rules for right
and the invocation property which are rules around invocations calls such as calls to subjects
i mentioned security models are focused on enforcing integrity confidentiality or other control so
let's break these models out into the appropriate category based on their focus to make them a little easier to
remember so we have biba which is built on the state machine concept it's an
information flow model and it focuses on flow from low to high you'll hear the phrase no read down no write up
associated with biba more on that in a moment the clark wilson model which features
the access control triple go gwen massigure the non-interference model
and the sutherland model which is also focused on preventing interference and based in information flow and the state
machine concept bel la padula which falls into the confidentiality category
and it's focused on flow in the opposite direction of biba with bellapadula we're focused on flow from high to low and
you'll hear the phrase no read up no write down with bellapadula we have brewer and nash this model is also
referred to as the chinese wall take grant a model that employs a directed graph
and bel la pajula is a model used in government circles most of the rest of these models are used in
the commercial space so another difference you can park in the back of your mind and with clark wilson you see
i mentioned the access control triple that's the defining characteristic there so if you see a question on the exam
that mentions the access control triple you're going to know that it's definitely clerk wilson
so bel la padula mentioned this is based on the state machine model it enforces confidentiality
it uses mandatory access control to enforce the dod multi-level security policy
so government again the simple security property which is the read property the subject cannot
read data at a higher level of classification that is the no read up and the star property remember is the
right property a subject cannot write info to the lower level of classification so
no write down so in a
sensitive information scenario a worker cannot read data at a higher level of classification nor can they
down classify data by writing it down to a lower level this is lattice-based multi-level
security policy so another way to look at bellapadula i'm just going to give you a visual
memory anchor here no read up no write down i had a student give me a mnemonic they used to remember this no running
under nets with dingoes if that helps you have at it
so bel la padula if we just look at it in another way here i'm looking at information classifications from
unclassified at the lowest level of sensitivity to top secret at the highest level of sensitivity we have our read
and our right property so the subject cannot read classifications
uh cannot read information at higher classification so that's no read up and they cannot write data into a lower
classification so no write down it's enforcing confidentiality biba
is another lattice-based model developed to address concerns of integrity so the simple integrity property the
subject at one level of integrity is not permitted to read an object of lower integrity so no read down that is the
read property then the star property which is the right the object
at one level of integrity is not allowed to write to an object of higher integrity so no
write up and the invocation property prohibits the subject at one level of integrity
from invoking a subject at a higher level of integrity
so remember the simple property is read the star property is right using the same visualization we used for
bel la padula with biba the subject cannot read lower classifications no read down and the
subject cannot write data to higher classifications no write up so biba focuses on the flow
of low to high so clark wilson is a model that uses security labels to grant access to
objects constrained data items in the clark wilson model are any data item whose
integrity is protected by the security model an unconstrained data item is not controlled by the model
an integrity verification procedure is one that scans data items and confirms their integrity
and transformational procedures are the only procedures that are allowed to modify
a constrained data item i mentioned clark wilson features the access control triple which you'll see
in the ninth edition of the official study guide is now termed the access control triplet updated language for the
same concept no worries there so this features the concept of an authenticated principle a user think a
subject and then a program that's our transformational procedure in this
example the only procedure allowed to modify a
constrained data item and then we have our data items the unconstrained data items and the constrained data items
think of those as the the object so the access control triplet refers to that relationship
between an authenticated principle the set of programs the transformational procedures
that can operate on a set of data items the cdis and udis the constrained and
unconstrained data items touching on a few other models here we have the take grant model which i
mentioned is a confidentiality based model it supports four basic operations take grant create and revoke
the brewer and nash model the chinese wall it's called that was developed to prevent conflict of interest problems it
is confidentiality based the graham denning model which uses a formal set of protection rules for which
each object has an owner and a controller now it's focused on the secure creation
and deletion of both subjects and objects and it's a collection of eight primary
protection rules or actions that define the boundaries of certain actions remember i mentioned models focus on
integrity confidentiality or other controls those eight rules of graham denning
revolve around secure creation and deletion of objects and subjects those are our first four rules and
the second four of the eight are about securely providing access rights read
grant delete and transfer of access rights all right
so security mode so it starts with dedicated mode so security clearance permits access to
all information processed by a system approval for all and valid need to know for all so that's dedicated mode all all
right access approval and need to know multi-level mode on the other hand can process information at different
levels even when all system users don't have the required security clearance to access all
information processed by the system so there are some distinctions there so the key there is when when all users
don't have the required security clearance multi-level mode can be very useful
system high mode requires that each user have valid security clearance access approval
for all information processed by the system and valid need to know for at least some of the info on the system
this this offers of all the models this offers the most granular control over resources
and users and then there's compartmented mode which goes one step further than system
high and in compartmented mode each user has to have valid security clearance and access approval for all
info based processed by the system but it also requires valid need to know for all info so that's how compartmented
varies from system high is that it requires valid need to know for all info as opposed to uh to only some
so so before it gets away from me let's talk about the uh the state machine model uh which i said those security
models that we talked about a minute ago are based on so a state machine model describes a system that's always secure
no matter what state it's in so it's based on the computer science definition of a finite state machine
so a state is a snapshot of a system at a specific moment in time and all your state transitions the transition from
one state to another has to be evaluated like the transition from onto off for example
but if each possible state transition results in another secure state then a
system can be called a secure state machine so that's the key
and an information flow model focuses on the flow of information information flow models are actually
based on a state machine model so biba and bellapadula are both in both information flow models remember they
were looking at no read up no write down they're talking about the flow of information in read and write to
simplify that bill la padula in preventing information flow from a high security level to a low security level
right remember it was no right down and
biba focuses on flow from low to high remember no write up so so bella
padula focuses on enforces confidentiality biba focuses on integrity integrity
all right trusted computing base you're going to expect it to be able to define a trusted computing base which is a
combination of hardware software and controls that work together to form a trusted base
to inform your security policy it's a subset of a complete information system it's it's the portion that can be
trusted to enforce your security policy to to always adhere to your security rules now security perimeter is another
topic that may come up on the exam you'll be expected to know what that is a security perimeter is an imaginary
boundary that separates the the trusted computing base from the rest of the system from from the
not secure parts of the the system so a trusted computing base has to create secure channels trusted
paths to communicate with the rest of the system and then it protects users from
compromise essentially so reference model and security kernel two two concepts that will come up on
the exam potentially as well so the reference model reference monitor rather is the logical part of the trusted
uh computing base that confirms whether a subject has the right to use a resource
prior to granting access and the security kernel is a collection of
trusted computing based components that implement functionality of the reference monitor so security kernel implements
access control and ref reference model enforces it generally basically if we boil it down
hopefully that helps kind of solidify that a little more simply than what uh what the official text will tell you
so domain three includes some drill down on three sets of evaluation criteria
designed to evaluate uh the security criteria around systems and products the first of these is iso iec
15408 also known as the common criteria this was established to enable objective evaluation around a product or a system
based on a defined set of security requirements okay this is really the gold standard so you're also going to
see mentioned trusted computer system evaluation criteria which is an earlier system for
evaluating computer security and then you'll also see information technology security evaluation criteria which was
actually an attempt uh to create a security evaluation standard in europe basically though the common criteria has
replaced both uh the trusted computer and information technology standards there so tc sec and
itsec have been supplanted by common criteria so that's where you're going to want to put your focus you can't forget
about these other two entirely i'll explain why in a moment first though i want to drill down and break down common
criteria for you just a bit i want to give you a quick visual of common criteria as a process so it starts with
a description of the assets that we need to evaluate and then identifying the threats to
those assets the potential threats and then analyzing and rating those threats quantifying prioritizing
and based on the output of those first three steps then determining what our security objectives are for the for the
situation for the product or the the the system that we're dealing with and ultimately establishing our functional
requirements so really what you have here amounts to a five step process
that you could then repeat and refine as necessary so you're making some assumptions establishing security
policies based on the assets you're dealing with and the threats to those assets
you're performing some risk analysis and then
establishing your objectives based on on the system you're evaluating in the environment that it's going to operate
and there are actually two flavors of common criteria there's the community protection profile or cpp
which i think you're going to see a little less on on the exam it comes with it's a black box system that comes with
pre-defined requirements or or let's call them standardized sets of requirements where whereas the eal the
white box flavor allows for greater scope and flexibility in defining the the set of claims now the the study
guide says that you will need to be prepared to list the classes of tc sec itsec and
common criteria so these are the the levels of each of those systems now remembering that tc second itsec are
legacy right they've been supplanted they've been replaced by common criteria uh the official study guide calls out
the evaluation assurance level the uh the eal the white box uh version of uh of the levels and they're listed for you
here and i'm also going to put them for you here with a tighter description
according to the common criteria from eal0 up to eal7 with eal7 being the
more mature end of the scale so so as i mentioned you
it's called out that you should be prepared to lift the levels within these three
different standards for evaluation criteria but if i were going to prioritize my effort i'd
be looking at common criteria as the current standard
covert channels you'll be expected to know what a covert channel is so a covert channel is a method used to pass
information over a path that's not normally used for communication
and because it's not normally used it may not it may not be protected by the system's normal security controls uh so
for example steganography uh the the the process of transmitting information embedded in a
photograph basically a way to to covertly pass information through a seemingly benign object
but but it's not normally used it may not be protected by the system's normal security controls as in the case of
steganography right there's two types of covert channels there's covert timing and covert
storage so timing channels are based on on the time it takes to access certain
components like systems paging rate uh the time a certain transaction takes to execute or the time it takes to get
access to a shared bus and the storage channel occurs when out-of-band data is stored
in a message so icmp that what's used for ping that protocol will sometimes have some extra information in the
packets which will tell us something about the identity of the target operating system so an
attacker can use that that extra information covert channels are difficult to detect
because it's outside normal communication channels so trusted platform module so this is a
chip that resides on the motherboard of a device it's really commonly used in the windows operating system in linux as
well for that matter it's multi-purpose it's it's like storage and management for keys used for for disk encryption
for example but it provides the operating system with access to keys but prevents
component removal and access essentially but but the tpm is a chip and you're going to find it in all your modern
laptops these days so let's talk about types of access control starting with mandatory access control and this is a
policy that's determined by the system not the owner so there is a mandatory uh
access control system in place that the the user cannot that the object owner can't define and
it relies on classification labels that are representative of security domains discretionary access control allows the
owner or creator of an object to control access at their discretion that's how you remember discretionary access
control access control is at the discretion of the owner or creator
non-discrete non-discretionary access control enables enforcement of system-wide
restrictions that override object
specific access control and rule-based access control defines specific functions
for access to requested objects specific functions or rules for access so remember discretionary is at the
discretion of the owner creator non-discretionary is system wide and mandatory is determined by the system
not the owner so role based access controller are back as you're often going to hear it called
this uses a well-defined collection of named job roles to endow someone with specific
permissions for example in the cloud in microsoft azure we have a global administrator who has
access to everything we have an access administrator that role can handle issues with relation to access there is
a security reader role that has permission to read security information throughout the
system so role-based access control is is something you'll hear out there frequently and it'll it'll have a role
that you can then assign users or groups to quite typically if you think about it in the windows context so back to
mandatory access control your your mac models are going to work on one of three environment types classifications
you've got a hierarchical environment where where the labels are assigned in an ordered structure from low to to high
security low to medium to high you have compartmentalized which requires specific security clearances over
compartments or domains instead of objects and then you have
the hybrid environment which which combines hierarchical and compartmentalized so
the security levels you have security levels and within those levels you have sub compartments so that's going to be
the most granular and and flexible of the three a key point about the mac model though
is that every object and every subject has one or more labels classification labels they're
predefined and the system determines access based on on the assigned labels so let's talk about
just a few terms here so certification this is the the technical evaluation of each part of a computer assist a
computer system to assess its concordance with security standards that's the official definition what the
heck does concordance mean well it really means uh
agreement or alignment or compliance with with security standards and then accreditation is the process of formal
acceptance of certified configuration from a designated authority it's one thing to have a
a certified you know technical compliance accreditation is where a governing body
then certifies that configuration an open system these are designed using industry standards are usually easy to
integrate with other open systems and and and then you have by comparison a closed system that's generally
proprietary hardware or software and with these they're kind of black box their specs
aren't normally published they're going to be harder to integrate because they are
what we'd call a black box they're proprietary and secret uh to a degree
so techniques for ensuring cia what do i mean by cia no i'm not i'm not
talking about the cia the government cia i'm talking about the cia triad confidentiality integrity and
availability so confinement restricts a process to reading from and
writing to certain memory locations bounds are the limits of memory a process can't exceed
when reading or writing and isolation is the mode a process runs in when it's confined
through the use of memory bounds so so definitely know the definitions for confinement bounds and and isolation
because these are all techniques for for ensuring cia so let's talk about authentication
factor so with multi-factor authentication you can have something you know like a
pin or a password something you have like a trusted device it's quite common in in secure
environments that you have to to authenticate with something you know and you have to be attempting to
authenticate from a device that is trusted it's known to not be compromised it complies with the organization's
standards then something you are like biometric like windows hello does face scanning
when you when you go to secure data centers many times there's a biometric
mechanism like a retina scan or maybe even a fingerprint
authentic this is authentication and authorization so authentication often is the process of proving that you are who
you say you are then authorization is the act of granting
an authenticated party permission to do something so that's identity
and access control if i were to say it another way so permissions rights and privileges are
granted to users based on their identity and if a user has rights to a resource they're granted
authorization that's that's basically authenticity and authentication can be achieved with
both the metrics and an asymmetric cryptosystems but you know whether it's symmetric or asymmetric will will also
factor in on the uh you know how secure it is and the speed right and how scalable
okay so a few terms around multi x here so multitasking this is
simultaneous execution of more than one application on a computer and it's managed by the operating system so i can
run multiple applications on windows or on my mobile phone multi-threading permits multiple concurrent tasks to be
performed within a single process so multi-threading gives me multiple threads within within a process
so multiple concurrent tasks is the key to remember in multi-threading then there's multi-processing which is
the use of more than one processor to increase computing power pretty much everything i can think of
in terms of standards you know desktop and and laptop computing devices now uh have long supported more than one
processor and then in uh the mainframe world we have something called multi-programming it's
similar to multi-tasking but it takes place on mainframe systems and requires some specific programming
so think about multi-programming as multitasking for mainframe that's the the bottom line there
so single state and multi-state processor pretty pretty simple single state processors are capable of
operating only one security level at a time and multi-state can operate at multiple levels
of security okay processor operating modes there's user mode which is where applications
operate with limited instruction sets uh so these are going to be your ordinary
end user operations typically and then privileged mode are where it's known as system mode or kernel mode
or sometimes supervisory mode but this is where controlled
secure privileged operations occur so it's often going to be a protected area in terms of of memory under processor
and storage access but but think controlled operations i think of user as end user
operations and privileged as system or administrator operations you'll want to be familiar with these
memory types and the differences between them for the exam so we have read only memory or rom where the contents are
burned in at the factory it's not writable we have two flavors of ram static ram
which uses flip-flops dynamic ram which uses capacitors we have programmable rom it's similar to
rom with several subtypes we'll take a look at here so we have erasable prom we're erasing that read-only memory is
possible we then have two sub-categories of eprom which are uv e-prom and eeprom so we
have ultraviolet eeprom where the chips have a small window that when illuminated
with a special ultraviolet light it will erase the contents and then there is electronically
erasable prom where we use electric voltages to force erasure
and flash memory which is a derivative concept from eeprom it's non-volatile and can be electronically erased
and rewritten so uh security issues with storage so primary storage is is the same as memory
the primary classification secondary storage consists of magnetic flash and optimal media that
first has to be read into primary memory before the cpu can use the data and then random access storage devices
can be read at any any point in time and sequential access storage requires scanning through all the data physically
stored before uh the desired location so you have to access all the data in order so
sequential would be difficult uh to leverage in some circumstances
uh three main security issues around secondary storage so not memory right removable media can be used to steal
data i can plug a usb key into a computer copy some data and walk out the door right
so we have to to secure that channel of moving data access controls and encryption have to
be applied to protect data right we have to apply uh you know some sort of limitation of access role-based access
control for example and data can remain on the media even after file deletion or media formatting
what i just mentioned right that when you delete the file you're not always deleting the file i can use forensic
means to to find that data after you've deleted it so so you want to
to be very aware of that input and output devices so so input and output devices are going to be subject
to eavesdropping and tapping so so think back to phone systems you know uh tapping a phone
used to be a common um you know mechanism for for uh breaching
security of voice conversations a network connection a network cable can be tapped
as well we can tap directly into a cable with something called a vampire tap so so eavesdropping and tapping are used to
smuggle data out of an organization so you have to be careful about
securing entry points into your environment this is really where physical security starts to come into
play we have to secure the wiring closet for example and we'll talk about securing a wiring
closet in a bit uh so the purpose of firmware you'll be expected to know what firmware actually does it's basically a
software that's stored on a read-only memory chip and it contains basic instructions needed to start a computer
or a peripheral device like a printer so vulnerability threats counter measures let's talk about uh processes
so process isolation uh ensures that individual processes can only access their own data so so one process can't
read from another you can imagine if an attacker knew they could read other processes that would be
an interesting channel for them to pursue layering creates different security realms within a process and
limits communication between them and then abstraction creates a black box interface for programmers to use without
knowledge of the devices interworking so you'd see abstraction in a proprietary system
and then data hiding prevents information from being read at a different security level so
hardware segmentation enforces process isolation uh with physical security controls but it prevents information
data hiding prevents information from being read from a different security level so so that's the key to remember
there so the role of security policy so the the role of a security policy is to
inform and guide the design development implementation testing and maintenance of a particular system so so we start
for example with our organization security policy and that gives us the rules that we need to adhere to in in
designing and implementing a solution to solve a problem that gives us the the security standards
by which we go it may be the organization it could be a governing body in the case of a regulated
environment you know pci dss for example lays out policy related to handling credit card data for
example cloud computing you'll be expected to know what cloud computing is right so
this is where where processing and storage is performed somewhere else over a network connection rather than locally
so so really commonly you can think azure amazon and google cloud which which you know have their own data
centers that you can rent time in you know you pay as you pay for what you use essentially and and
sensitive and confidential data can be at risk if the cloud provider and their personnel don't adhere to the same
security standards as your organization i tend to think with the major cloud providers it's actually more secure and
and all three of these providers are going to give you some way to see the security standards to which they are
they adhere and for which they are certified azure last i looked as the most certified in terms of the various
standards they adhere to i'm a big believer that that in the cloud the major providers these days do it better
than the average i.t department can do in their own data center i think the cloud's come a long way in that respect
hypervisors you'll expect it to be known to know that what a hypervisor is and the two types so so
there's a type one hypervisor which is a native or bare metal hypervisor so you can think of of
um an esxi server from vmware that basically there's no operating system
you're logging into and using and then launching virtual machines it's just bare metal running vms that's its sole
purpose uh hyper-v uh has has a type one hypervisor option as well and then there's a type
2 hypervisor which is a hosted hypervisor so a couple of things you could think about
here would be well on windows 10 for example you can light up the hyper-v feature and you can in the windows 10
gui you know create and launch virtual machines that would be kind of a type 2
scenario other type 2 hypervisors uh oracle virtualbox
vmware workstation you know where you've got a gui and then you can then go in and mess with your your virtual machines
a casby a cloud access security broker so this is a security policy enforcement solution that can be installed on
premises or in cloud so so casby's haven't been around that long you'll often hear casby's mentioned uh with the
phrase shadow i.t because we can use casbi's to enforce security policies to ensure
that only secure applications are used in our environment and that our data is not stored in unauthorized repositories
so we can we can make sure that if we're using cloud storage that it's only
approved or sanctioned storage locations security is a service basically a cloud
provider concept where security is provided to an organization through or by an online entity and there are many
flavors of of security as a service there are many services that you can acquire in
the cloud to protect information identities uh security information event management systems which can can do some
centralized processing of your environment so really just think of of security as a service as outsourcing the
security function smart devices so so smart devices are typically mobile devices that offer
customization options you know often through installing apps and they might use you know
technology on the device or in the cloud you know hey the ai can be local or it can be cloud based
uh internet of things so that's a class of devices connected to the internet you'd be familiar with the internet of
things you know that that can include all the devices in your home automation automation your uh your home assistant
like google or alexa uh or or siri for example um
or or a car connected to the internet right so there are billions of devices that fall into the world of internet of
things or iot it's called so be basically familiar with what internet of things refers to
so mobile device and mobile app security this is a big space you'll need to know some of the basics here so so a range of
potential security features available to a mobile device could include encrypting the device uh which
is very common with both ios and android uh remote wiping a device and and typically you can
wipe just business data you can do what they call a selective wipe with with the right management software so you can
wipe just the business data off a device locking screens requiring pins gps controlling which applications access
which types of data which leads me to the reality here that mobile application security is also
pretty important and likely to come up on any any
question around mobile devices so these are applications that need to be secured
um and and could be related to securing uh you know through credentials uh application whitelisting etc and in
the world of of you know enterprise computing byod bring your own devices really popular in large companies and
that's a policy that allows employees to use their own personal device to access business information and
resources you know this this tends to make people happier but it increases our security risk
because we have to put some boundaries around what type of device they can bring
and what applications they can use to access our corporate data so that's going that's where where device security
and mobile application security factor in and your major
platforms nowadays major mobile device management platforms nowadays give us the ability to manage
the device and to manage applications on devices that we cannot fully control
mdms would include things like microsoft intune airwatch mobileiron quite quite a few quite a few
mobile device management platforms out there intune and airwatcher two that come to mind that give us the the
capabilities we're talking about here so let's talk about embedded systems and static environments so an embedded
system is typically designed around a limited set of specific functions
in relation to a larger product for which it's a component lots of devices that fall into this
category motion sensors lighting systems cache registers digital signature pads wi-fi routers
then static environments are applications uh oss hardware sets or networks that
are configured for a specific need capability or function and they're they're set to remain
unaltered uh you know change is reality in this world but uh they're set they mean set to remain unaltered even
uh through interaction with with people with users and administrators and both of these need to be managed and
managing these you can use network segmentation security layers firewalls manual updates controlling your firmware
versions you know any any sort of wrappers around these but just understand the basic definitions i
don't expect to see a lot of focus on this on the exam but just fyi privilege and accountability so there's the
principle of least privilege this is a foundational component of secure computing
and and separation of privilege so so least privilege ensures that only a minimum number of processes are
authorized to run in in supervisory mode this also factors in
when we grant people role-based access control the principle least privilege means we give someone for the
permissions they need to do their job and no more and separation of privilege increases
the granularity of secure operations by separating the privileged operations any one entity can perform be that a system
or a person so so we sometimes call that in the world of people we call that role separation
you know maybe the same person can't establish permissions who then administers the system somebody else
grants permissions they grant they are the access administrator and then somebody else performs the technical
functions of the system administrator so so accountability ensures that through all of this an audit trail
exists so we can trace operations back to their source so if permissions are granted at a higher level for someone we
know who or what did that and and if we don't have proper you know separation of privilege there's an audit
trail that shows us where one person maybe was was temporarily granted elevated privileges performed multiple
operations that broke our separation of privilege clause and and moved on
okay common flaws and vulnerabilities we have the buffer overflow and this this occurs
when a programmer fails to check the size of of input data prior to writing data to a specific memory location so if
we don't if if software is poorly written and it doesn't check the size of the data it can potentially
overwrite the bounds of memory to for which it's been granted access and potentially
overwrite more important or other important data which can cause
a system to to malfunction in a number of ways including crash you know back in the
early days of computing you know buffer overflows were really common in addition to buffer overflows programmers can
leave backdoors and privileged programs on a system after it's deployed that's that's where we have to to employ
security um you know policies and and standards to and and tooling to ensure that we we
catch anything installed on a system that shouldn't be there
uh even and even well-written systems can be susceptible to what we call time of check to time a use attack so any
any state change presents an opportunity for an attacker to compromise a system so if i if i
you know get uh credentials at one time you know credentials captured at one time used it
as a at another uh can can factor for example in a replay i think i think
of a replay attack as as something i can relate to this because in a replay attack i capture credentials and then i
attempt to reuse those credentials at a later time so so i think of that as kind of an equivalent
concept to time a check time of use the functional order of security controls may come up on the exam and
you'll want to know these in order so it starts with deterrence our
security controls should deter or discourage any malicious or negative activity and if deterrence
fails then our control should deny that activity if denial
fails then our controls should detect that activity and allow us to track that activity as it
occurs and finally it should also help serve to
delay the progress of that activity now in 2021 we saw this language evolve just a
bit so i saw those terms
simplified a bit to deter deny detect and delay and we also saw
two additional controls added to the functional order and you see them there determine and
decide so determine the cause of the incident or assess the situation to understand what is occurring
and decide on the response to implement such as apprehending the intruder or collecting evidence for further
investigation now we're going to dive into a wide range of material around physical
security and this is super important because it's an area that many it folks haven't spent a lot of time with so
physical security controls can be divided into three groups administrative logical also known as
technical if you see technical controls or logical controls two ways to say the same thing
and and physical controls now i have some listed here i want to break these out in a way that's easier for you to
memorize so let's start with the logical controls the technical control so these will be
items like access controls intrusion detection alarms uh closed circuit tv and monitoring hvac systems in your data
centers power supplies fire detection and suppression and we'll dig into some of these
into some of these individual areas uh momentarily here so administrative controls
are more focused on policies and procedures facility construction facility selection
picking the right site uh site management having proper procedures for managing your site uh
personnel controls employee policies security awareness training emergency response
and then within emergency response having emergency procedures you know laid out at the step-by-step level so
administrative controls can be wide-ranging and then physical controls for physical security
are exactly what they sound like this will be things like fences lights locks construction materials
man traps to allow only one person in at a time bollards to keep someone from driving up on a facility
uh dogs guards quite quite a few options there but but remember for the exam there's no
security without physical security without control over the physical environment
uh no amount of administrative or or technology is going to provide adequate security
security that's bottom line if a malicious person can gain access to your facility or your equipment
like your wiring closet they can do just about anything they want from you know destroying equipment
outright to disclosing or changing configurations in a way that may be difficult for you to recover from
so in terms of physical security controls uh no no your fences so so three to four feet for example decor
deters a casual trespasser if you're trying to deal with serious intruders eight feet with barbed wire
uh temperature understand that temperatures for computers uh 60 to 75 degrees fahrenheit in the ideal range
that's 15 to 23 celsius computer damage at 175 fahrenheit storage device damage at 100 and your ideal humidity
is 40 to 60 percent there there are negative consequences on both sides of that which i'll talk about in just a
moment electrical impacts know the difference between a blackout a brownout fault
surge spike sag uh and i've labeled them here to to the degree uh that they will differentiate
enough for you to remember for the exam so a blackout is prolonged loss of power where brownout for example is just
prolonged low voltage where your your electricity is not consistent and clean so remember these six
for sure uh light know that uh lights eight feet high with two feet of candle power is the uh
the uh the magic and the are the magic numbers for security controls okay humidity and static so so
when we're dealing with humidity too much humidity if we get much over percent we can get to a situation where
we have uh condensation that can cause corrosion uh your condensation is going to be bad
for for uh equipment right and too little humidity causes static electricity even
on a non-static carpet low humidity can generate a 20 000 volt static discharge which
which is enough to damage just about any sort of equipment
let's talk about fire suppression agents we're going to go from class a to class d so class a are going to be your common
combustibles like wooden paper and these can be extinguished with water or soda acid
uh class b boil and you notice i have um the the acronyms there so ash boil so
class b boil these are burning burning alcohol oil and other petroleum products like gasoline these are
extinguishing with with gas or soda acid you should never use water on a class b fire
period class c these are electrical fires that are fed by the electricity that started
them so electrical fires are conductive fires and and the agent
has to be non-conductive i mean meaning it cannot conduct electricity like any type of gas and incidentally when you
disconnect the power source the electrical fire then becomes another class of fire based on what what is
burning so when we remove the power source it becomes a class a b or d fire
uh and then cla but any type of gas is good for electrical fire because we need something that doesn't conduct
electricity you know water would be catastrophic for example uh class d
these fires are burning metals and they're extinguished with
dry powder uh you know when you get into the into these odd classes of fire like
classy these are scary because these are you're putting these out are not going to be common knowledge your
organization has to be prepared for these right
class k is a kitchen fire that's going to be like burning oil or grease your wet chemicals are used
to extinguish class k fires i'm not convinced you'll see anything
about kitchen fires on the exam i put it on there just in case uh you know offices have kitchens
right so worth worth mentioning i think there are three categories of fire detection
though they include smoke sensing flame sensing and heat sensing so know your three categories of fire detection
as well uh fire extinguisher classes and suppression agents in a table here if you want to
memorize these with a bit less detail there's just a table that very comes out for you a little more cleanly
voltage and noise so you have two types of electromagnetic interference you have common mode noise which is generated by
the difference in power between the hot and the ground wires of a power source and then you have traverse mode noise
which is generated by the the difference in the hot and the neutral wire so that's that's the key
the key differentiators between the two that i would memorize and and radio frequency or rfi interference is
generated by you know electrical appliances light sources you know cable circuits etc really
any anything you know running on electricity right voltage i mentioned static voltage
earlier here are some common levels of static thresholds of static voltage uh damage you should you should probably be
uh familiar with this this isn't the first thing i'd memorize but if you can if you can park these these voltage
levels in your head uh it's worth doing right so damage from from fire suppression itself so the destructive
elements of a fire include smoke and heat but also the suppression medium so like like water or soda acid you know
what we're using to suppress the fire can cause damage so smoke is damaging to you to most of your storage devices
heat can damage you know any electronic or computer component uh suppression mediums can cause a
variety of problems short circuits they can initiate corrosion uh or or otherwise just render equipment
useless you might put the fire out and and really you know the suppression medium might be so so damaging that you
know really all you're saving is human life because at the end of the day that's the most important thing
right so all of these issues have to be addressed when designing a fire response system but at the end of the day the
number one concern is always going to be human safety so if you are faced with any sort of choose the best
answer if uh or the most important you have human safety is always going to be the
top of the list so water suppression systems so so pre-action systems use close sprinkler
heads and the pipe is charged with compressed air instead of water uh the water's held held in check by
electronically operated sprinkler valves and the compressed air these are going to be good for areas with people and
computers wet pipe systems are filled with water um
dry pipe systems are you know contain compressed gas dry pipe systems also have close sprinkler heads the
difference is the pipes are filled with compressed air not water the water is held back by a valve that remains closed
as long as there's enough air pressure in the pipe so this is used in areas a lot of times where
water might might freeze like like parking garages dailer systems are pretty similar to dry
pipe systems except the sprinkler heads are open and they're larger than dry pipe heads that's why you get a deluge a
large amount the pipes are empty at normal air pressure the water is held back by a deluge valve
but but the sprinkler heads are going to be larger which means they can they can disperse more water more quickly
but also remember you know just as oil and water don't mix water and electricity do not mix right so that's
always that's always an an easy answer when you're thinking about those classes of fire you know
elec electrical in particular you know we know we're not going to use anything that conducts electricity which would
include water uh gas discharge so gas disc discharge systems tend to be more effective
than water systems but they shouldn't be used in environments where people are located
because gas discharge systems work by removing oxygen from the air so so gas discharge and people don't mix
okay uh halon is effective it's bad for the environment though it's ozone depleting
and and it turns to toxic gas at 900 fahrenheit note to self and suitable replacements um
a number of suitable replacements here argon energen arrow k so so there's a list here um
do your best to memorize this this this is down in the nooks and crannies i'm not sure how
uh how detailed a question would ever get to to get down to these levels but know that the halon is effective as a
gas system but it's bad for the environment so other gases would be suitable replacements
for that reason so lock types you've got electronic combination locks which would like a cipher lock that's something you
know key card systems which would be something you have the key card in your
hand right biometric system something you are like a retina scan a fingerprint scanner
uh conventional locks you know where we use a key so those are easily picked or bumped and keys can be duplicated right
conventional locks are going to be the least secure of the lot often pick and bump
resistant locks are expensive but they make it harder to pick and keys aren't as easily
duplicated so if you're going to go with conventional locks the the pick and bump resistant locks
are are better so for the exam now remember that locks can be picked and which need to be bumped remember how
lights and fences need how high lights and fences need to be right so we said lights eight feet
to uh candle power two and fences need to be eight feet to deter
serious intruders right know the difference the different physical controls related
to entry and i want to just mention a couple here so this is a man trap in case you've never seen it somebody
mentioned out in one of the the public forums that they got a question on on not a man trap but i wanted to show you
that in case you don't know what a man trap is you see basically the door opens one person can go in and then when
they're cleared the door on the other side opens and then a bollard bollards are these poles you'll see
these in front of office buildings these they show up in front of even grocery stores
and prevent somebody from driving into a facility that's what a baller does so just in case you've never seen them
now you've seen them so site selection and facility design so know the key elements in site selection and facility
design so for for site selection visibility is important uh composition of the surrounding area how accessible
is the area and what are the effects of natural disaster so in terms of visibility can i see threats coming
right um are there are there
elements in the surrounding area that could hurt me do i am i building a building next to a cliff where rocks
could fall um if i have a natural disaster you know am i am i building you know near the
edge of a riverbank and an earthquake you know causes our building to fall into the water we need to think about
all those those elements in in site selection and for facility design we need to think about the level of
security that our organization requires and planning for that before we begin
construction because we have to deal with a variety of factors when it comes to physical security right we have to
have controls for entry we can think about those things like ballers to prevent people from driving into a
facility if if driving into a facility would be a desirable way to to
breach our our site um know how to design and configure secure
work areas so there shouldn't be equal access to all locations within a facility which you probably know so
areas with the high value assets require restricted access and your
valuable assets your confidential assets they should be located at the heart or or the center of protection provided by
the facility there should be layers of of you know access controls and preventative measures in place so so
send and centralize server or computer rooms don't necessarily need to be human compatible because they're they're meant
to house server or computer rooms which means they're their temperatures are going to be optimized for computers the
the materials are going to be optimized for computers there's a certain level of human safety because people have to go
in there at some some level right but the fire suppression for example is going to be optimized to putting out uh
electrical fires not not fires that happen in a kitchen right uh and and a lot of times those those
you know fire fire suppression systems in a computer room assume that the doors are locked or will even kick off a
procedure that automatically locks the door so when the system goes off people are not present
and and you know put in harm's way threats to physical access control so no matter which physical access control is
used a security guard or a monitoring system needs to be deployed to prevent abuses of the controls like propping
open secure doors and and bypassing locks uh masquerading using somebody else's security id to gain an entry to a
facility see this all the time with uh with folks that have vendors on site for the day they'll just lend their card to
a vendor that wants to go uh for a smoke break or something you know then potentially giving them access
to a server room so you have to watch that sort of thing and then piggybacking which is following someone through a
secured gator doorway without being identified or authorized so somebody else swipes a badge for example opens
the door and then the the person piggybacking just catches the door behind them before it closes right so so
no masquerading and piggybacking as well securing a wiring closet so no security concerns
of a wiring closet you know first and foremost preventing physical unauthorized access is going to be first
and foremost right because i can go in there and i can pull cables and cause disruptions i can potentially put a tap
in place so i can eavesdrop on your uh your communications lot lots of negative there but with with
the wiring closet secure physical security first and foremost everything else is going to be secondary because
once i'm in the closet there's little you can do right
uh understand how to handle visitors in a secure facility so so if a facility employs restricted areas to control
physical security there needs to be a mechanism to handle visitors so so maybe an escort is assigned to visitors and
their activities are monitored they have to they have to have somebody accompanying them you may have a badge
on them that says your visitor requires escort uh tracking actions of outsiders when
they're granted access to prevent malicious activity is is going to be key for most protected
assets there needs to be you know deterrence and and uh
you know some some sort of denial and certainly an audit trail of one sort or another
understand needs for media storage as well this could well come up on the exam and this feels less relevant you know in
in 2021 but uh you know media storage facilities folks still do use tape out there it's
not not unheard of and we do have you know all sorts of storage devices so media storage facilities have to be
designed to securely store you know blank reusable and installation media so concerns are going to include theft
corruption uh data remnant recovery so when we erase something it's not fully erased
uh so so for example like with a hard drive i said that you know just deleting data still leaves it there recoverable
by forensic means so we can we can kick off an overwrite that right overwrites the drive with ones or zeros we can use
a degaussing tool to to send a charge through and wipe a
device uh your media facility protections should include locked cabinets or safes
a librarian or a custodian that is a gate and access gate to those two said cabinets or safes
implementing a check-in or check out process which could be facilitated or
administered by a librarian or custodian for sure and using media sanitation
lots of media sanitation we have techniques out there one of the one of the simplest is shredding right we have
confidential paper documents we shred you know i mentioned degaussing that's not going to be effective for a lot of
the modern uh storage devices but uh
check check the uh the cissp official study guide try to try to
memorize some of the media sanitation i really don't think that's going to be front and center according to the skills
measured but but worth having a look at as your time allows
and let's talk about evidence storage so so when we think about evidence we need to
retrain logs drive images snapshots data sets for for internal investigations or potentially
uh you know external forensic investigations with law enforcement so protections for evidence storage include
locked cabinets or safes dedicated isolated storage facilities offline storage access restrictions and
activity tracking and hash management and encryption at the end of the day chain of custody
is important for evidence when it comes to legal proceedings we'll touch on this in a later domain
but but when it comes to evidence yeah we're trying to to at the end of the day protect that
uh chain of custody because the integrity of that evidence would be of paramount
concern audit trails and access logs very useful tools for managing
physical access control because in part you know like like at a front desk right that if we use audit
trailing if we use an access log to sign folks in that that helps it's a good deterrent control when we think about
electronic uh audit trails for privileged operation so we may need to create access logs
manually like by a security guard they can be automated with the right equipment if you've got you know
smart cards for example that folks used to log in you can also monitor
entry points with with closed circuit tv that way we can compare the audit trail with the closed circuit tv to see if
what the the the sign in log says happened actually happened if the sign in log says one
person entered but but cctv footage shows two people entering then we have a
divergence in um the recorded event
um you know why are these important well at the end of the day it's critical to
reconstructing the events of an intrusion and a breach or an attack you know whether we're talking about
physical audit trails and access logs to physical entry and exit to a building or or
electronic logs you know related to to sign in and administrative activities
in a computing system so the need for clean power so power supplied by electric companies isn't
always consistent and clean meaning it's not always at the same level and coming without spikes and and drop so we
remember we talked about the six six impacts to electrical power so most of your equipment requires clean power
in order to function properly and to potentially avoid damage um a ups uninterruptible power supply is
a type of self-charging battery that can be used to supply consistent complete power
consistent clean power to sensitive equipment um in the event of power failure so so
number one if we have a problem with the consistency of our power and we have to drop back to battery while it's it's
repaired we can do that or if power drops altogether we can supply power for minutes or hours
depending on the size of our ups and when organizations build data centers they look at a ups that can run their
entire data center for a period of hours and then we look to generators to provide power for an extended period of
time during recovery and that's what i have for domain three next on our agenda is domain four
communication and network security so let's take a look at the exam outline for domain four it starts with 4.1
implement secure design principles in network architectures 4.2 secure network components and 4.3
implement secure communication channels according to design and
the content really belies the short outline here it's a fairly short list of objectives but quite a lot
of content around network network protocols and network security technologies here
so let's take a look at what's new in domain 4 in the 2021 release of the exam so 4.1 on the syllabus is assess and
implement secure design principles in network architectures so micro segmentation is is a topic here so this
includes software-defined networks virtual extensible lans software-defined wide area networks
sd-wans they're called wireless networks will come up now satellite was mentioned at least briefly
in the 2018 version of the exam i do want to touch on li-fi and zigbee uh that could come up on the new exam and
then cellular networks i want to talk about 5g in particular and security concerns around 5g in particular you
know how 5g uh relates back to legacy versions of cellular and then we'll touch on
content distribution networks or cdns so let's start with virtual extensible land or vxlan so so this is
network virtualization that enables network segmentation at high scale specifically what this does is helps us
solve a scale limitation in vlanding where we can only create 4096 vlans versus uh in
in vxlan we can create millions of vx lands it's and and this is really a tunneling protocol that encapsulates
an ethernet frame a layer two frame in a udp packet and layer two
can generally only be attacked from within uh you know max spoofing or flooding to cause denial of service such
as by a rogue host the attack vectors are actually explained
to some degree in rfc 7348 which is the rfc where the vxlan concept
is described let's shift gears and talk about software defined network so this is an
architecture approach that enables a network to be intelligently and centrally controlled or programmed
basically using software so it has the capacity to reprogram the data plane at any time
so so use cases where we see sdn come into play are our sd lan and sd-wan so this is really
separating the control plane from the data plane and it's going to open up a number of potential security challenges
so sdn vulnerabilities can include man-in-the-middle attacks
and denial of service attack so we secure an sdn with with tls so encryption
helps essentially sd-wan so one of the use cases for for
the sdn concept that's a software-defined wide area network this enables users and branch offices to
remotely connect to an enterprise's network but what it enables is the use of a variety of network services from
mpls to cellular to broadband to securely connect users to applications and security is largely based on
on ip security vpn tunnels next-gen firewalls and and micro segmentation
of of your application traffic but sd-wan uses a centralized control function for
intelligent routing and there's a concept called secure access service edge or sas to decentralize connectivity
where necessary li-fi so light fidelity so li-fi is is a form of wireless networking that
uses modulation of of light intensity to transmit data it uses led light essentially it can safely function
in areas that are otherwise susceptible to to electromagnetic interference and
theoretically li-fi can transmit at speeds of up to 100 gigabits or higher so li-fi only requires working led
lights that's a big advantage uh you know and and then you know the
reality is visible light uh you know can't penetrate opaque walls so we can think of that as a negative for
connectivity right because a wall is a barrier uh we might on the other hand think of that as positive in
certain security scenarios because it means you know
light doesn't penetrate opaque walls so if you're outside those walls you're not a threat right
you don't hear about li-fi much today so so i think it's still in development
is a fair statement and and you know we may see lifi come into more widespread use down the road there's certainly
some some scenarios where we're using light over traditional radio would would be a
big advantage so let's talk for a moment about zigbee which is a personal area network
so this is a short range wireless pan developed to support automation machine to machine communication and and remote
control and monitoring of iot devices it supports a centralized or distributed
security model and mesh topology it does assume that symmetric keys that are used with the devices are
transmitted securely that they're encrypted in transit
you know there's a pre-configuration of a new device in which a single key might be sent
unprotected which can create a brief vulnerability so where do people use zigbee zigbee is in widespread use in
iot smart home hub scenarios so an amazon echo for example alexa your personal assistants your amazon echo
devices are are zigbee
ready so we see zigbee and widespread use in in
the in smart home scenarios but you know that can carry over into commercial scenarios into business
scenarios as well for for iot uh device monitoring and control
another new concept for 2021 comes with the rise of fifth generation cellular so 5g so 5g brings faster speeds lower
latency no longer identifying each device through a sim card
now there are some air interface threats like session hijacking
that are dealt with in 5g now there are there's a standalone version of 5g in a non-standalone
version and the the standalone version of 5g will be more secure than the non-standalone because
the non-standalone version anchors the control signal signaling of the 5g network to the 4g core so you're relying
on a legacy technology there essentially so the diameter protocol which provides
authentication authorization and accounting in in 5g will potentially be a an attack target
and because 5g has to work alongside older tech 3g and 4g specifically old vulnerabilities could be targeted
and because of the scale of endpoint counts on 5g being exponentially greater distributed
denial of service can be a concern so some some carriers some cellular carriers launched
originally launched an nsa version of 5g which continues to rely on availability of that 4g core
so that problem will go away in time so we'll close out domain four by talking about content delivery network
so a content delivery network is a geographically distributed network of proxy servers and and the data centers
they live in the goal of a cdn is fast and highly available content
delivery basically distributes the content out so it's closer to the user cdn networks that serve up javascript
have been targeted to inject malicious content into pages for sure but vendor vendors in the cdn space typically offer
ddos protection and web app firewalls a couple of common examples of content delivery networks would be for for video
and audio streaming or for software download services where you need to move
a lot of content to a user quickly for a good user experience that's where a cdn can come in really
handy because it caches that content out where it's closer to
the end user now let's take a look at the rest of domain four
for the exam you will be expected to be very familiar with the osi model so there are seven
layers here going from physical up to the application layer at seven so the physical
is typically considered layer one application layer seven i have two memory devices here two acronyms you can
use to easily remember these layers if you struggle so if we look at going up we have please
do not throw sausage pizza away and you can actually go the other direction with all people seem to need
data processing i actually like this one better because it's also relevant to the topic at hand so that
tends to make a memory device better when it's when it's relevant but those are some acronyms you can use to lock
this in you'll also be expected to be familiar with the protocols and services that happen at each layer
so just in case you don't know what these layers are i'm going to give you two charts that you can use to prepare
your foundational knowledge for the exam so here's the osi model the seven layers starting with the physical layer up to
layer seven which is the application layer and here are some protocol examples this
will show you where the protocols live in the model and not every protocol is terribly simple for example tls shows
characteristics of layer four and five but but never mind that this is going to give you a foundation
and in case you're unfamiliar here's the osi model by function starting with the physical layer layer one so the physical
layer contains the device drivers that tell the protocol how to use the hardware for transmitting data
data link is where packet formation happens the protocol data unit at the data link layer is the
frame at the network layer we're adding routing and addressing information
source and destination addresses the protocol data unit at the network layer is the packet so if you hear
any discussion of packet they're talking about the network layer the transport layer manages integrity of
a connection and controlling the session so you'll have some protocols that will re-transmit lost
packets they'll use tcp others will not worry about session and re-transmission those will
typically use udp at the session layer layer 5 we're establishing maintaining and terminating
connection sessions between computers layer 6 is transforming data received from layer 7 from the application layer
into a format that any system any protocol following the model can understand
and layer 7 is about interfacing user applications services or the operating
system with the protocol stack so that's a quick study it'll give you something to look at if you're not already
familiar with the osi model all right and common tcp udp ports uh this could
well come up on the exam you want to be familiar with the common uh protocols and not only the port but
whether it's it's tcp or udp noticing that some of these have functions on both tcp and udp so so
session oriented and session less or connection oriented and connectionless
and you'll also be expected uh to be familiar with the the tcp stack versus the osi model so
understanding where tcpip falls in relation to the osi reference model
so here's here's an approximation of of where the tcp stack falls with osi you'll need to know this for the exam so
commit that one to memory and tcp versus udp this is layer 4 this is the transport layer
and we're going to just break these out you know so how is tcp different from udp so tcp first and foremost is
connection oriented where udp is connection less tcp
functions on a byte stream so so it's it's transmitting uh at at a byte level which allows it for for re-transmission
if there are problems or edp is message stream so it's it's happening at
a different level and you might ask well why is that important well there are some conversations where getting every
bite from from source to destination is very important and getting those bytes
properly ordered there are other situations such as video streaming where there's no point in trying to
re-transmit right with with video it's it's all about just streaming uh the current video as it's playing so
so each of these has its place so udp will support multicasting and broadcasting where tcp does not
tcp supports full duplex transmission and you may ask what is full duplex
exactly well it's simultaneously bi-directional so so both source and destination can can each transmit in
both directions simultaneously where with udp we don't have that that full duplex support and if you can think
about it in the context of like video streaming for example there's not not need for bi-directional right you're
streaming from source to destination all right so going down the list reliable service of data transmission so
so unreliable doesn't necessarily mean bad but reliable means that we have we have
air checking there right there is a connection oriented process that make sure that what's sent by the source is
received by the destination essentially a tcp packet is called the segment and the udp packet
