Skip to content
CBT Nuggets
DemoBook a Demo

Defining Security and its Roles

This skill provides an in-depth overview of cybersecurity fundamentals, focusing on IT security, network security, and data protection. It covers the ISACA organization and its ITCA certification, detailing the various components and subcategories of security, including physical and logical security measures. The content also emphasizes the importance of understanding different types of security threats and the necessary policies and practices to mitigate them.

Full skill from Cybersecurity Fundamentals (ITCA). Preview the IT training 23,000+ organizations trust.

53m

Skill 1 of 27 in Cybersecurity Fundamentals (ITCA)

What is ISACA and the ITCA?

ISACA has been around for decades, and is a well-respected organization in the IT industry. Let's get a closer look at the organization and the ITCA exam itself!

Knowledge Check

What did the ISACA acronym originally stand for?

IT Security

The first categorization of security is IT security. Although somewhat general, it has specific protection targets of which to be aware.

Knowledge Check

IT Security protects:

Information and Communications Technology (ICT)

The transmission and reception of data is potentially insecure. Let's understand which elements are a part of this communications method.

Knowledge Check

What are some of the elements of ICT communication?

Network Security

Of course, much of what needs to be protected occurs over a network - whether local networks in an enterprise, or the Internet.

Knowledge Check

The majority of software is insecure in some way.

Cybersecurity

Let's introduce cybersecurity! The specifics of cybersecurity are discussed throughout the rest of this course.

Knowledge Check

Much of the emphasis of cybersecurity is on:

Specialized Systems

Specialized systems are an often overlooked attack vector for bad actors. However, weaknesses in these systems can lead to devastating consequences.

Knowledge Check

What is ICS?

Validation

Let's summarize what we've learned with a validation exercise, comprised of three additional quiz questions!

Knowledge Check

Why are specialized systems sometimes insecure?

Knowledge Check

What Does CIA stand for in IT Security?

Knowledge Check

What does physical security safeguard? (Choose Four)

Knowledge Check

What do you think about the separate, different categories of security?

This interactive assessment is available in the full learning experience.

Want to answer questions like this yourself?
with no purchase required. Already have an account?

View Transcript

What is ISACA and the ITCA?

0:00Alright, I thought before we would get started here in the main material for

0:03the Cybersecurity Fundamentals exam.

0:06First of all, take a look at the umbrella over that exam, and that is a larger

0:11organization known as ISACA.

0:15And the exam we're looking at really is only part of a larger certification

0:20that's called the ITCA.

0:22Oh my gosh, too many acronyms going on here, right?

0:25Well, if you're anything like me, the first thing I want to know is, what in

0:27the world are these acronyms?

0:29Where does this all come from?

0:31Well, here is the ISACA website.

0:34And one of the things that kind of disturbed me a little bit when I first

0:39learned about ISACA is that there is no real definition for ISACA.

0:43You can look on their website on this page or any other page you go to.

0:48You know, what I would do is I'd go to the About Us, and I'd go to the About Us

0:51Home,

0:51and that should surely tell me what the acronym means.

0:54But no, you'll just see ISACA without any other reference there.

0:58Okay, so finally we have, though, Wikipedia to the rescue.

1:02So here it is, folks.

1:04ISACA stands for Information Systems, Audit and Control Association.

1:10Although, I think it says it in here, too, that ISACA now goes by its acronym

1:16only.

1:17So I guess that's why they don't define it on the web page, but I just kind of

1:20wanted to know what it was.

1:21Now, here's the other thing.

1:23This organization originated in the United States in 1967.

1:29Wow, I was but a wee lad back then.

1:31But if you think about it, there were not really that many digital assets back

1:35then.

1:35We really didn't have the internet as we know it now.

1:38I mean, it did exist, but it was mostly for educational and military purposes,

1:42government purposes,

1:43and it is nothing like what we use today.

1:46As far as digital assets go, we didn't really even have hard drives.

1:50Much less solid state drives like we have right now.

1:54In fact, my mother, when she was alive, she got started in IT, and my dad also,

2:01and they had stacks of cards, punch cards.

2:04I can't remember how big they were, but like maybe three or four inches wide by

2:08six or eight inches long.

2:10And that was their digital asset.

2:12These cards had little punched holes in them that each one of the holes would

2:16represent some kind of binary information.

2:19And they would run those through a machine.

2:21That was their version of digital data back in the day.

2:24Much more cumbersome and much harder to store any quantity of information

2:29when you're physically limited by how many stacks of cards you can stack up.

2:34They used to feed those into these old IBM machines.

2:36So anyway, fast forward to today.

2:39And here we have a specific certification that we are trying to achieve.

2:44So let's take a look at that. If we go to credentialing, they have a lot of

2:47different ones here.

2:48Some of them are more advanced than others.

2:50But the one we're looking at today in this course is the ITCA, which is

2:54information technology certified associate.

2:57Oh, so now they're defining acronyms.

2:59Anyway, that's what that one is.

3:01And this is an entry-level certification.

3:05Now it doesn't stand on its own.

3:07It really is a larger part of five smaller certifications that are within it.

3:12So if you take a look at it, you can get some fundamental deals, information

3:16about here.

3:17And you can Google or go to their website, which you can see up here as well.

3:20And you see that we have five separate exams that we need to know about in

3:24order to achieve the ITCA.

3:27That would be computing fundamentals, cyber security fundamentals, which is the

3:31course that we're working on here, of course.

3:33Data science fundamentals, which is an emerging but huge field.

3:38It's probably as big as a big impact on society and culture as the internet

3:44itself was a few years ago.

3:46Networks and infrastructure fundamentals and software development fundamentals.

3:51So cyber security fundamentals, of course, is where we're headed.

3:54So I'm going to click there and get a look here at what we've got going on.

3:59So first of all, that gives you a little bit of an idea of what you'll need to

4:02know here.

4:03There is an exam, of course, so that you have to pass.

4:06But what I'm going to point out here is for every other exam that I've taken,

4:10and I've been taking them for close to 30 years now, starting with Microsoft

4:13exams.

4:14I think it was Windows NT 3.51 or 4.0. I can't remember which one.

4:19Anyway, I've taken them for a long time.

4:22Every other exam I've taken through my whole career gives you a list of bullet

4:26points that you have to study.

4:28Usually it's on a web page or you can save it as a PDF.

4:31And the last course I did was also on cyber security.

4:35There's 23 pages of little bullet points of all the stuff you'd need to know.

4:39Here, I sack a gives us this.

4:42This is your outline right here.

4:44Okay.

4:45For that landscape information security fundamentals, security operations and

4:48response and securing assets.

4:50All of that could mean almost anything.

4:53There are no specific bullet points for what you have to learn.

4:56So what you might have to do is to go to view all study materials.

5:01Now you don't really have to do that because I'm going to be your source of

5:05information here for what you need to do to do well with this particular exam.

5:10Before I click on this, I want to point out, I cannot quote to you verbatim of

5:14any of their materials.

5:17I cannot share with you what's on the exam specifically anything like that.

5:21That would be in, you know, run afoul of the non disclosure agreement or the N

5:25DA that you have when you become a member.

5:28Now, what's this significance of a membership here?

5:31If you go here, you'll notice that.

5:33Yeah, there are some materials you could get.

5:35There is an online course.

5:37You could take it if you want.

5:38But honestly, again, I think you'll do better if you just watch this one.

5:42That's not out of company pride.

5:44I'm just telling you, trust me on this.

5:46Anyway, you can see that there's member pricing and $160 for that and $220 for

5:51non member pricing.

5:53Likewise, there's a pretty big price difference here for their lab package.

5:58Again, $136 or $200 and the study guide, $40 or $44.

6:04I haven't added this up, but the non member price would be, see, that's $220

6:10for $64 if you got all of those items.

6:12$464 if you become a member of Isaka, which is not hard to do, by the way, but

6:17you do have to pay for it.

6:18It's $160 plus $136.

6:21That's $196 plus $40.

6:23That would be $236, right?

6:25I'm doing the math right in my head.

6:27You're going to find out quickly as you watch me train that I am no math genius

6:30, but I think I got that right.

6:32The membership will kind of pay for that difference for you.

6:36Remember, this is just one of the exams.

6:39If you used only their materials, you'd have to use five other certifications

6:44or actually four other certifications worth of materials as well.

6:47The membership would really start to save you some money there.

6:51If you go to membership here, click right there.

6:54I can't remember what I paid for mine, but anyway, we'll click on it here.

6:57Oh, and it limited time offer, $123.

7:01So that is really a pretty good savings.

7:04I think it renews annually, but that's pretty good savings on materials if you

7:07buy their materials.

7:09They do have other benefits to membership.

7:10I'll leave that up to you to look into on your own.

7:13And so that's a little bit about Isaka, the ITCA, the Cybersecurity Fundament

7:18als Exam, and some of their materials.

7:20I will point out you could get the materials if you want.

7:23I'm not offended if you want to get those, okay, which certainly wouldn't hurt.

7:27I do think I'm going to be able to provide you with everything you're going to

7:30need here, though, for exam success.

7:32However, if you buy the book, I'm just going to tell you right now, it's very

7:36dry.

7:37Nothing against Isaka. They're just very academic organization, very, I guess,

7:41formal, if you want to put it that way.

7:43They have some very smart people working there, but you'll find that it kind of

7:46reads like a college textbook that you have to memorize and try to fall asleep

7:51in.

7:52Obviously, their own materials are the best source of truth for a lot of that.

7:58Nevertheless, I think you'll do well if you just watch this course in

8:02preparation for the exam, which we'll start in the next NUGIT, which is what we

8:06call videos around here at CBT NUGIT.

8:08NUGIT is called a video, or videos called a NUGIT. We'll start about defining

8:14security, and in particular, things like IT security and cyber security and

8:18information security.

8:19We'll be looking at all that kind of stuff in the next NUGIT.

IT Security

0:00All right, so now let's get our discussion started about cybersecurity

0:03fundamentals and in particular what security really is now I

0:07Saka would have you kind of split hairs upon what all the different types of

0:12security are I have no hairs to split

0:15And I think it's being a little bit granular in the whole definition

0:19But nevertheless, let's go ahead and address it because there are different umb

0:23rellas of security in some areas of security are

0:26Topics of other areas of security and with that in mind, let's start here with

0:31the generic IT security

0:33Okay information technology security now this relates to protecting company

0:37assets

0:38When you think about an asset that could be a lot of things

0:41Assets could be data. Yeah, that's one of the first things we look at here

0:46That's primarily what we think of when we think of cyber security and we also

0:50think of you know the internet and things like this with

0:52With data we also look at hardware now you might think how could hardware

0:57relate to security?

0:58You know like a video card is that related to security a network card is that

1:02related to security?

1:04Yes, okay

1:06So for example there have been network devices that have actually had

1:11Embedded code in the firm in the hardware of those devices that is actually spy

1:17ware

1:18Yeah, that's happened nation states have done that

1:20Okay, and if you're not familiar with spyware, it's a way of collecting

1:24information and then forwarding it on to a destination

1:27That's of course unauthorized

1:30Hacker or another nation state or something like that. There's also software

1:34software is big because a lot of security threats that occur are

1:38Through weaknesses in software. I'm not I'm gonna go into more details on some

1:43of these things as we go

1:44But I'm just kind of getting the 30,000 foot view here. There's also the

1:47facilities themselves

1:49You might have physical security requirements for different organizations again

1:55We'll be discussing that but that's all part of the umbrella of

1:58IT security now

2:00What are we doing with this? Well, what's our objective to protect information

2:04from theft? That's a big one. All right, okay

2:06It can also be misuse sometimes. It's just an honest mistake

2:10One employee is excited to be part of a project and so they forward their best

2:15friend at the company a list of topics

2:17They're gonna be working on for this new project. Well, that was forwarded to a

2:21department that's not read in on this particular topic

2:25And it might be confidential or even classified information that is crossed to

2:30boundary now

2:31So that's a kind of a misuse although well-intentioned not authorized

2:36There's also unauthorized access so could be that something has permissions on

2:41let's say file system

2:43Where the permissions are too broad and people just out of curiosity can click

2:47their way through folders and say oh look at these files

2:50And well, they weren't supposed to read those files

2:52So they were unauthorized really to be able to access those and that follows a

2:57couple of different levels

2:59There's the actual access that's been assigned and there's the logical access

3:04So the logical access is we know that people those people that were clicking on

3:10that file

3:10We're not supposed to the actual access is that it was too broad. Okay. Well

3:15again talk more about all of this as we go

3:17There's also modification. That's a big part of hacking by the way

3:20So hackers sometimes don't actually just reach in and steal something a lot of

3:24times

3:25They'll just modify something kind of slip it under the radar

3:28It looks a lot like what was supposed to be there

3:31It's been specifically modified to benefit that hacker, okay, or it could just

3:36be vandalizing data

3:38Or otherwise subverting some kind of data

3:41So maybe company a has a competitor called company B

3:44Company B figured out a way to get into the company's

3:47Servers and their file servers and modify some of their financial data

3:52Which would then of course cause company a to take wrong actions in response

3:57So this kind of stuff actually does still happen

3:59There's also CIA. This is not the law enforcement organization

4:04But this is confidential confidentiality integrity and availability

4:09These are just kind of three tenants that you'll see all the time as you move

4:13through IT and in particular

4:15Cybersecurity and these tenants really apply to most areas of IT so

4:21confidentiality

4:22You want to make sure that it's confidential, right?

4:25So this could relate to a lot of different kinds of things again company

4:28secrets trade secrets or

4:30Personally identifiable information like if you're in a medical organization,

4:34you want to protect your patients

4:37Social security numbers or other government ID depending upon where you are

4:41anything else

4:42It could be uniquely tied to that individual even just something like their

4:46address their phone number

4:47Yeah, it's still important to keep that kind of data confidential. There's also

4:52integrity

4:52This relates to the modification thing I was talking about earlier

4:55Where you don't want someone to modify data and manipulate that data well with

5:02CIA and integrity

5:03There are ways to be able to protect against that again stuff. We talk about

5:07later on

5:08There's also availability this is really just making sure that something is

5:12Available as designed for whoever's supposed to be able to access it. Okay, so

5:17a lot of times what hackers do

5:20and by the way when I say hackers we kind of tend to think of

5:23You know a 13 year old in grandma's basement hacking away from down there a lot

5:28of our nation states right now and

5:29A lot of them are from very powerful countries where the hackers are actually

5:35state employees and

5:37Have benefits from the country and so forth. They get it on salary and

5:41everything they take lunch breaks

5:42No, whatever, you know, they're just like normal employees. It's just that they

5:45're also hackers for a country

5:48Anyway, a lot of these hackers which are also known as bad actors if I can say

5:52that as well these bad actors

5:54a lot of times will do something called a denial of

5:57service attack or a

5:59DOS attack against

6:01Certain kinds of assets could be a like a web server

6:05Maybe they don't like a specific companies web companies

6:10Objectives or tenants or they feel like that companies too greedy or whatever

6:13and so they will possibly send a denial of service attack

6:17Against their website and bring it down kind of in a vandalism kind of a way

6:21but to make a point

6:23Okay, and sometimes that DOS attack will simply be a distraction because they

6:27're actually doing something else

6:28And they just want everyone to look at the DOS attack and all of it to pay

6:32attention to that while they're actually

6:34Doing something else that they don't want people to notice. Okay, so that's CIA

6:39There's also protecting from both inside and outside threats

6:44So when it comes to IT security we have a tendency to think of only the evil

6:48internet hackers and people out there that are trying to hack in

6:52from this

6:53Outside world known as the internet and trying to penetrate our interior

6:57networks and to sneak away all of our data

6:59And that's all true

7:00We do need to be concerned about that

7:02But a lot of times the threats are actually internal like I was telling you

7:05about earlier where an employee

7:07Share something with another employee that they weren't supposed to share they

7:10didn't have authorization to do that

7:12Okay, that would be an insider threat another insider threat would be a fired

7:16employee

7:17Now if a company follows good procedure

7:20They should disable that employees access to everything before they're even

7:24notified that they're fired

7:25but or closely thereafter

7:28but if that company if that employee has left the company and

7:32It's possible that there are still resources that are still open to that

7:36employee that we forgot about or it kind of slipped through the cracks

7:39Well, they could possibly still gain access to all of our systems all of our

7:43data or whatever kind of files that they used to work on

7:46For example databases and the like and they could vandalize that or they might

7:50even leave on good terms

7:52go to a

7:53in a lateral move go to a different company and then still have access to our

7:57database and

7:57Siphon off our database of customers and bring it to their next company

8:01So that's kind of a insider threat that you might need to think about there now

8:05There's also information security and here's where we're kind of starting to

8:09split hairs

8:09But information security would relate to the data itself. That's where the big

8:15emphasis is

8:15Now this we generally tend to think of as only digital data, but it's also

8:21analog when I say analog

8:23This would be things like notebooks papers

8:27schematics anything that's printed out

8:30That sort of thing whereas digital would generally be things like maybe

8:34confidential information going across a network cable or

8:37Digital data stored on a thumb drive for example that someone's been able to

8:42steal out of the organization

8:44So but analog again is still a big factor

8:47I'll give you another example of that an employee that has got ill intent

8:51against our organization

8:53They could take digital assets that are maybe a file on a server somewhere

8:58Print it out once it's printed out. It's now analog

9:01Slipping into their backpack and walk out of the building with it now

9:04They have that data that they're not supposed to abscond with also

9:08We have things such as verbal and visual communication

9:12Remember let's go back to that employee example again where they share

9:15something with another employee that they're not supposed to do

9:17Well, it doesn't have to be that they emailed them a list of what they're

9:21working on or whatever

9:22It might just be standing at the water cooler. Maybe they're really close

9:25friends and they're sharing a Greek yogurt

9:27You know while they're in between bites of this Greek yogurt

9:31There's they're saying what kinds of things are working on which again

9:35We'd like to be able to be friendly with everybody

9:37But we might have to have authorization to share certain things or we might be

9:41in a phone conversation with even a relative or our spouse

9:45And we're on our lunch break

9:47We're talking to our spouse and say hey you wouldn't believe what the company's

9:51gonna do tomorrow

9:52They're gonna release this great new product and our stock is gonna go skyrock

9:56eting through the roof

9:57Well, you should not be doing that because especially with publicly traded

10:01companies

10:01That anything that could affect the stock price or insider information stuff

10:06like that. That is a big big no-no

10:08so that stuff still counts folks and

10:11visual communication so this is kind of the

10:14Stereotypical thing where you might have seen in movies or something where you

10:18know a detective says to someone who's a civilian

10:21Well, I'm not supposed to show you these records. These are confidential and

10:25they're police data

10:26But and they have the file on their desk. I'm just gonna go on a coffee break

10:30for about

10:30Mmm 15 minutes and no more than 15 minutes when I come back

10:35Maybe we can discuss it some more of course

10:37They leave the room and that someone takes their phone out and they take

10:40pictures of all the files

10:41That are on that desk. Okay of all the papers

10:45So that would still be a visual communication that has to be protected against

10:50and in fact by the way

10:51These things here are just deadly to security sometimes a lot of organizations

10:56Will not even allow them in the building depending upon the sensitivity of

11:01their data

Information and Communications Technology (ICT)

0:00All right, as we move closer to a discussion of cybersecurity in particular,

0:04there's still

0:04other types of security that we need to know about that are also relevant. And

0:09one of those

0:09would be information and communications technology or ICT. This is really

0:13simple. It's really anything

0:15that carries information in the days of telephone lines when we used to use

0:19those more frequently.

0:21That telephone line that carried an analog phone conversation from you to

0:26another person,

0:27that would be part of ICT and carried information. It carried voice signals,

0:32analog signals to whoever

0:35you were speaking with. In modern times, of course, there's lots of other kinds

0:38of things that can

0:39carry that information, which we'll talk about here. There are three main

0:42components here. First of

0:43all, there's a transmitter. All right, the simplest way to understand that is

0:47now with maybe even a

0:48cell phone. So when I speak into my cell phone, and I'm talking to someone,

0:52that's this is the

0:53transmitter. On their end, they have a similar device. It's a receiver. Okay,

0:59so we have a transmitter

1:00and a receiver. You can also think of the similar idea there with a walkie talk

1:06ie, or with a citizen's

1:07band radio, or with a radio station, transmitter from a radio station through

1:13an antenna over the

1:15airwaves to a receiver, which would be a radio. Right? Lots of different ways

1:19that this could

1:20happen. And then whatever is in between the transmitter and the receiver is the

1:25medium. Now,

1:25that might just be airwaves, right? Radio signals transmit over airwaves. And

1:30yes,

1:31radio signals can also get hijacked. And radio signals can also get manipulate.

1:36So can television

1:37signals, for example, if you ever saw the movie, V for Vendetta, it's kind of a

1:42lower movie now,

1:43but V for Vendetta, they were hijacking television signals and they were

1:49inserting their broadcast.

1:49This also happens in at least one movie a year where a hacker or a political

1:54activist, somebody

1:55will hijack a television signal and they'll interrupt the broadcast and they'll

1:59transmit their

2:00own message over the medium of those airwaves. So what kind of elements do we

2:05have to play

2:06a part here? Well, there's the communications technology. Again, we had radio

2:11television.

2:11There's also microwave, not just for cooking popcorn, by the way, can also be

2:16used to send

2:17data. Okay, so microwave's also a factor there. We have cellular, we have

2:22internet, which really

2:24encompasses a lot of these different kinds of things. Okay, so internet could

2:28be over Wi-Fi.

2:29It could be over a cabled internet connection. It could be internet that you

2:34receive over

2:35cellular signals to your cell phone. So lots of different kinds of technologies

2:39. We're not going

2:40to exhaust all of those right here and now, but that definitely is a factor. In

2:44fact, let me

2:45point something else out. Let's just use this globe. It's kind of hard to see

2:47because of the

2:48little mesh that's over it. But here's the United States right here. And then

2:52across the ocean,

2:53there are actually even underground fiber optic cables that right now are going

2:59through kind of

3:00a pinch point in the Middle East that we don't know if it's hackers or

3:05activists or who's doing it,

3:07but in recent news as of this recording, there have been damaged fiber optic

3:11cables that threaten

3:13a lot of the communications throughout the rest of the world over here because

3:16there's a real

3:17significant juncture right there of fiber optic cables. Well, that's a medium

3:21that's under threat

3:22right now. And it's not just for internet. Those cables are used for everything

3:26. Okay,

3:26lots of different kinds of transmission. And big part of that is because it's

3:29internet because

3:30internet, you can have voice over the internet. You're listening to me right

3:34now,

3:34through voice. You can have voice over IP. So phone calls that now take place

3:39over the internet

3:40instead of old copper wiring like they used to. Anyway, for some reason, all

3:44that looks like a

3:45spider, but anyway, lots of different kinds of communications technology that

3:49can be at risk

3:51when it comes to security, digital transactions, credit card transactions, for

3:55example,

3:56those can also be hijacked. A big thing that happens now is even at gas station

4:01pumps or at

4:02convenience store checkout counters, people can put a skimmer on top of the

4:07credit card reader

4:09right there, you know, where you usually insert your chip or tap to pay or

4:12swipe your magnetic

4:13stripe. Well, magnetic magnetic stripe is particularly vulnerable to this

4:17because there's no security

4:18built in. When it comes to a credit card, there's that little chip on there for

4:23when you insert the

4:24card, there's a little bit of storage behind that chip that has cryptographic

4:28information that would

4:30generate unique information for specific transactions. So there's built in

4:34security to that. The

4:36magnetic strip, there's no security built into that really. So if someone puts

4:40a fake credit card

4:41reader over top of an existing one, when you swipe your credit card in and out

4:45of that,

4:46they can read that swipe, they can read that magnetic magnetic data. Okay, that

4:51's a digital

4:52transaction that is at risk. There's also data that's kind of a generalized

4:56term could be anything,

4:58but most data is kind of important. So we want to protect that. And then of

5:01course,

5:02we talked about the internet as well. And again, the internet really

5:06encompasses almost every type

5:07of communication in our current world. Even when we were talking about earlier,

5:11radio and television,

5:13most radio and television signals can actually be broadcast over the internet

5:18and streamed that

5:19way. We used to watch television, ABC, CBS, NBC in the United States, BBC,

5:25overseas in England.

5:26I canceled my cable service for television. I don't even use anymore. I watch

5:29who the little

5:30word Netflix or something like that. Okay. So the internet is significant here.

5:34There's also the

5:34cloud, which will talk about more again as we move along. But that is also

5:39significant. It's all

5:40connected by the internet. So it's dependent upon the internet. There are

5:44private clouds, but those

5:46are kind of a little bit more of a minority. Most of what goes on in the cloud

5:50does use normal

5:51internet signals. And the advantage of that is we can have data centers that I

5:55could never afford

5:56to pay for, but that Microsoft or Amazon pays for, for example, or Google, and

6:01I store my data on

6:02their servers. They're the ones that spent billions of dollars to build the

6:05whole thing.

6:06And I just kind of lease a tiny little bit of it for a few bucks a month. Okay.

6:10One of the advantages

6:11of the cloud, it's on a consumer level, but it's also in a big way on a

6:15corporate level. Many

6:17government organizations and large corporations really don't have their own

6:21data centers the way

6:22they used to. Now they still have some data centers locally, but now a lot of

6:27their data has been

6:28shifted to the cloud. There's also software. There's an organization called Ver

6:33acode. And a few years

6:35back, they did a study and they found that 83% of applications that were being

6:40written had at least

6:42one security flaw on us on an initial scan. They have a way of scanning for

6:45weaknesses there.

6:47Well, they were able to detect that 83% of software out of the gate is flawed

6:52somehow.

6:53So that again is where hackers have a significant foothold in two cybersecurity

6:58. And again, there's

6:59also the hardware itself, which I talked about again in our last nugget.

Network Security

0:00Alright, now let's continue our discussion of security.

0:03In particular here, we're going to be discussing network security.

0:06Now this is where a lot of security happens because probably the biggest threat

0:11in security

0:12is usually cyber security.

0:14So a lot of times that's going to be internet based.

0:17And of course, the internet is just a big network and corporate networks are

0:20trying to

0:21protect themselves from the evil bad internet.

0:24But network security is a subset of cybersecurity, which we have yet to discuss

0:29fully.

0:29But we'll get there.

0:31And then also, it's both physical and logical.

0:34Now, what do I mean by that?

0:35Well, let's take a look at these two subnets here.

0:38These could be called subnets.

0:39Okay, I'll just put that on there for clarity subnet.

0:42I'm not sure if my handwriting is very good clarity, but anyway.

0:45Alright, so two different subnets.

0:47What is a subnet?

0:48Well, generally speaking, it would be a family of devices that all share the

0:54same range of

0:55IP addresses.

0:56It's a little oversimplified, but for now that will suffice.

0:59So for example, maybe all the hosts in this subnet would be on the 10 dot

1:03network.

1:04So 10 dot nine dot eight dot something.

1:07Okay, let's put a zero for something there.

1:09And we'll discuss more about networking in a different course, but that would

1:14also assume

1:14a 24 bit subnet mask for our purposes.

1:17And then over here, we would have a another subnet.

1:20This would be a different subnet though.

1:2110 dot nine dot seven dot something over here.

1:25Right.

1:26Those are two separate subnets and they may be separated physically or

1:32logically.

1:33Okay.

1:34So all of the hosts on this subnet might be connected to a single switch.

1:39This would be called a switch and it just connects.

1:41It gets the whites kind of disappearing in there, but it connects all of those

1:44computers

1:45in there.

1:46We also have another switch over here that also connects all the computers that

1:50you see

1:51on this side.

1:52So this is just like an ethernet cable that comes out of the back of the

1:56computer, goes

1:57into the switch and allows each computer to communicate with the other

2:01computers on its

2:02same network.

2:03And then if I have a message that needs to go from this computer on this

2:06network over

2:07to this computer on this network, how does that happen?

2:11Well, these two switches are probably connected to a router.

2:14I'll put an R for a router here.

2:16Okay.

2:17So they're both connected.

2:18Okay, when a message is destined for this computer, it goes from this computer

2:22into the

2:23switch, the switch communicates with the router, the router forwards the

2:27message onto this

2:28switch over here, and then the message gets to its destination.

2:33We can also just make this logical.

2:34So what if this was just a larger switch?

2:37And if I wasn't clear about it before, a switch is what all the devices will

2:40connect

2:41to and it allows traffic to pass back and forth between one host and another.

2:46Right?

2:47There could be computers on this network.

2:48There could be printers, servers, all kinds of things.

2:52All right.

2:53But mostly it's going to be PCs in our particular context.

2:55So this switch, it might connect both of these networks.

3:00All right.

3:01And then maybe they're all on the same physical switch, but the switch can have

3:06a logical

3:07division in it known as VLANs or virtual local area networks, VLAN, right?

3:12And you can program.

3:13You don't have to memorize this.

3:15I'm just telling you how a logical division might work.

3:18A switch can be programmed to have one subnet on one side like a 10.9.8.0, like

3:27I was saying

3:27before, and maybe a 10.9.8 or 7.0 on this side, all these hosts can physically

3:35connected

3:36to the same device.

3:37But logically internally, we've programmed it to have two separate VLANs.

3:42So that's beyond our scope really quite for right now.

3:46But I TSC seems to want us to be able to differentiate between the physical and

3:51the logical.

3:52Okay.

3:53So I put that out there.

3:54All right.

3:55Now that could be on premises like the diagram I just showed or remote.

3:58Remote's actually a big issue because let's say that you're out here, you're

4:01maybe on

4:01a business trip.

4:02This is your trusty little MacBook Pro or something.

4:05And you're trying to communicate with corporate HQ up here where all your

4:09resources are.

4:10That's where your maybe your mail servers up there.

4:13Maybe your intranet is up there.

4:14Maybe some web applications.

4:16Some other things you need to connect to are in the headquarters office.

4:20So how do you make that connection?

4:21Because you're in a hotel room over here.

4:24HQ is over here in a well protected corporate network.

4:26You have to have a secure way to make this connection.

4:30A spoiler alert.

4:31Normally that's going to be through something called a virtual private network

4:34or VPN which

4:35would encrypt this connection.

4:37All right.

4:38That's all we'll talk about for there for right now.

4:40That's another way to provide good security for your connections.

4:44And there's also the cloud which again is another whole topic.

4:48But a lot of corporations are making big moves to the cloud and we need to

4:51secure those

4:52networks as well.

4:53And beyond network security, there's also application security.

4:56And again, a lot of these things we're talking about here.

4:59This is kind of the overview of them.

5:00We cover them in more detail at a future point in time.

5:03So application security, it's really again a subset of cybersecurity.

5:08So that's part of it.

5:09And just as NFYI mentioned this a couple of nuggets ago, about 83% of initial

5:14scans reveal

5:15vulnerabilities.

5:16And that's on the first scan.

5:19There's software and programming and companies that can do automated scans of

5:24code that developers

5:25create, that programmers create.

5:28And it can alert to certain weaknesses in the code that could be a security

5:32vulnerability.

5:33Well, 83% of those initial scans reveal some kind of a vulnerability.

5:38So a couple of other areas of security stick around for the next nugget where

5:42we'll talk

5:42about cybersecurity specifically.

Cybersecurity

0:00All right, now let's move here into cybersecurity, which is, again, another

0:04subset of IT security,

0:06but also a big part of what we're going to be discussing throughout the rest of

0:10this course.

0:10So what we do here is we primarily focus on internet threats. I don't want to

0:15say it's only

0:15internet, but probably the ITCA would really mostly focus on internet threats.

0:21And we all go into a

0:22lot of detail in this particular video, only because the rest of the course is

0:27mostly cybersecurity.

0:28Okay, but what does it involve? Well, it has a lot of different policy that you

0:32have to

0:32establish. This is kind of done on a more administrative level, a planning

0:36level, stuff like that.

0:38It's not the day to day actively resisting cybersecurity, although that's also

0:44necessary.

0:45But when it comes to making policy, that's something you have to do in advance.

0:48You don't do that on

0:49the fly when you're under a cyber attack actively. That has to be planned in

0:54advance, because if

0:55it's not, then you're really running around in a panic and nobody knows what

0:59their job is at the

1:00time and all this kind of stuff. So that has to be a process for that whole

1:05idea. All right.

1:06Now part of that policy that you can establish will be risk assessment. So you

1:11have to see

1:12what your potential points of entry are, and that will also reveal what your

1:16potential weaknesses

1:18could be. So just as an FYI, most people that are in cybersecurity will tell an

1:24organization

1:25that it's not a matter of if you get hacked, it's a matter of when. And by the

1:29way, you might

1:30already be hacked. Okay, very often that's the case, because a lot of

1:34organizations or a lot of

1:35hackers, excuse me, a lot of hackers will hack into an organization quietly.

1:40They'll slip under

1:41the radar. It's not this big splash that's made all the time. And it's not

1:45always very obvious.

1:46So they might already be in the network, they might be able to

1:49create a couple of secret accounts, open up what we call back doors and be able

1:54to then do

1:55something like elevate their privilege. So they might find just an average

1:59account that doesn't

2:00really have a lot of privilege, they might be able to find ways to elevate it.

2:04So you have to

2:04understand what the risks are there across a lot of different vectors. What's

2:09your risk assessment

2:10from the internet? It's likely that you will get attacked. Okay, everybody gets

2:15attacked. The only

2:16way to protect 100% from that is to not be connected to the internet. And even

2:22then,

2:23you still run risks from cybersecurity. Well, how can that be if you're not

2:26connected to the

2:27internet? Because your users, your users have phones that are connected to the

2:31internet. They

2:32could snap a screenshot or take a photograph of their screen where they're

2:36supposed to be

2:37confidential schematics, company secrets, personal information. And they could

2:43just send that to

2:44somebody over the internet because they're using cellular instead of your

2:48corporate network to

2:49transmit that data. So even if you're not connected to the internet at all,

2:54there is still risk.

2:55Many organizations will prohibit their users from carrying cell phones into the

3:00workplace.

3:00An acquaintance of mine that works in a nuclear lab, that's the case with him,

3:04he doesn't even

3:05own a cell phone. He says, I don't have much use for one because I'm at work a

3:09lot. And when I go

3:10home, I'll just use the landline at home. If I need to call somebody who he's

3:13also kind of old

3:13fashion. Anyway, that's other stuff to think about there. Also, password

3:17management, we'll get into

3:18this in much more detail in the future. But I will say this, most people are

3:23resistant to good

3:24passwords because they're difficult to remember. I have a couple of friends

3:27that have photographic

3:29or near photographic memories, not that big a deal for them. Okay, most mortal

3:34humans have

3:35difficulty remembering their passwords or or just entering in and wrong on the

3:40keyboard, just

3:40getting a fat fingering and I do that all the time. So what do they do then?

3:44They make easier

3:45passwords. They'll get it. Most people will get as easy of a password as they

3:50can possibly come up

3:51with within the bounds of your requirements. Most organizations will require

3:55upper lower case,

3:57you know, alpha, numeric, special characters, certain length, that sort of

4:02thing. Okay, so the

4:04password management is a big factor. And it's not always passwords anymore.

4:08There are other ways to

4:09authenticate besides passwords. So it's really kind of breaks beyond just that

4:13barrier of passwords.

4:14Could be other things like biometric authentication, two factor authentication,

4:18which by the way,

4:19both of those are much, much better ways to either improve passwords, improve

4:24using passwords,

4:25or not use a password at all. Because there is such a thing called password

4:29less authentication.

4:30We'll talk about that coming up in a future video. Okay, there's also

4:34encryption. This is

4:35something that is commonly misunderstood. And it's probably because a lot of

4:39people watch too much

4:40TV. Okay, it's where in some movie or TV show, there'll be an expert

4:46cybersecurity specialist.

4:48Maybe they're with the FBI or something like that. And they'll say, Oh, it's

4:52encrypted, but I'll

4:53crack that in about 20 minutes. And so or less, you know, before the show is

4:57over for sure. So

4:58they'll just crack through all of this encryption. They'll smash through a

5:01bunch of firewalls, all

5:03this kind of stuff. And it makes it look as if cracking encryption is easy.

5:07Well, some encryption

5:09is easier than others. But if you're using a highly respectable level of

5:13encryption, these days,

5:14it's very difficult to circumvent that encryption. A lot of times hackers will

5:18use other methods to

5:20attack you as opposed to directly trying to crack your encryption algorithm.

5:24Nevertheless,

5:25you need to know what good encryption is. You need to know how and where to use

5:28it,

5:28and how it can improve your security posture. And there's also then the data

5:32security. This again,

5:33also has many other areas that are within it. So where do you store that data?

5:38How is that data

5:39stored? Is it backed up? That's a big part of data security. A lot of times we

5:44think about

5:44just protecting it with right permissions so that only authenticated people and

5:49authorized people

5:50can access that data. What happens if something goes wrong with that data

5:54itself?

5:55A drive fails, hard drive fails, or you get hit with ransomware, which is a

6:00significant threat

6:02in today's landscape, both for individual users as well as corporations. If the

6:06data is backed up

6:07properly and on a good schedule, you might have some protection against

6:11ransomware. Also, where

6:13are the actual devices stored that store your security? Are they are the

6:17servers that store that

6:19data in a secure location who can access those servers where the data is stored

6:24? Is your data

6:25stored in the cloud? What are you using to protect that data in the cloud? I'm

6:30not providing

6:30answers right now because there's a lot to it, but it does bring up questions

6:34that have to be answered

6:36when you look at data security. All right, so anyway, that's a little bit of an

6:39intro into parts of

6:41cybersecurity, which we'll cover throughout the rest of our course. And our

6:44next nugget,

6:45that we're going to be discussing specialized systems.

Specialized Systems

0:00Now, another potential security threat vector would be specialized systems.

0:05It's a little bit of an umbrella term here, but generally it falls in the area

0:10of things

0:10like factories and automations, things like this, but it could be with

0:15industrialized

0:16control systems or ICS systems.

0:18Okay.

0:19And again, you can think of something like the factory where there's an

0:21industrialized

0:22control system that might mix a specific batch of chemicals into a VAT, for

0:27example.

0:28It's a pharmaceutical company that has very, very granular and very specific

0:33measurements

0:34that have to be issued when a specific drug, for example, is me.

0:39Well, there are computers and systems that control that.

0:42You wouldn't want someone to get a hold of that or to hack into that and to

0:46adjust those

0:47potencies and potentially create a problem.

0:50There are a lot of checks and balances in the pharmaceutical industry, so there

0:54's regular

0:54testing that goes on to make sure that and confirm that the correct dosages and

0:59mixture

1:00of chemicals is proper.

1:02I have a friend of mine that that's his full time job.

1:04He works very deeply in that space.

1:07Everything from the time that the source materials are delivered to the dock,

1:10the time the drugs

1:11are made, and then from the time that they leave the dock.

1:14That's all his job is to monitor that whole process.

1:17Okay.

1:18And it's not of course just for drugs.

1:19It could be for anything else that's really made.

1:22There's also SCADA or SCADA as some people might call it.

1:27This would be supervisory control and data acquisition.

1:30We just call it SCADA devices.

1:31Anyway, these again will be automations that occur that you use to perform

1:37certain tasks,

1:38very similar to industrialized control systems.

1:41So where would these kinds of things be used?

1:43Well, again, a factory floor, for example, could be where automobiles are made.

1:47There was an automobile manufacturer recently.

1:50I don't think it was as a matter of hacking, but an automobile manufacturer

1:53recently that

1:54had a robot that builds cars that bolts on fenders or something like that.

1:59I don't know what I can't remember what it was.

2:01But an employee was in the vicinity and that robot accidentally attacked that

2:06employee.

2:07I think that was errors in other areas besides security, but nevertheless, you

2:11could see

2:12some of the dangers that occur if somebody were to be in the way of some kind

2:16of a malfunction

2:17or a hack.

2:18Okay.

2:19So that's the science industry.

2:20Yeah.

2:21There's a lot that goes on there.

2:22I mean, if a nation state that was an enemy of another country were able to

2:26hack into something

2:27and adjust how missiles are made or how military equipment is manufactured or

2:33at least gum

2:34up the works or prevent those devices from being made, you can imagine the

2:39impact of

2:39that.

2:40Okay.

2:41Utilities.

2:42There have been various utilities that have been hacked.

2:44They are actually a pretty big target.

2:46So nation states will regularly go after utilities like power plants, water,

2:51water treatment

2:51plants, all those sorts of things.

2:53Few years ago, there was a water treatment plant that got hacked into and I

2:57guess the

2:58hacker released a higher level of chemicals into the water system, the water

3:03supply, then

3:03was supposed to be there.

3:05The application, I'm familiar with it.

3:06There is chlorine that gets put into your into normal tap water, at least in

3:10the United

3:10States.

3:11There's fluoride.

3:12There might be other chemicals.

3:13I don't know the others.

3:14They were able to adjust the quantity of chemicals that got into the water

3:18supply.

3:18You can imagine how that could have gone.

3:21The United States has also been involved in this, something called Stuxnet.

3:24This is going back years now, but where we created sophisticated malware that

3:30deliberately

3:31was deliberately used to infect computer systems of another nation and it

3:37affected their nuclear

3:39centrifuges.

3:40It had something to do with affecting the timing that was being used in those.

3:44So it caused things to go haywire there.

3:47Utilities, infrastructure.

3:49You'll see this in a lot of different things.

3:51It could be in transportation networks, traffic control systems, railways,

3:57shipping ports.

3:58Actually, that reminds me, I have an article.

4:01Let me try to bring it over here and find it for you.

4:03All right, here it is.

4:04I just saw this yesterday.

4:06Chinese spy cranes in US ports are caught with covert modems.

4:10I'll link this for you down below, but the basic idea here is that there are

4:15these cranes

4:16that are used quite frequently in shipping docks in ports.

4:21And for some inexplicable reason, they have a modem in them.

4:25Now, I'm not sure if they're oversimplifying the word "botem" there because a

4:28modem really

4:28just modulates and demodulates.

4:31It modulates analog data to digital data and digital data to them.

4:35Analog data, you can also think of it as an internet modem that you might have

4:39in your

4:39home.

4:40That's what you use to connect your digital computers to an analog network that

4:44communicates

4:45over the internet.

4:46So that's what a modem is.

4:49But in this context, where it's in those cranes, those Chinese manufactured cr

4:53anes had a modem

4:54that was able to transmit data to and from those cranes.

4:59And there's not really a reason for it that they could determine.

5:02So what's being done with that?

5:04Could those modems be used to shut down those cranes, to deliberately deliver a

5:09bad up data

5:09that causes some kinds of problems, that puts a snag in those ports and in

5:15their ability

5:16for people to do their jobs there.

5:18That's a big one there in terms of infrastructure.

5:20Another reason why this is a big problem is because on a factory floor, for

5:25example, a

5:26lot of these systems were originally designed before the internet.

5:29There's a company called Siemens, which is a good company, and they created a

5:34lot of

5:34these control devices that were very reliable, very good devices in controlling

5:40automation

5:41and robots and assembly lines and all different kinds of things.

5:46Well, when they first came out with these devices, people weren't using the

5:49internet

5:50decades ago the way they are right now.

5:52And there wasn't a threat vector from the internet.

5:55So they were really built without any security in mind at all.

5:59And so you think about it, a lot of the times there were devices like this that

6:03might control

6:04some kind of machinery on the factory floor.

6:06Maybe there was just a green button here and a red button here and an operator

6:11would just

6:12stay in there and they would push green or they would push red and make the

6:16machine

6:16go, make the machine stop.

6:18Maybe that's the kind of the only thing that was in mind with this.

6:21Well, now that we have internet connections, some of these that were designed

6:26in old methods,

6:27now if they're connected to the internet so that we can kind of automate things

6:30, there's

6:31no built-in security there.

6:32Is it possible that someone could hit the big red button from another country?

6:36Yes.

6:37And I'm oversimplifying again a little bit here, but you get the idea.

6:40So much of this was created without the internet in mind and without any

6:43security in mind because

6:44it wasn't needed at the time.

6:46And as a result, many systems are extremely vulnerable because in a

6:51foundational way they

6:52don't have security built in.

6:54And modern devices are better, but nevertheless there's still a lot of these

6:58weak systems out

Validation

0:00Alright, let's take a look at a summarization of what we've learned in this

0:03validation

0:04where we have three quiz questions that we'll take a look at to see how well we

0:08've learned

0:09our material.

0:10Alright, what are specialized, excuse me, why are specialized systems sometimes

0:15insecure?

0:15Let's start at the bottom.

0:17They are always internet connected.

0:18Well, no, they're not always internet connected.

0:21Some of them are not actually internet connected at all, and so they're not

0:24vulnerable in that

0:25sense.

0:26Many of them were not originally internet connected and then modifications were

0:30made

0:30to connect them to the internet.

0:32Okay, so that's not particularly an answer right there.

0:35Number two right here, they are not insecure.

0:38Well, they are insecure in many instances, so you can't just categorically say

0:43they're

0:43not insecure.

0:44How about this one?

0:45They have aging electronic systems that can burn out.

0:48Well, that is an issue, but it's not a security issue.

0:50And more of a maintenance issue.

0:52Our correct answer here is they were not originally designed with security as a

0:56priority, and

0:57they were just designed to operate those machines, and they were usually pretty

1:02simple.

1:02But now that a lot of them have internet connections and potentially a way to

1:07access

1:08them potentially from a bad actor or a hacker, they might be able to modify

1:13what that machinery

1:14is supposed to do, for example, right?

1:16Let's take a look at this.

1:17What does CIA stand for in IT security?

1:20How about corporate infrastructure assessment, confidential insider access,

1:25neither one of

1:25those two are correct.

1:27How about the central intelligence agency?

1:29CIA does stand for that, but not in an IT security context.

1:33For that, we have confidentiality, integrity, and availability.

1:39What does physical security safeguard?

1:41Let's take a look at these.

1:43How about sabotage?

1:44Yeah, that would be one.

1:46Okay.

1:47You might want to sabotage the function of a company, right?

1:50And interfere with its operation or government or utility or something like

1:54that.

1:54How about theft?

1:55Certainly, we want to protect against theft.

1:58That's why we have security measures that in a lot of places might prevent an

2:02employee

2:02from walking out of the building with something valuable, for example.

2:05Or we didn't really cover this part of the material, but you'll see it later on

2:10.

2:10Some places, USB flash drives, you know, just like, oh, this kind of little

2:14thing here

2:14that you plug into a USB port as a little USB connection on there.

2:18A lot of times those are not allowed because you can steal information onto

2:23those, slip

2:23it into your pocket and walk out with something valuable that you're not

2:27supposed to have.

2:28How about damage?

2:29Yes.

2:30There are certain physical protections we can use to protect against damage of

2:35equipment.

2:36How about espionage?

2:37Certainly that as well, because that kind of relates to the theft.

2:41We could steal data that they're not supposed to be able to steal or otherwise

2:46access our

2:47resources.

2:48That's also why we have physical security measures such as, you know, badged

2:53access

2:53and things like this.

2:55So that only the appropriate people are supposed to enter the building or the

2:58work site and

2:59that it's not a spy, so to speak, or somebody who does not offer authority to

3:04access that

3:05location.

3:06And then internet attacks is not really a part of physical security.

3:09Although it's a concern just not for this particular topic.

What's next?

Ready to keep going?

For your team

Bring this training to your team

See how CBT Nuggets helps IT teams close skills gaps, hit compliance targets, and prove training ROI.

Book a Demo

Learning on your own? Browse individual plans ($49/month, billed annually)

Not ready to buy?
with no purchase required. Already have an account?
Book a Demo