All language subtitles for 002 Risk (OBJ 1.2)

af Afrikaans
ak Akan
sq Albanian
am Amharic
ar Arabic
hy Armenian
az Azerbaijani
eu Basque
be Belarusian
bem Bemba
bn Bengali
bh Bihari
bs Bosnian
br Breton
bg Bulgarian
km Cambodian
ca Catalan
ceb Cebuano
chr Cherokee
ny Chichewa
zh-CN Chinese (Simplified)
zh-TW Chinese (Traditional)
co Corsican
hr Croatian
cs Czech
da Danish
nl Dutch
en English
eo Esperanto
et Estonian
ee Ewe
fo Faroese
tl Filipino
fi Finnish
fr French
fy Frisian
gaa Ga
gl Galician
ka Georgian
de German
el Greek
gn Guarani
gu Gujarati
ht Haitian Creole
ha Hausa
haw Hawaiian
iw Hebrew
hi Hindi
hmn Hmong
hu Hungarian
is Icelandic
ig Igbo
id Indonesian
ia Interlingua
ga Irish
it Italian
ja Japanese
jw Javanese
kn Kannada
kk Kazakh
rw Kinyarwanda
rn Kirundi
kg Kongo
ko Korean
kri Krio (Sierra Leone)
ku Kurdish
ckb Kurdish (Soranรฎ)
ky Kyrgyz
lo Laothian
la Latin
lv Latvian
ln Lingala
lt Lithuanian
loz Lozi
lg Luganda
ach Luo
lb Luxembourgish
mk Macedonian
mg Malagasy
ms Malay
ml Malayalam
mt Maltese
mi Maori
mr Marathi
mfe Mauritian Creole
mo Moldavian
mn Mongolian
my Myanmar (Burmese)
sr-ME Montenegrin
ne Nepali
pcm Nigerian Pidgin
nso Northern Sotho
no Norwegian
nn Norwegian (Nynorsk)
oc Occitan
or Oriya
om Oromo
ps Pashto
fa Persian
pl Polish
pt-BR Portuguese (Brazil)
pt Portuguese (Portugal)
pa Punjabi
qu Quechua
ro Romanian
rm Romansh
nyn Runyakitara
ru Russian
sm Samoan
gd Scots Gaelic
sr Serbian
sh Serbo-Croatian
st Sesotho
tn Setswana
crs Seychellois Creole
sn Shona
sd Sindhi
si Sinhalese
sk Slovak
sl Slovenian
so Somali
es Spanish
es-419 Spanish (Latin American)
su Sundanese
sw Swahili
sv Swedish
tg Tajik
ta Tamil
tt Tatar
te Telugu
th Thai
ti Tigrinya
to Tonga
lua Tshiluba
tum Tumbuka
tr Turkish
tk Turkmen
tw Twi
ug Uighur
uk Ukrainian
ur Urdu
uz Uzbek
cy Welsh
wo Wolof
xh Xhosa
yi Yiddish
yo Yoruba
zu Zulu

Original subtitles

Instructor: Before we can dive deeply

into the world of penetration testing,

it's important for us to take a few minutes

and talk about risk.

Good risk management skills are incredibly important

in the world of penetration testing, because without them,

you're gonna cause some horrific accidents

that could cost you your job, your company its contract,

or at least some serious downtime for the network

that you're conducting a penetration test against.

So let's start with two basic questions:

What is risk, and where does risk exist?

Now, risk at its core is the probability

that a threat will be realized.

Risk is a continual balancing act between vulnerabilities

and the threats that try to exploit them.

If you're a cybersecurity professional

working on the defensive side of the industry,

like a cybersecurity analyst would,

then your job is to minimize vulnerabilities.

But when we're working as a penetration tester,

our job is to find vulnerabilities in a system

and then exploit them to prove

that the network is truly vulnerable to an outside attack.

Now, when you hear the term vulnerability,

you should remember that it simply means any weakness

in the system design or implementation.

Vulnerabilities come from internal factors,

things like software bugs, misconfigured software,

improperly protected network devices,

lacking physical security, and other issues like this.

Vulnerabilities are within the control

of the system owner to correct.

So if you're conducting a penetration test

against an organization,

it is within their ability to mitigate

or fix most of those vulnerabilities that you find.

Conversely, however, as cybersecurity professionals,

we can't fully control threats,

but instead, we attempt to minimize or mitigate them.

Now, when you're conducting a penetration test,

you are technically the threat actor in that situation,

and so you are the enemy

of the cyber security analyst who are charged

with defending their organizational networks.

In general, though, a threat is anything

or anyone that could cause harm, loss, damage,

or compromise to our information technology systems.

These threats come from external sources,

things like natural disasters, cyber attacks,

data integrity breaches,

disclosure of confidential information,

and numerous other issues that may arise

during our daily operations.

But those threats can also come from internal sources,

such as an insider threat

who's trying to steal corporate secrets

or an employee who mistakenly leaves the back door unlocked

after taking out the trash before going home at night.

So now that we've covered the concept of vulnerabilities

and threats, let's answer our second question:

Where does risk exist?

Well, risk exists in the intersection area

between threats and vulnerabilities when we diagram them

with two overlapping circles in a Venn diagram.

Now, this is a key point to understand.

If you have a threat, but there is no vulnerability,

then there is no risk.

The same holds true that if you have a vulnerability

but there's no threat against it, there's also no risk.

Let's consider the example of trying to get

to work on time in the morning.

Your alarm clock goes off just after 6:00 AM

and you hop out of bed, you get dressed,

you eat breakfast, and now you have to get

from your house to your office across town,

but there are many vulnerabilities

and threats all around you that could cause a bad outcome,

like you arriving late for work.

This is an everyday example that most of us live with

in the world of risk management.

Let's consider a few possible vulnerabilities.

One might be that you forgot to put gas

in your car the night before,

so let's call this the vulnerability

of a lack of preparation.

Another might be that you forgot it was your day

to drop the kids off at school before driving to work.

There are a lot of possible vulnerabilities to your plan

of getting to work on time, but you can control these

because vulnerabilities are internal factors.

But there are several other threats

to your arriving on time that are outside of your control.

What if there is a traffic jam this morning?

That would certainly cause a delay to your commute

and you would arrive late to work,

which is a realization of that threat.

Another threat could be a natural disaster that's occurring,

like a flood or an earthquake that causes the road

between your home and your office to become unusable.

Now, I know that's a little dramatic,

but you're getting the idea hopefully.

You can't stop a flood or an earthquake.

It's an external factor, and it's a threat

to you arriving to work on time if they were to happen.

Now, we have several threats

and several vulnerabilities that we just identified

in this simple example, but what can we do about them?

Well, if we're worried about being late for work,

one thing we could do is wake up a little bit earlier.

That way, even if an external threat like a traffic jam

or a flooded or destroyed road was in the way,

we can actually find an alternate route

and still get to the office on time.

This is what is referred to as risk management.

It's all about finding ways to minimize the likelihood

of a certain outcome from occurring

and achieving the outcomes that you really wanna achieve.

Now, let's circle back to the world of penetration testing.

As you look at a system,

you need to identify the vulnerabilities that it has

so that you as the threat can go and exploit them.

Going back to my earlier statement,

if there is no vulnerability,

then the threat cannot put that system at risk.

For example, let's say I have a laptop here

that has top secret information on it

but I never connected it to the internet.

You're gonna have a really hard time

conducting a remote exploitation of that laptop system

because it's not online.

By choosing to eliminate the vulnerability

of a remote connection, I have effectively stopped

all remote exploits against that laptop.

It's no longer at risk for those.

Now, unfortunately, this also means

that laptop is no longer useful if I wanted to use it

to do my online banking or something else

that requires an internet connection.

And so you have to think about the pros and the cons

for each mitigation that you apply

against a known vulnerability.

Now, in general, a risk is any vulnerability

that exists that has a threat that could exploit it.

So if I have a server connected to the internet,

it has some vulnerabilities

that we're gonna need to mitigate

as cyber security professionals and defenders,

while a threat actor or penetration tester

is on the other side of things trying to break into it.

To properly manage risk in the world of cyber security,

we first are gonna categorize each risk.

Now, risk is identified

by the different risk types that exist,

things like inherent, residual, and exceptions.

Inherent risk is gonna occur when a risk is identified

but no mitigation factors have been applied.

For example, if I'm gonna drive to work,

there is an inherent risk that I could get

into a car accident and injure myself.

In everything we do in cyber security

as well as the real world, there is some inherent risk.

If I'm gonna install a software patch

to my domain controller, then there's gonna be a risk

that that patch might be faulty

and it could prevent the domain controller

from working as designed.

If my office is located in the area of the world is prone

to hurricanes like Puerto Rico, then guess what?

There's an inherent risk that we could lose power

because there's a hurricane that hits the island.

Essentially, inherent risk is the level of risk in place

prior to us taking any mitigating actions

to reduce the impact or likelihood

of that risk being realized.

Now, if you have a server that's connected to the internet,

there is an inherent risk that it could be attacked.

For example, if an advanced persistent threat,

or APT, wants to target your network,

it really is only a matter of time and resources

before they're ultimately gonna be successful

in exploiting your network.

Now, this doesn't mean we can throw up our hands and give up

on applying controls to make our organization more secure,

but there is always gonna be some level of inherent risk

in all the operations we do,

and a cyber attacker is gonna try to exploit those

to be able to gain access to our systems.

The second type of risk is known as residual risk.

Residual risk occurs when we calculate the risk

after we apply our mitigations and security controls.

So going back to the advanced persistent threat example,

we may decide to create operational policies

to secure our network.

We're then gonna ensure

that every system is fully patched and compliant,

and we're also gonna make sure

that they're as secure as they can be.

Now, there's still a residual risk there,

that there could be a zero day vulnerability

that we didn't know about, and it's gonna be discovered

by an advanced persistent threat.

Now, they're gonna be able to exploit that vulnerability

to gain access to our networks.

That is a residual risk, that amount left over

after we applied all of our security controls.

It's important to understand this

when you're conducting risk management.

Now, the final type of risk we have

is one known as a risk exception.

A risk exception is any risk that is created

due to an exemption being granted

or a failure to comply with corporate policy.

Essentially, think about it this way.

Your organization is implement a cyber security policy,

and it says that all users have to change their passwords

once a quarter, which is every 90 days,

to help prevent brute force attacks.

Well, your CEO decides

that they don't wanna follow this policy

because they hate having to remember new passwords.

So they have the IT department put in an exception

on their user account that lets them change their password

once a year instead of once every 90 days.

This exception to policy

now creates a risk to the organization,

and this risk is known as a risk exception.

In general, risk exception should be avoided

in your organization, but if you do need to use one,

you should always have a process to track these exceptions,

measure the potential impact of allowing these exceptions,

and implement compensating controls

to help mitigate these risks.

(light upbeat music)

Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.