You are on page 1of 37

1

00:00:00,256 --> 00:00:02,304


<font color="#d1d1d1">Welcome 90 protv I'm your host.</font>

2
00:00:06,912 --> 00:00:09,472
<font color="#f1f1f1">You're watching iPhone</font>

3
00:00:12,032 --> 00:00:18,176
<font color="#d9d9d9">Hello protv empowering the world through engaging learning on
your host Zach Memphis</font>

4
00:00:18,432 --> 00:00:19,712
<font color="#fcfcfc">Ceh V10</font>

5
00:00:19,968 --> 00:00:23,552
<font color="#e6e6e6">This episode is intro to ethical hacking and security
controls part</font>

6
00:00:23,808 --> 00:00:24,320
<font color="#e8e8e8">2</font>

7
00:00:24,576 --> 00:00:29,184
<font color="#b2b2b2">And once again are experts in the field in the studio and
everywhere he goes Daniel Lowery is here</font>

8
00:00:29,440 --> 00:00:34,816
<font color="#c0c0c0">Just show us the way Daniel get to see his</font>

9
00:00:35,072 --> 00:00:35,584
<font color="#e0e0e0">If you could folks</font>

10
00:00:37,632 --> 00:00:40,192
<font color="#e0e0e0">What better way to spend your day right</font>

11
00:00:40,448 --> 00:00:45,824
<font color="#c9c9c9">So that being said let's get at it let's get back to it and
our previous episode we were talking about Sakura</font>

12
00:00:46,080 --> 00:00:47,360
<font color="#cdcdcd">Policies</font>

13
00:00:47,616 --> 00:00:48,640
<font color="#fcfcfc">Continue on with that</font>

14
00:00:49,920 --> 00:00:54,528
<font color="#eeeeee">Security policy development how about that so we talked about
what a security policy is</font>

15
00:00:54,784 --> 00:01:00,928
<font color="#f0f0f0">Now it's time to start looking at developing a security
policy of our own right</font>

16
00:01:01,184 --> 00:01:03,488
<font color="#f3f3f3">What is it all about how do we how we do this break it down
for me Daniel</font>

17
00:01:03,744 --> 00:01:04,768
<font color="#fcfcfc">Let's do it</font>

18
00:01:07,072 --> 00:01:09,120
<font color="#fcfcfc">Never do that again</font>

19
00:01:09,376 --> 00:01:14,240
<font color="#dcdcdc">Ec-council does</font>

20
00:01:14,496 --> 00:01:18,336
<font color="#d6d6d6">Give you some proprietary steps of Lisa wood looks like
proprietary steps</font>

21
00:01:18,592 --> 00:01:19,616
<font color="#fcfcfc">From what I can tell</font>

22
00:01:19,872 --> 00:01:22,688
<font color="#fcfcfc">But still very very helpful when it comes to</font>

23
00:01:22,944 --> 00:01:23,456
<font color="#f7f7f7">Creating us</font>

24
00:01:25,760 --> 00:01:29,344
<font color="#f0f0f0">They start talking about types different types of</font>

25
00:01:29,600 --> 00:01:30,368
<font color="#fbfbfb">Security policies</font>

26
00:01:31,392 --> 00:01:31,904
<font color="#ebebeb">Develop</font>

27
00:01:32,928 --> 00:01:35,232
<font color="#f1f1f1">First one is</font>

28
00:01:36,000 --> 00:01:36,512
<font color="#eeeeee">So</font>

29
00:01:37,280 --> 00:01:43,168
<font color="#d4d4d4">We all know what promiscuous mean network card totally you do
which means to</font>

30
00:01:43,680 --> 00:01:44,704
<font color="#fcfcfc">Allow everything</font>

31
00:01:45,728 --> 00:01:47,008
<font color="#868686">But want everything</font>

32
00:01:47,264 --> 00:01:50,336
<font color="#e8e8e8">To come my way that's exactly right so</font>

33
00:01:50,592 --> 00:01:53,408
<font color="#fcfcfc">When you have a promiscuous security policy</font>

34
00:01:53,664 --> 00:01:55,200
<font color="#d6d6d6">It means it's really not</font>

35
00:01:55,456 --> 00:01:57,760
<font color="#d5d5d5">I mean I don't know how this is a security policy be honest
with you</font>

36
00:01:58,016 --> 00:01:59,296
<font color="#fcfcfc">I'm allowing everything</font>

37
00:02:00,064 --> 00:02:02,880
<font color="#f6f6f6">So there is no security it's just</font>

38
00:02:03,136 --> 00:02:03,648
<font color="#e1e1e1">Go for it</font>

39
00:02:04,416 --> 00:02:07,744
<font color="#b6b6b6">But I guess it's there just labeling of it are an idea
of</font>

40
00:02:08,000 --> 00:02:10,304
<font color="#a3a3a3">Or you don't really have your security policy is that
enough</font>

41
00:02:11,072 --> 00:02:12,608
<font color="#cdcdcd">No respect</font>

42
00:02:14,400 --> 00:02:15,936
<font color="#d1d1d1">Then we get into her missing</font>

43
00:02:16,448 --> 00:02:17,984
<font color="#f2f2f2">Now we're starting to</font>

44
00:02:18,240 --> 00:02:19,776
<font color="#eeeeee">Get some ideas because permissive</font>

45
00:02:20,032 --> 00:02:21,312
<font color="#d1d1d1">Allow at least it</font>

46
00:02:21,824 --> 00:02:23,104
<font color="#d3d3d3">Give the idea</font>

47
00:02:23,360 --> 00:02:24,128
<font color="#e6e6e6">Of that</font>

48
00:02:24,384 --> 00:02:25,920
<font color="#f7f7f7">There are things that are allowed in things</font>

49
00:02:26,176 --> 00:02:26,688
<font color="#8d8d8d">Games that are not</font>

50
00:02:27,200 --> 00:02:28,992
<font color="#efefef">And that's more of a Albert Russo</font>

51
00:02:29,504 --> 00:02:30,016
<font color="#cfcfcf">Policy</font>

52
00:02:30,528 --> 00:02:32,320
<font color="#d8d8d8">But there are things that are disallowed</font>

53
00:02:34,112 --> 00:02:35,904
<font color="#f3f3f3">What is permissive</font>

54
00:02:36,160 --> 00:02:38,208
<font color="#fcfcfc">It's only the known dangers</font>

55
00:02:38,464 --> 00:02:39,744
<font color="#f2f2f2">That are disallowed</font>

56
00:02:40,512 --> 00:02:41,280
<font color="#e0e0e0">I not think about that</font>
57
00:02:42,048 --> 00:02:44,864
<font color="#b0b0b0">Is arnone age of things you know for certain</font>

58
00:02:45,120 --> 00:02:45,888
<font color="#666666">AR</font>

59
00:02:46,144 --> 00:02:47,424
<font color="#fcfcfc">Not good for your organs</font>

60
00:02:49,216 --> 00:02:50,240
<font color="#f5f5f5">Now that's cool</font>

61
00:02:52,032 --> 00:02:52,800
<font color="#a9a9a9">You don't know</font>

62
00:02:53,824 --> 00:02:57,152
<font color="#bebebe">I saw this is obviously a policy that you're going to ARA
policy type</font>

63
00:02:57,664 --> 00:02:59,200
<font color="#8d8d8d">It will have to reinvent the wheel</font>

64
00:02:59,456 --> 00:03:00,224
<font color="#fcfcfc">On occasion</font>

65
00:03:00,480 --> 00:03:02,784
<font color="#fcfcfc">To make sure that those known variables</font>

66
00:03:03,040 --> 00:03:05,600
<font color="#eeeeee">Are put in this kind of like blacklisting</font>

67
00:03:06,624 --> 00:03:09,184
<font color="#d9d9d9">So you're blacklisting certain activities or</font>

68
00:03:09,440 --> 00:03:10,720
<font color="#fcfcfc">Or connections or whatever</font>

69
00:03:12,256 --> 00:03:14,048
<font color="#fcfcfc">And that's that's the the idea that</font>

70
00:03:15,584 --> 00:03:16,096
<font color="#ffffff">Permissive</font>

71
00:03:16,608 --> 00:03:17,120
<font color="#e9e9e9">Type of</font>

72
00:03:20,448 --> 00:03:21,984
<font color="#c0c0c0">I need to tell you about that</font>

73
00:03:22,240 --> 00:03:24,544
<font color="#e6e6e6">So these are our only known dangerous will be services</font>

74
00:03:25,312 --> 00:03:26,080
<font color="#c7c7c7">Or behaviors</font>

75
00:03:26,336 --> 00:03:28,640
<font color="#bcbcbc">I will be disallowed the things that you know are bad</font>

76
00:03:28,896 --> 00:03:29,920
<font color="#fcfcfc">Don't leave the doors open</font>

77
00:03:30,176 --> 00:03:31,968
<font color="#ececec">And don't say you must lock</font>

78
00:03:32,480 --> 00:03:35,296
<font color="#d6d6d6">You're filing cabinets if they're not locked then that's not
allowed</font>

79
00:03:35,552 --> 00:03:36,064
<font color="#939393">Rancho</font>

80
00:03:36,320 --> 00:03:37,856
<font color="#fcfcfc">Things that you know even even</font>

81
00:03:38,112 --> 00:03:38,880
<font color="#848484">I'll Behavior</font>

82
00:03:39,136 --> 00:03:40,160
<font color="#fcfcfc">Everything else</font>

83
00:03:40,416 --> 00:03:40,928
<font color="#dbdbdb">Is allowed</font>

84
00:03:41,440 --> 00:03:45,536
<font color="#e9e9e9">It's not specifically called out in the black list of things
that are bad for us</font>

85
00:03:46,048 --> 00:03:48,352
<font color="#fcfcfc">Then I am free to roam about the cabin</font>
86
00:03:48,608 --> 00:03:49,376
<font color="#dcdcdc">Okay</font>

87
00:03:49,632 --> 00:03:51,680
<font color="#fcfcfc">And then of course this must be updated</font>

88
00:03:54,752 --> 00:04:00,128
<font color="#e8e8e8">Yes which is kind of the opposite it's it's more like a white
listing</font>

89
00:04:00,640 --> 00:04:01,152
<font color="#d8d8d8">Of</font>

90
00:04:01,408 --> 00:04:02,432
<font color="#dbdbdb">No I'm good activity</font>

91
00:04:02,688 --> 00:04:03,456
<font color="#d1d1d1">Please or behavior</font>

92
00:04:05,248 --> 00:04:07,040
<font color="#e4e4e4">Isis, the opposite of</font>

93
00:04:07,552 --> 00:04:08,320
<font color="#a9a9a9">Well we just talk</font>

94
00:04:09,088 --> 00:04:14,464
<font color="#c5c5c5">Cancel or being prudent I know what's good for us so I asked
what I'm going to allow everything else</font>

95
00:04:14,976 --> 00:04:15,744
<font color="#f7f7f7">Is this allowed</font>

96
00:04:16,512 --> 00:04:20,351
<font color="#e4e4e4">Unify don't know about it so if you think that this activity
should be allowed</font>

97
00:04:20,607 --> 00:04:23,167
<font color="#eeeeee">You have to make a case for it bring it to us and then we
will</font>

98
00:04:23,679 --> 00:04:24,191
<font color="#929292">Effect change</font>

99
00:04:25,727 --> 00:04:26,239
<font color="#cecece">Okay</font>

100
00:04:28,287 --> 00:04:30,335
<font color="#a9a9a9">Usually involves a high-level vlogging</font>

101
00:04:30,847 --> 00:04:34,687
<font color="#c8c8c8">So they were looking for things that we would want to allow
or disallow</font>

102
00:04:34,943 --> 00:04:36,991
<font color="#c4c4c4">Probably on both ends of the spectrum</font>

103
00:04:37,247 --> 00:04:40,575
<font color="#e9e9e9">Going on it is is this an activity we should allow for</font>

104
00:04:40,831 --> 00:04:41,599
<font color="#f4f4f4">If we can't</font>

105
00:04:42,111 --> 00:04:47,231
<font color="#d7d7d7">Monitor for that we can't look and see what activities are
happening give me a hard time for us to figure out</font>

106
00:04:47,487 --> 00:04:50,815
<font color="#f7f7f7">What's going on with whitelisting that can be really really
tough</font>

107
00:04:51,327 --> 00:04:54,911
<font color="#fcfcfc">And it's really just the idea of either an implicit
deny</font>

108
00:04:57,215 --> 00:04:57,727
<font color="#bfbfbf">Allow in</font>

109
00:04:58,751 --> 00:04:59,519
<font color="#fcfcfc">That would be</font>

110
00:05:01,567 --> 00:05:06,431
<font color="#c6c6c6">Then there's the one that I can really appreciate paranoid
paranoid Android</font>

111
00:05:06,687 --> 00:05:09,759
<font color="#fcfcfc">Paranoid is everything right or almost everything</font>

112
00:05:10,527 --> 00:05:14,879
<font color="#c2c2c2">Either make myself remind or almost everything always
everything but for the most part</font>
113
00:05:15,135 --> 00:05:16,159
<font color="#f5f5f5">Everything is just</font>

114
00:05:16,415 --> 00:05:17,951
<font color="#d2d2d2">This is a non permissive environment</font>

115
00:05:18,719 --> 00:05:19,231
<font color="#eeeeee">At all</font>

116
00:05:20,511 --> 00:05:21,023
<font color="#dfdfdf">Cuz everyone's office</font>

117
00:05:21,791 --> 00:05:23,327
<font color="#d5d5d5">The World At Large want us dead</font>

118
00:05:30,239 --> 00:05:31,263
<font color="#9e9e9e">Yasso</font>

119
00:05:31,775 --> 00:05:35,103
<font color="#e9e9e9">That that is sometimes a necessary thing</font>

120
00:05:35,359 --> 00:05:37,663
<font color="#fcfcfc">There might be extremely sensitive</font>

121
00:05:38,175 --> 00:05:42,527
<font color="#f0f0f0">Systems are information or assets of some sort</font>

122
00:05:43,807 --> 00:05:46,111
<font color="#fcfcfc">You just can't let anyone get their hands on</font>

123
00:05:46,623 --> 00:05:48,671
<font color="#fcfcfc">And I'm thinking of things like government Secret</font>

124
00:05:48,927 --> 00:05:51,487
<font color="#ececec">That would probably be a very much so a</font>

125
00:05:51,743 --> 00:05:53,535
<font color="#fcfcfc">Paranoid environment banking information</font>

126
00:05:53,791 --> 00:05:56,095
<font color="#cfcfcf">You were alright and evenly even then</font>

127
00:05:56,351 --> 00:05:58,911
<font color="#efefef">Banking information is does have allowance</font>

128
00:05:59,167 --> 00:06:02,239
<font color="#9d9d9d">Right so we could follow and apparently just depends on
it</font>

129
00:06:02,495 --> 00:06:03,263
<font color="#f5f5f5">How deep</font>

130
00:06:03,775 --> 00:06:05,567
<font color="#fcfcfc">The access controls go</font>

131
00:06:06,079 --> 00:06:06,591
<font color="#d6d6d6">If there</font>

132
00:06:08,895 --> 00:06:10,175
<font color="#d5d5d5">No access then yeah they would follow</font>

133
00:06:10,431 --> 00:06:10,943
<font color="#fcfcfc">Paranoid</font>

134
00:06:11,199 --> 00:06:12,223
<font color="#cbcbcb">Otherwise are probably Beyond</font>

135
00:06:14,015 --> 00:06:14,527
<font color="#fcfcfc">Permissive</font>

136
00:06:15,551 --> 00:06:16,319
<font color="#e1e1e1">Okay</font>

137
00:06:16,831 --> 00:06:17,599
<font color="#fcfcfc">Everything is</font>

138
00:06:17,855 --> 00:06:18,367
<font color="#8e8e8e">Disallowed</font>

139
00:06:18,623 --> 00:06:20,927
<font color="#d8d8d8">You're right. Everything is just</font>

140
00:06:21,695 --> 00:06:22,463
<font color="#bbbbbb">These known good fat</font>

141
00:06:23,999 --> 00:06:27,583
<font color="#f0f0f0">So those are the four different types of ch</font>
142
00:06:27,839 --> 00:06:29,119
<font color="#fcfcfc">Calls out specifically</font>

143
00:06:29,375 --> 00:06:31,935
<font color="#fcfcfc">For your security policy development</font>

144
00:06:32,191 --> 00:06:34,751
<font color="#bfbfbf">Whiskey was permissive prudent and paranoid</font>

145
00:06:35,007 --> 00:06:35,519
<font color="#7a7a7a">What's ketosis</font>

146
00:06:37,823 --> 00:06:39,103
<font color="#f2f2f2">Moving on don't forget about work</font>

147
00:06:39,359 --> 00:06:41,919
<font color="#eeeeee">Workplace privacy policy say that</font>

148
00:06:42,175 --> 00:06:43,199
<font color="#e2e2e2">3 * 5</font>

149
00:06:43,455 --> 00:06:46,271
<font color="#dbdbdb">That's not</font>

150
00:06:48,319 --> 00:06:50,111
<font color="#fcfcfc">If you have them they will they will show up</font>

151
00:06:50,367 --> 00:06:55,231
<font color="#e9e9e9">The song to do with employee PIR personally I'd personally
identifiable in</font>

152
00:06:56,255 --> 00:07:02,399
<font color="#dcdcdc">What do we do with that are we are we Gathering that is that
something that we're in the business of doing what if you are in some sort of
Industry</font>

153
00:07:02,655 --> 00:07:03,423
<font color="#d9d9d9">Organization</font>

154
00:07:03,679 --> 00:07:06,495
<font color="#eaeaea">You probably to some extent are gathering</font>

155
00:07:08,031 --> 00:07:09,311
<font color="#f1f1f1">Your staff employees or whatever</font>
156
00:07:11,615 --> 00:07:14,431
<font color="#adadad">You don't just open the doors and anybody that wants to come
in and do stuff</font>

157
00:07:14,943 --> 00:07:15,711
<font color="#ededed">Is allowed</font>

158
00:07:16,223 --> 00:07:17,247
<font color="#f3f3f3">Right you have</font>

159
00:07:17,759 --> 00:07:18,783
<font color="#f1f1f1">You are</font>

160
00:07:19,039 --> 00:07:21,599
<font color="#eeeeee">I joined to this organization</font>

161
00:07:21,855 --> 00:07:25,951
<font color="#f0f0f0">Through hiring or volunteering or whatever but there's a
official</font>

162
00:07:26,463 --> 00:07:28,255
<font color="#dfdfdf">Relationship and partnership that data</font>

163
00:07:29,279 --> 00:07:30,047
<font color="#efefef">When that happens</font>

164
00:07:30,303 --> 00:07:32,607
<font color="#fcfcfc">We have to be able to identify you as such</font>

165
00:07:33,631 --> 00:07:36,191
<font color="#fcfcfc">That is what is involved with taking in</font>

166
00:07:38,495 --> 00:07:39,007
<font color="#ededed">From</font>

167
00:07:40,543 --> 00:07:42,591
<font color="#dddddd">So is that comes to work for me I'm going to need things
like</font>

168
00:07:42,847 --> 00:07:43,615
<font color="#f7f7f7">What is your name</font>

169
00:07:46,431 --> 00:07:50,527
<font color="#d5d5d5">I might need Social Security number for financial purposes if
I'm going to pay him</font>
170
00:07:50,783 --> 00:07:52,319
<font color="#c8c8c8">I need that okay let's write that down</font>

171
00:07:52,575 --> 00:07:55,647
<font color="#e8e8e8">He's going to be putting a lot more information into
government forms that week</font>

172
00:07:55,903 --> 00:07:57,439
<font color="#fcfcfc">That we actually hold</font>

173
00:07:57,951 --> 00:07:58,719
<font color="#ebebeb">And use</font>

174
00:07:58,975 --> 00:08:00,511
<font color="#d3d3d3">Farrar Financial purposes</font>

175
00:08:01,023 --> 00:08:03,583
<font color="#d1d1d1">What it contains his personal information things like this
so</font>

176
00:08:04,351 --> 00:08:04,863
<font color="#fcfcfc">Number</font>

177
00:08:05,119 --> 00:08:06,399
<font color="#d9d9d9">Things like his address</font>

178
00:08:07,935 --> 00:08:10,239
<font color="#d3d3d3">A lot of different formations is age</font>

179
00:08:10,751 --> 00:08:14,335
<font color="#f2f2f2">That could be used for nefarious purposes I want to</font>

180
00:08:14,591 --> 00:08:16,639
<font color="#e1e1e1">Make sure that you understand if we are taking that</font>

181
00:08:16,895 --> 00:08:18,175
<font color="#fcfcfc">We need to have a policy</font>

182
00:08:18,687 --> 00:08:22,271
<font color="#fcfcfc">That sets out security to keep that information</font>

183
00:08:23,039 --> 00:08:23,551
<font color="#fcfcfc">Confidential</font>
184
00:08:25,599 --> 00:08:26,623
<font color="#cecece">The availability to the</font>

185
00:08:27,391 --> 00:08:29,695
<font color="#cacaca">The necessary bodies get access to it</font>

186
00:08:30,719 --> 00:08:31,743
<font color="#d4d4d4">To all that CIA</font>

187
00:08:33,279 --> 00:08:36,863
<font color="#f3f3f3">So as we move on we need to explain to our staff</font>

188
00:08:37,119 --> 00:08:39,935
<font color="#efefef">Why we are taking pii don't just</font>

189
00:08:40,191 --> 00:08:42,751
<font color="#cecece">Ask you if you are an employee should be asking</font>

190
00:08:43,007 --> 00:08:45,311
<font color="#d1d1d1">So what is it that you need from this and why do you need
it</font>

191
00:08:45,567 --> 00:08:47,359
<font color="#9a9a9a">And they should be happy to explain it to you</font>

192
00:08:47,871 --> 00:08:49,407
<font color="#fcfcfc">Probably even making that information</font>

193
00:08:49,663 --> 00:08:50,175
<font color="#a4a4a4">Unavailable</font>

194
00:08:50,431 --> 00:08:51,199
<font color="#cfcfcf">There's some means</font>

195
00:08:51,455 --> 00:08:52,735
<font color="#f0f0f0">Maybe an internet page</font>

196
00:08:52,991 --> 00:08:54,015
<font color="#fcfcfc">Employee handbook</font>

197
00:08:56,831 --> 00:08:58,367
<font color="#ededed">Also you'll need to explain</font>

198
00:08:58,623 --> 00:08:59,135
<font color="#fcfcfc">What</font>

199
00:08:59,647 --> 00:09:00,415
<font color="#fcfcfc">You are gathering</font>

200
00:09:01,183 --> 00:09:02,719
<font color="#d4d4d4">Don't keep this thing secret it's not</font>

201
00:09:04,767 --> 00:09:05,535
<font color="#d9d9d9">We don't like Secret</font>

202
00:09:06,559 --> 00:09:08,351
<font color="#ededed">Only real Secrets but</font>

203
00:09:08,607 --> 00:09:10,911
<font color="#e4e4e4">When you're taking information for me that's not something
I'm just</font>

204
00:09:13,215 --> 00:09:14,751
<font color="#dadada">I want to know why is your taking it</font>

205
00:09:15,007 --> 00:09:15,775
<font color="#fcfcfc">What you're taking</font>

206
00:09:16,287 --> 00:09:18,847
<font color="#a1a1a1">Do have to add a little bit of paranoid because that's
what</font>

207
00:09:20,127 --> 00:09:22,943
<font color="#e7e7e7">And then we develop a policy around that that should
be</font>

208
00:09:23,199 --> 00:09:24,223
<font color="#e5e5e5">Again disseminated</font>

209
00:09:24,479 --> 00:09:26,527
<font color="#d5d5d5">To our users aurstaff whoever</font>

210
00:09:26,783 --> 00:09:27,551
<font color="#f3f3f3">That they know</font>

211
00:09:27,807 --> 00:09:29,087
<font color="#fcfcfc">This is why we're doing this</font>

212
00:09:29,343 --> 00:09:31,647
<font color="#f3f3f3">This is what we're taking from you and these are the
security</font>

213
00:09:35,231 --> 00:09:37,535
<font color="#e5e5e5">So also tell them what you do with it</font>

214
00:09:39,071 --> 00:09:41,375
<font color="#dfdfdf">I'm were just storing it for financial purpose</font>

215
00:09:44,703 --> 00:09:46,239
<font color="#e8e8e8">Maybe you work at a daycare center</font>

216
00:09:46,495 --> 00:09:47,775
<font color="#e3e3e3">And yeah that background checks</font>

217
00:09:48,287 --> 00:09:48,799
<font color="#fcfcfc">That information</font>

218
00:09:51,615 --> 00:09:53,151
<font color="#e7e7e7">At for the sake of the workers and</font>

219
00:09:55,455 --> 00:09:56,223
<font color="#fcfcfc">Let's see here</font>

220
00:09:57,247 --> 00:09:58,271
<font color="#797979">Lemon what you collect</font>

221
00:09:58,783 --> 00:09:59,551
<font color="#fcfcfc">If it all possible</font>

222
00:09:59,807 --> 00:10:01,599
<font color="#d2d2d2">And you don't want to over grab</font>

223
00:10:02,111 --> 00:10:02,879
<font color="#fcfcfc">What do you need that stuff</font>

224
00:10:03,647 --> 00:10:05,439
<font color="#b6b6b6">You just some sort of like nosy Nelly</font>

225
00:10:06,207 --> 00:10:07,743
<font color="#f8f8f8">You don't need a bunch of information on you</font>

226
00:10:07,999 --> 00:10:08,767
<font color="#828282">I just need</font>
227
00:10:09,023 --> 00:10:09,791
<font color="#fcfcfc">The bare minimums</font>

228
00:10:10,047 --> 00:10:10,559
<font color="#fcfcfc">So just</font>

229
00:10:10,815 --> 00:10:12,095
<font color="#fafafa">Try to stay out of the business</font>

230
00:10:12,351 --> 00:10:12,863
<font color="#fcfcfc">Collecting</font>

231
00:10:13,119 --> 00:10:14,911
<font color="#fcfcfc">Superfluous information</font>

232
00:10:15,423 --> 00:10:15,935
<font color="#ececec">About your employer</font>

233
00:10:17,471 --> 00:10:19,007
<font color="#fbfbfb">I keep occurrence</font>

234
00:10:19,263 --> 00:10:20,287
<font color="#f9f9f9">Don't let it fall out of date</font>

235
00:10:20,543 --> 00:10:22,079
<font color="#fcfcfc">Because then it becomes irrelevant</font>

236
00:10:23,103 --> 00:10:25,407
<font color="#ececec">If you are gathering it you've got a reason for
Gathering</font>

237
00:10:26,431 --> 00:10:28,479
<font color="#fcfcfc">And if the information is incorrect</font>

238
00:10:28,735 --> 00:10:30,015
<font color="#cbcbcb">It defeats the purpose of gas</font>

239
00:10:32,575 --> 00:10:36,927
<font color="#d6d6d6">Make sure the employees have access to it so if it is their
information</font>

240
00:10:37,439 --> 00:10:38,719
<font color="#f2f2f2">So this is their file</font>

241
00:10:39,231 --> 00:10:40,255
<font color="#fcfcfc">Now maybe</font>

242
00:10:41,791 --> 00:10:46,143
<font color="#f7f7f7">Other things like reviews and things of that nature that
might not be something they have access to</font>

243
00:10:46,655 --> 00:10:49,215
<font color="#e9e9e9">But their personal information their W-2s</font>

244
00:10:49,727 --> 00:10:50,495
<font color="#fcfcfc">Other Financial in</font>

245
00:10:51,775 --> 00:10:52,799
<font color="#c5c5c5">Formation about their person</font>

246
00:10:53,055 --> 00:10:54,335
<font color="#fcfcfc">The company keeps</font>

247
00:10:54,591 --> 00:10:56,383
<font color="#fcfcfc">That is identifiable for them</font>

248
00:10:57,919 --> 00:10:58,687
<font color="#f9f9f9">Have access to</font>

249
00:10:58,943 --> 00:11:01,759
<font color="#e9e9e9">And also welcome forget keep it secure</font>

250
00:11:02,015 --> 00:11:03,295
<font color="#cecece">I got in big letters</font>

251
00:11:03,807 --> 00:11:04,319
<font color="#efefef">He pits</font>

252
00:11:04,831 --> 00:11:05,599
<font color="#cfcfcf">Cure exclamation</font>

253
00:11:07,391 --> 00:11:12,511
<font color="#b7b7b7">Security is the name of this game we're doing here</font>

254
00:11:14,047 --> 00:11:15,839
<font color="#fcfcfc">Certified ethical forget about it</font>

255
00:11:16,863 --> 00:11:19,935
<font color="#e8e8e8">We are security might have people there for we need to be
in</font>

256
00:11:20,703 --> 00:11:21,215
<font color="#9e9e9e">Insecurities</font>

257
00:11:21,727 --> 00:11:23,007
<font color="#c9c9c9">Creating a security policy</font>

258
00:11:23,263 --> 00:11:26,079
<font color="#fafafa">If you're not doing things if it's a hard file</font>

259
00:11:26,335 --> 00:11:28,383
<font color="#dadada">Put it in a filing cabinet that's Fireproof</font>

260
00:11:29,151 --> 00:11:30,943
<font color="#d5d5d5">As good locking systems</font>

261
00:11:31,455 --> 00:11:32,479
<font color="#d3d3d3">And keep them locked</font>

262
00:11:32,735 --> 00:11:35,551
<font color="#d7d7d7">Keep them away or so maybe those fine systems go</font>

263
00:11:35,807 --> 00:11:38,111
<font color="#aeaeae">Behind a locked door not only are they locked with the doors
locked</font>

264
00:11:38,623 --> 00:11:41,695
<font color="#ebebeb">And only people in HR have access to her managers have access
to</font>

265
00:11:42,207 --> 00:11:46,559
<font color="#e3e3e3">And then you have to create policies that say here are the
people that are supposed to have</font>

266
00:11:46,815 --> 00:11:48,095
<font color="#f8f8f8">Access to the HR files</font>

267
00:11:49,119 --> 00:11:49,631
<font color="#e5e5e5">And there you go</font>

268
00:11:49,887 --> 00:11:50,399
<font color="#525252">Chainsaw</font>

269
00:11:50,911 --> 00:11:53,215
<font color="#d3d3d3">Putting those security controls around this security</font>

270
00:11:55,007 --> 00:11:55,519
<font color="#a9a9a9">Other steps</font>

271
00:11:55,775 --> 00:12:01,919
<font color="#d0d0d0">Security policy creation yes and easy Council calls them out
for the ceh exam they have a specific order and</font>

272
00:12:02,175 --> 00:12:03,199
<font color="#959595">I would like you to</font>

273
00:12:03,455 --> 00:12:04,479
<font color="#d9d9d9">Know about and</font>

274
00:12:04,735 --> 00:12:08,831
<font color="#b2b2b2">Get on then we all need some help in these Endeavors we
aren't born knowing this stuff</font>

275
00:12:09,087 --> 00:12:11,135
<font color="#d4d4d4">And this is all convention right it's something that</font>

276
00:12:11,391 --> 00:12:13,183
<font color="#fcfcfc">The security industry at Large</font>

277
00:12:13,439 --> 00:12:14,207
<font color="#c0c0c0">Give me</font>

278
00:12:14,463 --> 00:12:18,047
<font color="#e5e5e5">As devised in this is a based off of that idea</font>

279
00:12:18,303 --> 00:12:21,375
<font color="#dadada">Here we go take a look at my screen right here</font>

280
00:12:21,631 --> 00:12:27,007
<font color="#fcfcfc">And we've got nine different steps for creating a security
policy</font>

281
00:12:29,055 --> 00:12:30,591
<font color="#f3f3f3">First one is risk assessment</font>

282
00:12:31,359 --> 00:12:32,383
<font color="#fcfcfc">You can't create</font>

283
00:12:32,639 --> 00:12:33,919
<font color="#f9f9f9">An effective security policy</font>

284
00:12:34,175 --> 00:12:35,711
<font color="#fafafa">If you don't know what the risks to your</font>

285
00:12:37,503 --> 00:12:40,063
<font color="#a8a8a8">So it's very important that the first step that you do</font>

286
00:12:40,319 --> 00:12:41,343
<font color="#fcfcfc">Is assess</font>

287
00:12:41,599 --> 00:12:44,671
<font color="#d7d7d7">The landscape around you I'm take a look what are the
risks</font>

288
00:12:44,927 --> 00:12:45,439
<font color="#c4c4c4">2R</font>

289
00:12:45,695 --> 00:12:46,975
<font color="#d6d6d6">Systems and environment at Large</font>

290
00:12:47,743 --> 00:12:49,535
<font color="#fcfcfc">Once you figure those out</font>

291
00:12:49,791 --> 00:12:53,887
<font color="#e4e4e4">You'll be able to take the next few steps but until you do
your you're stuck</font>

292
00:12:54,911 --> 00:12:57,727
<font color="#f6f6f6">First thing you need to do is perform some form of risk
assessment</font>

293
00:12:57,983 --> 00:13:00,287
<font color="#ececec">Even if it's rudimentary Enfamil just get the ball
rolling</font>

294
00:13:00,799 --> 00:13:04,383
<font color="#f4f4f4">You can always come back and do a second draft on 3rd Drive
in Fords</font>

295
00:13:04,639 --> 00:13:05,919
<font color="#f8f8f8">Up until your final draft</font>

296
00:13:06,175 --> 00:13:07,967
<font color="#e4e4e4">Continually revising and maintaining</font>
297
00:13:08,223 --> 00:13:10,015
<font color="#f3f3f3">Until you get there and you feel like you</font>

298
00:13:10,271 --> 00:13:12,319
<font color="#ebebeb">You've reached the station you've reached the mount</font>

299
00:13:13,087 --> 00:13:15,391
<font color="#c5c5c5">You have a good security policy that you feel and
Compasses</font>

300
00:13:18,463 --> 00:13:18,975
<font color="#cfcfcf">Security gold</font>

301
00:13:19,231 --> 00:13:19,743
<font color="#bdbdbd">What you had in mind</font>

302
00:13:21,535 --> 00:13:23,839
<font color="#fcfcfc">So make sure you do that risk assess</font>

303
00:13:24,863 --> 00:13:28,703
<font color="#cacaca">Then you can use a lien on security standards and
Frameworks</font>

304
00:13:28,959 --> 00:13:29,727
<font color="#eeeeee">As guides</font>

305
00:13:30,239 --> 00:13:34,591
<font color="#d4d4d4">To help you right you don't want to be Reinventing the wheel
if not if it's not necessary</font>

306
00:13:35,103 --> 00:13:35,871
<font color="#fcfcfc">And in a lot of</font>

307
00:13:36,127 --> 00:13:36,895
<font color="#c1c1c1">Organizations</font>

308
00:13:37,151 --> 00:13:37,919
<font color="#b6b6b6">Businesses in industry</font>

309
00:13:38,687 --> 00:13:39,455
<font color="#d2d2d2">Already have</font>

310
00:13:39,967 --> 00:13:42,527
<font color="#fafafa">Set standards and Frameworks to help you do this</font>
311
00:13:42,783 --> 00:13:46,879
<font color="#fcfcfc">So why not use them if they are a resource that are out there
Avail yourself of it</font>

312
00:13:47,135 --> 00:13:47,647
<font color="#9d9d9d">And</font>

313
00:13:47,903 --> 00:13:48,671
<font color="#bbbbbb">And grab ahold of</font>

314
00:13:50,207 --> 00:13:51,743
<font color="#fcfcfc">Get management and staff</font>

315
00:13:52,767 --> 00:13:53,535
<font color="#eeeeee">So</font>

316
00:13:54,303 --> 00:13:56,607
<font color="#fcfcfc">Worst thing you can do is think I got this</font>

317
00:13:57,119 --> 00:14:00,191
<font color="#fcfcfc">I am the person that knows about security</font>

318
00:14:00,447 --> 00:14:03,519
<font color="#ededed">Therefore this is just on my Comedown heavy-handed ham-
fisted</font>

319
00:14:04,031 --> 00:14:05,823
<font color="#f0f0f0">And Scooby my-way-or-the-highway</font>

320
00:14:06,847 --> 00:14:10,431
<font color="#e2e2e2">With an iron fist that will rule the security
landscape</font>

321
00:14:10,687 --> 00:14:14,015
<font color="#c0c0c0">That's a bad way to go.</font>

322
00:14:14,271 --> 00:14:17,087
<font color="#bbbbbb">The one big promises is you have blind</font>

323
00:14:17,855 --> 00:14:18,623
<font color="#adadad">I don't care who you are</font>

324
00:14:19,391 --> 00:14:20,159
<font color="#fcfcfc">You're going to miss something</font>
325
00:14:20,927 --> 00:14:24,767
<font color="#d4d4d4">So a team is always helpful and a team that comes from
varying</font>

326
00:14:25,023 --> 00:14:27,071
<font color="#d9d9d9">Different areas of your organization</font>

327
00:14:27,839 --> 00:14:28,351
<font color="#d2d2d2">Perspective</font>

328
00:14:29,119 --> 00:14:34,751
<font color="#f0f0f0">Perspective is very helpful because they'll be able to tell
you all that control won't work because we do x y and z</font>

329
00:14:35,007 --> 00:14:37,055
<font color="#9e9e9e">That will stop that from happening that's mission-
critical</font>

330
00:14:37,823 --> 00:14:38,847
<font color="#545454">Oii</font>

331
00:14:39,103 --> 00:14:40,383
<font color="#fcfcfc">I know you did that</font>

332
00:14:41,407 --> 00:14:44,991
<font color="#bbbbbb">Okay so you need those different perspective</font>

333
00:14:45,247 --> 00:14:47,295
<font color="#f7f7f7">So I definitely Management's</font>

334
00:14:47,551 --> 00:14:48,575
<font color="#fcfcfc">Because</font>

335
00:14:48,831 --> 00:14:49,343
<font color="#c9c9c9">But their manager</font>

336
00:14:49,599 --> 00:14:53,183
<font color="#b1b1b1">Tried the kind of run the show they make things happen there
that the grease in the wheel</font>

337
00:14:54,463 --> 00:14:55,999
<font color="#e9e9e9">Staff input is great because</font>

338
00:14:56,255 --> 00:14:57,023
<font color="#e3e3e3">Are the boots on the ground</font>
339
00:14:57,535 --> 00:14:59,327
<font color="#efefef">Either the people in the trenches everyday</font>

340
00:14:59,839 --> 00:15:03,679
<font color="#dedede">That these security policies and controls and which we
implement</font>

341
00:15:03,935 --> 00:15:04,703
<font color="#b5b5b5">Will affect them</font>

342
00:15:05,471 --> 00:15:06,751
<font color="#d5d5d5">We want to make sure</font>

343
00:15:09,823 --> 00:15:10,847
<font color="#c6c6c6">They help to their job</font>

344
00:15:11,103 --> 00:15:12,127
<font color="#c2c2c2">Sometimes</font>

345
00:15:12,639 --> 00:15:14,175
<font color="#fbfbfb">It just happens where</font>

346
00:15:14,687 --> 00:15:18,015
<font color="#f5f5f5">This is an unacceptable risk we must put a controlling
place</font>

347
00:15:18,527 --> 00:15:20,063
<font color="#fcfcfc">And yes it will make your job more difficult</font>

348
00:15:21,087 --> 00:15:22,879
<font color="#f6f6f6">And we understand that we apologize</font>

349
00:15:24,159 --> 00:15:26,463
<font color="#fcfcfc">The implications of a data breach</font>

350
00:15:26,719 --> 00:15:30,303
<font color="#f1f1f1">Through this mechanism through the the function that you
perform here</font>

351
00:15:30,559 --> 00:15:31,327
<font color="#eeeeee">An organization</font>

352
00:15:31,583 --> 00:15:32,607
<font color="#f1f1f1">Is so</font>
353
00:15:33,631 --> 00:15:34,655
<font color="#fcfcfc">Devastating to us</font>

354
00:15:34,911 --> 00:15:36,191
<font color="#dfdfdf">That you would be out of a job</font>

355
00:15:36,703 --> 00:15:37,727
<font color="#fcfcfc">If we don't do</font>

356
00:15:38,495 --> 00:15:44,127
<font color="#adadad">Okay so it it sounds more so that's the kind of thing you
need to get that from your user base can you get that buy-in from your
manager</font>

357
00:15:45,151 --> 00:15:48,479
<font color="#c6c6c6">I think need to understand that you're not doing this just
make allies</font>

358
00:15:48,991 --> 00:15:49,759
<font color="#fcfcfc">You're doing it</font>

359
00:15:50,015 --> 00:15:56,159
<font color="#d1d1d1">To help increase the security so that the organization
flourishes and prosperous and doesn't get data breaches</font>

360
00:15:56,671 --> 00:15:58,463
<font color="#f8f8f8">And all the ramifications thereof</font>

361
00:15:58,975 --> 00:16:02,559
<font color="#c3c3c3">Alright so that is what you need to do when it comes to
getting mansion</font>

362
00:16:03,839 --> 00:16:04,607
<font color="#ebebeb">Once you have that</font>

363
00:16:04,863 --> 00:16:05,631
<font color="#9a9a9a">Chicago</font>

364
00:16:06,143 --> 00:16:08,959
<font color="#cccccc">You need to be able to enforce the policy is an hour moving
out here</font>

365
00:16:09,215 --> 00:16:09,727
<font color="#939393">Force policy</font>
366
00:16:09,983 --> 00:16:12,031
<font color="#d8d8d8">Use penalties for non-compliance with necessary</font>

367
00:16:12,543 --> 00:16:14,335
<font color="#e5e5e5">And a lot of times it is</font>

368
00:16:14,591 --> 00:16:16,639
<font color="#f5f5f5">There's no real repercussions</font>

369
00:16:17,151 --> 00:16:17,663
<font color="#e4e4e4">4</font>

370
00:16:17,919 --> 00:16:18,431
<font color="#fcfcfc">Not being</font>

371
00:16:20,479 --> 00:16:21,247
<font color="#fcfcfc">What you going to do</font>

372
00:16:22,015 --> 00:16:23,807
<font color="#fcfcfc">So you need to make those</font>

373
00:16:24,319 --> 00:16:26,879
<font color="#ececec">Known to the company a large organization at Large</font>

374
00:16:27,391 --> 00:16:29,183
<font color="#fcfcfc">If you do not follow</font>

375
00:16:29,439 --> 00:16:30,463
<font color="#fcfcfc">These security procedure</font>

376
00:16:32,255 --> 00:16:33,023
<font color="#a3a3a3">Compliance</font>

377
00:16:33,535 --> 00:16:34,303
<font color="#f3f3f3">Keep us legally</font>

378
00:16:34,559 --> 00:16:38,143
<font color="#d2d2d2">Ensure they keep us regulatory with a government body</font>

379
00:16:38,399 --> 00:16:39,423
<font color="#aaaaaa">Whatever the case</font>

380
00:16:39,679 --> 00:16:41,727
<font color="#b1b1b1">We've created you know even though it is just</font>
381
00:16:41,983 --> 00:16:44,287
<font color="#dfdfdf">Comes down from on high and CEO of the company said</font>

382
00:16:44,543 --> 00:16:48,127
<font color="#dcdcdc">He wants to increase security we've developed a security
policy you must follow it</font>

383
00:16:48,383 --> 00:16:50,175
<font color="#eeeeee">Listen to write their checks</font>

384
00:16:53,759 --> 00:16:57,855
<font color="#ececec">Authority before and</font>

385
00:16:58,111 --> 00:17:04,255
<font color="#c0c0c0">Yui Auto</font>

386
00:17:04,511 --> 00:17:05,279
<font color="#949494">Experian</font>

387
00:17:06,559 --> 00:17:09,375
<font color="#f9f9f9">So there must be a penalty in some way</font>

388
00:17:09,887 --> 00:17:10,399
<font color="#d7d7d7">Shape or form</font>

389
00:17:10,911 --> 00:17:12,191
<font color="#d9d9d9">A negative repercussions</font>

390
00:17:12,703 --> 00:17:13,215
<font color="#929292">4</font>

391
00:17:13,727 --> 00:17:15,007
<font color="#ededed">Not following being uncle</font>

392
00:17:16,799 --> 00:17:17,567
<font color="#f6f6f6">That's how we enforce</font>

393
00:17:18,847 --> 00:17:22,687
<font color="#fcfcfc">Then once we're all done we have a final draft ready to go we
publish it</font>

394
00:17:22,943 --> 00:17:23,711
<font color="#fcfcfc">To everyone</font>
395
00:17:23,967 --> 00:17:25,247
<font color="#e1e1e1">We make sure they've read it</font>

396
00:17:25,503 --> 00:17:28,063
<font color="#bfbfbf">Maybe do digitally sign documents if your</font>

397
00:17:28,319 --> 00:17:29,599
<font color="#fcfcfc">Disseminated them digitally</font>

398
00:17:30,111 --> 00:17:32,671
<font color="#cfcfcf">Mckeithen available on an Internet site or</font>

399
00:17:33,183 --> 00:17:34,207
<font color="#cfcfcf">Via</font>

400
00:17:34,463 --> 00:17:38,815
<font color="#9b9b9b">KO I can e-mail or an attachment or something always just
request it and we'll give you a copy</font>

401
00:17:40,607 --> 00:17:45,983
<font color="#c9c9c9">It needs to be available because here's what invariably
habits you write this wonderful security policy</font>

402
00:17:46,495 --> 00:17:47,007
<font color="#808080">It's cover</font>

403
00:17:47,263 --> 00:17:48,287
<font color="#fcfcfc">Every last thing</font>

404
00:17:48,543 --> 00:17:54,687
<font color="#f1f1f1">And nobody knows about it they have no idea where to get to
it how to get to it what it says or even though I know it's</font>

405
00:17:54,943 --> 00:17:58,015
<font color="#cacaca">Read it so and whatever I'm pretty sure I know what to
do</font>

406
00:17:58,271 --> 00:17:59,807
<font color="#dddddd">And then they do something that violates it</font>

407
00:18:00,063 --> 00:18:01,855
<font color="#f9f9f9">And now they're subject to the sanctions</font>

408
00:18:03,135 --> 00:18:09,279
<font color="#e4e4e4">Maybe they're getting fired maybe they're getting you no
wages doc maybe they lose vacation time whatever it is that you use</font>

409
00:18:10,047 --> 00:18:11,071
<font color="#e6e6e6">A formal write-up</font>

410
00:18:11,583 --> 00:18:12,863
<font color="#dddddd">You get three of those and you're gone</font>

411
00:18:17,727 --> 00:18:19,775
<font color="#fbfbfb">But it is our responsibility to make sure</font>

412
00:18:20,031 --> 00:18:21,055
<font color="#969696">That they do have that access</font>

413
00:18:21,567 --> 00:18:22,079
<font color="#f8f8f8">I can't find it</font>

414
00:18:22,591 --> 00:18:24,383
<font color="#b8b8b8">And then we have directed it to him and we have been</font>

415
00:18:24,639 --> 00:18:26,687
<font color="#f2f2f2">Neon blinking signs going</font>

416
00:18:26,943 --> 00:18:29,247
<font color="#fcfcfc">Here is the security policy</font>

417
00:18:29,759 --> 00:18:33,343
<font color="#b0b0b0">Read That's & Science dinosaur</font>

418
00:18:34,623 --> 00:18:35,903
<font color="#d5d5d5">Very important part right</font>

419
00:18:36,415 --> 00:18:42,047
<font color="#9b9b9b">I've also read and sign that they understood</font>

420
00:18:42,303 --> 00:18:45,375
<font color="#e7e7e7">We just got here</font>

421
00:18:46,655 --> 00:18:49,471
<font color="#eaeaea">Reading it is great but I need to make sure that you've
understood his</font>

422
00:18:50,495 --> 00:18:51,007
<font color="#d9d9d9">If I don't</font>
423
00:18:51,263 --> 00:18:52,543
<font color="#9c9c9c">Zack and come to bingo</font>

424
00:18:52,799 --> 00:18:54,079
<font color="#c0c0c0">I didn't notice what that means</font>

425
00:18:54,847 --> 00:18:56,383
<font color="#dbdbdb">Will you sign the thing</font>

426
00:19:07,135 --> 00:19:09,183
<font color="#e1e1e1">Then we want to avoid those situations</font>

427
00:19:09,439 --> 00:19:13,279
<font color="#e3e3e3">I'm not looking for trying to call the herd of bad employees
even though a problem</font>

428
00:19:13,535 --> 00:19:14,303
<font color="#f3f3f3">We will do that</font>

429
00:19:15,071 --> 00:19:15,583
<font color="#cecece">But</font>

430
00:19:16,095 --> 00:19:19,167
<font color="#a5a5a5">If I'd known that you read and signed it I've got it right
here in black and white</font>

431
00:19:19,423 --> 00:19:21,215
<font color="#f1f1f1">You can't try to pull the wool over my eyes</font>

432
00:19:21,471 --> 00:19:21,983
<font color="#fcfcfc">So you haven't done it</font>

433
00:19:22,495 --> 00:19:25,823
<font color="#d8d8d8">And then employee we're going to go number 7 here employee
tools</font>

434
00:19:26,079 --> 00:19:27,103
<font color="#ececec">Help enforce</font>

435
00:19:27,359 --> 00:19:27,871
<font color="#fcfcfc">The policy</font>

436
00:19:28,383 --> 00:19:29,663
<font color="#d6d6d6">And this is going to be found in very soon</font>
437
00:19:29,919 --> 00:19:32,223
<font color="#c8c8c8">Underway so whatever the case is Maybe</font>

438
00:19:32,479 --> 00:19:33,503
<font color="#fcfcfc">Through digital suits</font>

439
00:19:34,271 --> 00:19:36,063
<font color="#b8b8b8">You going to a website you click a check mark</font>

440
00:19:36,319 --> 00:19:37,599
<font color="#fcfcfc">Whatever the case is</font>

441
00:19:38,367 --> 00:19:38,879
<font color="#d5d5d5">Find some</font>

442
00:19:39,647 --> 00:19:40,159
<font color="#cfcfcf">Or</font>

443
00:19:40,415 --> 00:19:42,207
<font color="#eeeeee">Ensuring that that has been done monitoring something</font>

444
00:19:43,999 --> 00:19:45,535
<font color="#f3f3f3">Engagement staff training</font>

445
00:19:46,047 --> 00:19:49,887
<font color="#adadad">It's because they say and read and have signed that they
understood doesn't actually</font>

446
00:19:50,399 --> 00:19:51,423
<font color="#fcfcfc">Necessarily</font>

447
00:19:53,471 --> 00:19:53,983
<font color="#858585">Rantso</font>

448
00:19:55,007 --> 00:19:59,615
<font color="#f1f1f1">Backing all this up with some training is a very useful and
beneficial thing</font>

449
00:20:00,639 --> 00:20:01,151
<font color="#fcfcfc">Do</font>

450
00:20:01,407 --> 00:20:03,455
<font color="#e2e2e2">That way we know for certain and we ask questions</font>

451
00:20:03,711 --> 00:20:06,271
<font color="#dfdfdf">I didn't know that's what that meant I thought I meant
this</font>

452
00:20:06,527 --> 00:20:07,551
<font color="#f6f6f6">Great now we've clarify</font>

453
00:20:08,319 --> 00:20:11,647
<font color="#939393">It's a great way to clarify and know that all of our
staff</font>

454
00:20:11,903 --> 00:20:14,719
<font color="#c4c4c4">I've had an opportunity to answer any questions they have
about the</font>

455
00:20:15,743 --> 00:20:17,279
<font color="#f2f2f2">Understand how it's going to work week</font>

456
00:20:17,535 --> 00:20:19,071
<font color="#d3d3d3">Show it in real-time and implemented</font>

457
00:20:19,583 --> 00:20:21,631
<font color="#cccccc">They can see it in effect pragmatically</font>

458
00:20:23,167 --> 00:20:24,191
<font color="#fcfcfc">So it's always a good idea</font>

459
00:20:24,447 --> 00:20:24,959
<font color="#cfcfcf">Staff training</font>

460
00:20:25,215 --> 00:20:27,519
<font color="#f3f3f3">Regularly review and update</font>

461
00:20:28,543 --> 00:20:30,847
<font color="#dadada">Because invariably and inevitably</font>

462
00:20:31,359 --> 00:20:32,127
<font color="#fcfcfc">They go out of date</font>

463
00:20:33,407 --> 00:20:35,711
<font color="#e3e3e3">Things change we bring in new things we</font>

464
00:20:35,967 --> 00:20:37,247
<font color="#f5f5f5">Retire old things</font>

465
00:20:37,503 --> 00:20:40,831
<font color="#f3f3f3">And that changes the landscape of our business and our
organization</font>

466
00:20:43,135 --> 00:20:45,951
<font color="#e2e2e2">Go back to the drawing board see what's working see what's
not</font>

467
00:20:46,463 --> 00:20:50,559
<font color="#fcfcfc">Make some customizations maybe make some changes maybe do
some wholesale removal</font>

468
00:20:52,351 --> 00:20:57,983
<font color="#e6e6e6">That security policy maybe create a whole new security policy
based off of what the landscape looks like now as it has evolved</font>

469
00:20:58,495 --> 00:20:59,007
<font color="#f4f4f4">Into something</font>

470
00:21:00,543 --> 00:21:04,127
<font color="#e2e2e2">So that are are those are the security policy creation
steps</font>

471
00:21:04,383 --> 00:21:05,919
<font color="#fafafa">That are laid out by</font>

472
00:21:06,175 --> 00:21:08,735
<font color="#b1b1b1">Chinese counsel for the ceh V10 exam</font>

473
00:21:08,991 --> 00:21:10,015
<font color="#fcfcfc">Looking at our clock</font>

474
00:21:10,527 --> 00:21:12,575
<font color="#e6e6e6">A great spot for us to take another stop</font>

475
00:21:14,623 --> 00:21:20,768
<font color="#bebebe">Hacking security controls part 3 will be coming your way make
sure you see Parts 1 2 and 3</font>

476
00:21:21,024 --> 00:21:23,072
<font color="#bfbfbf">And make sure you see everything is ceh V10</font>

477
00:21:23,328 --> 00:21:26,656
<font color="#b1b1b1">The dentist put together for you that'll help you with that
exam rules around big-time</font>

478
00:21:27,168 --> 00:21:33,056
<font color="#f9f9f9">I just remembered</font>

479
00:21:33,312 --> 00:21:35,872
<font color="#b3b3b3">Just for for the sake of</font>

480
00:21:36,128 --> 00:21:36,640
<font color="#fcfcfc">It kind of goes</font>

481
00:21:36,896 --> 00:21:43,040
<font color="#b7b7b7">Is HR what their job is you don't need to know that if you
are in the HR like what</font>

482
00:21:44,064 --> 00:21:44,576
<font color="#cbcbcb">Asian 30s</font>

483
00:21:44,832 --> 00:21:45,344
<font color="#ababab">When it comes to the secure</font>

484
00:21:45,600 --> 00:21:51,744
<font color="#b9b9b9">This really quickly it is to publish the policy that's that's
part of HRS position to do the training for the info</font>

485
00:21:52,512 --> 00:21:55,328
<font color="#f8f8f8">Make sure that happens that falls under their
responsibilities</font>

486
00:21:55,584 --> 00:21:59,936
<font color="#c0c0c0">Also to answer questions about the pasta all those things we
just talked about those are the duties</font>

487
00:22:00,192 --> 00:22:01,216
<font color="#fcfcfc">Under HR</font>

488
00:22:02,240 --> 00:22:03,520
<font color="#f3f3f3">And of course monitor</font>

489
00:22:03,776 --> 00:22:08,128
<font color="#d2d2d2">Then we have legal you might have a legal team and I would
highly recommend it</font>

490
00:22:08,384 --> 00:22:09,920
<font color="#e1e1e1">If you can if you do have the minions</font>

491
00:22:10,176 --> 00:22:15,552
<font color="#fcfcfc">I highly recommend</font>
492
00:22:16,320 --> 00:22:19,648
<font color="#d7d7d7">And they make sure that no laws are being violated by the
policy</font>

493
00:22:20,160 --> 00:22:20,928
<font color="#e9e9e9">That's probably</font>

494
00:22:22,208 --> 00:22:25,792
<font color="#e8e8e8">Even inadvertently you might inadvertently violating some law
or maybe some</font>

495
00:22:26,048 --> 00:22:26,560
<font color="#eeeeee">White</font>

496
00:22:27,328 --> 00:22:28,608
<font color="#fafafa">Like a citizen rights</font>

497
00:22:28,864 --> 00:22:29,888
<font color="#ebebeb">Human rights</font>

498
00:22:30,144 --> 00:22:32,960
<font color="#f4f4f4">Maybe not in the worst way possible but in some way</font>

499
00:22:33,216 --> 00:22:34,496
<font color="#f8f8f8">You could be violating a law</font>

500
00:22:34,752 --> 00:22:36,288
<font color="#e9e9e9">Having legal look over</font>

501
00:22:36,544 --> 00:22:38,336
<font color="#d2d2d2">Those things.</font>

502
00:22:39,104 --> 00:22:41,152
<font color="#a7a7a7">Keep you out of that legal hot water and that's always a nice
day</font>

503
00:22:41,920 --> 00:22:43,456
<font color="#fcfcfc">Okay now I'm done for this episode</font>

504
00:22:44,480 --> 00:22:47,552
<font color="#ebebeb">Good catch Daniel intro to ethical hacking security controls
part</font>

505
00:22:47,808 --> 00:22:50,112
<font color="#d0d0d0">Three is coming your way this been part 2 in once
again</font>

506
00:22:50,368 --> 00:22:53,440
<font color="#acacac">Ceh V10 great series of Daniel's put together for you</font>

507
00:22:53,952 --> 00:22:58,560
<font color="#bcbcbc">Make sure you want it'll help me with that exam rolls
around</font>

508
00:23:00,096 --> 00:23:06,240
<font color="#bbbbbb">Library with this thousands of hours of complementary
information it's there to help you go even further so checked out</font>

509
00:23:07,264 --> 00:23:13,408
<font color="#c2c2c2">I told her you know but I see Brody vippro TV is binge-worthy
thanks for watching him he will see you again</font>

510
00:23:20,576 --> 00:23:21,344
<font color="#f8f8f8">Thank you for watching</font>

You might also like