Time
1 hour 41 minutes
Difficulty
Beginner
CEU/CPE
2

Video Transcription

00:00
all right. Welcome to missed 853 security privacy controls. Where we'll be talking about the document. Some of the ideas behind that this one doesn't understand. Not really focusing on specifically every one of the hundreds of controls.
00:17
And so for Model One will be getting a known estate and 53 1st just said, get the background to it
00:24
First, let me give you introduction. My name is Phil Cope. I'm a system administrator before going to cyber our disciple Security Or I start working as a pen tester Auditor. I've been doing instant response without testing more recently,
00:39
so I have 20 years of cybersecurity experience. My undergrad was in information systems. My master's degree with an e commerce. Why was a self employed So I was trying to get a bit of a mix between business and not specific. I t
00:53
I finish up my doctor in cyber security
00:57
and I have a C i S S P certification and a couple of the offensive security certifications.
01:03
I said there's a picture of ah computer there. It actually looks like a keyboard was my first, uh,
01:10
computer when I was when I was young, when I'm not doing I t stuff. I still like programming, but I also like, try to get out, do mountain biking, hiking, photography. There's a picture up there about what off when a shot I took from Harpers Ferry, West Virginia
01:25
If you're interested in contacting me, Lincoln is my best the best way, and I have been up there on the screen.
01:33
So for less than 1.1 disc over a little bit on the course, just kind of get a free where prerequisites and understand what the course is about. What's gonna be important?
01:42
I mentioned the prerequisites. They're not hard too fast, but you should understand a little bit about the NIST risk management framework. I'll be calling it the arm F Cyber security People love jargon link are this lingo. So just get to get to know
01:57
that said I might be switched between Arm F and risk member Mr Rist Magic Framework.
02:05
You need a little bit about Phipps wanting that fits 1 99 I'll talk about it, give you information, but it is the prerequisite to 853 to understand.
02:15
There's also missed 812 which is core principles. That is good to understand. So if you know the kind of the terminology says you're reading 353 is it really rains? In this document? You understand their definitions of what things mean
02:30
and also confidentiality. Integrity, availability are three very important concepts.
02:35
They come up a lot of lots of times throughout the throat, through through the documents role
02:40
otherness, documentations Well,
02:45
so within the course materials
02:46
provided links here, you can get that. They're also very easy to find. So that's 853. Guess that's what we're really talking about. There's a dinner 37 with It's the risk management framework, said 51 99 200 are prerequisites.
03:01
You don't have to read all these, Understand? Of course, we'll talk about them, but maybe looking at them and getting idea what there are will help understand.
03:08
And as you mentioned, 812 which is the introduction of information security
03:14
and also within the course materials later on in module to will be talking about the ESCAP tools, which is automated tools for establishing baselines. So have a windows and a Lennox one. There you can you can take a look at those later on but will be referencing those documents as well.
03:31
The target audience is really anybody in cyber security. Now, just because 853 is important everybody where you might come into it, no matter what your role. So as an authorising official, you're gonna be looking You're gonna be trying to assess risk across your systems across the organization,
03:50
and you probably see these nous controls mapped. And if not, you'll you can understand the source material.
03:55
The same thing would be for ah, sis. Oh, with the be assessing risk and then as an isis so you might be looking at or you're the interface between the system owner and the the technical staff into you're really gonna be trying to understand those risks mapping Tunis controls and being able to talk to executives.
04:15
Even if you're a technical person. Azad ministrations. Er, you might be seeing these controls coming coming in. And when you're running your automated tools or you may get reports from somebody's you need toe, really understand what they mean in the context of the risk to your system and how the map vulnerabilities.
04:33
So just kind of some of the notes will be using missed 800 revision for everybody calls the Red For another jargon, our lingo did to get used to.
04:44
There's red five that's coming out at the time of this recording, but it's not finalized. We're not gonna be using that will be focusing mostly on ref or we'll talk a little bit about red five within the course. Just understand where it's going.
04:58
So a couple places you'll see this little pencil icon. I tried to put it in there to say reference that external material that I mentioned, you know that their source material, if you want to look at
05:08
and then the other one is this little character there that I'm calling practitioners notes. I've tried to intersperse that throughout the videos, of course, to say, you may not read this or get this understanding specifically from reading the documents, but this is something that's important from somebody who's actually practices in the real world.
05:26
Here's the 1st 1 a practitioner notes. Always check the revision used by the organization, so it's it's not guaranteed that an organization is right is using the most recent version just because it's a lot to do to transition from a new one to an old one usually takes a couple of years, and it may not apply. So
05:45
don't spend time
05:46
working on a revision and then go back and you ask him. And then also, you worked on all these controls that aren't applicable.
05:54
All right, here's a rough outline. So first with the module one. Except we're getting noticed a little bit. Well, we're doing this introduction. We understand how it fits into the arm F process because it's the core that it goes across all the different phases.
06:09
I said, We're focusing on revision for, but we'll talk a little bit about region revision five and just kind of understand how to transition even beyond that.
06:18
And then I'm gonna look at a little bit. How honest explains 853 just so because it's their documents. So you need to understand why they have to use a certain charm terminology and just understand throughout this. Like I say, they is n'est they're the ones that publish it, but it's put out there for
06:36
many, many cycles, and there's many revisions. Hundreds of people respond to it, so it it's a community effort, but we just say n'est
06:44
as they're not the only ones talking about the document
06:47
and the module to will focus a little more on actually using the security controls. See how they apply.
06:55
He's learning objectives just kind of set here on all the objective I've created. You'll see this inverted pyramid, which is Bloom's taxonomy. It's just a way of organizing the way, acknowledges learned. So the term, remember would be has the action. Verbs like list
07:14
described things like that, Uh, and as you get
07:16
further on its more concentrated form or
07:20
it's not more important but a little bit different. So down at the bottom we have created is thes objective you create, so you would actually be developing things like that.
07:30
So you see that throughout the just kind of understand what you're learning,
07:33
but specific to this, we're gonna be learning. About 853 control families described where it belongs in the arm F process. Explain the need of, ah, for common taxonomy. I call it a taxonomy. Just cause I like to use that worries. It's these buckets that if it fits into so we're all using the same lingo.
07:51
It's it's a taxonomy, it's a framework.
07:56
And then we're gonna demonstrate the selection of a baseline. We'll talk a little more what that means, but that's just understanding that what controls apply based on your categorization, and then you'll be able to differentiate the parts of 853 control. So understanding what each part means. So that again,
08:13
I'm not gonna explain all of them to you. It's easier to stay. Here's how to interpret them and then you can you can you be able to do it yourself.
08:20
And we're gonna learn about common hybrid system controls and what those mean in the context of a crediting a system.
08:28
And then we'll talk about mapping a weakness to 853 control. So you have these automated tools. They output results. How does it How does that work into the 8 53

Up Next

NIST 800-53: Introduction to Security and Privacy Controls

This course will provide Executives, Assessors, Analysts, System Administrators and students with the foundational knowledge to understand NIST 800-53 Security and Privacy Controls.

Instructed By

Instructor Profile Image
Philip Kulp
Instructor