Time
7 hours 33 minutes
Difficulty
Advanced
CEU/CPE
8

Video Transcription

00:00
Hello and welcome back the Cyber. It's certified advance. A critic practices certification Preparation course. We can continue our discussion on margin number three, which is titled Organizational Security. These other objectives of this particular marker. Let's not turn attention toward a discussion or participate in change management.
00:21
Let's take a look at a pre assessment question before begin this process. Which of the following operational aspects of configuration management is it, eh?
00:30
Was it be
00:32
or is it C
00:34
or D?
00:38
If you said later, eh? Your absolute correct its identification, control, accounting and auditing.
00:45
Well, now when you think about
00:47
change control,
00:48
it refers to the formal procedures adopted by your organization to ensure that all the changes to your systems or whatever applications somewhere a seven to what we call a poor pret levels off management control.
01:00
Changing so what it does. It seeks to eliminate unauthorized changes and reduce the defects and problems related to a poor planning and communication of those changes. Change controls offered and four student use of a change control board again. What? This board doesn't review those changes for impact and when it does essentially so sure that they're appropriate implementation
01:21
plans have been prepared and it follows changed to approval. Impose implementation type review.
01:30
Looking again at the invitation of Configuration Mansion. On the other hand, this is clue document. How again, configure It mentions, manage rose responsibility, how configuration items changes are made and communicate all aspects of gin of the CME to your project stakeholders. The overall objective again of configuration management plan is to document in form
01:49
your
01:49
project stakeholders about the configuration magic or the CM within a project, what seem to be used and how they will be applied by the project.
02:00
Throughout this system, lifecycle changes made to the system is individual components. Oi! It's operational system can induce new vulnerabilities and thus impact the security baseline configuration Management is a discipline at six to mansion configuration changes so that they are properly approved and documented.
02:16
So did the integrity of the security state that's maintained so that the disruption to performance
02:23
and availability or minimize
02:25
when you think about a security impact assessment, it is analysis conducted by a qualified staff with an organization to determinate extent to which changes to your invasive system affected security posture of the system. The rationale for this a Pro pro is because in face assistant, typically in a constant state of change,
02:45
is important, too.
02:46
Understand impact These changes on the functionality of existence Acuna controls and extent of organizational risk. Tolerance. Security impact analysis is incorporated into the document configures and change your whole process.
03:00
Lastly, you secure the package now. It's may also include an assessment of risk to understand the impact of the changes and to determine if additional couldn't shoulder required security. Packing knives is important activity in the ongoing monitoring of his scooter controls and your information systems.
03:15
This brings us to systems, architecture and interoperability of your system. A system, architecture or system architect is a conceptual model that defines the structure, behaviour and more views of the system and architecture. Description is a former description and representation of a system organized in a way that it supports
03:34
reason about the structure and the behavior of the system,
03:37
and offer really describes extent to which systems and advices can change exchange data and interpret that share data.
03:46
Now we get into testing implemented patches, fixes nice was update when you think my Patch man trick is the application software firm will patches to correct. Vulnerable is is a critical component of vulnerabilities and configuration management practices. When you look at it, most of the security breaches that occur
04:04
have occurred over the past decade are not the result of a so called zero day attack, but rather about perpetrate
04:12
by Attackers explored in your known vulnerabilities. So the past, him said it must be a quiet,
04:17
obviously must test amount. You might describe him. He must also verify it and coordinated in Children. It which means process, must be designed and followed religiously to ensure the overall effectiveness. Now, one thing that's really interesting nowadays in the past, when you had your program that were paired of various software application
04:36
that we're not so much concern again about the security aspect of that.
04:42
What it was primarily concerned about was making sure that it actually work. But nowadays part of that process and now we're seeing a lot of applications. Security is integrated within the software development assistance of intimate life cycle the purposes again to make sure that we mitigate a minimize the impact to those
05:00
potential applications that will
05:02
producing are putting together as well. So again, it looks at it forced the phases. You have requirement gathering and analysis. It looks at the design implementation You tested your deployment as well as the mains. But the most important thing is security is important. That overall process. In the past, it was not the case. This makes us to our post assessment course. In
05:23
what does Father standing with system that advice, get exchange data and interpret that share data?
05:27
Is it a interoperability of system, the system architecture? See deterrent controls or D identity and several factor authentication?
05:38
If you say, let the air you after the greatest title in probability of the systems,
05:44
this brings us to our review. During this price of you discussed implantation of configuration management plan, we discussed it defined exactly what security impact analysis is all about. We took a licking security architecture operative system, and last we took a look at testing and men and patches fixes as well as updates,
06:01
and our upcoming presentation will be discussing Section number five, taking a look at participate in security awareness and training. Again, I look forward to seeing you on the next video

Up Next

CompTIA CASP+

In this course, you will learn all of the domains and concepts associated with the CompTIA Advanced Security Practitioner CAS-003 CASP+ Exam. Through this course you will be fully prepared to sit for your CompTIA A+ Exam!

Instructed By

Instructor Profile Image
Jim Hollis
Independent Contractor
Instructor