Lesson 2.2 You can't protect what you don't know about
in this lesson. We're going to talk about how you define what high value assets, or HV A's are and how they impact risk. And security decisions will also understand the need for mature I. T. Asset Management or I Tam and discuss the type of information that search should have access to in order to be successful
during an incident response.
So let's talk about high value assets.
High value assets are those assets that are valuable to the organization's NOAA trickery there in the name. But most organizations, I have found, haven't really done a good job about going back and identifying what in fact is considered an H V A. For them so well, look at this as we go through this lesson,
but it's critically important to know where the crown jewels restored. What are those assets and those
applications that, if they were to go down, would be detrimental to the organization and having some smarts around? What are the riskiest applications that you have? And how may they be impacted by a cyber incident
with I T Asset Management? It's comprised both of hardware, asset management and Software Asset Management.
It's also talking about the criticality of systems and though, should be taken into account. So it's great and one of the top 20 security controls to have a hardware and software asset management list. And as the lesson title describes here, you cannot protect what you don't know in.
I could say that 100 times it really is absolutely true.
It's why it's usually listed as one and two and the top 20 security controls of anywhere you look.
It is simply because of that you cannot control or protect. What you don't know is out there. So when we look at I ts at management,
it's great to have that list. But then take it a step further and say Here's the listing of all the things we have But then here's the criticality of those. We cannot treat every server, every application, every database the same because they're not the same
disaster recovery and business continuity planning Rto and RP Oh, we talked about that in the last lesson.
They all should have those objectives included in this decision on what is a high value asset
and the next part of it is a mature change management database, or CMD be with clear linkages with other systems is absolutely necessary
if you are a cyber incident responder, and you need to know how a particular system being taken off line is going to affect the rest of the organization. That's where CMD B comes in to play.
What router is that hanging off of? What switch, what ports on the switch, What databases does this application talk to? What's the front end application and maybe the Web server look like? And what is it connected? Teoh. What other applications may ride on the same physical server? Because they're all virtual applications?
These are all things that should be clearly linked together in a C M D. B.
Accurate information as well is very important for an incident response team. To have access to
search should always have access to up to date network diagrams. And honestly, this is something I see a lot of organizations not do a very good job with. I've gone and asked for network diagrams and been told we don't even have any, and I've seen some that are years outdated.
So then you have to pull in the network architecture, people and the individuals that just know the network because they built it and sketch something out quickly,
which is never a good way to do business.
Certain also needs access to the sea. MDB data that I talked about They should be able to pull and have read only access to the Sea MDB application to find out the information we've been talking about.
Also, security plans for systems I t should be writing system security plans for all of the systems that are being put into service. And this includes things like ports and protocols, recovery time objectives, recovery point objectives, data owners, sensitivity of data.
AP I calls and interconnections between systems,
Internet accessibility and requirements for external parties to touch the system. Any security that's in place in any logs that have generated all of these things should be already well documented for any system in an enterprise or in a business or an organization,
and certain needs to have access to those so they can see how systems talk to each other.
And then, of course, vulnerability scanning results.
It's really important to know what is out on your network that is vulnerable. What vulnerabilities do they have? What has been identified already? Do you have systems that are critical and also vulnerable, and that can help shape the incident responders targeting and triage of incidents that come out.
So some quick quiz questions on this Why does certainly to have access to a c M D B
A. To make sure that I t has one
be to provide incident responders with dependency and impact information during an incident?
See, in orderto audit the I T department, or D. None of the above.
Well, the answer to this one is be to provide incident responders with dependency and impact information during an incident. If you remember, I spoke about
how it's important for an incident responder to be able to walk in and see how a server talks to a database. What switches there on what other systems they may interact with
because it's not only important from connectivity reasons, but also if something has to be taken off line, it's important to know what else that may impact.
Another quiz question. Why should organizations identify their high value assets?
A. To make auditors happy during an annual PIN test
be so those devices could be patched last. So no impacts happen to the business or C to give additional context to vulnerability management, risk assessments and incident response activities and put some additional intelligence into decision making.
If he answered c on this one, you got it correct.
It is so important to not just patch things and jam patches out without any type of context or understanding what's critical, what's not. And when I say that, I mean, we shouldn't be patching
a end user desktop oven intern before we patch the domain controllers. And I see that all the time where patches come in and they just get deployed. But there's really no intelligence around any of this and making sure that we take care of those high value assets that we've identified
and that those are the things that we triage and prioritize. First
is very important, but it requires some maturity, and a lot of organizations just aren't there yet. So that's why this is the right answer to make sure you have some intelligence wrapped around vulnerability management patch management and also incident response. If you get to alerts at the same time and you're trying to triage them.
One alert is for a high value asset. One alert is for
a non high value asset.
You should be most of the time investigating that high value asset first, because we've already identified that any impact to that system is going to be much more detrimental to the non high value assets.
So in summary in this lesson, we talked about what HV A's are and how they may impact security decisions. Also the type of information that Certs should have access to to be successful and then finally the need for a mature I T asset management programme.