WEBVTT

00:00.490 --> 00:06.220
Vulnerabilities are just a fact of life in information technology.

00:06.430 --> 00:12.190
In fact, in an upcoming video, I'm going to go ahead and classify the different types of vulnerabilities.

00:12.430 --> 00:15.330
That's something that is very important for us to do.

00:15.340 --> 00:23.230
And one of the reasons we want to do that is because of the fact that these vulnerabilities are so common.

00:23.560 --> 00:25.210
You know, they're everywhere.

00:25.420 --> 00:31.690
So we need to categorize them and then work to guard against them being exploited.

00:32.230 --> 00:33.730
I'm getting ahead of myself, though.

00:34.060 --> 00:35.800
What is a vulnerability?

00:35.890 --> 00:38.800
Well, it's any weakness that can be exploited.

00:39.100 --> 00:41.600
As you're going to see, we're going to classify these.

00:41.620 --> 00:47.890
So we might be talking about some vulnerability that exist in the system because of a misconfiguration

00:47.920 --> 00:48.390
doe.

00:48.850 --> 00:50.020
So that's a problem.

00:50.200 --> 00:52.540
But maybe it's a software bug.

00:52.570 --> 00:54.100
Maybe it's a hardware bug.

00:54.760 --> 01:00.790
We are going to want to obtain full, complete lists of vulnerabilities.

01:01.000 --> 01:07.780
We want to know about the vulnerability before the computer criminal does, if at all possible.

01:08.560 --> 01:16.750
Now, when we learn about vulnerabilities, what we need to be doing is analyzing them and thinking

01:16.750 --> 01:18.040
about risks.

01:18.310 --> 01:26.200
By the way, this often has to do this analysis with the value or the sensitivity of the information

01:26.200 --> 01:27.040
that we're dealing with.

01:27.400 --> 01:27.670
Right.

01:27.670 --> 01:29.080
So it's that balancing act.

01:29.320 --> 01:31.960
You've got to go, geez, is this even important data?

01:32.140 --> 01:32.680
Oh, okay.

01:32.680 --> 01:33.730
It is important data.

01:33.910 --> 01:37.570
Oh, there's a vulnerability that could make this data be accessed.

01:37.870 --> 01:43.210
What are the chances what are the real chances that someone would do that?

01:43.240 --> 01:47.710
So these are all of the types of questions you need to be ready to ask yourself.

01:48.730 --> 01:56.440
Now, the next thing I want to discuss with you is the simple fact that assessment reports are going

01:56.440 --> 02:01.960
to be a huge part of what we deal with now in cybersecurity.

02:02.320 --> 02:09.070
You want vulnerability assessments performed against your hardware and software, and in fact, you

02:09.070 --> 02:14.440
may be the one performing the assessment, the vulnerability assessment testing.

02:14.440 --> 02:14.790
Yeah.

02:14.800 --> 02:17.710
It may be your job to produce these reports.

02:18.680 --> 02:24.410
There are four styles of reports I want you to be familiar with.

02:24.830 --> 02:29.990
You can create vulnerability assessment reports that are what we call product based.

02:30.320 --> 02:34.100
These are typically private, completely private.

02:34.100 --> 02:36.560
So you have some router.

02:36.680 --> 02:43.310
You have this software that is going to stay within the confines of your organization and is going to

02:43.310 --> 02:45.820
privately on a private network.

02:45.830 --> 02:49.490
It's going to test that router for vulnerabilities.

02:49.910 --> 02:57.050
This is very different from a service based type of vulnerability assessment report creation in the

02:57.050 --> 02:58.460
service based approach.

02:58.640 --> 03:00.650
You're working with a third party.

03:00.920 --> 03:07.910
And what's probably happening is the data is being sent outside of your private network and your private

03:07.910 --> 03:08.720
organization.

03:09.500 --> 03:14.570
There is a tree based assessment report approach in the tree based.

03:14.600 --> 03:21.710
You're providing a ton of information upfront and then the system will test for vulnerabilities.

03:22.040 --> 03:29.780
And finally, there's the coolest name, the inference based type of assessment, report generation

03:29.780 --> 03:30.320
process.

03:30.500 --> 03:38.150
And with the inference based, the software that's doing the vulnerability assessment will actually

03:38.150 --> 03:40.910
be mapping out the addresses and the ports.

03:40.910 --> 03:48.240
And so it will be going in and it will be discovering what needs to be vulnerability assessment test.

03:48.260 --> 03:48.890
How cool.

03:49.160 --> 03:55.220
So we're getting a lot out of that software approach to assessment reports.

03:55.760 --> 03:56.230
All right.

03:56.240 --> 04:00.380
Well, we've got lots more to say about vulnerabilities.

04:00.530 --> 04:04.100
So I want you to I want to thank you for watching this.

04:04.100 --> 04:05.750
Look at the basic concepts.

04:06.200 --> 04:07.880
But more is on the way.
