Shon Gerber from CISSPCyberTraining.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge in cybersecurity from being a Red Team Squadron Commander; Chief Information Security Officer (CISO); and Adjunct Professor providing superior training from his years of experience in educating people in cybersecurity.
In this episode, Shon will talk about the following items that are included within Domain 4 (Communication and Network Security) of the CISSP Exam:
· CISSP / Cybersecurity Integration – Data Communications
· CISSP Training – Implement Secure Communication Channels
· CISSP Exam Question – Point to Point / OSI Layers
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
https://www.isc2.org/Training/Self-Study-Resources
Quizlet
https://quizlet.com/87472460/official-isc-cissp-domain-1-security-and-risk-management-flash-cards/
Infosec Institute
https://resources.infosecinstitute.com/category/certifications-training/cissp/domains/communications-and-network-security/secure-communications-channels/#gref
Wikipedia
Transcript:
Hey y'all is Shon Garrigan was her new cyber risk I hope you're all having a wonderful day today It's a great day in Wichita Kansas A Heartland of America. Basically smack dab in the middle of the United States So yeah there's pretty flat here it's pretty hot here but it's July 8th. Hey just wanted to go over We're going to be talking about in our site. OSI CISSP cybersecurity integration. Data communications. And then on our CISSP training where to get into implement secure communication channels. And then in our exam question where to get to point to point, it's not from like point a to point B it's a different kind of point to point. And then the OSI layers. All right before we get started I want to just throw out a plug there for my C I S S P training that you can find on youtube.com. You can check it out there at a Shawn S H O N Gerber. And I have CIS. training CISSP certification training You can find specifically on YouTube or you can go to reduce cyber risk.com at CIS slash C I S S P dash training at. you'll take you to the UME links as well So you check it out It's a lot of great information you're going to have there, all the domain stuff that you're going to have for as it relates to the CIS. P exam. To properly prepare you for that exam It's a great way to augment your training. And as you well know, you to me has some great deals as it relates to training. especially as for what I got So. Some really good things. Also all my CAS is P training. the various domains will be updated on a weekly basis Now some domains may be. Updated one week and then another domain the next week But they all all of my training is updated on a weekly basis So. some great things that are coming out there as far as the CISSP to help you be successful and pass the exam…Okay So the CIS is P integration This is from the InfoSec Institute and we're going to focus on objective four dot three which is implementing secure communication channels. According to design. and the topic will be specifically data communications…Now as you're dealing with different communication protocols we're going to you're going to hear some different terms and it's important to understand what these terms mean. you'll hear these terms thrown out like SSL and TLS and all of that, not TLC which is tender loving care It's different It's transport layer security Yes Security. Now the SSL is secure socket layer and what this is it's a standard security technology to create an encrypted link. it what it does it ensures that data is pat that's data's past remains private. It means specifically for private to individuals. And it does not go out to anybody else And that's the whole purpose of it right Is to have the SSL to protect your data and to ensure that it is private from other people looking over and stealing your information. It is also considered an industry standard to protect online transactions Now. SSL has been moved on It was it's still considered a industry standard. However the new version of SSL is what we call T L S I which is transport layer security. And they have TLS version two as well as one of the key points that are out there. But it's, it is the newest version of encryption of TLS is, and it utilizes symmetric crypto cryptography. basically there's two layers as a TLS record and a TLS handshake. and those are the aspects around the security but so you'll hear a lot of the synonymous…where you see third grade education. the SSL secure socket layer is being used synonymously with TLS, but everybody has moved on In most cases if you are dealing with the next level of security is around TLS and it's the next area. I said that twice. I know it's kind of not really cool but anyway did I did just did. All right then there's another product out there called swipe which is your swipe IP security protocol. and this little S little w capital IP and then he you got to love how they'd make these fun little things Swipe. it provides confidentiality integrity and authentication of network traffic. it does not however handle policy and key management. it that has can handle outside of the specific swipe protocol. so that is those just specifically swipe encapsulates each IP data gram Okay To be secured with inside the swipe packet. So basically the IP datagram which we talk about in the different levels of the OSI model and so forth the IP data gram will be secured inside the overall swipe packet And that's where it encapsulates it and wraps it up in a pretty little boat. But that is the swipe IP security protocol…Set is a secure electronic transaction and what this is at communicates. It's a communication protocol standard for securing credit card transactions…Set is a secure electronic transaction. and it's a communication protocol standard for securing credit card transactions. and so that's what you'll see typically within when you're using credit cards now, as in the United States. Many other countries have just got back from China They don't really use credit cards They use their product called we-chat and or Ali pay And it's the same concept but they it has to be tied to a bank account specifically within China. And but it's what they utilize at least in the United States for secure electronic transactions. it has a set of security protocols and it's set user provides electronic wallet or digital cert that basically puts you who you are. and if that's kind of how the whole. Basically ties you to the individuals through that digital SERP. the digital certificates and signatures are amongst the purchasers the merchant and the purchasers bank. It's just kind of how they the. The digital signature works between them all. But that is utilizing the term. Are the protocols security protocol of set secure electronic transaction…Then there's pap which is the password authentication protocol. Now this is a password based authentication protocol used by point to point protocol or PPP through triple P. you deserve Pippa PPP. it's considered a weak authentication scheme and it's not one that typically is used as much, but it still is used It's just not. you wouldn't want to use it for your main authentication or your main type of authentication scheme that you're working with in your organization. It does transmit un-encrypted passwords over the network So hence that's kind of why it's not utilized as much. there are some others which is the extensible authentication protocol which is EAP. You have your secure remote procedure call which is S dash RPC and then chat which is your challenge handshake authentication protocol. Now as far as the CISSP is concerned I remember seeing all of these you will you will come to some level of understanding around all three of these pieces are all these various levels authentication protocols And so. protocols. They are on the CISSP exam. Garrone T now. Some may not be on it Some will be on it but you do they do cover these in different aspects on the CISSP exam. So it'd be prepared for that…And understand how they are used. the key point around this again in the exam is that you will see they utilize these in ways that are kind of designed to trick you up a little bit and they'll utilize the pap aspect and they'll say password authentication. Protocol is used with set and you go oh yeah yeah PPP or no eight pap Wait. I said oh no And you'll make a mistake So, the goal is is to understand all these protocols and how they all work together. Okay So that is what I have for the CISSP integration And that again was from InfoSec Institute. Let's roll down to this CIS JSP training. Okay And the CISSP training we are gonna focus on objective four dot three implement secure communication channels According to design. Okay Voice. voiceover digital is quickly becoming the standard from teams to Skype to you Name it. Voice is becoming the standard over the digital platform, but this the old business of private branch exchanges or PBX's is going away And that's your typical phone routing switch switches that are out there. Those are all going away to a product called VoIP. Which is by far more flexible and secure. in most cases, Yeah I mean flexible in the fact that sometimes Skype doesn't work so well. But VoIP is a TCP IP network connection And it's configured to be simple, to the more complex depending upon what level of encryption and where that is protected at now standard phone conversations does have encryption built into it. these these do occur. However it depending upon if you want to have secure voice, like in the case of the military there's different levels of, infrastructure that needs to be put in place to ensure that the communication channel can be clear from. somebody over eavesdropping and con and collecting the information. Now there are some problems associated with VoIP A caller ID can be spoofed That is a possibility, and they are susceptible to denial of service attacks Hence the reason is they're on an IP network So if they're on an IP network they can be. denial of service They can basically be that they can flood gates with the network connections with nothing but garbage and therefore your voice connection will go down. Man in the middle. Issues can occur with VoIP and the traffic is not that is not encrypted can be deciphered. so you can listen to these information these conversations. If it's not encrypted. Now in many cases this stuff is encrypted but there are situations there are protocols where it may not be. So therefore you need to be aware that voice is like anything else Now if you do standard PBX where it's right over the wire, those can be listened to as well but they are not susceptible to denial of service tax. Unless you take out a switching environment then yeah Then your voice. You're basically you're. One heart. The line the phone line goes down. That's it? He goes bye. Bye. Goodbye. The next is PBX fraud What does that mean Well basically in the past it used to be where they would do it would take advantage of long distance phone calls and they would call this. Freakers And now I say that because it's still. We usually may have in the CSPs cause it's still a valid attack. And you deal there's there still are lines out there that you can utilize from a freaking standpoint. But it basically was designed to gain unauthorized access to phone systems and they would rack up toll charges for other peoples, that would try to be utilizing Unless your international phone calls or whatever they would then rock up phone call charges for them. This is becoming less and less of a problem because of cell phones and those that capability but it still does exist. that to limit this you'd have logical or technical controls on the network specifically to keep this and this would roll into administrative. that you need to have in place. you want to also avoid securing These are you don't want to avoid securing these older systems. You want to look at what are some of the ways you can secure them and protect them from these type of attacks from a PBX fraud attack. So don't just say well they're all So nobody's going to mess with them I'm not going to worry about it. That's really a bad idea in today's world where everything's interconnected more and more than ever You can be vulnerable to any type of attack that may be out there So again PBX fraud is still existed It still does exist and people still do it, but it is come down quite substantially from the previous days of like, Mitnick and all of them…Multimedia collaboration what this is is working on projects from a distance So now if you are anybody in the cybersecurity space or in it, you realize you know what, there's all kinds of collaboration that occurs through multimedia uses. from you incorporate email video voice you name it It's all there from a multimedia stay. and everybody does it. so therefore you must consider all of these voices security, all of these channels to secure, which becomes a very daunting task as a cybersecurity professional. you will see that this is a problem and it's something we struggle with on a daily basis. these remote meeting concepts and capabilities These are all something that you'll have to go through. And as you'll see they understand that from a multimedia standpoint it is everywhere. Now remote meetings this allows for interacting with remote parties which kind of comes into the collaboration space And it's important that you be able to do this in today's world because guess what? It's everybody's shares it and everybody's working remotely and they're working from dis I can't think of that big $10 word but from remotely geographic remotely separated locations Yeah There was a probably a really cool $10 word that would work well there, but yeah I couldn't think of it. now there's some key concern security considerations As you're dealing with this strong authentication activities are logged and monitored and open and encrypted. So those are key aspects you need to be aware of as you're dealing with remote meetings. And also understanding who's listening in And if there's somebody that logs into your remote meeting, that you don't know who it is, you might want to boot them out and tell you can figure out who they are because guess what? A lot of people drop in I used to do that We would drop in on phone calls. conference calls but see us before Skype where they'd have a phone number pop up. And so therefore they wouldn't know who we are We would just log in and listen. Instant messaging What this does is this allows for real time chatting right So this is the ability for you to have real time chatting through a digital media platform And everybody, everybody does. Instant messaging at some form or another it could be from your, when you're on Facebook it could be in various aspects but allows you to have instant communication back and forth through a texting environment. Now it is possible to do file transfer through instant messaging. And so from a security professional you need to be aware of that And if can you send voices can you send pictures Can you do all of those aspects can be put and they're all done. in potentials. On this security environments. sending social security numbers or PII personally identifiable information over texting is a bad idea Typically. there's some key security considerations that you need to keep in mind That's careful communications on what you put in a text Cause guess what? If you put in a text it's got to come out They always do They never ever not come out They always do. you also need to have records management Cause these records they go everywhere and you will run into them They will they they get legs and they move. So understand the records aspect around this. Also you need to limit your encryption as it relates to. or it has limited encryption I should say. The the aspect of text messaging, some, some text messaging depending upon the application you use does have a little bit of encryption involved with it or does have encryption. But in most cases these do not They the only encryption they have is the encryption through the telephone network the CDMA network. In most cases there are no. encryption from a texting standpoint. many are public services such as slacks Hangouts et cetera. And so when you send this out your text it's going to the cloud which everybody it goes to a server which everybody potentially could have access to. At least at a minimum the administrators have access to it. So there is no privacy There's very limited to new privacy when it comes to texting Snapchat all of those those things do get legs and move. So as a cybersecurity professional it's important for you to make sure that you teach people that this is a situation and working on your CIS. Especially you need to understand how that all plays into the overall game…Security and the email. Do you need to address this with your security policy There are some acceptable policies for email that you need to put in place. And as you're looking to secure your email, there are ways to do this through PKI which is your public key infrastructure You can get digital signatures on your email which will help protect it. but you also can have access controls Do you allow all old w a like is your, outlook web access you and your basically your online capability to your email? Do you have multi-factor in place on your email That's available online. and so those are key considerations And also as you're dealing with privacy around email it's important to consider. How do you protect your company's email as it relates to GDPR? So it's important that you have that in place as well. So you as a cybersecurity professional working on your CIS S. P you need to understand V. Cognizant of these different aspects around privacy. And and what you should do as far as dealing with the email, also understand the security person You should not have access to email You should have or people's emails You should have that all run through your legal and compliance teams If you have them. if not and you are the person then you definitely need to run that through legal before you do anything along those lines. as your backup and records management keeping emails until the apocalypse just a bad idea. so you need to consider getting purging those emails when it's appropriate, do not keep that stuff you're getting from legal considerations It's important to understand that you don't need all that forever. now if your company had puts it on legal hold where you have to maintain it well then obviously you have to keep those emails for whatever reason. But for the most part you you need to make sure that you don't keep any more data than you absolutely have to because, because storage is so cheap everybody keeps everything. It opens you up for a lot of different issues especially legal and litigation issues. so just kind of keep that in the back of your cranium…As we're looking at other email security solutions you need to understand the secure multipurpose internet mail extensions S mime. And privacy enhanced mail which is another term which is PEM. And then you're pretty good privacy which is PGP which you'll see with from an encryption standpoint for your email works typically for most of those providers that provide you some level of. email protection The PGP is typically used for the third party types. and S S. Mine is used for the more like your outlooks and so forth. And then you have your sender policy framework which is the F S. F those are again other email security solutions that you need to be aware of for the C I S S P…Okay C I S S P exam questions domain four…All right So in this question we're going to be talking about point to point. What layer formats packets from network layer for transmission and is commonly used point to point protocol and the integrated services digital network ISD N. Session layer. That's a…data link layer. That's B. Application layer. At sea. Network layer. That's D. And the, and the winner is B the data link layer is responsible for formatting packets from the network layer to be used in the transmission of data. So yes as the data link layer that is one that puts them all together And when you're dealing with the OSI model the seven layer burrito and puts it all together to get it shipped out the door. All right So now this question is about the OSI model. What layer which will you almost last minute about those I model too. Well what is the layer three? Of the OSI model…A transport layer. B data link layer. See physical layer. Or D the network layer. And the answer is D the network layer is the layer three of the OSI model situated between the data link which is layer two Okay So you guys see the video. Got layer two or I'm actually a layer two is down here And our toe, and then you have layer three which is the data link layer And then you have transport layer which is above that. Okay. That is the different models of the OSI. Seven liter layer burrito. Layer three of the OSI model is the. network layer. All right…All right That's all we've got for reduced cyber risk podcast today And we are going to be moving on to Hey I'll see the next podcast coming out next week. But the links today with ISC squared training study guide Quizzlet InfoSec Institute and Wikipedia. All right Hope you enjoyed this podcast Also remember that there's training available for you@reducecyberrisk.com. slash C I S S P training or you can check out my videos on YouTube amy.com which you will get a great deal by going to youtube.com and you'll get updates. from what's happening within the CIS SP on a weekly basis. All right Have a great and wonderful week We'll catch you on the flip side See. Thanks so much for joining me today on my podcast. If you like what you heard please leave a review on iTunes is I would greatly appreciate your feedback. Also check out my CA S P videos that are on YouTube. Lastly head over to reduce cyber risk and look at the cornucopia of free CISSP S P materials. Available do all my email subscribers. Thanks again for listening…