Shon Gerber from CISSPCyberTraining.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge in cybersecurity from being a Red Team Squadron Commander; Chief Information Security Officer (CISO); and Adjunct Professor providing superior training from his years of experience in educating people in cybersecurity.

In this episode, Shon will talk about the following items that are included within Domain 3 (Engineering Secure Design) of the CISSP Exam:

  • CISSP Articles – How to Start Looking for a Infosec Job
  • CISSP Training – Managing Engineering Processes
  • CISSP Exam Questions

BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com

Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?

LinkedIn – www.linkedin.com/in/shongerber

CISSPCyberTraining.com - https://www.cisspcybertraining.com/

Facebook - https://www.facebook.com/CyberRiskReduced/

LINKS:

  • ISC2 Training Study Guide
  • https://www.isc2.org/Training/Self-Study-Resources

  • Peerlyst

  • https://www.peerlyst.com/posts/how-to-start-looking-for-an-infosec-job-my-list-of-tips-evgeny-belenky-1?utm_source=linkedin&utm_medium=Application_Share&utm_content=peerlyst_post&utm_campaign=peerlyst_shared_post

  • TechTarget

  • https://searchsecurity.techtarget.com/quiz/Security-Engineering-CISSP-Domain-3-practice-quiz?q0=0&q1=2&q2=2&q3=1&q4=1&q5=0&q6=0&q7=1&q8=1&q9=1&x=58&y=6

Transcript:

Hey y'all welcome to the reduce cyber risk podcast This is Shawn Gerber Again calling out to you and hope everybody's doing well This beautiful week. We have a wonderful. Thanksgiving holiday coming up here in the United States And so everything is getting prepared for that. It's a great time to be If you like food it's an awesome time And United States. Is one of the things that we actually trust truly crave It's great Yet turkeys you got a ham you've got everything you could possibly think of. On this Thanksgiving holiday season. And for us it's just a great time. The everybody has been doing well this past couple of weeks. And things have been really busy here at Gerber central here in Wichita Kansas. It's been pretty crazy as I've been working with my wife and her business. We've now bedded that down for the season So that's been a good thing And I'm able to spend a little bit more time on reduced cyber risk podcast and creating some great content around the CIS SP. And so as we know the one thing that we're trying to get into more is. As you view. there self studying for the CIS. it can be a bit of a challenge to do that And I've I've just been paying attention to some people that were in the Wichita area that have been studying for that exam. And it's been kind of interesting talking to them. They they've been having some study groups They've been trying to get that. That going for quite some time now. And they've had some good success but at the end of it it really comes down to is trying to self study for this thing can be a challenge So that's kind of the purpose behind reduced cyber risk podcast and why we've put all this together. So today's podcast we're going to be getting to a couple of key things And as you if you have already known we kind of pull out some CISP articles that are on the web, as well as providing some CISP training that I provide through the courseware that you can go ahead and Google that you'll find it real quickly, but there's also the training that I provide there as well. And then finally some CISP exams will be available to you Quite exam questions are there as well So that stuff that you can do to study for for the exam and that's the one thing I was also reading a recent article on about the CISP is that 50% is knowledge and 50% is based on how you take these exam questions. And I will also say though that the interesting part around that is if you taking. I remember when I studied for this thing it was how many questions can I cram in? How fast can I do it And can I regurgitate it as quickly as I possibly can. And then that's changed a lot over time but at the end of it the questions that they provide in the test banks. We'll not, I mean there probably are some that will go word for word but at the end of it, ISC square puts out questions that you can use. The books have questions you can use. And…you just got to ask yourself though. The ISC is not going to make these questions the same. Now they may make them similar, but they're not going to make them the same So understanding the content is really a great way for you to actually be able to to get do well on this test And at the end of it, when you pass the test, You want the CISP certification You want the ability to get a job? And so you're going to have to know this information You can't just go in and take a test and dump it and go, my kids do that quite frequently They would they would take a test and then they would just dump it And then you'd ask them that same question, not too long later And they would go what are you talking about So it's kind of interesting because. They they don't think about the long-term consequences for just cramming for these tests So it's kind of interesting. All right So let's get into our first question Our first. Comment we're going to have today on this podcast and what it is we're looking for the basically around who's how to start looking for an InfoSec which is information security job. That's going to be the article that we're going to go into today. And and what I'll tell you also as we go into this, you can get some, the free videos that I have available out there. Basically domain one through fours but the CIS is P videos The full length videos that I use for teaching. Yeah you can get a plethora of those through domains One through four, I've got to select a select number of those videos out there available. But if you go and you set up for my email list you'll be able to get 11 videos free just for signing up. So I highly recommend you go out there and you do that as it was also on building other various free content that will be available out there. Podcasts the links to those podcasts are all there as well. And so there's a lot of different aspects you can do by just going to the website. If you want you also can buy my, the full domains one through eight video train that's available@shaundra.com You can get all of that there. There's a really good black pro black Friday pricing here in the United States We have black Friday and that's coming up in June Uh on. I think it's in Yeah it's on Friday. This coming Friday. And so you can pick up all of that content right there and available for you And it's awesome So we're going to have a really reduced price going to be basically 50% off of buy more normal pricing. Okay so let's roll right into the CISP articles. This comes from peer list.com and they have some articles out there about what should you do when you're looking for an InfoSec job? How how should you handle it? And. so here's some key nuggets from this article that they had put out there and you can click you'll have the link will be on my show notes So you can be able to click on that link and go to them directly. And one of the key these are some big bullets but I'll I'll add some context to this as well. They talk about don't be afraid to ask questions Now the one thing I've I've done numerous interviews with people because I'm pretty old. I've been around for quite a while And and so when I first did interviews I one thing I was concerned about as the interview E is what should I ask questions? Being on the opposite end of the table Ask asking the questions of people that want a job. I will tell you flat out right now If you have the ability to ask questions please do it It shows that you actually are interested It shows that you have done some thought into this So asking questions is very important. No I add a little bit of a caveat to that. You need to be very careful about not asking too many questions. So it's, it's kind of one of those things where if you get asked. I'm just using this as an arbitrary number you get asked. Three questions are. questions, then you ask maybe one question. I'd say more like if you ask, if they ask four or five questions then you ask one So about 20%. And so you need to ask some question but they also need to be. Ones that have been thought out not like where's the bathroom…You need it and understanding if the job is going to be. If you're looking for benefits or maybe a benefits question would be good One question around benefits. But the questions need to be focused on around the security piece of this And how would you utilize security within their environment And I would ask them key questions based on the role. What is the role of if it's a security architect role? You know what is can you to explain a little bit more about your enterprise and the role of a security architect within your enterprise? And then that have them say some stuff around that But again you need to make sure you ask the right pertinent questions to the right pertinent people. You also need uh you need to specify the list of positions you're looking to move into and which ones do you want to go So if you are. you have your resume and you already applied for a role and say a security analyst role within a security operation center, you need to be. Understanding Those are the positions that are available. You also need to provide technical details about yourself and what you're trying to achieve. And that this comes under your goals What are you trying to be with your goals your, your bio how are you wanting to get there What did you start How did you end there again There? The employer's trying to pick out a, an aspect about you that they can decide Hey you know what I want to hire this person. Now try not to be too pushy And that's what. When it talks about when asking people for help So that means when you're talking to people that are helping you get in the role don't, don't try to push on them going Hey where am I at What am I what's going on How would I how'd I do. Those kinds of things you don't need to be. Pushing onto people. However you need to be able to to ask questions. So it's that fine balance of people skills. There's a really good book that I recommend and it's super thin It doesn't cost much It's like on Amazon for it's like two to three us dollars. It's called skill with people and it's I think less Gibson and it's a really good book on how to deal with people. If you're in it you probably struggle with this And sometimes a lot of it people do. It's a really good book and I'd highly recommend you go out and buy it. If you're looking for an internship. You but you must really first look at what are the companies out there that are looking for interns. It not all companies are looking for interns in the security space so that's kind of an important area to be there. Also you need to connect with various groups on social networks and engage there. Now key a key piece around that is. If you are a social networking person. Be very careful what you post online. Because again people are watching what you do and if you post some buffoonery out there of online, the interesting part is that never goes away. And as a security professional you should know this that when you put post something out there, it will always be there for avert. It will never go away ever. You can contact recruiters Italo agencies. I've done this as well and been in contact with various recruiters. It's it's a way that you can be…basically having guidance around that Now I also would recommend that one way to help when with recruiters. Is to provide value for them If you can look at ways that you can help them. And and help them find new people. That's always positive too So then the recruiters are helping you to find a role. Now as there are over 2 million jobs. That it's always good to have a recruiter on your side because they will help you kind of fish through or our funnel through some of the stuff that may be a good fit for your role That you're. With your background and or others that may not be a good fit…If it's relevant again look at what your what the opportunities are You need to Polish up your English skills It's always a plus and I would highly recommend that you do this Now I've got a daughter who is speaks English as a second language. And the one thing that I have talked to her on over and over is her Spengler English her Spanglish Now that's not a good word. Her English speaking skills and in the United States or in doesn't really matter what role you're working with. The common language typically used is English So if you have solid English skills and you can make those better that is wonderful. It to also also put it in perspective I said also twice. Geez That's crazy. To put it in perspective as well. One thing to consider is that. Do you need to in this role security roles, they are influencing roles They are roles that will you talk to two different companies You talked to leadership. And so therefore you need to be able to. To provide influence on leadership around what needs to occur Well if your English skills are not very good. It's pretty hard to go. And. Provide influence. So that's why we recommend that you get some level of, of increased knowledge around the English skills. Is it totally required No not at all. Like if you're from China and you're only going to work in the Chinese market. And you. don't want to go anywhere else. Well then your English skills may not be as important. But I will say you work with contractors and you work with vendors. And so having a good English skills would be helpful in that space as well. So just just something to consider. The other thing is one of the bolts they had also down there. Was that you should utilize Grammarly. It's a basically it's when you're dealing with. Writing. Uh content and you want to have the ability for it to to tell it's the grim grammatically correct. Use Grammarly to do that. Now I will say Grammarly is pretty close It does a pretty good job however it's not perfect. So don't rely totally on Grammarly. Also as you are understanding how Grammarly is doing things. You you need to understand as well. What is the sentence structure look like So my daughter, she she's really good at leaving off prepositions. Now she's Chinese So that. That that makes sense Right So I I've, it was all funny when I was. up with a kid I could never understand why. The Chinese would leave off prepositions Well in their language they don't have that. And and so I didn't get it when I was younger and I really actually didn't get it until I adopted a child from China. And now has she speaks I see her leave out those key. Uh prepositions and adjectives that. She just doesn't do it She has doesn't do a very good job with it So it's important that as you were studying Grammarly and that you if it's helping you with your. Uh sentence structure that you understand why you're doing that and pay attention to it because if you do it it will go very well for you It really well. You also need to tweak your message when contacting people based on that what's worked best so far for you. And it's always good to have someone that's personally within a company to help you, because again they are. If they can help walk your resume in it's way easier for you to get a job or at least get an interview. Then if you just start blasting people with emails that just doesn't work out. it may work but you may not get what you may not want what you get And that's really what it, what could happen to you So make sure that you build personal relationships And if you haven't figured it out yet in the world of security, Personal relationships are everything. And that is how everything is built here And so if you build those good relationships the good roles will come to you. And then not so good roles will move on or at least you'll have a heads up on what role is good and what one is not good. You mean to use job boards There's various ones that Peerless talks about once they've had indeed Gaudet not go daddy, monster.com. That dice.com is another one that is for more of technical people. And again that's those are important places to go freelance fiver as well. You need to treat your job search. Basically as your current jobs it's like, again I use my kids as an analogy cause I got so many of them I mean I have I have seven children so it. I see things on a daily basis that most people deal with and you just like really. I mean I had a daughter come in a day. She's 18. She made the comment to my wife. She was going downstairs and they were having a bit of a challenge and basically did this. And these are the scales from Uganda. And you know it didn't, didn't didn't have anything and which, which and the United States it's interesting because you don't necessarily need all the stuff that you get in the United States And so this girl who came from Uganda, Walks down the stairs and she goes, After having a little bit of a TIFF with my wife and says you started this. And you're just like are you kidding me? So that a interesting world So if you have children out there you know what. Yeah they're they're great Or they they're fun when they're little and they're fun when they're middle And then then when they get older they're not so much fun anymore So. It's interesting time. And if those of you who don't have children great uses as an opportunity possibly to think of but think twice about doing that. Wait a little while before you do it That's for sure. So again those are those are important things to consider when you're. at a job. Now I'm going to give you my takeaway So Gerbes is takeaway again Gerbes is my call sign I have on my flu B ones, but I give you my takeaway on all of this. You need to work on your certifications. Uh security plus network plus, and then also the CIS. P associate I think it's very important that you get those certifications done. If you can get the certified ethical hacker I think that helps put a different perspective on how you look at things. So those are those are some key certifications that if you can get those I would highly recommend it. Also if you are in the United States you can join the military or even in your organism in your country They may have this cyber forces that are within your military. If you can join their military I would recommend that. One if you use patriotism towards your country but two, they teach you also the skills you will never ever get anywhere else It's very hard to get those skills. And then basically three is join various local security organizations to help you with introductions to people, with getting some technical knowledge around these different aspects that are going on. So those are great ways to get started And then if you go to college or local university in your area that could also help you with depending upon what kind of security program they have in place. But again you get it's not just the technical pieces that you have to focus on. It's the soft skills as well. So those are very important that you get the right books You study the right. Uh techniques and you get the soft skills you need to be successful in security. All right So let's move on next to our C I S. P training. So overview the security is considered basically at all stages of system development So when you're looking at engineering processes and you're trying to divine. Design a secure environment. You need to have security considered at all stages of the system development. And I say this because I do this on a personal basis daily in my job, I am always dealing with security in the various stages from the beginning of the applications creation all the way to the completion and it could be the application built itself. for a specific process or it could be. A already pre-built application that a vendor's providing a for you. And one of the questions that I asked these vendors that bring us products is your your pro your security people do they are they understanding the secure development life cycle and as our secure software development life cycle which is typically called SDLC. Sometimes you'll see it acronym as just SDLC for software development life cycle, and security is considered one aspect underneath that, but that's it should be considered a basically an all does areas of system development. And following the following one I'll throw out there are really some key items that you'd need to be aware of as you're dealing with secure design. Now you have objects and subjects. An object is a resource that used by a subject. So as an example an object would be a computer system that would be an object subject would be basically the process requesting access. could be We call them an RPA robot process algorithm. Or it could possibly be an individual. It could be a service account It could be anything that is reaching in and using that object or that computer system, that wireless router that whatever that might be. Okay So those are objects and subjects. Now the other key point around this is that as we all know security is based around trust and there has to be trust set up between the objects and the subjects. And so as a user let's say a service account as a user. And then you in this in this scenario You know R and D computer system is the object. Well these two must have a trust between the two. The service account and the R and D computer system. Well the manipulate this could be manipulated by attackers in the fact that attackers would come out and they would go after that R and D computer hoping to get access to it And an example of this would be. It was occurred a while back where the Iranians had a centrifuges that were hacked. Using I think Stuxnet. And and so that's those accounts that acted the. Are activated and worked on those centrifuges. They had they were user access. Well there was a service account or individual user's credentials were compromised. Those are user accounts. So that R and D computer system would be hacked by these attackers So these trusts though, are in place Now if the trust didn't exist well then the attackers wouldn't get anything. So that's why it's important that a trust is set up between these objects and the subjects. Some other key terms is closed and open systems. You hear terms about this but a closed system is designed to work with a, in a very narrow range. So we would have typically in the military we'd have a closed environment network. And what you would do is that they would, it would not be connected to anything else You couldn't do anything other than what's inside that system. So if that system is able to hook to the F 20. To fighter, then what would happen is is that system would be connected to it but it would not be connected to any nit internet, any other network shares nothing. It would be a closed system. And it's really defined by the manufacturer So many of the defense contractors will develop closed systems so that they don't get hacked. The problem with this just to keep in mind is that they take a lot more overhead to ensure that they are protected. These closed systems the manufacturers put things in place but they don't always put the level of security in there as well. And and. Again it can be a little bit more. They are not little. They can be. Significantly more secure. However it's just you need to plan for this You need to make sure that you have people that can manage these systems. Now open systems these are agreed upon on an industry standard So if there's an industry standard set up around these particular environments, These are open systems and they're much easier to integrate with other systems as well. There's more options into the network they're less secure, and this would be a computer current computer system that you would run into would fall into these open systems. And in typical networking and typical computer systems are open So…Now there's close and open source code and a closed source code is proprietary code that is set up specifically for your environment. You may have a a. I don't know a lab. I usually keep kind of gonna go back to the lab environment or you built up just a basic application that maybe working as and I've seen this in like visual basic six right So it was really old, but that application works specifically for whatever you want it to do That would be proprietary code. These can be designed for both open and closed systems but what ends up happening is is. They're not always updated because they rely on the manufacturer for those. If they're a home grown system like I just mentioned with the VB six. You do run into risks where they will get exploited by people. And so these people exploit them. And they're never really updated because one person just made this out of convenience made this application and it works and it doesn't get provides what they want. But it's never updated So therefore over time creates a vulnerability. There's good companies around. this space will be Microsoft Boeing I mean you name it There's software development people everywhere. Here in Wichita Kansas we got to an individual We have Flint Hills group which is another company that does software development for all kinds of contractors You name it They're there all over the place. You also need to have techniques to maintain your confidentiality integrity and availability Now if you're studying for your CIS as P CIA is extremely important and there's various techniques by software developers to do this. And basically you can any of the following that we're going to talk about here. Can be used outside of software development as well. But software development is the primary place where this kind of begins. Now confinement. Is a restricted user you process access and actions to a program So what happens as you restrict the user to, or the process to a specific program or a specific action within a program? Now it does allow the process to read right For specific locations. And that would be just you're confining the capability of what it can cannot do. Now the sandbox also can provide some level of confinement You want that? Applications to run in the sandbox And this is where you place these restrictions. On where they can operate and they must meet or operate areas with a higher sense of security. Now, when it comes right down to is this is like an example I could have for you is only a specified systems can operate against a specified database You get very narrowed on what they can and cannot do. They also have any systems outside of the scope will not be allowed So those are kind of the examples that are in place I use this all the time especially when dealing with higher proprietary systems. You want to make sure that they'll only these ones can talk to certain other ones that didn't really make sense All these ones that's not that's starting to sound like my daughter. No, all of this systems that can to only a certain subset so only a can talk to be It can't talk to see but it can only talk to B. Those are kind of important areas to put in place…Now as we get into bounds bounds are defined process is a given specific authority to operate and there can be many or there can be few. I recommend less is more. Don't do a lot Keep it little. Okay. That doesn't make keep it little. That's really strange by English language His skills are not so good today. When it comes into as you get your user you get your kernel you got administrator. They needed to find these processes for a specific capability So if you need this Colonel the Colonel process to run a certain way, then you define that If you have your administrator to run a certain way, you define that. And these bounds will keep them from doing this from doing more than they should. They operate You also have to put these bounds in place for operating systems memory and hardware. Do you want the kernel to be running in a certain format? Do you want it to have full capability within the entire system up and down the stack? Or do you want the user to have that capability? Those are key things you need to put in place to restrict that kind of use. As an example you'd have a malware utilizes errors wince in setting bounds and basically deals with the Colonel manipulates the curve. you see this fruit routinely in the security space that the. Because what's happening as a user accounts are getting locked out pretty well. So now what are they doing They're going after the system or the use or the Colonel accounts to try to manipulate the overall system themselves…Now process isolation ensure that it only affects specific memory locations. These you mean to make sure you you isolate the processes so that only areas within memory are affected. It's a, it's really a part of a stable system And what'll happen with hackers If they're trying to do a denial of service attack. They will go and mess with these processes and if they can cause them to be unstable while then it causes the system. Not work and and realistically, you don't have to nuke the system to make it not a functional You just have to create unstability in it And it will that will do a huge factor in as well. As an example you could have cut paste Copy You would allow those to transition between the two. You can have macros to run outside to find parameters All of those pieces can be available. So it's just something to kinda keep in mind…As you deal with controls. There's also you need to put in place different controls to limit the access to authorized objects. These rules are in place to limit your access For example, file access You may have only. You may have a lot of people have read only, but you may only want a few that can modify. So again those are the type of controls you would put in place to restrict access to an environment. There's mandatory discretionary access controls, Mack and Dak, and these are designed to limit. Access to objects by subjects So the object are limited in And so there are only certain subjects can talk to these objects which we talked If you start at the beginning of this section on the podcast around, and those what these max and Dax are for a Mac is a subject cannot define the object that can be accessed by the user. So. Basically the saying is that the subject can't define what it was going to go after You have to define that for them So that's a Mac mandatory access controls. And so those are already set. for that user. DAC is flexibility with access. Objects can be accessed by the user So the user has the capability to move things around to decide what he wants He or she wants to have access to. So again mandatory it's defined. Discretionary. It's more, it's more loosey goosey It's more available for you to do be able to do what you need to do. And so an identity of a user may be granted greater access That would be an example of Adak and and that in that space would be. It depends on the situation You may want the user to be able to do that. So those are kind of different access controls Mac and Dak and you'll see these kinds of all these questions are all these terms in various formats within the CIS SP exam…All right so let's move on to the CIS. P exam questions. And we've got three questions for you today. And we're going to go through and find out which ones do you think fit? The mole. All right So this comes from tech target tech target had some different options out there and I like what tech target brings from some different CISP exam questions They pull some of these specifically from ISC squared. So the first one. What are the various SDLC development models covered in the CIS is P exam. Now I didn't talk about these today but they are covered in the exam And if you are dealing with development you will have to deal with these in some form or shape or another. So the first one is waterfall. Second or I should say Hey waterfall, V-shaped iterative, agile spiral and big bang. Now these are the different methodologies on how you do development work So…if you've dealt with development, these are all relatively you know these but if you have never dealt with development which when I first took my CISP As P I'd never dealt with that at all. It was very interesting And uh now I deal with development a lot so. I have a development team that works specifically for me. So those are key pieces right So waterfall V-shaped iterative agile spiral and big bang. Waterfall. Yeah it was a boy. waterfall X shaped So V-shaped X shape. Repetitive agile spiral and big bang. C waterfall Y shaped repetitive agile spiral and big bang. Or D none of the above. Okay So the big difference on all that again if you're taking the CISP exam pick out the ones that kind of stand out which ones you have if you don't know then guests…So in this case here I is a waterfall V it's waterfall V-shaped iterative agile spiral and big bang. All right So that is the first question. Second question attempt to take advantage of how the system handles multiple requests. So if there's an attempt to take advantage of how a system handles multiple requests, what kind of attack is this? So you have aggregation is a. B is a state attack. C is a state machine model. D is a method author, author. The key on. I can't even say it Authorization authentication. code Mack. I can't even say it It's really sad. So aggregation state attacks state machine model and message authentication code. Okay So if you're taking the CISP look for some things that may be similar. So in the case of state of tax and state machine models do you know the difference between the two if you don't know what those two seem to stand out as. They're trying to say the same question twice. Maybe it's one of those. And it is it's state attacks…All right So this involves removal of characteristic from an identity in order to easily. Represent in essential properties. All right So this comes down to is a algorithm. B abstraction. C diffusion. D substitution. So it involves removal of characteristics from an entity in order to easily represent its essential properties. All right So it's taking characteristics away. To basically represent what does it look like? So. It's algorithm. abstraction diffusion, substitution. And it is obstruction So you're removing the characteristics from an entity to try to pull pieces out abstracting pieces out to understand the essential properties of that. Okay so that's obstruction. The core of N O S…and one of its main functions is to provide. Access to system resources which includes the systems hardware and processes. So the core of an oh S and one of its main functions is to provide access to system resources which includes the systems hardware and processes. A system kernel. B state attack C abstraction. D firmware. Okay So if you looked at it listen to the last couple of questions, none of those two of those don't make any sense right Distraction and stare attacks that that doesn't make any sense. So you could narrow it down to two system. Kernel is the answer a.