Shon Gerber from CISSPCyberTraining.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge in cybersecurity from being a Red Team Squadron Commander; Chief Information Security Officer (CISO); and Adjunct Professor providing superior training from his years of experience in educating people in cybersecurity.

In this episode, Shon will talk about the following items that are included within Domain 1 (Security and Risk Management) of the CISSP Exam:

· CISSP / Cybersecurity Integration – HITECH

· CISSP Training – Compliance Requirements

· CISSP Exam Question – Preventive Controls / CIA Triangle

BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com

Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?

LinkedIn – www.linkedin.com/in/shongerber

CISSPCyberTraining.com - https://www.cisspcybertraining.com/

Facebook - https://www.facebook.com/CyberRiskReduced/

LINKS:

  • ISC2 Training Study Guide
  • https://www.isc2.org/Training/Self-Study-Resources

  • Quizlet

  • https://quizlet.com/87472460/official-isc-cissp-domain-1-security-and-risk-management-flash-cards/

  • Tech Target

  • https://searchsecurity.techtarget.com/quiz/Cybersecurity-risk-management-CISSP-practice-exam

  • Compliancy Group

  • https://compliancy-group.com/what-is-the-hitech-act/

  • Wikipedia

  • https://en.wikipedia.org/wiki/Arms_Export_Control_Act

  • Wiley

  • https://testbanks.wiley.com/WPDA

Transcript:

Hey Alice younger from reduced cyber risk and I hope you're all having a wonderful day in this beautiful state of Kansas I'm having a great day It's 75 degrees is going to be gorgeous today. It can be a little warm which is awesome It's also going to be just a little bit on the cool side in the evening which is even better. And the mosquitoes haven't come out yet That are the size of birds. I saw some small spiders running around which are quite large actually but yeah that's not bad My dog just eats those. But other than that life is good here in Kansas And we are going to be taught about some awesome things as it relates to cybersecurity today on today's podcast. But before we do I wanted to kind of go talk to you a little bit about Ru cyber risk and some great training that I've got out there for you specifically. And this is CIS S P train that you can get through you to me right now It's awesome You can just go to the site You to me and you can search for my name Sean dot Gerber or you can click on the show notes and I've got a great link to it on CISP training at reduced cyber risk. And it will take you specifically straight straight to you to me and get some incredible CISP training that I have available. you, and this is great stuff And as you know with you to me, They give you some really good prices on this You really can't beat it at all. I mean, honestly the bargain basement prices are pretty amazing just by going to YouTube and getting those. So again you can check those out@youtube.com or you can go click on my link at reduce cyber risk and get that C I S S P training specifically for you. All right So we're going to be talking about today The CISP cyber security integration. We're gonna be getting into a product called high-tech. Okay That's a health insurance. Uh in for our health information piece of this And we'll kind of go into that in just a little bit. CIS has P training's going to be aware on compliance requirements. And then the CISP exam questions are going to be on preventative controls and the CIA triangle. All right let's get going…Okay let's roll into this. So this is for Wikipedia and it talks about high-tech and high-tech is the health information technology for economic and clinical health act. Have to. Okay Yeah Say that 10 times and your brain will freeze and you're probably going what the Dickens is that. Well this final falls under the compliance aspects that we're going to get into and Wikipedia had a really good product about this and put it out there. Someone had obviously typed it into Wikipedia. And went through the different aspects of high-tech. And in high-tech is one of those things If you're dealing with the health insurance aspects and if you are studying for your CISP which I assume you probably are if you're listening to this podcast and or you're a cybersecurity professional wanting to understand a little bit more about these aspects. Because honestly when being a CISP myself, you get very niched and do a certain area. And so therefore you kind of forget or you don't really deal with these other aspects. And this is just a really good way of for you to kind of understand a broaden your capabilities. And this was per the anticipated the expansion of III protected health information, which is the electronic Phi And I don't know if you all are in the United States and you probably run this around the globe as well. I just got back from China and I notice that everything they have is online I mean you use we-chat for everything. They use Ali pay for other aspects. So I mean they are totally connected in China. And I think there's just it's It was when I was in India is the same thing Everybody's on their phone They're walking around the streets. So it's only going to be more and more of this Well in the United States we are all as to are are moving along in this base. And an electronic…health records are actually all out there. Uh right now if I can go online I can look at all my kids and what they have online. What what are some of the different cases are I have to go to the doctor all of my authorizations all that stuff is done online. And so this, this was designed to help with that electronic capability that just kept coming up as they kept dealing with this And this was passed by the Obama administration back in 29, 20 2009. And the goal of it. Was to reduce the cost of healthcare sharing as they're putting stuff out. And and so therefore it that's kind of why it came out was just to help reduce those physical costs…Now this is the design is that it would be if you're having data between hospitals and other entities that store your EPHI or your E patient health information, and that's the whole purpose of it So there's lots of information that is passed back and forth between an entity that let's just say you have a company that is a third party to a hospital, and these people work on MRIs. Well they have the ability to have some data of individuals that is passing back and forth. Well they wanted some level of privacy added to these and it expanded the scope of privacy and security protections for this data that is moving around. Tween these entities. And it also increased the light legal liability If you don't protect it Now one thing I've learned in corporate world is that you have lots of third-party vendors and these vendors will, are basically the little fish that sit around the big whale. And so therefore they are all servicing this big, the big whale Well what ends up happening is is sometimes these guys security isn't as, as intense as it possibly should be. And so therefore they induce a lot of issues to companies because of the simple fact is that they're tied in, well now you add the complexity So you know corporate America you have a vendor that takes care of you You have those requirements to make sure they protect your data, but now you add that additional component of having. Uh, per PII or Phi which is your patient health information. Potentially being stored by these third parties Well then what ends up happening is now you've just incurred greater risk by having these third parties involved within your hospitals. So therefore this was to increase the legal liability of individuals who do not protect this information. Now they had put out some monetary incentives back in 2011 to 2015 to get people to migrate to this direction. I know in China they moved people to we-chat and I honestly I can't even use a corporate credit card in China anymore just because everything is on Weechat. Well in the United States they've they've tried to move them in that direction They didn't really say this is the way it's going to be. And so therefore, And those incentives were set up until 2015. And there were penalties out for not acting after 2015 So for some reason you said, you know what I'm not going to do it after 2015. Then there were some penalties that you would have been incurred for not doing that…Well so it's 2019. And now what. Well, the thing is that's interesting is, and again this comes from Wikipedia So I don't know if this is truly the case It'd be interesting to see if anybody would provide some feedback around this but when it comes to 2019, There is an industry perception that it really isn't inforced that they're not enforcing any of this capability at all. And so therefore it's interesting how they're going to do this And what is the longterm play in this space Not really sure It it'll be interesting to see if there's going to be more enforcement. Now I am. You are seeing some things out there that there's more of this ratcheting up. However one of the things is just the perception is that it isn't really being enforced. Audits are occurring but many fields that they're just not very effective in what they're doing. And the one thing that high-tech had talked about the high-tech act was that if you have willful neglect and they have prosecuted some of these where you will be penalized and it but it is set up on a case by case basis. The fines will range anywhere from 250,000 to 1.5 million. At depending upon how willfully neglectful you are. So that's a lot of cash and you really not really focused on this And if you're a CISP going to work or a health insurer or a health company, and you're dealing with high tech, you better understand how you're protecting these people's information because it. Again I come back to this. If if you're not being audited and penalized now, it's, it will be It's just a matter of time. It's just a matter of time before there's a big breach or something large that happens. And then there will be a knee jerk reaction to then enforce these audits If they're not already being done. So the best thing to do is to work to strive to get towards compliance on these as best as you can, just because of sin. fact of it is is that you're going to have to deal with it at some point. And it's only going to get worse as we get more and more cyber breaches that occur. With in every career whether it's in the health industry or whether it's in manufacturing whatever it might be…Now high-tech also had a brief note breach notification and this breach notification is similar to others that you deal with PII disclosure. Now high-tech requires patients to be notified at any unsecured breach You see this a lot in pretty much anything out there deals with these unsecured breaches. But if it's got 500 plus patients, Then health and human services must be notified of the situation. Also in to include that your state privacy officer would need to be notified as well. So now you're not just involving the individuals that are involved the 500 plus people are at H S H H H S your own notifying the private state privacy officers that the state that they resided in. Now if you are a large hospital there's really good chance that you could have multiple states involved. So then you gotta deal with multiple lawsuits. So the fine is just one aspect of it So 250 grand of 1.5 million is the fine from HHS from health and human services. But now you Gail into lawsuits for loss of their privacy information Are there. There are data that that can go up and be millions as well So it's it really behooves you to pay attention to this stuff and to strive to deal with trying to protect the data. And I've also mentioned this before you. When it comes to these compliance aspects And again I am not a lawyer so do not take this as legal advice. But one thing that I would say is if you do everything in your power to protect information and we all know that people's data will still get breached from time to time, it still will happen. But if you've done everything you can to protect your data and put it in. In respect to what the is defined within the high-tech act. Then you are in a much better more defensible position in the event of a breach still doesn't mean you're not going to eat fine And it still doesn't mean you're not going to get sued by customers. However you're in a much. more defensible position than if you just say eh I'm not going to worry about it It's not being audited Nobody's caring about it Matt We'll just keep moving on. That is not a good place to be. So just just keep that in your back pocket Again not a lawyer, not the one that can tell you what to do. But it's just from what I've seen in this space in this world that doing those things and that due diligence goes a long way especially with the courts. They also talked about breach Patients need a first-class mailing and then they must basically Reese resolution to the issue And it must specify specifically what did you do to fix it? Are you putting them on some sort of, oh what do they call that I can't think of the name of it. Well you're dealing with the…identity theft protection those kinds of things Are you dealing with that Are you putting on people in there protecting their data through a Experian or one of those? And then if you have possible credit monitoring services that you may offer to them, all of those things they're going to ask what did you do to resolve the challenge that was occurred because of the breach? Okay. That's all I've got for this cybersecurity integration Let's move on to the training…Okay this is under the CISP domain one security and risk management. We're going to be a topic on this one is determining compliance requirements. All right As we all know compliance is a huge aspect as relates to cybersecurity and the CIS has P so one dot three of the CIS is P training manual that you'll get through ISC squared kind of talks a little bit about some compliance requirements and some of the things you need to be considering about that. And one of the topics is determining compliance requirements. So let's kind of roll into a little bit about this and see what you will we can kind of dig into but. Basically it's an overview There's an act of conforming or adhering to rules, policies regulations standards or requirements. And it's basically you must comply with these things And I kind of talk about there's a couple different areas There's, there's a big C compliance and little C compliance Well, when you're dealing with these big C compliance this means you must follow rules policies regulations standards or requirements And I deal with this on a daily basis. If you're a cybersecurity professional this is summer. that is near and dear to your heart and you must deal with it all the time. And our employees need to be trained on their responsibility around complying with applicable laws and the regulations And you need to make sure that you teach people this. And as it relates to cybersecurity in the past it's always been compliance Does one thing cybersecurity does another because we're under it. That is not the case at all I deal with our compliance folks all the time. I mean on it almost on a daily basis. And it's because not especially now with cybersecurity rolling into every space of. The world and from privacy to data protection you name it It's it's all over that Yet GDPR you've got Chinese cyber laws You got privacy laws that are in Singapore. Yeah all over the place. So you're going to have to deal with these Now you've got states that hell have different laws that are involved in So you have you get called in on a routine basis to kind of go over. What do you think about that I mean just to be honest I've got emails in my inbox right now to talk about those specific issues. So those are things you need to consider and it's very important to overall in your overall. governance to understand these pieces. Now as an example you got PCI DSS Now there's extensive training available and required that you have to do when you're dealing with PCI DSS. And I've also got on reduced cyber risk of get some more training that's available for you on the PCI aspects that are kind of go over that specifically and some specific training around it. But there's 12 main requirements are as a firewall configurations. There's a unique voice. A vendor supplied default passwords That's a big one, encrypt transmissions between locations And we'll talk about in future podcasts around some different kind of transmission protocols and with encryption. Uh restrict access on car data to only the people that need to know, not the guy you hired for the summer That's going to be surfing the web on the computer that holds all that information. Not not a good idea Just don't do that. And then there's many many others obviously but bottom line is there's some key things that you must maintain with your when you're trying to get PCI DSS certified. And so as a vendor who or as an individual. has a credit card at their location. You're going to have to make sure that these things are set in place. Now there's different PCI criteria that that are available for you. That you, you need depending upon what your company does where you'll have to follow. But bottom line is is that you need to maintain these And so therefore as a cybersecurity professional, you need to make sure you're in compliance with that specific regulation than that rule…Now when we're dealing with contractual legal and industrial standards this is kind of an objective that's on the CIS. And a privacy has been, been and continues to grow as a hot topic within the United States And we see this all over the United States. Especially in the California and I'm seeing in Massachusetts but you're also seeing it states that don't typically fall the California Massachusetts type of timeline where you know those are the key drivers the key. Ones that many people use to guide their direction around cybersecurity are actually around privacy And there's many other states now that are adopting this piece countries were addressing this as a digital age continues to grow And yet China us EU, and this will vary from country to country. And I've also noticed like even within China the country may say one thing, but even the provinces have different perspective of what the country is saying So you've got that dynamic to deal with as well. You have us privacy laws and there's a fourth amendment of the us constitution And this kind of talks about this And this was again obviously the constitution was dude done in 1919. Uh 1770, I think it was 78 is when the actual constitution was done up. I get I I think I screwed that up Probably they'll probably be somebody that'll let me know No, the constitution was donut in 1786 and 20 two-toned high. It's I think it was two years after it was actually ratified. Are they actually the signers sign The, the, yeah What did they sign? I'm blown away. It's all right It's quite early here in Kansas And so I'm half asleep as we're doing this but, but it's a right for the people to secure their persons or houses or papers and effects against unreasonable searches seizures and shall not be violated And this was designed in the United States around the king. The the the United Kingdom and England coming in and they're they're soldiers undoing unlawful search and seizures. And just basically just ransacking the place trying to find what they want and what they could about you. And there should be no warrants shall issue, but upon probable cause support by oath or affirmation, and particularly describing the place to be searched and the persons and things to be seized. Bottom line is you can't go in and just grab people's stuff And you got to have a warrant to say that you're going to do it as the United States I don't know how that is in the country of where you're listening to this but it hopefully you have something similar to that. Bottom line is though is us constitution spells it out So you can pull that out when someone tries to do it. Changes to the amendment have included what we call wiretapping to include with, with now it moved into the. I was the it wasn't the digital age. 'cause wiretapping has been around right after obviously in the early 19 hundreds is when the a that started all coming to be. And these these. Laws are woefully inadequate In some cases they're actually getting better over time. But I think in many cases this just they've had. key try to keep up with the digital transformation which is extremely hard and challenging…The privacy act of 1974 the federal government this is where they deal with private information about individual citizens. And it's get puts limits Thank goodness on what the government can do. Now It doesn't mean that they're actually following it You would love to say they are but there's lots of wiggle room in legal language. And so therefore they do these things And this is kind of also where the Patriot act came into play. And we'll talk about that later on but it allowed them to use SERP Some of these privacy laws that are in place and they had to go back and get resole or re get it reaffirmed every year. But that's one of the thing that's that it's a whole different animal. There's only applies to government agencies in this case here So when you're dealing with privacy is it comes down to is that only government agencies will be able to limit that about individual citizens and what they can actually do. Now the exceptions are health and safety census law enforcement court orders and national archives. And again those those could be. Tweaked a bit to help you help the government get what they want. But bottom line is those are the main exceptions to the privacy act of 1974…Now the electronic privacy act This is basically came out in 1986 which is kind of more my generation. And yeah that just dated me I'm like really really old it's basically it was to evade. It was. Designed to invade the privacy electronic privacy of an individual It's a crime to do that And so therefore they wanted to put this in place. And it helped broaden the federal wiretap act that had been put in place in the early I think it was in the fifties that they put that fifties or sixties They put that in place. I'm probably wrong on that as well. But it it prohibited the interception of the electronic communication So they just couldn't go out and start sucking down information about you as it related to our proper warrants Right. And it's illegal to for mobile to tapping to mobile phone conversations. Now that has changed a lot in this from 1986 from when I had the big old bag phone that I put in my car. With an antenna and it was just it was tied to a wire. That's come a long way since then or now everybody has mobile phones and you. I still say I walk it through India and you know they got 1.4 billion people and everybody is on a phone Everybody's got their head down walking on a phone. It's just it blows my mind And that's what that's kind of what cellular technology has done is it's helped expand these networks. Two places where typically phone coverage wasn't covered. You didn't have phone coverage and now everybody does It's connected the world even more. Communications assistance for law enforcement This act as a 1994, and it allows for communication carriers to, to allow for wiretaps Now that's where this came into play where you could actually get into mobile phone conversations. Of the 1994 and hence that's why because now they went from bag phones to everybody has a cell phone…Now the electronic economic espionage act of 1996 this diff extends the definition of personal property into the electronic property. So now you're getting you're getting out of this whole physical. Data or I have a check now for a bank I now have an electronic apple pay account. So it's going from personal property into elect. property. The health insurance portability hiphop that was set up in 1996 This is privacy and security regulations incorporate into the law. These are specifically set up as they were set up in that law. And then then we get into high-tech which you talked about earlier, and this is the health information technology for economic clinical health act of 2009. And this was also to help update the HIPAA and privacy and security requirements as it relates to what. What's in place and it deal with the, the technology The EPHI is we had talked about before. And the bottom line is it comes down to breach notification again over 500 individuals You have to notify HHS. And then also the state privacy officers as well…Some other notable mentions around this would be Copa And this is a big one As it relates to taking care of kids online. This is the children's online privacy protection act of 1998. And this is basically online privacy for children. And there's the Gramm-Leach-Bliley act of 1999 This this is a the financial restrictions between institutions and allow more communication between them. The one thing I wanted to come back with Copa. That's actually a really good thing that they finally put in place for that And it helps add put a little bit of restrictions around what you can show children what you can't. I would say in some cases that are kind of pushing the envelope on some of that a little bit. And again that comes down to what some people believe but. It's as as data becomes more and more open and available, you really got to watch what's out there for these kids because some of this stuff is pretty, that's not so good It's That's so good. You just Patriot act to talk about that of 2001 that was a result or a resolution of nine 11 that it hit New York trade centers and took those out. And it basically allows for blanket authority to monitor a person. Now it's set to expire in 2019. It's reviewed by Congress and it has been reviewed over the past Yeah I mean I guess every year they have to reaffirm it or every two years. And they have to reinstate this Uh, again I think at this point in time it's interesting to see it's one of those things It's like taxes Once you give once you've set up a certain amount of taxes and you pay taxes. It's really hard to revoke those taxes In many cases they don't Virgo away They always just stay there and you end up making more money to offset the cost of those taxes. Same thing comes into place around this with the Patriot act. They got Congress doesn't want to lose their control And so it'll be interesting to see what happens with it I think people are finally getting fed up from a privacy standpoint. That you know you're protecting us from the bad guy whoever the quote unquote bad guy is of the day, but at the end of the end of it what do you lose from a privacy standpoint which is very different than some other countries don't necessarily care so much. But I would say here in the United States it's becoming a more and more a problem. This with me. I don't, I'm not a big fan of it I'm. I'm former military And I I'm all for having the government have control in some cases to help protect the citizens, but it needs to be a restructured and limited cause at some point then it becomes ultimate power and that's just not a good thing So. You got to, got to kind of watch that and put checks and balances on that. On the family education rights and privacy act FERPA. This is for parents students with parents of students with the rights with educational institutions So. this is how you set this up with educational institutions that they ma manage the rights of your students. And then identity theft and assumption deterrence axial That's all these lots of bills lots of laws, severe criminal penalties for identity theft So this kind of falls in line with when you deal with identity theft if someone steals your stuff, They get nailed with multiple things They'll get nailed with wiretap They'll get Neal nail with money fraud with money laundering They'll get nailed with in this case here identity theft and this could be a $250,000 Fine Up to 15 years in prison term. So there's a lot of things you can get added for doing this identity theft stuff. That's why, again that the upside might be good You might think it is you get some short-term cash and you can be living large for awhile. But the downside is you got to break big rocks into little rocks and that's not just a good thing So there's the issues as it deals with identity theft and assumption deterrence act…Okay So that's all I have for the CIS. SP training Let's roll right into the exam questions…All right these damn questions are over domain one…All right Here's a question. Preventative controls. Okay That's an authorize the president to designate those items that shall be considered as defense articles and defense services and control their import and export. All right So what does that mean What basically means is that there are is true because there are controls in place that the government can put in place that gives the president the ability to put in restrictions around what can and cannot be imported and export. Now the arms control act of 1976 does this this gives the president the United States the authority to control import export of defense articles and defense services. Typically this gets called into play is the cryptography. And so therefore various cryptography and or cryptographic technology can be limited based on import export laws. This has been in the past This has been seen where we used to have the Cray supercomputer which in today's world is probably old school, but it you could only export certain technologies and that even and when it gets to the UK I know they, they didn't have all the technology They they could be potentially sent to the United Kingdom. And so those are the president of United States can authorize that Now that goes both ways right The government other countries do the same thing to the United States for import export. I know Israel Israel has a lot of stuff that they make specifically internally to them that they do export and sell. But I know they keep back some of the things that are specifically to their country. So those are aspects around it that you've, that you'll understand from a CISP question. It's the arms export control act of 1976. For anything that might be used from a defense standpoint for military purposes can be limited. All right Another question is vulnerabilities and risks that are evaluated based on their own threats against which of the following Okay So we have a one or more of the CIA triad triangle. Principles. B data usefulness…See. Do care. And D extent of liability. All right The answer is dun dun da. One or more of the CIA triad Brian's principles All right So when you're focusing on vulnerabilities and risks that are evaluated what do you do against them You focus them on the CIA which is confidentiality integrity and availability. How do they affect each of those three? That will then determine how do you want to deal with that specific threat? So therefore when you're evaluating it you focus on the CIA triangle and it really is that it comes back to that If you can focus on those three things, how does it affect confidentiality? How does it affect integrity of the data? And how does it affect availability of the data? Those are all very important pieces that you need to keep in.