शैडोइंग अभ्यास: Cybersecurity Architecture: Data Security - वीडियो के साथ अंग्रेजी बोलना सीखें

पाठ बनाया जा रहा है...
1
4 .35 million.
2
9 .44 million.
3
83%.
4
What do those numbers have to do with data security?
5
I'll tell you in a minute.
6
Welcome back to the Cybersecurity Architecture series, where in the first few videos, we talked about principles, fundamentals, about the various domains of cybersecurity.
7
We covered identity and access.
8
We looked at the endpoint, the network, applications in the last video.
9
Today, we're going to talk about data security.
10
which is what these numbers have to do with.
11
So the first one, 4 .35 million?
12
Well, according to the Poneman Institute, that's the average cost of a data breach.
13
worldwide.
14
That's a lot of money.
15
Every time somebody breaks in, that's what it's costing the organization on average.
16
And by the way, that's taking out some of the really large numbers that might have skewed the average.
17
So this is the baseline that we're looking at.
18
$9 .44 million cost of a data breach in the U .S.
19
twice as much if you're in the US if you get hit with this.
20
And 83%, what does that have to do with anything?
21
That is the number of organizations that have been hit by more than one data breach.
22
So this is answering the question, why do we need to care about data security?
23
Now we're going to talk about in the rest of the video about some of these aspects, about governance, about discovery, about protection, compliance detection, response.
24
survey found we reduce the cost of a data breach for you.
25
So stay tuned for that.
26
First of all, we're going to cover governance and discovery.
27
So think of this as a data security ecosystem, we're going to fill this thing out.
28
These are the technologies that go into allowing us to secure our data.
29
First of all, we have to have some sort of governance plan.
30
This is our way of saying, this is what we want to do.
31
If I don't define where the finish line is, I can't expect people to end up there.
32
So first of all, we're going to have a policy, a data security policy.
33
And in that, we're going to spell out what kinds of things are sensitive and what kinds of things aren't.
34
We're going to spell out a classification criteria.
35
that says this is keys to the kingdom and this is the lunchroom menu.
36
Nobody needs to protect that.
37
We don't really care.
38
That sort of thing, we need to spell out that criteria.
39
We need to also spell out what kinds of protections go with those different levels of sensitivity.
40
So we may have confidential, unclassified.
41
We may have super confidential, super top secret, super duper top secret, whatever your classification scheme is.
42
But you need to spell out what those are.
43
We can't expect the users in our company to protect the data if we haven't spelled out what those guidelines are.
44
governance, policy, classification.
45
Build a catalog that tells us this is where the data is.
46
This is where the really sensitive stuff is.
47
And you want to know where that is all the time.
48
We're going to be updating that as well.
49
And then build a resilience plan.
50
that says, if we lose data, how do we recover?
51
So we'll talk a little more about that later as well.
52
So that's the first stage, is build the plan.
53
Then we're going to move into discovery.
54
Now I've said this is what I want to do to cover our data and protect it.
55
Now let's go find where the data is.
56
A couple of different places that we can look for data types.
57
Databases, that's where we expect.
58
That's going to be structured data in most cases.
59
That's where we're going to see a lot of the keys to the kingdom, but don't overlook this other area.
60
files, emails, spreadsheets, all kinds of other things that make up unstructured data.
61
We need to be able to discover sensitive content in unstructured data as well.
62
In other words, in places where we might not otherwise look.
63
We expect the keys to the kingdom to be in the very sensitive database, but what if somebody makes a copy of that?
64
What if somebody excerpts parts of it and emails it to someone?
65
Now we've got sensitive data flying around a lot of other places.
66
And I'd like to look on the network and see as this data is moving around as well.
67
And maybe discover when there are certain types of issues that we could be running into.
68
protection.
69
So DLP is a technology that's important, that allows us to discover this stuff in real time on various systems,
70
and as data is flowing across our networks.
71
Okay, now we've covered the why of data security.
72
These numbers down here should be sufficient motivation for you.
73
How do we do governance and discovery, some of the general technologies there.
74
Now let's talk about protection and compliance.
75
I figured out how I need to secure things and where the stuff is, now how am I going to actually protect it?
76
Well, encryption is a huge part of that.
77
That is, I scramble the data so that only I can read it and the bad guys can't.
78
And I need to be able to do that for data at rest, like sitting in a database for instance, or data at motion.
79
Data that's in motion could be moving from one user to another, could be on a web server, and then it's being served up over across the internet.
80
So there's, I wouldn't need to be able to keep the data secure all the time, at rest and in motion.
81
If I'm going to be encrypting data, the other thing I need to be able to do a really good job of is managing the keys.
82
If you lose the keys, you lose the data.
83
So remember that we want to generate keys in a random way.
84
If anyone can predict the way keys are generated, then all bets are off.
85
They can read all your data.
86
So it has to be done randomly and we need to be able to keep it.
87
We also need to be able to keep up with the lifecycle of a key.
88
That is, don't encrypt it once and forget it.
89
It's not encrypt and forget.
90
It's encrypt and then continuously follow the life cycle and re -encrypt at appropriate times.
91
We have keys that we rotate in and we rotate out.
92
Another aspect of all this that you need to be paying attention to is this notion of quantum safe crypto.
93
Quantum computers are going to be able to break all of our existing cryptography in the next number of years.
94
We don't know exactly when, but it's not that far off.
95
And so we're going to need to keep an eye on this space right here
96
so that we use new algorithms
97
that will keep our data safe against the quantum threat
98
that would be out there if someone had a quantum computer
99
and started trying to crack all of our data that we had previously secured.
100
Access control is another part of data security.
101
Access control is also part of identity and access management, which was the first of the seven domains that we covered.
102
But it relates here as well, because it doesn't matter how strong I've encrypted the information, if a user that has access to this,
103
set their password to the word password, then it doesn't matter because they're getting in.
104
If we don't have a good way of authenticating and authorizing users, then all of this strong crypto isn't going to matter.
105
So access controls need to be there.
106
Backup.
107
If we face in particular a disaster recovery scenario or a ransomware type scenario, where someone says, I've got your data and I'm not giving it back.
108
Well, the best defense against that is saying, guess what ransomware guy?
109
I've also got a copy of my data and I'll just restore it and you can go pound sand.
110
So this is the type of protection that we need, not only to keep the data from prying eyes,
111
but also keep the data so that we have a level of resilience that I mentioned earlier.
112
or disaster or things of that sort.
113
Also, I need to be able to ensure that I'm complying to some of the industry regulations that might exist.
114
The Generalized Data Protection Regulation in Europe, GDPR, we have in the US HIPAA for healthcare information.
115
There are lots of regulations in lots of industries in lots of parts of the world.
116
It's essentially, if you've got any information about somebody, there's a chance that you would be subject to one of these regulatory requirements.
117
So I need to be able to report.
118
on am I complying with that?
119
Just as much I need to be able to report when I'm not complying.
120
Because if I don't know that, then one of the costs that goes into these data breaches are the fines that go along with it.
121
And with GDPR in particular, it's very substantial.
122
And if you think because you're operating a company that's not in the in Europe, in the European Union, that you're exempt from this, think again.
123
If you've got European citizen data, even if you don't operate there, you could potentially be subject to that check with your lawyers to find out.
124
And then, a policy, I need an ability to retain records, but only as long as is necessary according to the law or other regulation.
125
It really doesn't do us good to keep a lot of information and just store everything forever.
126
So what we need to do though is the law will require that we store data for a certain period of time, and we want to store it for that long, and probably not longer, because it gets more expensive.
127
And the longer we're holding this data, the longer we're holding a burden that if in fact, we could be held liable.
128
So it's best not to have it in the first place if you don't really need it.
129
Okay, now we've covered the first bunch of security protections that are needed about governance, about discovery, and things of that sort.
130
Now we're going to take a look at two more.
131
Detection and response.
132
Security is about prevention, detection and response.
133
These first ones are mostly about the prevention.
134
This is about the detection and response.
135
Detection.
136
Now, what does that involve?
137
Well, I need to be able to monitor my systems and see how data is being used.
138
How is it moving around my organization?
139
Who's using it under what conditions?
140
And in fact, I also may want to use a technology called user behavior analytics
141
that will monitor users and the way that they're looking at the data.
142
If they're downloading normally a thousand files a day and suddenly they start downloading a million files in a day, then that could be suspicious.
143
starts having a lot of interest in that data, then that could be an issue.
144
If someone is doing something different than their peer group, then that could be an issue.
145
So that's what user behavior analytics is looking for, those kind of cases.
146
So we're trying to detect misuse and abuse of the data.
147
And ultimately, I'm going to generate alerts
148
that are going to go up to some console and someone then can go take an action on that.
149
And the action is our response part.
150
So one of the things I might do is open a case.
151
and then assign that case to someone, and then they begin an investigation.
152
We might guide all of those efforts with something called a dynamic playbook.
153
A dynamic playbook would tell you, this is what just happened, now you need to do the following steps.
154
And based upon the results of those steps, I'm going to specify other steps for you to follow.
155
So that's the dynamic nature of it, as opposed to just a hard coded script that someone follows.
156
This is more like a dynamic script that they can follow.
157
But it leads people through and allows them to automate the recovery and orchestration and automation of these problems.
158
What's the difference between those two?
159
In a perfect world, I'd automate all of my responses, but we don't live in a perfect world.
160
Because we see a lot of these things that are first of a kind, type of situations a first of a kind i can't automate
161
because i don't know what i should have done
162
because i've never seen it before orchestrate is what i have
163
to do in a lot of these cases where basically i'm looking for certain things
164
and i'm providing guidance
165
but like an orchestra the conductor of the orchestra is conducting who's going to come in
166
when do the trumpets come in when do the the saxophones come in this sort of thing they're going to
167
basically direct all of this.
168
And that's what we're going to do in our response.
169
So think about those things.
170
We're going to talk about these actually in more detail in our next two videos, where we're going to talk about security monitoring and security response.
171
Okay, now we've done a quick flyover view of data security.
172
We started off talking about governance, setting the plan and saying this is what we intend to do.
173
And if we don't have that right, we can't expect to do the other parts right.
174
Then we move into discovery, find out where all the data is that we need to apply those policies to.
175
Then we're going to put those protections in place.
176
Then we're going to check our compliance and see if in fact we're doing what we intended to do.
177
We're going to look for anomalies.
178
Then we're going to respond when we find those and feed that information back into our policy.
179
So the whole thing then becomes this ecosystem of data security, and it involves a lot of different technologies.
180
So that's in general how we want to do this.
181
Now what I told you is if you would stay to the end, I'm going to tell you the top five things and you can see them here already.
182
So no need for a drum roll.
183
But According to the cost of data breach survey, these were the top five things that reduced the cost of a data breach.
184
Number one, AI.
185
Using artificial intelligence was top on the list.
186
And in fact, we started using AI a good deal already in this detect phase.
187
You'll hear more about that in the future videos as we cover that in the next one.
188
But you can expect to see AI be infused in all of these different spaces.
189
So look for that moving forward.
190
DevSecOps, that was a big part of the discussion in the previous video on application security.
191
If you missed that, make sure you go back and check that out.
192
But that breaks down the walls between DevSec and ops organizations and put security in a shift left position.
193
Incident response.
194
We talked about that here.
195
That's this response capability, and it's going to be the subject of our video two videos from now.
196
So again, stay tuned for that.
197
Cryptography, we've talked about that here in this particular space.
198
And as I said, if you can't encrypt the data, you can't protect it.
199
And then ultimately, employee training.
200
Because at the end of the day, it's not all about the technology.
201
There's an end user.
202
And the user, the human, is almost always the weakest link in any security system. So don't.
203
Ignore this part.
204
If you do, it's at your own peril.
205
Okay, there we go.
206
Those are the top five things that you can do to reduce the cost of a data breach, to reduce the likelihood that it ever happens to you in the first place.
207
Make sure you have a good plan for doing all of these things.
208
All right, now in the next video we will cover monitoring and then the following video security response.
209
So make sure you stay tuned to check those out.
210
Like, subscribe and hit the notify button so you'll know and not miss any videos in the series.

इस वीडियो के साथ बात करने का अभ्यास क्यों करें?

अंग्रेजी बोलने का अभ्यास करते समय इस वीडियो का संदर्भ अत्यंत महत्वपूर्ण है। Cybersecurity जैसे जटिल विषयों पर चर्चा करने से न केवल आपकी अंग्रेजी शब्दावली में वृद्धि होती है, बल्कि आप विभिन्न तकनीकी और औपचारिक स्थितियों में अपने विचार व्यक्त करने की क्षमता भी विकसित करते हैं।

यह वीडियो आपको shadowspeaks तकनीक का उपयोग करके बोलने में मदद करेगा। शैडोइंग अभ्यास के माध्यम से आप सही उच्चारण, गति, और तात्कालिकता को भी समझेंगे। यह तरीका आपको आत्मविश्वास प्रदान करता है और आपके संवाद कौशल को बेहतर बनाता है, खासकर जब आप विभिन्न डेटा सुरक्षा पहलुओं पर चर्चा करते हैं।

व्याकरण और संदर्भ में अभिव्यक्तियाँ

इस वीडियो में निम्नलिखित महत्वपूर्ण वाक्य संरचनाएँ का विश्लेषण किया जा सकता है:

  • "According to the Ponemon Institute, that's the average cost of a data breach worldwide." - यह वाक्य एक तथ्य प्रस्तुत करने के लिए आदर्श है और "according to" जैसे शब्दों का उपयोग करके सटीकता प्रदान करता है।
  • "If I don't define where the finish line is, I can expect people to end up there." - यह एक कारण और प्रभाव संबंध को स्पष्ट करता है, जिसका उपयोग आप अपनी बात समझाने के लिए कर सकते हैं।
  • "We need to spell out what those guidelines are." - यह स्पष्टता और शुद्धता के महत्व को दर्शाता है, जो कि किसी भी संवाद में आवश्यक है।

इन संरचनाओं का अभ्यास करते समय, ध्यान दें कि आप प्रत्येक शब्द को सही तरीके से उच्चारित कर रहे हैं। यह आपको अंग्रेजी शैडोइंग अभ्यास के लिए मददगार साबित होगा।

सामान्य उच्चारण की समस्याएँ

वीडियो में कुछ शब्दों और अभिव्यक्तियों का उच्चारण कष्टकर हो सकता है। उदाहरण के लिए:

  • "breach" - यह शब्द अक्सर गलत उच्चारित होता है। इसे "ब्रीच" के रूप में उच्चारित करें।
  • "governance" - यह शब्द "गवर्नन्स" के बजाय "गर्वनन्स" के रूप में उच्चारित किया जा सकता है।
  • "sensitive" - यह शब्द "सेंसिटिव" के रूप में सही उच्चारित होगा, जबकि कई लोग इसे "सेंसिटिव" कहते हैं।

इन उच्चारण समस्याओं पर ध्यान दीजिए, और नियमित अभ्यास से अपने बोलने के कौशल में निपुणता लाएं। अंग्रेजी बोलने का अभ्यास करते समय, ध्यान दें कि आप अपने उच्चारण में कितनी सटीकता ला सकते हैं। आपके लिए यह जरूरी है कि आप गलतियों से सीखें और लगातार बेहतर होते रहें।

शैडोइंग तकनीक क्या है?

शैडोइंग (Shadowing) एक विज्ञान-समर्थित भाषा सीखने की तकनीक है जो मूल रूप से पेशेवर दुभाषिया प्रशिक्षण के लिए विकसित की गई थी। विधि सरल लेकिन शक्तिशाली है: आप मूल अंग्रेज़ी ऑडियो सुनते हैं और तुरंत इसे ज़ोर से दोहराते हैं — जैसे वक्ता की छाया 1-2 सेकंड की देरी से। शोध से पता चलता है कि यह उच्चारण सटीकता, स्वर, लय, जुड़ी हुई ध्वनियाँ, सुनने की समझ और बोलने की प्रवाहशीलता में काफ़ी सुधार करता है।

शैडोइंग तकनीक: पूरी चरण-दर-चरण गाइड पढ़ें →