[00:02.930 --> 00:06.050] Five, three, four, two, one. [00:18.350 --> 00:20.130] Well, thank you everybody for coming. [00:21.270 --> 00:26.470] After that wonderful speech, I think we'll bring it back a little bit more towards the technical and professional hacking. [00:28.710 --> 00:30.350] Thanks and welcome to my presentation. [00:30.670 --> 00:32.610] Today we'll be discussing professional hacking. [00:33.530 --> 00:45.450] In particular, I'll be covering how the security testing professional or hackers, such as yourselves, can interface with, utilize, and contribute to the Open Source Testing Methodology Manual, also known as the OSTO. [00:50.110 --> 00:56.070] Normally this presentation is about two hours long, but due to time constraints, I have to squeeze it into about 40 minutes. [00:56.850 --> 01:00.490] So if I go too fast or you need additional information, please make note of it. [01:00.570 --> 01:04.250] Ask me at the end in the Q&A session so that we can get through it all by the end. [01:05.910 --> 01:11.330] I'll also be available after the presentation and throughout the remainder of the conference, so feel free to grab me and ask questions. [01:12.010 --> 01:14.890] So the audience I have here at this conference is very broad. [01:15.010 --> 01:17.690] You folks are the entire gambit of security professionals. [01:18.170 --> 01:24.690] Novice hackers, technology visionaries, malicious hackers, federal agents, security professionals, system administrators. [01:24.870 --> 01:25.730] We've got the whole thing here. [01:28.710 --> 01:32.850] It makes it very difficult for me to attempt to make this presentation fit all those levels. [01:33.850 --> 01:39.750] So there will most likely be parts that are going to be too technical for some folks, and some parts that are going to bore some or most of you. [01:40.130 --> 01:44.930] So please bear with me if this happens, and we can get together for more questions afterwards. [01:45.810 --> 01:47.590] So these are the topics that I'm going to cover. [01:48.910 --> 01:51.850] Overview of the security testing profession and the OSTOM itself. [01:52.290 --> 01:59.330] This section will include a brief synopsis of the security testing field today, as well as background on the Idea Hamster organization that houses the OSTOM. [02:00.690 --> 02:05.390] Idea Hamster originated the idea for the OSTOM, and I will also give a background on the OSTOM itself. [02:05.870 --> 02:13.710] From there, we will briefly touch on privacy law, and how the OSTOM tries to cover and be responsive to as many laws internationally as possible. [02:15.830 --> 02:20.110] Then we will get in the meat of the presentation with the section entitled Planning an OSTOM Security Test. [02:20.350 --> 02:22.190] It is obvious what that section is about. [02:22.370 --> 02:30.550] Then we'll go over in some detail the testing process that has to be covered to be an OSTOM certified test, and evaluation of that output and results and finally the Q&A. [02:32.330 --> 02:34.070] So just what the hell is an OSTOM anyhow? [02:37.160 --> 02:40.520] Let me take a step back and give you a little background on myself. [02:40.740 --> 02:47.040] I'm the director of the knowledge transfer project of the Idea Hamster organization, and have been involved with it since its inception in January 2001. [02:47.840 --> 02:54.240] Basically, this just means I spend my time figuring out how to get the word out about our project and our open source manuals to people like yourselves. [02:55.740 --> 02:58.640] Idea Hamster is not a profit-making company or organization. [02:58.840 --> 03:00.880] Instead, we're a house for open source projects. [03:01.400 --> 03:08.800] So all the travel, lodging, everything comes out of our own pockets to do these presentations to you guys to try to get people to sign up and help this thing grow. [03:09.960 --> 03:17.080] I'm also a primary contributor to the OSTOM itself, and I have helped on many of the modules and given significant feedback in the peer review process of the manual. [03:17.080 --> 03:24.440] I'm co-founder of a company called Security Sciences Corporation, as well as a freelance security consultant to both government and private industry. [03:28.720 --> 03:30.340] The Idea Hamster organization. [03:30.920 --> 03:35.640] It's an organization dedicated to the development of security standards through the open peer review process. [03:36.120 --> 03:40.860] The organization is an independent third party and receives no money or benefits from any commercial means. [03:41.380 --> 03:45.600] Anyone is allowed to comment, criticize, and contribute to any of the projects or submit new ones. [03:47.200 --> 03:53.040] Whether or not the project becomes a standard is purely up to peer review and overall acceptance through non-commercial and non-political means. [03:53.380 --> 03:55.640] It means you guys make these things real. [03:55.780 --> 03:57.720] You guys make these things grow and become solid. [03:59.020 --> 04:02.260] We established January 2001 as simply a small idea. [04:02.720 --> 04:05.680] We let the hamster run free and many projects grew out of it. [04:06.180 --> 04:08.580] The list of projects is always growing in a state of flux. [04:08.740 --> 04:13.700] Currently we have the open source security testing methodology manual, the one I'm going to talk about today. [04:13.960 --> 04:20.280] The Jack of all trades security testing training supplement, which is a technical training supplement to the OSSTMM itself. [04:21.340 --> 04:30.700] The secure programming standards methodology manual, which is a supplement to the OSSTMM for the development of secure code for internet applications and some OSSTMM tools that are also in development. [04:31.540 --> 04:36.160] These tools are all GPL tools and are all released open source to support the adoption of the OSSTMM. [04:37.520 --> 04:42.420] All idea hamster projects maintain a simple theme surrounding information security and best practices. [04:43.020 --> 04:51.480] All documents written use an open peer review process, which allows all professionals in the field to comment and or review each other's comments for inclusion into the document. [04:53.880 --> 05:02.740] Idea hamster itself is independent, non-political, non-profit, simply the organization of the peer review process, the coordination of the data, and the hosting of all the information. [05:03.000 --> 05:04.320] The rest is up to you guys. [05:07.080 --> 05:08.620] So the OSSTMM project. [05:11.580 --> 05:19.980] The open source security testing methodology manual, OSSTMM, is the first and most widely accepted standard in the development for the security testing of internet systems and networks. [05:20.520 --> 05:28.240] It's been downloaded by over a million individuals worldwide since its inception, with a lot of collaborators and currently being translated into five different languages. [05:31.800 --> 05:35.560] The OSSTMM is truly an expression of expert collaboration of expert knowledge. [05:37.020 --> 05:40.820] The OSSTMM is rapidly becoming a standard for security testing industry-wide. [05:41.040 --> 05:47.000] It has been adopted by a good portion of the companies that test internet security, mainly because the methodology is so solid. [05:48.740 --> 05:56.840] Since there are over a hundred contributors from all different companies, agencies, and walks of life, the OSSTMM is truly a merging of information into a single best practices document. [05:57.500 --> 06:01.080] The OSSTMM is currently 93 pages of information checklists and templates. [06:01.260 --> 06:03.260] I have a hard copy with me if anybody wants to see it. [06:04.100 --> 06:10.540] The OSSTMM offers a certification seal for those who complete a thorough security test according to specific sections of the manual. [06:11.440 --> 06:18.140] That way your customers know that you've completed the test with the best practices in mind, and they can see the methodology that you use to do those tests. [06:18.580 --> 06:25.740] As legal best practice and commercial information changes and is shared amongst the security community, it will get incorporated into the OSSTMM. [06:25.960 --> 06:30.820] This will result in greater number of templates and aid to help accelerate the security testing process. [06:31.520 --> 06:37.560] New modules are being added even today to deal with emerging technology as well as obscure and optional facets of testing. [06:38.300 --> 06:43.580] Since this is a living document, the OSSTMM needs professionals like yourselves to contribute time and ideas to the project. [06:43.980 --> 06:46.100] Help us continue to help the security community. [06:53.770 --> 06:57.110] Alright, as we all know, the stats of computer security breaches are on the rise. [06:57.390 --> 07:02.370] I'm not going to bore you with all the usual bullshit about 85% of respondents detected blah, blah, blah, all that crap. [07:02.690 --> 07:03.850] We all know it's going up. [07:04.990 --> 07:08.270] We also know the percentage of companies that claim financial loss is going up. [07:08.270 --> 07:12.750] Well, what can we do to help you guys as security professionals to bring down those stats? [07:13.470 --> 07:20.130] We formulate a standard for tests that is always updated, always current, always being reviewed by the practitioners themselves. [07:21.010 --> 07:23.110] And we take this standard and we GPL it. [07:24.330 --> 07:29.590] We have many companies, organizations, and agencies donating their time and some human resources to the OSSTMM. [07:29.590 --> 07:32.570] One example would be the U.S. [07:33.290 --> 07:34.710] Department of Treasury Office of Thrift. [07:35.270 --> 07:39.850] There are other examples including MITRE Corporation, DaVinci Consulting, VeriSign, and Interarm. [07:40.890 --> 07:53.450] By being early adopters of the OSSTMM, these companies recognize that it offers participants a consistent framework and clearly quantifiable results, thereby affording a level of assurance of the output quality, accuracy, and validity of the tests. [07:54.910 --> 07:57.790] End users have not seen this level of testing before. [07:58.310 --> 07:58.630] The U.S. [07:58.930 --> 08:06.410] Department of Treasury Office of Thrift is currently working with the OSSTMM considering making OSSTMM certified tests mandatory for banking throughout the United States. [08:07.070 --> 08:12.130] This level of adoption is occurring throughout the world in many different government and private organizations in many different countries. [08:15.390 --> 08:19.790] So, let's take a quick step backward here and cover what exactly meant by security testing. [08:24.240 --> 08:26.300] What's the definition of a security professional? [08:26.880 --> 08:31.620] A security professional has to be one of the most difficult professions in the information technology field. [08:32.000 --> 08:36.320] A security professional has to know not a little bit about a few things, but a lot about everything. [08:37.680 --> 08:48.360] Security professionals have to be network architects, software tester, programmer, safety engineer, business manager, operations manager, marketing specialist, HR manager, incident response engineer, among other things. [08:48.900 --> 08:55.860] If you aren't proficient at all of these fields, you need to, at a bare minimum, communicate clearly and effectively to the organizations that are experts in the field. [08:57.600 --> 09:02.420] Without constant communication with those experts, your security tests are doomed to fail. [09:03.080 --> 09:05.900] The OSSTMM has contributors from all of these fields and others. [09:11.120 --> 09:15.140] We understand the need to have expertise from across the board in the drafting of the standard. [09:15.140 --> 09:16.640] This begs the next question. [09:16.860 --> 09:20.380] Where's the future of the security professional headed? [09:23.520 --> 09:29.100] Security testing professional of the future will have to maintain all the specialties we just discussed, along with many more. [09:29.820 --> 09:34.440] They will need to be part help desk support, statistician, safety officer, trainer, privacy officer. [09:34.880 --> 09:37.240] The role is just going to continue to grow and expand. [09:37.900 --> 09:40.960] No longer will a security professional be just a technical guru. [09:41.420 --> 09:47.700] Interfacing with people and understanding and knowing the skill sets of those people will be crucial to your advancement as a security professional. [09:51.400 --> 09:53.380] Let's talk about security tests themselves. [09:53.680 --> 09:56.360] They come in all different shapes and sizes, as you can see by this chart. [09:56.940 --> 09:58.700] Some tests are all-encompassing tests. [09:58.820 --> 10:01.680] Others are defined and agreed upon to be subset tests of the whole. [10:03.240 --> 10:07.260] Vulnerability scanning, pen testing, security testing, security scanning, and ethical hacking. [10:07.380 --> 10:10.960] They're all different forms of security tests, sometimes overlapping. [10:11.720 --> 10:14.580] Each test takes a differing amount of time and resources to complete. [10:14.980 --> 10:19.200] The chart here demonstrates the depth of each test in relation to a full security assessment. [10:19.880 --> 10:26.840] Vulnerability testing costing the least and taking the least amount of time is a subset of security auditing and penetration tests, which are subsets to ethical hacking. [10:28.420 --> 10:34.780] Ethical hacking is the process that is most exhausted, takes the most time, and costs nearly the most amount of money to complete. [10:35.040 --> 10:38.940] The goal of the OSM is to cover all aspects of all these tests in an open fashion. [10:44.620 --> 10:51.280] So I actually considered taking this section out because of the experts that are here, one of which I am not. [10:53.960 --> 10:58.040] But privacy laws play a strong role in methodology used in security testing. [10:58.040 --> 11:06.200] Depending on the laws in your local jurisdiction, there will be certain tests that can or can't be done, and information that must legally remain secure or stored for significant periods of time. [11:07.220 --> 11:10.420] These privacy laws are dependent upon your country, state, region, etc. [11:11.400 --> 11:13.840] Both pros and cons result from these privacy laws. [11:14.020 --> 11:17.160] Privacy laws generate awareness to the non-security community as a whole. [11:17.820 --> 11:18.680] That's a good thing. [11:19.120 --> 11:23.920] However, it also causes confusion, as most of these laws are generic, poorly written when it comes to specifics. [11:25.340 --> 11:27.280] They generate the need for security tests. [11:27.800 --> 11:28.700] That's a good thing. [11:29.160 --> 11:32.360] But there's not clearly and legally defined standards for these tests. [11:32.640 --> 11:34.440] That's where the OSM really comes into play. [11:35.860 --> 11:39.940] They are good for the public as a whole, yet there's no place to report issues or complaints. [11:40.700 --> 11:41.760] Audit versus test. [11:42.000 --> 11:43.640] Which does a security tester do? [11:44.840 --> 11:48.900] Right now, based on privacy law and the company that is contracting us, we get to choose. [11:49.240 --> 11:53.240] The real question is which one is right and are we liable if we choose the right one? [11:54.040 --> 11:55.980] Privacy laws are a source of revenue for us. [11:56.420 --> 11:57.740] This, of course, is a very good thing. [11:58.680 --> 12:04.780] However, if we don't comply properly with these laws, will it also be a source of fines and mail practice? [12:05.660 --> 12:10.820] Privacy laws, while in general very positive and well-meaning, can also be very dangerous to the security testing industry. [12:13.850 --> 12:15.570] Let's talk a little bit about compliancy. [12:15.570 --> 12:20.470] At this point in time, there is no security testing specific laws within the United States. [12:21.210 --> 12:27.050] Within the United States, at the time of this writing, the only privacy law currently in effect is the HIPAA law. [12:27.190 --> 12:29.950] The Health Insurance Portability and Accountability Act of 96. [12:31.070 --> 12:33.210] Internationally, we have a few other laws pertaining to privacy. [12:33.370 --> 12:44.590] Basically, as countries and governments pass these laws pertaining to security testing and privacy, lawyers that are contributing time to the OSM project review the laws and incorporate any specifics that they can gather out of them into the manual. [12:51.200 --> 12:55.940] The OSM tries to take into account as many privacy and security laws internationally as possible by doing that. [12:56.520 --> 13:02.160] One point of interest here is the NIST, the National Institute of Standards and Technology, has recently released a paper on security testing. [13:02.660 --> 13:10.500] After release of that paper, they have been in discussions with us at Idea Hamster and have included the OSM in that next version of that paper, which is soon to be released. [13:10.500 --> 13:16.720] So you can see it's gaining ground nationally and internationally as attempting to become a standard. [13:20.500 --> 13:24.880] To summarize, the security professional of the future is going to need a little bit of everything... [13:24.880 --> 13:29.640] is going to need to be a little bit of everything to everyone, and the depth of security tests are only going to grow. [13:30.280 --> 13:36.400] This quote signifies the mental attitude required to do an OSM test, and to be honest with you, the mental attitude of the best hackers today. [13:40.860 --> 13:42.580] Okay, so now we know who we're talking about. [13:42.680 --> 13:46.400] We know a little bit about the laws that are in question, and the OSM takes those into account. [13:46.560 --> 13:49.400] Let's discuss planning a security test with the OSM in mind. [13:53.660 --> 14:00.540] Before we get into the meat of the presentation and the sections and modules of the OSM itself, we should briefly define what exactly a security test is. [14:00.540 --> 14:04.480] The OSM definition of a security test incorporates all of the listed factors. [14:05.680 --> 14:09.940] A security test must be quantifiable, consistent, and repeatable. [14:10.120 --> 14:12.500] It must be valid beyond the now timeframe. [14:12.980 --> 14:17.720] By using the OSM, we give the tester and the customer a way of timing the validity of the tests that are performed. [14:18.500 --> 14:21.620] Each module is given a time that will remain valid. [14:22.000 --> 14:26.480] That time can be measured, and an indication of when a test should be re-administered can be gathered. [14:27.180 --> 14:31.440] A security test should be based on the merit of the tester and analyst, not on the brand name. [14:32.500 --> 14:37.200] As I'm sure you are all aware, there are many companies out there that have the best and the brightest testers. [14:37.520 --> 14:42.580] Yet they lose the bid for the security test to a big five company simply because they're a mom-and-pop shop. [14:45.600 --> 14:50.040] What it really needs to come right down to is ability and merits of the tester and not the name of the brand. [14:50.580 --> 14:55.920] All tests must be thorough and compliant to individual and local laws as well as the right to human privacy. [14:57.040 --> 14:59.520] By human privacy, we mean a moral and ethical code. [15:00.100 --> 15:04.320] Security testers have a moral obligation to alert companies of human rights privacy issues. [15:04.760 --> 15:09.840] Just because you have told them what you need to tell them to be legal, doesn't mean you don't have to tell them everything. [15:18.320 --> 15:23.580] Security testing in practice is more of a practical look at what needs to occur for a test to be successful. [15:24.560 --> 15:29.160] Defining usable security, not just pointing out tasks or problems that might be impossible to fix. [15:30.280 --> 15:33.820] You must make sure to look at all the results against the business justification. [15:34.640 --> 15:37.420] I mean, after all, we're talking about mitigating risk, not eliminating it. [15:38.140 --> 15:39.720] Most of all, we need to build trust. [15:39.960 --> 15:43.660] That means promote good security and do not promote paranoia with your customers. [15:43.940 --> 15:46.900] The media does a fine job of promoting paranoia enough for all of us. [15:51.460 --> 15:54.400] So planning a security, planning an Austin security test. [15:55.480 --> 15:59.120] It's not necessarily as simple as here, sign a contract and we'll hack your network. [15:59.780 --> 16:03.480] Although I'm sure a lot of private consultants and mom and pop security shops think it is. [16:03.800 --> 16:05.860] It's a very dangerous way of conducting your business. [16:06.700 --> 16:08.740] Planning a security engagement takes time. [16:08.740 --> 16:12.780] You need to understand many aspects of the customer's requirements and the engagement as a whole. [16:13.560 --> 16:17.840] From there, you'll be able to determine the time, man hours, place, target, and their points of presence. [16:18.300 --> 16:25.160] This information is needed before you can even begin to give your potential customer a price quote. [16:26.320 --> 16:29.320] It's very difficult to give an average time for an Austin test. [16:29.660 --> 16:37.920] One rule of thumb that's been submitted is for every ten visible IP addresses and one tester, you can estimate 120 man hours, including report generation. [16:38.680 --> 16:44.480] This is obviously debatable, depending on how automated the individual tasks are for each module and for your organization. [16:45.100 --> 16:54.100] Overall, the time can be determined from the number of targets, services and systems that need to be tested, and how big is the client's presence and what is the extent of the testing. [16:58.240 --> 17:02.060] Typically, the first step that's completed toward an Austin security test is an assessment. [17:05.540 --> 17:13.300] An assessment consists of many sub-pieces that are all used in conjunction with one another to determine the overall cost and time of doing a full subset of security tests. [17:14.320 --> 17:20.180] Assessing the client is done either by remote, unobtrusive scanning or by asking the client to fill out a questionnaire or both. [17:21.360 --> 17:27.040] What you are attempting to determine is the cost in man hours and resources it's going to take you to complete the security test. [17:28.560 --> 17:37.380] These variables are primarily determined from your distance hops to the client, the reliability of both the internet links and the links between, the size of the client and the presence that they have. [17:38.380 --> 17:44.360] The ISP that is providing the client's bandwidth should also be considered as well as the systems and particular services to be tested. [17:45.660 --> 17:53.940] All of these pieces of information combined with previous experience administering Austin tests should lead a security professional to a reasonably accurate time and resource assumption. [17:55.080 --> 17:59.800] Remember, as with any project management, time can be shortened by adding additional resources to the project. [18:04.740 --> 18:07.520] Assessment techniques usually include these steps. [18:08.760 --> 18:16.060] Remember, the point of an assessment is to determine the cost in man hours of doing the entire project, so to accurately project the price in a quote to the customer. [18:17.860 --> 18:21.460] The point of this step is not to do a full security test of the customer's presence. [18:21.820 --> 18:24.260] There's a fine line here between an assessment and a test. [18:24.540 --> 18:32.000] You need to do enough accurate work to get a proper estimate, yet do not do too much that if you don't win the engagement you haven't wasted resources that could have been used elsewhere. [18:33.560 --> 18:37.720] Simple ICMP and TCP scanning should be used to scan the potential client's IP ranges. [18:38.280 --> 18:44.680] This will show you how many external facing Internet addresses may need to be tested during the engagement, along with some of the services that are being offered. [18:45.280 --> 18:48.780] DNS scanning should be used to look for any information leaks or IP address information. [18:49.460 --> 18:55.860] Routing review will help determine choke points for DOS and DDoS, as well as what ISPs and networks are between you and the target network. [18:56.620 --> 19:04.300] Network registration review, web crawling, search engine, news group crawling, can determine additional information leaks and data for your assessment. [19:08.620 --> 19:14.000] The tasks used in the techniques we just discussed can vary wildly. [19:15.100 --> 19:22.580] You, as a security professional, need to weigh the time invested against the reward of winning the contract and accuracy of the time and resource quote given. [19:23.240 --> 19:25.400] Some of the tasks are listed here on this slide. [19:27.580 --> 19:38.140] For example, we can look at name server responses in the form of examining domain registry information, finding the IP block owned, and questioning the primary, secondary, and ISP name servers for host names and IP addresses. [19:38.600 --> 19:44.240] If the name servers are not properly secured, you might be able to get a list of all IP addresses and host names that are published externally. [19:45.780 --> 19:50.460] Determine the outer network layer and routers via TCP and ICMP ping sweeps and scans. [19:50.460 --> 19:54.860] This and other more advanced techniques can be used to determine a semi-accurate network map. [19:56.380 --> 20:03.160] Once the network map is created, we can focus our searching more towards external sources, including tracks and information leaks. [20:03.660 --> 20:09.040] Searching board logs, intrusion logs, news group postings, much data can be gleaned on the target organization. [20:09.940 --> 20:15.060] Another interesting way of determining information about a target is searching job available postings from the company. [20:15.680 --> 20:26.080] These IT-based postings put requirements that many times give away significant amounts of data as to operating system, type of machine, application layer, and possibly network design. [20:28.800 --> 20:30.600] Some of the tools used in assessments. [20:30.980 --> 20:35.560] Here we have some of the tools that can be used to gather the assessment data without spending significant amounts of time. [20:36.180 --> 20:42.700] Many of these tools can be scripted and automated to make your assessment information gathering sessions significantly less of a task. [20:51.340 --> 20:58.200] So after you have spent time collecting the assessment information about the potential client, you might possibly be able to draw maps somewhat similar to this. [20:59.100 --> 21:06.080] Normally, the maps that are generated from a security perspective simply include the physical network devices and the interfaces to the public from them. [21:07.100 --> 21:11.040] Of important note on the picture we have here are the information gathering results. [21:12.020 --> 21:15.500] There are many more interfaces into an organization than just through the firewall. [21:15.500 --> 21:21.260] There is information leaks from the mobile office laptops, the internet results, the news group postings. [21:21.680 --> 21:32.200] All of this data, when combined and properly mined, can be pieced together to interpolate much more important pieces of data, the end result of which might possibly be the compromise of the client's information resources. [21:38.900 --> 21:40.860] Obviously, there is more than one way into a network. [21:41.160 --> 21:45.020] As a security professional, your job is to show the customer as many of these as possible. [21:45.680 --> 21:48.120] Don't limit yourself in what you display to the client. [21:48.380 --> 21:51.320] Only limit yourself in what you can legally do to demonstrate it. [21:54.640 --> 22:00.080] Now I move on to the true guts of the presentation, the security testing process done Austin style. [22:08.460 --> 22:13.940] The Austin defines the process of a security test as being evaluated on these four areas. [22:14.840 --> 22:17.020] Visibility, access, trust, and alarm. [22:18.100 --> 22:21.140] All of your output will be evaluated on these four tenets. [22:22.660 --> 22:30.580] Visibility is what can be seen, logged, or monitored in the security presence, both with and without the aid of electronic devices. [22:31.100 --> 22:41.000] This includes, but is not limited to, radio waves, light beyond the visible spectrum, communication devices such as telephones, GSM and email, and network packets, of course, TCPIP. [22:42.260 --> 22:45.040] Access is an entry point into the security presence. [22:45.680 --> 22:48.840] An access point need not be a physical barrier. [22:48.840 --> 23:01.660] This can include, but is not limited to, a web page, a window, a network connection, radio waves, or anything in which a location supports the definition of quasi-public or where a computer interacts with another computer within a network. [23:02.540 --> 23:08.340] Limiting access means denying all except what is expressly permitted financially and in best practices. [23:10.060 --> 23:10.700] Trust. [23:10.840 --> 23:14.240] Trust is a specialized pathway in regards to the security presence. [23:14.240 --> 23:25.280] Trust includes the kind and amount of authentication, non-repudiation, access control, accountability, confidentiality, and integrity between two or more factors within the security presence. [23:26.440 --> 23:27.860] And last, alarm. [23:28.520 --> 23:36.920] Alarm is the timely and appropriate notification of activities that violate or attempt to violate any of the other three tenets, visibility, access, and trust. [23:36.920 --> 23:43.420] In most security breaches, alarm is often the single process which initiates further consequences. [23:51.380 --> 23:56.780] Again, we base the review on the visibility, access, and trust, and alarm of the data that we receive back. [23:57.400 --> 24:01.300] For example, low visibility might be less IP addresses showing to the external world. [24:01.880 --> 24:07.400] An example of access might be streaming media that your customer currently allows access to for the users. [24:07.620 --> 24:08.760] Is it business justified? [24:08.920 --> 24:10.220] Do they actually have a need for it? [24:10.900 --> 24:13.160] Do you have a high level of access just because? [24:13.660 --> 24:15.600] Do you have a high level of access just because? [24:16.000 --> 24:18.020] Or can it all be justified for business reasons? [24:18.960 --> 24:19.220] Trust. [24:19.400 --> 24:23.460] Does the customer have the appropriate levels of trust with only proper entities? [24:24.120 --> 24:25.980] And, of course, are the alarms reasonable? [24:26.300 --> 24:29.540] If there are too many false alarms, the real alarms will be drowned out. [24:29.680 --> 24:33.260] Yet, on the other hand, if there aren't enough alarms, you will be missing important data. [24:36.350 --> 24:37.970] So let's look at the security map. [24:38.410 --> 24:41.210] The security map is a visual display of the security presence. [24:42.570 --> 24:47.230] Within the OSSTMM, we break the security presence into sections, modules, and tasks. [24:47.810 --> 24:51.670] The sections directly correspond to the six sections in this security map. [24:52.270 --> 25:02.590] These sections represent the security presence of a company, internet security, information security, physical security, communication security, wireless security, and security training. [25:04.930 --> 25:08.250] This is a close-up of those sections, demonstrating how they look as a whole. [25:09.690 --> 25:14.730] These sections are the whole security presence and model divided into manageable, testable slices. [25:19.190 --> 25:22.290] The connectedness of the map is also of significant importance. [25:25.550 --> 25:28.570] Everywhere the sections overlap, there is an overlap in definition. [25:29.110 --> 25:36.070] For example, where security training intersects all of the bottom three, communications, wireless, and Internet, Internet security. [25:36.290 --> 25:42.290] It is understood that there has to be security training in each of those disciplines to the customer for a security test to be successful. [25:43.050 --> 25:46.270] Another example is physical security and information security. [25:47.850 --> 25:51.990] They overlap because if I can get into your server room with a boot disk, I've owned one or all of your machines. [25:52.670 --> 25:58.930] There is a distinct interaction and correlation between all of the sections that form a full security map for a security tester to go by. [25:59.330 --> 26:01.450] So let's go over each of the sections a little bit closer. [26:06.540 --> 26:07.120] Physical security. [26:07.140 --> 26:11.180] The OSSTMM breaks down the physical security section into six different modules. [26:11.900 --> 26:20.180] Access control testing, perimeter review, monitoring review, alarm response review, location review, and environment review. [26:20.880 --> 26:29.780] Each of these modules is then broken down into specific tasks that a security tester can easily and repeatedly perform to allow a thorough testing of physical security. [26:30.200 --> 26:42.680] Some example tasks might be to examine the alarm types, test access control devices for vulnerabilities and weaknesses, map out the location of monitoring devices, map out the location of monitoring devices, discovery of the persons involved in alarm review, [26:43.000 --> 26:44.520] and testing those set alarm procedures. [26:53.220 --> 26:58.020] Before I move on to the next two sections of the OSSTMM, I want to point out one of my favorite slides of the presentation. [26:59.340 --> 27:02.620] I've been doing security tests for quite some time now, many years, in fact. [27:03.160 --> 27:10.040] The first time I saw this slide, it really brought together a lot of the information that had been in my head that didn't have a great way of being visualized. [27:10.660 --> 27:13.960] It also added a lot of pieces I hadn't necessarily thought about. [27:13.960 --> 27:16.320] in reference to security testing. [27:17.260 --> 27:29.600] The majority of security testers stray down the path, always staying on the right-hand side of the flow chart, checking the network, port scanning, system identification, exploit research, firewall testing, IDS testing, and of course, denial of service. [27:30.120 --> 27:40.180] Very few and sometimes only the best security testers take the time to do some of the more obscure tests, such as competitive intelligence scouting, document grinding, containment measures testing. [27:42.800 --> 27:49.580] All of these tests are outlined in the OSSTMM as modules that have undergone significant peer review to meet the highest of industry standards. [27:50.140 --> 27:53.320] In other words, there's a lot more to security testing than just internet security. [27:53.760 --> 27:57.080] We have the whole other half of the picture here, information security to worry about. [27:57.440 --> 27:59.160] It's all outlined in the next two modules. [28:02.140 --> 28:03.100] Information security. [28:04.840 --> 28:12.180] This module is important in the verification of much of the tested information and pertains to many levels of what is considered information security. [28:12.840 --> 28:15.140] This section isn't always desired by the customer. [28:15.280 --> 28:18.020] However, there's much information to be gleaned using some of these techniques. [28:18.560 --> 28:24.240] The information found can help piece together some missing parts when it comes to what end result the customer really does want to see. [28:25.060 --> 28:41.360] Tasks in this module include searching news groups for references to and submissions from people within the organization, searching documents for hidden codes or revision data, such as tracking changes being left on, examining P2P networks for references to and submissions from within the organization. [28:42.040 --> 28:48.300] Any and all of this information that is publicly available can be used to penetrate and gather additional data during the security test. [28:53.950 --> 28:55.030] Internet security. [28:55.490 --> 29:00.210] I'm sure this is where the majority of you have played and quite possibly have your area of expertise. [29:01.910 --> 29:05.090] It's the largest of the sections in the OSSTMM. [29:05.230 --> 29:07.950] We break down the internet security section into many modules. [29:08.250 --> 29:21.270] Network surveying, port scanning, services identification, systems identification, vulnerability research and verification, internet applications, containment measures testing, password cracking and DDoS. [29:22.330 --> 29:29.270] The OSSTMM is taking peer review from professionals and hackers worldwide on each of these modules and the tasks that are involved to complete these modules. [29:30.590 --> 29:34.290] There really isn't the scope of this presentation to go into detail on each of these modules. [29:34.530 --> 29:37.230] I mean, you could talk for hours if you wanted to get to that level of detail. [29:38.510 --> 29:47.190] However, I implore each of you to go look at www.ideahamster.org and take a look at these modules for yourself and join in on the peer review process. [29:47.190 --> 29:49.170] It's your comments that help it to grow. [29:53.430 --> 29:58.510] www.ideahamster.org Or see me afterward. [29:58.570 --> 30:00.070] I got business cards if anybody wants them. [30:04.630 --> 30:05.670] Communication security. [30:06.350 --> 30:12.930] This section goes over the modules and tasks involved in gaining access privileges to the telephone exchange of a target organization. [30:13.610 --> 30:18.610] This section is broken down into PBX testing, voicemail testing, fax review and modem testing. [30:18.610 --> 30:22.770] These modules do yield significant information in a majority of organizations. [30:23.090 --> 30:25.490] A lot of times this section is overlooked by companies. [30:27.870 --> 30:36.310] These tests include war dialing, brute force pin attempts, fax machine detection and location, and verification of remote dial and authentication mechanisms. [30:40.740 --> 30:41.640] Security training. [30:41.820 --> 30:43.800] I personally don't care for the name of this module. [30:44.000 --> 30:47.240] To me, it should be called social engineering, which is really what it is. [30:47.240 --> 30:49.160] How do you test security training? [30:49.680 --> 30:53.120] One effective way is to attempt social engineering to see who is educated on it. [30:56.320 --> 30:59.160] The way that it is suggested is through social engineering attempts. [30:59.340 --> 31:01.220] We have broken down this section into three modules. [31:01.480 --> 31:05.460] External requests, forged internal requests, and guided suggestions. [31:06.540 --> 31:18.600] As an example, external request module breaks into tasks such as querying gateway personnel over standard communications media, when the gateway person themselves have the authority to grant access privileges to others. [31:19.460 --> 31:29.500] The forged internal request module involves impersonating a trusted person to subvert the internal person into disclosing information concerning the target organization. [31:30.240 --> 31:40.500] Guided suggestion module involves subverting trust via guiding the person at the other end of the communication medium into downloading or going to specific malicious internet locations and downloading specific content. [31:43.800 --> 31:44.900] Wireless security. [31:45.640 --> 31:48.280] Grown significantly in the recent past. [31:48.640 --> 31:53.020] As such, the OSSTMM has increased this module and task count in this section to match. [31:53.860 --> 32:01.200] Wireless security currently includes wireless networks, cordless communication testing, public and private privacy requirements, infrared systems. [32:01.620 --> 32:05.440] This module is going through constant review and testing as new techniques come into being. [32:12.220 --> 32:13.080] Test requirements. [32:13.360 --> 32:21.280] Depending on the country you are performing the test from, and quite possibly the country of the client itself, you have to consider many important factors prior to completing the test. [32:22.400 --> 32:27.380] Just like your get-out-of-jail-free card, it's wise to gather this information early on in the process. [32:27.980 --> 32:36.580] The company's name and legal address, as well as all contact information, this includes the lead tech resources, as well as the officers of the company that are sponsoring the project. [32:36.580 --> 32:37.500] You need to have both. [32:38.420 --> 32:42.520] Written legal contract with the target organization, your get-out-of-jail-free card. [32:42.820 --> 32:47.820] And sometimes, depending on the countries that are involved, a written legal contract with the hosting ASP or ISP. [32:48.200 --> 32:52.120] That's definitely something you need to consider if you're working in or around Europe at all. [32:53.820 --> 32:58.020] Does the customer require all of the OSSTMM sections or just a subset of those sections? [32:58.340 --> 33:02.460] You need to define which of the security testing styles you will be performing and to what degree. [33:04.920 --> 33:07.420] You also need to define what your goals are going to be. [33:10.330 --> 33:12.330] These are the primary goals of an OSSTMM test. [33:12.530 --> 33:21.010] By using the sections, modules, and tasks in the OSSTMM, you will be able to assess the security of the organization as a whole, while giving them proven best practices. [33:22.230 --> 33:31.810] Completing the steps of an OSSTMM test, you will be able to recognize and quantify the business risks that an organization has, as well as privacy issues both internal and external to the organization. [33:32.410 --> 33:39.230] From the gathering of all of this data, it will be very straightforward to suggest and help implement practical security solutions to your customer. [33:40.430 --> 33:48.810] Having the OSSTMM methodology behind you during the test also will allow you to fall back on the best practices of the industry, and the customer will know what you had given them. [33:57.390 --> 33:59.690] All right, let's talk about limits of a security test. [33:59.890 --> 34:06.990] You have to be sure many things while doing a security test, the most important of which is do not cause any unauthorized downtime and loss of revenue to the customer. [34:06.990 --> 34:07.930] That's very key. [34:09.070 --> 34:12.830] Doing so is very detrimental to your credentials as a security professional. [34:13.550 --> 34:19.450] Try not to lead the customer into a false sense of security and avoid the politics within the organization, if at all possible. [34:21.190 --> 34:26.370] Be careful not to waste any resources of the organization in the form of unintentional alarm states. [34:27.010 --> 34:35.090] If it is a goal of the test previously stated during the goal outline stages, triggering alarm states and reviewing the responses is acceptable. [34:35.650 --> 34:37.890] In other words, be careful and always know your limits. [34:38.050 --> 34:39.070] Don't overstep your bounds. [34:42.760 --> 34:44.640] OSSTMM reporting requirements. [34:44.920 --> 34:50.680] To achieve OSSTMM certification on a test, the security practitioner must meet reporting requirements. [34:50.680 --> 34:51.600] This is kind of the key. [34:52.160 --> 34:53.960] It's the deliverables to the customer. [34:54.120 --> 34:58.900] And it has to meet certain deliverable standards for areas within the testing. [34:59.820 --> 35:00.680] Be careful. [35:02.560 --> 35:10.900] These requirements are listed and displayed in the OSSTMM itself for client review prior to the engagement so that they know what to expect from the security tester. [35:11.680 --> 35:14.100] The sections of the report are listed on this slide. [35:14.300 --> 35:16.660] Most of them are fairly obvious as their need. [35:17.000 --> 35:22.540] Of course, a security test can still be an OSSTMM test even if the report doesn't have all of these sections. [35:23.220 --> 35:28.140] Assuming that it's restricted because those sections aren't applicable or within scope of the customer's requirements. [35:32.310 --> 35:35.810] As we've shown, the OSSTMM is divided into modules, sections, and tests. [35:36.350 --> 35:42.690] The sections directly correspond to the main divisions of the security map and are also in direct correlation to the Internet presence points. [35:43.570 --> 35:50.190] When doing an OSSTMM test, the security tester flows from one module to the next module by using the tasks listed in each module. [35:51.250 --> 35:56.550] The input to a module, when processed, using the tasks listed, will generate an expected output. [35:57.390 --> 36:01.950] That output is then taken and fed into the next module and augmented with additional input information. [36:02.790 --> 36:05.910] This module generates the next set of output, and so on, and so on. [36:06.550 --> 36:11.290] The output is simply the result of the completed tasks of a module based on the input put into it. [36:17.920 --> 36:22.860] Here's a summary slide of the sections that we went through, along with each of the modules that make up those sections. [36:23.380 --> 36:30.600] If we really wanted to get into further detail, we could break this slide down into additional levels and write out the tasks that are defined within each of the modules. [36:32.100 --> 36:40.000] The flow would then be blatantly obvious as you can see the input tasks, what was required for the input tasks, and the output as it flows from module to module throughout the methodology. [36:43.420 --> 36:46.180] So what happens if we do a module and it has no output? [36:47.920 --> 36:50.400] It doesn't necessarily mean that you did the module wrong. [36:50.740 --> 36:57.800] It could certainly indicate tester inability, but more than likely it indicates very tight security from the organization. [36:58.160 --> 36:59.860] It doesn't have to mean that either. [37:00.180 --> 37:07.500] It could mean that the module was not applicable to what the organization required, or that the output of the task has been improperly analyzed by the tester. [37:07.980 --> 37:18.980] If for some reason a test were to give you no output or incomprehensible output, it is the job of the tester and quite possibly co-testers to look over each other's shoulders and double-check the validity of the module results. [37:19.200 --> 37:21.940] If they come back valid, they come back valid. [37:22.060 --> 37:22.820] There was no output. [37:25.300 --> 37:27.180] So let's actually look at a module here. [37:28.540 --> 37:32.080] This is kind of the format and the template within the OSSTMM for a module. [37:33.700 --> 37:37.940] Let's use the Internet Security section of the OSSTMM as an example since you guys know this stuff pretty well. [37:38.860 --> 37:40.620] At the top you can see the name of the module. [37:40.800 --> 37:45.240] For our example within Section 1, that might say System Identification. [37:46.220 --> 37:48.000] Underneath that is the description of the module. [37:48.000 --> 37:58.660] For System Identification, it would say something to the effect of system fingerprinting is the active probing of a system for responses that can distinguish unique systems to the operating system and version level. [38:00.060 --> 38:03.260] We then list the expected results for this particular module. [38:03.720 --> 38:11.120] We list the expected results because if you don't know what you're looking for in a security test, you're going to end up spinning your wheels looking for something you're never going to find. [38:11.920 --> 38:23.860] Our example of expected results for the one we're talking about is OS type, patch level, system type, system enumeration, and internal system network addressing. [38:27.170 --> 38:30.670] Finally, at the bottom is a list of the tasks to perform to complete the module. [38:31.370 --> 38:37.830] The inputs to the module would have come from previous modules, while the outputs gathered from this module feed into future modules in your test. [38:39.010 --> 38:52.350] Since we're doing system identification, some of the tasks listed in the OS team for this module include examine system responses to determine operating system type and patch level, examine application responses to determine operating system type and patch level, [38:52.870 --> 38:56.650] search job postings for server and application information from the target, etc. [39:00.850 --> 39:02.350] Process of a security test. [39:03.010 --> 39:05.310] Definition of the process types of an OS team test. [39:05.690 --> 39:09.570] Just like any good security test, you can break up the modules and tasks into two categories. [39:11.050 --> 39:13.090] Passive and intrusive attacks. [39:13.450 --> 39:16.910] Passive attacks will not affect or trespass on the target systems at all. [39:17.210 --> 39:19.730] No degradation of remote services in the least. [39:19.930 --> 39:27.110] Intrusive attacks will trespass on target systems or networks and quite possibly can degrade or utilize services. [39:28.290 --> 39:31.390] Dedicated sniffer box being attached to the network in appropriate checkpoint. [39:31.630 --> 39:32.270] Passive attack. [39:33.170 --> 39:39.090] Sin flooding the web server to discover the ability of the router and end server to handle high traffic loads or essentially DOSing their network. [39:39.550 --> 39:40.230] Intrusive attack. [39:42.850 --> 39:43.930] Evaluation of output. [39:44.450 --> 39:46.590] This is a very important piece of the security puzzle. [39:47.590 --> 39:52.350] You need to understand how to evaluate all the output based upon the tests that are completed. [39:54.630 --> 39:56.690] So let's take a quick look at the evaluation process. [39:56.890 --> 39:58.890] I'm running low on time here, so I'm going to fly through this. [40:01.250 --> 40:04.510] Again, we go back to the four tenets of visibility, access, trust, and alarm. [40:06.690 --> 40:11.350] When the output is returned from each of the modules, a good security tester will evaluate it on its visibility. [40:12.450 --> 40:16.530] I know none of us in this room has ever had a company or organization tell us, oh, that machine. [40:16.750 --> 40:18.930] Yeah, we don't publish that machine's IP address. [40:19.070 --> 40:20.370] So nobody knows it's there. [40:21.970 --> 40:26.950] Well, it's visible and has high visibility to anyone who is actively searching the company's IP address space. [40:27.830 --> 40:34.910] So knowing the ports, types of systems, all of your output should be looked at for its visibility to an external source. [40:38.630 --> 40:39.050] Access. [40:39.050 --> 40:43.290] Access, as the data is returned from the modules, we need to evaluate it against its accessibility. [40:44.170 --> 40:49.150] Do you really need access to web, or do you really need web access to MP3 files for your internal users? [40:49.830 --> 40:52.490] Do you really need streaming media from CNN.com? [40:52.750 --> 40:55.390] All data must be evaluated against access. [40:55.990 --> 40:59.810] Is it business justified is basically the question you need to ask yourself and the customers. [41:02.370 --> 41:02.850] Trust. [41:03.110 --> 41:05.210] How much can people trust your systems to be up? [41:06.210 --> 41:09.230] How much can they trust the integrity of the data that you are sending them? [41:09.790 --> 41:17.450] Some pieces of the puzzle include authentication before data is submitted, non-repudiation of the data, access controls of the data, and data confidentiality. [41:18.470 --> 41:22.730] Do the business partners have a higher level of trust than they should, or are they limited to what they really need to know? [41:25.790 --> 41:27.570] And last, alarm. [41:31.560 --> 41:35.820] From my experiences, quite often this is the weakest link in an organization's security measures. [41:37.880 --> 41:40.560] Too many false alarms, the true alarms are going to get drowned out. [41:40.700 --> 41:44.500] Too many alarms, and you're bound to be missing some of the right ones, some of the true ones. [41:44.500 --> 41:49.160] There's a fine line to the alarm quantity that meets but does not exceed expectations. [41:49.640 --> 41:51.680] Make sure the company is not crying wolf. [41:52.400 --> 41:57.300] Also note what alarm systems are being used and if they are adequate to catch the output that is coming from the modules. [42:01.060 --> 42:01.500] Conclusions. [42:02.760 --> 42:07.860] In conclusion, the OSSTMM is the industry's attempt to legitimize the security testing profession. [42:08.440 --> 42:15.060] Make the professional live up to the standards of the best and the brightest security testers that contribute to the manual on a regular basis. [42:15.600 --> 42:19.660] If you read the manual and determine there is something that we're missing, submit it. [42:20.240 --> 42:24.620] If you've read the manual and determined there is something in there that shouldn't be there, submit it. [42:25.600 --> 42:31.340] And last but not least, if you like what you see, join the peer review process and check other people's submissions. [42:31.900 --> 42:36.280] Please take the time to visit www.ideahamster.org. [42:36.420 --> 42:38.820] Join the mailing list and the peer review process. [42:39.880 --> 42:40.880] Thank you for your time. [42:49.360 --> 42:55.840] I don't see a lot of emphasis on identifying an organization's assets before deciding what to test. [42:56.300 --> 42:57.420] Is that one of the modules? [42:58.440 --> 43:01.060] It's incorporated across the board in a few modules. [43:01.060 --> 43:05.920] If you go down to the task level, it may be something that we should expand on. [43:06.200 --> 43:09.600] I seriously consider that as something that should grow into potentially a module of its own. [43:10.100 --> 43:12.660] And I also see an emphasis on the outsider risk. [43:13.260 --> 43:13.660] Outsider... [43:13.660 --> 43:14.140] That's correct. [43:14.280 --> 43:15.660] ...attacker and not the insider threat. [43:15.700 --> 43:16.100] That's correct. [43:16.220 --> 43:18.800] It is predominantly targeted at outsider threat. [43:18.940 --> 43:23.520] It's not necessarily something you'd use on an internal security audit, although it could be applied there. [43:23.820 --> 43:27.340] Also, I'm not sure I see a lot of explicit review of policies and procedures. [43:29.340 --> 43:31.120] At the task level, it gets down to that. [43:31.320 --> 43:32.600] I can only break it down so far. [43:33.040 --> 43:38.340] In an hour, like I said, this presentation, it's three, four hours long if I want to go all the way down into it. [43:39.960 --> 43:40.280] Hi. [43:40.480 --> 43:44.640] I know you talked a lot about local laws and geographical laws applying. [43:44.640 --> 43:51.760] I just wanted to know, is that really more where the client is located or where, you know, the testers are located or sort of you have to hear both? [43:52.040 --> 43:52.520] It's both. [43:52.780 --> 43:53.900] It's absolutely both. [43:55.980 --> 44:00.460] The laws part is something that actually I don't know enough about. [44:00.460 --> 44:04.260] And I think a lot of the testers and a lot of the people contributing don't necessarily know enough about. [44:04.260 --> 44:05.740] We have a few lawyers that contribute. [44:05.980 --> 44:08.780] So as the laws come out, we try to incorporate them as best we can. [44:09.740 --> 44:14.000] But we could use any additional resources that people can donate in that area. [44:15.520 --> 44:18.720] I haven't looked at the ASTEM in about nine months or so. [44:18.960 --> 44:19.920] A lot of changes. [44:20.300 --> 44:20.960] I can imagine. [44:20.960 --> 44:30.380] Does it include any guidelines or any modules dealing with third-party interactions with the customer that you're testing? [44:30.720 --> 44:34.420] Like potentially business partners or... [44:34.420 --> 44:34.520] Yes. [44:35.120 --> 44:38.740] Not specifically in the essence that it would say this is a module pertaining to that. [44:38.980 --> 44:44.980] But again, that's something that's folded in a kind of a theme across because you have to evaluate all your output based upon the trust tenant. [44:45.360 --> 44:45.620] Right. [44:45.860 --> 44:47.000] So a lot of that... [44:47.000 --> 44:48.280] If you have something like a... [44:48.280 --> 44:58.780] If you're doing a full penetration testing and, you know, a business partner has access to your customer network, does it deal with how far you can go as far as accessing... [44:58.780 --> 44:59.560] As far as... [44:59.560 --> 45:01.480] Getting into the partner's areas? [45:02.280 --> 45:03.160] Not per se. [45:03.420 --> 45:04.100] Not per se. [45:04.460 --> 45:06.340] It's definitely something that you could submit though. [45:09.080 --> 45:09.560] Hi. [45:10.140 --> 45:15.240] You have alarm, but you don't have response to the alarm as a whole category. [45:16.880 --> 45:25.220] You have a list of what services are on or off, but you don't have the contingencies and the analysis of the control of those services. [45:25.460 --> 45:30.040] So let's say there's a new story and you want the screaming stuff to come in. [45:30.620 --> 45:36.580] You want to be able to analyze who controls turning it on and off and their ability to turn it on and off. [45:36.580 --> 45:39.340] And what are your responses when the alarm goes off? [45:39.620 --> 45:39.660] Right. [45:39.760 --> 45:42.660] Alarm is something you evaluate your output based upon. [45:42.860 --> 45:44.620] It's not that it's a module per se. [45:44.820 --> 45:46.500] So if you look at physical... [45:46.500 --> 45:48.920] Let's look at physical security piece of it. [45:49.080 --> 45:52.960] Some of the tests are to trigger the alarms and look at the responses. [45:52.960 --> 45:58.920] So I think what you're talking about is task level stuff, then you evaluate it based upon the alarms. [45:59.520 --> 46:00.500] Does that make sense? [46:02.060 --> 46:06.210] Yes, but I'm saying you don't have an analysis of the response structure. [46:07.000 --> 46:08.420] Let's say it was a fire. [46:08.540 --> 46:09.540] I would have to look through it. [46:09.540 --> 46:10.600] You have the detectors. [46:10.820 --> 46:11.680] You analyze the stuff. [46:11.840 --> 46:12.480] You don't have... [46:12.480 --> 46:14.040] How do we evacuate the building? [46:14.180 --> 46:15.440] What things need to be saved? [46:15.620 --> 46:16.840] Who is it that does it? [46:16.920 --> 46:17.820] Where are the wardens? [46:18.120 --> 46:24.060] You know, the whole structure involved in how to respond to the alarm after it goes off isn't being analyzed. [46:24.240 --> 46:24.800] Catch me afterward. [46:24.840 --> 46:25.560] I have the hard copy. [46:25.620 --> 46:26.060] We can go through it. [46:26.120 --> 46:28.120] I bet you there's going to be tasks in there that address that. [46:28.240 --> 46:29.260] I don't know the task level. [46:29.400 --> 46:30.180] I don't have it memorized. [46:30.340 --> 46:31.580] I mean, it's almost a hundred page document. [46:31.760 --> 46:31.940] Sure. [46:32.040 --> 46:33.920] But I'll bet you there's task levels that go over that. [46:36.400 --> 46:38.100] One of the biggest things that I've run into... [46:38.100 --> 46:41.480] I actually work for a company that has HIPAA considerations for medical information. [46:42.100 --> 46:45.280] Have you specifically started to address a section concerning HIPAA? [46:45.440 --> 46:51.360] One of my biggest concerns in that particular area is going to be the safe harbor clause for people that provide hosting services. [46:51.460 --> 46:52.900] We provide portals for medical information. [46:53.480 --> 46:59.480] And unfortunately, I think for our network, our security guy, he's a policy writer. [46:59.620 --> 47:04.440] He basically has stood up and said, well, since we're doing portal hosting, then we can fall under safe harbor. [47:04.500 --> 47:05.780] We don't really need to worry about this stuff. [47:06.960 --> 47:08.340] I mean, what do we... [47:08.340 --> 47:10.460] I mean, how do we convince people that that's just bullshit? [47:10.700 --> 47:13.860] I mean, we need... [47:15.160 --> 47:19.020] I honestly don't have too much of an answer for specifics on that. [47:19.940 --> 47:21.780] Again, I'm not a lawyer, so I haven't... [47:21.780 --> 47:24.160] I've glossed over the HIPAA laws. [47:24.280 --> 47:28.280] And I don't know them nearly to the degree that you guys, you know, will probably know them. [47:29.360 --> 47:36.640] But in essence, we try to incorporate the pieces of the laws that say hold data this amount of time. [47:36.860 --> 47:39.500] If they're in effect as a law, we have to do them. [47:40.040 --> 47:43.320] You know, I mean, whether they're right or wrong, the majority of the time they may not be right. [47:43.320 --> 47:44.340] And I agree with you completely. [47:44.540 --> 47:49.420] But we have to include them in the methodology of something that we have to do until we can get them taken out. [47:49.780 --> 47:53.360] You know, once they're... once they're removed, we can remove them from the document, absolutely. [47:53.820 --> 47:55.700] But I don't have anything else in that. [47:57.380 --> 47:58.680] I think we might be in it anyways. [47:59.520 --> 48:00.360] I have three minutes. [48:02.700 --> 48:03.540] Okay, thank you. [48:11.870 --> 48:15.290] I'm going to step out the back just because I don't want to hold up the next verse.