Welcome to lesson 18. Okay, in this lesson, let's try our hand at an abbreviated version of the ES-C2M2 process. Let's pretend that we're the system security officer for "Anywhere" Power. Ready, ES-C2M2 step one, Perform Evaluation. And we are evaluating the maturity level of domain 2, Asset Change and Configuration Management. Domain objective 2.1 is Manage Asset Inventory. As all good power plants do, we have a schematic diagram of all the plants components and how they're interconnected. Given this description, how would you evaluate the plant's maturity level with respect to domain objective 2.1? Choose from one of the following options. Do you rate it maturity level zero? It doesn't meet any of the specifications. Or is it maturity level one? There's an inventory of assets that are important to the delivery of the function. There's an inventory of information assets that are important to the function. For example, set point values, default parameters, etc. Or is it maturity level two? Meaning that it meets all the maturity level one requirements, plus it also has inventory attributes supporting cybersecurity strategy. They're documented, such as the asset location, its owner, its service dependencies. Also, its inventoried assets are prioritized based on their importance to the delivery of the function. Or could it possibly be at maturity level three? It meets all level one and level two requirements, plus the asset inventory is current, as defined by the organization. There's an inventory for all connected assets related to the delivery of the function. What do you think? Take your time, pause the video if necessary to consider your response. Are you ready? Did you pick a maturity level? The best answer in this case is maturity level zero. Anywhere powers asset inventory doesn't meet any of the specified requirements. It might satisfy practice A, but given the description, it certainly doesn't satisfy B. And remember you must satisfy all criteria within a domain in order to be evaluated at that maturity level. Piece of cake, right? Let's try another one. Let's move on to a domain objective 2.2, Manage Asset Configuration. This time, your plant maintenance shop maintains a configuration database of each piece of operational equipment. This database is consulted every time a piece of equipment is maintained or replaced. Given this description, how would you evaluate the plants maturity level with respect to domain objective 2.2? Chose one on the following options. You say it's maturity level zero, it means non on the specifications. Or could it be maturity level one? Configuration baselines are established for inventoried assets, where it is desirable to insure that multiple assets are configured similarly. Configuration baselines are used to configure assets at deployment. Or could it be at maturity level two? Meaning that it meets all level one requirements, plus the following. The design of configuration baselines includes cybersecurity objectives. Or could it be at maturity level three? Meeting all level one and level two requirements plus the following, configuration assets are monitored for consistency with baselines throughout the asset's life cycle and configuration baselines are routinely reviewed and updated. Which maturity level would you say best describes this system? Take your time, pause the video if necessary to consider your response. Are you ready? Did you pick a maturity level? The best answer in this case is maturity level one. Anywhere power's configuration management practices maybe considered initiated. Did you choose maturity level two? I don't think this is correct, because the description didn't say how the configuration baselines where developed. You might be tempted to assume the plant operators follows sub-security objectives. But without specific evidence you would only be fooling yourself, impossibly perpetuating a vulnerability. Still, there is room for interpretation since the given description didn't match maturity level one exactly, but I would say close enough. And if you don't qualify for maturity level two, then according to the rules, you can't qualify for maturity level three. Okay, still with me? Rewind the video and review it again if you're unsure of the situation. Otherwise, let's try one more. Moving on to domain objective 2.3, Managed Changes to Assets. This time your plant maintenance shop is very thorough. They carefully evaluate every piece of equipment before it's placed in operation. Whenever possible, they test the new equipment before it's installed to ensure it will perform as specified. They are also careful to update their schematics and configuration database after each new install. Any replaced item is carefully inspected for unexpected ware and properly disposed after analysis. Given this description, how would you evaluate the plant's maturity level with respect to domain objective 2.3? Choose from one of the following. Is it at maturity level zero? Does it meet any of the below specifications? Or is it maturity level one? Changes to inventoried assets are evaluated before being implemented, changes to inventory assets or log. Or could it be maturity level two? Meaning that it needs all level one requirements plus changes to assets or tested prior to being deployed whenever possible. Change management practices address the four life cycle of assets, that including Acquisition, Deployment Operation and Retirement. Or could it even be at maturity level three? Meaning it meets all level one and level two requirements, plus changes to assets are tested for cybersecurity impact prior to being deployed. Change logs include information about modifications that impact the cyber security requirements of assets, such as their availability, integrity and confidentiality. Take your time, pause the video if necessary to consider your response. Are you ready? Did you pick a maturity level? The best answer in this case is maturity level two. Anywhere powers configuration management practices maybe considered performed. I hope the answer was fairly obvious, at least I tried to make it so. All together I think these questions were pretty easy. Again, rewind and review if you didn't find them so. Otherwise, let's move on to the next lesson, and try our hand at some harder questions. So see you next time, cheers.