Hello, my name is James Youngblood. And in this module, Defensible Security Architecture, we're gonna talk about different approaches to Defensible Architecture. And in this particular lesson, I'm gonna discuss the Archaic Perimeter Defense. Now, when we talk about security on a network we have to talk about the Perimeter Defense Method. And the reason why is because for many years this was the way that we protected our company's networks. The way that a Perimeter Defense would work is we would actually have our connection coming in from the outside from the Internet would pass through a Perimeter Firewall. A firewall that served kind of like a first line of defense for our network. All the traffic going into and coming out of our network passes through this firewall. So, it's a good way of making sure that any information that's being exchanged between our company and the outside world is gonna pass through this firewall, and it'll be filtered, and we can make sure there's nothing malicious going on. Now, Perimeter Firewalls are a great thing to have. And we still use them even in today's networks for obvious reasons. We do have serious threats that are coming from the outside, but there is a major flaw when we're looking at the Perimeter Defense Method, and that is the fact that the Perimeter Defense does nothing to protect us against an insider threat. So, if we actually look, we have an insider here, and there is nothing that prevents the person logged onto this computer from being able to do something on our network maliciously. Our firewall only protects us from the outside world. It does nothing to restrict or limit our insider threat. And so, we have a huge problem here. So, I want you to think of it this way. When you go to your office, or you go to your workplace, if you're the first one there in the morning the doors may be actually locked. So, you have to use a key. There may even be an alarm system that's there, and you have to disarm the alarm system. That's typical practice, and that's good security. But here's the question is, once that the doors are unlocked, you are open for business, and anyone can come into and out of your place of business. What would stop somebody from being able to walk into your business, walk in over to your filing cabinet, and start looking through all the files in the filing cabinet? Now, this may seem kinda like an absurd example, but I want you to listen to what I'm explaining to you here. This is exactly what we're dealing with. You see, what's gonna stop someone from doing that is the fact that we know, yo, we can't just walk into any business, and start looking through people's files. The employees there are going to stop us. They're gonna say, "Hey, you can't be doing that", and they will make us leave. But in a Perimeter Defense network, there's no one watching to see whether or not someone is actually rummaging through the files. There's no one watching to see if someone is accessing files, and data that they shouldn't be. So, as I said, this is the problem we deal with when we're dealing with the Perimeter Defense Method of providing security for our network. It's a great starting point for security, but it doesn't do enough to protect us from that insider threat, that person inside our network that is actually working against our company. We want to believe that everyone that works for our company has good intentions. But the fact of the matter is is that that's not always the case. And sometimes it may not even be that they're deliberately trying to cause problems in our network. It may simply be that they clicked on a link in an email that they shouldn't have clicked on, or they opened up a file that they shouldn't have opened up. But that's the problem that we deal with on a daily basis in IT security. And so, we need some kind of method of not just monitoring the traffic coming into and out of our network, but also the actual communications that's occurring inside of our network. Thank you for watching this lesson on Defensible Security. Join me in my next video as I talk about the Unobtainable Zero Trust Method.