1
1

00:00:00,000  -->  00:00:01,500
<v ->In this section of the course,</v>
2

2

00:00:01,500  -->  00:00:02,910
we're going to discuss how to conduct
3

3

00:00:02,910  -->  00:00:04,980
incident response preparation.
4

4

00:00:04,980  -->  00:00:06,960
Now, over the next few sections together,
5

5

00:00:06,960  -->  00:00:09,750
we're going to be covering the full incident response process,
6

6

00:00:09,750  -->  00:00:12,840
but in this section, we're really going to be diving deep
7

7

00:00:12,840  -->  00:00:15,150
into the incident response preparation phase
8

8

00:00:15,150  -->  00:00:17,880
by looking at domain three, incident response management,
9

9

00:00:17,880  -->  00:00:20,550
and domain four, reporting and communication,
10

10

00:00:20,550  -->  00:00:24,570
specifically looking at objectives 3.3 and 4.2.
11

11

00:00:24,570  -->  00:00:27,390
Objective 3.3 states that you must be able to explain
12

12

00:00:27,390  -->  00:00:29,970
the preparation and post-incident activity phases
13

13

00:00:29,970  -->  00:00:32,040
of the incident management lifecycle.
14

14

00:00:32,040  -->  00:00:34,170
As I said, though, we're really going to be focused
15

15

00:00:34,170  -->  00:00:36,960
in this section only on the preparation phase
16

16

00:00:36,960  -->  00:00:39,480
and this includes things like planning, training,
17

17

00:00:39,480  -->  00:00:42,690
testing, and the documentation portions of this objective
18

18

00:00:42,690  -->  00:00:45,390
as we start going through that preparation phase.
19

19

00:00:45,390  -->  00:00:47,910
We'll also be looking at objective 4.2.
20

20

00:00:47,910  -->  00:00:50,070
Objective 4.2 states that you must be able
21

21

00:00:50,070  -->  00:00:52,050
to explain the importance of incident response
22

22

00:00:52,050  -->  00:00:53,910
reporting and communication.
23

23

00:00:53,910  -->  00:00:55,830
Specifically, we're going to be focused here
24

24

00:00:55,830  -->  00:00:57,630
on the communication planning portion
25

25

00:00:57,630  -->  00:01:00,750
of the incident response lifecycle's preparation phase.
26

26

00:01:00,750  -->  00:01:02,670
Now, as we move throughout this section,
27

27

00:01:02,670  -->  00:01:04,110
we're going to start with a broad look
28

28

00:01:04,110  -->  00:01:05,970
at the incident response process
29

29

00:01:05,970  -->  00:01:08,340
and all of the portions and phases of it.
30

30

00:01:08,340  -->  00:01:10,230
That way, you'll have a good overview
31

31

00:01:10,230  -->  00:01:12,360
for the next few sections of the course.
32

32

00:01:12,360  -->  00:01:14,190
Then, we're going to dive into the concepts
33

33

00:01:14,190  -->  00:01:17,130
covered by documenting the incident response process.
34

34

00:01:17,130  -->  00:01:18,660
Next, we're going to be talking about
35

35

00:01:18,660  -->  00:01:20,610
the seven types of data criticality
36

36

00:01:20,610  -->  00:01:22,380
that you need to consider when you're developing
37

37

00:01:22,380  -->  00:01:24,240
your incident response plans.
38

38

00:01:24,240  -->  00:01:26,730
Then, we're going to be talking about communication plans
39

39

00:01:26,730  -->  00:01:28,050
and reporting requirements,
40

40

00:01:28,050  -->  00:01:30,180
because these are critical to have pre-planned
41

41

00:01:30,180  -->  00:01:32,880
before an incident actually occurs.
42

42

00:01:32,880  -->  00:01:34,710
Next, we're going to cover how you can best
43

43

00:01:34,710  -->  00:01:37,380
coordinate your response efforts across your organization
44

44

00:01:37,380  -->  00:01:39,900
and with your external stakeholders, too.
45

45

00:01:39,900  -->  00:01:43,290
Then, we'll be discussing the of a business continuity plan
46

46

00:01:43,290  -->  00:01:45,420
and how we use these to ensure our businesses
47

47

00:01:45,420  -->  00:01:47,850
can continue to operate during natural disasters,
48

48

00:01:47,850  -->  00:01:50,460
cyber attacks, and other malicious events.
49

49

00:01:50,460  -->  00:01:53,010
After that, we're going to discuss training and testing,
50

50

00:01:53,010  -->  00:01:54,240
as both of these are critical
51

51

00:01:54,240  -->  00:01:56,610
to the success of any incident response.
52

52

00:01:56,610  -->  00:01:58,110
If you are not well prepared,
53

53

00:01:58,110  -->  00:02:00,270
your instant response is going to fail
54

54

00:02:00,270  -->  00:02:01,890
and it's going to become even more costly
55

55

00:02:01,890  -->  00:02:04,080
and disastrous for your organization.
56

56

00:02:04,080  -->  00:02:06,030
So an ounce of prevention here
57

57

00:02:06,030  -->  00:02:08,070
is going to be worth a pound of cure.
58

58

00:02:08,070  -->  00:02:10,410
After all, these days, it's not really a matter
59

59

00:02:10,410  -->  00:02:12,180
of if you're going to have an incident response,
60

60

00:02:12,180  -->  00:02:13,800
it's really a matter of when.
61

61

00:02:13,800  -->  00:02:15,420
Cyber attacks and data breaches
62

62

00:02:15,420  -->  00:02:17,310
are increasing at an alarming rate,
63

63

00:02:17,310  -->  00:02:19,320
and so it's really important that we are well prepared
64

64

00:02:19,320  -->  00:02:21,540
for these things because they are going to happen
65

65

00:02:21,540  -->  00:02:23,310
at some point in the future.
66

66

00:02:23,310  -->  00:02:25,020
Finally, we're going to take a short quiz
67

67

00:02:25,020  -->  00:02:27,210
to see what you learned during this section of the course
68

68

00:02:27,210  -->  00:02:28,740
and we'll review those quiz questions
69

69

00:02:28,740  -->  00:02:30,660
to ensure you can explain why the correct answers
70

70

00:02:30,660  -->  00:02:31,680
were correct.
71

71

00:02:31,680  -->  00:02:34,530
So let's start talking all about incident responses
72

72

00:02:34,530  -->  00:02:37,020
by considering the different phases of an incident response
73

73

00:02:37,020  -->  00:02:39,570
and then focusing in depth on the preparation phase
74

74

00:02:39,570  -->  00:02:41,070
in this section of the course.
