1
1

00:00:00,630  -->  00:00:02,490
<v Tutor>Reporting Requirements.</v>
2

2

00:00:02,490  -->  00:00:03,480
In this lesson,
3

3

00:00:03,480  -->  00:00:06,330
we are going to talk about the different reporting requirements
4

4

00:00:06,330  -->  00:00:09,270
that you may have to face as an instant responder.
5

5

00:00:09,270  -->  00:00:11,370
Now again, this is something we have to think about
6

6

00:00:11,370  -->  00:00:13,530
all the way back in our preparation phase
7

7

00:00:13,530  -->  00:00:15,450
to ensure we're ready to do our reporting
8

8

00:00:15,450  -->  00:00:18,210
as required by law or regulation.
9

9

00:00:18,210  -->  00:00:20,040
Now, when we talk about reporting requirements,
10

10

00:00:20,040  -->  00:00:22,110
these are notifications that must be made
11

11

00:00:22,110  -->  00:00:23,520
to the affected parties
12

12

00:00:23,520  -->  00:00:25,080
in the event of a data breach,
13

13

00:00:25,080  -->  00:00:28,440
as required by legislation or regulation.
14

14

00:00:28,440  -->  00:00:31,620
Now, there are five different types of breaches that exist,
15

15

00:00:31,620  -->  00:00:32,880
and depending on the breach,
16

16

00:00:32,880  -->  00:00:35,100
there are different reporting requirements.
17

17

00:00:35,100  -->  00:00:37,740
The first one is data exfiltration.
18

18

00:00:37,740  -->  00:00:40,020
This occurs when an attacker breaks into a system
19

19

00:00:40,020  -->  00:00:42,420
and transfers data to another system.
20

20

00:00:42,420  -->  00:00:44,310
So if an attacker's being able to get into
21

21

00:00:44,310  -->  00:00:47,070
your credit card database and take those numbers out,
22

22

00:00:47,070  -->  00:00:50,160
that would be considered a data exfiltration attempt.
23

23

00:00:50,160  -->  00:00:51,120
Now, in addition to that,
24

24

00:00:51,120  -->  00:00:52,530
we might have another type of breach,
25

25

00:00:52,530  -->  00:00:55,350
which is known as insider data exfiltration.
26

26

00:00:55,350  -->  00:00:56,940
This occurs when an employee
27

27

00:00:56,940  -->  00:00:59,640
or an ex-employee with privileges on the system
28

28

00:00:59,640  -->  00:01:01,740
transfers data to another system.
29

29

00:01:01,740  -->  00:01:04,800
So for example, if somebody at my office goes in
30

30

00:01:04,800  -->  00:01:06,660
and downloads files from our share drive
31

31

00:01:06,660  -->  00:01:09,660
onto a USB thumb drive and takes it home with them,
32

32

00:01:09,660  -->  00:01:11,520
and then uploads it to WikiLeaks,
33

33

00:01:11,520  -->  00:01:14,190
that would be considered an insider data exfiltration
34

34

00:01:14,190  -->  00:01:15,930
because one of our employees is doing it
35

35

00:01:15,930  -->  00:01:17,910
with their normal permissions and rights.
36

36

00:01:17,910  -->  00:01:19,650
The third type of breach we might have
37

37

00:01:19,650  -->  00:01:22,530
can occur when we have a device theft or loss.
38

38

00:01:22,530  -->  00:01:25,740
This is when a device containing data is lost or stolen.
39

39

00:01:25,740  -->  00:01:28,320
So one of the typical examples is a smartphone.
40

40

00:01:28,320  -->  00:01:29,153
You have a smartphone
41

41

00:01:29,153  -->  00:01:30,780
that has a lot of corporate data on it,
42

42

00:01:30,780  -->  00:01:33,060
and if you leave it in the back of a taxi cab, for instance,
43

43

00:01:33,060  -->  00:01:35,160
that would be device loss.
44

44

00:01:35,160  -->  00:01:35,993
Another thing would be
45

45

00:01:35,993  -->  00:01:37,500
if you had a laptop in the back of your car
46

46

00:01:37,500  -->  00:01:40,470
and somebody broke into your car and stole that laptop.
47

47

00:01:40,470  -->  00:01:42,210
Now, this has happened numerous times
48

48

00:01:42,210  -->  00:01:44,460
to many organizations around the world,
49

49

00:01:44,460  -->  00:01:46,650
and it does put your data at risk.
50

50

00:01:46,650  -->  00:01:47,790
The fourth type we have
51

51

00:01:47,790  -->  00:01:50,160
is known as an accidental data breach.
52

52

00:01:50,160  -->  00:01:50,993
Now, this occurs
53

53

00:01:50,993  -->  00:01:52,650
when there's public disclosure of information
54

54

00:01:52,650  -->  00:01:54,210
or unauthorized transfer
55

55

00:01:54,210  -->  00:01:57,420
that's caused by human error or a misconfiguration.
56

56

00:01:57,420  -->  00:02:00,360
Essentially, this happened because somebody made a mistake,
57

57

00:02:00,360  -->  00:02:01,920
it wasn't intentional.
58

58

00:02:01,920  -->  00:02:04,500
And as you can see here as we're moving down the scale,
59

59

00:02:04,500  -->  00:02:06,840
we're getting less and less severe.
60

60

00:02:06,840  -->  00:02:07,740
And then finally,
61

61

00:02:07,740  -->  00:02:10,620
we have integrity or availability breaches.
62

62

00:02:10,620  -->  00:02:12,510
This occurs when there's corruption of the data
63

63

00:02:12,510  -->  00:02:15,930
or destruction of a system that processes that data.
64

64

00:02:15,930  -->  00:02:16,890
So if I had somebody
65

65

00:02:16,890  -->  00:02:19,200
who was able to modify data in a database,
66

66

00:02:19,200  -->  00:02:20,910
that would be an integrity breach.
67

67

00:02:20,910  -->  00:02:23,610
If I do a denial of service attack against your web server,
68

68

00:02:23,610  -->  00:02:25,740
that would be an availability breach.
69

69

00:02:25,740  -->  00:02:27,420
And again, as we go forward,
70

70

00:02:27,420  -->  00:02:29,580
starting with data exfiltration,
71

71

00:02:29,580  -->  00:02:31,440
and then insider data exfiltration,
72

72

00:02:31,440  -->  00:02:33,210
and then device theft or loss,
73

73

00:02:33,210  -->  00:02:34,740
and then accidental data breach,
74

74

00:02:34,740  -->  00:02:37,200
and finally, integrity and availability breach,
75

75

00:02:37,200  -->  00:02:40,080
we go from the most significant, being data exfiltration
76

76

00:02:40,080  -->  00:02:42,390
because an attacker broke into our systems,
77

77

00:02:42,390  -->  00:02:44,220
all the way down to the least,
78

78

00:02:44,220  -->  00:02:46,530
which is integrity or availability breaches,
79

79

00:02:46,530  -->  00:02:47,760
that usually occurs
80

80

00:02:47,760  -->  00:02:50,940
when something other than confidentiality is being breached,
81

81

00:02:50,940  -->  00:02:52,680
which means it's data integrity
82

82

00:02:52,680  -->  00:02:55,020
or availability that's being affected.
83

83

00:02:55,020  -->  00:02:56,910
Now, depending on the type of breach you have,
84

84

00:02:56,910  -->  00:02:59,040
there's going to be different laws and regulations
85

85

00:02:59,040  -->  00:03:01,590
that govern your requirements for reporting.
86

86

00:03:01,590  -->  00:03:03,090
These requirements are going to tell you
87

87

00:03:03,090  -->  00:03:04,200
what you have to report
88

88

00:03:04,200  -->  00:03:06,450
and in what timeframe you have to report,
89

89

00:03:06,450  -->  00:03:08,940
and to who you have to report these things to.
90

90

00:03:08,940  -->  00:03:11,460
For example, if you have a HIPAA issue,
91

91

00:03:11,460  -->  00:03:13,500
which would be something that has to deal with PHI
92

92

00:03:13,500  -->  00:03:15,450
or Protected Health Information,
93

93

00:03:15,450  -->  00:03:17,490
you would have to actually report that.
94

94

00:03:17,490  -->  00:03:19,920
Now, HIPAA is a law inside the United States,
95

95

00:03:19,920  -->  00:03:21,390
and so if you have a data breach
96

96

00:03:21,390  -->  00:03:23,130
affecting this type of data,
97

97

00:03:23,130  -->  00:03:26,070
you are going to be required to notify the affected individuals
98

98

00:03:26,070  -->  00:03:29,070
the Secretary of Health and Human Services, and the media
99

99

00:03:29,070  -->  00:03:32,250
if there's over 500 people affected by that data breach.
100

100

00:03:32,250  -->  00:03:33,240
Now, another example
101

101

00:03:33,240  -->  00:03:35,040
of a regulatory requirement for reporting
102

102

00:03:35,040  -->  00:03:36,600
would be under GDPR,
103

103

00:03:36,600  -->  00:03:39,300
which is the General Data Protection Regulation.
104

104

00:03:39,300  -->  00:03:42,180
This applies inside the European Union.
105

105

00:03:42,180  -->  00:03:44,250
Now with GDPR, this is going to require
106

106

00:03:44,250  -->  00:03:46,350
a notification within 72 hours
107

107

00:03:46,350  -->  00:03:49,350
of becoming aware of the breach of personal data.
108

108

00:03:49,350  -->  00:03:50,910
You need to notify the person
109

109

00:03:50,910  -->  00:03:52,980
as well as the GDPR regulators,
110

110

00:03:52,980  -->  00:03:54,870
which is the European Union.
111

111

00:03:54,870  -->  00:03:57,480
Now, the final thing we want to talk about is disclosure,
112

112

00:03:57,480  -->  00:03:59,310
and this is something that has to do with
113

113

00:03:59,310  -->  00:04:01,830
how are you going to tell the person affected?
114

114

00:04:01,830  -->  00:04:03,450
If we think back to Yahoo,
115

115

00:04:03,450  -->  00:04:05,460
Yahoo has had a number of data breaches
116

116

00:04:05,460  -->  00:04:06,990
over the last decade.
117

117

00:04:06,990  -->  00:04:08,280
Now, if you're like most people,
118

118

00:04:08,280  -->  00:04:10,380
you've probably received at some point in your life,
119

119

00:04:10,380  -->  00:04:12,270
one of these notices from Yahoo.
120

120

00:04:12,270  -->  00:04:14,490
This is because Yahoo has had the information
121

121

00:04:14,490  -->  00:04:18,450
of over 1 billion people breached over the last decade.
122

122

00:04:18,450  -->  00:04:20,010
Now, disclosure here would be,
123

123

00:04:20,010  -->  00:04:21,990
when they tell you that this has happened,
124

124

00:04:21,990  -->  00:04:23,670
they're going to say, "Dear user.
125

125

00:04:23,670  -->  00:04:25,530
We want to let you know about this security issue.
126

126

00:04:25,530  -->  00:04:27,000
We had some bad things happen.
127

127

00:04:27,000  -->  00:04:27,833
Here's what they were,
128

128

00:04:27,833  -->  00:04:29,580
and here's what we're doing about it."
129

129

00:04:29,580  -->  00:04:32,370
Essentially, the disclosure's going to have key information
130

130

00:04:32,370  -->  00:04:34,770
like a description of what information was breached,
131

131

00:04:34,770  -->  00:04:36,810
the details of who the main point of contact is
132

132

00:04:36,810  -->  00:04:38,100
if you have any questions,
133

133

00:04:38,100  -->  00:04:40,980
and any likely consequences arising from that breach,
134

134

00:04:40,980  -->  00:04:44,280
as well as measures that were taken to mitigate that breach.
135

135

00:04:44,280  -->  00:04:46,320
All of this is the information that would be disclosed
136

136

00:04:46,320  -->  00:04:47,730
to the person who was affected
137

137

00:04:47,730  -->  00:04:50,013
and had their data lost or data stolen.
