1
1

00:00:00,570  -->  00:00:02,400
<v Instructor>Response coordination.</v>
2

2

00:00:02,400  -->  00:00:05,040
Now, in preparation, one of the other things we have
3

3

00:00:05,040  -->  00:00:08,550
to think about is how we're going to coordinate our response
4

4

00:00:08,550  -->  00:00:10,950
because an incident response is going to require coordination
5

5

00:00:10,950  -->  00:00:12,570
between different internal departments
6

6

00:00:12,570  -->  00:00:14,400
and external agencies.
7

7

00:00:14,400  -->  00:00:16,410
Let me give you a quick example of this.
8

8

00:00:16,410  -->  00:00:19,380
Twitter had a massive breach to their security.
9

9

00:00:19,380  -->  00:00:21,060
Now, due to the massive breach,
10

10

00:00:21,060  -->  00:00:24,480
lots of high profile accounts started tweeting out messages
11

11

00:00:24,480  -->  00:00:25,860
asking for Bitcoin.
12

12

00:00:25,860  -->  00:00:28,080
We started seeing this from companies like Apple
13

13

00:00:28,080  -->  00:00:29,580
and we saw it from Jeff Bezos
14

14

00:00:29,580  -->  00:00:31,440
which is one of the richest people in the world.
15

15

00:00:31,440  -->  00:00:32,940
We saw it from Barack Obama
16

16

00:00:32,940  -->  00:00:34,920
the former president of the United States.
17

17

00:00:34,920  -->  00:00:38,220
We also saw it from Kanye West, one of the big music stars.
18

18

00:00:38,220  -->  00:00:40,950
And we saw from Joe Biden, who was a presidential candidate
19

19

00:00:40,950  -->  00:00:42,480
at the time, as well as Warren Buffet
20

20

00:00:42,480  -->  00:00:46,350
another large investor in the world, and even Elon Musk.
21

21

00:00:46,350  -->  00:00:48,330
And all of these were high-profile accounts
22

22

00:00:48,330  -->  00:00:50,490
that were hacked as part of this breach.
23

23

00:00:50,490  -->  00:00:51,450
Now, when this happened,
24

24

00:00:51,450  -->  00:00:53,970
Twitter immediately locked down those accounts
25

25

00:00:53,970  -->  00:00:56,100
so that the attackers couldn't use them anymore
26

26

00:00:56,100  -->  00:00:57,960
and then they started working
27

27

00:00:57,960  -->  00:01:00,570
with external agencies such as the FBI
28

28

00:01:00,570  -->  00:01:03,240
to come help them figure out what was going on.
29

29

00:01:03,240  -->  00:01:05,490
And within two weeks, they had the suspect
30

30

00:01:05,490  -->  00:01:08,460
in custody at the FBI and started to figure out
31

31

00:01:08,460  -->  00:01:11,370
exactly what happened as part of this incident response.
32

32

00:01:11,370  -->  00:01:13,560
Now, in this case, this was a big event
33

33

00:01:13,560  -->  00:01:16,320
and it became very newsworthy, but this kind of thing
34

34

00:01:16,320  -->  00:01:18,570
does happen a lot in the industry
35

35

00:01:18,570  -->  00:01:20,190
where you're going to be working with both internal
36

36

00:01:20,190  -->  00:01:23,160
and external players to work on your incident response.
37

37

00:01:23,160  -->  00:01:26,070
And when you do that, you have to coordinate that.
38

38

00:01:26,070  -->  00:01:28,350
Now, one of the questions you have to ask yourself is
39

39

00:01:28,350  -->  00:01:30,570
who are the affected stakeholders?
40

40

00:01:30,570  -->  00:01:31,830
In the case of Twitter
41

41

00:01:31,830  -->  00:01:34,890
the FBI got involved because this was a major attack
42

42

00:01:34,890  -->  00:01:37,440
against all these high profile accounts.
43

43

00:01:37,440  -->  00:01:39,060
Two of those accounts I just showed you
44

44

00:01:39,060  -->  00:01:40,590
were President Barack Obama
45

45

00:01:40,590  -->  00:01:43,080
and presidential candidate Joe Biden.
46

46

00:01:43,080  -->  00:01:44,340
And that's a real good reason
47

47

00:01:44,340  -->  00:01:46,590
for the FBI to get involved pretty quickly here.
48

48

00:01:46,590  -->  00:01:47,700
But when you have an incident,
49

49

00:01:47,700  -->  00:01:48,630
you need to start thinking about
50

50

00:01:48,630  -->  00:01:50,490
who are the affected stakeholders.
51

51

00:01:50,490  -->  00:01:52,500
There are lots of them out there inside
52

52

00:01:52,500  -->  00:01:53,910
and outside your organization.
53

53

00:01:53,910  -->  00:01:54,743
For instance,
54

54

00:01:54,743  -->  00:01:57,000
you might have senior leadership that gets involved.
55

55

00:01:57,000  -->  00:01:58,920
You might have regulatory bodies,
56

56

00:01:58,920  -->  00:02:01,050
you might have your internal legal counsel
57

57

00:02:01,050  -->  00:02:02,910
or external law enforcement.
58

58

00:02:02,910  -->  00:02:04,740
It might be your internal human resources
59

59

00:02:04,740  -->  00:02:06,510
or your internal public relations
60

60

00:02:06,510  -->  00:02:08,280
and externally with the media.
61

61

00:02:08,280  -->  00:02:10,440
All of these are people who are valid stakeholders
62

62

00:02:10,440  -->  00:02:12,390
when you have an incident and you have to consider
63

63

00:02:12,390  -->  00:02:14,220
how does this incident affect them
64

64

00:02:14,220  -->  00:02:16,500
and how are you going to coordinate your response.
65

65

00:02:16,500  -->  00:02:18,120
Let's go ahead and look at each of these.
66

66

00:02:18,120  -->  00:02:20,250
First we have senior leadership.
67

67

00:02:20,250  -->  00:02:22,950
When we talk about senior leadership, this is the executives
68

68

00:02:22,950  -->  00:02:25,530
and managers who are responsible for business operations
69

69

00:02:25,530  -->  00:02:28,500
and various functional areas within your company.
70

70

00:02:28,500  -->  00:02:30,570
Now, the reason this is important is because a lot
71

71

00:02:30,570  -->  00:02:33,270
of our incident responders tend to be technical people
72

72

00:02:33,270  -->  00:02:35,970
and so we might, as technical people say, the quickest way
73

73

00:02:35,970  -->  00:02:38,490
to solve this incident is to shut down that server.
74

74

00:02:38,490  -->  00:02:40,860
But if we're not understanding the business impact
75

75

00:02:40,860  -->  00:02:42,810
of those actions, that could have second
76

76

00:02:42,810  -->  00:02:44,610
and third order effects, they'll be very bad
77

77

00:02:44,610  -->  00:02:45,810
for our organization.
78

78

00:02:45,810  -->  00:02:48,390
So we're going to have to get senior leadership involved
79

79

00:02:48,390  -->  00:02:51,750
to understand if I do this, it's going to have this and that
80

80

00:02:51,750  -->  00:02:54,420
and the other effect, and we have to mitigate those.
81

81

00:02:54,420  -->  00:02:56,790
For example, if your credit card processing system
82

82

00:02:56,790  -->  00:02:59,490
has been compromised, if you immediately shut it down,
83

83

00:02:59,490  -->  00:03:00,840
you are cutting off your ability
84

84

00:03:00,840  -->  00:03:02,760
to process new transactions.
85

85

00:03:02,760  -->  00:03:05,160
Now, that might be the right answer technically
86

86

00:03:05,160  -->  00:03:06,840
but from a business standpoint
87

87

00:03:06,840  -->  00:03:08,640
that could actually hurt you even worse.
88

88

00:03:08,640  -->  00:03:10,740
And so you have to start weighing these factors
89

89

00:03:10,740  -->  00:03:12,900
and working across the organization
90

90

00:03:12,900  -->  00:03:14,340
to make sure you have another way
91

91

00:03:14,340  -->  00:03:16,230
to accept payments before shutting down
92

92

00:03:16,230  -->  00:03:17,580
that credit card system.
93

93

00:03:17,580  -->  00:03:18,990
Or maybe you're going to make the decision
94

94

00:03:18,990  -->  00:03:20,790
that it's okay to shut down the system
95

95

00:03:20,790  -->  00:03:23,070
but you understand you're going to be giving up the ability
96

96

00:03:23,070  -->  00:03:24,840
to process credit cards right now.
97

97

00:03:24,840  -->  00:03:27,990
That is a business decision, not a technical decision.
98

98

00:03:27,990  -->  00:03:29,100
And so it is one that you have to have
99

99

00:03:29,100  -->  00:03:30,780
senior leaderships buy-in on.
100

100

00:03:30,780  -->  00:03:32,130
The next key stakeholder we have
101

101

00:03:32,130  -->  00:03:34,260
to consider is regulatory bodies.
102

102

00:03:34,260  -->  00:03:36,570
These are governmental organizations that oversee
103

103

00:03:36,570  -->  00:03:39,510
the compliance with specific regulations and laws.
104

104

00:03:39,510  -->  00:03:41,700
For example, if we're talking about HIPAA
105

105

00:03:41,700  -->  00:03:43,140
which has to do with healthcare,
106

106

00:03:43,140  -->  00:03:44,640
you're going to have to be overseen
107

107

00:03:44,640  -->  00:03:46,500
by health and human services
108

108

00:03:46,500  -->  00:03:49,050
because they're the ones who run the HIPAA program.
109

109

00:03:49,050  -->  00:03:50,040
If you're dealing with something like
110

110

00:03:50,040  -->  00:03:53,280
the California Consumer Privacy Act or CCPA,
111

111

00:03:53,280  -->  00:03:55,680
you're going to be dealing with the state of California.
112

112

00:03:55,680  -->  00:03:57,720
If you're dealing with something like credit card data
113

113

00:03:57,720  -->  00:04:00,180
you're going to be dealing with PCIDSS
114

114

00:04:00,180  -->  00:04:02,700
and those people who run that program.
115

115

00:04:02,700  -->  00:04:04,950
Again, these are the different regulatory bodies
116

116

00:04:04,950  -->  00:04:06,180
you're going to have to consider.
117

117

00:04:06,180  -->  00:04:09,090
Now, a quick note, when you're dealing with PCIDSS
118

118

00:04:09,090  -->  00:04:11,490
they're not technically a regulatory body
119

119

00:04:11,490  -->  00:04:13,020
from a legal standpoint
120

120

00:04:13,020  -->  00:04:15,840
but they do oversee all of the payment card systems.
121

121

00:04:15,840  -->  00:04:18,390
Now, generally, when we talk about the term regulatory
122

122

00:04:18,390  -->  00:04:19,830
we are talking about legal.
123

123

00:04:19,830  -->  00:04:22,590
And with PCIDSS, it is not a legal requirement.
124

124

00:04:22,590  -->  00:04:24,240
It is a contractual requirement
125

125

00:04:24,240  -->  00:04:26,970
between you and your payment processor.
126

126

00:04:26,970  -->  00:04:29,370
The next stakeholder we have to consider is legal.
127

127

00:04:29,370  -->  00:04:32,430
Now, legal is the business or organization's legal counsel
128

128

00:04:32,430  -->  00:04:33,600
and they're going to be responsible
129

129

00:04:33,600  -->  00:04:36,330
for mitigating risk from civil lawsuits.
130

130

00:04:36,330  -->  00:04:38,460
For example, as you're planning out your response
131

131

00:04:38,460  -->  00:04:40,950
of what you're going to do to stop the breach of data
132

132

00:04:40,950  -->  00:04:42,480
you want to make sure legal is in the room
133

133

00:04:42,480  -->  00:04:44,910
because your actions could come up later on
134

134

00:04:44,910  -->  00:04:47,400
if your company is sued for its response.
135

135

00:04:47,400  -->  00:04:48,900
And so you want to make sure they're in the room
136

136

00:04:48,900  -->  00:04:50,430
and they understand what you're doing
137

137

00:04:50,430  -->  00:04:52,380
and they have input into it.
138

138

00:04:52,380  -->  00:04:55,110
On the other side of the coin, we have law enforcement
139

139

00:04:55,110  -->  00:04:57,750
and law enforcement is an external stakeholder.
140

140

00:04:57,750  -->  00:04:58,920
They may provide services
141

141

00:04:58,920  -->  00:05:01,800
to assist in your incident handling efforts or to prepare
142

142

00:05:01,800  -->  00:05:04,590
for legal action against the attacker in the future.
143

143

00:05:04,590  -->  00:05:06,450
Just like I was talking about earlier with Twitter,
144

144

00:05:06,450  -->  00:05:07,590
they brought the FBI in
145

145

00:05:07,590  -->  00:05:09,630
because they wanted to pursue legal action
146

146

00:05:09,630  -->  00:05:12,180
against that attacker, and the FBI was able
147

147

00:05:12,180  -->  00:05:14,280
to bring in additional services to help them
148

148

00:05:14,280  -->  00:05:15,113
in that incident response
149

149

00:05:15,113  -->  00:05:17,580
to be able to deal with it much quicker.
150

150

00:05:17,580  -->  00:05:19,830
Now, one quick thing to note, your decision
151

151

00:05:19,830  -->  00:05:21,120
to involve law enforcement
152

152

00:05:21,120  -->  00:05:23,430
has to be made by senior executives
153

153

00:05:23,430  -->  00:05:26,280
with guidance from your internal legal counsel.
154

154

00:05:26,280  -->  00:05:27,630
You as an incident responder,
155

155

00:05:27,630  -->  00:05:29,100
should not immediately pick up the phone
156

156

00:05:29,100  -->  00:05:31,470
and call the FBI or the local police.
157

157

00:05:31,470  -->  00:05:33,930
This is something your business has to decide.
158

158

00:05:33,930  -->  00:05:36,330
Now, there are cases where it is legally required
159

159

00:05:36,330  -->  00:05:37,650
to bring in law enforcement,
160

160

00:05:37,650  -->  00:05:39,570
but in a lot of cases it is more
161

161

00:05:39,570  -->  00:05:42,150
of a civil issue, and you have the determination
162

162

00:05:42,150  -->  00:05:44,580
and the right to decide if you want to press charges
163

163

00:05:44,580  -->  00:05:46,140
and bring in law enforcement.
164

164

00:05:46,140  -->  00:05:47,910
So keep that in mind and remember,
165

165

00:05:47,910  -->  00:05:50,640
your senior executives get to make that decision.
166

166

00:05:50,640  -->  00:05:52,740
Our next stakeholder is human resources
167

167

00:05:52,740  -->  00:05:54,690
and this is an internal stakeholder.
168

168

00:05:54,690  -->  00:05:56,670
They're going to be used to ensure there's no breaches
169

169

00:05:56,670  -->  00:05:59,040
of employment law or employee contracts
170

170

00:05:59,040  -->  00:06:00,840
during the incident response.
171

171

00:06:00,840  -->  00:06:01,673
For example,
172

172

00:06:01,673  -->  00:06:03,930
if you are suspecting that there's an internal threat
173

173

00:06:03,930  -->  00:06:05,790
and you want to start questioning employees
174

174

00:06:05,790  -->  00:06:07,800
or you want to start going through employee files,
175

175

00:06:07,800  -->  00:06:09,870
you're going to have to consult human resources
176

176

00:06:09,870  -->  00:06:11,640
because you could be breaching employment law
177

177

00:06:11,640  -->  00:06:12,780
or employee contracts.
178

178

00:06:12,780  -->  00:06:15,330
So make sure you involve human resources.
179

179

00:06:15,330  -->  00:06:17,010
And our final stakeholder we want to consult
180

180

00:06:17,010  -->  00:06:19,290
is public relations or PR.
181

181

00:06:19,290  -->  00:06:21,930
Public relations is used to manage the negative publicity
182

182

00:06:21,930  -->  00:06:23,460
from a serious incident.
183

183

00:06:23,460  -->  00:06:25,710
Now, this is important because you want to make sure
184

184

00:06:25,710  -->  00:06:28,410
as the technical lead, as an incident responder
185

185

00:06:28,410  -->  00:06:31,110
you're not the one answering questions to the media.
186

186

00:06:31,110  -->  00:06:32,310
You don't want to be the one up there
187

187

00:06:32,310  -->  00:06:33,720
behind all those microphones
188

188

00:06:33,720  -->  00:06:36,330
with a sea of reporters asking you questions.
189

189

00:06:36,330  -->  00:06:38,010
You have people in your organization
190

190

00:06:38,010  -->  00:06:39,690
whose job it is to handle that
191

191

00:06:39,690  -->  00:06:42,240
and they're going to come up with a clear, concise message
192

192

00:06:42,240  -->  00:06:44,070
that can be said over and over again
193

193

00:06:44,070  -->  00:06:46,230
to all the inquiries reporters have.
194

194

00:06:46,230  -->  00:06:47,820
This way, you're on-brand
195

195

00:06:47,820  -->  00:06:50,400
and on-message across your organization.
196

196

00:06:50,400  -->  00:06:52,680
Remember, public relations needs to be involved
197

197

00:06:52,680  -->  00:06:55,620
especially with larger breaches that may get the interest
198

198

00:06:55,620  -->  00:06:57,570
of media and the press.
199

199

00:06:57,570  -->  00:07:00,330
Now, as part of the CSIRT team, it's going to be your role
200

200

00:07:00,330  -->  00:07:03,360
to help provide information to these stakeholders.
201

201

00:07:03,360  -->  00:07:05,040
As part of the CSIRT, you're going to be asked
202

202

00:07:05,040  -->  00:07:07,620
for information regarding the estimated downtime,
203

203

00:07:07,620  -->  00:07:09,720
the scope of the systems and data affected
204

204

00:07:09,720  -->  00:07:11,430
and other relevant details.
205

205

00:07:11,430  -->  00:07:12,690
And by having that information
206

206

00:07:12,690  -->  00:07:15,060
and providing that up to the appropriate senior leadership,
207

207

00:07:15,060  -->  00:07:18,690
human resources, legal, public relations, and others
208

208

00:07:18,690  -->  00:07:19,523
it's going to make sure
209

209

00:07:19,523  -->  00:07:21,420
that we all are providing a consistent message
210

210

00:07:21,420  -->  00:07:23,920
and that we are coordinating our response efforts.
