1
1

00:00:00,330  -->  00:00:02,670
<v Instructor>Post-incident activities.</v>
2

2

00:00:02,670  -->  00:00:04,530
Our final phase of an incident response
3

3

00:00:04,530  -->  00:00:07,410
is to conduct our post-incident activities.
4

4

00:00:07,410  -->  00:00:09,360
This is going to occur once the attack
5

5

00:00:09,360  -->  00:00:11,490
or immediate threat has been neutralized
6

6

00:00:11,490  -->  00:00:14,760
and the system has been restored to secure operation.
7

7

00:00:14,760  -->  00:00:17,280
So once we've done all that, we are back in business.
8

8

00:00:17,280  -->  00:00:20,400
Everything is hunky dory and we're back to normal,
9

9

00:00:20,400  -->  00:00:22,470
but there's still some things we need to do,
10

10

00:00:22,470  -->  00:00:25,470
and this is where post-incident activity comes into play.
11

11

00:00:25,470  -->  00:00:28,080
We're going to analyze the incident and responses to identify
12

12

00:00:28,080  -->  00:00:31,350
whether the procedures or systems could have been improved.
13

13

00:00:31,350  -->  00:00:33,420
Now, as part of our post-incident activities,
14

14

00:00:33,420  -->  00:00:34,980
we have three main areas
15

15

00:00:34,980  -->  00:00:37,230
that we're going to consider in this lesson.
16

16

00:00:37,230  -->  00:00:39,030
We have report writing,
17

17

00:00:39,030  -->  00:00:42,450
incident summary reports, and evidence retention.
18

18

00:00:42,450  -->  00:00:44,880
First, let's talk about report writing.
19

19

00:00:44,880  -->  00:00:47,490
Report writing is an essential analyst skill,
20

20

00:00:47,490  -->  00:00:49,981
and it's used to communicate information
21

21

00:00:49,981  -->  00:00:52,680
about the incident to a wide variety of stakeholders.
22

22

00:00:52,680  -->  00:00:54,390
Now, when you're making these reports
23

23

00:00:54,390  -->  00:00:56,460
you want to make sure you're clearly marking them
24

24

00:00:56,460  -->  00:00:58,230
for the intended audience,
25

25

00:00:58,230  -->  00:01:00,720
because depending on who you're writing it for,
26

26

00:01:00,720  -->  00:01:02,820
that is either going to have different classification levels
27

27

00:01:02,820  -->  00:01:06,060
or different audiences who have different needs.
28

28

00:01:06,060  -->  00:01:08,040
For example, if I work for the government,
29

29

00:01:08,040  -->  00:01:09,450
and I'm talking about something that happened
30

30

00:01:09,450  -->  00:01:11,010
on a top secret system,
31

31

00:01:11,010  -->  00:01:13,560
that report needs to be marked Top Secret,
32

32

00:01:13,560  -->  00:01:16,710
to make sure only cleared people can read that report.
33

33

00:01:16,710  -->  00:01:19,290
Additionally, if I'm in a business organization,
34

34

00:01:19,290  -->  00:01:21,330
I might write a report for the technical audience
35

35

00:01:21,330  -->  00:01:22,770
and one for leadership,
36

36

00:01:22,770  -->  00:01:25,080
and those are going to be very different reports.
37

37

00:01:25,080  -->  00:01:27,150
When I write one for my senior leadership,
38

38

00:01:27,150  -->  00:01:29,520
I'm going to create an Executive Summary.
39

39

00:01:29,520  -->  00:01:32,760
This is a shorter report that has different sections on it
40

40

00:01:32,760  -->  00:01:34,590
for things like our problem statement,
41

41

00:01:34,590  -->  00:01:38,190
our observations, our conclusions, and our recommendations.
42

42

00:01:38,190  -->  00:01:39,690
Inside this executive summary,
43

43

00:01:39,690  -->  00:01:42,480
it usually is just going to be a handful of pages.
44

44

00:01:42,480  -->  00:01:44,640
These are going to have a lot of charts and graphs in there.
45

45

00:01:44,640  -->  00:01:45,660
They're going to have a lot of bullets
46

46

00:01:45,660  -->  00:01:47,670
that bring out the key information,
47

47

00:01:47,670  -->  00:01:48,900
because they don't need
48

48

00:01:48,900  -->  00:01:51,270
all the technical details of the incident.
49

49

00:01:51,270  -->  00:01:53,550
They need to know what was the business impact,
50

50

00:01:53,550  -->  00:01:55,920
and how can we prevent this from happening again.
51

51

00:01:55,920  -->  00:01:57,600
Generally, if you have an incident
52

52

00:01:57,600  -->  00:01:59,700
you have some kind of a deficiency, right?
53

53

00:01:59,700  -->  00:02:01,890
Somebody was able to break into your systems.
54

54

00:02:01,890  -->  00:02:03,690
So in your executive summary,
55

55

00:02:03,690  -->  00:02:05,190
you should tell them how they broke in
56

56

00:02:05,190  -->  00:02:08,340
and what you need to stop that from happening again.
57

57

00:02:08,340  -->  00:02:10,650
That may be a higher budget, more people,
58

58

00:02:10,650  -->  00:02:13,650
or some other type of resource that you just don't have.
59

59

00:02:13,650  -->  00:02:14,880
And so asking for those things
60

60

00:02:14,880  -->  00:02:16,440
as part of your executive summary
61

61

00:02:16,440  -->  00:02:18,420
is an important thing to do.
62

62

00:02:18,420  -->  00:02:20,820
Next we have an Incident Summary Report,
63

63

00:02:20,820  -->  00:02:23,220
and this is a report written for a specific audience
64

64

00:02:23,220  -->  00:02:26,790
with key information about the incident for their use.
65

65

00:02:26,790  -->  00:02:29,100
Now, these incident summary reports are going to contain
66

66

00:02:29,100  -->  00:02:31,560
information about how the incident occurred,
67

67

00:02:31,560  -->  00:02:33,420
how it could have been prevented in the future,
68

68

00:02:33,420  -->  00:02:35,130
the impact and damage on the systems,
69

69

00:02:35,130  -->  00:02:36,720
and any lessons learned.
70

70

00:02:36,720  -->  00:02:38,250
Now, I know this sounds a lot like
71

71

00:02:38,250  -->  00:02:40,050
the executive summary I just mentioned,
72

72

00:02:40,050  -->  00:02:41,640
so what's the difference?
73

73

00:02:41,640  -->  00:02:44,070
Well, the executive summary is one type
74

74

00:02:44,070  -->  00:02:47,160
of incident summary report, but there's many others.
75

75

00:02:47,160  -->  00:02:49,350
For instance, if you're working with public relations
76

76

00:02:49,350  -->  00:02:51,270
you're going to have to write a report for them
77

77

00:02:51,270  -->  00:02:53,910
with the key details they need to be able to release that
78

78

00:02:53,910  -->  00:02:56,100
to the media and the public at large.
79

79

00:02:56,100  -->  00:02:58,500
That would be one incident summary report.
80

80

00:02:58,500  -->  00:03:00,030
Now, if I'm working, working with the system administrators
81

81

00:03:00,030  -->  00:03:02,250
on how they can prevent this from happening in the future,
82

82

00:03:02,250  -->  00:03:04,320
I might have a different incident summary report
83

83

00:03:04,320  -->  00:03:06,480
written in a very high tech language
84

84

00:03:06,480  -->  00:03:08,430
so they know all the different configurations
85

85

00:03:08,430  -->  00:03:09,877
that were wrong,
86

86

00:03:09,877  -->  00:03:11,280
and what they can do to prevent this in the future.
87

87

00:03:11,280  -->  00:03:14,220
So again, it goes back to knowing who your audience is
88

88

00:03:14,220  -->  00:03:17,340
and getting the right report for the right people.
89

89

00:03:17,340  -->  00:03:18,870
The third thing we need to talk about here
90

90

00:03:18,870  -->  00:03:20,490
is Evidence Retention.
91

91

00:03:20,490  -->  00:03:23,100
Now, evidence retention is the preservation of evidence
92

92

00:03:23,100  -->  00:03:25,290
based upon the required time period
93

93

00:03:25,290  -->  00:03:26,730
defined by regulations
94

94

00:03:26,730  -->  00:03:29,070
if there's a legal or regulatory impact
95

95

00:03:29,070  -->  00:03:31,110
that's caused by the incident.
96

96

00:03:31,110  -->  00:03:33,870
For example, if you want to be able to go after the attacker
97

97

00:03:33,870  -->  00:03:35,370
who got into your network
98

98

00:03:35,370  -->  00:03:37,230
and you want to prosecute that person,
99

99

00:03:37,230  -->  00:03:39,270
you're going to need to retain the evidence.
100

100

00:03:39,270  -->  00:03:41,550
This is important because all of that evidence
101

101

00:03:41,550  -->  00:03:44,340
is going to have to be retained until all the legal actions
102

102

00:03:44,340  -->  00:03:47,280
including any appeals, have been completed.
103

103

00:03:47,280  -->  00:03:50,100
When you're dealing with cases where prosecution is desired,
104

104

00:03:50,100  -->  00:03:51,660
you can expect that you're going to have to retain
105

105

00:03:51,660  -->  00:03:54,270
that evidence for several years.
106

106

00:03:54,270  -->  00:03:55,890
This is a big deal.
107

107

00:03:55,890  -->  00:03:57,510
Now, why is it a big deal?
108

108

00:03:57,510  -->  00:04:01,080
Well, because that retention is going to cost you money.
109

109

00:04:01,080  -->  00:04:02,730
It's going to cost you resources,
110

110

00:04:02,730  -->  00:04:04,380
and so you have to be able to weigh that
111

111

00:04:04,380  -->  00:04:06,450
as part of your evidence retention.
112

112

00:04:06,450  -->  00:04:08,400
Now, every organization has the ability
113

113

00:04:08,400  -->  00:04:11,550
to set its own period in their data retention policy.
114

114

00:04:11,550  -->  00:04:13,590
And as you think about your data retention,
115

115

00:04:13,590  -->  00:04:16,050
you are free to set it any way you want,
116

116

00:04:16,050  -->  00:04:18,720
but in some cases, your organization will have
117

117

00:04:18,720  -->  00:04:21,900
additional requirements that are set forth by law.
118

118

00:04:21,900  -->  00:04:24,570
For example, if you're a publicly traded company,
119

119

00:04:24,570  -->  00:04:26,100
you might fall into the requirements
120

120

00:04:26,100  -->  00:04:28,890
of Sarbanes Oxley here in the United States.
121

121

00:04:28,890  -->  00:04:31,080
Now, in general most organizations
122

122

00:04:31,080  -->  00:04:34,290
will set a minimum retention period of at least six months,
123

123

00:04:34,290  -->  00:04:36,090
but some of these other laws and regulations
124

124

00:04:36,090  -->  00:04:39,090
may require you to hold that data for several years
125

125

00:04:39,090  -->  00:04:40,980
as part of that law and regulation.
126

126

00:04:40,980  -->  00:04:43,320
So make sure you're dealing with your legal team as well
127

127

00:04:43,320  -->  00:04:46,410
when you're developing your data retention policies.
128

128

00:04:46,410  -->  00:04:48,780
Now, another factor you have to consider is cost.
129

129

00:04:48,780  -->  00:04:52,080
I said it costs a lot of money to retain this evidence.
130

130

00:04:52,080  -->  00:04:53,790
Now, it would be great for us to be able to retain
131

131

00:04:53,790  -->  00:04:57,030
all the data and evidence for an unlimited duration of time,
132

132

00:04:57,030  -->  00:04:59,490
but that is simply not practical.
133

133

00:04:59,490  -->  00:05:00,900
The more stuff you retain.
134

134

00:05:00,900  -->  00:05:03,060
the more hard drive space or server space
135

135

00:05:03,060  -->  00:05:05,460
or cloud storage space you are going to need,
136

136

00:05:05,460  -->  00:05:06,630
and all of that represents
137

137

00:05:06,630  -->  00:05:08,970
additional cost to your organization.
138

138

00:05:08,970  -->  00:05:10,140
Thankfully, the price
139

139

00:05:10,140  -->  00:05:13,290
of storage continues to decrease exponentially over time.
140

140

00:05:13,290  -->  00:05:16,800
For example, my company uses an online backup solution
141

141

00:05:16,800  -->  00:05:18,600
that provides us with unlimited storage
142

142

00:05:18,600  -->  00:05:20,370
for a fixed annual fee.
143

143

00:05:20,370  -->  00:05:22,170
Using an offsite storage solution like this
144

144

00:05:22,170  -->  00:05:24,660
can be a great option for you to consider.
145

145

00:05:24,660  -->  00:05:26,280
The other concern with cost occurs
146

146

00:05:26,280  -->  00:05:28,350
when some of your hardware has to be collected
147

147

00:05:28,350  -->  00:05:30,450
as evidence during a response.
148

148

00:05:30,450  -->  00:05:32,130
For example, if one of your servers
149

149

00:05:32,130  -->  00:05:35,040
is collected as evidence for a case headed to prosecution,
150

150

00:05:35,040  -->  00:05:37,590
you may not get it back for two or three years.
151

151

00:05:37,590  -->  00:05:40,080
In this case, you're going to have to replace that server
152

152

00:05:40,080  -->  00:05:42,300
in order to fully recover your operations,
153

153

00:05:42,300  -->  00:05:44,820
and this could cost you tens of thousands of dollars
154

154

00:05:44,820  -->  00:05:46,380
depending on the scale of your incident.
155

155

00:05:46,380  -->  00:05:48,450
And therefore, it's important for you to consider
156

156

00:05:48,450  -->  00:05:50,760
that your organization has to address this
157

157

00:05:50,760  -->  00:05:53,250
in their budgeting for a potential incident response
158

158

00:05:53,250  -->  00:05:54,083
in the future.
