1
1

00:00:00,240  -->  00:00:02,150
<v ->Plans and procedures.</v>
2

2

00:00:02,150  -->  00:00:03,750
In this video, we're going to discuss
3

3

00:00:03,750  -->  00:00:05,170
the various plans and procedures
4

4

00:00:05,170  -->  00:00:07,950
that are used in the management of your enterprise networks.
5

5

00:00:07,950  -->  00:00:10,830
This includes change management, incident response plans,
6

6

00:00:10,830  -->  00:00:13,690
disaster recovery plans, business continuity plans,
7

7

00:00:13,690  -->  00:00:14,950
system life cycle,
8

8

00:00:14,950  -->  00:00:17,130
and standard operating procedures.
9

9

00:00:17,130  -->  00:00:19,780
First, let's discuss change management.
10

10

00:00:19,780  -->  00:00:21,320
Change management is a structured way
11

11

00:00:21,320  -->  00:00:23,190
of changing the state of a computer system,
12

12

00:00:23,190  -->  00:00:25,130
network, or IT procedure.
13

13

00:00:25,130  -->  00:00:27,650
Change management is used to make changes to the secure
14

14

00:00:27,650  -->  00:00:31,090
and known good baseline that exists in our network devices.
15

15

00:00:31,090  -->  00:00:32,510
A good change management policy
16

16

00:00:32,510  -->  00:00:34,590
is going to be designed to make sure that all the risks
17

17

00:00:34,590  -->  00:00:36,980
are considered prior to implementing a change
18

18

00:00:36,980  -->  00:00:38,850
to your systems or networks.
19

19

00:00:38,850  -->  00:00:40,920
This ensures that our services remain stable,
20

20

00:00:40,920  -->  00:00:42,510
reliable, and predictable,
21

21

00:00:42,510  -->  00:00:45,570
even in the face of rapidly changing business requirements.
22

22

00:00:45,570  -->  00:00:48,270
Essentially change management is a coordinated system
23

23

00:00:48,270  -->  00:00:49,440
to account for any upgrades,
24

24

00:00:49,440  -->  00:00:52,000
installations or network outages and repairs.
25

25

00:00:52,000  -->  00:00:54,450
For example, let's assume that you need to upgrade a router
26

26

00:00:54,450  -->  00:00:55,460
or switch in your network,
27

27

00:00:55,460  -->  00:00:58,660
but you don't want to cause a bunch of unnecessary downtime.
28

28

00:00:58,660  -->  00:01:00,310
Well, with change management,
29

29

00:01:00,310  -->  00:01:02,840
we can ensure that all of our actions are pre coordinated
30

30

00:01:02,840  -->  00:01:04,920
and approved by the relevant stakeholders
31

31

00:01:04,920  -->  00:01:07,410
prior to us implementing a firmware upgrade.
32

32

00:01:07,410  -->  00:01:09,440
After all, if I simply ran a firmware upgrade
33

33

00:01:09,440  -->  00:01:10,630
in the middle of the workday,
34

34

00:01:10,630  -->  00:01:13,610
I could cause a lot of unnecessary downtime for my end users
35

35

00:01:13,610  -->  00:01:15,220
because they're relying on those devices
36

36

00:01:15,220  -->  00:01:16,750
for their network connectivity.
37

37

00:01:16,750  -->  00:01:18,650
This is because during a firmware upgrade,
38

38

00:01:18,650  -->  00:01:20,860
that router switch is going to be taken offline
39

39

00:01:20,860  -->  00:01:23,370
and it won't provide services to our end users
40

40

00:01:23,370  -->  00:01:25,510
until the firmware has been properly flashed,
41

41

00:01:25,510  -->  00:01:27,640
and then the configurations are reloaded.
42

42

00:01:27,640  -->  00:01:30,810
Therefore we need to instead coordinate the firmware upgrade
43

43

00:01:30,810  -->  00:01:33,700
for the right time so that it would be the least impactful
44

44

00:01:33,700  -->  00:01:35,650
against our business operations.
45

45

00:01:35,650  -->  00:01:38,140
For example, at most of my organizations,
46

46

00:01:38,140  -->  00:01:40,470
we use the period between midnight and 4:00 am
47

47

00:01:40,470  -->  00:01:41,810
to do our upgrades because
48

48

00:01:41,810  -->  00:01:43,500
relatively few people are online
49

49

00:01:43,500  -->  00:01:45,390
and working during those hours.
50

50

00:01:45,390  -->  00:01:47,640
As you move through your change management process,
51

51

00:01:47,640  -->  00:01:48,670
you're going to need to ensure
52

52

00:01:48,670  -->  00:01:51,470
that the upgrade is being planned, approved as a change,
53

53

00:01:51,470  -->  00:01:53,920
the relevant documentation diagrams are being updated
54

54

00:01:53,920  -->  00:01:56,710
and our network documentation remains current
55

55

00:01:56,710  -->  00:01:58,820
after we finish doing the change.
56

56

00:01:58,820  -->  00:02:01,180
Next, we have incident response plans.
57

57

00:02:01,180  -->  00:02:03,820
An incident response plan contains a set of instructions
58

58

00:02:03,820  -->  00:02:05,620
to help our network and system administrators
59

59

00:02:05,620  -->  00:02:07,770
detect, respond to, and recover
60

60

00:02:07,770  -->  00:02:09,640
from network security incidents.
61

61

00:02:09,640  -->  00:02:10,570
These types of plans
62

62

00:02:10,570  -->  00:02:13,220
are going to address issues like cyber crime, data loss,
63

63

00:02:13,220  -->  00:02:16,200
and service outages that could threaten our daily work.
64

64

00:02:16,200  -->  00:02:17,850
Basically what we're doing here
65

65

00:02:17,850  -->  00:02:19,310
is decide what we're going to do
66

66

00:02:19,310  -->  00:02:20,930
if there's a security violation
67

67

00:02:20,930  -->  00:02:23,160
and what are our response actions going to be?
68

68

00:02:23,160  -->  00:02:25,390
Are we going to take the device off the network and wipe it
69

69

00:02:25,390  -->  00:02:26,600
and then put it back on?
70

70

00:02:26,600  -->  00:02:27,990
Are you going to handle it in-house?
71

71

00:02:27,990  -->  00:02:29,600
Or are you going to fire an employee over it?
72

72

00:02:29,600  -->  00:02:31,100
Are you going to call the police?
73

73

00:02:31,100  -->  00:02:32,520
What is your plan going to be?
74

74

00:02:32,520  -->  00:02:34,260
How are you going to respond?
75

75

00:02:34,260  -->  00:02:36,270
Now, I don't have these answers for you
76

76

00:02:36,270  -->  00:02:37,570
because all this is going to depend
77

77

00:02:37,570  -->  00:02:39,840
on your organization's incident response plan
78

78

00:02:39,840  -->  00:02:41,300
that you need to create.
79

79

00:02:41,300  -->  00:02:43,200
When it comes to an incident response plan,
80

80

00:02:43,200  -->  00:02:45,950
you need to cover six main steps or phases.
81

81

00:02:45,950  -->  00:02:47,540
First; preparation,
82

82

00:02:47,540  -->  00:02:49,420
second; identification,
83

83

00:02:49,420  -->  00:02:51,060
third; containment,
84

84

00:02:51,060  -->  00:02:52,840
fourth; eradication,
85

85

00:02:52,840  -->  00:02:54,310
fifth; recovery,
86

86

00:02:54,310  -->  00:02:56,350
and sixth; lessons learned.
87

87

00:02:56,350  -->  00:02:59,140
Also, if you're intending to prosecute a computer crime
88

88

00:02:59,140  -->  00:03:01,260
in conjunction with your incident response,
89

89

00:03:01,260  -->  00:03:02,610
that's extremely important
90

90

00:03:02,610  -->  00:03:04,160
that you maintain the chain of custody
91

91

00:03:04,160  -->  00:03:07,420
over all the data and all the information being collected.
92

92

00:03:07,420  -->  00:03:10,090
Next, we have disaster recovery plans.
93

93

00:03:10,090  -->  00:03:11,340
A disaster recovery plan
94

94

00:03:11,340  -->  00:03:13,230
is a documented structured approach
95

95

00:03:13,230  -->  00:03:14,960
that documents how an organization
96

96

00:03:14,960  -->  00:03:18,120
can quickly resume their work after an unplanned incident.
97

97

00:03:18,120  -->  00:03:19,500
Now, these unplanned incidents
98

98

00:03:19,500  -->  00:03:21,440
can be things like natural disasters,
99

99

00:03:21,440  -->  00:03:24,850
power outages, cyber attacks, or other disruptive events.
100

100

00:03:24,850  -->  00:03:26,450
Now a disaster recovery plan
101

101

00:03:26,450  -->  00:03:28,560
will outline your processes and procedures
102

102

00:03:28,560  -->  00:03:29,750
for shifting your operations
103

103

00:03:29,750  -->  00:03:31,530
from your main headquarter facilities
104

104

00:03:31,530  -->  00:03:33,200
to your disaster recovery sites,
105

105

00:03:33,200  -->  00:03:35,850
such as a hot site, a warm site, a cold site,
106

106

00:03:35,850  -->  00:03:37,430
or a cloud site.
107

107

00:03:37,430  -->  00:03:39,320
Now remember a disaster recovery plan
108

108

00:03:39,320  -->  00:03:41,060
is focused on business interruptions
109

109

00:03:41,060  -->  00:03:42,800
that are caused by a disaster,
110

110

00:03:42,800  -->  00:03:44,580
but these aren't going to include things
111

111

00:03:44,580  -->  00:03:46,760
like everyday operational challenges.
112

112

00:03:46,760  -->  00:03:48,410
For those types of challenges,
113

113

00:03:48,410  -->  00:03:50,780
we instead need to look at a different type of plan
114

114

00:03:50,780  -->  00:03:54,150
known as a business continuity plan or BCP.
115

115

00:03:54,150  -->  00:03:55,660
Now a business continuity plan
116

116

00:03:55,660  -->  00:03:57,740
is a document that outlines how a business
117

117

00:03:57,740  -->  00:03:59,100
is going to continue operating
118

118

00:03:59,100  -->  00:04:01,480
during an unplanned disruption in service.
119

119

00:04:01,480  -->  00:04:04,040
Now, a business continuity plan is more comprehensive
120

120

00:04:04,040  -->  00:04:05,540
than a disaster recovery plan,
121

121

00:04:05,540  -->  00:04:06,850
and it contains contingencies
122

122

00:04:06,850  -->  00:04:08,940
for lots of different business processes,
123

123

00:04:08,940  -->  00:04:11,730
your assets, your human capital and business partners,
124

124

00:04:11,730  -->  00:04:13,360
and essentially every other thing
125

125

00:04:13,360  -->  00:04:16,470
and aspect that may be affected in your business.
126

126

00:04:16,470  -->  00:04:18,840
Now, when you're dealing with a disaster recovery plan,
127

127

00:04:18,840  -->  00:04:21,760
we're focused mainly on your technology and your facilities,
128

128

00:04:21,760  -->  00:04:24,700
but a business continuity plan is much more in-depth
129

129

00:04:24,700  -->  00:04:26,160
as it looks at how you're going to continue
130

130

00:04:26,160  -->  00:04:28,010
all of your business operations.
131

131

00:04:28,010  -->  00:04:31,040
In general, a disaster recovery plan or DRP
132

132

00:04:31,040  -->  00:04:31,950
is going to be referenced
133

133

00:04:31,950  -->  00:04:34,900
as part of your business continuity plan or BCP,
134

134

00:04:34,900  -->  00:04:37,070
and the two will work very closely together
135

135

00:04:37,070  -->  00:04:38,810
when you have a real disaster,
136

136

00:04:38,810  -->  00:04:41,740
like a hurricane, a fire, or a flood that occurs.
137

137

00:04:41,740  -->  00:04:44,840
Next, we need to consider the system life cycle plans.
138

138

00:04:44,840  -->  00:04:46,200
System life cycle plans
139

139

00:04:46,200  -->  00:04:48,080
also known as the life cycle planning
140

140

00:04:48,080  -->  00:04:50,200
is going to describe the approach that you're going to use
141

141

00:04:50,200  -->  00:04:51,360
to maintaining an asset
142

142

00:04:51,360  -->  00:04:53,730
from its creation to its disposal.
143

143

00:04:53,730  -->  00:04:55,720
Now, in the information technology world,
144

144

00:04:55,720  -->  00:04:57,960
we normally have a five phase life cycle
145

145

00:04:57,960  -->  00:05:00,160
that's used for all of our systems and networks.
146

146

00:05:00,160  -->  00:05:02,240
This includes planning, design,
147

147

00:05:02,240  -->  00:05:05,070
transition, operations, and retirement.
148

148

00:05:05,070  -->  00:05:06,700
Phase one is planning.
149

149

00:05:06,700  -->  00:05:09,100
Planning involves the planning and requirement analysis
150

150

00:05:09,100  -->  00:05:10,150
for a given system,
151

151

00:05:10,150  -->  00:05:11,960
including outlining the architecture
152

152

00:05:11,960  -->  00:05:14,000
and identifying the possible risks.
153

153

00:05:14,000  -->  00:05:15,410
Phase two is design.
154

154

00:05:15,410  -->  00:05:16,900
Design is going to involve the outlining
155

155

00:05:16,900  -->  00:05:18,130
of the new system or network,
156

156

00:05:18,130  -->  00:05:20,100
including what interconnections there's going to be,
157

157

00:05:20,100  -->  00:05:21,460
what technologies will be used,
158

158

00:05:21,460  -->  00:05:23,010
and how it should be implemented.
159

159

00:05:23,010  -->  00:05:25,430
This can even include some building of the new system
160

160

00:05:25,430  -->  00:05:27,750
or even a prototype to validate the architecture
161

161

00:05:27,750  -->  00:05:29,250
that we want to use.
162

162

00:05:29,250  -->  00:05:30,940
Phase three is transition.
163

163

00:05:30,940  -->  00:05:33,130
Transition involves the actual implementation,
164

164

00:05:33,130  -->  00:05:34,990
which could involve coding some new software,
165

165

00:05:34,990  -->  00:05:36,070
installing the systems,
166

166

00:05:36,070  -->  00:05:38,990
or cabling up the networks and their configurations.
167

167

00:05:38,990  -->  00:05:41,530
All of this is going to be a part of taking this asset
168

168

00:05:41,530  -->  00:05:44,010
and moving it from a prototype or an initial build
169

169

00:05:44,010  -->  00:05:46,500
into something that's ready for full production and use,
170

170

00:05:46,500  -->  00:05:48,140
that's why we call it transition.
171

171

00:05:48,140  -->  00:05:50,920
We're transitioning it into production and use.
172

172

00:05:50,920  -->  00:05:52,830
Phase four is operations.
173

173

00:05:52,830  -->  00:05:54,680
Operations is where the system or network
174

174

00:05:54,680  -->  00:05:58,120
is now going to be used on a daily basis to do productive work.
175

175

00:05:58,120  -->  00:06:01,070
In general, about 70% of a system's lifecycle
176

176

00:06:01,070  -->  00:06:03,410
is going to be spent during operations.
177

177

00:06:03,410  -->  00:06:04,640
Now, operations includes
178

178

00:06:04,640  -->  00:06:06,480
things like the daily running of the asset,
179

179

00:06:06,480  -->  00:06:08,380
as well as updating it, patching it,
180

180

00:06:08,380  -->  00:06:11,190
fixing any issues that may occur and things like that.
181

181

00:06:11,190  -->  00:06:13,700
This is often referred to as operations and support
182

182

00:06:13,700  -->  00:06:16,050
because we're going to conduct our break fix actions
183

183

00:06:16,050  -->  00:06:18,680
during this portion of the asset's life cycle.
184

184

00:06:18,680  -->  00:06:20,710
Our fifth phase is retirement.
185

185

00:06:20,710  -->  00:06:22,650
Retirement is the end of the life cycle
186

186

00:06:22,650  -->  00:06:24,240
and it occurs when the system or network
187

187

00:06:24,240  -->  00:06:26,800
no longer has any useful life remaining in it.
188

188

00:06:26,800  -->  00:06:27,750
At this point,
189

189

00:06:27,750  -->  00:06:30,410
a single device or your entire system or network
190

190

00:06:30,410  -->  00:06:32,820
could be retired and the assets will be disposed of
191

191

00:06:32,820  -->  00:06:34,430
as part of this retirement.
192

192

00:06:34,430  -->  00:06:36,350
For example, if you had a network switch
193

193

00:06:36,350  -->  00:06:38,350
that's been used for the last five years,
194

194

00:06:38,350  -->  00:06:41,070
it's probably reaching the end of its useful lifespan.
195

195

00:06:41,070  -->  00:06:43,590
So it needs to be replaced with a newer model,
196

196

00:06:43,590  -->  00:06:45,810
and then we're going to retire that old switch.
197

197

00:06:45,810  -->  00:06:47,210
Before we throw it away though,
198

198

00:06:47,210  -->  00:06:49,200
it's important for us to think about that device
199

199

00:06:49,200  -->  00:06:50,440
and how we're going to sanitize it
200

200

00:06:50,440  -->  00:06:53,480
or clear it of any configurations or sensitive information
201

201

00:06:53,480  -->  00:06:56,580
using our proper asset disposal procedures too.
202

202

00:06:56,580  -->  00:06:59,270
Next, we have standard operating procedures.
203

203

00:06:59,270  -->  00:07:00,840
Everything we spoke about so far
204

204

00:07:00,840  -->  00:07:03,250
has been at a higher and more generic level,
205

205

00:07:03,250  -->  00:07:06,130
but a standard operating procedure or SOP
206

206

00:07:06,130  -->  00:07:08,090
is a set of step-by-step instructions
207

207

00:07:08,090  -->  00:07:10,020
that are compiled by an organization
208

208

00:07:10,020  -->  00:07:12,920
to help its employees carry out their routine operations.
209

209

00:07:12,920  -->  00:07:16,010
Standard operating procedures aim to achieve efficiency,
210

210

00:07:16,010  -->  00:07:19,150
quality output, and a uniformity of performance
211

211

00:07:19,150  -->  00:07:21,240
while they reduce misconfigurations
212

212

00:07:21,240  -->  00:07:23,420
and a failure to comply with regulations.
213

213

00:07:23,420  -->  00:07:25,410
For example, our disaster recovery plan
214

214

00:07:25,410  -->  00:07:27,050
might say that within 48 hours
215

215

00:07:27,050  -->  00:07:29,000
of a named hurricane reaching our city,
216

216

00:07:29,000  -->  00:07:31,020
we need to ensure that all of our diesel generators
217

217

00:07:31,020  -->  00:07:32,220
have been refueled.
218

218

00:07:32,220  -->  00:07:34,160
Now, this is a single one-line statement
219

219

00:07:34,160  -->  00:07:36,570
from a disaster recovery plan or DRP,
220

220

00:07:36,570  -->  00:07:40,130
but that statement doesn't tell you how to actually do it.
221

221

00:07:40,130  -->  00:07:42,720
Instead, you'd pull out the standard operating procedure
222

222

00:07:42,720  -->  00:07:44,480
named fueling the generators,
223

223

00:07:44,480  -->  00:07:46,760
and this would tell you how to perform the operation.
224

224

00:07:46,760  -->  00:07:48,890
So if I was told to refuel the generators,
225

225

00:07:48,890  -->  00:07:51,800
I could pull out this SOP and follow it step-by-step,
226

226

00:07:51,800  -->  00:07:54,620
step one; call the fuel company and schedule a delivery,
227

227

00:07:54,620  -->  00:07:56,400
step two; turn off the generators
228

228

00:07:56,400  -->  00:07:57,680
and open the storage tanks,
229

229

00:07:57,680  -->  00:08:00,150
step three; put the diesel into the storage tanks.
230

230

00:08:00,150  -->  00:08:01,630
You get the idea here, right?
231

231

00:08:01,630  -->  00:08:04,450
Now, there might be 5 or 10 or 20 steps to this procedures
232

232

00:08:04,450  -->  00:08:05,870
as part of this SOP,
233

233

00:08:05,870  -->  00:08:07,680
but in a disaster recovery plan,
234

234

00:08:07,680  -->  00:08:09,280
it's just one line that says,
235

235

00:08:09,280  -->  00:08:12,480
you need to do this thing known as refueling the generators.
236

236

00:08:12,480  -->  00:08:14,690
So remember when it comes to managing your networks,
237

237

00:08:14,690  -->  00:08:16,540
there are lots of different plans and procedures
238

238

00:08:16,540  -->  00:08:17,900
that you may come across.
239

239

00:08:17,900  -->  00:08:19,450
We just covered a few in this lesson
240

240

00:08:19,450  -->  00:08:21,380
that you may get asked about on the exam,
241

241

00:08:21,380  -->  00:08:22,320
but in the real world,
242

242

00:08:22,320  -->  00:08:24,090
there are many others too.
243

243

00:08:24,090  -->  00:08:25,500
For the exam, remember,
244

244

00:08:25,500  -->  00:08:28,140
we have change management, incident response plans,
245

245

00:08:28,140  -->  00:08:30,880
disaster recovery plans, business continuity plans,
246

246

00:08:30,880  -->  00:08:32,110
system life cycles,
247

247

00:08:32,110  -->  00:08:33,830
and standard operating procedures,
248

248

00:08:33,830  -->  00:08:35,380
to help us manage our networks.
249

249

00:08:36,381  -->  00:08:38,744
(upbeat music)
