1
00:00:00,420 --> 00:00:02,250
In this lesson, we're going to discuss

2
00:00:02,250 --> 00:00:05,700
the incident response process and its different phases.

3
00:00:05,700 --> 00:00:08,370
First, let's define what an incident is.

4
00:00:08,370 --> 00:00:11,040
An incident is an act of violating an explicit

5
00:00:11,040 --> 00:00:12,840
or implied security policy.

6
00:00:12,840 --> 00:00:14,220
There are lots of different things

7
00:00:14,220 --> 00:00:16,200
that could be categorized as an incident.

8
00:00:16,200 --> 00:00:17,820
For instance, if I stole your password

9
00:00:17,820 --> 00:00:19,710
and tried logging into computer issue,

10
00:00:19,710 --> 00:00:21,210
that would be classified as an incident

11
00:00:21,210 --> 00:00:24,030
because it goes against the organization's security policy

12
00:00:24,030 --> 00:00:27,000
that state and employee should only log into their account

13
00:00:27,000 --> 00:00:29,250
using their own account credentials.

14
00:00:29,250 --> 00:00:30,720
Similarly, if an attacker wanted

15
00:00:30,720 --> 00:00:32,460
to install malware on the system,

16
00:00:32,460 --> 00:00:34,320
that would also be considered an incident

17
00:00:34,320 --> 00:00:36,480
because it breaks the security policies inside

18
00:00:36,480 --> 00:00:38,190
of your organization.

19
00:00:38,190 --> 00:00:39,630
There are lots of different things

20
00:00:39,630 --> 00:00:41,460
that could be categorized as an incident,

21
00:00:41,460 --> 00:00:44,310
but in this lesson we're going to be focused on what steps

22
00:00:44,310 --> 00:00:46,200
or phases will be conducted in response

23
00:00:46,200 --> 00:00:49,110
to any generic incident that should occur.

24
00:00:49,110 --> 00:00:51,030
There are different ways to define the phases

25
00:00:51,030 --> 00:00:52,260
of an incident response,

26
00:00:52,260 --> 00:00:55,380
but one of the most commonly used is produced by NIST,

27
00:00:55,380 --> 00:00:58,110
the National Institute of Standards and Technology.

28
00:00:58,110 --> 00:01:01,470
In the NIST Computer Security Incident Handling Guide,

29
00:01:01,470 --> 00:01:04,500
special publication number 800-61,

30
00:01:04,500 --> 00:01:07,770
NIST defines a four phase incident response process,

31
00:01:07,770 --> 00:01:11,130
which includes preparation, detection and analysis,

32
00:01:11,130 --> 00:01:13,470
containment, eradication and recovery,

33
00:01:13,470 --> 00:01:16,050
and post-incident activity.

34
00:01:16,050 --> 00:01:18,510
Often though, when conducting an incident response,

35
00:01:18,510 --> 00:01:21,750
you will start an incident, move through preparation,

36
00:01:21,750 --> 00:01:23,670
then go into detection and analysis.

37
00:01:23,670 --> 00:01:26,340
Then when you find something more suspicious,

38
00:01:26,340 --> 00:01:29,130
you might move into containment, eradication and recovery.

39
00:01:29,130 --> 00:01:31,410
Just when you think you have gotten everything handled,

40
00:01:31,410 --> 00:01:32,880
you find something else suspicious

41
00:01:32,880 --> 00:01:35,910
and have to move backwards to detection and analysis again.

42
00:01:35,910 --> 00:01:38,580
And so, you can see that this isn't always strictly

43
00:01:38,580 --> 00:01:40,320
a linear process, but instead,

44
00:01:40,320 --> 00:01:42,840
you'll often loop around in the four phases.

45
00:01:42,840 --> 00:01:44,610
Inside each of these four phases,

46
00:01:44,610 --> 00:01:47,250
there are different actions that we're going to take,

47
00:01:47,250 --> 00:01:49,890
and these are all based on different procedures.

48
00:01:49,890 --> 00:01:52,080
When we talk about incident response procedures,

49
00:01:52,080 --> 00:01:53,820
these are procedures and guidelines

50
00:01:53,820 --> 00:01:56,010
that are covering the appropriate priorities,

51
00:01:56,010 --> 00:01:57,480
actions and responsibilities,

52
00:01:57,480 --> 00:02:00,300
that should occur in the event of a security incident.

53
00:02:00,300 --> 00:02:01,680
As I said earlier,

54
00:02:01,680 --> 00:02:04,890
there are many different incident response processes used

55
00:02:04,890 --> 00:02:06,480
in the cybersecurity industry,

56
00:02:06,480 --> 00:02:09,330
and the NIST guideline is by far the most common one.

57
00:02:09,330 --> 00:02:12,990
But for the exam, CompTIA actually breaks down detection

58
00:02:12,990 --> 00:02:15,480
and analysis into two different phases.

59
00:02:15,480 --> 00:02:18,150
And the containment, eradication, and recovery phase,

60
00:02:18,150 --> 00:02:19,980
from this into three separate phases,

61
00:02:19,980 --> 00:02:22,410
creating a seven phase model.

62
00:02:22,410 --> 00:02:24,960
During the exam, if you get asked about the phases

63
00:02:24,960 --> 00:02:26,400
of the incident response,

64
00:02:26,400 --> 00:02:29,430
you should use the seven phase model covered in this lesson.

65
00:02:29,430 --> 00:02:32,970
The seven phases of the CompTIA incident response cycle are,

66
00:02:32,970 --> 00:02:37,410
preparation, detection, analysis, containment, eradication,

67
00:02:37,410 --> 00:02:41,340
recovery, and post-incident activity or lesson learned.

68
00:02:41,340 --> 00:02:43,440
Let's go ahead and look at these seven phases

69
00:02:43,440 --> 00:02:45,330
in a little bit more detail.

70
00:02:45,330 --> 00:02:46,950
First, we have preparation.

71
00:02:46,950 --> 00:02:49,860
Preparation is a phase where cybersecurity practitioners try

72
00:02:49,860 --> 00:02:51,630
to make the system resilient to attack

73
00:02:51,630 --> 00:02:53,790
by hardening their systems and networks.

74
00:02:53,790 --> 00:02:55,440
This is also the phase where policies

75
00:02:55,440 --> 00:02:56,790
and procedures are written.

76
00:02:56,790 --> 00:02:58,920
And your communication plan is created

77
00:02:58,920 --> 00:03:02,250
to set up encrypted out-of-band communication paths.

78
00:03:02,250 --> 00:03:05,430
The preparation phase is focused on doing everything needed

79
00:03:05,430 --> 00:03:08,580
to get ready for some kind of future incident to occur.

80
00:03:08,580 --> 00:03:11,760
During the preparation phase, you'll also conduct training,

81
00:03:11,760 --> 00:03:13,830
testing, and exercising of your staff

82
00:03:13,830 --> 00:03:15,210
with simulated incidents,

83
00:03:15,210 --> 00:03:18,150
as well as the creation of incident response kits.

84
00:03:18,150 --> 00:03:19,800
Second, we have detection.

85
00:03:19,800 --> 00:03:22,380
The detection phase is really focused on determining

86
00:03:22,380 --> 00:03:24,690
whether a security incident has occurred.

87
00:03:24,690 --> 00:03:27,480
Your organization's cybersecurity and triage analysts

88
00:03:27,480 --> 00:03:29,430
play a crucial role in categorizing

89
00:03:29,430 --> 00:03:32,430
and assessing the potential incident severity.

90
00:03:32,430 --> 00:03:35,010
Once an incident is categorized and triaged,

91
00:03:35,010 --> 00:03:37,320
we can then move into our third phase.

92
00:03:37,320 --> 00:03:39,600
Third, we have analysis.

93
00:03:39,600 --> 00:03:41,220
Analysis occurs when an incident

94
00:03:41,220 --> 00:03:43,440
is thoroughly examined and evaluated.

95
00:03:43,440 --> 00:03:46,050
Analysts work diligently to understand the scope

96
00:03:46,050 --> 00:03:47,700
and impact of the incident

97
00:03:47,700 --> 00:03:50,100
and to provide valuable insights into the nature

98
00:03:50,100 --> 00:03:51,690
and potential consequences.

99
00:03:51,690 --> 00:03:54,450
Subsequently, relevant stakeholders are notified,

100
00:03:54,450 --> 00:03:56,250
containment phases is initiated,

101
00:03:56,250 --> 00:03:57,390
and the implementation

102
00:03:57,390 --> 00:04:00,510
of the necessary initial response action is completed.

103
00:04:00,510 --> 00:04:02,250
Fourth, we have containment.

104
00:04:02,250 --> 00:04:04,110
Containment is used to limit the scope

105
00:04:04,110 --> 00:04:06,510
and magnitude of the incident by securing data

106
00:04:06,510 --> 00:04:09,000
and minimizing the impact on business operations

107
00:04:09,000 --> 00:04:11,970
and your organization's customer and business partners.

108
00:04:11,970 --> 00:04:14,460
For example, if a piece of malware was detected

109
00:04:14,460 --> 00:04:17,310
on a given system in the detection and analysis phase,

110
00:04:17,310 --> 00:04:20,370
our goal in containment is to prevent that piece of malware

111
00:04:20,370 --> 00:04:22,980
from spreading to other systems on our network.

112
00:04:22,980 --> 00:04:25,650
In this case, we might disconnect the infected client

113
00:04:25,650 --> 00:04:27,420
from the network and lock out the user

114
00:04:27,420 --> 00:04:28,650
from using the workstation

115
00:04:28,650 --> 00:04:31,470
until we can clean the effective system.

116
00:04:31,470 --> 00:04:33,060
Fifth, we have eradication.

117
00:04:33,060 --> 00:04:35,550
Eradication begins once the incident is contained

118
00:04:35,550 --> 00:04:37,830
and it's focused on removing the malicious activity

119
00:04:37,830 --> 00:04:39,660
from a given system or network.

120
00:04:39,660 --> 00:04:42,180
For example, using a previous malware example,

121
00:04:42,180 --> 00:04:43,890
if we have stopped it from spreading

122
00:04:43,890 --> 00:04:46,050
by disconnecting the client from the network,

123
00:04:46,050 --> 00:04:48,930
we can now remove the malware from that system,

124
00:04:48,930 --> 00:04:52,080
or reinstall a known good image to a client

125
00:04:52,080 --> 00:04:54,780
to eradicate that malware fully from the system.

126
00:04:54,780 --> 00:04:56,580
Sixth, we have recovery.

127
00:04:56,580 --> 00:04:59,220
Recovery is focused on restoring the effective system

128
00:04:59,220 --> 00:05:01,620
and services to their normal secured state.

129
00:05:01,620 --> 00:05:04,050
Recovery often involves restoring a system

130
00:05:04,050 --> 00:05:07,140
from a known good backup, installing security patches,

131
00:05:07,140 --> 00:05:09,360
or implementing configuration updates,

132
00:05:09,360 --> 00:05:11,640
to ensure that any vulnerabilities exploited

133
00:05:11,640 --> 00:05:13,440
during the incident have been fully

134
00:05:13,440 --> 00:05:15,930
and appropriately remediated.

135
00:05:15,930 --> 00:05:18,660
Additionally, your organization's recovery procedures

136
00:05:18,660 --> 00:05:20,010
may include monitoring systems

137
00:05:20,010 --> 00:05:21,660
for any signs of lingering threats

138
00:05:21,660 --> 00:05:24,240
to ensure a smooth return to normal operations.

139
00:05:24,240 --> 00:05:27,210
The ultimate goal is to minimize the impact of the incident

140
00:05:27,210 --> 00:05:28,800
and ensure the organization can resume

141
00:05:28,800 --> 00:05:31,200
its regular activities with increased resilience

142
00:05:31,200 --> 00:05:32,490
against future threats.

143
00:05:32,490 --> 00:05:36,360
Seventh, we have post-incident activity or lessons learned.

144
00:05:36,360 --> 00:05:38,850
Post-incident activity occurs after the system

145
00:05:38,850 --> 00:05:42,150
has been contained and malicious activity was eradicated

146
00:05:42,150 --> 00:05:44,010
and the system is fully recovered

147
00:05:44,010 --> 00:05:45,750
and restored to operations.

148
00:05:45,750 --> 00:05:48,240
At this point, we will spend some time analyzing

149
00:05:48,240 --> 00:05:49,800
the incident and the response

150
00:05:49,800 --> 00:05:52,560
to identify whether the procedures and systems

151
00:05:52,560 --> 00:05:54,120
that we had worked properly,

152
00:05:54,120 --> 00:05:57,000
or is there anything else we can do better next time.

153
00:05:57,000 --> 00:05:58,740
During the post-incident activity,

154
00:05:58,740 --> 00:06:00,690
there are three major actions that occur.

155
00:06:00,690 --> 00:06:03,150
The root cause analysis, the lessons learn process,

156
00:06:03,150 --> 00:06:04,860
and the after-action report.

157
00:06:04,860 --> 00:06:07,290
The root cause analysis is a systematic approach

158
00:06:07,290 --> 00:06:09,570
to identify the initial source of the incident

159
00:06:09,570 --> 00:06:12,150
and how to prevent it from occurring again.

160
00:06:12,150 --> 00:06:15,540
This analysis usually occurs using a four step process.

161
00:06:15,540 --> 00:06:18,660
One, define/scope the incident.

162
00:06:18,660 --> 00:06:21,180
Two, determine the causal relationship

163
00:06:21,180 --> 00:06:22,950
that led to the incident.

164
00:06:22,950 --> 00:06:25,440
Three, identify an effective solution.

165
00:06:25,440 --> 00:06:28,290
And four, implement and track the solutions

166
00:06:28,290 --> 00:06:31,140
to ensure that the incident is fully resolved.

167
00:06:31,140 --> 00:06:33,930
So, let's consider an example of a malware infection

168
00:06:33,930 --> 00:06:35,190
in your organization.

169
00:06:35,190 --> 00:06:36,720
First, you would want to determine

170
00:06:36,720 --> 00:06:38,460
the initial cause of the incident.

171
00:06:38,460 --> 00:06:39,900
Maybe it was caused by malware

172
00:06:39,900 --> 00:06:41,550
being introduced to your network

173
00:06:41,550 --> 00:06:44,490
by a user plugging in a thumb drive to their workstation.

174
00:06:44,490 --> 00:06:46,230
Whatever the initial vector was,

175
00:06:46,230 --> 00:06:48,900
you want to find it and prevent it from occurring again.

176
00:06:48,900 --> 00:06:51,780
So, how can we prevent this from occurring again?

177
00:06:51,780 --> 00:06:53,850
First, we might ensure all of our workstations

178
00:06:53,850 --> 00:06:54,750
have the latest version

179
00:06:54,750 --> 00:06:57,300
of our vendors' antivirus signatures on them.

180
00:06:57,300 --> 00:07:00,120
Next, we might also want to prevent data transfer

181
00:07:00,120 --> 00:07:03,480
from the USB devices like thumb drive for all the users.

182
00:07:03,480 --> 00:07:06,360
And third, made with this particular piece of malware

183
00:07:06,360 --> 00:07:08,820
was found to only infect the windows machines

184
00:07:08,820 --> 00:07:10,950
that are missing a certain software patch.

185
00:07:10,950 --> 00:07:12,330
On with this information,

186
00:07:12,330 --> 00:07:14,760
we can develop a plan to correct the incident,

187
00:07:14,760 --> 00:07:16,950
update all of the antivirus signatures,

188
00:07:16,950 --> 00:07:19,680
reconfigure the workstations to prevent USB devices,

189
00:07:19,680 --> 00:07:22,710
and install the windows patch across our network.

190
00:07:22,710 --> 00:07:25,110
Our IT management team can track the implementation

191
00:07:25,110 --> 00:07:28,650
of the solutions as we fully recover from this incident.

192
00:07:28,650 --> 00:07:30,990
Next, we have the lessons learned process.

193
00:07:30,990 --> 00:07:33,090
This process is a formalized method

194
00:07:33,090 --> 00:07:35,700
to document the things we've experienced during an incident,

195
00:07:35,700 --> 00:07:37,530
what went right, what went wrong,

196
00:07:37,530 --> 00:07:39,720
and what could we do better next time.

197
00:07:39,720 --> 00:07:41,610
All of these things should be recorded

198
00:07:41,610 --> 00:07:43,080
in our internal organization.

199
00:07:43,080 --> 00:07:45,150
Processes should be improved,

200
00:07:45,150 --> 00:07:47,520
so that the same issue does not occur again

201
00:07:47,520 --> 00:07:48,900
in our next incident.

202
00:07:48,900 --> 00:07:52,080
For example, maybe the change management board was too slow

203
00:07:52,080 --> 00:07:54,660
to approve the security fix we needed to implement

204
00:07:54,660 --> 00:07:56,400
to fully secure the network.

205
00:07:56,400 --> 00:07:58,500
One lessons learned that might be captured

206
00:07:58,500 --> 00:08:00,690
is the need to decrease the approved times

207
00:08:00,690 --> 00:08:03,660
for emergent change requests during an incident.

208
00:08:03,660 --> 00:08:06,540
We don't have to redevelop and change processes

209
00:08:06,540 --> 00:08:07,620
during the lessons learned.

210
00:08:07,620 --> 00:08:10,530
We just need to identify what could be improved.

211
00:08:10,530 --> 00:08:13,320
Finally, we have the after-action report.

212
00:08:13,320 --> 00:08:15,900
This is a formalized report that collects information

213
00:08:15,900 --> 00:08:17,160
about what happened.

214
00:08:17,160 --> 00:08:19,500
In this report, you should have the root cause analysis

215
00:08:19,500 --> 00:08:21,420
and the recommendations for improvements

216
00:08:21,420 --> 00:08:22,680
from your lessons learned.

217
00:08:22,680 --> 00:08:24,150
Depending on your organization,

218
00:08:24,150 --> 00:08:26,520
the report may be very detailed and technical,

219
00:08:26,520 --> 00:08:30,000
or it may be written instead as an executive summary.

220
00:08:30,000 --> 00:08:31,350
Incident response and recovery

221
00:08:31,350 --> 00:08:33,539
is a truly important function in our organizations

222
00:08:33,539 --> 00:08:35,880
because it seems every day there's another story

223
00:08:35,880 --> 00:08:38,010
of a major data breach in the news.

224
00:08:38,010 --> 00:08:40,650
Try as we might, we can never make our networks

225
00:08:40,650 --> 00:08:41,760
a hundred percent secure.

226
00:08:41,760 --> 00:08:44,250
And that means, eventually, we will likely have to reform

227
00:08:44,250 --> 00:08:46,170
an incident response and recovery.

228
00:08:46,170 --> 00:08:48,540
How you handled this situation during that critical time

229
00:08:48,540 --> 00:08:51,360
will determine how bad the incident will truly become

230
00:08:51,360 --> 00:08:52,950
for your organization.

231
00:08:52,950 --> 00:08:55,350
In order to conduct a proper incident response,

232
00:08:55,350 --> 00:08:58,260
your organization should utilize a team of professionals.

233
00:08:58,260 --> 00:09:00,930
But what does this incident response team look like?

234
00:09:00,930 --> 00:09:02,760
Well, the core team is made up

235
00:09:02,760 --> 00:09:03,960
of cybersecurity professionals

236
00:09:03,960 --> 00:09:05,880
with incident response experience,

237
00:09:05,880 --> 00:09:08,010
and they're supplemented by temporary members

238
00:09:08,010 --> 00:09:10,230
that are brought in for a specific incident.

239
00:09:10,230 --> 00:09:12,420
For example, if a database is involved,

240
00:09:12,420 --> 00:09:15,000
you may wish to deputize a database administrator

241
00:09:15,000 --> 00:09:17,310
be part of the team during this response.

242
00:09:17,310 --> 00:09:19,860
Large organizations often have dedicated

243
00:09:19,860 --> 00:09:21,150
incident response teams

244
00:09:21,150 --> 00:09:23,400
where the members perform this role fully,

245
00:09:23,400 --> 00:09:24,600
but smaller organizations

246
00:09:24,600 --> 00:09:27,390
will instead create temporary teams that are brought in

247
00:09:27,390 --> 00:09:29,430
and brought together for a specific incident.

248
00:09:29,430 --> 00:09:32,100
These roles on the team become a sort of additional duty

249
00:09:32,100 --> 00:09:34,410
for an IT administrator or other employees

250
00:09:34,410 --> 00:09:36,540
in addition to their normal job functions.

251
00:09:36,540 --> 00:09:38,310
The team is made up of a leader,

252
00:09:38,310 --> 00:09:40,230
who is a skilled incident responder,

253
00:09:40,230 --> 00:09:43,830
subject-matter experts, IT support staff, legal counsel,

254
00:09:43,830 --> 00:09:46,260
and human resources and public relations.

255
00:09:46,260 --> 00:09:48,690
Your organizational leadership and management teams

256
00:09:48,690 --> 00:09:51,810
are responsible for ensuring the team has funding,

257
00:09:51,810 --> 00:09:53,370
resources and expertise,

258
00:09:53,370 --> 00:09:55,410
needed to conduct the incident response.

259
00:09:55,410 --> 00:09:56,730
Management is also required

260
00:09:56,730 --> 00:09:58,590
to make the critical business decisions

261
00:09:58,590 --> 00:09:59,940
during the incident's response

262
00:09:59,940 --> 00:10:02,490
and communicating those decisions to key stakeholders

263
00:10:02,490 --> 00:10:04,290
or the media as appropriate.

264
00:10:04,290 --> 00:10:06,090
The other method that some organizations

265
00:10:06,090 --> 00:10:08,250
have taken to handle incident response,

266
00:10:08,250 --> 00:10:10,830
is to outsource the incident response teams.

267
00:10:10,830 --> 00:10:12,330
While this can be effective,

268
00:10:12,330 --> 00:10:14,370
since these teams specialize in doing nothing

269
00:10:14,370 --> 00:10:16,320
but incident response all day long,

270
00:10:16,320 --> 00:10:19,249
this can be a very expensive method to utilize.

271
00:10:19,249 --> 00:10:21,810
The other challenge with outsourcing your incident response

272
00:10:21,810 --> 00:10:24,420
is that these outside organizations are not familiar

273
00:10:24,420 --> 00:10:25,920
with your enterprise networks,

274
00:10:25,920 --> 00:10:28,320
so they will have to spend some time learning your network

275
00:10:28,320 --> 00:10:30,840
before they can conduct their response efforts.

276
00:10:30,840 --> 00:10:33,480
From my experience, when it comes to incident responses,

277
00:10:33,480 --> 00:10:34,313
they are not something

278
00:10:34,313 --> 00:10:35,760
that you should be looking forward to.

279
00:10:35,760 --> 00:10:38,580
They are stressful and they include days without sleep

280
00:10:38,580 --> 00:10:40,830
and the constant threat that the threat actors

281
00:10:40,830 --> 00:10:42,960
are still one step ahead of you.

282
00:10:42,960 --> 00:10:46,260
So, remember, our job during the incident response

283
00:10:46,260 --> 00:10:48,660
is to contain the issue, mitigate the threats,

284
00:10:48,660 --> 00:10:51,360
and get the organization back until solid footing

285
00:10:51,360 --> 00:10:52,800
as quickly as possible.

286
00:10:52,800 --> 00:10:54,870
This includes detecting the incident,

287
00:10:54,870 --> 00:10:56,250
responding to the threat,

288
00:10:56,250 --> 00:10:58,710
collecting evidence, containing the issue,

289
00:10:58,710 --> 00:11:00,900
restoring the network to full functionality,

290
00:11:00,900 --> 00:11:03,423
and further securing it to prevent reinfection.

