1
00:00:00,000 --> 00:00:00,900
In this lesson,

2
00:00:00,900 --> 00:00:03,360
we're going to cover policies and handbooks.

3
00:00:03,360 --> 00:00:05,670
Now, policies and handbooks are not just documents

4
00:00:05,670 --> 00:00:07,170
that are gathering dust on your shelf

5
00:00:07,170 --> 00:00:09,330
or take up storage space on your computer,

6
00:00:09,330 --> 00:00:11,220
but instead, you should really use these

7
00:00:11,220 --> 00:00:14,100
as living, breathing guidelines that shape your behavior,

8
00:00:14,100 --> 00:00:17,280
decision making, and protocols within your organization.

9
00:00:17,280 --> 00:00:19,410
Now, it is crucial to understand that these policies

10
00:00:19,410 --> 00:00:21,000
and handbooks aren't going to be the same

11
00:00:21,000 --> 00:00:23,070
across every organization you work at,

12
00:00:23,070 --> 00:00:24,750
because each organization will operate

13
00:00:24,750 --> 00:00:26,160
their business functions based on

14
00:00:26,160 --> 00:00:29,130
their specific industry, needs, and use cases.

15
00:00:29,130 --> 00:00:31,980
Therefore, your organization's policies on data management,

16
00:00:31,980 --> 00:00:33,840
for example, might be drastically different

17
00:00:33,840 --> 00:00:35,490
from the one you used at another company

18
00:00:35,490 --> 00:00:37,260
that you previously worked at.

19
00:00:37,260 --> 00:00:38,580
This is why it is really important

20
00:00:38,580 --> 00:00:40,590
that you not just read your organization's policies

21
00:00:40,590 --> 00:00:42,330
and handbooks, but that you also fully

22
00:00:42,330 --> 00:00:44,340
comprehend and understand them.

23
00:00:44,340 --> 00:00:47,490
So what is a policy and what is a handbook?

24
00:00:47,490 --> 00:00:50,100
Well, a policy is a deliberate system of principles

25
00:00:50,100 --> 00:00:51,570
and rules that guide decisions

26
00:00:51,570 --> 00:00:53,190
and achieve rational outcomes,

27
00:00:53,190 --> 00:00:54,210
and they're typically crafted

28
00:00:54,210 --> 00:00:56,520
to uphold an organization's internal controls

29
00:00:56,520 --> 00:00:59,490
and ensure compliance with legal and ethical standards.

30
00:00:59,490 --> 00:01:02,190
A handbook, on the other hand, is a comprehensive guide,

31
00:01:02,190 --> 00:01:04,200
usually in booklet form, that provides

32
00:01:04,200 --> 00:01:06,360
detailed information on procedures, guidelines,

33
00:01:06,360 --> 00:01:09,340
and best practices to assist individuals in understanding

34
00:01:09,340 --> 00:01:11,539
and navigating specific operational aspects

35
00:01:11,539 --> 00:01:13,470
of an organization.

36
00:01:13,470 --> 00:01:15,840
These policies and handbooks can be written to cover

37
00:01:15,840 --> 00:01:18,840
a myriad of different things inside of your organization.

38
00:01:18,840 --> 00:01:21,840
For example, you might have a policy on data protection,

39
00:01:21,840 --> 00:01:24,120
one for remote work, another for acceptable use

40
00:01:24,120 --> 00:01:26,175
of technology, and yet another for conflicts of interest

41
00:01:26,175 --> 00:01:28,020
and things like that.

42
00:01:28,020 --> 00:01:29,720
On the other hand, handbooks might be created

43
00:01:29,720 --> 00:01:32,400
for employees, another one for training,

44
00:01:32,400 --> 00:01:34,920
another for compliance, and things like that.

45
00:01:34,920 --> 00:01:37,290
For example, let's assume you just got hired on

46
00:01:37,290 --> 00:01:38,883
at a new company and you want to throw away

47
00:01:38,883 --> 00:01:40,950
or discard a five page printout

48
00:01:40,950 --> 00:01:42,540
that contains sensitive data on it,

49
00:01:42,540 --> 00:01:45,000
like your organization's last quarter sales numbers

50
00:01:45,000 --> 00:01:47,250
that are not yet being released to the public.

51
00:01:47,250 --> 00:01:49,200
How should you dispose of this paper?

52
00:01:49,200 --> 00:01:50,280
Should you throw it away?

53
00:01:50,280 --> 00:01:51,360
Should you recycle it?

54
00:01:51,360 --> 00:01:52,200
Should you shred it?

55
00:01:52,200 --> 00:01:53,250
Should you burn it?

56
00:01:53,250 --> 00:01:55,410
Well, it all depends, but if you check

57
00:01:55,410 --> 00:01:57,600
your organization's data destruction policy,

58
00:01:57,600 --> 00:01:59,160
it will clearly define the right way

59
00:01:59,160 --> 00:02:01,740
for you to dispose of this type of printout that contains

60
00:02:01,740 --> 00:02:04,560
your organization's sensitive financial data audit.

61
00:02:04,560 --> 00:02:06,685
At one organization I worked at, there was a policy

62
00:02:06,685 --> 00:02:08,580
that said that anything that was printed out

63
00:02:08,580 --> 00:02:10,169
that contains sensitive information

64
00:02:10,169 --> 00:02:11,843
had to be printed on a specific printer

65
00:02:11,843 --> 00:02:14,070
that was loaded with pink paper.

66
00:02:14,070 --> 00:02:16,520
In that same policy, it stated that any pink paper

67
00:02:16,520 --> 00:02:19,350
was not allowed to be thrown away or recycled.

68
00:02:19,350 --> 00:02:21,930
It had to be shredded using a cross-cut shredder

69
00:02:21,930 --> 00:02:24,360
to prevent any of that sensitive data from being the victim

70
00:02:24,360 --> 00:02:26,280
of a dumpster diving attack.

71
00:02:26,280 --> 00:02:27,960
Now, I also worked at a high security

72
00:02:27,960 --> 00:02:29,610
governmental organization in the past,

73
00:02:29,610 --> 00:02:30,617
and they had a similar process

74
00:02:30,617 --> 00:02:33,659
where white paper was used for unclassified documents,

75
00:02:33,659 --> 00:02:35,970
pink was used for secret documents,

76
00:02:35,970 --> 00:02:38,400
and yellow was used for top secret documents.

77
00:02:38,400 --> 00:02:40,620
For white documents, you could recycle them.

78
00:02:40,620 --> 00:02:42,720
For pink documents, you could shred them.

79
00:02:42,720 --> 00:02:45,840
But for yellow documents, you had to incinerate or burn them

80
00:02:45,840 --> 00:02:48,344
using our organization's internal processes.

81
00:02:48,344 --> 00:02:50,430
Another common area that you need to review

82
00:02:50,430 --> 00:02:52,403
inside your organization's policies and handbooks

83
00:02:52,403 --> 00:02:55,380
concerns remote work or taking work home.

84
00:02:55,380 --> 00:02:57,540
These days, remote work and work from home

85
00:02:57,540 --> 00:02:59,880
have become fairly normal in most industries,

86
00:02:59,880 --> 00:03:02,381
but several organizations still do not allow this to occur

87
00:03:02,381 --> 00:03:04,770
because of a wide variety of security issues

88
00:03:04,770 --> 00:03:06,780
that could arise from allowing remote work

89
00:03:06,780 --> 00:03:08,160
or work from home.

90
00:03:08,160 --> 00:03:10,560
So you need to review your organization's policies

91
00:03:10,560 --> 00:03:11,790
and handbooks to determine

92
00:03:11,790 --> 00:03:13,890
what their remote work policy is going to be,

93
00:03:13,890 --> 00:03:15,805
because many organizations have strict guidelines

94
00:03:15,805 --> 00:03:18,300
on what type of information can actually leave

95
00:03:18,300 --> 00:03:21,090
the physical confines of their office building.

96
00:03:21,090 --> 00:03:22,941
These policies and handbooks aren't just focused

97
00:03:22,941 --> 00:03:24,925
on the digital files, but they also include

98
00:03:24,925 --> 00:03:26,781
what you should be doing with physical files

99
00:03:26,781 --> 00:03:28,440
that somebody may want to take home

100
00:03:28,440 --> 00:03:30,390
with them to do work at home.

101
00:03:30,390 --> 00:03:32,301
For example, when I worked at that high security

102
00:03:32,301 --> 00:03:34,301
government organization, we were not allowed

103
00:03:34,301 --> 00:03:36,445
to have smartphones or personal digital assistants

104
00:03:36,445 --> 00:03:38,100
inside of the building.

105
00:03:38,100 --> 00:03:40,365
So I always carried around with me an old fashioned notebook

106
00:03:40,365 --> 00:03:42,300
all day long to take notes

107
00:03:42,300 --> 00:03:44,190
at all the various meetings I attended.

108
00:03:44,190 --> 00:03:45,981
I'd also write down any tasks or appointments I had

109
00:03:45,981 --> 00:03:47,640
and things like that.

110
00:03:47,640 --> 00:03:48,840
Now, at the end of the day,

111
00:03:48,840 --> 00:03:50,561
I can't take this notebook home with me though

112
00:03:50,561 --> 00:03:53,040
because it has sensitive information written in it

113
00:03:53,040 --> 00:03:55,170
about things that were secret or top secret,

114
00:03:55,170 --> 00:03:57,810
depending on the meetings I was attending during that day.

115
00:03:57,810 --> 00:03:59,885
So this organization had a policy that said

116
00:03:59,885 --> 00:04:02,070
what kind of things could be taken home with you

117
00:04:02,070 --> 00:04:04,200
and worked on and which ones couldn't.

118
00:04:04,200 --> 00:04:05,580
For example, if I had to do

119
00:04:05,580 --> 00:04:08,490
my annual cybersecurity training, I could do that from home

120
00:04:08,490 --> 00:04:10,500
because I could log into an internet-based website

121
00:04:10,500 --> 00:04:11,670
and complete it from there

122
00:04:11,670 --> 00:04:13,650
as part of my work from home hours.

123
00:04:13,650 --> 00:04:16,019
But for about 99% of the other things

124
00:04:16,019 --> 00:04:18,630
I did on a weekly basis, I couldn't do those at home

125
00:04:18,630 --> 00:04:21,269
because they were classified as secret or top secret.

126
00:04:21,269 --> 00:04:22,650
And so I couldn't work on those things

127
00:04:22,650 --> 00:04:25,230
unless I was inside of the official government building

128
00:04:25,230 --> 00:04:27,960
because that's where that secret information was located.

129
00:04:27,960 --> 00:04:29,363
In fact, at this organization,

130
00:04:29,363 --> 00:04:30,845
anytime you left the building,

131
00:04:30,845 --> 00:04:32,760
they would actually look through your backpacks,

132
00:04:32,760 --> 00:04:34,860
your briefcases, and your purses to ensure

133
00:04:34,860 --> 00:04:37,080
you didn't inadvertently take home any documents

134
00:04:37,080 --> 00:04:39,870
that might violate their data protection policies.

135
00:04:39,870 --> 00:04:41,370
Now, this isn't just a matter of trust,

136
00:04:41,370 --> 00:04:43,890
it's about securing the organization's information,

137
00:04:43,890 --> 00:04:45,464
and your home probably hasn't been vetted

138
00:04:45,464 --> 00:04:47,310
by your organization's security team

139
00:04:47,310 --> 00:04:49,530
to hold top secret information, right?

140
00:04:49,530 --> 00:04:52,080
So we don't want any secret or top secret documents

141
00:04:52,080 --> 00:04:53,730
sitting in your home office where somebody

142
00:04:53,730 --> 00:04:56,070
can break into your house and steal them easily.

143
00:04:56,070 --> 00:04:58,410
Instead, we want them in our secure facilities

144
00:04:58,410 --> 00:05:00,270
that are provided by the government.

145
00:05:00,270 --> 00:05:01,624
Now, up to this point, I've been focusing

146
00:05:01,624 --> 00:05:03,379
on policies and handbooks that tell us

147
00:05:03,379 --> 00:05:05,190
what we aren't allowed to do.

148
00:05:05,190 --> 00:05:07,380
But a lot of policies and handbooks will also provide you

149
00:05:07,380 --> 00:05:08,370
with guidance for navigating

150
00:05:08,370 --> 00:05:09,780
your day-to-day responsibilities

151
00:05:09,780 --> 00:05:11,670
and what you are allowed to do.

152
00:05:11,670 --> 00:05:13,740
For example, these policies and handbooks

153
00:05:13,740 --> 00:05:16,320
are going to cover everything from how to handle a data breach

154
00:05:16,320 --> 00:05:18,870
to the steps for reporting suspicious activities.

155
00:05:18,870 --> 00:05:19,830
Let's pretend for a moment

156
00:05:19,830 --> 00:05:21,261
that you just received a strange email,

157
00:05:21,261 --> 00:05:22,980
and as you read that email,

158
00:05:22,980 --> 00:05:24,510
your gut tells you there's just something

159
00:05:24,510 --> 00:05:25,890
not right about it.

160
00:05:25,890 --> 00:05:27,363
Well, how do you report it?

161
00:05:27,363 --> 00:05:29,820
If you check the chapter in your employee handbook,

162
00:05:29,820 --> 00:05:32,460
it'll tell you who to contact, what information to provide,

163
00:05:32,460 --> 00:05:34,770
and how to isolate the potential threat that is represented

164
00:05:34,770 --> 00:05:37,245
by this email for your organization's systems.

165
00:05:37,245 --> 00:05:40,200
These policies and handbooks also evolve over time

166
00:05:40,200 --> 00:05:42,090
because cybersecurity isn't static,

167
00:05:42,090 --> 00:05:43,710
and what was relevant two years ago

168
00:05:43,710 --> 00:05:46,230
might not be something we need to think about today.

169
00:05:46,230 --> 00:05:48,600
For this reason, every policy and handbook

170
00:05:48,600 --> 00:05:50,820
needs to be reviewed at least once per year

171
00:05:50,820 --> 00:05:52,620
and updated as appropriate.

172
00:05:52,620 --> 00:05:55,140
Additionally, when the policy or handbook is updated,

173
00:05:55,140 --> 00:05:57,120
your organization must ensure that your employees

174
00:05:57,120 --> 00:05:59,610
take the time to read the latest versions as well.

175
00:05:59,610 --> 00:06:01,290
If there's any significant changes,

176
00:06:01,290 --> 00:06:02,490
you should probably highlight those

177
00:06:02,490 --> 00:06:04,050
in a single one-page summary too,

178
00:06:04,050 --> 00:06:05,880
and provide that with the policy.

179
00:06:05,880 --> 00:06:07,920
After all, you don't want a system administrator

180
00:06:07,920 --> 00:06:09,720
who missed a memo on the updated protocol

181
00:06:09,720 --> 00:06:11,580
for your organization's password complexity

182
00:06:11,580 --> 00:06:13,920
to not implement those changes on your domain controller

183
00:06:13,920 --> 00:06:15,750
or other important systems and servers

184
00:06:15,750 --> 00:06:17,790
simply because they missed the memo.

185
00:06:17,790 --> 00:06:20,243
Now, as much as we rely on these policies and handbooks,

186
00:06:20,243 --> 00:06:23,040
it is worth noting that they are not foolproof.

187
00:06:23,040 --> 00:06:25,440
Mistakes are going to happen, breaches are going to occur,

188
00:06:25,440 --> 00:06:26,584
and new threats are going to emerge

189
00:06:26,584 --> 00:06:27,960
that may not have been covered

190
00:06:27,960 --> 00:06:29,940
in your training or in your handbook.

191
00:06:29,940 --> 00:06:32,340
For this reason, it's important to train your employees

192
00:06:32,340 --> 00:06:34,243
on the why behind your policies and handbooks

193
00:06:34,243 --> 00:06:36,461
because they may be asked to make a judgment decision

194
00:06:36,461 --> 00:06:38,910
when the policy doesn't specifically cover something

195
00:06:38,910 --> 00:06:40,424
that comes up in their daily work.

196
00:06:40,424 --> 00:06:43,043
Your policies and handbooks should always be designed

197
00:06:43,043 --> 00:06:46,590
to foster a secure environment and a culture of mindfulness.

198
00:06:46,590 --> 00:06:48,660
If you encounter something that doesn't fit the mold,

199
00:06:48,660 --> 00:06:50,040
it's not just your right,

200
00:06:50,040 --> 00:06:52,380
but also your responsibility to bring it up

201
00:06:52,380 --> 00:06:54,270
to your management and leadership teams

202
00:06:54,270 --> 00:06:55,950
because that way, they can provide you guidance

203
00:06:55,950 --> 00:06:58,050
and help you in that decision making.

204
00:06:58,050 --> 00:06:59,670
This is what we're referring to when we talk about

205
00:06:59,670 --> 00:07:01,245
creating a culture of security.

206
00:07:01,245 --> 00:07:04,230
So remember, your organization's policies and handbooks

207
00:07:04,230 --> 00:07:05,981
are going to be used to help you make informed decisions

208
00:07:05,981 --> 00:07:07,440
and be a proactive part

209
00:07:07,440 --> 00:07:09,870
of your organization's cybersecurity mechanisms.

210
00:07:09,870 --> 00:07:11,581
They serve as guides, not guardrails,

211
00:07:11,581 --> 00:07:14,285
to help your employees understand the principles behind them

212
00:07:14,285 --> 00:07:17,043
and recognize when something doesn't quite line up.

213
00:07:17,043 --> 00:07:18,690
So take the time to read

214
00:07:18,690 --> 00:07:20,520
your organization's policies and handbooks,

215
00:07:20,520 --> 00:07:22,800
and if you're ever in doubt, ask for additional guidance

216
00:07:22,800 --> 00:07:25,770
or clarification from your management or leadership team.

217
00:07:25,770 --> 00:07:28,560
After all, there is no question that is too insignificant

218
00:07:28,560 --> 00:07:31,140
to your organization's overall cybersecurity posture

219
00:07:31,140 --> 00:07:32,740
except the one that isn't asked.

