1
00:00:06,540 --> 00:00:07,800
- Welcome to lesson 21,

2
00:00:07,800 --> 00:00:10,800
explain appropriate incident
response activities.

3
00:00:10,800 --> 00:00:12,960
In our first lesson, 21.1

4
00:00:12,960 --> 00:00:15,423
we're gonna focus in
on incident management.

5
00:00:16,355 --> 00:00:18,480
Now, incident management is inclusive

6
00:00:18,480 --> 00:00:20,370
of the roles and the responsibilities,

7
00:00:20,370 --> 00:00:23,850
the strategies and the
procedures for preparing for,

8
00:00:23,850 --> 00:00:27,783
responding to and managing
security incidents.

9
00:00:28,770 --> 00:00:31,080
Now, a security incident is an event

10
00:00:31,080 --> 00:00:34,650
or an action that endangers
the confidentiality,

11
00:00:34,650 --> 00:00:37,920
the integrity, or the
availability of information

12
00:00:37,920 --> 00:00:39,540
or information systems.

13
00:00:39,540 --> 00:00:41,880
But I do wanna make sure that
we're distinguishing that

14
00:00:41,880 --> 00:00:43,230
from a data breach.

15
00:00:43,230 --> 00:00:46,980
A data breach is when data
is exfiltrated or extracted

16
00:00:46,980 --> 00:00:48,870
or there's a loss of control.

17
00:00:48,870 --> 00:00:50,850
Now, data breaches may trigger reporting

18
00:00:50,850 --> 00:00:52,710
and notification requirements

19
00:00:52,710 --> 00:00:55,920
or a security incident is
really could be as common

20
00:00:55,920 --> 00:00:57,570
as a everyday event, right?

21
00:00:57,570 --> 00:01:00,090
It doesn't tend to trigger any reporting

22
00:01:00,090 --> 00:01:01,680
or notification requirements,

23
00:01:01,680 --> 00:01:03,720
it's just an event or
action that endangers

24
00:01:03,720 --> 00:01:06,720
or potentially endangers
confidentiality, integrity,

25
00:01:06,720 --> 00:01:09,393
and availability that
we need to respond to.

26
00:01:11,580 --> 00:01:14,670
There are four primary
incident management components

27
00:01:14,670 --> 00:01:18,900
or activities, incident
prevention, incident preparation,

28
00:01:18,900 --> 00:01:22,590
incident detection, and incident response.

29
00:01:22,590 --> 00:01:24,870
Now, how awesome if we
can prevent an incident

30
00:01:24,870 --> 00:01:26,460
from even happening.

31
00:01:26,460 --> 00:01:28,980
So what do we do to try
to prevent incidents?

32
00:01:28,980 --> 00:01:30,090
What we do threat modeling?

33
00:01:30,090 --> 00:01:33,030
To understand the most likely threats.

34
00:01:33,030 --> 00:01:36,000
We do risk assessments to
understand risk levels.

35
00:01:36,000 --> 00:01:38,190
We do a controls implementation, right?

36
00:01:38,190 --> 00:01:41,370
We put in multiple layers
of diverse controls,

37
00:01:41,370 --> 00:01:44,520
we monitor and then we do our
assurance activities, right?

38
00:01:44,520 --> 00:01:47,430
We test to make sure that
our controls are all working

39
00:01:47,430 --> 00:01:50,040
exactly the way we think they're working,

40
00:01:50,040 --> 00:01:51,840
but we won't prevent every incident

41
00:01:51,840 --> 00:01:54,750
so we have to be prepared for an incident.

42
00:01:54,750 --> 00:01:58,980
And that preparation will
include planning, documenting,

43
00:01:58,980 --> 00:02:01,800
assigning responsibilities, training,

44
00:02:01,800 --> 00:02:04,653
and practicing our response capabilities.

45
00:02:05,700 --> 00:02:09,930
Then we need to be able to very
quickly detect an incident.

46
00:02:09,930 --> 00:02:12,720
So our activities there
include monitoring,

47
00:02:12,720 --> 00:02:16,380
incident reporting,
analysis, and participation

48
00:02:16,380 --> 00:02:19,800
in threat intelligence and
information sharing activities

49
00:02:19,800 --> 00:02:22,620
so that we can recognize an incident.

50
00:02:22,620 --> 00:02:25,260
And lastly, actual incident response.

51
00:02:25,260 --> 00:02:27,990
So an incident has
happened, we've detected it.

52
00:02:27,990 --> 00:02:29,580
Now we're gonna go through the process

53
00:02:29,580 --> 00:02:32,970
of validating the incident, containing it,

54
00:02:32,970 --> 00:02:36,750
mitigating it, eradicating
it, recovering from it,

55
00:02:36,750 --> 00:02:39,783
and then doing a post-incident evaluation.

56
00:02:41,790 --> 00:02:44,400
So who's responsible
for incident management?

57
00:02:44,400 --> 00:02:46,740
Well, there's a lot of folks involved

58
00:02:46,740 --> 00:02:48,210
and a lot of components.

59
00:02:48,210 --> 00:02:52,203
We have policies, we have
plans, and we have procedures.

60
00:02:53,220 --> 00:02:56,160
Now we're gonna focus in
at the plan and procedure

61
00:02:56,160 --> 00:02:58,590
but it's worth mentioning
the policy, right,

62
00:02:58,590 --> 00:03:00,450
at the policy level, right?

63
00:03:00,450 --> 00:03:02,700
We're going to sort of set the framework

64
00:03:02,700 --> 00:03:04,080
for incident management.

65
00:03:04,080 --> 00:03:06,390
And policy should always be approved

66
00:03:06,390 --> 00:03:08,550
by the highest level in your organization

67
00:03:08,550 --> 00:03:10,740
perhaps a board of directors
or a board of trustees

68
00:03:10,740 --> 00:03:13,383
or an agency, maybe agency leadership.

69
00:03:14,220 --> 00:03:17,550
Then we have plan components,
and then we have procedures.

70
00:03:17,550 --> 00:03:19,890
So I wanna talk about the
various plan components

71
00:03:19,890 --> 00:03:21,960
and then specifically for procedures,

72
00:03:21,960 --> 00:03:23,643
I wanna talk about playbooks.

73
00:03:25,920 --> 00:03:27,620
So let's start with playbooks.

74
00:03:27,620 --> 00:03:30,660
An incident playbook is
a set of instructions

75
00:03:30,660 --> 00:03:35,070
for planning for and responding
to a specific type of attack

76
00:03:35,070 --> 00:03:36,660
or event or scenario.

77
00:03:36,660 --> 00:03:39,030
So while our incident
plans as we're going to see

78
00:03:39,030 --> 00:03:42,060
are more generic, there are certain steps

79
00:03:42,060 --> 00:03:44,880
we're going to have to
take for high risk events.

80
00:03:44,880 --> 00:03:47,820
And so we're going to
have a playbook designed

81
00:03:47,820 --> 00:03:49,890
for those high risk events.

82
00:03:49,890 --> 00:03:51,450
We're measuring them
in terms of how likely

83
00:03:51,450 --> 00:03:53,610
is this to happen and
what would be the impact.

84
00:03:53,610 --> 00:03:55,260
So for example, malware

85
00:03:55,260 --> 00:03:58,380
or a distributed denial
of service, a DDOS attack

86
00:03:58,380 --> 00:04:02,403
or a ransomware extortion attack
or payment card compromise.

87
00:04:04,560 --> 00:04:07,710
So we have those playbooks
that's really specific, right?

88
00:04:07,710 --> 00:04:09,510
But then we come back up to our plan

89
00:04:09,510 --> 00:04:12,390
which is overarching and
a little bit more generic.

90
00:04:12,390 --> 00:04:14,070
Some of the things we're
gonna have in our plan

91
00:04:14,070 --> 00:04:15,990
will be threat modeling, right?

92
00:04:15,990 --> 00:04:19,140
Which is our process of how
we're anticipating threats.

93
00:04:19,140 --> 00:04:21,390
Categorization, which is the process

94
00:04:21,390 --> 00:04:25,380
of how we're gonna classify
incidents based on severity.

95
00:04:25,380 --> 00:04:26,430
And that's gonna be important

96
00:04:26,430 --> 00:04:29,070
because we're gonna use it
to determine response times,

97
00:04:29,070 --> 00:04:33,120
resource assignments, and
preparation requirements.

98
00:04:33,120 --> 00:04:34,890
Then we're gonna have
our reporting standards

99
00:04:34,890 --> 00:04:36,900
for how incidents should be documented

100
00:04:36,900 --> 00:04:40,980
and communicated as well as
when notification requirements

101
00:04:40,980 --> 00:04:42,630
are going to be triggered.

102
00:04:42,630 --> 00:04:45,810
And then importantly, we wanna
have escalation thresholds.

103
00:04:45,810 --> 00:04:48,210
Escalation thresholds
referred to the point

104
00:04:48,210 --> 00:04:52,980
at which an incident or an
issue require a higher level

105
00:04:52,980 --> 00:04:54,633
of response or attention.

106
00:04:57,120 --> 00:04:58,950
Now, another component of our plan

107
00:04:58,950 --> 00:05:01,470
is going to be the incident response team.

108
00:05:01,470 --> 00:05:04,770
The membership of an incident
response team or an IRT

109
00:05:04,770 --> 00:05:07,890
is generally composed
of internal personnel

110
00:05:07,890 --> 00:05:10,533
and then adjunct external resources.

111
00:05:11,730 --> 00:05:14,010
The internal personnel
should always represent

112
00:05:14,010 --> 00:05:16,590
a cross section of the organization.

113
00:05:16,590 --> 00:05:19,350
So including operations,
information security,

114
00:05:19,350 --> 00:05:21,660
information technology, risk management,

115
00:05:21,660 --> 00:05:25,710
marketing, legal and compliance,
executive management,

116
00:05:25,710 --> 00:05:27,570
maybe some key business units.

117
00:05:27,570 --> 00:05:30,720
Why? Because an incident
isn't just an IT issue,

118
00:05:30,720 --> 00:05:32,790
it isn't just a security issue,

119
00:05:32,790 --> 00:05:34,440
it is an organizational issue.

120
00:05:34,440 --> 00:05:36,780
So we want a cross section
of the organization

121
00:05:36,780 --> 00:05:38,280
as part of our team.

122
00:05:38,280 --> 00:05:40,980
Then we wanna have external resources

123
00:05:40,980 --> 00:05:43,800
that we have identified,
we have relationships with

124
00:05:43,800 --> 00:05:46,350
and we're appropriate, we
already have contracts with.

125
00:05:46,350 --> 00:05:49,080
Forensic experts in
case there's an incident

126
00:05:49,080 --> 00:05:51,690
that has to have a forensic investigation,

127
00:05:51,690 --> 00:05:54,720
legal counsel our
insurance representatives,

128
00:05:54,720 --> 00:05:57,870
we really need to understand
how we're supposed to react

129
00:05:57,870 --> 00:06:00,660
and what timeframe, what
we can say and not say.

130
00:06:00,660 --> 00:06:05,660
Because you know, if we don't
follow insurance protocols,

131
00:06:05,880 --> 00:06:08,730
there's a good chance that
insurance won't pay out.

132
00:06:08,730 --> 00:06:11,640
We wanna have public relations
folks available to us

133
00:06:11,640 --> 00:06:14,520
because this may become
a public facing issue,

134
00:06:14,520 --> 00:06:17,160
and we wanna know how to
work with law enforcement.

135
00:06:17,160 --> 00:06:20,790
So external resources, forensic experts,

136
00:06:20,790 --> 00:06:22,920
legal counsel, insurance representatives,

137
00:06:22,920 --> 00:06:25,320
public relations and law enforcement

138
00:06:25,320 --> 00:06:27,683
and I'm sure you could
probably think of others.

139
00:06:28,560 --> 00:06:30,450
Now, we also wanna make
sure that everybody

140
00:06:30,450 --> 00:06:34,080
in the organization is ready
to respond to an incident.

141
00:06:34,080 --> 00:06:36,630
So incident response
training should be included

142
00:06:36,630 --> 00:06:38,790
in our organizational
wide set of programs,

143
00:06:38,790 --> 00:06:41,973
security, education, training,
and awareness programs.

144
00:06:43,320 --> 00:06:45,210
At the highest level, our executives

145
00:06:45,210 --> 00:06:47,310
including our board of directors as well

146
00:06:47,310 --> 00:06:52,080
should be educated on incident
related organizational risks.

147
00:06:52,080 --> 00:06:55,740
All personnel in our
organization should be aware

148
00:06:55,740 --> 00:06:59,460
of potential incident scenarios
and how to report them.

149
00:06:59,460 --> 00:07:01,860
And then first responders,
who's ever going to be

150
00:07:01,860 --> 00:07:05,010
responding initially boots on the ground

151
00:07:05,010 --> 00:07:09,240
to an incident as well as all
incident response team members

152
00:07:09,240 --> 00:07:12,753
should receive training related
to their assigned tasks.

153
00:07:14,700 --> 00:07:18,120
Then we also want to
exercise our preparedness.

154
00:07:18,120 --> 00:07:20,970
So incident response
exercises should be conducted

155
00:07:20,970 --> 00:07:24,780
on a periodic basis to assure readiness.

156
00:07:24,780 --> 00:07:28,620
Now, exercises include things
like walkthroughs, tabletops,

157
00:07:28,620 --> 00:07:31,650
and simulations, very
similar to what we talked

158
00:07:31,650 --> 00:07:34,410
about earlier with
continuity of operations.

159
00:07:34,410 --> 00:07:37,170
Now, participants in our
exercises should include

160
00:07:37,170 --> 00:07:40,590
the incident response team,
our external resources,

161
00:07:40,590 --> 00:07:43,050
and as applicable executive management,

162
00:07:43,050 --> 00:07:45,270
even our board of directors, perhaps.

163
00:07:45,270 --> 00:07:48,510
For a good example would be ransomware.

164
00:07:48,510 --> 00:07:50,550
You know, ransomware
is all about extortion.

165
00:07:50,550 --> 00:07:53,430
And we definitely wanna
have executive management

166
00:07:53,430 --> 00:07:55,110
and a representative of the board

167
00:07:55,110 --> 00:07:58,533
when we're making decisions
about pain and extortion demand.

168
00:08:00,270 --> 00:08:02,370
So let's look at those exercise options,

169
00:08:02,370 --> 00:08:05,100
walkthrough, tabletop, and simulation.

170
00:08:05,100 --> 00:08:07,950
Walkthrough is when our
personnel or departments review

171
00:08:07,950 --> 00:08:09,990
or kind of literally
walkthrough their plans

172
00:08:09,990 --> 00:08:11,940
and procedures for completeness.

173
00:08:11,940 --> 00:08:14,730
So we say, okay, here's
your incident response plan.

174
00:08:14,730 --> 00:08:16,440
Go through it. Is it right? Is it wrong?

175
00:08:16,440 --> 00:08:17,970
Does it need to be modified?

176
00:08:17,970 --> 00:08:20,880
Really, our objective here is accuracy.

177
00:08:20,880 --> 00:08:24,450
A tabletop, again, it's
scenario-based group workshop.

178
00:08:24,450 --> 00:08:26,497
We're gonna bring people
together and we're gonna say,

179
00:08:26,497 --> 00:08:28,440
"Okay here's an incident.

180
00:08:28,440 --> 00:08:31,200
Pull out your plans, your
procedures, your playbook,

181
00:08:31,200 --> 00:08:33,840
see if we have anything
that actually can address

182
00:08:33,840 --> 00:08:35,340
this particular incident."

183
00:08:35,340 --> 00:08:37,890
And we're also looking
for participant readiness.

184
00:08:37,890 --> 00:08:39,930
Like, have you ever even
looked at that plan before?

185
00:08:39,930 --> 00:08:42,210
Do you know what to pull
out? Do you know what to do?

186
00:08:42,210 --> 00:08:45,090
So our objectives are
familiarity with the plan,

187
00:08:45,090 --> 00:08:47,340
accuracy of the plan and coordination

188
00:08:47,340 --> 00:08:49,560
between departments and groups.

189
00:08:49,560 --> 00:08:51,150
And then lastly, with a simulation.

190
00:08:51,150 --> 00:08:52,860
And that's a localized scenario

191
00:08:52,860 --> 00:08:55,173
that simulates an actual event.

192
00:08:56,010 --> 00:08:57,930
- In a pre-planned simulation,

193
00:08:57,930 --> 00:09:00,870
it's scheduled and our
attendees are invited.

194
00:09:00,870 --> 00:09:02,700
In a surprise simulation,

195
00:09:02,700 --> 00:09:05,610
our attendees are kind of
notified in the moment.

196
00:09:05,610 --> 00:09:08,850
So we have a scenario and
we go through the motions

197
00:09:08,850 --> 00:09:12,480
of how we would respond if
that was an actual event.

198
00:09:12,480 --> 00:09:14,703
Again, our objective is readiness.

199
00:09:15,750 --> 00:09:16,830
You know, there's pros and cons

200
00:09:16,830 --> 00:09:18,780
to both pre-planned and surprise.

201
00:09:18,780 --> 00:09:20,010
Pre-planned, you're gonna know

202
00:09:20,010 --> 00:09:21,270
that everybody's attending, right?

203
00:09:21,270 --> 00:09:22,890
It's on everybody's schedule.

204
00:09:22,890 --> 00:09:25,200
Surprise, there's a good
chance you won't get everybody.

205
00:09:25,200 --> 00:09:27,540
You won't get your whole
incident response team

206
00:09:27,540 --> 00:09:29,610
but you're gonna learn a
lot about how do you work

207
00:09:29,610 --> 00:09:32,793
with a smaller team and who
needs to be cross-trained?

208
00:09:35,070 --> 00:09:37,890
And that, my friends, brings
us to a three second challenge.

209
00:09:37,890 --> 00:09:39,900
Five challenge questions,
three seconds each.

210
00:09:39,900 --> 00:09:40,733
Let's do it.

211
00:09:41,940 --> 00:09:43,560
A set of instructions for responding

212
00:09:43,560 --> 00:09:46,110
to a specific type of event.

213
00:09:46,110 --> 00:09:47,793
1, 2, 3.

214
00:09:48,810 --> 00:09:51,030
That's gonna be an incident playbook.

215
00:09:51,030 --> 00:09:54,573
Number two, the process
of anticipating threats.

216
00:09:55,650 --> 00:09:57,333
1, 2, 3.

217
00:09:58,170 --> 00:09:59,610
And that's gonna be threat modeling.

218
00:09:59,610 --> 00:10:01,410
Remember, we talked about
three different ways

219
00:10:01,410 --> 00:10:03,360
to approach threat modeling, right?

220
00:10:03,360 --> 00:10:07,803
Asset centric, architecture
centric, and attacker centric.

221
00:10:08,790 --> 00:10:11,400
Number three, scenario-based
group workshop

222
00:10:11,400 --> 00:10:14,943
focused on the application
of plans and procedures.

223
00:10:15,810 --> 00:10:17,373
1, 2, 3.

224
00:10:18,420 --> 00:10:20,373
It's gonna be a tabletop exercise.

225
00:10:21,300 --> 00:10:23,970
Number four, the point
at which an incident

226
00:10:23,970 --> 00:10:27,573
or issue require a higher
level of attention or response.

227
00:10:28,590 --> 00:10:30,273
1, 2, 3.

228
00:10:31,380 --> 00:10:33,870
That's gonna be the escalation threshold.

229
00:10:33,870 --> 00:10:38,130
And lastly, number five, the
type of simulation exercise

230
00:10:38,130 --> 00:10:40,173
that attendees are scheduled for.

231
00:10:41,160 --> 00:10:42,693
1, 2, 3.

232
00:10:43,530 --> 00:10:44,973
It's gonna be a pre-planned.

233
00:10:46,200 --> 00:10:48,810
All right, that brings us to
yet another security in action.

234
00:10:48,810 --> 00:10:51,210
This one about an incident response team.

235
00:10:51,210 --> 00:10:54,300
Your study and your organization's
incident response plan

236
00:10:54,300 --> 00:10:55,350
and playbooks.

237
00:10:55,350 --> 00:10:57,720
And you're really,
really surprised to learn

238
00:10:57,720 --> 00:11:00,390
that all of the incident
response team members

239
00:11:00,390 --> 00:11:02,220
are IT personnel.

240
00:11:02,220 --> 00:11:06,030
And when you ask your
manager, why is this,

241
00:11:06,030 --> 00:11:08,850
you're told that, "Only IT personnel

242
00:11:08,850 --> 00:11:11,700
have the necessary skills
to evaluate an incident

243
00:11:11,700 --> 00:11:16,050
and quickly fixing the issue
is our number one priority."

244
00:11:16,050 --> 00:11:17,760
Uh-oh, okay?

245
00:11:17,760 --> 00:11:18,630
What's your response?

246
00:11:18,630 --> 00:11:20,070
Do you agree with that?

247
00:11:20,070 --> 00:11:22,650
Again, you've been looking at
your incident response plan

248
00:11:22,650 --> 00:11:26,610
and playbook, and what you
learn is that every member

249
00:11:26,610 --> 00:11:30,123
of that incident response
team are IT personnel.

250
00:11:30,960 --> 00:11:33,750
So you say to your
manager, why is this right?

251
00:11:33,750 --> 00:11:35,730
And they say, well, yeah,
but only IT personnel

252
00:11:35,730 --> 00:11:37,590
really will know what to do, right?

253
00:11:37,590 --> 00:11:39,300
They only have that necessary skills

254
00:11:39,300 --> 00:11:42,450
to evaluate the incident
and quickly fix it.

255
00:11:42,450 --> 00:11:43,283
Do you agree?

256
00:11:43,283 --> 00:11:44,400
How would you respond?

257
00:11:44,400 --> 00:11:45,570
Go ahead and put me on pause.

258
00:11:45,570 --> 00:11:47,340
Think about your response,
jot some notes down

259
00:11:47,340 --> 00:11:48,190
and come on back.

260
00:11:51,300 --> 00:11:54,750
Well, security incident often
has business implications

261
00:11:54,750 --> 00:11:57,813
and should be considered
a risk management issue.

262
00:11:58,680 --> 00:12:01,620
The IRT, the incident response
team should be expanded

263
00:12:01,620 --> 00:12:04,350
to include a cross section
of the organization

264
00:12:04,350 --> 00:12:07,440
including operations,
information security.

265
00:12:07,440 --> 00:12:09,480
It of course, are very important.

266
00:12:09,480 --> 00:12:13,230
Risk management, marketing,
legal, compliance,

267
00:12:13,230 --> 00:12:18,230
executive management and
potential external resources

268
00:12:18,690 --> 00:12:21,180
should be identified and documented,

269
00:12:21,180 --> 00:12:24,600
including forensic experts, legal counsel,

270
00:12:24,600 --> 00:12:26,490
insurance representatives,

271
00:12:26,490 --> 00:12:29,910
public relations and law enforcement.

272
00:12:29,910 --> 00:12:32,940
You never know when you might
need to call on one of them.

273
00:12:32,940 --> 00:12:35,550
So explaining this to your manager

274
00:12:35,550 --> 00:12:38,070
why it's not just an IT issue.

275
00:12:38,070 --> 00:12:40,980
Why an incident is absolutely

276
00:12:40,980 --> 00:12:45,000
a business risk management issue.

277
00:12:45,000 --> 00:12:46,530
Hopefully you get through.

278
00:12:46,530 --> 00:12:49,020
You get some changes
made and if you do that,

279
00:12:49,020 --> 00:12:51,150
that is security in action.

280
00:12:51,150 --> 00:12:53,430
There's your word cloud a lot there.

281
00:12:53,430 --> 00:12:54,930
You know what to do.

282
00:12:54,930 --> 00:12:57,570
When you're ready, go on
over to the next lesson,

283
00:12:57,570 --> 00:12:59,070
I'll be waiting for you there.
