1
00:00:06,480 --> 00:00:09,360
- In this lesson, 21.5, we're gonna focus

2
00:00:09,360 --> 00:00:13,443
on disclosure if there is an
incident and notification.

3
00:00:14,520 --> 00:00:16,410
Now, a data breach is an incident

4
00:00:16,410 --> 00:00:19,770
where unauthorized individuals
or entities gain access

5
00:00:19,770 --> 00:00:23,280
to legally protected or
confidential information stored

6
00:00:23,280 --> 00:00:27,630
by an organization resulting
in potential misuse, loss,

7
00:00:27,630 --> 00:00:30,960
theft, or exposure of that data.

8
00:00:30,960 --> 00:00:33,510
Now, specific types of
information compromised

9
00:00:33,510 --> 00:00:36,690
in a data breach can vary
depending upon the industry,

10
00:00:36,690 --> 00:00:39,630
the organization, and the
attacker's objectives.

11
00:00:39,630 --> 00:00:42,840
So examples include personally
identifiable information

12
00:00:42,840 --> 00:00:46,590
or PII, login credentials,
government records,

13
00:00:46,590 --> 00:00:50,690
payment card information, PCI,
personal health information,

14
00:00:50,690 --> 00:00:54,540
PHI, trade secrets or
intellectual property.

15
00:00:54,540 --> 00:00:57,870
Now, a security incident is
also considered a data breach

16
00:00:57,870 --> 00:01:00,810
if there is a loss of
control of the system

17
00:01:00,810 --> 00:01:02,433
that the data is stored upon.

18
00:01:04,350 --> 00:01:07,710
Now, the dark web is part of
the internet that's not indexed

19
00:01:07,710 --> 00:01:12,540
by search engines, and it's
known for its anonymity.

20
00:01:12,540 --> 00:01:16,200
That compromised data often
ends up on the dark web

21
00:01:16,200 --> 00:01:18,330
after a data breach occurs.

22
00:01:18,330 --> 00:01:21,870
The dark web hosts various
illicit marketplaces

23
00:01:21,870 --> 00:01:26,870
and forms where stolen data is
bought, sold, and exchanged.

24
00:01:26,910 --> 00:01:30,690
These marketplaces provide a
platform for cyber criminals

25
00:01:30,690 --> 00:01:34,140
to profit from the data
obtained through data breaches.

26
00:01:34,140 --> 00:01:38,310
Now, they may offer databases
of compromised information

27
00:01:38,310 --> 00:01:42,153
or sell individual records
to interested buyers.

28
00:01:45,540 --> 00:01:48,030
So let's say you've had a data breach.

29
00:01:48,030 --> 00:01:49,770
What do you do, do you have to disclose

30
00:01:49,770 --> 00:01:51,030
that you've had a data breach?

31
00:01:51,030 --> 00:01:53,610
Do you have to notify
impacted individuals?

32
00:01:53,610 --> 00:01:55,620
Well, it's going to depend.

33
00:01:55,620 --> 00:01:58,920
It's going to depend on
one, your jurisdiction.

34
00:01:58,920 --> 00:02:01,710
And as a refresher,
jurisdiction is an area

35
00:02:01,710 --> 00:02:03,300
of legal authority.

36
00:02:03,300 --> 00:02:06,810
In relation to cyber, jurisdiction
pertains to the location

37
00:02:06,810 --> 00:02:09,240
of the data and systems in all its forms,

38
00:02:09,240 --> 00:02:11,880
processing, transmission, and storage,

39
00:02:11,880 --> 00:02:15,210
the residence of the data
owners, the type of data,

40
00:02:15,210 --> 00:02:17,700
and the residence of the data subjects.

41
00:02:17,700 --> 00:02:19,920
Now, jurisdictional requirements

42
00:02:19,920 --> 00:02:23,553
may necessitate disclosure
and notification.

43
00:02:25,860 --> 00:02:29,640
And disclosure is a requirement
to reveal a situation.

44
00:02:29,640 --> 00:02:31,770
Notification is the actual act

45
00:02:31,770 --> 00:02:34,380
of informing affected parties.

46
00:02:34,380 --> 00:02:37,140
Now, the purpose of
disclosure and notification

47
00:02:37,140 --> 00:02:39,900
is to inform others of potential risk

48
00:02:39,900 --> 00:02:42,150
so they can make informed decisions

49
00:02:42,150 --> 00:02:44,193
and take appropriate action.

50
00:02:46,080 --> 00:02:48,840
Organizations have an obligation to comply

51
00:02:48,840 --> 00:02:52,860
with regulatory and
contractual requirements.

52
00:02:52,860 --> 00:02:55,560
Now, here in the US, all
states and territories

53
00:02:55,560 --> 00:02:59,580
have enacted data breach
notification legislation.

54
00:02:59,580 --> 00:03:01,800
We don't have one at the national level.

55
00:03:01,800 --> 00:03:03,780
Each one of our states and each

56
00:03:03,780 --> 00:03:05,970
of our territories have all enacted

57
00:03:05,970 --> 00:03:08,490
their own data breach
notification legislation.

58
00:03:08,490 --> 00:03:10,200
And what's crazy is that many

59
00:03:10,200 --> 00:03:12,360
of them conflict with each other.

60
00:03:12,360 --> 00:03:13,380
At the federal level,

61
00:03:13,380 --> 00:03:16,290
we have some sector-specific
security legislation.

62
00:03:16,290 --> 00:03:18,960
So for example, Gramm-Leach-Bliley, GLBA,

63
00:03:18,960 --> 00:03:21,330
and HIPAA have risk assessment

64
00:03:21,330 --> 00:03:23,490
and breach notification requirements,

65
00:03:23,490 --> 00:03:27,330
GLBA for a breach of
financial information,

66
00:03:27,330 --> 00:03:30,120
HIPAA for a breach of
healthcare information.

67
00:03:30,120 --> 00:03:32,490
Now, the EU/EEA GDPR,

68
00:03:32,490 --> 00:03:34,860
that's General Data Protection Regulation,

69
00:03:34,860 --> 00:03:37,350
has very, very stringent breach disclosure

70
00:03:37,350 --> 00:03:39,420
and notification requirements.

71
00:03:39,420 --> 00:03:41,820
The Payment Card Industry
Data Security Standard,

72
00:03:41,820 --> 00:03:45,180
PCI-DSS, has breach
notification requirements,

73
00:03:45,180 --> 00:03:46,590
so if you handle credit cards,

74
00:03:46,590 --> 00:03:48,540
you are responsible to comply with that.

75
00:03:48,540 --> 00:03:51,690
And then you just may have
other contractual obligations

76
00:03:51,690 --> 00:03:53,823
that have notification requirements.

77
00:03:55,320 --> 00:03:59,130
Now, aside from notifying
from a regulatory perspective,

78
00:03:59,130 --> 00:04:01,800
you may also wanna share information

79
00:04:01,800 --> 00:04:04,290
with other trusted parties.

80
00:04:04,290 --> 00:04:06,630
So information sharing describes a means

81
00:04:06,630 --> 00:04:09,420
of conveying information or experience

82
00:04:09,420 --> 00:04:11,433
from one trusted party to another.

83
00:04:13,080 --> 00:04:15,480
In the US, we have what's known as ISACs,

84
00:04:15,480 --> 00:04:18,240
Information Sharing and Analysis Centers.

85
00:04:18,240 --> 00:04:21,480
And those are trusted
sector-specific entities

86
00:04:21,480 --> 00:04:23,880
that facilitate sector-specific

87
00:04:23,880 --> 00:04:27,570
and/or geographic specific
information sharing

88
00:04:27,570 --> 00:04:29,850
about vulnerabilities, threats,

89
00:04:29,850 --> 00:04:32,640
and incidents including data breaches.

90
00:04:32,640 --> 00:04:34,860
Now, there are 20 plus ISACs that range

91
00:04:34,860 --> 00:04:37,530
from an aviation ISAC to a water ISAC,

92
00:04:37,530 --> 00:04:39,060
and if you wanna learn more about them,

93
00:04:39,060 --> 00:04:41,880
you can go out to nationalisacs.org.

94
00:04:41,880 --> 00:04:44,250
They're industry-specific,
but they also have some

95
00:04:44,250 --> 00:04:46,203
that are geographically-specific.

96
00:04:47,400 --> 00:04:50,010
Now, ISACs, government and agencies

97
00:04:50,010 --> 00:04:53,610
and industry actually uses STIX and TAXII,

98
00:04:53,610 --> 00:04:55,470
we're gonna talk about
those in just a second,

99
00:04:55,470 --> 00:04:58,350
to facilitate the exchange and the sharing

100
00:04:58,350 --> 00:05:00,600
of threat intelligence information.

101
00:05:00,600 --> 00:05:03,450
Now, you may not wanna share the specifics

102
00:05:03,450 --> 00:05:07,620
of the data that may have been breached,

103
00:05:07,620 --> 00:05:09,630
but what you may wanna be sharing, right,

104
00:05:09,630 --> 00:05:11,940
is how did it happen, what happened?

105
00:05:11,940 --> 00:05:13,920
What do you see for
indicators of compromise?

106
00:05:13,920 --> 00:05:15,960
What do you see for indicators of attack?

107
00:05:15,960 --> 00:05:18,060
All of that is great information

108
00:05:18,060 --> 00:05:20,523
to share in a trusted forum.

109
00:05:23,790 --> 00:05:27,300
So STIX is Structured Threat
Information Expression

110
00:05:27,300 --> 00:05:30,030
and TAXII is Trusted Automation Exchange

111
00:05:30,030 --> 00:05:32,070
of Intelligence Information.

112
00:05:32,070 --> 00:05:33,990
So these are two components

113
00:05:33,990 --> 00:05:36,660
of automated information sharing.

114
00:05:36,660 --> 00:05:40,680
STIX is the standardized
language developed by MITRE

115
00:05:40,680 --> 00:05:44,820
and the OASIS Cyber Threat
Intelligence, or CTI,

116
00:05:44,820 --> 00:05:49,680
technical committee for describing
cyber threat information.

117
00:05:49,680 --> 00:05:53,370
STIX is structured to
describe a threat in terms

118
00:05:53,370 --> 00:05:57,633
of motivations, abilities,
capabilities, and response.

119
00:05:59,070 --> 00:06:02,280
Where TAXII defines how
cyber threat information

120
00:06:02,280 --> 00:06:06,630
can be shared via services
and message exchanges

121
00:06:06,630 --> 00:06:09,840
by defining an API, an
application programming interface.

122
00:06:09,840 --> 00:06:11,880
And it's designed to specifically

123
00:06:11,880 --> 00:06:14,010
to support STIX information.

124
00:06:14,010 --> 00:06:16,470
And there are three
principle models in TAXII

125
00:06:16,470 --> 00:06:19,410
which include hub and spoke,
where there's one repository

126
00:06:19,410 --> 00:06:21,660
of information, source and subscriber,

127
00:06:21,660 --> 00:06:23,940
where we have a single
source of information,

128
00:06:23,940 --> 00:06:27,663
and peer-to-peer, we have
multiple groups share information.

129
00:06:30,300 --> 00:06:31,830
If you have a data breach

130
00:06:31,830 --> 00:06:35,370
or before you share information
even with trusted parties,

131
00:06:35,370 --> 00:06:37,920
you may wanna consider
working with legal counsel.

132
00:06:37,920 --> 00:06:39,600
And there are several scenarios

133
00:06:39,600 --> 00:06:42,450
that consulting with legal
counsel before acting

134
00:06:42,450 --> 00:06:45,180
is really, really highly recommended.

135
00:06:45,180 --> 00:06:47,130
So if there's a possibility that legally

136
00:06:47,130 --> 00:06:50,010
or contractually protected
information has been exposed

137
00:06:50,010 --> 00:06:52,740
or compromised, call legal counsel.

138
00:06:52,740 --> 00:06:54,900
If there's a potential violation

139
00:06:54,900 --> 00:06:57,060
of a contract or a legal agreement,

140
00:06:57,060 --> 00:07:00,750
including internal negligence,
call legal counsel.

141
00:07:00,750 --> 00:07:03,270
if there is potential
downstream liability,

142
00:07:03,270 --> 00:07:05,400
what do we mean by downstream liability?

143
00:07:05,400 --> 00:07:08,280
Downstream liability is a
responsibility for damages

144
00:07:08,280 --> 00:07:11,880
that result from a security
compromise in your business.

145
00:07:11,880 --> 00:07:13,920
You're gonna wanna call legal counsel.

146
00:07:13,920 --> 00:07:17,250
if you get notification from
a third party service provider

147
00:07:17,250 --> 00:07:20,400
or from a customer that they've
experienced an incident,

148
00:07:20,400 --> 00:07:22,020
call legal counsel.

149
00:07:22,020 --> 00:07:23,610
And if you've been contacted by

150
00:07:23,610 --> 00:07:26,100
or you plan to contact law enforcement,

151
00:07:26,100 --> 00:07:29,520
definitely you want to
contact legal counsel.

152
00:07:29,520 --> 00:07:30,360
Now, you wanna make sure

153
00:07:30,360 --> 00:07:32,070
that you're contacting legal counsel

154
00:07:32,070 --> 00:07:36,180
who has expertise in
security and specifically

155
00:07:36,180 --> 00:07:39,303
in data breach notification
and disclosure.

156
00:07:41,100 --> 00:07:43,620
There may be scenarios
where you need to work

157
00:07:43,620 --> 00:07:46,140
with law enforcement, but bear in mind

158
00:07:46,140 --> 00:07:50,040
that the primary focus of law
enforcement is to identify,

159
00:07:50,040 --> 00:07:52,830
catch, and prosecute criminals.

160
00:07:52,830 --> 00:07:55,260
They probably won't get
your data back or, you know,

161
00:07:55,260 --> 00:07:58,080
deal with the extortion
demand in itself, right,

162
00:07:58,080 --> 00:08:02,103
they're looking to identify,
catch, and prosecute criminals.

163
00:08:03,390 --> 00:08:06,870
Now, while generally helpful,
right, they have no obligation

164
00:08:06,870 --> 00:08:10,350
to recover that stolen funds or property.

165
00:08:10,350 --> 00:08:12,750
You do wanna consult in with legal counsel

166
00:08:12,750 --> 00:08:14,760
before calling law enforcement.

167
00:08:14,760 --> 00:08:17,070
Once you contact them, they can confiscate

168
00:08:17,070 --> 00:08:19,920
what they will call crime scene evidence.

169
00:08:19,920 --> 00:08:22,830
That means they can take a
drive, they can take a machine,

170
00:08:22,830 --> 00:08:26,220
they can take a device,
they can take a router,

171
00:08:26,220 --> 00:08:28,320
they can take control of your server room.

172
00:08:29,940 --> 00:08:32,850
And they also may ask
you to allow an attack,

173
00:08:32,850 --> 00:08:35,160
if you're under an attack, to continue

174
00:08:35,160 --> 00:08:36,720
while they investigate.

175
00:08:36,720 --> 00:08:38,250
But unless court-ordered,

176
00:08:38,250 --> 00:08:40,803
you do not have to
comply with this request.

177
00:08:41,700 --> 00:08:44,400
And here's the last thing
you need to keep in mind.

178
00:08:44,400 --> 00:08:47,010
They have no obligation
to keep you updated

179
00:08:47,010 --> 00:08:50,340
on their investigation,
and in my experience,

180
00:08:50,340 --> 00:08:51,453
they probably won't.

181
00:08:52,860 --> 00:08:53,700
All right, that, my friends,

182
00:08:53,700 --> 00:08:55,260
brings us to a three-second challenge,

183
00:08:55,260 --> 00:08:58,710
five challenge questions, three
seconds each, let's do it.

184
00:08:58,710 --> 00:09:00,840
Incident that results in the disclosure

185
00:09:00,840 --> 00:09:03,780
of data or loss of control.

186
00:09:03,780 --> 00:09:05,463
One, two, three.

187
00:09:06,720 --> 00:09:08,730
It's gonna be a data breach.

188
00:09:08,730 --> 00:09:11,973
Number two, an area of legal authority.

189
00:09:12,810 --> 00:09:14,550
One, two, three.

190
00:09:14,550 --> 00:09:15,573
Jurisdiction.

191
00:09:17,070 --> 00:09:20,190
Number three, the EU/EEA regulation

192
00:09:20,190 --> 00:09:22,380
that has very stringent breach disclosures

193
00:09:22,380 --> 00:09:24,213
and notification requirements.

194
00:09:25,200 --> 00:09:27,240
One, two, three.

195
00:09:27,240 --> 00:09:29,193
That's gonna be GDPR.

196
00:09:30,690 --> 00:09:34,380
Number four, a trusted
sector-specific entity

197
00:09:34,380 --> 00:09:36,780
that facilitates information sharing

198
00:09:36,780 --> 00:09:41,280
about vulnerabilities,
threats, and incidents.

199
00:09:41,280 --> 00:09:42,813
One, two, three.

200
00:09:44,280 --> 00:09:46,050
That's gonna be an ISAC.

201
00:09:46,050 --> 00:09:49,770
And lastly, number five,
standardized language developed

202
00:09:49,770 --> 00:09:52,833
for describing cyber threat information.

203
00:09:54,000 --> 00:09:55,443
One, two, three.

204
00:09:56,700 --> 00:09:58,143
And that's gonna be STIX.

205
00:09:59,730 --> 00:10:01,230
All right, let's do a security-in-action

206
00:10:01,230 --> 00:10:02,700
about a data breach.

207
00:10:02,700 --> 00:10:05,880
You just received a call
from your very panicked boss.

208
00:10:05,880 --> 00:10:08,910
She just got off the phone with
an investigative journalist

209
00:10:08,910 --> 00:10:11,400
who informed her that there is a cache

210
00:10:11,400 --> 00:10:14,040
of your organization's
customer information

211
00:10:14,040 --> 00:10:16,350
for sale on the dark web.

212
00:10:16,350 --> 00:10:19,140
He sends her a snippet as evidence.

213
00:10:19,140 --> 00:10:22,230
She's asking you what should she do.

214
00:10:22,230 --> 00:10:24,450
So what are your recommendations?

215
00:10:24,450 --> 00:10:28,290
So your boss just calls you
really, really panicked.

216
00:10:28,290 --> 00:10:30,660
Just heard from an
investigative journalist

217
00:10:30,660 --> 00:10:32,100
who said that there's a cache

218
00:10:32,100 --> 00:10:35,160
of your organization's
customer information

219
00:10:35,160 --> 00:10:36,423
for sale on the web.

220
00:10:37,920 --> 00:10:41,040
And to prove it, he sends
her a snippet of evidence.

221
00:10:41,040 --> 00:10:42,360
And she goes to you and it's like,

222
00:10:42,360 --> 00:10:44,370
oh my God, what should I do?

223
00:10:44,370 --> 00:10:46,770
So the question for you is,
what are your recommendations?

224
00:10:46,770 --> 00:10:49,290
Go ahead and put me on pause,
jot some recommendations down,

225
00:10:49,290 --> 00:10:50,313
then come on back.

226
00:10:52,710 --> 00:10:55,470
Well, the very first
action should be to inform

227
00:10:55,470 --> 00:10:57,930
and involve executive management.

228
00:10:57,930 --> 00:11:01,050
I don't know how far down
or up the chain your boss is

229
00:11:01,050 --> 00:11:03,660
or you are, but we wanna
go right to the top.

230
00:11:03,660 --> 00:11:06,120
We're gonna inform and
involve executive management

231
00:11:06,120 --> 00:11:08,320
and probably the board
of directors as well.

232
00:11:09,420 --> 00:11:11,520
Now, executive management should reach out

233
00:11:11,520 --> 00:11:14,733
to legal counsel for guidance,
always a great first step.

234
00:11:15,570 --> 00:11:19,290
It's then time to activate
your incident response plan,

235
00:11:19,290 --> 00:11:22,530
right, including how you
interact with law enforcements,

236
00:11:22,530 --> 00:11:24,750
'cause you're gonna wanna
contact law enforcement,

237
00:11:24,750 --> 00:11:26,970
and your crisis communication plan.

238
00:11:26,970 --> 00:11:29,730
How are you gonna be talking
about this both internally

239
00:11:29,730 --> 00:11:31,560
and externally?

240
00:11:31,560 --> 00:11:33,270
In best case, you have prepared

241
00:11:33,270 --> 00:11:37,080
for disclosure notification
by already understanding all

242
00:11:37,080 --> 00:11:38,580
of your applicable jurisdictions,

243
00:11:38,580 --> 00:11:39,990
that you've done a massive whiteboard

244
00:11:39,990 --> 00:11:42,780
and you understand all the
jurisdictions that apply to you

245
00:11:42,780 --> 00:11:46,170
as well as all of your
compliance requirements.

246
00:11:46,170 --> 00:11:48,300
And then lastly, you might wanna consider

247
00:11:48,300 --> 00:11:50,850
sharing threat intelligence
about your attack

248
00:11:50,850 --> 00:11:54,870
with applicable agencies
and trusted organizations.

249
00:11:54,870 --> 00:11:57,240
There's your word cloud.
Boy, there's a lot here.

250
00:11:57,240 --> 00:11:59,880
Make sure that you know,
right, all of these terms,

251
00:11:59,880 --> 00:12:01,410
all of the concepts,
you can speak to them,

252
00:12:01,410 --> 00:12:03,570
you can explain them, you're
comfortable with them.

253
00:12:03,570 --> 00:12:06,630
And then when you're ready,
you're confident, right,

254
00:12:06,630 --> 00:12:08,070
you're ready to go.

255
00:12:08,070 --> 00:12:10,800
Next, we're gonna do a 10-question quiz.

256
00:12:10,800 --> 00:12:11,750
I'll see you there.
