1
00:00:06,480 --> 00:00:09,570
- Welcome to Lesson 21, Deep Dive Quiz.

2
00:00:09,570 --> 00:00:11,700
Now, Lesson 21 was all about explaining

3
00:00:11,700 --> 00:00:14,070
the appropriate incident
response activities.

4
00:00:14,070 --> 00:00:17,400
And in 21.1, we talked
about incident management;

5
00:00:17,400 --> 00:00:19,800
21.2, incident response;

6
00:00:19,800 --> 00:00:22,320
21.3, evidence handling;

7
00:00:22,320 --> 00:00:25,440
21.4, forensic examination;

8
00:00:25,440 --> 00:00:29,370
and 21.5, disclosure and notification;

9
00:00:29,370 --> 00:00:31,380
as well as information sharing.

10
00:00:31,380 --> 00:00:33,090
Covered a lotta material.

11
00:00:33,090 --> 00:00:33,923
So you ready?

12
00:00:33,923 --> 00:00:35,970
Together, we're gonna do 10 questions.

13
00:00:35,970 --> 00:00:38,850
Make sure you have a pen
or pencil, piece of paper,

14
00:00:38,850 --> 00:00:40,920
and keep putting me on pause as often

15
00:00:40,920 --> 00:00:43,770
as you need so you can be
answering the questions.

16
00:00:43,770 --> 00:00:45,220
All right, let's get started.

17
00:00:46,320 --> 00:00:48,180
Your organization is particularly worried

18
00:00:48,180 --> 00:00:50,010
about a ransomware attack.

19
00:00:50,010 --> 00:00:52,440
Which document would most likely be used

20
00:00:52,440 --> 00:00:55,200
to detail your response instructions?

21
00:00:55,200 --> 00:00:57,180
Incident management procedures,

22
00:00:57,180 --> 00:01:00,720
an incident playbook, an
incident response plan

23
00:01:00,720 --> 00:01:03,063
or an incident management policy.

24
00:01:04,440 --> 00:01:05,670
This is about ransomware.

25
00:01:05,670 --> 00:01:07,890
Which document would most likely be used

26
00:01:07,890 --> 00:01:10,203
to detail the response instructions?

27
00:01:11,700 --> 00:01:13,590
What are you gonna choose?

28
00:01:13,590 --> 00:01:16,170
I like incident playbook.

29
00:01:16,170 --> 00:01:18,540
That's the one I'm gonna choose because

30
00:01:18,540 --> 00:01:20,010
that's the one that's gonna allow us

31
00:01:20,010 --> 00:01:23,460
to be very, very specific in our details.

32
00:01:23,460 --> 00:01:26,550
Now, we also wanna have
an incident response plan,

33
00:01:26,550 --> 00:01:28,290
for sure, right, but that's gonna

34
00:01:28,290 --> 00:01:31,350
be sort of more overarching and generic.

35
00:01:31,350 --> 00:01:33,930
Incident management procedures
isn't specifically about

36
00:01:33,930 --> 00:01:35,700
how we respond, but really about how

37
00:01:35,700 --> 00:01:38,160
our whole incident management program is.

38
00:01:38,160 --> 00:01:40,110
And, of course, our
incident management policy

39
00:01:40,110 --> 00:01:42,210
is gonna be a very high-level document.

40
00:01:42,210 --> 00:01:45,000
So I'm going with playbook. You like it?

41
00:01:45,000 --> 00:01:46,440
Yeah, that's correct.

42
00:01:46,440 --> 00:01:47,273
Let's move on.

43
00:01:48,540 --> 00:01:50,340
All right, we are gonna
drag the appropriate words

44
00:01:50,340 --> 00:01:53,550
to best describe exercises and testing.

45
00:01:53,550 --> 00:01:55,530
So let's read this paragraph first.

46
00:01:55,530 --> 00:01:57,240
It's important to exercise and test

47
00:01:57,240 --> 00:01:58,980
incident response disaster recovery

48
00:01:58,980 --> 00:02:01,140
and business continuity plans.

49
00:02:01,140 --> 00:02:04,230
The objective of a blank
is to review procedures

50
00:02:04,230 --> 00:02:06,660
for completeness and accuracy.

51
00:02:06,660 --> 00:02:09,600
A blank is a scenario-based group workshop

52
00:02:09,600 --> 00:02:12,210
that focuses on the application of plans,

53
00:02:12,210 --> 00:02:14,790
as well as participant readiness.

54
00:02:14,790 --> 00:02:17,640
And a blank is a localized scenario

55
00:02:17,640 --> 00:02:19,860
that mimics an actual event.

56
00:02:19,860 --> 00:02:24,330
And formats include
surprise and preplanned.

57
00:02:24,330 --> 00:02:27,930
So we have walkthrough,
group, service provider,

58
00:02:27,930 --> 00:02:32,283
external, simulation and tabletop.

59
00:02:33,330 --> 00:02:35,550
So important to exercise and test

60
00:02:35,550 --> 00:02:37,470
our incidence response,
our disaster recovery,

61
00:02:37,470 --> 00:02:39,300
our business continuity plans.

62
00:02:39,300 --> 00:02:42,300
The objective of a blank
is to review procedures

63
00:02:42,300 --> 00:02:45,090
for completeness and accuracy.

64
00:02:45,090 --> 00:02:45,940
What do you like?

65
00:02:47,520 --> 00:02:50,313
I like a walkthrough.

66
00:02:51,660 --> 00:02:52,860
In a walkthrough, right,

67
00:02:52,860 --> 00:02:55,500
we're just walking through,
step by step by step,

68
00:02:55,500 --> 00:02:58,140
through our procedures, to
say, "Are these complete?

69
00:02:58,140 --> 00:02:59,280
Are these accurate?"

70
00:02:59,280 --> 00:03:01,080
Usually, that'll be done by an individual

71
00:03:01,080 --> 00:03:02,343
or by a department.

72
00:03:03,510 --> 00:03:06,930
A blank is a scenario-based group workshop

73
00:03:06,930 --> 00:03:09,660
that focuses on the application of plans,

74
00:03:09,660 --> 00:03:12,000
as well as participant readiness.

75
00:03:12,000 --> 00:03:15,270
So we're bringing a group together, right?

76
00:03:15,270 --> 00:03:18,060
We're sitting them all around a table.

77
00:03:18,060 --> 00:03:20,433
So how about a tabletop?

78
00:03:21,300 --> 00:03:24,150
A tabletop being a
scenario-based group workshop

79
00:03:24,150 --> 00:03:26,430
that focuses on the application of plans,

80
00:03:26,430 --> 00:03:29,040
as well as participant readiness.

81
00:03:29,040 --> 00:03:31,530
And then our last one, a blank

82
00:03:31,530 --> 00:03:33,450
is a localized scenario that mimics

83
00:03:33,450 --> 00:03:34,860
an actual event.

84
00:03:34,860 --> 00:03:38,133
Formats includes surprise and preplanned.

85
00:03:39,420 --> 00:03:42,660
I'm gonna go with simulation.

86
00:03:42,660 --> 00:03:43,680
Do you agree? You like those?

87
00:03:43,680 --> 00:03:45,540
Well, let's read through this.

88
00:03:45,540 --> 00:03:47,790
The objective of a walkthrough
is to review procedures

89
00:03:47,790 --> 00:03:49,560
for completeness and accuracy.

90
00:03:49,560 --> 00:03:52,830
A tabletop is a
scenario-based group workshop

91
00:03:52,830 --> 00:03:54,780
that focuses on the application of plans,

92
00:03:54,780 --> 00:03:56,520
as well as participant readiness.

93
00:03:56,520 --> 00:03:59,430
And a simulation is a localized scenario

94
00:03:59,430 --> 00:04:01,440
that mimics an actual event,

95
00:04:01,440 --> 00:04:05,370
and formats include
surprise and preplanned.

96
00:04:05,370 --> 00:04:06,570
Now, I didn't prompt you to put me

97
00:04:06,570 --> 00:04:07,500
on pause to do this.

98
00:04:07,500 --> 00:04:08,940
I hope you did or I hope you

99
00:04:08,940 --> 00:04:10,860
just worked it out right with me.

100
00:04:10,860 --> 00:04:13,200
Are you ready to check it? Let's see.

101
00:04:13,200 --> 00:04:14,343
And that is correct.

102
00:04:15,510 --> 00:04:17,700
All right, next question.

103
00:04:17,700 --> 00:04:21,090
Defines how cyber threat
information can be shared

104
00:04:21,090 --> 00:04:24,690
via services and message exchanges.

105
00:04:24,690 --> 00:04:27,810
Is this an ISAC, GDPR,

106
00:04:27,810 --> 00:04:30,810
TAXII or STIX?

107
00:04:30,810 --> 00:04:33,060
This defines how cyber threat information

108
00:04:33,060 --> 00:04:35,913
can be shared via services
and message exchanges.

109
00:04:37,140 --> 00:04:40,410
ISACs, GDPR, TAXII or STIX.

110
00:04:40,410 --> 00:04:42,683
Put me on pause if you
wanna think it through.

111
00:04:44,460 --> 00:04:47,640
Well, ISACs are, they're our
information-sharing groups,

112
00:04:47,640 --> 00:04:49,290
so it's not that one.

113
00:04:49,290 --> 00:04:53,370
GDPR is our general data
protection regulation, right?

114
00:04:53,370 --> 00:04:54,333
Not that one.

115
00:04:55,380 --> 00:04:56,880
TAXII. Hmm.

116
00:04:56,880 --> 00:04:59,830
TAXII really is about
how we share information

117
00:05:01,412 --> 00:05:02,790
via message exchanges.

118
00:05:02,790 --> 00:05:04,890
And STIX, well, STIX is actually

119
00:05:04,890 --> 00:05:06,870
the language that we used, right,

120
00:05:06,870 --> 00:05:10,050
to define the information
that we're gonna share.

121
00:05:10,050 --> 00:05:12,600
So I'm going to TAXII. You like it?

122
00:05:12,600 --> 00:05:14,130
Let's see.

123
00:05:14,130 --> 00:05:15,243
And that's correct.

124
00:05:16,620 --> 00:05:18,240
Which in the following is not

125
00:05:18,240 --> 00:05:21,060
an evidence collection imperative?

126
00:05:21,060 --> 00:05:24,330
Avoiding contamination,
creating a media clone,

127
00:05:24,330 --> 00:05:26,730
maintaining an evidentiary chain

128
00:05:26,730 --> 00:05:29,070
or acting in order of volatility.

129
00:05:29,070 --> 00:05:32,100
Three of these are absolutely definite

130
00:05:32,100 --> 00:05:34,320
evidence collection imperatives.

131
00:05:34,320 --> 00:05:35,340
One is not.

132
00:05:35,340 --> 00:05:36,540
Tell me which one isn't.

133
00:05:37,800 --> 00:05:40,373
Put me on pause if you wanna
read through this again.

134
00:05:41,940 --> 00:05:43,620
Well, avoiding contamination

135
00:05:43,620 --> 00:05:46,290
is an evidence collection imperative.

136
00:05:46,290 --> 00:05:48,390
Maintaining an evidentiary chain

137
00:05:48,390 --> 00:05:49,830
or a chain of custody,

138
00:05:49,830 --> 00:05:53,070
definitely a evidence
collection imperative.

139
00:05:53,070 --> 00:05:54,930
And acting in order of volatility,

140
00:05:54,930 --> 00:05:57,540
meaning collecting information or evidence

141
00:05:57,540 --> 00:05:59,610
before it disappears, is overwritten

142
00:05:59,610 --> 00:06:00,960
or no longer useful,

143
00:06:00,960 --> 00:06:03,750
is an evidence collection imperative.

144
00:06:03,750 --> 00:06:06,120
Creating a media clone, that's not done

145
00:06:06,120 --> 00:06:08,010
during the evidence collection stage.

146
00:06:08,010 --> 00:06:09,900
Creating the media clone would be done

147
00:06:09,900 --> 00:06:12,030
during the acquisition stage.

148
00:06:12,030 --> 00:06:14,820
So I'm gonna choose
creating a media clone.

149
00:06:14,820 --> 00:06:17,310
You agree? Let's check.

150
00:06:17,310 --> 00:06:18,363
And that's correct.

151
00:06:20,100 --> 00:06:21,660
My next question, why should

152
00:06:21,660 --> 00:06:25,113
media evidence hash
fingerprints be created?

153
00:06:25,980 --> 00:06:28,110
So why do we ever create a hash?

154
00:06:28,110 --> 00:06:31,590
To prove integrity, to
establish non-repudiation,

155
00:06:31,590 --> 00:06:34,440
to identify the examination technique

156
00:06:34,440 --> 00:06:37,620
or to maintain confidentiality.

157
00:06:37,620 --> 00:06:39,450
So why are we gonna have a media evidence

158
00:06:39,450 --> 00:06:42,120
hash fingerprint or a CRC,

159
00:06:42,120 --> 00:06:43,470
however we wanna call it?

160
00:06:43,470 --> 00:06:45,480
Kinda hash fingerprints,
a little bit redundant.

161
00:06:45,480 --> 00:06:47,790
It's like saying hash, hash
or fingerprint, fingerprint,

162
00:06:47,790 --> 00:06:49,560
but you get the idea.

163
00:06:49,560 --> 00:06:51,390
Why are we doing this?

164
00:06:51,390 --> 00:06:52,740
Oh, I think we all know, right?

165
00:06:52,740 --> 00:06:55,410
We do it to prove integrity.

166
00:06:55,410 --> 00:06:58,530
A hash or a CRC or a fingerprint, right,

167
00:06:58,530 --> 00:07:02,310
is a visual representation,
right, of the media.

168
00:07:02,310 --> 00:07:04,980
And we know that if
anything changes whatsoever

169
00:07:04,980 --> 00:07:07,470
when we make that next
hash or fingerprint,

170
00:07:07,470 --> 00:07:10,080
CRC, it will be different and we'll know

171
00:07:10,080 --> 00:07:11,310
that something changed.

172
00:07:11,310 --> 00:07:14,370
Or if it's the same, well,
we've proven the integrity.

173
00:07:14,370 --> 00:07:16,620
We know that everything has remained

174
00:07:16,620 --> 00:07:17,940
as it should be.

175
00:07:17,940 --> 00:07:18,773
Do you agree?

176
00:07:19,680 --> 00:07:21,573
Let's check. And that's correct.

177
00:07:22,440 --> 00:07:24,420
We're gonna arrange the evidence here

178
00:07:24,420 --> 00:07:26,940
in order of volatility.

179
00:07:26,940 --> 00:07:28,290
So we're gonna arrange the evidence

180
00:07:28,290 --> 00:07:29,670
in order of volatility.

181
00:07:29,670 --> 00:07:32,280
We'll start with number one.

182
00:07:32,280 --> 00:07:34,410
We have virtual memory, log files,

183
00:07:34,410 --> 00:07:36,840
RAM and static data.

184
00:07:36,840 --> 00:07:39,300
So if we're gonna collect virtual memory,

185
00:07:39,300 --> 00:07:41,550
log files, RAM and static data,

186
00:07:41,550 --> 00:07:44,370
what's the very first thing
that we're gonna collect?

187
00:07:44,370 --> 00:07:46,230
Then do the second, then the third,

188
00:07:46,230 --> 00:07:47,063
then the fourth.

189
00:07:47,063 --> 00:07:48,390
Definitely put me on pause for a moment

190
00:07:48,390 --> 00:07:49,590
and figure this one out.

191
00:07:51,120 --> 00:07:53,940
Well, the first thing
we're gonna collect is RAM.

192
00:07:53,940 --> 00:07:55,088
Why?

193
00:07:55,088 --> 00:07:56,580
'Cause we know that RAM
is easily degradable,

194
00:07:56,580 --> 00:07:58,140
that it gets overwritten,

195
00:07:58,140 --> 00:08:00,240
or it could end up not being useful.

196
00:08:00,240 --> 00:08:03,210
Or if we lose power, right,

197
00:08:03,210 --> 00:08:04,680
we're gonna lose what's in RAM.

198
00:08:04,680 --> 00:08:05,763
So first, RAM.

199
00:08:06,930 --> 00:08:08,910
Oh, number two is already there for us.

200
00:08:08,910 --> 00:08:10,470
Next, we're gonna do virtual memory,

201
00:08:10,470 --> 00:08:11,940
for really all of the same reasons

202
00:08:11,940 --> 00:08:14,520
that we collected RAM,
except that virtual memory,

203
00:08:14,520 --> 00:08:15,990
at least, is written to the drive,

204
00:08:15,990 --> 00:08:17,790
so we've got a little bit of better chance

205
00:08:17,790 --> 00:08:19,770
of keeping it around.

206
00:08:19,770 --> 00:08:22,230
After that, oh, already
right in our order.

207
00:08:22,230 --> 00:08:23,520
How about log files?

208
00:08:23,520 --> 00:08:26,070
The log files is written to static media,

209
00:08:26,070 --> 00:08:27,570
but we know that log files

210
00:08:27,570 --> 00:08:30,270
have a specific size
that they can grow to,

211
00:08:30,270 --> 00:08:32,940
so there's always the
possibility a log file

212
00:08:32,940 --> 00:08:34,650
is gonna get overwritten.

213
00:08:34,650 --> 00:08:36,540
And then, lastly, static data,

214
00:08:36,540 --> 00:08:38,670
which should not change.

215
00:08:38,670 --> 00:08:41,790
So our evidence in order
of volatility: RAM,

216
00:08:41,790 --> 00:08:45,600
virtual memory, log files, static data.

217
00:08:45,600 --> 00:08:46,800
Do you agree?

218
00:08:46,800 --> 00:08:48,510
All right, let's see.

219
00:08:48,510 --> 00:08:49,653
And that is correct.

220
00:08:52,380 --> 00:08:54,690
Okay, I want you to select the cluster

221
00:08:54,690 --> 00:08:57,060
that illustrates slack space.

222
00:08:57,060 --> 00:09:00,060
So we have three 4K clusters here.

223
00:09:00,060 --> 00:09:02,460
It looks like in the first cluster,

224
00:09:02,460 --> 00:09:05,550
we've got ones and zeros
throughout the whole cluster.

225
00:09:05,550 --> 00:09:07,620
The second cluster looks like it's empty,

226
00:09:07,620 --> 00:09:09,690
like it's never been written in.

227
00:09:09,690 --> 00:09:12,090
And the third 4K cluster looks like

228
00:09:12,090 --> 00:09:14,880
it has information in about,

229
00:09:14,880 --> 00:09:16,800
I don't know, 9/10 of it.

230
00:09:16,800 --> 00:09:19,140
It's been written to about 9/10 of it.

231
00:09:19,140 --> 00:09:20,940
So which one of these clusters

232
00:09:20,940 --> 00:09:23,520
illustrates slack space?

233
00:09:23,520 --> 00:09:24,600
All right, and make your choice.

234
00:09:24,600 --> 00:09:27,120
Are we gonna click on the first 4K,

235
00:09:27,120 --> 00:09:30,333
the middle 4K or the last 4K?

236
00:09:32,430 --> 00:09:34,583
Put me on pause if you
wanna think about it.

237
00:09:35,550 --> 00:09:38,220
I'm gonna click on the last 4K

238
00:09:38,220 --> 00:09:39,960
because this area right here,

239
00:09:39,960 --> 00:09:41,190
the area that's grayed out,

240
00:09:41,190 --> 00:09:42,990
that you don't see ones and zeros,

241
00:09:42,990 --> 00:09:44,700
that's gonna be the slack space.

242
00:09:44,700 --> 00:09:47,370
And that's the area where
we could potentially

243
00:09:47,370 --> 00:09:49,230
get parts of deleted files,

244
00:09:49,230 --> 00:09:51,750
recover parts of deleted files from.

245
00:09:51,750 --> 00:09:52,980
Let's check.

246
00:09:52,980 --> 00:09:54,453
And that is correct.

247
00:09:57,030 --> 00:09:58,770
All right, our next question.

248
00:09:58,770 --> 00:10:02,190
We want to arrange the
incident response phases

249
00:10:02,190 --> 00:10:04,050
in the correct order.

250
00:10:04,050 --> 00:10:06,810
So we've got detection, containment,

251
00:10:06,810 --> 00:10:09,540
eradication, lessons learned,

252
00:10:09,540 --> 00:10:13,170
validation and confirmation, and recovery.

253
00:10:13,170 --> 00:10:15,690
And we wanna arrange these
incident response plans

254
00:10:15,690 --> 00:10:16,680
in the correct order.

255
00:10:16,680 --> 00:10:19,620
So what's the first thing
that's gotta happen?

256
00:10:19,620 --> 00:10:22,470
Well, you gonna put me on
pause and figure it out?

257
00:10:22,470 --> 00:10:24,390
Go ahead and do that, if you want.

258
00:10:24,390 --> 00:10:26,190
All right, well, let's
do it together, then.

259
00:10:26,190 --> 00:10:27,300
We have detection.

260
00:10:27,300 --> 00:10:28,830
That's right up there
already as number one.

261
00:10:28,830 --> 00:10:30,990
That's the first thing
we're gonna do, right?

262
00:10:30,990 --> 00:10:32,880
After we have detected,
what do we do next,

263
00:10:32,880 --> 00:10:35,760
contain, eradicate, lessons learned,

264
00:10:35,760 --> 00:10:37,593
validation or recovery?

265
00:10:38,460 --> 00:10:40,110
Well, I think the next
thing we're gonna do

266
00:10:40,110 --> 00:10:42,210
is validation and confirmation

267
00:10:42,210 --> 00:10:44,220
that this really is an incident.

268
00:10:44,220 --> 00:10:46,350
Once we have confirmed it's an incident,

269
00:10:46,350 --> 00:10:47,340
what do we wanna do?

270
00:10:47,340 --> 00:10:48,780
Well, already, right there,

271
00:10:48,780 --> 00:10:50,373
we're gonna contain it, right?

272
00:10:51,600 --> 00:10:52,710
We don't want it to get any bigger.

273
00:10:52,710 --> 00:10:55,023
We wanna contain it, limit the damage.

274
00:10:56,340 --> 00:10:58,050
After that, oh, already there.

275
00:10:58,050 --> 00:10:59,343
We're gonna eradicate it.

276
00:11:00,750 --> 00:11:02,940
After eradication, what do we wanna do?

277
00:11:02,940 --> 00:11:05,610
Well, now we're gonna go
into our recovery phase

278
00:11:05,610 --> 00:11:07,740
and get everything back to normal.

279
00:11:07,740 --> 00:11:10,080
And then once everything
is back to normal,

280
00:11:10,080 --> 00:11:12,300
we're gonna do our lessons learned, right,

281
00:11:12,300 --> 00:11:14,400
so that we can say, "Why did this happen?

282
00:11:14,400 --> 00:11:16,200
Should we do anything
different in the future?

283
00:11:16,200 --> 00:11:18,540
Could we have prevented
this from happening?"

284
00:11:18,540 --> 00:11:21,090
So our correct order: detection,

285
00:11:21,090 --> 00:11:23,220
validation and confirmation,

286
00:11:23,220 --> 00:11:25,860
containment, eradication,

287
00:11:25,860 --> 00:11:28,050
recovery, lessons learned.

288
00:11:28,050 --> 00:11:31,200
You agree? Let's check.

289
00:11:31,200 --> 00:11:32,880
And that is correct.

290
00:11:32,880 --> 00:11:35,340
So question nine.

291
00:11:35,340 --> 00:11:38,430
This method of problem
solving is used to investigate

292
00:11:38,430 --> 00:11:41,790
known problems and identify what happened,

293
00:11:41,790 --> 00:11:44,490
and the underlying causes.

294
00:11:44,490 --> 00:11:46,200
Is this key performance indicators,

295
00:11:46,200 --> 00:11:49,980
also known as KPIs, a
cost-benefit analysis,

296
00:11:49,980 --> 00:11:52,800
a root cause analysis, known as an RCA,

297
00:11:52,800 --> 00:11:55,050
or a balanced scorecard?

298
00:11:55,050 --> 00:11:56,490
This was a method of problem solving

299
00:11:56,490 --> 00:11:58,770
that we used to investigate known problems

300
00:11:58,770 --> 00:12:02,130
and identify what happened
and the underlying causes.

301
00:12:02,130 --> 00:12:03,900
So not just the symptoms,

302
00:12:03,900 --> 00:12:06,000
but the underlying causes.

303
00:12:06,000 --> 00:12:08,010
So go ahead and put me
on pause, if you need,

304
00:12:08,010 --> 00:12:11,280
but if not, just go ahead
and choose that answer.

305
00:12:11,280 --> 00:12:14,100
Key performance indicators,
a cost-benefit analysis

306
00:12:14,100 --> 00:12:17,043
a root cause analysis
or a balanced scorecard.

307
00:12:18,990 --> 00:12:21,870
I'm gonna choose a root cause analysis

308
00:12:21,870 --> 00:12:25,440
because the underlying
causes, that's the root cause.

309
00:12:25,440 --> 00:12:27,750
And we really want to
identify what happened

310
00:12:27,750 --> 00:12:30,600
and the underlying causes
so they can prevent

311
00:12:30,600 --> 00:12:32,493
that problem from happening again.

312
00:12:34,020 --> 00:12:36,003
Let's check. And that's correct.

313
00:12:37,440 --> 00:12:38,850
All right, our last one.

314
00:12:38,850 --> 00:12:40,500
Responsibility for damages

315
00:12:40,500 --> 00:12:42,510
that result from a security compromise

316
00:12:42,510 --> 00:12:43,890
in your business.

317
00:12:43,890 --> 00:12:46,050
Is this downstream liability,

318
00:12:46,050 --> 00:12:48,840
due care, due diligence

319
00:12:48,840 --> 00:12:51,000
or a declaration?

320
00:12:51,000 --> 00:12:53,160
This is responsibility
for damages that result

321
00:12:53,160 --> 00:12:55,803
from a security compromise
in your business.

322
00:12:57,540 --> 00:12:59,100
What do you think?

323
00:12:59,100 --> 00:13:01,800
I introduced this term
to you in this lesson.

324
00:13:01,800 --> 00:13:03,480
Downstream liability, due care,

325
00:13:03,480 --> 00:13:05,673
due diligence or declaration.

326
00:13:08,670 --> 00:13:10,770
Well, due care is a standard of care

327
00:13:10,770 --> 00:13:13,200
that a reasonable person would exercise.

328
00:13:13,200 --> 00:13:15,060
Due diligence, remember, is doing

329
00:13:15,060 --> 00:13:20,060
our investigation before we
enter into a relationship,

330
00:13:20,100 --> 00:13:21,690
during the life of a relationship,

331
00:13:21,690 --> 00:13:24,453
and definitely before we renew a contract.

332
00:13:25,410 --> 00:13:27,900
Declaration, that's just kind of a term

333
00:13:27,900 --> 00:13:29,760
thrown in here, I think.

334
00:13:29,760 --> 00:13:32,220
Downstream liability,
that's what I'm going with.

335
00:13:32,220 --> 00:13:34,350
The responsibility for damages that result

336
00:13:34,350 --> 00:13:35,610
from a security compromise

337
00:13:35,610 --> 00:13:38,160
in your business that would impact others

338
00:13:38,160 --> 00:13:40,080
right, downstream, right?

339
00:13:40,080 --> 00:13:43,140
And the responsibility
for damages is liability.

340
00:13:43,140 --> 00:13:44,940
So downstream liability,

341
00:13:44,940 --> 00:13:46,230
that's what we're gonna go with.

342
00:13:46,230 --> 00:13:48,330
You agree? Let's check.

343
00:13:48,330 --> 00:13:49,350
And that is correct.

344
00:13:49,350 --> 00:13:51,330
Awesome. Great job.

345
00:13:51,330 --> 00:13:53,880
All right, up next, Lesson 22.

346
00:13:53,880 --> 00:13:56,460
Given a scenario, we're
gonna use data sources

347
00:13:56,460 --> 00:13:58,353
to support an investigation.

348
00:13:59,610 --> 00:14:00,560
I'll see you there.
