Educause Security Discussion mailing list archives
Re: Ransomware Playbook
From: John Ramsey <jramsey () STUDENTCLEARINGHOUSE ORG>
Date: Tue, 14 Jan 2020 17:18:15 +0000
I’m also working on getting clearance to share a few more. John Ramsey, Chief Information Security Officer, National Student Clearinghouse Certified: CISSP, CISM, PMP, CSSLP, CRISC, CGEIT 2300 Dulles Station Blvd., Suite 220, Herndon, VA 20171 P: 703.742.4428 | http://www.studentclearinghouse.org<https://nam01.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwww.studentclearinghouse.org%2F&data=02%7C01%7Cjramsey%40studentclearinghouse.org%7Cb9a990ac212442f4966708d7307ccb81%7C8cc02fea054043a688b6069d3eac0119%7C0%7C1%7C637031184868460784&sdata=rnlj9A1ay7hmHTLXDAE0sESGGvBVWkPDO3NekqwvRIM%3D&reserved=0> Read the Clearinghouse Today Blog<https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fnscblog.org%2F&data=02%7C01%7Cjramsey%40studentclearinghouse.org%7Cb9a990ac212442f4966708d7307ccb81%7C8cc02fea054043a688b6069d3eac0119%7C0%7C1%7C637031184868460784&sdata=%2BIijkuOIRKNNuBeLyoZeeSAuxkRsldvCfMOFWXWf7wQ%3D&reserved=0> Winner “2016 When Work Works” & “Excellence in Work-Life Balance” From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU> On Behalf Of Francisco Chavez Sent: Tuesday, January 14, 2020 11:15 AM To: SECURITY () LISTSERV EDUCAUSE EDU Subject: Re: [SECURITY] Ransomware Playbook Paul, It is available here. https://library.educause.edu/resources/2019/10/national-student-clearinghouse-playbooks Regards, Francisco Chavez [cid:image001.jpg@01D5CAD4.B18F1740] Manager - IT Security fac3 () stmarys-ca edu<mailto:fac3 () stmarys-ca edu> Office: (925) 631-8236 On Jan 14, 2020, at 8:00 AM, Paul Usama <paul.usama () SAIT CA<mailto:paul.usama () SAIT CA>> wrote: Hi, Am not sure if this is still shared, I am interested in the Ransomware Playbook. <image002.jpg> Paul Usama Information Security Analyst Information Technology Services Southern Alberta Institute of Technology E.H. Crandell, G200 1301 – 16 Avenue NW, Calgary AB, T2M 0L4 (Cell) 403.836.3489 (Ph) 403.284.8328 Paul.Usama () sait ca<mailto:Paul.Usama () sait ca> From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU>> On Behalf Of Jamie Schademan Sent: Friday, October 4, 2019 11:08 AM To: SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU> Subject: Re: [SECURITY] Ransomware Playbook Me too please. Jamie CWU Jamie Schademan, CISM Chief Information Security Officer CWU ________________________________ From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU>> on behalf of Oberlin, Craig <coberlin1 () CCCD EDU<mailto:coberlin1 () CCCD EDU>> Sent: Friday, October 4, 2019 11:03:02 AM To: SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU> <SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU>> Subject: Re: [SECURITY] Ransomware Playbook Caution: This email originated from outside the university. Do not click on links, open attachments, or reply unless you recognize the sender and know the content is safe. If you have questions about this email please forward it tocwuservicedesk () cwu edu<mailto:cwuservicedesk () cwu edu>. John, My thanks and I would appreciate copies as well. Craig Craig Oberlin, CISSP Sr. Director IT, Users Services & Chief Information Security Officer Coast Community College District P 714.438.6808 coberlin1 () cccd edu<mailto:coberlin1 () cccd edu> <image001.png> From: The EDUCAUSE Security Community Group Listserv [mailto:SECURITY () LISTSERV EDUCAUSE EDU] On Behalf Of Babak Oskouian Sent: Friday, October 4, 2019 9:49 AM To: SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU> Subject: Re: [SECURITY] Ransomware Playbook Hi John, It goes without saying that you and your team must have done a tremendous amount of work to put these playbooks together and it is very generous of you to be willing to share them with the community. So, thank you very much indeed. Babak Babak Oskouian, Ph.D. | Director of Networking and Infrastructure Mills College | 5000 MacArthur Blvd | Oakland, CA 94613-1301 Office: Stern Hall 007; Phone: 510-430-2224 <tel:510-430-2224> On Fri, Oct 4, 2019 at 4:47 AM John Ramsey <jramsey () studentclearinghouse org<mailto:jramsey () studentclearinghouse org>> wrote: Everybody, The interest in playbooks, especially ransomware, is great to see (as playbooks are time consuming to create and there aren’t enough hours in the day as it is). I’ve been through a few ransomware incidents, so the playbook is battle ready. However, as some have pointed out, you’ll want to customize to your organization where applicable. When my team creates playbooks, our goal is to keep it simple and flexible and easy to follow (versus flipping back and forth as you might in a plan.) The first page is almost always how to easily and quickly contain and then triage. Once that is done, the rest is post event activities. If you have any questions, please don’t hesitate to ask me. Since the NSC is a third-party service provider for most of you, I’m happy to share what we’re doing in order to further gain your confidence in our processes to protect your data. At the end of the day, we’re one team! We also have other playbooks that I’m happy to share (maybe it makes sense for Educause or REN-ISAC or both to post what all of us are willing to share amongst ourselves. Then we’ll have a pretty robust set to select from and modify as appropriate). Here are some others that we have finalized: 1. Notifications and Escalations Playbook. This walks through the first six hours of an incident in 30-minute increments indicating what each stakeholder is doing as well as what message gets communicated and to whom. 2. DDOS Playbook. Being one of the top attacks in the Education industry, this was one of the first ones we did. Internet 2 was kind enough to provide some guidance on the playbook (which we incorporated.) 3. Foreign Travel Playbook. Actions we take when somebody travels overseas and has the requirement to take a company device. 4. Incident Handling Checklists/Chains of Custody forms. 5. Network Compromise Playbook. 6. Spoofed URL Playbook. John John Ramsey, Chief Information Security Officer, National Student Clearinghouse Certified: CISSP, CISM, PMP, CSSLP, CRISC, CGEIT 2300 Dulles Station Blvd., Suite 220, Herndon, VA 20171 P: 703.742.4428 | http://www.studentclearinghouse.org<https://urldefense.proofpoint.com/v2/url?u=http-3A__www.studentclearinghouse.org_&d=DwMFaQ&c=fH4LSaxSgjWoCqli9ejpOKSimqfdcqwvdi9ZfjV67eI&r=L2JLRtXHlhmcrIANbzJ5bJIItX7BypJgN7IAY1kklS0&m=0-1lrb9bNf5O_UNDlxFb2Xqz31Z6UafxAW4sVo70TsY&s=6KKsFoIKTYgAD7pi6C5TjYlGRwjXxnpP9eNEoUg6tCk&e=> Read the Clearinghouse Today Blog<https://urldefense.proofpoint.com/v2/url?u=https-3A__nscblog.org_&d=DwMFaQ&c=fH4LSaxSgjWoCqli9ejpOKSimqfdcqwvdi9ZfjV67eI&r=L2JLRtXHlhmcrIANbzJ5bJIItX7BypJgN7IAY1kklS0&m=0-1lrb9bNf5O_UNDlxFb2Xqz31Z6UafxAW4sVo70TsY&s=br2kQUxQhQEaZoZzMS3ZTNXObY1JGi_7GUtwR3uC7kg&e=> Winner “2016 When Work Works” & “Excellence in Work-Life Balance” ********** Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the person who sent the message, copy and paste their email address and forward the email reply. Additional participation and subscription information can be found at https://www.educause.edu/community<https://urldefense.proofpoint.com/v2/url?u=https-3A__www.educause.edu_community&d=DwMFaQ&c=fH4LSaxSgjWoCqli9ejpOKSimqfdcqwvdi9ZfjV67eI&r=L2JLRtXHlhmcrIANbzJ5bJIItX7BypJgN7IAY1kklS0&m=0-1lrb9bNf5O_UNDlxFb2Xqz31Z6UafxAW4sVo70TsY&s=DhYpkgwVTyvpma9kqNW0oPJOoD9fGCjPJNYoFsmlsjU&e=> ------------------------------------------------------------------------------------- *** NOTICE *** This message was sent from an external sender and did not originate from Coast Community College District. If you are unsure of the authenticity of the sender, DO NOT click any links or download any attachments. Instead, click on FORWARD and address to phishing ********** Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the person who sent the message, copy and paste their email address and forward the email reply. Additional participation and subscription information can be found at https://www.educause.edu/community ********** Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the person who sent the message, copy and paste their email address and forward the email reply. Additional participation and subscription information can be found at https://www.educause.edu/community ********** Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the person who sent the message, copy and paste their email address and forward the email reply. Additional participation and subscription information can be found at https://www.educause.edu/community ********** Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the person who sent the message, copy and paste their email address and forward the email reply. Additional participation and subscription information can be found at https://www.educause.edu/community ********** Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the person who sent the message, copy and paste their email address and forward the email reply. Additional participation and subscription information can be found at https://www.educause.edu/community
Current thread:
- Re: Ransomware Playbook Paul Usama (Jan 14)
- Re: Ransomware Playbook Francisco Chavez (Jan 14)
- Re: Ransomware Playbook John Ramsey (Jan 14)
- Re: Ransomware Playbook Paul Usama (Jan 14)
- Re: Ransomware Playbook Francisco Chavez (Jan 14)