Time
1 hour 34 minutes
Difficulty
Advanced
CEU/CPE
1

Video Transcription

00:00
in this lesson, we'll talk about the importance of backing up case data
00:05
timeframes for data backup,
00:08
incremental versus full verses, differential backups
00:12
and storage media and requirements such as tape versus disk.
00:17
Besides creating backups, what is required for a successful backup strategy?
00:26
Testing backups A backup strategy is incomplete if backups are not successfully tested by ensuring they can be successfully restored.
00:36
As with data retention, taking and testing regular backups off case data and evidence is an essential part off enterprise security case management.
00:46
If any case related data is deleted or becomes corrupt, having a successful backup which is capable off restoration might read the difference between a case being successful or not.
00:59
There are obviously several ways to back up case data, including both commercial and open source solutions.
01:07
Which of a solution you choose to utilise? It must be able to take regular, consistent copies of data while maintaining the integrity off data being backed up.
01:15
Depending on the type of data, backups should be created daily, weekly, monthly
01:23
or on a longer timescale to ensure that if data must be restored, it is consistent and any and all work or changes made to a case are correctly reflected.
01:34
Typically,
01:36
full backups are taken weekly, and, as the name suggests, they take a full backup off all the relevant data.
01:42
Whether that's the contents off a specific case folder or an entire medium,
01:49
full backups are also taken when major changes occur.
01:53
Differential backups, also aptly named,
01:57
create a backup of all the files, which have changed since the most recent full backup.
02:02
This type of backup is usually used for more frequent backups.
02:07
For example, if only full backups are being taken, and each is created on a Sunday if a system dies on Wednesday.
02:15
All of the work between Sunday and Wednesday has been lost,
02:21
however,
02:22
with a differential backup being taken daily.
02:23
All of that work and those changes are captured in the differential backups.
02:29
The drawback off a differential backup strategy is that it takes up a lot of storage space.
02:36
The backup on Tuesday captures the changes since Monday,
02:39
but also the changes, which were captured in the Monday differential.
02:44
The benefit of differential backups is that you only need to restore to backups in the event of a system failure.
02:51
The most recent full backup
02:53
and the most recent differential.
02:54
In contrast, incremental backups only back up the changes made since the most recent backup off any kind.
03:02
Therefore, these types of backups are smaller than differential backups. However, in the event of a system failure, you would need to restore the most recent full backup
03:13
and all of the incremental backups. Since that full backup was created.
03:19
Your backup strategy will be bespoke
03:21
and will need to be defined with your organization's needs in mind.
03:25
Try to create a strategy which will allow you to recover as much relevant data as possible in the least amount of time.
03:34
However, also be sure to consider the amount of storage required. And don't forget to regularly test restore your backups to ensure they can actually be restored.
03:45
There are few things worse than trying to restore valuable data,
03:49
only to find your backups a corrupt.
03:51
Finally,
03:52
it's necessary to understand which type of storage media is best for your backups. For example, backups, which will be used for long term storage should most likely be sent to tape, media and stored offsite. The issue with tape is speed
04:09
tape media. I usually very slow and restoring from type can take a very long time.
04:15
The benefit of type is that they are less volatile and less prone to errors than other types of medium, such as spinning hard disks.
04:24
If time is of the essence when restoring data, it would be best to consider some type of hard disk, whether it be traditional spinning disc, more, more in SS days or some kind of enterprise grade SAS drives,
04:36
regardless of the type of media, make sure that you choose a solution with enough storage for your security teams needs.
04:45
What are the three times of backups?
04:49
Full differential and incremental the three types of backups?
04:55
In this lesson, we covered
04:57
the importance of backing up case data
05:00
timeframes four data backup,
05:01
incremental versus full versus differential backups as well as storage media and requirements.

Up Next

Enterprise Security Case Management

In this online course about Enterprise Security Case Management, you will learn about tools and techniques which help cybersecurity practitioners manage evidence and related case data to preserve their integrity.

Instructed By

Instructor Profile Image
Seth Enoka
Consultant
Instructor