heureka webinar – security, the growth engine for ediscovery professionals

28
Security – The Growth Engine for eDiscovery.

Upload: heureka-software

Post on 13-Aug-2015

62 views

Category:

Law


1 download

TRANSCRIPT

Page 1: Heureka Webinar – Security, the Growth Engine for eDiscovery Professionals

Security – The Growth Engine for eDiscovery.

Page 2: Heureka Webinar – Security, the Growth Engine for eDiscovery Professionals

PANELISTSNate Latessa Heureka Chief Operating Officer [email protected]

Ron CopferCEO

[email protected]

Donald WochnaCo-Chair, E-Data Law Group

[email protected]

Page 3: Heureka Webinar – Security, the Growth Engine for eDiscovery Professionals

HEUREKA OVERVIEW

Heureka Meaning: “I’ve found it!”

Heureka was formed to allow clients to search and respond quickly to discovery, security, compliance and free-form investigation needs.

Page 4: Heureka Webinar – Security, the Growth Engine for eDiscovery Professionals

WHY?There is a need for quick information

regarding:

• Breaches• Data Classification• Lawsuits• Failed Audits• HR Issues• BSA Licensing • Process Changes• Data in the Cloud• IP Loss• Unpatched Endpoints• Proof of Compliance

Page 5: Heureka Webinar – Security, the Growth Engine for eDiscovery Professionals

HOW?

• Endpoint Intelligence

• Viewed via the search and correlation platform

• Numerous workflows – eDiscovery– Data Classification– Incident and Indicator

Response– Audit and Compliance– Free Form Investigation

Page 6: Heureka Webinar – Security, the Growth Engine for eDiscovery Professionals

WOCHNA LAW BACKGROUND

Attorney, Client and Technology:• We embed technology in our legal

solutions.• Created an E-data law group• New site opening January 1, 2015• [email protected]• 330.815.2891

Page 7: Heureka Webinar – Security, the Growth Engine for eDiscovery Professionals

OVERVIEW• Trends in eDiscovery and Security• Why security is ready for eDiscovery

professionals to lead• How to leverage eDiscovery processes to

impact security• Why your experience and expertise is

desperately needed • How to cross the boundary, impact your

company, and build your career

Page 8: Heureka Webinar – Security, the Growth Engine for eDiscovery Professionals

PANELIST OPENING COMMENTS

How and why did you get from eDiscovery to Security?

Page 9: Heureka Webinar – Security, the Growth Engine for eDiscovery Professionals

eDISCOVERY AND SECURITY • eDiscovery

– Episodic– Non-budgeted– Fractured data repositories– Immature standards

• Security– Continuous– Budgets Increasing– Holistic to the Enterprise– Mature standards

Page 10: Heureka Webinar – Security, the Growth Engine for eDiscovery Professionals

eDISCOVERY AND SECURITY • Similarities

– Data explosion– Needle in the haystack identification– Forensic analysis– Malware explosion– Need quicker response time– Need for enterprise-wide data analytics– Both assume huge risks to the business– Challenges in communicating needs to

mgmt.

Page 11: Heureka Webinar – Security, the Growth Engine for eDiscovery Professionals

WHAT ISSUES/COMMENTS/NEEDS HAVE YOU HEARD OR SEEN THE MOST FROM CLIENTS IN THE LAST 12 MONTHS?

Page 12: Heureka Webinar – Security, the Growth Engine for eDiscovery Professionals

TRENDS• Many articles written in last two years

• Executives Taking Ownership of Cybersecurity

• Players: IT, Legal, CFO, Insurance, Vendors, Experts

• Legal is moving to become CISO

Page 13: Heureka Webinar – Security, the Growth Engine for eDiscovery Professionals

WHAT ARE THE STANDARDS DRIVING THE

INDUSTRIES AND WHAT DO THEY HAVEIN COMMON?

Page 14: Heureka Webinar – Security, the Growth Engine for eDiscovery Professionals

ISO ALIGNMENT• ISO 9000—requirements and best practices for

the quality management systems

• ISO 27001, 27002 — The process and controls for an Information Security Management System (ISMS) .

• ISO/IEC 27050 — Information technology — Security techniques — Electronic discovery (DRAFT). This ISO standard is within the family of standards that focus on information security management.

Page 15: Heureka Webinar – Security, the Growth Engine for eDiscovery Professionals

ISO 27050

• The fundamental purpose of the digital forensics standards ISO/IEC 27037, 27041, 27042 and 27043 and 27050 is to promote good practice methods and processes for forensic capture and investigation of digital evidence

• This four-part standard concerns the discovery phase, specifically the discovery of Electronically Stored Information (ESI), a legal term-of-art for data.

Page 16: Heureka Webinar – Security, the Growth Engine for eDiscovery Professionals

IMPACT OF ISO

• Rise of Certification to ISO standard– Law firms– Vendors– Experts

• ISO standard requires “measurement of accuracy”

• How accurate are the results of the ediscovery process used

Page 17: Heureka Webinar – Security, the Growth Engine for eDiscovery Professionals

WHAT IS THE CHANGE FROM PROCESS TO ANALYTICS IN THE EDISCOVERY FIELD AND WHY IS IT IMPORTANT?

Page 18: Heureka Webinar – Security, the Growth Engine for eDiscovery Professionals

ACCURACY OF RESULTS

• Accuracy of Results measures the output—not the process

• Accuracy of Results relates to the Data—not the process

• Accuracy of Results requires moving beyond Process and analyze the Data being identified, preserved, and produced

Page 19: Heureka Webinar – Security, the Growth Engine for eDiscovery Professionals

ACCEPTANCE TESTING

• Establish whether or not it can be stated, at a given level of confidence, that recall is at or above a specified level.

• EG: a passing acceptance test would allow us to state with a 95% confidence interval that our retrieval efforts have achieved 80% recall or better.

Page 20: Heureka Webinar – Security, the Growth Engine for eDiscovery Professionals

STANDARDS REQUIRE SAMPLING

• Sampling is the “bridge” between e-discovery and cybersecurity.

• Sampling applicable to eDiscovery tests the Data—not the process

• Tools used in eDiscovery are applicable in cybersecurity to test the Data

Page 21: Heureka Webinar – Security, the Growth Engine for eDiscovery Professionals

SAMPLING AND DATA ANALYTICS• Data analytics is the key to the future of

eDiscovery and cybersecurity

• Data analytics is the result of the application of defensible sampling techniques to a universe of data in order to extract reliable intelligence about the data that informs business decisions.

• Data analytics is being applied to eDiscovery and to cybersecurity, data breach areas

Page 22: Heureka Webinar – Security, the Growth Engine for eDiscovery Professionals

EDRM

Page 23: Heureka Webinar – Security, the Growth Engine for eDiscovery Professionals

R3 MODEL

Page 24: Heureka Webinar – Security, the Growth Engine for eDiscovery Professionals

USING THE STRENGTHS OF AN EDISCOVERY BACKGROUND, HOW CAN ATTENDEES LEVERAGE THEIR LEGAL CONTACTS AND EDISCOVERY PROCESSES?

Page 25: Heureka Webinar – Security, the Growth Engine for eDiscovery Professionals

WHAT WOULD YOU RECOMMEND EDISCOVERY/LEGAL PROFESSIONALS LEARN TO INCREASE THEIR REACH AND INFLUENCE?

Page 26: Heureka Webinar – Security, the Growth Engine for eDiscovery Professionals

PANELIST CLOSING COMMENTS

Additional Questions?

Page 27: Heureka Webinar – Security, the Growth Engine for eDiscovery Professionals

THANK YOU!

Page 28: Heureka Webinar – Security, the Growth Engine for eDiscovery Professionals

HEUREKA – I’VE FOUND IT!

www.heurekasoftware.com