CertaDNS
Skip to lesson

What You Are Not Doing · lesson 2 of 2

Defending it afterwards

After this lesson you can

Answer for an omission after an incident, when the omission was deliberate.

Assumes you have read The list.

An incident happens in an area you deliberately deferred. The not-doing entry exists, with its reasoning and its trigger. That conversation still has to be had, and how it goes depends almost entirely on what was written down beforehand.

Two versions of the same situation

UndocumentedDocumented with a trigger
The question askedWhy was this not done?Has the trigger been met?
What you produceA recollection of a conversationA dated entry naming the reasoning
What it looks likeAn oversight being explainedA decision being revisited
Who it reflects onYou, personallyA process, which is what should be examined
What happens nextA reactive commitment to do everythingA specific reassessment of one item

Holding the position, or changing it

  • Check the trigger honestly, first. If the circumstances that made the deferral reasonable have changed, the entry has done its job and the answer is now different. Say so.
  • If the trigger has not been met, the reasoning stands. An incident is evidence about the world, not automatically evidence that the reasoning was wrong. Deferring DNSSEC because the team cannot operate it is not refuted by a phishing campaign.
  • Distinguish “would this have helped” from “was this the right call”. The four surfaces answer the first in seconds, and the answer is frequently no — the deferred control was on a different surface entirely.
  • Do not concede a control that would not have helped. Agreeing to deploy something irrelevant to quiet a room spends budget and attention on the wrong surface, and the next incident will be in the same place.

The conversation, worked

"We were phished through a lookalike domain. Why
 hasn't this company deployed DNSSEC?"

 DNSSEC is an integrity control — it stops somebody
 forging answers for our zone. The attacker registered
 their own domain and published correct records for it.
 DNSSEC on our zone could not have affected that.

 What addresses this is detection and takedown, which
 is item 4 in the 90-day plan, and it found this domain
 on day two. The gap was that nobody was resourced to
 work the queue — which is the entry on the not-doing
 list, with the trigger "the internal queue is being
 worked and is the constraint".

 That trigger has now been met.

The four surfaces are the tool for this conversation

Name the surface the attack targeted, name the surface the deferred control defends, and the question answers itself. It is faster than arguing, it is checkable, and it moves the discussion to the control that actually would have helped — which is the outcome worth having.

Last reviewed