# Welcome to ​the Citizen Clinic Cybersecurity Education Center

The [Citizen Clinic](https://cltc.berkeley.edu/about-us/citizen-clinic/) is a public interest cybersecurity clinic at the University of California, Berkeley. We support the capacity of politically targeted organizations to defend themselves against online threats. Building off the Center for Long-Term Cybersecurity’s [research](https://cltc.berkeley.edu/defendingpvos/) on the ecosystem of organizations providing technical assistance to civil society, the clinic supports multidisciplinary teams of students to assess threats to targeted organizations, recommend risk-appropriate mitigations, and work collaboratively with clients to implement new policies and technical controls that enhance their cybersecurity.

For organizations seeking more information about Citizen Clinic, please visit <https://cltc.berkeley.edu/about-us/citizen-clinic/>.

### **The Citizen Clinic Cybersecurity Education Center**

The Citizen Clinic Cybersecurity Education Center is designed to share basic cybersecurity resources for civil society organizations, and to inform other academic institutions that may be interested in adopting the clinic model.

Visit this page to read case studies about our recent work.

#### [**Curriculum**](/clinic-curriculum/syllabus)

**Interested in setting up a cybersecurity clinic?** View current and past Citizen Clinic syllabi and reading lists, case studies, in-class activities, and work assignments.

#### [**Infrastructure**](/clinic-infrastructure/virtual-private-network-vpn)

**Setting up the technology infrastructure for your own program?** Check out our primers and policies for setting up virtual profiles, virtual private networks, and phishing simulators.

#### [**Baseline Organizational Security Guide**](https://cltc.berkeley.edu/wp-content/uploads/2019/02/LRO-Security-Guide-COMPLETE-2.2.19-1.pdf)

**All organizations need a basic level of cybersecurity**, so whether or not you think you are at risk of a cyberattack, we encourage you to read our Baseline Organizational Security Guide.

**Comments or Ideas?** [Submit an issue](https://github.com/cltc-berkeley/c3ec/issues) or email us at <citizenclinic@berkeley.edu>.

![](/files/uhZJDOrckUEdTaqvEOO1)

Citizen Clinic is a program of the Center for Long-Term Cybersecurity. Learn more at <https://cltc.berkeley.edu/>.

License for written content: [**CC BY 3.0.**](https://creativecommons.org/licenses/by/3.0/) See original sources for license information of any images and linked publications.


# Case Studies

### A Voting Rights Organization

{% hint style="warning" %}
**The Challenge:** In the run up to the 2020 primary election, a volunteer-led, U.S.-based voting rights organization had increasing concerns about the digital safety of their team members and the integrity of their data. In particular, the organization was concerned that online disinformation campaigns could hamper its efforts to ensure a fair and open democracy.
{% endhint %}

{% hint style="info" %}
**What Citizen Clinic Did:** A team of students from Citizen Clinic, led by mentors from UC Berkeley and partner organizations, reached out to help the organization secure its online systems to be more resistant to cyberattacks.
{% endhint %}

They began by conducting a large-scale audit to understand the organization’s cybersecurity challenges and the threats their team members faced. This audit exposed that the organization had no formalized structures in place for securing online accounts and responding to security incidents. More worryingly, many of the organization’s online accounts were accessed by multiple volunteers through shared logins.\
\
The Citizen Clinic student team identified the shared accounts as the greatest immediate risk, and focused their efforts on moving the organization toward a more robust, secure account system.

{% hint style="success" %}
**Outcomes:** As a result of Citizen Clinic’s recommendations, the organization has successfully created an account structure through which login credentials do not have to be shared among volunteers, which will make it easier to implement further security measures in the future. With a plan for improving its cybersecurity in place, the organization can more confidently carry out its mission to protect voter rights.
{% endhint %}

### A Regional Abortion Fund

{% hint style="warning" %}
**The Challenge:** A regional abortion fund dedicated to supporting the reproductive rights of Americans faced diverse challenges online, including online harassment from bots and trolls, threats of data breaches to reveal patient, provider, and donor information, and fraudulent websites that promote fake clinics or scams to collect donations.
{% endhint %}

{% hint style="info" %}
&#x20;**What Citizen Clinic Did:** The Citizen Clinic student team performed an audit of the client’s information storage and communication systems, as well as a comprehensive risk assessment that led to the identification of key organizational assets and likely threat scenarios. As part of this process, the team met with different people in the organization and rigorously documented the organization’s information workflow.
{% endhint %}

The students created a series of spreadsheets to help organize this information, which ultimately helped identify which systems were most vulnerable and contained sensitive information. This risk assessment revealed a major vulnerability in a document storage system that contained both financial information and patient data. In addition, vulnerabilities were found in the organization’s email system, as well as in an online form and data collection tool.\
\
The Citizen Clinic’s student team also upgraded some of the organization’s key digital business systems, which had previously been too difficult to safely and efficiently use. They also completed a migration of assets to a more secure data storage platform; re-organized a folder structure to better manage access permissions; and enabled multi-factor authentication for the organization’s new accounts.

{% hint style="success" %}
"**Outcomes**" The team provided the client with a comprehensive report that included a risk assessment, explanation of deliverables, and original context research for the project. They created security policies and information workflows for different roles within the organization — including board members, staff, and volunteers — and drew an outline of each member’s access to the digital storage system and how each member can manage their permissions optimally. Working with the fund’s interim executive director, the team delivered a comprehensive security training that introduced members to the threats they face, the new storage system, and the security policies and general best practices to follow on a daily basis to keep the organization secure.\
\
“We used our training and policies to present the ideas from our threat model to the staff of the organization and to begin an organizational conversation about information security,” one of the students explained. “Cybersecurity is not all tech. It involves strategic thinking and prioritization of threats, and a strategic search for creative end solutions that are simple and practical enough for clients to implement.”
{% endhint %}

***

### A Domestic LGBTQ Support Organization

{% hint style="warning" %}
**The Challenge:** A U.S.-based LGBTQ nonprofit organization was subjected to hate campaigns from extremist groups and violent online communities. Beyond harassment on social media and denial of service attacks on their web applications, the organization has had its member’s personal information - home addresses, dead names, phone numbers, and photographs - collected and published on the web (also known as *doxxing*). This has led to staff members’ facing in-person harassment and death threats.
{% endhint %}

{% hint style="info" %}
**What Citizen Clinic Did**: The Citizen Clinic team first gained a foundational understanding of the organization’s unique context, a contextual research process that included an in-depth interview with the technology director and a review of the organization’s existing cybersecurity protocols.
{% endhint %}

Based on insights from industry experts, the students provided concrete suggestions about how the organization could enhance its cybersecurity training program, as well as its telephone and website security. They also connected the organization with experts who could provide future support beyond the Clinic’s capabilities.\
\
After implementing cybersecurity practices, the students developed short security quizzes to assess the degree to which these practices had “sunk in” to the organization’s members. The quizzes were intended to remind staff about existing policies as well as to assess any possible weak spots in training. In addition, the students instigated a comprehensive phishing campaign, and emailed fifteen members from an unfamiliar email address and urged them to click a link and submit their credentials. The phishing campaign provided the Technology Director with concrete feedback on the organization’s strengths and vulnerabilities to phishing attacks.

{% hint style="success" %}
**Outcomes:** The Citizen Clinic student team holistically assessed this organization’s cybersecurity capabilities, improved its training program, provided feedback on strengthening its hotline and website, and connected the organization to additional pro bono resources. Ultimately, the efforts improved the organization’s ability to handle DDoS attacks, misinformation campaigns, phishing attempts, and doxxing by trolls. “We were successful in helping the organization because we understood its unique needs, concerns, and goals,” one of the students said. “By focusing on both implementing new policies and making sure those policies were accepted by members, we helped the organization find effective and practical solutions.
{% endhint %}

### Land Is Life, an Indigenous Community Support Network

{% hint style="warning" %}
**The Challenge:** Land is Life is a non-profit civil society organization that supports local communities around the world that are adversely affected by development projects, particularly those that relate to environmental and human rights. Land Is Life and its partner network are frequently subjected to online disinformation campaigns, data breaches, and other online threats from a variety of threat actors, including governments, corporations, cartels, and paramilitary groups.
{% endhint %}

{% hint style="info" %}
**What Citizen Clinic Did:** A student team from Citizen Clinic performed an analysis of factors contributing to vulnerabilities and threats to Land is Life. The students interviewed regional field directors in different geographies (i.e. Africa, Asia, and Latin America), which revealed that team members around the world used a variety of digital devices, communication methods, and security practices. While the organization had baseline security practices in place, they lacked standardized secure protocols for communications and travel.
{% endhint %}

Citizen Clinic addressed this problem by developing a communications and travel protocol guide with a quick-guide section for easy usage. The student team also wrote an onboarding guide for technology so that employees could quickly set up their devices in a secure fashion, independent of their understanding of secure communications or travel practices. They also conducted phishing testing that revealed the organization is vulnerable to phishing attacks. They presented Land is Life’s leaders with a series of recommendations for implementation and integration.\
\
“We wanted to keep documents concise and condensed so that users of the document could quickly acquire the information they need and would not get fatigued from its density, while also being thorough in informing people of the motivations behind why such practices are necessary or important,” the students explained.

{% hint style="success" %}
**Outcomes:** The Citizen Clinic team recommended and implemented a variety of solutions to help Land is Life and its partners to improve their cybersecurity, including multi-factor authentication, password management tools, and enhancing other security protocols. As a result of implementing these recommendations, the organization’s baseline digital defenses were greatly improved. “In some ways, Citizen Clinic engaging with Land is Life is like engaging with many dozens of organizations,” says Casey Box, Executive Director of Land is Life. “Citizen Clinic took the time to do a diagnostic amongst my entire team and partners to understand how they operate day-to-day at the organization, and what kind of threats and concerns they had in regards to their digital security. We developed a plan that we rolled out over the course of two years to develop protocols, systems, and different ways that we could strengthen our digital security as an organization.”
{% endhint %}


# Syllabus

### **Course description**

For individuals and organizations involved in political advocacy, cybersecurity threats are an increasingly common reality of operating in the digital world. Civil society has always been under attack from ideological, political, and governmental opponents who seek to silence dissenting opinions, but the widespread adoption of connected technologies by the individuals and organizations that make up civil society creates a new class of vulnerabilities.

Citizen Clinic at the Center for Long-Term Cybersecurity provides students with real-world experience assisting politically vulnerable organizations and persons around the world to develop and implement sound cybersecurity practices. Clinic students will participate in both a classroom and clinic component. In the classroom, students will study the basic theories and practices of digital security, the intricacies of protecting largely under-resourced organizations, and the tools needed to manage risk in complex political, sociological, legal, and ethical contexts. In the clinic component, students will work in teams supervised by the Clinic staff to provide direct cybersecurity assistance to civil society organizations. Students’ clinic responsibilities will include learning about an organization’s mission and context, assessing its vulnerabilities, and ultimately recommending and implementing mitigations to the identified security risks. The emphasis will be on pragmatic, workable solutions that take into account the unique operational needs of each partner organization. Weekly lectures will provide students with the background information and tools they will need to engage with partners. Coursework will focus on partner-facing, hands-on projects. Students will be expected to work an average of 10 hours per week, although the distribution of this workload may fluctuate based upon the availability and needs of the partner.&#x20;

### **Schedule**

In the first half of the semester, class meetings will be a mix of lectures & discussions with project-oriented workshops. In the second half of the semester, these class times will be reserved for work with the teaching team and check-ins tailored to the specific needs of your partner organization.  &#x20;

**Most assignments (some exceptions) are listed with a due date on the Sunday at 11:59 PM (Pacific). Readings are to be completed by the end of the week in preparation for the next week’s lectures.**

*Note: This schedule is tentative and may be adjusted - assignment dates may change, additional readings may be assigned, speakers/lectures may be shuffled, etc. The teaching team will announce when changes are made.*<br>

#### Week 1: Introduction / What is Public-Interest Cybersecurity? <br>

**5/2 Lecture Week 1A:**&#x20;

●        **Introduction to Public Interest Cybersecurity**

&#x20;           o   Introductions

&#x20;           o   Content and methods of the course

&#x20;           o   What is Public Interest Cybersecurity?<br>

**Assignments Due (by Tuesday 11:59PM Pacific):**

●        **(Review)** Code of conduct: Posted in “files” section on 2U. *\[Individual]*

●        **(Read)** pages 7 - 21 & 48 - 52 of [*“An Introduction to Cybersecurity Ethics”*](https://www.scu.edu/media/ethics-center/technology-ethics/IntroToCybersecurityEthics.pdf) *(Shannon Vallor,* \
&#x20;           *The Markkula Center for Applied Ethics)*&#x20;

**Prepare answers** to questions on pages 13-15 and page 53 for in-class discussion (don’t submit anything).

●        **(Read)** Sandro Contento, Toronto Star, [“How these Toronto sleuths are exposing the world’s \
&#x20;          digital spies while risking their own lives”](https://www.thestar.com/news/canada/2019/12/13/from-a-tower-in-toronto-they-watch-the-watchers-how-citizen-lab-sleuths-are-exposing-the-worlds-digital-spies-while-risking-their-own-lives.html)

●        **(Explore & use)** [Citizen Lab’s Security Planner](https://securityplanner.org/).

●        **(Skim)** [Tactical Tech's Annual Report](https://cdn.ttc.io/s/tacticaltech.org/public_annual_report_2020_final.pdf)&#x20;

&#x20;

**5/3 Assignments Due (by Wednesday 11:59PM Pacific):**

●        **(Submit)** Signed code of conduct: *\[Individual]*

&#x20;                     &#x20;

**5/4 Lecture Week 1B:**

●        Ethical Considerations.&#x20;

●        Citizen Clinic “Rules of the Road”&#x20;

&#x20;           o   Citizen Clinic Code of Conduct.&#x20;

&#x20;           o   Personal Risk of Citizen Clinic.

&#x20;           o   How to talk about Citizen Clinic.

&#x20;           o   Security Response Plan.<br>

&#x20;           **Read (by next week):**&#x20;

●        Citizen Lab. [“Bittersweet: Supporters of Mexico’s soda tax targeted with NSO exploit links”](https://citizenlab.ca/2017/02/bittersweet-nso-mexico-spyware/)&#x20;

●        Access Now. [“Spyware in Mexico: an interview with Luis Fernando García of R3D Mexico”](https://www.accessnow.org/spyware-mexico-interview-luis-fernando-garcia-r3d-mexico/)&#x20;

●        Silver & Elgin. [“Torture in Bahrain Becomes Routine With Help From Nokia Siemens”](https://web.archive.org/web/20111006185329/http:/www.bloomberg.com/news/2011-08-22/torture-in-bahrain-becomes-routine-with-help-from-nokia-siemens-networking.html)&#x20;

●        Arthur Turner. [“Consulting Is More Than Giving Advice.”](https://hbr.org/1982/09/consulting-is-more-than-giving-advice)&#x20;

●        Thomas Wedell-Wedellsborg. [“Are You Solving the Right Problems?”](https://hbr.org/2017/01/are-you-solving-the-right-problems)&#x20;

●        **(Optional)** Joseph Cox. [“I Gave a Bounty Hunter $300. Then He Located Our Phone”](https://motherboard.vice.com/en_us/article/nepxbz/i-gave-a-bounty-hunter-300-dollars-located-phone-microbilt-zumigo-tmobile)&#x20;

●        **(Optional)** Stephen Arnold. [“Telestrategies - An Interview with Dr. Jerry Lucas” ](http://www.arnoldit.com/search-wizards-speak/telestrategies-2.html)<br>

#### Week 2: Threats to Civil Society’s Cybersecurity

\
**5/9 Lecture Week 2A:**

●        Problem Diagnosis and Reframing

&#x20;

**5/11 Lecture Week 2B:**&#x20;

●        **Guest Speaker:** “How to inventory cyber security assets”

**Read:**

●        Electronic Frontier Foundation, [“Surveillance Self-Defense: Your Security Plan”](https://ssd.eff.org/en/playlist/activist-or-protester#your-security-plan) \
&#x20;          \- **know** the definitions of underlined terms.

●        Jorge Luis Sierra [“Digital and Mobile Security for Mexican Journalists and Bloggers”](https://freedomhouse.org/sites/default/files/Digital%20and%20Mobile%20Security%20for%20Mexican%20Journalists%20and%20Bloggers.pdf) &#x20;

●        Le Blond et al. [“A look at targeted attacks through the lense of an NGO” ](http://www.usenix.org/system/files/conference/usenixsecurity14/sec14-paper-blond.pdf)

●       [ SAFETAG Guide.](https://safetag.org/guide/) **Skim** to Section 2.2, then **read Section 2.2 and Section 2.3**.&#x20;

●        **(Read and Explore Examples)** [About PESTLE](https://pestleanalysis.com/what-is-pestle-analysis/) (use an ad-blocker!)&#x20;

●        **(Optionally Watch)** CLTC / TechSoup. Webinar. [“Cybersecurity in Low-Risk Organizations: \
&#x20;           Understanding Your Risk and Making Practical Improvements.”](https://cltc.berkeley.edu/2019/02/25/cltc-and-citizen-clinic-present-cybersecurity-in-low-risk-organizations-webinar/)

&#x20;

#### Week 3: Meet the First Client and Threats to Civil Society’s Cybersecurity

&#x20;

**5/16: Meet the first client**&#x20;

●        **Guest Speaker:**  Client

Week 4: Threats to Civil Society’s Cybersecurity

&#x20;

**5/18 Lecture Week 4A:**

●        **Current Event Brief**

●        **Contextual Brief**

&#x20;           o   SAFETAG

&#x20;           o   PESTLE

&#x20;**Read:**

●        NIST SP 800-37 [“Risk Management Framework for Information Systems and Organizations.” ](https://csrc.nist.gov/CSRC/media/Publications/sp/800-37/rev-2/draft/documents/sp800-37r2-draft-ipd.pdf)    \
&#x20;          Chapter 2 only.&#x20;

●        **(Skim)** NIST SP 800-39 [“Managing Information Security Risk.” ](https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-39.pdf)Chapter 2 only.&#x20;

●        **(Skim)** NISTIR 8062 [“An Introduction to Privacy Engineering and Risk Management in \
&#x20;           Federal Systems.”](https://nvlpubs.nist.gov/nistpubs/ir/2017/NIST.IR.8062.pdf)

●        Example Risk Assessment shared via email.

●        Julian Cohen. [“Playbook Based Testing.”](https://medium.com/@HockeyInJune/playbook-based-testing-5df4b656113a)&#x20;

●        [MSFT’s STRIDE](https://cloudblogs.microsoft.com/microsoftsecure/2007/09/11/stride-chart/) and related blog posts.

●        Bill Marczak and John Scott-Railton. [“Keep Calm and (Don’t) Enable Macros: A New Threat \
&#x20;          Actor Targets UAE Dissidents”](https://citizenlab.ca/2016/05/stealth-falcon/)

&#x20;

#### Week 4: Risk Assessment&#x20;

\
**5/23 Assignments Due (by Tuesday, 11:59PM Pacific):**

●        Communication Plan and Collaboration Plan (Break-out Groups) *\[Team]*

&#x20;           o   In Class Collaborative Plan \[Team]

&#x20;           o   Due After Class (11:59pm Pacific) Communication Plan \[Team]  &#x20;

&#x20;

**5/25 Lecture Week 4B:**&#x20;

●        Current Event Brief

●        Contextual Brief

●        Bounding Risk Assessments – Alex’s presentation

&#x20;           o   Review Teams’ Communication Plans *\[Team]*

**Read:**

●        Amnesty International. [“Digitally dissecting atrocities – Amnesty International’s open source \
&#x20;           investigations.”](https://www.amnesty.org/en/latest/news/2018/09/digitally-dissecting-atrocities-amnesty-internationals-open-source-investigations/)&#x20;

●        Sarah Jeong, Charlie Warzel, Brianna Wu, Joan Donovan. New York Times. [“Everything is \
&#x20;           GamerGate”](https://www.nytimes.com/interactive/2019/08/15/opinion/gamergate-twitter.html) - **Read all of the four essays.**

●        Angela Chen. The Verge. [“Moderating content doesn’t have to be so traumatic”](https://www.theverge.com/2019/2/27/18243359/content-moderation-mental-health-ptsd-psychology-science-facebook)&#x20;

●        Sam Dubberley & Michele Grant. First Draft. [“Journalism and Vicarious Trauma”](https://firstdraftnews.org/wp-content/uploads/2017/04/vicarioustrauma.pdf)&#x20;

●        (Explore) [The EFF’s Security Education Companion](https://sec.eff.org/).<br>

#### Week 5: Digital Security Training & Recognizing PTSD (post-traumatic stress disorder)

&#x20;

**5/30 Week 8A:**

●        Contextual Brief

●        Current Event Brief

●        Social Engineering & Phishing Simulations

&#x20;

**6/1 Week 8B:**&#x20;

●        Contextual Brief

●        Current Event Brief

**Read:**

●        Protective Intelligence. [“Part I: An Introduction To OSINT Research For Protective \
&#x20;           Intelligence Professionals”](https://www.protectiveintelligence.com/blog/osint-intro-for-protective-intelligence-pt1)&#x20;

●        Protective Intelligence. [“Part 2: An Introduction To OSINT Research For Protective \
&#x20;           Intelligence Professionals”](https://www.protectiveintelligence.com/blog/osint-intro-for-protective-intelligence-pt2)

●        Ian Barwise. [“Open-Source Intelligence (OSINT) Reconnaissance”](https://medium.com/@z3roTrust/open-source-intelligence-osint-reconnaissance-75edd7f7dada) &#x20;

●        **(Explore)** [OSINT Framework](https://osintframework.com/)

●        **(Explore)** [OSINT.link](https://osint.link)

●        **(Explore)** [Awesome OSINT](https://github.com/jivoi/awesome-osint)

●        **(Try)** [SECALERTS - Automated Security Audit](https://secalerts.co/security-audit)

&#x20;

#### Week 6: Information Gathering and Analysis

&#x20;

**6/6: Lecture Week 5A:**

●        Current Event Brief

●        Contextual Brief

&#x20;           o   Adversary Persona Development&#x20;

●        Threat Scenario Development

●        Open Source Research Methods, Safety, and Tools

&#x20;           o   Virtual Machines, Networks, & Identities

&#x20;           o   Manual Searches & Google Hacking

&#x20;           o   Automated Tools

&#x20;

**6/8 Lecture Week 5B:** continued

**Read:**

●        Netgain [“Digital Security and Grantcraft Guide”](https://www.fordfoundation.org/media/3334/digital-security-grantcraft-guide-v10-final-22317.pdf)&#x20;

●        The Engine Room. [“Ties That Bind: Organizational Security for Civil Society”](https://www.theengineroom.org/civil-society-digital-security-new-research/) - read Full \
&#x20;           Report.

●        APF et al. [“Improving SSL Warnings: Comprehension and Adherence”](https://dl.acm.org/citation.cfm?id=2702442)&#x20;

●        Abu-Salma et al. [“Obstacles to the Adoption of Secure Communication Tools”](https://ieeexplore.ieee.org/abstract/document/7958575/)&#x20;

#### Week 7: Improving Baseline Digital Security (Part 1)

&#x20;

**6/12 Assignments Due (by Sunday, 11:59PM Pacific):**

●        Draft Midterm Report and Work Plan *\[Team]*

&#x20;

**6/13 Lecture Week 6A:**&#x20;

●        Contextual Brief

●        Legal and Policy Factors For Non-Profits’ Cybersecurity

&#x20;

**6/15: Lecture Week 6B:**

●        Misinformation & Harassment

&#x20;          o   Definitions & Risks

**Read:**

●        Micah Lee. [“It’s Impossible To Prove Your Laptop Hasn’t Been Hacked. I Spent Two Years Finding Out.”](https://theintercept.com/2018/04/28/computer-malware-tampering/)

●        (Watch) Rachel Tobac. [“How I would Hack You: Social Engineering Step-by-Step”](https://www.youtube.com/watch?v=L5J2PgGOLtE)&#x20;

●        Weidinger et al. [“How To Give A Digital Security Training”](https://medium.com/@geminiimatt/how-to-give-a-digital-security-training-4c83af667d40)&#x20;

●        EFF. [“Am I the Right Person?”](https://sec.eff.org/articles/right-person-to-train)

●        EFF. [“How to Teach Adults”](https://sec.eff.org/articles/how-to-teach-adults)

●        (Skim) Weidinger et al. [“Digital Security Training Resources for Security Trainers, Fall 2019 \
&#x20;          ](https://medium.com/cryptofriends/digital-security-training-resources-for-security-trainers-spring-2017-edition-e95d9e50065e)[Edition”](https://medium.com/cryptofriends/digital-security-training-resources-for-security-trainers-spring-2017-edition-e95d9e50065e)&#x20;

#### Week 8: Improving Baseline Digital Security (Part 2)

&#x20;

**6/19Assignments Due (by Sunday, 11:59PM Pacific):**

●        Work Plan Updated & Finalized *\[Team]*

●        Slides for Midterm Class Presentation \[*Team*]

&#x20;                                                                   6

**6/20 Lecture Week 7A:**

No class – holiday

&#x20;

**6/22 Lecture Week 7B:**

●        MIDTERM PRESENTATION

&#x20;

**Read:**

●        IFTF [“State-Sponsored Trolling: How Governments Are Deploying Disinformation as Part of \
&#x20;          Broader Digital Harassment Campaigns”](http://www.iftf.org/statesponsoredtrolling). Read pages 3 to 21 & 45 to 51.&#x20;

●        Cindy Otis. USA Today. [“Americans could be a bigger fake news threat than Russians in the \
&#x20;           2020 presidential campaign”](https://www.usatoday.com/story/opinion/2019/07/19/disinformation-attacks-americans-threaten-2020-election-column/1756092001/) &#x20;

●        InterAction [“Disinformation Toolkit.”](https://staging.interaction.org/documents/disinformation-toolkit/)&#x20;

●        Reply All podcast. [“#112 The Prophet”](https://www.gimletmedia.com/reply-all/112-the-prophet) Listen to or read transcript.&#x20;

●        (Optional) Tahmina Ansari. First Draft. [“This Muslim journalist embraced social media until it \
&#x20;           ‘ruined’ his life”](https://firstdraftnews.org/this-muslim-journalist-embraced-social-media-until-it-ruined-his-life/)

&#x20;

#### Week 9: Disinformation & Harassment

&#x20;

**6/26 Assignments Due (by Sunday, 11:59PM Pacific):**

●        Team Evaluation 1 *\[Individual]*&#x20;

&#x20;

**6/27 Week 9A:**

●        Briefings

&#x20;

**6/29 Week 9B:**&#x20;

●      Briefings<br>

#### Week 10:&#x20;

**7/4 Holiday**<br>

**7/6 Week 10A:** Clinic Core Hours / Team Check-in

*“Clinic Core Hours” refers to the required student attendance of official class meeting hours that will be reserved for instruction specific to partner needs, feedback and guidance from the teaching team, and ad-hoc lectures. Each team member will provide a \~5 minute update on the progress of their assigned partner work.*

&#x20;

#### Week 11:&#x20;

**7/11 Week 11A:** Clinic Core Hours / Team Check-in

**7/13 Week 11B:** Clinic Core Hours / Team Check-in

#### Week 12:

**7/18 Week 12A:** Clinic Core Hours / Team Check-in

**7/20 Week 12B:** Clinic Core Hours / Team Check-in<br>

#### Week 13:&#x20;

\
**7/24 Assignments Due (by (by Sunday, 11:59PM Pacific):**

●         Final Partner Report (for Teaching Team Review) *\[Team]*

&#x20;

**7/25 Week 13A:** Physical and Electronic Security demo

&#x20;

**7/27 Week 13B:** Cell Phone cybersecurity<br>

#### Week 14: Wrap-up & Project Presentations

\
**7/31 Assignments Due (by Tuesday, 11:59PM Pacific):**

●        Project Presentations to the class *\[Team]*

**8/1 Assignments Due (by Friday, 6:00PM Pacific):**

●        Team Evaluation 2 *\[Individual]*

&#x20;

**8/3 Week 14A:**&#x20;

**Presentation to Client**

### Course policies

**Workload.**

This is a 3-unit, 14-week class. Coursework will primarily focus on partner-facing projects while weekly lectures will be used to inform and engage with students’ hands-on experiences. Students are expected to work an average of 10 hours per week on this course; however, the distribution of this workload may fluctuate based on the availability and needs of the partner.&#x20;

**Evaluation.**

Assignments will largely be evaluated on the following rubric that emphasizes (1) sound rationale in assessments, recommendations, and reflections, (2) “partner-ready” work products which reflect professional quality, and (3) completing the instructions of the assignment or the requirements agreed upon work plan with the partner.&#x20;

&#x20;

**General Grading Rubric\***&#x20;

| *Component*     | **0 points**                                                                                                                                     | **5 points**                                                                                                             | **10 points**                                                                                                                                                                        |
| --------------- | ------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Rationale       | Does not meet partner needs, introduces serious harms to partner, shows limited or inappropriate consideration for context                       | Addresses most of partner needs, some oversight of potential harms to partner, mostly appropriate for given context.     | All partner needs are met, feasible & effective rationale that addresses all major threats, appropriate for given context.                                                           |
| Professionalism | Hard to understand, full of jargon, serious writing/format errors present, tone / design unsuitable for its audience                             | Writing is mostly understandable; minor writing/format errors (typos), mostly appropriate tone / design                  | “Partner-ready,” clear and concise writing, almost no writing/formatting errors, appropriate tone & design for its audience                                                          |
| Requirements    | Some requirements in assignment or work plan not met; no insights or connections to readings/lectures; for group work: no evidence of group work | Most requirements met, some evidence for connections with readings/lectures; for group work: some evidence of group work | All requirements met, with clear, thoughtful insights and multiple cited connections to relevant readings/lectures; for group work: full evidence of strong, equitable collaboration |

&#x20;

***\*Note:** Students taking the course for P/NP or S/U are expected to participate in classes and complete all work to the same level of quality as students taking the course for a letter grade.*

&#x20;

**Assignments.**

&#x20;

**1. Partner Deliverables - 60%**&#x20;

The largest portion of graded evaluation will be based upon your team’s work and support for its assigned partner. These deliverables may include assessments, recommendations, and guides, each tailored towards the partner’s needs. Each team will also deliver a final report summarizing work performed with their partner.

&#x20;

**2. Individual Assignments - 10%**&#x20;

Two individual assignments will be given:

&#x20;

**Current Event Discussion Lead (5%):** Each student will sign up to lead one 15 minute discussion at the beginning of most lectures. Students will be expected to locate and share about a recent, current event relevant to the day’s lecture topic. Topic leaders will emphasize interesting or relevant points while other students are expected to ask questions and comment.

&#x20;

**Contextual Briefs (5%):** Each student is expected to share findings of their contextual research in one 10 + 5 minute presentation (no more than 10 minutes of content saving at least 5 minutes for Q\&A) during the first half of the semester. Students will share relevant, up-to-date, sourced information on one or more PESTLE factors and, importantly, provide an analysis on those factors’ impact on their partner’s security. Briefers will emphasize why their research is relevant to their partner organization while other students are expected to ask questions and comment.

&#x20;

**3. Team Case Study - 10%**&#x20;

We want students to be able to discuss and share their experience in the course with others, including future employers. We also want our partners to remain confidential and protected. This being said, each student team will submit a write-up of work performed and takeaways with sensitive information removed. The teaching team will review to ensure your experience is captured in an effective & safe manner. &#x20;

&#x20;

**4. Participation - 10%**&#x20;

We consider “participation” in two major components: participating in regular class discussions and participating in team & partner meetings outside of class hours.

a.     **You are expected to attend each official class meeting** and contribute substantially to class discussions. The teaching team should be notified in advance of absences from class meetings (including Clinic Core Hours). You do not need to share the reason for the absence. Not showing up to team check-ins will also negatively impact this grade.&#x20;

b.     **As a rule, two people from your team must attend any partner meeting or call.** While you may not be able to attend every team meeting and partner engagement outside of normal class hours, you are expected to attend and contribute to your team’s effort as often as possible.&#x20;

&#x20;

**5. Team Evaluations - 10%**&#x20;

Throughout the course, you will submit confidential evaluation forms which ask you to evaluate the contributions of each team member including yourself. Your final course grade will be adjusted, higher or lower, if you are contributing more or less than those within your group. If there are difficulties with any team member, discuss the matter within your team and seek resolution. If you cannot resolve the problem, immediately contact any faculty member, so that we can make an appointment to discuss the situation individually or with the entire group as needed.&#x20;

**Late assignments.**

&#x20;As we want to respect the time of our partners and ensure a high level of quality control (the teaching team will review deliverables before it reaches the partner), we expect students to adhere to timelines and due dates. **Each day an assignment is late will result in a letter grade deduction.** Recognizing that emergencies arise and partners may require schedule adjustments, exceptions will be made on a case-by-case basis.

**Code of Conduct.**

Each student enrolled in the course must agree in writing to the Citizen Clinic’s Code of Conduct (to be distributed) for maintaining a safe and secure learning experience and partner relationship. This Code of Conduct will be respected by all students, the teaching team, and CLTC staff and it is the responsibility of all personnel to report possible violations of the Code of Conduct to the teaching team. &#x20;

Additionally, we expect all students to abide by the Berkeley Student Code of Conduct (see <https://sa.berkeley.edu/student-code-of-conduct>) and act with honesty, integrity, and respect for others. (See also [https://diversity.berkeley.edu/principles-community](http://diversity.berkeley.edu/principles-community)).  The consequences for failing to act within these standards may include failing an assignment, a referral to the Center for Student Conduct and Community Standards, a failed grade in the course, and even immediate expulsion. A note on plagiarism: even in the scope of providing a partner with a walkthrough for securing a certain account or system, you are expected not to copy material from another guide, website, article or book (word-for-word or paraphrased) without citing the source - it’s a small community and we should give credit where it is due. Other examples of unacceptable conduct include turning in deliverables created by students not currently in the course, work found on the Internet, or created by a commercial service.

**Disability Accommodation**.

If you need disability-related accommodations in this class, if you have emergency medical information you wish to share with us, or if you need special arrangements in case the building must be evacuated, please inform us as soon as possible.


# Lesson Modules


# Introduction to Public Interest Cybersecurity

#### \*\* Summary \*\*

Module 1, Introduction to Public Interest Cybersecurity, illuminates core themes of the course such as access to cybersecurity, the threat landscape, and the role of ethical considerations in guiding public-interest cybersecurity work. Ultimately, students should emerge from this module with a greater contextual understanding of what public interest cybersecurity work looks like and the implications of engaging in this work. Students should also understand the time commitment and responsibilities associated with successfully completing this course.

#### \*\* Learning Objectives \*\*

* Understand and explain public interest cybersecurity work
* Identify and understand barriers of civil society’s access to cybersecurity
* Understand and explain how Citizen Clinic supports politically targeted communities
* Identify how public interest cybersecurity has value to individuals, organizations, and society

#### \*\* Pre-Readings \*\*

* See readings for “Introduction to Public Interest Cybersecurity”

#### \*\* Resources \*\*

* [Baseline Organizational Security Guide](https://www.citizenclinic.io/LRO/0-Introduction_and_TOC_\(README\)/)

#### \*\* Activities \*\*

* Icebreaker activity. As this module will start off any clinic iteration, it is important that instructors establish an inclusive environment and the class starts to learn about one another. Icebreakers that avoid putting students “on the spot” or excluding them due to ability is key. While there are many good activities, we suggest achieving these goals:
  * Learning preferred pronouns. *(Note: Do not make this mandatory: if someone skips listing their pronouns, there may be a personal reason. Also, reassure the class that you realize that the pronouns shared on the first day may change and that students may prefer to use different pronouns in this context versus outside of the program.)*
  * Learning preferred names.
  * Learning proper pronunciation of names.
* As an instructor, it is important that you model your requests for information. Share your pronouns and your reasons for teaching the course. Participate in any fun activities that you want your students to do - this exemplifies the nature of clinical learning.

#### \*\* Discussion \*\*

Ask your students:

* What does work in the “public interest” mean? Who does it impact?
* What is “cybersecurity”?
  * What about trolling, harassment, and disinformation?

#### \*\* Input \*\*

* What is the “public interest”?
  * Describe types of work or professions associated as public interest work.
  * Describe how that work may be distinct from private sector or government work.
  * Define civil society.
  * Describe the history of public interest clinics in law and medicine, and the impact they’ve had on the field long term.
* Who has access to cybersecurity?
  * Provide examples of enterprise expenses and other security costs:
    * Examples from industry reports: “The average large enterprise spends $16.7 million annually on security software and the people who run it.”
      * $160,000 per year on advanced threat protection (ATP) software.
      * $44,000 per year on traditional or next-gen antivirus software.
      * $30,000 per year on whitelisting/blacklisting solutions.
      * $112,200 per year on detonation environments” (Source: Bromnum report: <https://learn.bromium.com/rprt-hidden-costs.html>)
    * Security keys can be $50 a piece
  * What about organizations that are “low risk”? IT investments will likely be lower priority than direct mission/impact expenses regardless of risk.
  * Why do even “low risk” organizations need cybersecurity assistance?
* Who does public-interest cybersecurity work?
  * Is this just a technical field? Why or why not?
  * Why can’t governments do this work? Aren’t they responsible for citizen security?
  * Provide diverse examples of practitioners in the field.
* What role does Citizen Clinic and other cybersecurity clinic programs have?
  * Build greater capacity for technical assistance over long-term versus simply providing training.
  * Much of civil society’s digital protection needs are not highly sophisticated but require time, people, and understanding of context.
  * What Citizen Clinic is not: \* Not a penetration testing lab. \* Not a software development lab. \* Not a cybersecurity law clinic.
  * Program goals for students:
    * Broadening: Introduced to broader aspects of cybersecurity.
    * Deepening: Gain a deeper understanding of the digital safety needs and challenges for under-resourced civil society.
    * Hands-on: Gain hands-on experience uncovering practical solutions to those cybersecurity challenges.
    * Impact: Create positive change in the real-world by protecting civil society.

#### \*\* Deepening \*\*

* Break students into small groups and discuss the similarities and differences of a public interest law clinic or a medical clinic program from a technology / cybersecurity clinic.
  * Discussion groups should have students from different departments to engender cross-program conversations and illuminate key differences between fields. Depending on the size of the class, assign groups to compare or contrast either public interest law clinics or medical clinics with your clinic program.
  * After some time in groups, have those groups share with the rest of the class.
  * Key points to discuss:
    * The creation of “public interest” professions
    * Supervision by licensed, active professionals from outside the clinic
    * Experiential learning
    * Elements of scale: clients, students, workforce
    * Institutional appreciation
    * Prestige
    * Long-term engagements
    * High-impact cases versus student growth

#### \*\* Synthesis \*\*

* How does public-interest cybersecurity work have value for...
  * Individuals?
  * Organizations?
  * Society?

#### \*\* Assignments \*\*

* Students submit a brief explanation \[no more than 1 page;] of (1) why they want to learn about public interest cybersecurity and (2) how they might apply their prior experience, skills, or past coursework to protect politically vulnerable organizations as defined in this report <https://cltc.berkeley.edu/defendingpvos/> *(Note: Our students do not learn about the identity of their partner organization until they have agreed to the Clinic Code of Conduct (see Module 2))*


# Ethics and the Citizen Clinic Code of Conduct

#### \*\* Summary \*\*

Module 2 introduces ethical considerations for clinical security work. Our look at ethics builds on the work of the Markulla Center for Applied Ethics, at Santa Clara University, and introduces a set of ethical considerations and norms specific to the work of Citizen Clinic. (For more information, see Citizen Clinic Code of Conduct.)

#### \*\* Learning Objectives \*\*

* Identify ethically significant harms in cybersecurity (and the Clinic)
* Identify ethical challenges in cybersecurity (and the Clinic)
* Understand best practices for cybersecurity ethics including the three components of informed consent
* Understand one's mandate to regularly consider the ethics of their position and work

#### \*\* Pre-Readings \*\*

* See Course Readings for "Ethics and the Citizen Clinic Code of Conduct"

#### \*\* Resources \*\*

* Citizen Clinic Code of Conduct

#### \*\* Activities \*\*

Read pages 7-21 & 48-52 of “An Introduction to Cybersecurity Ethics” (Shannon Vallor, The Markkula Center for Applied Ethics) \[<https://www.scu.edu/media/ethics-center/technology-ethics/IntroToCybersecurityEthics.pdf>] Prepare answers to questions on pages 13-15 and page 53 for discussion.

Question 1.1: What risks of ethically significant harm, as defined in Part One, are involved in this case? Who could be harmed if Leslie makes poor choices in this situation, and how? What potential benefits to others should she consider in thinking about BioHack’s proposal?

Question 1.2: Beyond the specific harms noted in your answer to 1.1, what are some ethical concerns that Leslie should have about the proposed arrangement with BioHack? Are there any ethical ‘red flags’ she should notice?

Question 5.1: Of these 12 best practices for cybersecurity ethics, which two do you think are the most challenging to carry out? What do you think could be done (by an individual, team, or organization) to make those practices easier?

#### \*\* Discussion \*\*

What ethically significant harms should we consider?

What ethical challenges (Vallor pg 15-20) might we encounter?

#### \*\* Input \*\*

Consider “First, do no harm”...

...but discuss the limitations of that guiding principle.

We should be intentional about the decisions we make and intervene in ways that will not make the situation worse. Ultimately, the organization and its well-being should be your primary concern. However, you also have a duty to yourself, your family, and your team members. Sometimes it may seem like there are no good answers (for instance, doing nothing because there might be risk is not a resolution). If we view our interventions as already raising the risks for our partners and ourselves, what can we actively do to mitigate that?

Informed Consent

* Discuss and define disclosure, comprehension, and voluntary participation.
* Understand the effect of your institutional affiliation and positioning.

Tools and methods for good (ethical) can be used for bad (unethical).

Important questions to regularly ask:

* Are you, your team, or your partner able to do this?
* Are you, your team, or your partner willing to do this?
* Do you, your team, or your partner have any conflicts of interest?

#### \*\* Deepening \*\*

What should our Code of Ethics look like? (Vallor pg 48)

#### \*\* Synthesis \*\*

Review the Citizen Clinic Code of Conduct. Highlights:

* Harassment and Discrimination
* Operational Security
* Confidentiality
* Professionalism
* Reporting

#### \*\* Assignments \*\*

Review and submit signed Code of Conduct.


# Citizen Clinic Student Code of Conduct

The Citizen Clinic is an inclusive course where students, mentors, and staff should feel comfortable sharing their work, opinions, and perspectives. All of us commit to engaging with each other mindfully to ensure an environment that promotes shared learning and collaboration.

!!! tip "When does the Code of Conduct apply?" This Code of Conduct governs participation at the Citizen Clinic. It applies to all Clinic participants during all class meetings, as well as to all Clinic participants at after-hours working sessions or social events. The internet is real life. This Code of Conduct applies in all digital spaces connected to the Clinic (e.g., group chat channels, mailing lists, collaborative documents) as well as physical ones. Participants who violate this Code may be excluded from this and future Clinic opportunities, and may be prohibited from attending Clinic social events.

Clinic participants are expected to comply with the policies that govern all activities and behavior at UC Berkeley, in particular the [Nondiscrimination Policies and Procedures, Sexual Violence and Harassment Policies and Procedures](https://ophd.berkeley.edu/policies-and-procedures/students), the [Student Code of Conduct](http://sa.berkeley.edu/sites/default/files/UCB-Code-of-Conduct-new%20Jan2012_0.pdf), and the [Computer Use Policy](https://security.berkeley.edu/computer-use-policy).

In addition, we expect all Clinic participants to abide by the following parameters:

* Be respectful to others. Do not engage in homophobic/homomisic, racist, transphobic/transmisic, ageist, ableist, sexist, or otherwise exclusionary behavior. Honor individuals’ preferences for how they prefer to be addressed.
* Use welcoming and inclusive language. Exclusionary comments or jokes, threats or violent language are not acceptable while working in the Clinic. Do not address others in an angry, intimidating, or demeaning manner. Be considerate of the ways the words you choose may impact others. Be patient and respectful of the fact that English may be a second (or third or fourth!) language for Clinic participants.
* Do not harass people. Harassment includes unwanted physical contact, sexual attention, or repeated social contact. Know that consent is explicit, conscious and continuous—not implied. If you are unsure whether your behavior towards another person is welcome, ask them. If someone tells you to stop, do so.
* Respect the privacy and safety of others. Do not take photographs of others without their permission. Note that posting (or threatening to post) personally identifying information of others without their consent (“doxing”) is a form of harassment.
* Be considerate of others’ participation. Everyone should have an opportunity to be heard. While working in teams, please keep comments succinct so as to allow maximum engagement by all members. Be conscious and respectful of the fact that your team members may have different methods of communicating, and work to enable the most collaborative environment among your team.
* Don’t be a bystander. If you see something inappropriate happening, speak up. If you don’t feel comfortable intervening but feel someone should, please feel free to ask a member of the Clinic staff to intervene.
* As an overriding general rule, please be intentional in your actions and humble in your mistakes.

## **Operational Security**

Working with the Citizen Clinic will require engagement with its partner organizations. These organizations and their staff, partners, and the communities they serve are often at risk of online or physical attacks. Therefore, adherence to Clinic operational security procedures is not just a requirement for academic success, but for safeguarding the lives and livelihoods of Clinic partners, students, staff, and their friends and families.

In order to facilitate a secure, safe working environment, all Clinic participants are expected to:

* Adhere strictly to any operational security requirements set for partner communications by your team, by Clinic staff, or by the partner.
* Do not seek to undermine existing security controls. Should you feel a security measure is ineffective, bring your concerns to Clinic staff before taking measures to alter any security systems or policies.
* Respect partners’ perspectives. Even if we do not agree with a partner’s security concerns, we learn more about their security context by listening than telling. We do not know what we do not know.
* Keep track of any Clinic-owned devices assigned to you or your team. Ensure they are under the control of you or your team at all times, or are securely stored when not in use, and do not engage in any unlawful or unethical online or offline behavior with them. Do not change any device settings in ways that would reduce device security. These devices are the gateway to our partners and the Clinic’s electronic infrastructure. You are the gatekeeper.
* Report any security incidents or concerns immediately to Clinic staff. This includes, but is not limited to, the loss, theft, or compromise of Clinic-owned devices or data stored on them.

## **Confidentiality**

As a condition of allowing students to participate in the Clinic, including access to the Clinic’s

computers or other systems, all students agree to strictly protect any Confidential

Information they receive as a result of their work with the Clinic. While the decision about whether information is “Confidential Information” depends on the specific information itself, some examples of Confidential Information include:

* The names of partner organizations, their staff or clients, or other persons related to a Clinic project, or information likely to indicate identity;
* Any information related to organizational assessments or policy findings and recommendations;
* Any private communication or information regarding a specific partner, a case, research data or analysis, including any underlying facts and circumstances not already revealed to the public;
* Any report or other written material, including that which the undersigned or their team has drafted, unless such document has been approved for release and properly redacted by a member of the Clinic supervising faculty or professional staff; and
* Identities or other personal information about partners required by applicable research protocols to remain confidential to minimize the risk to research subjects of participation in research.

The undersigned student agrees that they will not violate the confidentiality of the Clinic’s interests or those of the Clinic’s partners by revealing Confidential Information to those outside the Clinic. By signing this agreement, the student agrees not to disclose Confidential Information orally or in writing, including through electronic media or any online forum, and not to write about any aspect of a Clinic case or project in any print or online publication without the express, prior permission of the Clinic’s supervising faculty or professional staff. The obligation of each student to maintain the confidentiality of information is on-going and continues after the student’s participation in the Clinic has ended.

Clinic faculty and professional staff are available to answer any questions or concerns about this

Agreement, or about disclosure of any specific information. Students who are uncertain about whether certain information is Confidential Information should ask mentors, Clinic faculty or professional staff before any disclosure.

## **Professionalism**

Working with partner organizations is a position of significant privilege and trust. Your work does not just represent you, but your team, Citizen Clinic, the Center for Long-Term Cybersecurity, the School of Information, and UC Berkeley at-large. Students are expected to be on-time to all partner meetings (*remember: partners are not on Berkeley time*), and to be attentive and respectful during all external-facing engagements.

Work product, communications, and other partner-facing materials you may produce over your time with the Clinic must adhere to a very high standard of quality. The work that is done in this course varies from team to team, but always keep in mind these three characteristics when preparing work for partners:

* **Rigor:** Be thorough in your research. Do not make recommendations for partners based on what you assume they need—all recommendations should have a rigorous explanation behind them.
* **Attention to Detail:** Spelling, grammar, design, organization—do not underestimate the importance of details. We want partners to rely on the materials we create when they are considering meaningful decisions about their security. Bad writing does not instill confidence.
* **Contextualize:** Think about who your audience is for any document or deliverable—whether it is an email, an organizational policy, or a report. Who is reading it? Who might read it? How technical are they? Do they read English? How well? Tailoring your work to your audience is critical to making the work meaningfully received and understood.

## **How do I report an issue related to the Code of Conduct?**

Please report any issues related to the Code of Conduct to:

* Faculty or staff member
* Faculty or staff member

Please speak to us if you encounter an issue—whether related to a specific situation or to a more general aspect of the Citizen Clinic. You can contact the Citizen Clinic staff team as a group or individually, in person or by email.

You can also report issues to the Citizen Clinic staff **anonymously**\[^1] — but please use an email address where you’ll be able to receive replies.

Many campus resources are also available for reporting incidents of harassment, violence, or discrimination. You can find information about those programs and contacts (including official reporting pathways) here:

* PATH to Care Center: <http://survivorsupport.berkeley.edu/report>
* Office for the Prevention of Harassment and Discrimination: <https://ophd.berkeley.edu/home>

## **Conflicts of Interest - Reporting**

If an issue, complaint or concern involves a member of Clinic staff or mentors, that person will be removed from the issue response process and will not have access to documentation related to the issue.

## **Conflicts of Interest – Partner Services**

Students must seriously consider their own political, religious, cultural, and social affiliations before agreeing to work with any given partner. If anything about a student’s personal beliefs may cause a conflict of interest or prevent them from providing effective support to a partner, they are obligated to communicate with Clinic staff immediately so they can be assigned to a new team.

## **Appropriate Responses**

Staff will address all complaints or concerns in a responsive and expedient manner. Each case will be processed as is contextually appropriate and in line with existing University procedures. If, at any point, a student feels a concern, complaint, or report is not being addressed appropriately, they should escalate issues to the CLTC Faculty Director or other campus resources (such as Office for the Prevention of Harassment and Discrimination).

Based on the nature of the issue, the Clinic Staff will propose a course of action to the individual who made the report, and, where not prohibited by law or university policy, work with them to determine whether that proposal is an appropriate response before acting.

An appropriate response is one which:

* Seeks to ensure the safety, dignity and security of all Clinic participants;
* Respects the autonomy, experience and judgment of those who decide to report an issue;
* Aims to provide a resolution that is meaningful and fair to all participants affected;
* Encourages accountability, responsibility, cooperation, honesty, personal growth and respect on the part of all participants affected;
* Is context-specific and aims to “make things right,” repairing specific harms to affected individuals;
* Works toward greater inclusiveness in the Clinic; and
* Complies with UC Berkeley policies, and involves University staff as appropriate and required by those policies.

***

The undersigned agrees to abide by the terms of this Code of Conduct for the duration of their involvement with the Citizen Clinic. Failure to do so may result in disciplinary action outlined within the code, or as required by UC Berkeley policy.

Your Name (Printed):

Your Signature:

Date:

## ***Attribution***

*Much of this Code of Conduct is based on the* [*Citizen Lab Summer Institute Code of Conduct*](https://citizenlab.ca/2017/07/citizen-lab-summer-institute-code-conduct/)*. Parts of this Code are based on the* [*xvzf Code of Conduct*](http://xvzf.io/)*, the* [*Contributor Covenant*](http://contributor-covenant.org/)*, the* [*Django Code of Conduct*](https://www.djangoproject.com/conduct/) *and* [*Reporting Guide*](https://www.djangoproject.com/conduct/reporting/)*. This code has also been influenced by* [*this guidance from Ada Initiative*](https://adainitiative.org/2014/02/18/howto-design-a-code-of-conduct-for-your-community/)*.*

## Notes

\[^1]: An example of how to anonymously report: Use Tor to create and log in to a new email address, use the address exclusively for the purpose of your report, and never provide information that would personally identify you—to either the email service provider or to us.


# Old School INFOSEC: Basic Controls

#### \*\* Summary \*\*

Module 3, Old School INFOSEC: Basic Controls, provides an introduction to tools and other controls for students and their partner organizations to use in mitigating risks to their digital safety. This module helps bolster the capacity for individuals and organizations to compare security policy by prescription versus critical evaluation.

#### \*\* Learning Objectives \*\*

* Introduce students to common security controls
* Identify methods to deploy organizational policy
* Identify friction / obstacles to setting up security controls

#### \*\* Pre-Readings \*\*

* See readings for Old School INFOSEC: Basic Controls

#### \*\* Resources \*\*

* [Baseline Organizational Security Guide](https://www.citizenclinic.io/LRO/0-Introduction_and_TOC_\(README\)/)

#### \*\* Activity \*\*

This activity is to identify as many security-related activities, ideas, questions and potential misconceptions. Have students brainstorm individually or as a team answers to these questions. We suggest writing answers on sticky-notes or on a whiteboard and group the answer in similar clusters as they are shared.

* What is the one thing that everyone should do to protect themselves or their systems?
* What is one thing that everyone should avoid doing?
* What is one thing that you want to learn about cybersecurity?

Other options:

* What things do we do to protect digitally ourselves?
* What things have we heard about that protect our systems?
* What are security or other digital things that we’ve been confused about?

#### \*\* Discussion \*\*

* What things are missing from the resulting groups of suggested actions and ideas?
* Why do you think these clusters formed?
* How did we learn how to “be secure”?

#### \*\* Input \*\*

* Why even “low risk” organizations need cybersecurity
  * Confidentiality, Integrity, Availability
* Strong Authentication
  * Multi-factor Authentication
  * Strong Passwords and Password Managers
  * Account Monitoring
* Automatic Updates and Software Licenses
* The Cloud
  * HTTPS
  * Data Security
  * Encryption
  * Access Management
* Friction of getting existing staff on board with the new security protocols
  * “This is the way we’ve always done things”: the story of the five gorillas
  * Leadership buy-in vs ground floor buy-in
* Friction of getting new staff on board with existing security
  * The dreaded “New Employee Handbook”
  * Non-profit pressure to hit the ground running

#### \*\* Deepening \*\*

\[30 mins in-class, continue as homework] Have students set up their personal devices or assigned devices according to a default, prescribed organizational “secure” configuration or policy that you create.

* The purpose of this activity is to setup the basic security to conduct clinic work. Second, students will empathize with an onboarding process that they may propose for their future client organizations. Finally, they may gain further appreciation of the operational burdens of working in a “high security” environment.
* When possible, check on student learning by having them perform a task that demonstrates that they have completed the proper setup. For instance, students can send you an encrypted message or a secure note via a password manager. Alternatively, use admin tools from managed service providers to report whether students have enrolled in 2FA or changed passwords.
* Use the Baseline Organizational Security Guide to help you create this policy in advance of your course creation. Elements to consider:
  * How might students use their personal devices or clinic-assigned devices? What device policies are required? Automatic updates?
  * Will you use virtual machines? If a student’s device does not meet your minimum system requirements, how will you provide a device?
  * How might students connect to the Internet? Will they use virtual private networks?
  * How will students use email and collaborate via shared folders?
  * How might students communicate via mobile devices, with you, their client organization, and each other?
  * Consider having the students...
    * Setup a password manager
    * Create strong, unique passwords for their Clinic accounts
    * Setup multi-factor authentication
    * Setup a VPN client
    * Install specific browsers & plugins
    * Install an SSH client
    * Setup an E2E encrypted messenger
* During the class activity, we’ve found it useful to have students with similar devices but different levels of technical expertise to work together. We lead the students through steps in the setup process and discuss any tricky or confusing steps in this process.

#### \*\* Synthesis \*\*

Discuss the advantages and disadvantages of prescribed security policy. Receiving instructions on how to set-up accounts without a full understanding of what each control protects may not always be a bad thing. When and why may dictating initial setup procedures be useful, especially in a non-profit organization? How might this “onboarding” process be improved?

#### \*\* Assignments \*\*

**Complete communications setup.**

Complete the communications setup (see Deepening activity) according to your Clinic protocol. Encourage students to help one another to complete or to use office hours.

**Optional reflection assignment.**

* Being a security practitioner requires you to be intimately familiar with the steps someone could take to protect themselves: one must understand the burden on the user, learn how to communicate those steps effectively, and, most importantly, define the “protection” offered by implementing certain controls (eg. “Security keys can help *which persons* to protect *what information* from *which threats* in *which contexts*?”). At this early stage in the course, we don’t expect you to already know every reason why the clinic’s information system is setup in the above manner, but you should be asking yourself why you took certain steps and, perhaps, questioning why or how certain decisions were made.
* Write a reflection on the above communications setup process.\
  1\. What parts of the process were difficult to complete? What factors contributed to those challenges? How would you improve the process if you were guiding someone else to complete these tasks? 2. Which parts of the process were easy for you to complete? What factors contributed to you having a relatively easier time with parts of this process? 3. Consider your new system setup (equipment, service providers, identifiers) we’ve provided in terms of security or privacy for you and a potential client. What are the advantages of this setup? What are its disadvantages? How might we overcome those disadvantages during this course?


# Digital Surveillance of Politically Vulnerable Organizations: The Threat Landscape

#### \*\* Summary \*\*

Module 4, Digital Surveillance of Politically Vulnerable Organizations: The Threat Landscape, immerses students in most salient threats to vulnerable civil society organizations and their use of both encrypted and unencrypted systems. This module explores common surveillance threats such as intercepting communication, deanonymizing targets, accessing targets’ online accounts, malware, and zero day exploits. Credit to Bill Marczak for developing the majority of this module and our specific implementation for Citizen Clinic.

#### \*\* Learning Objectives \*\*

* Be able to define and identify common threats
* Compare surveillance threats across encrypted and unencrypted systems
* Understand the fiscal incentives involved in the likelihood of attacks

#### \*\* Pre-Readings \*\*

See readings for Digital Surveillance of Politically Vulnerable Organizations: The Threat Landscape

#### \*\* Activity \*\*

Using a recent breach or cyberattack in recent news or current events, have students discuss how they believe the attack happened, how the attack might have been worse, and what other techniques the adversary could have tried.

* The goal of this activity is to start building the foundations of applying theory from the literature to current scenarios in advance of breaking down individual steps in the attack.
* Students should begin highlighting where and when the attack could have been prevented, according to the scenarios that they suggest (it’s ok if they do not have the facts on how the event actually happened). Introduce concepts such as ‘cyber kill chain’ if you feel it is appropriate.

#### \*\* Discussion \*\*

1. Are we concerned about a similar situation happening to us? Why or why not?
2. What activities, tools, or other measures do we individually take that could prevent a similar situation from happening to us? What about the measures we take as a Clinic?
3. Which of those things should be done regardless of the likelihood of the same attack happening to us? Which things might be burdensome for us to keep doing?

#### \*\* Input \*\*

* (*Reference to the Le Blond reading*) Define “targeted attacks” and “APTs” or “advanced persistent threats.”
* Reminder of ethical use of the discussed information
* Risks of unencrypted communications
  * Phone calls and SMS are really bad for confidentiality!
  * Weaknesses in SS7 protocol: See Circles and Hacking Team <https://www.adaptivemobile.com/blog/can-they-hear-you-now-hacking-team-ss7>
  * Telecommunication provider cooperation with governments: See case of Nokia Siemens
  * Also, call detail records, tower dumps, and cell site simulators
* Risks of Encrypted communications
  * Deanonymizing targets
    * Identifying IP address via IP loggers sites, server logs, and tracking images
    * Governments take IP address to ISP via court order
  * Accessing targets’ online accounts and communications
    * Frontdoor: Social engineering
      * Phishing
      * Account Recovery Process
      * Asking recovery code sent to their own phone
    * Backdoor: Government requests to platforms
      * See Transparency Reports to get an idea of which countries are more likely to get responses from platforms
  * Malware and zero-day exploits
    * Malicious attachments & macros: See Finfisher and Project Raven
    * MITM & Deep Packet Inspection to replacing (unencrypted) downloads with spyware: See PacketLogic and spyware injection in Turkey
    * NSO Group: Pegasus and 1-click / 0-click deployment on phones

#### \*\* Deepening \*\*

How should we think of these threats?

* Wiretapping
* Phone tracking
* Targeted deanonymization
* Intel gathering
* Phishing
* Targeted malware
* Zero-day
* Packet injection
* Non-targeted surveillance
* Accidental ransomware download
* Bitcoin scam

In small groups, have students categorize those attacks into 4 to 5 groups according to...

* the relative cost for adversaries to deploy them against an individual NGO.
* the relative frequency that adversaries deploy them against an individual NGO.

As groups share their suggested categories & rankings, discuss how fiscal incentives may or may not have a bearing on how common an attack is likely to occur. Ask and discuss how controls from the communications setup in Module 3 might help protect the Clinic from the described attacks.

#### \*\* Synthesis \*\*

Given all of these threats, how can an organization raise the bar and the resources an adversary needs to dedicate against the targeted NGO?

* Securing accounts is something we’ve discussed but now we see the need to understand these attacks, think critically, and rely upon others in an organization.
  * Use an alternative communication channel to contact the sender of a suspicious message
  * Don’t click immediately or at all (eg, expand shortened URLs, go to website directly)
  * Ask yourself: would the government actually call me if there was a problem with my taxes?
  * See something, say something: others in an organization are likely to be targeted as well.

Social engineering is an important component of targeted attacks. Why?

We see the need for not just technical controls, but organizations require awareness, training, policies, cohesion, and well-being in its staff. Why?


# Problem Diagnosis and Reframing

#### \*\* Summary \*\*

Effective problem diagnosis and reframing is integral to developing appropriate risk mitigations for the security of civil society organizations. When cybersecurity consultants focus on solving the immediate or obvious problems, sometimes the more important problems go unaddressed - consider the difference between patching a vulnerability and maintaining a security program that will ensure patches are quickly and regularly applied. This module will introduce practices for reframing problems such that higher objectives such as improving organizational effectiveness can be achieved.

#### \*\* Learning Objectives \*\*

* Diagnose problems and solutions to determine whether the “right” problem is being addressed.
* Learn how to reframe problems so that higher consulting objectives can be achieved.
* Introduce the reframing of complex problems to the client or others.

#### \*\* Pre-Readings \*\*

* See Course Readings for "Problem Diagnosis and Reframing"

#### \*\* Activities \*\*

Discuss the *seven practices for effective reframing* described in the “Are You Solving the Right Problems?” article. Consider the Slow Elevator problem or the Dog Adoption problem.

* In your own experience, have you encountered times where the “right problem” was missed?
* Did you use any of the practices or do you think any of the practices would have helped you in that situation?
* What resistance or obstacles did you or might you encounter when reframing problems that your partner organization might present to you?

#### \*\* Discussion \*\*

From “Consulting is More than Giving Advice”, these are consulting’s eight fundamental objectives:

1. Providing information to a client.
2. Solving a client’s problems.
3. Making a diagnosis, which may necessitate redefinition of the problem.
4. Making recommendations based on the diagnosis.
5. Assisting with implementation of recommended solutions.
6. Building a consensus and commitment around corrective action.
7. Facilitating client learning—that is, teaching clients how to resolve similar problems in the future.
8. Permanently improving organizational effectiveness.

Where in this hierarchy does our Clinic work fall?

Public interest cybersecurity has few service providers that reach objectives 5 - 8. Why?

#### \*\* Input \*\*

Why do we miss the “right” problem or focus on the “wrong” problem? Common reasons for missing the “right” problem or solution.

* Confirmation Bias.
* Mental Rigidity / “Paradigm Paralysis.”
* Unnecessary Constraints.
* Groupthink.
* Irrelevant Information.

Problem Reframing

* Broaden the focus. Explore the more general problems that your problem may be a part of.
* Narrow the focus. Break down your problem and focus on its component parts.
* Reverse the focus. Take on the opposite view of your problem statement. This technique may challenge the underlying premise.
* Rephrase the issue. Rephrase or paraphrase the words in your problem statement. What parts of your problem are highly defined? What parts are ambiguous? Replace any value-laden words.
* Pros and cons. What do you like about your problem statement? What do you not like? Improve the parts that you're not satisfied with.
* Validate your thinking. Have you validated that you are working on the real problem? If so, how? (Example, Socratic questioning)

Validate your thinking (from <https://hbr.org/2017/01/are-you-solving-the-right-problems>).

* Question the objective.
* Consult outsiders.
* Gather individual definitions of the root cause of the problem.
* Explicitly define what might be missing in the problem statement.
* Have multiple people identify what type/category of problem you are trying to solve (ex: “resources” “incentives” “values”“systemic”)
* Identify positive exceptions. (When the problem does not occur, what was different about those circumstances?)

#### \*\* Deepening \*\*

Consider the question: “Hi! What is the best app to use for setting up a remote call with our partner organization? Should we use Hangouts in the virtual machine or something else?”

Individually or in small groups, re-envision the questions when you do the following:

* Broaden the focus.
* Narrow the focus.
* Reverse the focus.
* Rephrase the issue. What parts are highly defined? Ambiguous? Value-laden?
* Pros and cons.
* Validate your thinking.

#### \*\* Synthesis \*\*

Review the fundamental objectives of consulting and how problem reframing can help with reaching those higher level objectives. In practice, revisiting problems with your client may require a combination of strategies:

* Deep Listening
* Framing Trade offs
* Finding some no-brainers and quick wins
* Low cost experiments and incremental steps
* It was their idea not yours

#### \*\* Assignments \*\*

Develop your communications plan for working with your partner organization:

* Define / Validate the Problem.
* Conduct Mini-PESTLE.
* Determine Threat Model.
* Select Options
  * Consider Security, Usability, Reliability, Familiarity, Cost, Backup
* Test Options & Reassess.


# Threat Modeling & Bounding Risk Assessments

#### \*\* Summary \*\*

This module will describe the concepts of threat modeling and bounding risk assessments. These concepts are important for practitioners since we will never have enough time to conduct as thorough a risk assessment as we would like. Having some practical bounds when analyzing risk is even more important for organizations attempting to adopt risk-informed practices and proactive security given the resource constraints commonly facing our clients.

#### \*\* Learning Objectives \*\*

* Understand how to prioritize security measures based on risk and other organizational pressures.
* Identify the cybersecurity maturity and path of growth for an organization.
* Develop threat models bounded by given resource constraints.

#### \*\* Pre-Readings \*\*

* See Course Readings for "Threat Modeling and Bounding Risk Assessments"

#### \*\* Resources \*\*

* [EFF, Threat Modeling Activity Handout For Learners](https://sec.eff.org/materials/threat-modeling-activity-handout-for-learners)

#### \*\* Activities \*\*

Play the following newscast from CyberWire:

<https://youtu.be/MyY6hjABkk4?t=115>

As small groups, discuss the targeting of Citizen Lab and then share answers to the class:

* What are the threats?
* What are the adversaries seeking?
* What damage could this cause? How might this situation played out differently?

#### \*\* Discussion \*\*

Discuss the following questions:

* How concerned should Citizen Clinic be about a similar approach?
* What is the probability of this happening?
* What is the potential impact?

#### \*\* Input \*\*

NIST Cybersecurity Framework allows us to define the *things an organizations should do, and where to find commonly-accepted definitions of those things*

One of the better things to come out of the Cybersecurity Framework is the implementation tier maturity model: describe what cybersecurity growth looks like -- where is an organization at now, where do they want to *get* to, and where do they want to be set up to go long-term?

(See explainer: <https://www.cybersaint.io/blog/the-nist-cybersecurity-framework-implementation-tiers-explained>)

* Tier 1 - Partial: Risk management is typically performed in an ad-hoc/reactive manner. Security activities are typically performed with little to no prioritization based on risk.
* Tier 2 - Risk-Informed: Risk management practices are typically not established as organizational-wide policies but, along with the organizational objectives, the threat environment, and business requirements, directly inform the prioritization of security activities.
* Tier 3 - Repeatable: Formally approved and regularly updated risk management practices that are expressed as policy.
* Tier 4 - Adaptive: Organizations adapt their security practices, including lessons learned and predictive factors, implementing a process of continuous improvement.

Our clients are almost exclusively at Tier 1. To reach Tier 2, our clients need risk-informed security activities, but what does it mean to be risk-informed?

**Threat modeling allows us to prioritize by risk and resources: Probability x Impact = Risk (see EFF’s <https://ssd.eff.org/>).**

1. What do I want to protect? (Assets)
2. Who do I want to protect it from? (Threats / Adversaries)
3. How bad are the consequences if I fail? (Impact)
4. How likely is it that I will need to protect it? (Probability)
5. How much trouble am I willing to go through to try to prevent potential consequences? (Mitigations)

Risk (impact and likelihood) is one pressure for prioritization but an organization must also consider urgency (availability, dependencies), requirements (legal, contractual) and incentives (funding, opportunities).

We still need to scope the bounds of risk assessments since analyzing all risk can be unwieldy for even less complex systems. Also, people (including the security practitioner) only have so much time and attention. Bounding assessments is about finding specific areas of focus: where do we need more time, attention, details?

#### \*\* Deepening \*\*

Share the following scenarios with students to discuss in small groups.

Part 1. You’re conducting a broad organizational security assessment for a partner. You discover a few critical pieces of information:

* You suspect many of their devices may be out of date or running illegitimate copies of software
* A system they are deeply dependent runs on a service that is out of the support lifecycle
* A member of their staff recently had the webcam on their laptop turn on and off mysteriously

All of these things will take time to assess. Where do you start? How would you figure out what to focus on?

Part 2. Your partner wants to use Skype as the primary way to communicate. Everyone in their organization has a Skype account and it is currently the primary way they hold conference calls and send messages between staff and partners.

Discuss in assigned teams:

* Initial reactions: Is it secure? Is it reliable?
* What are the risks? What adversaries might present greater concerns?
* What is the your risk *tolerance*? Why should you tolerate any risk for this partner to use their preferred communications method?

#### \*\* Synthesis \*\*

Review the concepts of threat modeling and risk assessment by discussing the threat model for your own Clinic program and how various activities were prioritized. Discuss resource constraints or other business requirements that were considered in implementing risk mitigations.

#### \*\* Assignments \*\*

Develop your initial client threat model.

1. What do they want to protect? (Assets)
2. Who do they want to protect it from? (Threats / Adversaries)
3. How bad are the consequences if they fail? (Impact)
4. How likely is it that they will need to protect it? (Probability)
5. How much trouble are they willing to go through to try to prevent potential consequences? (Mitigations)


# Contextual & Capacity Research

#### \*\* Summary \*\*

Security does not happen in a bubble. Every security policy, setting, and tool needs to be tailored for the specific context of the organization. Particularly with non-profit organizations that work with fewer resources, under different circumstances, and for different motivations than for-profit or government entities, "industry best practice" and boilerplate policies can actually cause more harm than good. Instead, security assistance providers must consider the context and capacity of their partner organizations, including political, economic, social, technological, legal, and environmental factors both within and beyond the organization.

#### \*\* Learning Objectives \*\*

* Understand how contextual factors can impact an organization's security
* Understand methods to identify relevant contextual factors
* Understand methods to identify and categorize gaps and assumptions in one's analysis
* Understand how to use the PESTLE framework

#### \*\* Pre-Readings \*\*

* See Course Readings for "Contextual & Capacity Research"

#### \*\* Resources \*\*

* Contextual Factors (PESTLE-M) Worksheet
* Contextual Assessment Information Requirements

#### \*\* Activities \*\*

\*\* Assumptions Game (for small class size) \*\*

Each student writes an interesting "hard to guess" fact about themselves (that they feel comfortable revealing to the class) on a sticky note and gives to the instructor (or private messages the instructor). The instructor displays all the "facts" (without the fact's owner) to the entire class. The class votes to match up each fact to a specific student. After each student is assigned a fact, the instructor asks which students have the correct fact assigned to them. When students are correctly matched with a fact, the class discusses why or why not they made that guess. Conduct multiple rounds until all students are assigned their correct fact.

\*\* Assumptions Game (for large class size) \*\*

Each student writes three interesting facts about themselves believed to be unique among the rest of the class. Ensure that students feel comfortable revealing this information to the rest of the class. One by one, have students state the three facts and then see, by show of hands, whether any facts might also describe other students. If a student raises their hand, the student that stated the three facts must guess which of the facts is shared between the two students.

#### \*\* Discussion \*\*

Why were some "secrets" figured out quickly while others took a long time? What assumptions did you make that helped or hurt your guesses?

Consider the following perspectives:

*“I shall reconsider human knowledge by starting from the fact that we can know more than we can tell”* Michael Polanyi, The Tacit Dimension (1966)

*“No man ever looks at the world with pristine eyes. He sees it edited by a definite set of customs and institutions and ways of thinking.”* Ruth Benedict, Patterns of Culture (1976)

*“Experienced analysts have an imperfect understanding of what information they actually use in making judgments. They are unaware of the extent to which **their judgments are determined by a few dominant factors,** rather than by the systematic integration of all available information. Analysts actually use much less of the available information than they think they do.”* Richards J. Heuer, Jr., Psychology of Intelligence Analysis (2007)

Would considering (ie, "thinking hard") these insights have impacted your guesses during the activities?

#### \*\* Input \*\*

There's an enormous range of factors that can impact and influence the security of an organization. We need a systematic approach to narrow relevant “context” down, including:

* What should we search for?
* How do we organize the information we collect?
* What relevant information are we missing?
* What are our assumptions?

Existing frameworks include:

1. Frontline Defenders' Workbook on Security: Practical Steps for Human Rights Defenders at Risk. See [CONTEXT ANALYSIS QUESTIONS.](https://www.frontlinedefenders.org/en/file/1111/download?token=7aoFdNX3)
2. SAFETAG. <https://safetag.org/guide/>

How to use SAFETAG:

* A “How-To”
* A checklist
* A list of information resources

SAFETAG (“Guiding Questions” from Section 2.2 “Context”):

* What infrastructural barriers exist in the region?
* What are the top, non-targeted digital threats in this region?
* What are the top targeted digital threats facing organizations doing this work in this region / country?
* Are there legal ramifications to digital security in the country? (e.g. legality of encryption, anonymity tools, etc.)
* Has any organization or individual made specific threats, or demonstrated intention or mindset to attack on the organization or similar organizations?

SAFETAG (“Guiding Questions” from Section 2.3 “Capacity”):

* What is the organization's ability to adopt new technologies or practices?
* What resources does the organization have available to them?
* What is the environment that the organization works within like? What barriers, threat actors, and other aspects influence their work?
* Are there any specific considerations for the audit that would require modifying the overall approach, tools, preparation steps, or timeline?

1. PMESII-PT Operational Variables may be seen in some INFOSEC circles.

Considers Political, Military, Economic, Social, Infrastructure, Information, Physical Environment, and Time factors, usually in a "crosswalk" matrix with "ASCOPE civil considerations" (Area, Structures, Capabilities, Organizations, People, Events). However, same as in describing threats, we'll want to avoid adopting militaristic terminology and methods. See example:

&#x20;\[Image source: US Marine Corps Training Command]

1. Especially in the business world, PESTLE (or PEST) may be a good choice for categorizing contextual factors.

&#x20;\[Source: Free Templates]

Political, Economic, Social, Technological, Legal, Environment (and sometimes Military) factors can be displayed in a matrix bounded by:

* SWOT: Strength, Weaknesses, Opportunities, Threats
* Time: Past, Present, Future
* Control: Internal (within Organization’s Control), External Factors (Within Organization’s Influence), External Factors (Beyond Organization’s Influence)

#### \*\* Deepening \*\*

As a class, work through the Contextual Factors (PESTLE-M) Worksheet for an example or actual partner organization.

Additionally, discuss the following:

* In which ways could you discover this information?
* How do you do this securely? Collaboratively?
* What might cause you to stop the process?

#### \*\* Synthesis \*\*

Great example from STS ethnography on why this is important:

*“The \[Xerox copier repair] technicians should be viewed as an occupational community (van Maanen and Barley 1984). They are focused on the work, not the organization, and the only valued status is that of full member of the community, that is, being considered a competent technician. In pursuit of this goal, they share information, assist in each other's diagnoses, and compete in terms of their relative expertise. Promotion out of the community is thought not to be worthwhile. The occupational community shares few cultural values with the corporation; technicians from all over the country are much more alike than a technician and a salesperson from the same district.”* Julian Orr, Talking About Machines (1996)

Do the members of your client org consider themselves members of an occupational community before the organization?

#### \*\* Assignments \*\*

\*\* PESTLE Analysis Brief \*\*

* You will create a 10 minute brief on a contextual factor that is relevant to your client’s organization. While you will receive individual credit for this assignment, do collaborate as a team in order to plan, collect, and analyze this information.
* Planning (As a Team). Create a game plan with your team so that each of your team members’ efforts focus on a relevant PESTLE category of factors.
  * Create a team collective document / spreadsheet where you can keep a running track of information / sources as you collect them. You will need to maintain this over the course of the semester and you will add to it as you complete your research & interviews with your client.
  * Select topics that each team individually will research in breadth (eg. encompass a range of political factors that may affect your client) or in depth (eg. research how a specific data protection law might impact your client). Strive to meaningfully inform the other members of your team about content that is directly relevant to your client’s security posture.
  * You may need to perform some initial research as a team to understand what important topics may be to consider. Your client’s website or other bits of information about your client organization may be a great place to start to do this planning - what is their mission? What recent work have they promoted?
* Collection. Seek open source information - this is a broad category that can include books, studies, websites, social media. Do not solely focus on gathering information from your client. This is the time to do your homework on the topic but also to figure out the best way for your team to collect / store this information. Remember: we are at one of the premier research universities in the world. There may be a subject matter expert available at UC Berkeley who can help you navigate a complex topic.
* Analysis. Perform some meaningful analysis on your topic instead of simply recalling information found online. For example, tell us why the education level or types of employees at the organization matter to their cybersecurity or to the Clinic’s work. Focus on providing the answer to “So what? Why does this matter?” when you provide information for your team.


# Contextual Assessment Informational Requirements

#### BACKGROUND

*Understand the history of the organization and its mission*

**How did your organization form? What are its objectives?**

* Mission:
* Year established:
* Brief history:
* Summary of current programs?
* Upcoming campaigns?

#### INTERNAL FACTORS

*Understand the assets used to achieve the organization’s goals*

**PHYSICAL**

**Where are you headquartered?**

* Address(es):
* Reason for chosen location(s):
* Do you share this space with anyone outside the organization?
* Do you rent, own, borrow this space?

**What other facilities do you own or occupy?**

* E.g. Satellite offices, warehouses, intermittent environments (temporary workspaces, conferences, workshops)

**What equipment do you rely on?&#x20;*****(Will be explored more deeply in Device Inventory)***

* Devices (computers, phones, tablets, routers, TVs, any other IoT like thermostat, alexa, etc.)
  * Provided to employees? Or do employees use their own?
* Vehicles
  * Own, rent?

**What other physical infrastructure does the organization depend upon?**

* Power
  * What is the regular system for providing power to the organization? On-grid, generator, solar?
  * What backup power systems are available to the organization?
* Travel
  * Are employees allowed to travel with organization-owned devices? What devices are they likely to travel with?
  * Are "travel devices" available for employees to use? What is the organizational expectation of their use?
  * Are employees likely to travel to locations where device theft is common?
  * Are employees travelling through checkpoints (government, private, bandits, international)?
* Trash removal and other janitorial services & recycling
  * How does the organization dispose of trash?
  * How does the organization dispose of sensitive documents?
  * How does the organization manage janitorial services for their workspace?
  * How does the organization perform cleaning their offices or other workspace?
  * Who conducts maintenance of physical infrastructure (plumbing, electricity)?

**POLITICAL**

**How are you structured?**

* Leadership team (executives):
* Board:
* Management structure:

**What politics are in play within the organization?**

* What are the political affiliations of its board members and leaders? (in general, or any heavily political advisors)
* What are current political aspirations of current employees? Is anyone running for office?
* What are the internal relationships between members?
* Describe past and current internal conflicts -- organizational changes, layoffs & firing
* Immigration/Citizenship/Refugee status:
  * Staff:
  * Beneficiaries:

**ECONOMIC**

**What is your business model?**

* Corporate Structure (Non-profit, for-profit, hybrid)
* Dependencies
  * Who are your Clients / Customers / Beneficiaries?
  * Who are your Donors?
  * Who are your other Funders (Grantors, Governments)?
  * Who are your partners for Contracted Services?
* Current Financial Situation
  * Describe your organization’s Financial Health including inputs/outputs
* What is your Financial Infrastructure - Where/How are funds stored?
  * Do you use Formal banking?
  * Do you keep Cash on hand?
  * Do you use Informal value transfer?
* Seasonality
  * Are there specific times of year where you conduct certain programs or when fundraising or operations will intensify?
* Advertising and Publicity Operations (Avenues for advertising, press, publicity - how is your organization known?)
* Current Financial Situation
  * What is your Internal Cash Flow & Funding Streams?
  * What are your sources of Funding, grants, & Initiatives?

**SOCIAL**

**Who keeps your organization running?**

* Number of employees:
* Types of employees:
  * Full-time, part-time, intern, volunteer, contractor
  * Occupations & Salaries paid
* Demographics (ages, genders, ethnicities, tribes):
  * Staff:
  * Beneficiaries:
* Education
  * Formal education of staff members
  * Literacy of staff members
  * Technological knowledge and proficiency
* Living Situations
  * Geographic dispersal - where do staff live in relation to work?
  * Where do they live in relation to beneficiaries?
  * In relation to their family (Diaspora?)?
  * Living conditions - what are the living conditions for staff?

**What is your organization’s culture?**

* Organizational Practices (of Staff or Beneficiaries)
  * Which languages are used?
  * What perspectives on Security exist?
  * What perspectives on Privacy exist?
* Working environment
  * Office bound?
  * Remote workers?
  * “Work from home” culture?
* Organizational Practices (of Staff or Beneficiaries)
  * What norms are realized?
  * What taboos exist?
* Hiring Practices
  * Describe current hiring practices. How are people screened before employment?
  * Describe current recruiting initiatives. How are people recruited?
* Leisure Activities
* Health Conditions
  * Current issues
  * Clinic / Medical Care Providers
  * Insurance Providers

**TECHNOLOGICAL**

* See Device Inventory and Technical assessment
* Do you currently have organizational policies for...
  * Technology Use?
  * System Access?
  * Privacy or data protection?
* What are your future plans...
  * For acquiring replacement technologies or solutions?
  * For digitization of paper records or other assets?
  * For conducting software upgrades?

**LEGAL**

* Do you have an internal legal team or rely on outside counsel?
* What are your statutory & regulatory commitments for...
  * Business / Financial?
  * Ethical?
  * Environmental?
  * Data protection regulations (GDPR, etc)?
  * Others?
* What are your current contractual obligations?
  * Have there been past breaches of contract?
* Describe your organization’s lawsuits & legal challenges in the...
  * Past?
  * Present?
  * Future (Expected/Planned)?

#### THREATS

Consider...

* Organized Crime
* Nation State
* Professional Hacker (Individual / Collective)
* Hacktivists
* Corporations
* Terrorism
* Criminal (Scammer / Opportunist)
* **Who were your past threats?**
  * **What persons, groups, or organizations have threatened, attacked, or harmed your organization, its employees, or beneficiaries in the past?**
    * Cyberattacks
    * Physical harms
    * Other Crimes
  * **What prior attacks has your organization experienced in the past?**
    * Cyberattacks
    * Physical harms
    * Other Crimes
* **Who are your current threats?**
  * **What persons, groups, or organizations are your current threats to your organization?**
    * Cyberattacks
    * Physical harms
    * Other Crimes
  * **Which persons, groups, or organizations do you feel may harm your organization in the future?**

#### EXTERNAL FACTORS

*Factors beyond the organization’s Control, but that are highly relevant to their functioning*

\####POLITICAL

* Support from Government Leadership of Organization’s Missions or Causes
  * Who are their supporters?
  * Who are their opponents?
* Government Stability
  * Any recent shifts of power or structure?
  * Is there turmoil expected turmoil in the future?
  * Are there ongoing or nascent insurgencies?
* External Stakeholders in Organization’s Mission
  * What other politicians or political groups are involved or impacted by the organization’s work?
  * What home pressure groups / lobbyists are for / against the organization’s work?
  * What international pressure groups / lobbyists are for / against the organization’s work?
* Corruption in Government
  * What is the country’s general propensity & accountability for bribery, graft, etc?
  * Are there past or current corruption scandals involving the above stakeholders?

\####ECONOMIC

* Home economic situation
  * Describe the general economic conditions in the home country.
  * Are there ongoing crises related to recession, hyperinflation, or other decline?
  * What is the unemployment rate?
* Trade Agreements
  * What other countries are relevant trade partners?
  * Are any countries involved in an ongoing trade war with the home country?

\####SOCIAL

* Cultural Practices
  * What other languages are used in the area of interest?
  * Are there any prevalent perspectives on Security in this area?
  * Are there any prevalent perspectives on Privacy in this area?
  * What cultural norms are relevant?
  * What cultural taboos are relevant?
* Ethnic issues
  * Are there any ethnic groups that suffer from discrimination?

\####TECHNOLOGICAL

* Law Enforcement
  * What means do the area’s law enforcement use to access private digital systems?
  * What technologies do law enforcement or other government forces use to monitor or collect information on the populace?
* Supply chains for Information-sharing
  * How is information transmitted between community members?
* Are there any prevalent attitudes towards online security tools in this area?

\####LEGAL

* What protections exist for Freedom of Speech?
* What are the relevant Privacy Laws?
* What are the relevant Data Protection Laws? (GDPR, etc)
* What are the relevant Cybersecurity Laws?
* Criminality
  * Who are the major organized crime groups?
  * What other crimes may be relevant?

\####MILITARY

* What are current or recent local conflicts? Include terrorism.
* Are there any international conflicts involving home country or partners’ home countries?
* Are there nearby Installations and bases to the organization’s work?
  * What capabilities or equipment for collection or intercept may be present?


# PESTLE M Worksheet

**Status: Last updated 4/20/20**

\*\*See \*\*Contextual Assessment Information Requirements **for example questions.**

|                                                                                                                                                                                                                                                                                                                                                    | **Internal Factors (ie. within the org’s control, how the org functions)** | **External Factors beyond the org’s control but within an org’s possible influence** | **External Factors outside of org’s influence but will impact the org** |
| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------- | ------------------------------------------------------------------------------------ | ----------------------------------------------------------------------- |
| <p><strong>Political</strong></p><p>(Ex: government type and stability, freedom of press, rule of law, levels of bureaucracy & corruption, social and employment legislation, tax policy and trade & tariff controls, likely changes in the political environment)</p>                                                                             |                                                                            |                                                                                      |                                                                         |
| <p><strong>Economic</strong></p><p>(Ex: stage of business cycle, current & projected economic growth, e.g. GDP / GNP growth inflation & interest rates, unemployment and labor supply, labor costs, levels of disposable income & income distribution, likely impact of technological or other change on the economy)</p>                          |                                                                            |                                                                                      |                                                                         |
| <p><strong>Social</strong></p><p>(Ex: population health, education & social mobility, and attitudes to these population employment patterns, job market freedom & attitudes to work, press attitudes, public opinion, social attitudes & social taboos , lifestyle choices and attitudes to these socio-cultural changes health consciousness)</p> |                                                                            |                                                                                      |                                                                         |
| <p><strong>Technology</strong></p><p>(Ex: impact of emerging technologies, impact of internet, reduction in communication costs & increased remote working, research & development (R\&D) activity, impact of technology transfer, degree of automation, rate of technological change)</p>                                                         |                                                                            |                                                                                      |                                                                         |
| <p><strong>Legal</strong></p><p>(Ex: antitrust law, consumer law, discrimination law, employment law, health & safety laws)</p>                                                                                                                                                                                                                    |                                                                            |                                                                                      |                                                                         |
| <p><strong>Environmental</strong></p><p>(Ex: weather, natural disasters, climate, climate change, environmental taxes, demand for "green" products)</p>                                                                                                                                                                                            |                                                                            |                                                                                      |                                                                         |
| <p><strong>Military</strong></p><p>(Ex: military equipment, personnel, operations or other presence in the area, foreign armies, paramilitaries, war, internal may be associations with military members, attitudes)</p>                                                                                                                           |                                                                            |                                                                                      |                                                                         |


# Information Gathering

#### \*\* Summary \*\*

This module introduces two information gathering methods for practitioners, interviews and surveys. While students may use open source investigative techniques (OSINT) or technical measurement tools during the risk assessment process, much of what you will learn from a partner organization will be directly shared by members of that organization. This module also introduces the advantages, disadvantages, and pitfalls of interviews and surveys.

#### \*\* Learning Objectives \*\*

* Understand the elements of an effective interview.
* Be able to prepare an interview guide.
* Consider the advantages and disadvantages of using interviews and surveys.

#### \*\* Pre-Readings \*\*

* See Course Readings for "Information Gathering"

#### \*\* Activities \*\*

In Module 7, students will have started a PESTLE analysis. Introduce this module while students are working on their analysis assignments. Have students briefly discuss their research so far.

#### \*\* Discussion \*\*

Provide a recap on contextual/capacity research and PESTLE analysis.

1. We need to understand an organization’s context and capacity as these factors greatly influence the organization’s ability to improve their security.
2. SAFETAG gives us some guidance, some “how-to,” and online links.
3. We still need something to help us plan and organize this “universe” of context.
4. PESTLE is a tool to identify
   1. what stuff we already know
   2. what stuff we need to learn more about
   3. what stuff we don’t know yet
   4. And what stuff we didn’t even consider.

Focusing on information we still need to learn or haven’t even considered:

What are the most effective ways to discover this information?

What is the best approach for discovering “unknown unknowns”?

#### \*\* Input \*\*

Beyond open source internet research and technical tools, interviews and surveys are effective methods for gathering information about your client.

**Interviews**

Interviews should be more than just data gathering:

* A guided but open-ended conversation exploring a person’s experiences.
* You should be fluid and able to react to new information.
* The interviewee should do the majority (90%) of the talking.
* Be comfortable with brief silence.

Rapport is key

* Be active & respectful listeners
* Smooth transitions
* Professionalism

“Good interviews are like telling good stories” - Steve Fadden’s INFO 213 at UC Berkeley:

1. Introduction
2. Rapport-Building & Setup
3. The “Heart”
4. Retrospection
5. Wrap-up

**Introduction.**

* Greetings & Thanks.
* Informed Consent. Even if employee or referral from a client, everyone will be given the opportunity to choose what shall happen to them and their information.
* 3 Elements (from Belmont Report):
  * Information: Who you are, what will happen during the interview, how will data be stored & used
  * Comprehension: Adapt delivery of info to ensure understanding
  * Voluntariness: free of coercion, “end at anytime”, “refuse to answer any question”, ask for permission and will reiterate during interview

**Building the “Heart” of the interview guide:**

Types of questions.

* Direct: “What types of multi-factor authentication do you use?”
* Sequence: “Walk me through your process to reset a password...”
* Specific Examples: “In the last month, what strange incidents have you experienced with your online accounts?”
* Projection: “What do you think would happen if that information was stolen...”
* Changes Over Time: “What are the differences in online attacks since the election?”
* Exhaustive List: “What are all the devices you use in your office in an average week/day?”
* Tasks and organizational structures: “Can you draw me a diagram of your incident response plan?”

Probing deeper into a “story” or “incident”:

* Time since last experience: “When was the last time you experienced online harassment?”
* Description of experience: “Can you describe that time...”
* Actions taken: “What did you do next... “
* Feelings: “How did you feel when that happened... “
* Outcome: “How did the situation get resolved?”
* Future actions: “If this happened again tomorrow, what would you do...”

Be prepared with common follow-ups

* “5 Why’s”: “Why do you use security keys...”
* Naïve Outsider Perspective: “I’m not familiar with the US’s freedom of information laws, can you explain how you obtain that information?”
* Quantity: “How many of your employees fall into that category?”
* Peer Comparison: “Do your colleagues also use wireless hotspots?”
* Reflecting Back: “So, what I hear you saying is..... is that right?”
* Native Language: “Why did you refer to Facebook as “Spambook”?”
* Clarification: “...when you mentioned ‘probably from the United States’, what threat did you mean exactly?”
* Point to Their Reaction: “Why did you laugh when you said that?”

**Retrospection**

* Anything that you missed or want to clarify?
* Ask your subject what they thought you should’ve asked

**Wrap-ups**

* Any next steps you need to describe?
* Reiterate how you will use this information and provide options for follow-up
* Thank yous

**Surveys**

Surveys don’t allow you to interact with the respondent and there may not be much opportunity to clarify or improve survey questions after they have been completed by your client.

* Questions should be unambiguous. For example, asking “what is the version number of your device?” can result in operating system numbers, model numbers, serial numbers. Providing detailed examples or instructions can help.
* Shorter surveys are generally better. Remember the time constraints for your partner.
* Each question should be justified. Consider what is potentially useful information and how will the answers affect your analysis.
* Consider the risks of the survey system and each question. Is there a less riskier way to collect this information? Do we really need this information?
* Other considerations include language, jargon, accessibility, and usability of the survey tool.

Pilot the interview guide or survey with an advisor not on your team or with one employee in the organization.

#### \*\* Deepening \*\*

What do these two questions look like when actually interviewing someone?

* What do you want to protect?: Make a list of your assets: data that you keep, where it’s kept, who has access to it, and what stops others from accessing it.
* Who do you want to protect it from?: Make a list of your adversaries, or those who might want to get a hold of your assets. Your list may include individuals, a government agency, or corporations.” - EFF SSD

Next 15 minutes: Work with a partner and come up with a brief interview guide (3 - 5 questions) to ask a person about their personal threat model. Each pair will pilot their questions with another pair with one student as the interviewer and the other one as an observer.

#### \*\* Synthesis \*\*

Reflecting on the last activity, discuss the advantages, disadvantages, and potential pitfalls when using interviews and surveys to gather information from a sensitive population.

#### \*\* Assignments \*\*

Interview Guide. For an upcoming partner interview, students will complete and submit an interview guide for review to the Clinic staff.


# Open Source Research Methods, Safety, and Tools

#### \*\* Summary \*\*

This module describes how open source intelligence (or open source investigative techniques or OSINT) can be used for research. While OSINT uses publicly available sources of information to learn about an organization, an individual, or their contexts, there are risks that students and partners may face by gathering the information. This module will discuss safety precautions and tools to effectively organize collected information.

#### \*\* Learning Objectives \*\*

* Learn how open source information can be used to protect civil society from cyberattacks.
* Understand common OSINT techniques & sources for security researchers.
* Determine when and how to begin collecting open source information.

#### \*\* Pre-Readings \*\*

* See Course Readings for "Open Source Research Methods, Safety, and Tools"

#### \*\* Resources \*\*

* Citizen Clinic Virtual Identities guide
* Citizen Clinic Virtual Private Network guide

#### \*\* Activities \*\*

OSINT, open source intelligence (or open source investigative techniques), is using publicly available sources of information to learn about an organization, an individual, or their contexts.

Pop quiz! True or False?

1. OSINT-gathering activities cannot be attributed to the collector or collecting organization.
2. Sources of OSINT information or methods of collection do not need to be protected.
3. OSINT is easily accessible.
4. OSINT can require a degree of technical expertise.

#### \*\* Discussion \*\*

Discuss the answers to the previous activity as a class.

Why might open source information be useful in our work with civil society organizations?

#### \*\* Input \*\*

Major categories of open source information:

* Public media sources: news reports, printed magazines, and newspapers
* Internet (Web 2.0) sources: archives, social media, blogs, discussion groups
* Public government data: hearings, budgets, directories, and other public records.
* Professional and academic publications: papers, theses, dissertations, and journals.
* Commercial data: corporate databases, financial, and industrial assessments.
* Grey data: Public but hard to get… conference promotional material, business documents, unpublished works, technical reports...

Starting points:

* Direct from target websites
* Nihad Hassan’s OSINT.Link: <https://osint.link>
* OSINT Framework: <https://osintframework.com/>
* Bellingcat Online Investigation Toolkit: <https://docs.google.com/document/d/1BfLPJpRtyq4RFtHJoNpvWQjmGnyVkfE2HYoICKOGguA/edit>

OSINT is an iterative process of methodically collecting, archiving, analyzing, and re-examining available data. Provide examples of taking a piece of information (such as domain name) and uncovering additional pieces of information (such as the real name of a website owner).

Key questions for this work:

* How to organize collected information?
* How to keep track of where you’ve been?
* How to stay safe?

Tools for organization and archiving:

* CherryTree
* Maltego
* Hunch.ly

How and where can your OSINT activities be tracked ?

* Browser History
* Router / Access Point
* Internet Service Provider
* Sites you directly visit (HTTP vs HTTPS)
* 3rd Party Sites (Lightbeam extension on Firefox)
* What else?

How can we protect our open source investigations?

* Virtual Private Networks
* The Onion Router aka TOR (or Orbot)
* Using a common browser (<https://panopticlick.eff.org/>)
* Using Incognito / Private Mode
* Using browser extensions:
  * HTTPSeverywhere
  * PrivacyBadger
  * Brave “Shields Up”
* “Burner” devices / virtual machines
* Virtual identities, profiles & user accounts
* Maintain separation between searches / sessions
* Smart defaults (Ex: DuckDuckGo vs Google for searches)
* Critical Thinking (avoid inadvertent connections)

Google Dorking (Advanced Search Queries): <https://exposingtheinvisible.org/guides/google-dorking/>

```
Search: 

* site:[target website] filetype:[pdf, docx, doc, xls or xlsx]

* [target name] filetype:pdf 

Write a script: 

* site:[target website] + https://gist.github.com/heiswayi/641201f3bac04168108a 
```

Automated:

recon-ng (in Kali) - you still need to enter API keys for most searches

#### \*\* Deepening \*\*

Each student team should create an OSINT research plan to gather information about their client’s context or potential threats.

The plan should contain the following:

1. What information are you seeking?
2. Where are you going to look?
3. What tools / resources do you need? (including burner accounts)
4. What precautions will you take to…
   1. Protect yourself?
   2. Protect your partner(s)?
   3. Protect your investigation?
5. What is your documentation system?
   1. Document your searches performed / sites visited / tools used
      1. Date, URL, & search terms at minimum
   2. Investigation type can dictate archive needs (do you need to capture the entire site? Screenshot?)

Each team will share elements of their plan with the class.

#### \*\* Synthesis \*\*

OSINT is not just an exercise in collecting all available information about an individual or organizations. When a practitioner reports their findings, they should succinctly describe:

1. What is the information?
2. Why does it matter? How could it be used?
3. Where (and when) did the information come from?
4. If defensive (ie, about a partner), is there a way to mitigate or prevent the information from being used in an attack?
5. If offensive (ie, about a threat), what are the next steps? Are there immediate actions that should take place?


# Adversary Persona Development

#### \*\* Summary \*\*

**What are adversary personas and why do we use them?** Context makes security complicated. Continent, country, region, state, locality, political union, political party, opposition or in-power, served audience, community, religion, demographics, labor, environment, elections, media, social media may direct how you control for risk. This is also true for adversaries, their capabilities, and motivations. Personas help describe the who (description), why (motivation/goals), and what (resources/capabilities) for an adversary of an organization. By borrowing some tools from product and user experience design, we can construct adversary personas to help us challenge common assumptions and fallacies about attackers while imagining other creative yet realistic possibilities.

#### \*\* Learning Objectives \*\*

* Enable students to think broadly and creatively about potential cybersecurity threats.
* Understand and build a realistic "who" behind security threats considering their identity, motivations, and resources.
* Identify common fallacies about adversaries.

#### \*\* Pre-Readings \*\*

* See Course Readings for "Adversary Personas"

#### \*\* Resources \*\*

* Daylight Security Research Lab's [Adversary Persona Cards](https://daylight.berkeley.edu/adversary-personas/)

#### \*\* Activities \*\*

**Create Initial Adversary Personas:** Create groups of 3-5 students based on their client or project. Tell each group to decided upon their top 3 adversaries. Each group will present the adversaries' identity, their motivation for attacking the client's assets, the resources they have at their disposal including any particular capabilities or tactics used.

#### \*\* Discussion \*\*

* How do these inital personas incorporate the perspectives from the readings?
* Do any of these adversaries fall into Julian Cohen's categories of attacker fallacies (Resourced Attackers, Motivated Attackers, Intelligent Attackers, Inadequate Attackers)?
* What does your adversary's typical day look like? What would your adversary be doing when off from work or during their downtime?

#### \*\* Input \*\*

Not only are adversaries impacted by context, they are also people. Each of the following adversary types are still people with motivations and needs not unlike our own (see Maslow's Heirarchy of Needs):

* Organized Crime
* Nation State
* Professional Hacker (Individual / Collective)
* Hacktivists
* Corporations
* Terrorism (Organized / Lone Wolf)
* Criminal (Scammer / Opportunist)
* Trolls
* Insiders (Intentional / Unintentional)

**Attacker Fallacies**

Realistic concepts of attackers have been a focus of Julian Cohen's work (see <https://medium.com/@HockeyInJune/>).

!!! quote "Julian Cohen on *Playbook-based Testing*" To achieve low-overhead and scalability, attackers create playbooks.\
Attackers that have multiple targets care about repeatability and scalability.\
Repeatability — The capability to change the target and have the attack still work with the same success rate.\
Scalability — The capability to launch the attack against multiple targets with minimal cost per additional target.

Resourced attackers (whether by size, amount of money, or skill) may still prefer low-sophistication but effective attacks such as phishing. This does not mean they are inadequate or unmotivated. See APT1.

Motivated attackers may have very strong incentives for attacking an organization, but still might only work during business hours. See APT28.

Intelligent attackers can still make mistakes or their methods may not be resistant to simple countermeasures.

Unsophisticated attacks should not be confused with inadequate attackers. Market efficiency drives the tactics used based on repeatability and scalability.

If attackers with multiple targets care about repeatability and scalability, then...

"All attackers are resource-constrained." - Dino A. Dai Zovi

"All attackers have a boss and a budget." - Phil Venables

Consider adversaries such as intimate partners or lazy employees. Do they also have resource constraints, bosses, and budgets?

**Creating Adversary Personas.**

Traditional "Threat Actor Profiles" may be found across the web for various threat groups (See <https://oasis-open.github.io/cti-documentation/stix/intro>). In accordance with standardized formats, these profiles include name, description, aliases, roles, goals, sophistication, resource level, and motivations (primary, secondary, and personal).

How might we avoid fallacies? Ground these profiles in reality (<https://methods.18f.gov/decide/personas/>).

* Gather research from earlier activities.
* Create a set of \[adversary] archetypes based on how you believe the \[adversary will threaten your partner]
* Analyze your records for patterns as they relate to \[adversary] archetypes
* Pair recurring goals, behaviors, and pain points with archetypes. Give each archetype a name and a fictional account of their day.
* Link your persona to your research.

#### \*\* Deepening \*\*

Adversary Personas (<https://daylight.berkeley.edu/adversary-personas/>) is an improvisational role-playing game designed to help teams think broadly and creatively about their cybersecurity threats. Developed by researchers from UC Berkeley's Daylight Security Research Lab (<https://daylight.berkeley.edu/adversary-personas/>), the game focuses on the who of security, by forcing players to ask: who might our adversaries be, what do they want, and what would they be willing to go through to get it? The game can be played by teams of employees in any organization. It is recommended for groups of between 2-10 people. Download the game [here](https://daylight.berkeley.edu/assets/adversary-personas-cards.pdf).

Follow the instructions listed [here](https://daylight.berkeley.edu/adversary-personas/) under "How to Play." The game could be played in groups by student team and their assigned client so that students can brainstorm about the adversaries for their current project. Alternatively, you can mix teams and get new perspectives on various security problems.

Have each group present their answers to "Step 4. Who are you most concerned about?." Reflect on how the discussion and the card game caused any changes from their initial personas from the Activity section. When they were role-playing or talking through motivations or tactics, did the adversaries seem like realistic threats or did their attacks require stretches of imagination?

#### \*\* Synthesis \*\*

Reiterate the reasons for understanding one's adversaries. Developing personas is a great technique for brainstorming and uncovering likely adversary strategies, tactics, and targets. In a future module, we will learn about constructing a threat scenarios to communicate potential actions of the adversaries in a meaningful way to our clients.

#### \*\* Assignments \*\*

Have each team develop a set of adversary personas. These personas will be used to create effective threat scenarios.


# Threat Scenario Development

#### \*\* Summary \*\*

This module gives students the requisite framework to create threat scenarios to communicate risks facing their partner organizations. Threat scenarios help illuminate elements of organizations’ context that put them at risk, and provide more tangible description of threats we seek to prevent (as opposed to a more generic description that often appears in a threat map or model).

#### \*\* Learning Objectives \*\*

* Understand how to use scenarios to develop and communicate threats.
* Understand and demonstrate what makes a “good” threat scenario.
* Learn the limitations of threat scenarios.

#### \*\* Pre-Readings \*\*

* See Course Readings for "Threat Scenario Development"

#### \*\* Activities \*\*

Combining risks and context.

Describe the following scenario to your students:

Your partner works with an at-risk population providing a sensitive service. They want to conduct a survey of their community of interest to determine how to improve the service they provide. Where do you start in your assessment? (For example, do you want to know the operating system of all of their phones? Do you need to know what email client they’re using?)

Next, describe the following two contexts:

What if...

* The partner provides reproductive health services to women in rural Texas?
* The partner provides information about troop/militant movements to journalists in Myanmar?

How are these situations different? How are they the same? What are the most urgent things you need to know?

#### \*\* Discussion \*\*

Remember that risk is not just a factor of likelihood and impact. A holistic approach also includes consideration of urgency (availability, dependencies), requirements (legal, contractual), and incentives (funding, opportunities) of the context.

Comparing our answers from the activity, how can we check whether we are focused on “the right risks?”

How can we communicate to others that the threats considered are impactful and feasible?

#### \*\* Input \*\*

Without an understanding of the details of how and when a threat may be realized, it can be difficult to determine and communicate why various threats matter to an organization.

While personas help describe:

* The Who (description),
* The Why (motivation/goals), and
* The What (resources/capabilities) for an adversary,

Threat Scenarios help describe:

* The How (tactics/playbook),
* The When (conditions) of an attack against your partner organization, and
* The Why it matters.

Scenarios help illuminate elements of organizations’ context that put them at risk, and provide more tangible description of threats we seek to prevent (as opposed to a more generic description that often appears in a threat map or model).

Good scenarios have a few key characteristics:

* They are simple - involving a limited number of actors and devices
* They are likely - the attack involved is not particularly exotic or well outside the expected attack vectors of an organization
* They are meaningful - the results of the scenario have significant impact on the organization or individuals affiliated with it

A good scenario describes a few consistent elements - threat actors, threat vectors, and the potential impact of an exploited system or vulnerability. The scenario should be described in a narrative format, and be no longer than a paragraph. A few examples are below:

***Border Security***

*Government orders border security agents to confiscate \[ORGANIZATION] employees’ devices when they cross border security. \[ORGANIZATION] called for investigations into \[GOVERNMENT ENTITY]’s allegations that it had never used malware against activists. The \[GOVERNMENT ENTITY] is concerned about \[ORGANIZATION]’s litigation and public calls for action and want to disrupt \[ORGANIZATION]’s operations and silence its employees. These government bodies have ordered border security agents to look out for \[ORGANIZATION] employees when they leave or return to \[COUNTRY OF ORIGIN] and search or confiscate their devices on the pretext that they pose a threat. \[RECOMMENDED MITIGATION].*

***Account Compromise***

*Elizabeth is a well-known activist in \[COUNTRY] who uses Facebook and Facebook Messenger to communicate with others and defend their community against oil exploitation. They often use Facebook to create public posts and organize community meetings and protests. One day, Elizabeth tries to log into their Facebook account and receives a notification that their password is incorrect. They try to change their password but discover that their recovery email address has been changed as well. Elizabeth’s family and friends are sent offensive messages from their hijacked account, and public posts defaming their character are created by their impersonator. After this incident, Elizabeth is no longer able to continue their activism work and loses the trust they have built through their online presence. \[RECOMMENDED MITIGATION].*

These scenarios tell a story and allow us to explore the potential actions of a threat actor, and examine how different controls might (or might not) make a meaningful difference.

#### \*\* Deepening \*\*

Each student or student team should create two to three threat scenarios (no more than a paragraph each) that help us imagine a specific incident that could take place in an organization's systems, or in systems closely affiliated to the organization or its staff, partners, or community.

Each group will share the “highest priority” threat scenario they have developed for class discussion.

#### \*\* Synthesis \*\*

Revisit the purpose for threat scenarios:

What do scenarios and personas demonstrate to our client? How are we advocating here?

Why can’t we just use scenarios then? Why not just skip threat modeling/mapping, etc.?

#### \*\* Assignments \*\*

Threat Scenarios. Continue to refine and develop the partner threat scenarios.


# Changing Security Behaviors

#### \*\* Summary \*\*

This module introduces concepts to consider when changing security behaviors of individuals. Every organization is made up of people so security practitioners must understand that people use mental models and metaphors to understand and/or react to threats. Using these concepts, students can consider trade-offs of various approaches in behavioral security.

#### \*\* Learning Objectives \*\*

* Understand the use of mental models and metaphors in cybersecurity
* Describe concepts such as attention filter, system 1 vs system 2 thinking, FOMO vs. JOMO and how these are reflected in user interface design.
* Learn which trade-offs exist between approaches to improving security behaviors.

#### \*\* Pre-Readings \*\*

* See Course Readings for "Changing Security Behaviors"

#### \*\* Discussion \*\*

Students will be asked to volunteer examples from their own experiences.

* Describe a risky or dangerous security (in)action or practice that you have done or you’ve seen in an organization that you’ve worked with or for (or with the Clinic). Example: “Holding doors open for coworkers between biometrically-secured entrances.”
* Discuss why this practice took place. Example: “social norms making it impolite to close doors on other people.”
* Was there anything meant to prevent this practice from taking place? Why didn’t it work?

#### \*\* Input \*\*

**Discuss the use of mental models and metaphors in cybersecurity.**

Mental models take time to develop. Compare gunpowder and TCP/IP.

Gunpowder over hundreds of years

* China: 9th Century
* Europe: 17th Century
* Outmodes personal armor, traditional fortresses, and military doctrine
* Creates new ideals of leadership, new industrial establishments, new relationships between government and governed., etc.

TCP/IP over tens of years

* DARPA: mid 1970s
* Apple Macintosh: 1984
* WWW: early 90s
* iPhone: 2007
* ‘The Cloud’: 2010

We use many metaphors to describe cybersecurity challenges, yet none of them are close to adequate for capturing the nature of the challenge that we will face. They lead the people who use them to think and act in ways that make no sense to the users of other metaphors.

**Building from mental models and metaphors, there are simple design principles for behavioral security.**

* Reward pro-security behaviors immediately and visibly (should Comcast pay people or increase their Internet speeds in return for taking security measures?)
* Enhance the awareness of risk (could you make the security messages and alerts look very different than other messages and alerts?)
* ‘Naming and Shaming’ of security policy violators?
* Default settings — obvious, but key

**Attention filter.**

Every time you make a decision, you run down your neural gas tank for the day.

The conscious mind can process about 120 bits /second (bandwidth) while one person speaking is about 60 bits/second. The brain’s attentional filter tells the rest of the brain what to focus on. You can train it, and so can your users… but it’s not easy.

Your attention filter evolved to respond to two categories of stimuli

* Change: Carla Schatz and the Cat visual cortex
* Importance: what happens when you are in a crowded room and someone across the room says “fire,””sex,” or “your name!”

**System 1 and System 2 thinking.**

* Simple and specific is good (‘open a window’ gets better adherence than ‘use in a well-ventilated room’). But presumably less comprehension
* Large quantities of text look like they will take a lot of effort to read, so people often read none of it. But it’s hard to explain security trade-offs in very few words.
* Illustrations convey lots of emotion but less information.
* What Chrome did (see APF paper):
* Nearly gave up on the comprehension objective
* Was able to almost double the adherence objective (roughly 30 to roughly 60%) by using colors, defaults, and demoting the unsafe choice to an ‘advanced’ button
* But they don’t know how many people might have become frustrated and switched browsers

**Fear of Missing Out (FOMO) vs. Joy of Missing Out (JOMO).**

* Precisely the same engineering (technical and social) that leads to engagement, leads to many security problems.
* Provocation: Texting while driving is a behavioral semi-equivalent to clicking on a link.
* Provocation 2: Distraction is the attacker’s best friend.

#### \*\* Deepening \*\*

Have students consider the following approaches to changing the security behavior of their partner organization.

* Should they make users aware of how the underlying technology works? Or make their choices as simple as possible?
* Should they use peer learning and social influence? Or rules?
* Should they use risk-assessment mindsets? Or simple heuristics?

Use this list of tradeoffs to guide the conversation:

* Concrete incentives vs peer pressure vs knowledge of why
* Specificity and customization (guides) vs Generalizability and transferability
* Assume a level of pre-existing knowledge vs Idiot-proofness
* Showing a payoff (you’re more secure) vs the Fredkin paradox
* Risk mindset vs Worst-case thinking
* Feedback and dialogue vs Time and efficacy

#### \*\* Synthesis \*\*

Discuss the following examples and strategies of changing security behavior (and connect them to the aforementioned tradeoffs):

* 1-on-1 Training
* Workshop
* Online training
* Guides
* Reports
* Technical Audits
* Workplace Incentive Programs
* “Name and Shame” Programs


# Social Engineering and Phishing

#### \*\* Summary \*\*

In this module, students will learn how and why social engineering is a common threat to civil society organizations. Attacks like phishing are simple and inexpensive to construct and execute and are a common vector for additional escalating threats. By understanding how these attacks are constructed, security practitioners are able to implement mitigations, deliver training, and evaluate resilience via phishing simulations.

#### \*\* Learning Objectives \*\*

* Understand common social engineering attacks or attack vectors.
* Identify how the principles of persuasion are used for successful social engineering attacks,
* Describe the elements of a phishing simulation for training and evaluation.

#### \*\* Pre-Readings \*\*

* See Course Readings for "Social Engineering and Phishing"

#### \*\* Resources \*\*

* Citizen Clinic Phishing Simulation Resources

#### \*\* Activities \*\*

Break into small groups and use <https://phishingquiz.withgoogle.com/>.

Have each group reflect on their experience.

* Considering past module "Changing Security Behaviors," how might a quiz like this be useful to you or your client?

#### \*\* Discussion \*\*

* What is phishing and why do we care about it?

#### \*\* Input \*\*

Define social engineering.

Define the following social engineering attack vectors:

* Phishing
* Spear Phishing
* Whaling
* Smishing (SMS Phishing)
* Vishing (Voice Phishing)

Source: <https://www.social-engineer.org/framework/attack-vectors/>

Examples: <https://security.berkeley.edu/resources/phishing/phishing-examples-archive>

How do these attacks actually work?

* Reciprocity:
  * What could be offered to your partner that creates a desire for them to return the favor?
  * The Golden Rule
* Scarcity (“Urgency”)
  * What does your partner need more of?
  * What services does your partner rely upon?
* Authority
  * What sources of authority exist over your partner?
  * Where does your partner lack expertise?
  * Who would your partner let “overrule” their own judgement?
* Consistency
  * What activities, questions, or requests would be similar to what your partner already handles?
  * What language, manners, and perspectives match an expected sender?
* Liking
  * What appeals to your partner?
  * What characteristics are desirable in your partner’s context?
* Consensus (“Social Proof”)
  * How would you introduce a new collaborator to your partner?
  * What bona fides does your partner look for from outsiders?
  * Who are the other organizations that your partner works with?
  * What statistical evidence might your partner care about?

Provide examples of successful phishing attacks (eg, John Podesta DNC attack) and discuss how the principles of persuasion were leveraged.

How do we deal with phishing? How can your partner reduce the likelihood or impact of phishing?

* Training
* Technical Measures
* Multi-factor authentication
* Unique passwords
* Information sharing and reporting across organizations
* Critical thinking

Creating a phishing campaign simulation for evaluation and training:

* Target Research
  * Context(s)
  * Contact(s)
  * Devices / OS
  * Who and which platforms might your adversary target?
  * Which approaches (Six Principles of Persuasion) might best “convince” your partner?
* Sending Profile
  * False persona, name, email address and domain (does the domain have DMARC or other spoof protection? Check [www.dmarcian.com](http://www.dmarcian.com))
  * Name
  * Email Address + Domain / Phone Number
  * Persona
* Sending Infrastructure
  * Email Account (inside access?)
  * SMTP Server (Simple Mail Transfer Protocol)
  * Websites for sending spoof email / texts
  * Twilio / ClockworkSMS
  * Automated Software (GoPhish)
* Email/Message Template
  * To Line
  * Subject
  * Body
  * Links
  * Signature (2 types - signature block and PGP signature)
  * Attachments
* Landing Page (see <https://data.phishtank.com/> )
  * Web server
  * Form Submission
  * Describe what happens when a link is clicked. Are you presenting them with a web form to collect credentials? Are you attempting to install malware?
  * What tracking or other data collection do you want? Do you want to learn how many employees opened the email, clicked the link, and/or entered their passwords?
  * What URL / Domain will you use? Is it available?
  * Will the landing page forward them to a benign final destination page?
* Other

  * Think about what timing considerations for when the training emails should reach your partner.
  * What amount of repetition or variation between training messages would be appropriate? Would you likely need to generate similar messages?

  Test your infrastructure (website, email address, etc), however phish filters may be alerted by future deployments of the same infrastructure.

  Avoid spam filters or suspicious email labeling. The goal posts are always moving - creativity is necessary.

  Create a phishing simulation plan with training objectives & consent agreement for your partner. Your phishing simulation and data collection must support your training goals. There should be various recommendations based upon an organization’s performance

#### \*\* Deepening \*\*

As a team, design a concept for a phishing campaign simulation to support improving your partner’s resilience against phishing.

* Identify training objectives, data collection, and elements of the phishing attack.
* Describe how the phishing simulation will support those training objectives. Again, the organization’s performance should have some impact on any subsequent recommendations.

Share each concept with the class. Discuss which principles of persuasion are used for each simulation.

#### \*\* Synthesis \*\*

Reiterate the importance of a phishing simulation plan and agreement with your partner before conducting any phishing simulation.


# Designing Security Training

#### \*\* Summary \*\*

This module introduces practical considerations for designing a security training. This module essentially summarizes the amazing work of the Electronic Frontier Foundation’s Security Education Companion team (see <https://sec.eff.org>). While this module provides an outline of key topics to cover in class, review the Security Education Companion (<https://sec.eff.org/articles>) for greater discussion of each of these topics before tailoring the module for your clinic’s needs.

#### \*\* Learning Objectives \*\*

* Understand considerations for the “nuts and bolts” of training logistics and training team creation.
* Understand how to learn about your audience via pre-event data collection and persona development
* Understand lesson creation using learning objectives, stress cases, and lesson plans.

#### \*\* Pre-Readings \*\*

* See Course Readings for "Designing Security Training"

#### \*\* Resources \*\*

* [EFF's Security Education Companion](https://sec.eff.org)

#### \*\* Discussion \*\*

Even many new security practitioners have been subject to cybersecurity training. As a class, have students volunteer stories of their best and worst experiences as either a trainer or trainee, whether in a workshop, lecture, 2 hour seminar, or online session. What changes could have improved a bad experience or ruined a good experience?

#### \*\* Input \*\*

**Training logistics**

* Consider Who, When, and Where
* Get a feel for the space that you’re setting up in.
* Understand the temperature, lighting, and what technology is available.
* Do not assume that the technology you’re bringing and that your trainees are bringing are compatible.
* Think about accessibility at the forefront of your event. If you didn’t think about accessibility, it shows in your event. If someone mentions they’re Hard of Hearing or Deaf and asks for an interpreter, and you don’t have resources to make that happen, then push the training to a later time so that you can make it possible.
* People need to feel safe and to be safe to ask questions.
* Trial and error. Be prepared to make mistakes and to handle those situations.

**Creating a training team & establishing trainer roles**

* Build a “Superhero” team: play to your strengths. You can have someone who is good at facilitation, witnessing what’s going on in the group, and it helps balance things. You can help each other out.
* Work together: When people are missing something, the other facilitator will be available to identify the gaps. People who have different operating systems on their devices may require more helpers for specific issues.
* Learn from each other: Leverage different backgrounds and styles. Also, junior trainers can learn and improve from helping more experienced trainers.

**Understanding your audience**

* Pre-event data collection: Perform training intake survey and get a feel for needs, as well as identifying when you might not be the right person (e.g. if it’s government hacking as a threat, that’s out of scope for most trainers, bring them to specialists!) Also, interviews can more deeply inform your understanding of people’s learning needs and mindsets you’ll be working with, especially understanding which misconceptions people might hold.
* How will you gather this information?
  * Technical expertise
  * Device use
  * Threat Models
  * Accommodation requests
  * With cultural sensitivities? Privacy? Security?
* Persona development: Trainers can use combinations of personas that incorporated threat models and other various factors as a way to include real-world considerations for trainers and their audiences.
* The EFF used personas when creating the Security Education Companion as a basis for content-creation sprints, and thinking collaboratively through what kind of advice and content would be useful.
* Personas can deliberately include misconceptions, disabilities, mindsets, threats, and stress factors that may make it difficult for someone to fully participate in a workshop.
* Personas are not perfect and care must be exercised not to promote or incorporate stereotypes regarding disability inclusion, stress considerations, device limitations, misconceptions, and motivations.

**Develop learning objectives using inclusive education framing.**

Learning objectives are important. They’re not the most exciting part about teaching, but it’s valuable to learn how to determine the base level of teaching a concept and then layering on top of it. “Stress cases” for those objectives include:

* Threat model considerations
* Disability considerations that may affect how someone processes information or engages with people in a group
* Financial constraints
* Varying degrees of literacy
* Levels of familiarity with devices

**Create lesson plans.**

* Don’t reinvent the wheel
* Be creative and inclusive with activities and delivery methods
* Keep track of materials and other requirements (should learners bring their devices? Do learners need to know their account passwords in advance?)

#### \*\* Deepening \*\*

If you already have trainee personas:

Break the class into pairs of students, each with a persona and have them discuss the question: “how would you teach this person?” Share back to the group.

If you do not already have trainee personas:

Break the class into assigned teams where each team will develop a persona based on their experiences with their partner, other training experiences, and class discussions. Include misconceptions, disabilities, mindsets, threats, and stress factors that may make it difficult for someone to fully participate in a workshop. Share back to the group.

#### \*\* Synthesis \*\*

Recap training logistics, creating a training team and defining roles, understanding one’s audience, and actually planning the lessons. Ground this summary in an example or two from recent or upcoming training events.

#### \*\* Assignments \*\*

As a class, use the material in this module to support the creation and implementation of security workshops for the public (or, as teams, for their respective partners.)


# Psychosocial Resilience

#### \*\* Summary \*\*

This module introduces the concept of psychosocial resilience and how mental wellness impacts security practitioners and the organizations that they support. Addressing psychosocial resilience is important since trauma, including vicarious trauma, can compound vulnerabilities of digital safety and physical security. This module, based on work led by the UC Berkeley Human Rights Center and Rated R for Resilience, centers on open discussion as students and staff explore common scenarios that may introduce psychosocial harms.

#### \*\* Learning Objectives \*\*

* Understand what psychosocial resilience and secondary/vicarious trauma are and why they are important in the context of helping partner organizations improve their digital security.
* Be familiar with how psychosocial resilience interacts with physical security and digital safety (holistic security).
* Discuss tools or approaches to enhance one’s own psychosocial resiliency for themselves, to minimize the risk of secondary trauma including work practices, identifying warning signs, and how to seek help.

#### \*\* Pre-Readings \*\*

* See Course Readings for "Psychosocial Resilience"

#### \*\* Resources \*\*

* [Rated R for Resilence toolkits](https://sites.google.com/view/ratedr/toolkits)

#### \*\* Discussion \*\*

Throughout this module, students will be introduced to four scenarios that stress the importance of psychosocial resilience. Each scenario can be discussed as a class, in teams, or individually.

**Scenario 1.**

*1.* Employees of a Clinic partner NGO suffer recurring violent online threats that include the public sharing of their names, telephone numbers, and home addresses. Once phone numbers are shared, the employees receive a storm of threatening text messages and voicemail from multiple people. The NGO asks the student team for best practices on how to handle this case.

1. How might employees’ decision-making be affected during this crisis?
2. What can an organization do to improve resiliency in advance?
3. What can an organization offer for their employees’ recovery / repair?

#### \*\* Input \*\*

Definitions (see <https://sites.google.com/view/ratedr/basics> for more)

* Trauma: A deeply distressing and disturbing experience or physical injury or fear for life
* Secondary trauma or vicarious trauma: An adverse reaction to the emotional residue of exposure to the pain and suffering of trauma survivors. Natural result of exercise of empathy as our brains don’t always distinguish between harm to self vs. harm to others.
* Stress: a state of mental or emotional strain or tension resulting from adverse or very demanding circumstances
* Burnout: physical or mental collapse caused by overwork or stress.
* Resiliency: the capacity to recover quickly from difficulties; toughness; another definition: the ability of a substance or object to spring back into shape; elasticity. Both a trait and a process; adapting well in the face of adversity, trauma, tragedy, threats, or significant sources of stress; May not be springing back but moving forward changed.

Psycho-social wellness interacts with physical security and digital safety in the framework of holistic security (see Tactical Tech’s <https://holistic-security.tacticaltech.org/>)

Several tools and resources may be helpful to maintaining or recovering psycho-social wellness. Rated R for Resilience has several good toolkits: <https://sites.google.com/view/ratedr/toolkits>

Key question to self-care is knowing the answer to “what’s normal for you?”

**Discuss Scenario 2.**

*2.* Students working with a Clinic partner NGO conduct interviews of employees to learn about the nature of threats to the organization. The NGO employees speak frankly about the threats or harms that face their organization or their colleagues, including telling the student teams about NGO colleagues that have been victims of sexual violence and murder.

1. How might students prepare for these types of discussions?
2. How might students handle possible triggers during a partner interaction, especially when other students seem unaffected?
3. How might students process (emotionally) and analyze (for work) the collected information?

**Discuss Scenario 3.**

*3.* Students while researching a far-right wing extremist group may view violent and hateful content on online forums and social media. Some of the threats are very graphic, may include imagery (usually memes) and involve targeting people based on gender, sexuality, race, or ability.

1. How might students prepare for this type of research?
2. How might students identify their boundaries for the content that they view?
3. How might students process (emotionally) and analyze (for work) the collected information?

#### \*\* Deepening \*\*

**Discuss Scenario 4.**

*4.* Security assistance providers often have a heightened fear of failure or the perception of failure given their position of providing security advice. Undue stress may affect students as they may adopt a protector role, wanting to ensure their recommendations are unrealistically “perfect” so that they don’t feel be responsible for the next attack against the partner NGO.

1. How might the Clinic avoid creating a zero-defect environment?
2. How might students maintain realistic expectations and/or “healthy anxiety” about
3. their recommendations?
4. How might students handle the stress of real-world work?
5. How might students process a future cyberattack to their partner NGO?

#### \*\* Synthesis \*\*

Summarize the psychosocial harms stemming from trauma. Describe any particular resources that are available to Clinic students (such as access to mental healthcare providers using student insurance) and emphasize channels of communication to discuss concerns with Clinic staff.


# Harmful Information (Misinformation and Harassment)

#### \*\* Summary \*\*

The purpose of this module is to provide a conceptual framework for small civil society organizations to address threats of harmful information including disinformation and online abuse such as harassment. These attacks spread hate and sway popular opinion using botnets, armies of trolls, and divisive fabricated content. They can target organizations, especially those engaged in political advocacy, with many tactics: activists and journalists are harassed, the reputations of advocacy organizations are tarnished, and public support for social causes is shifted. Complicating this picture, an organization’s ability to protect itself from harmful online information attacks can be impeded by the lack of a shared understanding of harm reduction across its own security, communications, human resources, and management functions.

#### \*\* Learning Objectives \*\*

* Understand the nature and the challenges of harmful information, such as misinformation and online abuse.
* Understand harms and risks of harmful information in order to prioritize controls.
* Learn major categories of improving defenses against harmful information from the perspective of a leader in a single organization.

#### \*\* Pre-Readings \*\*

* See Course Readings for "Harmful Information (Misinformation and Harassment)"

#### \*\* Resources \*\*

**\* Mitigation Framework**

**\* Harmful Information Case Studies**

#### \*\* Activities \*\*

In small groups, consider: How might Twitter be used to harm an organization... even when the site is used as designed (ie not being “hacked”)?

Discuss as a class.

#### \*\* Discussion \*\*

There will probably be some vocabulary and classification issues with some of these threats:

To which category of acceptability (Usually Acceptable, Sometimes/Borderline Acceptable, Always Unacceptable) do the following threats belong:

Propaganda – Disinformation – Misinformation – Malinformation – Internet Shutdowns - Harassment – Trolls – Bots – Doxxing – Mobbing – Swatting – Leaks – Sockpuppets – Astroturfing – Clickfarms - Deceptive Advertising – Exclusionary Advertising – Dog Whistles – Subtweeting – Parody News – Clickbait

#### \*\* Input \*\*

We define **“harmful information”** as the harmful threats that stem from the use or abuse of information systems as they are designed or intended to be used. For example, by the nature of its design, a system may be designed to allow its users to spread hate speech to any user even though that behavior is against a community standards policy. Major categories of abuses fall into “misinformation” and “harassment.”

**Why “Misinformation”?**

We use the term “misinformation” to classify false information spread about an organization or individual regardless of the accuracy of the information or the intent to cause harm.

The terms *“disinformation,” “malinformation,” and “misinformation*” among others may be used by some experts to more precisely describe the intent and factual accuracy of the information being spread. However, it is important to stress that information in each of these categories can harm an organization or individual regardless of its intent or accuracy. **An organization’s focus on the harm caused by a threat should be more important than their concerns about its proper technical classification.**

Understand the intent behind and accuracy of elements of an attack when possible.

* Knowing the intent of an adversary is useful for anticipating how an incident might escalate in severity, persist over time, and evolve into future attacks.
* Factual accuracy can be leveraged in most information attacks since “kernels of truth” can provide the attack more credibility but complete falsehoods can still dangerously spread despite being easy to disprove to careful observers.

When might the organization not care about the accuracy or intent of the harmful information?

**Understanding the Types of Threats**

Most concerns will fall into the following interactions between an organization and the harmful information:

* Direct Targeting: Harmful information is sent directly to the organization and its members.
* Indirect Threats: Harmful information is spread about the organization to those outside of the organization.
* Ingestion: An individual or organization unwittingly incorporates and uses harmful information in its decision-making processes.
* Generation: The organization unwittingly creates or spreads harmful information. Insiders may also harass or spread lies about fellow staff members or organization outsiders.

**Harassment is not the same as misinformation**

* Harm/violation occurred, usually to an individual
* Information may or may not be false, attack may not even contain content
* Different communities of action and approaches to mitigations

**Why consider them together?**

* Both “trust and safety” problems that don’t fall into traditional digital security domain.
* Attacks and tactics can be similar or intertwined.
* Mitigations for harassment are an important subset of which actions mitigate the harms of larger misinformation problems

Practical “Solutions” for Civil Society:

1. Increase understanding / practices around holistic security
   1. **Physical Security:** Inadequate protection for our people, our devices, and workplaces allow online threats of physical violence to cause more psychological harm as the risk and perception of physical harm increases.
   2. **Digital Security:** The security of data and information systems are important as confidential information is often used in misinformation attacks and threats to the integrity and availability of our information can damage our credibility and hurt our ability to respond.
   3. **Psychosocial Wellbeing:** Misinformation and harassment can be damaging to our psychological well-being or mental health, yet the harms caused also confounds our ability to protect and respond to threats extending to both physical and digital domains.
2. Integrate risk mitigation into existing systems and processes
   1. While some mitigations implemented by individuals may be adopted as organization-wide practices or policies, nearly all the protective measures can fit into processes that should already exist in most healthy, sustainable non-profit organizations. Alternatively, these existing practices, processes, and policies are generally “necessary but not sufficient” for protecting an organization from harmful information threats. For example, if an organization does not have practices for security incident response or policies to ensure inclusion and equity of its staff members, those will need to be created first.
   2. One example of integration into an existing Security program would be to match and nest additional mitigations within a previously selected framework. The NIST Cybersecurity Framework is a useful example given its functions parallel several activities in countering harmful information.
3. Strengthen external relationships and collaboration
   1. Media outlets and tech platforms play an outsized role as vehicles for the spread and prevention of misinformation and online abuse while the governmental actors can have potential roles as both purveyors of harmful information and avenues to pursue legal action and criminal justice. Given limited formal systems to offer efficient incident resolution for human rights defense organizations, relationships with those entities ultimately will be only as strong as one’s personal relationships with their employees in influential operations, security, trust & safety, legal, and policy positions.
   2. These relationships can be personal, formal, backchannel, and collective.

**Prioritization by Risk**

What are the differences between the threats that matter and the ones that don’t?

Threats may have greater impact depending on the context, content, audience, motivation, medium, and the capabilities of an attacker to gain legitimacy, impersonate, link, amplify, collect, and suppress information. Adversary methods frequently include combining the following operations or strategies to make information attacks more effective and sustainable:

**Gaining Legitimacy:** By establishing or co-opting seemingly authoritative sources of information, adversaries can threaten the authority of your own organization or sources of information that support your mission. Legitimate news organizations may give a platform for adversaries, adversaries may create enduring organizations and media outlets, websites, and social media accounts, celebrity endorsements, or algorithmic decision-making may give the appearance of the adversaries’ legitimacy or how acceptable (legally, socially, or otherwise justified by norms) their message may be.

**Collecting Sensitive Information:** Adversaries may gather confidential or sensitive information to gain advantage in the control of information perception, content, and flow. Beyond extorting or blackmailing an entity via threats of disclosure, adversaries can publish embarrassing information not intended for outside audiences, share out-of-context information that supports conspiracy theories, or prevent information-sharing by creating fear around the organization’s ability to maintain confidentiality.

**Impersonation:** Adversaries may imitate trusted sources to build or decrease the confidence in information transferred. This may include creating numerous individual accounts that parrot talking points from supporting or opposing groups, the creation of organizational presence that mimics those in the field, or even spoofing real organizations and their staff members by using impostor websites and social media accounts. The goal of these tactics is to create doubt in the authenticity of information from your organization or to trick others into trusting the information coming from the impostor accounts.

**Linking Together Targets:** Some adversaries may try to capitalize on negative opinions or damaging information about associated organizations and individuals. Such “guilt by association” strategies are conducted by identifying and reporting on financial, personal/familial, geographic, and other connections among individuals, groups, and organizations. Given the transparency of financing and accounting required of most civil society organizations, the autonomy for a single organization can be threatened when disinformation campaigns target unrelated organizations that share common funding sources.

**Amplifying the Message:** Using progressions of dissemination channels, techniques, and resources, adversaries can spread information and even create a perception of consensus. Amplification can begin with its delivery to niche online forums & groups and progress to widely-used social media platforms and eventually more traditional media and celebrity endorsements. This amplification is usually intended to increase the signal strength or reach of its messages and increase the likelihood that opposing information is “drowned out.” Additionally, tactics can be used to create more awareness of the harmful content on a single platform such as creating inauthentic accounts to spread content or hijacking of hashtags.

**Suppressing opposing perspectives:** Suppression includes intentional efforts to restrict access and flow of alternative information. Adversaries can target the availability of an organization’s messaging by shutting down internet access, censoring online content and users, or blocking access to outside perspectives.

**Identify Harmful Information Risks**

1. Identify Potential Threats
   * Consider threats to individuals, groups, or the organization
   * Consider direct targeting, indirect attacks, ingestion, and generation
2. Connect Threats to Potential Harms
   * Identify the impact of potential threats to individuals, groups, and the organization
   * Consider physical, reputational, financial harms
3. Create and Prioritize Threat Scenarios
   * Describe threat scenarios in detail
   * Evaluate and prioritize scenarios based on likelihood and impact

**Identify controls.**

Top 4:

* Physical Security (‘Get out of Dodge’ plan)
* Digital Security (Lock down accounts)
* Mental Wellbeing (Preventing psychological harms)
* DOCUMENTATION PLAN

#### \*\* Deepening \*\*

Have teams step through the Harmful Information Mitigation Framework using Case Study 1 or 2 in the Harmful Information Case Studies).

* What are the harms or risks you find most important to address? (top 3)
* Which mitigations would you prioritize for implementation? (top 3)

#### \*\* Synthesis \*\*

Summarize the module with an additional framing of asking “is the juice worth the squeeze?” or “how much effort/time/money is worth how much protection from misinformation and online abuse?” Are there some protections that should be in place regardless of resource constraints?

Provoke: If resources are currently unavailable to address online abuse, how might you convince your boss or your client that this is a problem that requires a reallocation of resources?


# Fictional Case Studies

## Case Study 1: HopeAssistOrg

“HopeAssistOrg” (ed: fake name) is a nonprofit organization focused on providing direct resources and counseling support to the trans community in the United States. Headquartered in New York City, it has employees, volunteers, and executives working remotely across the country. HopeAssistOrg depends on external funding from individual donors and grants from private foundations. Leaders believe it is imperative that HopeAssistOrg protect the financial and personal data associated with its funding to maintain a reputation as a responsible organization.

Some of the top threat actors for HopeAssistOrg are transphobic groups like trolls from “fast moving image boards” or “chans”. Users on these websites use OSINT skills to collect personal information (like home addresses or dead names) about HopeAssistOrg affiliates and post them on public platforms for harassment. They sometimes organize online harassment campaigns on social media (Twitter, LinkedIn, Facebook) directly targeting the organization’s staff and volunteers with hateful speech. Chan “trolls” will typically send hateful content via public or private social media channels but someone has previously left a letter on the front door of the home HopeAssistOrg senior employee. The trolls have threatened SWATing several times, but thankfully, this attack has not happened yet. HopeAssistOrg will not engage directly with law enforcement.

A previous audit of HopeAssistOrg’s security revealed several good practices such as (1) organizational devices which can be wiped remotely, (2) mandatory 2FA (authenticator app) for all employees and volunteers on organizational (GSuite) accounts (3) mandatory comprehensive training on phishing (4) a dedicated Slack channel for cybersecurity incident reporting, and (5) 2FA (authenticator app) for organizational social media accounts. They currently do not have policies for handling harassment, online or offline, or misinformation, however the organization does set Google alerts for the names of the organization and its staff as a simple way to keep abreast of brewing attacks.

Select roles as the HopeAssistOrg’s Executive Director, Technical Lead, Human Resources / Admin Lead, and a Program Manager.

1. What are the harms or risks you find most important to address? (top 3)
2. Which mitigations would you prioritize for implementation? (top 3)

 

## Case Study 2: HaveAHeartOrg

“HaveAHeartOrg” (ed: fake name) supports the safety and advocates for the land rights of Indigenous groups in the Sahel region of Africa. Based in London, HaveAHeartOrg helps facilitate organization, funding, and exposure for these groups. HaveAHeartOrg primarily functions as a matchmaker and enabler by connecting its partners with private foundations for grant opportunities, with journalists and activists to report on the situation facing the partner, and with legal experts to help with litigation efforts. HaveAHeartOrg relies upon its website, social media presence, and newsletter to raise awareness of the needs in this space.

Given conflicts over natural resources and borders, Indigenous groups face a wide range of threats from governments, paramilitaries, other Indigenous groups, and corporations. One major threat for HaveAHeartOrg is the nation of Abkhazia and its state owned enterprises that invest and operate in Sahel Africa. Abkhazian cyber attacks by security services will often gain access to email or social media accounts (via spear phishing) to collect personal or compromising information for leverage over their adversaries. Additionally, Abkhazia’s funding and influence over media throughout the Sahel region creates a platform where information leaks and disinformation can be easily disseminated. Abkhazia have used these platforms (web, print, radio) to discredit “Western” organizations and competing stakeholders internationally.

HaveAHeartOrg’s connections and funding to many partners across the region is a valuable asset for HaveAHeartOrg. However, for some partners, the local perception of being affiliated or funded by a Western NGO would damage the reputation of the partner and place employees of both organizations in physical danger in that country. HaveAHeartOrg communicates with many partners that have minimal digital security measures and, while the organization has enabled 2FA (YubiKey) on all of its organizational email and social media accounts, they don’t feel comfortable helping their partners use 2FA. In a survey, a couple employees of HaveAHeartOrg stated that they felt leadership does not take disinformation threats seriously since no proactive steps have been taken to “bolster the organization’s reputation” in the region.

You are a consultant team working directly with the organization’s Technical Lead.

1. What are the harms or risks you find most important to address? (top 3)
2. Which mitigations would you prioritize for implementation? (top 3)


# Mitigation Framework

#### Step 1. Threat Map. Identify potential threat methods for analysis.

|                 | **Subject Type**                                                                                                                                                                                                                                                 |                                                                                                                                                                                                                                                                                                                    |                                                                                                                                                                                                                                              |
| --------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Threat Type** | Individual                                                                                                                                                                                                                                                       | Group Identity                                                                                                                                                                                                                                                                                                     | Organization                                                                                                                                                                                                                                 |
| Direct          | Bullying; coordinated targeting; hateful, inflammatory, or embarrassing comments; threats of violence; upsetting content; gendered threats; sustained harassment; mob harassment; sexual harassment; stalking; doxxing; SWATing; and account takeovers/lockouts. | Tactics leveraging social cleavages (for example hate speech or dog whistles) such as race, ethnicity, socioeconomic status or class, gender, sexual orientation, religion, regional or national origin, citizenship status, occupation, employment status, age / generation, education, or political affiliation. | Coordinated targeting to organizational accounts; Denial of service or access to an organization’s content;                                                                                                                                  |
| Indirect        | Spreading of false or misleading information about an individual; defamatory information; disclosure of non-consensual intimate images; impersonation; hateful, inflammatory, or embarrassing comments.                                                          | Spreading of false or misleading information about a social group; hate speech directed towards a social group; divisive speech that may be either opposed or supportive of various social groups.                                                                                                                 | Mass internet shutdowns, establishing seemingly allied organizations to share disingenuous content; establishing opposition organizations to spread opposing viewpoints; imitation of the organization’s online presence(eg, typosquatting). |
| Ingestion       | Persuasion of the individual to believe or biased towards inaccurate information.                                                                                                                                                                                | Persuasion of groups to believe inaccurate information about other groups, sowing division or apathy or bolstering alliances.                                                                                                                                                                                      | Persuasion of the organization to use inaccurate information in decision making.                                                                                                                                                             |
| Generation      | Creation, publishing, or sharing of misinformation, harassment against co-workers and others outside of the organization                                                                                                                                         | Creation and spreading of misinformation; harassment against co-workers and others outside of the organization                                                                                                                                                                                                     | Creation / spreading of misinformation, harassment against co-workers and others outside of the organization                                                                                                                                 |

#### Step 2. Harm Map. Connect scenarios to potential harms for the organization or its individuals or groups of individuals.

| **Individual Harms**            |                                                                                                                                                                                                                        |                                                                                                                                                                                                                    |
| ------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| **Harms to Self Determination** | **Definition**                                                                                                                                                                                                         |                                                                                                                                                                                                                    |
|                                 | Loss of autonomy                                                                                                                                                                                                       | Loss of autonomy includes needless changes in behavior, including self-imposed restrictions on freedom of expression or assembly.                                                                                  |
| Loss of liberty                 | Improper exposure to arrest or detainment. Even in democratic societies, false or negative information can lead to increased scrutiny, arrest or, abuse of governmental power.                                         |                                                                                                                                                                                                                    |
| Power imbalance                 | Information, or threat of disclosure, can create an inappropriate power imbalance or takes unfair advantage of a power imbalance between acquirer and the individual.                                                  |                                                                                                                                                                                                                    |
| Physical harm                   | Actual physical harm to a person, including the potential to cause death.                                                                                                                                              |                                                                                                                                                                                                                    |
| Psychological harm              | Information can cause psychological distress to the target such as increased anxiety, fear, and depression, possibly triggering reactions to previous trauma. This distress can also contribute to physical self-harm. |                                                                                                                                                                                                                    |
| **Reputational Harms**          |                                                                                                                                                                                                                        |                                                                                                                                                                                                                    |
|                                 | Loss of trust                                                                                                                                                                                                          | The breach of implicit or explicit expectations about the character and behavior between individuals or organizations. Loss of trust can leave entities reluctant to engage in further cooperation.                |
| Stigmatization                  | Information can create a stigma that can cause embarrassment, emotional distress or discrimination.                                                                                                                    |                                                                                                                                                                                                                    |
| **Economic Harms**              |                                                                                                                                                                                                                        |                                                                                                                                                                                                                    |
|                                 | Financial losses                                                                                                                                                                                                       | Harms due to a result of loss of employment, business relationships, increased government scrutiny, and imprisonment.                                                                                              |
| **Group Harms**                 |                                                                                                                                                                                                                        |                                                                                                                                                                                                                    |
| **Reputational Harms**          |                                                                                                                                                                                                                        |                                                                                                                                                                                                                    |
|                                 | Discrimination                                                                                                                                                                                                         | Groups within an organization or individuals may be unfairly judged, scrutinized, or excluded based on their actual or perceived group affiliation.                                                                |
| Stigmatization                  | Information can create a stigma that can cause embarrassment, emotional distress or discrimination of a certain group.                                                                                                 |                                                                                                                                                                                                                    |
| **Organizational Harms**        |                                                                                                                                                                                                                        |                                                                                                                                                                                                                    |
| **Operational Harms**           |                                                                                                                                                                                                                        |                                                                                                                                                                                                                    |
|                                 | Loss of productivity                                                                                                                                                                                                   | Inefficiencies due to decision-making based on inaccurate or misleading information leading to increased delays, false starts on program activities, or time spent sorting and verifying information for accuracy. |
| Loss of mission impact          | Decreased impact due to organizational decision-making, activities that incorporate or promote inaccurate information, or from the influence of competing narratives on the organizations’ supported beneficiaries.    |                                                                                                                                                                                                                    |
| **Reputational Harms**          |                                                                                                                                                                                                                        |                                                                                                                                                                                                                    |
|                                 | Loss of trust                                                                                                                                                                                                          | Damage to trust with public and private entities such as individuals, partner organizations, funders, government agencies, and other external supporters.                                                          |
|                                 | Loss of morale                                                                                                                                                                                                         | Damage to internal attitudes from individual embarrassment, emotional distress or discrimination due to association with the organization.                                                                         |
| **Economic Harms**              |                                                                                                                                                                                                                        |                                                                                                                                                                                                                    |
|                                 | Direct financial losses                                                                                                                                                                                                | Lost time and money spent to counter false information or improve security.                                                                                                                                        |
|                                 | Indirect financial losses                                                                                                                                                                                              | Lost funding and business relationships due to reputational damage or lack of productivity.                                                                                                                        |

#### Step 3. Threat Scenarios. Develop practical description of the threat and challenge assumptions.

|                   | **Probing Questions**                                                                                                                                                                                                                                                                                                                                                                               |
| ----------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Adversary**     | <ul><li>What is the identity of the adversary responsible for the harmful information?</li><li>What are the goals (if any) of an adversary sharing the harmful information?</li><li>What resources might an adversary have at their disposal?</li></ul>                                                                                                                                             |
| **Content**       | <ul><li>Does the content contain personal information?</li><li>Does the content threaten or create fear for one’s safety?</li><li>What elements of “truth” are contained in the message?</li></ul>                                                                                                                                                                                                  |
| **Context**       | <ul><li>How is the harmful information delivered?</li><li>When and how often are interactions taking place?</li><li>How might the harmful information affect current events or campaigns?</li></ul>                                                                                                                                                                                                 |
| **Audience**      | <ul><li>Who is the intended recipient of the information?</li><li>How could various stakeholders of the organization perceive the harmful information? What social norms might be violated?</li><li>How might the audience react to the harmful information?</li><li>How might law enforcement or government regulators react to the harmful information, if known?</li></ul>                       |
| **Legitimacy**    | <ul><li>What might give this threat legitimacy with an influential audience?</li><li>Why might the threat’s message or methods be perceived as normatively acceptable?</li><li>How might those information sources already deemed legitimate by certain audiences spread or give additional credibility to the threat?</li><li>Who in power may spread or give credibility to the threat?</li></ul> |
| **Impersonation** | <ul><li>How might an adversary take over or share information from an account belonging to the target?</li><li>How might an adversary convince an audience that their information is being shared with the target’s approval?</li><li>How might an adversary bypass any vetting processes intended to ensure representations are made by authentic sources of information?</li></ul>                |
| **Linking**       | <ul><li>How have associates of the target been subject to harmful information threats in the past?</li><li>How might publicly disclosed information about associations of the target tie to additional harmful information threats?</li><li>How might historical information about the target’s associations and activities be used in combination with the threat?</li></ul>                       |
| **Amplification** | <ul><li>How might an adversary disseminate information to a large audience?</li><li>What is the current number of followers or subscribers of the adversary?</li><li>How might a harmful message move, intentionally or unintentionally, from less active online forums to more popular platforms?</li><li>How has an adversary’s message or similar threats been amplified in the past?</li></ul>  |
| **Collection**    | <ul><li>How might sensitive information about the target be gathered by an adversary?</li><li>How might a threat have been able to access, store, or share private information about the target?</li><li>How might publicly available information about the target give credibility to a threat?</li></ul>                                                                                          |
| **Suppressing**   | <ul><li>How might an adversary prevent opposing perspectives from being shared and heard?</li><li>Why might the target be unable to use existing their information channels (website, social media accounts, newsletter) to counter the threat?</li><li>How might an audience be blocked from accessing the target’s information or counter-messaging?</li></ul>                                    |

#### Step 4: Mitigation Map. Select suitable controls to mitigate potential harms.

| **Identify**                                                    |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |                                                                                                                                                                                                                                                                                                                                                                                                                       |
| --------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Identify Harmful Information Risks**                          |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |                                                                                                                                                                                                                                                                                                                                                                                                                       |
| Identify Harmful Information Risks                              | Identify Potential Threats                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | <ul><li>Consider threats to individuals, groups, or the organization</li><li>Consider direct targeting, indirect attacks, ingestion, and generation</li></ul>                                                                                                                                                                                                                                                         |
| Connect Threats to Potential Harms                              | <ul><li>Identify the impact of potential threats to individuals, groups, and the organization</li><li>Consider physical, reputational, financial harms</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                               |                                                                                                                                                                                                                                                                                                                                                                                                                       |
| Create and Prioritize Threat Scenarios                          | <ul><li>Describe threat scenarios in detail</li><li>Evaluate and prioritize scenarios based on likelihood and impact</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |                                                                                                                                                                                                                                                                                                                                                                                                                       |
| **Identify informal practices or formal policies**              |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |                                                                                                                                                                                                                                                                                                                                                                                                                       |
| Identify informal practices or formal policies                  | Security (Physical or Digital) or Incident Response                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | <p>Identify and evaluate the following:</p><ul><li>Evaluate security risk management abilities and training.</li><li>Consider how psychosocial risks are addressed in the risk assessment / management program.</li><li>Improve account security of organizational and personal social media accounts.</li><li>Decrease the online availability of personal information about staff members.</li><li>Other:</li></ul> |
| Social Media Use                                                | <p>Identify and evaluate the following:</p><ul><li>Acceptable social media use for organizational accounts, including response policy for comments and private messages.</li><li>Monitoring protocols for mentions of your organization and staff members in social media, comments, and forums.</li><li>How policies consider the subjective experience of online abuse.</li><li>Other:</li></ul>                                                                                                                                                                                                                             |                                                                                                                                                                                                                                                                                                                                                                                                                       |
| Communications and Public Relations strategy                    | <p>Identify and evaluate the following:</p><ul><li>Media literacy and verification processes to avoid sharing and consuming misinformation.</li><li>Plans to address potential information threats in advance.</li><li>Existing messaging that addresses misinformation directly or offers constructive alternative narratives in outreach to funders and stakeholders</li><li>Contacts at social media platforms, media outlets, academia, government, and intermediaries that can support the organization during a crisis</li><li>“First page” search results for the organization and its members</li><li>Other:</li></ul> |                                                                                                                                                                                                                                                                                                                                                                                                                       |
| Human Resources or Employee Health & Wellness                   | <p>Identify and evaluate the following:</p><ul><li>The ability and experience of members of historically disadvantaged or marginalized groups to report, respond, and recover from harmful information</li><li>Reporting and confidential disclosure mechanisms for online and offline abuse</li><li>Partnerships with programs offering mental health counseling, trainers, and other resources for victims and subjects of harmful information</li><li>Other:</li></ul>                                                                                                                                                      |                                                                                                                                                                                                                                                                                                                                                                                                                       |
| Workplace Ethics / Code of Conduct                              | <p>Identify policies and practices regarding:</p><ul><li>Financial accounting</li><li>Managing conflict of interests</li><li>Political endorsements and advocacy</li><li>Whistleblower protections</li><li>Other:</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                    |                                                                                                                                                                                                                                                                                                                                                                                                                       |
| **Evaluate Organizational Culture**                             |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |                                                                                                                                                                                                                                                                                                                                                                                                                       |
| Evaluate Organization’s capacity to address harmful information | Leadership                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | <p>Identify and evaluate the following:</p><ul><li>Buy-in to address concerns of misinformation and online abuse</li><li>Openness and transparency on areas for improvement</li><li>Other:</li></ul>                                                                                                                                                                                                                  |
| Values                                                          | <p>Identify and evaluate the following:</p><ul><li>Explicit values</li><li>Implicit values</li><li>Other:</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |                                                                                                                                                                                                                                                                                                                                                                                                                       |
| Performance                                                     | <p>Identify and evaluate the following:</p><ul><li>How leadership and staff uphold organizational values</li><li>How staff and leadership perform and manage the identified policies or practices</li><li>Other:</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                     |                                                                                                                                                                                                                                                                                                                                                                                                                       |

| **Protect**                                                                                                         |                                                                                                                                                                                                      |                                                                                                                                                                                                                 |
| ------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Improve Organization-wide Digital Security**                                                                      |                                                                                                                                                                                                      |                                                                                                                                                                                                                 |
| Protect the confidentiality, integrity, and availability of the organization’s and individuals’ information systems | Maintaining confidentiality                                                                                                                                                                          | <ul><li>Secure accounts (personal & organizational)</li><li>Secure devices</li><li>Implement network monitoring</li><li>Other:</li></ul>                                                                        |
| Maintaining availability of information                                                                             | <ul><li>Implement DoS Protection</li><li>Enable Censorship Circumvention</li><li>Other:</li></ul>                                                                                                    |                                                                                                                                                                                                                 |
| Maintain integrity of information                                                                                   | <ul><li>Enable domain spoofing protection. eg DMARC</li><li>Enable DNS Hijacking protection (DNSSEC)</li><li>Register similar URLs</li><li>Other:</li></ul>                                          |                                                                                                                                                                                                                 |
| **Minimize the Availability of Potentially Harmful Information.**                                                   |                                                                                                                                                                                                      |                                                                                                                                                                                                                 |
| Reducing or obfuscating available open source information on organization or members.                               | Organizational Data Management                                                                                                                                                                       | <ul><li>Implement data minimization strategy</li><li>Conduct open source audit</li><li>Other:</li></ul>                                                                                                         |
| Personal Data Management                                                                                            | <ul><li>Review Old Social Media Posts</li><li>Review Social Media Privacy Settings</li><li>“Dox Yourself”</li><li>Other:</li></ul>                                                                   |                                                                                                                                                                                                                 |
| Maintain Social Media Management best practices                                                                     | <ul><li>Create policies for how to engage with legitimate commentators versus “trolls” in public and via private messages.</li><li>Maintain social media manager anonymity.</li><li>Other:</li></ul> |                                                                                                                                                                                                                 |
| **Strengthen Communication Plan and Social Media Policies**                                                         |                                                                                                                                                                                                      |                                                                                                                                                                                                                 |
| Develop communication plan and social media policies                                                                | Create a strategy for when to let harmful information to “die out”, when to counter with direct refutations, or when to promote new narratives.                                                      | <ul><li>Create messages in advance.</li><li>Connect with a network of journalists and fact-checkers.</li><li>Create advertising and automation strategies for messaging amplification.</li><li>Other:</li></ul> |
|                                                                                                                     | Maintaining organizational presence and accurate information on authoritative sources of information                                                                                                 | <ul><li>Improve web presence and search engine optimization including strengthened networks of supporting sites.</li><li>Correct the record on authoritative sources such as Wikipedia</li><li>Other:</li></ul> |

| **Detect**                                                                                                           |                                                                                                                                                                                                                                      |                                                                                                                                                                                                                                                                                                                       |
| -------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Implement Individual Detection**                                                                                   |                                                                                                                                                                                                                                      |                                                                                                                                                                                                                                                                                                                       |
| Develop individual skills to identify known strategies for creating harmful information                              | Identify and learn how to react when in potentially compromising situations                                                                                                                                                          | <ul><li>Verify the identity of new contacts, online and offline</li><li>Familiarize with counterintelligence tradecraft</li><li>Avoid discussing politically or culturally sensitive topics with strangers</li><li>Other:</li></ul>                                                                                   |
| Improve media literacy to reduce an organization's susceptibility to its own digestion and spread of misinformation. | <ul><li>Teach source checking</li><li>Implement content verification procedures</li><li>Other:</li></ul>                                                                                                                             |                                                                                                                                                                                                                                                                                                                       |
| **Implement Organizational Detection**                                                                               |                                                                                                                                                                                                                                      |                                                                                                                                                                                                                                                                                                                       |
| Develop organizational policies and practice for detecting harmful content                                           | Implement manual content monitoring                                                                                                                                                                                                  | <ul><li>Implement and train staff on reporting harmful (or suspected) online information, including seemingly innocuous behavior</li><li>Create a plan to relieve subjects of abuse from self-monitoring</li><li>Create an emergency plan for manual monitoring of abuse campaigns by staff.</li><li>Other:</li></ul> |
| Implement automatic content monitoring                                                                               | <ul><li>Set free keyword notification tools such as Google Alerts</li><li>Preset filtered feeds in tools such as TweetDeck</li><li>Employ social sensing or brand monitoring services</li><li>Other:</li></ul>                       |                                                                                                                                                                                                                                                                                                                       |
| Implement external content monitoring                                                                                | <ul><li>Collaborate with other organizations to monitor and research developments in misinformation in one’s domain</li><li>Create an intake plan for colleagues from other organizations that request help</li><li>Other:</li></ul> |                                                                                                                                                                                                                                                                                                                       |

| **Respond**                                          |                                                                                                                                                                                                                 |                                                                                                                                                                                                                                |
| ---------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| **Immediate Response -**                             |                                                                                                                                                                                                                 |                                                                                                                                                                                                                                |
| “Top 3 Things”, planned in advance.                  | Physical Safety and Wellbeing                                                                                                                                                                                   | <ul><li>Train staff for initial shock: “breathe and connect with support, don’t handle this alone”</li><li>Plan to move to safety if credible threats</li><li>“Better to be safe than sorry” policies</li><li>Other:</li></ul> |
| Digital Security                                     | <ul><li>Conduct Incident Response procedures</li><li>Other:</li></ul>                                                                                                                                           |                                                                                                                                                                                                                                |
| Gather Evidence and Stay Aware of Threats            | <ul><li>Monitor and Archive (Tweetdeck, Dox Yourself, Hunch.ly, Archive.org, Google Alerts)</li><li>Manage manual monitoring of abuse campaigns by co-workers accounting for burn-out.</li><li>Other:</li></ul> |                                                                                                                                                                                                                                |
| **Next Stage Response**                              |                                                                                                                                                                                                                 |                                                                                                                                                                                                                                |
| Prevent Escalation of Harms                          | Respond to content on Platforms                                                                                                                                                                                 | <ul><li>Engage with platforms or intermediaries for removal of harmful content or automated accounts</li><li>Use tools to identify, ignore, and/or block bots/trolls</li><li>Other:</li></ul>                                  |
| Execute Crisis Communication Plan                    | <ul><li>Engage with supporters and funders to keep them informed</li><li>Inform public via media or other outlets (as needed)</li><li>Other:</li></ul>                                                          |                                                                                                                                                                                                                                |
| Engage legal protections from harassment or threats. | <ul><li>Notify law enforcement authorities if appropriate (SWATing prevention)</li><li>Contact legal counsel for jurisdiction-based guidance</li><li>Other:</li></ul>                                           |                                                                                                                                                                                                                                |

| **Recover**                               |                                                                                                                                                                                    |                                                                                                                                                                                                               |
| ----------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Improving Safety**                      |                                                                                                                                                                                    |                                                                                                                                                                                                               |
| Holistic Recovery                         | Rebuild Psychological Resilience                                                                                                                                                   | <ul><li>Offer multiple avenues for coping</li><li>Provide counseling services for employees</li><li>Other:</li></ul>                                                                                          |
| Improve Physical Protections              | <ul><li>Reassess physical vulnerabilities at work locations and increase protections as appropriate</li><li>Revisit personal security plans for employees</li><li>Other:</li></ul> |                                                                                                                                                                                                               |
| Recover Digital Safety                    | <ul><li>Reassess digital vulnerabilities and increase protections as appropriate</li><li>Other:</li></ul>                                                                          |                                                                                                                                                                                                               |
| **Repair Information Harms**              |                                                                                                                                                                                    |                                                                                                                                                                                                               |
|                                           | Refine Communications Plan                                                                                                                                                         | <ul><li>Adjust messaging based on counternarratives and situation</li><li>Engage with supporters and funders to keep them informed.</li><li>Inform public via media or other outlets</li><li>Other:</li></ul> |
| Continue to use Platform-Specific Methods | <ul><li>Search engine optimization</li><li>Search result downranking</li><li>Content removal processes such as Right to be Forgotten / DMCA.</li><li>Other:</li></ul>              |                                                                                                                                                                                                               |
| Seek Legal Remedies                       | <ul><li>Contact legal counsel for jurisdiction-based guidance</li><li>Other:</li></ul>                                                                                             |                                                                                                                                                                                                               |
| **Reassessment**                          |                                                                                                                                                                                    |                                                                                                                                                                                                               |
|                                           | Conduct a Formal After-Event Assessment                                                                                                                                            | <ul><li>Learn how the organization could improve</li><li>Learn and validate what people did well</li><li>Describe resources that you wish were available.</li><li>Other:</li></ul>                            |


# Condensed Bibliography

#### **Introduction to Public Interest Cybersecurity**

Sean Brooks, Center for Long-Term Cybersecurity. “Defending Politically Vulnerable Organizations Online” \[<https://cltc.berkeley.edu/wp-content/uploads/2018/07/CLTC_Defending_PVOs.pdf>]

Citizen Lab’s “About Us” Paper. \[<https://citizenlab.ca/wp-content/uploads/2018/05/18033-Citizen-Lab-booklet-p-E.pdf>]

Citizen Lab’s Security Planner. \[<https://securityplanner.org/>]

Sandro Contenta, Toronto Star. “How these Toronto sleuths are exposing the world’s digital spies while risking their own lives” \[<https://www.thestar.com/news/canada/2019/12/13/from-a-tower-in-toronto-they-watch-the-watchers-how-citizen-lab-sleuths-are-exposing-the-worlds-digital-spies-while-risking-their-own-lives.html>]

Havron et al. "Clinical computer security for victims of intimate partner violence." In Proceedings of the 28th USENIX Security Symposium (pp. 105-122).\[<https://www.nixdell.com/papers/2019-usenix_clinical_security_FULL.pdf>]

Deji Olukotun, Access Now. “Spyware in Mexico: an interview with Luis Fernando García of R3D Mexico” \[<https://www.accessnow.org/spyware-mexico-interview-luis-fernando-garcia-r3d-mexico/>]

Tactical Tech's Annual Report \[<https://cdn.ttc.io/s/tacticaltech.org/Tactical-Tech-2018-Annual-Report.pdf>]

#### **Ethics and the Citizen Clinic Code of Conduct**

Citizen Clinic. "Student Code of Conduct" \[<https://www.citizenclinic.io/Clinic\\_Curriculum/Modules/Ethics/Student\\_Code\\_of\\_Conduct/>]

Shannon Vallor, The Markkula Center for Applied Ethics. “An Introduction to Cybersecurity Ethics” \[<https://www.scu.edu/media/ethics-center/technology-ethics/IntroToCybersecurityEthics.pdf>]

#### **Old School INFOSEC: Basic Controls**

Le Blond et al. “A look at targeted attacks through the lense of an NGO” \[[www.usenix.org/system/files/conference/usenixsecurity14/sec14-paper-blond.pdf](https://www.usenix.org/system/files/conference/usenixsecurity14/sec14-paper-blond.pdf)]

Sean Brooks, CLTC, TechSoup Webinar. “Cybersecurity in Low-Risk Organizations: Understanding Your Risk and Making Practical Improvements.”: \[<https://cltc.berkeley.edu/2019/02/25/cltc-and-citizen-clinic-present-cybersecurity-in-low-risk-organizations-webinar/>]

Citizen Lab’s Security Planner. \[<https://securityplanner.org/>]

Electronic Frontier Foundation’s Surveillance Self-Defense guide. \[<https://ssd.eff.org/>]

Alex Gaynor. “What happens when you type google.com into your browser's address box and press enter?" \[<https://github.com/alex/what-happens-when>]

Rus Shuler. “How Does the Internet Work?” \[[web.stanford.edu/class/msande91si/www-spr04/readings/week1/InternetWhitepaper.htm](https://web.stanford.edu/class/msande91si/www-spr04/readings/week1/InternetWhitepaper.htm)]

#### **Digital Surveillance of Politically Vulnerable Organizations: The Threat Landscape**

Stephen Arnold. “Telestrategies - An Interview with Dr. Jerry Lucas” \[<http://www.arnoldit.com/search-wizards-speak/telestrategies-2.html>]

Joseph Cox. “I Gave a Bounty Hunter $300. Then He Located Our Phone” \[<https://motherboard.vice.com/en_us/article/nepxbz/i-gave-a-bounty-hunter-300-dollars-located-phone-microbilt-zumigo-tmobile>]

Vernon Silver and Ben Elgin. “Torture in Bahrain Becomes Routine With Help From Nokia Siemens” \[<https://web.archive.org/web/20111006185329/http://www.bloomberg.com/news/2011-08-22/torture-in-bahrain-becomes-routine-with-help-from-nokia-siemens-networking.html>]

John Scott-Railton et al, Citizen Lab. “Bittersweet: Supporters of Mexico’s soda tax targeted with NSO exploit links” \[<https://citizenlab.ca/2017/02/bittersweet-nso-mexico-spyware/>]

#### **Problem Diagnosis and Reframing**

Netgain. “Digital Security and Grantcraft Guide” \[[fordfoundation.org/media/3334/digital-security-grantcraft-guide-v10-final-22317.pdf](https://www.fordfoundation.org/media/3334/digital-security-grantcraft-guide-v10-final-22317.pdf)]

Arthur Turner. “Consulting Is More Than Giving Advice” \[<https://hbr.org/1982/09/consulting-is-more-than-giving-advice>]

Thomas Wedell-Wedellsborg. “Are You Solving the Right Problems?” \[<https://hbr.org/2017/01/are-you-solving-the-right-problems>]

#### **Threat Modeling & Bounding Risk Assessments**

Electronic Frontier Foundation, “Surveillance Self-Defense: Your Security Plan” \[<https://ssd.eff.org/en/playlist/activist-or-protester#your-security-plan>]

NIST SP 800-37 “Risk Management Framework for Information Systems and Organizations.” Chapter 2 only. \[<https://csrc.nist.gov/CSRC/media/Publications/sp/800-37/rev-2/draft/documents/sp800-37r2-draft-ipd.pdf> or [Shutdown Mirror](https://github.com/danphilpott/fismapedia-files/blob/master/NIST%20SP%20800-037r2%20Risk%20Management%20Framework%20for%20Information%20Systems%20and%20Organizations;%20A%20System%20Life%20Cycle%20Approach%20for%20Security%20and%20Privacy,%202018-12-20%20\(Final\).pdf)]

NIST SP 800-39 “Managing Information Security Risk.” Chapter 2 only. \[<https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-39.pdf> or [Shutdown Mirror](https://github.com/danphilpott/fismapedia-files/blob/master/NIST%20SP%20800-039%20Managing%20Information%20Security%20Risk;%20Organization,%20Mission,%20and%20Information%20System%20View,%202011-03-01%20\(Final\).pdf)]

NISTIR 8062 “An Introduction to Privacy Engineering and Risk Management in Federal Systems.” \[<https://nvlpubs.nist.gov/nistpubs/ir/2017/NIST.IR.8062.pdf> or [Shutdown Mirror](https://github.com/danphilpott/fismapedia-files/blob/master/NIST%20IR%208062.pdf)]

#### **Contextual & Capacity Research**

SAFETAG, Internews. "SAFETAG Guide" ***Skim to Section 2.2, then read Section 2.2 and Section 2.3.*** \[<https://safetag.org/guide/>]

Read and Explore Examples About PESTLE. *(use an ad-blocker!)* \[<https://pestleanalysis.com/what-is-pestle-analysis/>]

Jorge Luis Sierra. “Digital and Mobile Security for Mexican Journalists and Bloggers” \[<https://freedomhouse.org/sites/default/files/Digital%20and%20Mobile%20Security%20for%20Mexican%20Journalists%20and%20Bloggers.pdf>]

#### **Information Gathering**

Ruba Abu-Salma et al. “Obstacles to the Adoption of Secure Communication Tools” \[<https://ieeexplore.ieee.org/abstract/document/7958575/>]

Jeanette Blomberg et al. "An Ethnographic Approach to Design" \[<https://www.researchgate.net/publication/262363851_An_Ethnographic_Approach_to_Design>]

Jenna Burrell. "The Field Site as a Network: A Strategy for Locating Ethnographic Research" \[<https://doi.org/10.1177/1525822X08329699>]

Collaboration on International ICT Policy in East and Southern Africa. “Safeguarding Civil Society: Assessing Internet Freedom and the Digital Resilience of Civil Society in East Africa” - Read each chapter, but for one country only. \[<https://cipesa.org/?wpfb_dl=237>]

Lofland and Lofland. Read Chapter 5 (66-98) "Logging Data" in "Analyzing social settings: A guide to qualitative observation and analysis" \[<https://searchworks.stanford.edu/view/10531063>]

#### **Open Source Research Methods, Safety, and Tools**

Awesome OSINT \[<https://github.com/jivoi/awesome-osint>]

Ian Barwise. “Open-Source Intelligence (OSINT) Reconnaissance” \[<https://medium.com/@z3roTrust/open-source-intelligence-osint-reconnaissance-75edd7f7dada>]

Conor Fortune, Amnesty International. “Digitally dissecting atrocities – Amnesty International’s open source investigations.” \[<https://www.amnesty.org/en/latest/news/2018/09/digitally-dissecting-atrocities-amnesty-internationals-open-source-investigations/>]

OSINT Framework \[<https://osintframework.com/>]

OSINT.link \[<https://osint.link>]

Travis Lishok, Protective Intelligence. “Part I: An Introduction To OSINT Research For Protective Intelligence Professionals” \[<https://www.protectiveintelligence.com/blog/osint-intro-for-protective-intelligence-pt1>]

Travis Lishok, Protective Intelligence. “Part 2: An Introduction To OSINT Research For Protective Intelligence Professionals” \[<https://www.protectiveintelligence.com/blog/osint-intro-for-protective-intelligence-pt2>]

SECALERTS - Automated Security Audit \[<https://secalerts.co/security-audit>]

Marc Wilson, PCWDLD.com. "OSINT Tools & Software for Passive & Active Recon & Security!" \
\[<https://www.pcwdld.com/osint-tools-and-software>]

#### **Security Law and Policy Factors**

James C. Scott. “Seeing Like a State” - Chapter 9 \[<https://libcom.org/files/Seeing%20Like%20a%20State%20-%20James%20C.%20Scott.pdf>]

Kim Fong et al. “A CRIMSon Tide of Data: An Assessment of Potential Privacy Problems of the Consolidate Records Information Management System” \[<http://people.ischool.berkeley.edu/~strush/CRIMS_FongRowlandTrush_Feb2018.pdf>]

#### **Adversary Persona Development**

Julian Cohen. “Playbook Based Testing.” \[<https://medium.com/@HockeyInJune/playbook-based-testing-5df4b656113a>]

Bill Marczak and John Scott-Railton, Citizen Lab. “Keep Calm and (Don’t) Enable Macros: A New Threat Actor Targets UAE Dissidents” \[<https://citizenlab.ca/2016/05/stealth-falcon/>]

Nick Merrill, Daylight Security Research Lab. "Adversary Personas" \[<https://daylight.berkeley.edu/adversary-personas/>]

Microsoft’s STRIDE and related blog posts. \[<https://cloudblogs.microsoft.com/microsoftsecure/2007/09/11/stride-chart/>]

#### **Threat Scenario Development**

Mitre’s ATT\&CK Wiki. \[<https://attack.mitre.org/>]

Mitre’s PRE-ATT\&CK Techniques. \[<https://attack.mitre.org/techniques/pre/>]

Mitre’s Common Vulnerabilities and Exposures search.\[<https://cve.mitre.org/cve/>]

#### **Changing Security Behaviors**

The Engine Room. “Ties That Bind: Organisational Security for Civil Society” \[<https://www.theengineroom.org/civil-society-digital-security-new-research/>]

Adrienne Porter Felt et al. “Improving SSL Warnings: Comprehension and Adherence” \[<https://dl.acm.org/citation.cfm?id=2702442>]

Francesca Musiani and Ksenia Ermoshina. “What is a Good Secure Messaging Tool? The EFF Secure Messaging Scorecard and the Shaping of Digital (Usable) Security” \[<https://www.westminsterpapers.org/articles/10.16997/wpcc.265/>]

Alma Whitten and Doug Tygar. “Why Johnny Can’t Encrypt” \[<https://www.usenix.org/legacy/publications/library/proceedings/sec99/full_papers/whitten/whitten_html/index.html>]

#### **Social Engineering and Phishing**

Citizen Clinic. "Phishing Simulation Policy" \[<https://www.citizenclinic.io/Clinic\\_Infrastructure/Phishing\\_Simulation/>]

Masashi Crete-Nishihata et al, Citizen Lab. "Spying on a Budget: Inside a Phishing Operation with Targets in the Tibetan Community" [\[https://citizenlab.ca/2018/01/spying-on-a-budget-inside-a-phishing-operation-with-targets-in-the-tibetan-community/\]](https://citizenlab.ca/2018/01/spying-on-a-budget-inside-a-phishing-operation-with-targets-in-the-tibetan-community/)]

Micah Lee, The Intercept. “It’s Impossible To Prove Your Laptop Hasn’t Been Hacked. I Spent Two Years Finding Out.” \[<https://theintercept.com/2018/04/28/computer-malware-tampering/>]

Rachel Tobac. Social Proof Security. “How I would Hack You: Social Engineering Step-by-Step” \[<https://www.youtube.com/watch?v=L5J2PgGOLtE>]

#### **Designing Security Training**

Electronic Frontier Foundation. “Am I the Right Person?” [\[https://sec.eff.org/articles/right-person-to-train\]](https://sec.eff.org/articles/right-person-to-train)

Electronic Frontier Foundation. “How to Teach Adults” \[<https://sec.eff.org/articles/how-to-teach-adults>]

Browse the rest of EFF’s Security Education Companion. \[<https://sec.eff.org/>]

Rachel Weidinger et al. “How To Give A Digital Security Training” \[<https://medium.com/@geminiimatt/how-to-give-a-digital-security-training-4c83af667d40>]

Rachel Weidinger et al. “Digital Security Training Resources for Security Trainers, Fall 2019 Edition” \[<https://medium.com/cryptofriends/digital-security-training-resources-for-security-trainers-spring-2017-edition-e95d9e50065e>]

#### **Psychosocial Resilience**

Rated R for Resilience resource site. \[<https://sites.google.com/view/ratedr/basics>]

Angela Chen. The Verge. “Moderating content doesn’t have to be so traumatic” \[<https://www.theverge.com/2019/2/27/18243359/content-moderation-mental-health-ptsd-psychology-science-facebook>]

Sam Dubberley and Michele Grant. First Draft. “Journalism and Vicarious Trauma” \[<https://firstdraftnews.org/wp-content/uploads/2017/04/vicarioustrauma.pdf>]

Sarah Jeong, Charlie Warzel, Brianna Wu, Joan Donovan. New York Times. “Everything is GamerGate” \[<https://www.nytimes.com/interactive/2019/08/15/opinion/gamergate-twitter.html>] - **Read all of the four essays.**

#### **Harmful Information (Misinformation and Harassment)**

Tahmina Ansari, First Draft. “This Muslim journalist embraced social media until it ‘ruined’ his life” \[<https://firstdraftnews.org/this-muslim-journalist-embraced-social-media-until-it-ruined-his-life/>]

Nicholas Monaco and Carly Nyst. Institute For The Future. “State-Sponsored Trolling: How Governments Are Deploying Disinformation as Part of Broader Digital Harassment Campaigns”. Read pages 3 to 21 & 45 to 51. \[<http://www.iftf.org/statesponsoredtrolling>]

Sarah Oh and Travis L. Adkins. InterAction. “Disinformation Toolkit.” \[<https://staging.interaction.org/documents/disinformation-toolkit/>]

Cindy Otis. USA Today. “Americans could be a bigger fake news threat than Russians in the 2020 presidential campaign” \[<https://www.usatoday.com/story/opinion/2019/07/19/disinformation-attacks-americans-threaten-2020-election-column/1756092001/>]

Reply All podcast. “#112 The Prophet” Listen to or read transcript. \[<https://www.gimletmedia.com/reply-all/112-the-prophet>]**Introduction to Public Interest Cybersecurity**

Sean Brooks, Center for Long-Term Cybersecurity. “Defending Politically Vulnerable Organizations Online” \[<https://cltc.berkeley.edu/wp-content/uploads/2018/07/CLTC_Defending_PVOs.pdf>]

Citizen Lab’s “About Us” Paper. \[<https://citizenlab.ca/wp-content/uploads/2018/05/18033-Citizen-Lab-booklet-p-E.pdf>]

Citizen Lab’s Security Planner. \[<https://securityplanner.org/>]

Sandro Contenta, Toronto Star. “How these Toronto sleuths are exposing the world’s digital spies while risking their own lives” \[<https://www.thestar.com/news/canada/2019/12/13/from-a-tower-in-toronto-they-watch-the-watchers-how-citizen-lab-sleuths-are-exposing-the-worlds-digital-spies-while-risking-their-own-lives.html>]

Havron et al. "Clinical computer security for victims of intimate partner violence." In Proceedings of the 28th USENIX Security Symposium (pp. 105-122).\[<https://www.nixdell.com/papers/2019-usenix_clinical_security_FULL.pdf>]

Deji Olukotun, Access Now. “Spyware in Mexico: an interview with Luis Fernando García of R3D Mexico” \[<https://www.accessnow.org/spyware-mexico-interview-luis-fernando-garcia-r3d-mexico/>]

Tactical Tech's Annual Report \[<https://cdn.ttc.io/s/tacticaltech.org/Tactical-Tech-2018-Annual-Report.pdf>]

#### **Ethics and the Citizen Clinic Code of Conduct**

Citizen Clinic. "Student Code of Conduct" \[<https://www.citizenclinic.io/Clinic\\_Curriculum/Modules/Ethics/Student\\_Code\\_of\\_Conduct/>]

Shannon Vallor, The Markkula Center for Applied Ethics. “An Introduction to Cybersecurity Ethics” \[<https://www.scu.edu/media/ethics-center/technology-ethics/IntroToCybersecurityEthics.pdf>]

#### **Old School INFOSEC: Basic Controls**

Le Blond et al. “A look at targeted attacks through the lense of an NGO” \[[www.usenix.org/system/files/conference/usenixsecurity14/sec14-paper-blond.pdf](https://www.usenix.org/system/files/conference/usenixsecurity14/sec14-paper-blond.pdf)]

Sean Brooks, CLTC, TechSoup Webinar. “Cybersecurity in Low-Risk Organizations: Understanding Your Risk and Making Practical Improvements.”: \[<https://cltc.berkeley.edu/2019/02/25/cltc-and-citizen-clinic-present-cybersecurity-in-low-risk-organizations-webinar/>]

Citizen Lab’s Security Planner. \[<https://securityplanner.org/>]

Electronic Frontier Foundation’s Surveillance Self-Defense guide. \[<https://ssd.eff.org/>]

Alex Gaynor. “What happens when you type google.com into your browser's address box and press enter?" \[<https://github.com/alex/what-happens-when>]

Rus Shuler. “How Does the Internet Work?” \[[web.stanford.edu/class/msande91si/www-spr04/readings/week1/InternetWhitepaper.htm](https://web.stanford.edu/class/msande91si/www-spr04/readings/week1/InternetWhitepaper.htm)]

#### **Digital Surveillance of Politically Vulnerable Organizations: The Threat Landscape**

Stephen Arnold. “Telestrategies - An Interview with Dr. Jerry Lucas” \[<http://www.arnoldit.com/search-wizards-speak/telestrategies-2.html>]

Joseph Cox. “I Gave a Bounty Hunter $300. Then He Located Our Phone” \[<https://motherboard.vice.com/en_us/article/nepxbz/i-gave-a-bounty-hunter-300-dollars-located-phone-microbilt-zumigo-tmobile>]

Vernon Silver and Ben Elgin. “Torture in Bahrain Becomes Routine With Help From Nokia Siemens” \[<https://web.archive.org/web/20111006185329/http://www.bloomberg.com/news/2011-08-22/torture-in-bahrain-becomes-routine-with-help-from-nokia-siemens-networking.html>]

John Scott-Railton et al, Citizen Lab. “Bittersweet: Supporters of Mexico’s soda tax targeted with NSO exploit links” \[<https://citizenlab.ca/2017/02/bittersweet-nso-mexico-spyware/>]

#### **Problem Diagnosis and Reframing**

Netgain. “Digital Security and Grantcraft Guide” \[[fordfoundation.org/media/3334/digital-security-grantcraft-guide-v10-final-22317.pdf](https://www.fordfoundation.org/media/3334/digital-security-grantcraft-guide-v10-final-22317.pdf)]

Arthur Turner. “Consulting Is More Than Giving Advice” \[<https://hbr.org/1982/09/consulting-is-more-than-giving-advice>]

Thomas Wedell-Wedellsborg. “Are You Solving the Right Problems?” \[<https://hbr.org/2017/01/are-you-solving-the-right-problems>]

#### **Threat Modeling & Bounding Risk Assessments**

Electronic Frontier Foundation, “Surveillance Self-Defense: Your Security Plan” \[<https://ssd.eff.org/en/playlist/activist-or-protester#your-security-plan>]

NIST SP 800-37 “Risk Management Framework for Information Systems and Organizations.” Chapter 2 only. \[<https://csrc.nist.gov/CSRC/media/Publications/sp/800-37/rev-2/draft/documents/sp800-37r2-draft-ipd.pdf> or [Shutdown Mirror](https://github.com/danphilpott/fismapedia-files/blob/master/NIST%20SP%20800-037r2%20Risk%20Management%20Framework%20for%20Information%20Systems%20and%20Organizations;%20A%20System%20Life%20Cycle%20Approach%20for%20Security%20and%20Privacy,%202018-12-20%20\(Final\).pdf)]

NIST SP 800-39 “Managing Information Security Risk.” Chapter 2 only. \[<https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-39.pdf> or [Shutdown Mirror](https://github.com/danphilpott/fismapedia-files/blob/master/NIST%20SP%20800-039%20Managing%20Information%20Security%20Risk;%20Organization,%20Mission,%20and%20Information%20System%20View,%202011-03-01%20\(Final\).pdf)]

NISTIR 8062 “An Introduction to Privacy Engineering and Risk Management in Federal Systems.” \[<https://nvlpubs.nist.gov/nistpubs/ir/2017/NIST.IR.8062.pdf> or [Shutdown Mirror](https://github.com/danphilpott/fismapedia-files/blob/master/NIST%20IR%208062.pdf)]

#### **Contextual & Capacity Research**

SAFETAG, Internews. "SAFETAG Guide" ***Skim to Section 2.2, then read Section 2.2 and Section 2.3.*** \[<https://safetag.org/guide/>]

Read and Explore Examples About PESTLE. *(use an ad-blocker!)* \[<https://pestleanalysis.com/what-is-pestle-analysis/>]

Jorge Luis Sierra. “Digital and Mobile Security for Mexican Journalists and Bloggers” \[<https://freedomhouse.org/sites/default/files/Digital%20and%20Mobile%20Security%20for%20Mexican%20Journalists%20and%20Bloggers.pdf>]

#### **Information Gathering**

Ruba Abu-Salma et al. “Obstacles to the Adoption of Secure Communication Tools” \[<https://ieeexplore.ieee.org/abstract/document/7958575/>]

Jeanette Blomberg et al. "An Ethnographic Approach to Design" \[<https://www.researchgate.net/publication/262363851_An_Ethnographic_Approach_to_Design>]

Jenna Burrell. "The Field Site as a Network: A Strategy for Locating Ethnographic Research" \[<https://doi.org/10.1177/1525822X08329699>]

Collaboration on International ICT Policy in East and Southern Africa. “Safeguarding Civil Society: Assessing Internet Freedom and the Digital Resilience of Civil Society in East Africa” - Read each chapter, but for one country only. \[<https://cipesa.org/?wpfb_dl=237>]

Lofland and Lofland. Read Chapter 5 (66-98) "Logging Data" in "Analyzing social settings: A guide to qualitative observation and analysis" \[<https://searchworks.stanford.edu/view/10531063>]

#### **Open Source Research Methods, Safety, and Tools**

Awesome OSINT \[<https://github.com/jivoi/awesome-osint>]

Ian Barwise. “Open-Source Intelligence (OSINT) Reconnaissance” \[<https://medium.com/@z3roTrust/open-source-intelligence-osint-reconnaissance-75edd7f7dada>]

Conor Fortune, Amnesty International. “Digitally dissecting atrocities – Amnesty International’s open source investigations.” \[<https://www.amnesty.org/en/latest/news/2018/09/digitally-dissecting-atrocities-amnesty-internationals-open-source-investigations/>]

OSINT Framework \[<https://osintframework.com/>]

OSINT.link \[<https://osint.link>]

Travis Lishok, Protective Intelligence. “Part I: An Introduction To OSINT Research For Protective Intelligence Professionals” \[<https://www.protectiveintelligence.com/blog/osint-intro-for-protective-intelligence-pt1>]

Travis Lishok, Protective Intelligence. “Part 2: An Introduction To OSINT Research For Protective Intelligence Professionals” \[<https://www.protectiveintelligence.com/blog/osint-intro-for-protective-intelligence-pt2>]

SECALERTS - Automated Security Audit \[<https://secalerts.co/security-audit>]

#### **Security Law and Policy Factors**

James C. Scott. “Seeing Like a State” - Chapter 9 \[<https://libcom.org/files/Seeing%20Like%20a%20State%20-%20James%20C.%20Scott.pdf>]

Kim Fong et al. “A CRIMSon Tide of Data: An Assessment of Potential Privacy Problems of the Consolidate Records Information Management System” \[<http://people.ischool.berkeley.edu/~strush/CRIMS_FongRowlandTrush_Feb2018.pdf>]

#### **Adversary Persona Development**

Julian Cohen. “Playbook Based Testing.” \[<https://medium.com/@HockeyInJune/playbook-based-testing-5df4b656113a>]

Bill Marczak and John Scott-Railton, Citizen Lab. “Keep Calm and (Don’t) Enable Macros: A New Threat Actor Targets UAE Dissidents” \[<https://citizenlab.ca/2016/05/stealth-falcon/>]

Nick Merrill, Daylight Security Research Lab. "Adversary Personas" \[<https://daylight.berkeley.edu/adversary-personas/>]

Microsoft’s STRIDE and related blog posts. \[<https://cloudblogs.microsoft.com/microsoftsecure/2007/09/11/stride-chart/>]

#### **Threat Scenario Development**

Mitre’s ATT\&CK Wiki. \[<https://attack.mitre.org/>]

Mitre’s PRE-ATT\&CK Techniques. \[<https://attack.mitre.org/techniques/pre/>]

Mitre’s Common Vulnerabilities and Exposures search.\[<https://cve.mitre.org/cve/>]

#### **Changing Security Behaviors**

The Engine Room. “Ties That Bind: Organisational Security for Civil Society” \[<https://www.theengineroom.org/civil-society-digital-security-new-research/>]

Adrienne Porter Felt et al. “Improving SSL Warnings: Comprehension and Adherence” \[<https://dl.acm.org/citation.cfm?id=2702442>]

Francesca Musiani and Ksenia Ermoshina. “What is a Good Secure Messaging Tool? The EFF Secure Messaging Scorecard and the Shaping of Digital (Usable) Security” \[<https://www.westminsterpapers.org/articles/10.16997/wpcc.265/>]

Alma Whitten and Doug Tygar. “Why Johnny Can’t Encrypt” \[<https://www.usenix.org/legacy/publications/library/proceedings/sec99/full_papers/whitten/whitten_html/index.html>]

#### **Social Engineering and Phishing**

Citizen Clinic. "Phishing Simulation Policy" \[<https://www.citizenclinic.io/Clinic\\_Infrastructure/Phishing\\_Simulation/>]

Masashi Crete-Nishihata et al, Citizen Lab. "Spying on a Budget: Inside a Phishing Operation with Targets in the Tibetan Community" [\[https://citizenlab.ca/2018/01/spying-on-a-budget-inside-a-phishing-operation-with-targets-in-the-tibetan-community/\]](https://citizenlab.ca/2018/01/spying-on-a-budget-inside-a-phishing-operation-with-targets-in-the-tibetan-community/)]

Micah Lee, The Intercept. “It’s Impossible To Prove Your Laptop Hasn’t Been Hacked. I Spent Two Years Finding Out.” \[<https://theintercept.com/2018/04/28/computer-malware-tampering/>]

Rachel Tobac. Social Proof Security. “How I would Hack You: Social Engineering Step-by-Step” \[<https://www.youtube.com/watch?v=L5J2PgGOLtE>]

#### **Designing Security Training**

Electronic Frontier Foundation. “Am I the Right Person?” [\[https://sec.eff.org/articles/right-person-to-train\]](https://sec.eff.org/articles/right-person-to-train)

Electronic Frontier Foundation. “How to Teach Adults” \[<https://sec.eff.org/articles/how-to-teach-adults>]

Browse the rest of EFF’s Security Education Companion. \[<https://sec.eff.org/>]

Rachel Weidinger et al. “How To Give A Digital Security Training” \[<https://medium.com/@geminiimatt/how-to-give-a-digital-security-training-4c83af667d40>]

Rachel Weidinger et al. “Digital Security Training Resources for Security Trainers, Fall 2019 Edition” \[<https://medium.com/cryptofriends/digital-security-training-resources-for-security-trainers-spring-2017-edition-e95d9e50065e>]

#### **Psychosocial Resilience**

Rated R for Resilience resource site. \[<https://sites.google.com/view/ratedr/basics>]

Angela Chen. The Verge. “Moderating content doesn’t have to be so traumatic” \[<https://www.theverge.com/2019/2/27/18243359/content-moderation-mental-health-ptsd-psychology-science-facebook>]

Sam Dubberley and Michele Grant. First Draft. “Journalism and Vicarious Trauma” \[<https://firstdraftnews.org/wp-content/uploads/2017/04/vicarioustrauma.pdf>]

Sarah Jeong, Charlie Warzel, Brianna Wu, Joan Donovan. New York Times. “Everything is GamerGate” \[<https://www.nytimes.com/interactive/2019/08/15/opinion/gamergate-twitter.html>] - **Read all of the four essays.**

#### **Harmful Information (Misinformation and Harassment)**

Tahmina Ansari, First Draft. “This Muslim journalist embraced social media until it ‘ruined’ his life” \[<https://firstdraftnews.org/this-muslim-journalist-embraced-social-media-until-it-ruined-his-life/>]

Nicholas Monaco and Carly Nyst. Institute For The Future. “State-Sponsored Trolling: How Governments Are Deploying Disinformation as Part of Broader Digital Harassment Campaigns”. Read pages 3 to 21 & 45 to 51. \[<http://www.iftf.org/statesponsoredtrolling>]

Sarah Oh and Travis L. Adkins. InterAction. “Disinformation Toolkit.” \[<https://staging.interaction.org/documents/disinformation-toolkit/>]

Cindy Otis. USA Today. “Americans could be a bigger fake news threat than Russians in the 2020 presidential campaign” \[<https://www.usatoday.com/story/opinion/2019/07/19/disinformation-attacks-americans-threaten-2020-election-column/1756092001/>]

Reply All podcast. “#112 The Prophet” Listen to or read transcript. \[<https://www.gimletmedia.com/reply-all/112-the-prophet>]


# Introduction

*Please Note: Cybersecurity is a rapidly evolving field. This document was last updated on February 2, 2019. Some of the technical guidance within this document may change, and some of the risks defined may increase or decrease in their potential likelihood or impact.*

An introductory webinar to this guide including information about it's contents and how to use it, [can be seen here](https://www.techsoup.org/community/events-webinars/cybersecurity-in-low-risk-organizations-understanding-your-risk-2019-02-19).

This guide is intended as an introductory document for low-risk organizations interested in improving their cybersecurity practices, ***specifically nonprofits and public interest organizations at low risk of targeted cyberattacks.*** By "targeted cyberattacks," this guide refers to attacks on systems that seek to disrupt or surveil a specific organization or individual (as opposed to attacks meant to compromise as many devices or accounts as possible). This document provides guidance to improve the resilience of low-risk organizations (LROs) to common cyberattacks, and a framework for LROs to develop a basic cybersecurity policy. It is worth noting that all organizations are at some risk of cybersecurity incidents. Though not all organizations are equally likely to be victimized by online attacks, there are basic steps that LROs can take to improve their resiliency and keep themselves at lower risk—even while recognizing the limits to their potential investments of time, people, and money.

This is not intended to be a comprehensive guide to cybersecurity, nor an exhaustive set of recommendations. This guide is intended to help individuals in leadership positions and technical staff with little or no cybersecurity background understand some of the fundamentals of their own security context and guide them toward initial steps for improving their cybersecurity. The audience for this guide could include executive staff, system administrators, financial officers, general counsels, non-profit board members, or anyone interested in elevating their organizations' appreciation of cybersecurity issues.

This guide has three primary sections: the first introduces basic cybersecurity concepts, including the fundamentals of cybersecurity risk management; the second describes a series of basic cybersecurity "controls" – or measures organizations can take to improve their resilience to cybersecurity threats; the third describes additional cybersecurity best practices and policies LROs should adopt. Appendix A is designed to help organizations draft a basic cybersecurity policy using the controls and best practices described in this guide. Appendix B provides guidance on how to implement selected cybersecurity controls. Appendix C describes a series of additional resources for organizations interested in moving toward a more sophisticated cybersecurity posture.


# Section 1: Why do Low-Risk Organizations Need Cybersecurity?

*Please Note: Cybersecurity is a rapidly evolving field. This document was last updated on February 2, 2019. Some of the technical guidance within this document may change, and some of the risks defined may increase or decrease in their potential likelihood or impact.*

A 2018 report from the Public Interest Registry surveyed over 5,300 NGOs and demonstrated that, while nonprofits invest in information technology to conduct mission-critical activities, information security investment continues to be low.\[^1] Beyond low cybersecurity investment, mission-driven organizations often lack the expertise at the staff level to fend off basic online threats. Connectivity is crucial for organizations with decentralized operations or a wide volunteer base. As a result, organizations establishing such connectivity often ignore many of the basic steps that more technically mature organizations would take to preserve system security (like using formal identity systems or multi-factor authentication) in order to establish an online presence quickly.

They may not be of high risk of a cyberattack, but low-risk organizations are often resource-constrained. Therefore, the loss of control of an organizational bank account, of donor lists, or of important internal documents can have an outsized impact on organizations who otherwise might not consider cybersecurity important to their mission.

Nonprofits and public interest organizations are unlikely to make significant investments in cybersecurity. On average, small nonprofits (defined as organizations with 15 or fewer employees) have one IT person on staff, and the ratios of IT staff to non-technical staff are even more uneven in larger organizations.\[^2] Given that cybersecurity jobs only account for 11 percent of all IT jobs,\[^3] the small IT staff of most nonprofits are unlikely to provide much, if any, cybersecurity support. Nonprofits face intense competition to attract IT talent. Some studies have estimated that the global cybersecurity labor market (including both the public and private sectors) will face a shortage of 1.8 million workers by 2022.\[^4] Given that 92 percent of nonprofits surveyed in a 2010 study by the John Hopkins Center for Civil Society Studies indicated a lack of funds to be a primary barrier to increasing their organization's IT capacity, it would be unrealistic to expect that these organizations have the capital to compete with the private sector to attract cybersecurity talent.\[^5] Nonprofits have traditionally used their missions to attract staff at sub-market rates, but still face challenges in recruiting the number of individuals needed to make up this gap.

**What makes an organization "low risk"?**

While many of the basic recommendations in this guide are applicable to all organizations, this guide is designed with "low-risk" organizations in mind. But what does it mean for an organization to be "low risk"? The "Digital Security & Grantcraft Guide"\[^6] published in early 2017 by the NetGain Partnership provides information for funders about how to evaluate if a grantee organization is at high risk of a cyberattack. Some of the same considerations can be applied to determining if an organization is low risk. The paper describes three basic layers of consideration: "Is the grantee high risk; is the context high risk; is the project high risk?" Each of these questions explores whether or not an element of a funded project or program is more or less at risk of a cyberattack.

Consider the following questions:

* Do you believe your organization is actively at risk of a cyberattack? Are you aware of other organizations like yours that have been actively targeted with a cyberattack?
* Does your work generate controversy, or is it viewed with hostility by government actors, government-backed organizations, or independent malicious actors?
* Are any individuals affiliated with your organization (staff, board members, advisors, etc.) engaged in work or behaviors that might draw the attention of adversaries or malicious actors?
* Do you collect, generate, or otherwise handle sensitive information (such as names, addresses, phone numbers, banking information, gender identity, or other personally identifiable information) about a vulnerable population, or of interest to an oppressive government or malicious non-state actor?

If the answer to any of the above questions is "yes," your organization is not low risk, and this guide should not be considered sufficient for establishing a baseline security practice. While some of the recommendations in this guide may be useful for high-risk organizations, groups concerned about targeted attacks should consult a cybersecurity specialist, as well as the following resources:

* Electronic Frontier Foundation - Surveillance Self Defense: <https://ssd.eff.org/>
* Internews - SAFETAG Framework: <https://safetag.org/>
* Tactical Tech - Security in a Box: <https://securityinabox.org/en/>

**Organizations who identify as high risk should consult cybersecurity specialists.**

While the contents of this guide offer a baseline for any organization's cybersecurity, they should not be considered a comprehensive set of cybersecurity tools. No organization or system is ever completely "secure" – and those at greater risk must evaluate their context and individual technical circumstances to understand how to best protect themselves from online threats.

> **PLEASE NOTE:** Cybersecurity is a rapidly changing field. Many useful and reliable tools can become obsolete – even to a dangerous degree – overnight as new attacks emerge. The advice and tools offered in this report are considered reliable by the authors and a panel of cybersecurity experts as of February 2, 2019, but as this report ages, readers should consider this advice subject to deprecation.

### Introduction to Cybersecurity

There are a range of formal and legalistic definitions of cybersecurity and information security. An example: "The protection of information and information systems from unauthorized access, use, disclosure, disruption, modification, or destruction in order to provide confidentiality, integrity, and availability."\[^7] If this seems incredibly broad – that is because it is. Cybersecurity has become a wide-ranging discipline as the use of information technology has stretched across all corners of our daily lives. Because of its breadth, its rapid evolution, and the sometimes counterintuitive nature of emerging challenges, understanding cybersecurity can feel overwhelming. This can be particularly true for organizations that do not consider cybersecurity to be an integral part of their mission. This section will outline the basic tenets of cybersecurity, and includes some examples to illustrate how cybersecurity disruptions can interfere with mission priorities in organizations that have not historically considered online threats.

***In practical terms, an organization's cybersecurity is its ability to operate information and online technologies safely, accurately, and without interruption or unintended observation.***

Most experts will point to the cybersecurity "objectives" of Confidentiality, Integrity, and Availability, known colloquially as "CIA" or the "CIA Triad." These objectives are not goals, but rather, they describe the characteristics of secure information systems. No system has perfect confidentiality, integrity, or availability. These objectives can be used to articulate how a certain technique, tool, or policy might improve a system's security, or how a system's security might be diminished by an attack. These security-enhancing tools, techniques, or policies are referred to as "controls" - cybersecurity measures that can mitigate risk. The cybersecurity objectives may be briefly summarized as follows\[^8]:

* Confidentiality: Information is only readable by its intended audience.
* Integrity: Information is accurate and maintained in its intended state.
* Availability: Information is accessible to individuals and systems as intended.

The following sections will further describe these objectives using real-world examples.

**A Note on Privacy**

While this guide is focused on cybersecurity, there are a number of privacy issues that intersect with the security of information systems. Many of the privacy issues highlighted in the news are related to breaches of security, but things can go wrong for privacy even without an active "attack." For example, if an organization shares a list of attendees to a past event with a partner, and that partner wants to expand its own email list to promote a similar event, this sharing might generate backlash from supporters. Individuals may lose trust in the original organization and feel they have been signed up for "spam" if they learn their information was shared without their consent.

While a number of the recommendations in this guide may improve the privacy of LROs' employees, supporters, and partners, this is not a guide to managing privacy risks. An organization's general or outside counsel can often serve as a good resource for learning more about the basics of managing privacy. The International Association of Privacy Professionals provides many tools, trainings, and even certifications in modern privacy practices for organizations who wish to expand their internal privacy expertise: <https://iapp.org/>.

#### Confidentiality

Attacks on confidentiality make up the majority of what are often described as "data breaches." When a system loses its confidentiality, someone has gained access to information without permission, or information is inappropriately released. Attacks on confidentiality could make public information that an organization wishes to keep private, such as donor lists, financial documents, human resource files, or sensitive emails. These attacks can also victimize partners, supporters, and clients by putting their personal or financial information in the hands of criminals or other malicious actors.

> **Confidentiality Under Attack at the Utah Food Bank:** For a period of nearly two years, a security flaw in the website of the Utah Food Bank (UFB) allowed an attacker to access the personal information of individuals who submitted a donation through that site. The information, belonging to over 10,000 people (or 8% of the Food Bank's donors), included names, addresses, email addresses, credit or debit card numbers, security codes and expiration dates. The UFB underwent an extensive investigation, but was unable to ascertain the identity of the attacker. The UFB offered free credit monitoring to those affected by the breach, and had to undergo an 18-month restructuring of its website to enable more secure payment methods for its donors.

#### Integrity

A system loses integrity when a person can change something without permission. For example, a student hacking into their school's system to change their grades would be an attack on the integrity of that grading system. Attacks on integrity often challenge one of the primary virtues of using information systems: that information can be maintained and shared in a way that is consistent and accurate.

> **Online Vandals Disrupt the Website Integrity of Schools and Nonprofits:** In November of 2017, a service called SchoolDesk – which provides web hosting services for thousands of schools across the US – was attacked by online vandals who altered a common system shared by many of SchoolDesk's customers. As a result, the homepages of about 800 schools were changed to display images and videos celebrating the Islamic State in Syria and the Levant. The sites were taken offline while SchoolDesk's systems were repaired, and while the attack did not disrupt the data or internal systems of school districts, it was deeply embarrassing for the affected schools. In 2015, the same groups of online vandals used a weakness in outdated versions of Wordpress – a common website design system – to display similar messages. The attack affected many small organizations who had not updated their Wordpress service, causing many to permanently lose portions of their website that were not backed up.

#### Availability

Availability attacks affect the ability to access data or systems. These attacks can create restrictions for user access, can take entire websites offline, or can even hold devices hostage.

> **Ransomware Attacks Availability of the St. Louis Public Library:** In early 2017, the St. Louis Public Library suffered a ransomware attack. Ransomware uses strong encryption software to lock individuals out of their devices, holding the devices hostage until a ransom is paid. In this case, the ransomware's authors demanded $35,000 to release systems that had been maliciously encrypted at all 17 branches of the library. The library refused to pay the ransom, but it needed nearly a week to regain access to its systems. Other ransomware victims are not so lucky, and if a ransom is not paid, all the data on a device can be lost. In 2017, multiple large-scale ransomware attacks crawled from system to system, locking millions of devices around the world.

The security objectives are useful tools for discussing what kind of security any given system needs. In combination with some basic risk management considerations, the objectives can help LROs ask, "What kinds of cyberattacks are we most worried about affecting our systems, and what kinds of controls will be effective at preventing those attacks?"

### Understanding Cybersecurity Risk

Risk management is an important tool that provides a way for organizations to prioritize how to spend limited resources. Given the broad range of potential cybersecurity threats, effective use of organizational resources requires a focus on mitigating threats that are important and relevant to an organization's mission.

Risk management relies on two metrics to assess potential issues: the likelihood of an attack, and the impact of that potential attack. These two components are common for evaluating all forms of risk – including risk to finances, people, and mission. In cybersecurity, advanced risk management involves assessing particular systems for vulnerabilities and the likelihood an attacker might try to exploit those vulnerabilities – often through a process called "threat modeling" or "threat mapping."\[^9] While LROs are unlikely to have the time and resources to complete a detailed risk assessment exercise, they can still benefit from a less intensive effort to understand the likelihood and potential impact of some basic threat areas. This simpler exercise may be enough to determine what steps an LRO needs to take to improve its cybersecurity, and shift its organizational approach to cybersecurity towards one that is more risk-informed.

#### Common Threat Areas

While cybersecurity threats will vary depending on context, LROs should focus their energy on mitigating the most common forms of attacks. Many of these common attacks use techniques that have not changed substantially for many years, but LROs can still be victimized if they have not implemented basic security measures. The goal of LRO risk management is to deny attackers this "low hanging fruit."

Attackers targeting LROs are likely to be motivated by profit rather than by politics.\[^10] Whereas politically-minded attackers tend to carry out sophisticated and targeted attacks, profit-minded attackers are much more concerned with their cost margins, and a sophisticated, time-consuming, or expensive method of attack limits the breadth of their potential pool of targets.\[^11] This means attacks on LROs are likely to be unsophisticated, automated, and targeted at simple, known systems vulnerabilities. Three types of common attacks described below represent the most common threats LROs will likely face online:

**Account Compromise:** According to Verizon, the most common tactic used to facilitate data breaches in 2018 was the reuse of stolen usernames and passwords.\[^12] The proliferation of stolen passwords and usernames (also known as "account credentials") online – combined with the reality that people tend to recycle the same passwords across accounts – means that one of the most common forms of online attacks doesn't require any "hacking" at all. By buying or otherwise accessing dumps of already-compromised logins, attackers can attempt to take over multiple accounts owned by the same user. Account credentials are the "front door" to many sensitive or important services, and their design is generally unfriendly to humans (they are hard to memorize, hard to share, etc.). This means account credentials are often the easiest way to gain access to the most delicate of information - why do any complicated "hacking" if you can just get someone to send you their password in an email, or find a reused password in old breach data?

**Phishing:** Phishing is the use of email or another digital communications platform to trick an individual into disclosing sensitive information that can then be used to carry out a cyberattack. Phishing attacks generally require low technical sophistication to execute, often relying on simple techniques like sending emails with links to fake websites that prompt individuals to "log in" with their usernames and passwords, when really they are submitting this sensitive information directly to the attacker. Phishing emails can also trick individuals into opening attachments that include malicious software. While it may seem embarrassing to fall for a phishing email, these attacks often fool even the most sophisticated targets, and in many ways it is the simplicity of this type of attack that makes it so dangerous. Phishing is the entry point for a range of attacks, so the consequences of being phished can vary widely. Some of those consequences can include the loss of control of important accounts (such as banking, email, or social media accounts), the infection of devices with malicious software, or the theft of important data.

**Data Promiscuity:** The sprawl of data – both online and across internal systems – is a reality that can have many potential negative outcomes for an organization. Poor data security practices within an organization greatly increase the likelihood of an attacker siphoning off information from its systems. Poor internal access controls may allow employees of an organization to access privileged information – such as HR files – inappropriately. Especially for organizations with significant staff turnover, it is often challenging to manage and secure internal access to information. For example: every time an organization shares a password with an employee or grants them access to sensitive systems, then forgets to revoke that employee's access or change passwords once the employee leaves the organization or changes roles, an opportunity arises for an accidental or malicious leakage of information.

**Malware:** Malicious software (or "malware") is a broad threat area, but one that encompasses many of the terms that people generally associate with cybersecurity, such as viruses, worms, and trojan horses. Malware generally takes advantage of a flaw in a system's design (a "vulnerability") to make the system act in a manner that is not intended. Many people have experienced firsthand a form of malware "exploiting" a vulnerability on a system or device they own or rely on. While a malware attack is one of the more clear and present dangers online, the technical vulnerabilities malware exploits often get fixed before the attack can be carried out. Attackers who use malware rely on individuals and organizations not updating their software frequently. They focus on systems with out-of-date web browsers or other common software (like Microsoft Office or Adobe Acrobat) with known vulnerabilities to maximize the reach of their attack.

For example, one type of malware is ransomware, which uses encryption software to lock up a device so its basic functions and data are inaccessible unless and until the victim pays a ransom. . Ransomware has seen an explosive increase in growth in recent years.\[^13] Like most malware, it takes advantage of known security vulnerabilities in common software or operating systems. Like other forms of malware, it often requires some user interaction to operate (e.g. a user must click "ok" when prompted to install a piece of unknown software). However, recent variants of ransomware have used powerful methods stolen from intelligence agencies that enable the software to run on victims' computers with minimal user interaction.\[^14]

\[^1]: Nonprofit Tech for Good, *2018 Global NGO Technology Report* (Reston, VA: Public Interest Registry, 2018), <http://techreport.ngo/>.

\[^2]: Lyndal Cairns, "Nonprofit Technology Staffing and Investments Report," *Non-Profit Technology Network*, May 2017, <https://www.nten.org/article/your-guide-to-nonprofit-it-investment/>.

\[^3]: Burning Glass, "Job Market Intelligence: Cybersecurity Jobs, 2015," *Burning Glass Technologies*, July 2015, <http://burning-glass.com/research/cybersecurity/>.

\[^4]: Frost & Sullivan, *2017 Global Information Security Workforce Study: Benchmarking Workforce Capacity and Response to Cyber Risk* (Clearwater, FL: Center for Cyber Safety and Education), 2017,\_ \_<https://iamcybersafe.org/wp-content/uploads/2017/06/Europe-GISWS.pdf>.

\[^5]: Stephanie L Geller, Alan J Abramson, and Erwin de Leon, *The Nonprofit Technology Gap–Myth or Reality* (Johns Hopkins Listening Post Project, Communique 20, 2010), <http://ejewishphilanthropy.com/wordpress/wp-content/uploads/2010/12/Nonprofit-Technology-Gap-Dec.-2010.pdf>.

\[^6]: "Digital Security & Grantcraft Guide," Ford Foundation, accessed February 15, 2018, <https://www.fordfoundation.org/library/reports-and-studies/digital-security-grantcraft-guide/>.

\[^7]: Federal Information Processing Standard 199. "Standards for Security Categorization of Federal Information and Information Systems." (2004): <https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.199.pdf>.

\[^8]: These definitions are simplified for this document. More formal definitions can be found in *CNSSI 4009* or NIST Special Publication 800-53.

\[^9]: "Hacked! Crooks Are Grabbing Nonprofit Websites and Demanding Ransom." *The NonProfit Times* (blog). Accessed December 20, 2017. <http://www.thenonprofittimes.com/news-articles/hacked-crooks-grabbing-nonprofit-websites-demanding-ransom/>, "More than 10,000 Utah Food Bank Donors Notified of Breach." SC Media US, August 31, 2015. <https://www.scmagazine.com/the-data-breach-blog/more-than-10000-utah-food-bank-donors-notified-of-breach/article/532920/>.

\[^10]: "800 US Schools' Websites Hacked with Saddam Hussein Photo, 'I Love Islamic State' Message." International Business Times UK, November 7, 2017. <http://www.ibtimes.co.uk/pro-isis-hackers-hijack-800-us-schools-sites-saddam-hussein-photo-i-love-islamic-state-message-1646210>.

\[^11]: "When ISIS Hacks Your Website." *Nick Fogle* (blog), January 7, 2015. <http://nickfogle.com/hacked-by-isis/>.

\[^12]: "St. Louis Public Library Recovers from Ransomware Attack." Threatpost. Accessed December 20, 2017. <https://threatpost.com/st-louis-public-library-recovers-from-ransomware-attack/123297/>.

\[^13]: For organizations who are interested in learning more about threat modeling, the Electronic Frontier Foundation has an introductory guide on the topic: <https://ssd.eff.org/en/module/assessing-your-risks>.

\[^14]: "The Verizon 2018 Data Breach Investigations Report" Verizon Enterprise Solutions, accessed February 1, 2019, <https://enterprise.verizon.com/resources/reports/dbir/>.


# Section 2: Common Cybersecurity Controls

*Please Note: Cybersecurity is a rapidly evolving field. This document was last updated on February 2, 2019. Some of the technical guidance within this document may change, and some of the risks defined may increase or decrease in their potential likelihood or impact.*

Improving cybersecurity in any organization often requires moving from ad-hoc responses to intentional planning. Many of the technical steps that an organization can take to improve its cybersecurity posture are relatively simple – some can even be automated for an entire organization with the click of a button. But making any type of organization-wide change often requires a cultural change as well. Creating an organizational policy outlining cybersecurity expectations for staff can help usher in this cultural change. The active participation of staff is critical in ensuring that changes stick.

This section will provide a series of technical controls and best practices a LRO can use to mitigate common cybersecurity issues, such as the three common threat areas described previously. A control is a tool, technique, or policy that makes hackers work harder, or makes a cybersecurity risk less likely to materialize.

**No control is 100% effective, and no system can ever be 100% secure. The controls described in this document may age over time, and in some cases may become obsolete.**

This section will briefly describe a control, then provide an overview of the time and complexity required for implementation. Each control includes a "Baseline" and "Baseline +" policy recommendation, where "Baseline+" requires a deeper level of staff engagement. These are not black and white distinctions, but are meant to illustrate how organizations can require different levels of adherence to specific practices.

LROs can use Appendix A to design a policy for these controls that is appropriate for their organization. Cybersecurity policies are a place for an organization to document expectations for its staff. These policies can also dictate certain technical requirements (e.g. "all employees must enable two-factor authentication for email accounts" or "employees may not email HR files to personal email accounts"). Appendix A of this document provides a basic template for such a policy, with suggestions for how to tailor the language to your own organization.

Not all security technologies are appropriate for all contexts, but the controls that follow are widely accepted as low-effort and high-impact solutions useful for most types of organizations. Given that LROs are not likely to be targeted by sophisticated or highly-motivated attackers (such as governments), these mostly context-agnostic controls should help to increase the security of an LRO's data and systems.

Appendix B provides additional information and links to further guidance on how to implement controls and select the systems and accounts requiring protection.

> #### How to Use This Guide
>
> 1. **Read** through the controls (in Section 2) and best practices (in Section 3) and understand what types of risks they mitigate. Section 2 controls are generally more technical, while the best practices in Section 3 are more generally designed to serve as a template for policy language for specific practices your organization may need to follow (i.e. travel policy or incident response).
> 2. **Select** the level of controls appropriate for your organization, and use those controls and best practices described in Section 3 to build your security policy. Appendix A can help walk you through considerations for each control, and help you identify if Baseline or Baseline+ measures are correct for your organization.
> 3. **Implement** security controls within your organization based upon your new security policy. Appendix B offers additional guidance on how to implement each of the controls.
>
> You can jump between the control descriptions in Section 2, the policy assistance in Appendix A, and the implementation guidance in Appendix B by using the links below each headline.

#### Strong Authentication

Set policy for this control here.

Additional implementation guidance can be found here.

| **Baseline:** Require multi-factor authentication for all organization-managed accounts. Turn on login alerts where offered.                                               |                                                 |                                            |
| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------- | ------------------------------------------ |
| **What time and technical sophistication is required to set up this control?**                                                                                             | **Who enables this control?**                   | **What risks does this control mitigate?** |
| <p>Low Sophistication</p><p>Less than 1 hour</p>                                                                                                                           | System administrators and individuals set it up | Phishing/Account Takeovers                 |
| **Baseline +:** Require multi-factor authentication for all organization-managed accounts. Require the use of password managers. Turn on account monitoring where offered. |                                                 |                                            |
| <p>Moderate Sophistication</p><p>Less than 1 day</p>                                                                                                                       | System administrators and individuals set it up | Phishing/Account Takeovers                 |

> **NOTE:** As a general rule, **do not** recycle the same password across multiple accounts. When choosing a password, pick something unique, and make it **long**. You should focus more on length than on adding in hard-to-remember characters or complex upper/lower case combinations. The use of a "passphrase" - a string of at least 4 unrelated words - instead of a password is encouraged.

**Multi-factor Authentication**

Multi-factor authentication (MFA) is a tool that offers additional security online accounts by requiring an extra layer of user verification. When MFA is enabled for an account, a user must not only enter a username and password, but they must also verify additional "factors" – like a code texted to their phone – that prove they are the true owner of the account. When accounts have MFA enabled, attackers who attempt to log in using stolen usernames and passwords will have a much harder time succeeding.

LROs should encourage employees to enable MFA on as many accounts as possible, but should mandate the use of MFA on critical accounts like email, data storage systems storing HR files, and financial accounts. Depending on the platform, administrators of centrally managed accounts (like G Suite) can flip a technical switch that forces all users to enable MFA. This technical solution can help LROs ensure staff use MFA, rather than hoping that staff will follow written policy. LROs can also require MFA when staff log into organization-owned computers, a policy that lowers the risk of a security incident in the event of loss or theft of devices.

MFA "factors" come in many forms, but the three most common types are SMS-based, application-based, and physical tokens. While there are substantial differences between these three methods, each requires a different level of effort to set up and maintain. In choosing an MFA method, it is important to consider the needs and constraints of your organization. For example, while token-based MFA is the most secure method, your organization may not have the budget to purchase security keys, and so enabling SMS-based MFA will be a more realistic fit, and will still be a more secure option than not enabling any form of MFA. A security control that is not (or cannot be) used consistently is not a good security control.

Below you will find a brief description of each of these MFA methods:

* **SMS:** After entering their username and password, a user will receive a prompt to verify a code (usually between 6-8 digits) sent via SMS to their mobile device. It is important to note this method is widely considered to be less secure than other methods (attackers have increasingly found ways to intercept text messages containing these verification codes). As such, SMS-based MFA is slowly being phased out. Nevertheless, SMS-based MFA is still better than no MFA at all, so LROs should absolutely enable it if it is the only option available for a service.
* **Authenticator App:** Companies like Google, Microsoft, Duo, and others offer free applications that generate a one-time, time sensitive code on your phone to serve as a "second factor" for individual user accounts. After a user enters their username and password, they will be prompted to enter a code generated by the app of their choosing. Authenticator apps are easy to set up, and can be quickly configured to work with many common web services. Apps have many advantages over SMS as an MFA method, but one of the most important is that the app will continue to generate codes even when the device is offline or out of cell range. This means apps are a particularly good option for LROs with poor cellular connection or with staff that travels internationally.
* **Token:** Physical tokens are the most secure form of MFA. They generally consist of small pieces of hardware that plug directly into a computer (or connect by Bluetooth), and they can be carried around on a keychain. Tokens can be more complicated to set up, but once configured, they eliminate the need to enter additional codes following a username and password combination, since connecting the token to your computer automatically generates a long and complex code. Unlike MFA and authenticator apps, tokens do come with a cost (each token runs between $15-50), but if you can afford it, the investment is worth the security payoff.

A list of common websites with MFA and links to instructions on how to enable it can be found here: <https://twofactorauth.org/>.

**Organizations should note that in the event of a lost second factor (like your phone or hardware token), account recovery becomes much more challenging with MFA enabled. Your staff may need to reset their account credentials by going to your IT staff, or through the help staff of a specific service.**

**Password Managers**

It is really difficult to create strong passwords, and even more difficult to remember them. For this reason, organizations should encourage (or require) employees to use password manager software like [LastPass, especially in cases where a service does not offer MFA.](https://www.lastpass.com/) Password managers help users generate long, random passwords and then stores them for users across devices. Attackers may still get ahold of these passwords through phishing or other means, but password managers make it much harder for attackers to guess or "brute force" a password (using a computer algorithm to make many guesses in a short period of time) since the software generates and remembers a strong, unique password on the user's behalf. Password managers can (and should!) be used in tandem with MFA, Moreover, many offer "enterprise" versions (for a small fee) that allow organizations to set use policies and even enable users to safely exchange passwords for shared accounts. While MFA provides a greater degree of security for an individual account, password managers significantly diminish the risk that one compromised account will lead to other compromised accounts due to recycled passwords.

**Account Monitoring**

Many common services offer suspicious login alerts, usually in the form of a push notification or an email that lets users know when someone has tried to access their account from a new device or location. Individuals can manually turn on these alerts or organizations can set technical policies for organization-managed accounts that require these alerts by default. In the event of an account compromise, these login alerts can substantially minimize the time an attacker has unauthorized access to an account by prompting a user to change their password and lock out the attacker.

> **Learn How to Spot a Phishing Email** MFA can help prevent attackers from accessing an account even when they have a user's account credentials. But, in cases where MFA is not enabled or not available, a username and password is all the attacker needs to break in. One of the most common ways attackers get their hands on user credentials is via phishing emails. Learning how to spot a phish is the best defense against losing control of accounts. The Electronic Frontier Foundation has a guide on how to spot a phishing email or scam here: <https://ssd.eff.org/en/module/how-avoid-phishing-attacks>
>
> In general, when you receive an email, do not click on links or open files you do not recognize, even if it came from a trusted source. If you're unsure about the origin of a link or document, it is usually worth a quick call or message (through a channel other than email) to the sender. It only takes a minute, and can save hours of headache in the case that your account does become compromised in some way.

#### Automatic Updates and Software Licenses

Set policy for this control here.

Additional implementation guidance can be found here.

| **Baseline:** Force automatic updates for all operating systems, productivity software, and web browsers, and require other software updates to be installed as quickly as possible. Ensure all software licenses are renewed in a timely fashion. |                                                 |                                            |
| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------- | ------------------------------------------ |
| **What time and technical sophistication is required to set up this control?**                                                                                                                                                                     | **Who enables this control?**                   | **What risks does this control mitigate?** |
| <p>Low Sophistication</p><p>Less than 1 hour</p>                                                                                                                                                                                                   | Individuals and system administrators set it up | Malware                                    |
| **Baseline +:** Force automatic updates for all operating systems, productivity software, and web browsers, and require other software updates to be installed as quickly as possible. Auto-renew all critical software licenses.                  |                                                 |                                            |
| <p>Moderate Sophistication</p><p>Ongoing</p>                                                                                                                                                                                                       | System administrators set it up                 | Malware                                    |

Enabling automatic updates is a simple and powerful cybersecurity control. While some larger organizations with more robust IT infrastructures may need to carefully consider this control (sometimes updates may interfere with the function of custom-built information systems), most LROs should enable automatic updates. There is a small chance an update might create problems for a system – particularly older computers or devices. However, problems with updates are often patched quickly. Out-of-date software is the primary way attackers can take over devices, steal or delete data, or otherwise interrupt systems, websites, and devices. This is because as vulnerabilities in various pieces of software are found, companies issue updates (or "patches") to fix those security flaws. Software that has not been updated retains those security flaws, and becomes increasingly vulnerable as attackers build malicious software that takes advantage of those known vulnerabilities.

Most software now defaults to enabling automatic updates. An organization's security policy should require this function on all operating systems, web browsers, email clients, productivity software (like Microsoft Office), instant messengers, or other commonly-used programs. This includes updates for mobile device software.

Some LROs may use expired software licenses to save money. Without a valid license, software is often not eligible for updates, exposing the organization to the risks described above. While software licenses can be expensive, many non-profits are eligible for free or reduced-costs software. Organizations like TechSoup (<http://www.techsoup.org/>) are an easy source of reduced-price software for eligible non-profits. Popular software and services suites like [Microsoft Office](https://products.office.com/en-us/nonprofit/office-365-nonprofit-plans-and-pricing?tab=1), [Salesforce](http://www.salesforce.org/nonprofit/), and [Google's G-Suite](https://www.google.com/nonprofits/) are available at greatly reduced prices for eligible non-profit organizations.

> **A Note on Antivirus Software** Organizations may choose to purchase antivirus software, but most major operating systems build in much of the protection LROs need to prevent malware infections. At a bare minimum, your organization should enable either Windows Defender or Apple's Gatekeeper – the default security services on both major operating systems. These services will harden most laptops and desktops against common threats.
>
> * How to enable Windows Defender: <https://support.microsoft.com/en-us/help/17464/windows-defender-help-protect-computer>
> * How to enable Gatekeeper on OSX: <https://support.apple.com/en-us/HT202491>
>
> It is critical to allow these services to run their automatic updates. Without the latest information, these services cannot protect your device against new forms of malicious software.

#### The Cloud

Set policy for this control here.

Additional implementation guidance can be found here.

| **Baseline:** Migrate organizational email to a cloud-based provider                                            |                               |                                                        |
| --------------------------------------------------------------------------------------------------------------- | ----------------------------- | ------------------------------------------------------ |
| **What time and technical sophistication is required to set up this control?**                                  | **Who enables this control?** | **What risks does this control mitigate?**             |
| <p>Moderate Sophistication</p><p>Variable time – days or weeks</p>                                              | Organizations set it up       | Malware, Phishing, Web-Based Attacks, Data Theft, etc. |
| **Baseline +:** Migrate organizational email, data storage, and productivity software to a cloud-based provider |                               |                                                        |
| <p>Moderate Sophistication</p><p>Variable time – weeks</p>                                                      | Organizations set it up       | Malware, Phishing, Web-Based Attacks, Data Theft, etc. |

Building and maintaining technical resources for your organization requires a large investment in time, money, and energy. Even managing a "simple" service like an email server can be very complicated, and keeping any of these systems up to date and secure is often a task beyond the capabilities of many LROs. It is widely recognized that moving to cloud-based technologies is a good way to offload many of the more difficult and resource intensive tasks related to managing these services, in turn allowing an organization's employees to focus on their mission priorities. Cloud service providers like Google, Amazon, Microsoft, and Salesforce employ some of the best security teams in the world, and are constantly improving the security of their services. They also provide secure backups of data, which means that in the event of a breach or another data loss event, a previous version of that data is still available. Most IT needs of an LRO, including web hosting, email, productivity tools, and storage, can be migrated to cloud-based services. Nevertheless, these services can be expensive. Thankfully many cloud service providers offer free or discounted services for nonprofits and other public-interest organizations. Some examples of those services include:

* **Productivity Suites and Email:**
  * <https://products.office.com/en-us/nonprofit/office-365-nonprofit-plans-and-pricing?tab=1>
  * <https://www.google.com/nonprofits/>
* **Web Hosting:**
  * <https://help.dreamhost.com/hc/en-us/articles/215769478-Non-profit-discount>
* **Contact/Customer Relationship Management:**
  * <http://www.salesforce.org/nonprofit/>
* **Web Services:**
  * <https://aws.amazon.com/government-education/nonprofits/>

In the event that moving services to the cloud is impractical, an organization's leadership should focus instead on ensuring any local storage, mail, or other servers are running up-to-date software and are configured appropriately. It is likely that ensuring this will require the services of an external consultant or internal IT staff.

#### HTTPS

Set policy for this control here.

Additional implementation guidance can be found here.

| **Baseline:** Ensure all organization-owned websites use HTTPS                 |                                                          |                                                                |
| ------------------------------------------------------------------------------ | -------------------------------------------------------- | -------------------------------------------------------------- |
| **What time and technical sophistication is required to set up this control?** | **Who enables this control?**                            | **What risks does this control mitigate?**                     |
| <p>High Sophistication</p><p>Days</p>                                          | Set up by the site service provider or web administrator | Web-based attacks on visitors, changing information in transit |

HTTPS is a protocol (or set of rules) that encrypts the information flowing between a browser (like Chrome or Firefox) and a website, giving visitors to that website an added layer of protections. It is often represented by a lock icon or the word "Secure" in a browser's URL bar. HTTPS ensures traffic is encrypted (confidential) and authenticated (you can be confident that you are speaking to the real entity and not a malicious actor spoofing it). Starting July 2018, the popular Google Chrome browser started marking all websites without HTTPS as "Not Secure," which it formally announced on its Chrome blog.\[^15] Other major browsers are also making design interface changes to flag non-HTTPS sites as insecure.\[^16]

While maintaining a secure connection between a website and its visitors may seem obvious, it is something many organizations overlook. The vast majority of sites on the internet still do not offer HTTPS connections. Failing to offer an HTTPS connection to visitors of your website puts them at risk of attackers interfering with their connection. For example, when a visitor to your website enters sensitive information such as a credit card number or account password, without the encryption that HTTPS offers, a malicious actor may gain access to this unencrypted information.

Configuring HTTPS for a website can be a complicated task, but thankfully, many website hosting services – like Wordpress or Squarespace will configure it for you at no additional cost. However, if an organization hosts its own website, the web administrator will need to enable HTTPS.

HTTPS is the only control that does not have a Baseline + option because it is considered absolutely necessary for any organization that hosts a website. Organizations should not only provide visitors with a secure connection to their website(s), but should also avoid compromising the trust of their visitors, who will likely see a "Not Secure" warning in the URL bar so long as HTTPS is not enabled.

#### Data Security

Set policy for this control here.

Additional implementation guidance can be found here.

| **Baseline:** Enable full-disk encryption on servers, cell phones, tablets, laptops, and desktops with access to critical or sensitive information.                                                                                                                                                                                                                                                                                    |                               |                                            |
| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------- | ------------------------------------------ |
| **What time and technical sophistication is required to set up this control?**                                                                                                                                                                                                                                                                                                                                                         | **Who enables this control?** | **What risks does this control mitigate?** |
| <p>Medium Sophistication</p><p>Hours or days</p>                                                                                                                                                                                                                                                                                                                                                                                       | Individuals or Organizations  | Data theft and loss                        |
| **Baseline +:** Enable full-disk encryption on all servers, cell phones, tablets, laptops, and desktops with access to organization resources. Regularly review permissions on cloud-based storage accounts to ensure access controls are appropriately granted and MFA is enabled. Consider adopting and implementing a device management system (learn more in the [fleet management](broken://pages/eHrlmtEtpwb7HhfxSow3) section). |                               |                                            |
| <p>Medium Sophistication</p><p>Weeks</p>                                                                                                                                                                                                                                                                                                                                                                                               | Individuals or Organizations  | Data theft and loss                        |

Data security is a difficult problem, and a wide variety of cybersecurity controls can help to manage the potential risks of lost or stolen data. The two controls described in this document are the most common, and should protect LROs in the case of accidental device loss or data theft. However, the generation, collection, and processing of data can create many risks for an organization – particularly when the data collected contains information about individuals and their behavior. Retaining sensitive data of this nature may move an organization out of the category of "low risk" into a higher category of risk.

**Encryption**

> ***Note: Encrypting your data provides an important layer of security, but it also runs the risk of data lock-out. It is crucial that you store your encryption key(s) in a safe place, and that you create a back-up plan in the case that you lose a key. Locking yourself out can be costly and may temporarily interrupt the operation of your organization.***

Encryption conceals data on a device from any user without the "key" to unlock it. That key can come in the form of a password or an MFA token. Many applications rely on encryption to increase the security of messages they send or data they store. Most cloud-based email and storage services encrypt data they store by default. For LROs, encryption can be useful for protecting sensitive data or for securing devices in the event of theft or loss.

* *Full-disk encryption* encrypts all information on a device. When an individual logs into that device, the data is decrypted. But, without the appropriate login, the data will be inaccessible to most attackers. Note that some older devices may run more slowly with full-disk encryption enabled. Full-disk encryption is generally favorable to file-based encryption. Unlike file-based encryption, which requires manual encryption of individual files, full-disk encryption ensures that all files on a device are consistently encrypted, meaning there is no risk an important document or file will be left unsecured. Organizations can enable full-disk encryption on Windows and OSX using BitLocker and FileVault, respectively.
* *File-based encryption* allows an organization or individual to encrypt a specific file or folder to add additional security to that item. This form of encryption may be particularly useful for protecting sensitive files like HR documents, financial statements, or strategic plans. However, keep in mind that sharing encrypted files with others can pose challenges because the recipient of the file will need a password or key to decrypt the file.. Nevertheless, when transferring sensitive files between devices, it is highly recommended to transfer them in an encrypted state. Encrypted files can sometimes create challenges for an organization and its partners. To relieve some of these challenges, organizations can migrate to cloud-based storage for sensitive materials, where files are encrypted by default and access to those files can be easily customized.
* *End-to-end encryption* ("E2E") applies specifically to digital communications, and ensures that only the recipients and senders of messages can see and read those messages. For anyone else (including owners of messaging platforms and potential attackers wishing to intercept messages), the data will appear encrypted. Some of the most common E2E messaging apps are Signal, Whatsapp, and iMessage. Note that email is not encrypted by default. While communications applications encrypted with end-to-end encryption are excellent for securing communications about sensitive topics, they can create problems for some organizational processes (like discovery in legal proceedings) that require third-party access to previous communications.

**Access Management**

Merely encrypting data is not always enough to keep it "secure." While encrypted devices are generally safe from the prying eyes of outsiders, there are plenty of internal risks posed by data sharing within organizations or between partners. For example, it would be disastrous if all employees were able to view each other's HR files. Similarly, a strategic planning document shared with a close partner organization could be passed along inappropriately to a third party. Access management can help to address these internal risks. Access management is the process of reviewing who within an organization has access to different resources, and setting clear "permissions" (or technical abilities) that restrict or grant access for each employee to the appropriate resources. Access management is particularly important for organizations with cloud-based storage, since cloud services make it very easy to share documents inside and outside of an organization. Many cloud services provide administrators with easy ways to manage access across their organizations' documents. However, fine-grained management of access permissions can take time - it is important to designate ownership of this task to specific individuals in your organization to ensure access controls are regularly refreshed.

#### Notes

\[^15]: Dino Dai Zovi, a cybersecurity researcher, has said that "If the cost to attack is less than the value of your information to the attacker, you will be attacked." To learn more about the basic economic logic of online attackers, you can view his presentation here: <https://trailofbits.files.wordpress.com/2011/08/attacker-math.pdf>

\[^16]: "2018 DBIR."


# Section 3: Additional Cybersecurity Best Practices

*Please Note: Cybersecurity is a rapidly evolving field. This document was last updated on February 2, 2019. Some of the technical guidance within this document may change, and some of the risks defined may increase or decrease in their potential likelihood or impact.*

Beyond the technical controls listed above, additional organizational expectations for cybersecurity can be documented as policies. This section reviews key areas of policy that your organization should establish in order to facilitate secure day-to-day practices. These best practices do not have Baseline or Baseline+ categories, because they are more generally about setting ground rules for behavior instead of particular technical configurations. The best practices in this section are designed as templates your organization can further customize based on your needs.

### "Fleet" Management

In a large organization, merely keeping track of the broad array of devices your employees use can be a huge challenge. Even in small organizations, keeping track of phones, laptops, and tablets can be a time-consuming exercise, particularly when employee turnover is high and your organization must regularly purchase new devices and retire old ones.

At a minimum, an organization should keep track of the following information:

1. What devices does the organization own?
2. Who is in possession/responsible for that device?
3. Are automatic updates turned on for that device?
4. Are the licenses for the device's operating system and software up to date?

This information should be collected and refreshed at regular intervals – at a minimum once a year, but semi-annually is best. As staff depart or join, or devices are upgraded/deprecated, the running list of devices should be updated accordingly.

Each organization should also have a policy for device turnover before a device is handed off to a new employee. At a minimum, this should include the following:

1. Before an employee departs or takes possession of a new device, they must return the old device to the organization.
2. Employees should back up important data on their devices to a shared or otherwise accessible drive or cloud storage, and should inform relevant staff of the data's location.
3. The organization should completely wipe the device and have a fresh system install of its operating system and important software before giving it to an employee.
4. If the device owner is leaving the organization, permissions (such as passwords to sensitive accounts, access to shared documents) should be revoked for the user of the device.

> **A Note on Device Management Systems**
>
> There are some device management systems on the market that help organizations centrally manage their devices. These systems require time and some practice to use, but they can increase an organization's visibility into what devices are part of their network, and help alert managers to potential security issues. While these systems can be very helpful, they are usually unnecessary for organizations with fewer than 25 employees. Organizations should have dedicated IT staff in charge of operating these systems. Some common ways that device management systems help organizations manage their security include:
>
> * enforcing organizational security settings such as mandatory strong passwords and forced screen lockout after a certain amount of time;
> * pushing out email profile configuration to the devices;
> * executing remote wipe and remote lock for managed devices; and
> * generating reports of device inventories on the network.
>
> Different device management solutions have different strengths and weaknesses. There are two key types of solutions:
>
> **Server management systems:** These systems can comprehensively manage intranet servers. Some can also manage network appliances (servers, standalone firewalls, etc.). However, operating such systems usually requires strong IT proficiency and infrastructure to execute. Example server management systems include:
>
> * [Microsoft System Center Operations Manager](https://docs.microsoft.com/en-us/system-center/scom/deploy-overview?view=sc-om-1807)
> * [Splunk](https://www.splunk.com/)
>
> **Mobile device management systems (including client computer management):** These systems can manage most modern mobile devices and client computers. The user interface is friendly and easier to use compared to server management systems. However, they require more time and attention than server management systems. Examples include:
>
> * [VMWare AirWatch](https://www.air-watch.com/)
> * [Microsoft Intune](https://www.microsoft.com/en-us/cloud-platform/microsoft-intune)
> * [MobileIron](https://www.mobileiron.com/en/modern-security-modern-work)

### Travel Policy

Travelling – whether domestically or abroad – can create unique risks for an organization's cybersecurity. Different regions have different cybersecurity laws and expectations, and different contexts can create new risks an organization might not ordinarily encounter. There are few hard and fast rules with regards to travel policies, but there are a few basic questions that all organizations should ask themselves. A strong travel policy for your organization will address the following:

1. *Should employees bring organization-owned devices on work or personal travel?*

The most likely cybersecurity risk while travelling is an increased chance of device loss or theft. Therefore, at a basic level, employees should only travel with devices that utilize strong full-disk or device-level encryption so that in the event of loss, an attacker will have a difficult time accessing the information.

Some organizations provide staff with special "travel" devices that have limited capabilities. While this can limit an organization's exposure to risk, configuring devices for travel and wiping them after travel can be time consuming. An organization should always consider what work the employee will need to do while travelling: will they need access to sensitive data, and is that data stored on their device? How regularly will they need to email and communicate with their team? In general, organizations should not travel with devices that hold sensitive information, as loss or theft of these devices could have an outsized impact on an organization. If an employee has limited needs while traveling, like basic access to email, organizations can minimize risk by limiting the number of devices an employee can take with them (for example, allowing them to take only a phone, as opposed to a phone and a laptop).

Below is a summary of policies to help employees keep their devices safe while travelling:

* Only travel with devices that use full-disk encryption.
* Never travel with devices that store sensitive information (such as HR files, financial statements, strategic documents, or information about people or their behavior).
* Keep devices with you at all times (do not leave them unattended or unsecured in hotel rooms).
* Keep devices locked or off when not using them.

1. *How should employees connect to the internet while travelling?*

Another common risk while travelling is an insecure connection to the internet. This may include connecting to untrustworthy Wi-Fi or accessing work resources through a public computer in a library or café. Unsafe connections can allow hackers to spy on your connection, steal sensitive data, or hijack important accounts. Policies to help employees avoid unsafe connections may include:

* Ensure all devices have up-to-date software before travel.
* Do not connect to the internet in places that are unknown or untrustworthy. Only use connections provided by partner organizations or large chain hotels and cafes (even these connections can be insecure, but they are less likely to be compromised).
* Avoid open/unsecured Wi-Fi networks (e.g. networks not protected by passwords).
* Never accesswork resources on a computer not owned by your organization, such as a public computer in an internet cafe.
* When not using devices, turn off Wi-Fi and Bluetooth radios.

The US Department of Homeland Security has published a guide that offers some specific guidelines for protecting your devices and online accounts while travelling: <https://www.dhs.gov/sites/default/files/publications/Cybersecurity%20While%20Traveling_7.pdf>

### Incident Response

Given that no system or device is ever 100% secure, it is inevitable that something bad will happen at some point. People frequently lose devices and experience compromise of online accounts or theft of bank account information. Having a plan for how your organization will deal with an incident can make a significant difference in limiting its impact. This section reviews key steps LROs should take in response to common cybersecurity incidents.

*If a device is lost or stolen:*

*\*Note: if the stolen device was used as an MFA method to access your accounts, you may need to contact your account providers to recover your accounts.*

1. If an employee loses a device, they should report that loss to their supervisor immediately. If the device potentially stores or has access to personally identifiable information, the supervisor should alert the general counsel immediately.
2. It may be possible to locate a lost device. Many common devices have services that can show owners the last known location of their device, and even help them remotely wipe or deactivate the device.
   * Apple
     * Find my Mac: <https://support.apple.com/en-us/HT204756>
     * Find my Phone: <https://support.apple.com/en-us/HT201472>
   * Android: <https://myaccount.google.com/find-your-phone>
   * Microsoft: <https://support.microsoft.com/en-us/help/11579/microsoft-account-find-and-lock-lost-windows-device>
3. The supervisor and employee should then catalog a list of information that was stored on that device, even if it is encrypted. Any of that information might be sensitive, and some may have regulatory consequences if lost. That list should include data like:
   * Documents and spreadsheets relevant to their projects
   * Usernames and passwords to important accounts saved in their browser
   * Any information or documents stored in their email or messaging applications
   * Strategic planning document
   * Financial documents
   * HR or personnel documents
4. Assume all of the information on the device is compromised. If the information is sensitive or potentially contains personally identifiable information, send the list of information to the organization's general counsel or legal representative. Discuss with them any potential regulatory requirements or any other issues of liability regarding the loss of that data. Consult with an attorney about reporting the loss or theft to the police.
5. Change the passwords for any accounts that may have been accessible through the lost device (e.g. through passwords saved on the device). Enable MFA on any accounts that did not already have it enabled. Some accounts may allow users to close sessions that are active, forcing anyone with access to the account to log in again. Here is how to view account activity or log out of active sessions on common services:
   * Facebook: <https://www.facebook.com/help/211990645501187?helpref=faq_content>
   * Google: <https://support.google.com/mail/answer/8154?co=GENIE.Platform%3DDesktop&hl=en>
   * Microsoft: <https://account.live.com/activity>
   * Apple: <https://support.apple.com/en-us/HT205064>
   * Twitter: <https://help.twitter.com/en/safety-and-security/twitter-account-compromised>

*If an account is compromised:*

1. If an employee loses control of an account or is concerned their username and password have been compromised, they should report that loss to their supervisor immediately. The supervisor should alert the organization's general counsel.
2. Attempt to reestablish control of the account immediately and turn on MFA. Often the easiest way to do this is to initiate the "Forgot my Password" process on a website or service. By setting a new password and enabling MFA, most attackers will lose access to your account. Some accounts may allow users to close sessions that are active, forcing anyone with access to the account to log in again. Here is how to view account activity or log out of active sessions on common services:

* Facebook: <https://www.facebook.com/help/211990645501187?helpref=faq_content>
* Google: <https://support.google.com/mail/answer/8154?co=GENIE.Platform%3DDesktop&hl=en>
* Microsoft: <https://account.live.com/activity>
* Apple: <https://support.apple.com/en-us/HT205064>
* Twitter: <https://help.twitter.com/en/safety-and-security/twitter-account-compromised>

1. Examine if any actions have been taken with the account. Review account activity: Have any public posts been made? Have any messages been sent?
2. The supervisor and employee should then catalog a list of information that was stored on that account, even if it is encrypted. Any of that information might be sensitive, and some may have regulatory consequences if lost. That list could include data like:
   * Documents and spreadsheets relevant to their projects
   * Any information or documents stored in email or messaging applications
   * Strategic planning document
   * Financial documents
   * HR or personnel documents
3. Assume all of the information on the device is compromised. If the information is sensitive or potentially contains personally identifiable information, send the list of information to the organization's general counsel or legal representative. Discuss with them potential regulatory requirements or any other issues of liability regarding the loss of that data. Consult with an attorney about reporting the loss or theft to the police.
4. Consider if any other accounts use the same username or password, or could be otherwise accessed as a result of this account being compromised. Change the passwords of any accounts with shared or similar login information and enable MFA.

*If a device is infected with malware or ransomware:*

It is not always easy to tell if a device is infected, but sometimes it can become rapidly obvious. If a device is acting strangely (suddenly very slow, randomly turns off or restarts, or displays any suspicious messages), do not panic. Many infections are easily cleaned.

1. Disconnect the device from the internet. Alert a supervisor.
2. Run a scan with your computer's AV software
   * Windows Defender: <https://support.microsoft.com/en-us/help/4026780/windows-10-scan-an-item-with-windows-defender-antivirus>
   * Norton AntiVirus: <https://support.norton.com/sp/en/us/home/current/solutions/v13139256_ns_retail_en_us>
   * McAfee AntiVirus: <https://service.mcafee.com/webcenter/portal/cp/home/articleview?articleId=TS101105>
3. If the device cannot be recovered or contains sensitive information, document the information as described above as if the device had been lost or stolen, and contact your General Counsel.
4. If the device is not working properly, or you are unable to run AntiVirus software (as would be the case with Ransomware), attempt to turn off the computer. At this stage, you may need to consult a professional to restore, or refresh your operating system.
5. If the malware is removed, update all software. Consider changing all important passwords that may have been saved on that computer and enable MFA on any accounts that may have been compromised.

*In the event of a data breach:*

1. In the event an organization loses access to sensitive information, they should consult their general counsel or legal representative immediately. There may be regulatory requirements to report that breach to authorities, or to notify individuals whose data may be affected.
2. Do not ignore the breach. See above sections for documenting and recovering any compromised devices or accounts.
3. Do not attempt to delete information or destroy devices that have been compromised, or communications about the breach. Doing so may be seen by authorities or regulators as an attempt to conceal the breach.
4. Organizations should seek the advice of an attorney on how and when to contact the authorities. In the event of a serious breach, investigators may need to examine devices and systems for forensic evidence of the attack.

### Social Media Use

Every organization has a different level of comfort with social media. By and large, use of social media is a communications issue, but cybersecurity concerns can arise and organizations should take steps to get ahead of opportunistic attackers. When developing a set of norms for the use of social media, LROss should include expectations such as the following:

* Secure important [accounts with MFA](broken://pages/zVpFcXKpcgG57tdJ4cby) and avoid sharing passwords between users (if possible – not all social media services allow multiple users to manage one account).
* Employees should not click on links or attachments sent from unknown sources. If employees are unsure if they can trust a link, they should use a service such as [Norton SafeWeb](https://safeweb.norton.com/), [URLVoid](http://www.urlvoid.com/), or [ScanURL](http://scanurl.net/) to inspect the link for potential malicious activity – but these services cannot provide guarantees of security. Suspicious documents or PDFs should always be opened in a web-based service like Google Drive, instead of being downloaded and opened directly on an employee's computer. This will prevent any malicious code embedded in the document from running on the employee's device.
* Do not engage with aggressive, abusive, or harassing accounts. Online trolls often seek simply to provoke an unflattering reaction from organizations that they can use to diminish its reputation. Managers of an organization's social media presence should familiarize themselves with the process of reporting malicious, abusive, or hateful comments – and should know how to use tools provided by social media services such as blocking or muting accounts. More information about how to counter harassment or abuse online can be found here:
  * HeartMob: <https://iheartmob.org/>
  * Facebook Safety Tips (specifically for journalists, but much of the advices is generally applicable): <https://www.facebook.com/facebookmedia/blog/safety-tips-for-journalists>
  * Twitter Safety Features: <https://about.twitter.com/en_us/safety/safety-tools.html>

### Payment Card Security

LROs may take donations via credit cards online. There are many legal requirements for processing payment cards, and the general counsel should be an organization's first stop for understanding the specific regulatory expectations applicable to their context. In general, organizations should avoid processing payments on their own. Many web services make this process easy – including PayPal, Square, and Venmo – by providing plugins or other website add-ons that give visitors a simple way to send donations or other payments to an organization.

**\_Low-risk organizations should avoid collecting and storing payment card information. Organizations may be required to maintain a record of donations or other transactions, but should always consult legal counsel about the level of detail required. \_**


# Appendices


# Appendix A: Building a Security Policy for Your Organization

*Please Note: Cybersecurity is a rapidly evolving field. This document was last updated on February 2, 2019. Some of the technical guidance within this document may change, and some of the risks defined may increase or decrease in their potential likelihood or impact.*

Security policies can serve many purposes for organizations. Some prefer these documents to be legal policies that establish clear responsibilities and liability. This section focuses on elements of security policies that can be used to plan for effective cybersecurity practice. But, if your organization wishes to utilize more legally-oriented language, the SANS Institute maintains a consensus-based collection of organizational cybersecurity policy language that your organization can use, free of charge: <https://www.sans.org/security-resources/policies>

Each section will include a template for writing an organizational cybersecurity policy to implement the controls described in Section 2. These fillable templates, in combination with the best practices described in Section 3, can serve as a baseline cybersecurity policy for an organization.

Each template can be expanded as needed – while there may not be enough fields in the examples to capture all of the devices, accounts, etc. in an organization, each policy, best practice, and control can be modified to fit the context of a specific organization. More guidance on how to select a policy and implement a control can be found in Appendix C.

### Strong Authentication

Read the description of this control here.

Additional implementation guidance can be found here.

**Policy Selection:**

* **Baseline:** Require multi-factor authentication for all organization-managed accounts. Turn on login alerts where offered.
* **Baseline +:** Require multi-factor authentication for all organization-managed accounts. Require the use of password managers. Turn on account monitoring where offered.
* **No Policy**

**Policy Details:** Person(s) responsible for implementing this policy:

(*Name*)

***

This individual is responsible for ensuring multifactor authentication is enabled on all critical accounts, and will serve as a resource for other staff who need assistance with MFA set up or recovery. This individual is also responsible for ensuring that backup MFA codes for organization-owned accounts are stored in a safe, secure place - such as an external USB drive in a locked cabinet.

What accounts are considered critical?

| Account          | MFA Forced? |
| ---------------- | :---------: |
| *(Account Name)* |  *(yes/no)* |
|                  |             |
|                  |             |

### Automatic Updates and Software Licenses

Read the description of this control here.

Additional implementation guidance can be found here.

**Policy Selection:**

* **Baseline:** Force automatic updates for all operating systems, productivity software, and web browsers, and require other software updates to be installed as quickly as possible. Ensure all software licenses are renewed in a timely fashion.
* **Baseline +:** Force automatic updates for all operating systems, productivity software, and web browsers, and require other software updates to be installed as quickly as possible. Auto-renew all critical software licenses.
* **No Policy**

**Policy Details:**

Person(s) responsible for implementing this policy:

(*Name*)

***

This individual is responsible for ensuring automatic updates are turned on for all required software, and that software and services licenses are current. They will also serve as a resource for any staff having trouble updating their software.

What software is considered critical?

| Software or Operating System | Updates Forced? | Auto-Renew License? |
| ---------------------------- | --------------- | ------------------- |
| *(Software or OS Name)*      | *(yes/no)*      | *(yes/no)*          |
|                              |                 |                     |
|                              |                 |                     |
|                              |                 |                     |

### The Cloud

Read the description of this control here.

Additional implementation guidance can be found here.

**Policy Selection:**

* **Baseline:** Migrate organizational email to a cloud-based provider
* **Baseline +:** Migrate organizational email, data storage, and productivity software to a cloud-based provider
* **No Policy**

**Policy Details:**

Person(s) responsible for implementing this policy:

(*Name*)

***

This individual is responsible for leading the migration to any new cloud-based services - either migrating data themselves, or managing a contract with a third party to conduct that migration. They should become knowledgeable users of that service, so that any staff struggling with the transition can use them as a resource.

What services are considered critical?

| Software or Services         | Cloud-based? |
| ---------------------------- | :----------: |
| *(Software or Service Name)* |  *(yes/no)*  |
|                              |              |
|                              |              |

What services or software will your organization migrate to the cloud?

| Software or Services    | Persons or third party responsible for migration | Timeline for migration |
| ----------------------- | ------------------------------------------------ | ---------------------- |
| *(Software or OS Name)* | *(Staff/Contractor Name)*                        | *(Timeframe)*          |
|                         |                                                  |                        |
|                         |                                                  |                        |
|                         |                                                  |                        |

It is *highly* recommended you enable strong authentication for any cloud-based services important to your organization.

### HTTPS

Read the description of this control here.

Additional implementation guidance can be found here.

**Policy Selection:**

* \*\*Baseline: \*\*Ensure all organization-owned websites uses HTTPS
* **No Policy**

**Policy Details:**

Person(s) responsible for implementing this policy:

(*Name*)

***

This individual will be responsible for enabling HTTPS on any organization owned or supported sites - either themselves or by working with a third party contractor/servicer.

What sites does the organization own or support?

| Site URL                              | Site Administrator        | HTTPS enabled? | Timeline for enabling HTTPS? |
| ------------------------------------- | ------------------------- | -------------- | ---------------------------- |
| *([www.xyz.org](http://www.xyz.org))* | *(Staff/Contractor Name)* | *(yes/no)*     | *(Timeframe)*                |
|                                       |                           |                |                              |
|                                       |                           |                |                              |
|                                       |                           |                |                              |

### Data Security

Read the description of this control here.

Additional implementation guidance can be found here.

**Policy Selection:**

* **Baseline:** Enable full-disk encryption on servers, cell phones, tablets, laptops, and desktops with access to critical or sensitive information.
* **Baseline +:** Enable full-disk encryption on all servers, cell phones, tablets, laptops, and desktops with access to organization resources. Regularly review permissions on cloud-based storage accounts to ensure access controls are appropriately granted and MFA is enabled. Consider adopting and implementing a device management system (learn more in the fleet management section).
* **No Policy**

**Policy Details:**

Person(s) responsible for implementing this policy:

(*Name*)

***

This individual will be responsible for ensuring critical devices are encrypted and access management reviews are conducted. They should become knowledgeable about how to enable device encryption, as well as how to review the permissions of shared resources, so that any staff struggling with the transition can use them as a resource.

| *What devices do those staff members use to access critical or sensitive information? Those devices should have full disk encryption enabled.* |             |
| ---------------------------------------------------------------------------------------------------------------------------------------------- | ----------- |
| **Staff**                                                                                                                                      | **Devices** |
|                                                                                                                                                |             |
|                                                                                                                                                |             |
|                                                                                                                                                |             |

All staff who store data deemed sensitive or critical to the organization should keep it in an encrypted state on their devices. Any data that can be stored and accessed from a shared or cloud service should remain there, under strong account security. Any information downloaded should not be held on individual devices unless necessary. If there are questions about the necessity of on-device access to certain sensitive data, employees should contact the owner of that data type.

Employees who do not have a direct mission or business need should never access sensitive information. In particular, HR or personnel files should only be accessed with the explicit permission of the organization's HR team.

Employees responsible for working with relevant account owners to manage, revoke, or edit access to sensitive data. The individual responsible for this policy shall implement an annual or semi-annual process to revise account permissions to ensure these permissions are up-to-date and commensurate with staff's current responsibilities. Employees who work with that data regularly are expected to contribute to that review.

| *What services do those staff members use to store or share critical or sensitive information? Those services should be subject to a regular review of permissions.* |                                                                         |
| -------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------- |
| **Service**                                                                                                                                                          | **Interval for reviewing permissions (quarterly, semi-annual, annual)** |
|                                                                                                                                                                      |                                                                         |
|                                                                                                                                                                      |                                                                         |
|                                                                                                                                                                      |                                                                         |


# Appendix B: Implementation Guidance

*Please Note: Cybersecurity is a rapidly evolving field. This document was last updated on February 2, 2019. Some of the technical guidance within this document may change, and some of the risks defined may increase or decrease in their potential likelihood or impact.*

While many of the controls described in this guide are simple, that does not mean it is easy to decide where (or how strictly) to implement them in an organization. This section provides additional resources and guidance to help identify critical accounts, priority devices, and other information to help prioritize where an organization focuses its limited time and attention.

### Strong Authentication

Read the description of this control here.

Set policy for this control here.

The below chart is a basic way to determine which accounts should be considered "critical" to an organization. By rating the accounts and mapping them to the staff with access, organizations can determine which staff members need to prioritize enabling strong authentication.

| **Account Inventory**                                                                                                                                      |             |                                                                                                     |
| ---------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------- | --------------------------------------------------------------------------------------------------- |
| *What online accounts does your organization consider important to your mission? This could include email, social media, financial, online storage, etc.:* |             |                                                                                                     |
| **Account**                                                                                                                                                | **Purpose** | <p><strong>Impact on organization if access is lost</strong></p><p><em>(High, Medium, Low)</em></p> |
|                                                                                                                                                            |             |                                                                                                     |
|                                                                                                                                                            |             |                                                                                                     |
|                                                                                                                                                            |             |                                                                                                     |
| *What staff members have access to which account? Include if they "own" the account and are responsible for its activity.*                                 |             |                                                                                                     |
| **Account**                                                                                                                                                | **Staff**   | **MFA Enabled?**                                                                                    |
|                                                                                                                                                            |             |                                                                                                     |
|                                                                                                                                                            |             |                                                                                                     |
|                                                                                                                                                            |             |                                                                                                     |

### Automatic Updates and Software Licenses

Read the description of this control here.

Set policy for this control here.

#### Turning on Automatic Updates

*If an organization uses enterprise software that requires centralized deployment of patches and updates, an IT administrator should be in charge of patch management for critical software.*

Guides on how to enable automatic updates on common operating systems can be seen below:

* **Android Devices:** <https://support.google.com/googleplay/answer/113412?hl=en>
* **OSX Devices:** <https://support.apple.com/kb/PH25532?locale=en_US>
* **iOS Devices:** <https://support.apple.com/en-us/HT202180>
* **Windows 10:** <https://support.microsoft.com/en-us/help/3067639/how-to-get-an-update-through-windows-update>
  * \*\*Previous versions: \*\*<https://support.microsoft.com/en-us/help/3067639/how-to-get-an-update-through-windows-update>

#### Finding Affordable Software Licenses

Software is expensive. Cost is a major contributor to why many organizations fail to update their software. Organizations like [TechSoup](https://www.techsoup.org/) can help provide non-profits with affordable, discounted, or free software. But many cloud service providers offer free or discounted services for nonprofits and other public-interest organizations. Some examples of those services include:

* **Productivity Suites:**
  * <https://products.office.com/en-us/nonprofit/office-365-nonprofit-plans-and-pricing?tab=1>
  * <https://www.google.com/nonprofits/>
* **Web Services:**
  * <https://aws.amazon.com/government-education/nonprofits/>
* **Web Hosting:**
  * <https://help.dreamhost.com/hc/en-us/articles/215769478-Non-profit-discount>
* **Contact/Customer Relationship Management:**
  * <http://www.salesforce.org/nonprofit/>

### The Cloud

Read the description of this control here.

Set policy for this control here.

Moving data to cloud-based services can be a challenge. And, just as important, ensuring that old devices are cleaned of that data can also be difficult. This section outlines a number of important steps to take into account when migrating important data away from legacy devices. For some organizations, this is a process that can be run internally. For other organizations with a greater "sprawl" of data or devices, services exist to support migration to cloud-based services. TechSoup provides cloud migration consultation services for non-profits: <http://page.techsoup.org/cloud-services?cg=pc>

#### Migrating Files to Cloud-Based Storage

It is likely that data - both sensitive and insensitive - is currently spread across many personal devices. These files should now be consolidated in a single place. Cloud storage services, such as Google Drive or Office OneDrive, provide a simple way for employees to migrate files into a centralized location. Employees can log into a cloud storage service and upload any legacy files. This process is imperfect - it is very easy to miss files. Here a few common locations that individuals often miss when looking for legacy files on a device:

* **Downloads folders:** This applies to both mobile devices and laptops. Files downloaded onto devices for one-time viewing are often forgotten, making the downloads file a honeypot of potentially sensitive information. Employees should search through their downloads for documents that need to be archived in the cloud, and delete the entirety of their downloads folders when they have finished. For information on how to find common downloads directories, see below:
  * [Windows](https://support.microsoft.com/en-us/help/17436/windows-internet-explorer-download-files-from-web)
  * [OSX](https://support.apple.com/guide/mac-help/see-your-files-in-the-finder-mchlp2605/mac)
  * [Android](https://support.google.com/android/answer/2781972?hl=en)
  * [iOS](https://support.apple.com/en-us/HT206481)
* **Search:** Organizations can save documents in many locations, sometimes accidentally, sometimes on purpose. The result is that most organizations end up having a sprawl of folders across their "documents" library, their desktop, and everywhere in-between. While spending time searching through common directories for important documents is worthwhile, it is not always clear where to look. Using the search function in your operating system can be a powerful shortcut - but what should you search for? Depending on what type of work you do, there are likely only a few file types with which you regularly work - Microsoft Word, Excel, and Powerpoint are some of the most common. By searching for their extension name (or the .xyz at the end of the file type - such as .doc or docx for Word, or .xls or .xlsx for Excel), you can search your operating system for documents that are important to migrate. The searching process can also reveal folders you may have forgotten about that are hiding important files. Some common extensions you may want to search for include:
  * **Microsoft Word:** .doc, .docx, .odt
  * **Microsoft Excel:** .xls, .xlsx, .csv
  * **Microsoft Powerpoint:** .ppt, .pptx
  * **Adobe:** .pdf
  * **Apple Pages:** .pages
  * **Apple Numbers:** .number
  * **Apple Keynote:** .key, .keynote
  * An exhaustive list of other file formats and their associated applications can be found here: <https://en.wikipedia.org/wiki/List_of_file_formats>.
* **Temporary folders and other hidden locations:** Some operating systems will have "temp" folders for a number of applications, such as Office, that save in-progress documents. While it is possible to find these folders, they can often be hidden and rarely contain complete documents or files that you'll want to back up. The best way to ensure a device is clean of legacy files is to reinstall its operating system. Newer devices make this refresh easy - but many will ask if you'd like to keep an archive of the old files. This is fine, but make sure you remove that archive and store it somewhere safe - like on a USB drive not connected to the internet.

> **WARNING:** Resetting a device to factory settings or reinstalling its operating system will purge all data and applications from the device. Make sure any information you want to keep is backed up in the cloud or on an external drive before resetting your device.

Information on how to reset, refresh, or reinstall common operating systems can be found here:

* [Resetting Windows 10](https://support.microsoft.com/en-us/help/4026528/windows-reset-or-reinstall-windows-10)
* [How to refresh, reset, or reinstall older versions of Windows](https://support.microsoft.com/en-us/help/17085/windows-8-restore-refresh-reset-pc)
* [How to restore iOS device to factory settings](https://support.apple.com/en-us/HT201252)
* [How to wipe and reset macOS device](https://support.apple.com/en-us/HT204904)
* [How to restore factory settings on an Android device](https://support.google.com/android/answer/6088915?hl=en)

### HTTPS

Read the description of this control here.

Set policy for this control here.

For most websites, enabling HTTPS will not be a giant task - but it does require some baseline technical knowledge. Trying to enable HTTPS may be possible without any technical experience if you use a platform like Wordpress or Squarespace that does some of the work for you - but depending on your site's style and configuration, it can still be a challenge. It is advisable to rely on whoever administers or designed your site for support in enabling HTTPs. Some general information about how to turn on HTTPS can be found in this guide: <https://httpsiseasy.com/>.

Other guides to enabling HTTPS can be found here:

* **Let's Encrypt** is a free source of the certificates needed to offer HTTPS on your website. Their documentation is generally geared toward more technical users: <https://letsencrypt.org/>
* **Facebook** has provided a quick guide on how and why to enable HTTPs, with links to a number of additional resources: <https://developers.facebook.com/docs/facebook-login/web/enabling-https>

Additional information on how to enable HTTPS in common site hosting and design services can be found here:

* **Wordpress:** <https://make.wordpress.org/support/user-manual/web-publishing/https-for-wordpress/>
* **Squarespace:** <https://support.squarespace.com/hc/en-us/articles/205815898-Squarespace-and-SSL>

### Data Security

Read the description of this control here.

Set policy for this control here.

#### Data Inventory

Data security is a difficult task, and requires ongoing management and attention. However, basic measures to encrypt devices with access to sensitive information can go a long way for low-risk organizations. The below inventory is an example of how to identify which devices should be encrypted:

| **Data Inventory**                                                                                                                                                                                                                                       |              |
| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------ |
| *What data does your organization consider "sensitive" or to be essential to fulfilling its mission? This could include strategic plans, donor lists, financial records, HR records, etc. Where (what devices or systems) does that information reside?* |              |
| **Data Type**                                                                                                                                                                                                                                            | **Location** |
|                                                                                                                                                                                                                                                          |              |
|                                                                                                                                                                                                                                                          |              |
|                                                                                                                                                                                                                                                          |              |
| *What staff members regularly access or process that information? Include if they "own" that data type.*                                                                                                                                                 |              |
| **Data Type**                                                                                                                                                                                                                                            | **Staff**    |
|                                                                                                                                                                                                                                                          |              |
|                                                                                                                                                                                                                                                          |              |
|                                                                                                                                                                                                                                                          |              |
| *What devices do those staff members use to access critical or sensitive information? Those devices should have full disk encryption enabled.*                                                                                                           |              |
| **Staff**                                                                                                                                                                                                                                                | **Devices**  |
|                                                                                                                                                                                                                                                          |              |
|                                                                                                                                                                                                                                                          |              |

#### Access Management in the Cloud

Access management is an ongoing task, but many cloud-based storage services provide a high-level view of document permissions in use across the organization. Larger organizations may need to deploy more robust solutions to manage access to organization resources, but these two guides are a good place to start for LROs using common cloud storage services:

* **Microsoft One Drive:** <https://support.office.com/en-us/article/stop-sharing-onedrive-files-or-folders-or-change-permissions-0a36470f-d7fe-40a0-bd74-0ac6c1e13323>
* **Google Drive:** <https://support.google.com/a/answer/60781?hl=en>

Not all documents or directories warrant constant monitoring for access permissions. However, a few key considerations that may help organizations identify documents and directories likely to need their permissions reviewed:

* **Documents of critical importance to organizational operations:** Strategic plans, budgets, funding agreements or plans.
* **Documents containing personal or sensitive information:** HR files, donor or outreach lists with contact information, payment records, or any data that might illustrate information about individuals' behavior or preferences
* **Files exposed to external viewers:** Documents shared outside of your organization for purposes of external review or collaboration.
* **Files accessed by departing staff:** When staff leave, they are unlikely to resolve any outstanding access permissions issues. For example: owners of documents may have allowed a personal account to access an organization-owned document. Once their organization account is disabled, they may be able to retain access to that document if their personal account has opened it even once. They may have also shared documents and directories outside the organization in a way that other staff are unaware of. When staff leave, it is important to review their files for permissions issues - or to archive all their documents in a new directory where the permissions can be holistically altered.

#### Enabling Device Encryption

**Windows Devices**

Information on how to turn on device encryption in Windows 10 devices can be found here: <https://support.microsoft.com/en-us/help/4028713/windows-10-turn-on-device-encryption>

**Note:** This feature is not available on Windows Home edition, requires at least Windows Professional license.

**Apple Devices**

FileVault is a disk encryption feature built in to Mac OS X. FileVault provides 128bit AES encryption with a 256 bit key to encrypt the disk and all files located on the drive. This is a very strong encryption mechanism. Strong encryption helps to prevent unauthorized access to the Mac since the disk and all file contents are encrypted, requiring that the password be entered on boot before the computer, data, and files can be accessed.

The following link provides a step- by- step instructions on how to enable FileVault: <https://support.apple.com/en-us/HT204837>

All iOS devices (iPads, iPhones) from recent years have been encrypted by default, but the vast majority of iOS devices can have encryption enabled. If you need to enable device encryption on an iOS device, you can follow these directions: <https://ssd.eff.org/en/module/how-encrypt-your-iphone>

**Android Devices**

General instructions on how to enable full-disk encryption on Android devices can be found here: <https://docs.microsoft.com/en-us/intune-user-help/encrypt-your-device-android>, though the settings may differ across devices. Many new Android devices are encrypted by default.

Note: Chromebooks, which run a similar (but distinct) operating system called ChromeOS, are encrypted by default.


# Appendix C: Moving Beyond the Baseline

*Please Note: Cybersecurity is a rapidly evolving field. This document was last updated on February 2, 2019. Some of the technical guidance within this document may change, and some of the risks defined may increase or decrease in their potential likelihood or impact.*

As an organization grows and takes advantage of more online technologies, the opportunities for attacks on your systems and sensitive data will grow. It will be important to consider these risks as the organization adopts new technology and works to improve security practices. This section includes a list of resources that can help a LRO become more informed about cybersecurity, and can help move the organization's security practices to the next level of sophistication.

1. **Citizen Lab Security Planner** The Citizen Lab, a cybersecurity research lab at the University of Toronto, recently published a web-based guide that helps individuals find cybersecurity tools and tips based on the types of devices they use and the services they tend to access online. Security Planner can be accessed here: <https://securityplanner.org/>. Note that this guide is more appropriate to individuals than to LROs, but may still serve as a useful assessment and recommendation tool.
2. **NIST Small and Medium-Sized Business Guidance** The National Institute of Standards and Technology is an agency within the US Department of Commerce that issues sophisticated cybersecurity guidance that is adopted widely across the US government and in many large companies. While most of their guidance is highly technical, they also have some resources on how to apply their work in smaller and more resource-constrained organizations.
   * NISTIR 7621: Small Business Information Security: The Fundamentals <http://nvlpubs.nist.gov/nistpubs/ir/2016/NIST.IR.7621r1.pdf>
   * Slides: <https://csrc.nist.gov/csrc/media/projects/small-business-community/documents/sbc_workshop_presentation_2015_ver1.pdf>
3. **FCC CyberPlanner** The Federal Communications Commission of the US Government is a regulatory agency focused on telecommunications issues. They have many cybersecurity resources for small organizations, but their CyberPlanner page is a clear, helpful tool for developing a written organizational security policy that addresses common issues: <https://www.fcc.gov/cyberplanner>
4. **EFF Cybersecurity Training Materials** The Electronic Frontier Foundation is a technology privacy and civil liberties advocacy organization. They have developed a number of strong, clear, and succinct training materials for improving individuals' cybersecurity practices. While many of their materials are geared toward high-risk individuals and organizations, their lessons are clear and usable by a broad audience.
   * The Security Education Companion: <https://sec.eff.org/topics>
   * Surveillance Self-Defense: <https://ssd.eff.org/>


# Virtual Private Network (VPN)

## Introduction to Virtual Private Networks (VPNs)

Virtual Private Networks can be an important part to protecting your students' privacy and the security of your client's data. What is a Virtual Private Network or VPN? Read the Center for Democracy & Technology's [VPN Techplanation](https://cdt.org/insights/techsplanations-part-5-virtual-private-networks/).

Below we describe a phased approach for students to practice setting up a virtual private network. The process can be broken into three main phases that allow students and staff to explore the advantages and disadvantages of its installation and management.

As students go through the steps, they should keep track of things that went well, things that were difficult or pain points, and ideas/opportunities for improving the process. They can use the tables below each section. Also, they can flag any “make sure you do this” thoughts that they have and add them to the short list of instructions in each phase.

### Primary Option: Algo VPN

The first option to explore is Algo, an open source VPN project supported by Trail of Bits (<https://www.trailofbits.com/>).

#### Installation and Dependencies

* Follow these instructions: <https://github.com/trailofbits/algo#deploy-the-algo-server>
* Install the VPN Builder on your local machine.
* This is the most complicated step and it’s possible another organization or tech expert needs to help you do this.

| Strengths | Weaknesses | Opportunities |
| --------- | ---------- | ------------- |
|           |            |               |
|           |            |               |
|           |            |               |

#### Access and Deployment to AWS

* Follow these instructions: <https://github.com/trailofbits/algo/blob/master/docs/cloud-amazon-ec2.md>
* Setup an Amazon Web Service account for hosting the VPN on EC2.
* Create an “IAM” user on AWS named something like “Algo VPN” with appropriate permissions. Make sure to use an IAM user with an acceptable policy attached (see <https://github.com/trailofbits/algo/blob/master/docs/deploy-from-ansible.md>).
* Run the VPN builder, select AWS EC2 and input the public/secret key for the “Algo VPN” account:
  * Enter your aws\_access\_key (<https://docs.aws.amazon.com/general/latest/gr/managing-aws-access-keys.html>): *\[AKIA...]:*
  * Enter your aws\_secret\_key (<https://docs.aws.amazon.com/general/latest/gr/managing-aws-access-keys.html>): *\[ABCD...]:*

| Strengths | Weaknesses | Opportunities |
| --------- | ---------- | ------------- |
|           |            |               |
|           |            |               |
|           |            |               |

#### VPN User Setup on Laptops and Mobile devices

* Follow these instructions: <https://github.com/trailofbits/algo#configure-the-vpn-clients>
* Users will download Wireguard to their phones and laptops.
* Managers will share the setup configurations with users.
* Users finish setting up the VPN by importing config file or scanning the QR code.
* If WireGuard doesn’t work, users can use another setup method, but they will need more instructions.

| Strengths | Weaknesses | Opportunities |
| --------- | ---------- | ------------- |
|           |            |               |
|           |            |               |
|           |            |               |

### Alternative Option: Outline

Beyond using Algo, students can also try setting up Outline by Jigsaw (a Alphabet/Google initiative) to provide "a safer way for news organizations and journalists to access the internet." Visit <https://getoutline.org/>.

Follow a similar phased setup approach.

### Wrap Up

Consider the following questions:

* Including security and usability, what other values should be considered when selecting a VPN?
* What are the advantages and disadvantages of using Algo versus Outline? Consider your threat model.
* What are the advantages and disadvantages of using either Algo or Outline versus a commercial VPN provider? Consider your threat model.
* Which contextual factors (PESTLE) may influence selecting one solution over another?

Document your findings and present your recommendations based on your experiences and the answers to the above questions.


# Creating Virtual Identities

## Introduction to Virtual Identities

Anonymity and non-attribution are key principles for conducting open source research on the Internet given the importance of avoiding the disclosure of identifiable elements of the investigating individual and organization to a third party. As such, students or staff should never use their own personal accounts and profiles to conduct contextual or threat research on social media sites. Instead, they should use virtual identities. You may have heard "virtual identities" being referred to as "burner profiles" or "throwaway accounts."

We have documented some best practices for creating these identities given privacy, security, and ethical concerns. These practices evolve as platforms change and malicious actors use "fake accounts" to abuse or attack users.

!!! info "Definitions" Members of the open source investigation community, led by UC Berkeley's Human Rights Center, are attempting to standardize vocabulary for virtual identities and its components. The Human Rights Center uses the following definitions:\
\
**Virtual identity:** A false online identity that is used to conduct secure online activities for intelligence and investigation purposes on social media platforms and other websites that require users to log in to access content.\
**Virtual account:** A private account on an email or messaging service, database, application, or website that uses one’s false online identity rather than one’s real life identity.\
**Virtual profile:** A public-facing profile on a specific social media platform or website that uses one’s false online identity rather than one’s real life identity.

## Before You Begin

You should have a documentation system for managing virtual identities. You will need to create multiple accounts; some of these might not be frequently used yet still require "maintenance." We offer an example worksheet that describes much of the information you will need to create a new identity.

### Virtual Identity Worksheet

This browser does not support PDFs. Please download the PDF to view it: Download PDF.

How you store this information will depend upon the assessed risks for both your organization and for the project that requires the particular identities.

## Risk Assessment

The first step in creating a virtual identity should be performing a risk assessment or conducting a threat modeling exercise. What do you intend for your virtual identity to protect? From which threats?

Will you need to use the profile to engage with content (liking, retweeting, commenting) or accessing semi-public groups? Your answers will affect whether you need a new virtual identity and how much effort you should put into creating and maintaining one for this investigation or in the future.

## Guidelines

Here are some guidelines for account creation that we have consolidated from previous work. Again, each of these will depend upon your risk assessment and are subject to change across platforms. You should consider and document these elements of your identity before you start creating a persona on any platform.

### Name

* Do not assume the name or identity of a real person.
* Select a name that is either very generic or unique.
* A name may provide clues about the person’s origins.

### Personal Information

* Gender
* Age (date of birth): Remember not to use your real date of birth.
* Nationality
* Birth location
* Residence
* Occupation
* Employer: Avoid using organizations that are easy for others to verify whether an individual works there.
* Interests: Avoid interests that might make your profile the subject of an investigation such as terrorist or criminal content.
* Hobbies

### Email

* Most social media platforms and website registration require an email address to set up a profile.
* While Proton Mail provides more anonymity, some platforms may suspect you are not authentic and ask for more identity verification.
* The email address can be a variation of your identity’s name or something more random.
* Create an email account, preferably with a provider known for security.
  * Do NOT give away your real phone or email address if you’re asked.
  * First option (easier): Open an email account on fastmail.com or gmail.com.
  * You may be asked for a second email (recovery email).
  * For added privacy from the email provider, open a ProtonMail account using TOR (<https://protonirockerxow.onion/>).

### Phone Number

* Using a VPN or TOR during account creation might cause you to be prompted for a recovery phone number. Try instead connecting using commercial or public internet.
* If you still do need a phone number:
  * Google Voice if in US
  * Twilio has international numbers
  * Don't ask us about "burner phones" or SIMs - that's beyond the scope of this document.

### Infrastructure

* VPN: What is the appropriate location to gain access to the information you need?
* Device(s) Used: Does your identity primarily use mobile devices or desktop?
* Operating System(s)
* Browser (s): Which browser should your identity use?
* Browser Plugin(s): Are there certain extensions that would be a "red flag" for some identities?
* Computer clock: In which timezone should the virtual identity's computer be? Is this consistent with the VPN?

### User Behavior

* User’s Time Zone: Similar to computer clock, the browser and platform may also need to configured for the appropriate time zone.
* Time of Day when Active: When would your identity be actively browsing the web?
* Use of scripts: Should your virtual profile use automation or bots?

### Profile Information

* Usernames: Choose usernames that are a variation of your identity’s name, email address, or something more random.
* Passwords: Passwords should be long, strong, and unique for each account / profile. Do NOT reuse passwords as tempting as it may seem for a virtual profile. Why not?
* Security & Privacy settings: Enable 2-Factor Authentication (2FA) for your accounts to keep your investigation data more secure and to possibly protect your account from being deleted by the platform. In general, you should adjust privacy settings to their most restrictive setting.
* Creation date: Document the creation date for all profiles and accounts.

### Images

* Do not use pictures of real people due to privacy and ethical harms.
* Do not use your own picture.
* Avoid human-like images or altered human faces: Even computer-generated images typically offer one angle and are currently easy to detect as fake.
* Profile pictures can be landscape photographs, sports teams, music bands, or cat photos.
* Consider banner images as well.

## Identity Maintenance

Your intent should be to make your profiles look real upon first glance and a longer second look. Secondly, you should try to keep your profiles alive, especially as realistic profiles take some effort and should look like they've existed for some time.

* Create a regular schedule for logging in, posting content, or changing profile information.
* Check email accounts for notifications from the social media platforms. These may concern suspicious login activity, requests to change passwords, authentication requests via email or phone, or requests for official ID cards.
* Recheck your privacy settings regularly.
* Reassess the needs and risks associated with the virtual identity. If there's no longer a need for an account which has already beeen used, you might delete the identity and its accounts and profiles for the sake of safety and efficiency.


# Security Evaluation Framework for OSINT Tools

Research Process, Prototype, and Justifications

Citizen Clinic, Spring 2020

Rachael Cornejo and Thyne Boonmark

***

Skip to [current prototype.](https://www.citizenclinic.io/Clinic_Infrastructure/OSINT_Evaluation/#prototype)

Want to get involved? Fill out this form: <https://forms.gle/8pKCoVpkKKEzrjU6A>

***

## Motivation

Public-interest investigative research using online open source intelligence (OSINT) methods involves utilizing various online tools and searching through various online platforms to find sensitive information.^1 During this process, public-interest OSINT researchers such as journalists, lawyers, and human rights defenders open themselves up to online risks: use of digital tools creates points of weakness which can reveal researchers’ locations, activities, contacts, and other data.^2^4^6 Protecting oneself online is thus an essential part of OSINT investigations, but unfortunately doing so can be a difficult process. For many investigators, conducting a comprehensive risk assessment and choosing appropriate mitigations is too time consuming and difficult a task to incorporate into their workflow. Our team’s work attempts to make this process easier. We provide a framework to help investigators understand their security needs before beginning a project, and then decide which tools are appropriate for this project based on these security needs.

## Target Audience

To envision our target audience and design our framework accordingly, we crafted user personas.^7 Our personas were public-interest investigators with different levels of experience and technical knowledge. The process of creating user personas revealed multiple insights about how our target audience could utilize our framework: first, our framework could help researchers new to OSINT reflect on their security needs before an investigation and point them in the direction of tools that would suit these needs. Second, our framework could help more experienced investigators educate others as part of a security training curriculum. Third, our framework could be particularly useful for investigators working on particularly sensitive projects with greater security needs than normal projects.

1. Our first user persona, Fátima, is an experienced investigator who is being paid by an advocacy-oriented nonprofit within the United States to investigate local white supremacist groups: her bosses want to understand who these groups’ leaders are, what types of news and multimedia group members share, whether this news is accurate, and how these groups organize protests and other events. Although she has investigated problematic leaders in other countries, Fátima feels trepidation about carrying out such a project in the U.S., where she thinks those she is researching could easily do harm to her if they found out she was investigating them. She wants to learn how to protect her identity, but is not sure where to look.
2. Our second user persona, Javier, lives in Mexico and spends his time training professionals around the world – mostly journalists and lawyers – on the benefits of utilizing OSINT both in the newsroom and the courtroom. Javier trains professionals in OSINT because he believes OSINT techniques open up new opportunities for them for more impactful pieces of journalism and more impactful legal cases. However, he knows the professionals he works with deal with sensitive issues and wants them to be safe while they use these techniques – he does not want to teach these professionals skills which leave them in more danger than they were before. At the same time, teaching professionals these skills takes a long time and it can be hard to find time to teach security – plus, he does not want to scare professionals away from using these tools.
3. Our third user persona, Aiko, is an U.S.-based investigative journalist who just learned some basic OSINT techniques at a training. She thinks these new skills could make for a cool, unique story. She has also been turning over the idea of breaking a story on surveillance of Islamic Americans who are suspects of terrorism. After the OSINT training, she decides to see whether she can use OSINT to find out more about occasions in which Islamic-Americans have been victims of police surveillance. Aiko has read info about Snowden’s leak and knows American government surveillance of these types of issues is high after 9/11, thus leading to potential risk for herself if she investigates further. However, she thinks this is an important under-reported story and wants to work on it, both to bring much-needed attention to this issue and to advance her career.

## Methodology

### Background Research

To inform our design and prototyping, we conducted research on approaches for helping users to understand their digital security and on previous attempts to create frameworks for evaluating digital tools.

#### \*\* Helping Users Understand Digital Security \*\*

1. The paper “Obstacles to the Adoption of Secure Communication Tools”\[^8] explores how different users understand the security of communication tools, and explains what motivates their messaging app choices.The researchers found that many participants have misconceptions about different communication tools’ security, and are mistaken in their reasoning behind which tools to use.The paper’s findings showed us that average users are not familiar with security concepts and thus need more detailed guidance on risks associated with using certain applications.
2. The paper “Why Johnny Can’t Encrypt”\[^9] explains that security mechanisms are only effective when used correctly, and that more than 90% of all computer security failures occur because users have not configured their technologies properly. This paper showed us that in order to help keep investigators secure, we should not only help them choose tools which are appropriately secure for their purposes, but also help them understand how to configure any tool they choose to use in the most secure way possible.

#### **Previous Frameworks for Evaluating Digital Tools**

1. The primary case study we considered was Version 1 of the Electronic Frontier Foundation (EFF’s) Secure Messaging Scorecard. While outdated and considered by the EFF to be insufficient as a recommendation tool, the secure messaging scorecard provided a good starting point for creating a tool evaluation system. The scorecard is presented as a graph with checkmarks notating whether or not a variety of messaging platforms satisfy certain security considerations, such as providing encryption in transit and keeping past communications secure if one’s encryption keys are stolen. Although it has been left online for historical reasons, EFF’s website states that this scorecard does not reflect the most recent developments for all of these messaging platforms.\[^10] As an alternative, EFF offers *Surveillance Self-Defense*, a more complex set of tools and how-tos for safer online communications which includes “how-to” guides for certain security tools but does not offer an overarching security matrix of tools in the field for easy comparison.^11 In a separate article entitled “Why We Can’t Give You a Recommendation,”^12 EFF explains why the org has steered away from making recommendations on which messaging tool users should implement to be most secure. Tool developers can make sudden changes to their tools which change the tools’ pros and cons with regard to security, security features are only one of multiple variables that matter when choosing a secure messenger (including usability, cost, countries a tool is used in, whether it works on iPHone or Android), and the specific threats someone is worried about influence which messenger is right for their purposes. Another EFF article called “What Is a Good Secure Messaging Tool?” points out that by including checkboxes, Version 1 of EFF’s scorecard can accidentally suggest that there is a single standard for security and that a tool can be 100% “secure” if it checks all the boxes, when in reality security is context-specific and never guaranteed.\[^13] These observations from EFF suggested to our team that if we were to create an effective framework to evaluate the security of OSINT tools, we should do three things: include categories beyond traditional “security” features, avoid the checkbox format, and create a clear process for the continued maintenance of our tool.
2. In addition to the EFF scorecard, we researched two other websites which are designed to help users to improve their online safety: Citizen Lab’s security planner and the Digital Defenders Partnership’s digital safety manual for human rights defenders.^14 Both resources suggest a variety of tools (such as browser extensions) and practices (such as updating your apps) which can help users become more secure. However, these publications primarily propose more secure solutions rather than evaluating the security of existing tools which those in the field already use. In addition, neither website caters this information specifically to the tools which public-interest investigators use in order to accomplish their work: more popular tools like web browsers and secure messaging tools are covered, but not investigator-specific tools like Hunch.ly and SunCalc. Thus, although these tools provide helpful potential models for structuring our tool, their content differs greatly from our project content, showing us that our framework occupies a unique niche.
3. The closest comparison we found to a security framework for OSINT is Michael Bazzell’s Buscador OSINT Virtual Machine, a collection of instructions for users to create a secure “investigative operating system.”\[^16] Although Buscador is now out-of-date and Bazzell now recommends a DIY Custom OSINT VM, Buscador provides an example of a secure OSINT setup. However, rather than providing his readers with understanding of why he has housed his system in a VM and why each of the tools he has suggested are necessary, Bazzell lists them and provides instructions for installation. Based on our research into helping users understand digital security, we decided that our tool should focus more on providing explanations and offering options for tools than does Bazzell’s.

### Interviews

To supplement our desk research, we judged that user testing through interviews would provide us with the best sense of how to structure our framework. We focused on individuals who have experience within the public-interest OSINT community either as investigators, trainers of OSINT investigators, and investigative tool developers.

We first interviewed investigators to gain an understanding of what they do to perform investigations securely and if there are any ways to improve this process. These initial interviews showed us that OSINT investigators lack a quick and efficient method of evaluating security tools, and that many investigators forgo the tool evaluation process as they do not have time to do it.

Once we had a prototype for our framework, we conducted interviews with members of the OSINT community to get feedback on its design, usefulness, and ways to incorporate it into their investigative workflows. Some of these individuals also train investigators, and we asked for their feedback on ways to improve our framework’s usefulness as a training tool. While our framework’s target audience is mainly investigators, we wanted to ensure that our framework formed an accurate depiction of various OSINT tools’ security. We thus also spoke with application developers who had experience as online investigators.

#### Interview Takeaways

\*\* Use Cases: \*\* The investigators we spoke with believed that our framework would be valuable early on in the investigative process. Interviewees stated that the framework could encourage investigators to better think through security considerations when deciding what tools to use in an investigation, perhaps as part of an initial risk assessment and/or threat modeling process. However, we also learned of some limitations of our work. Because of our framework’s length, interviewees believed that the framework would mainly be useful when planning for longer term investigations into high risk areas. They emphasized that if an investigator has a shorter timeline, they are more likely to stick to whatever tools they are more familiar with and not spend the extra time assessing and choosing new tools. We also found a use case we had not previously considered: tool developers we spoke with found that our framework would be helpful for informing clients and consumers of the features and limitations of their product. This is because the questions included in our framework align with those law enforcement and larger companies ask before deciding to use an investigative tool.

\*\* Compatibility with Existing OSINT Workflows & Training Programs: \*\* We asked our interviewees about their existing workflows and their thoughts as to where our framework could fit. Multiple interviewees said they would like to see our tool integrated with the Berkeley Protocol on Open-Source Investigations, a forthcoming resource which will set common guidelines for the use of OSINT in international legal and human rights investigations.^17 The Protocol outlines steps for OSINT researchers to build an online investigation plan & strategy, and although the Protocol is not yet public, some interviewees stated that OSINT trainings for journalists and lawyers already take place with the Protocol in mind. Overall, our interview responses emphasized our framework’s potential usefulness as a tool for training OSINT researchers and investigative journalists, and highlighted the need for further research into how we can align future versions of the tool with these established OSINT workflows and training programs. One interviewee even suggested linking our tool to existing security resources, such as the EFF Security Scorecard and Citizen Lab security planner.

\*\* Tool Format: \*\* When speaking to investigators, we found that many would find a “security scorecard” rating system very useful. Interviewees said having a concrete score of some kind would make the tool evaluation process much more convenient. One investigator also stated that he would like to see a rating of whether a tool is “low risk” or a “high risk” plotted against a y-axis of how often breaches happen. However, although we noticed demand for a true rating system and for quantification of the risks inherent to a tool, our initial research led us to reject such a system due to the way that security is context-specific – a tool which is secure or low-risk for one investigation could be completely insecure or high-risk for another. This topic is discussed further in our Attributes and Justifications section.

In addition, our interviewees suggested two different ways to organize the information provided about each tool. One suggestion was to show a list of pros and cons for each tool. The other was to separate different attributes based on which tool type they were applicable to. For example, interviewees mentioned that they would like to choose a specific type of tool to examine, messaging tools for instance, and then be shown all the tools specific to that type of application, in order to compare and contrast across tools. Also, our interviewees stated that they would appreciate guidance on how to configure settings to optimize each tool’s security, so that once they decide on a particular tool they can make sure it is configured as securely as possible. Finally, one investigator suggested that he would like to see an “endorsements” section of our tool – similar to the one which can be found on Hunch.ly’s website – in order to lend the tool legitimacy.

\*\* Tool Categories: \*\* In our interviews, investigators said they would like to see our framework applied to the following categories of investigative tools: social media platforms, satellite tools, data organizing tools, browsers, VPNs, email services, and collaboration applications. Tool categories could also take into account existing well-known lists and categorizations of OSINT tools, such as Bellingcat’s Online Investigations Toolkit^18 and First Draft News’s Verification Workstation.^19 Interviewees also said they would like our framework to include case studies to help them understand the real world implications of certain features. Case studies could also show how specific features were useful to past investigators, which would help cement their practical application to our framework’s users.

\*\* Visual Design: \*\* Our interviewees, particularly the non-developer interviewees, emphasized that an appealing visual design would be necessary in order to convince them to use the tool. Because they have limited time for each investigation, interviewees said they would not use our framework if it was hard to navigate, too detailed, and not visually intuitive. One interviewee suggested the idea of having a few key security considerations outlined at the top of the framework webpage, with a dropdown menu which highlights other categories of interest. Similarly, multiple interviewees said they would love to see a compact number of boxes or attributes which expand to reveal more text once the user clicks on it. Our team sees pros and cons to this idea – such a design could perhaps obscure important information about a particular tool, but could also increase the overall usability, and therefore likelihood of use, of our framework.

## Security Assessment Design

To organize our framework, we created five overarching categories which our research suggested investigators should be aware of: provider & geography, provider transparency, personal identifiers, security features, and tool usability & maintenance.

We created these categories based upon feedback from our initial conversations with OSINT investigators. Initial interviewees highlighted the need for some sort of overarching categorization which would help investigators understand the different types of security considerations they should keep in mind. Because one of our project goals is to make security approachable for those unfamiliar, we thus decided to adopt a categorization system.

Although we renamed and slightly reshuffled these categories throughout the design process, the same five general concepts held firm throughout. In contrast to the EFF secure messaging scorecard which primarily addressed technical security of tools, we reasoned that although these technical security features are very important, technical security should be one of multiple categories that investigators consider when evaluating security. Thus, technical security features make up one category of five, and are not the first category listed in our prototype. Instead, we reasoned that the identity of the tool's provider – as well as location of that provider – would be important initial information for investigators to know, since where a tool’s provider is based can impact which governments have most potential access to any information stored by their systems. Similarly, we decided that tool provider transparency regarding legal threats and security vulnerabilities within a tool was an important category to then consider. Third, we reasoned that if a tool requires certain personal identifiers to use, this may necessitate the use of burner profiles and affect how investigators interact with the tool – thus, we listed personal identifiers third. Only after considering provider and geography, transparency, and potential necessity or personal identifiers did we judge it necessary for investigators to need information about a tool’s particular security features, making security features our fourth category. Finally, we reasoned that an investigator happy with a tool’s security features would have questions about its usability and maintenance, making this question the farthest down of our five categories. In particular tool usability and maintenance (as well as creator transparency) can be vital if investigators are considering using a tool long term.

Since we want our tool to be usable by investigators with little to no technical background, with each security attribute we have included a high level description and a justification for its inclusion in our framework – in other words, an appeal to why investigators should consider it important. This additional explanation and information should help define security concepts in concrete terms relevant to OSINT investigators and help them reflect on their security needs before an investigation.

## Attributes and Justifications by Category

\*\* Not Including a Tool Rating: \*\* While a numeric score representing tools’ security was requested by multiple investigators, our team avoided implementing such a system because it leaves little room for nuance and would not teach investigators how to evaluate their own context-specific security needs. Looking at the EFF’s previous endeavors in security scorecards, we learned that we cannot label tools as completely “secure.” The importance of certain security factors heavily depends on the context in which the tool will be used, and lots of information needs to be understood about an investigator’s context before making this decision.^20 Our team thus wanted to outline what considerations investigators should think about and to teach investigators to think critically about these considerations, rather than making a decision for them.

### Provider & Geography

The “Provider & Geography” category of our framework contains information about the tool provider’s access and retention of information and motives for developing the tool, as well as the country where the provider is located and any countries in which use of the tool is restricted. The “Provider – Goal” attribute was initially called “Provider – Entity” and, along with the ““Provider – Country” attribute, was listed before all other categories in this section. We initially placed these two categories highest on the list because they seemed intuitively important. However, based on feedback from one of our project advisors, we realized that in order to make effective decisions as to whether to use a tool from a specific provider, an investigator first needs to understand what types of data the tool can access, as well as whether, and how, the tool stores this information. If investigators do not know what data is being accessed temporarily by a tool and whether this data is stored more permanently even temporarily, they cannot accurately make other key security decisions. Once investigators understand these two key considerations, they can then evaluate whether they are willing to input their data for a specific investigation into a tool whose provider has specific potential goals and is from a specific country.

\*\* “Provider” vs “Developer” vs “Owner” \*\* – Our team initially labeled this category “Owner & Geography” and also included the phrase “developer” in our prototype – however, we realized that owner and developer were two different categories, and that using the two terms interchangeably was confusing. In addition, one project advisor pointed out to us that the developer or a tool may not be its owner. Thus, we settled on the phrase “provider” to describe the entity which owns, and/or develops, and/or maintains the tool.

\*\* “Provider – Entity” → “Provider – Goal” \*\* – Initially we included an attribute called “Provider – Entity” which listed the name of the tool provider, but after speaking with one of our project mentors. we decided the name of the provider was not as important as the goals this provider has for the tool. Thus, the new category, “Provider – Goal,” includes both the provider name and their goal. In addition, although we reason that funding can sometimes give clues as to the goal of a project, funding never came up in our interviews or discussions with project mentors, and thus we do not currently include an attribute for funding, although one could be created or included as part of a reworked “Provider – Goal” attribute.

\*\* Location-Based Bans \*\* – Although this attribute does not fit into the roadmap outlined above which connects the rest of the attributes in the “Provider & Geography” category, we included it in this category because it involves geography. We determined that access by country is important to include because some governments block the use of certain tools, rendering these tools unsuitable for certain investigations – one investigator confirmed that this attribute was important.

### Provider Transparency

The “Provider Transparency” section of our framework contains information regarding whether the provider is transparent about potential weaknesses within their platform which could make it insecure: this includes both technical vulnerabilities, and requests from governments and law enforcement to turn over data. One interviewee suggested that we combine this section with the country of origin section because creator transparency is dictated by jurisdiction in a lot of cases. Our research team felt that provider transparency was different enough from geography that it deserves its own category, but decided to order this section immediately after the “Provider and Geography” in the hopes that investigators will keep provider location in mind when evaluating provider transparency.

\*\* Vulnerability Transparency – \*\* At first, this attribute was amorphous: “vulnerabilities” were not clearly defined. We included touting code as open source in this category, as an example of vulnerability transparency. However, one of our research mentors suggested that this section include information about bug bounty programs, as bug bounty programs suggest that a tool’s provider values security, as well as encourages tool providers to continually improve the security of their tools. One interviewee suggested that this category could also include information about how tool providers respond to known security issues, although our research team has debated creating a separate category for this attribute.

\*\* Government / Law Enforcement Interaction Transparency \*\* – Our interviewees agreed that this category was important. One interviewee suggested multiple metrics by which to evaluate tool providers’ transparency with regard to government and law enforcement interaction, including transparency reports and warrant canaries. Our team has observed that there is no universal way to quantify this attribute, and recommends further exploration.

\*\* Legal Obligations \*\* – This category initially included a section titled “legal obligations” which, like all other categories in the spreadsheet, contained a description, as well as a space to provide tool-specific information. However, multiple interviewees, including a lawyer who gave us feedback, emphasized that providers in any location can be obligated to turn content over to law enforcement when legally requested. Thus, we decided to take out space for tool-specific information in favor of notating that legal obligations are applicable to all tools. However, one interviewee suggested that our description should explain that these legal obligations are driven by jurisdiction – for example, US and Canada privacy/security laws are different – and that we could perhaps make it apparent in our chart which jurisdiction particular tools fall under.

### Personal Identifiers

The “Personal Identifiers” section provides a variety of information which relates to users’ personal identities – although these attributes do not build upon each other in a linear fashion, they share this common theme. Interviewees appeared to find this grouping of criteria intuitive.

\*\* Aliases \*\* – Developer interviewees found that this is a very important category that can make or break a product for users. Law enforcement groups in particular have a great need for aliases in certain tools.

\*\* Data Required to Use \*\* – Interviewees found this to be important. Depending on the data required to use a tool (name, phone number, etc), investigators might have to set up a burner profile which is an important consideration to think about before starting a project. Although this category overlaps with the information collected in the “Provider access” and “Provider retention” areas of the scorecard, interviewees did not appear to notice this redundancy – no interviewees mentioned it. However, this overlap may still perhaps be an area for further refinement.

\*\* Data Collected \*\* – Interviewees found this important and most relevant if they were working in sensitive scenarios. Developer interviewees also found that many investigators they worked with in the past cared about this, especially in terms of data portability (could users access and download data associated with them?). As with “data required to use,” thus section overlaps with the information collected in the “Provider access” and “Provider retention” areas of the scorecard, interviewees did not appear to notice this redundancy, although it could use more fine-tuning.

\*\* Login and Contact Authentication \*\* – Forms of login authentication such as MFA and contact authentication like safety numbers were very important to our interviewees. It was suggested to us that other investigators with less familiarity of common security practices could use examples that demonstrate the importance of MFA and safety numbers. Threats associated with not having authentication may not be immediately clear to some potential users of our framework.

### Security Features

Our prior research and interviews demonstrated that before a researcher decides whether to incorporate a tool into an investigative workflow, this researcher must understand the security features the tool supports^21 – although we contend that “security features” is an amorphous term which may require more precise definition. However, we reasoned that since not all investigators have a technical background in regards to security there is a need to explain certain features in terms of their impact rather than their technical specifications, an attitude which was confirmed in our interviews with non-technical investigators. Our team’s goal in this section was thus not just to tell investigators what features a tool has, but to get them to understand what these features help protect against and if they would be necessary in the investigators’ context.

\*\* Retention of Metadata \*\* – Feedback from developers was that this is very important for investigators to consider, because metadata can be as powerful as actual data in terms of identifying individuals or groups.

\*\* Cloud Storage \*\* – Feedback was mixed. Our project mentor noted that it is hard to define whether data is stored in the Cloud “securely,” and wonders how investigators will assess this. Further consideration of whether to include this category, and how to quantify it, is needed.

\*\* Transport and End-to-End Encryption \*\* – Interviewees found these categories to be very important. However, they mentioned that for investigators with no familiarity with encryption or cybersecurity these category labels would not properly convey their importance. One interviewee thus suggested linking to supplementary materials that explain the technical details of these attributes more thoroughly for investigators who are curious, while others emphasized that we should use case studies and clear examples to convey the importance of encryption to our audience. In addition, one interviewee suggested combining these two categories together, although we ultimately decided to leave them separate transport encryption and end-to-end encryption provide very different levels of security.

\*\* Access Controls \*\* – Interviewees thought this category is important to keep in mind if a tool is going to have multiple collaborators.

\*\* Open Source Code \*\* – From our developer interviews, this category appears to be important in certain cases. Some tools that are open sourced can be made more secure for users if they host these tools on their own servers. However, just because a tool is open source does not mean it is free of vulnerabilities – a third party audit can help determine this. Thus, the fact that an application has open source code may not be the best metric by which investigators should judge their security. However, our team left this metric in the scorecard for further development because our tool could perhaps serve as an opportunity to write a description for investigators as to why open source code is not an appropriate security metric.

\*\* Independently Audited \*\* – Mixed response from interviewees. They stated that although public independent audits exist for some tools, such as Signal, the public often has no way to evaluate whether these audits have exposed vulnerabilities in the tools or not. In addition, tool developer interviewees suggested that law enforcement or government agencies perform many independent audits of applications, yet the results of these audits are kept private even from the tool developers. Thus, while potentially informative when available, audits may not be the best metric by which to judge the security of a tool.

\*\* App vs Browser \*\* – We wanted to distinguish the difference between using a tool through its downloaded application versus using it through a web browser. Downloading an application can give it more permissions/access to certain aspects of a user’s device while using the browser version does not. From our interviews we found that investigators were interested in how security differs across app-based and web-based versions of a tool, and in the question of whether one version gives users more security than another. Further research and clarification is needed. In addition one interviewee brought up the question of whether tools operate using HTTPS vs HTTP, a consideration which we did not include but could be incorporated in the future.

\*\* Ephemeral Messages \*\* – We added this category when we were testing our framework for the Signal messaging app, but eventually deleted it due to unfavorable reactions from interviewees. Investigators were not immediately sure of the term “ephemeral messages” and when clarified, it appeared to be low on their priorities in terms of security considerations. Developers could see how this could be important, but it seems to be more of a niche category that is not as much of a primary concern. We eventually concluded that the availability of ephemeral messaging as a feature could perhaps be subsumed under “data collected” or “provider retention.”

### Tool Usability and Maintenance

\*\* Cost \*\* – Very important for our interviewees. For investigative teams, certain costs may be prohibitive and make a tool unfeasible to use. Developer feedback also told us that specific pricing models of tools could also be important for users (one-time payment, renewing license, etc). In addition, one interviewee mentioned security considerations related to the method of billing. He noted that a user in a particular country may not be able to purchase a certain because purchase by international credit cards is blocked. In addition, this interviewee mentioned that payments could potentially be tracked. Additional research into exact methods for quantifying this category is needed.

\*\* Ease of Use \*\* – Feedback suggested that this category was too broad. One investigator mentioned that he would like us to expand upon the category and that he would want to know whether the tool provided a “good user experience,” although he admitted this terminology was vague. Developer interviewees suggested adding specificity around whether a tool requires a large amount of training. They found that if a tool is complicated enough to require training before it can be used properly, users might be turned away from the tool as it would take too long to incorporate into their work. More research into how to quantify this category is needed.

\*\* Cross-user Collaboration \*\* – Interviewees found this to be very important. If an investigator is working in a team on a project, tools that enable them to collaborate in one space become very valuable.

\*\* User Support Capability \*\* – Interviewees found this to be important for tools. If they run into an issue while using an application, they want some form of support/troubleshooting available to them.

\*\* Consistent Maintenance & Updates \*\* – Mixed response from interviewees. We originally had an “update frequency” category that was meant to gauge how well a developer was handling the security of their tool. However, the developers we interviewed mentioned how update frequency alone is not a great measure of a tool’s security: simply being updated a lot does mean a tool’s security is improving, because these updates may not relate to security. In addition, one interviewee brought up the consideration of how updates are delivered – whether they are delivered online vs deployed by the provider. Further refinement is needed.

\*\* Compatibility with Other Systems \*\* – Our initial draft of our prototype contained this category, but we removed it because we thought it was vague and was not sure how to quantify it. However, one interviewee mentioned this category of his own accord. He explained that outlining a tool’s compatibility with other commonly used OSINT tools could be useful because he has observed that many users do not often buy tools in isolation This interviewee explained that private investigators and journalists may buy tools in isolation; but users running firms, law enforcement agencies, and research organizations buy stacks of compatible tool chains. However, because the primary audience of our scorecard is investigators who work alone or in small teams, we decided not to add this attribute back into our framework.

## Next Steps

\*\* Testing and Community Feedback \*\*

We conducted research with a small sample size of participants and believe that further input from a wide variety of OSINT researchers will be key to developing a tool which works for as many researchers as possible. We need to test our prototype to see whether what we have built actually solves the problems we initially thought it could solve, and whether it fits nicely into existing OSINT workflows. Thus, we recommend sending our prototypes out to a large group of international public-interest OSINT researchers from a variety of fields, including journalism, law, and advocacy. This “call to action” could include sending our prototype out via Google Docs or GitHub and asking for comments, and scheduling interviews with those interested in providing more in-depth feedback. It could also include presenting our prototype at conferences and working groups composed of relevant stakeholders.

\*\* Refining Categories: \*\* To make using our framework easier for investigators, our current should be grouped hierarchically based on tool type and importance of an attribute. Not every attribute in our framework is relevant for every tool, and it would be useful to clarify which tool types (messaging, preservation, geo-locating, etc) each attribute is meant for. For example, it would be useful for all criteria relevant to messaging apps to be grouped together, all criteria relevant to preservation tools grouped together, etc. Interviewees also mentioned that they would like to view highly impactful application features first – such as cost, end-to-end encryption in messaging apps, etc – and then be able to optionally view “nice to have” features. Thus, future research could identify what information is necessary to show at the top of the framework, and how to order all other features.

\*\* Developing UI system \*\*

From our interviews we found that the current table format of our framework can take a long time to read through. Once we have further refined our tool evaluation attributes and grouped them into categories, it would be helpful to integrate them into some interactive system so users could choose to look at the features most relevant to them rather than the entire list. The investigators we spoke to suggested that the tool would be easier to use if it was interactive and let users select certain attributes based on tool types. Creating such a system would require more design work, web interface work, as well as thorough usability testing with members of the OSINT community.

\*\* Increasing Accessibility \*\*

In order to not alienate the users whom our tool is meant for, future work on this prototype should include simplifying its technical language, as well as providing more tangible examples, case studies, and explanations which help users learn about security and change the way they think about security, rather than simply informing them of tool attributes.

\*\* Expanding Framework to More Tools \*\*

Our current framework has primarily tested messaging and preservation tools, but in the future we would like to expand it to be applicable to other types of tools, such as social media platforms, satellite tools, data organizing tools, browsers, VPNs, email services, and collaboration applications. The four tools we have tested so far include Signal, Whatsapp, Hunch.ly, and Check – thus, the current iteration of our work is mostly geared to describe the security of these types of messaging and preservation tools. However, expanding the types of tools our framework can evaluate would make our framework more comprehensive, and make it more useful to investigators who may require a wider array of tools. Testing other types of investigative applications would help uncover features specific to them, which in turn could help clarify what security considerations investigators should think about when choosing these tools.

## Conclusion

Our research team has completed the first steps towards creating a framework which can be used to evaluate the security of tools which public-interest OSINT researchers commonly use. We have identified that many OSINT researchers input sensitive information into a variety of digital tools, yet lack effective methods for evaluating the security of these tools and deciding which tools are appropriate for a particular investigation. We explore a potential solution to this problem by proposing a framework which OSINT researchers can use during the initial planning stages of their investigation to decide which tools will be most secure for the project. In the future, we recommend continued testing of our framework to discover whether it actually helps address the problem it purports to solve. We also recommend the exploration and creation of an intuitive UI system which ensures that our framework can be easily implemented by our intended audience. Finally, we recommend additional research into ways in which this tool could be designed and presented to fit into investigators’ existing workflows.

We learned that rather than subjectively evaluating whether a certain tool is “safe,” we should teach investigators to evaluate tools based upon the investigators’ specific project and situation. Our framework should bring investigators attention to security features that are important, but which these investigators may never have considered. Thus, our tool should provide a learning experience to investigators as to which security considerations should be taken into account and why. Our team is still grappling with the best way to encourage such learning in a usable, simple format, but further testing and refinement should help achieve this goal.

### Acknowledgments

We extend our utmost thanks to the following people for providing invaluable input and advice on this project: Steve Trush, Citizen Clinic; Kristin Berdan, Citizen Clinic; Bill Marczak, Citizen Clinic & Citizen Lab; Justin Seitz, Hunch.ly; Michael Elsanadi, Syrian Archive; John Ortilla, Human Rights Investigations Lab at UC Berkeley Law.

## Current Prototype

| **Security Framework for OSINT Tools**                |                                                                                                                                                    |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |                                                                                                                                                                                                                                                                                                                                                                            |
| ----------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Category**                                          | **Attribute**                                                                                                                                      | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | **Why choose this attribute?**                                                                                                                                                                                                                                                                                                                                             |
| Basic Functionality                                   | How can the tool be useful for an investigation?                                                                                                   |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |                                                                                                                                                                                                                                                                                                                                                                            |
| Provider & Geography                                  | Provider Access                                                                                                                                    | What information does the tool gain from the user, even temporarily?                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | Outlines the information companies/government(s)/cyber criminals could potentially have access to – how sensitive is this information?                                                                                                                                                                                                                                     |
| Provider Retention                                    | Does the tool retain this info more permanently and if so, how/where is it stored?                                                                 | Outlines the information companies/government(s)/cyber criminals could potentially have access to                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |                                                                                                                                                                                                                                                                                                                                                                            |
| Provider Goal                                         | Who owns and/or developed the tool and what are their plans for the data?                                                                          | Gives a tentative idea of what the owner may do with the information stored in the tool. (Targeted advertising, used to improve the service, etc.)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |                                                                                                                                                                                                                                                                                                                                                                            |
| Provider Location                                     | Where is the provider located or headquartered?                                                                                                    | Gives an idea of which government(s) could potentially gain access to above information which goes through a tool.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |                                                                                                                                                                                                                                                                                                                                                                            |
| <p>Location-</p><p>Based</p><p>Bans</p>               | Banned in any locations? Attempts to block?                                                                                                        | Ex. if investigating China, using Facebook will not be useful because Facebook is disabled in China.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |                                                                                                                                                                                                                                                                                                                                                                            |
| Provider Transparency                                 | Vulnerability Transparency                                                                                                                         | Does the provider have a robust bug bounty program? Do they publish public bug reports? How does the provider handle known security issues?                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | <p>Publishing bug reports and having a bug bounty program can encourage third party researchers to uncover potential flaws in a tool. This then helps developers strengthen the security of their product.</p><p>Notification of security issues helps users understand when a product’s security has been compromised.</p>                                                |
| Government / Law Enforcement Interaction Transparency | Do developers have a realistic and transparent attitude toward government and law enforcement?                                                     | Organizations which care about notifying their consumers of possible legal requests may publish transparency reports and/or utilize warrant canaries to alert the public to both the existence and the fulfillment of such requests.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |                                                                                                                                                                                                                                                                                                                                                                            |
| Legal Obligations                                     | All providers can be obligated to turn content over to law enforcement when legally requested.                                                     |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |                                                                                                                                                                                                                                                                                                                                                                            |
| Personal Identifiers                                  | Aliases                                                                                                                                            | Do you have to use a personal identifier (phone number, real name, etc) as a public-facing username?                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | Having an alias can safeguard against leaking personal identifiers (such as phone numbers) to onlookers.                                                                                                                                                                                                                                                                   |
| Data required to use                                  | How much information do you have to hand over to the provider in order to sign up?                                                                 | While performing research on certain online communities, investigators should take care to protect their anonymity and reduce the amount of information that may point to their true identity, else open themselves to greater risks.For example, if a tool user is forced to enter their personal phone number as their username and police track their phone number, police could arrest them. Accounts and services that require personal identifiers to sign up (such as phone number, full name, etc) may then necessitate the use of burner profiles/devices by an investigator. Some information, such as a linked phone number, are more resource intensive to set up and should be taken into account before an investigation. |                                                                                                                                                                                                                                                                                                                                                                            |
| Data collected                                        | What type of information does the company collect?                                                                                                 | If an investigator is performing sensitive work on a platform or service, it is important to know if any of this will be stored by the host. If so, this information could be requested and accessed by other entities such as law enforcement.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |                                                                                                                                                                                                                                                                                                                                                                            |
| Login Authentication                                  | If login required, offers multi-factor authentication?                                                                                             | Multi-factor authentication (use of a second method of verifying your identity when you log into an account, in addition to a password) adds an extra layer of protection. If an attacker got their hands on your login credentials and you use MFA, they will have much more trouble accessing the user’s account without access to the user’s secondary authentication method than if you do not use MFA.                                                                                                                                                                                                                                                                                                                             |                                                                                                                                                                                                                                                                                                                                                                            |
| Contact Authentication                                | Can you be certain that the person being contacted is the intended recipient?                                                                      | Apps that let you verify the identity of your contacts helps protect against man in the middle attacks. Verifying who you are communicating with can help prevent you from sending information to an unintended audience – for example, an enemy pretending to be someone you trust.                                                                                                                                                                                                                                                                                                                                                                                                                                                    |                                                                                                                                                                                                                                                                                                                                                                            |
| Tool Security features                                | Retention of Metadata                                                                                                                              | Does the company retain data surrounding the content you create/upload?                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | Metadata relation to an individual’s use or interactions with a tool/platform could possibly reveal personally identifying information. For example, if an investigator is working on a collaborative platform with individuals of a vulnerable population, metadata related to who accessed/made changes on the platform could linke the individuals to the investigator. |
| Cloud Storage                                         | Does the company retain data in the cloud? If so, is it stored securely?                                                                           | <p>If a company keeps users’ data in the cloud and proper protections are not implemented, there is increased risk of personal data being exposed or leaked to the public.</p><p>Failure of a cloud service may also lead to irreversible loss of users’ data.</p><p>If data is kept unencrypted in the cloud, the data may be shared if the company is compelled by law enforcement or other government entities.</p>                                                                                                                                                                                                                                                                                                                  |                                                                                                                                                                                                                                                                                                                                                                            |
| Transport encryption                                  | Does the tool protect messages from being listened in on by outsiders?                                                                             | Transport encryption protects data when it is being transported between two communicating parties. This helps protect against adversaries trying to spy on the data. However, transport encryption does not hide data from the company hosting the communication.                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |                                                                                                                                                                                                                                                                                                                                                                            |
| End-to-end encryption                                 | Does the tool protect messages from being listened in on by outsiders AND the company hosting the tool?                                            | E2E encryption, like transport encryption, protects data while it is being transported. In addition, E2E also protects data from anyone besides the communicating parties. This means that the company behind the communication would not be able to access the data or share it with other entities. One might use end-to-end encryption so that instead of $5 to get your conversations, attackers have to pay $1 million to get these conversations – these attackers often practice “targeted interception” where they only attempt to compromise their top 1000 targets.                                                                                                                                                           |                                                                                                                                                                                                                                                                                                                                                                            |
| App vs browser                                        | Do you have to download an app, or can you use this tool in your browser?                                                                          | Downloading a tool’s application may give it greater access to your device compared to using the tool as a browser extension or web-page.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |                                                                                                                                                                                                                                                                                                                                                                            |
| Access Controls                                       | Can you control who can access shared information?                                                                                                 | If an investigator is planning on sharing private documents or performing sensitive work through a tool, it is important that they be able to control who can access this information. If a tool defaults to making documents/information public, it is important that an investigator adjust settings.                                                                                                                                                                                                                                                                                                                                                                                                                                 |                                                                                                                                                                                                                                                                                                                                                                            |
| Open-Source Code                                      | Is the code publicly available for audits?                                                                                                         | **If you are an activist, what is actionable about this for you?**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |                                                                                                                                                                                                                                                                                                                                                                            |
| Independently audited                                 | Have independent auditors checked the tool for security vulnerabilities? What have they found?                                                     | If a tool has been independently audited by a third party and has a security report available, this could provide valuable information regarding the security of the application. If an audit has not found any significant security/privacy issues, then the tool may be less open to attacks from more technical adversaries and hackers.                                                                                                                                                                                                                                                                                                                                                                                             |                                                                                                                                                                                                                                                                                                                                                                            |
| Tool Usability & Maintenance                          | Cost                                                                                                                                               | Free to use? If not, how expensive?                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | Free to use tools are more accessible, especially to non-profit or resource constrained organizations.                                                                                                                                                                                                                                                                     |
| Ease of use                                           | Easy to set up? Does it require training to know how to use it?                                                                                    | <p>A good tool should be straightforward and easy to use. If the tool is unintuitive, users may accidentally misuse the tool and introduce new risk into their workflow.</p><p>If the tool is complicated enough to require training to use it properly, it would be more difficult to initially incorporate it into investigations.</p>                                                                                                                                                                                                                                                                                                                                                                                                |                                                                                                                                                                                                                                                                                                                                                                            |
| Cross-user collaboration                              | Does this tool allow for multiple collaborators/contributors in real time?                                                                         | If multiple investigators will be working together on a project, cross-user support may facilitate easier and more convenient collaboration.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |                                                                                                                                                                                                                                                                                                                                                                            |
| User support capacity                                 | If you run into issues using the tool, can you get support? How much support can you get                                                           | <p>Running into issues while using an application should be expected, and in these cases company support can be helpful and make the experience using a tool smoother.</p><p>Support FAQs and training guides provide by a company can also be helpful in making the most out of a tool.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                            |                                                                                                                                                                                                                                                                                                                                                                            |
| Consistent Maintenance & Updates                      | Are developers frequently maintaining and updating their application? If a security issue is found, do the developers quickly address the problem? | <p>If an application is not currently being maintained, then any security flaws already existing in the tool will not be addressed. For long-term investigations, investigators may want to avoid out-dated tools in favor of tools that will continue to be updated to reduce the risk of technical vulnerabilities.</p><p>Frequency of updates can be helpful in determining how well a tool is maintained, but may not always be a good indicator of a tool’s security.</p>                                                                                                                                                                                                                                                          |                                                                                                                                                                                                                                                                                                                                                                            |

## Notes

\[^8]:

```
 [Abu-Salma et al., 2017 IEEE Symposium on Security and Privacy. doi:10.1109/SP.2017.65](https://ieeexplore.ieee.org/document/7958575)
```

\[^9]:

```
 [Whitten & Tygar, SSYM ‘99. doi:10.5555/1251421.1251435](https://dl.acm.org/doi/10.5555/1251421.1251435)
```

\[^10]:

```
 [https://www.eff.org/pages/secure-messaging-scorecard](https://www.eff.org/pages/secure-messaging-scorecard) 
```

\[^13]: [Musiani, F. and Ermoshina, K. (2017). What is a Good Secure Messaging Tool? The EFF Secure Messaging Scorecard and the Shaping of Digital (Usable) Security. Westminster Papers in Communication and Culture, 12(3), 51–71. doi:10.16997/wpcc.265](https://www.westminsterpapers.org/articles/10.16997/wpcc.265/)

\[^14]:

```
 [https://securityplanner.org/#/all-recommendations](https://securityplanner.org/#/all-recommendations) 
```

\[^16]:

```
 [https://inteltechniques.com/buscador/](https://inteltechniques.com/buscador/) 
```


