Get in Touch
 Duration 21 hours

Course Outline

Introduction to Incident Handling

  • Comprehending cybersecurity incidents
  • Objectives and advantages of incident handling
  • Incident response standards and frameworks (NIST, ISO, etc.)

The Incident Response Process

  • Readiness and strategic planning
  • Identification and deep-dive analysis
  • Categorization and setting priorities

Approaches to Containment

  • Distinguishing between short-term and long-term containment
  • Techniques for network segmentation and isolation
  • Aligning with stakeholders and following notification protocols

Eradication and Restoration

  • Pinpointing root causes
  • System reinstatement and patch application
  • Monitoring systems after recovery

Documentation and Reporting

  • Best practices for documenting incidents
  • Crafting actionable post-mortem reports
  • Identifying lessons learned and key performance metrics

Incident Response Tools and Technologies

  • SIEM platforms and log analysis utilities
  • Endpoint detection and response (EDR)
  • Automation and orchestration within IR

Tabletop Drills and Simulations

  • Interactive incident scenarios
  • Team coordination exercises
  • Assessing the effectiveness of the response

Conclusion and Path Forward

Requirements

  • Fundamental comprehension of IT security principles
  • Proficiency with network protocols and system administration
  • Recognition of cybersecurity risks and vulnerabilities

Target Audience

  • IT security analysts
  • Members of incident response teams
  • Professionals in cybersecurity operations

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories