
About the subject and the structure of the course
About the concept of information security and what is information security management
About the most popular standards in the ISO/IEC 27000 series and what they refer to
About the purpose of ISO/IEC 27035 and the different documents that make up the ISO/IEC 27035 standard. What is the subject for each of those documents and how they are intended to be used
About the difference between information security events and incidents
A brief enumeration of different types of attacks that may lead to information security incidents
What are the common objectives that an organization is looking to achieve with its information security incident management process
An overview of the 5-phase process for informations security incident management according to ISO/IEC 27035
About the role and the recommended content for the incident management policy according to ISO/IEC 27035-2
About the content of the incident management plan
More information about what should be part of an incident management plan according to the guidelines in ISO/IEC 27035-2
The system for categorizing information security incidents propsed by ISO/IEC 27035-2
About the benefits of using forms to records incidents, events or vulnerabilities. Templates proposed by ISO/IEC 27035-2 for the different forms
About the incident management team, its responsibilities and activities
About the role of the incident response team and requirements for its members
About the need to establish relationships that may be necessary in the response to information security incidents
About the technical and other support that should be available for an adequate response to an information security incident
Guidelines for awareness and training on information security incident management
About the benefits of testing the information security incident management plan and the different options for testing available to an organization
About legal and regulatory requirements in relation to information security incident management
A recapitulation of the guidelines in ISO/IEC 27035-2 for the first phase of the incident management process - Plan and prepare
A short story about the data breach that occured at Equifax in 2017
About the importance of detecting information security events on time. About proactive and reactive detection.
About the channel for reporting information security events. About the point of contact and the decision as to whether an information security event represents an incident.
About the triage of information security incidents. Examples of criteria to be used for the classification of incidents
About the importance of analyzing information security incidents and the different types of files that are commonly the subject of analysis
About the different tools that analysts use and the difference between the intra-incident and the inter-incident analysis
About the objective of containment and the strategies recommended by ISO/IEC 27035-3 for incident containment
About the process of incident eradication and what it may involve. About the recovery from the incident and the relative guidance for this process according to ISO/IEC 27035
About reporting information security incidents inside the organization and to external stakeholders
About the guidelines in ISO/IEC 27035-2 for learning lessons from handling information security incidents and using the lessons learned as a driver for improvement
A recapitulation of the subjects discussed as part of the following phases in the incident management process: detect and report, assess and decide, respond and learn lessons
A short story about the data breach that occured at the American retailer Target in December 2013
About the options for certification in the context of information security incident management - certification for organizations and for individuals
Thank you for taking this course!
Every organization, regardless of size or industry, can become the target of a cyber attack — and security controls alone cannot guarantee total protection. Residual vulnerabilities will always exist, new threats emerge constantly, and information security incidents are a matter of when, not if. What separates a minor disruption from a business-ending crisis is how well the organization prepares for and responds to incidents.
This course teaches information security incident management according to ISO/IEC 27035, the international standard for incident management. You will learn the complete process for planning, detecting, assessing, responding to and learning from security incidents — the foundation of any incident response capability, and a natural complement to an ISO/IEC 27001 information security management system.
The five phases of incident management under ISO/IEC 27035
A section of the course is dedicated to each phase, with examples and case studies throughout:
Plan and prepare — developing incident management plans and policies, training and awareness, identifying resources, establishing forms and templates, and setting up organizational structures such as the incident management team and the incident response team (IRT/CSIRT)
Detect and report — identifying and reporting information security events, and the monitoring and detection capabilities that make this possible
Assess and decide — triaging events, categorizing incidents by their impact on the organization, and deciding on the appropriate response
Respond — containing the incident, eradicating the cause, and recovering affected systems and services
Learn lessons — using the information collected during incident handling to improve security controls, the incident management process and the wider organization
What you will gain
A complete understanding of the concepts, roles and tools of information security incident management
The ability to categorize and analyse security incidents and select appropriate responses
Practical knowledge for designing or improving your organization's incident response process — including plans, policies and team structures
A foundation for incident manager or incident responder certification paths, and for consulting or auditing engagements covering incident management
Who this course is for
IT and information security professionals building or joining an incident response team
SOC analysts and incident responders who want the management-system view of incident handling
CISOs, security managers and IT managers responsible for incident preparedness
ISO/IEC 27001 implementers and auditors — incident management is a required control area of every ISMS
Consultants supporting clients with incident management processes
Use this course to design or improve your company's incident management process, to support your consulting or audit work, or to advance your career in information security.