Category : Cyber Security

Security Analyst - InfoSec Incident Response

Start Date : March 12, 2021
Course Duration : 45 Hours
Course Type : Self paced
Course Validity : 180 days

15000
Description

This Course is Aligned to Competency Standards developed by SSC NASSCOM in collaboration with Industry and approved by Government

It helps to learn how to effectively respond to Cyber Security incidents and includes  the fundamentals of incident response establishing requirements, setting up operations and communicating effectively. With frequency and complexity of today's cyber attacks, incident response is a critical function for organizations.

Course Description

InfoSec Incident Response is about playing a co-ordinating role in responding to information security incidents, liaising with members of the security team who carry out investigations and other stakeholders or business users.


Prerequisites

  • Incident responders
  • Network and system administrators
  • Ethical hackers and penetration testers
  • Anyone looking to develop hands-on, technical incident response skills


Course Outline

  • This course helps to establish your role and responsibilities in co-ordinating responses to information security incidents
  • Helps to record, classify and prioritize information security incidents using standard templates and tools.
  • How to access your organization’s knowledge base for information on previous information security incidents and how these were managed.
  • How to assign information security incidents promptly to appropriate people for investigation/action.
  • How to liaise with stakeholders to gather, validate and provide information related to information security incidents, where required 
  • Ways to track progress of investigations into information security incidents and escalate to appropriate people where progress does not comply with standards or service level agreements (SLAs).
  • To prepare accurate preliminary reports on information security incidents using standard templates and tools
  • To submit preliminary reports promptly to appropriate people for action
  • To update the status of information security incidents following investigation/action using standard templates and tools.
  • How to update your organization’s knowledge base promptly and accurately with information security incidents and how they were managed.
  • To comply with your organization’s policies, standards, procedures, guidelines and service level agreements (SLAs) when co-ordinating responses to information security incidents.


Learning Objectives

  • Understand the importance of an incident response plan.
  • Understand the six phases of incident response.
  • Access a sample incident response plan.
  • Understand the necessary steps taken after the Cyber Security incident.
  • Understand the steps to Cyber Security incidents.
  • Know which roles are necessary for the Incident Response team.
  • Examine outcomes of Incident Response scenarios.


Target Audience

  • Risk management professionals.
  • Information security engineers and managers.
  • IT managers.
  • Operations managers.
  • IT/System Administration/Network Administration Professionals.
  • IT auditors.
  • Business continuity and disaster recovery staff.


Keywords

Incident Response, Incident Response Planning, Incident Detection, Incident Classification, Forensic Investigation, Compliance audit, Trend Analysis, Compliance audit, Trend Analysis

Course Duration (in Hours): 45

Announcements
Theory: Lesson 1 - Co-ordinating responses to information security incidents
Quiz: Co-ordinating responses to information security incidents
Lab 01 - Roles and responsibilities in IS incidents
Theory: Lesson 2 - Record, classify and prioritize information security incidents
Quiz: Record, classify and prioritize information security incidents
Lab 02 - IS incident prioritization
Theory: Lesson 3 - Managing and Accessing previous information security incidents
Quiz: Managing and Accessing previous information security incidents
Lab 03 - Lessons learned from previous information security incidents
Theory: Lesson 4 - Investigation Action on Information Security Incidents
Quiz: Investigation Action on Information Security Incidents
Lab 04 - Evidence collection
Theory: Lesson 5 - Communication Prior and Post Incident
Quiz: Communication Prior and Post Incident
Lab 05 - Incident investigation
Theory: Lesson 6 - Incident Management
Quiz: Incident Management
Lab 06 - Reporting IS incidents
Theory: Lesson 7 - Documenting Security Incidents
Quiz: Documenting Security Incidents
Lab 07- Incident compliance with policies and procedures