ITS-INC
New IT security incident management
Description
Security incident management is the process and support for identifying, managing, recording and analysing security threats or incidents in real time. It aims to provide a reliable and comprehensive picture of security issues within the IT infrastructure. A security incident can be anything from an active threat to an intrusion attempt to a successful compromise or data breach.
The training aims to familiarise participants with the basics, processes and procedures of security incident management. It will cover the incident classification system, the components of an incident response plan, the structure and responsibilities of the incident management organisation. The national and international CERT/CSIRT network will be presented. The training will also cover business continuity planning issues and how to share incident information with official and industry stakeholders.
Practical exercises will introduce the technical tools of the incident management process, which will be demonstrated and applied through case studies.
Suggested For
The training is designed for professionals with a basic security background who will be responsible for developing and supporting IT security, including incident management processes, solutions and resources in their organisation. The course is ideal for novice/prospective security professionals, security testers, security managers, security auditors, operations and development managers.
Benefits
On completion of the training, participants will acquire the following skills:
- Understand the concepts of incident and incident management
- Incident management process, developing incident management procedures
- Structure, scope and principles of the incident management organisation
- Familiarisation and application of technical incident management tools and procedures
- Business continuity planning
Outline
- Theory of incident management
- The legal background to incident management
- Organisational background of incident management in Hungary and internationally, introduction of CERT/CSIRT organisations
- Overview of Security Operation Centers
- Technical tools for incident management
- Sharing incident information
- Business continuity planning
- Definition of event, problem, incident, practical examples
- Presentation of incident case studies
- Creating an incident management team
- The incident management process in practice
Prerequisites
IT security/cybersecurity and information security basics. CompTIA Security+ training or knowledge of CompTIA Security+ is recommended.