Đề cương khóa học

Introduction to Incident Handling

  • Understanding cybersecurity incidents
  • Goals and benefits of incident handling
  • Incident response standards and frameworks (NIST, ISO, etc.)

Incident Response Process

  • Preparation and planning
  • Detection and analysis
  • Classification and prioritization

Containment Strategies

  • Short-term vs long-term containment
  • Network segmentation and isolation techniques
  • Coordination with stakeholders and notification protocols

Eradication and Recovery

  • Identifying root causes
  • System restoration and patching
  • Monitoring post-recovery

Documentation and Reporting

  • Incident documentation best practices
  • Generating actionable post-mortem reports
  • Lessons learned and metrics for improvement

Incident Response Tools and Technologies

  • SIEM systems and log analysis tools
  • Endpoint detection and response (EDR)
  • Automation and orchestration in IR

Tabletop Exercises and Simulations

  • Interactive incident scenarios
  • Team coordination drills
  • Evaluating response effectiveness

Summary and Next Steps

Requirements

  • Nắm vững các khái niệm cơ bản về an ninh IT
  • Thành thạo các giao thức mạng và quản trị hệ thống
  • Có nhận thức về các mối đe dọa và lỗ hổng an toàn mạng

Đối tượng

  • Nhân viên phân tích an ninh IT
  • Thành viên đội phản ứng sự cố
  • Nhân viên chuyên nghiệp về vận hành an toàn mạng
 21 Hours

Number of participants


Price per participant

Testimonials (4)

Provisional Upcoming Courses (Require 5+ participants)

Related Categories