Get in Touch
 Duration 35 hours

Course Outline

Introduction to ISO/IEC 27035

  • Survey of ISO/IEC 27035 components and structural layout
  • Interconnections with ISO/IEC 27001 and other industry standards
  • Essential terminology, definitions, and foundational concepts

Principles of Incident Management

  • Analyzing threats, vulnerabilities, and associated risks
  • Categorizing and classifying different types of incidents
  • Stages of the incident lifecycle

Planning an Incident Management Program

  • Setting clear scope and strategic objectives
  • Defining roles, duties, and escalation procedures
  • Establishing incident response policies and operational procedures

Incident Detection and Reporting

  • Identifying indicators of compromise and early warning signals
  • Establishing internal and external reporting pathways
  • Maintaining accurate incident logs and records

Incident Analysis and Evaluation

  • Collection and preservation of digital evidence
  • Methods for conducting root cause analysis
  • Assessing impact and evaluating associated risks

Incident Response, Containment, and Recovery

  • Strategies for containment and effective communication
  • Eliminating threats and addressing vulnerabilities
  • System restoration and validation processes

Post-Incident Activities and Continual Improvement

  • Compiling incident reports and documentation
  • Extracting lessons learned and implementing corrective actions
  • Incorporating enhancements into the ISMS

Summary and Next Steps

Requirements

  • A solid grasp of information security management fundamentals
  • Working knowledge of ISO/IEC 27001 or similar standards
  • Hands-on experience in IT security or incident response positions

Target Audience

  • Information security officers and managers
  • Incident response team leaders
  • Risk and compliance specialists

Number of participants


Price per participant

Testimonials (1)

Provisional Upcoming Courses (Require 5+ participants)

Related Categories