Get in Touch
 Duration 35 hours

Course Outline

Introduction to ISO/IEC 27035

  • Overview of the ISO/IEC 27035 components and structure.
  • Interconnections with ISO/IEC 27001 and other relevant standards.
  • Essential terminology, definitions, and core concepts.

Incident Management Principles

  • Analyzing threats, vulnerabilities, and associated risks.
  • Categorizing and classifying different types of incidents.
  • The stages of the incident lifecycle.

Planning an Incident Management Program

  • Establishing scope and strategic objectives.
  • Defining roles, responsibilities, and escalation pathways.
  • Formulating incident response policies and operational procedures.

Incident Detection and Reporting

  • Identifying indicators of compromise and early warning signals.
  • Utilizing internal and external reporting channels.
  • Maintaining accurate incident logs and documentation.

Incident Analysis and Evaluation

  • Techniques for gathering and preserving digital evidence.
  • Applying root cause analysis methodologies.
  • Conducting impact assessments and risk evaluations.

Incident Response, Containment, and Recovery

  • Implementing containment strategies and managing communications.
  • Eradicating threats and mitigating vulnerabilities.
  • Executing system recovery and validation processes.

Post-Incident Activities and Continual Improvement

  • Compiling final incident reports and documentation.
  • Extracting lessons learned and defining corrective actions.
  • Integrating derived improvements into the ISMS.

Summary and Next Steps

Requirements

  • Foundational knowledge of information security management concepts.
  • Working familiarity with ISO/IEC 27001 or similar standards.
  • Practical experience in IT security or incident response roles.

Audience

  • Information security officers and managers.
  • Incident response team leaders.
  • Risk and compliance professionals.

Number of participants


Price per participant

Testimonials (1)

Upcoming Courses

Related Categories