Creating a Computer Security Incident Response Team: Learning Outcomes

This CSIRT course will help participants to:

Creating a Computer Security Incident Response Team: Course Overview

This 1-day course is designed for managers and project leaders who have been tasked with implementing a computer security incident response team (CSIRT). This course provides a high-level overview of the key issues and decisions that must be addressed in establishing a CSIRT. As part of the course, attendees will develop an action plan that can be used as a starting point in planning and implementing their CSIRT.

The course is composed of lectures and class exercises. Participants will learn the requirements for establishing an effective CSIRT, the various organisational models for a CSIRT, the variety and level of services that can be provided by a CSIRT, and the types of resources and infrastructure needed to support a team. Additionally, attendees will identify policies and procedures that should be established and implemented when creating a CSIRT.

Attendees may also want to register for the three-day companion course, Managing Computer Security Incident Response Teams, which is scheduled immediately following this course.

World leading course

This course is presented in association with Axenic, a member of the SEI (Software Engineering Institute) Partner Network, Carnegie Mellon University. SEI is a recognised world leader and one of the most respected names in computer, software and security research, development and education. Other courses in this series are:

Fundamentals of Incident Handling
Managing Computer Security Incident Response Teams

ALC Training -ALC Training - SEI Partner Network Black

Managing Computer Security Incident Response Teams: Exams and Stuff

Prerequisites

There are no prerequisites for this course; however, prospective attendees may wish to consider attending the Creating a Computer Security Incident Response Team one-day class (usually scheduled the day before the Managing CSIRTs course).

Materials

Participants will receive a course notebook and a CD containing the course materials.

Certificate of Completion

Participants will receive a SEI–CERT branded Certificate of Completion.

CERT-Certified Computer Security Incident Handler

SEI has available the CERT-Certified Computer Security Incident Handler (CSIH) certification program. The awarding of the certification is upon application to SEI and is based on a combination of demonstrable experience plus performance in the CSIH certification examination. For further details please refer to this link.

Managing Computer Security Incident Response Teams: Sidebar Content

Managing Computer Security Incident Response Teams: Dates and Fees

This course is currently available for in-house presentation only. Please contact us for further information.

Managing Computer Security Incident Response Teams: Course Contents

Managing Computer Security Incident Response Teams: Learning Outcomes

This CSIRT course will help participants to:

Managing Computer Security Incident Response Teams: Who Should Attend

Managing Computer Security Incident Response Teams: Course Overview

This 3-day course provides current and future managers of computer security incident response teams (CSIRTs) with a pragmatic view of the issues that they will face in operating an effective team.

The course provides insight into the work that CSIRT staff may be expected to handle. The course also provides prospective or current managers with an overview of the incident handling process and the types of tools and infrastructure needed to be effective.

Technical issues are discussed from a management perspective. Topics include hiring CSIRT staff, identifying critical information, publishing information, establishing effective working relationships, working with law enforcement, evaluating CSIRT operations, building CSIRT service capacity, and the importance of pre-established policies and procedures.

The course incorporates interactive instruction, exercises, and role playing. During a simulated incident, attendees will gain experience with the type of decisions they might face on a regular basis.

Before attending this course, participants are encouraged to attend the companion course, Creating a Computer Security Incident Response Team. This course is offered the day before the Managing CSIRTs course.

Note: There is some content overlap between this course and the Fundamentals of Incident Handling course. We recommend that attendees register for one course or the other, but not both. This course focuses on incident handling issues from an operational management perspective and discusses best practices in sustaining an effective operation. Whereas the Fundamentals of Incident Handling course covers more technical topics such as email and malware attacks and is designed to introduce new incident handlers to the basic skills and processes they will need to perform their duties.

 

World leading course

This course is presented in association with Axenic, a member of the SEI (Software Engineering Institute) Partner Network, Carnegie Mellon University. SEI is a recognised world leader and one of the most respected names in computer, software and security research, development and education. Other courses in this series are:

Fundamentals of Incident Handling
Creating a Computer Security Incident Response Team

ALC Training -ALC Training - SEI Partner Network Black

Fundamentals of Incident Handling: Sidebar Content

Fundamentals of Incident Handling: Exams and Stuff

Prerequisites

Before registering for this course, participants must be familiar with Internet services and protocols. It is recommended but not required that participants have some experience with system administration for Windows or UNIX systems.

Materials

Participants will receive a course notebook and a CD containing the course materials.

Certificate of Completion

Participants will receive a SEI–CERT branded Certificate of Completion.

CERT-Certified Computer Security Incident Handler

SEI has available the CERT-Certified Computer Security Incident Handler (CSIH) certification program. The awarding of the certification is upon application to SEI and is based on a combination of demonstrable experience plus performance in the CSIH certification examination. For further details please refer to this link.

Fundamentals of Incident Handling: Dates and Fees

$3450 + gst

Course fee includes: