Fundamentals of Incident Handling: Course Contents

Fundamentals of Incident Handling: Learning Outcomes

This Fundamentals of Incident Handling course will help participants to:

Fundamentals of Incident Handling: Who Should Attend

Fundamentals of Incident Handling: Course Overview

World-renowned CMU-SEI (Carnegie Mellon University – Software Engineering Institute) course on Incident Handling*

This 5-day course is for computer security incident response team (CSIRT) technical staff who have little or no incident handling experience. It provides a strong introduction to the main incident handling tasks and critical thinking skills that will help an incident handler perform their daily work. It is recommended for personnel new to incident handling work.

The course is designed to provide insight into the work that an incident handler may perform. It provides a comprehensive overview of the incident handling arena, including CSIRT services, intruder threats, and the nature of incident response activities.

Course attendees will learn how to gather the information required to handle an incident; realise the importance of having and following pre-defined CSIRT policies and procedures; understand the technical issues relating to commonly reported attack types; perform analysis and response tasks for various sample incidents; apply critical thinking skills in responding to incidents, and identify potential problems to avoid while taking part in CSIRT work. The course incorporates interactive instruction, practical exercises, and role playing. Attendees have the opportunity to participate in sample incidents that they might face on a day-to-day basis.

This course is part of the curriculum for the CERT-Certified Incident Handler program. After completing this course, participants are encouraged to attend the companion course, Advanced Incident Handling.

Note: There is significant content overlap between this course and the Managing Computer Security Incident Response Teams course. We recommend that attendees register for one course or the other, but not both. This course covers more technical topics such as email and malware attacks, PGP, and recognising signs of attack. It is designed to introduce new incident handlers to the basic skills and processes they will need to perform duties. Whereas the Managing CSIRTs course focuses on incident handling issues from an operational management perspective.

 

*World leading course

This course is presented in association with Axenic, a member of the SEI (Software Engineering Institute) Partner Network, Carnegie Mellon University. SEI is a recognised world leader and one of the most respected names in computer, software and security research, development and education. Other courses in this series are:

Creating a Computer Security Incident Response Team
Managing Computer Security Incident Response Teams

Advanced Incident Handling: Sidebar Content

Advanced Incident Handling: Exams and Stuff

Prerequisites

Before registering for this course, it is recommended that participants attend the Fundamentals of Incident Handling course. It is also recommended that participants have the following:

It is recommended but not required that participants also have experience programming in C, Perl, Java, or similar languages.

Materials

Participants will receive a course notebook and a CD containing the course materials.

Certificate of Completion

Participants will receive a SEI–CERT branded Certificate of Completion.

CERT-Certified Computer Security Incident Handler

SEI has available the CERT-Certified Computer Security Incident Handler (CSIH) certification program.  The awarding of the certification is upon application to SEI and is based on a combination of demonstrable experience plus performance in the CSIH certification examination.  For further details please refer to this link.

Advanced Incident Handling: Dates and Fees

This course is currently available for in-house presentation only.  Please contact us for further information.

Advanced Incident Handling: Who Should Attend

Advanced Incident Handling: Course Contents

Advanced Incident Handling: Learning Outcomes

This Advanced Incident Handling course will help participants to:

Advanced Incident Handling: Course Overview

This 5-day course, designed for computer security incident response team (CSIRT) technical personnel with several months of incident handling experience, addresses techniques for detecting and responding to current and emerging computer security threats and attacks that are targeted at a variety of operating systems and architectures.

Building on the methods and tools discussed in the Fundamentals of Incident Handling course, this course provides guidance that incident handlers can use in responding to system compromises at the privileged (root or administrator) level. Through interactive instruction, facilitated discussions, and group exercises, instructors help participants identify and analyse a set of events and then propose appropriate response strategies.

Participants work as a team throughout the week to handle a series of escalating incidents that are presented as part of an ongoing scenario. Work includes team analysis of information and presentation of findings and response strategies. Participants also review broader aspects of CSIRT work such as computer forensics, artefact analysis; vulnerability handling; and the development of advisories, alerts, and management briefings.

This course is part of the curriculum for the CERT-Certified Incident Handler program. Before registering for this course, participants are encouraged to attend the companion course, Fundamentals of Incident Handling.

 

World leading course

This course is presented in association with Axenic, a member of the SEI (Software Engineering Institute) Partner Network, Carnegie Mellon University. SEI is a recognised world leader and one of the most respected names in computer, software and security research, development and education. Other courses in this series are:

Fundamentals of Incident Handling
Creating a Computer Security Incident Response Team
Managing Computer Security Incident Response Teams

Digital Forensics Fundamentals: Sidebar Content