Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 35 hours
Course Outline
Introduction to ISO/IEC 27035
- Overview of the different parts and structure of ISO/IEC 27035.
- Alignment with ISO/IEC 27001 and other relevant standards.
- Essential terminology, definitions, and foundational concepts.
Core Principles of Incident Management
- Analyzing threats, vulnerabilities, and associated risks.
- Categorizing and classifying security incidents.
- Understanding the stages of the incident lifecycle.
Developing an Incident Management Program
- Establishing clear scope and strategic objectives.
- Defining roles, responsibilities, and escalation protocols.
- Drafting incident response policies and operational procedures.
Detecting and Reporting Incidents
- Identifying indicators of compromise and early warning signals.
- Establishing internal and external reporting channels.
- Maintaining accurate incident logs and records.
Analyzing and Evaluating Incidents
- Collecting and preserving digital evidence.
- Applying root cause analysis techniques.
- Conducting impact assessments and risk evaluations.
Responding, Containing, and Recovering from Incidents
- Implementing containment strategies and managing communication.
- Eradicating threats and closing vulnerability gaps.
- Restoring systems and validating their integrity.
Post-Incident Review and Continuous Improvement
- Finalizing incident reports and comprehensive documentation.
- Extracting lessons learned and implementing corrective actions.
- Integrating enhancements into the broader ISMS.
Summary and Path Forward
Requirements
- Foundational knowledge of information security management concepts.
- Practical familiarity with ISO/IEC 27001 or similar standards.
- Professional experience in IT security or incident response roles.
Target Audience
- Information security officers and managers.
- Leaders of incident response teams.
- Professionals specializing in risk management and compliance.
Testimonials (1)
Speed of response and communication