Get in Touch
 Duration 35 hours

Course Outline

Introduction to ISO/IEC 27035

  • Overview of the different parts and structure of ISO/IEC 27035.
  • Alignment with ISO/IEC 27001 and other relevant standards.
  • Essential terminology, definitions, and foundational concepts.

Core Principles of Incident Management

  • Analyzing threats, vulnerabilities, and associated risks.
  • Categorizing and classifying security incidents.
  • Understanding the stages of the incident lifecycle.

Developing an Incident Management Program

  • Establishing clear scope and strategic objectives.
  • Defining roles, responsibilities, and escalation protocols.
  • Drafting incident response policies and operational procedures.

Detecting and Reporting Incidents

  • Identifying indicators of compromise and early warning signals.
  • Establishing internal and external reporting channels.
  • Maintaining accurate incident logs and records.

Analyzing and Evaluating Incidents

  • Collecting and preserving digital evidence.
  • Applying root cause analysis techniques.
  • Conducting impact assessments and risk evaluations.

Responding, Containing, and Recovering from Incidents

  • Implementing containment strategies and managing communication.
  • Eradicating threats and closing vulnerability gaps.
  • Restoring systems and validating their integrity.

Post-Incident Review and Continuous Improvement

  • Finalizing incident reports and comprehensive documentation.
  • Extracting lessons learned and implementing corrective actions.
  • Integrating enhancements into the broader ISMS.

Summary and Path Forward

Requirements

  • Foundational knowledge of information security management concepts.
  • Practical familiarity with ISO/IEC 27001 or similar standards.
  • Professional experience in IT security or incident response roles.

Target Audience

  • Information security officers and managers.
  • Leaders of incident response teams.
  • Professionals specializing in risk management and compliance.

Testimonials (1)

Related Categories