Get in Touch
 Duration 35 hours

Course Outline

Introduction to ISO/IEC 27035

  • Overview of the various parts and structure of ISO/IEC 27035
  • Interplay with ISO/IEC 27001 and other relevant standards
  • Essential terminology, definitions, and foundational concepts

Incident Management Principles

  • Grasping threats, vulnerabilities, and associated risks
  • Classification of incident categories
  • Stages of the incident lifecycle

Planning an Incident Management Program

  • Establishing scope and defining clear objectives
  • Assigning roles, responsibilities, and defining escalation paths
  • Formulating incident response policies and procedural guidelines

Incident Detection and Reporting

  • Identifying indicators of compromise and early warning signals
  • Utilizing internal and external reporting channels effectively
  • Maintaining accurate incident logs and records

Incident Analysis and Evaluation

  • Collecting and securing digital evidence
  • Applying root cause analysis methodologies
  • Conducting impact assessments and risk evaluations

Incident Response, Containment, and Recovery

  • Developing containment strategies and managing communications
  • Eliminating threats and patching vulnerabilities
  • Executing system recovery and verification processes

Post-Incident Activities and Continual Improvement

  • Finalizing incident reports and documentation
  • Extracting lessons learned and defining corrective actions
  • Incorporating enhancements into the ISMS

Summary and Future Directions

Requirements

  • Solid understanding of information security management principles
  • Proficiency with ISO/IEC 27001 or comparable standards
  • Practical experience in IT security or incident response positions

Target Audience

  • Information security officers and managers
  • Leaders of incident response teams
  • Specialists in risk management and compliance

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories