$2,900 – $3,600

Fundamentals of Incident Handling

Event Information

Share this event

Date and Time

Location

Location

Canberra

Canberra, ACT 2601

Australia

View Map

Event description

Description

This course is created and certified by the Software Engineering Institute at Carnegie Mellon University. It is delivered locally by authorised SEI Instructors.

This five-day course is for staff who have little or no incident handling experience. It provides a basic introduction to the main incident handling tasks and critical thinking skills that will help an incident handler perform their daily work. It is recommended for those new to incident handling work.

The course is designed to provide insight into the work that an incident handler may perform. It will provide an overview of the incident handling arena, including computer security incident response team (CSIRT) services, intruder threats, and the nature of incident response activities.

Course attendees will learn how to gather the information required to handle an incident; realize the importance of having and following pre-defined CSIRT policies and procedures; understand the issues relating to commonly reported attack types; perform analysis and response tasks for various sample incidents; apply critical thinking skills in responding to incidents, and identify potential problems to avoid while taking part in CSIRT work. The course incorporates interactive instruction, practical exercises, and role playing. Attendees have the opportunity to participate in sample incidents that they might face on a day-to-day basis.

This course is part of the curriculum for the CERT-Certified Incident Handler program.

Before registering for this course, participants must be familiar with Internet services and protocols. It is recommended but not required that participants have some experience with system administration for Windows or UNIX systems.



WHO SHOULD ATTEND?

  • new CSIRT staff (one to three months of experience)
  • experienced CSIRT staff who would like to benchmark their CSIRT processes and skill sets against best practices
  • anyone who would like to learn about basic incident handling functions and activities


TOPICS

  • understanding the CSIRT environment and basic incident management processes
  • CSIRT code of conduct
  • understanding security tools and technologies used by CSIRTs
  • identifying and gathering critical information
  • recognizing signs of attacks
  • detecting and analyzing incidents
  • finding contact information
  • coordinating response and disseminating information
  • handling email and malicious code attacks
  • working with law enforcement



OBJECTIVES

This course will help participants to

  • recognize the importance of following well-defined processes, policies, and procedures
  • understand the technical, communication, and coordination issues involved in providing a CSIRT service
  • critically analyze and assess the impact of computer security incidents
  • effectively build and coordinate response strategies for various types of computer security incidents



MATERIALS

Participants will receive a course notebook and a USB with the course material.



REFUND POLICY

You can apply for a refund via your eventbrite account or by emailing contact@cybertoa.com

For cancellations:

  • more than 7 days before the course starts: 80% of the fee will be refunded
  • more than 48 hours before the course starts: 50% of the fee will be refunded
  • less than 48 hours before the course starts: no refund
Share with friends

Date and Time

Location

Canberra

Canberra, ACT 2601

Australia

View Map

Save This Event

Event Saved