Get in Touch
 Duration 35 hours

Course Outline

Introduction to ISO/IEC 27035

  • Insight into the components and architecture of ISO/IEC 27035
  • Correlation with ISO/IEC 27001 and other relevant standards
  • Essential terminology, definitions, and foundational concepts

Principles of Incident Management

  • Assessing threats, vulnerabilities, and associated risks
  • Categorisation and classification of security incidents
  • Phases of the incident lifecycle

Planning an Incident Management Programme

  • Establishing clear scope and strategic objectives
  • Defining roles, responsibilities, and escalation protocols
  • Developing incident response policies and operational procedures

Incident Detection and Reporting

  • Identifying indicators of compromise and early warning signs
  • Utilising internal and external reporting channels
  • Maintaining accurate incident logs and documentation

Incident Analysis and Evaluation

  • Collection and preservation of digital evidence
  • Techniques for conducting root cause analysis
  • Assessing impact and evaluating associated risks

Incident Response, Containment, and Recovery

  • Strategies for containment and stakeholder communication
  • Eradication of security threats and vulnerabilities
  • System restoration and validation processes

Post-Incident Activities and Continual Improvement

  • Compiling incident reports and documentation
  • Extracting lessons learned and implementing corrective actions
  • Embedding enhancements into the ISMS

Summary and Next Steps

Requirements

  • Proficiency in information security management principles
  • Working knowledge of ISO/IEC 27001 or comparable standards
  • Practical experience in IT security or incident response functions

Target Audience

  • Information security officers and managers
  • Incident response team leaders
  • Risk and compliance specialists

Testimonials (1)

Upcoming Courses

Related Categories