Get in Touch
 Duration 35 hours

Course Outline

Introduction to ISO/IEC 27035

  • Overview of ISO/IEC 27035 components and structural layout
  • Interrelationship with ISO/IEC 27001 and other relevant standards
  • Essential terminology, definitions, and foundational concepts

Core Principles of Incident Management

  • Understanding threats, vulnerabilities, and associated risks
  • Categorization and classification of security incidents
  • Phases of the incident lifecycle

Strategizing the Incident Management Program

  • Setting clear scopes and strategic objectives
  • Defining roles, responsibilities, and escalation pathways
  • Developing robust incident response policies and procedures

Detecting and Reporting Incidents

  • Identifying indicators of compromise and early warning signs
  • Establishing internal and external reporting channels
  • Maintaining accurate incident logs and documentation

Analyzing and Evaluating Incidents

  • Collection and preservation of digital evidence
  • Applying root cause analysis methodologies
  • Conducting impact assessments and risk evaluations

Response, Containment, and Recovery Strategies

  • Implementing containment strategies and effective communication
  • Eliminating threats and addressing vulnerabilities
  • System restoration and validation processes

Post-Incident Review and Continuous Improvement

  • Finalizing incident reports and documentation
  • Extracting lessons learned and defining corrective actions
  • Integrating enhancements into the ISMS

Wrap-up and Future Directions

Requirements

  • Solid understanding of information security management concepts
  • Proficiency with ISO/IEC 27001 or equivalent standards
  • Practical experience in IT security or incident response roles

Target Audience

  • Information security officers and managers
  • Leaders of incident response teams
  • Risk and compliance specialists

Testimonials (1)

Related Categories