Get in Touch
 Duration 35 hours

Course Outline

Introduction to ISO/IEC 27035

  • Overview of the various parts and structure of ISO/IEC 27035
  • Interconnection with ISO/IEC 27001 and other relevant standards
  • Essential terminology, definitions, and core concepts

Principles of Incident Management

  • Comprehending threats, vulnerabilities, and associated risks
  • Categorisation and classification of incidents
  • Stages within the incident lifecycle

Planning an Incident Management Program

  • Establishing scope and strategic objectives
  • Defining roles, responsibilities, and escalation pathways
  • Developing incident response policies and procedures

Detection and Reporting of Incidents

  • Identifying indicators of compromise and early warning signals
  • Utilising internal and external reporting channels
  • Maintaining accurate incident logs and records

Analysis and Evaluation of Incidents

  • Collecting and preserving forensic evidence
  • Applying root cause analysis techniques
  • Conducting impact assessments and risk evaluations

Response, Containment, and Recovery

  • Implementing containment strategies and managing communication
  • Eliminating threats and resolving vulnerabilities
  • Executing system recovery and validation processes

Post-Incident Activities and Continual Improvement

  • Finalising incident reports and documentation
  • Reviewing lessons learned and implementing corrective actions
  • Integrating improvements into the ISMS

Summary and Recommended Next Steps

Requirements

  • A solid understanding of information security management concepts
  • Experience with ISO/IEC 27001 or comparable standards
  • Professional experience in IT security or incident response roles

Intended Audience

  • Information Security Officers and Managers
  • Incident Response Team Leaders
  • Risk and Compliance Professionals

Number of participants


Price per participant

Testimonials (1)

Provisional Upcoming Courses (Require 5+ participants)

Related Categories