Course Outline
Introduction to ISO/IEC 27035
- Overview of ISO/IEC 27035 parts and structure.
- Relationship with ISO/IEC 27001 and other standards.
- Key terms, definitions, and concepts.
Incident Management Principles
- Understanding threats, vulnerabilities, and risks.
- Incident categories and classification.
- Incident lifecycle stages.
Planning an Incident Management Program
- Defining scope and objectives.
- Roles, responsibilities, and escalation paths.
- Incident response policy and procedures.
Incident Detection and Reporting
- Indicators of compromise and early warning signs.
- Internal and external reporting channels.
- Maintaining incident logs and records.
Incident Analysis and Evaluation
- Gathering and preserving evidence.
- Root cause analysis techniques.
- Impact assessment and risk evaluation.
Incident Response, Containment, and Recovery
- Containment strategies and communication.
- Eradication of threats and vulnerabilities.
- System recovery and validation.
Post-Incident Activities and Continual Improvement
- Incident reporting and documentation.
- Lessons learned and corrective actions.
- Integrating improvements into the ISMS.
Summary and Next Steps
Requirements
- Understanding of information security management concepts.
- Familiarity with ISO/IEC 27001 or related standards.
- Practical experience in IT security or incident response roles.
Target Audience
- Information security officers and managers.
- Incident response team leaders.
- Risk and compliance professionals.
Testimonials (4)
Theory followed by practical examples and exercices. Job well done!
Vincenzo Delle Donne - Department of National Defence
Course - ISO 37301 Compliance Management System
the expertise & knowledge of the trainer
Erica DeRosa DeRosa - Aecon Group INc.
Course - ISO 37001 Anti-Bribery Management System
With both my 2022 ISO 9001 audit prep-related training & the recently completed ISO 9001 audit prep refresher course; Dereck has helped me significantly with regards to gaining a new & practical perspective of the ISO 9001:2015 clauses & sections & how they apply to our business. Dereck has also helped me with both training courses --- to improve my ISO-related communications both with our company's employees and the external ISO Auditors .
Dana Foster - Corrigan Oil Company
Course - ISO 9001 Foundation
The quizzes to reinforce the reading and the ability to ask questions at any time