Course Outline
Introduction to ISO/IEC 27035
- Overview of the components and structure of ISO/IEC 27035 parts
- Correlation with ISO/IEC 27001 and other relevant standards
- Essential terminology, definitions, and foundational concepts
Principles of Incident Management
- Comprehending threats, vulnerabilities, and associated risks
- Categorizing and classifying incidents
- Stages of the incident lifecycle
Planning an Incident Management Program
- Establishing scope and strategic objectives
- Defining roles, responsibilities, and escalation procedures
- Formulating incident response policies and procedural guidelines
Detection and Reporting of Incidents
- Identifying indicators of compromise and early warning signals
- Utilizing internal and external reporting channels
- Maintaining accurate incident logs and records
Analysis and Evaluation of Incidents
- Collection and preservation of digital evidence
- Techniques for conducting root cause analysis
- Assessing impact and evaluating associated risks
Response, Containment, and Recovery
- Strategies for containment and effective communication
- Eradication of threats and remediation of vulnerabilities
- Restoring systems and validating integrity
Post-Incident Activities and Continual Improvement
- Comprehensive incident reporting and documentation
- Extracting lessons learned and implementing corrective actions
- Integrating enhancements into the ISMS framework
Summary and Next Steps
Requirements
- Working knowledge of information security management concepts
- Familiarity with ISO/IEC 27001 or equivalent standards
- Practical experience in IT security or incident response positions
Target Audience
- Information security officers and management staff
- Leaders of incident response teams
- Professionals specializing in risk management and compliance
Testimonials (4)
Theory followed by practical examples and exercices. Job well done!
Vincenzo Delle Donne - Department of National Defence
Course - ISO 37301 Compliance Management System
the expertise & knowledge of the trainer
Erica DeRosa DeRosa - Aecon Group INc.
Course - ISO 37001 Anti-Bribery Management System
I enjoyed the quizzes, and Driton's style of teaching.
Chloe - SEEC MM Ltd.,
Course - ISO 9001 Lead Implementer
With both my 2022 ISO 9001 audit prep-related training & the recently completed ISO 9001 audit prep refresher course; Dereck has helped me significantly with regards to gaining a new & practical perspective of the ISO 9001:2015 clauses & sections & how they apply to our business. Dereck has also helped me with both training courses --- to improve my ISO-related communications both with our company's employees and the external ISO Auditors .