Special offers now — see discounted courses.
day
:
hour
:
min
:
sec
See special offers
Certified Information Security Manager (CISM) Cert Prep (2022): 4 Incident Management

Certified Information Security Manager (CISM) Cert Prep (2022): 4 Incident Management

2h 21mAdvanced2022-09-08

Authors

Mike Chapple

Mike Chapple

Teaching Professor at the University of Notre Dame

Course details

Even the best security controls aren't foolproof. That's why security professionals need a solid incident management plan. The fourth domain of the Certified Information Security Manager (CISM) exam—Information Security Incident Management—tests your mastery of this important topic. Take this CISM Cert Prep course to study for the exam and gain a deeper understanding of how your team should react to and resolve a security incident, whether it's an attack on your network, an email-born virus, or data theft. Instructor Mike Chapple explains how to identify, triage, and respond to an event, minimizing the damage and maximizing your ability to find the root cause, so you can resume normal operations. He also provides tips for logging and monitoring ongoing security-related events. Each topic maps to a relevant objective from the CISM certification exam.

Skills covered

Governance, Risk, and ComplianceDevOps FoundationsDevOpsCybersecurityCert Prep

Concepts

0. Introduction

  • 01 - Incident management
  • 02 - What you need to know
  • 03 - Study resources

1. Incident Response

  • 04 - Role of a manager in incident response
  • 05 - Creating an incident response team

2. Assessing Incidents

  • 06 - Identifying and classifying security incidents
  • 07 - Threat classification
  • 08 - Zero days and the advanced persistent threat
  • 09 - Determining incident severity

3. Incident Response Process

  • 10 - Build an incident response program
  • 11 - Incident communications plan
  • 12 - Incident identification
  • 13 - Escalation and notification
  • 14 - Mitigation
  • 15 - Containment techniques
  • 16 - Incident eradication and recovery
  • 17 - Validation
  • 18 - Post-incident activities
  • 19 - Incident response exercises

4. Incident Symptoms

  • 20 - Network symptoms
  • 21 - Rogue access points and evil twins
  • 22 - Endpoint symptoms
  • 23 - Application symptoms

5. Forensic Investigations

  • 24 - Conducting investigations
  • 25 - Evidence types
  • 26 - Introduction to forensics
  • 27 - System and file forensics
  • 28 - File carving
  • 29 - Creating forensic images
  • 30 - Digital forensics toolkit
  • 31 - Operating system analysis
  • 32 - Password forensics
  • 33 - Network forensics
  • 34 - Software forensics
  • 35 - Mobile device forensics
  • 36 - Embedded device forensics
  • 37 - Chain of custody
  • 38 - Ediscovery and evidence production
  • 39 - Exploitation frameworks

6. Logging and Monitoring

  • 40 - Security information and event management
  • 41 - Continuous security monitoring

Conclusion

  • 42 - Continuing your studies

About us

LyndaKade is a leading learning platform that helps people learn business, software, technology, and creative skills to achieve personal and professional goals.

Phone numberAparat ChannelTelegram SupportTelegram ChannelInstagram Page

All rights to this site belong to LyndaKade.

Terms of Service|Privacy Policy

نماد الکترونیک enamad در صورت اتصال با آی‌پی داخل کشور، نمایش داده خواهد شد.
logo-samandehi - لوگو ساماندهی
Zarinpal
Zibal