Incident Response Planning

Incident Response Planning

5h 38mBeginner2023-02-22

Authors

Jason Dion

Jason Dion

Cybersecurity Trainer at Dion Training Solutions

Course details

If your organization is the victim of a cyberattack, are you ready to respond? In this course, cybersecurity trainer Jason Dion teaches you how to create, provision, and operate a formal, effective incident response capability within your organization to minimize the damage a cyberattack could cause. Jason guides you through incident response planning, including events, incidents, policies, plans, and procedures. He covers gathering and training your incident response team, as well as establishing and maintaining needed communications. Jason guides you through preparing for an incident and explains how to detect and analyze an incident. Plus, he goes over containment, eradication, recovery, and post-incident activities. Jason fully covers the guidance provided in the NIST SP 800-61, as well as recommendations based upon practical experience from the field.

Skills covered

Incident ResponseCybersecurityDeep Dive (X:Y)

Concepts

Introduction

  • Overview
  • Why do you need a plan
  • Lifecycle of an incident response
  • Review - Introduction

Incident Response Planning

  • Incident response planning
  • Events and incidents
  • Policy, plans, and procedures
  • Policy elements
  • Plan elements
  • Procedure elements
  • Review - Incident response planning

Incident Response Team

  • Incident response team
  • Incident response team structure
  • Types of teams
  • Selecting a team model
  • Team members
  • Leading a team
  • Organizational dependencies
  • Review - Incident response team

Communication

  • Communication
  • Coordinating your efforts
  • Internal information sharing
  • Business impact analysis
  • Technical analysis
  • External information sharing
  • Review - Communication

Preparation

  • Preparation
  • Communications and facilities
  • Hardware and software
  • Technical resources and information
  • Software resources
  • Incident prevention
  • Review - Preparation

Detection and Analysis

  • Detection and analysis
  • Attack vectors
  • Detecting an incident
  • Indicators of compromise
  • Conducting analysis
  • Documenting the incident
  • Prioritizing the incident
  • Notification procedures
  • Review - Detection and analysis

Containment, Eradication, and Recovery

  • Containment, eradication, and recovery
  • Containment strategy
  • Evidence collection and handling
  • Identifying the attacker
  • Eradication and recovery
  • Review - Containment, eradication, and recovery

Post-Incident Activity

  • Post-incident activity
  • Lessons learned
  • Metrics and measures
  • Evidence retention
  • Calculating the cost
  • Review - Post-incident activity

Conclusion

  • What to do next
100,000 Toman