Strategies for Computer Security Incident Response Team (CSIRT)
1h 30mIntermediate2024-12-20
Authors

Viktor Hedberg
Course details
In spite of all the options available on the market today, basic security hygiene is still one of the best ways to prevent a potentially devastating breach or attack. In this course, designed uniquely for cybersecurity and IT professionals, instructor Viktor Hedberg covers the essentials of working on a Computer Security Incident Response Team (CSIRT), highlighting some of the most important topics relevant to the role. Discover the core concepts and strategies used by a successful CSIRT such as network segmentation, using the correct tool for the correct job, administrative tiering, Active Directory, Entra ID, and more. Along the way, Viktor shows you how to secure both your data center and your backup solution.
Skills covered
Incident ResponseFoundationsCybersecurity
Concepts
Introduction
- CSIRT strategies
Computer Security Incident Response (CSIRT) Basics
- Antivirus and endpoint detection and response (EDR)
- Lack of monitoring
- Spreading credentials
Implementing Administrative Tiering in Active Directory
- Why is Active Directory tiering important
- Implement Active Directory tiering
Implementing Administrative Tiering in Entra ID and Azure
- Why Entra ID tiering is important
- Entra ID and Azure tiering 101
Network Segmentation
- Next generation firewalls
- Virtual private networks
- Why network segmentation is super important
Backup Architecture
- Issues with agent-based backup
- Ideal backup architecture
Securing the Modern Data Center
- Direct and indirect administrators
- Separating data center from workload
Using the Right Tool for the Job
- Windows LAPS (Local Administrator Password Solution) vs. RDP (Remote Desktop Protocol)