Strategies for Computer Security Incident Response Team (CSIRT)

Strategies for Computer Security Incident Response Team (CSIRT)

1h 30mIntermediate2024-12-20

Authors

Viktor Hedberg

Viktor Hedberg

Course details

In spite of all the options available on the market today, basic security hygiene is still one of the best ways to prevent a potentially devastating breach or attack. In this course, designed uniquely for cybersecurity and IT professionals, instructor Viktor Hedberg covers the essentials of working on a Computer Security Incident Response Team (CSIRT), highlighting some of the most important topics relevant to the role. Discover the core concepts and strategies used by a successful CSIRT such as network segmentation, using the correct tool for the correct job, administrative tiering, Active Directory, Entra ID, and more. Along the way, Viktor shows you how to secure both your data center and your backup solution.

Skills covered

Incident ResponseFoundationsCybersecurity

Concepts

Introduction

  • CSIRT strategies

Computer Security Incident Response (CSIRT) Basics

  • Antivirus and endpoint detection and response (EDR)
  • Lack of monitoring
  • Spreading credentials

Implementing Administrative Tiering in Active Directory

  • Why is Active Directory tiering important
  • Implement Active Directory tiering

Implementing Administrative Tiering in Entra ID and Azure

  • Why Entra ID tiering is important
  • Entra ID and Azure tiering 101

Network Segmentation

  • Next generation firewalls
  • Virtual private networks
  • Why network segmentation is super important

Backup Architecture

  • Issues with agent-based backup
  • Ideal backup architecture

Securing the Modern Data Center

  • Direct and indirect administrators
  • Separating data center from workload

Using the Right Tool for the Job

  • Windows LAPS (Local Administrator Password Solution) vs. RDP (Remote Desktop Protocol)
40,000 Toman