Software Engineering Institute Carnegie Mellon

Course Offerings
Prices
Locations, Travel, and Lodging
Courses FAQ
Privacy Information (FERPA)
Registration
Contact Information
Credentials Program
SEI Certification

Creating a Computer Security Incident Response Team

Dates

2008* Prices (USD)

2008 Dates
February 12, 2008 (SEI Frankfurt, Germany)
March 4, 2008 (CMU/CIC Bldg. Pittsburgh, PA)
May 6, 2008 (CMU/CIC Bldg. Pittsburgh, PA)
July 22, 2008 (SEI Arlington, VA)
October 14, 2008 (SEI Arlington, VA)

Course Registration
Software Engineering Institute
Carnegie Mellon University
Pittsburgh, PA 15213-3890
Phone: 412 / 268-7388
FAX: 412 / 268-7401
Questions: courseregistration@sei.cmu.edu

To Register: 2008 Click Here

This course may also be offered by arrangement at customer sites. E-mail training-info@cert.org or call +1 412-268-9564 for details.

*Course dates and fees are subject to change.

U.S.
Course Fee:
Industry: $600
Government: $480
Academic: $480

International
Course Fee:
$1000


   Register for
2008 Dates

Course Description

 

This one-day course is designed for managers and project leaders who have been tasked with implementing a computer security incident response team (CSIRT). This course provides a high level overview of the key issues and decisions that must be addressed in establishing a CSIRT. As part of the course, attendees will develop an action plan that can be used as a starting point in planning and implementing their CSIRT.

The course is composed of lectures and class exercises. Participants will learn the requirements for establishing an effective CSIRT, the various organizational models for a CSIRT, and the variety and level of services that can be provided by a CSIRT. Additionally, attendees will identify policies and procedures that should be established and implemented when creating a CSIRT.

Attendees may also want to register for the three-day companion course, Managing Computer Security Incident Response Teams, which is scheduled immediately following the Creating a CSIRT course.

Audience   ·    Prerequisites    ·    Objectives   ·    Logistics

 

AUDIENCE

  • current and prospective CSIRT managers; C-level managers such as CIOs, CSOs, CROs; and project leaders interested in establishing or starting a CSIRT
  • other staff who interact with CSIRTs and would like to gain a deeper understanding of how CSIRTs operate. For example, CSIRT constituents; higher-level management; media relations, legal counsel, law enforcement, human resources, audit, or risk management staff

PREREQUISITES
There are no prerequisites for this course.

TOPICS

  • incident management and the relationship to CSIRTs
  • prerequisites to planning a CSIRT
  • creating a CSIRT vision
  • CSIRT mission, objectives, and level of authority
  • CSIRT organizational issues and models
  • range and levels of provided services
  • funding issues
  • hiring and training initial CSIRT staff
  • implementing CSIRT policies and procedures
  • requirements for a CSIRT infrastructure
  • implementation and operational issues and strategies
  • collaboration and communication issues

OBJECTIVES
This course will help participants to

  • understand the requirements for establishing an effective CSIRT
  • strategically plan the development and implementation of a new CSIRT
  • highlight issues associated with assembling a responsive, effective team of computer security professionals
  • identify policies and procedures that should be established and implemented
  • understand various organizational models for a new CSIRT
  • understand the variety and level of services that can be provided by a CSIRT

Course Materials
Participants will receive a course notebook, CSIRT action plan, and a CD containing the course materials.

LOGISTICS

Class Schedule
This one-day course meets at the following times:
9:00 a.m.-5:00 p.m.

Hotel and Travel Information
Information about traveling to the SEI offices is available on our
Travel and Lodging Web pages.

Questions about this course?
Please see our Frequently Asked Questions Web page for answers to some of the more common inquiries about SEI Education and Training.

If you need more information, contact us via e-mail at training-info@cert.org or telephone at +1 412-268-9564.



 

 

Related Products and Services

 

Courses
Managing Computer Security Incident Response Teams
Fundamentals of Incident Handling
Advanced Incident Handling
Information Security for Technical Staff
Information Security for Network Managers
Computer Forensics for Technical Staff

Publications
Defining Incident Management Processes for CSIRTs
The Critical Success Factor Method: Establishing a Foundation for Enterprise Security Management
Handbook for Computer Security Incident Response Teams (CSIRTs), Second Edition
Organizational Models for CSIRTs Handbook
State of the Practice of CSIRTs
Outsourcing Managed Security Practices
Insider Threat Study: Illicit Cyber Activity in the Banking and Finance Sector
Insider Threat Study: Computer System Sabotage in Critical Infrastructure Sectors
National CSIRTs
Staffing Your CSIRT: Basic Skill Set
Challenges of Security Management
Governing for Enterprise Security
Managing for Enterprise Security
First Responders Guide to Computer Forensics

Events
Annual Computer Security Incident Handling Conference

Other Related Information
CSIRT Development Information
CERT-Certified Incident Handler Certification
CERT Training and Education

Course Registration

 

  Register for 2008 Dates
 

^
TOP