|
AUDIENCE
- new CSIRT technical staff (one to three months of experience)
- experienced CSIRT staff who would like to benchmark their CSIRT processes and skill sets against best practices
- anyone who would like to learn about basic incident handling functions and activities
PREREQUISITES
Before registering for this course, participants must be familiar with Internet services and protocols.
It is recommended but not required that participants have some experience with system administration for Windows or UNIX systems.
TOPICS
- understanding the CSIRT environment and basic incident management processes
- CSIRT code of conduct
- understanding security tools and technologies used by CSIRTs
- identifying and gathering critical information
- recognizing signs of attacks
- detecting and analyzing incidents
- finding contact information
- coordinating response and disseminating information
- handling email and malicious code attacks
- working with law enforcement
OBJECTIVES
This course will help participants to
- recognize the importance of following well-defined processes, policies, and procedures
- understand the technical, communication, and coordination issues involved
in providing a CSIRT service
- critically analyze and assess the impact of computer security incidents
- effectively build and coordinate response strategies for various types of computer security incidents
Course Materials Participants will receive a course notebook and a CD containing the course materials.
LOGISTICS
Class Schedule This five-day course meets at the following times:
Days 1-5, 9:00 a.m.-5:00 p.m.
Hotel and Travel Information
Information about traveling to the SEI offices is available on our Travel and Lodging Web pages.
Questions about this course?
Please see our Frequently Asked Questions Web page for answers to some of the more common inquiries about SEI Education and Training.
If you need more information, contact us via e-mail at training-info@cert.org
or telephone at +1 412-268-9564.
|