Software Engineering Institute Carnegie Mellon

Course Offerings
Prices
Locations, Travel, and Lodging
Courses FAQ
Privacy Information (FERPA)
Registration
Contact Information
Credentials Program
SEI Certification

Managing Computer Security Incident Response Teams

Dates

2008* Prices (USD)

2008 Dates
February 13-15, 2008 (SEI Frankfurt, Germany)
March 5-7, 2008 (CMU/CIC Bldg. Pittsburgh, PA)
May 7-9, 2008 (CMU/CIC Bldg. Pittsburgh, PA)
July 23-25, 2008 (SEI Arlington, VA)
October 15-17, 2008 (SEI Arlington, VA)

Course Registration
Software Engineering Institute
Carnegie Mellon University
Pittsburgh, PA 15213-3890
Phone: 412 / 268-7388
FAX: 412 / 268-7401
Questions: courseregistration@sei.cmu.edu

To Register: 2008 Click Here

This course may also be offered by arrangement at customer sites. E-mail training-info@cert.org or call +1 412-268-9564 for details.

*Course dates and fees are subject to change.

U.S.
Course Fee:
Industry: $1575
Government: $1250
Academic: $1250

International
Course Fee:
$3150


   Register for
2008 Dates

Course Description

 

This three-day course provides current and future managers of computer security incident response teams (CSIRTs) with a pragmatic view of the issues that they will face in operating an effective team.

The course provides insight into the type and nature of the work that CSIRT staff may be expected to handle. The course also provides prospective or current managers with an overview of the incident handling process and the types of tools and infrastructure needed to be effective.

Technical issues are discussed from a management perspective. Topics include hiring CSIRT staff, identifying critical information, publishing information, establishing effective working relationships, working with law enforcement, evaluating CSIRT operations, building CSIRT service capacity, and the importance of pre-established policies and procedures.

The course incorporates interactive instruction, exercises, and role playing. During a simulated incident, attendees will gain experience with the type of decisions they might face on a regular basis.

Before attending this course, participants are encouraged to attend the companion course, Creating a Computer Security Incident Response Team. This course is offered the day before the Managing CSIRTs course.

Note: There is some content overlap between the Managing CSIRTs course and the Fundamentals of Incident Handling course. We recommend that attendees register for one course or the other, but not both. The Fundamentals of Incident Handling course covers more technical topics such as email and malware attacks. The Fundamentals of Incident Handling course is designed to introduce new incident handlers to the basic skills and processes they will need to perform incident handling work. The Managing CSIRTs course focuses on incident handling issues from an operational management perspective and discusses best practices in sustaining an effective operation.

Audience   ·    Prerequisites    ·    Objectives   ·    Logistics

 

AUDIENCE

  • managers who are interested in implementing or are required to implement a CSIRT
  • managers who have responsibility or must work with those who do have responsibility for computer security incident and management activities
  • managers who have experience in incident handling and want to learn more about operating effective CSIRTs
  • other staff who interact with CSIRTs and would like to gain a deeper understanding of how CSIRTs operate. For example, CSIRT constituents; higher-level management; media relations, legal counsel, law enforcement, human resources, audit, or risk management staff.

PREREQUISITES
There are no prerequisites for this course; however, prospective attendees may wish to consider attending the Creating a CSIRT one-day class (usually scheduled the day before the Managing CSIRTs course).

TOPICS

  • incident management process
  • hiring and mentoring CSIRT staff
  • developing CSIRT policies and procedures
  • requirements for developing CSIRT services
  • handling media issues
  • building and managing the CSIRT infrastructure
  • coordinating response
  • handling major events
  • working with law enforcement
  • evaluating CSIRT operations
  • incident management capability metrics

OBJECTIVES
This course will help participants to

  • recognize the importance of establishing well-defined policies and procedures for incident management processes
  • identify policies and procedures that should be established and implemented for a CSIRT
  • understand incident management activities, including the types of activities and interactions that a CSIRT may perform
  • learn about various processes involved in detecting, analyzing, and responding to computer security events and incidents
  • identify key components needed for protecting and sustaining CSIRT operations
  • manage a responsive, effective team of computer security professionals
  • evaluate CSIRT operations and identify performance gaps, risks, and needed improvements

Course Materials
Participants will receive a course notebook and a CD containing the course materials.

LOGISTICS

Class Schedule
This three-day course meets at the following times:
Days 1-3, 9:00 a.m.-5:00 p.m.

Hotel and Travel Information
Information about traveling to the SEI offices is available on our
Travel and Lodging Web pages.

Questions about this course?
Please see our Frequently Asked Questions Web page for answers to some of the more common inquiries about SEI Education and Training.

If you need more information, contact us via e-mail at training-info@cert.org or telephone at +1 412-268-9564.



 

 

Related Products and Services

 

Courses
Creating a Computer Security Incident Response Team
Fundamentals of Incident Handling
Advanced Incident Handling
Information Security for Technical Staff
Information Security for Network Managers
Computer Forensics for Technical Staff

Publications
Defining Incident Management Processes for CSIRTs
The Critical Success Factor Method: Establishing a Foundation for Enterprise Security Management
Handbook for Computer Security Incident Response Teams (CSIRTs), Second Edition
Organizational Models for CSIRTs Handbook
State of the Practice of CSIRTs
Outsourcing Managed Security Practices
Insider Threat Study: Illicit Cyber Activity in the Banking and Finance Sector
Basic Skills Set
Insider Threat Study: Computer System Sabotage in Critical Infrastructure Sectors Attack Trends
National CSIRTs
Challenges of Security Management
Governing for Enterprise Security
Managing for Enterprise Security
How the FBI Investigates
First Responders Guide to Computer Forensics

Events
Annual Computer Security Incident Handling Conference, sponsored by FIRST.ORG, Inc.

Other Related Information
CERT Training and Education
CERT-Certified Incident Handler Certification

Course Registration

 

  Register for 2008 Dates
 

^
TOP