Threat intelligence and incident management Course

2 hours, 26 minutes

Syllabus

Establish and maintain an incident handling and investigation program: Doing root cause analysis

Video - 00:07:00

During the eradication phase, determine the root cause of the incident.
Establish and maintain an incident handling and investigation program: Quantifying and reporting on the financial and operational impact of incidents

Video - 00:07:00

Determine the financial and operational impact of incidents and report to the appropriate stakeholder.
Establish and maintain an incident handling and investigation program: Establishing and maintaining the investigation process

Video - 00:25:00

Implement an investigation process.
Establish and maintain an incident handling and investigation program: Establishing and maintaining the incident handling process

Video - 00:07:00

Implement an incident handling process.
Establish and maintain an incident handling and investigation program: Applying incident management methodologies

Video - 00:06:00

Identify and integrate IR management methodologies.
Establish and maintain an incident handling and investigation program: Establishing an Incident Response Team (IRT)

Video - 00:06:00

Identify the IRT members.
Establish and maintain an incident handling and investigation program: Establishing an incident response case management process

Video - 00:10:00

Establish an IR management process.
Establish and maintain an incident handling and investigation program: Develop incident management program documentation

Video - 00:09:00

Document the IR program.
Developing and managing a threat intelligence program: Creating actionable alerting to the appropriate responders/resources

Video - 00:09:00

Set KRIs to report as alerts on anomalous activity.
Developing and managing a threat intelligence program: Correlating security event and threat data

Video - 00:06:00

Match security events with captured threat data.
Developing and managing a threat intelligence program: Identifying and categorizing attacks

Video - 00:08:00

Analyze and categorize attacks.
Developing and managing a threat intelligence program: Doing threat modeling

Video - 00:13:00

Identify a threat modeling program for the organization and then implement it.
Developing and managing a threat intelligence program: Detecting and analyzing anomalous behavior patterns

Video - 00:06:00

Analyzing any anomalous activity on the network, user or data movement activities.
Developing and managing a threat intelligence program: Conducting baseline analysis of network traffic, user and data movement behavior

Video - 00:05:00

Establishing a baseline of network, user and data movement behavior for analytics.
Developing and managing a threat intelligence program: Assembling threat data from multiple sources

Video - 00:11:00

Merging threat data from all internal and external sources available to the organization.
Introduction to threat intelligence and incident management

Video - 00:03:00

This is an introduction to Domain 4 of ISSMP.
ISSMP Domain 4 Practice Exam

Assessment - 12 questions

Unlock 7 days of free training

  • 1,400+ hands-on courses and labs
  • Certification practice exams
  • Skill assessments

Plans & pricing

Infosec Skills Personal

$299 / year

  • 190+ role-guided learning paths (e.g., Ethical Hacking, Threat Hunting)
  • 100s of hands-on labs in cloud-hosted cyber ranges
  • Custom certification practice exams (e.g., CISSP, Security+)
  • Skill assessments
  • Infosec peer community support

Infosec Skills Teams

$799 per license / year

  • Team administration and reporting
  • Dedicated client success manager
  • Single sign-on (SSO)
    Easily authenticate and manage your learners by connecting to any identity provider that supports the SAML 2.0 standard.
  • Integrations via API
    Retrieve training performance and engagement metrics and integrate learner data into your existing LMS or HRS.
  • 190+ role-guided learning paths and assessments (e.g., Incident Response)
  • 100s of hands-on labs in cloud-hosted cyber ranges
  • Create and assign custom learning paths
  • Custom certification practice exams (e.g., CISSP, CISA)
  • Optional upgrade: Guarantee team certification with live boot camps

Learn about scholarships and financing with

Affirm logo

Award-winning training you can trust