|
所在平台: Coursera |
课程主页: https://www.coursera.org/learn/stages-of-incident-response
课程评论:没有评论
课程名称:事件响应阶段 课程概述:网络事件响应课程将使学生了解在高层次上如何响应事件,并通过实操实验室和项目建立重要的技术技能。课程开始时,讨论响应事件各个阶段的高层内容,接着深入探讨内存、网络和主机分析及取证中一些更具吸引力的部分。本课程适合任何希望将所学取证和攻击性知识(如道德黑客)应用于事件响应过程的人。 课程大纲: 1. **准备阶段(Preparation)** 本模块详细介绍了常见定义和严重性标准,特别强调学生需要理解严重性标准应基于组织的总体定义和程序。模块后期探讨了资产清单和识别的重要性,以此为基础建立严重性标准,这些都是为任何事件做出适当准备所必需的内容。 2. **事件响应:识别(Incident Response: Identification)** 此阶段专注于事件的识别,以及事件可能分类的级别。同时提醒学生,这些分类级别需由高层管理和其他组织成员提供意见。详细讲解事件通知的适当方式,并讨论常用工具和技术。 3. **事件响应:遏制(Incident Response: Containment)** 本部分探讨事件的遏制及其适当的范围和管理。分析如何遏制事件及定义遏制的含义,并介绍常见的遏制工具。 4. **事件响应:调查(Incident Response: Investigation)** 在调查环节,学习正常调查中需要提出的问题以及如何妥善回答这些问题。探讨数据来源和该过程在整体事件响应中的角色。 5. **事件响应:消除(Incident Response: Eradication)** 深入了解在威胁被遏制后如何清除环境中的威胁,以及如何验证威胁已被消除,并通知其他授权方。最后,讨论一些常用的消除工具。 6. **事件响应:恢复(Incident Response: Recovery)** 恢复阶段展示了如何在此阶段直接与业务连续性和灾难恢复相结合。讲解如何以最小干扰和最高效的方式恢复系统,并定义“恢复”的标准。 7. **后续/经验教训(Follow Up/Lessons Learned)** 着重验证和签署恢复的有效性,评估团队响应的效果。还探讨了实施必要改进的方法,以及如何从组织内部或外部获取反馈。 此课程旨在为参与者提供全面的事件响应知识和实践技能,使其能够有效应对各种网络安全事件。
Name:Stages of Incident Response
Description:The Preparation section of the module goes into some detail with common definitions and severity criteria, with special attention being paid to making sure the student understands that the severity criteria should be based on overall organizational definitions and procedures. The latter part of the module goes into the importance of asset inventory and identification as a basis for establishing severity criteria. All these pieces are required for proper preparation for any incident.
Name:Incident Response: Identification
Description:The Identification section deals specifically with how incidents are identified, as well as the classification levels that incidents might fall within. It also reminds the student that these classification levels are established with input from upper management and the rest of the organization. We go into details of notifying the appropriate parties of the incident and how to do that properly. We end this course with a discussion of common tools and techniques.
Name:Incident Response: Containment
Description:This section explores containment and the proper scoping and management of it. We examine the details of how to contain an incident and, more importantly, how to define what containment means. We also explore common containment tools.
Name:Incident Response: Investigation
Description:In the Investigation segment, you’ll learn the questions asked in normal investigations and how to properly answer them. You’ll explore the important data sources these answers are pulled from and the role this process plays in incident response overall.
Name:Incident Response: Eradication
Description:Dive into what it takes to remove threats from and environment after the threat has been contained. We’ll also take a look at how to verify the threat has been eradicated and address proper notification of eradication to other authorized parties. Lastly, we’ll discuss some common tools for eradication.
Name:Incident Response: Recovery
Description:This Recovery segment shows how we tie directly into business continuity and disaster recovery at this phase. We deal with how to restore systems in the least disruptive and most efficient way, as well as defining what constitutes "recovered."
Name:Follow Up/Lessons Learned
Description:Look at validation and sign-off of recovery. The module looks at how to effectively assess how well the team responded. It also looks at implementing needed improvements and how to ingest feedback from the rest of the organization or even outside organizations.
The Cyber Incident Response course will give students an understanding of how incidents are responded to at a high level, as well as allow them to build important technical skills through the hands-on labs and projects. This course starts with a high-level discussion of what happens at each phase of responding to an incident, followed by a technical deep dive into some of the more exciting parts of memory, network, and host analysis and forensics. This course is for anyone wishing to apply learned forensics and offensive knowledge such as ethical hacking to the incident response process.