ISO/IEC 27035. Information security incident management

所在平台: Udemy

课程主页: https://www.udemy.com/course/isoiec-27035-information-security-incident-management/

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:ISO/IEC 27035 信息安全事件管理 课程概述:在当今的网络环境中,信息安全事件已经成为普遍现象,任何规模的组织都可能成为攻击的受害者。仅依靠安全控制和政策无法完全保障信息、网络、系统或服务的安全,因为始终存在可能被威胁利用的残余漏洞。此外,新的、之前未被识别的威胁也会导致事件的发生。信息安全事件的后果可能从对正常操作的轻微干扰到整个组织的崩溃。缺乏应对事件的准备会降低组织的应对有效性,增加潜在的不利业务后果。因此,每个公司设计和实施一个强有力的信息安全计划是必要的,其中一部分需要专门用于事件处理。本课程提供了ISO/IEC 27035关于信息安全事件管理的指南,提出了一个包括五个阶段的过程: 1. 计划与准备:制定计划和政策,提供培训和意识,识别和配置必要资源,建立表单和组织结构,例如事件管理团队和事件响应团队; 2. 检测与报告:识别和报告信息安全事件; 3. 评估与决策:根据对组织的影响对事件进行分类,并分析以判断最合适的应对解决方案; 4. 应对:首先控制事件,然后消除影响,最后恢复受影响的系统和服务; 5. 经验教训:利用在事件处理过程中收集的信息来改进流程、安全控制和组织流程。 课程中每个事件管理过程的五个步骤都有专门的内容,并结合实例和案例研究,帮助学习者更有效和愉悦地掌握知识。通过参与此课程,您将理解事件管理的概念和工具,学习如何对信息安全事件进行分类和分析,提高在信息安全管理领域的技能,并能够自信地申请事件经理认证。您可以利用本课程中的信息来设计或改进公司管理信息安全事件的流程,还可以将其作为咨询服务或审计目的的支持工具,甚至利用本课程推进您的信息安全管理职业发展。

课程评论(0条)

课程详情

Information security incidents have become a common occurrence in today's landscape, where every organization, regardless of its size or dependence on IT & C, can be the victim of an attack.Security controls and policies alone cannot guarantee a total protection of information, networks, systems or services, because there will always be residual vulnerabilities that may be exploited by threats, leading to information security incidents. Furthermore, it is inevitable that new instances of previously unidentified threats cause incidents to occur.The consequences of an information security incident can go from minor disturbances to the regular operations, up to the collapse of the entire organization. The insufficient preparation to deal with incidents will make the response of the organization less effective and will increase the degree of potential adverse business consequences. Therefore, it is mandatory for each company to design and to implement a robust information security programme, with a key part of that programme dedicated to the handling of incidents.This course presents the guidelines for managing information security incidents provided by ISO/IEC 27035. This international standard proposes a process that includes 5 phases:- plan and prepare where plans and policies are developed, training and awareness are provided, the necessary resources are identified and made available, forms are established and organizational structures, such as the incident management team and the incident response team are set up;- detect and report, where information security events are identified, reported;- assess and decide, where incidents are categorized based on their impact on the organization and analyzed to determine the most suitable solutions for the response;- respond, where the incident is contained first, then eradicated and in the end the systems and services affected by the incident are recovered; and- learn lessons, where the organization uses the information collected while handling incidents to improve its process, its security controls and organizational processes.A section of the course is dedicated to each of the five steps of the incident management process and along the way there are examples and case studies to make your learning journey more useful and pleasant.By participating in this course you will understand the concepts and tools of incident management; you will learn about how to categorize and analyze information security incidents; you will improve your skills in the information security management field and you can confidently apply for a certification as incident manager.You can use the information in this course to design or to improve your company's processes for managing information security incidents. You can use the course as support for your consulting services or for auditing purposes. Or, you can use this course as a method to advance your career in information security management.

课程标签

0人关注该课程

主题相关的课程