|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/isoiec-270352023-incident-management-step-by-step/
课程评论:没有评论
## ISO/IEC 27035:2023 - 事件管理分步详解 (Coursera 课程总结) 本课程旨在帮助您系统地理解并实施 ISO/IEC 27035:2023 标准,建立一个有效的、可复用的信息安全事件管理框架。无论您是管理企业安全运营中心 (SOC) 还是负责小型云工作负载安全,本课程都将提供实用的指导和模板。 **核心内容涵盖:** * **ISO 27035:2023 生命周期解析:** 详细讲解标准的六个阶段:准备 (Preparation)、检测与报告 (Detection & Reporting)、评估与决策 (Assessment & Decision)、响应 (Response)、经验教训 (Lessons Learned) 和持续改进 (Continual Improvement)。 * **现实威胁场景映射:** 将标准生命周期与现实世界威胁(如网络钓鱼、勒索软件、云配置错误、内部人员滥用等)相结合,加深理解。 * **策略与团队建设:** 指导您构建符合 ISO 27001 附录 A 控制的事件响应策略,定义计算机安全事件响应团队 (CSIRT) 的角色,并建立符合合规性和业务风险偏好的升级阈值。 * **实用的检测技术:** 深入介绍日志关联、SIEM 规则、端点遥测和威胁情报源等检测方法。 * **动手实践操作:** 通过演示,教您如何配置事件记录、应用严重性分类、启动遏制剧本 (playbooks) 以及维护可审计的证据链。 * **关键要素的深入讨论:** * **证据保全:** 强调在事件处理过程中证据的完整性和合法性。 * **法规通报:** 涵盖向相关监管机构进行通报的要求。 * **跨部门协作:** 指导如何与人力资源、法律和公关等部门协同合作。 * **事故后复盘:** 教授如何进行“无指责”的事故后审查,提炼可衡量的经验教训,并将其纳入漏洞管理和安全意识培训等项目中。 * **与现有框架的集成:** 演示如何将 ISO 27035 与 NIST CSF 或 CIS Controls 等其他安全框架集成。 * **审计与合规性:** 帮助您向审计员和管理层展示持续改进的能力。 **学习目标:** 完成课程后,您将能够: * 快速实施符合 ISO 27035 标准的事件响应流程。 * 可靠地检测和分类安全事件。 * 为快速遏制事件激活相应的剧本。 * 协调证据收集和法规报告。 * 系统性地进行事件复盘并推动持续改进。 **先决条件:** 无需事先的审计经验,只需具备信息安全基础知识。 **立即加入,将混乱的安全事件管理转化为有条理、以数据驱动的流程,显著提升您组织的抗网络攻击能力!**
Modern organizations can no longer afford ad-hoc reactions to security breaches. ISO/IEC 27035:2023 delivers a proven, structured framework for detecting, assessing, and resolving information-security incidents-then turning every event into actionable improvement. This step-by-step Udemy course translates the standard's requirements into plain English, hands-on templates, and repeatable practices that you can use immediately, whether you manage enterprise SOC operations or secure a small cloud workload.We begin by mapping the ISO 27035:2023 lifecycle-Preparation, Detection & Reporting, Assessment & Decision, Response, Lessons Learned, and Continual Improvement-to real-world threats such as phishing, ransomware, cloud misconfigurations, and insider misuse. You will learn how to build an incident-response policy aligned with ISO 27001 Annex A controls, define roles for your Computer Security Incident Response Team (CSIRT), and establish escalation thresholds that meet both compliance and business-risk appetites.Next, we dive into practical detection techniques: log correlation, SIEM rules, endpoint telemetry, and threat-intel feeds. Through narrated demos you will configure an incident record, apply severity classification, launch containment playbooks, and maintain an auditable chain of custody. Each section ends with a short knowledge check and downloadable template-policy outline, incident form, communication matrix-to accelerate implementation in your own environment.The course also covers often-overlooked requirements around evidence preservation, regulatory notification, and cross-team collaboration with HR, legal, and public-relations staff. A dedicated lesson shows how to conduct blameless post-incident reviews, extract measurable lessons learned, and feed them into vulnerability management and security-awareness programs.Upon completion you will be able to operationalize ISO 27035 quickly, integrate it with NIST CSF or CIS Controls, and demonstrate continuous improvement to auditors and executives alike. No prior audit experience is required-only a basic familiarity with information-security concepts.Key outcomes include:Build ISO 27035-aligned response policyDetect and classify security incidents reliablyActivate playbooks for rapid containmentCoordinate evidence and regulatory reportingRun reviews and drive continual improvementEnroll today to turn chaos into a disciplined, metrics-driven incident-management program and boost your organization's resilience against the next cyberattack.