1 – Assessing Information Security Risk
- Topic A: Identifying the Importance of Risk Management
- Topic B: Assessing Risk
- Topic C: Mitigating Risk
- Topic D: Integrating Documentation into Risk Management
2 – Analysing the Threat Landscape
- Topic A: Classifying Threats and Threat Profiles
- Topic B: Performing Ongoing Threat Research
3 – Analysing Reconnaissance Threats to Computer and Network Environments
- Topic A: Implementing Threat Modelling
- Topic B: Assessing the Impact of Reconnaissance
- Topic C: Assessing the Impact of Social Engineering
4 – Analysing Attacks on Computer and Network Environments
- Topic A: Assessing the Impact of System Hacking Attacks
- Topic B: Assessing the Impact of Web-Based Attacks
- Topic C: Assessing the Impact of Malware
- Topic D: Assessing the Impact of Hijacking and Impersonation Attacks
- Topic E: Assessing the Impact of DoS Incidents
- Topic F: Assessing the Impact of Threats to Mobile Security
- Topic G: Assessing the Impact of Threats to Cloud Security
5 – Analysing Post-Attack Techniques
- Topic A: Assessing Command and Control Techniques
- Topic B: Assessing Persistence Techniques
- Topic C: Assessing Lateral Movement and Pivoting Techniques
- Topic D: Assessing Data Exfiltration Techniques
- Topic E: Assessing Anti-Forensics Techniques
6 – Managing Vulnerabilities in the Organisation
- Topic A: Implementing a Vulnerability Management Plan
- Topic B: Assessing Common Vulnerabilities
- Topic C: Conducting Vulnerability Scans
7 – Implementing Penetration Testing to Assess Security
- Topic A: Conducting Penetration Tests on Network Assets
- Topic B: Following Up on Penetration Testing
8 – Collecting Cybersecurity Intelligence
- Topic A: Deploying a Security Intelligence Collection and Analysis Platform
- Topic B: Collecting Data from Network-Based Intelligence Sources
- Topic C: Collecting Data from Host-Based Intelligence Sources
9 – Analysing Log Data
- Topic A: Using Common Tools to Analyse Logs
- Topic B: Using SIEM Tools for Analysis
10 – Performing Active Asset and Network Analysis
- Topic A: Analysing Incidents with Windows-Based Tools
- Topic B: Analysing Incidents with Linux-Based Tools
- Topic C: Analysing Malware
- Topic D: Analysing Indicators of Compromise (IoCs)
11 – Responding to Cybersecurity Incidents
- Topic A: Deploying an Incident Handling and Response Architecture
- Topic B: Containing and Mitigating Incidents
- Topic C: Preparing for Forensic Investigation as a CSIRT
12 – Investigating Cybersecurity Incidents
- Topic A: Applying a Forensic Investigation Plan
- Topic B: Securely Collecting and Analysing Electronic Evidence
- Topic C: Following Up on the Results of an Investigation
13 – Appendix A: Mapping Course Content to CyberSec First Responder™ (Exam CFR-310)
14 – Appendix B: Regular Expressions
15 – Appendix C: Security Resources
16 – Appendix D: U.S. Department of Defense Operational Security Practices
This course is primarily aimed at cybersecurity professionals whose task is to protect information systems by ensuring their availability, integrity, authentication, confidentiality and non-repudiation. The course focuses on the knowledge, skills and competencies required to defend these information systems in a cybersecurity context, including the processes for protection, detection, analysis, investigation and response. In addition, the course ensures that all members of an IT team – from helpdesk staff to the Chief Information Officer – understand their role in these security processes.
In this course, you will assess security threats, respond to them, and operate a platform for the security analysis of systems and networks.
- Assessing information security risk in computer and network environments.
- Analysing the threat landscape in cybersecurity.
- Analysing reconnaissance threats to computer and network environments.
- Analysing attacks on computer and network environments.
- Analysing post-attack techniques on computer and network environments.
- Implementing a vulnerability management programme.
- Assessing the organisation’s security through penetration testing.
- Collecting cybersecurity intelligence.
- Analysing data from security and event logs.
- Performing active analysis of assets and networks.
- Responding to cybersecurity incidents.
- Investigating cybersecurity incidents.