IIKG3020

Introduction to incident response

Autumn

Trondheim and Gjøvik

Norwegian

Overview

71 candidates

Average grade

B

3.80

0.09

Pass rate

100%

same

Grade distribution
Average over time
Pass rate over time

About this course

Content

  • Incident response planning: preparation, organization, building and running a CSIRT, operational issues, hiring and training of personnel
  • Incident response: prevention, detection, notification, reaction, recovery, maintenance
  • Advanced computer network defence: vulnerability and threat management, threat intelligence and situational awareness, tools and processes, frameworks (ATT&CK, Cyber Kill Chain, etc.), threat hunting, information sharing
  • Planning and running incident response team exercises

Learning outcomes

Knowledge

  • The student understands cyber incident response and its components.
  • The student has a good overview of known frameworks and tools for incident response.
  • The student has general knowledge of planning for incident response readiness and managing the operational aspects of the incident response team.
  • The student has general knowledge of how to perform incident response for various types of adverse incidents, including intrusions from advanced threat actors.

Skills

  • The student can plan for and handle larger and smaller cyber incidents.
  • The student can organize an incident response team in a manner that ensures good handling of incidents while also making sure staff burnout is avoided.

General Competence

  • The student has broad knowledge of cyber incident response and is able to communicate this to others.

Teaching methods

  • Online lectures
  • Group project work

Project and lab assignments will be facilitated across Trondheim and Gjøvik campuses.