IIKG3020
Introduction to incident response
Autumn
Trondheim and Gjøvik
Norwegian
About this course
Content
- Incident response planning: preparation, organization, building and running a CSIRT, operational issues, hiring and training of personnel
- Incident response: prevention, detection, notification, reaction, recovery, maintenance
- Advanced computer network defence: vulnerability and threat management, threat intelligence and situational awareness, tools and processes, frameworks (ATT&CK, Cyber Kill Chain, etc.), threat hunting, information sharing
- Planning and running incident response team exercises
Learning outcomes
Knowledge
- The student understands cyber incident response and its components.
- The student has a good overview of known frameworks and tools for incident response.
- The student has general knowledge of planning for incident response readiness and managing the operational aspects of the incident response team.
- The student has general knowledge of how to perform incident response for various types of adverse incidents, including intrusions from advanced threat actors.
Skills
- The student can plan for and handle larger and smaller cyber incidents.
- The student can organize an incident response team in a manner that ensures good handling of incidents while also making sure staff burnout is avoided.
General Competence
- The student has broad knowledge of cyber incident response and is able to communicate this to others.
Teaching methods
- Online lectures
- Group project work
Project and lab assignments will be facilitated across Trondheim and Gjøvik campuses.