This five-day workshop is for computer security incident response team (CSIRT) technical personnel with little or no incident handling experience. It provides a basic introduction to the main incident handling tasks and critical thinking skills that will help an incident handler perform their daily work. It is recommended to those new to incident handling work.
The workshop is designed to provide insight into the type and nature of work that an incident handler may perform. It will provide an overview of the incident handling arena, including CSIRT services, intruder threats, and the nature of incident response activities.
Workshop attendees will learn how to gather the information required to handle an incident; realize the importance of having and following pre-defined CSIRT policies and procedures; understand the technical issues relating to commonly reported attack types; perform analysis and response tasks for various sample incidents; apply critical thinking skills in responding to incidents, and identify potential problems to avoid while taking part in CSIRT work. The workshop incorporates interactive instruction, practical exercises, and role playing. Attendees have the opportunity to participate in sample incidents that they might face on a day-to-day basis.
After completing this workshop, participants are encouraged to attend the companion workshop, Advanced Incident Handling.
Note: There is significant content overlap between the Managing CSIRTs workshop and the Fundamentals of Incident Handling workshop. We recommend that attendees register for one workshop or the other, but not both. The Fundamentals of Incident Handling workshop covers more technical topics such as email and malware attacks, PGP, and recognizing signs of attack. The Fundamentals of Incident Handling workshop is designed to introduce new incident handlers to the basic skills and processes they will need to perform incident handling work. The Managing CSIRTs workshop focuses on incident handling issues from an operational management perspective.
Before registering for this workshop, participants must
This workshop will help participants to