Foundations of Incident Management

Heinz College

How long?

  • 4 days
  • online

What are the topics?

Heinz College


Coursalytics is an independent platform to find, compare, and book executive courses. Coursalytics is not endorsed by, sponsored by, or otherwise affiliated with any business school or university.

Full disclaimer.

Read more about Cybersecurity

The modern world of security systems is changing rapidly, and these days cybersecurity has become one of the most essential parts of protecting data s...


Comprehensive course analysis

Unbiased reviews from past participants
Global companies alumni of this course worked for
Positions of participants who took this course
Countries where most past participants are from
Individual needs analysis

Who should attend

  • new incident handlers, investigators, and SOC analysts (one to three months of experience) who will be performing various incident management or security operations activities
  • staff performing work roles in the NICE1 Computer Network Defense Analysis and Incident Response specialty areas
  • experienced staff who would like to benchmark their processes and skill sets against incident management and security operations best practices
  • anyone who would like to learn about basic incident handling functions and activities

About the course

This four-day course provides foundational knowledge for those in security-related roles who need to understand the functions of an incident management capability and how best to perform those functions. It is recommended for those new to incident handling or security operations work.

The course provides an introduction to the basic concepts and functions of incident management. The course addresses where incident management activities fit in the information assurance or information security ecosystem and covers the key steps in the incident handling lifecycle. Discussions include topics on security operations services, intruder threats, and the nature of incident response activities. Course modules present standard practices to enable a resilient incident management capability.

Course attendees will learn how to gather the information required to handle an incident; realize the importance of having and following pre-defined security operations policies and procedures; understand the technical issues relating to commonly reported attack types; perform analysis and response tasks for various sample incidents; apply critical thinking skills in responding to incidents, and identify potential problems to avoid while taking part in incident management work. The course incorporates interactive instruction, in class discussions, small group work, and practical exercises. Attendees have the opportunity to participate in sample incidents that they might face on a day-to-day basis.

This CERT incident handling course, which provides a well-rounded understanding of incident handling practices and functions, can be used to prepare for the CERT-Certified Incident Handler Certification. After completing this course, participants are encouraged to attend the companion course, Advanced Topics in Incident Handling.

Note: There is significant content overlap between the Foundations of Incident Management course and the Managing CSIRTs course. We recommend that attendees register for one course or the other, but not both. The Foundations of Incident Management course covers more technical topics such as email and malware attacks, PGP, and recognizing signs of attack. The Foundations of Incident Management course is designed to introduce new incident handlers to the basic skills and processes they will need to perform incident handling work. The Managing CSIRTs course focuses on incident handling issues from an operational management perspective. The Managing course includes modules on staffing issues, needed infrastructure, publishing information, and handling major events which are not covered in the Foundations course.


This course will help participants to

  • identify key preparations to have in place to facilitate incident handling
  • define situational awareness and the types of data sources to collect
  • compare types of analysis that may be performed and how they differ and when to use them
  • explore the challenges in information sharing and some initiatives that look to address those challenges
  • recognize current threats and targets
  • recognize the importance of following well-defined processes, policies, and procedures
  • identify the technical, communication, and coordination issues involved in performing successful incident handling
  • critically analyze and assess the impact of information security incidents
  • effectively build and coordinate response strategies for various types of information security incidents


  • the current threat environment and basic incident management processes
  • team code of conduct
  • security tools and technologies used by incident handlers
  • gathering critical information
  • detecting and analyzing incidents
  • performing triage
  • identifying the basic steps in response
  • using the Domain Name System for handling information security incidents
  • finding contact information
  • coordinating response and disseminating information
  • handling email and malicious code attacks
  • working with law enforcement

Foundations of Incident Management at Heinz College

From  $5,000
Add coaching to your course booking

Coaching can personalize and deepen learning for you and your organization.

Something went wrong. We're trying to fix this error.

Thank you for your application

We will contact the provider to ensure that seats are available and, if there is an admissions process, that you satisfy any requirements or prerequisites.

We may ask you for additional information.

To finalize your enrollment we will be in touch shortly.


Coursalytics is an independent platform to find, compare, and book executive courses. Coursalytics is not endorsed by, sponsored by, or otherwise affiliated with any business school or university.

Full disclaimer.

Read more about Cybersecurity

Сybersecurity courses offer an excellent opportunity to develop the knowledge and skills necessary to implement a perfect cybersecurity strategy that will accelerate the main security protocols' efficiency. After the successful completion of cybersec...

Because of COVID-19, many providers are cancelling or postponing in-person programs or providing online participation options.

We are happy to help you find a suitable online alternative.