CERT Incident Response Process Professional Certificate
Detect and Respond to Computer Security Threats and Attacks
Earning this certificate prepares you to be a member of a computer security incident response team (CSIRT). You study incident handling and common and emerging attacks that target a variety of operating systems and architectures. You also study other topics related to incident handling, including detecting various types of malicious activity, performing artifact analysis, and coordinating responses to reported vulnerabilities.
Benefits of the CERT Incident Response Process Professional Certificate
The first course in the certificate provides an introduction to the main incident handling tasks and critical thinking skills that help incident handlers perform their jobs. The second course addresses commonly used and emerging attacks that target a variety of operating systems and architectures. Both courses incorporate interactive construction, facilitated discussions, practical group exercises, and role playing.
This certificate is designed to provide insight into the type and nature of work that an incident handler may perform. It also helps organizations train their CSIRT staff so they can benchmark their CSIRT processes and skill sets against best practices, encourage teamwork, and improve communication.
After completing the certificate, participants may choose to be listed on the SEI website as an SEI Certificate Holder.
Summary of Fees
Participants pay fees for courses; there is no additional fee for the certificate.
Organizations considering this training for a group of students can take advantage of eLearning group discounts or schedule a private, instructor-led, onsite training delivery. Email course-info@sei.cmu.edu or telephone +1 412-268-1817 for details.
How to Earn the Certificate
To earn this certificate, complete the following courses within two years:
Classroom | eLearning | Onsite | |
Foundations of Incident Management |
|
|
|
Advanced Topics in Incident Handling |
|
|
To request your SEI Professional Certificate, contact credentials-info@sei.cmu.edu and identify the certificate program you have completed. After we verify your credentials, we email your certificate within four business days.
Related Courses
Advanced Topics in Incident Handling
This four-day course, designed for cybersecurity incident management and security operations center (SOC) technical personnel with several months of incident handling experience, addresses techniques for detecting and responding to current and emerging cybersecurity threats and attacks.
Building on the methods and tools discussed in the Foundations of Incident Management course, this course provides guidance that incident handlers can use in responding to more complex threats and attacks, including persistent threats. Through interactive instruction, facilitated discussions, and group exercises, instructors help participants identify and analyze a set of events and then propose appropriate response strategies. This course was updated over the 2022-2023 timeframe.
Participants work as a team throughout the week to handle a series of escalating incidents that are presented as part of an ongoing scenario. Work includes team analysis of information and presentation of findings and response strategies. Participants also review more advanced types of activities related to incident handling such as threat hunting, artifact and malware analysis, vulnerability handling, major or crisis events, and publishing and communicating information.
This CERT incident management course adds additional expertise for understanding incident handling and related practices and functions. Before registering for this course, participants are encouraged to attend the companion course, Foundations of Incident Management.
Foundations of Incident Management
This four-day course provides foundational knowledge for those in security-related roles who need to understand the functions of an incident management capability and how best to perform those functions. It is recommended for those new to incident handling or security operations work. This course was recently updated in September 2022, including a new ransomware exercise.
The course provides an introduction to the basic concepts and functions of incident management. The course addresses where incident management activities fit in the information assurance or information security ecosystem and covers the key steps in the incident handling lifecycle. Discussions include topics on security operations services, intruder threats, and the nature of incident response activities. Course modules present standard practices to enable a resilient incident management capability.
Course attendees will learn how to gather the information required to handle an incident, realize the importance of having and following pre-defined security operations policies and procedures, understand the technical issues relating to commonly reported attack types such as phishing and ransomware, perform analysis and response tasks for various sample incidents, apply critical thinking skills in responding to incidents, and identify potential problems to avoid while taking part in incident management work. The course incorporates interactive instruction, in class discussions, small group work, and practical exercises. Attendees have the opportunity to participate in sample incidents that they might face on a day-to-day basis in a group or team scenario/situation.
After completing this course, participants are encouraged to attend the companion course, Advanced Topics in Incident Handling.
Note: There is significant content overlap between the Foundations of Incident Management course and the Managing CSIRTs course. We recommend that attendees register for one course or the other, but not both. The Foundations of Incident Management course covers more technical topics such as phishing, email, and malware attacks, PGP, and recognizing signs of attack. The Foundations of Incident Management course is designed to introduce new incident handlers to the basic skills and processes they will need to perform incident handling work. The Managing CSIRTs course focuses on incident handling issues from an operational management perspective. The Managing course includes modules on staffing issues, needed infrastructure, publishing information, and handling major events which are not covered in the Foundations course.
Training courses provided by the SEI are not academic courses for academic credit toward a degree. Any certificates provided are evidence of the completion of the courses and are not official academic credentials. For more information about SEI training courses, see Registration Terms and Conditions and Confidentiality of Course Records.