Security Operations Management (Level 7)
This module will introduce the student to the key aspects of Security Operations Management, focusing on the information technology of products/services and their performance capabilities. Students will learn how to predict the future needs and demands in information technology. This involves an understanding of technical requirements, limitations and channel considerations.
The objectives of this module are to provide students with: A basic understanding of the key decision criteria for Security Operations Management including addressing the following topics:
- Planning within the Cybersecurity area; An Industry Overview
- Selection Process for security operations strategy
- information technology Productivity Micro & Macro Approaches
- Inbound risk mitigation
- information technology security products and how they can be customised for consumers
- Importance of Security Operations Management performance
Indicative Syllabus
Business Continuity Planning
Business Continuity Planning vs. Disaster Recovery Planning, Project scope and planning, Business impact assessment, Identify Priorities, Business Impact Assessment (BIA), Prioritization and classification of business functions, evaluating impact and dependencies, Resource Prioritization, Continuity planning, implementation, BCP Team Selection, Legal and Regulatory Requirements, Testing and Exercises for BCP resilience, use cases of BCPs.
Assessment and Testing
Categorizing Threat Actors Tools Techniques and Procedures (TTPs), MITRE ATT&CK, Strategies for Threat Modelling, Threat Analysis Practices and Tools, Categorizing Threats, Threat Models, Attack Trees, Attack Libraries, Threat Profiles, IDDIL/ATC, STRIDE/DREAD, Security Testing, Vulnerability Scanning, Penetration Testing, Log Reviews, Software Testing, Third Party Software. Managing Threat Assessment and Intelligence Operations.
Awareness, training and education
User awareness and educational programmes, protecting personal privacy, elements of the digital footprint, security technologies and tools, host firewalls, VPN, proxies, access points, SSL/TLS, anti-spam, anti-virus, considerations for different device categories, computer backups (on and offline), patch application and management. Incident Reporting culture. Security Operating Procedures. Insider threats. External Attacks. Staff induction process. Maintaining user awareness.
Incident Response
Defining security events and incidents, Attack and incident response lifecycles, Volatile and non-volatile data, IOCs vs IOAs, Laws relating to the capture of static and dynamic data, Pre-Incident Preparation, Scoping an Incident, Incident response team management, EU and Global legal frameworks. Best practices and uses cases. NIST 800-61 r2 and SANS PICERL. Developing and Managing Incident Response Teams and Frameworks.
Backup and Availability
Backup and Recovery Procedures, Storage Disk Layouts, RAID, On site and off site backups, Backup Strategies, Cloud based, Backup testing, Information storage and disposal, Server backups, Electronic Vaulting, remote journaling and mirroring, best practices, ISO/IEC 27040 and ISO 20001 requirements.
Course Details
Security Operations Management (Level 7)
Learn from the best in your industry
Study your way, on your time
Programmes with purpose, aimed at your future
Here for you, every step of the way