IR
IR
CONTINUING EDUCATION
COURSE OUTLINE
SECTION I
COMP 656
COURSE TITLE
TYPE COURSE
NON-FEE VOCATIONAL
This course covers cybersecurity incident response planning, tools and techniques. Students
will build a formal incident response handling program. Students use tools to contain, cleanup,
recover and prepare a post incident report. Topics include forensic tools, their appropriate use,
and analysis of the symptoms of an incident. The purpose and importance of communication
and role-based responsibilities will be integrated throughout the course. (FT)
LECTURE/LABORATORY HOURS
45
ADVISORIES
Possess a 12th grade reading level; ability to communicate effectively in the English language;
knowledge of math concepts at the 8th grade level and computer literacy.
1. Social Responsibility
SDCE students demonstrate interpersonal skills by learning and working cooperatively in a
diverse environment.
2. Effective Communication
SDCE students demonstrate effective communication skills.
3. Critical Thinking
SDCE students critically process information, make decisions, and solve problems
independently or cooperatively.
CEISO 2/18
CYBER INCIDENT RESPONSE
PAGE 2
COURSE GOALS
1. Learn about the roles and responsibilities of a computer security incident response team.
2. Gain an understanding of threat behavior and its impact.
3. Learn about threat data, including classification and impact.
4. Learn about the common tools found in a forensic investigation suite.
5. Explore the purpose and importance of communication during incident response.
6. Learn to recognize the symptoms of a security incident.
7. Gain an understanding of the post-incident response process and summary report.
COURSE OBJECTIVES
SECTION II
CEISO 2/18
CYBER INCIDENT RESPONSE
PAGE 3
CEISO 2/18
CYBER INCIDENT RESPONSE
PAGE 4
APPROPRIATE READINGS
Readings may include, but are not limited to, textbooks, manuals, periodicals, instructor-
written materials, and websites related to cyber incident response.
CEISO 2/18
CYBER INCIDENT RESPONSE
PAGE 5
WRITING ASSIGNMENTS
Appropriate writing assignments may include, but are not limited to, preparing text for an
assigned project, documenting all laboratories and project work, and completing all written
assigned reports, such as developing an incident communications plan.
OUTSIDE ASSIGNMENTS
Outside assignments may include, but are not limited to, reading texts and reference
resources; research as needed to complete projects, such as determining and prioritizing
factors that contribute to incident severity; and organizing and preparing written answers to
assigned questions.
Assignments which exhibit critical thinking may include analysis and evaluation of assigned
text and reference resources, and utilize this analysis in classroom discussions, as well as
completing lab activities. Appropriate assignments may include performing network scans and
preparing a service issue response plan. Students must select appropriate forensic tools and
employ appropriate methods needed to complete laboratory assignments, including recovering
volumes or drives.
EVALUATION
A student’s grade will be based on multiple measures of performance and will include
evaluation of student’s ability to:
METHOD OF INSTRUCTION
Methods of instruction may include, but are not limited to, lectures, self-paced lab,
demonstrations, individualized study, use of audio-visual aids, group/team work, tutorials,
outside assignments, guest lectures, field trips, and guided student job assignments. This
course, or sections of this course, may be offered through distance education.
CEISO 2/18
CYBER INCIDENT RESPONSE
PAGE 6
Web Resources:
ITPRO.TV, https://itpro.tv/course-library/cybersecurity-analyst-csa/overview70770;
CompTIA Marketplace, https://www.comptiastore.com/CompTIA-Cybersecurity-Analyst-CSA-
eBook-Labs-p/pl720ebk.htm;
CYBRARY, https://www.cybrary.it/catalog/practice_labs/comptia-cybersecurity-analyst-csa
Instructors must meet all requirements stated in Policy 3100 (Student Rights, Responsibilities
and Administrative Due Process), and the Attendance Policy set forth in the Continuing
Education Catalog.
REFERENCES:
CEISO 2/18