Cyber Security Incident Response and Recovery

Course #CS4684

Est.imated Completion Time: 3 months

Overview

This course defines the nature and scope of cyber security incident handling services, including intrusion/incident detection, damage control, service continuity, forensic analysis, service/data restoration, and incident reporting. Material covers policy, planning, operations, and technology issues involved in related cyber incident handling plans; i.e., Business Continuity, Disaster Recovery, and Continuity of Operations. Specific incident types addressed include, natural disasters, denial of service, malicious code, malicious misuse of hardware and firmware, unauthorized access, data compromise and inappropriate use, including insider attacks. Emphasis is given to the detection and analysis of infiltration and exfiltration techniques employed during cyber attacks, thus enabling the incident handler to detect low noise attacks, and to deconstruct particularly insidious attacks. Based upon the choice of case studies, this course will be taught at either the unclassified or TS/SCI levels.

Included in degrees & certificates

  • 258
  • 367

Prerequisites

  • CS3690
Offerings database access
Asset Publisher

Academic Calendar

  •  09 Jun 2023

    Spring quarter last day of classes

  •  13 Jun 2023

    Spring quarter final examinations begin

  •  15 Jun 2023

    Spring quarter final examinations end