Incident Response for an Organisation
Who declares an incident, who is woken, who is allowed to speak, which clocks are running, and the tabletop that finds out whether any of it is true. The organisation's half of incident response — the analyst's half is segment C2.
- trending_upIntermediate
- schedule7h 43m
- menu_book12 bài học
- publicEnglish
- workspace_premiumBasic
Tóm tắt
An analyst escalates. They say some version of "this is bigger than a ticket". Almost every organisation has written material covering everything up to that sentence and nothing at all covering the ten minutes after it. This segment is those ten minutes, and the four days that follow. Who is allowed to say the word incident, and what it costs them to be wrong. Who is woken at three in the morning, on what number, held on what piece of paper, and what happens when both the accountable executive and her deputy are unreachable. Which clocks start running, who in your organisation answers each one, and why any deadline you memorise on a course is the wrong number for somebody. What you must not write down while it is still running, and the four-part form that replaces it. Then the tabletop, run properly rather than described — a ninety-minute script with six timed injects — and the report that follows, which contains exactly three changes and not eleven. Every lesson produces a document you can put in front of a director. A declaration rule. A leaver-incident checklist with an owner against each of six decisions. A decision log. A role card. A printed call tree with a test date on it. A delegation ladder with thresholds you could apply at 03:00. An obligations table in which every cell holds a document and a role rather than a number. Four notifications written from one fact set. A tabletop design sheet, a filled observer sheet, and a post-incident report with three changes, three owners and three tests. Two cases run through it that are never an analyst's to close: a departing employee who took the client list, and a payment approved outside the process that had already left the account an hour before anybody noticed. One ransomware case runs through modules 2, 3 and 4, and it stops at the decisions — the restore, the recovery point and what a faster recovery tier costs belong to segment R6. Nothing in this segment is legal advice, and it contains no notification deadlines. Disclosure obligations differ by jurisdiction, sector and contract, and they change. Every obligation here is written as a question you answer for your own organisation, with the source named and dated.
Nội dung khóa học · 4 mô-đun
lockMở khóa với quyền truy cập- 01 When It Stops Being a Ticket3 bài học·1h 36m
Segment C2 is the analyst's half of this subject and it ends at an escalation. This module begins at that sentence. If a lesson here tells you what to type, it has drifted into C2 and you should…
- 02 The Roles and the Call3 bài học·1h 39m
Everything in module 1 assumed somebody could be reached. This module is about the machinery of reaching them, and about what the organisation is allowed to do when nobody can be. The ransomware case…
- 03 The Clock3 bài học·1h 41m
This module gives you no deadlines. Notification duties differ by jurisdiction, sector, regime and contract, and they change; a number memorised on a course is the wrong number for somebody. What is…
- 04 The Tabletop and What It Changes3 bài học·2h 47m
A tabletop is not a test that the plan works. It exists to find where the plan is silent, which is why it is designed so that nobody can win it. The product is a findings list, and the product of the…
Các câu hỏi thường gặp
- Tôi sẽ học gì trong Incident Response for an Organisation?
- Who declares an incident, who is woken, who is allowed to speak, which clocks are running, and the tabletop that finds out whether any of it is true. The organisation's half of incident response — the analyst's half is segment C2.
- Tôi có cần kinh nghiệm trước đó không?
- Nên có một số kiến thức trước đó trước khi bắt đầu Incident Response for an Organisation.
- Incident Response for an Organisation mất bao lâu?
- Incident Response for an Organisation bao gồm 4 mô-đun và 12 bài học. Bạn học theo tốc độ của riêng mình.
- Làm cách nào để tôi có quyền truy cập?
- Incident Response for an Organisation được bao gồm trong bất kỳ gói đăng ký nào.