К содержимому
learnspaceYOUR NEXT CHAPTER
ПРОСТРАНСТВО ОБУЧЕНИЯ
ГлавнаяКаталог курсовМоё обучениеCoursera

Знания без границ

Учитесь у лучших университетов и компаний мира.

Открыть Coursera
Интеграция
Пространство университета
Моё пространствоСтраница курса
↵
ЯЛичный кабинетСтудент
© 2026 LearnSpaceКаждый день — возможность узнать больше.Помощь
Cyber Incident Response: Triage, Containment & Recovery · LearnSpace
Назад в каталог
courseraIT и технологии

Cyber Incident Response: Triage, Containment & Recovery

Курс от Macquarie University
Средний≈ 10.8 чАнглийский
О курсеНавыкиПрограммаПреподаватели

О курсе

When a cyber attack hits, the speed and structure of your response determines everything — how much damage is done, how quickly systems recover, and whether your organisation emerges stronger. Yet structured incident response remains one of the most underdeveloped capabilities in security teams worldwide. This course gives you a complete, operational incident response skillset — from the first alert through to post-incident learning. You'll begin with preparation: assessing your security landscape, establishing a Computer Security Incident Response Team (CSIRT), and developing crisis communication strategies for staff, leadership, stakeholders, and media. You'll then develop triage and analysis skills — distinguishing real incidents from noise, identifying early indicators of compromise, and analysing logs and alerts to assess the scale and impact of a breach. Moving from analysis to action, you'll apply containment strategies that isolate compromised systems while maintaining business continuity, and eradicate threats including malware and insider attacks. The final stage covers recovery, post-incident documentation, root cause analysis, and presenting lessons learned to executive audiences. Interactive role plays simulate real-world pressure: CSIRT activation, SOC manager briefings, live breach response, and leadership debriefs. Job skills taught: Incident Detection & Classification · CSIRT Management · Incident Triage & Analysis · Threat Containment · System Eradication & Recovery · Post-Incident Documentation · Post-Incident Review · Crisis Communication · SOC Operations · Security Resilience Features Coursera Coach, Dialogues and Role Plays - a smarter way to learn with interactive, real-time conversations that help you test your knowledge, challenge assumptions, and deepen your understanding as you progress through the course.

Навыки, которые вы освоите

Incident ResponseTechnical CommunicationComputer Security Incident ManagementIncident ManagementThreat DetectionMalware ProtectionRecord KeepingCybersecurityThreat ManagementRoot Cause AnalysisTriageVulnerability AssessmentsCyber Security AssessmentSecurity ManagementCyber AttacksDisaster RecoveryCyber OperationsResilienceEvent MonitoringCrisis Intervention

Программа курса

5 модулей · 43 учебных материалов

01Incident Detection and Classification12 материалов
OverviewPLUGINIntroductionPLUGINBeing preparedPLUGINOrganisational security landscapePLUGINBuilding a Response Team (CSIRT)

Учитесь у экспертов

Matt Bushby

Преподаватель курса

Cyber Incident Response: Triage, Containment & Recovery
В каталоге вашей программы

Инвестируйте в себя

Новые знания — в удобное для вас время.

Начать на Coursera

Обучение откроется на Coursera
в новой вкладке

Обучение на Coursera

≈ 10.8 ч

5 модулей

Язык: Английский

Часть программы вашего университета
PLUGIN
Crisis communicationPLUGIN
First Response: Coordinating the CSIRT ActivationDIALOGUE
Defining a Common LanguagePLUGIN
SummaryPLUGIN
ReferencesPLUGIN
End of module quizЗадание
Managing the Message: Crisis Communication with External StakeholdersDIALOGUE
02Incident Triage and Analysis11 материалов
OverviewPLUGINIntroductionPLUGINDetectionPLUGINEvents and indicatorsPLUGINAnalysisPLUGINAnalysing incidentsPLUGINSignal or Noise? Triaging Ambiguous AlertsDIALOGUEAlert Escalation: Briefing the SOC ManagerDIALOGUESummaryPLUGINReferencesPLUGINEnd of module quiz - Incident Triage and AnalysisЗадание
03Containment Strategies, Eradication and Recovery9 материалов
OverviewPLUGINIntroductionPLUGINContainmentPLUGINImplementing containmentPLUGINEradication and recoveryPLUGINCrisis at TechCorp: Leading the Incident ResponseDIALOGUESummaryPLUGINReferencesPLUGINEnd of module quizЗадание
04Post-Incident Review and Lessons Learned9 материалов
OverviewPLUGINIntroductionPLUGINPost-incident documentationPLUGINThe post-incident reviewPLUGINLessons learnedPLUGINThe Post-Incident Debrief: Presenting to LeadershipDIALOGUESummaryPLUGINReferencesPLUGINEnd of module quizЗадание
05Mini Project2 материалов
Reflective questionsЗаданиеProject: Operational Incident Response & Executive BriefingЗадание