Go to Charter Oak State College home page
Request InfoApply Now

CSS 207: Incident Response

Course Description

This course will focus on incident detection and response. Topics will include: defining a security incident and explaining the incident response lifecycle, including the roles and responsibilities of incident response teams, analyzing and interpreting network communications to detect security incidents using packet sniffing tools. It will also explore the incident investigation and response processes and procedures and the use of Intrusion Detection Systems (IDS) and Security Information Event Management (SIEM) tools. (3 credits)

Prerequisite

  • CSS 101: Cybersecurity Fundamentals

Student Learning Outcomes (SLOs)

Upon completion of the course, the students will be able to:

  1. Explain the lifecycle of an incident.
  2. Describe the tools used in documentation, detection, and management of incidents.
  3. Illustrate and explain fundamental architectures of networks and the Internet, as well as their underlying principles.
  4. Analyze packets to interpret network communications.
  5. Identify and critically assess issues and concepts related to the protection of information and information systems.
  6. Perform artifact investigations to analyze and verify security incidents.
  7. Use risk management principles to assess threats, vulnerabilities, countermeasures, and impact contributions at risk in information systems.
  8. Identify the steps to contain, eradicate, and recover from an incident.
  9. Determine when and how to escalate a security incident.
  10. Determine how to read and analyze logs during incident investigation.
  11. Interpret the basic syntax and components of signatures and logs in Intrusion Detection Systems (IDS) and Network Intrusion Detection Systems (NIDS) tools.
  12. Perform queries in Security Information and Event Management (SIEM) tools to investigate an event.
  13. Communicate sensitive information with care and confidentiality.
  14. Engage with the cybersecurity community.

Course Activities and Grading

AssignmentsWeight

Discussion (Weeks 1-8)

16%

Assignments (Weeks 1-8)

84%

Total

100%

Required Textbooks

  • This course uses Open Educational Resources (OER). OER are openly licensed, educational resources that can be used for teaching, learning and research. OER may consist of a variety of resources such as textbooks, videos and software that are no cost for students.

Course Schedule

Week

SLOs

Readings and Exercises

Assignments

1

1,2

Topics: Introduction to Detection and Incident Response

  • Sound the Alarm: Detection and Response - Module 1
  • Review assigned material
  • Participate in the Discussions
  • Submit the Week 1 assignments

2

3,4

Topic: Network Monitoring and Analysis

  • Sound the Alarm: Detection and Response - Module 2
  • IT Security: Defense against the digital dark arts - Module 4
  • Review assigned material
  • Participate in the Discussions
  • Submit the Week 2 assignments

3

5,10

Topic: Incident Investigation and Response

  • Sound the Alarm: Detection and Response - Module 3
  • Detect, Respond, and Recover from Cloud Cybersecurity Attacks - Module 1
  • Review assigned material
  • Participate in the Discussions
  • Submit the Week 3 assignments

4

11,12

Topic: Network Traffic and Logs Using IDS and SIEM Tools

  • Sound the Alarm: Detection and Response - Module 4
  • Detect, Respond, and Recover from Cloud Cybersecurity Attacks - Module 2
  • Review assigned material
  • Participate in the Discussions
  • Submit the Week 4 assignments

5

6,7

Topic: Protect Data and Communicate Incidents

  • Put It to Work: Prepare for Cybersecurity Jobs - Module 1
  • Cloud Security Risks: Identify and Protect Against Threats - Module 4
  • Review assigned material
  • Participate in the Discussions
  • Submit the Week 5 assignments

6

8,9

Topic: Escalate Incidents

  • Detect, Respond, and Recover from Cloud Cybersecurity Attacks - Module 3
  • Put It to Work: Prepare for Cybersecurity Jobs - Module 2
  • Review assigned material
  • Participate in the Discussions
  • Submit the Week 6 assignments

7

13

Topics: Communicate Effectively

  • Put It to Work: Prepare for Cybersecurity Jobs - Module 3
  • IT Security: Defense against the digital dark arts - Module 6
  • Review assigned material
  • Participate in the Discussions
  • Submit the Week 7 assignments

8

14

Topics: Engage with the Cybersecurity Community

  • Put It to Work: Prepare for Cybersecurity Jobs - Modules 4 & 5
  • Review assigned material
  • Participate in the Discussions
  • Submit the Week 8 assignments
  • Complete Course Evaluation

COSC Accessibility Statement

Charter Oak State College encourages students with disabilities, including non-visible disabilities such as chronic diseases, learning disabilities, head injury, attention deficit/hyperactive disorder, or psychiatric disabilities, to discuss appropriate accommodations with the Office of Accessibility Services at OAS@charteroak.edu.

COSC Policies, Course Policies, Academic Support Services and Resources

Students are responsible for knowing all Charter Oak State College (COSC) institutional policies, course-specific policies, procedures, and available academic support services and resources. Please see COSC Policies for COSC institutional policies, and see also specific policies related to this course. See COSC Resources for information regarding available academic support services and resources.