Skip to main content Skip to navigation

WM9PE-15 Cyber Incident Management

Department
WMG
Level
Taught Postgraduate Level
Module leader
Maria Papadaki
Credit value
15
Module duration
4 weeks
Assessment
100% coursework
Study location
University of Warwick main campus, Coventry

Introductory description

A cyber security incident can have a significant impact on the operational efficiency of a business. There are essential mechanisms and skillset that can be utilised to allow a potential attack against infrastructure to be effectively identified, managed and mitigated in a timely manner.
This module aspires to equip students with these skills and consists of two main parts. First, it explores the principles of responding to a cyber security incident and the incident response lifecycle. Second, it focuses on familiarising the students with the scientific techniques utilised for the technical analysis of the systems involved in a cyber security incident.

Module aims

This module aims to provide the students with a detailed understanding of the principles of managing a cyber security incident and allow them to apply advanced technical concepts and practices in cyber investigations.

Outline syllabus

This is an indicative module outline only to give an indication of the sort of topics that may be covered. Actual sessions held may differ.

The module follows the incident response lifecycle:

  • Preparation for responding to a cyber security incident and forensic readiness
  • Understanding a threat - threat hunting
  • Identification of a cyber security incident - detection methods, first response and management
  • Intrusion analysis, monitoring and logging
  • Digital forensics process in incident response - collection and preservation
  • Investigation techniques
  • Host forensics
  • Network collection and analysis - log analysis
  • Malware handling
  • Cyber security incident remediation
  • The future of cyber incident response

This is an indicative module outline and actual sessions held may differ.

Learning outcomes

By the end of the module, students should be able to:

  • Comprehensively identify the different phases comprising the incident response lifecycle
  • Critically evaluate the principles of cyber incident management across diverse scenarios
  • Demonstrate the ability to analyse an individual approach of responding to a cyber security incident with the application of relevant techniques
  • Evaluate and provide sound reasoning for suitable responses to identified cyber security incidents

Indicative reading list

Reading lists can be found in Talis

Specific reading list for the module

Interdisciplinary

There is some interdisciplinary element relevant to the nature of the digital forensics part of the module. It involves relevant law elements.

Subject specific skills

Incident response lifecycle and practices, investigation principles, evaluation of a cyber security incident, host based analysis, network based analysis

Transferable skills

Problem solving, critical thinking, digital literacy, information literacy, ethical values, communication.

Study time

Type Required
Lectures 10 sessions of 1 hour (11%)
Seminars 5 sessions of 1 hour (6%)
Supervised practical classes 15 sessions of 1 hour (17%)
Online learning (independent) 10 sessions of 1 hour (11%)
Private study 50 hours (56%)
Total 90 hours

Private study description

Studying textbooks, lecture notes and other resources provided. It may also involve preparation tasks before a seminar and coursework preparation.

Costs

No further costs have been identified for this module.

You must pass all assessment components to pass the module.

Assessment group A1
Weighting Study time Eligible for self-certification
Assessment component
Managing Incident Response 20% 12 hours No

Multiple-choice closed-book in class test on the different phases comprising the incident response lifecycle.

Reassessment component is the same
Assessment component
Managing a cyber security incident 80% 48 hours Yes (extension)

The portfolio may consist of multiple small pieces of work. It may include a proposal of an incident response plan, a small practical task, and a short report outlining the findings or a short research paper.

Reassessment component
Managing a cyber security incident No

The portfolio may consist of multiple small pieces of work. It may include a proposal of an incident response plan, a small practical task, and a short report outlining the findings or a short research paper.

Feedback on assessment

Summative feedback will be provided on the assignment.
Verbal formative feedback will be offered during practical sessions on both the assignment and the in class test.

Courses

This module is Optional for:

  • Year 1 of TWMS-H1S1 Postgraduate Taught Cyber Security Engineering (Full-time)
  • Year 1 of TWMS-H1SH Postgraduate Taught Cyber Security Management (Full-time)