WM9PE-15 Cyber Incident Management
Introductory description
A cyber security incident can have a significant impact on the operational efficiency of a business. There are essential mechanisms and skillset that can be utilised to allow a potential attack against infrastructure to be effectively identified, managed and mitigated in a timely manner.
This module aspires to equip students with these skills and consists of two main parts. First, it explores the principles of responding to a cyber security incident and the incident response lifecycle. Second, it focuses on familiarising the students with the scientific techniques utilised for the technical analysis of the systems involved in a cyber security incident.
Module aims
This module aims to provide the students with a detailed understanding of the principles of managing a cyber security incident and allow them to apply advanced technical concepts and practices in cyber investigations.
Outline syllabus
This is an indicative module outline only to give an indication of the sort of topics that may be covered. Actual sessions held may differ.
The module follows the incident response lifecycle:
- Preparation for responding to a cyber security incident and forensic readiness
- Understanding a threat - threat hunting
- Identification of a cyber security incident - detection methods, first response and management
- Intrusion analysis, monitoring and logging
- Digital forensics process in incident response - collection and preservation
- Investigation techniques
- Host forensics
- Network collection and analysis - log analysis
- Malware handling
- Cyber security incident remediation
- The future of cyber incident response
This is an indicative module outline and actual sessions held may differ.
Learning outcomes
By the end of the module, students should be able to:
- Comprehensively identify the different phases comprising the incident response lifecycle
- Critically evaluate the principles of cyber incident management across diverse scenarios
- Demonstrate the ability to analyse an individual approach of responding to a cyber security incident with the application of relevant techniques
- Evaluate and provide sound reasoning for suitable responses to identified cyber security incidents
Indicative reading list
Reading lists can be found in Talis
Specific reading list for the module
Interdisciplinary
There is some interdisciplinary element relevant to the nature of the digital forensics part of the module. It involves relevant law elements.
Subject specific skills
Incident response lifecycle and practices, investigation principles, evaluation of a cyber security incident, host based analysis, network based analysis
Transferable skills
Problem solving, critical thinking, digital literacy, information literacy, ethical values, communication.
Study time
| Type | Required |
|---|---|
| Lectures | 10 sessions of 1 hour (11%) |
| Seminars | 5 sessions of 1 hour (6%) |
| Supervised practical classes | 15 sessions of 1 hour (17%) |
| Online learning (independent) | 10 sessions of 1 hour (11%) |
| Private study | 50 hours (56%) |
| Total | 90 hours |
Private study description
Studying textbooks, lecture notes and other resources provided. It may also involve preparation tasks before a seminar and coursework preparation.
Costs
No further costs have been identified for this module.
You must pass all assessment components to pass the module.
Assessment group A1
| Weighting | Study time | Eligible for self-certification | |
|---|---|---|---|
Assessment component |
|||
| Managing Incident Response | 20% | 12 hours | No |
|
Multiple-choice closed-book in class test on the different phases comprising the incident response lifecycle. |
|||
Reassessment component is the same |
|||
Assessment component |
|||
| Managing a cyber security incident | 80% | 48 hours | Yes (extension) |
|
The portfolio may consist of multiple small pieces of work. It may include a proposal of an incident response plan, a small practical task, and a short report outlining the findings or a short research paper. |
|||
Reassessment component |
|||
| Managing a cyber security incident | No | ||
|
The portfolio may consist of multiple small pieces of work. It may include a proposal of an incident response plan, a small practical task, and a short report outlining the findings or a short research paper. |
|||
Feedback on assessment
Summative feedback will be provided on the assignment.
Verbal formative feedback will be offered during practical sessions on both the assignment and the in class test.
Courses
This module is Optional for:
- Year 1 of TWMS-H1S1 Postgraduate Taught Cyber Security Engineering (Full-time)
- Year 1 of TWMS-H1SH Postgraduate Taught Cyber Security Management (Full-time)