Skip to content
KnowledgeCity

Defensible Security Architectures: Responding to Breaches

Learn to navigate the unique challenges of customer contact centers
Preview the first lesson free — get full access to all 6 lessons.
Course: On-Demand
Intermediate Provider James Youngblood  6 Lessons ·  41m  in Arabic, German, English, Spanish, French, Portuguese, Chinese 

Course Description

When a breach occurs, there are several very important questions that need to be addressed. What happens when a breach occurs? Who handles it, and how do they find out who is responsible? When asked about a breach, how much information is legally allowed to be released internally and externally? What can be done to prevent breaches in the future? As a security professional, you should know the answers to these questions. Security breaches are no longer isolated incidents, so it’s crucial to ask yourself if your company is prepared for a breach. We will discuss how to have a response plan in place and the ways that simulating a breach can help your company be prepared for a worst-case scenario.

In these lessons, you will learn about how to respond to a breach. We will discuss the responsibilities of the Incident Response Team and Disaster Recovery Team to investigate a breach, preserve any relevant data about a breach, and work to prevent further breaches. We will also discuss best practices for controlling internal and external communications regarding security breaches.

What You'll Learn

  • Identify the members of the Incident Response Team and their responsibilities
  • Define the relationship between the Incident Response Team and the Disaster Recovery Team
  • Control internal and external communications and reactions after a breach
  • Explain why breaches should be monitored before being blocked
  • Identify the tools and methods for preserving evidence and data
  • Apply reactive steps to monitor or block subsequent breaches

Key Takeaways

  • Security breaches are no longer isolated incidents, so companies must be prepared with a response plan in place.
  • The Incident Response Team and Disaster Recovery Team are responsible for investigating a breach, preserving relevant data, and working to prevent further breaches.
  • Controlling both internal and external communications is a best practice when responding to a security breach.
  • Simulating a breach can help a company prepare for a worst-case scenario.
  • Breaches should be monitored before being blocked, and reactive steps can be taken to monitor or block subsequent breaches.

Frequently Asked Questions

Who is this course for?

This course is for security professionals who should know how to respond to a breach, including how it is handled, who is responsible, and what can be done to prevent future breaches.

What does this course cover?

It covers how to respond to a breach, including the responsibilities of the Incident Response Team and Disaster Recovery Team to investigate a breach, preserve relevant data, and prevent further breaches, as well as best practices for controlling internal and external communications about security breaches.

What skills will I gain from this course?

You will gain skills in Computer Security Incident Response, Cyber Incident Response, Disaster Response, Incident Response, Incident Response Management, and Vulnerability Management.

Why does the course say breaches should be monitored before being blocked?

One of the learning objectives is to explain why breaches should be monitored before being blocked, and the course includes a lesson on reactive steps to monitor or block subsequent breaches.

What lessons are included in this course?

The lessons are: The Incident Response Team; Disaster Recovery's Role in Response to Breaches; Preserving Evidence and Data; Control Internal Communication and Reaction to Breaches; Control External Communication and Reaction to Breaches; and Reactive Steps To Monitor or Block Subsequent Breaches.