HomeCoursesCognicert ISO/IEC 27035 Information Security Incident Manager Course
post · Courses, Continuity, Resilience and Recovery

Cognicert ISO/IEC 27035 Information Security Incident Manager Course

Training Overview: ISO/IEC 27035 Information Security Incident Management training equips professionals with the skills to manage and respond to security incidents effectively.

  • Practical, standards-based professional learning
  • Assessment and verifiable Cognicert certification
  • Flexible online, self-study and organisational delivery

Overview

ISO/IEC 27035 Information Security Incident Management training is designed to equip professionals with the knowledge and skills necessary to effectively manage and respond to information security incidents within an organization. This training program covers incident management principles, processes, and best practices outlined in ISO/IEC 27035 to ensure that organizations can identify, assess, and mitigate security incidents while minimizing potential damage.

Objectives

Detailed information for this section is available from the Cognicert course adviser.

Learning outcomes

Detailed information for this section is available from the Cognicert course adviser.

Reference standard

The primary reference standard for ISO/IEC 27035 Information Security Incident Management training is ISO/IEC 27035 itself, titled "Information technology — Security techniques — Information security incident management." This standard provides guidelines and best practices for establishing and operating an incident management process. Training Objectives:
  1. Comprehensive Understanding: Ensure participants have a deep understanding of ISO/IEC 27035 and its relevance to information security incident management.
  2. Incident Identification: Teach participants how to recognize and classify various types of information security incidents.
  3. Incident Response Planning: Enable participants to develop and implement incident response plans and procedures aligned with ISO/IEC 27035.
  4. Effective Incident Handling: Equip participants with the skills to respond promptly and effectively to security incidents, including containment, eradication, and recovery.
  5. Evidence Preservation: Provide knowledge on preserving digital evidence during incident response for potential legal and forensic purposes.
  6. Reporting and Communication: Teach participants how to communicate and report incidents internally and externally, as required.
  7. Continuous Improvement: Encourage participants to continuously improve their incident management processes through lessons learned and post-incident analysis.
Training Content: The training content should cover a range of topics to meet the specified objectives. Here's a breakdown of the content: Module 1: Introduction to ISO/IEC 27035
  • Overview of ISO/IEC 27035 and its importance
  • Role of incident management in information security
  • Relation to other ISO/IEC standards (e.g., ISO/IEC 27001)
Module 2: Incident Classification and Identification
  • Identifying and classifying information security incidents
  • Incident categorization and severity assessment
  • Early warning signs and indicators
Module 3: Incident Response Planning
  • Developing an incident response plan
  • Establishing an incident management team
  • Legal and regulatory considerations
Module 4: Incident Handling and Response
  • Incident handling phases (preparation, detection, containment, eradication, recovery, lessons learned)
  • Escalation procedures and decision-making during an incident
  • Coordinating response efforts
Module 5: Digital Evidence Preservation
  • Preserving digital evidence during incident response
  • Chain of custody and forensic considerations
  • Legal admissibility of evidence
Module 6: Incident Reporting and Communication
  • Internal and external incident reporting requirements
  • Communicating with stakeholders, including regulatory bodies and law enforcement
  • Managing public relations during incidents
Module 7: Post-Incident Analysis and Lessons Learned
  • Conducting post-incident analysis and root cause analysis
  • Lessons learned and continuous improvement
  • Updating incident response plans based on findings
Module 8: Case Studies and Best Practices
  • Real-world examples of effective incident management
  • Best practices from organizations with mature incident response programs
Module 9: Action Plan and Implementation
  • Developing an action plan for implementing ISO/IEC 27035 practices within participants' organizations
  • Steps to initiate and sustain effective incident management practices
Module 10: Q&A and Course Evaluation
  • Opportunity for participants to ask questions and seek clarification
  • Course evaluation and feedback collection

Target audience

The target audience for ISO/IEC 27035 Information Security Incident Management training includes:
  1. Information Security Professionals: Security managers, officers, and analysts responsible for incident response and management.
  2. IT Managers and Administrators: IT personnel who play a role in responding to and mitigating security incidents.
  3. Compliance Officers: Professionals tasked with ensuring that the organization adheres to security standards and regulations.
  4. Business Continuity and Disaster Recovery Teams: Those responsible for maintaining business continuity in the event of security incidents.
  5. Risk Managers: Professionals focused on assessing and managing information security risks.
  6. Incident Responders: Individuals involved in the technical aspects of incident handling, such as forensics and incident analysis.

Benefits

Detailed information for this section is available from the Cognicert course adviser.

Course content

Detailed information for this section is available from the Cognicert course adviser.

Training methodologies

  • Case Study
  • Individual Exercises
  • Role Play
  • Group Exercises
  • Group Presentation
  • Examination
Duration: 5 Days Delivery Options:  Frequently Asked Questions: https://cognicert.com/faqs/   Enroll Now [contact-form-7 id="2fc7c20" title="Course Sign up"]
2026 COURSE CALENDAR

Training, exam and application dates

Fees include the items specified in the Cognicert 2026 training calendar. Late applications incur £50.

TRAINING DATESEXAMAPPLICATION DEADLINELATE APPLICATIONONLINE FEESELF-STUDY FEEENROL
23–27 February 202627 February 20263 February 202610 February 2026£1,500£600Enrol
4–8 May 20268 May 202613 April 202621 April 2026£1,500£600Enrol
3–7 August 20267 August 202613 July 202620 July 2026£1,500£600Enrol
9–13 November 202613 November 202612 October 202621 October 2026£1,500£600Enrol
VERIFIABLE ACHIEVEMENT

Independently verify your certificate

Successful candidates receive a uniquely numbered Cognicert certificate that another person can check through our public certificate-verification service.

View certificate verification →
YOUR COURSE ADVISER

Need help before enrolling?

Lisa Williams
Course and Business Development Adviser
Monday–Friday, 09:00–17:00 UK time

WhatsApp only: +44 7899 782438
bizdev@cognicert.com

Related Cognicert resources

ISO 37001 Anti-Bribery Management Systems: A Strategic and Operational Guide for Governance and Risk ProfessionalsRead more →Corporate Governance: A Comprehensive Analytical Framework for Strategic and Operational ExcellenceRead more →Why Pipeline Risk Registers Often Miss Real ThreatsRead more →
Ready to enrol?

Choose online or self-study and continue securely to Stripe, or ask an adviser first.