This training entitles the participant to a certificate of participation issued by an approved professional training organisation under the number 10060172/3.
Goals
- Understand the ICT incident management, classification and reporting process, including the criteria for identifying major incidents and the applicable CSSF reporting deadlines.
- Understand the requirements for digital operational resilience testing, from the risk-based testing programme to Threat-Led Penetration Testing (TLPT).
- Understand the structure and requirements of the Register of Information used to identify and document dependencies on ICT third-party service providers.
Program
- Managing ICT-Related Incidents
- ICT-related Incident Management Process
- Incident detection, triage and categorisation
- Incident logging and traceability
- Root Cause Analysis
- Escalation to Senior Management and the Management Body
- Preservation of evidence
- Classifying Incidents and Cyber Threats
- ICT incident classification criteria
- Identification of Major ICT-related Incidents
- Assessment of impact on clients, services, data and operations
- Significant Cyber Threats
- Recurring incidents
- Coordination with other notification obligations
- Reporting Major Incidents to the CSSF
- Initial notification within DORA deadlines
- Intermediate Report
- Final Report
- Harmonised reporting content and templates
- Coordination with the CSSF and ICT providers
- Information to affected clients
- Digital Operational Resilience Testing Programme
- Establishing a Digital Operational Resilience Testing Programme
- Risk-Based Approach
- Independence of testers
- Identification, classification and remediation of weaknesses
- Annual testing of systems supporting critical or important functions
- Vulnerability Assessments, Network Security Assessments, scenario-based testing and Penetration Testing
- Threat-Led Penetration Testing (TLPT)
- Entities subject to TLPT
- Scope of critical or important functions
- Testing of live production systems
- Threat Intelligence and Red Team Testing
- Internal and external testers
- TLPT phases and Purple Team Exercise
- Reporting, remediation and attestation
- Register of Information
- Purpose and scope of the register
- Identification of ICT providers and services
- Critical or important functions supported by ICT providers
- Intragroup providers and subcontracting chains
- Regulatory template structure
- xBRL-CSV format and submission to the CSSF
- Ongoing maintenance and update of the register
Duration
- 1h30
Language
- French/English
Practicalities
- Access sent within 24 hours
- 100% online training accessible from computer, tablet and smartphone
- Certificate of participation issued by an approved professional training organisation under the number 10060172/3.
Knowledge check
- Knowledge validation test at the end of each chapter
Learning method and pedagogy
- Theoretical presentations & practical cases
- Quizzes
- Animations, diagrams & summaries
Group discounts
Send your request by email to constance@easylearning.eu
- Between 11 and 25 accesses: 10 % discount + free reporting
- Between 26 and 50 accesses: 15% discount + free reporting
- Between 51 and 100 accesses: 20% discount + free reporting
- 100+ accesses: Ask for a tailor-made offer
Personalisation (Ask for a quote)
- Add your logo to the course
- Add your internal documents (procedure, risk analysis, etc.)
- Add practical case studies specific to your sector
- Creation of tailor-made training courses

