Skip to main content

Incident Management, Response and SOC (5 cr)

Code: TTC6060-3008

General information


Enrollment
18.11.2024 - 09.01.2025
Registration for the implementation has ended.
Timing
13.01.2025 - 30.04.2025
Implementation is running.
Number of ECTS credits allocated
5 cr
Local portion
0 cr
Virtual portion
5 cr
Mode of delivery
Online learning
Unit
School of Technology
Teaching languages
English
Seats
0 - 35
Degree programmes
Bachelor's Degree Programme in Information and Communications Technology
Teachers
Jarmo Nevala
Heikki Järvinen
Groups
TTV22S5
Tieto- ja viestintätekniikka (AMK)
TTV22S2
Tieto- ja viestintätekniikka (AMK)
TTV22S3
Tieto- ja viestintätekniikka (AMK)
TIC22S1
Bachelor's Degree Programme in Information and Communications Technology
TTV22S1
Tieto- ja viestintätekniikka (AMK)
TTV22S4
Tieto- ja viestintätekniikka (AMK)
ZJA25KTIKY2
Avoin amk, Kyberturvallisuus 2, Verkko
Course
TTC6060

Realization has 15 reservations. Total duration of reservations is 37 h 30 min.

Time Topic Location
Tue 14.01.2025 time 14:30 - 17:00
(2 h 30 min)
Incident Management, Response and SOC TTC6060-3008
Online
Tue 21.01.2025 time 14:30 - 17:00
(2 h 30 min)
Incident Management, Response and SOC TTC6060-3008
Online
Tue 28.01.2025 time 14:30 - 17:00
(2 h 30 min)
Incident Management, Response and SOC TTC6060-3008
Online
Tue 04.02.2025 time 14:30 - 17:00
(2 h 30 min)
Incident Management, Response and SOC TTC6060-3008
Online
Tue 11.02.2025 time 14:30 - 17:00
(2 h 30 min)
Incident Management, Response and SOC TTC6060-3008
Online
Tue 18.02.2025 time 14:30 - 17:00
(2 h 30 min)
Incident Management, Response and SOC TTC6060-3008
Online
Tue 04.03.2025 time 14:30 - 17:00
(2 h 30 min)
Incident Management, Response and SOC TTC6060-3008
Online
Tue 11.03.2025 time 14:30 - 17:00
(2 h 30 min)
Incident Management, Response and SOC TTC6060-3008
Online
Tue 18.03.2025 time 14:30 - 17:00
(2 h 30 min)
Incident Management, Response and SOC TTC6060-3008
Online
Tue 25.03.2025 time 14:30 - 17:00
(2 h 30 min)
Incident Management, Response and SOC TTC6060-3008
Online
Tue 01.04.2025 time 14:30 - 17:00
(2 h 30 min)
Incident Management, Response and SOC TTC6060-3008
Online
Tue 08.04.2025 time 14:30 - 17:00
(2 h 30 min)
Incident Management, Response and SOC TTC6060-3008
Online
Tue 15.04.2025 time 14:30 - 17:00
(2 h 30 min)
Incident Management, Response and SOC TTC6060-3008
Online
Tue 22.04.2025 time 14:30 - 17:00
(2 h 30 min)
Incident Management, Response and SOC TTC6060-3008
Online
Tue 29.04.2025 time 14:30 - 17:00
(2 h 30 min)
Incident Management, Response and SOC TTC6060-3008
Online
Changes to reservations may be possible.

Evaluation scale

0-5

Objective

The objective of the course
The student masters the most essential Security Operations Center functionalities such as organizational models, processes and technical environments.

Competences
EUR-ACE: Knowledge and understanding 
EUR-ACE: Engineering practice 

The learning objectives of the course
The student knows how to carry out different functionalities of a SOC: develop technical systems to enhance the detection capabilities of an organization, investigate detected incidents from information systems and work as a part of an organization's processes. The student can effectively work in a SOC and develop his/her work community.

Content

The course contains the concepts of SOC and organizational models. During the course, students design an organizational model for an SOC and technical tools to manage incidents.

Materials

Materials in the e-learning environment.

Teaching methods

- lectures
- independent study
- distance learning
- webinars
- small group learning
- exercises
- learning tasks

Employer connections

- visiting lecturers
- projects

Exam schedules

The possible date and method of the exam will be announced in the course opening.

Completion alternatives

The admission procedures are described in the degree rule and the study guide. The teacher of the course will give you more information on possible specific course practices.

Student workload

One credit (1 Cr) corresponds to an average of 27 hours of work.

- lectures 52 h
- exercises 15 h
- assignment 36 h
- independent study 32 h
Total 135 h

Assessment criteria, satisfactory (1)

Sufficient 1: The student understands some of the theory basis of SOCs. The student is able to design and implement some technical information systems for SOC. The student participates in process design in a group.

Satisfactory 2: The student understands the theory basis of SOCs. The student is able to design and implement the installations of technical information systems for an SOC. The student designs processes for an organization in a group.

Assessment criteria, good (3)

Good 3: The student has a versatile understanding of the theory basis of SOCs. The student is able to versatilely design and implement installations of technical information systems for an SOC. The student designs extensively the processes for an organization in a group.

Very good 4: The student has an in-depth understanding of the theory basis of SOCs. The student is able to thoroughly design and implement installations of technical information systems in a cyber security exercise. The student designs extensively the processes for an organization in a group.

Assessment criteria, excellent (5)

Excellent 5: The student has an out of the ordinary, excellent understanding of the theory basis of SOCs. The student is able to design and implement outstandingly the installations of technical information systems in a cyber security exercise. The student designs superbly the processes for an organization in a group.

Qualifications

Cyber Security

Further information

The course assessment methods will be presented during the first meeting.

Go back to top of page