This course focuses on how organizations detect, respond to, and recover from cybersecurity threats through effective security operations. Students examine the functions of a Security Operations Center (SOC), incident response lifecycle, threat detection strategies, and the use of logs, alerts, and telemetry to investigate suspicious activity. The course emphasizes operational playbooks, escalation and communication procedures, evidence handling, and continuous improvement through lessons learned. Students gain the ability to design and evaluate operational workflows that support timely response and measurable security outcomes.
CYL 520: Security Operations
Level
Graduate