CERT - Software Engineering Institute
CERT - Certified Computer Security Incident Handler (CSIH)
Credential: CERT - Certified Computer Security Incident Handler (CSIH)
Credentialing Agency: CERT - Software Engineering Institute
Renewal Period: 3 years
The CERT – Software Engineering Institute, CERT – Certified Computer Security Incident Handler (CSIH) provides incident handling professionals with the latest knowledge and skills for handling cybersecurity incidents. CSIHs demonstrate competency in Protect Infrastructure, Event/Incident Detection, Triage & Analysis, Respond, and Sustain. Candidates should meet experience requirement and must pass a written exam.
More information can be found on the certifying agency's website.
CERT - Certified Computer Security Incident Handler (CSIH)
Attainability: 
Eligibility Requirements (View Details)
- Credential Prerequisite
- Experience: 1 year recommended
- Education
- Training
- Membership
- Other
- Fee
Note: This credential may have multiple options for a Service member to meet eligibility requirements. Requirements listed here are based on the minimum degree required.
To view other options, see the Eligibility tab.
Exam Requirements (View Details)
- Exam
- Written Exam
- Oral Exam
- Practical Exam
- Performance Assessment
Exam Administration (View Details)
- In-person exam
- Remote proctored on-line exam
- Third-party test vendor
Renewal Period: 3 years
- Continuing Education
- Exam
- Continuing Education OR Exam
- Fee
- Other
CERT - Software Engineering Institute
4500 Fifth Avenue
Pittsburgh, PA 15213-2612
Phone: (412) 268-5800
Fax: (412) 268-6989
Email: info@sei.cmu.edu
Candidate should have one or more years of experience in incident handling and/or equivalent security-related experience.
The CERT - Certified Computer Security Incident Handler (CSIH) credential has the following other requirements:
-
Candidate must submit an application with a current resume and a Certification Recommendation Form and may take the exam only after notification of acceptance.
-
Protect Infrastructure (7%)
-
Assist constituents with correcting problems identified by vulnerability scanning activities
-
Implement changes to the computing infrastructure (to stop or mitigate an ongoing incident, to stop or mitigate the potential exploitation of a vulnerability, or as a result of postmortem reviews or other process improvement mechanisms)
-
Provide constituents with guidance in best practices for protecting their systems and networks
-
Event/Incident Detection (17%)
-
Monitor networks and information systems for security
-
Analyze the data or indicators from the networks and systems being monitored
-
Enter event/incident reports received from the constituency into the incident management knowledgebase
-
Collect incident data and intrusion artifacts (e.g., malware, logs) to enable mitigation of incidents
-
Perform initial, forensically sound collection of images for forensic analysis and investigation
-
Identify missing data or additional sources of information and artifacts
-
Triage and Analysis (28%)
-
Categorize events using the organization's standard category definitions
-
Perform correlation analysis on event reports to determine if there is affinity between two or more events
-
Prioritize events (includes determining scope, urgency, and potential impact)
-
Assign events for further analysis, response, or disposition/closure
-
Determine cause and symptoms of the incident
-
Analyze intrusion artifacts and malware (e.g., malware, source code, Trojan horse programs) to understand their purpose and/or to identify the specific vulnerability
-
Perform vulnerability analysis
-
Determine the risk, threat level, or business impact of a confirmed incident
-
Respond (40%)
-
Develop an incident response strategy and plan to limit incident effect and to repair incident damage
-
Perform real-time incident response tasks (e.g., direct system remediation) to support deployable incident response teams
-
Determine the risk of continuing operations
-
Change passwords
-
Improve defenses
-
Remove the cause of the incident
-
Validate the system
-
Identify relevant stakeholders that need to be contacted or that may have a vested interest or vital role in communications about an organizational incident
-
Identify the appropriate communications protocols and channels (media and message) for each type of stakeholder
-
Coordinate, integrate, and lead team responses with other internal groups (e.g., IT, management, compliance, legal, human resources), according to applicable policies and procedures
-
Provide notification service to other constituents (e.g., write and publish guidance or reports on incident findings) to enable constituents to protect their assets and/or detect similar incidents
-
Report and coordinate incidents with appropriate external organizations or groups in accordance with organizational guidelines, policies, and procedures
-
Serve as technical experts and liaisons to law enforcement personnel (e.g., to explain incident details, provide testimony)
-
Track and document incidents from initial detection through final resolution
-
Assign and label data/information according to the appropriate class or category of sensitivity
-
Collect and retain information on all events/incidents in support of future analytical efforts and situational awareness
-
Enter information (shift change transitions, current state of activity) into an operations log or record of daily operational activity
-
Sustain (8%)
-
Perform risk assessments on incident management systems and networks
-
Run vulnerability scanning tools on incident management systems and networks
There are a number of resources available to help you prepare for the CERT - Certified Computer Security Incident Handler (CSIH) examination:
An additional resource is O'Reilly Learning Safari Books Online, a searchable digital library that provides online access to thousands of books, training videos and conference sessions. See the Educational Resources section on the
Related Sites page here on COOL to learn how to get free access.
-
Exam Administration
Credential exams may be administered in-person at a testing site, proctored on-line remotely, or have options for both. If an exam is administered through a test vendor, the third-party test vendor box will be checked. The following test administration options apply to the CERT - Certified Computer Security Incident Handler (CSIH) credential where checked:
- In-person exam
- Remote proctored on-line exam
- Third-party test vendor
-
Third-Party Test Vendor Information
Testing for this credential is handled by the following vendor:
Kryterion
The test centers are located in the U.S.
To find out more, use the following links on the Kryterion website:
CERT - Certified Computer Security Incident Handler (CSIH)
Renewal Period: 3 years
The CERT - Certified Computer Security Incident Handler (CSIH) credential has the following recertification information:
-
Certification holders are required to earn 60 Professional Development Units (PDUs) during the three-year certification period. For details, see the CSIH renewal webpage.
-
Note: Marine Corps COOL will only pay recertification fees for the current year, no arrears will be paid.
Voucher requests for recertification fees must be submitted with proof of the current status of the certification (for example, a screen shot of your
credentialing agency dashboard or a copy of a current fee receipt).
MOS is Military Occupational Specialty
ASI is Additional Skill Identifier
WOMOS is Warrant Officer Military Occupational Specialty
AOC is Area Of Concentration Officer
Functional Area
Branch
Bright Outlook – new job opportunities are very likely in the future for this job
This is an official U.S. Marine Corps website
Updated: January 29, 2021
Marine Occupations Table Legend
Related As
The military occupations shown in this table are related to this credential in one of three ways: Most, Some, or Other.
MOST
This credential is directly related to most of the major duties associated with the military occupation (at least 80%). Note that the credential may require additional education, training or experience before you are eligible for it.
SOME
This credential is related to some tasks associated with the duties of the military occupation (related 80% to at least one or more critical tasks but less than 80% of all of the entire military occupation). Note that the credential may require additional education, training or experience before you are eligible for it.
OTHER
This credential is related to this military occupation, but is more advanced or specialized and therefore will most likely require additional education, training, or experience.
COOL$
Contact usmccool@navy.mil or call 850-452-6337/6583 for a Marine Corps COOL Program Analyst.
Federal Occupations Table Legend
Related As
The federal occupations shown in this table are related to this credential in one of three ways: Most, Some, or Other.
MOST
This credential is directly related to most of the major duties associated with the federal occupation (at least 80%). Note that the credential may require additional education, training or experience before you are eligible for it.
SOME
This credential is related to some tasks associated with the duties of the federal occupation (related 80% to at least one or more critical tasks but less than 80% of all of the entire military occupation). Note that the credential may require additional education, training or experience before you are eligible for it.
OTHER
This credential is related to this federal occupation, but is more advanced or specialized and therefore will most likely require additional education, training, or experience.
Civilian Occupations Table Legend
Bright Outlook
The Bright Outlook icon indicates that new job opportunities are very likely in the future for this job. Click the links in this column to go to the external link My Next Move For Veterans State Map.
Registered Apprenticeship
The Registered Apprenticeship icon indicates that this job has an apprenticeship program registered with the U.S. Department of Labor. Click the links in this column to go to the Apprenticeship Finder and enter career path or location to find apprenticeship opportunities
Local Salary Information
Click the links in this column to go to the external link My Next Move for Veterans web site to view salary and employment information for the job.
Top