Micro Focus ArcSight ESM Advanced Training Course
Micro Focus ArcSight ESM (Enterprise Security Manager) is a robust security information and event management (SIEM) solution designed to assist organizations in detecting, analyzing, and responding to cybersecurity threats and incidents in real time.
This instructor-led, live training (available online or onsite) targets advanced-level security analysts looking to enhance their skills in leveraging advanced Micro Focus ArcSight ESM content. The goal is to improve an organization's capability to detect, respond to, and mitigate cyber threats with greater precision and speed.
Upon completing this training, participants will be able to:
- Optimize the use of Micro Focus ArcSight ESM to strengthen monitoring and threat detection capabilities.
- Create and manage advanced ArcSight variables to refine event streams for more precise analysis.
- Develop and implement ArcSight lists and rules to achieve effective event correlation and alerting.
- Apply advanced correlation techniques to identify complex threat patterns and reduce false positives.
Course Format
- Interactive lectures and discussions.
- Extensive exercises and practice sessions.
- Hands-on implementation within a live-lab environment.
Course Customization Options
- To request customized training for this course, please contact us to arrange your schedule.
Course Outline
Introduction to ArcSight ESM
- Overview of SIEM and ArcSight ESM.
- Understanding the ArcSight ESM architecture.
Configuring ArcSight Connectors
- Types of ArcSight connectors and their purposes.
- Installing and configuring ArcSight connectors.
- Managing connector updates and health.
ArcSight ESM Management
- Navigating the ArcSight Console.
- Managing users, groups, and permissions.
- Configuring network and device resources.
Correlation Rules and Security Monitoring
- Basics of correlation rules and their creation.
- Deploying correlation rules for real-time threat detection.
- Utilizing the dashboard for security monitoring.
Reporting and Visualization
- Creating custom reports for security analytics.
- Designing effective dashboards and visualizations.
- Best practices for reporting and alerting.
Active Lists, Session Lists, and Data Monitors
- Introduction to lists and data monitors in ArcSight.
- Configuring and managing lists for dynamic threat detection.
- Practical applications of data monitors.
Tool Optimization
- Customizing dashboards for enhanced operational visibility.
- Streamlining event streams for efficient monitoring and analysis.
Advanced Variable Construction and Developing Lists and Rules
- Techniques for creating complex variables in ArcSight.
- Using variables to filter and refine event data.
- Developing and managing lists for dynamic event categorization.
- Creating advanced rules for automated threat detection and response.
Advanced Correlation Techniques and Search Methods
- Strategies for correlating disparate event data to uncover sophisticated threats.
- Applying advanced correlation for real-world threat scenarios.
- Leveraging ArcSight's search capabilities for deep-dive investigations and threat hunting.
- Tips and tricks for constructing effective search queries.
System Maintenance and Troubleshooting
- ArcSight ESM backup and restore procedures.
- Monitoring system performance and troubleshooting common issues.
- Best practices for ArcSight ESM maintenance.
Summary and Next Steps
Requirements
- Basic knowledge of cybersecurity concepts and SIEM (Security Information and Event Management) fundamentals.
- Prior experience with Micro Focus ArcSight ESM.
Audience
- Security analysts.
- Cybersecurity and IT professionals.
Open Training Courses require 5+ participants.
Micro Focus ArcSight ESM Advanced Training Course - Booking
Micro Focus ArcSight ESM Advanced Training Course - Enquiry
Micro Focus ArcSight ESM Advanced - Consultancy Enquiry
Testimonials (1)
The report and rules setup.
Jack - CFNOC- DND
Course - Micro Focus ArcSight ESM Advanced
Upcoming Courses
Related Courses
AI and IT Audit
14 HoursThis instructor-led live training in Mexico (online or onsite) is designed for intermediate-level IT auditors who wish to effectively incorporate AI tools into their audit practices.
By the end of this training, participants will be able to:
- Grasp the core concepts of artificial intelligence and how it is applied in the context of IT auditing.
- Utilize AI technologies such as machine learning, NLP, and RPA to improve audit efficiency, accuracy, and scope.
- Perform risk assessments using AI tools, enabling continuous monitoring and proactive risk management.
- Integrate AI into audit planning, execution, and reporting, enhancing the overall effectiveness of IT audits.
CCTV Security
14 HoursThis instructor-led, live training in Mexico (online or onsite) is aimed at security managers who wish to learn basic to intermediate-level CCTV security surveillance and management skills.
By the end of this training, participants will be able to:
- Familiarize the types of CCTV systems and know their benefits and features.
- Understand cabling and CCTV systems setup requirements.
- Install, configure, and manage CCTV systems.
Certified Fraud Examiner (CFE) Preparation
70 HoursThis instructor-led live training in Mexico (online or on-site) is tailored for advanced-level professionals who wish to gain a comprehensive understanding of fraud examination concepts and prepare for the Certified Fraud Examiner (CFE) exam.
By the end of this training, participants will be able to:
- Gain a comprehensive understanding of fraud examination principles and the fraud examination process.
- Learn to identify, investigate, and prevent various types of financial fraud schemes.
- Understand the legal environment related to fraud, including the legal elements of fraud, relevant laws, and regulations.
- Acquire practical skills in conducting fraud investigations, including evidence collection, interviewing techniques, and data analysis.
- Learn to design and implement effective fraud prevention and deterrence programs within organizations.
- Gain confidence and knowledge to successfully pass the Certified Fraud Examiner (CFE) exam.
CISM - Certified Information Security Manager
28 HoursDescription:
Please note that the updated CISM exam content outline applies to exams beginning on June 1, 2022.
CISM® stands as the most prestigious and rigorous qualification for Information Security Managers worldwide today. This credential offers you a pathway to join an elite peer network of professionals capable of continuously learning and adapting to the expanding opportunities and challenges in Information Security Management.
Our CISM training methodology delivers comprehensive coverage of the four CISM domains, focusing on building strong conceptual foundations and solving questions released by ISACA for the CISM exam. This course serves as intense training and rigorous exam preparation for the ISACA’s Certified Information Security Manager (CISM®) Examination.
Our instructors encourage all participants to review the ISACA-released CISM QA&E (Questions, Answers, and Explanations) as part of their exam preparation. The QA&E is invaluable in helping participants understand the style of ISACA questions, the approach to solving them, and facilitates rapid retention of CISM concepts during live classroom sessions.
All our trainers bring extensive experience in delivering CISM training. We will thoroughly prepare you for the CISM examination.
Goal:
The primary objective is to help you pass your CISM examination on the first attempt.
Objectives:
- Apply the acquired knowledge in a practical manner that benefits your organization
- Establish and maintain an information security governance framework to achieve your organization's goals and objectives
- Manage information risk to an acceptable level to meet business and compliance requirements
- Establish and maintain information security architectures (people, process, technology)
- Integrate information security requirements into the contracts and activities of third parties/ suppliers
- Plan, establish, and manage the capability to detect, investigate, respond to, and recover from information security incidents to minimize business impact
Target Audience:
- Security professionals with 3-5 years of front-line experience
- Information security managers or individuals with management responsibilities
- Information security staff and assurance providers who require a deep understanding of information security management, including: CISOs, CIOs, CSOs, privacy officers, risk managers, security auditors, compliance personnel, BCP/ DR staff, and executive or operational managers responsible for assurance functions
Cybersecurity Governance, Risk & Compliance (GRC)
14 HoursThis instructor-led live training in Mexico (available online or onsite) is designed for intermediate-level cybersecurity professionals seeking to expand their understanding of GRC frameworks and apply them to secure and compliant business operations.
By the end of this training, participants will be able to:
- Understand the core components of cybersecurity governance, risk, and compliance.
- Conduct risk assessments and develop strategies to mitigate risks.
- Implement compliance measures and manage regulatory requirements.
- Develop and enforce security policies and procedures.
Cybersecurity Fundamentals
28 HoursDescription:
Cybersecurity expertise is in high demand, as threats continue to plague enterprises around the world. An overwhelming majority of professionals surveyed by ISACA recognise this and plan to work in a position that requires cybersecurity knowledge.
To fill this gap, ISACA has developed the Cybersecurity Fundamentals Certificate, which provides education and verification of skills in this area.
Objectives:
With cybersecurity threats continuing to rise and the shortage of appropriately-equipped security professionals growing worldwide, ISACA's Cybersecurity Fundamentals Certificate programme is the perfect way to quickly train entry-level employees and ensure they have the skills and knowledge they need to successfully operate in the Cyber arena.
Target Audience:
The certificate program is also one of the best ways to gain foundational knowledge in cybersecurity and begin to build your skills and knowledge in this crucial area.
Data Sovereignty Fundamentals for Enterprise Leaders
14 HoursThis instructor-led, live training (online or in-person) is designed for enterprise leaders who aim to understand data sovereignty principles and develop compliant data management strategies.
By the end of this training, participants will be able to define data sovereignty, identify applicable laws, assess compliance risks, and implement governance frameworks for cross-border data management.
DevOps Security: Creating a DevOps Security Strategy
7 HoursIn this instructor-led live course in Mexico, participants will learn how to develop an appropriate security strategy to address the challenges of DevOps security.
Encryption Key Management
21 HoursEncryption Key Management involves the secure creation, storage, distribution, rotation, and retirement of cryptographic keys to safeguard sensitive information and meet regulatory requirements.
This instructor-led, live training (available online or onsite) is designed for intermediate-level IT and security professionals seeking to implement robust encryption key management practices and systems within enterprise environments.
Upon completion of this training, participants will be able to:
- Comprehend the encryption key lifecycle and adhere to best practices for key protection.
- Configure and manage Key Management Systems (KMS) in both on-premises and cloud environments.
- Enforce access controls and auditing mechanisms for key usage.
- Ensure compliance with relevant regulations and standards regarding encryption key security.
Course Format
- Interactive lectures and discussions.
- Practical experience with key management tools in lab settings.
- Guided exercises focused on implementing a secure key lifecycle.
Course Customization Options
- To request customized training tailored to your infrastructure or compliance needs, please contact us to arrange.
Accessibility by Design (Compliance with EU ACT)
21 HoursThis course offers a comprehensive introduction to the newly implemented Accessibility Law, equipping developers with the practical skills necessary to design, develop, and maintain fully accessible applications. Beginning with a contextual discussion on the law's significance and implications, the training quickly transitions into hands-on coding practices, tools, and testing techniques to ensure compliance and inclusivity for users with disabilities.
PECB ISO/IEC 27001 Foundation
14 HoursWhy participate in this course?
The ISO/IEC 27001 Foundation training equips you with the essential knowledge to implement and manage an Information Security Management System (ISMS) in accordance with ISO/IEC 27001 standards. Throughout this course, you will gain a comprehensive understanding of the various ISMS components, including ISMS policies, procedures, performance metrics, leadership commitment, internal auditing, management reviews, and continuous improvement practices.
Upon completion of the course, you will be eligible to take the examination and apply for the "PECB Certified ISO/IEC 27001 Foundation" credential. Earning a PECB Foundation Certificate demonstrates that you have mastered the fundamental methodologies, requirements, framework, and management approaches associated with ISO/IEC 27001.
Who is this course for?
- Professionals currently involved in Information Security Management
- Individuals looking to acquire knowledge about the core processes of Information Security Management Systems (ISMS)
- Aspiring professionals interested in building a career in Information Security Management
Te methodology
- Lectures are enhanced with practical questions and real-world examples
- Hands-on exercises incorporate illustrative examples and group discussions
- Practice tests mirror the format and difficulty of the official Certification Exam
PECB ISO/IEC 27001 Lead Implementer
35 HoursInformation security threats and attacks increase and improve constantly. The best form of defense against them is the proper implementation and management of information security controls and best practices. Information security is also a key expectation and requirement of customers, legislators, and other interested parties.
This training course is designed to prepare participants in implementing an information security management system (ISMS) based on ISO/IEC 27001. It aims to provide a comprehensive understanding of the best practices of an ISMS and a framework for its continual management and improvement.
After attending the training course, you can take the exam. If you successfully pass it, you can apply for a “PECB Certified ISO/IEC 27001 Lead Implementer” credential, which demonstrates your ability and practical knowledge to implement an ISMS based on the requirements of ISO/IEC 27001.
Who Can Attend?
- Project managers and consultants involved in and concerned with the implementation of an ISMS
- Expert advisors seeking to master the implementation of an ISMS
- Individuals responsible for ensuring conformity to information security requirements within an organization
- Members of an ISMS implementation team
General information
- Certification fees are included in the exam price
- Training material containing over 450 pages of information and practical examples will be distributed
- A participation certificate of 31 CPD (Continuing Professional Development) credits will be issued
- In case of exam failure, you can retake the exam within 12 months free of charge
Educational approach
- This training course contains essay-type exercises, multiple-choice quizzes, examples, and best practices used in the implementation of an ISMS.
- The participants are encouraged to communicate with each other and engage in discussions when completing quizzes and exercises.
- The exercises are based on a case study.
- The structure of the quizzes is similar to that of the certification exam.
Learning objectives
This training course will help you:
- Gain a comprehensive understanding of the concepts, approaches, methods, and techniques used for the implementation and effective management of an ISMS
- Acknowledge the correlation between ISO/IEC 27001, ISO/IEC 27002, and other standards and regulatory frameworks
- Understand the operation of an information security management system and its processes based on ISO/IEC 27001
- Learn how to interpret and implement the requirements of ISO/IEC 27001 in the specific context of an organization
- Acquire the necessary knowledge to support an organization in effectively planning, implementing, managing, monitoring, and maintaining an ISMS
Compliance and the Management of Compliance Risk
21 HoursAudience
This course is designed for all employees who need a practical grasp of Compliance and effective Risk Management.
Course Format
The training employs a blended methodology that features:
- Guided discussions
- Slide-based presentations
- Case studies
- Real-world examples
Course Objectives
By the end of the course, participants will be able to:
Gain a solid understanding of the key aspects of Compliance, alongside national and international initiatives aimed at managing associated risks.
Explain how organizations and their teams can establish an effective Compliance Risk Management Framework.
Describe the responsibilities of the Compliance Officer and the Money Laundering Reporting Officer, and understand how these roles integrate within a business structure.
Identify critical risk areas in Financial Crime, particularly in the context of international operations, offshore centres, and high-net-worth clients.
Open Source Software (OSS) Management
14 HoursOpen Source Software (OSS) Management involves overseeing the entire lifecycle of open-source components within an organization, ensuring their use is secure, compliant, and efficient.
This instructor-led, live training, available online or onsite, targets intermediate-level IT professionals seeking to implement best practices for managing open-source software in enterprise and government settings.
By the conclusion of this training, participants will be able to:
- Develop effective OSS policies and governance frameworks.
- Utilize SBOM and SCA tools to identify, track, and manage open-source dependencies.
- Mitigate risks related to licensing and security vulnerabilities.
- Streamline OSS adoption to maximize innovation and cost savings.
Course Format
- Interactive lectures and discussions.
- Case studies and scenario-based exercises.
- Hands-on demonstrations using OSS management tools.
Customization Options
- This course can be customized to align with specific organizational OSS policies and toolchains. Please contact us to arrange.
PCI-DSS Practitioner
14 HoursThis instructor-led, live Payment Card Industry Professional training in Mexico (available online or in-person) offers a professional qualification for practitioners aiming to showcase their expertise and comprehension of the PCI Data Security Standard (PCI DSS).
Upon completing this training, participants will be able to:
- Comprehend the payment process and the PCI standards established to safeguard it.
- Grasp the roles and responsibilities of entities operating within the payment industry.
- Gain deep insight into and understanding of the 12 PCI DSS requirements.
- Demonstrate knowledge of PCI DSS and its application to organizations involved in the transaction process.