RCCE Course
Course #917

Crisis management Playbook for Teams

📊 Level: Intermediate
⏱️ Duration: 2 Days
🏷️ Track: Incident Response
📋 Prerequisites: IR foundations
🖥️ Mode: Online Instructor-Led
📝 Course Description

RCCE students will learn incident detection, containment procedures, evidence preservation, communication protocols, and post-incident analysis. RCCE students will learn to respond to security incidents with structured methodologies, coordinate cross-functional teams under pressure, execute containment and recovery operations, and drive continuous improvement through thorough post-incident reviews. This team-oriented course builds collaborative workflows and organizational playbooks for security operations. Building on core knowledge, RCCE students will learn to create and implement standardized procedures that enable consistent performance across team members and shifts. Students develop the documentation, communication, and coordination skills needed for effective team-based security operations.

🎯 Target Audience
  • Security Engineers building defensive controls
  • Security Analysts and Blue Team members
  • Systems Administrators with security responsibilities
  • GRC and Risk Professionals supporting controls
  • Professionals implementing Crisis management Playbook for Teams
🧠 What You Will Learn
  • Execute hands-on tasks for crisis management playbook for
  • Explain Course Overview fundamentals
  • Execute hands-on tasks for what you will learn
  • Execute hands-on tasks for course structure — covering 6 hours of instruction and labs.
  • Build detections and response workflows for privilege escalation, including Preparation phase emphasis.
  • Build detections and response workflows for privilege escalation
  • Execute hands-on tasks for crisis management team structure
  • Execute hands-on tasks for incident commander
  • Execute hands-on tasks for triage lead
  • Execute hands-on tasks for containment lead
  • Execute hands-on tasks for comms lead
📚 Course Outline
Module 01Crisis Management Playbook for
Module 02Course Overview
Module 03What You Will Learn
Module 04Course Structure
Module 05Incident Response Frameworks
Module 06Incident Response Lifecycle
Module 07Preparation ▶ Detection ▶ Containment ▶ Eradication ▶
Module 08Crisis Management Team Structure
Module 09Incident Commander
Module 10Triage Lead
Module 11Containment Lead
Module 12Comms Lead
Module 13Recovery Lead
Module 14Core Responsibilities
🧪 Lab Details

All hands-on labs run on Rocheston Rose X OS. Students practice crisis management playbook for teams by implementing the controls discussed in class, with a focus on real-world deployment, monitoring, and validation.

  • Lab 1: Execute hands-on tasks for crisis management playbook for
  • Lab 2: Explain Course Overview fundamentals
  • Lab 3: Execute hands-on tasks for what you will learn
  • Lab 4: Execute hands-on tasks for course structure
  • Lab 5: Build detections and response workflows for privilege escalation
📊 Skill Level
Intermediate
Beginner Intermediate Advanced Expert
Duration
2 Days
🎓
Certificate
Completion
🖥️
Lab Platform
Rose X OS
👨‍🏫
Mode of Training
Online Instructor-Led
🔥
Platform
Zelfire
🐦‍⬛
Cyber Range
Raven
📓
Study Material
CyberNotes
🏆 Certificate

Upon successful completion of this course, students will receive an official RCCE Course Completion Certificate for Crisis management Playbook for Teams, verifiable through the Rocheston certification portal.

🔑 Student Access & Materials
  • Full access to all course materials and slide decks
  • Hands-on lab access on Rocheston Rose X OS environment
  • Access to Rocheston CyberNotes
  • Access to Rocheston Zelfire — EDR/XDR SIEM platform
  • Access to Rocheston Raven — online cyber range exercise platform
  • Access to Rocheston Vulnerability Vines AI