# Federal Incident Response for Agency Practitioners Course

Canonical URL: <https://www.graduateschool.edu/courses/federal-incident-response-for-agency-practitioners>

## Overview

This course develops the capability to run a federal incident response program from end to end — not simply reacting to a single case, but designing, operating, and steadily improving the program behind it.

The structure follows NIST SP 800-61 Revision 3, which frames incident response against the six NIST Cybersecurity Framework 2.0 Functions instead of the older standalone four-phase model. Govern, Identify, and Protect account for the preparatory work that lowers both the odds and the cost of an incident. Detect, Respond, and Recover account for the reactive work of finding it, containing it, and restoring operations. Improvement returns lessons learned to the preparation side continuously, rather than only once a case closes.

Mandatory federal reporting duties run through the Respond function throughout, because reporting clocks start at detection rather than at closure. The course ends with a full-lifecycle capstone simulation and a tabletop exercise design workshop, worked alongside the instructor, so practitioners leave able to build and facilitate their own exercises back at the agency.

## What you'll learn

- Describe the governance and legal basis for federal incident response — FISMA, NIST SP 800-61 Rev. 3, OMB memoranda, and CISA directives — and explain how the Govern function anchors the program
- Explain how the Identify and Protect functions put readiness in place ahead of any incident
- Detect and classify incidents with NCISS scoring and the federal incident categories
- Carry out containment and eradication while preserving evidence and coordinating across stakeholders
- Determine which mandatory reporting obligations attach to a given incident, and meet the deadlines
- Carry out recovery actions and recovery communications that restore operations
- Run a structured post-incident review and turn the findings into program improvements
- Design and facilitate a tabletop exercise, including scenario design and a Master Scenario Events List (MSEL)
- Walk a simulated incident through the full lifecycle, from detection to after-action report

## Curriculum

#### Module 1. Program Governance and Risk Management Strategy 

- The federal IR landscape, the IR charter and CSIRC/SOC standup, roles and a RACI matrix, program maturity and metrics

#### Module 2. Risk-Informed Readiness 

- Asset and risk awareness that tunes an IR program to the agency's real exposure, and the preventive controls and workforce readiness that keep detection and response from being overwhelmed

#### Module 3. Detection and Classification

- Detection sources and the 2026 logging baseline, triage and NCISS scoring, determining major-incident status, applied classification exercise

#### Module 4. Containment and Eradication 

- Containment strategy, coordinating across on-premises, cloud and OT environments, evidence preservation and chain of custody, root cause analysis and eradication

#### Module 5. Incident Reporting, Notification and Communication 

- The one-hour CISA notification, the seven-day congressional notification and annual FISMA reporting, PII and breach-specific notification, and a horizon scan of pending rules

#### Module 6. Restoration and Recovery Communication 

- Phased restoration and return-to-operations sign-off, aligning recovery with binding remediation deadlines, and keeping leadership and oversight informed

#### Module 7. Post-Incident Review and Lessons Learned

- After-action methodology, root-cause-to-control mapping, closing the loop back into governance and readiness

#### Module 8. Tabletop Exercise Design

- Exercise design fundamentals and MSELs, building realistic scenarios, facilitation and evaluation, and a design workshop

#### Module 9. Capstone Simulation and Program Self-Assessment 

- A full-lifecycle simulated incident worked through every Function in sequence, then a program self-assessment and 90-day action plan

## Schedule
- Nov 9, 2026 – Nov 10, 2026 — Live Online
- Jan 25, 2027 – Jan 26, 2027 — Live Online
- Feb 17, 2027 – Feb 18, 2027 — Live Online
- Mar 17, 2027 – Mar 18, 2027 — Live Online
- Apr 12, 2027 – Apr 13, 2027 — Live Online
- May 25, 2027 – May 26, 2027 — Live Online
- Jun 21, 2027 – Jun 22, 2027 — Live Online
- Jul 7, 2027 – Jul 8, 2027 — Live Online

## Instructors

### Wes Bryan — Instructor

Wes Bryan resides in Gainesville, Florida, and has built his career around technology, education, and helping others understand complex subjects. He values continuous learning, clear communication, and practical problem-solving. Outside of work, Wesley enjoys running, hiking, fishing, and spending time outdoors. He also has a strong interest in music and literature, enjoys reading both fiction and nonfiction, as well as playing guitar.

### Chuck Moore — Instructor

With more than 25 years of experience in IT and cybersecurity, Chuck has built a career on a strong foundation in security, networking, help desk operations, and technical training. He has helped organizations strengthen their security posture by identifying vulnerabilities, conducting threat assessments, implementing security controls, and ensuring compliance with industry standards. Combining extensive technical expertise with a passion for education, Chuck equips professionals with the knowledge and practical skills needed to recognize risks, risks and respond effectively.

## Pricing

**Tuition:** $1049
