Online professional certificate

Professional Certificate in Information Security Analysis: Monitoring, Triage and Incident Handoff

Turn incomplete security signals into evidence-qualified decisions, reproducible investigations and accountable incident handoffs.

Format
Online, self-paced
Study time
Up to 1 month
Curriculum
20 applied lessons
Language
English

Practical capability

Investigate security signals with discipline, evidence and clear authority.

The course develops six connected capability groups while keeping offensive testing, legal decisions, executive risk ownership and third-party certification outside the analyst role.

01Evidence-led triage

Turn alerts into bounded questions, priorities and evidence-qualified dispositions.

02Reproducible investigation

Retain sources, entities, time ranges, queries, timelines, alternatives and confidence.

03Cross-domain evidence

Correlate identity, endpoint, network, email, cloud and application records without overclaiming.

04Controlled response

Recommend proportionate actions with exact targets, approval, preservation, rollback and verification.

05Decision-ready handoff

Communicate verified facts, uncertainty, ownership, deadlines and the next required decision.

06Human-controlled AI

Use AI only as an optional drafting and checking aid under data protection and human validation.

Who this course is for

A practical route into defensive information-security analysis.

Designed for beginning, transitioning and developing professionals who need a repeatable way to triage, investigate, document and hand off defensive security work.

ISAInformation security analyst
SOCSOC analyst
CDACyber defense analyst
IRJunior incident-response analyst
ITIT professional moving into security

The analyst workflow

Move from signal to verified decision or clean handoff.

Practise one connected sequence that keeps evidence quality, uncertainty, ownership and the next decision visible.

Step 1Frame scope, authority and the question
Step 2Validate telemetry and context
Step 3Test hypotheses across evidence
Step 4Recommend a bounded decision
Step 5Record, brief, hand off and verify

Curriculum

Four modules. Twenty applied lessons.

Module 1

Analyst Foundations: Evidence, Context and Triage

A security alert is not yet an incident, and a tool score is not yet a conclusion. The analyst’s first responsibility is to turn an uncertain signal into a controlled piece of professional work. That means confirming what can be examined, understanding the quality of available data, adding the business context that makes technical activity meaningful, choosing a proportionate triage outcome, and leaving a record another person can continue without rebuilding the case.

01The Defensive Analyst Role, Authority and Evidence Standards

By the end of the lesson, you will be able to define the analyst’s responsibility for a security signal, confirm the scope of permitted analysis, separate source statements from verified findings and inference, choose proportionate confidence language, and document an escalation when a requested action lies outside your authority.

Five practical steps

  1. Set the authorized scope and the question
  2. Review the supplied synthetic evidence and its limitations
  3. Complete the lesson's professional artifact
  4. Critique the reasoning, wording and control boundaries
  5. Record the next decision, owner, verification or handoff

Primary deliverable: Analyst Decision Boundary and Evidence Note.

02Security Telemetry, Data Quality and Coverage Gaps

By the end of the lesson, you will be able to select relevant telemetry for a defensive question, evaluate source and field quality, distinguish event time from collection time, identify entity-linking risks, document coverage gaps, and state how those gaps limit a triage verdict.

Five practical steps

  1. Set the authorized scope and the question
  2. Review the supplied synthetic evidence and its limitations
  3. Complete the lesson's professional artifact
  4. Critique the reasoning, wording and control boundaries
  5. Record the next decision, owner, verification or handoff

Primary deliverable: Telemetry Coverage and Quality Map.

03Assets, Identities, Business Context and Risk

By the end of the lesson, you will be able to identify the entities involved in a signal, verify their ownership and relationships, add relevant privilege and business context, describe exposure and potential consequence without overstating impact, and produce a risk-enrichment sheet that supports triage.

Five practical steps

  1. Set the authorized scope and the question
  2. Review the supplied synthetic evidence and its limitations
  3. Complete the lesson's professional artifact
  4. Critique the reasoning, wording and control boundaries
  5. Record the next decision, owner, verification or handoff

Primary deliverable: Context and Risk Enrichment Sheet.

04Alert Triage, Prioritization and Evidence-Qualified Verdicts

By the end of the lesson, you will be able to verify alert identity and scope, identify the decision question, assess evidence and business context, assign priority through a transparent rationale, select a triage outcome, write an evidence-qualified verdict, and define the next action or escalation.

Five practical steps

  1. Set the authorized scope and the question
  2. Review the supplied synthetic evidence and its limitations
  3. Complete the lesson's professional artifact
  4. Critique the reasoning, wording and control boundaries
  5. Record the next decision, owner, verification or handoff

Primary deliverable: Alert Triage Decision Record.

05Case Records, Shift Handoffs and Decision-Ready Escalation

By the end of the lesson, you will be able to maintain a reproducible case record, summarize findings without losing uncertainty, request a decision with consequence and deadline, transfer work to a named receiver, confirm acceptance, and close or continue the case with every remaining action owned.

Five practical steps

  1. Set the authorized scope and the question
  2. Review the supplied synthetic evidence and its limitations
  3. Complete the lesson's professional artifact
  4. Critique the reasoning, wording and control boundaries
  5. Record the next decision, owner, verification or handoff

Primary deliverable: Triage and Handoff Packet.

Module 2

Reproducible Investigation Across Security Domains

An alert rarely contains the whole story. An analyst must turn scattered records into a defensible account of what was observed, what probably happened, what remains unknown, and which person owns the next decision. This module teaches that work as a reproducible investigation rather than a sequence of tool clicks. You will build hypotheses, normalize time, preserve query details, correlate identifiers carefully, and distinguish an indicator from access, execution, persistence, or impact.

06Hypotheses, Timelines and Cross-Source Correlation

Apply the lesson method to a synthetic defensive-security case and produce a reviewable workplace artifact.

Five practical steps

  1. Set the authorized scope and the question
  2. Review the supplied synthetic evidence and its limitations
  3. Complete the lesson's professional artifact
  4. Critique the reasoning, wording and control boundaries
  5. Record the next decision, owner, verification or handoff

Primary deliverable: Investigation Reasoning Workbook.

07Identity, Authentication and Session Investigation

Apply the lesson method to a synthetic defensive-security case and produce a reviewable workplace artifact.

Five practical steps

  1. Set the authorized scope and the question
  2. Review the supplied synthetic evidence and its limitations
  3. Complete the lesson's professional artifact
  4. Critique the reasoning, wording and control boundaries
  5. Record the next decision, owner, verification or handoff

Primary deliverable: Identity and Session Investigation Sheet.

08Endpoint and Process Evidence

Apply the lesson method to a synthetic defensive-security case and produce a reviewable workplace artifact.

Five practical steps

  1. Set the authorized scope and the question
  2. Review the supplied synthetic evidence and its limitations
  3. Complete the lesson's professional artifact
  4. Critique the reasoning, wording and control boundaries
  5. Record the next decision, owner, verification or handoff

Primary deliverable: Endpoint Process Investigation Record.

09Network, Email and Communication Evidence

Apply the lesson method to a synthetic defensive-security case and produce a reviewable workplace artifact.

Five practical steps

  1. Set the authorized scope and the question
  2. Review the supplied synthetic evidence and its limitations
  3. Complete the lesson's professional artifact
  4. Critique the reasoning, wording and control boundaries
  5. Record the next decision, owner, verification or handoff

Primary deliverable: Communication Path Evidence Map.

10Cloud, SaaS and Application Audit Evidence

Apply the lesson method to a synthetic defensive-security case and produce a reviewable workplace artifact.

Five practical steps

  1. Set the authorized scope and the question
  2. Review the supplied synthetic evidence and its limitations
  3. Complete the lesson's professional artifact
  4. Critique the reasoning, wording and control boundaries
  5. Record the next decision, owner, verification or handoff

Primary deliverable: Cloud and Application Audit Evidence Matrix.

Module 3

Controlled Response, Exposure and Detection Improvement

Investigation becomes useful when it leads to a careful decision: contain a verified threat, reduce a real exposure, improve a weak detection, or explain why no change is justified. This module teaches that transition without turning an analyst into an unrestricted system administrator or incident commander. You will learn to define the exact target, confirm the action boundary, preserve what must be retained, request approval when consequences exceed your role, and verify the resulting state instead of trusting a success message. You will also distinguish a public vulnerability from a locally relevant exposure and a promising detection idea from a production-ready rule.

11Incident Response Lifecycle and Bounded Containment

Apply the lesson method to a synthetic defensive-security case and produce a reviewable workplace artifact.

Five practical steps

  1. Set the authorized scope and the question
  2. Review the supplied synthetic evidence and its limitations
  3. Complete the lesson's professional artifact
  4. Critique the reasoning, wording and control boundaries
  5. Record the next decision, owner, verification or handoff

Primary deliverable: Containment Decision Record.

12Vulnerability and Exposure Validation

Apply the lesson method to a synthetic defensive-security case and produce a reviewable workplace artifact.

Five practical steps

  1. Set the authorized scope and the question
  2. Review the supplied synthetic evidence and its limitations
  3. Complete the lesson's professional artifact
  4. Critique the reasoning, wording and control boundaries
  5. Record the next decision, owner, verification or handoff

Primary deliverable: Exposure Validation Brief.

13Detection Hypotheses, Rule Testing and Change Control

Apply the lesson method to a synthetic defensive-security case and produce a reviewable workplace artifact.

Five practical steps

  1. Set the authorized scope and the question
  2. Review the supplied synthetic evidence and its limitations
  3. Complete the lesson's professional artifact
  4. Critique the reasoning, wording and control boundaries
  5. Record the next decision, owner, verification or handoff

Primary deliverable: Detection Change Test Plan.

14Safe Scripting, Automation and AI-Assisted Analysis

Apply the lesson method to a synthetic defensive-security case and produce a reviewable workplace artifact.

Five practical steps

  1. Set the authorized scope and the question
  2. Review the supplied synthetic evidence and its limitations
  3. Complete the lesson's professional artifact
  4. Critique the reasoning, wording and control boundaries
  5. Record the next decision, owner, verification or handoff

Primary deliverable: Automation Control Sheet.

15Stakeholder Briefing, Recovery Verification and Post-Incident Learning

Apply the lesson method to a synthetic defensive-security case and produce a reviewable workplace artifact.

Five practical steps

  1. Set the authorized scope and the question
  2. Review the supplied synthetic evidence and its limitations
  3. Complete the lesson's professional artifact
  4. Critique the reasoning, wording and control boundaries
  5. Record the next decision, owner, verification or handoff

Primary deliverable: Recovery and Learning Brief.

Module 4

Operational Practice and Professional Readiness

Security analysis is sustained work, not a sequence of isolated technical puzzles. An analyst must control a changing queue, limit unfinished work, make progress when records are noisy or incomplete, and recognize situations that require specialized human ownership. This module turns the analytical and response methods from earlier modules into a dependable operating rhythm. The emphasis is on choices, communication, and work products that keep risk visible without pretending that every uncertainty can be resolved immediately.

16Shift Operations, Queue Control and Work-in-Progress Discipline

Apply the lesson method to a synthetic defensive-security case and produce a reviewable workplace artifact.

Five practical steps

  1. Set the authorized scope and the question
  2. Review the supplied synthetic evidence and its limitations
  3. Complete the lesson's professional artifact
  4. Critique the reasoning, wording and control boundaries
  5. Record the next decision, owner, verification or handoff

Primary deliverable: Shift Queue Control Board.

17Ambiguous, Noisy and Incomplete Cases

Apply the lesson method to a synthetic defensive-security case and produce a reviewable workplace artifact.

Five practical steps

  1. Set the authorized scope and the question
  2. Review the supplied synthetic evidence and its limitations
  3. Complete the lesson's professional artifact
  4. Critique the reasoning, wording and control boundaries
  5. Record the next decision, owner, verification or handoff

Primary deliverable: Ambiguity Reduction Worksheet.

18High-Risk Escalation, Privacy, Legal and Safety Boundaries

Apply the lesson method to a synthetic defensive-security case and produce a reviewable workplace artifact.

Five practical steps

  1. Set the authorized scope and the question
  2. Review the supplied synthetic evidence and its limitations
  3. Complete the lesson's professional artifact
  4. Critique the reasoning, wording and control boundaries
  5. Record the next decision, owner, verification or handoff

Primary deliverable: High-Risk Escalation Routing Brief.

19Building an Evidence Portfolio and Truthful ATS Resume

Apply the lesson method to a synthetic defensive-security case and produce a reviewable workplace artifact.

Five practical steps

  1. Set the authorized scope and the question
  2. Review the supplied synthetic evidence and its limitations
  3. Complete the lesson's professional artifact
  4. Critique the reasoning, wording and control boundaries
  5. Record the next decision, owner, verification or handoff

Primary deliverable: Evidence Portfolio and Resume Claim Matrix.

20Integrated Analyst Practice and Capstone Readiness

Apply the lesson method to a synthetic defensive-security case and produce a reviewable workplace artifact.

Five practical steps

  1. Set the authorized scope and the question
  2. Review the supplied synthetic evidence and its limitations
  3. Complete the lesson's professional artifact
  4. Critique the reasoning, wording and control boundaries
  5. Record the next decision, owner, verification or handoff

Primary deliverable: Capstone Investigation Execution Plan.

Applied capstone

Investigate the Northstar identity and cloud case.

Use the complete analyst workflow on one fictional event sequence. The goal is a defensible decision and handoff, not a dramatic claim.

The situation

A finance account records a new session, an authentication-method change and cloud-resource access. The legitimate user confirms a separate session and denies the suspicious one.

Your task

Define authority, triage the signal, plan and record checks, build a UTC timeline and evidence matrix, write a qualified finding, recommend bounded response, brief the business owner and hand the case to Tier 2.

Northstar Analyst Case PackOne integrated professional record covering intake, triage, evidence, reasoning, response recommendation, briefing, handoff and closure learning.

The people behind MTF

Meet MTF faculty and the learner community.

Explore the professional backgrounds of MTF faculty and learn more about the international community studying with the Institute.

Enrollment

Enroll in Professional Certificate in Information Security Analysis: Monitoring, Triage and Incident Handoff

One-time course price: €10, including applicable taxes. Payment is processed securely by Stripe. No card details are stored on the MTF Institute website.

You will receive an email with access to the course. If you have any difficulties, please write to welcome@gtf.pt.

Secure payment on this page

Enter your enrollment email to continue in Stripe's encrypted form.

Cards, Apple Pay, Google Pay and other eligible methods

Questions and details

Frequently asked questions

Open the sections that matter to you, including scope, delivery, AI practice, research evidence and credential status.

Who is this information security analysis course for?

It is designed for aspiring and early-career information security analysts, SOC analysts, IT support professionals moving into security, and practitioners who want a coherent defensive investigation workflow. No specific commercial security platform is required.

What practical work will I complete?

Every lesson produces one reusable analyst artifact, including evidence, coverage, triage, investigation, containment, exposure, detection, automation, briefing and handoff records. The Northstar capstone combines the full workflow in a fictional identity and cloud investigation.

Does the course teach offensive security or live penetration testing?

No. The course is defensive and uses synthetic or explicitly authorized records. It does not authorize testing of third-party systems, credential use, exploit execution, malware operation or other intrusive activity.

How does the course address AI?

AI is treated as an optional drafting and checking aid. The learner protects data, verifies every output against source evidence, retains human ownership of decisions and can complete every activity without AI.

What is included in the Role Starter Pack?

The course includes a model Information Security Analyst job description, an ATS-friendly resume template with a clearly fictional example, and a model analyst SOP / operating playbook for supervised local adaptation.

What evidence supports the course design?

The curriculum is grounded in MTF Institute analysis of 100 current United States vacancies, a separate 24-source current-change study and an open Zenodo research record.

What certificate do I receive?

After completing the required activities and capstone, you receive the named MTF Institute course-completion certificate. It is not academic credit, a professional licence or a third-party cybersecurity certification.