Micro Focus ArcSight ESM Advanced Training Course
The Micro Focus ArcSight Enterprise Security Manager (ESM) serves as a robust Security Information and Event Management (SIEM) platform, enabling entities to identify, evaluate, and address cybersecurity incidents in real-time. This program is specifically developed for government agencies seeking scalable security infrastructure solutions.
This instructor-led training, available via online or onsite delivery, targets senior security analysts aiming to deepen their proficiency with advanced Micro Focus ArcSight ESM functionalities. The curriculum focuses on enhancing organizational capacity to detect, respond to, and mitigate cyber threats with increased accuracy and operational efficiency.
Upon completion of this instruction, participants will be equipped to:
- Leverage Micro Focus ArcSight ESM capabilities to strengthen monitoring and threat identification processes.
- Create and administer advanced ArcSight variables to streamline event streams for enhanced analytical precision.
- Design and deploy ArcSight lists and rules to facilitate effective event correlation and alerting mechanisms.
- Utilize sophisticated correlation methods to uncover complex threat indicators while minimizing false positive reports.
Course Delivery Format
- Engaging lectures and structured discussions.
- Extensive practical exercises and skill-building activities.
- Direct implementation within a live-lab simulation environment.
Customization Opportunities
- For entities requiring tailored training aligned with specific operational requirements, please contact our team to arrange customized services.
Course Outline
Introduction to ArcSight ESM
- Overview of SIEM and ArcSight ESM
- Understanding the ArcSight ESM architecture
Configuring ArcSight Connectors
- Types of ArcSight connectors and their purposes
- Installing and configuring ArcSight connectors
- Managing connector updates and health
ArcSight ESM Management
- Navigating the ArcSight Console
- Managing users, groups, and permissions
- Configuring network and device resources
Correlation Rules and Security Monitoring
- Basics of correlation rules and their creation
- Deploying correlation rules for real-time threat detection
- Utilizing the dashboard for security monitoring
Reporting and Visualization
- Creating custom reports for security analytics
- Designing effective dashboards and visualizations
- Best practices for reporting and alerting
Active Lists, Session Lists, and Data Monitors
- Introduction to lists and data monitors in ArcSight
- Configuring and managing lists for dynamic threat detection
- Practical applications of data monitors
Tool Optimization
- Customizing dashboards for enhanced operational visibility
- Streamlining event streams for efficient monitoring and analysis
Advanced Variable Construction and Developing Lists and Rules
- Techniques for creating complex variables in ArcSight
- Using variables to filter and refine event data
- Developing and managing lists for dynamic event categorization
- Creating advanced rules for automated threat detection and response
Advanced Correlation Techniques and Search Methods
- Strategies for correlating disparate event data to uncover sophisticated threats
- Applying advanced correlation for real-world threat scenarios
- Leveraging ArcSight's search capabilities for deep-dive investigations and threat hunting
- Tips and tricks for constructing effective search queries
System Maintenance and Troubleshooting
- ArcSight ESM backup and restore procedures
- Monitoring system performance and troubleshooting common issues
- Best practices for ArcSight ESM maintenance
Summary and Next Steps
Requirements
- Fundamental understanding of cybersecurity principles and Security Information and Event Management (SIEM) architectures
- Professional proficiency with Micro Focus ArcSight ESM
Target Audience
- Security analysts
- Cybersecurity and IT specialists serving for government entities
Runs with a minimum of 4 + people. For 1-to-1 or private group training, request a quote.
Micro Focus ArcSight ESM Advanced Training Course - Booking
Micro Focus ArcSight ESM Advanced Training Course - Enquiry
Micro Focus ArcSight ESM Advanced - Consultancy Enquiry
Testimonials (1)
The report and rules setup.
Jack - CFNOC- DND
Course - Micro Focus ArcSight ESM Advanced
Upcoming Courses
Related Courses
AI and IT Audit
14 HoursThis instructor-led, live training in US (delivered online or onsite) is designed for intermediate-level IT auditors seeking to integrate artificial intelligence tools into their audit operations.
Upon completion of this program, participants will be able to:
- Understand fundamental artificial intelligence principles and their application within the framework of IT auditing for government.
- Leverage AI technologies, including machine learning, natural language processing, and robotic process automation, to enhance audit efficiency, precision, and coverage.
- Conduct risk assessments using AI-driven tools to facilitate continuous monitoring and proactive risk management.
- Incorporate AI capabilities into audit planning, execution, and reporting phases to improve the overall efficacy of IT audits.
AI Security & Governance: Enterprise Implementation
7 HoursCourse Overview
This comprehensive curriculum addresses artificial intelligence security, governance, regulatory compliance, and risk mitigation strategies tailored for enterprise environments. The program is specifically developed for government and public sector personnel, including security analysts, compliance officers, and technology executives who oversee secure AI deployment and establish robust governance frameworks.
Accountability in Professional Regulatory Boards — Legal, Procedural, and Jurisprudential Aspects (TCU)
14 HoursAccountability in Professional Regulatory Boards is an applied course focusing on the legal framework, procedural duties, and TCU jurisprudence that guide oversight and accountability for professional councils in Brazil for government entities.
This instructor-led, live training (online or onsite) is aimed at intermediate-level to advanced-level professionals who wish to understand TCU oversight, prevent common irregularities, and strengthen internal controls and responses to audit findings.
Upon completion of this training, participants will be able to:
- Explain the institutional role of the TCU and the legal nature of professional councils.
- Identify common irregularities found by the TCU and understand relevant jurisprudence.
- Design internal control measures and segregation of duties to mitigate accountability risks.
- Prepare compliant annual accountability submissions (SISTC / e-Contas) and structured responses to TCU determinations.
Format of the Course
- Interactive lecture and legal analysis.
- Case study review and group discussion.
- Practical workshop and simulation exercises.
Course Customization Options
- To request a customized training for this course, please contact us to arrange.
BCS Practitioner Certificate in Information Risk Management (CIRM)
35 HoursWho is it for:
This program is designed for professionals engaged in information security and assurance disciplines, providing resources tailored for government sectors.
What will I learn:
Participants will demonstrate competency in the following areas:
- The strategic business advantages derived from effective information risk management.
- The application of standard terminology associated with information risk management.
- The execution of threat and vulnerability assessments, business impact analyses, and comprehensive risk evaluations.
- The fundamental principles governing controls and risk treatment strategies.
- The development of reporting formats that establish the foundation for a risk treatment plan.
- The implementation of information classification frameworks.
CCTV Security
14 HoursThis instructor-led, live training in US (online or onsite) is designed for security managers seeking to develop foundational to intermediate competencies in CCTV surveillance and management. This program delivers practical insights for government
Upon completion of this course, participants will be able to:
- Distinguish between various CCTV system types and identify their respective benefits and features.
- Evaluate cabling infrastructure and setup requirements for CCTV systems.
- Install, configure, and manage CCTV systems effectively.
Certified Fraud Examiner (CFE) Preparation
70 HoursThis instructor-led, live training in US (online or onsite) is aimed at advanced-level professionals who wish to gain a comprehensive understanding of fraud examination concepts and prepare for the Certified Fraud Examiner (CFE) exam.
By the end of this training, participants will be able to:
- Gain comprehensive knowledge of fraud examination principles and the fraud examination process.
- Learn to identify, investigate, and prevent various types of financial fraud schemes.
- Understand the legal environment related to fraud, including the legal elements of fraud, relevant laws, and regulations.
- Acquire practical skills in conducting fraud investigations, including evidence collection, interviewing techniques, and data analysis.
- Learn to design and implement effective fraud prevention and deterrence programs within organizations.
- Gain confidence and knowledge to successfully pass the Certified Fraud Examiner (CFE) exam.
CISM - Certified Information Security Manager
28 HoursDescription:
Note: The revised CISM exam content outline applies to examinations administered beginning on 1 June 2022.
The CISM® certification represents a globally recognized, rigorous credential for Information Security Managers. It provides a foundation for professionals to join a distinguished community dedicated to the continuous evolution of knowledge and expertise in Information Security Management.
This training program delivers comprehensive coverage of the four core CISM domains, emphasizing conceptual mastery and the application of ISACA-published exam questions. The course serves as intensive preparation for the ISACA Certified Information Security Manager (CISM®) Examination, designed to support candidates in achieving certification readiness.
Participants are advised to review the ISACA-published CISM QA&E (Questions, Answers and Explanations) resource as a primary study aid. This material is instrumental in familiarizing candidates with ISACA’s testing methodology and question structure, facilitating the rapid retention of key concepts during instruction.
All faculty members possess extensive experience in delivering CISM curriculum. The program ensures thorough preparation for the certification examination.
Goal:
The primary objective is to assist candidates in passing the CISM examination on their initial attempt.
Objectives:
- Apply acquired knowledge in ways that directly benefit organizational operations
- Develop and sustain an information security governance framework aligned with organizational goals
- Manage information risk to acceptable levels consistent with business needs and regulatory requirements
- Establish and maintain information security architectures encompassing people, processes, and technology
- Incorporate information security obligations into third-party contracts and supplier activities
- Plan, implement, and manage capabilities for the detection, investigation, response to, and recovery from information security incidents to reduce business impact
Target Audience:
- Security professionals with 3-5 years of hands-on experience
- Information security managers or individuals holding management responsibilities
- Information security personnel and assurance providers requiring comprehensive understanding of information security management, including: CISOs, CIOs, CSOs, privacy officers, risk managers, security auditors, compliance staff, business continuity/disaster recovery professionals, and executive or operational managers overseeing assurance functions
Cybersecurity Governance, Risk & Compliance (GRC)
14 HoursThis instructor-led live training program, offered in US via online or onsite delivery, is designed for intermediate-level cybersecurity practitioners seeking to deepen their knowledge of GRC frameworks and integrate them into secure, compliant organizational operations.
Upon completion of this curriculum, attendees will be equipped to:
- Analyze the fundamental elements of governance, risk, and compliance within cybersecurity.
- Execute risk assessments and formulate effective mitigation strategies for government and private sector contexts.
- Administer compliance protocols and manage adherence to regulatory mandates.
- Create, implement, and oversee security policies and procedural guidelines.
Cybersecurity Fundamentals
28 HoursDescription:
Cybersecurity expertise remains critically important as organizations worldwide face persistent digital risks. A significant majority of professionals surveyed by ISACA acknowledge this reality and intend to pursue roles requiring cybersecurity proficiency.
To address this demand, ISACA offers the Cybersecurity Fundamentals Certificate, which provides rigorous education and validation of competencies in this domain, tailored for government.
Objectives:
In response to escalating cyber threats and a global shortage of qualified security personnel, ISACA’s Cybersecurity Fundamentals Certificate program serves as an effective mechanism for rapidly training entry-level staff. This ensures they possess the necessary skills and knowledge to operate effectively within the cybersecurity landscape.
Target Audience:
This certificate program offers one of the most effective pathways for acquiring foundational cybersecurity knowledge and developing essential competencies in this vital field.
Data Sovereignty Fundamentals for Enterprise Leaders
14 HoursThis instructor-led training, available in online or onsite formats, is designed for enterprise executives seeking to master the principles of data sovereignty and formulate compliant data management strategies tailored for government.
Upon completion, participants will possess the ability to define data sovereignty, identify applicable legal requirements, evaluate compliance risks, and establish governance frameworks for cross-border data management.
Accessibility by Design (Compliance with EU ACT)
21 HoursThis curriculum offers a comprehensive overview of recent accessibility legislation and provides developers with the essential competencies required to construct, implement, and sustain fully compliant digital solutions. Following an initial examination of the statute’s significance and operational impact, the training transitions to practical implementation strategies, utilizing specific coding methodologies, assessment instruments, and validation procedures to guarantee adherence to regulatory standards and ensure equitable access for individuals with disabilities for government initiatives.
PECB ISO/IEC 27001 Lead Implementer
35 HoursThe landscape of information security threats is dynamic, requiring robust defenses through the strategic deployment and oversight of security controls. Compliance with these security standards is a fundamental mandate for government entities and other public stakeholders.
This curriculum is structured to equip participants with the competencies necessary to establish an Information Security Management System (ISMS) in accordance with ISO/IEC 27001 standards. The program provides a thorough framework for the ongoing governance, management, and enhancement of security protocols specifically for government operations.
Upon completion of the coursework, participants may sit for the associated assessment. Successful candidates become eligible to pursue the PECB Certified ISO/IEC 27001 Lead Implementer credential, validating their technical proficiency in deploying ISMS frameworks aligned with regulatory requirements.
Eligibility Criteria
- Project managers and advisors engaged in the deployment of ISMS infrastructure
- Subject matter experts aiming to refine their capabilities in ISMS execution
- Officials tasked with ensuring organizational adherence to information security mandates
- Personnel assigned to ISMS implementation teams
Program Details
- Examination fees are incorporated into the total tuition cost
- Comprehensive instructional materials, exceeding 450 pages and including practical case examples, will be provided
- A certificate confirming 31 Continuing Professional Development (CPD) credits will be awarded upon completion
- Participants who do not pass the assessment may retake it at no additional cost within a 12-month period
Pedagogical Methodology
- The course integrates analytical exercises, multiple-choice assessments, and best practice applications relevant to ISMS deployment.
- Collaborative dialogue is encouraged among participants during the resolution of quizzes and practical tasks.
- All exercises are derived from comprehensive case study scenarios.
- Assessment formats mirror the structure of the official certification examination.
Educational Outcomes
This course enables participants to:
- Develop a thorough understanding of the methodologies and techniques required for effective ISMS implementation and oversight
- Recognize the interrelationships between ISO/IEC 27001, ISO/IEC 27002, and applicable regulatory frameworks
- Comprehend the operational mechanics of an ISMS as defined by ISO/IEC 27001 standards
- Master the interpretation and application of ISO/IEC 27001 requirements within organizational contexts for government applications
- Acquire the expertise necessary to guide organizations in the planning, execution, monitoring, and maintenance of robust ISMS structures
Compliance and the Management of Compliance Risk
21 HoursTarget Audience
This instructional module is designed for federal personnel seeking to acquire a functional knowledge of compliance standards and risk management principles. The curriculum is developed specifically for government entities and their workforce.
Instructional Methodology
The program utilizes a hybrid delivery model comprising the following components:
- Guided group dialogue
- Visual presentation materials
- Analysis of historical scenarios
- Application of practical case studies
Learning Outcomes
Upon completion, learners will be capable of:
Demonstrating a comprehensive grasp of compliance fundamentals and national and international initiatives relevant to risk mitigation.
Articulating the methods for establishing a robust Compliance Risk Management Framework within organizational structures.
Defining the duties associated with the Compliance Officer and Money Laundering Reporting Officer roles, including their integration into broader business operations.
Recognizing significant risk vectors within Financial Crime, with particular attention to international activities, offshore jurisdictions, and high-net-worth individual interactions.
Open Source Software (OSS) Management
14 HoursOpen Source Software (OSS) management encompasses the comprehensive oversight of open-source component lifecycles within an organization, guaranteeing secure, compliant, and efficient deployment.
This instructor-led training, available online or onsite, targets intermediate IT professionals seeking to implement best practices for managing open-source software in enterprise and government environments. The curriculum is specifically designed to address the unique requirements for government agencies and public sector entities.
Upon completion of this training, participants will be equipped to:
- Develop robust OSS policies and governance frameworks.
- L utilize Software Bill of Materials (SBOM) and Software Composition Analysis (SCA) tools to identify, track, and manage open-source dependencies.
- Mitigate risks related to licensing compliance and security vulnerabilities.
- Optimize OSS adoption to enhance innovation while realizing cost efficiencies.
Course Format
- Interactive lectures and group discussions.
- Case studies and scenario-based exercises.
- Hands-on demonstrations utilizing OSS management tools.
Customization Options
- This course can be customized to align with specific organizational OSS policies and technical workflows. Please contact us to arrange these modifications.
PCI-DSS Practitioner
14 HoursThis instructor-led, live Payment Card Industry Professional training delivered US (via online or onsite modalities) grants individual qualification for industry practitioners seeking to validate their professional expertise and comprehension of the PCI Data Security Standard (PCI DSS). This program is designed for government entities and other organizations requiring specialized knowledge in payment security.
Upon completion of this course, participants will be able to:
- Comprehend the payment processing framework and the PCI standards established to safeguard it.
- Identify the roles and responsibilities assigned to entities operating within the payment industry.
- Demonstrate a thorough understanding of the 12 PCI DSS requirements.
- Showcase knowledge of PCI DSS applicability to organizations engaged in the transaction process.