SIM3 Certified Auditor training

On 18-20 September 2019 (following the TF-CSIRT), the Open CSIRT Foundation (OCF) will organise a 3-day training to become a Certified SIM3 Auditor .

The OCF shepherds the further development of the SIM3 maturity model, that is used by TF-CSIRT/TI, by ENISA for national teams in the EU, by the NCA (Nippon CSIRT Association) in Japan, and is now also being taken up by the Global Forum on Cyber Expertise (GFCE) for their GCMF – Global CSIRT Maturity Framework.

Certified Auditors play an important role in making it possible that SIM3 is used in a professional and objective way, and also contribute to further improving SIM3 in the near future.

Trainers: Don Stikvoort MSc (original author of SIM3), Dr. Klaus-Peter Kossakowski and Mirosław Maj.
Location: hotel Annabelle, 10 Poseidonos Avenue, 8042 Pafos, Cyprus.
Schedule: 18-20 Sep 2019 every day from 08:00-14:00. You are advised to have breakfast in your own hotel, and lunch after 14:00 – remember that dinner will be late (normally not before 20:00). Meals are not included in the training.
Fee: € 850 VAT excluded. This includes tea/coffee/water/cookies on. Also, the fee includes the first year of being a Certified SIM3 Auditor, assuming you pass the exam.

Note: the Annabelle is the TF-CSIRT meeting hotel, and you can reserve a room there or in other hotels close by, making use of the special TF-CSIRT rate. See https://tf-csirt.org/tf-csirt/meetings/58th/logisitics/ .

The training ends with a short exam – providing you have experience in the CSIRT field, and providing you pay attention during the training, you will pass that exam. (If for whatever reason, you might not pass the exam, then OCF will allow you to take another exam within 6 months, at no extra cost.)

The Cyprus training is fully booked, but if you are interested to follow this SIM3 training, write us please, as the next training of this kind will be early 2020 and most likely take place close to Amsterdam, The Netherlands. We already have subscribed 9 people for that training, so if you are interested to join, let us know! Do bear in mind that to follow this training you need to have sufficient experience in cyber security incident management, and know and understand CSIRTs and their national, regional and worldwide communities – if you are in doubt about whether you have the right skillset and experience, do feel free to ask us please.

Note: we are grateful to CSIRT-CY for helping prepare this training, and for securing the special hotel rates provided! We also express our gratitude to TF-CSIRT for encouraging us to align our training with the TF-CSIRT events on Cyprus.

Cancellation clause: cancellation for the Cyprus training is possible without charge no later than September 1st. If cancellation takes place after 1 September until 10 Sep by midnight, 50% of the full amount will be due. In case of a cancellation on 11 Sep or later, or a no-show on Cyprus, 100% of the full amount will be due. In clear cases of absence due to “Act of God” the payment obligation remains, but OCF will seek to provide due care, e.g. offering access to the next training at only marginal cost.

Auditor certification clause: OCF will provide due care to prepare the trainees for certification as SIM3 Auditors at the end of each training, and after successful certification, the first year of being certified will be at zero cost.However if (a) a trainee is absent during parts of the training (unless after explicit consent of the OCF head trainer), or (b) fails or misses the exam on the 3rdday, certification will not take place, nor will any re-fund. In the case of failed exams only, OCF will provide a timeslot of 6 months in which, at no additional cost, the trainee will receive a task to fill any knowledge/experience gaps, and after successful completion of that task, will get  a verbal repeat exam (this can be done via videoconferencing) – and providing this is completed successfully, certification will then take place. (In case of repeated failure, OCF has no more obligations towards the trainee and/or the organisation who paid for their participation.)