SEC-220 · Kernel Security

Building an Advisory Workflow

The process around the engineering: intake, assessment, communication and evidence, on a deadline.

Practitioner 2 days in person4 half-days online Max 14 in person

Who this course is for

Technical leads and security-response owners who must turn kernel CVE intake into customer advisories and regulatory evidence on a deadline.

Prerequisites

SEC-101 or equivalent CVE-triage experienceCurrent or imminent responsibility for a product's security responseBasic scripting ability for the intake-automation labs

Course outline

Day 1 — Intake and assessment

  • Monitoring sources: the kernel CNA feed, NVD, distro trackers, stable lists and oss-security
  • Normalising intake: dedupe, map to products and trees, automate the boring parts
  • Severity-based routing and assessment SLAs that engineering can actually meet
  • The handoff from triage to engineering: what a good ticket contains
  • Tracking state — open, assessing, affected, fixed, released — and proving it later

Day 2 — Communication and compliance

  • Customer advisories: what to say, what not to say, and worked examples
  • Coordinated disclosure and embargoes: handling a fix you cannot ship yet
  • Regulatory and contractual reporting obligations: what evidence gets retained and for how long
  • The audit trail: triage records, decision logs and advisory history as one system
  • Advisory drafting for three scenarios: public CVE, embargoed fix, disputed applicability

Hands-on labs

Labs follow the academy model — 35% principles, 20% guided investigation, 45% engineering studio. Every claim you make in a lab is backed by a trace, a counter or a measurement you captured yourself. How we teach

  1. Lab: Build a minimal intake pipeline that pulls a CVE feed, dedupes and maps entries to your product list
  2. Lab: Triage a simulated week's intake against SLA targets and route each item with a written justification
  3. Lab: Draft a customer advisory for a public CVE and get it red-lined in review
  4. Lab: Run an embargoed-fix tabletop: timeline, communications and evidence capture from report to release
  5. Lab: Assemble the evidence bundle for one scenario and audit it against a retention checklist

Capstone project

Stand up a working advisory workflow for a hypothetical product line — intake automation, severity routing with SLAs, advisory templates, an evidence-retention layout and a decision log — then run it end to end on a scripted two-week incident scenario and present the resulting audit trail.

What you leave with

  • An intake-automation skeleton you can adapt to your own feeds
  • SLA and severity-routing definitions that survive contact with engineering
  • Reviewed advisory drafts for public, embargoed and disputed cases
  • An evidence-retention structure ready for audit

How it runs

Every course follows the same model: 35% principles, 20% guided investigation, 45% engineering studio. You leave with working code, raw measurements and an evidence-based report — not a certificate of attendance. Read the methodology or see a full sample lesson.

Material is adapted to your kernel version, hardware and workload before a private delivery. For public cohorts, the environment is provided and configured.

Questions

Who is this course for?

Technical leads and security-response owners who must turn kernel CVE intake into customer advisories and regulatory evidence on a deadline. It sits at practitioner level within the Kernel Security track.

What do I need to know already?

Specific prerequisites for this course: SEC-101 or equivalent CVE-triage experience; Current or imminent responsibility for a product's security response; Basic scripting ability for the intake-automation labs. We confirm levels before the cohort starts and adapt if a group is stronger or weaker than expected.

Can this run privately for my team?

Yes. Any course runs on-site at your offices anywhere, or live online for a distributed team, with labs adapted to your hardware and codebase.

What is the difference between in-person and online?

In person is 2 full days with hardware on your desk, capped at 14. Online is 4 half-day sessions across about two weeks so you can keep working, capped at 20, with remote lab access.

Do you invoice companies?

Yes. Purchase orders are accepted and invoicing is available in USD, EUR, GBP, SAR and CAD.

Upcoming dates

DatesWhereSeatsEarly birdRegular
15 Nov – 16 Nov 20262 full days RiyadhIn person · KAFD Conference Centre 3 of 14 SAR 4,720until 16 OctSAR 5,250
22 Nov – 23 Nov 20262 full days Kuwait CityIn person · Al Hamra Tower 8 of 14 KWD 390until 23 OctKWD 430
29 Nov – 30 Nov 20262 full days MuscatIn person · Knowledge Oasis Muscat 3 of 14 OMR 490until 30 OctOMR 540
29 Nov – 2 Dec 20264 half-days Gulf bandLive online · 09:00–13:00 GMT+3 7 of 20 US$900until 30 OctUS$1,000
30 Nov – 1 Dec 20262 full days OttawaIn person · Kanata North Tech Park 8 of 14 CAD 1,710until 31 OctCAD 1,900
7 Dec – 8 Dec 20262 full days TorontoIn person · MaRS Discovery District 3 of 14 CAD 1,710until 7 NovCAD 1,900
7 Dec – 10 Dec 20264 half-days Europe bandLive online · 09:00–13:00 CET 12 of 20 US$900until 7 NovUS$1,000
7 Dec – 10 Dec 20264 half-days Americas bandLive online · 13:00–17:00 ET 17 of 20 US$900until 7 NovUS$1,000
14 Dec – 15 Dec 20262 full days LondonIn person · Shoreditch Works 8 of 14 GBP 980until 14 NovGBP 1,090
14 Dec – 15 Dec 20262 full days BerlinIn person · Factory Görlitzer Park 3 of 14 EUR 1,160until 14 NovEUR 1,290

Dates shown for the next few months. If nothing fits, tell us where and when — cohorts are added on demand, and private delivery can be scheduled any week.

More in Kernel Security

SEC-1012 days Reading Kernel CVEs Assessing whether a kernel CVE actually affects you, which is usually a different question from whether it is severe. Practitioner Practitioner-taught SAR 5,250Next 11 Oct SEC-1103 days Exploit Mitigations & Hardening The mitigations available in a modern kernel, what each actually stops, and what they cost. Advanced Practitioner-taught SAR 9,000Next 8 Nov SEC-1202 days Attack Surface Reduction Making the kernel smaller and less reachable, which beats mitigating attacks you could have made impossible. Advanced Practitioner-taught SAR 6,000Next 25 Oct SEC-2013 days Multi-Branch Backporting Taking an upstream fix and applying it correctly across several maintained branches — the core skill of a vendor security team. Advanced Practitioner-taught SAR 9,000Next 1 Nov SEC-2102 days Stable, LTS & Vendor Tree Hygiene Working with the upstream stable process and keeping a vendor tree that does not rot. Practitioner Practitioner-taught SAR 5,250Next 18 Oct SEC-3013 days LSM, SELinux & AppArmor Mandatory access control on Linux: how the LSM framework works and how to write policy that is actually enforced. Advanced Practitioner-taught SAR 9,000Next 22 Nov SEC-3102 days Landlock & Kernel Lockdown Newer confinement mechanisms: unprivileged sandboxing with Landlock and restricting root with lockdown. Advanced Practitioner-taught SAR 6,000Next 8 Nov SEC-3203 days Integrity: IMA/EVM & dm-verity Measuring and verifying what runs on the system, from block device to individual file. Advanced Practitioner-taught SAR 9,000Next 18 Oct