SEC-220 · Kernel Security · Practitioner
Building an Advisory Workflow — full syllabus
The process around the engineering: intake, assessment, communication and evidence, on a deadline.
Who this course is for
Technical leads and security-response owners who must turn kernel CVE intake into customer advisories and regulatory evidence on a deadline.
Prerequisites
- SEC-101 or equivalent CVE-triage experience
- Current or imminent responsibility for a product's security response
- Basic scripting ability for the intake-automation labs
Course outline
Day 1 — Intake and assessment
- Monitoring sources: the kernel CNA feed, NVD, distro trackers, stable lists and oss-security
- Normalising intake: dedupe, map to products and trees, automate the boring parts
- Severity-based routing and assessment SLAs that engineering can actually meet
- The handoff from triage to engineering: what a good ticket contains
- Tracking state — open, assessing, affected, fixed, released — and proving it later
Day 2 — Communication and compliance
- Customer advisories: what to say, what not to say, and worked examples
- Coordinated disclosure and embargoes: handling a fix you cannot ship yet
- Regulatory and contractual reporting obligations: what evidence gets retained and for how long
- The audit trail: triage records, decision logs and advisory history as one system
- Advisory drafting for three scenarios: public CVE, embargoed fix, disputed applicability
Hands-on labs
- Lab: Build a minimal intake pipeline that pulls a CVE feed, dedupes and maps entries to your product list
- Lab: Triage a simulated week's intake against SLA targets and route each item with a written justification
- Lab: Draft a customer advisory for a public CVE and get it red-lined in review
- Lab: Run an embargoed-fix tabletop: timeline, communications and evidence capture from report to release
- Lab: Assemble the evidence bundle for one scenario and audit it against a retention checklist
Capstone project
Stand up a working advisory workflow for a hypothetical product line — intake automation, severity routing with SLAs, advisory templates, an evidence-retention layout and a decision log — then run it end to end on a scripted two-week incident scenario and present the resulting audit trail.
What you leave with
- An intake-automation skeleton you can adapt to your own feeds
- SLA and severity-routing definitions that survive contact with engineering
- Reviewed advisory drafts for public, embargoed and disputed cases
- An evidence-retention structure ready for audit
Upcoming dates
| Dates | Where | Seats | Early bird | Regular | |
|---|---|---|---|---|---|
| 15 Nov – 16 Nov 20262 full days | RiyadhIn person · KAFD Conference Centre | 3 of 14 | SAR 4,720until 16 Oct | ||
| 22 Nov – 23 Nov 20262 full days | Kuwait CityIn person · Al Hamra Tower | 8 of 14 | KWD 390until 23 Oct | ||
| 29 Nov – 30 Nov 20262 full days | MuscatIn person · Knowledge Oasis Muscat | 3 of 14 | OMR 490until 30 Oct | ||
| 29 Nov – 2 Dec 20264 half-days | Gulf bandLive online · 09:00–13:00 GMT+3 | 7 of 20 | US$900until 30 Oct | ||
| 30 Nov – 1 Dec 20262 full days | OttawaIn person · Kanata North Tech Park | 8 of 14 | CAD 1,710until 31 Oct | ||
| 7 Dec – 8 Dec 20262 full days | TorontoIn person · MaRS Discovery District | 3 of 14 | CAD 1,710until 7 Nov | ||
| 7 Dec – 10 Dec 20264 half-days | Europe bandLive online · 09:00–13:00 CET | 12 of 20 | US$900until 7 Nov | ||
| 7 Dec – 10 Dec 20264 half-days | Americas bandLive online · 13:00–17:00 ET | 17 of 20 | US$900until 7 Nov | ||
| 14 Dec – 15 Dec 20262 full days | LondonIn person · Shoreditch Works | 8 of 14 | GBP 980until 14 Nov | ||
| 14 Dec – 15 Dec 20262 full days | BerlinIn person · Factory Görlitzer Park | 3 of 14 | EUR 1,160until 14 Nov |
Book a seat, or bring this course to your team
Seats can be reserved online; private delivery runs on-site or live online, adapted to your stack.
Questions about fit or prerequisites? Email hello@kernelsystems.academy. To save this syllabus, print this page to PDF from your browser.