
Explore how the NIST Cybersecurity Framework provides a blueprint for building cyber resilience, detailing six core functions—governance, identify, protect, detect, respond, recover—and practical tools like community profiles.
Explore the business value of the NIST cybersecurity framework, a free, vendor-neutral playbook that unifies risk management, continuous improvement, and cyber resilience across organizations.
Discover who can use the NIST Cybersecurity Framework version 2, from critical infrastructure to any organization, and apply its flexible five key benefits to fit size, risk, and resources.
Explore the core of the NIST cybersecurity framework and its six functions: govern, identify, protect, detect, respond, recover, and how industry standards enable concurrent, adaptive risk management and cross-stakeholder communication.
Explore the NIST Cybersecurity Framework implementation tiers from tier one to four, their risk management methods, and why they are not a maturity model.
Explore how core profiles tailor the NIST CSF for your organization, selecting relevant activities and outcomes to close the gap between current and target states while considering risk appetite.
Explore NIST CSF version 2 resources that simplify implementation. See how CPRT and machine readable tools map to ISO 27001 or PCI DSS, with templates and FAQs.
Explore chapter two of implementing the NIST cybersecurity framework, version two, as Glenn and Ahanu explain the framework core, the six functions, second-level activities, and the outcomes and controls relationship.
Explore the govern function of version 2 NIST Cybersecurity Framework (CSF), detailing six activities: organizational context, risk management strategy, roles, responsibilities, and authorities, policy, oversight, and supply chain risk management.
Explore the identify function of the NIST CSF, detailing asset management, risk assessment, and improvement to understand the business, identify resources that support critical functions, and prioritize cybersecurity risk.
Describe Protect function of NIST CSF, detailing activities: identity management and access control, awareness and training, data security, platform security, and technology infrastructure resilience to safeguard assets and business continuity.
Explore the detect function of the NIST cybersecurity framework (csf), focusing on continuous monitoring and adverse event analysis to detect dwell time, tune alerts, and use honeypots for suspicious interactions.
Explore the Respond function (RS) of the NIST CSF version 2, detailing four activities—incident management, incident analysis, response reporting and communication, and incident mitigation—to contain and recover from incidents.
Explore the recover function (RC) of the NIST CSF v2, focusing on incident recovery plan execution and incident recovery communication to restore normal operations and resilience.
Learn how the NIST Cybersecurity Framework emphasizes outcomes over controls and offers flexible, non-prescriptive guidance to convert them into testable requirements using informative references.
Explore four studies of NIST cybersecurity framework version two, including two from the NIST site and two from cyber risk opportunities, and learn to implement the framework for your organization.
Cimpress applies the NIST framework with Fair to create a top-down, maturity-based cybersecurity program using a self-assessment questionnaire across 17 business units, quantifying risk in dollars.
This case study shows how the University of Kansas Medical Center used the NIST Cybersecurity Framework in a four-step self-assessment to boost buy-in and strengthen cybersecurity across the healthcare organization.
Leverage the NIST cybersecurity framework to guide priorities and risk mitigation, focusing on response and recovery with targets tailored to organizational context, demonstrated by an energy company's case study.
Apply version 2 of the NIST Cybersecurity Framework to a fishing company to identify top cyber risks, use a spider graph, and tailor mitigations to align current with target scores.
Develop a cyber risk management action plan using phase one of the CR map in version two of the NIST CSF. Prioritize the top five risks based on collected data.
Learn how the CR-MAP uses version 2 of the NIST CSF to reduce top cyber risks and drive a prioritized year-long action plan.
Widen your scope to include people, process, policy, and technology, identify high-value digital assets, and rank them as you begin phase one of the CR-MAP.
Master securing buy-in at every level using John Kotter's framework, collaborative interviews within a cyber risk management action plan, and clear messaging that distinguishes assessments from audits.
Conduct 15–20 in-person interviews with influencers and senior staff from finance, HR, operations, and IT to score CSF outcomes and scale for large firms by divisions and shared services.
Generate a questionnaire to assess your organization's CSF implementation using the online cyber risk workbook's Google Sheets with 31 questions, scored 0–10 across identify through recover.
Choose target scores for each NIST cybersecurity function using a 0–10 scale, prioritizing green zone targets (5–8) and adopting a first responder or modern city approach to optimize risk management.
Conduct in-person interviews to gather candid cyber risk insights, using a 0–10 scoring key across departments, recording responses in a spreadsheet, and mitigating biases with careful data handling.
Compile and average scores from the CR-MAP process against target scores of six in the NIST CSF, using radar diagrams to reveal gaps across detect, identify, response, and recover.
Identify your top five cyber risks and read the stories they tell about your organization through phase one of CR-MAP, highlighting gaps in detect and recover functions.
Implement phase two of NIST CSF version 2 by designing a prioritized set of mitigations to reduce the top five risks, following a seven-step workflow, and securing buy-in for roadmap.
Close your gaps by analyzing top risks and the gap between actual and target scores. Implement role-based training to raise PR.AT outcomes toward a five, with LMS integration.
Calculate the three year total cost of ownership (3TCO) for each mitigation to close csf gaps, by combining implementation costs with three years of operating costs.
perform a business value analysis to translate cybersecurity mitigations into financial, technical, legal, and operational benefits, using relatable examples to secure buy-in and justify cybersecurity investments.
Pull all mitigations into a simple dashboard and an implementation roadmap. Prioritize by gap size, show 3TCO and business benefits, and plan with two tracks to balance staff impact.
Drive buy-in for mitigations through internal marketing in phase two of the CR-MAP method, using marketing channels to communicate goals, timelines, and productivity benefits of a password manager.
Learn to present your cybersecurity program using a one-page scorecard and anonymized data within the NIST CSF framework, with strict need-to-know access and NDAs.
Explore phase three of the cyber risk management action plan: maintenance and updates, with three recurring steps (two explained here). Build buy-in to your NIST CSF v2 program.
Phase three maintains and updates the CR-MAP through monthly reviews, quarterly scorecard updates, and annual summits to track progress, celebrate wins, and a data-driven narrative to executives every 90 days.
Pre-schedule a year of cyber security check-ins on the same day and time, update risk scores and CR-MAP, remove blockers, celebrate wins, and plan next steps when scores meet targets.
Conduct quarterly reviews to align executive sponsor buy-in, track the CR-MAP progress, and manage expectations for cyber resilience, reduced risk, and business value.
Lead the annual cybersecurity summit to review last year's progress, compare four scorecards, and align with the 22 NIST CSF version two risks for a strengthened cyber resilience.
Adopt version two of the NIST Cybersecurity Framework to transform your organization into a more cyber resilient state with top-down implementation and stronger workforce buy-in.
The NIST Cybersecurity Framework isn't just another dusty document. It's a practical tool that can help protect your organization. But many people tell me they're confused about how to actually use it.
We've been implementing the Framework with paying customers for over 8 years, so I've seen lots of confusion.
In this course, I'm going to demystify the Framework, show you how to implement it, and give you a straight-forward method along with a free tool for automating the workflow and reporting.
You'll start by learning the basics of the NIST Cybersecurity Framework, like who made it and who can use it.
Then, you'll dive deeper into the framework to fully understand the Framework Core, the Framework Tiers, and the Implementation Profiles.
You'll also review case studies from diverse organizations across the globe, including a critical infrastructure organization, a large global business, and others.
Finally, we'll spend most of our time learning how to implement the framework within your own organization by making a Cyber Risk Management Action Plan (CR-MAP). This CR-MAP of your organization will discover your time five cyber risks and help you to create a mitigation plan to reduce your cyber risk and make your organization more cyber resilient.
You'll also get a free bonus digital workbook that helps you conduct a CR-MAP step-by-step.
Remember: Cyber criminals don't care how big or small your organization is. They only care if you're an easy target.
The Framework helps make you a harder target. Let's get going!