
The NIST cybersecurity framework synthesizes expert thinking into a practical structure for superior risk management. This course offers overview and guidance for applying the framework, even for non cybersecurity professionals.
Trace the origin of the NIST framework from the 2013 executive order to a voluntary, risk-based standard, with 2018 supply chain updates expanding its scope beyond critical infrastructure.
Explore the NIST framework core and its five functions—identify, protect, detect, respond, recover—along with implementation tiers and profiles guiding risk-based cybersecurity across an organization.
Explore NIST developments shaping cybersecurity risk management, including the executive order, zero-trust architecture, critical software definitions, software supply chain security, and IoT security standards aligned to CSF core functions.
Learn to map system risk profiles and inform management as part of cyber risk planning. Develop plans for high-priority risks to stay prepared against cyber attacks and protect the enterprise.
Frame the risk, assess assets and vulnerabilities, define responses, and monitor risks daily using the NIST cybersecurity risk management framework, with organization-wide ownership.
Master asset management to strengthen cybersecurity hygiene by maintaining up-to-date inventories, patching software, protecting systems with antivirus protection, and applying authentication and authorization controls, including role-based access.
Maintain an up-to-date hardware inventory across all locations, linking devices to the data asset owner, department, IP addresses, and hardware addresses, and ensure ongoing updates and monitoring for unauthorized assets.
Maintain a comprehensive software inventory across all devices to track authorized software, identify unauthorized apps, and support automated whitelisting, blacklisting, and vulnerability management.
Prioritize devices, software, and apps by establishing a risk planning framework that assigns assets to a clear classification, assesses business value, and documents standard prioritization criteria.
Define personal security requirements for all personnel and third party stakeholders in the NIS framework. Establish a security awareness program, and assign named cyber security leads with contracted audits.
Define governance to manage regulatory, legal, risk, environmental, and operational requirements by turning policies and procedures into day-to-day actions while educating top management and treating cybersecurity as an operational risk.
Identify threats, assess likelihood and consequences, and apply a risk assessment framework to measure risk objectively, deploy controls, and protect assets through vulnerability management and asset inventories.
Identify internal and external threats, document them, distinguish threats from vulnerabilities, and apply automated tools, threat modeling, and information sharing to stay informed and mitigate risks.
Identify the highest risks by evaluating threats, vulnerabilities, likelihoods, and impacts, then focus on critical assets to protect e-commerce reliability; use scoring, risk assessment, and tools to address residual risks.
Learn to address the highest risk under the NIST CSF by assigning an owner, documenting actions and milestones, and integrating scenario testing with risk management strategy.
Explore infrastructure planning to strengthen your organization's network, aligning with the NIST CSF protect function and topics like access control, awareness and training, and data security.
Learn how authentication verifies identities and access control limits user permissions to protect assets; apply least privilege, manage accounts, and track activity across systems.
Establish and audit an access control list to verify who may physically access systems using a card key and two-factor authentication, and manage remote access with VPN and device policies.
Enforce network security controls by applying least privilege and separation of duties, strengthen privileged access management, enforce passwords and multi factor authentication, and apply firewall policies across segmented internal networks.
Associate actions with real people through identity proofing and authenticate securely using single- and multi-factor methods aligned with risk.
organizations must implement awareness and training to increase phishing assessments, help employees spot phishing, and understand roles and responsibilities while building fundamental security skills.
Protect data by implementing cryptography and safeguards for data in transit and at rest, including databases and DBMs, aligned with the organization's risk strategy to preserve confidentiality, integrity, and availability.
Enforce strict authorization to protect data integrity and restrict administrative access. Document users and procedures, monitor critical assets, protect hardware physically, and separate development from production to verify integrity.
Develop information protection programs with company policies, establish baseline it and ot configurations, and implement configuration management with defined roles to control changes, restrict ports, update passwords, and use sudo.
Implement patch management with a risk-based assessment of vendor patches, balancing downtime and data loss. Maintain frequent backups offsite and establish disaster recovery and business continuity plans.
Develop and maintain formal maintenance procedures for system, software, and devices, aligned with organizational policies and vendor specifications; assign authorized personnel and manage third-party maintenance with documented controls.
Protect organizational assets with protective technology and a technical security architecture, apply least functionality, and strengthen resilience with fail safe, load balancing, and hot swap.
Explore how timely post-incident actions shape continuity of operations and resilience, using a detailed cyberattack case to illustrate incident response, vulnerability patching, and building organization-level cybersecurity policies.
Define an incident response plan and establish a diverse CSI team to limit damage, reduce recovery time, and improve communications, learning from the Equifax breach and its organizational failures.
Develop an executable incident response plan by identifying critical resources, assigning responsibilities, coordinating with management, formalizing policies, and securing insurance for timely, effective response.
Define clear incident response communications with roles, thresholds, and protocols; educate personnel and coordinate executive involvement with banks, authorities, regulators, and communications across the organization.
Analyze incidents to identify root causes, collect evidence with the intrusion detection system, and prioritize responses while preserving data for Isac sharing and bug reports.
Explore post-incident risk mitigation, including isolating assets, backing up evidence, changing passwords, and discreet attacker tracing, while balancing acceptance, avoidance, and limitation strategies.
Learn how to plan and execute cyber incident recovery, distinguishing disaster recovery from business continuity, and implement activation, execution, and reconstruction phases with damage assessment and communications.
Investigate supply chain risk management and how multinational hardware, software, and services introduce complex threats. Identify counterfeits, unauthorized production, theft, and malicious software and hardware as key risks.
Identify supply chain risk management practices under the nist framework, guided by the 2015 Nysed document. Understand software bill of materials and how it informs vendor cybersecurity decisions.
Identify and manage supply chain risks by assessing suppliers, testing service distribution, and prioritizing high-value, high-access vendors, while aligning contracts with stakeholders to improve resilience.
Develop, assess and test supply chain risks by enforcing contract-based cyber security requirements, ongoing vendor audits, and disaster recovery planning with high-risk suppliers.
In today's interconnected world, where businesses heavily rely on technology and global supply chains, cybersecurity and supply chain risk management have become paramount. This comprehensive course, "Mastering NIST Cybersecurity Risk Management (CSF)," equips you with the essential knowledge and skills to safeguard your organization's assets and operations.
Course Highlights:
Cybersecurity Expertise: Explore the intricacies of cybersecurity risk planning, asset management, personnel security requirements, and more. Learn to identify and combat internal and external threats effectively.
Network Security: Dive into the world of network security controls, authentication, access control, and data security, ensuring the protection of your organization's digital infrastructure.
Business Continuity: Develop continuity of operations plans and executable response strategies. Understand the importance of communication during incidents and how to analyse and respond to them effectively.
Supply Chain Resilience: Delve into supply chain risk management practices, incorporating supply chain categories, and the assessment and testing of supply chain risks. Gain insights into maintaining the integrity of hardware and protecting critical information.
By the end of this course, you will have the expertise to navigate the complex landscape of cybersecurity and supply chain risk management, making informed decisions to secure your organization's future in the digital era. Join us on this journey to build resilience and stay ahead in today's dynamic and interconnected business environment.