
Explore the NIST cybersecurity and risk management frameworks, including the CSF and RMF, to understand guidance, assess risk, and drive remediation and control-based activities from IT and audit perspectives.
Define cybersecurity and culture through a practical lens, showing prevention, protection, restoration, and governance aligned with NIST risk management and cybersecurity frameworks and the CSRC publications library.
Explore how NIST collaborates with CISA and FBI, ISO standards (27001, 27002, 27005), CIS controls with IG1–IG3, PCI DSS, and HIPAA HITECH to boost global cybersecurity.
Explore the NIST CSF and RMF, detailing their five functions and risk-based controls. Learn the RMF steps—prepare, categorize, select, implement, assess, authorize, monitor—and how they guide asset risk management.
Explore the heart of the NIST cybersecurity framework, including the core functions identify, protect, detect, respond, and recover, and how tiers and profiles customize its use for your organization.
Define the vocabulary of risk, including threat, vulnerability, likelihood, and impact, using NIST SP 800-30 R1 and the CSRC glossary, and apply risk management with residual risk and countermeasures.
Apply the NIST cybersecurity framework and RMF to a case study toolkit with downloadable resources, guiding you through case study details and regulatory considerations for a fictional firm.
Explore the identify function of the NIST cybersecurity framework, connect asset management with governance and risk, and reference subcategories and informative references.
Identify and inventory critical assets, including hardware, software, data, and personnel, and explain asset management, CMDB, data flows, external systems, and vendor relationships to support risk-based decision making.
Explore how the NIST cybersecurity framework identify function links the business environment to a business impact assessment, detailing BIA processes, RTO, RPO, and recovery strategies, including supply chain considerations.
Explore security policies and procedures within the NIST cybersecurity framework, focusing on governance, organizational policy, roles and responsibilities, and how standards, guidelines, and processes drive risk management.
This lecture explains the NIST core protect function, building on identify outputs to safeguard prioritized data, applications, operating systems, and the network through administrative, technological, and physical controls.
Explore why awareness and training are essential in protecting organizations, examine how human failure drives breaches, and outline practical topics, methods, and role-based training.
Learn how access control safeguards assets via identity and access management, authentication, authorization, and auditing, highlighting factors of authentication, least privilege, and separation of duties.
Explore protective technology for networks, including network access control, firewalls, VPNs, DNS, DNSSec, segmentation, and zero-trust concepts, tied to NIST SP800-53r5 controls.
Learn how to protect and harden endpoint systems with protective technologies, encryption, firewalls, and patch management. Compare network and system protections, and address BYOD, mobile devices, and secure remote access.
Explore data security and encryption within the NIST framework, covering symmetric and asymmetric encryption, key management, hashing, PKI, and digital signatures for data protection.
Maintain assets through ongoing care and vulnerability remediation, while applying formal change management with RFCs, change advisory boards, deployment planning, post-implementation reviews, and CMDB and configuration items.
Protect assets by integrating personnel and physical security within the NIST CSF's protect function, prioritizing life safety, the four Ds, and HR management.
Learn how system logging and auditing underpin the detect function of the NIST CSF, including anomalies and events, baselines, data collection, and continuous monitoring via SIEM and ISCM practices.
Explain how detection under the NIST CSF uses continuous monitoring and alerting to capture activity, identify anomalies, and support audit and accountability through system monitoring and logging.
Explore how to conduct security and privacy control assessments by defining objectives, methods, and objects. Report outcomes with standardized measures aligned to NIST SP 800-53 and CSF.
Explore the respond function within the NIST cybersecurity framework, distinguishing events from incidents, and learn how preparation, planning, and a structured incident response lifecycle guide containment, eradication, and recovery.
Develop and align an incident response plan with CSF guidance, focusing on communications, roles, and coordination; explore IR4 and IR8, and templates for detection, containment, recovery, and lessons learned.
Explore digital forensics within the incident response framework, focusing on forensic analysis, evidence collection, chain of custody, and forensically sound techniques to uncover and preserve data.
Develop proactive incident response skills through role-specific training and diverse testing types, including checklists, walk-through tabletop exercises, simulations, and real-life exercises, guided by NIST SP 800-53r5.
Explore how mitigation and improvements within the NIST cybersecurity and risk management frameworks drive containment, vulnerability identification, patch management, remediation, and continual lessons learned.
Explore the recovery function of the CSF, focusing on continuity of operations, disaster recovery planning, and recovery planning with practical examples and testing guidance.
Explore the NIST CSF recovery function, contingency planning, backups and recovery sites, including three-two-one data copies, testing, cloud options, and hot to cold site strategies.
Explore how virtualization and the cloud enable rapid recovery in the NIST CSF by restoring from templates or clones and mixing on-premises and cloud environments.
Discover the NIST RMF overview and preparation, detailing risk management framework goals and the seven steps: prepare, categorize, select, implement, assess, authorize, monitor, for consistent risk-based security.
Define risk with NIST vocabulary and apply a risk-based security approach aligned to the RMF and CIA triad, then outline the SP 800-30R1 risk assessment steps.
Explore the RMF preparation step in the NIST framework, focusing on organizational and system-level readiness, risk tolerance, asset prioritization, and documented preparation for risk assessment.
Identify and document the system with a system security plan (SSP) that inventories hardware and software, defines controls, and supports incident response and minimum security baselines.
Explore the categorized system step in the NIST RMF, assess confidentiality, integrity, and availability, prioritize likely negative incidents, and use task guidance to describe and categorize systems.
Define scope in the NIST RMF by asking who, what, when, where, why and how, distinguishing in and out of scope assets and dependencies to protect confidentiality, integrity, and availability.
Learn how to scope and categorize assets in the RMF step, applying risk analysis to determine confidentiality, integrity, and availability impacts, and derive security baselines.
Explore step 2 of the NIST RMF—categorizing systems—through risk assessment, identifying threat sources and events, vulnerabilities, likelihood, and impacts to determine adversarial and non adversarial risk.
Select and tailor security controls in the NIST RMF to protect assets commensurate with risk, using common or unique controls as needed. Document, obtain AO approval, and monitor outcomes.
Explore how NIST defines security and privacy controls as administrative, technical, and physical safeguards, and how NIST SP 800-53R5 structures these controls across 20 families for risk management.
Discover how to set and tailor NIST RMF control baselines for the system and environment of operation, focusing on S-1 control selection and S-2 tailoring.
Explore how the RMF select step allocates security and privacy controls—common, system-specific, and hybrid—across system elements and the environment of operation, and monitor their ongoing effectiveness.
Examine how documentation and approval guide the RMF select step, detailing S4–S6 tasks, continuous monitoring, and AO approval for system security and privacy plans.
Implement controls in the RMF step four by applying security and privacy controls to the baseline configuration details, and update control implementation information to reflect as-implemented states.
Explore how common controls are inherited from cloud providers and third parties, with physical security resting on the provider, and how compensating controls like multi-factor authentication strengthen gaps.
Explore how to document and update control implementations across CMDB, SSP, and run books, ensuring aligned, auditable, and ongoing RMF control coverage through a living authorization package.
In the US, NIST is the de-facto standard for security, compliance and privacy. If you are doing business with the US federal government, manage critical infrastructure, or maintain personally identifiable information (PII), you must be compliant with NIST standards.
NIST provides the Cybersecurity Framework (CSF) and Risk Management Framework (RMF) to guide organizations on securing their infrastructure, systems, and data. In this course, you will apply the NIST Cybersecurity and Risk Management Frameworks to better protect their infrastructure, detect possible cyber incidents and appropriately respond and recover should they occur. You'll become well-versed in the NIST CSF and RMF, how to implement them, and ways to effectively manage CSF & RMF processes for optimal security, privacy and compliance.
This course provides an overview of the NIST Cybersecurity and Risk Management Frameworks and their application. Organizations may require additional industry-specific knowledge and specialized guidance to tailor these frameworks to their unique needs and compliance requirements.
Upon completing the course, participants should have the knowledge and skills necessary to assess, implement, and enhance cybersecurity practices within their organizations using the NIST Cybersecurity and Risk Management Frameworks. They will be equipped to make informed decisions regarding risk management, establish appropriate controls, and respond to cybersecurity incidents in a proactive and efficient manner.