Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Course Outline
Module 1: Introduction to NIST and the Cybersecurity Framework
- What is NIST and its role in global cybersecurity?
- Evolution of the NIST Cybersecurity Framework
- Scope, objectives, and benefits of the NIST CSF
- Risk-based approach
- Alignment of the NIST CSF with business operations
Module 2: Structure of the NIST Cybersecurity Framework
- NIST CSF components:
- Core
- Profiles
- Implementation Tiers
- NIST CSF functions:
- Identify
- Protect
- Detect
- Respond
- Recover
- Categories and subcategories
- Practical exercise: identification of assets and risks
Module 3: Identify Function
- Asset management
- Business environment
- Governance and policies
- Risk assessment
- Risk management strategy
- Hands-on workshop: organizational risk analysis
Module 4: Protect Function
- Access and identity control
- Awareness and training
- Data security
- Maintenance and information protection
- Protection technologies
- Practical exercise: defining security controls
Module 5: Detect Function
- Anomalies and events
- Continuous security monitoring
- Incident detection
- Metrics and alerts
- Case study: security incident detection
Module 6: Respond Function
- Incident response planning
- Communication and crisis management
- Incident analysis
- Mitigation and improvement
- Practical incident response simulation
Module 7: Recover Function
- Recovery plans
- Business continuity
- Post-incident improvement management
- Communication and reputation
- Hands-on workshop: recovery plan and lessons learned
Module 8: Implementation and Continuous Improvement of the NIST CSF
- Creating current and target profiles
- Implementation Tiers
- Cybersecurity roadmap
- Integration with:
- ISO/IEC 27001
- NIST SP 800-53
- COBIT
- Auditing, metrics, and continuous improvement
Requirements
Requirements
- Basic knowledge of IT, information security, or risk management.
- No specific prior experience with NIST is required.
Target Audience
- Information Security Leaders (CISO, ISO)
- IT and Cybersecurity Teams
- Internal and External Auditors
- Compliance and Risk Officers
- Consultants and IT Governance Leaders
21 Hours
Testimonials (3)
Experience sharing, it's teacher's know-how and valuable.
Carey Fan - Logitech
Course - C/C++ Secure Coding
get to understand more about the product and some key differences between RHDS and open source OpenLDAP.
Jackie Xie - Westpac Banking Corporation
Course - 389 Directory Server for Administrators
the knowledge of the trainer was very high - he knew what he was talking about, and knew the answers to our questions