Get in Touch

Course Outline

Course Outline

Module 1: Introduction to NIST and the Cybersecurity Framework

  • What is NIST and its role in global cybersecurity?
  • Evolution of the NIST Cybersecurity Framework
  • Scope, objectives, and benefits of the NIST CSF
  • Risk-based approach
  • Alignment of the NIST CSF with business operations

Module 2: Structure of the NIST Cybersecurity Framework

  • NIST CSF components:
    • Core
    • Profiles
    • Implementation Tiers
  • NIST CSF functions:
    • Identify
    • Protect
    • Detect
    • Respond
    • Recover
  • Categories and subcategories
  • Practical exercise: identification of assets and risks

Module 3: Identify Function

  • Asset management
  • Business environment
  • Governance and policies
  • Risk assessment
  • Risk management strategy
  • Hands-on workshop: organizational risk analysis

Module 4: Protect Function

  • Access and identity control
  • Awareness and training
  • Data security
  • Maintenance and information protection
  • Protection technologies
  • Practical exercise: defining security controls

Module 5: Detect Function

  • Anomalies and events
  • Continuous security monitoring
  • Incident detection
  • Metrics and alerts
  • Case study: security incident detection

Module 6: Respond Function

  • Incident response planning
  • Communication and crisis management
  • Incident analysis
  • Mitigation and improvement
  • Practical incident response simulation

Module 7: Recover Function

  • Recovery plans
  • Business continuity
  • Post-incident improvement management
  • Communication and reputation
  • Hands-on workshop: recovery plan and lessons learned

Module 8: Implementation and Continuous Improvement of the NIST CSF

  • Creating current and target profiles
  • Implementation Tiers
  • Cybersecurity roadmap
  • Integration with:
    • ISO/IEC 27001
    • NIST SP 800-53
    • COBIT
  • Auditing, metrics, and continuous improvement

Requirements

Requirements

  • Basic knowledge of IT, information security, or risk management.
  • No specific prior experience with NIST is required.

Target Audience

  • Information Security Leaders (CISO, ISO)
  • IT and Cybersecurity Teams
  • Internal and External Auditors
  • Compliance and Risk Officers
  • Consultants and IT Governance Leaders
 21 Hours

Number of participants


Price per participant

Testimonials (3)

Upcoming Courses

Related Categories