Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Course Outline
Module 1: Introduction to NIST and the Cybersecurity Framework
- What is NIST and its role in global cybersecurity?
- Evolution of the NIST Cybersecurity Framework
- Scope, objectives, and benefits of the NIST CSF
- Risk-based approach
- Relationship between the NIST CSF and business objectives
Module 2: Structure of the NIST Cybersecurity Framework
- Components of the NIST CSF:
- Core
- Profiles
- Implementation Tiers
- NIST CSF Functions:
- Identify
- Protect
- Detect
- Respond
- Recover
- Categories and subcategories
- Practical exercise: Identifying assets and risks
Module 3: Identify Function
- Asset management
- Business environment
- Governance and policies
- Risk assessment
- Risk management strategy
- Practical workshop: Organizational risk analysis
Module 4: Protect Function
- Access control and identities
- Awareness and training
- Data security
- Maintenance and information protection
- Protection technologies
- Practical exercise: Defining security controls
Module 5: Detect Function
- Anomalies and events
- Continuous security monitoring
- Incident detection
- Metrics and alerts
- Practical case study: Security incident detection
Module 6: Respond Function
- Incident response planning
- Communications and crisis management
- Incident analysis
- Mitigation and improvement
- Practical incident response simulation
Module 7: Recover Function
- Recovery plans
- Business continuity
- Post-incident improvement management
- Communication and reputation
- Practical workshop: Recovery plan and lessons learned
Module 8: Implementation and Continuous Improvement of the NIST CSF
- Creating current and target profiles
- Implementation Tiers
- Cybersecurity roadmap
- Integration with:
- ISO/IEC 27001
- NIST SP 800-53
- COBIT
- Audit, metrics, and continuous improvement
Requirements
Requirements
- Basic knowledge of IT, information security, or risk management.
- No prior specific experience with NIST is required.
Target Audience
- Information Security Officers (CISO, ISO)
- IT and cybersecurity teams
- Internal and external auditors
- Compliance and risk officers
- Consultants and IT governance managers
21 Hours
Testimonials (3)
Experience sharing, it's teacher's know-how and valuable.
Carey Fan - Logitech
Course - C/C++ Secure Coding
get to understand more about the product and some key differences between RHDS and open source OpenLDAP.
Jackie Xie - Westpac Banking Corporation
Course - 389 Directory Server for Administrators
the knowledge of the trainer was very high - he knew what he was talking about, and knew the answers to our questions