
Explore the NIST cybersecurity framework 2.0 fundamentals, from the CIA triad and risk management to the CSF core, five-step profile creation, and tiers for integrating cybersecurity.
Explore what cybersecurity is, its importance, and its connection to information security, with a focus on the CIA triad—availability, integrity, confidentiality, authentication, and non-repudiation.
Explore the CIA triad: confidentiality, integrity, and availability, and learn how these security goals protect information from unauthorized access, ensure accuracy, and keep data accessible on demand.
Explore authenticity and non-repudiation as additions to the CIA triad, supported by digital signatures that verify sender identity and data integrity within an asymmetric cryptography framework.
Explore how the NIST cybersecurity framework 2.0 guides organizations to identify, analyze, and respond to cybersecurity risk using threat sources, vulnerabilities, and preventive, detective, and corrective controls.
Explore the NIST cybersecurity framework 2.0 and its core functions governance, identify, protect, detect, respond, and recover, plus organizational profiles and tiers to tailor risk-based cybersecurity posture.
Navigate the CSF 2.0 resource center to access informative references, implementation examples, quick start guides, and profile templates that support achieving CSF outcomes.
Explore the CSF core structure, six functions, 22 categories, and 106 subcategories, and see how governance, identify, protect, detect, respond, and recover drive desirable cybersecurity outcomes.
Explore the governance function of the CSF 2.0, detailing six categories and thirty subcategories that establish and monitor organizational cybersecurity risk management, roles, policy, oversight, and supply chain risks.
Identify function helps understand and manage cybersecurity risks by asset management, risk assessments, and improvement. It emphasizes inventories, data flows, threat intelligence, vulnerabilities, and ongoing risk management improvement.
Explore the protect (PR) function of the NIST Cybersecurity Framework 2.0, including five categories and 22 subcategories that secure identities, data, platforms, and technology infrastructure resilience.
Identify cybersecurity events quickly by continuously monitoring networks, physical environments, personnel activity, external providers, and computing resources, then analyze adverse events through correlation and incident declaration to guide response.
Activate the incident response plan, manage incidents, analyze details, respond and report, communicate with stakeholders, and contain and eradicate threats to minimize damage and speed recovery under NIST CSF 2.0.
Examine the recover function of the NIST CSF 2.0, focusing on incident recovery plan execution, incident recovery communication, restoration prioritization, and verification of restored assets.
Explore how organizational profiles steer risk-based cybersecurity improvements within the CSF core, comparing current and target profiles to identify gaps and implement a five-step, continuous improvement process.
Define the scope to shape an organizational profile by assessing organizational, physical, and technological scopes, guiding focused cybersecurity efforts and the applicability of KSF outcomes.
Gather essential information to build an organizational profile by leveraging scope, business impact analysis, risk assessments, policies and procedures, compliance documents, and incident response plans aligned with NIST and ISO.
Create the organizational profile by selecting CSF outcomes within the defined scope, documenting current and target states, and prioritizing actions to close gaps for the NIST CSF 2.0 foundation.
Identify gaps between current and target profiles and create an action plan that assigns tasks, owners, and deadlines to close them, using available tools and resources.
Learn how CSF tiers gauge maturity of cybersecurity practices, from Basic to adaptive, and guide goals, track progress, and drive improvements aligned with risk tolerance and business needs.
Explore tier one of the NIST CSF 2.0, where practices are informal and reactive, with ad hoc risk management and limited awareness, often post-incident, supplier risk remains unclear.
Tier two aligns cybersecurity with business objectives and threats, with leadership-approved risk management that lacks cross-organization consistency, informal information sharing, and incomplete organization-wide strategy and supplier risk monitoring.
Define tier three repeatable risk management as systematic, policy-driven, organization-wide, and supplier-aware, with regular updates and training; illustrate with an enterprise incident response plan and supplier contracts.
Tier four organizations integrate cybersecurity risk management into culture and decision making, monitor risks in real time, and share insights with internal and external partners to adapt to emerging threats.
The NIST Cybersecurity Framework (CSF) is a widely recognized tool designed to help organizations of all sizes and industries manage and mitigate cybersecurity risks. This course offers a detailed exploration of the newly updated CSF 2.0, equipping you with the knowledge and skills to effectively implement this framework within your organization.
We’ll start by breaking down the Core of the CSF, covering its six key functions—Govern, Identify, Protect, Detect, Respond, and Recover—and explore how these functions guide the development of a robust cybersecurity program. Next, we’ll dive into CSF Profiles, demonstrating how they can be tailored to align cybersecurity priorities with organizational goals and unique risk landscapes. Finally, we’ll examine the Implementation Tiers, which help organizations evaluate their current cybersecurity maturity and set clear, actionable goals for improvement.
This course is designed to be practical and actionable. You’ll learn how to assess your cybersecurity posture, develop custom profiles, and utilize tiers to guide decision-making and resource allocation. Whether you’re a security professional, risk manager, or business leader, this course will empower you to leverage the NIST CSF 2.0 to enhance resilience, align with industry standards, and effectively communicate cybersecurity initiatives across your organization.
Start building your cybersecurity expertise today!