
Meet your instructor as he introduces the updated NIST cybersecurity framework 2.0, highlights governance, and explains its applicability to any organization with practical, quiz-based learning.
discover how the NIST cybersecurity framework 2.0 integrates core functions, implementation tiers, and profiles to bridge business and security, enabling flexible, organization-specific risk management.
Explore the history and timeline of the NIST framework, from executive order 13636 in 2013 to version 1.1 in 2018, and how updates prioritize backwards compatibility and stakeholder needs.
Explore the NIST framework profile, aligning security objectives with business requirements, risk tolerance, and resources, and compare current and future profiles to reveal gaps and guide risk management.
Explore the core of the NIST cybersecurity framework as a three-layer taxonomy of outcomes, categories, and subcategories across six functions, focusing on risk management over specific controls.
Explore the six csf functions: govern, identify, protect, detect, respond, and recover, and how governance shapes risk appetite, priorities, funding, and accountability, noting they operate concurrently.
Explore the NIST cybersecurity framework 2.0 categories and subcategories, learn how business-friendly category naming, outcome-oriented measurements, and technology-neutral design enable traceable, board-ready security discussions.
Explore the governance function in the NIST framework 2.0, which oversees the five functions, sets direction and accountability, and drives policy, risk strategy, and supply chain risk management.
Explore the organizational context within governance, detailing the mission, internal and external stakeholders, legal and contractual requirements, and the essential capabilities and services driving cybersecurity risk management.
Establish risk management objectives with IT, leadership, and legal to align cybersecurity with business goals, define risk appetite and tolerance, and embed cyber risk into enterprise risk management and communication.
Leadership owns cybersecurity risk and builds a risk-aware culture, while clearly defining roles, securing resources, and embedding cybersecurity in human resources practices.
Establish and enforce a cybersecurity policy aligned with organizational context, strategy, and priorities, ensure compliance is not optional, and review and update to reflect evolving threats, technology, and risk management.
Explore oversight activities in the NIST framework: use metrics to evaluate risk management outcomes, adjust strategy, and engage independent audits for transparency and continuous improvement.
Establish and operationalize the cybersecurity supply chain risk management program with defined strategy, roles for suppliers, risk assessment, and integration with enterprise risk management and contracts.
Identify function establishes organizational context by clarifying assets, the business environment, and cybersecurity risks. It highlights asset management, risk assessment, and a 2.0 category aligned with mission and business objectives.
Master the NIST asset management process by identifying and inventorying hardware, software, and third-party services, prioritizing assets, assigning owners, and managing the life cycle.
Identify and evaluate vulnerabilities, threats, likelihood, and impact to prioritize risks and guide risk responses in a continuous, decision-driven process focused on business impact.
Identify improvements from evaluation, operational processes, security tests, and incident response plans. Learn faster, reduce repeat failures, and demonstrate measurable maturity through joint tests with third party suppliers and contractors.
Explore the protect function of the NIST framework 2.0. Prevent incidents, limit impact, and sustain operations through identity management, access control, awareness training, data security, platform security, and resilience.
Identity is the new perimeter; manage identities, prove who you are, and enforce intentional access with least-privilege and authentication based on the context of interaction for digital and physical assets.
Deliver security awareness training to all organization's users and clearly communicate each user's cybersecurity roles and responsibilities.
Master data security across data at rest, in transit, and in use by safeguarding confidentiality, integrity, and availability, while ensuring backups are created, protected, maintained, and tested.
Explains platform security as hardening hardware, software, and platforms across operating systems, servers, cloud, and containers; emphasizes configuration management, software maintenance, logs, unauthorized software prevention, and secure development.
Technology infrastructure resilience ensures networks and environments withstand disruptions from cyber attacks, failures, or disasters, reduce single points of failure, and maintain availability through capacity and resilience mechanisms.
The detect function identifies abnormal activity to recognize cybersecurity incidents early, enabling timely, accurate response information. It emphasizes visibility and awareness through continuous monitoring and adverse event analysis.
Explore continuous monitoring under the detect function by tracking networks, physical environment, user behavior, third-party activities, and system and data visibility to spot anomalies, adverse events, and indicators of compromise.
Analyze anomalies and IOCs to characterize adverse events and detect cybersecurity incidents, distinguish normal from suspicious activity, correlate data from sources, integrate threat intelligence, and declare incidents when criteria met.
Understand how the respond function of the NIST framework guides action after a cybersecurity incident, from incident management to analysis, response communication, reporting, and mitigation.
Execute the incident response plan with relevant third parties to manage detected incidents. Triage and validate reports, categorize by impact, prioritize, escalate as needed, and apply recovery criteria.
Master the NIST framework incident analysis examines investigations, forensics, and recovery to determine what happened, how severe it is, and root causes, preserving evidence integrity and provenance.
Coordinate incident response reporting with internal and external stakeholders, ensuring timely, accurate communications. Translate technical details into plain language for executives, avoid deceit, manage media messaging, and preserve trust.
Explore incident mitigation (RS.MI) by containing incidents to prevent spread and eradicate them to reduce impact, completing the response function in the NIST framework.
Explore the recover function, focusing on restoring operations, data, and mission-critical services after a cyber incident, while learning from the experience to strengthen resilience and communicate recovery status.
Execute the incident recovery plan to restore operations and data after a cyber security incident, verify backup integrity, and establish post-incident norms, ending with formal recovery closure.
Communicate incident recovery activities and progress to internal and external stakeholders, inform customers of what happened and how it was resolved, and share safeguards via updates on internet.
Understand CSF profiles as the starting point to describe current and target cybersecurity posture using NIST core outcomes, guided by objectives, stakeholders, threats, and regulatory demands.
Explore the five-step process to build a NIST CSF 2.0 profile, defining scope and technology scope, gathering evidence, selecting risk-based outcomes, and analyzing gaps to plan and implement updates.
Explore the four CSF tiers—partial to adaptive—and how risk governance and risk management evolve from reactive to predictive, with consistent policies, repeatable processes, and the distinction between profiles and tiers.
Build current and target csf profiles and perform gap analysis in a practical exercise. Translate csf outcomes into decisions that address ransomware and downtime risk for Horizon Retail Solutions.
Apply the NIST cybersecurity framework to harmonize security controls across 23 departments at the University of Chicago, enabling a risk-informed program, target state, and prioritized roadmaps with ongoing governance.
Explore the risk management framework, distinguishing inherent and residual risk, and learn to balance security controls, cost, and timing to accept an appropriate level of residual risk.
Preview the NIST SP 800-37 risk management framework, outlining seven steps, with purpose statements, outcomes, and P1–P7 tasks, includes references to NIST SP 853 Rev 5 and free downloads.
Explore the rmf process, detailing the preparatory step and six main steps—prepare, categorize, select, implement, assess, authorize, and monitor—used to manage risk and privacy.
Master the latest NIST Cybersecurity Framework (CSF) 2.0 through comprehensive theory and real-world practical exercises. This fully updated course guides you step-by-step to effectively manage cybersecurity risks and enhance your organization's resilience.
Why Choose This Course?
Updated for NIST CSF 2.0: Stay ahead of cybersecurity threats with insights and updates directly aligned with the latest NIST framework.
Practical Hands-On Learning: Move beyond theory—gain practical experience through realistic, scenario-based exercises tailored for real-world applications.
Easy-to-Follow Approach: Clear explanations and structured content designed for professionals at all experience levels.
Course Highlights:
In-depth Coverage: Detailed explanations of all 6 core functions (Govern, Identify, Protect, Detect, Respond, Recover).
Real-world Case Study: Apply your knowledge to a realistic fictional company scenario, helping you bridge theory and practice.
Downloadable Resources: Practical worksheets and checklists ready for immediate implementation.
Interactive Learning: Quizzes and assignments to reinforce your learning and help you assess your progress.
Who Should Take This Course?
IT and cybersecurity professionals
Risk management professionals
Business leaders and executives responsible for cybersecurity governance
Anyone looking to enhance their understanding of cybersecurity frameworks
What You'll Gain:
Comprehensive understanding of the latest NIST CSF 2.0 standards.
Ability to identify, assess, and manage cybersecurity risks effectively.
Practical skills to implement and improve cybersecurity strategies in your organization.
Enroll today and transform your cybersecurity approach from theory to impactful, real-world application with confidence and clarity.