NIST CSF

所在平台: Coursera

课程主页: https://www.coursera.org/learn/nist-csf

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:NIST CSF 概述:该课程旨在帮助学员建立对NIST网络安全基础知识的基本理解。学员将学习风险管理框架(RMF)过程,并通过识别、评估和应对风险来管理风险。此外,课程还将教授如何利用框架评估一个组织的网络安全风险,以及实施或改进网络安全计划的步骤。网络安全框架技能路径介绍了提高基础设施网络安全性的框架。 课程大纲: 1. 课程介绍:介绍国家标准与技术研究院(NIST)网络安全框架(NIST CSF)2.0,用于提高关键基础设施的网络安全性。 2. 网络安全基础知识:包含NIST CSF的术语和概念,涵盖行业内普遍存在的安全基本知识,例如CIA三元组等。 3. 网络安全框架组成部分:NIST CSF由框架核心、框架实施层级和框架轮廓等三个部分组成,强调商业驱动和网络安全活动之间的联系。 4. 沟通网络安全需求:NIST CSF提供一种通用语言,帮助组织与相关利益相关者沟通网络安全需求。 5. 风险管理:持续识别、评估和应对风险,课程讨论风险管理框架的过程,帮助组织在不确定环境中表现更好。 6. 网络供应链风险管理(SCRM):管理与外部方相关的网络安全风险及其影响。 7. 网络安全框架核心功能:描述六个核心功能(治理、识别、保护、检测、响应和恢复),强调并行和持续的执行。 8. 七步网络安全框架过程:课程强调如何利用NIST CSF来比较当前网络安全活动与框架核心的差距。 9. 网络安全框架自我评估过程:帮助组织评估其网络安全风险及其与组织目标之间的关系。 10. 网络安全框架总结与建议。 总之,本课程通过系统化的学习路径,帮助学员全面了解NIST CSF,提升他们在网络安全领域的知识和技能。

课程大纲

Name:NIST CSF instructor and path introduction

Description:This video introduces the National Institute of Standards and Technology Cybersecurity Framework (NIST CSF) 2.0 for improving critical infrastructure cybersecurity.

Name:NIST cybersecurity basics

Description:The NIST CSF contains terminology and concepts that may be expressed in specific ways to include perspectives and usages that may be unique to the framework implementation and different from what you are used to dealing with in your normal operations. You must have a basic understanding of security fundamentals used throughout the industry. For instance, the familiar CIA triad will be mentioned extensively throughout our courses. Additionally, there are some aspects of the framework that are contained throughout all discussion of the topics in this course. We’re introducing them here, they include: Cybersecurity & Information Security, Drivers of Business & Environments, and Cybersecurity Fundamentals. These concepts will be included in various discussions throughout all modules of this course, and you should become familiar with them.

Name:Cybersecurity framework components

Description:The NIST CSF, because it is a risk-based approach for managing cybersecurity risk, is composed of three parts: the Framework Core with its four areas and five processes, the four Framework Implementation Tiers and its programs and processes, and the Framework Profiles, goals, types and levels. Each Framework component reinforces the connection between business and mission drivers and cybersecurity activities.

Name:Communicating cybersecurity requirements

Description:The NIST CSF provides a common language to communicate requirements among interdependent stakeholders responsible for the delivery of essential critical infrastructure products and services. For example, an organization may use a target profile to express cybersecurity risk management requirements to an external service provider (e.g., a cloud provider to which it is exporting data). In addition, an organization may express its cybersecurity state through a current profile to report results or to compare with acquisition requirements, we will cover more examples in the course.

Name:Risk management

Description:Risk management is the ongoing process of identifying, assessing, and responding to risk. To manage risk, organizations should understand the likelihood that an event will occur and the potential resulting impacts. With this information, organizations can determine the acceptable level of risk for achieving their organizational objectives and can express this as their risk tolerance. Risks affecting organizations can have consequences from economic performance impacts to professional reputation. In this course we discuss the RMF process which provides a disciplined, structured, and flexible process for managing security and privacy risk which includes information security categorization; control selection, implementation, and assessment; system and common control authorizations; and continuous monitoring. We also discuss how managing risk by identifying, assessing, and responding to risk helps organizations perform better in an environment full of uncertainty.

Name:Cyber supply chain risk management (SCRM)

Description:Cyber SCRM is the set of activities necessary to manage cybersecurity risk associated with external parties. More specifically, cyber SCRM addresses both the cybersecurity effect an organization has on external parties and the cybersecurity effect external parties have on an organization.

Name:Cybersecurity framework core functions

Description:The core functions are a listing of categories, subcategories and informative references that describe specific cybersecurity activities common across all critical infrastructure sectors. They are not intended to form a serial path or lead to a static desired end state. Rather, the functions should be performed concurrently and continuously to form an operational culture that addresses the dynamic cybersecurity risk. This course describes the six framework core functions (Govern, Identify, Protect, Detect, Respond and Recover) and includes descriptions of categories, subcategories and informative references.

Name:7-step cybersecurity framework process

Description:The CSF is designed to complement existing business and cybersecurity operations. It can serve as the foundation for a new cybersecurity program or a mechanism for improving an existing program. It provides a means of expressing cybersecurity requirements to business partners and customers. Additionally, it can help identify gaps in an organization’s cybersecurity practices. The course outlines the steps an organization can use to compare their current cybersecurity activities with those outlined in the CSF core through the creation of profiles to determine if it has opportunities to or needs to improve.

Name:Cybersecurity framework self assessment process

Description:The CSF is designed to reduce risk by improving the management of cybersecurity risk to organizational objectives. Ideally, organizations using the Framework will be able to measure and assign values to their risk along with the cost and benefits of steps taken to reduce risk to acceptable levels. This course describes the importance of having a clear understanding of the organizational objectives, the relationship between those objectives and supportive cybersecurity outcomes, and how those discrete cybersecurity outcomes are implemented and managed to assist the organization in predicting whether a cybersecurity risk may occur, and the impact it might have.

Name:Cybersecurity Framework Summary and Tips

Description:

课程评论(0条)

课程详情

This course will help you to build a basic understanding of NIST cybersecurity fundamentals. You will learn about the RMF process and managing risk by identifying, assessing and responding to risk. Additionally, you will learn how to use the framework to assess an organization's cybersecurity risk and the steps to implement or improve a cybersecurity program. The Cybersecurity Framework skill path introduces the framework for improving infrastructure cybersecurity.

课程标签

0人关注该课程

主题相关的课程