|
所在平台: Coursera |
课程主页: https://www.coursera.org/learn/nist-dod-rmf
课程评论:没有评论
课程名称:NIST DoD RMF 课程概述:风险管理框架(RMF)提供了一种有纪律、结构化和灵活的过程,用于管理安全和隐私风险。该框架涵盖信息安全分类、控制选择、实施与评估、系统及共同控制授权,及持续监控等内容。课程内容将帮助组织为在适当的风险管理水平上执行框架做准备,解释RMF的步骤及其过程(即任务),将系统级的关键风险管理流程与组织级的风险管理流程连接起来。本学习路径讲解风险管理框架(RMF)及其过程,并提供将RMF应用于信息系统和组织的指导。 课程大纲: 1. **法律与监管**:本模块介绍国家标准与技术研究院(NIST)风险管理框架(RMF)技能课程,教学内容包括如何利用风险管理框架更好地管理和减少网络安全风险,并讨论一些监管机构在RMF发展和执行中的参与。 2. **法律、政策与法规**:本模块解释一些法律、政策和条例,要求实施NIST RMF并规范其执行,讨论隐私法、计算机欺诈与滥用法、美国爱国者法案等内容。 3. **综合组织范围的风险管理**:本模块描述与管理组织中信息系统相关的安全和隐私风险的基本概念,强调风险管理是一项整体性活动,需要整个组织的参与。 4. **风险管理框架阶段**:本模块讨论NIST RMF的步骤,提供框架的结构化和灵活的过程指南,以管理安全和隐私风险,并准备组织在适当的风险管理水平上执行框架的活动。 5. **风险管理框架回顾**:本模块回顾六个RMF步骤:分类/识别、选择、实施、评估、授权和监控,并提供理解课程的评估。课程包括一个项目,学员需通过填写NIST 800-60v1分类工作表来审查分类过程,并将信息转移到FIPS 199分类表单,深入了解六个RMF步骤。
Name:Legal and regulatory
Description:This course provides an introduction to the National Institute of Standards and Technology (NIST) Risk Management Framework (RMF) Skills course. In this course, we will teach you how to employ the Risk Management Framework to better manage and reduce cybersecurity risks. In this module, we provide a brief overview, and then detail the involvement of some regulatory organizations in the development and execution of the NIST RMF. We specifically discuss executive orders, NIST, the Office of Management and Budget, the Committee on National Security Systems and more.
Name:Laws Policies and Regulations
Description:In this module, we explain some of the laws, policies and regulations which mandate the implementation of the NIST RMF and govern the execution of the NIST RMF. This module discusses the Privacy Act, the Computer Fraud and Abuse Act, the USA PATRIOT Act and more.
Name:Integrated Organization Wide Risk Management
Description:In this module, we describe the basic concepts associated with managing information system-related security and privacy risk in organizations. Managing information system-related security and privacy risk is a complex undertaking that requires the involvement of the entire organization. Risk management is a holistic activity that affects every aspect of the organization and cannot be made in isolation. This module discusses risk, the system development life cycle, key roles and more.
Name:Risk Management Framework Phases
Description:In this module, we discuss the NIST RMF steps. describes the RMF and provides guidelines for applying it to information systems and organizations. We discuss the RMF structured and flexible process for managing security and privacy risk, as well as RMF activities to prepare organizations to execute the framework at appropriate risk management levels.
Name:Risk Management Framework Review
Description:In this module, we review the six RMF steps: Categorize/Identify; Select; Implement; Assess; Authorize; and Monitor and provide an assessment to gauge your understanding of the course. In addition, there is a project in which you will review the categorization process by completing the NIST 800-60v1 categorization worksheet. You will then transfer the information over to the FIPS 199 Categorization Form and look at the six RMF steps.
The Risk Management Framework (RMF) provides a disciplined, structured and flexible process for managing security and privacy risk. It includes information security categorization; control selection, implementation and assessment; system and common control authorizations; and continuous monitoring. It includes activities to prepare organizations to execute the framework at appropriate risk management levels. This learning path explains the RMF steps and its processes (aka tasks) which link essential risk management processes at the system level to risk management processes at the organization level. This learning path explains the Risk Management Framework (RMF) and its processes and provides guidance for applying the RMF to information systems and organizations.