|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/nist-cyber-security-framework/
课程评论:没有评论
**Coursera 课程概述:NIST 网络安全框架** 本课程将深入介绍 NIST(美国国家标准与技术研究院)网络安全框架。 **NIST 简介:** NIST 成立于 1901 年,隶属于美国商务部,是美国历史最悠久的物理科学实验室之一。其成立宗旨在解决当时美国工业竞争力面临的重大挑战——落后于英国、德国等经济对手的国家测量基础设施。 **NIST 网络安全框架简介:** 该框架是一种基于风险的网络安全风险管理方法,由三个主要部分组成:框架核心、框架实施 tiers(层级)和框架 profiles(剖面)。每个组成部分都强化了业务使命与网络安全活动之间的联系。 **框架核心:** 包括功能 (Function)、类别 (Category) 和子类别 (Sub category),并提供信息参考 (Informative Reference)。 **框架实施 tiers(层级):** * Tier 1: 局部 (Partial) * Tier 2: 风险知情 (Risk Informed) * Tier 3: 可重复 (Repeatable) * Tier 4: 自适应 (Adaptive) **框架 profiles(剖面):** 包括当前状态 (Current state) 和目标状态 (Target State)。 **为何使用该框架?** 该框架为内部和外部利益相关者提供了一种理解、管理和表达网络安全风险的通用语言。它可以帮助识别和优先处理降低网络安全风险的行动,并作为协调政策、业务和技术方法的工具。该框架可用于管理整个组织的网络安全风险,也可专注于组织内关键服务的交付。 **如何使用该框架?** 该框架可用于定义关键基础设施,保护其免受攻击,识别漏洞,响应事件并恢复到原始状态。 **课程目标:** 本课程将帮助您理解 NIST 网络安全框架是什么、为何使用它以及如何使用它。
What is NIST?NIST stands for The National Institute of Standards and Technology.It is part of U.S. department of commerce and was founded in 1901.NIST is one of the nation's oldest physical science laboratories.Congress established the agency to remove a major challenge to U.S. industrial competitiveness at the time-a second-rate measurement infrastructure that lagged behind the capabilities of the United Kingdom, Germany, and other economic rivals.What is NIST Cyber Security Framework?The Framework is a risk-based approach to managing cybersecurity risk, and is composed of three parts: the Framework Core, the Framework Implementation Tiers, and the Framework Profiles. Each Framework component reinforces the connection between business mission and cybersecurity activities.What is Framework core?FunctionCategorySub categoryInformative Reference What is Framework Implementation tier?Tier 1: PartialTier 2: Risk InformedTier 3: RepeatableTier 4: AdaptiveWhat is Framework Profile?Current stateTarget StateWhy we use this Framework?The Framework provides a common language for understanding, managing, and expressing cybersecurity risk to internal and external stakeholders. It can be used to help identify and prioritize actions for reducing cybersecurity risk, and it is a tool for aligning policy, business, and technological approaches to managing that risk. It can be used to manage cybersecurity risk across entire organizations or it can be focused on the delivery of critical services within an organization.How to use this framework?This framework can be use by defining critical infrastructure, Protect attack on them, Identify vulnerabilities, respond to incident and recover to original state.This course will help you to understand what is this framework, why we use this? and how to use this?