|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/nist-cyber-security-framework-o/
课程评论:没有评论
**课程名称:** NIST网络安全框架 **课程概述:** 本课程旨在帮助学习者深入理解NIST网络安全框架(CSF),并判断其是否适用于自身的组织。NIST CSF作为一个通用的分类体系和机制,能帮助组织: 1. **描述当前的网络安全现状:** 了解组织在网络安全方面所处的位置。 2. **描绘网络安全的目标状态:** 设定和沟通组织希望达到的网络安全水平。 3. **识别和优先改进领域:** 在一个持续可重复的过程中,找出并优化网络安全实践。 4. **评估进展:** 衡量组织在实现目标状态方面的进度。 5. **内部与外部沟通:** 与内外部利益相关者就网络安全风险进行有效沟通。 NIST CSF并非适用于所有关键基础设施的标准,组织在风险、威胁、漏洞和风险容忍度方面存在差异,因此CSF的定制化程度也会有所不同。组织可以根据其关键服务交付需求,确定重要活动,并优先投资以最大化资金效益。最终,CSF的目的是降低并更好地管理网络安全风险。 **课程内容将涵盖:** * CSF的五个核心功能(Identify, Protect, Detect, Respond, Recover) * 每个功能下的“类别”(Categories)和“子类别”(Subcategories) * 对整个框架的深入探讨 * CSF的优缺点分析 * 在公司项目、团队或部门中实施CSF的指南
Understanding what the NIST Cybersecurity Framework is helps us to decide whether it's the right framework for us. If we look at what NIST says the CSF is we read the following:Building from those standards, guidelines, and practices, the Framework provides a common taxonomy and mechanism for organizations to:1. Describe their current cybersecurity posture;2. Describe their target state for cybersecurity;3. Identify and prioritize opportunities for improvement within the context of a continuous and repeatable process;4. Assess progress toward the target state;5. Communicate among internal and external stakeholders about cybersecurity risk.The Framework is not a one-size-fits-all approach to managing cybersecurity risk for critical infrastructure. Organizations will continue to have unique risks - different threats, different vulnerabilities, different risk tolerances. They also will vary in how they customize practices described in the Framework. Organizations can determine activities that are important to critical service delivery and can prioritize investments to maximize the impact of each dollar spent. Ultimately, the Framework is aimed at reducing and better managing cybersecurity risks.This course will focus on the 5 Areas, Categories and Sub Categories of each area, we then work our way through the whole framework to then discuss the Pros and Cons of the CSF and how to implement it in a project at your company or for your company / team / department.