|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/nist-risk-management-framework/
课程评论:没有评论
课程名称:实施NIST风险管理框架(RMF) 课程概述:您是否想过如何实际使用NIST风险管理框架并将其应用到您的企业或组织中?在本课程中,您将深入了解网络安全、信息技术(IT)和商业专业人士如何利用NIST风险管理框架(RMF)理解并积极管理其风险态势。课程将从学习7步NIST风险管理框架(RMF)过程的基本知识开始,包括: 1. **准备**:为组织管理安全与隐私风险做好准备的基本活动。 2. **分类**:根据影响分析对系统与信息过程进行分类。 3. **选择**:根据风险评估选择保护系统的一套NIST SP 800-53控制措施。 4. **实施**:实施控制措施并记录控制部署方式。 5. **评估**:评估控制措施是否到位、按预期运行并产生预期结果。 6. **授权**:高级官员基于风险做出决策,授权系统运行。 7. **监控**:持续监控控制实施情况和系统风险。 然后,您将深入探讨框架,全面理解每一步的实际应用以及使用RMF和eMass的其他考虑。NIST风险管理框架(RMF)提供了一个将安全、隐私和网络供应链风险管理活动整合到系统开发生命周期中的过程。这种基于风险的控制选择和规范方法考虑了适用法律、指令、行政命令、政策、标准或法规的有效性、效率和限制。通过使用NIST风险管理框架(RMF),您可以更好地管理组织风险,确保在政府和国防行业中运营时信息安全与隐私项目的成功。完成本课程后,您将获得4个CEU,用于更新CompTIA A+、Network+、Security+、Linux+、Cloud+、PenTest+、CySA+或CASP+认证。
Have you ever wondered how to actually use the NIST Risk Management Framework and apply it to your business or organization?In this course, you will get an inside look at how cybersecurity, information technology (IT), and business professionals use the NIST Risk Management Framework (RMF) to understand and actively manage their risk posture.You will begin by learning the fundamentals of the 7-step NIST Risk Management Framework (RMF) process, including:PREPAREEssential activities to prepare the organization to manage security and privacy riskCATEGORIZECategorize the system and information processes, stored, and transmitted based on an impact analysisSELECTSelect the set of NIST SP 800-53 controls to protect the system based on a risk assessmentIMPLEMENTImplement the controls and document how controls are deployedASSESAssess to determine if the controls are in place, operating as intended, and producing the desired resultsAUTHORIZEThe senior official makes a risk-based decision to authorize the system (to operate)MONITORContinuously monitor control implementation and risks to the systemThen, you will dive deeper into the framework to fully understand each of the seven steps, how they are applied in the real world and other considerations for using RMF and eMass in your career.The NIST Risk Management Framework (RMF) provides a process that integrates security, privacy, and cyber supply chain risk management activities into the system development lifecycle.This risk-based approach to control selection and specification considers the effectiveness, efficiency, and constraints available due to applicable laws, directives, Executive Orders, policies, standards, or regulations.By using the NIST Risk Management Framework (RMF), you can better manage organizational risk and ensure the success of your information security and privacy programs when operating within the government and defense industries. Upon completion of this course, you will earn 4 CEUs towards the renewal of your CompTIA A+, Network+, Security+, Linux+, Cloud+, PenTest+, CySA+, or CASP+ certifications.