Cyber Incidents· PremiumLevel: Intermediate
Overview
The NIST Cybersecurity Framework is one of the most widely adopted voluntary standards for organizing and communicating cybersecurity risk management across industries. This two-part course walks participants through the Framework's Core functions—Identify, Protect, Detect, Respond, and Recover—along with Implementation Tiers and Profiles that help organizations gauge and improve their current security posture. The course also introduces key supporting publications, SP 800-53 and SP 800-171, which provide detailed control catalogues relevant to federal contractors and organizations handling sensitive data. By establishing a common vocabulary and structure, the Framework enables more productive conversations between technical teams, leadership, legal counsel, and insurance professionals.
What you’ll learn
- ✓Explain the structure and purpose of the NIST Cybersecurity Framework, including its Core functions, Implementation Tiers, and Profiles
- ✓Distinguish between SP 800-53 and SP 800-171 and identify the organizational contexts in which each applies
- ✓Apply the Framework's Core functions to assess gaps in an organization's current cybersecurity risk management approach
- ✓Use Implementation Tiers to communicate an organization's cybersecurity maturity to board members and senior leadership
- ✓Recognize how Framework Profiles can be used to set target security states and prioritize improvement efforts
- ✓Identify how alignment with the NIST Cybersecurity Framework may be relevant to insurance underwriting, legal due diligence, and regulatory conversations
Skills you’ll gain
Explain the structure and purpose of the NIST Cybersecurity Framework, including its Core functions, Implementation Tiers, and ProfilesDistinguish between SP 800-53 and SP 800-171 and identify the organizational contexts in which each appliesApply the Framework's Core functions to assess gaps in an organization's current cybersecurity risk management approachUse Implementation Tiers to communicate an organization's cybersecurity maturity to board members and senior leadershipRecognize how Framework Profiles can be used to set target security states and prioritize improvement effortsIdentify how alignment with the NIST Cybersecurity Framework may be relevant to insurance underwriting, legal due diligence, and regulatory conversations
Audience and prerequisites
Who this is for
This course is designed for board members, executives, CISOs and security teams, cyber-insurance professionals, and legal advisors who need a shared, working understanding of the NIST Cybersecurity Framework to collaborate effectively on cybersecurity risk management.
Prerequisites
None — designed for non-technical professionals, though security practitioners will also find value in the cross-functional perspective.
Curriculum
1. Survey of NIST Cybersecurity Framework Part 1 of 2
In part one (1) of this seminar, our expert panelists introduce the high-risk cybersecurity concerns companies face and the NIST Cybersecurity Framework. The panel outlines critical framework structures for organizations and guides counsel on keeping clients compliant. Our speakers provide vital insight into the current cybersecurity requirements, an overview of NIST, the NIST framework, NIST Cybersecurity Framework Core and NIST Cybersecurity Framework Implementation Tiers, and the importance to lawyers in understanding each phase of the framework. Topics covered in this webinar: National Institute of Standards and Technology Cybersecurity (NIST) Framework Part 1: NIST Cybersecurity Framework Core Part 2: NIST Cybersecurity Framework Implementation Tiers
Free preview Video coming soon2. Survey of NIST Cybersecurity Framework Part 2 of 2
In part two (2) of this seminar, our expert panelists explain NIST Cybersecurity Framework Profiles and describe how organizations may seek to use them to achieve their desired cybersecurity posture. Our speakers give an overview of the NIST Special Publication 800-53 and highlight the most important revisions and additions of Revision 5. They additionally break down the NIST Special Publication 800-171, which was created for the proper protection and consistency of unclassified nonfederal information and conclude by giving an overview of its requirements. Topics covered in this webinar: Part 3: NIST Cybersecurity Framework Profile NIST Special Publication 800-53 NIST Special Publication 800-171 FTC's Application of the NIST Cybersecurity Framework
Video coming soon