Implementing the NIST Risk Management Framework

Implementing the NIST Risk Management Framework

1h 42mIntermediate2024-10-28

Authors

Ronald Woerner

Ronald Woerner

Professor, Cybersecurity Expert

Course details

As the industry standard, the U.S. National Institute of Standards and Technology (NIST) Risk Management Framework (RMF) process provides a simple way for organizations to categorize and effectively manage their security and privacy programs throughout the system management lifecycle. In this course, Ron Woerner—a noted speaker and writer in the security industry—shows you how organizations of all types and sizes can manage their security and privacy risks. Learn about each step in detail, go over a sample case study, and consider how to practice implementation in your own organization. Explore challenges and solutions to gain real-world experience with the process. Plus, gain hands-on experience with the related NIST Special Publications. By the end of this course, you will be well-versed in the NIST RMF, how to implement it, and how to manage each step for your own organization.

Learning objectives
Assess techniques for implementing the NIST Risk Management Framework in various organizational contexts.
Adapt methods for identifying, managing, and mitigating compliance risks for a sample or real-world organization, considering its specific requirements and constraints.
Interpret case studies showcasing how sample organizations successfully solved common security problems by applying the NIST Risk Management Framework.
Evaluate relevant publications, procedures, and tools for effectively implementing the NIST Risk Management Framework's Seven Steps within an organization.
Choose and recommend best practices for conducting comprehensive NIST Risk Management Framework assessments tailored to organizations of diverse sizes, structures, and industry sectors.

Skills covered

Vulnerability ManagementGovernance, Risk, and ComplianceCybersecurityOne-Off

Concepts

Introduction

  • Managing risks using a standard framework

NIST RMF Preparation

  • Preparing for a NIST Risk Management Framework (RMF) assessment
  • Taking a risk-based approach for security
  • NIST RMF Prepare step
  • NIST RMF Resources

Categorizing Systems

  • Determining in-scope systems
  • Identifying and inventorying information systems and data
  • System Categorization Process
  • Using a Business Impact Assessment for system categorization
  • Categorization terms and resources

Control Selection and Implementation

  • Selecting security and privacy controls
  • Security controls
  • Security control baselines
  • Security control implementation

Assessing Controls

  • Establishing NIST RMF assessment goals
  • NIST RMF assessment steps
  • Documenting risk assessment results

Authorizing Systems

  • Authorize - Risk analysis
  • NIST Authorization process

Monitor

  • Establishing monitoring goals
  • Scenario - Continuous monitoring examples
  • Continuous monitoring strategy

Conclusion

  • Best practices in implementing the NIST RMF
40,000 Toman