Security for the SMB: Implementing the NIST Cybersecurity Framework

Security for the SMB: Implementing the NIST Cybersecurity Framework

1h 23mIntermediate2020-01-02

Authors

Ronald Woerner

Ronald Woerner

Professor, Cybersecurity Expert

Course details

Cybersecurity incidents impact organizations of all sizes, in all sectors. Small and medium businesses (SMBs) may not have the same infrastructure or resources for security, but face the same risks. In this course, Ron Woerner explains how to secure SMB assets, systems, and networks, leveraging the five functions of the National Institute of Standards and Technology (NIST) Cybersecurity Framework—identify, protect, detect, respond, and recover—as a scaffold for creating a robust cybersecurity program. Learn how to identify your assets and necessary levels of access, set up defenses such as firewalls and encryption, monitor your systems, create an effective incident response plan, and use backups and cloud services to ensure you can recover and resume operations as quickly as possible.

Topics include:
- Cybersecurity threats and vulnerabilities
- Building a cybersecurity program
- Creating an inventory of critical assets
- Writing security policies and procedures
- Network defenses
- Personal and physical security
- Establishing a response plan
- Response testing and training
- Backup and recovery

Skills covered

Incident ResponseCybersecurityDeep Dive (X:Y)

Concepts

Introduction

  • secure your infrastructure with nist

Review of Cybersecurity Fundamentals

  • understanding and managing your risks
  • cybersecurity threats and vulnerabilities
  • cybersecurity requirements
  • nist cybersecurity framework
  • cybersecurity five-step process overview
  • building a cybersecurity program

Identify

  • inventory of critical assets
  • business impact assessment
  • security policies and procedures
  • i-aaa

Protect

  • overview of defending business assets
  • network defenses
  • system security
  • encryption
  • personnel and physical security

Detection

  • detecting security issues overview
  • system auditing and logging
  • monitoring and alerting
  • assessments and audits

Respond

  • establishing a response plan
  • incident response plan examples
  • digital forensics
  • response testing and training

Recover

  • your continuity of operations plan
  • backups, virtualization, and the cloud

Conclusion

  • best practices
  • resources
40,000 Toman