Security for the SMB: Implementing the NIST Cybersecurity Framework
1h 23mIntermediate2020-01-02
Authors

Ronald Woerner
Professor, Cybersecurity Expert
Course details
Cybersecurity incidents impact organizations of all sizes, in all sectors. Small and medium businesses (SMBs) may not have the same infrastructure or resources for security, but face the same risks. In this course, Ron Woerner explains how to secure SMB assets, systems, and networks, leveraging the five functions of the National Institute of Standards and Technology (NIST) Cybersecurity Framework—identify, protect, detect, respond, and recover—as a scaffold for creating a robust cybersecurity program. Learn how to identify your assets and necessary levels of access, set up defenses such as firewalls and encryption, monitor your systems, create an effective incident response plan, and use backups and cloud services to ensure you can recover and resume operations as quickly as possible.
Topics include:
- Cybersecurity threats and vulnerabilities
- Building a cybersecurity program
- Creating an inventory of critical assets
- Writing security policies and procedures
- Network defenses
- Personal and physical security
- Establishing a response plan
- Response testing and training
- Backup and recovery
Topics include:
- Cybersecurity threats and vulnerabilities
- Building a cybersecurity program
- Creating an inventory of critical assets
- Writing security policies and procedures
- Network defenses
- Personal and physical security
- Establishing a response plan
- Response testing and training
- Backup and recovery
Skills covered
Incident ResponseCybersecurityDeep Dive (X:Y)
Concepts
Introduction
- secure your infrastructure with nist
Review of Cybersecurity Fundamentals
- understanding and managing your risks
- cybersecurity threats and vulnerabilities
- cybersecurity requirements
- nist cybersecurity framework
- cybersecurity five-step process overview
- building a cybersecurity program
Identify
- inventory of critical assets
- business impact assessment
- security policies and procedures
- i-aaa
Protect
- overview of defending business assets
- network defenses
- system security
- encryption
- personnel and physical security
Detection
- detecting security issues overview
- system auditing and logging
- monitoring and alerting
- assessments and audits
Respond
- establishing a response plan
- incident response plan examples
- digital forensics
- response testing and training
Recover
- your continuity of operations plan
- backups, virtualization, and the cloud
Conclusion
- best practices
- resources