Hyppää sisältöön

Koulutus

NIST Cybersecurity Foundation

Access expert-led QA training live online, wherever you learn best.

Overview

This 2-day course provides a foundation-level introduction to NIST-based cybersecurity principles. It helps participants understand cybersecurity risks, support organisational security initiatives, and contribute to the effective implementation of cybersecurity programmes. Through practical explanations of risk management, security controls, awareness and training, and incident management, learners gain knowledge to support informed decision-making and strengthen overall cybersecurity governance.

Prerequisites

There are no prerequisites to participate in this training course.

Target audience

  • Managers, consultants, and team leaders responsible for supporting cybersecurity initiatives within their organisation
  • Staff involved in cybersecurity or information security activities seeking to understand best practices and frameworks
  • Professionals aiming to broaden their knowledge of cybersecurity governance, risk management, and incident response
  • Individuals interested in starting a career in cybersecurity or enhancing their understanding of NIST guidelines
  • IT personnel and system administrators supporting the implementation and maintenance of secure systems

Objectives

Delegates will learn how to:

  • Explain fundamental cybersecurity concepts
  • Describe the purpose of principal NIST cybersecurity publications
  • Understand the NIST approach to cybersecurity risk management
  • Recognise common security controls and best practices in line with NIST guidance
  • Explain the purpose and structure of the NIST Cybersecurity Framework 2.0
  • Understand the fundamentals of incident management
  • Apply NIST concepts to support basic organisational cybersecurity activities

Outline

Cybersecurity fundamentals

  • Core cybersecurity terminology and principles, including information systems, assets, threats, vulnerabilities, risk, and security controls
  • Establishing vocabulary required to understand the NIST ecosystem

The NIST cybersecurity ecosystem

  • Introduction to NIST standards, frameworks, and Special Publications
  • Distinguishing between guidance for managing organisational cyber risk and detailed publications for selecting, implementing, and assessing controls
  • Overview of key publications: NIST SP 800-12, NIST SP 800-53, NIST SP 800-37, NIST SP 800-171, and NIST Cybersecurity Framework (CSF 2.0)

Cybersecurity risk management

  • Introduction to risk concepts and NIST’s approach to risk-based cybersecurity
  • Identifying assets, threats, and vulnerabilities
  • Understanding likelihood and impact, determining risk, selecting responses, and maintaining risk awareness

NIST risk management framework

  • Foundation-level introduction to the RMF lifecycle and its relationship with security controls
  • Overview of the seven RMF stages: Prepare, Categorise, Select, Implement, Assess, Authorise, Monitor

NIST security controls

  • Purpose and structure of NIST SP 800-53
  • Control families, selection, implementation, assessment, and monitoring
  • Distinction between administrative, technical, and physical controls
  • Understanding how controls support risk treatment

NIST cybersecurity framework 2.0

  • Coverage of the six CSF 2.0 Functions: Govern, Identify, Protect, Detect, Respond, Recover
  • Introduction to Functions, Categories, Subcategories, organisational Profiles, Current and Target Profiles, Implementation Tiers
  • How the CSF supports cybersecurity improvement and communication between stakeholders

Protecting sensitive information – NIST SP 800-171

  • Introduction to protecting Controlled Unclassified Information in non-federal environments
  • Importance for defence and government supply chains
  • Relationship between information requirements, security controls, and supplier assurance

Cybersecurity awareness and training

  • Role of people within the NIST approach to cybersecurity
  • Security awareness, responsibilities, acceptable behaviour, and building organisational security capability

Incident management

  • Foundation-level incident management: preparation, detection, analysis, containment, response, and recovery
  • Connection between incident response, risk management, controls, monitoring, and organisational resilience

Applying NIST in practice

  • Scenario-based application of NIST publications
  • Identifying key risks, relevant CSF Functions, appropriate control areas, and response to incidents
  • Reinforcing the relationship: Risk, Framework, Controls, Implementation, Monitoring, Response, Improvement

Exams and assessments

The course includes a certification examination covering fundamental principles and concepts of cybersecurity, and risk management and cybersecurity controls. The training fee includes the first exam attempt, one free retake, the certification application fee, and the first year of the Annual Maintenance Fee. An attestation of course completion worth 14 CPD credits will be awarded.

Hands-on learning

Participants receive comprehensive training materials with practical examples, exercises, and quizzes. Scenario-based activities encourage learners to apply NIST concepts in practice, and interactive discussions support engagement and knowledge sharing.

Osta liput

QA’s online-courses from Tieturi

Questions about QA courses?

Find out how QA’s live online courses work, what you need to participate, and what to expect before booking your training.

Accreditation and trademark notice

ITIL® and PRINCE2® courses are provided by QA Ltd, an ATO of People Cert.

ITIL®, PRINCE2® are registered trademarks of the PeopleCert group. Used under licence from PeopleCert. All rights reserved.

TOGAF® is a registered trademark of The Open Group.