Risk management is an evolving discipline. In this video, discover new concepts provided in the latest risk management framework published by NIST in their Special Publication 800-37 (Revision 2).
- [Narrator] NIST, in December 2018, issued revision two … to their original special publication on risk, … SP 800-37 Risk Management Framework. … The risk management framework provides a disciplined, … structured and flexible process for managing security … and privacy risk. … It covers information security categorization, … control selection, implementation, and assessment, … system and common control authorizations, … and continuous monitoring of risks. … The risk management framework considers risk … at three levels, … information systems risk, mission or business process risk, … and whole of business risk. … The risk management process involves preparation … of the necessary risk material … needed to carry out a risk management. … And then, a six stage process of categorization, … selection, implementation, assessment, … authorization and monitoring. … The prepare stage of the framework involves seven actions, … three of which are risk related and four controls related. … They are assign people to risk management roles, …
Author
Released
2/13/2020- Dissecting cyber risk
- Working with NIST, COBIT, and other frameworks
- Exploring cybercrime
- The different stages of the cyber kill chain
- How cyber criminals hide their attacks
- Measuring incident management maturity
- Detecting and responding to attacks
Skill Level Intermediate
Duration
Views
Related Courses
-
Learning Security Frameworks
with Mandy Huth47m 8s Intermediate -
Security Matters (To Everyone)
with Mandy Huth33m 8s Beginner -
GDPR Compliance: Essential Training
with Mandy Huth55m 17s Intermediate -
Penetration Testing Essential Training
with Malcolm Shore2h 29m Intermediate
-
Introduction
-
1. Frameworks and Controls
-
An advanced risk framework5m 22s
-
Managing security with COBIT3m 15s
-
ASD and its top controls2m 49s
-
Protecting payment card data7m 14s
-
Clouding the issues3m 44s
-
2. Cyber Threats
-
Hiding using processes3m 59s
-
3. Managing Cyber Incidents
-
Incident management basics3m 48s
-
Detecting an attack4m 4s
-
Responding to an incident2m 33s
-
-
Conclusion
-
What's next55s
-
- Mark as unwatched
- Mark all as unwatched
Are you sure you want to mark all the videos in this course as unwatched?
This will not affect your course history, your reports, or your certificates of completion for this course.
CancelTake notes with your new membership!
Type in the entry box, then click Enter to save your note.
1:30Press on any video thumbnail to jump immediately to the timecode shown.
Notes are saved with you account but can also be exported as plain text, MS Word, PDF, Google Doc, or Evernote.
Share this video
Embed this video
Video: An advanced risk framework