Choose your language
NIST (National Institute of Standards and Technology) Cybersecurity Framework 2.0: Managing Risks Course
More than 2 million students worldwide

NIST (National Institute of Standards and Technology) Cybersecurity Framework 2.0: Managing Risks Course

Master the NIST Cybersecurity Framework 2.0 and build a risk management program that actually protects your organization. This course walks you through all six CSF Functions — Govern, Identify, Protect, Detect, Respond, and Recover — with practical tools you can apply immediately. Whether you're a security professional, risk manager, or IT leader, you'll gain the structured approach needed to manage cyber risk with confidence.

Dedika for businesses

What you will learn:

  • Apply all six NIST CSF 2.0 Functions to build a complete organizational risk management lifecycle.

  • Design governance structures, cybersecurity policies, and executive reporting mechanisms aligned to business objectives.

  • Conduct asset inventories, threat assessments, and risk register development using qualitative and quantitative methods.

  • Implement layered protective controls spanning identity management, data security, and infrastructure hardening.

  • Build detection architectures and incident response plans that minimize dwell time and operational disruption.

  • Integrate NIST CSF 2.0 with complementary standards, supply chain risk programs, and continuous improvement cycles.

How you study in practice NIST (National Institute of Standards and Technology) Cybersecurity Framework 2.0: Managing Risks Course

How you practice NIST (National Institute of Standards and Technology) Cybersecurity Framework 2.0: Managing Risks Course

For companies looking to train their teams

With Dedika for businesses, the course includes exercises and examples tailored to your own business and the way your company needs.

Click here

Course Content

8 Chapters • 38 LessonsDuration between 4 and 360 hours (you decide)

Chapter 1See details

Foundations of Cybersecurity Risk Management

  • Lesson 1 • Overview of Cybersecurity Frameworks

    Surveys major cybersecurity frameworks and their purposes. Positions NIST CSF 2.0 within the broader landscape of standards.

  • Lesson 2 • Core Cybersecurity Concepts and Terminology

    Defines threats, vulnerabilities, assets, and risk. Provides the shared vocabulary needed throughout the entire course.

  • Lesson 3 • Organizational Context for Cybersecurity

    Examines how business size, sector, and mission shape cybersecurity needs. Prepares learners to tailor framework adoption to their context.

  • Lesson 4 • Risk Management Principles and Objectives

    Explains risk tolerance, appetite, and treatment options. Connects risk decisions to organizational strategy and mission.

Chapter 2See details

NIST CSF 2.0 Architecture and Structure

  • Lesson 1 • Categories, Subcategories, and Informative References

    Explains how Functions break into Categories and Subcategories. Shows how Informative References link CSF outcomes to other standards.

  • Lesson 2 • The Six Core Functions Explained

    Introduces Govern, Identify, Protect, Detect, Respond, and Recover. Explains how each Function contributes to a complete risk management lifecycle.

  • Lesson 3 • Implementation Tiers and Their Meaning

    Defines the four Implementation Tiers from Partial to Adaptive. Clarifies that Tiers measure rigor and integration, not maturity scores.

  • Lesson 4 • Organizational Profiles Concept

    Introduces Current and Target Profiles as tools for capturing desired cybersecurity outcomes. Connects Profiles to gap analysis and prioritization.

  • Lesson 5 • History and Evolution of NIST CSF

    Traces CSF development from version 1.0 through 2.0. Highlights key changes that expand applicability beyond critical infrastructure.

Chapter 3See details

The Govern Function: Cybersecurity Governance

  • Lesson 1 • Cybersecurity Policy Development

    Guides creation of policies that reflect organizational risk tolerance. Policies become the authoritative basis for all security controls.

  • Lesson 2 • Governance Roles and Accountability

    Defines board, executive, and operational cybersecurity roles. Establishes clear accountability lines required by the Govern Function.

  • Lesson 3 • Organizational Risk Strategy and Context

    Establishes how mission, legal obligations, and stakeholder expectations shape risk strategy. Outputs feed directly into Identify Function activities.

  • Lesson 4 • Cybersecurity Program Oversight and Metrics

    Defines how leadership monitors program effectiveness through metrics and reporting. Connects governance oversight to continuous improvement.

  • Lesson 5 • Supply Chain Risk Governance

    Addresses governance requirements for third-party and supply chain risks. Learners design oversight mechanisms for vendor cybersecurity accountability.

Chapter 4See details

The Identify Function: Asset and Risk Discovery

  • Lesson 1 • Improvement Identification and Prioritization

    Translates risk assessment findings into a prioritized improvement backlog. Links Identify outputs directly to Protect and Respond planning.

  • Lesson 2 • Asset Management Practices

    Covers hardware, software, data, and service inventory methods. Accurate asset inventories are the prerequisite for all subsequent risk decisions.

  • Lesson 3 • Supply Chain Risk Identification

    Identifies cybersecurity risks introduced by suppliers, partners, and service providers. Extends the risk register to cover third-party exposure.

  • Lesson 4 • Business Environment and Dependency Analysis

    Maps critical business processes and their technology dependencies. Reveals which assets are most consequential to mission continuity.

  • Lesson 5 • Risk Assessment Methodologies

    Applies qualitative and quantitative risk assessment techniques. Produces risk registers that drive prioritized treatment decisions.

Chapter 5See details

The Protect Function: Safeguards and Controls

  • Lesson 1 • Data Security and Protection

    Addresses encryption, data loss prevention, and secure data handling. Protects data confidentiality and integrity across its full lifecycle.

  • Lesson 2 • Platform and Infrastructure Security

    Applies hardening, patching, and configuration management to systems. Reduces the attack surface across on-premises and cloud environments.

  • Lesson 3 • Technology Protection and Resilience

    Implements protective technologies including firewalls, secure development, and resilience controls. Ensures systems can withstand and recover from disruptions.

  • Lesson 4 • Workforce Awareness and Training

    Designs security awareness programs that change employee behavior. Human-layer protection complements technical controls throughout the framework.

  • Lesson 5 • Identity Management and Access Control

    Covers authentication, authorization, and least-privilege principles. Strong identity controls are the first line of defense for critical assets.

Chapter 6See details

The Detect Function: Monitoring and Anomaly Detection

  • Lesson 1 • Adverse Event Analysis and Triage

    Develops analyst skills for triaging alerts and confirming incidents. Accurate triage reduces false positives and accelerates response activation.

  • Lesson 2 • Security Information and Event Management

    Covers SIEM architecture, log aggregation, and correlation rule design. SIEM is the central platform for operationalizing detection outcomes.

  • Lesson 3 • Anomaly and Threat Detection Techniques

    Applies behavioral analytics and threat intelligence to identify malicious activity. Moves detection beyond signature-based methods to behavior-based approaches.

  • Lesson 4 • Continuous Monitoring Strategy

    Defines monitoring scope, frequency, and tooling requirements. A documented strategy ensures detection coverage aligns with the risk register.

Chapter 7See details

The Respond Function: Incident Response

  • Lesson 1 • Containment, Eradication, and Recovery Steps

    Executes tactical response phases to stop, remove, and restore after an incident. Each phase has defined entry and exit criteria to maintain control.

  • Lesson 2 • Incident Communication and Reporting

    Manages internal and external communications during active incidents. Timely, accurate reporting maintains stakeholder trust and meets obligations.

  • Lesson 3 • Post-Incident Analysis and Improvement

    Conducts structured post-incident reviews to extract lessons and improve controls. Findings feed back into Govern, Identify, and Protect Functions.

  • Lesson 4 • Incident Classification and Prioritization

    Applies severity criteria to classify and prioritize active incidents. Consistent classification ensures proportionate resource allocation during response.

  • Lesson 5 • Incident Response Planning

    Constructs incident response plans covering roles, procedures, and communication. Plans operationalize the Respond Function before incidents occur.

Chapter 8See details

The Recover Function and Continuous Improvement

  • Lesson 1 • Testing and Exercising Recovery Plans

    Designs tabletop, functional, and full-scale exercises to validate recovery plans. Regular testing reveals gaps before real incidents expose them.

  • Lesson 2 • Continuous Improvement Across All Functions

    Establishes a structured cycle for reviewing and improving all six CSF Functions. Improvement activities are tracked, prioritized, and reported to leadership.

  • Lesson 3 • Recovery Planning and Business Continuity

    Develops recovery plans that restore operations within defined time objectives. Plans align with business continuity and disaster recovery requirements.

  • Lesson 4 • Sustaining the CSF Program Long-Term

    Addresses resource planning, stakeholder engagement, and program maturation over time. Ensures the CSF program remains relevant as threats and business needs evolve.

  • Lesson 5 • Resilience Restoration Techniques

    Applies technical and operational techniques to restore full system capability. Restoration activities are sequenced to minimize business impact.

Certification

Your valid completion certificate

This course is for you:

  • IT managers ready to formalize their organization's cybersecurity risk approach.

  • Compliance officers navigating overlapping regulatory and security framework requirements.

  • Risk analysts seeking a structured methodology to assess and document cyber threats.

  • Security consultants advising clients on building defensible, audit-ready security programs.

  • Career changers from IT support who want to move into cybersecurity governance roles.

  • Operations leaders responsible for business continuity when cyber incidents strike.

What our students say

Your classes are perfect. I purchased the one-year package and finally have the opportunity to follow various topics of interest without needing to switch platforms... I thank you for everything you do, I've already recommended you to other people...
Giulio Carlo
Giulio CarloDigital Marketing Student
I like how the lessons are straight to the point and how I can switch chapters and skip content I don't need.
Mariana Ferres
Mariana FerresPhotography Student
I like the content and the presentation style and video transcription, which speeds up the process!
Luciana Alvarenga
Luciana AlvarengaNail Design Student
The platform is fast, simple to use. The diversity of content and complementary videos really help with learning.
André Felipe
André FelipePrompt Engineering Student

Top trainings

FAQ

Who is Dedika?

Is the certificate valid in United States?

Are the courses free?

What is the course workload?

What are the courses like?

How do the courses work?

What is the duration of the courses?

What is the cost or price of the courses?

What is an EAD or online course and how does it work?

PDF Course