NIST Cybersecurity Framework Risk Management Training Course

5 days Cyber Security Certificate on completion
Course codeSD-CS-014
Duration5 days
LevelIntermediate to Advanced
CategoryCyber Security
DeliveryClassroom or live online
LanguageEnglish
CertificateCertificate of completion

Course overview

Cybersecurity leaders are expected to explain which risks matter, who owns them, how controls reduce exposure, and when residual risk is acceptable. Many teams have security tools, policies and audit findings but lack a repeatable way to connect them to business objectives and the NIST Cybersecurity Framework (CSF). This course addresses that gap by showing participants how to use NIST CSF 2.0 to structure cyber risk decisions, prioritise improvement work, and produce evidence that executives, auditors and regulators can understand.

Participants work through the six NIST CSF 2.0 Functions—Govern, Identify, Protect, Detect, Respond and Recover—and apply them to a realistic organisational scenario. They learn to establish a Current Profile and Target Profile, identify risk scenarios and assets, assess likelihood and impact using NIST SP 800-30 methods, map safeguards to NIST SP 800-53 controls, define risk treatment actions, and measure progress through meaningful cybersecurity outcomes. The course also covers governance, risk appetite, supplier risk, control ownership, exception handling, metrics and board-level reporting.

Delivery combines instructor-led briefings with facilitated workshops, control-mapping exercises, risk-register analysis and group decision-making. Participants use templates that can be adapted to their own environment rather than completing abstract framework exercises. By the end of the week, each participant leaves with a documented NIST CSF risk management pack: a scoped Current and Target Profile, prioritised risk register, treatment roadmap, control crosswalk, ownership model and executive reporting outline.

The course is designed for experienced security, risk, technology and assurance professionals who need to operationalise NIST CSF across a business unit, programme or enterprise. It is particularly valuable where an organisation is preparing for a framework adoption programme, audit, regulatory review, cyber resilience initiative or major control improvement investment.

Course objectives

By the end of this course, participants will be able to:

  • Construct a NIST CSF 2.0 Current Profile and Target Profile for a defined business service or organisational scope
  • Translate business objectives, risk appetite and stakeholder requirements into measurable cybersecurity outcomes
  • Develop cyber risk scenarios using NIST SP 800-30 threat, vulnerability, likelihood and impact analysis
  • Build a prioritised cyber risk register with inherent risk, control effectiveness, residual risk and accountable owners
  • Map NIST CSF Categories and Subcategories to NIST SP 800-53 Rev. 5 control families and implementation evidence
  • Select risk treatment actions using avoid, mitigate, transfer and accept decisions with documented rationale
  • Design a cybersecurity improvement roadmap using risk-based sequencing, dependencies, milestones and success measures
  • Produce an executive-ready CSF risk report that communicates material exposure, treatment status and residual-risk decisions

Benefits of attending

For you

  • Gain a repeatable method for turning NIST CSF outcomes into practical risk assessments and improvement plans
  • Build confidence presenting residual cyber risk, treatment choices and investment priorities to senior stakeholders
  • Create portfolio evidence through a completed CSF Profile, risk register and control-mapping deliverable
  • Strengthen credibility for cybersecurity governance, GRC, risk management and security leadership roles
  • Learn to distinguish NIST CSF programme management from technical control testing and NIST RMF authorisation work

For your organisation

  • Establish a common NIST CSF vocabulary for security, IT, risk, audit and business leaders
  • Improve prioritisation of security remediation by linking control gaps to documented business risk scenarios
  • Produce more defensible risk acceptance and exception decisions with clear ownership and residual-risk evidence
  • Reduce duplicated framework effort through structured crosswalks between CSF outcomes and NIST SP 800-53 controls
  • Create an actionable cybersecurity roadmap that supports budgeting, governance reporting and audit readiness

Target competencies

CSF profile developmentCyber risk analysisControl crosswalk designRisk treatment planningSecurity governance reportingResidual risk evaluation

Who should attend

  • Cybersecurity Managers — who need a consistent method for prioritising security investment and reporting risk
  • Information Security Officers — who are responsible for implementing or improving a NIST CSF-based security programme
  • IT Risk Managers — who must connect technology risks, control gaps and treatment plans to enterprise risk processes
  • Security Architects — who need to translate framework outcomes into control requirements for systems and services
  • GRC and Compliance Managers — who map evidence, policies and controls to audit, regulatory and governance obligations
  • Internal Audit and Assurance Professionals — who assess whether cybersecurity risk management is structured and defensible

Requirements and prerequisites

Participants should have practical experience in cybersecurity, IT operations, IT risk, compliance or audit, and should understand common concepts such as assets, threats, vulnerabilities, controls, incidents, risk likelihood and business impact. Familiarity with a risk register, security policy set, ISO 27001, NIST publications or control frameworks is useful but not essential. Participants should be comfortable reviewing spreadsheets and structured documentation. No programming, penetration testing, SIEM administration or prior NIST CSF certification is required. This is not an entry-level cyber awareness course; complete beginners should first gain grounding in core information security and risk terminology.

Training methodology

The course uses short instructor-led modules to establish the NIST CSF 2.0 method, followed by workshops in which participants apply each element to a realistic business-service scenario. Teams define scope, build profiles, analyse risk scenarios, map controls and debate treatment decisions using supplied templates. Case discussions examine weak governance, supplier exposure, ransomware response and control-evidence gaps. The final day is an applied planning session in which participants adapt the course artefacts to their own organisation and receive facilitator feedback on a practical implementation roadmap.

Course outline

Day 1: NIST CSF 2.0 Foundations and Governance

  • Purpose, structure and intended uses of NIST CSF 2.0
  • The Govern Function and cybersecurity risk governance outcomes
  • CSF Functions, Categories and Subcategories navigation
  • Organisational Profiles: Current Profile and Target Profile concepts
  • Scope definition for business services, systems and enterprise programmes
  • Risk appetite, risk tolerance and escalation thresholds
  • Roles, accountability and decision rights for cybersecurity risk

Workshop: Participants scope a business service and draft governance assumptions, stakeholders and risk decision authorities for a CSF Profile.

Day 2: Cyber Risk Identification and Assessment

  • Asset, data, dependency and critical-service identification
  • Cyber threat scenario construction and threat-source analysis
  • Vulnerability, exposure and control-gap identification
  • NIST SP 800-30 likelihood and impact assessment method
  • Inherent risk, residual risk and control effectiveness evaluation
  • Risk register fields, scoring scales and evidence requirements
  • Third-party and supply-chain cyber risk considerations

Workshop: Participants develop three cyber risk scenarios and populate a scored risk register with evidence, owners and residual-risk statements.

Day 3: Control Mapping and Target-State Design

  • Using Identify, Protect and Detect outcomes to define control requirements
  • Mapping CSF Subcategories to NIST SP 800-53 Rev. 5 control families
  • Control design versus control operating effectiveness
  • Evidence collection for policies, configurations, logs and reviews
  • Gap analysis between Current Profile and Target Profile
  • Control ownership, frequency and assurance responsibilities
  • Prioritising control improvements by risk reduction and feasibility

Workshop: Participants create a CSF-to-SP 800-53 control crosswalk and identify the highest-priority control gaps for their scenario.

Day 4: Risk Treatment, Resilience and Measurement

  • Risk treatment options: mitigate, transfer, avoid and accept
  • Treatment-plan design with actions, dependencies and accountable owners
  • Respond and Recover outcomes for cyber resilience planning
  • Incident response, recovery objectives and lessons-learned integration
  • Risk exceptions, compensating controls and acceptance documentation
  • Cybersecurity metrics, key risk indicators and control performance measures
  • Executive dashboards and risk reporting narratives

Workshop: Participants prepare a risk treatment roadmap and executive dashboard for a simulated ransomware and supplier disruption scenario.

Day 5: Operationalising NIST CSF in the Organisation

  • Integrating CSF Profiles with enterprise risk management processes
  • Aligning CSF activities to audit, regulatory and customer assurance requests
  • Programme governance cadence and management review forums
  • Using maturity assessments without confusing maturity with risk
  • Budget justification and investment prioritisation techniques
  • Implementation planning for people, process and technology changes
  • Continuous profile review and improvement cycle design

Workshop: Participants assemble and present a NIST CSF risk management pack containing profiles, risk priorities, treatment roadmap, ownership model and reporting plan.

Tools & standards covered

NIST Cybersecurity Framework 2.0, NIST SP 800-30 Rev. 1, NIST SP 800-53 Rev. 5, Microsoft Excel

A typical training day

08:30 – 10:30First session
10:30 – 10:45Refreshment break
10:45 – 12:30Second session
12:30 – 13:30Lunch and networking
13:30 – 15:00Third session
15:00 – 15:15Refreshment break
15:15 – 16:30Workshop and daily review

Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.

What the fee includes

  • Instruction by a practitioner facilitator
  • Full course workbook and materials
  • Exercise files, templates and case studies
  • Certificate of completion
  • Refreshments and lunch (classroom deliveries)
  • Post-course application plan
  • Facilitator follow-up on request
  • Group rates from five participants

How you can take this course

Classroom

Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.

Live online

The same facilitator and materials, delivered live for distributed teams and individuals.

In-house

Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.

Certification

Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.

Frequently asked questions

Previous NIST CSF experience is helpful but not required. Participants should already understand core security and risk concepts, because the course focuses on applying CSF 2.0 to governance, assessment, control mapping and treatment decisions.

No. NIST CSF is a flexible cybersecurity risk management framework used to organise outcomes and improvement programmes, while NIST RMF under SP 800-37 is a system authorisation process commonly used in federal environments. The course references SP 800-30 and SP 800-53 where they strengthen CSF-based risk work.

A laptop is recommended for live online delivery and useful in the classroom for working with the supplied templates. No specialist security platform, coding environment or security testing tool is needed; exercises use structured profile, risk-register and control-mapping materials.

The strongest fit is for professionals who own, advise on or assure cybersecurity risk decisions: security managers, IT risk professionals, GRC leads, architects and internal auditors. It is best suited to people working with business stakeholders rather than purely technical operations roles.

You can use the Current Profile, Target Profile, risk register and treatment roadmap templates to assess a business service, programme or control domain. The approach can also support security strategy refreshes, supplier reviews, audit remediation and cyber investment cases.

You will leave with a NIST CSF risk management pack developed through the course scenario and adaptable to your own organisation. It includes profile structure, risk scenarios, control crosswalks, treatment actions, ownership assignments and an executive reporting outline.

Upcoming sessions

  • 21 – 25 Sep 2026
    Live Online · USD 1,500
    Book
  • 21 – 25 Sep 2026
    Nairobi · USD 3,000
    Book
  • 21 – 25 Sep 2026
    Kigali · USD 3,500
    Book
  • 28 Sep – 02 Oct 2026
    Nairobi · USD 3,000
    Book
  • 28 Sep – 02 Oct 2026
    Live Online · USD 1,500
    Book
  • 05 – 09 Oct 2026
    Mombasa · USD 3,200
    Book
  • 12 – 16 Oct 2026
    Live Online · USD 1,500
    Book
  • 19 – 23 Oct 2026
    Dubai · USD 4,500
    Book

49 more dates — ask us.


Group of 5+?

Request in-house delivery or group rates →

Related courses in Cyber Security

5 Days Certificate

Splunk Enterprise Security SIEM Operations Training Course

Security operations teams need more than dashboards and alert queues: they need a repeatable way to determine which detections represent cre…

5 Days Certificate

Secure Coding and Cyber Security for Software Developers Training Course

Software developers are increasingly expected to prevent security defects before code reaches production, yet many teams still discover inje…

5 Days Certificate

Cyber Security Compliance for Healthcare Organisations Training Course

Healthcare organisations must protect electronic protected health information (ePHI) while keeping clinical, administrative and patient-faci…

5 Days Certificate

Network and Endpoint Security Foundations Training Course

Network and endpoint security failures rarely begin with a single dramatic breach. They emerge through exposed services, unmanaged laptops, …