PECB Certified NIST Cybersecurity Professional

A five-day PECB course on using the NIST frameworks to manage risk, select security controls and handle incidents.

The NIST publications set out how security work can be structured, but the distance from written guidance to daily practice is where the work often stalls. This course works through NIST SP 800-12, NIST SP 800-53, the NIST RMF, NIST SP 800-171 and the NIST Cybersecurity Framework, and shows you how to use them to build a cybersecurity programme that fits what your organisation is trying to achieve. It also covers how to prevent, detect and respond to cyber threats. Berigo delivers the course as a PECB partner.

Who the course is for

  • Executives and directors responsible for overseeing cybersecurity work in their organisation
  • System administrators and network engineers who want a firmer grasp of security controls and risk management in order to meet the NIST standards
  • Professionals who develop and implement cybersecurity programmes
  • Advisors delivering cybersecurity and compliance services who need to keep up with the NIST frameworks
  • Digital forensics and cybercrime investigators who need both the technical and the regulatory side of the frameworks when investigating and responding to incidents
  • Anyone working in cybersecurity or information security who wants to understand the NIST guidance and manage risk in practice

Content

  • Day 1. Introduction to the NIST cybersecurity standards and principles: course objectives and structure, frameworks and standards for information security and cybersecurity, NIST and its role in cybersecurity, introduction to cybersecurity, the organisation and its context, roles, responsibilities and authorities, and cybersecurity policy
  • Day 2. Risk management strategy and supply chain risk: risk management strategy, risk assessment, supply chain risk management, improvement and asset management
  • Day 3. Selecting security controls, awareness and continuous monitoring: security control selection, security measures, awareness and training, and security continuous monitoring
  • Day 4. Cybersecurity incident management: incident management and analysis, incident response, mitigation and reporting, incident recovery and lessons learned, and closing of the course
  • Day 5. Certification exam

Certification

The exam runs for three hours and covers five competency domains: fundamental principles and concepts of cybersecurity, planning an organisational strategy in cybersecurity, assessing and advising on cybersecurity programmes and security controls, cybersecurity incident management, and cybersecurity incident response. Passing it lets you apply for certification. The credential PECB Certified Provisional NIST Cybersecurity Professional has no experience requirement. PECB Certified NIST Cybersecurity Professional requires five years of professional experience, two of them in cybersecurity, and at least 300 hours of work on cybersecurity programmes. Both require you to sign the PECB Code of Ethics. Participants receive an attestation of course completion worth 31 CPD credits. If you took the course with a PECB partner and do not pass on the first attempt, you can retake the exam at no extra cost within twelve months of receiving the coupon code.