NIST Organizational Risk Management

3 Day Course

SecureInfo Corporation is pleased to offer this 3-day course for those working within the Federal Government or their contractors who must understand, implement, maintain and transition to NIST SP 800-39. NIST SP 800-39, applicable to all federal information systems, is the flagship document in the series of information security standards and guidelines developed by the Joint Task Force (DoD, ODNI, NIST and CNSS) in response to FISMA.

This course consists of lecture and discussion to educate the student on the NIST guidance for an integrated, organization-wide program for managing information security risk to organizational operations (i.e., mission, functions, image, and reputation), organizational assets, individuals, other organizations, and the Nation resulting from the operation and use of federal information systems. The course provides the student with a structured, yet flexible approach for managing risk that is intentionally broad-based, with the specific details of assessing, responding to, and monitoring risk on an ongoing basis, supporting continuous monitoring. See the detailed course topics below.

Cost of Course: $1,500.00 per student (GSA and Volume Rates Available)

Materials Required

Laptops are required as each student will be asked to create documentation and participate in practical hands-on exercises that guide the students learning experience. The laptop must have Adobe Acrobat Reader, Microsoft Excel and Word. NOTE: SecureInfo training locations have appropriately configured computers for each student.

Course Materials Provided

Students will receive a workbook (to include instructional slides) and Resource Kit via CD (includes all supporting materials and exercises).

Instructor Policy

Students should arrive no later than 10 minutes prior to start time on the first day of class. If you have any special requirements that need to be addressed prior to arrival please let us know at the time of registration. Please do not make any travel arrangements prior to 6pm on the last day of training.

Locations

We offer this course in the SecureInfo training classroom (San Antonio, Texas or Alexandria, Virginia locations) or via mobile training at your facility for up to 20 students per course. Contact us at training@secureinfo.com or (210) 403-5600 (ask for training) for more information and pricing on mobile training options.

Who Should Attend?

NIST’s new common foundation for information security/assurance provides the Intelligence Community, Defense, and Civil sectors of the federal government and their supporting contractors, more uniform and consistent ways to manage the risk to operations, assets, individuals, other organizations, and the Nation from the operation and use of information systems. State, local, and tribal governments, as well as private sector organizations that compose the critical infrastructure of the United States, are also highly encouraged by NIST to consider the use of the new guidelines. The NIST RMF Workshop is intended to serve a diverse group of information system and information security/assurance professionals, both in and supporting the federal government including:

  • Individuals with information system development and integration responsibilities.
    (e.g., program managers, information technology product developers, information system developers, systems integrators)
  • Individuals with information system and security management and oversight responsibilities.
    (e.g., authorizing officials, chief information officers, senior agency information security officers, information system managers, information security managers)
  • Individuals with information system and security control assessment and monitoring responsibilities.
    (e.g., system evaluators, assessors/assessment teams, independent verification and validation assessors, auditors, Inspectors General, or information system owners)
  • Individuals with information security implementation and operational responsibilities.
  • (e.g., information system owners, common control providers, information owners/stewards, mission/business owners, information system security engineers/officers)

Course Topics

Module 1: Introduction to Risk Management (RM)

  • Introduction to Organizational-wide Risk Management
  • RM Key players Roles and Responsibilities
  • Fundamentals of Organizational RM
  • RM Process Steps/Tasks Overview

Module 2: RM Fundamentals

  • Tier One – Organization View
    • Governance
    • RM Strategy
    • Investment Strategies
  • Tier Two – Mission/Business Process View
    • Risk Aware Mission/Business Processes
    • Enterprise Architecture
    • Information Security Architecture
  • Tier Three – Information System View

Module 3: The Risk Management Process

  • Introduction/Key Concepts &Terms
  • Framing Risk
  • Assessing Risk
  • Responding to Risk
  • Monitoring Risk

Register Now

Questions about our corporate training may be directed to training@secureinfo.com, or call 888.677.9351.

Ask about our mobile training capability--it saves you money!