What is Risk Management Framework NIST 800 37

preview_player
Показать описание
Free cybersecurity downloads, Up to 60% discounts on courses (limited time):

Risk Management is being aware of and taking actions to prepare for probable unfavorable outcomes.

Risk Management Framework is a process the implement risk management in an organization.

There are (6) steps to the RMF:
1. Categorize
2. Select
3. Implement
4. Assess
5. Authorize
6. Continuous Monitoring

More on the Risk Management Framework Steps here:
Рекомендации по теме
Комментарии
Автор

I just started an information security course and have been so lost this first week... this helps so much! thank you

JustCallMeFluffy
Автор

Hi Bruce what a coincidence, my wife and I was watching some of your videos regarding fiance visa and green card process. It was very helpful for us. I just got job in RMF and I am new to this field. I am trying to have more knowledge about this. I find your videos are very useful. Thanks you Bruce.

seekknowledge
Автор

Excellent illustration of a risk framework, thanks a bunch bruv

brownoforrington
Автор

Bruce, you are the man, thank you so much for making this great video and breaking down RMF.

alexrichmond
Автор

Good job of providing a good summary in a short amount of time.

natb
Автор

Well spoken and very professional. Good work!

juliodelcid
Автор

Great job, providing short overview of risk management framework. Its understanding and simple to understand. The only challenges I have is with the scenarios you asserted. Example A and B as queried by rfranco below.

carlmic
Автор

Excellent and very informative presentation, I learned a lot...thank you for all your help

wdj
Автор

I really appreciate your help in better understanding this topic.

DDGainesJr
Автор

Hello. I have questions but is Bruce available?

garyclark
Автор

I love that explanation totally different from all the récital that others are doing. Thanks so much

wankicho
Автор

Good description, thanks. But why do we not authorize the controls after selecting, why implement and assess first ? Beats me the logic

mejas
Автор

Hello, I have a lot but don;t know how to break into this field. BS in IT, SEc+, AWS CP&dev, Datto MTA server08. knowledge of NIST 800 series and the whole 6 steps of RMF. cant get a job. is it my resume? how do i make it to the phone screen atleast?

JaeVoris
Автор

Hi Bruce really appreciate your help I'm Interviewing For A Position Of Information Systems Officer This Is Some Excellent And Very Informative Presentation

dailyhiphoplive
Автор

Thank you for the visuals. It made learning simple!

weenee
Автор

I have a few questions:

Depending on the function of the Web Server A
Q: If the site is providing a service to the public, shouldn't 'Availability' be HIGH. If there is a method of fault tolerance, arent you assuring high Availability? or at least "Moderate'
Q: Shouldn't 'Integrity' be high as well? The users (public) has to be confident that the site is what is says it is and not a hacked/re-directed site.

Depending on the function of the Web Server B
Q: Shouldn't 'Integrity' be 'High'? You want to be sure that the information is what it is supposed to be and not modified SPECIALLY if the information is 'Classified'.

rfrancoi
Автор

This is bad and wrong on soooo many levels. I don't have time to correct everything. The only thing i will WORDS MEAN SOMETHING! This is why many organizations don't understand the pieces and parts of the framework.

michaelredman