
本课程以日本武士铠甲(Yoroi)为隐喻,基于NIST CSF 2.0框架,通过Sakura Systems案例全流程实战,带领学员跳过理论死记硬背,直接操作官方工具深度解构核心功能与分类子项 [theyoroi, Requirements, What you’ll learn]。学员将在十个递进模块中,亲手构建包含当前/目标状态图谱、差距分析、成熟度评估及新增“治理(Govern)”职能在内的企业风险治理资产包 [What you’ll learn, theyoroi]。
课程采用标准与专家双轨模式,通过映射表复用已有控制措施,专注于将底层技术漏洞精准翻译为业务风险语言,助力学员产出可直接应用于实际工作、能够向董事会争取预算的汇报方案 [What you’ll learn]。通过完整学习,学员将掌握如何落地CSF 2.0架构,构建完善的供应链风险管理体系 [What you’ll learn, theyoroi]。
Published 7/2026
Created by David Martinez
MP4 | Video: h264, 1920×1080 | Audio: AAC, 44.1 KHz, 2 Ch
Level: All Levels | Genre: eLearning | Language: English + subtitle | Duration: 43 Lectures ( 3h 37m ) | Size: 1.4 GB
Apply NIST CSF 2.0 in real organizations: build profiles, run gap analyses, govern risk, and brief leadership
What you’ll learn
⚡ Explain the architecture of CSF 2.0: the Core, six Functions, Categories, Subcategories, and Implementation Examples
⚡ Build a Current State Organizational Profile for a real or fictional organization
⚡ Run a structured gap analysis and produce a Target Profile and gap heat map
⚡ Assess Implementation Tier maturity honestly and build a roadmap to advance it
⚡ Apply the Govern function: governance structures, accountability, and supply-chain risk management
⚡ Use CSF 2.0 crosswalks to map existing controls and avoid duplicated effort
⚡ Communicate cybersecurity risk to non-technical and board-level audiences
⚡ Complete a capstone simulation applying the entire framework to one realistic scenario
Requirements
❗ Basic familiarity with IT or cybersecurity concepts (you don’t need to be an expert)
❗ No prior NIST CSF experience required; the course starts from the architecture up
❗ A document, notebook, or notes app for the reflection journal and worksheets
❗ No paid software needed; the course uses the free, online NIST CSF 2.0 Reference Tool
Description
This course contains the use of artificial intelligence. All content has been curated and quality controlled by the instructor.
There’s a difference between someone who knows a framework and someone who can actually use one. Plenty of people can recite the six Functions of the NIST Cybersecurity Framework. Far fewer can sit down with a real organization, scope an assessment, build a Profile, and hand a board a gap analysis they’ll act on. This course is built to make you the second kind of person.
It’s for practitioners. If you need to apply NIST CSF 2.0 inside an actual organization, not describe it on a multiple-choice exam, you’re who this was written for. That includes security analysts and engineers moving into risk and governance work, GRC and compliance staff, IT managers who’ve been handed “do something about our cybersecurity posture,” consultants who need a repeatable method, and people studying the framework who want to come out able to do the work, not just pass a quiz.
What you actually do in this course
Over ten modules you’ll work through CSF 2.0 from the ground up, and at every step you build something. The Core, the six Functions, Organizational Profiles, Implementation Tiers, and the Govern function that version 2.0 introduced are each grounded in a running scenario: a fictional mid-size manufacturer called Sakura Systems, with global supply chain exposure and the kind of messy, real constraints you meet on the job. You’re not memorizing definitions in the abstract. You’re applying them to a company that has budget limits, a nervous board, a recent near-miss, and a new regulatory requirement landing on its desk.
By the end you’ll have a portfolio of deliverables you built with your own hands
✨ A Current State Organizational Profile
✨ A Target Profile and a gap analysis, presented as a heat map
✨ An Implementation Tier assessment and a roadmap to advance it
✨ A governance and supply-chain risk structure built on the Govern function
✨ A board-ready executive summary that translates technical gaps into business risk
✨ A full capstone simulation that ties the whole framework together on a single scenario
These aren’t worksheets you fill in and forget. They’re templates and reasoning you can take back to your own organization on Monday.
How each module is built
Every module follows the same rhythm, so you always know what’s coming
✨ A focused video lesson that explains the concept and shows it applied to Sakura Systems
✨ A hands-on activity with a downloadable worksheet and a model answer, so you get immediate feedback on your work
✨ An optional Expert Mode challenge that takes the same scenario, removes the scaffolding, and adds the ambiguity you face in real engagements
✨ A reflection journal prompt that connects what you just learned to your own organization
A short diagnostic at the start helps you decide whether to begin activities in standard or expert mode, so the course meets you at your level instead of boring you or losing you.
What CSF 2.0 changed, and why it matters to you
The February 2024 release was the framework’s first major update in a decade. It expanded CSF beyond critical infrastructure so it applies to any organization, of any size, in any sector, anywhere in the world. The biggest structural change was a sixth Function:Govern. Governance, risk strategy, roles and accountability, and supply chain risk management moved to the center of the framework instead of sitting on the edges. A lot of older training, and a lot of people who learned CSF 1.1, haven’t caught up to that shift. This course is built around 2.0, with Govern treated as a first-class part of the work, not a footnote.
Why this course is different
Most framework courses stop at explanation. You watch someone narrate the documentation, you take a quiz, and you’re left to figure out the application yourself. Here, explanation is the setup; application is the point. You leave having done the work end to end on a realistic company.
The course also uses a structure you won’t find anywhere else. It’s built around the metaphor of assembling a suit of Japanese samurai armor (theyoroi). Each module you complete earns a piece, from the body armor at the center, out to the limbs, the helmet, and the face guard, until you’ve assembled the full suit by the capstone. It’s a small thing, but it gives the path a shape. You can see how far you’ve come and what’s left, and the pieces map to how the framework fits together (the Core at the center, everything else connecting to it). Learning sticks better when it has a story, and this one does.
What you’ll be able to do when you finish
You’ll be able to scope a CSF assessment and explain what’s in and out. You’ll build a Current Profile that reflects how an organization actually operates, set a defensible Target Profile, and run a gap analysis that survives scrutiny. You’ll assess Implementation Tiers honestly rather than flattering the organization, and build a roadmap that sequences improvements in an order that’s actually achievable. You’ll stand up the governance and supply-chain pieces that 2.0 put front and center. And you’ll be able to walk into a room of non-technical executives and explain cybersecurity risk in language that gets you a decision and a budget.
A note on credibility
The course is taught by a CISSP-certified instructor with a career in cybersecurity, and it’s written to reflect how this work is really done, with the trade-offs, the disagreements, and the judgment calls included rather than sanded off. The Expert Mode tracks exist because real assessments rarely come with clean answers.
If you work in cybersecurity and you need todo something with CSF 2.0, not just talk about it, this is the course for you. Enroll, open your journal, and let’s build the first piece of armor.
Who this course is for
⭐ Security analysts and engineers moving into risk, governance, or GRC work
⭐ GRC, compliance, and audit staff who need to apply CSF in practice
⭐ IT managers and team leads asked to improve their organization’s security posture
⭐ Consultants who want a repeatable method for CSF engagements
⭐ Cybersecurity students and career-changers who want hands-on skills, not just exam recall
⭐ Anyone who learned CSF 1.1 and needs to get current on 2.0 and the Govern function
Password/解压密码www.tbtos.com
转载请注明:0daytown » The NIST CSF 2.0 Practitioner: From Framework to Action