CMM7XX

NIST Cyber Security Framework

Session 10: Risk Assessment

Learning Objectives

  • Differentiate Quantitative vs Qualitative Risk Assessment methodologies.
  • Apply the FAIR (Factor Analysis of Information Risk) framework mathematically.
  • Deconstruct the five core functions of the NIST Cybersecurity Framework (CSF).
  • Evaluate NIST Implementation Tiers and organizational maturity.
  • Design target NIST Profiles to align cyber defense with business objectives.

Task 1: Quantitative Risk Modeling

Timing: 45 minutes

A hospital database (AV = £10M due to regulatory fines and lost trust) faces a ransomware threat. If successful, the EF is estimated at 40%. Threat Intel estimates an ARO of 0.25 (once every 4 years).

  1. Calculate the SLE and the ALE for the current state.
  2. A vendor proposes an immutable backup solution costing £200,000/year. This solution does not stop the attack (ARO remains 0.25), but reduces the EF to 2%.
  3. Calculate the new SLE and ALE.
  4. Calculate the ROI: Does the reduction in ALE justify the £200,000 annual cost? Present your finding as a Board-level summary.
Practical Resource: MITRE ATT&CK Framework

15 Minute Break

Please return promptly for Part 2.

Part 2: The NIST Framework

Duration: 1.5 Hours

NIST Cybersecurity Framework (CSF)

A voluntary framework developed by the US government to help organizations manage cyber risk. It provides a common language for executives and engineers.

The CSF Core consists of five concurrent functions:

  • Identify (ID): Develop organizational understanding of assets and risks (Asset Management, Risk Assessment).
  • Protect (PR): Develop safeguards to ensure delivery of services (Access Control, Encryption, Training).

NIST CSF Core (Continued)

  • Detect (DE): Identify the occurrence of a cybersecurity event (Continuous Monitoring, Anomalies).
  • Respond (RS): Take action regarding a detected incident (Response Planning, Containment, Mitigation).
  • Recover (RC): Maintain plans for resilience and restore impaired capabilities (Recovery Planning, Communications).
Most organizations over-invest in Protect and heavily under-invest in Detect and Respond.

Implementation Tiers

Measure the organization's approach to cybersecurity risk management.

  • Tier 1 (Partial): Reactive. Ad hoc processes. No formalized risk management.
  • Tier 2 (Risk Informed): Management approves risk decisions, but processes are not organizational-wide policies.
  • Tier 3 (Repeatable): Formal policies in place. Risk management is treated as a corporate-wide requirement.
  • Tier 4 (Adaptive): Proactive. Continuous improvement based on predictive indicators and advanced threat hunting.
Practical Resource: MITRE ATT&CK Framework

Introduction to Task 2

A NIST "Profile" is the alignment of the CSF Core to a specific business scenario. You create a "Current Profile" and a "Target Profile" to identify gaps.

We will act as consultants developing a Target Profile for a recently breached organization.

Task 2: NIST Profile Development

Timing: 50 minutes

A regional healthcare provider (Tier 1) suffered a catastrophic ransomware attack because they lacked asset visibility and had no offline backups. They wish to reach Tier 3 within 18 months.

  1. Focusing only on the Identify and Recover functions, draft a Target Profile summarizing the specific outcomes they must achieve.
  2. Map at least two specific technical controls (e.g., automated network discovery, tape backups) to your stated outcomes.
  3. Formulate a high-level 18-month roadmap to bridge the gap between their Current (Tier 1) and Target (Tier 3) profiles.

Summary & Next Steps

  • Cybersecurity is fundamentally a risk management discipline. Technical controls exist solely to mitigate quantified business risks.
  • Frameworks like NIST provide the structure to communicate complex technical posture to non-technical boards.
Next Week: Security Policy (Formation and Enforcement)