1844063576
NIST that every CISO should meet

Advertise on podcast: NIST that every CISO should meet

Rating
★★★★★
5
from
1 reviews
This podcast has
7 episodes
Language
English
Publisher
Niso the CISO
Explicit
No
Date created
2025/10/04
Latest episode
2025/10/03
Average duration
-
Release period
0 days

Description

"NIST that every CISO should meet" The overarching theme is the application of NIST guidance through a risk management lens, moving from high-level strategy (RMF framing and preparation) to operational execution (controls, continuous monitoring, and incident handling). These NIST Special Publications establish comprehensive guidelines for Federal information systems concerning security and risk management. Specifically, NIST SP 800-37r2 focuses on the process of allocating security and privacy requirements, while NIST SP 800-53r4 details the actual security and privacy controls for federal systems, including categorization (low, moderate, high impact) and the tailoring process to create specialized control baselines and overlays. NIST SP 800-137 introduces the importance of Information Security Continuous Monitoring (ISCM) to maintain awareness of security posture and support ongoing risk decisions, often through automation and defined metrics. Finally, NIST SP 800-30r1 provides a guide for conducting risk assessments across three organizational tiers—organizational, mission/business process, and information system—to identify threats, vulnerabilities, and the resulting risk. NIST SP 800-61r2 complements these by outlining the necessary phases and coordination for computer security incident handling. Enjoy!

Unlock NIST that every CISO should meet podcast Email contact info,
Listeners & Audience details

Email contact information

Direct podcast contact details

Listeners

Audience numbers & engagement insights

Audience details

Podcast Insights

Podcast episodes

Check latest episodes from NIST that every CISO should meet podcast


Episode 6: Sustaining Compliance – Information Security Continuous Monitoring (NIST SP 800-137)
2025/10/03
This is Episode 6 of your podcast, "NIST that every CISO should meet." We have successfully covered the full Risk Management Framework (RMF) cycle from preparation through the formal authorization decision (Authorization to Operate, or ATO). Once the ATO is granted, the organization enters the most crucial phase for long-term security posture: continuous monitoring. This episode focuses entirely on RMF Step 7: Monitor and the methodology for Information Security Continuous Monitoring (ISCM), ensuring that the organization sustains compliance and manages risk proactively.
Episode 3: Navigating the RMF, Part 1 – Preparation and Categorization (NIST SP 800-37)
2025/10/03
This is Episode 3 of your podcast, "NIST that every CISO should meet," which transitions from pure risk assessment methodology (Episode 2) into the structured, life cycle approach mandated by NIST for risk management: the Risk Management Framework (RMF). This episode will focus on the first two, foundational steps of the RMF outlined in NIST Special Publication 800-37, Revision 2: Prepare and Categorize.
Episode 4: Navigating the RMF, Part 2 – Control Selection, Implementation, Assessment, and Authorization
2025/10/03
Welcome back to "NIST that every CISO should meet." In Episode 3, we covered the foundational RMF steps: Prepare (defining strategy and risk tolerance) and Categorize (setting the High Water Mark based on Confidentiality, Integrity, and Availability). This categorization is absolutely crucial, as it dictates the starting point for security: the control baseline. Episode 4 transitions from planning into action, focusing on selecting, implementing, and assessing the security controls, culminating in the formal accountability step: Authorization.
Episode 2: The Cornerstone – Understanding and Assessing Risk (NIST SP 800-30)
2025/10/03
This is the perfect transition for your podcast series, moving from the foundational discussion of Risk Management (Episode 1) to the critical process that underpins all security decisions: Risk Assessment. As outlined in the proposed structure, your second episode will focus entirely on NIST Special Publication 800-30, Guide for Conducting Risk Assessments. Here is a comprehensive outline and talking points for Episode 2: The Cornerstone – Understanding and Assessing Risk.
Episode 1: Laying the Foundation – The Risk Management Imperative
2025/10/03
That is an excellent starting point for your podcast series, "NIST that every CISO should meet". The podcast structure we previously outlined provides a clear roadmap for developing your first episode, focusing on the foundational concepts of risk management essential for a Chief Information Security Officer (CISO) audience.
Episode 5: The Control Ecosystem – Deep Dive into Controls (NIST SP 800-53)
2025/10/03
This is Episode 5 of your podcast, "NIST that every CISO should meet." Having authorized the system in the previous episode, this episode focuses on the practical content that operationalizes the RMF: the individual security and privacy controls found in NIST Special Publication 800-53, Revision 4. We move beyond the theoretical framework and dive into the specific actions CISOs must demand of their teams to achieve and maintain compliance and risk reduction.
Episode 7: When Things Go Wrong – Incident Handling and Response (NIST SP 800-61)
2025/10/03
This is the seventh and final episode of "NIST that every CISO should meet." We have successfully covered the entire spectrum of security governance, starting with Risk Framing (Episode 1), moving through Risk Assessment (Episode 2) and the Risk Management Framework (RMF) steps (Episodes 3, 4, and 6), and reviewing the Control Catalog (Episode 5). The final, essential topic addresses what happens when preventative and continuous monitoring controls inevitably fail: Incident Handling and Response, primarily guided by NIST Special Publication 800-61, Computer Security Incident Handling Guide.

Podcast reviews

Read NIST that every CISO should meet podcast reviews


5 out of 5
1 reviews

Podcast sponsorship advertising

Start advertising on NIST that every CISO should meet relevant audience podcasts


What do you want to promote?