top of page

NIST Cybersecurity Professional®
(NCSP®) 800‑39 Foundation Certificate


Learn how to apply NIST SP 800‑39 risk management principles for enterprise-wide information security risk management.

NIST Cybersecurity Professional (NCSP) 800-39 Foundation Certificate

NIST Cybersecurity Professional®

(NCSP®) 800‑39 Foundation Certificate

Course Description

Effective cybersecurity requires organisations to understand, assess, and manage risk across missions, business processes, and information systems. NIST SP 800‑39 provides the overarching guidance for risk management at the organisational, mission, and system levels, forming the strategic foundation for all NIST‑aligned cybersecurity programs.

The NCSP® 800‑39 Foundation Certificate is a 2‑day, instructor‑led course introducing participants to the principles and practices of enterprise risk management as defined in NIST SP 800‑39. This course explains how to establish risk frameworks, apply risk models, integrate risk decisions into organisational governance, and align risk management activities with the NIST Cybersecurity Framework (CSF 2.0).

Participants learn how to apply foundational risk management concepts across organisational structures, missions, and systems, preparing them for more advanced NCSP® risk, governance, and CSF‑aligned training.

 

What You Will Learn

Participants gain foundational knowledge principles and practices of enterprise risk management. You will learn:

  • How NIST SP 800‑39 aligns with NIST CSF 2.0 and supports enterprise risk governance.

  • The three‑tiered risk management approach: organisation, mission/business process, and information system.

  • How to establish risk frameworks, strategies, and governance structures.

  • How to identify, assess, respond to, and monitor cybersecurity risk.

  • The role of risk tolerance, risk appetite, and risk communication.

  • How to integrate risk management activities across organisational functions.

Course Agenda

Day 1: Risk Foundations, Governance & Organisational Strategy

Module 1: Introduction to NIST SP 800‑39

Module 2: Core Risk Management Concepts

Module 3: Governance, Risk Strategy & Organisational Roles

Module 4: Tier 1 Risk Activities: Organisation‑Level Risk

Day 2: Mission, System Risk & Continuous Monitoring

Module 5: Tier 2 Risk Activities: Mission & Business Processes

Module 6: Tier 3 Risk Activities: Information Systems

Module 7: Risk Response, Monitoring & Communication

Module 8: Continuous Improvement & Alignment with NIST CSF 2.0

Learning Outcomes

Participants will be able to:

  • Explain how NIST SP 800‑39 supports NIST CSF 2.0 and enterprise risk governance.

  • Describe the three‑tiered risk management approach.

  • Identify organisational, mission, and system‑level risks.

  • Apply foundational risk assessment and response practices.

  • Understand risk tolerance, appetite, and communication.

  • Translate NIST SP 800‑39 guidance into actionable organisational risk practices.

Who Should Attend?

Ideal for individuals responsible for supporting risk management and information security programmes including:

  • IT & Cybersecurity Staff

  • Risk Managers & Governance Personnel

  • Business Leaders & Process Owners

  • Compliance & Audit Teams

  • Cybersecurity Beginners & Career‑Changers

  • Anyone supporting NIST‑aligned risk management activities

Prerequisites

There are no formal prerequisites for this Foundation‑level course. It is designed as an accessible entry point into NIST‑aligned cybersecurity training.


Participants are provided with:

  • NIST Cybersecurity Professional® (NCSP®) 800‑39 Foundation Certificate courseware including links to further reading and resources.

  • NIST Cybersecurity Professional® (NCSP®) 800‑39 Foundation Certificate, Certificate of Completion.

  • NIST Cybersecurity Professional® (NCSP®) 800‑39 Foundation Certificate digital badge.

​Enrol Today

​​Learn how to apply NIST SP 800‑39 risk management principles to strengthen organisational cybersecurity governance.

NIST Cybersecurity Professional (NCSP) 800-39 Foundation Certificate
Further Reading

NIST Cybersecurity Professional® 

NCSP®, NIST Cybersecurity Professional® and NIST Cyber Security Professional® are registered trademarks of CySec Professionals Ltd. All frameworks, models, and course materials are proprietary intellectual property protected across the UK, EU, US, Canada, and Australia. The Digital Trust Institute® (DTI®) is a trading name of CySec Professionals Ltd.

NCSP® is a governed, trademarked credential ecosystem aligned to NIST CSF 2.0 and key NIST Special Publications, stewarded by CySec Professionals Ltd and The Digital Trust Institute® (DTI®).

NIST content is republished courtesy of the National Institute of Standards and Technology. CySec Professionals Ltd is an independent organisation and is not affiliated with or endorsed by NIST.

Part of the NCSP® Credential Ecosystem - https://digitaltrust.institute

© 2017 - 2026 CySec Professionals Ltd. All rights reserved.

Terms & Conditions

UK Cyber Security Council Membership
Federation of Small Business Member
Greater Manchester Chamber of Commerce Member
bottom of page