
NIST Cybersecurity Professional®
(NCSP®) 800‑39 Foundation Certificate
Learn how to apply NIST SP 800‑39 risk management principles for enterprise-wide information security risk management.

NIST Cybersecurity Professional®
(NCSP®) 800‑39 Foundation Certificate
Course Description
Effective cybersecurity requires organisations to understand, assess, and manage risk across missions, business processes, and information systems. NIST SP 800‑39 provides the overarching guidance for risk management at the organisational, mission, and system levels, forming the strategic foundation for all NIST‑aligned cybersecurity programs.
The NCSP® 800‑39 Foundation Certificate is a 2‑day, instructor‑led course introducing participants to the principles and practices of enterprise risk management as defined in NIST SP 800‑39. This course explains how to establish risk frameworks, apply risk models, integrate risk decisions into organisational governance, and align risk management activities with the NIST Cybersecurity Framework (CSF 2.0).
Participants learn how to apply foundational risk management concepts across organisational structures, missions, and systems, preparing them for more advanced NCSP® risk, governance, and CSF‑aligned training.
What You Will Learn
Participants gain foundational knowledge principles and practices of enterprise risk management. You will learn:
-
How NIST SP 800‑39 aligns with NIST CSF 2.0 and supports enterprise risk governance.
-
The three‑tiered risk management approach: organisation, mission/business process, and information system.
-
How to establish risk frameworks, strategies, and governance structures.
-
How to identify, assess, respond to, and monitor cybersecurity risk.
-
The role of risk tolerance, risk appetite, and risk communication.
-
How to integrate risk management activities across organisational functions.
Course Agenda
Day 1: Risk Foundations, Governance & Organisational Strategy
Module 1: Introduction to NIST SP 800‑39
Module 2: Core Risk Management Concepts
Module 3: Governance, Risk Strategy & Organisational Roles
Module 4: Tier 1 Risk Activities: Organisation‑Level Risk
Day 2: Mission, System Risk & Continuous Monitoring
Module 5: Tier 2 Risk Activities: Mission & Business Processes
Module 6: Tier 3 Risk Activities: Information Systems
Module 7: Risk Response, Monitoring & Communication
Module 8: Continuous Improvement & Alignment with NIST CSF 2.0
Learning Outcomes
Participants will be able to:
-
Explain how NIST SP 800‑39 supports NIST CSF 2.0 and enterprise risk governance.
-
Describe the three‑tiered risk management approach.
-
Identify organisational, mission, and system‑level risks.
-
Apply foundational risk assessment and response practices.
-
Understand risk tolerance, appetite, and communication.
-
Translate NIST SP 800‑39 guidance into actionable organisational risk practices.
Who Should Attend?
Ideal for individuals responsible for supporting risk management and information security programmes including:
-
IT & Cybersecurity Staff
-
Risk Managers & Governance Personnel
-
Business Leaders & Process Owners
-
Compliance & Audit Teams
-
Cybersecurity Beginners & Career‑Changers
-
Anyone supporting NIST‑aligned risk management activities
Prerequisites
There are no formal prerequisites for this Foundation‑level course. It is designed as an accessible entry point into NIST‑aligned cybersecurity training.
Participants are provided with:
-
NIST Cybersecurity Professional® (NCSP®) 800‑39 Foundation Certificate courseware including links to further reading and resources.
-
NIST Cybersecurity Professional® (NCSP®) 800‑39 Foundation Certificate, Certificate of Completion.
-
NIST Cybersecurity Professional® (NCSP®) 800‑39 Foundation Certificate digital badge.
Enrol Today
Learn how to apply NIST SP 800‑39 risk management principles to strengthen organisational cybersecurity governance.
