NIST SP 800-160 Vol. 2 — Cyber Resiliency Engineering Training by Tonex

NIST SP 800-160 Vol. 2 — Cyber Resiliency Engineering Training by Tonex provides professionals with a structured understanding of cyber resiliency concepts, engineering practices, objectives, techniques, and design considerations for systems operating in contested environments. Participants explore how resiliency principles can be integrated across system life cycles to anticipate, withstand, recover from, and adapt to adverse cyber conditions.
Cybersecurity is strengthened when systems are engineered to continue critical functions despite successful attacks or compromises. Cyber resiliency reduces mission and business disruption by combining security engineering, risk-informed design, operational continuity, and recovery considerations. The course emphasizes resilient architectures, system dependencies, threat-informed decisions, and protection of critical mission capabilities.
Learning Objectives
Upon completion of this course, participants will be able to:
- Explain the purpose, structure, terminology, and engineering principles presented in NIST SP 800-160 Vol. 2.
- Describe cyber resiliency objectives, goals, techniques, approaches, and their relationships to system engineering activities.
- Identify mission-critical functions, assets, dependencies, and potential sources of cyber-related disruption.
- Apply cyber resiliency concepts across system architecture, design, development, operation, maintenance, and evolution.
- Evaluate system characteristics that support anticipation, resistance, recovery, and adaptation following adverse cyber events.
- Integrate cybersecurity considerations with resiliency engineering to reduce mission impacts from advanced cyber threats.
- Analyze architectural and operational tradeoffs when selecting cyber resiliency techniques and implementation approaches.
- Develop resiliency-focused engineering information that supports risk management, system assurance, and technical decision-making.
- Use a practical training approach that includes exercises, real-world case studies, and examples of processes and documentation used in cyber resiliency engineering projects.
Audience
This course is designed for:
- Systems Engineers
- Security Engineers
- Cybersecurity Professionals
- Cyber Resiliency Engineers
- Systems Security Engineers
- Security Architects
- Enterprise Architects
- Risk Management Professionals
- Information Security Professionals
- Systems Acquisition Professionals
- Program and Project Managers
- Mission Assurance Professionals
- Defense and Government Technical Personnel
- Critical Infrastructure Professionals
Course Modules
Module 1: Cyber Resiliency Engineering Foundations
- Purpose and scope of NIST SP 800-160 Vol. 2
- Cyber resiliency terminology and foundational concepts
- Relationship between security, resilience, and mission assurance
- Cyber resiliency within systems security engineering
- Adversity, disruption, compromise, and operational consequences
- Role of engineering in maintaining mission capabilities
Module 2: Cyber Resiliency Goals and Objectives
- Understanding cyber resiliency goals and their engineering purpose
- Anticipating threats, disruptions, and adverse cyber conditions
- Withstanding attacks while maintaining essential system functions
- Recovering system capabilities following cyber-related degradation
- Adapting systems to changing threats and operational conditions
- Connecting resiliency objectives with mission and business priorities
Module 3: Cyber Resiliency Techniques and Approaches
- Applying architectural diversity to reduce common vulnerabilities
- Using redundancy to preserve essential system capabilities
- Segmentation and isolation of critical system resources
- Deception techniques for complicating adversary activities
- Dynamic positioning and reconfiguration of system resources
- Coordinating resiliency techniques across technical and operational environments
Module 4: Resilient System Architecture and Design
- Identifying critical functions, services, assets, and dependencies
- Developing architectural strategies for cyber-resilient systems
- Designing for controlled degradation and continued operation
- Incorporating protection, detection, response, and recovery mechanisms
- Evaluating system interfaces and dependency-related resilience risks
- Balancing performance, security, resilience, cost, and operational requirements
Module 5: Cyber Resiliency Lifecycle Integration
- Incorporating cyber resiliency into system lifecycle processes
- Establishing resiliency needs during requirements development
- Translating mission needs into engineering requirements
- Integrating resiliency considerations during architecture and design
- Maintaining resiliency through operation, sustainment, and system changes
- Documenting cyber resiliency assumptions, decisions, evidence, and dependencies
Module 6: Assessment and Resiliency Improvement
- Evaluating cyber resiliency capabilities against defined objectives
- Identifying weaknesses affecting mission-essential system functions
- Assessing consequences of compromise and operational disruption
- Reviewing architectural and operational resiliency effectiveness
- Prioritizing improvements using risk and mission impact information
- Applying lessons learned to strengthen future engineering decisions
Practical Training Approach
The course uses a practical training approach that includes exercises, real-world case studies, and examples of processes and documentation used in cyber resiliency engineering projects. Participants examine how organizations translate cyber resiliency goals into system requirements, architecture decisions, engineering activities, assessment criteria, and supporting documentation.
Exercises reinforce the identification of critical system functions, dependencies, potential disruption paths, and appropriate resiliency techniques. Real-world case studies demonstrate how engineering teams can address cyber adversity across complex information technology, operational technology, defense, critical infrastructure, and mission-oriented environments.
Participants also review examples of processes and documentation associated with cyber resiliency planning, requirements development, architectural analysis, risk assessment, engineering decisions, lifecycle integration, and continuous improvement. This approach helps connect NIST SP 800-160 Vol. 2 concepts with practical systems engineering and cybersecurity responsibilities.
Strengthen Cyber Resiliency with Tonex
Build the knowledge to engineer systems that can anticipate, withstand, recover from, and adapt to cyber adversity with NIST SP 800-160 Vol. 2 — Cyber Resiliency Engineering Training by Tonex.