Study. uk . com
  1. Home
  2. All questions
  3. Question 117

CISSP study material · question 117 of 500

An assessor finds risk practices that management has approved but that are not written as organisation-wide policy, and supplier risk that is recognised but never formally acted on. Which CSF Tier does this describe?

  1. Tier 4, Adaptive.
  2. Tier 2, Risk Informed.
  3. Tier 3, Repeatable.
  4. Tier 1, Partial.
Show the answer

Answer: B. Tier 2, Risk Informed.

At Tier 2 practices are approved by management but not established as organisation-wide policy, and supplier risk is understood without consistent or formal response.

Source: NIST CSWP 29 (NIST) — NIST CSWP 29 > Appendix B, CSF Tiers

Challenge yourself on this topic → Study as cards