- Home
- All questions
- Question 117
CISSP study material · question 117 of 500
An assessor finds risk practices that management has approved but that are not written as organisation-wide policy, and supplier risk that is recognised but never formally acted on. Which CSF Tier does this describe?
Show the answer
Answer: B. Tier 2, Risk Informed.
At Tier 2 practices are approved by management but not established as organisation-wide policy, and supplier risk is understood without consistent or formal response.
Source: NIST CSWP 29 (NIST) — NIST CSWP 29 > Appendix B, CSF Tiers