- Home
- All questions
- Question 118
CISSP study material · question 118 of 500
A supplier assurance lead wants to reach the CSF Tier at which supplier risk is acted on through written agreements, governance bodies and monitoring, with risk practices expressed as formal policy. Which Tier is that?
Show the answer
Answer: B. Tier 3, Repeatable.
Tier 3 has risk practices formally approved as policy, an organisation-wide approach, and supplier risk acted on through mechanisms such as written agreements, risk councils and monitoring.
Source: NIST CSWP 29 (NIST) — NIST CSWP 29 > Appendix B, CSF Tiers