Study. uk . com
  1. Home
  2. All questions
  3. Question 118

CISSP study material · question 118 of 500

A supplier assurance lead wants to reach the CSF Tier at which supplier risk is acted on through written agreements, governance bodies and monitoring, with risk practices expressed as formal policy. Which Tier is that?

  1. Tier 1, Partial.
  2. Tier 3, Repeatable.
  3. Tier 4, Adaptive.
  4. Tier 2, Risk Informed.
Show the answer

Answer: B. Tier 3, Repeatable.

Tier 3 has risk practices formally approved as policy, an organisation-wide approach, and supplier risk acted on through mechanisms such as written agreements, risk councils and monitoring.

Source: NIST CSWP 29 (NIST) — NIST CSWP 29 > Appendix B, CSF Tiers

Challenge yourself on this topic → Study as cards