Study. uk . com
  1. Home
  2. All questions
  3. Question 119

CISSP study material · question 119 of 500

Which two characteristics does CSF 2.0 associate with Tier 4, Adaptive, rather than with Tier 3? Choose two.

  1. Personnel possess the knowledge and skills to perform their assigned roles.
  2. Risk management practices are formally approved and expressed as policy.
  3. The security budget is built from an understanding of the current and predicted risk environment.
  4. Executives consider cyber risk in the same frame as financial and other organisational risk.
Show the answer

Answer: D. Executives consider cyber risk in the same frame as financial and other organisational risk.
C. The security budget is built from an understanding of the current and predicted risk environment.

Budgeting from the predicted risk environment and weighing cyber risk beside financial risk are Tier 4 traits. Formal policy and role competence already appear at Tier 3.

Source: NIST CSWP 29 (NIST) — NIST CSWP 29 > Appendix B, CSF Tiers

Challenge yourself on this topic → Study as cards