- Home
- All questions
- Question 120
CISSP study material · question 120 of 500
A consultancy proposes replacing a client's existing risk methodology with the CSF Tiers, presenting them as a maturity model to be climbed. What is wrong with this proposal?
Show the answer
Answer: A. Tiers are meant to complement an existing risk methodology, not replace it.
CSF 2.0 states Tiers should complement an organisation's cybersecurity risk management methodology rather than replace it; they characterise rigour and set the tone for managing risk.
Source: NIST CSWP 29 (NIST) — NIST CSWP 29 > 3.2 CSF Tiers