Study. uk . com
  1. Home
  2. All questions
  3. Question 120

CISSP study material · question 120 of 500

A consultancy proposes replacing a client's existing risk methodology with the CSF Tiers, presenting them as a maturity model to be climbed. What is wrong with this proposal?

  1. Tiers are meant to complement an existing risk methodology, not replace it.
  2. Tiers may only be used with a Community Profile, never an Organizational one.
  3. Tiers describe technical controls and so cannot substitute for a methodology.
  4. Tiers apply only to critical infrastructure operators.
Show the answer

Answer: A. Tiers are meant to complement an existing risk methodology, not replace it.

CSF 2.0 states Tiers should complement an organisation's cybersecurity risk management methodology rather than replace it; they characterise rigour and set the tone for managing risk.

Source: NIST CSWP 29 (NIST) — NIST CSWP 29 > 3.2 CSF Tiers

Challenge yourself on this topic → Study as cards