Study. uk . com
  1. Home
  2. All questions
  3. Question 13

CISM study material · question 13 of 1000

A consultant tells the board the organisation should aim for CSF Tier 4 because higher tiers are always better. How should the security manager correct this?

  1. Tiers are set by the regulator, not chosen by the organisation
  2. Tiers are mandatory and every organisation must reach Tier 4 within three years
  3. Tiers describe the rigour of risk governance, and moving up is advised only when risk, mandates or a cost-benefit case justify it
  4. Tiers apply only to the Govern function, so the advice is out of scope
Show the answer

Answer: C. Tiers describe the rigour of risk governance, and moving up is advised only when risk, mandates or a cost-benefit case justify it

CSF Tiers characterise how rigorous risk governance and management practices are, not a maturity score to be maximised. Progression is encouraged when risk, mandates or cost-benefit analysis support it.

Source: NIST CSWP 29 (NIST) — Sec. 3.2 CSF Tiers

Challenge yourself on this topic → Study as cards