Study. uk . com
  1. Home
  2. All questions
  3. Question 15

CISM study material · question 15 of 1000

At which CSF Tier would you expect executives to weigh cybersecurity risk alongside financial risk, with the organisational budget itself shaped by the predicted risk environment and risk tolerance?

  1. Tier 2, Risk Informed
  2. Tier 3, Repeatable
  3. Tier 4, Adaptive
  4. Tier 1, Partial
Show the answer

Answer: C. Tier 4, Adaptive

At Tier 4 the relationship between cybersecurity risk and objectives is clearly understood, executives monitor cyber risk in the same context as financial risk, and the budget reflects predicted risk and tolerance.

Source: NIST CSWP 29 (NIST) — Appendix B CSF Tiers

Challenge yourself on this topic → Study as cards