- Home
- All questions
- Question 15
CISM study material · question 15 of 1000
At which CSF Tier would you expect executives to weigh cybersecurity risk alongside financial risk, with the organisational budget itself shaped by the predicted risk environment and risk tolerance?
Show the answer
Answer: C. Tier 4, Adaptive
At Tier 4 the relationship between cybersecurity risk and objectives is clearly understood, executives monitor cyber risk in the same context as financial risk, and the budget reflects predicted risk and tolerance.
Source: NIST CSWP 29 (NIST) — Appendix B CSF Tiers