nerdexam
GIAC

GSEC · Question #262

What improvement could a company that is rated at a NIST Implementation Tier of 2: Risk Informed do to Increase their rating to a Tier 3: Repeatable?

The correct answer is C. Formalize organizational risk management processes. Advancing from NIST CSF Tier 2 to Tier 3 requires formalizing risk management into documented, organization-wide repeatable policy.

Incident Handling, Risk, and Governance

Question

What improvement could a company that is rated at a NIST Implementation Tier of 2:

Risk Informed do to Increase their rating to a Tier 3: Repeatable?

Options

  • AEstablish risk management processes as organization-wide policy
  • BIncrease awareness of cybersecurity risk at the organizational level
  • CFormalize organizational risk management processes
  • DFocus on internal participation in security programs and risk management

How the community answered

(27 responses)
  • A
    4% (1)
  • B
    11% (3)
  • C
    78% (21)
  • D
    7% (2)

Why each option

Advancing from NIST CSF Tier 2 to Tier 3 requires formalizing risk management into documented, organization-wide repeatable policy.

AEstablish risk management processes as organization-wide policy

Establishing org-wide policy overlaps with Tier 3 traits but does not capture the 'formalize' requirement - Tier 3 specifically requires that practices be formally approved and documented, not merely adopted.

BIncrease awareness of cybersecurity risk at the organizational level

Increasing cybersecurity risk awareness is associated with the transition from Tier 1 (Partial) to Tier 2 (Risk Informed), not from Tier 2 to Tier 3.

CFormalize organizational risk management processesCorrect

Tier 3 (Repeatable) is defined by risk management practices that are formally approved by management and expressed as enforceable organizational policy, applied consistently across the enterprise. Tier 2 organizations have risk-informed practices but they are not yet standardized or policy-driven. Formalizing those processes into documented, repeatable policy is the precise criterion that distinguishes Tier 3 from Tier 2 in the NIST CSF.

DFocus on internal participation in security programs and risk management

Internal participation in security and risk programs describes a Tier 2 characteristic, not the advancement step needed to reach Tier 3.

Concept tested: NIST CSF Implementation Tier 2 to Tier 3 advancement criteria

Source: https://www.nist.gov/cyberframework/framework

Topics

#NIST Cybersecurity Framework#risk management tiers#governance#organizational policy

Community Discussion

No community discussion yet for this question.

Full GSEC Practice