GSEC · Question #262
What improvement could a company that is rated at a NIST Implementation Tier of 2: Risk Informed do to Increase their rating to a Tier 3: Repeatable?
The correct answer is C. Formalize organizational risk management processes. Advancing from NIST CSF Tier 2 to Tier 3 requires formalizing risk management into documented, organization-wide repeatable policy.
Question
What improvement could a company that is rated at a NIST Implementation Tier of 2:
Risk Informed do to Increase their rating to a Tier 3: Repeatable?
Options
- AEstablish risk management processes as organization-wide policy
- BIncrease awareness of cybersecurity risk at the organizational level
- CFormalize organizational risk management processes
- DFocus on internal participation in security programs and risk management
How the community answered
(27 responses)- A4% (1)
- B11% (3)
- C78% (21)
- D7% (2)
Why each option
Advancing from NIST CSF Tier 2 to Tier 3 requires formalizing risk management into documented, organization-wide repeatable policy.
Establishing org-wide policy overlaps with Tier 3 traits but does not capture the 'formalize' requirement - Tier 3 specifically requires that practices be formally approved and documented, not merely adopted.
Increasing cybersecurity risk awareness is associated with the transition from Tier 1 (Partial) to Tier 2 (Risk Informed), not from Tier 2 to Tier 3.
Tier 3 (Repeatable) is defined by risk management practices that are formally approved by management and expressed as enforceable organizational policy, applied consistently across the enterprise. Tier 2 organizations have risk-informed practices but they are not yet standardized or policy-driven. Formalizing those processes into documented, repeatable policy is the precise criterion that distinguishes Tier 3 from Tier 2 in the NIST CSF.
Internal participation in security and risk programs describes a Tier 2 characteristic, not the advancement step needed to reach Tier 3.
Concept tested: NIST CSF Implementation Tier 2 to Tier 3 advancement criteria
Source: https://www.nist.gov/cyberframework/framework
Topics
Community Discussion
No community discussion yet for this question.