What characterizes a Tier 1 (Partial) organization?
A.The organization has optimized cybersecurity practices
B.The organization has repeatable processes across all business units
C.The organization's cybersecurity risk management practices are not formalized and risk is managed in an ad hoc and sometimes reactive manner
D.The organization adapts its practices based on predictive indicators
Why C is correct
Tier 1 (Partial) organizations have not formalized their cybersecurity risk management practices. Risk management is ad hoc, reactive, and often limited to awareness of cybersecurity risk at the organizational level.
Know someone studying for NIST CSF? Send them this one.
Where this fits in the NIST CSF exam
Framework Implementation
Implementing the NIST CSF: Implementation Tiers, current/target Profiles, and integration with risk management.
This question belongs to the "Identify" domain, which makes up about 20% of the NIST CSF exam.
CyberCertPrep gives you 20 free NIST CSF questions per day with this same answer-and-explanation depth, plus timed exam simulations and progress tracking. No card required.
NIST CSF and NIST are trademarks or registered trademarks of their respective owners. CyberCertPrep is an independent exam-preparation resource and is not affiliated with, authorized by, sponsored by, or endorsed by NIST or any other certification body. All study material is independently created; the certification name is used only to identify the exam this resource helps you prepare for.
Are organizations required to achieve Tier 4 (Adaptive) to be considered compliant with the NIST CSF?