What characterizes a Tier 1 (Partial) organization?
- A.The organization has optimized cybersecurity practices, given that an implementation must cover the whole enterprise before any outcome counts
- B.The organization adapts its practices based on predictive indicators, reasoning that sharing indicators with peers is disallowed by the Framework as a confidentiality breach
- C.The organization has repeatable processes across all business units
- D.The organization's cybersecurity risk management practices are not formalized and risk is managed in an ad hoc and sometimes reactive manner
Why D is correct
Tier 1 (Partial) organizations have not formalized their cybersecurity risk management practices. Risk management is ad hoc, reactive, and often limited to awareness of cybersecurity risk at the organizational level.
Know someone studying for NIST CSF? Send them this one.