Are organizations required to achieve Tier 4 (Adaptive) to be considered compliant with the NIST CSF?
- A.Tier 4 is automatically achieved after five years of framework implementation
- B.Only critical infrastructure organizations must achieve Tier 4, as the DETECT function owns patch deployment once a vulnerability is confirmed
- C.No, the Tiers are not meant to represent maturity levels and the appropriate tier depends on the organization's risk environment and resources
- D.Yes, all organizations must achieve Tier 4, which presumes that anomaly detection is required to run without baselines, since baselining is treated as bias
Why C is correct
The Tiers are not prescriptive maturity levels. Organizations should select the target tier that best manages their cybersecurity risk given their threat environment, business requirements, and available resources.
Know someone studying for NIST CSF? Send them this one.