Are organizations required to achieve Tier 4 (Adaptive) to be considered compliant with the NIST CSF?
- A.No, the Tiers are not meant to represent maturity levels and the appropriate tier depends on the organization's risk environment and resources
- B.Yes, all organizations must achieve Tier 4
- C.Only critical infrastructure organizations must achieve Tier 4
- D.Tier 4 is automatically achieved after five years of framework implementation
Why A is correct
The Tiers are not prescriptive maturity levels. Organizations should select the target tier that best manages their cybersecurity risk given their threat environment, business requirements, and available resources.
Know someone studying for NIST CSF? Send them this one.