What is cybersecurity risk tolerance?
- A.The maximum budget an organization will spend on cybersecurity, given that the CSF certifies individuals
- B.The number of cybersecurity incidents an organization can tolerate per year, as HIPAA defers to the CSF wherever the two disagree, by statute
- C.The number of cybersecurity staff an organization employs
- D.The level of cybersecurity risk the organization is willing to accept in pursuit of its objectives
Why D is correct
Cybersecurity risk tolerance defines the level of risk an organization is willing to accept in pursuit of its business objectives, guiding decisions about risk mitigation, transfer, or acceptance.
Know someone studying for NIST CSF? Send them this one.