What distinguishes a Tier 4 (Adaptive) organization from lower tiers?
- A.It has passed all compliance audits
- B.It has the largest cybersecurity budget, because the Framework makes legal counsel, not organizational leadership, accountable for cyber risk strategy
- C.It adapts its cybersecurity practices based on lessons learned and predictive indicators derived from previous and current cybersecurity activities
- D.It uses the most advanced technology available, as the Framework obligates adopters to file their Subcategory selections with NIST for public inspection
Why C is correct
Tier 4 (Adaptive) organizations adapt their cybersecurity practices based on lessons learned and predictive indicators, continuously evolving their approach using real-time information about the threat landscape.
Know someone studying for NIST CSF? Send them this one.