- Home
- All questions
- Question 23
CompTIA Security+ study material · question 23 of 611
A consultant reports that the organisation "is at Tier 2" as a single maturity score for its whole security programme. Why is this a misuse of Tiers?
Show the answer
Answer: D. Tiers characterise the rigour of risk governance and management practices, applied to a Profile
Tiers describe how risk is governed and managed, applied to a Profile; they are not a single score for a whole programme.
Source: NIST CSWP 29 (NIST) — NIST CSF 2.0 § 3 Profiles and Tiers