Study. uk . com
  1. Home
  2. All questions
  3. Question 23

CompTIA Security+ study material · question 23 of 611

A consultant reports that the organisation "is at Tier 2" as a single maturity score for its whole security programme. Why is this a misuse of Tiers?

  1. Tiers may only be assigned by an external auditor
  2. Tiers are ranked from 4 down to 1
  3. Tiers apply only to federal agencies
  4. Tiers characterise the rigour of risk governance and management practices, applied to a Profile
Show the answer

Answer: D. Tiers characterise the rigour of risk governance and management practices, applied to a Profile

Tiers describe how risk is governed and managed, applied to a Profile; they are not a single score for a whole programme.

Source: NIST CSWP 29 (NIST) — NIST CSF 2.0 § 3 Profiles and Tiers

Challenge yourself on this topic → Study as cards