- CSF Implementation Tiers characterize the rigor of organizational cybersecurity risk governance and management; they are not supplier risk categories.
References and citations
- Sections 3.1 and 3.5 support inventory, strategic grouping, risk-based acquisition treatment, life-cycle monitoring, and reevaluation after changes in risk conditions.