Problem 1: How have NIST's CSF become the dominant framework for information security programs inside public and private organizations? What makes the CSF more valuable than other frameworks like COBIT, CRR, or COSO ERM framework? What are ways to influence management to adopt and implement the NIST CSF?
Problem 2: Describe what inputs into decision making are needed to determine an initial implementation tier for NIST CSF adoption? Describe ways of collecting the data for all the inputs you need for the decision?