ExamGecko
Question list
Search
Search

Related questions

Question 133 - CISA discussion

Report
Export

A new regulation requires organizations to report significant security incidents to the regulator within 24 hours of identification. Which of the following is the IS auditor's BEST recommendation to facilitate compliance with the regulation?

A.
Include the requirement in the incident management response plan.
Answers
A.
Include the requirement in the incident management response plan.
B.
Establish key performance indicators (KPIs) for timely identification of security incidents.
Answers
B.
Establish key performance indicators (KPIs) for timely identification of security incidents.
C.
Enhance the alert functionality of the intrusion detection system (IDS).
Answers
C.
Enhance the alert functionality of the intrusion detection system (IDS).
D.
Engage an external security incident response expert for incident handling.
Answers
D.
Engage an external security incident response expert for incident handling.
Suggested answer: A

Explanation:

The best recommendation to facilitate compliance with the regulation that requires organizations to report significant security incidents to the regulator within 24 hours of identification is to include the requirement in the incident management response plan. An incident management response plan is a document that defines the roles, responsibilities, procedures, and tools for managing security incidents effectively and efficiently. Including the requirement in the incident management response plan can help ensure that security incidents are identified, classified, reported, and escalated in accordance with the regulation. The other options are not as effective as including the requirement in the incident management response plan, as they do not address all aspects of incident management or compliance. Establishing key performance indicators (KPIs) for timely identification of security incidents is a monitoring technique that can help measure and improve the performance of incident management processes, but it does not ensure compliance with the regulation. Enhancing the alert functionality of the intrusion detection system (IDS) is a technical control that can help detect and notify security incidents faster, but it does not ensure compliance with the regulation. Engaging an external security incident response expert for incident handling is a contingency measure that can help augment the organization's internal capabilities and resources for managing security incidents, but it does not ensure compliance with the regulation.Reference:CISA Review Manual (Digital Version), Chapter 4, Section 4.2.2

asked 18/09/2024
Andrew ROUSE
45 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first