ExamGecko
Question list
Search
Search

Related questions

Question 278 - CISA discussion

Report
Export

Which of the following would be of MOST concern for an IS auditor evaluating the design of an organization's incident management processes?

A.
Service management standards are not followed.
Answers
A.
Service management standards are not followed.
B.
Expected time to resolve incidents is not specified.
Answers
B.
Expected time to resolve incidents is not specified.
C.
Metrics are not reported to senior management.
Answers
C.
Metrics are not reported to senior management.
D.
Prioritization criteria are not defined.
Answers
D.
Prioritization criteria are not defined.
Suggested answer: D

Explanation:

he design of an incident management process should include prioritization criteria to ensure that incidents are handled according to their impact and urgency. Without prioritization criteria, the organization may not be able to allocate resources effectively and respond to incidents in a timely manner. Expected time to resolve incidents, service management standards, and metrics reporting are important aspects of incident management, but they are not as critical as prioritization criteria for the design of the process.Reference:ISACA Journal Article: Incident Management: A Practical Approach

asked 18/09/2024
Issam Boumlic
44 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first