ExamGecko
Question list
Search
Search

Question 9 - CISM discussion

Report
Export

Which of the following is MOST important to include in an incident response plan to ensure incidents are responded to by the appropriate individuals?

A.
Skills required for the incident response team
Answers
A.
Skills required for the incident response team
B.
A list of external resources to assist with incidents
Answers
B.
A list of external resources to assist with incidents
C.
Service level agreements (SLAs)
Answers
C.
Service level agreements (SLAs)
D.
A detailed incident notification process
Answers
D.
A detailed incident notification process
Suggested answer: D

Explanation:

A detailed incident notification process is most important to include in an incident response plan to ensure incidents are responded to by the appropriate individuals. The incident notification process defines the roles and responsibilities of the incident response team members, the escalation procedures, the communication channels, the reporting requirements, and the stakeholders to be informed. The incident notification process helps to ensure that the right people are involved in the incident response, that the incident is handled in a timely and efficient manner, and that the relevant information is shared with the appropriate parties. Skills required for the incident response team, a list of external resources to assist with incidents, and service level agreements (SLAs) are also important elements of an incident response plan, but they are not as critical as the incident notification process. Skills required for the incident response team describe the competencies and qualifications of the team members, but they do not specify who should be notified or involved in the incident response. A list of external resources to assist with incidents provides a directory of external parties that can provide support or expertise in the incident response, but it does not define the criteria or process for engaging them.Service level agreements (SLAs) define the expectations and obligations of the service providers and the service recipients in the incident response, but they do not detail the steps or procedures for notifying or escalating incidents.Reference= CISM Review Manual, 16th Edition, pages 191-1921; CISM Review Questions, Answers & Explanations Manual, 10th Edition, page 662

asked 01/10/2024
Mike Werts
32 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first