ExamGecko
Question list
Search
Search

Question 64 - CISM discussion

Report
Export

When investigating an information security incident, details of the incident should be shared:

A.
widely to demonstrate positive intent.
Answers
A.
widely to demonstrate positive intent.
B.
only with management.
Answers
B.
only with management.
C.
only as needed,
Answers
C.
only as needed,
D.
only with internal audit.
Answers
D.
only with internal audit.
Suggested answer: C

Explanation:

When investigating an information security incident, details of the incident should be shared only as needed, according to the principle of least privilege and the need-to-know basis. This means that only the authorized and relevant parties who have a legitimate purpose and role in the incident response process should have access to the incident information, and only to the extent that is necessary for them to perform their duties. Sharing incident details only as needed helps to protect the confidentiality, integrity, and availability of the incident information, as well as the privacy and reputation of the affected individuals and the organization. Sharing incident details only as needed also helps to prevent unauthorized disclosure, modification, deletion, or misuse of the incident information, which could compromise the investigation, evidence, remediation, or legal actions.

Reference= CISM Review Manual, 16th Edition, Chapter 4: Information Security Incident Management, Section: Incident Response Process, page 2311; CISM Review Questions, Answers & Explanations Manual, 10th Edition, Question 49, page 462.

asked 01/10/2024
Fabio Valenti
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first