ExamGecko
Question list
Search
Search

Question 95 - CISM discussion

Report
Export

A post-incident review identified that user error resulted in a major breach. Which of the following is MOST important to determine during the review?

A.
The time and location that the breach occurred
Answers
A.
The time and location that the breach occurred
B.
Evidence of previous incidents caused by the user
Answers
B.
Evidence of previous incidents caused by the user
C.
The underlying reason for the user error
Answers
C.
The underlying reason for the user error
D.
Appropriate disciplinary procedures for user error
Answers
D.
Appropriate disciplinary procedures for user error
Suggested answer: C

Explanation:

The underlying reason for the user error is the most important factor to determine during the post-incident review, as this helps the information security manager to understand the root cause of the breach, and to implement corrective and preventive actions to avoid similar incidents in the future. The underlying reason for the user error may be related to the lack of training, awareness, guidance, or motivation of the user, or to the complexity, usability, or design of the system or process that the user was using. By identifying the underlying reason for the user error, the information security manager can address the human factor of the information security program, and improve the security culture and behavior of the organization.The time and location that the breach occurred, evidence of previous incidents caused by the user, and appropriate disciplinary procedures for user error are not the most important factors to determine during the post-incident review, as they do not provide a comprehensive and holistic understanding of the breach, and may not help to prevent or reduce the likelihood or impact of future incidents.Reference= CISM Review Manual 2023, page 1671; CISM Review Questions, Answers & Explanations Manual 2023, page 382; ISACA CISM - iSecPrep, page 233

asked 01/10/2024
Mikael Klingebrant
30 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first