ExamGecko
Question list
Search
Search

Question 155 - CISM discussion

Report
Export

Which of the following is an information security manager's MOST important course of action when responding to a major security incident that could disrupt the business?

A.
Follow the escalation process.
Answers
A.
Follow the escalation process.
B.
Identify the indicators of compromise.
Answers
B.
Identify the indicators of compromise.
C.
Notify law enforcement.
Answers
C.
Notify law enforcement.
D.
Contact forensic investigators.
Answers
D.
Contact forensic investigators.
Suggested answer: A

Explanation:

When responding to a major security incident that could disrupt the business, the information security manager's most important course of action is to follow the escalation process. The escalation process is a predefined set of steps and procedures that define who should be notified, when, how, and with what information in the event of a security incident. The escalation process helps to ensure that the appropriate stakeholders, such as senior management, business units, legal counsel, public relations, and external parties, are informed and involved in the incident response process. The escalation process also helps to coordinate the actions and decisions of the incident response team and the business continuity team, and to align the incident response objectives with the business priorities and goals. The escalation process should be documented and communicated as part of the incident response plan, and should be reviewed and updated regularly to reflect the changes in the organization's structure, roles, and responsibilities.

Reference=

CISM Review Manual 15th Edition, page 1631

CISM 2020: Incident Management and Response, video 32

Incident Response Models3

asked 01/10/2024
Ibrahim Isaaq
31 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first