ExamGecko
Question list
Search
Search

Question 225 - CISM discussion

Report
Export

Which of the following should be given the HIGHEST priority during an information security post-incident review?

A.
Documenting actions taken in sufficient detail
Answers
A.
Documenting actions taken in sufficient detail
B.
Updating key risk indicators (KRIs)
Answers
B.
Updating key risk indicators (KRIs)
C.
Evaluating the performance of incident response team members
Answers
C.
Evaluating the performance of incident response team members
D.
Evaluating incident response effectiveness
Answers
D.
Evaluating incident response effectiveness
Suggested answer: D

Explanation:

An information security post-incident review is a process that aims to identify the root causes, impacts, lessons learned, and improvement actions of a security incident. The highest priority during a post-incident review should be evaluating the effectiveness of the incident response, which means assessing how well the incident response plan, procedures, roles, resources, and communication were executed and aligned with the business objectives and requirements. Evaluating the incident response effectiveness can help to identify the gaps, weaknesses, strengths, and opportunities for improvement in the incident response process and capabilities. Documenting actions taken in sufficient detail, updating key risk indicators (KRIs), and evaluating the performance of incident response team members are also important activities during a post-incident review, but they are not as critical as evaluating the incident response effectiveness, which can provide a holistic and strategic view of the incident response maturity and value.

Reference=

ISACA, CISM Review Manual, 16th Edition, 2020, page 2411

ISACA, CISM Review Questions, Answers & Explanations Database - 12 Month Subscription, 2020, question ID 2192

During post-incident reviews, the highest priority should be given to evaluating the effectiveness of the incident response effort. This includes assessing the accuracy of the response to the incident, the timeliness of the response, and the efficiency of the response. It is important to assess the effectiveness of the response in order to identify areas for improvement and ensure that future responses can be more effective. Documenting the actions taken in sufficient detail, updating key risk indicators (KRIs), and evaluating the performance of incident response team members are all important components of a post-incident review, but evaluating incident response effectiveness should be given the highest priority.

asked 01/10/2024
Osman Rana
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first