ExamGecko
Question list
Search
Search

Question 304 - CISM discussion

Report
Export

An organization is aligning its incident response capability with a public cloud service provider. What should be the information security manager's FIRST course of action?

A.
Identify the skill set of the provider's incident response team.
Answers
A.
Identify the skill set of the provider's incident response team.
B.
Evaluate the provider's audit logging and monitoring controls.
Answers
B.
Evaluate the provider's audit logging and monitoring controls.
C.
Review the provider's incident definitions and notification criteria.
Answers
C.
Review the provider's incident definitions and notification criteria.
D.
Update the incident escalation process.
Answers
D.
Update the incident escalation process.
Suggested answer: C

Explanation:

When an organization is aligning its incident response capability with a public cloud service provider, the information security manager's first course of action should be to review the provider's incident definitions and notification criteria. This is because the provider's incident definitions and notification criteria may differ from the organization's own, and may affect the scope, severity, and urgency of the incidents that need to be reported and handled. By reviewing the provider's incident definitions and notification criteria, the information security manager can ensure that there is a common understanding and agreement on what constitutes an incident, how it is classified, and when and how it is communicated.This will help to avoid confusion, delays, or conflicts in the incident response process, and to establish clear roles and responsibilities between the organization and the provider.Reference= CISM Review Manual, 16th Edition, page 1021

Reviewing the provider's incident definitions and notification criteria is the FIRST course of action when aligning the organization's incident response capability with a public cloud service provider. This is because the organization needs to understand how the provider defines and classifies incidents, what their roles and responsibilities are, and how they will communicate with the organization in case of an incident. This will help the organization align its own incident response processes and expectations with the provider's and ensure a coordinated and effective response.

Topic 3, Exam Pool C

asked 01/10/2024
Maxim Shpakov
41 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first