ExamGecko
Question list
Search
Search

Question 315 - CISM discussion

Report
Export

Which of the following should be the PRIMARY basis for a severity hierarchy for information security incident classification?

A.
Availability of resources
Answers
A.
Availability of resources
B.
Root cause analysis results
Answers
B.
Root cause analysis results
C.
Adverse effects on the business
Answers
C.
Adverse effects on the business
D.
Legal and regulatory requirements
Answers
D.
Legal and regulatory requirements
Suggested answer: C

Explanation:

The severity hierarchy for information security incident classification should be based on the potential or actual impact of the incident on the business objectives, operations, reputation, and stakeholders. The adverse effects on the business can be measured by criteria such as financial loss, operational disruption, legal liability, regulatory compliance, customer satisfaction, and public confidence. The other options are not the primary basis for a severity hierarchy, although they may be considered as secondary factors or consequences of an incident

asked 01/10/2024
Henock Asmerom
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first