ExamGecko
Question list
Search
Search

Question 392 - CISM discussion

Report
Export

Which of the following metrics is MOST appropriate for evaluating the incident notification process?

A.
Average total cost of downtime per reported incident
Answers
A.
Average total cost of downtime per reported incident
B.
Elapsed time between response and resolution
Answers
B.
Elapsed time between response and resolution
C.
Average number of incidents per reporting period
Answers
C.
Average number of incidents per reporting period
D.
Elapsed time between detection, reporting, and response
Answers
D.
Elapsed time between detection, reporting, and response
Suggested answer: D

Explanation:

Elapsed time between detection, reporting, and response is the most appropriate metric for evaluating the incident notification process because it measures how quickly and effectively the organization identifies, communicates, and responds to security incidents. The incident notification process is a critical part of the incident response plan that defines the roles and responsibilities, procedures, and channels for reporting and escalating security incidents to the relevant stakeholders. Elapsed time between detection, reporting, and response helps to assess the performance and efficiency of the incident notification process, as well as to identify any bottlenecks or delays that may affect the incident resolution and recovery. Therefore, elapsed time between detection, reporting, and response is the correct answer.

https://www.atlassian.com/incident-management/kpis/common-metrics

https://securityscorecard.com/blog/how-to-use-incident-response-metrics/

https://www.cisa.gov/sites/default/files/publications/Incident-Response-Plan-Basics_508c.pdf

asked 01/10/2024
Vinayaka G D
39 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first