ExamGecko
Question list
Search
Search

Question 419 - CISM discussion

Report
Export

After a ransomware incident an organization's systems were restored. Which of the following should be of MOST concern to the information security manager?

A.
The service level agreement (SLA) was not met.
Answers
A.
The service level agreement (SLA) was not met.
B.
The recovery time objective (RTO) was not met.
Answers
B.
The recovery time objective (RTO) was not met.
C.
The root cause was not identified.
Answers
C.
The root cause was not identified.
D.
Notification to stakeholders was delayed.
Answers
D.
Notification to stakeholders was delayed.
Suggested answer: C

Explanation:

= After a ransomware incident, the most important concern for the information security manager is to identify the root cause of the incident and prevent it from happening again. The root cause analysis (RCA) is a systematic process of finding and eliminating the underlying factors that led to the incident, such as vulnerabilities, misconfigurations, human errors, or malicious actions. Without performing a RCA, the organization may not be able to address the root cause and may face the same or similar incidents in the future, which could result in more damage, costs, and reputational loss. Therefore, the information security manager should prioritize the RCA over other concerns, such as meeting the SLA, RTO, or notification requirements, which are important but secondary to the RCA.

Reference= CISM Review Manual 15th Edition, page 254-2551; CISM Review Questions, Answers & Explanations Database - 12 Month Subscription, QID 4202

asked 01/10/2024
Wessel Beulink
39 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first