ExamGecko
Question list
Search
Search

Question 428 - CISM discussion

Report
Export

A security incident has been reported within an organization When should an information security manager contact the information owner?

A.
After the incident has been mitigated
Answers
A.
After the incident has been mitigated
B.
After the incident has been confirmed.
Answers
B.
After the incident has been confirmed.
C.
After the potential incident has been togged
Answers
C.
After the potential incident has been togged
D.
After the incident has been contained
Answers
D.
After the incident has been contained
Suggested answer: B

Explanation:

= An information security manager should contact the information owner after the incident has been confirmed, as this is the point when the impact and severity of the incident can be assessed and communicated. The information owner is responsible for the business value and use of the information and should be involved in the decision making process regarding the incident response. Contacting the information owner after the incident has been mitigated or contained may be too late, as the information owner may have different priorities or expectations than the security team.Contacting the information owner after the potential incident has been logged may be premature, as the incident may turn out to be a false positive or a minor issue that does not require the information owner's attention.Reference=1: CISM Review Manual, 16th Edition by Isaca (Author), page 292.

asked 01/10/2024
Bernardo Garcia
43 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first