ExamGecko
Question list
Search
Search

Question 537 - CISM discussion

Report
Export

A security incident has been reported within an organization. When should an information security manager contact the information owner?

A.
After the incident has been contained
Answers
A.
After the incident has been contained
B.
After the incident has been mitigated
Answers
B.
After the incident has been mitigated
C.
After the incident has been confirmed
Answers
C.
After the incident has been confirmed
D.
After the potential incident has been logged
Answers
D.
After the potential incident has been logged
Suggested answer: C

Explanation:

The information owner is the person who has the authority and responsibility for the information asset and its protection. The information security manager should contact the information owner as soon as possible after the incident has been confirmed, to inform them of the incident, its impact, and the actions taken or planned to resolve it. The information owner may also need to be involved in the decision-making process regarding the incident response and recovery. (From CISM Review Manual 15th Edition)

asked 01/10/2024
Eddie Martinez
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first