ExamGecko
Question list
Search
Search

Question 567 - CISM discussion

Report
Export

When developing an incident escalation process, the BEST approach is to classify incidents based on:

A.
estimated time to recover.
Answers
A.
estimated time to recover.
B.
information assets affected.
Answers
B.
information assets affected.
C.
recovery point objectives (RPOs).
Answers
C.
recovery point objectives (RPOs).
D.
their root causes.
Answers
D.
their root causes.
Suggested answer: B

Explanation:

The best approach to developing an incident escalation process is to classify incidents based on the information assets affected, because this will help to determine the impact and severity of the incidents, as well as the appropriate response and recovery actions. The information assets affected by an incident can indicate the potential loss of confidentiality, integrity, or availability of the information, as well as the legal, regulatory, contractual, or reputational implications. By classifying incidents based on the information assets affected, the organization can prioritize the incidents and escalate them to the relevant stakeholders and authorities.

Reference= CISM Review Manual, 16th Edition, page 2901; A Practical Approach to Incident Management Escalation2

asked 01/10/2024
Luyanda Hatta
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first