ExamGecko
Question list
Search
Search

Question 583 - CISM discussion

Report
Export

After the occurrence of a major information security incident, which of the following will BEST help an information security manager determine corrective actions?

A.
Calculating cost of the incident
Answers
A.
Calculating cost of the incident
B.
Conducting a postmortem assessment
Answers
B.
Conducting a postmortem assessment
C.
Performing an impact analysis
Answers
C.
Performing an impact analysis
D.
Preserving the evidence
Answers
D.
Preserving the evidence
Suggested answer: B

Explanation:

The best way to determine corrective actions after a major information security incident is to conduct a postmortem assessment, which is a systematic and structured review of the incident, its causes, its impacts, and its lessons learned. A postmortem assessment can help to identify the root causes of the incident, the strengths and weaknesses of the incident response process, the gaps and deficiencies in the security controls, and the opportunities for improvement and remediation. A postmortem assessment can also help to document the recommendations and action plans for preventing or minimizing the recurrence of similar incidents in the future.

Reference= CISM Review Manual, 16th Edition eBook1, Chapter 4: Information Security Incident Management, Section: Incident Response, Subsection: Postincident Activities, Page 211.

asked 01/10/2024
Ivan Mazala
43 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first