ExamGecko
Question list
Search
Search

Question 649 - CISM discussion

Report
Export

Which of the following is MOST important to include in security incident escalation procedures?

A.
Key objectives of the security program
Answers
A.
Key objectives of the security program
B.
Recovery procedures
Answers
B.
Recovery procedures
C.
Notification criteria
Answers
C.
Notification criteria
D.
Containment procedures
Answers
D.
Containment procedures
Suggested answer: C

Explanation:

The most important thing to include in security incident escalation procedures isnotification criteria. This is because notification criteria define who needs to be informed of an incident, when, and how, depending on the severity, impact, and nature of the incident. Notification criteria help to ensure that the appropriate stakeholders are aware of the incident and can take the necessary actions to respond, mitigate, and recover from it. Notification criteria also help to comply with legal and regulatory requirements for reporting incidents to external parties, such as customers, authorities, or media.

Notification criteria define who needs to be informed of an incident, when, and how, depending on the severity, impact, and nature of the incident. (From CISM Manual or related resources)

Reference= CISM Review Manual 15th Edition, Chapter 4, Section 4.2.2, page 2121; CISM Review Questions, Answers & Explanations Manual 9th Edition, Question 1, page 1

asked 01/10/2024
Rey Geric Villafranca
43 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first