ExamGecko
Question list
Search
Search

Question 667 - CISM discussion

Report
Export

Which of the following should be updated FIRST when aligning the incident response plan with the corporate strategy?

A.
Disaster recovery plan (DRP)
Answers
A.
Disaster recovery plan (DRP)
B.
Incident notification plan
Answers
B.
Incident notification plan
C.
Risk response scenarios
Answers
C.
Risk response scenarios
D.
Security procedures
Answers
D.
Security procedures
Suggested answer: C

Explanation:

The answer to the question is C. Risk response scenarios. This is because risk response scenarios are the predefined plans and actions that the organization will take to respond to specific types of incidents, such as cyberattacks, natural disasters, or data breaches. Risk response scenarios should be aligned with the corporate strategy, which defines the vision, mission, goals, and objectives of the organization, and guides the decision-making and resource allocation processes. By aligning the risk response scenarios with the corporate strategy, the organization can ensure that the incident response plan supports the achievement of the desired outcomes and benefits, and minimizes the impact and disruption to the business operations and performance.

Risk response scenarios are the predefined plans and actions that the organization will take to respond to specific types of incidents. Risk response scenarios should be aligned with the corporate strategy, which defines the vision, mission, goals, and objectives of the organization. (From CISM Manual or related resources)

Reference = CISM Review Manual 15th Edition, Chapter 4, Section 4.2.2, page 2111; CISM domain 4: Information security incident management [2022 update] | Infosec2; A Guide to Effective Incident Management Communications3

asked 01/10/2024
Francesco MARRELLA
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first