exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 62 discussion

Actual exam question from Isaca's CISM
Question #: 62
Topic #: 1
[All CISM Questions]

When developing an escalation process for an incident response plan, the information security manager should PRIMARILY consider the:

  • A. affected stakeholders.
  • B. incident response team.
  • C. availability of technical resources.
  • D. media coverage
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Abhey
Highly Voted 1 year, 6 months ago
When developing an escalation process for an incident response plan, the information security manager should PRIMARILY consider the affected stakeholders. The escalation process should be designed to ensure that the appropriate stakeholders are notified at the appropriate time, in order to minimize the impact of the incident on the organization. Stakeholders could include executives, legal counsel, IT teams, customers, vendors, and regulatory bodies, depending on the nature of the incident.
upvoted 10 times
Vovik373
1 month, 1 week ago
CISM Framework Approach An organization establishes an incident response escalation matrix: ✔ Level 1: Incident detected → Assigned to Tier 1 analysts. ✔ Level 2: Escalated to Incident Response Team (IRT) for in-depth investigation. ✔ Level 3: Escalated to senior security leadership for major security breaches. Stakeholders are important but not the primary factor in designing an escalation process. Stakeholder communication happens after the IRT manages the incident.
upvoted 1 times
...
...
Vovik373
Most Recent 1 month, 1 week ago
Selected Answer: B
CISM Framework Approach An organization establishes an incident response escalation matrix: ✔ Level 1: Incident detected → Assigned to Tier 1 analysts. ✔ Level 2: Escalated to Incident Response Team (IRT) for in-depth investigation. ✔ Level 3: Escalated to senior security leadership for major security breaches. By defining clear escalation paths, the IRT ensures a rapid, structured, and effective response, aligning with CISM risk and incident management best practices. Stakeholders are important but not the primary factor in designing an escalation process. Stakeholder communication happens after the IRT manages the incident. The primary factor when developing an escalation process is ensuring that the incident response team (IRT) can effectively respond to the incident.
upvoted 1 times
...
afoo1314
7 months, 2 weeks ago
Selected Answer: A
Incident Response team is often form with representative from various department such as IT, vendors, legal and etc. Stakeholders include larger group of representatives that not part of the IRT. During incident response escalation, IT/SECURITY MANAGER 1st escalation always to the affected stakeholders. Business need to be aware of what is going on and be inform that the incident response team will be looking into the incident and report to the manager on the status update. To certain point of escalation, incident response team might report the status to the stakeholder directly.
upvoted 3 times
...
AlexJacobson
9 months, 2 weeks ago
Selected Answer: A
Again, you are a manager and you are considering the bigger picture. "Affected stakeholders" is the most comprehensive answer here.
upvoted 1 times
...
Viperhunter
11 months, 1 week ago
Selected Answer: B
When developing an escalation process for an incident response plan, the primary consideration should be the incident response team. This involves defining how and when to escalate incidents within the team based on the severity, complexity, or other factors. The incident response team plays a crucial role in coordinating the organization's response to security incidents.
upvoted 2 times
...
Viperhunter
11 months, 2 weeks ago
Selected Answer: A
The primary consideration in developing an escalation process for an incident response plan is ensuring that the affected stakeholders are identified and included in the escalation procedures. This involves understanding who needs to be informed, involved, or notified at different stages of the incident response process based on the nature and severity of the incident. Stakeholders may include senior management, legal, communications, IT teams, and other relevant parties. While the incident response team (option B), availability of technical resources (option C), and media coverage (option D) are important factors, the focus in the escalation process is on addressing the needs and expectations of the stakeholders who are impacted or have a vested interest in the incident.
upvoted 1 times
...
acf4e9a
1 year ago
Selected Answer: A
Ideally affected stakeholders should already include incident response team so answer A is more suitable here.
upvoted 1 times
...
oluchecpoint
1 year, 1 month ago
A. affected stakeholders. The primary focus should be on ensuring that the affected stakeholders are identified, informed, and involved in the incident response process. This includes internal and external stakeholders such as employees, customers, partners, regulatory authorities, and potentially the public, depending on the nature and severity of the incident. Ensuring effective communication and coordination with stakeholders is crucial during incident response to manage the situation effectively and minimize potential damage. While the incident response team, technical resources, and media coverage are also important considerations, they should be addressed in conjunction with the needs and concerns of the affected stakeholders.
upvoted 3 times
...
Azurefox79
1 year, 2 months ago
Selected Answer: A
A. IRT is a subset of affected stakeholders
upvoted 1 times
...
DavoA
1 year, 3 months ago
Selected Answer: B
Primarily should be the team
upvoted 1 times
...
ddharia94
1 year, 4 months ago
Why not availability of technical resources? Escalation must be done to the correct resources to be able to resolve or contain the incident?
upvoted 1 times
...
rugerfan17
1 year, 4 months ago
Selected Answer: B
Incident response team notifies the affected stakeholders
upvoted 1 times
...
richck102
1 year, 5 months ago
B. incident response team.
upvoted 1 times
...
efeefe
1 year, 7 months ago
why not B?
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago