Certified Information Security Manager (CISM)Incident ManagementEasy
A CISO is establishing an incident response program for a mid-sized financial institution. The CISO wants to ensure that the program can adapt to emerging threats and technologies while maintaining core principles. Which of the following components is MOST crucial for achieving this adaptability?
- AA well-defined incident response policy that outlines roles, responsibilities, and guiding principles.
- BInvesting in a Security Orchestration, Automation, and Response (SOAR) platform.
- CDetailed, step-by-step incident response playbooks for every conceivable scenario.
- DRegularly scheduled, unannounced incident response drills and tabletop exercises.
Show answer & explanationAnswer & explanation
Correct answer: A. A well-defined incident response policy that outlines roles, responsibilities, and guiding principles.
A well-defined incident response policy provides the foundational framework and guiding principles that allow an incident response program to adapt. Playbooks can become outdated, SOAR is a tool, and exercises test readiness, but the policy defines the overarching strategy.
Why the other options are wrong
- B. SOAR platforms automate responses but do not define the strategic adaptability of the program itself.
- C. Detailed playbooks can become quickly outdated and rigid, hindering adaptability to new threats.
- D. Exercises test the current capabilities but do not, by themselves, provide the foundational adaptability to emerging threats.
Incident Response Policy
A formal document that establishes the organization's approach to incident response, outlining objectives, roles, responsibilities, and guiding principles.
- Provides strategic direction for incident management.
- Defines authority and scope for incident responders.
- Ensures consistency and compliance across the organization.
Memory trick: Policy is the bedrock, not the building itself.