Certified Information Security Manager (CISM)Incident ManagementMedium
A CISO is reviewing the organization's current incident response plan. The plan details steps for technical containment and eradication but lacks specific guidance on preserving potential evidence for legal or forensic purposes. What is the MOST significant risk posed by this oversight?
- AInability to prosecute attackers or recover damages.
- BIncreased Recovery Time Objective (RTO) for affected systems.
- CDiminished ability to detect future similar attacks.
- DHigher financial costs for incident response tools.
Show answer & explanationAnswer & explanation
Correct answer: A. Inability to prosecute attackers or recover damages.
Without proper evidence preservation, the organization significantly loses its ability to pursue legal action against attackers, support insurance claims, or comply with regulatory reporting requirements, which can lead to substantial financial and reputational losses.
Why the other options are wrong
- B. RTO is about system recovery speed, not evidence preservation.
- C. While forensic analysis aids future detection, the most direct and significant risk of *not preserving evidence* is losing legal recourse.
- D. This oversight does not directly increase tool costs; it impacts the outcome of an investigation.
Forensic Readiness
The organization's ability to collect, preserve, and analyze digital evidence in a legally sound and forensically sound manner during and after a security incident.
- Crucial for legal action, regulatory compliance, and post-incident analysis.
- Requires predefined procedures and trained personnel.
- Evidence must be collected without alteration to maintain its integrity.
Memory trick: No evidence, no justice, no recovery.