Certified Information Security Manager (CISM)Incident ManagementEasy
A CISO is tasked with developing an incident response capability for a rapidly growing startup with limited resources and a small IT team. The startup primarily uses SaaS applications and cloud infrastructure. The CISO needs an approach that is agile, cost-effective, and focuses on quick recovery. Which incident response methodology is BEST suited for this scenario?
- ABuilding an internal 24/7 Security Operations Center (SOC).
- BLean Incident Response.
- CSecurity Orchestration, Automation, and Response (SOAR) implementation.
- DTraditional NIST-based Incident Response Lifecycle.
Show answer & explanationAnswer & explanation
Correct answer: B. Lean Incident Response.
Lean Incident Response focuses on agility, cost-effectiveness, and rapid recovery by prioritizing essential activities and leveraging existing cloud and SaaS capabilities, which perfectly aligns with the startup's limited resources and cloud-centric environment.
Why the other options are wrong
- A. Building an internal 24/7 SOC is a significant investment in personnel and technology, making it unfeasible for a startup with a small IT team and limited budget.
- C. SOAR implementation can be costly and complex, requiring significant upfront investment and expertise that a startup with limited resources may not have.
- D. Traditional NIST-based IR is comprehensive but can be resource-intensive, which is not ideal for a startup with limited resources.
Lean Incident Response
An incident response methodology that prioritizes efficiency, rapid recovery, and leveraging existing resources, often suitable for organizations with limited budgets or cloud-native environments.
- Focuses on minimum viable response.
- Emphasizes agility and cost-effectiveness.
- Leverages cloud provider security features and SaaS capabilities.
Memory trick: For a lean startup, a lean IR is the smart start.