Certified Information Security Manager (CISM)Incident ManagementEasy

A CISO is tasked with developing an incident response capability for a rapidly growing startup with limited resources and a small IT team. The startup primarily uses SaaS applications and cloud infrastructure. The CISO needs an approach that is agile, cost-effective, and focuses on quick recovery. Which incident response methodology is BEST suited for this scenario?

  1. ABuilding an internal 24/7 Security Operations Center (SOC).
  2. BLean Incident Response.
  3. CSecurity Orchestration, Automation, and Response (SOAR) implementation.
  4. DTraditional NIST-based Incident Response Lifecycle.
Show answer & explanation

Correct answer: B. Lean Incident Response.

Lean Incident Response focuses on agility, cost-effectiveness, and rapid recovery by prioritizing essential activities and leveraging existing cloud and SaaS capabilities, which perfectly aligns with the startup's limited resources and cloud-centric environment.

Why the other options are wrong

  • A. Building an internal 24/7 SOC is a significant investment in personnel and technology, making it unfeasible for a startup with a small IT team and limited budget.
  • C. SOAR implementation can be costly and complex, requiring significant upfront investment and expertise that a startup with limited resources may not have.
  • D. Traditional NIST-based IR is comprehensive but can be resource-intensive, which is not ideal for a startup with limited resources.

Lean Incident Response

An incident response methodology that prioritizes efficiency, rapid recovery, and leveraging existing resources, often suitable for organizations with limited budgets or cloud-native environments.

  • Focuses on minimum viable response.
  • Emphasizes agility and cost-effectiveness.
  • Leverages cloud provider security features and SaaS capabilities.

Memory trick: For a lean startup, a lean IR is the smart start.

More Incident Management questions