Certified Information Security Manager (CISM)Incident ManagementMedium

During an ongoing major cyber incident, the CISO is informed that the primary incident response team is overwhelmed, and external experts need to be onboarded rapidly. Which of the following is the MOST important consideration for the CISO regarding these external resources?

  1. AProviding them with full administrative access to all affected systems immediately.
  2. BRequiring them to use only their own tools and equipment.
  3. CNegotiating the lowest possible hourly rate for their services.
  4. DEnsuring they have pre-existing non-disclosure agreements (NDAs) and clear scopes of work.
Show answer & explanation

Correct answer: D. Ensuring they have pre-existing non-disclosure agreements (NDAs) and clear scopes of work.

Before external experts can effectively assist, legal and operational frameworks like NDAs and clear scopes of work are crucial. This protects sensitive information and ensures their efforts are focused and permissible, minimizing legal risks and scope creep during a stressful event.

Why the other options are wrong

  • A. Full administrative access should be granted judiciously and with close monitoring, not immediately and broadly without established trust and control.
  • B. Requiring their own tools might hinder integration with existing IR infrastructure and data collection methods.
  • C. Cost is a secondary concern during a major incident; effectiveness and security are paramount.

External IR Team Integration

The process of bringing in and managing third-party incident response experts during a major security incident.

  • Requires clear legal agreements (NDAs) and defined responsibilities (SOW).
  • Focuses on secure and controlled access to organizational systems and data.
  • Aims to augment internal capabilities without introducing new risks.

Memory trick: Legal first, then tools and access.

More Incident Management questions