Certified Information Security Manager (CISM)Incident ManagementHard

A global e-commerce platform experiences a major data breach affecting millions of customer records. The CISO must prioritize actions to mitigate harm and control the incident. According to the NIST Incident Response Lifecycle, which phase is MOST critical immediately AFTER detection and analysis, to prevent further compromise and reduce damage?

  1. ACommunication and stakeholder notification
  2. BContainment, eradication, and recovery
  3. CPost-incident activity
  4. DPreparation
Show answer & explanation

Correct answer: B. Containment, eradication, and recovery

After detection and analysis, the immediate priority is to stop the incident from worsening and to begin removing the threat. This falls squarely into the Containment, Eradication, and Recovery phase of the NIST Incident Response Lifecycle, which is critical for limiting damage and preventing further compromise.

Why the other options are wrong

  • A. Communication is an ongoing activity throughout the incident, but containment is the immediate technical priority after detection to stop the bleeding.
  • C. Post-incident activity occurs after the incident is resolved and focuses on lessons learned.
  • D. Preparation is a pre-incident phase, establishing capabilities before an incident occurs.

NIST Incident Response Lifecycle (CER Phase)

The 'Containment, Eradication, and Recovery' phase of the NIST Incident Response Lifecycle focuses on limiting the scope and impact of an incident, removing the root cause, and restoring affected systems and services to normal operation.

  • Follows Detection and Analysis.
  • Aims to stop the attack and prevent further damage.
  • Includes activities like isolating systems, removing malware, and restoring from backups.

Memory trick: After finding the fire, put it out and rebuild.

More Incident Management questions