Certified Information Security Manager (CISM)Incident ManagementEasy

During a significant cyber incident, the CISO observes that the incident response team (IRT) is overwhelmed with manual tasks, leading to delays in containment and reporting. The CISO wants to improve the efficiency and speed of future incident response activities. Which of the following capabilities should the CISO prioritize for implementation?

  1. AImplementing a new threat intelligence platform to enrich incident data.
  2. BIncreasing the size of the incident response team with additional analysts.
  3. CAdopting a Security Orchestration, Automation, and Response (SOAR) platform.
  4. DDeveloping more stringent service level agreements (SLAs) with external vendors.
Show answer & explanation

Correct answer: C. Adopting a Security Orchestration, Automation, and Response (SOAR) platform.

A SOAR platform is specifically designed to automate repetitive, manual tasks in incident response workflows, orchestrate various security tools, and centralize incident data, directly addressing the issue of an overwhelmed team and delays due to manual processes.

Why the other options are wrong

  • A. Threat intelligence enriches data but does not directly address the manual workload or automation need.
  • B. Increasing staff might help, but it doesn't solve the underlying inefficiency of manual processes, which SOAR addresses.
  • D. SLAs with vendors manage external dependencies but don't solve internal team workload issues.

SOAR (Security Orchestration, Automation, and Response)

A technology solution that combines incident response, security operations automation, and security orchestration capabilities into a single platform.

  • Automates repetitive security tasks.
  • Orchestrates disparate security tools.
  • Helps standardize and accelerate incident response procedures.

Memory trick: SOAR makes your IR team fly, not just walk faster.

More Incident Management questions