Certified Information Security Manager (CISM)Incident ManagementEasy

A financial institution is developing its incident response capabilities. The CISO wants to ensure that the incident response plan (IRP) clearly defines the thresholds at which an event escalates to a major incident requiring executive notification and activation of the incident command structure. Which of the following elements of the IRP is MOST critical for this purpose?

  1. AThe post-incident review process and documentation requirements.
  2. BThe forensic analysis toolkit and procedures.
  3. CThe incident classification and severity matrix.
  4. DThe communication plan outlining stakeholder notification lists.
Show answer & explanation

Correct answer: C. The incident classification and severity matrix.

The incident classification and severity matrix provides predefined criteria for categorizing incidents, including the thresholds for escalation. This ensures consistent and timely decision-making regarding incident severity and required response levels.

Why the other options are wrong

  • A. This occurs after an incident and is not used for initial escalation decision-making.
  • B. This is a technical tool for investigation, not for determining incident severity or escalation thresholds.
  • D. While important for notifying, it does not define the criteria for escalation itself.

Incident Classification & Severity Matrix

A structured tool used in incident management to categorize incidents based on predefined criteria, determining their severity and the appropriate response level.

  • Defines thresholds for incident escalation.
  • Ensures consistent incident handling.
  • Guides resource allocation and communication.

Memory trick: To know when to 'raise the alarm,' you need a clear 'map' of severity.

More Incident Management questions