Certified Information Security Manager (CISM)Incident ManagementEasy
A financial institution is developing its incident response capabilities. The CISO wants to ensure that the incident response plan (IRP) clearly defines the thresholds at which an event escalates to a major incident requiring executive notification and activation of the incident command structure. Which of the following elements of the IRP is MOST critical for this purpose?
- AThe post-incident review process and documentation requirements.
- BThe forensic analysis toolkit and procedures.
- CThe incident classification and severity matrix.
- DThe communication plan outlining stakeholder notification lists.
Show answer & explanationAnswer & explanation
Correct answer: C. The incident classification and severity matrix.
The incident classification and severity matrix provides predefined criteria for categorizing incidents, including the thresholds for escalation. This ensures consistent and timely decision-making regarding incident severity and required response levels.
Why the other options are wrong
- A. This occurs after an incident and is not used for initial escalation decision-making.
- B. This is a technical tool for investigation, not for determining incident severity or escalation thresholds.
- D. While important for notifying, it does not define the criteria for escalation itself.
Incident Classification & Severity Matrix
A structured tool used in incident management to categorize incidents based on predefined criteria, determining their severity and the appropriate response level.
- Defines thresholds for incident escalation.
- Ensures consistent incident handling.
- Guides resource allocation and communication.
Memory trick: To know when to 'raise the alarm,' you need a clear 'map' of severity.