Certified Information Security Manager (CISM)Incident ManagementEasy

A global e-commerce company experiences a significant distributed denial-of-service (DDoS) attack that overwhelms its online sales platform. The incident response team successfully mitigates the attack after several hours. During the post-incident analysis, the CISO wants to understand the total cost incurred due to the incident, including lost revenue, mitigation efforts, and reputational damage. Which of the following metrics is MOST appropriate for this assessment?

  1. ARecovery Point Objective (RPO)
  2. BMean Time To Detect (MTTD)
  3. CMean Time To Recover (MTTR)
  4. DCost of Incident (COI)
Show answer & explanation

Correct answer: D. Cost of Incident (COI)

The Cost of Incident (COI) metric is specifically designed to quantify the total financial impact of an incident, encompassing direct costs like mitigation, indirect costs like lost revenue, and intangible costs like reputational damage.

Why the other options are wrong

  • A. RPO defines the maximum acceptable data loss, not the financial cost of an incident.
  • B. MTTD measures the time taken to detect an incident, not its financial impact.
  • C. MTTR measures the time taken to restore services, not the total financial impact.

Cost of Incident (COI)

A metric used to calculate the total financial burden of a security incident, including direct, indirect, and intangible costs.

  • Includes lost revenue, mitigation expenses, legal fees.
  • Can also account for reputational damage and customer churn.
  • Helps organizations justify security investments and prioritize risks.

Memory trick: Metrics 'M.E.A.S.U.R.E.': Mean Time, Efficacy, Alert Rate, Severity, Utilization, Recovery, and Expenses.

More Incident Management questions