Certified Information Security Manager (CISM)Incident ManagementEasy
A CISO is establishing an incident response program for a mid-sized financial institution. Which of the following is the MOST critical initial step to ensure the program aligns with organizational objectives and regulatory requirements?
- AProcuring advanced Security Information and Event Management (SIEM) tools.
- BConducting regular penetration testing and vulnerability assessments.
- CDeveloping a comprehensive incident response policy and plan.
- DHiring a dedicated team of incident response specialists.
Show answer & explanationAnswer & explanation
Correct answer: C. Developing a comprehensive incident response policy and plan.
Establishing a foundational incident response policy and plan is the most critical initial step. It provides the necessary framework, defines roles, responsibilities, and procedures, and ensures alignment with business and regulatory requirements before technology or staffing.
Why the other options are wrong
- A. Procuring tools is important but comes after defining the strategy and processes.
- B. Penetration testing and vulnerability assessments are proactive security measures, not the initial step for establishing an incident response program itself.
- D. Hiring specialists is necessary, but their efforts are most effective when guided by established policies and plans.
Incident Response Policy
A formal document that defines an organization's overall approach, objectives, and high-level procedures for managing security incidents.
- Sets the strategic direction for incident response.
- Ensures alignment with business objectives and legal/regulatory requirements.
- Provides the foundation for detailed incident response plans and procedures.
Memory trick: Policy First, then the rest will follow.