Certified Information Security Manager (CISM)Information Security ProgramMedium

An organization's information security program has successfully reduced the frequency of security incidents over the past year. However, a recent internal audit revealed that the average time to detect (MTTD) and time to respond (MTTR) to incidents have increased significantly. Which of the following areas of the information security program should the CISO prioritize for improvement?

  1. ASecurity awareness and training.
  2. BSecurity policy and governance.
  3. CIncident response and security operations.
  4. DVendor risk management.
Show answer & explanation

Correct answer: C. Incident response and security operations.

The scenario clearly indicates a problem with the time taken to detect and respond to incidents, despite a reduction in incident frequency. These metrics (MTTD and MTTR) are directly related to the efficiency and effectiveness of the incident response and security operations functions. Therefore, prioritizing improvement in this area will directly address the identified weaknesses.

Why the other options are wrong

  • A. Security awareness and training primarily aims to reduce the likelihood of incidents, not directly improve detection or response times for incidents that do occur.
  • B. While policies and governance provide the framework, they don't directly impact the operational speed of detection and response when the frequency of incidents is already down.
  • D. Vendor risk management focuses on third-party risks and does not directly address the internal operational efficiency of incident detection and response.

Incident Response & SecOps

The coordinated set of processes, technologies, and teams responsible for detecting, analyzing, containing, eradicating, recovering from, and post-incident activities related to cybersecurity incidents.

  • Focuses on rapid detection and response.
  • Aims to minimize incident impact.
  • Involves tools, playbooks, and skilled personnel.

Memory trick: Incidents happen; it's how fast you see them and act that defines your security ops health.

More Information Security Program questions