ISACA Certified Information Systems Auditor (CISA) ExamDomain 5: Protection of Information AssetsMedium
A CISA is evaluating an organization's incident response plan (IRP) following a recent phishing attack that compromised several employee credentials. The CISA notes that the IRP effectively details steps for containment and eradication but lacks clear guidance on how to assess the financial and reputational impact after an incident. What is the MOST significant risk posed by this deficiency?
- AUnderestimation of the true cost of the incident, hindering future security investment decisions.
- BInability to accurately report the incident to regulatory authorities, leading to potential fines.
- CDelay in restoring affected systems and services to normal operation.
- DFailure to identify the root cause of the phishing attack, increasing the likelihood of recurrence.
Show answer & explanationAnswer & explanation
Correct answer: A. Underestimation of the true cost of the incident, hindering future security investment decisions.
Without clear guidance on assessing financial and reputational impact, the organization cannot accurately quantify the total cost of an incident. This underestimation directly impairs the ability to justify necessary security investments, obtain appropriate budget, and make informed strategic decisions to prevent future incidents, thereby hindering long-term security posture improvement.
Why the other options are wrong
- B. While reporting is crucial, the primary deficiency is not about the report itself, but the lack of assessment of the impact that forms the basis of the report and future strategy.
- C. Restoration is part of recovery, which is different from post-incident impact assessment. The IRP is noted to be effective in containment and eradication, which precede recovery.
- D. Root cause analysis is a separate step, usually part of post-incident review. The deficiency specifically relates to assessing the 'impact' after an incident, not the cause of the incident itself.
Post-Incident Impact Assessment
The process of evaluating the full extent of financial, operational, reputational, and legal damage caused by a security incident.
- Crucial for understanding the true cost of security breaches.
- Informs future security investment and risk management decisions.
- Often involves collecting data on direct and indirect costs, legal liabilities, and brand damage.
Memory trick: ASSESS the damage to avoid future 'COSTLY' mistakes.