ISC2 CISSP (Certified Information Systems Security Professional)Security and Risk ManagementEasy

A financial institution is evaluating its current incident response plan. During a recent simulated attack, it was discovered that the legal department was not involved in the initial stages of incident containment and eradication, leading to potential missteps regarding evidence preservation and regulatory reporting requirements. Which aspect of security governance principles was most clearly overlooked in this scenario?

  1. AStakeholder engagement
  2. BSecurity architecture review
  3. CRisk tolerance definition
  4. DPerformance measurement
Show answer & explanation

Correct answer: A. Stakeholder engagement

The scenario highlights a failure to involve a critical internal stakeholder (legal department) in a key security process, leading to deficiencies. This directly points to a lack of proper stakeholder engagement within the security governance framework.

Why the other options are wrong

  • B. Security architecture review pertains to the design and implementation of security controls, not the operational involvement of legal during an incident.
  • C. Risk tolerance definition relates to the acceptable level of risk, not the involvement of departments in incident response.
  • D. Performance measurement focuses on evaluating the effectiveness of security controls, not the initial involvement of departments.

Stakeholder Engagement

The process by which an organization involves people who may be affected by the decisions it makes or can influence the implementation of its decisions.

  • Crucial for successful security programs.
  • Ensures all perspectives and requirements are considered.
  • Promotes ownership and support for security initiatives.

Memory trick: Govern with ALL hands on deck, from legal to tech.

More Security and Risk Management questions