nerdexam
Isaca

CISA · Question #28

Which of the following would be of MOST concern for an IS auditor evaluating the design of an organization's incident management processes?

The correct answer is A. Prioritization criteria are not defined.. The absence of defined prioritization criteria in an incident management process design is the greatest concern, as it prevents effective and consistent handling of security incidents based on their impact and urgency.

Submitted by joshua94· Apr 18, 2026Information Systems Operations and Business Resilience

Question

Which of the following would be of MOST concern for an IS auditor evaluating the design of an organization's incident management processes?

Options

  • APrioritization criteria are not defined.
  • BService management standards are not followed.
  • CExpected time to resolve incidents is not specified.
  • DMetrics are not reported to senior management.

How the community answered

(43 responses)
  • A
    79% (34)
  • B
    2% (1)
  • C
    7% (3)
  • D
    12% (5)

Why each option

The absence of defined prioritization criteria in an incident management process design is the greatest concern, as it prevents effective and consistent handling of security incidents based on their impact and urgency.

APrioritization criteria are not defined.Correct

Without defined prioritization criteria, incident responders cannot consistently determine which incidents are critical, which require immediate attention, and how to allocate resources effectively. This can lead to delays in resolving high-impact incidents, misallocation of resources, and a failure to protect critical assets, making it a fundamental flaw in the incident management process design that directly impacts the organization's ability to respond to threats.

BService management standards are not followed.

While following service management standards (like ITIL) is beneficial for process maturity, their absence is less critical than the fundamental inability to prioritize incidents based on risk and impact.

CExpected time to resolve incidents is not specified.

Not specifying an expected time to resolve incidents (SLAs) is a weakness in performance measurement, but the ability to prioritize incidents effectively comes before setting resolution targets.

DMetrics are not reported to senior management.

Lack of reporting metrics to senior management is a governance and oversight issue, but the operational effectiveness of incident handling, particularly prioritization, is more fundamental to the process design itself.

Concept tested: Incident prioritization in incident management

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf

Topics

#Incident Management#Process Design#Prioritization#IS Audit Concerns

Community Discussion

No community discussion yet for this question.

Full CISA Practice