CISA · Question #28
Which of the following would be of MOST concern for an IS auditor evaluating the design of an organization's incident management processes?
The correct answer is A. Prioritization criteria are not defined.. The absence of defined prioritization criteria in an incident management process design is the greatest concern, as it prevents effective and consistent handling of security incidents based on their impact and urgency.
Question
Which of the following would be of MOST concern for an IS auditor evaluating the design of an organization's incident management processes?
Options
- APrioritization criteria are not defined.
- BService management standards are not followed.
- CExpected time to resolve incidents is not specified.
- DMetrics are not reported to senior management.
How the community answered
(43 responses)- A79% (34)
- B2% (1)
- C7% (3)
- D12% (5)
Why each option
The absence of defined prioritization criteria in an incident management process design is the greatest concern, as it prevents effective and consistent handling of security incidents based on their impact and urgency.
Without defined prioritization criteria, incident responders cannot consistently determine which incidents are critical, which require immediate attention, and how to allocate resources effectively. This can lead to delays in resolving high-impact incidents, misallocation of resources, and a failure to protect critical assets, making it a fundamental flaw in the incident management process design that directly impacts the organization's ability to respond to threats.
While following service management standards (like ITIL) is beneficial for process maturity, their absence is less critical than the fundamental inability to prioritize incidents based on risk and impact.
Not specifying an expected time to resolve incidents (SLAs) is a weakness in performance measurement, but the ability to prioritize incidents effectively comes before setting resolution targets.
Lack of reporting metrics to senior management is a governance and oversight issue, but the operational effectiveness of incident handling, particularly prioritization, is more fundamental to the process design itself.
Concept tested: Incident prioritization in incident management
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf
Topics
Community Discussion
No community discussion yet for this question.