nerdexam
Isaca

CISM · Question #142

A Software as a Service (SaaS) application has been implemented to support a critical business process. Which of the following is MOST important to include within the service level agreement (SLA)…

The correct answer is C. Defined incident response roles and responsibilities. Defined incident response roles and responsibilities are the most critical SLA element for ensuring timely incident response. In a SaaS model, the customer organization and the vendor share responsibility for different aspects of incident handling. Without explicitly defining…

Submitted by obi.ng· Apr 18, 2026Information Security Incident Management

Question

A Software as a Service (SaaS) application has been implemented to support a critical business process. Which of the following is MOST important to include within the service level agreement (SLA) to ensure timely response to incidents affecting the application?

Options

  • AVendor declarations and warranties
  • BEnhanced monitoring of in-scope systems
  • CDefined incident response roles and responsibilities
  • DEstablished incident response procedures

How the community answered

(32 responses)
  • A
    6% (2)
  • B
    3% (1)
  • C
    72% (23)
  • D
    19% (6)

Explanation

Defined incident response roles and responsibilities are the most critical SLA element for ensuring timely incident response. In a SaaS model, the customer organization and the vendor share responsibility for different aspects of incident handling. Without explicitly defining who does what - who declares an incident, who communicates status, who has authority to escalate - response efforts become disorganized and delayed. Vendor declarations/warranties (A) are legal protections, not operational response mechanisms. Enhanced monitoring (B) supports detection, not response. Established incident response procedures (D) are important but procedures alone are ineffective if accountability is unclear. Roles and responsibilities are the foundation that makes procedures actionable.

Topics

#SaaS security#Service Level Agreement (SLA)#Incident response#Roles and responsibilities

Community Discussion

No community discussion yet for this question.

Full CISM Practice