nerdexam
Isaca

CISM · Question #149

Which of the following is MOST important for the information security manager to confirm when reviewing an incident response plan?

The correct answer is B. The plan is based on a business impact analysis (BIA). When reviewing an incident response plan, it is most important to confirm that the plan is based on a business impact analysis (BIA). This ensures that response efforts are prioritized according to the critical business functions and assets.

Submitted by carlos_mx· Apr 18, 2026Information Security Incident Management

Question

Which of the following is MOST important for the information security manager to confirm when reviewing an incident response plan?

Options

  • AThe plan includes a requirement for post-incident review
  • BThe plan is based on a business impact analysis (BIA)
  • CThe plan is stored at backup recovery locations
  • DThe plan is readily available to provide to auditors.

How the community answered

(37 responses)
  • A
    3% (1)
  • B
    92% (34)
  • C
    5% (2)

Why each option

When reviewing an incident response plan, it is most important to confirm that the plan is based on a business impact analysis (BIA). This ensures that response efforts are prioritized according to the critical business functions and assets.

AThe plan includes a requirement for post-incident review

Including a requirement for post-incident review is important for continuous improvement but does not fundamentally ensure the plan's effectiveness in protecting critical business operations during an incident.

BThe plan is based on a business impact analysis (BIA)Correct

An incident response plan that is based on a business impact analysis (BIA) ensures that the organization's response efforts are aligned with its most critical business functions and data. The BIA identifies essential assets and their recovery time objectives (RTO) and recovery point objectives (RPO), which directly inform incident prioritization and resource allocation during a response.

CThe plan is stored at backup recovery locations

Storing the plan at backup recovery locations is crucial for accessibility during a disaster but does not ensure the plan's content is effectively designed to protect business-critical processes.

DThe plan is readily available to provide to auditors.

Making the plan available to auditors is a compliance concern, not a primary driver for the operational effectiveness and prioritization of the incident response itself.

Concept tested: Incident response plan alignment with business criticality

Source: https://learn.microsoft.com/en-us/compliance/regulatory/offering-fedramp-business-continuity-and-disaster-recovery

Topics

#Incident Response Plan#Business Impact Analysis#Plan Review#Business Alignment

Community Discussion

No community discussion yet for this question.

Full CISM Practice