CISM · Question #263
Which of the following is MOST important to consider when developing an incident response playbook?
The correct answer is A. Criticality of the organization's digital assets. The criticality of an organization's digital assets is the most important factor when building an incident response playbook because it determines response priorities, escalation thresholds, resource allocation, and recovery time objectives. A playbook must reflect which assets…
Question
Which of the following is MOST important to consider when developing an incident response playbook?
Options
- ACriticality of the organization's digital assets
- BThe maturity level of the security incident response team
- CTypes of attacks likely to be used against the organization
- DAnalysis of internal and external threat actors
How the community answered
(20 responses)- A60% (12)
- B10% (2)
- C25% (5)
- D5% (1)
Explanation
The criticality of an organization's digital assets is the most important factor when building an incident response playbook because it determines response priorities, escalation thresholds, resource allocation, and recovery time objectives. A playbook must reflect which assets require the fastest response, the most resources, and executive notification. The team's maturity level (B) affects implementation but is not the primary driver of playbook content. While knowing likely attack types (C) helps shape specific runbooks, the underlying priority structure is asset-driven. Threat actor analysis (D) informs strategy but is too abstract to anchor a practical playbook.
Topics
Community Discussion
No community discussion yet for this question.