nerdexam
Isaca

CISM · Question #279

Which of the following should be the PRIMARY basis for a severity hierarchy for information security incident classification?

The correct answer is A. Adverse effects on the business. The severity of a security incident is fundamentally determined by its potential or actual impact on the organization’s operations, assets, and overall business objectives. Classifying incidents based on the adverse effects they impose ensures that the organization can…

Submitted by chen.hong· Apr 18, 2026Information Security Incident Management

Question

Which of the following should be the PRIMARY basis for a severity hierarchy for information security incident classification?

Options

  • AAdverse effects on the business
  • BRoot cause analysis results
  • CAvailability of resources
  • DLegal and regulatory requirements

How the community answered

(41 responses)
  • A
    90% (37)
  • B
    2% (1)
  • C
    2% (1)
  • D
    5% (2)

Explanation

The severity of a security incident is fundamentally determined by its potential or actual impact on the organization’s operations, assets, and overall business objectives. Classifying incidents based on the adverse effects they impose ensures that the organization can prioritize its response efforts effectively, allocating resources to incidents that pose the greatest threat to business continuity and integrity.

Topics

#Incident Classification#Incident Severity#Business Impact#Incident Management

Community Discussion

No community discussion yet for this question.

Full CISM Practice