nerdexam
Isaca

CISM · Question #332

The MOST important input for determining the severity of an incident is provided by the organization's:

The correct answer is C. risk evaluation results. Risk evaluation results identify which assets are critical, the magnitude of potential harm, and the likelihood of various threats materializing. This information directly determines how severe an incident is relative to what the organization has already analyzed and…

Submitted by rania.sa· Apr 18, 2026Information Security Risk Management

Question

The MOST important input for determining the severity of an incident is provided by the organization's:

Options

  • Abusiness continuity policy.
  • Bcompliance requirements.
  • Crisk evaluation results.
  • Drisk tolerance.

How the community answered

(36 responses)
  • A
    3% (1)
  • B
    8% (3)
  • C
    75% (27)
  • D
    14% (5)

Explanation

Risk evaluation results identify which assets are critical, the magnitude of potential harm, and the likelihood of various threats materializing. This information directly determines how severe an incident is relative to what the organization has already analyzed and documented. Business continuity policy (A) guides recovery priorities but does not classify incident severity. Compliance requirements (B) may set some thresholds but are not a comprehensive basis for severity. Risk tolerance (D) is an output of risk management used for decision-making; it is informed by evaluation results, making the evaluation results the more foundational input.

Topics

#Incident Severity#Risk Evaluation#Impact Assessment#Risk Management

Community Discussion

No community discussion yet for this question.

Full CISM Practice