nerdexam
Isaca

CISM · Question #402

An incident response policy should include:

The correct answer is C. notification requirements.. An incident response policy should include notification requirements. These requirements ensure that the right stakeholders are promptly informed about the incident, which is crucial for coordinating an effective response and mitigating damage. Clear communication protocols help

Submitted by sofia.br· Apr 18, 2026Information Security Incident Management

Question

An incident response policy should include:

Options

  • Arecovery time objectives (RTOs).
  • Ban infrastructure diagram.
  • Cnotification requirements.
  • Da description of testing methodology.

How the community answered

(56 responses)
  • B
    4% (2)
  • C
    95% (53)
  • D
    2% (1)

Explanation

An incident response policy should include notification requirements. These requirements ensure that the right stakeholders are promptly informed about the incident, which is crucial for coordinating an effective response and mitigating damage. Clear communication protocols help facilitate timely decision-making and ensure compliance with legal or regulatory obligations.

Topics

#Incident Response Policy#Notification Requirements#Incident Management#Policy Components

Community Discussion

No community discussion yet for this question.

Full CISM Practice