CISM · Question #41
When developing a categorization method for security incidents, the categories MUST:
The correct answer is C. have agreed-upon definitions. When developing security incident categorization, categories must have agreed-upon definitions to ensure consistent understanding, accurate classification, and effective response across the organization.
Question
When developing a categorization method for security incidents, the categories MUST:
Options
- Abe created by the incident hander.
- Balign with reporting requirements.
- Chave agreed-upon definitions.
- Dalign with industry standards.
How the community answered
(21 responses)- B5% (1)
- C90% (19)
- D5% (1)
Why each option
When developing security incident categorization, categories must have agreed-upon definitions to ensure consistent understanding, accurate classification, and effective response across the organization.
While incident handlers provide valuable input, categories should be developed collaboratively with management and other stakeholders, not solely by the handler.
Aligning with reporting requirements is important, but a prerequisite for this alignment is having clear definitions for the categories themselves.
For incident categorization to be effective, consistent, and actionable, each category must have clear, unambiguous, and agreed-upon definitions. This ensures all incident responders and stakeholders classify incidents uniformly, leading to accurate metrics, reporting, and resource allocation.
Aligning with industry standards can be beneficial for benchmarking, but the fundamental requirement is internal clarity and consistency through agreed-upon definitions.
Concept tested: Incident categorization principles
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf
Topics
Community Discussion
No community discussion yet for this question.