nerdexam
Isaca

CISM · Question #41

When developing a categorization method for security incidents, the categories MUST:

The correct answer is C. have agreed-upon definitions. When developing security incident categorization, categories must have agreed-upon definitions to ensure consistent understanding, accurate classification, and effective response across the organization.

Submitted by helene.fr· Apr 18, 2026Information Security Incident Management

Question

When developing a categorization method for security incidents, the categories MUST:

Options

  • Abe created by the incident hander.
  • Balign with reporting requirements.
  • Chave agreed-upon definitions.
  • Dalign with industry standards.

How the community answered

(21 responses)
  • B
    5% (1)
  • C
    90% (19)
  • D
    5% (1)

Why each option

When developing security incident categorization, categories must have agreed-upon definitions to ensure consistent understanding, accurate classification, and effective response across the organization.

Abe created by the incident hander.

While incident handlers provide valuable input, categories should be developed collaboratively with management and other stakeholders, not solely by the handler.

Balign with reporting requirements.

Aligning with reporting requirements is important, but a prerequisite for this alignment is having clear definitions for the categories themselves.

Chave agreed-upon definitions.Correct

For incident categorization to be effective, consistent, and actionable, each category must have clear, unambiguous, and agreed-upon definitions. This ensures all incident responders and stakeholders classify incidents uniformly, leading to accurate metrics, reporting, and resource allocation.

Dalign with industry standards.

Aligning with industry standards can be beneficial for benchmarking, but the fundamental requirement is internal clarity and consistency through agreed-upon definitions.

Concept tested: Incident categorization principles

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf

Topics

#Incident Categorization#Incident Management Process#Data Consistency#Standardization

Community Discussion

No community discussion yet for this question.

Full CISM Practice