nerdexam
Isaca

CISM · Question #469

Which of the following is the MOST important information to report to senior management after a significant security incident?

The correct answer is B. The impact and corrective actions taken. Senior management needs to understand the business impact of the incident (financial loss, data exposure, operational disruption, reputational harm) and what corrective actions are being taken to remediate it and prevent recurrence. This information supports executive…

Submitted by eva_at· Apr 18, 2026Information Security Incident Management

Question

Which of the following is the MOST important information to report to senior management after a significant security incident?

Options

  • AList of similar attacks from the previous period
  • BThe impact and corrective actions taken
  • CVulnerability scanning and penetration test results
  • DUpdated inherent risk levels

How the community answered

(47 responses)
  • A
    2% (1)
  • B
    81% (38)
  • C
    11% (5)
  • D
    6% (3)

Explanation

Senior management needs to understand the business impact of the incident (financial loss, data exposure, operational disruption, reputational harm) and what corrective actions are being taken to remediate it and prevent recurrence. This information supports executive decision-making and stakeholder communication. A list of similar past attacks (A) is historical context, not actionable intelligence. Penetration test results (C) are technical details irrelevant to the immediate incident discussion. Updated inherent risk levels (D) are a risk management metric, not an incident-specific communication. Impact and corrective actions directly address the 'what happened' and 'what are we doing about it' questions executives need answered.

Topics

#Incident Reporting#Senior Management Communication#Incident Response

Community Discussion

No community discussion yet for this question.

Full CISM Practice