CISM · Question #469
Which of the following is the MOST important information to report to senior management after a significant security incident?
The correct answer is B. The impact and corrective actions taken. Senior management needs to understand the business impact of the incident (financial loss, data exposure, operational disruption, reputational harm) and what corrective actions are being taken to remediate it and prevent recurrence. This information supports executive…
Question
Which of the following is the MOST important information to report to senior management after a significant security incident?
Options
- AList of similar attacks from the previous period
- BThe impact and corrective actions taken
- CVulnerability scanning and penetration test results
- DUpdated inherent risk levels
How the community answered
(47 responses)- A2% (1)
- B81% (38)
- C11% (5)
- D6% (3)
Explanation
Senior management needs to understand the business impact of the incident (financial loss, data exposure, operational disruption, reputational harm) and what corrective actions are being taken to remediate it and prevent recurrence. This information supports executive decision-making and stakeholder communication. A list of similar past attacks (A) is historical context, not actionable intelligence. Penetration test results (C) are technical details irrelevant to the immediate incident discussion. Updated inherent risk levels (D) are a risk management metric, not an incident-specific communication. Impact and corrective actions directly address the 'what happened' and 'what are we doing about it' questions executives need answered.
Topics
Community Discussion
No community discussion yet for this question.