nerdexam
Isaca

CISM · Question #661

Which of the following is MOST appropriate for an organization to consider when defining incident classification and categorization levels?

The correct answer is D. Incident impact. Classification and categorization levels determine how an incident is prioritized and how resources are allocated in response. Incident impact - the actual or potential harm to confidentiality, integrity, availability, financial standing, or reputation - is the most appropriate…

Submitted by amina.ke· Apr 18, 2026Information Security Incident Management

Question

Which of the following is MOST appropriate for an organization to consider when defining incident classification and categorization levels?

Options

  • AMaturity of incident response activities
  • BThreat environment
  • CQuantity of impacted assets
  • DIncident impact

How the community answered

(21 responses)
  • A
    5% (1)
  • B
    10% (2)
  • D
    86% (18)

Explanation

Classification and categorization levels determine how an incident is prioritized and how resources are allocated in response. Incident impact - the actual or potential harm to confidentiality, integrity, availability, financial standing, or reputation - is the most appropriate basis for these levels. It directly determines the urgency and severity of response. IR maturity (A) affects capability, not classification criteria. The threat environment (B) informs risk posture broadly. The number of impacted assets (C) is one element of impact but is too narrow on its own.

Topics

#Incident Classification#Incident Categorization#Incident Impact

Community Discussion

No community discussion yet for this question.

Full CISM Practice