nerdexam
Isaca

CISM · Question #69

Which of the following should be updated FIRST when aligning the incident response plan with the corporate strategy?

The correct answer is D. Risk response scenarios. When aligning an incident response plan with corporate strategy, the first step is to update the risk response scenarios.

Submitted by anna_se· Apr 18, 2026Information Security Risk Management

Question

Which of the following should be updated FIRST when aligning the incident response plan with the corporate strategy?

Options

  • ASecurity procedures
  • BDisaster recovery plan (DRP)
  • CIncident notification plan
  • DRisk response scenarios

How the community answered

(22 responses)
  • A
    5% (1)
  • B
    14% (3)
  • C
    18% (4)
  • D
    64% (14)

Why each option

When aligning an incident response plan with corporate strategy, the first step is to update the risk response scenarios.

ASecurity procedures

Security procedures detail the 'how-to' of incident response; they should be updated after the strategic risk response scenarios are defined.

BDisaster recovery plan (DRP)

The Disaster Recovery Plan (DRP) addresses broader recovery from major disruptions and is a separate, though related, plan that relies on the foundational risk appetite defined by corporate strategy.

CIncident notification plan

The incident notification plan specifies who gets informed and when, which is a procedural element determined by the nature of the incident and its strategic impact as defined by risk response scenarios.

DRisk response scenariosCorrect

When aligning an incident response plan with corporate strategy, updating risk response scenarios should be the first step because the corporate strategy dictates the organization's overall risk appetite and how it prioritizes responses to various threats. These scenarios directly reflect the business's tolerance for different types of incidents and guide the specific actions and priorities within the incident response framework, ensuring alignment with overarching business objectives.

Concept tested: Incident response strategic alignment

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf

Topics

#Incident Response Planning#Corporate Strategy Alignment#Risk Response#Information Security Governance

Community Discussion

No community discussion yet for this question.

Full CISM Practice