nerdexam
Isaca

CISM · Question #866

Which of the following is the MOST critical requirement to be included in a contract with a third party that provides security incident management?

The correct answer is A. Security incidents have to be reported to the client organization within a specified time frame. The most critical contractual requirement is timely incident reporting to the client within a defined timeframe, because rapid notification is essential for containment, regulatory notification deadlines, coordinated response, and reducing business impact.

Submitted by daniela_cl· Apr 18, 2026Information Security Incident Management

Question

Which of the following is the MOST critical requirement to be included in a contract with a third party that provides security incident management?

Options

  • ASecurity incidents have to be reported to the client organization within a specified time frame.
  • BRoot cause analysis and remediation plans for security incidents have to be provided to the
  • CIncident response team maturity assessment has to be conducted periodically.
  • DA documented policy for incident management has to be approved by senior management.

How the community answered

(26 responses)
  • A
    69% (18)
  • B
    12% (3)
  • C
    4% (1)
  • D
    15% (4)

Explanation

The most critical contractual requirement is timely incident reporting to the client within a defined timeframe, because rapid notification is essential for containment, regulatory notification deadlines, coordinated response, and reducing business impact.

Topics

#Incident Reporting#Third-Party Management#Contractual Requirements#Service Level Agreements

Community Discussion

No community discussion yet for this question.

Full CISM Practice