CISM · Question #866
Which of the following is the MOST critical requirement to be included in a contract with a third party that provides security incident management?
The correct answer is A. Security incidents have to be reported to the client organization within a specified time frame. The most critical contractual requirement is timely incident reporting to the client within a defined timeframe, because rapid notification is essential for containment, regulatory notification deadlines, coordinated response, and reducing business impact.
Question
Which of the following is the MOST critical requirement to be included in a contract with a third party that provides security incident management?
Options
- ASecurity incidents have to be reported to the client organization within a specified time frame.
- BRoot cause analysis and remediation plans for security incidents have to be provided to the
- CIncident response team maturity assessment has to be conducted periodically.
- DA documented policy for incident management has to be approved by senior management.
How the community answered
(26 responses)- A69% (18)
- B12% (3)
- C4% (1)
- D15% (4)
Explanation
The most critical contractual requirement is timely incident reporting to the client within a defined timeframe, because rapid notification is essential for containment, regulatory notification deadlines, coordinated response, and reducing business impact.
Topics
Community Discussion
No community discussion yet for this question.