CISM · Question #956
Which of the following BEST enables the design of an effective incident escalation process?
The correct answer is D. A well-defined organizational hierarchy. A well-defined organizational hierarchy directly enables incident escalation by establishing clear reporting lines, defined roles, and decision-making authority at each level - without this structure, there is no reliable path for routing incidents to the right people at the…
Question
Which of the following BEST enables the design of an effective incident escalation process?
Options
- AControls designed for defense in depth
- BA comprehensive risk register
- CEnforceable control baselines
- DA well-defined organizational hierarchy
How the community answered
(34 responses)- A6% (2)
- B15% (5)
- C3% (1)
- D76% (26)
Explanation
A well-defined organizational hierarchy directly enables incident escalation by establishing clear reporting lines, defined roles, and decision-making authority at each level - without this structure, there is no reliable path for routing incidents to the right people at the right time. Defense in depth (A) is a layered preventive/detective control strategy that reduces attack surface and blast radius, but it addresses how systems are protected, not how incidents are escalated. A risk register (B) catalogs risks and their treatments, making it a planning tool rather than a process-routing mechanism. Enforceable control baselines (C) define minimum security requirements across systems, which governs what controls exist, not who gets notified and in what order when those controls fail.
Memory tip: Think of escalation as "climbing a ladder" - you must know what the ladder looks like before you can climb it. Only option D builds the ladder (hierarchy); the other three options describe what you put on the rungs (controls, risk data, baselines).
Topics
Community Discussion
No community discussion yet for this question.