CISM - Incident Management (30% of the exam) - Section 4.5

Establish an incident classification and categorisation process to prioritise response activities appropriately.

Establish an incident classification and categorisation scheme that assigns severity levels and drives triage decisions to ensure response resources are directed appropriately. Recognise that consistent, well-defined classification criteria reduce response delays and prevent both under-resourcing of critical incidents and over-escalation of minor events.

Incident classificationSeverity levelsTriageIncident categorisation

Practice question for this objective

Free sampleIncident Managementmedium

An information security manager is establishing a formal incident classification and categorisation process for a new response team. A senior responder argues that experienced analysts can simply judge each incident's importance on its merits, so a documented scheme adds bureaucracy. Which argument best justifies establishing the documented process anyway?

  • AIt guarantees that every reported incident will be resolved within the agreed service-level target regardless of available responder capacity at that moment.
  • BIt removes the need for analyst training because the scheme itself decides the correct technical containment steps for each category of incident.
  • CIt produces consistent, repeatable prioritisation aligned to business impact, so scarce response effort is directed by agreed criteria rather than by individual judgement. Correct
  • DIt satisfies external auditors by demonstrating that the team owns a written procedure, which is the primary reason such a scheme is worth maintaining.
A documented classification scheme exists to make incident prioritisation consistent, repeatable and aligned to business impact rather than individual judgement. Classification translates business impact into agreed severity criteria that every analyst applies the same way, so limited response resources are allocated by governance rather than by who happens to be on shift, which is the management rationale for the process.

Why A is wrong: Tempting because faster resolution is a desired outcome, but classification governs prioritisation, not capacity; it cannot guarantee any resolution time when responders are saturated.

Why B is wrong: Tempting because schemes do route incidents, but categorisation informs handling, it does not replace responder skill or define containment, so training is still essential.

Why C is correct: Correct: a documented scheme makes prioritisation consistent and defensible across analysts and shifts, tying response effort to business impact rather than personal interpretation.

Why D is wrong: Tempting because auditability is a real benefit, but treating audit compliance as the primary purpose mistakes a by-product for the managerial goal of consistent prioritisation.

See more CISM practice questions, answers explained.

Exam traps in Incident Management

Answers that look right on this material and are not. Each one is a distractor from a different question in the CISM bank for this domain.

  • A requirement that the on-call manager personally approve every severity rating before an analyst proceeds

    Why it is wrong: Manager sign-off adds a control and may feel like rigour, but it creates a bottleneck and still leaves the rating subjective, so it does not address the root cause of inconsistent judgement.

  • The number of distinct security tools that generated alerts relating to the event

    Why it is wrong: A high alert count can feel significant and may correlate with noise, but tool volume reflects detection coverage and tuning rather than the harm to the organisation, so it is a poor basis for severity.

  • Require the analyst to use professional judgement each time and escalate only when personally confident that the incident is genuinely severe.

    Why it is wrong: Tempting because it respects analyst expertise, but relying solely on individual judgement produces inconsistent escalation, especially for junior staff under pressure, and risks both over- and under-reporting.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.