An information security manager is establishing a formal incident classification and categorisation process for a new response team. A senior responder argues that experienced analysts can simply judge each incident's importance on its merits, so a documented scheme adds bureaucracy. Which argument best justifies establishing the documented process anyway?
- AIt guarantees that every reported incident will be resolved within the agreed service-level target regardless of available responder capacity at that moment.
- BIt removes the need for analyst training because the scheme itself decides the correct technical containment steps for each category of incident.
- CIt produces consistent, repeatable prioritisation aligned to business impact, so scarce response effort is directed by agreed criteria rather than by individual judgement. Correct
- DIt satisfies external auditors by demonstrating that the team owns a written procedure, which is the primary reason such a scheme is worth maintaining.
Why A is wrong: Tempting because faster resolution is a desired outcome, but classification governs prioritisation, not capacity; it cannot guarantee any resolution time when responders are saturated.
Why B is wrong: Tempting because schemes do route incidents, but categorisation informs handling, it does not replace responder skill or define containment, so training is still essential.
Why C is correct: Correct: a documented scheme makes prioritisation consistent and defensible across analysts and shifts, tying response effort to business impact rather than personal interpretation.
Why D is wrong: Tempting because auditability is a real benefit, but treating audit compliance as the primary purpose mistakes a by-product for the managerial goal of consistent prioritisation.