CISM - Incident Management - Section 4.5

Establish an incident classification and categorisation process to prioritise response activities appropriately.

Establish an incident classification and categorisation scheme that assigns severity levels and drives triage decisions to ensure response resources are directed appropriately. Recognise that consistent, well-defined classification criteria reduce response delays and prevent both under-resourcing of critical incidents and over-escalation of minor events.

Incident classificationSeverity levelsTriageIncident categorisation

Practice question for this objective

Free sampleIncident Managementmedium

An information security manager is establishing a formal incident classification and categorisation process for a new response team. A senior responder argues that experienced analysts can simply judge each incident's importance on its merits, so a documented scheme adds bureaucracy. Which argument best justifies establishing the documented process anyway?

  • AIt guarantees that every reported incident will be resolved within the agreed service-level target regardless of available responder capacity at that moment.
  • BIt removes the need for analyst training because the scheme itself decides the correct technical containment steps for each category of incident.
  • CIt produces consistent, repeatable prioritisation aligned to business impact, so scarce response effort is directed by agreed criteria rather than by individual judgement. Correct
  • DIt satisfies external auditors by demonstrating that the team owns a written procedure, which is the primary reason such a scheme is worth maintaining.
A documented classification scheme exists to make incident prioritisation consistent, repeatable and aligned to business impact rather than individual judgement. Classification translates business impact into agreed severity criteria that every analyst applies the same way, so limited response resources are allocated by governance rather than by who happens to be on shift, which is the management rationale for the process.

Why A is wrong: Tempting because faster resolution is a desired outcome, but classification governs prioritisation, not capacity; it cannot guarantee any resolution time when responders are saturated.

Why B is wrong: Tempting because schemes do route incidents, but categorisation informs handling, it does not replace responder skill or define containment, so training is still essential.

Why C is correct: Correct: a documented scheme makes prioritisation consistent and defensible across analysts and shifts, tying response effort to business impact rather than personal interpretation.

Why D is wrong: Tempting because auditability is a real benefit, but treating audit compliance as the primary purpose mistakes a by-product for the managerial goal of consistent prioritisation.

See more CISM practice questions, answers explained.

More in this domain

Back to all Incident Management objectives, or the CISM cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.