CISM - Incident Management - Section 4.10

Manage incident response communications including reporting, notification and escalation to internal and external parties.

Manage incident communications by meeting notification obligations to regulators, affected parties, and internal stakeholders, and by executing escalation procedures to engage the right decision-makers at the right time. Distinguish between regulatory reporting deadlines - which are legally mandated - and internal stakeholder communication, which should be timely but allows more flexibility.

Notification obligationsEscalationRegulatory reportingStakeholder communication

Practice question for this objective

Free sampleIncident Managementmedium

During a confirmed data breach, technical responders, the corporate communications team and a business unit manager each begin contacting affected customers and a regulator with their own versions of events. The information security manager wants external communications during incidents to be authoritative and consistent. Which arrangement should the incident response plan define to achieve this?

  • AA requirement that each affected business unit notify its own customers promptly using the wording it judges most reassuring to its relationships
  • BA standing instruction that the technical responders publish factual status updates directly, since they hold the most accurate view of the incident
  • CA single approval authority and designated spokesperson channel through which all external incident communications must be cleared before release Correct
  • DA rule that no external party is told anything until the forensic investigation has fully closed and every fact is verified
Incident response plans should route all external incident communications through a single approval authority and spokesperson to keep them consistent and defensible. Inconsistent external messages during an incident create legal, regulatory and reputational risk. Channelling all communications through one approving authority and a designated spokesperson ensures statements are reviewed, accurate and aligned before release.

Why A is wrong: Devolving wording to business units feels responsive and customer-friendly, but it produces conflicting, unreviewed messages that create legal exposure and undermine the credibility of the organisation's response.

Why B is wrong: Responders do hold the freshest technical detail, but raw technical updates released without legal and communications review can disclose unconfirmed facts and create obligations the organisation cannot yet meet.

Why C is correct: Routing every external message through one approval authority and spokesperson keeps notifications consistent, legally reviewed and aligned with the organisation's position, which is the governance control for incident communications.

Why D is wrong: Waiting for full certainty seems prudent and avoids errors, but it ignores mandatory notification deadlines and stakeholder duties that often require communication well before an investigation closes.

See more CISM practice questions, answers explained.

More in this domain

Back to all Incident Management objectives, or the CISM cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.