CISM - Incident Management (30% of the exam) - Section 4.8

Investigate and evaluate information security incidents in accordance with legal and regulatory requirements.

Investigate information security incidents using digital forensics techniques and evidence preservation procedures that maintain a documented chain of custody. Recognise how legal requirements and regulatory obligations shape the scope, documentation standards, and permissible evidence-handling methods during an investigation.

Digital forensicsEvidence preservationChain of custodyLegal requirements

Practice question for this objective

Free sampleIncident Managementhard

An information security manager is setting up an investigation capability so that any incident which might involve regulators or prosecution is handled defensibly from the outset. Several drivers compete for attention. Which one should most strongly shape how the investigation is conducted before responders touch any evidence?

  • AThe technical preferences of the forensic team for the imaging and analysis tooling they are most experienced and comfortable using day to day.
  • BThe speed with which the affected systems can be returned to normal production so that the business disruption from the incident is minimised.
  • CThe expectations of senior executives who want a clear narrative of what happened delivered to the board as quickly as the team can produce it.
  • DThe legal and regulatory requirements applicable to the incident, established with counsel before evidence is handled and used to govern the procedures. Correct
Investigations that may involve regulators or prosecution must be governed first by the applicable legal and regulatory requirements, established with counsel before any evidence is handled. Admissibility and regulatory acceptance depend on meeting external legal standards, not internal convenience. Establishing those requirements with counsel up front lets every handling decision be measured against the standard the relevant authority will ultimately apply.

Why A is wrong: Tool familiarity speeds the work, but choosing the approach around team comfort can produce evidence handling that fails the legal tests an outside authority will apply.

Why B is wrong: Fast restoration matters to the business, yet prioritising it can overwrite or destroy evidence and undermine any later regulatory or criminal proceeding.

Why C is wrong: Executive demand for a quick narrative is real, but letting reporting pressure drive the method risks shortcuts that compromise evidence and the eventual legal position.

Why D is correct: Defining the applicable legal and regulatory requirements first, with counsel, sets the standards every later handling step must meet, which is what makes the investigation defensible.

See more CISM practice questions, answers explained.

Exam traps in Incident Management

Answers that look right on this material and are not. Each one is a distractor from a different question in the CISM bank for this domain.

  • Encryption of the seized media so that its contents cannot be altered while it is stored before collection.

    Why it is wrong: Encryption protects confidentiality and feels rigorous, but it does not prove who handled the media or that contents were unchanged, which is what a court must establish.

  • Shut the system down cleanly so the disk can be imaged without interference

    Why it is wrong: A clean shutdown feels orderly, but it destroys volatile memory and may trigger anti-forensic routines, losing evidence that only exists while powered on.

  • Restricting access to the analysis room so that only named members of the investigation team can enter while the work is under way.

    Why it is wrong: Access restriction supports security, but a controlled room alone does not prove the bytes are unchanged and cannot answer a technical challenge to data integrity.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.