CISM - Incident Management - Section 4.8

Investigate and evaluate information security incidents in accordance with legal and regulatory requirements.

Investigate information security incidents using digital forensics techniques and evidence preservation procedures that maintain a documented chain of custody. Recognise how legal requirements and regulatory obligations shape the scope, documentation standards, and permissible evidence-handling methods during an investigation.

Digital forensicsEvidence preservationChain of custodyLegal requirements

Practice question for this objective

Free sampleIncident Managementhard

An information security manager is setting up an investigation capability so that any incident which might involve regulators or prosecution is handled defensibly from the outset. Several drivers compete for attention. Which one should most strongly shape how the investigation is conducted before responders touch any evidence?

  • AThe technical preferences of the forensic team for the imaging and analysis tooling they are most experienced and comfortable using day to day.
  • BThe speed with which the affected systems can be returned to normal production so that the business disruption from the incident is minimised.
  • CThe expectations of senior executives who want a clear narrative of what happened delivered to the board as quickly as the team can produce it.
  • DThe legal and regulatory requirements applicable to the incident, established with counsel before evidence is handled and used to govern the procedures. Correct
Investigations that may involve regulators or prosecution must be governed first by the applicable legal and regulatory requirements, established with counsel before any evidence is handled. Admissibility and regulatory acceptance depend on meeting external legal standards, not internal convenience. Establishing those requirements with counsel up front lets every handling decision be measured against the standard the relevant authority will ultimately apply.

Why A is wrong: Tool familiarity speeds the work, but choosing the approach around team comfort can produce evidence handling that fails the legal tests an outside authority will apply.

Why B is wrong: Fast restoration matters to the business, yet prioritising it can overwrite or destroy evidence and undermine any later regulatory or criminal proceeding.

Why C is wrong: Executive demand for a quick narrative is real, but letting reporting pressure drive the method risks shortcuts that compromise evidence and the eventual legal position.

Why D is correct: Defining the applicable legal and regulatory requirements first, with counsel, sets the standards every later handling step must meet, which is what makes the investigation defensible.

See more CISM practice questions, answers explained.

More in this domain

Back to all Incident Management objectives, or the CISM cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.