An organisation's business impact analysis sets a recovery time objective of two hours for its order-processing system. The incident response plan, however, allows up to six hours of containment and evidence collection before any recovery action is permitted. What is the most significant concern an information security manager should raise about this incident response plan?
- AThe incident response plan does not name a specific forensic tool for evidence collection during the containment window.
- BThe incident response plan should remove the containment phase entirely so recovery can begin immediately when an incident is detected.
- CThe incident response plan should set the recovery time objective itself rather than deferring to the business impact analysis.
- DThe incident response plan's containment timeline is inconsistent with the recovery time objective set by the business impact analysis. Correct
Why A is wrong: Naming tools is an operational detail; it is tempting because forensics is mentioned, but the absence of a named tool is not the governance problem the recovery timeline creates.
Why B is wrong: Skipping containment is tempting as a way to meet the deadline, but it risks reinfection and loss of evidence; the fix is to reconcile the timelines, not abandon a necessary phase.
Why C is wrong: Recovery time objectives are derived from the business impact analysis, not authored by the incident response plan; reversing that ownership misplaces accountability for business-driven targets.
Why D is correct: A six-hour containment window cannot satisfy a two-hour recovery time objective; the incident response plan must be reconciled with the business impact analysis so containment does not breach agreed recovery commitments.