CISM - Incident Management - Section 4.7

Deploy and operate incident management tools and techniques to detect, analyse and respond to security events.

Deploy and operate incident management tools including SIEM for centralised log analysis and event correlation, SOAR for automated response orchestration, and forensic tools for evidence collection and analysis. Choose and configure these tools to support the full incident detection and response lifecycle from initial alert through containment.

SIEMSOARForensic toolsIncident detection

Practice question for this objective

Free sampleIncident Managementmedium

An organisation's business impact analysis sets a recovery time objective of two hours for its order-processing system. The incident response plan, however, allows up to six hours of containment and evidence collection before any recovery action is permitted. What is the most significant concern an information security manager should raise about this incident response plan?

  • AThe incident response plan does not name a specific forensic tool for evidence collection during the containment window.
  • BThe incident response plan should remove the containment phase entirely so recovery can begin immediately when an incident is detected.
  • CThe incident response plan should set the recovery time objective itself rather than deferring to the business impact analysis.
  • DThe incident response plan's containment timeline is inconsistent with the recovery time objective set by the business impact analysis. Correct
Reconcile incident response containment timelines with recovery time objectives derived from the business impact analysis. The business impact analysis sets recovery time objectives that the business continuity and disaster recovery plans must meet. If the incident response plan permits a containment window longer than the recovery time objective, recovery cannot start in time and the objective is breached, so the timelines must be aligned.

Why A is wrong: Naming tools is an operational detail; it is tempting because forensics is mentioned, but the absence of a named tool is not the governance problem the recovery timeline creates.

Why B is wrong: Skipping containment is tempting as a way to meet the deadline, but it risks reinfection and loss of evidence; the fix is to reconcile the timelines, not abandon a necessary phase.

Why C is wrong: Recovery time objectives are derived from the business impact analysis, not authored by the incident response plan; reversing that ownership misplaces accountability for business-driven targets.

Why D is correct: A six-hour containment window cannot satisfy a two-hour recovery time objective; the incident response plan must be reconciled with the business impact analysis so containment does not breach agreed recovery commitments.

See more CISM practice questions, answers explained.

More in this domain

Back to all Incident Management objectives, or the CISM cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.