Certified Information Security Manager (CISM) — Question 146
An information security manager has been tasked with developing materials to update the board, regulatory agencies, and the media about a security incident.
Which of the following should the information security manager do FIRST?
Answer options
- A. Invoke the organization's incident response plan.
- B. Set up communication channels for the target audience.
- C. Create a comprehensive singular communication.
- D. Determine the needs and requirements of each audience.
Correct answer: D
Explanation
The correct answer is D because understanding the needs and requirements of each audience is essential for effective communication. This step ensures that the information provided is relevant and appropriately tailored. The other options, while important, should come after identifying the audience's needs.