Certified Information Security Manager (CISM) — Question 574
When developing an incident escalation process, the BEST approach is to classify incidents based on:
Answer options
- A. their root causes.
- B. information assets affected.
- C. recovery point objectives (RPOs).
- D. estimated time to recover.
Correct answer: B
Explanation
Classifying incidents based on the information assets affected allows for a more targeted response and prioritization of incidents that impact critical assets. Other options, such as root causes or recovery objectives, may not effectively address the immediate needs of incident management and can complicate the escalation process.