インシデント管理チームは、セキュリティ イベントの疑いがあると警告されます。セキュリティ マネージャーにとって、疑わしいイベントをセキュリティ インシデントとして分類する前に、次のことが最も重要です。
正解:D
= Following the incident response plan is the most important step for the security manager before classifying the suspected event as a security incident, as it provides the guidance and procedures for the incident management team to follow in order to identify, contain, analyze, and resolve security incidents. The incident response plan should define the roles and responsibilities of the incident management team, the criteria and process for incident classification and prioritization, the communication and escalation protocols, the tools and resources for incident handling, and the post-incident review and improvement activities123. References =
1: CISM Review Manual 15th Edition, page 199-2004
2: CISM Practice Quiz, question 1011
3: Computer Security Incident Handling Guide5, page 2-3