Providing the help desk with clear criteria for what constitutes a security incident (C) is the most effective way to enable early recognition. In CISM incident management, frontline functions such as the help desk are critical for early detection and escalation, but only if they understand what events require security attention. Reviewing call logs (A) or participating in post-incident reviews (B) improves awareness after the fact, not recognition in real time. Including help desk staff on the response team (D) is unnecessary and impractical for incident identification. Clearly defined criteria and escalation thresholds empower the help desk to act quickly and consistently. References: ISACA CISM Review Manual (Incident management-incident identification and escalation); CISM Exam Content Outline (Domain 4).