Valid CISM Dumps shared by ExamDiscuss.com for Helping Passing CISM Exam! ExamDiscuss.com now offer the newest CISM exam dumps, the ExamDiscuss.com CISM exam questions have been updated and answers have been corrected get the newest ExamDiscuss.com CISM dumps with Test Engine here:
An information security manager has been tasked with developing materials to update the board, regulatory agencies, and the media about a security incident. Which of the following should the information security manager do FIRST?
Correct Answer: B
Explanation Determining the needs and requirements of each audience should be the FIRST step in developing materials to update the board, regulatory agencies, and the media about a security incident. This is because different audiences have different expectations, interests, and concerns regarding the incident and its impact. By understanding the needs and requirements of each audience, the information security manager can tailor the communication materials to address them effectively and appropriately. This will also help to avoid confusion, misinformation, or misinterpretation of the incident details and response actions
Recent Comments (The most recent comments are at the top.)
ola - Jul 09, 2025
D. Invoke the organization's incident response plan.
Before preparing or sharing any communication, the first step an information security manager should take during a security incident is to invoke the incident response plan (IRP).
The IRP:
Provides a structured approach to handling the incident
Includes roles and responsibilities for communication
Ensures that all actions are coordinated, legally sound, and aligned with company policy
Helps prevent premature or inappropriate disclosure
Communication strategies—including what to say, when, and to whom—are typically defined within the incident response plan, or in a supporting crisis communication plan.
Recent Comments (The most recent comments are at the top.)
D. Invoke the organization's incident response plan.
Before preparing or sharing any communication, the first step an information security manager should take during a security incident is to invoke the incident response plan (IRP).
The IRP:
Provides a structured approach to handling the incident
Includes roles and responsibilities for communication
Ensures that all actions are coordinated, legally sound, and aligned with company policy
Helps prevent premature or inappropriate disclosure
Communication strategies—including what to say, when, and to whom—are typically defined within the incident response plan, or in a supporting crisis communication plan.