Q: 15
Which of the following is the MOST important reason to document information security incidents
that are reported across the organization?
Options
Discussion
B , ISACA always dances around risk in every domain so I'd argue documenting incidents is mostly about identifying unmitigated risks too. Yeah, recurrence matters but those risks drive so much of what management cares about. Maybe I'm overthinking it.
B , since identifying unmitigated risk is usually what drives follow-up actions in real orgs.
Totally agree with C. The main goal is stopping future incidents by learning from what happened. A and B matter too, but preventing recurrence is usually the top driver for detailed documentation in most frameworks I've seen. Anyone think otherwise?
C here. Documenting incidents mainly helps us figure out what went wrong so we can stop it happening again. The others are good benefits but not the main reason in most best practices, I think. Agree?
Be respectful. No spam.
Question 15 of 35