The correct answer is D because the recovery phase focuses on restoring affected IT services, systems, and operations after containment and eradication have been completed. The objective is to return services to an operational state in a controlled manner while ensuring that the threat has been removed and systems are stable. Recovering business operation support is related to the broader business continuity goal, but the recovery phase of incident management is primarily concerned with restoring IT services and affected environments. Performing a lessons-learned review usually occurs after recovery, during post-incident review or improvement activities. Documenting restoration actions is important for evidence, accountability, and future analysis, but documentation is not the primary objective of recovery. In CISM incident management, recovery includes restoring systems, validating functionality, monitoring for recurrence, and returning operations to normal. Therefore, the primary objective of the recovery phase is to bring IT services back online safely and effectively.
[Reference: CISM Information Security Incident Management; recovery phase, service restoration, post-incident activities, and operational resilience principles., , ]
Submit