The correct answer is C because incident categorization directly influences how efficiently the organization responds immediately after detection. Categorization helps determine the type of incident, severity, priority, required resources, escalation path, communication requirements, and expected response procedure. Without quick and accurate categorization, responders may waste time deciding who should act, how urgent the situation is, and what containment actions are appropriate. Containment and mitigation are critical response activities, but they depend on proper categorization and prioritization. Root cause analysis is normally performed later to determine why the incident occurred and how to prevent recurrence. Lessons learned are also post-incident activities used to improve future response. CISM incident management emphasizes that detected incidents should be analyzed, classified, prioritized, and escalated based on impact and urgency. This allows the organization to apply the right response playbook quickly and use resources effectively. Therefore, incident categorization most directly improves response efficiency immediately after detection.
[Reference: CISM Information Security Incident Management; incident categorization, classification, prioritization, escalation, and response efficiency principles., , ]
Submit