CISM Certified Information Security Manager – Question0092

When developing incident response procedures involving servers hosting critical applications, which of the following should be the FIRST to be notified?

A.
Business management
B. Operations manager
C. Information security manager
D. System users

Correct Answer: C

Explanation:

Explanation: The escalation process in critical situations should involve the information security manager as the first contact so that appropriate escalation steps are invoked as necessary. Choices A, B and D would be notified accordingly.