CISM Certified Information Security Manager – Question1321

Which of the following is the MOST important factor to consider when establishing a severity hierarchy for information security incidents?

A.
Regulatory compliance
B. Business impact
C. Management support
D. Residual risk

Correct Answer: B