CISM Certified Information Security Manager – Question1460

Which of the following metrics is MOST appropriate for evaluating the incident notification process?

A.
Average total cost of downtime per reported incident
B. Average number of incidents per reporting period
C. Elapsed time between response and resolution
D. Elapsed time between detection, reporting and response

Correct Answer: D