CISM Incident Management Practice Question
A security manager is defining the incident classification scheme for a multinational retailer. Executive leadership wants to know which incidents will trigger a formal crisis management team (CMT) activation. Which criterion should PRIMARILY determine whether an incident is classified as a crisis-level event?
⚠ Common exam trap
The trap here is assuming that technical severity or asset criticality automatically equals crisis status, when CISM ties crisis classification to realized or potential business impact.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The incident has the potential to cause significant harm to the organization's brand, finances, or regulatory standing.
Crisis-level classification hinges on the potential for enterprise-wide harm to reputation, finances, operations, or regulatory compliance. This impact-based threshold ensures the CMT is convened only when executive authority, cross-functional coordination, and external stakeholder management are genuinely required. Detection source, staffing needs, and asset criticality labels are useful inputs but cannot by themselves indicate that an incident has crossed the crisis threshold.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The incident requires more than one analyst to investigate and remediate within the standard service-level agreement.
Why it's wrong here
Staffing demand reflects resource requirements, not crisis status. Many moderate incidents require several analysts yet remain fully manageable by the incident response team under normal escalation. Tying crisis activation to headcount would pull executives into routine events, diluting the CMT's effectiveness and delaying the strategic decisions it exists to make during genuinely enterprise-threatening situations.
- ✗
The incident was detected by the security operations center (SOC) outside of normal business hours.
Why it's wrong here
Detection timing is an operational detail, not a severity determinant. A phishing email quarantined at 2 a.m. is trivial; a payment-system outage discovered at noon may be a crisis. Using time of detection as the trigger would misclassify incidents in both directions and confuse escalation procedures with impact assessment, which is precisely the distinction CISM expects incident managers to maintain.
- ✓
The incident has the potential to cause significant harm to the organization's brand, finances, or regulatory standing.
Why this is correct
Crisis classification is driven by potential enterprise-level impact, spanning brand reputation, financial loss, legal or regulatory exposure, and continuity of critical services. When an incident threatens these dimensions beyond the tolerance defined by executive management, the CMT must be activated because response now requires cross-functional executive authority, external communications, and strategic decision-making rather than technical containment alone.
- ✗
The incident affects a system that is listed in the configuration management database (CMDB) as business-critical.
Why it's wrong here
A CMDB criticality flag is an input to impact assessment, not the trigger itself. Many business-critical systems can suffer contained incidents that never warrant CMT activation, and conversely a low-criticality system can cause enterprise-wide reputational harm. Classification must rest on realized business impact, so this criterion alone is insufficient and would produce both over- and under-activation of the crisis team.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.