Courseiva
Incident Management →mediumMultiple Choice

CISM Incident Management Practice Question

A security manager is drafting the incident response plan and needs to define how the organization will classify and escalate incidents. Executive leadership wants assurance that high-impact incidents reach the right decision-makers quickly. Which of the following should the security manager do FIRST to establish effective incident classification and escalation?

⚠ Common exam trap

The trap here is assuming that acquiring detection tooling or notifying executives broadly constitutes incident classification and escalation, when the foundational step is defining business-impact-based severity levels and their mapped escalation paths.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Define severity levels based on business impact criteria and map each level to a defined escalation path and notification timeframe.

Effective incident classification starts with business impact criteria, because severity must reflect consequences to the organization rather than technical indicators alone. Once severity levels are defined, each must be tied to a specific escalation path and notification timeframe so that executives are engaged promptly for high-impact events. This governance-first approach creates a consistent, repeatable basis for triage and escalation before any tooling or operational detail is layered on top.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Purchase a security information and event management (SIEM) platform with automated alert correlation and threat intelligence feeds.

    Why it's wrong here

    A SIEM improves detection and correlation but does not by itself define how incidents are classified or escalated to leadership. Buying tooling before agreeing on severity criteria and escalation paths leaves the organization with abundant alerts and no consistent decision framework. The question asks what to do first to establish classification and escalation, which is a governance and process design activity, not a technology acquisition.

  • ✗

    Ask each business unit to independently define its own incident severity scale and reporting thresholds.

    Why it's wrong here

    Independent severity scales across business units produce inconsistent classification, making enterprise-wide prioritization and reporting impossible. During a cross-functional incident, responders would disagree on severity and escalation, delaying response. Effective classification requires a single enterprise framework aligned to overall business impact, with business units contributing input rather than each defining separate, incompatible scales.

  • ✗

    Instruct the incident response team to notify the board of directors for every confirmed security event regardless of impact.

    Why it's wrong here

    Notifying the board for every event creates alert fatigue and dilutes attention from genuinely material incidents. Escalation should be tiered so that low-severity events are handled operationally while high-severity events reach executives. This approach also conflicts with the goal of timely, meaningful executive engagement because it floods leadership with immaterial information and slows decision-making during real crises.

  • ✓

    Define severity levels based on business impact criteria and map each level to a defined escalation path and notification timeframe.

    Why this is correct

    Classification must be anchored to business impact so that severity reflects real consequences rather than technical symptoms alone. Mapping each severity level to a specific escalation path and timeframe ensures executives are engaged consistently and quickly for high-impact events. This creates a repeatable, auditable decision structure that satisfies leadership's need for timely notification and gives responders clear triage guidance.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.