A security manager is drafting the incident response plan and must specify how the organization will communicate with regulators, law enforcement, and the media during a high-severity breach. The chief information security officer (CISO) wants to ensure that all external communications are coordinated, legally defensible, and consistent. Which of the following should the CISO require FIRST to meet this objective?
A single pre-authorized spokesperson with a defined approval chain ensures consistent, legally reviewed messaging and prevents conflicting statements to regulators, law enforcement, and media. This directly addresses the CISO's need for coordinated and defensible external communications before, during, and after a high-severity breach, and it aligns with CISM guidance on incident communication roles and escalation paths.
Why this answer
Coordinated external communication during a high-severity breach requires a single pre-authorized spokesperson and a defined approval chain. This ensures messages to regulators, law enforcement, and media are consistent, legally reviewed, and technically accurate. Empowering everyone to speak or relying solely on one department creates confusion, legal exposure, and inconsistent messaging that can worsen the incident's impact.
Exam trap
The trap here is assuming that faster, decentralized communication is always better, when uncontrolled external statements during a breach often create legal and reputational harm.