CISM Incident Management Practice Question
An information security manager is drafting the incident escalation criteria for the organization's incident response plan. Executive leadership has asked how the team will decide when an incident must be escalated to the crisis management team rather than handled by the technical response team alone. Which of the following is the MOST appropriate basis for defining these escalation thresholds?
⚠ Common exam trap
The trap here is assuming that escalation is driven by technical size or threat actor prestige, when it is actually driven by business impact and the need for executive decision authority.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The potential or actual business impact of the incident on critical services and objectives
Escalation criteria should reflect the consequence to the business, because the crisis management team's purpose is to make strategic decisions and commit resources when critical services, regulatory obligations, or stakeholder trust are at risk. Technical metrics such as system counts, response timing, and attribution describe the incident's mechanics or handling rather than its business significance, so they cannot reliably determine when executive engagement is warranted.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The number of systems or user accounts confirmed to be affected by the incident
Why it's wrong here
Counting affected systems or accounts is a useful technical metric, but it does not by itself indicate whether the organization faces a strategic, reputational, or regulatory crisis. A single compromised executive account can be far more severe than hundreds of infected workstations. Escalation criteria built only on volume would misclassify low-count but high-impact events, so this is not the most appropriate basis.
- ✗
The classification of the threat actor, such as nation-state, organized crime, or insider
Why it's wrong here
Attribution is frequently uncertain during the early hours of an incident and can change as intelligence develops. Basing escalation on who is believed to be responsible introduces delay and inconsistency, and the same actor can cause trivial or catastrophic impact depending on the target. Threat actor classification may inform response, but it is not a sound primary escalation threshold.
- ✗
The elapsed time between initial detection and the first containment action taken by the response team
Why it's wrong here
Detection-to-containment time is a valuable performance metric for measuring response efficiency, but it describes how quickly the team acted, not how severe the event is. A fast containment of a trivial event should not trigger executive escalation, and a slow response to a minor event likewise should not. Using timing as the escalation trigger confuses process performance with business consequence.
- ✓
The potential or actual business impact of the incident on critical services and objectives
Why this is correct
Escalation to the crisis management team exists to mobilize executive decision-making, communications, and resource authority when business objectives or critical services are threatened. Defining thresholds in terms of business impact aligns incident severity with the organization's risk appetite and ensures leadership engages when strategic decisions, regulatory notifications, or customer commitments are at stake.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.