Courseiva
hardMultiple ChoiceObjective-mapped

CISM Is developing an incident response plan Practice Question

An organization is developing an incident response plan. The CISO wants to ensure that the plan aligns with industry best practices. Which framework should the CISO use as a primary reference?

⚠ Common exam trap

Many candidates confuse the NIST Cybersecurity Framework (a broad risk management tool) with NIST SP 800-61 (the specific incident response standard), or they mistakenly think ITIL's 'incident management' covers security incidents when it is designed for IT service disruptions, not security breaches.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

NIST SP 800-61

NIST SP 800-61 (Computer Security Incident Handling Guide) is the definitive U.S. government standard for incident response processes, covering preparation, detection, containment, eradication, and recovery. It provides detailed, step-by-step guidance for building an incident response plan, making it the primary reference for aligning with industry best practices.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ISO 31000

    Why it's wrong here

    ISO 31000 is for risk management, not incident response.

  • NIST Cybersecurity Framework

    Why it's wrong here

    The CSF includes incident response but is broader; SP 800-61 is more detailed for incident handling.

  • ITIL

    Why it's wrong here

    ITIL focuses on service management, not incident response specifics.

  • NIST SP 800-61

    Why this is correct

    NIST SP 800-61 is the standard for computer security incident handling.

About these practice questions

This CISM question is part of Courseiva's 871-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.