CISM Incident Management Practice Question
An organization is reviewing its incident response plan after a prolonged outage caused by a coordinated attack. Management wants to improve the organization's ability to communicate effectively during future incidents. Which TWO of the following should be included in the incident communication plan? (Choose two.)
⚠ Common exam trap
The trap here is equating more communication with better communication, leading to choices that over-share, over-centralize, or collect unnecessary personal data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Predefined communication templates for different stakeholder groups and incident types
An effective incident communication plan includes prepared templates for different audiences and incidents, plus designated spokespersons with clear approval workflows. Templates speed response and ensure consistency, while spokesperson designation and approval controls prevent unauthorized or harmful statements. Collecting personal contact data, mandating real-time technical disclosure, or centralizing all communication in one executive do not constitute sound communication planning and can introduce privacy, security, or operational problems.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A requirement that all technical details of the incident be shared publicly in real time
Why it's wrong here
Real-time public disclosure of technical details can aid attackers, expose vulnerabilities, and create legal risk. Communication should be accurate, timely, and approved, but not necessarily exhaustive or immediate. CISM guidance balances transparency with security, legal, and reputational considerations. A blanket requirement for real-time technical disclosure is not a sound communication strategy and could harm the organization.
- ✗
A list of all employees' personal mobile numbers for emergency mass texting
Why it's wrong here
Collecting personal mobile numbers raises privacy concerns and may violate data protection regulations. It also does not constitute a structured communication plan. CISM favors defined channels, roles, and approval workflows over broad collection of personal contact data. Emergency notification systems, where used, should be governed by policy and consent, not by indiscriminate collection of personal numbers.
- ✗
A policy that only the CEO may speak to any stakeholder during an incident
Why it's wrong here
Concentrating all communication in the CEO creates bottlenecks and may not be practical during a prolonged incident. It also ignores the need for specialized messaging to technical, legal, and customer audiences. CISM recommends defined roles and delegation rather than a single point of communication. A more structured approach with designated spokespersons and workflows is more resilient and effective.
- ✓
Predefined communication templates for different stakeholder groups and incident types
Why this is correct
Predefined templates accelerate communication during high-pressure incidents and ensure consistent, accurate messaging. They reduce the risk of ad hoc statements that could create legal or reputational problems. CISM recommends preparing templates for internal staff, customers, regulators, and media in advance. This directly improves the organization's ability to communicate effectively when time and attention are constrained.
- ✓
Designated spokespersons and approval workflows for external communications
Why this is correct
Designating spokespersons and defining approval workflows prevents unauthorized or inconsistent statements that could worsen an incident. It ensures that legal, executive, and communications perspectives are coordinated before messages go out. CISM emphasizes that external communication during incidents must be controlled and aligned with legal and regulatory obligations. This is a core element of an effective incident communication plan.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.