CISM Incident Management Practice Question
An organization's incident response (IR) policy should be approved by which of the following to ensure authority and accountability?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The board of directors or executive management
The IR policy requires senior management approval to demonstrate organizational commitment and allocate necessary resources.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The incident response manager
Why it's wrong here
The incident response manager executes the policy, so self-approval removes independent oversight and senior accountability. It is tempting because this role owns IR content and day-to-day readiness, and would be correct for authoring or maintaining the policy document, not for granting it authority.
- ✗
The legal counsel
Why it's wrong here
Legal counsel advises on regulatory and contractual implications but holds no operational authority to mandate IR activities across business units. It is tempting because IR policy carries legal exposure, and counsel would be the correct approver for legal hold or breach-notification procedures, not the overarching policy.
- ✗
The IT director
Why it's wrong here
The IT director owns technology operations, so approval would lack the cross-functional authority and board-level accountability an IR policy requires. It is tempting because IT typically drafts and executes the technical response, and would be correct for approving runbooks or tooling standards rather than the enterprise policy.
- ✓
The board of directors or executive management
Why this is correct
Board or executive management approval confers enterprise-wide authority and accountability, since only top leadership can mandate compliance across all business units and commit resources. This satisfies the policy's requirement for authority and accountability by placing ownership at the highest governance level.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.