Courseiva
Incident Management →easyMultiple Choice

CISM Incident Management Practice Question

An organization's incident response (IR) policy should be approved by which of the following to ensure authority and accountability?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The board of directors or executive management

The IR policy requires senior management approval to demonstrate organizational commitment and allocate necessary resources.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The incident response manager

    Why it's wrong here

    The incident response manager executes the policy, so self-approval removes independent oversight and senior accountability. It is tempting because this role owns IR content and day-to-day readiness, and would be correct for authoring or maintaining the policy document, not for granting it authority.

  • ✗

    The legal counsel

    Why it's wrong here

    Legal counsel advises on regulatory and contractual implications but holds no operational authority to mandate IR activities across business units. It is tempting because IR policy carries legal exposure, and counsel would be the correct approver for legal hold or breach-notification procedures, not the overarching policy.

  • ✗

    The IT director

    Why it's wrong here

    The IT director owns technology operations, so approval would lack the cross-functional authority and board-level accountability an IR policy requires. It is tempting because IT typically drafts and executes the technical response, and would be correct for approving runbooks or tooling standards rather than the enterprise policy.

  • ✓

    The board of directors or executive management

    Why this is correct

    Board or executive management approval confers enterprise-wide authority and accountability, since only top leadership can mandate compliance across all business units and commit resources. This satisfies the policy's requirement for authority and accountability by placing ownership at the highest governance level.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.