CISM Incident Management Practice Question
An organization's incident response plan includes a communication tree that lists internal contacts and external parties. During a moderate incident, the incident manager must notify the party responsible for making binding decisions about public statements and regulatory disclosures. Which role should be contacted for this purpose?
⚠ Common exam trap
The trap here is equating technical incident leadership with authority over external communications, when legal counsel owns disclosure decisions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The legal counsel or chief legal officer
Decisions about public statements and regulatory disclosures require legal authority because they carry statutory, contractual, and liability implications. Legal counsel evaluates notification deadlines, privilege, and the accuracy of messaging. Technical roles supply facts, and vendors supply their own obligations, but neither can authorize the organization's external communications or regulatory filings during an incident.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The third-party cloud hosting provider's account manager
Why it's wrong here
An external vendor's account manager has no authority over the organization's public statements or regulatory filings and may have conflicting commercial interests. While vendors must be notified when their systems are involved, they do not decide the organization's disclosure posture. Contacting them first could leak information prematurely and complicate the incident response, so vendor notification should follow internal legal and executive decisions.
- ✓
The legal counsel or chief legal officer
Why this is correct
Legal counsel holds authority over what may be disclosed publicly and what must be reported to regulators, balancing statutory obligations, privilege, and liability. Public statements and regulatory notifications carry legal consequences, so the incident manager must route these decisions through legal. Counsel also determines whether attorney-client privilege should be invoked to protect investigation details from later discovery.
- ✗
The security operations center (SOC) shift lead
Why it's wrong here
The SOC shift lead coordinates technical detection and triage, not public statements or regulatory filings. Involving this role in external communications would bypass legal review and executive authority, creating risk of inconsistent or legally problematic messaging. The shift lead's proper function is to provide accurate technical facts to the incident manager, who then routes decision-making to the appropriate executive and legal functions.
- ✗
The IT service desk manager
Why it's wrong here
The service desk manager handles user-facing support and ticket escalation, not corporate communications or regulatory disclosure. Routing public statement decisions here would delay legally required notifications and could produce unauthorized statements. The service desk contributes by tracking reported symptoms and user impact, but decisions about what the organization says publicly must rest with legal and executive leadership.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.