Which TWO of the following are essential components of an incident response programme?
The incident response plan is an essential programme component, defining scope, roles, escalation paths, communication procedures and response phases. Without it, teams lack a coordinated, repeatable approach to detecting, containing and recovering from incidents, undermining the entire programme's effectiveness.
Why this answer
An incident response plan (A) is essential because it defines the documented, step-by-step procedures, roles, communication paths, and escalation criteria that guide the team through detecting, containing, eradicating, and recovering from a security incident. An incident response policy (B) is equally essential because it is the governing document that establishes the organization's mandate, scope, objectives, authority, and management commitment for incident handling, which the plan then implements. Together, the policy provides the 'why and who' while the plan provides the 'how and when,' forming the foundational pair of any incident response programme.
By contrast, an annual penetration test (C) and a vulnerability scanning schedule (D) are proactive vulnerability-management activities that feed the programme but are not core structural components of it, and security awareness training (E) is a preventive control that supports the programme rather than constituting an essential incident response component.