You are the information security program manager for a government agency. The agency has a highly regulated environment and is in the process of updating its incident response plan. During a tabletop exercise, it becomes clear that the detection capabilities are strong, but the response coordination between IT, legal, and public affairs is poor. This caused delays in containing a simulated ransomware attack. The existing program includes an incident response policy but no formal procedures for cross-department coordination. The agency's leadership wants quick improvement with minimal budget impact. What should you recommend?
Cross-department coordination gaps, not detection, caused containment delays. A coordination plan assigns explicit roles and communication channels across IT, legal and public affairs, while quarterly joint exercises rehearse them. This directly fixes the procedural void at minimal cost, satisfying leadership's quick, low-budget constraint.
Why this answer
The gap identified in the tabletop exercise is coordination, not detection or tooling, so the fix must address cross-department roles and communication. Developing a formal coordination plan with defined roles and quarterly joint exercises directly closes that gap at low cost, since it leverages existing staff and processes rather than new technology.
Exam trap
CISM often tests the principle that people and process gaps require people and process solutions, so candidates who jump to technology purchases (SIEM, MSSP) miss that the scenario explicitly says detection is already strong.
How to eliminate wrong answers
Option A is wrong because outsourcing to an MSSP does not fix internal coordination between IT, legal, and public affairs, and it adds recurring cost contrary to the minimal-budget constraint. Option B is wrong because a dedicated IR team reporting to the CISO still doesn't establish the cross-department communication channels and roles that the exercise showed were missing. Option C is wrong because the scenario explicitly states detection capabilities are strong, so a new SIEM addresses a problem that doesn't exist and incurs significant cost.