CISM Incident Management Practice Question
Which document outlines the overall strategy, roles, and responsibilities for incident response across the organization?
⚠ Common exam trap
CISM often tests the distinction between policy, plan, and playbook, and candidates frequently select 'policy' because it sounds authoritative, missing that the question asks for strategy plus roles and responsibilities, which is the plan.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Incident response plan
The incident response plan (IRP) is the overarching document that defines the organization's strategy, structure, roles, and responsibilities for handling incidents end to end. It establishes who does what across the full lifecycle — preparation, detection, containment, eradication, recovery, and lessons learned. The policy sets intent at a high level, while the plan operationalizes that intent with assigned roles and coordination procedures.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Communication plan
Why it's wrong here
A communication plan covers who is told what and when, not the strategy, roles and responsibilities for responding to incidents. It is tempting because communication is a genuine part of incident handling, and for coordinating notifications during a declared incident it is the right document.
- ✓
Incident response plan
Why this is correct
The incident response plan is the governing document defining response strategy, team roles, responsibilities, escalation paths and communication procedures organisation-wide. It provides the overarching framework that individual playbooks and procedures sit beneath, satisfying the requirement for an organisation-level strategy.
- ✗
Incident response policy
Why it's wrong here
A policy states management intent and principles but does not assign the operational roles and responsibilities across the response organisation. It is tempting because policies are mandatory and governance-level, and for setting incident response mandate and scope a policy is the correct document.
- ✗
Incident response playbook
Why it's wrong here
A playbook holds step-by-step procedures for specific incident types, not organisation-wide strategy, roles and responsibilities. It is tempting because playbooks are essential during response execution, and for a single, well-understood scenario a playbook is the correct artefact.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.