Aligning Incident Response Plan with Corporate Strategy
Which of the following should be updated FIRST when aligning the incident response plan with the corporate strategy?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests the hierarchy of planning components, specifically that strategic alignment requires updating risk scenarios before tactical procedures or notification lists.
When aligning an incident response plan with corporate strategy, updating risk response scenarios is the primary step. The community agrees this ensures the plan reflects the organization's overall risk management approach.
Selecting 'Security procedures' (A) or 'Incident notification plan' (C) is common because they are tangible parts of the plan, but they are tactical details that come after strategic alignment.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Risk response scenarios bridge the gap between high-level corporate risk appetite and specific incident handling. By updating these first, the IR plan directly supports the business objectives and risk tolerance defined in the corporate strategy. As noted in comments, this ensures the response plan aligns with the organization's overall risk management approach.Why the Other Options Are Wrong
Security procedures (A) are operational steps that execute the plan, not the strategic foundation. The Disaster Recovery Plan (B) focuses on continuity after a major disruption, not the broader scope of incident response alignment. The Incident notification plan (C) is a specific subset or procedural element that depends on the broader strategy defined in the risk scenarios.Community Comment Notes
Community feedback strongly supports D, emphasizing that 'Incidence RESPONSE PLAN' implies a 'RISK RESPONSE strategy.' Comments highlight that scenarios must be updated first to ensure the response mechanism matches the organizational risk posture.Official Reference
- ISACA CISM Review Manual
- ISACA CRISC Review Manual
Exam Strategy
Always prioritize strategic alignment over tactical implementation in CISM questions. Look for options that connect business goals or risk appetite to security processes, such as risk scenarios, rather than procedural steps.
Related Analysis
Practice All CISM Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISM Practice Test →