712-50 Question 247
Single answerDomain 4: Information Security Core Competencies (46%)A newly appointed CISO is reviewing the organization's incident response capability after a ransomware event exposed major coordination gaps. The security team contained the malware quickly, but legal notification deadlines were nearly missed, business executives were not informed in time to make operational decisions, and forensic evidence collection was inconsistent across business units. The board asks the CISO to recommend the MOST effective next step to improve the organization's readiness for future incidents. Which action should the CISO prioritize?
- A
Deploy a new endpoint detection and response (EDR) platform across all endpoints to improve technical containment speed
- B
Establish and exercise a formal incident response plan with defined roles, escalation criteria, communication workflows, and evidence-handling procedures
- C
Outsource all incident handling activities to a managed security service provider so internal teams are no longer responsible for coordination
- D
Increase the frequency of vulnerability scanning to reduce the likelihood of future ransomware infections
Show answer and explanation
Correct answer: B
Explanation
In CCISO Domain 4, leaders are expected to ensure that information security core capabilities operate effectively across technical, legal, and business functions. This scenario is fundamentally about incident response management rather than purely technical prevention or detection. The most effective next step is to formalize and rehearse an incident response capability that includes governance, playbooks, escalation matrices, communication plans, legal/regulatory notification triggers, and forensic procedures. This aligns with widely accepted best practices from NIST SP 800-61 Rev. 2, which emphasizes preparation, clearly assigned roles and responsibilities, communication and coordination, and evidence handling, and with ISO/IEC 27035 guidance on incident management lifecycle and organizational readiness. A CISO should prioritize process maturity and cross-functional readiness when prior incidents reveal coordination failures, even if technical containment was reasonably effective.
- A. Incorrect.
This is not the best answer. An EDR platform can improve detection and containment, but the scenario's primary failure was not technical tooling alone. The organization already contained the malware quickly. The larger gaps involved governance, communications, legal coordination, executive escalation, and forensic consistency. Buying or expanding tooling does not by itself resolve unclear responsibilities or procedural breakdowns.
- B. Correct.
This is the best answer. The scenario highlights failures in incident management governance: missed or delayed stakeholder communication, inadequate escalation to executives, legal notification risk, and inconsistent forensic handling. A formal incident response plan that defines roles and responsibilities, escalation thresholds, decision authority, legal and regulatory coordination, communication procedures, and chain-of-custody/evidence requirements directly addresses the root causes. Regular tabletop and operational exercises are essential to validate that the plan works across business, legal, HR, IT, and executive leadership.
- C. Incorrect.
This is incorrect because outsourcing can supplement capability but does not remove the organization's accountability for incident response governance, regulatory obligations, executive decision-making, or business continuity coordination. A managed provider may assist with monitoring or response, but without an internal, formally defined response structure, the same coordination failures can still occur.
- D. Incorrect.
This is not the best answer. Vulnerability scanning is a useful preventive control, but it does not address the immediate weaknesses identified by the board's concern: readiness, coordination, notification timing, and evidence preservation during an incident. This option focuses on reducing attack surface rather than improving incident response maturity.