712-50 Question 361
Single answerDevelop a plan to identify a potential security violation and take appropriate action to report the incidentA newly appointed CISO is formalizing the organization’s process for identifying potential security violations and ensuring incidents are reported appropriately. During a recent event, a database administrator noticed unusual after-hours queries against a payroll system containing employee PII. The administrator emailed the security team lead, but no formal ticket was created, legal was not notified, and key audit logs were overwritten during routine log rotation before the investigation began. The board now asks the CISO to implement a plan that improves both early identification of violations and timely reporting. Which action should the CISO prioritize FIRST to address the root governance gap exposed by this incident?
- A
Implement a formal incident reporting and escalation procedure that defines triggers, roles, evidence preservation requirements, and notification paths to security, legal, privacy, HR, and executive leadership
- B
Purchase a new SIEM platform with advanced behavioral analytics to automatically detect unusual database activity across all critical systems
- C
Require all administrators to report suspicious activity only to their direct manager so leadership can decide whether security involvement is necessary
- D
Delay documenting the process until the investigation is complete so the organization can avoid creating procedures that might need to be revised later
Show answer and explanation
Correct answer: A
Explanation
The best answer is to first implement a formal incident reporting and escalation procedure. The incident described did not primarily fail because the organization lacked detection; it failed because there was no disciplined process to identify a potential violation, preserve evidence, and report it to the right parties in time. In senior security leadership practice, the CISO must ensure suspected incidents are handled through documented workflows that include intake criteria, severity classification, ownership, evidence preservation, chain of custody, retention of relevant logs, and notification requirements for legal, privacy, HR, communications, and executives as appropriate. This aligns with widely accepted guidance such as NIST SP 800-61 Computer Security Incident Handling Guide, which emphasizes preparation, defined reporting paths, triage, and evidence handling, and ISO/IEC 27035, which stresses structured incident reporting and assessment. Because the system contains employee PII, timely legal and privacy review may also be necessary to support breach analysis and regulatory obligations. Once governance and reporting are established, the organization can then mature monitoring, training, and tooling.
- A. Correct.
Correct. The scenario exposes a governance and process failure more than a pure technology gap: suspicious activity was noticed, but there was no formal mechanism to classify, escalate, preserve evidence, and notify stakeholders. A CISO should first establish an incident reporting and escalation procedure with clear thresholds for suspected violations, chain of custody, logging retention requirements, and stakeholder notification paths. This directly addresses the missed ticket creation, absent legal/privacy notification, and overwritten logs. In CCISO context, governance, accountability, and repeatable reporting processes come before tool optimization.
- B. Incorrect.
Incorrect. Enhanced detection tooling may improve visibility, but it does not solve the primary failure in this case: personnel observed suspicious activity and still failed to trigger a controlled reporting and response process. Without defined procedures, roles, and evidence handling requirements, even the best SIEM may generate alerts that are mishandled or not escalated appropriately. Technology should support, not replace, incident governance.
- C. Incorrect.
Incorrect. Routing suspected violations only through direct management creates delay, inconsistency, and potential suppression of security reporting. Best practice is to define direct reporting channels into the incident response function, with clear escalation criteria and mandatory involvement of relevant stakeholders based on incident type. Managers may be informed, but they should not become a bottleneck for security incident reporting.
- D. Incorrect.
Incorrect. Postponing process documentation leaves the organization exposed to repeated failures and is inconsistent with effective security leadership. While procedures can be refined after lessons learned, the CISO should establish an initial formal process immediately, especially where regulated data such as PII is involved. Waiting increases legal, regulatory, and operational risk.