Which of the following should be an information security manager's MOST important criterion for determining when to review the incident response plan? A. When recovery time objectives (RTOs) are not met B. When missing information impacts recovery from an incident C. Before an internal audit of the incident response process D. At intervals indicated by industry best practice  Suggested Answer: D This question is in CISM exam For getting Certified Information Security Manager Certificate Disclaimers: The website is not related to, affiliated with, endorsed or authorized by ISACA. The website does not contain actual questions and answers from ISACA's Certification Exams. Trademarks, certification & product names are used for reference only and belong to ISACA.
Please login or Register to submit your answer