Requirements for Evidence Preservation Procedures in Incident Response Plan - SEO Optimization for CISA Exam

Information Security Manager: Guidance for Evidence Preservation Procedures

Prev Question Next Question

Question

An information security manager is developing evidence preservation procedures for an incident response plan.

Which of the following would be the BEST source of guidance for requirements associated with the procedures?

Answers

Explanations

Click on the arrows to vote for the correct answer

A. B. C. D.

D.

The BEST source of guidance for evidence preservation procedures associated with an incident response plan would be legal counsel (option C).

Legal counsel is the most appropriate source of guidance for evidence preservation procedures because they possess the legal expertise and knowledge required to develop and enforce procedures that will stand up in a court of law. In the event of a breach or other security incident, evidence may be required to prosecute the responsible parties, and the preservation of evidence is critical to ensuring its admissibility in court.

IT management (option A) may have technical expertise related to preserving evidence, but they may not be familiar with legal requirements for evidence preservation.

Executive management (option B) may have oversight responsibility for the incident response plan, but they may not have the legal expertise necessary to develop evidence preservation procedures.

Data owners (option D) may be responsible for the data that is affected by the security incident, but they may not have the legal expertise required to develop evidence preservation procedures or understand the implications of not preserving evidence properly.

Therefore, legal counsel is the most appropriate source of guidance for developing evidence preservation procedures associated with an incident response plan.