32. A Chief Information Security Officer is developing procedures to guide detective and corrective activities associated with common threats, including phishing, social engineering, and business email compromise. Which of the following documents will be most relevant to revise as part of this process?
Answer: B
IRP will be most relevant to revise as part of the process.
The Incident Response Plan (IRP) is crucial for guiding detective and corrective activities related to security threats such as phishing, social engineering, and business email compromise. Revising the IRP ensures that the organization is prepared to respond effectively to these common threats.
A) SDLC
The Software Development Life Cycle (SDLC) focuses on the stages of software development and does not directly address incident response or the management of security threats. While it is important for secure application development, it is not relevant for the procedures guiding response to incidents like phishing or social engineering.
B) IRP
The Incident Response Plan (IRP) is specifically designed to outline the procedures for detecting and responding to security incidents. Revising the IRP ensures that the organization has a clear strategy for mitigating risks associated with threats like phishing and business email compromise, making it the most relevant document in this context.
C) BCP
The Business Continuity Plan (BCP) focuses on maintaining business operations during and after a disaster. While it addresses recovery and continuity, it does not specifically provide guidance on detecting or responding to security incidents, making it less relevant to the immediate needs of addressing phishing and social engineering threats.
D) AUP
The Acceptable Use Policy (AUP) establishes guidelines for proper use of organizational resources. While it can help prevent certain types of threats, it does not provide procedures for detecting or responding to incidents, thus rendering it less relevant to the context of developing response procedures.
Conclusion
The IRP is essential for preparing an organization to respond to incidents like phishing, social engineering, and business email compromise, making it the correct choice to revise. In contrast, the SDLC, BCP, and AUP serve different purposes and do not specifically address the need for effective incident response strategies, highlighting their irrelevance in this scenario.