49. A Chief Information Security Officer is developing procedures to guide detective and corrective activities associated with common threats, including phishing, social engineering, and business email compromise. Which of the following documents would be most relevant to revise as part of this process?
Answer: B
IRP would be most relevant to revise as part of developing procedures for detecting and correcting threats.
Revising the Incident Response Plan (IRP) is crucial for a Chief Information Security Officer when addressing threats like phishing, social engineering, and business email compromise. The IRP outlines how an organization responds to security incidents, making it integral to implementing effective detective and corrective measures.
A) SDLC
The Software Development Life Cycle (SDLC) focuses on the processes involved in software development, including planning, designing, building, testing, and deploying applications. While important for secure software development, it does not directly address the immediate procedures needed for responding to security incidents like phishing or social engineering attacks.
B) IRP
The Incident Response Plan (IRP) is specifically designed to guide organizations in detecting and responding to security threats. Revising this document is essential as it lays out the steps for identifying incidents, managing them effectively, and mitigating their impact, thereby directly supporting the CISO's efforts in addressing the mentioned threats.
C) BCP
The Business Continuity Plan (BCP) focuses on maintaining business operations during and after a disaster. While it does include some aspects of security incidents, it is more concerned with overall business resilience rather than the specific detective and corrective activities related to cybersecurity threats like phishing.
D) AUP
The Acceptable Use Policy (AUP) governs the appropriate use of organizational resources and technology by employees. While it can help in preventing some security threats, it does not provide the necessary procedures for responding to incidents, making it less relevant for the CISO's current focus.
Conclusion
The Incident Response Plan (IRP) is the most relevant document for revising in the context of developing procedures to address common cybersecurity threats. It directly outlines how to detect and respond to incidents, while the other options, although important in their respective areas, do not address the immediate needs of incident detection and correction as effectively as the IRP does.