certslothcertsloth
CISA/Topic 06

ISACA / Professional

Incident Leadership, Continuity and Recovery Decisions

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: Prepare authority before the crisis; recover the business, not just servers.

Must remember

Define incident categories, severity criteria, decision rights and escalation paths before an incident. Train a cross-functional team including security, IT, business owners, legal/privacy and communications as appropriate. Tabletop exercises test coordination; technical exercises test execution. Neither alone proves the whole response works.

A business impact analysis identifies critical activities, dependencies and disruption effects. RTO targets recovery duration; RPO targets tolerable data loss. Business continuity keeps essential operations functioning; disaster recovery restores supporting technology. An incident-response plan coordinates security handling and must align with both.

During an event, validate evidence, classify impact and activate the appropriate response. Containment limits harm; eradication removes causes; recovery restores trusted operation. Preserve evidence and action records under the authorized process. Management decisions may balance evidence preservation with urgent safety/continuity needs; follow established authority and expert advice.

Communicate verified facts to the right audience. Notification obligations depend on circumstances and applicable rules; involve the responsible specialists rather than inventing a universal reporting deadline. Protect sensitive investigative details and avoid speculative public statements.

After restoration, monitor for recurrence, confirm business acceptance and conduct a blameless but accountable review. Update controls, playbooks, training and risk assessments. Restoring a vulnerable backup without fixing the entry path can restart the same incident.

Choose under exam pressure

Requirement Choice and reason
Unsure who can shut down a critical service Establish and exercise decision authority before an incident.
Server restored but business cannot operate Validate dependencies, data and business recovery criteria.
Repeated similar incidents Address root causes and program gaps through post-incident improvement.

Traps

  • Incident containment is not the same as complete recovery.
  • A backup restore test does not replace a full continuity exercise.

Active recall

1. BCP versus DRP?

Continuation of essential business operations versus restoration of technology services.

2. Why classify severity?

To allocate response, authority and communication proportional to impact.

3. Why coordinate legal/privacy specialists?

Notification, evidence and contractual duties depend on the incident context.

4. What proves recovery?

Trusted service, verified data/dependencies and business acceptance against criteria.

5. What should a post-incident review change?

Controls, procedures, training and risk decisions based on evidence.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.