A Chief Information Security Officer is developing procedures to guide detective and corrective activities associated with common threats, including phishing, social engineering, and business email compromise. Which of the following documents would be most relevant to revise as part of this process?
Choose an answer
Tap an option to check your answer.
Correct answer: IRP.
Why this is the answer
The Incident Response Plan (IRP) is the most relevant document. It outlines the procedures for identifying, containing, eradicating, recovering from, and learning from security incidents, such as phishing, social engineering, and business email compromise. Revising the IRP ensures that the organization has a structured approach to respond to these common threats effectively. The SDLC (Software Development Life Cycle) focuses on software creation and maintenance, not incident response. The BCP (Business Continuity Plan) addresses maintaining business operations during disruptions, which is broader than specific threat responses. The AUP (Acceptable Use Policy) defines how users can utilize organizational resources, but doesn't detail incident handling procedures.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed