by MTC Group, LLC
CISM D4: Incident Management
Domain 4 (30% weight) covers incident management readiness (the incident response plan, business impact analysis, business continuity and disaster recovery plans, incident classification, and training, testing and evaluation) and incident management operations. Much of this overlaps with CISSP Domain 7, but study it through a program-management and organizational-readiness lens rather than a hands-on operational one: plan development, testing, and organizational roles matter as much as technical containment steps.
Incident response plan (IRP) development
The IRP is a written plan, formally approved by senior leadership, that guides the organization before, during and after a confirmed or suspected incident. Writing it is only part of the work: the best IRPs are living documents reviewed regularly (CISA suggests quarterly). Testing validates capabilities and exercising the plan identifies planning gaps, and incident response exercises and tests also provide information for evaluating the program and prepare staff and third parties for future incidents.
Business Impact Analysis (BIA)
The foundational exercise that determines criticality, recovery priorities and recovery objectives (RTO, and the acceptable data loss behind the RPO) for business processes and the systems that support them. BIA results feed the strategy for everything else: business continuity, disaster recovery and resource prioritization.
Testing types for continuity plans
Checklist review and structured walkthrough or tabletop (discussion-based, no equipment deployed, lowest cost and disruption), then simulation (personnel perform a simulated emergency), then parallel test (critical systems run at the alternate site), then full interruption (the disaster is replicated and normal production is shut down, the most disruptive). Know the tradeoffs of each.
Roles during an incident
The incident manager leads the response and manages communication but performs no technical duties; a technical manager serves as the subject matter expert for the technical response; communications staff deal with the media and external stakeholders; legal advises on incidents with legal ramifications; and leadership oversees incident response, allocates funding, and may have decision-making authority on high-impact actions such as shutting down or rebuilding critical services. Know who should be making which decisions, especially around external communication and legal obligations.
Business Impact Analysis (BIA) vs. Risk Assessment
A risk assessment identifies, estimates and prioritizes risks by analyzing threats and vulnerabilities to determine likelihood and impact. A BIA determines the impact of losing the support of a resource or business process and how that loss escalates over time, focusing on the consequences of the disruption rather than its cause: the BIA is what actually drives recovery priorities and the RTO.
Tabletop exercise vs. full interruption test
A tabletop is a low-cost, discussion-based walkthrough of the plan that does not deploy equipment or affect live systems. A full interruption test replicates the disaster and actually shuts down normal production to validate recovery under real conditions: the most realistic test but also the most disruptive to the business.
- [1]
- [2]
- [3]
- [4]
- [5]
- [6]
- [7]
- [8]
- [9]
- [10]
- [11]
- [12]
- [13]
- [14]
- [15]
Practice D4 questions with instant feedback, free to start, no card required.
Start Free© 2026 MTC Group, LLC. All rights reserved. InfoSec ExamPrep™ and the InfoSec ExamPrep logo are trademarks of MTC Group, LLC.
For personal exam preparation only. Printed from examprep.mtcgroupllc.com.