← CISM: manage security, risk, and incidents
20 / 21 · 70 MIN

Coordination: facts, decisions and revisions

Build an update that supports decisions without turning suspicions into facts or hiding changes in evidence.

Coordination starts with the decision needed

In a fictional incident, a fund-settlement queue is delayed and the supplier is investigating a possible intrusion. APS knows instructions are pending; it does not yet know the cause or whether data was exposed. The coordination lead identifies decisions that cannot wait: limit new submissions, activate an alternative path or retain restricted operation. Each decision needs authority, expected impact, conditions and an execution owner. The person gathering information does not automatically gain authority over every action. The plan should allow action within defined mandates and escalation when a decision exceeds them. Also keep the incident coordinator visible so teams do not execute incompatible instructions from different channels.

A statement must retain its status

In the local exercise, impact-r1 describes a confirmed queue delay; cause-r1 describes only suspected supplier intrusion. The message can state confirmed impact and identify the cause as unknown. It cannot place the suspicion among facts merely because it appeared in technical chat. Record origin, time and scope of observation. A reachable application establishes reachability; it does not establish instruction reconciliation, data integrity or absence of malicious activity. Confirmation is an evidence-based judgment, not an adjective that makes communication persuasive. The program receives predefined synthetic labels; it does not verify the truth of human statements. In actual operations, someone must assess that evidence and own the classification.

Correct while retaining decision history

Investigation later shows that only fund group A is affected. The exercise creates impact-r2 with corrected scope and marks impact-r1 as superseded. The earlier message retains its reference to the revision available when it was approved. This explains why a decision was made with incomplete information. Silently rewriting the old statement would suggest that the team always knew the correct scope. The next update uses the current revision and explains how correction affects ongoing decisions. The lab’s in-memory history retains ordered entries but is neither tamper-proof storage nor forensic chain of custody. Those properties require separate access, retention, integrity and handling controls that the exercise does not implement.

Update even when the cause remains unknown

A useful update identifies its as-of time, known impact, actions, pending decisions, uncertainties and next update. In the model, the next update must follow the as-of time. The fifteen-minute interval is a teaching parameter, not a legal deadline or a bank’s rule. When an update commitment arrives without a new technical conclusion, communicate what remains valid and the work underway. Do not promise recovery at 14:00 merely because that time pleases the sponsor. If an estimate depends on validation, identify that dependency and confidence in the forecast. Cadence should support decisions and prevent multiple informal versions from filling silence with unsupported conclusions.

Practice: draft, challenge and revise

Run the lab and try adding cause-r1 as a fact, using a missing evidence reference and repeating a message revision. Compare rejection reasons. Then correct impact and observe that the old message remains in history but its evidence is no longer accepted for a new update. Draft two sentences for leadership: one about demonstrated impact and another about the required decision, identifying what is still unknown. Explain the difference between an approved draft, sending and receipt acknowledgment. The exercise’s approved-draft state establishes neither of the latter two. Validating the actual process requires exercising people, contacts, alternative channels, authority and message understanding in the authorized environment.

# Local fictional decision exercise; sends no messages:
python3 content/labs/cism-incident-communications/run.py \
 --output /tmp/cism-communications.json
# Inspect fact-corrected in ledger and claims in approvedDrafts.
# approved-draft is not evidence of delivery or receipt.
IN PRACTICE

The first message reports settlement delay. The next revision limits impact to group A, retains history and reassesses measures already taken.

Common pitfalls

Confirming a cause because many people repeat it; deleting earlier versions; treating reachability as recovery; confusing approval with sending.

Related topics: Sharing and handover · Recovery and reconciliation

Take this idea with you

Communication should show what supports the decision and how that knowledge changed.

Create account

Reference: NIST SP 800-61 Revision 3 · CISM current outline before November 3, 2026

CISM® is a registered trademark of ISACA. bigsavant.com is an independent preparation platform and is not affiliated with, associated with, sponsored, authorised or endorsed by ISACA. Content and questions are original, are not official exam questions, and completing our tests does not award or guarantee any certification. Names are used only to identify the subject. All other trademarks belong to their respective owners.