← CISM: manage security, risk, and incidents
21 / 21 · 70 MIN

Sharing, audiences and transfer of responsibility

Apply sharing boundaries and prepare a coordination handover that preserves decisions, actions and authority.

The audience changes the information needed

The technical team needs indicators and tasks; leadership needs impact, options and decisions; a client may need to know which operations are unavailable and when further information will arrive. Copying the whole bridge transcript to everyone exposes unnecessary detail and makes decisions harder. Prepare consistent versions from the same fact record, retaining scope and uncertainty. In the exercise, an operator authorized to update the internal team does not automatically have authority to release an external message. A designated deputy exists for that function. This role separation is a scenario choice; the actual organization must define and test its mandates, including out-of-hours availability and an unavailable primary owner.

TLP defines sharing boundaries

TLP 2.0 is a sharing convention, not a complete classification or encryption system. TLP:RED limits information to individual recipients. TLP:AMBER permits need-to-know sharing within the organization and with its clients; TLP:AMBER+STRICT restricts it to the organization. TLP:GREEN permits circulation within the defined community, not through a public channel. TLP:CLEAR imposes no TLP disclosure limit but does not remove other applicable requirements. In the scenario, a client with a need to know passes the AMBER check and fails AMBER+STRICT. That contrast does not authorize convenient relabeling. When wider sharing is needed, obtain explicit source permission and respect any additional source restrictions.

Permitted sharing is not authorized publication

A message can respect TLP yet exceed the author’s mandate or contain facts intended for another audience. The exercise separately evaluates label, recipient relationship, need to know, additional restrictions and release authority. A TLP:CLEAR document does not turn an unapproved internal statement into an authorized public announcement. Similarly, encrypting a message does not widen the group allowed to receive it. When external obligations may apply, involve the appropriate functions under the plan and applicable context. This lesson does not invent a universal notification deadline. Preparing contacts, messages and decisions before an incident reduces improvisation when the team is already under pressure.

Handover needs explicit acceptance

In the model, lead-a proposes transferring coordination to lead-b. The package includes impact, pending decisions, actions, next update and contacts. A proposal does not immediately change ownership: lead-a retains coordination until the recipient acknowledges. A third person cannot acknowledge for lead-b merely because they saw the message. After acceptance, new updates must reference the current owner. In practice, also confirm understanding of priorities, access to the record and ability to use the alternative channel. The package must be more than completed field names; it needs content that enables continued work. The script checks structure and synthetic transitions, not human understanding or actual handover quality.

Exercise what fails during shift changes

The lab executes the same decisions twice and records 38 checks per run. It tests wrong recipients, a hypothesis presented as fact, a superseded revision, an incomplete proposal and acknowledgment by the wrong person. Three messages remain approved drafts and six entries retain history. Nothing is sent. Use these cases to prepare an exercise with people: the primary owner is unavailable, the normal channel fails, impact is corrected and the shift ends before the next update. Define observers, criteria and how outcomes will be recorded. Improvement is established only when a later exercise confirms expected behavior. Names and phone numbers in a document do not prove contact reachability or understanding of authority.

# Fixture transitions, not a production approval system:
# lead-a -> propose complete package -> lead-b acknowledges -> owner=lead-b
# TLP:AMBER + client + need-to-know may pass the scope check.
# TLP:AMBER+STRICT + client fails it.
# Release authority, fact audience and extra restrictions are separate checks.
IN PRACTICE

The deputy can prepare the client update, but AMBER+STRICT prevents sharing that content outside the organization. The team needs content authorized for the audience.

Common pitfalls

Using TLP as blanket approval; confusing client with community; assuming a handover proposal transfers responsibility; treating a draft as acknowledged receipt.

Related topics: Governance and authority · Exercises and improvement

Take this idea with you

Share within appropriate scope and authority, retaining coordination until handover is accepted.

Create account

Reference: NIST SP 800-61 Revision 3 · CISM current outline before November 3, 2026

CISM® is a registered trademark of ISACA. bigsavant.com is an independent preparation platform and is not affiliated with, associated with, sponsored, authorised or endorsed by ISACA. Content and questions are original, are not official exam questions, and completing our tests does not award or guarantee any certification. Names are used only to identify the subject. All other trademarks belong to their respective owners.