CCSP · Question #258
Who should be the only entity allowed to declare that an organization can return to normal following contingency or BCDR operations?
The correct answer is D. Senior management. Only senior management should authorize the return to normal operations following contingency or BCDR activities, as they hold ultimate responsibility for organizational risk.
Question
Who should be the only entity allowed to declare that an organization can return to normal following contingency or BCDR operations?
Options
- ARegulators
- BLaw enforcement
- CThe incident manager
- DSenior management
How the community answered
(15 responses)- B7% (1)
- C7% (1)
- D87% (13)
Why each option
Only senior management should authorize the return to normal operations following contingency or BCDR activities, as they hold ultimate responsibility for organizational risk.
Regulators define compliance requirements but do not typically authorize an organization's internal return to normal operations.
Law enforcement may be involved in incident response but does not have the authority to declare an organization's return to normal business operations.
The incident manager leads the incident response and recovery efforts, but the decision to return to normal involves broader organizational and business risk considerations that fall under senior management's purview.
Senior management holds the ultimate responsibility for an organization's overall operations, risk posture, and business continuity strategy. Therefore, they are the only entity authorized to make the critical decision to declare a return to normal operations, ensuring that all critical business functions are stable, risks are appropriately mitigated, and the decision aligns with the organization's strategic objectives and risk tolerance.
Concept tested: Business continuity/disaster recovery roles
Source: https://csrc.nist.gov/publications/detail/sp/800-34/rev-1/final
Topics
Community Discussion
No community discussion yet for this question.