CGEIT · Question #621
An audit department recently uncovered a series of security breaches. It was determined that network intrusion detection logs were recording the suspicious activity, but IT staff were not reviewing lo
The correct answer is A. A re-prioritization of IT projects to address critical needs. Given security breaches due to unreviewed logs from competing business demands, the IT steering committee's first priority should be to re-prioritize IT projects to address this critical security need.
Question
An audit department recently uncovered a series of security breaches. It was determined that network intrusion detection logs were recording the suspicious activity, but IT staff were not reviewing logs due to competing business demands. To address this situation, the IT steering committee's FIRST priority should be:
Options
- AA re-prioritization of IT projects to address critical needs
- BUpdating the RACI chart to establish responsibility
- CThe hiring of additional staff to cope with the demand
- DAn assessment of the capacity of current resources
How the community answered
(53 responses)- A60% (32)
- B4% (2)
- C23% (12)
- D13% (7)
Why each option
Given security breaches due to unreviewed logs from competing business demands, the IT steering committee's first priority should be to re-prioritize IT projects to address this critical security need.
Security breaches represent a significant and critical risk to the enterprise. The IT steering committee's role is to align IT efforts with business priorities and risk management. If existing projects are preventing essential security monitoring, the immediate and most impactful action is to re-prioritize the IT project portfolio to ensure that critical security functions, like log review, receive the necessary resources and attention, thereby mitigating the immediate threat.
Updating the RACI chart might clarify responsibilities, but without ensuring the *resources* or *priority* to perform the task, it won't solve the core issue of competing business demands.
While hiring additional staff might eventually be a solution, it is a longer-term strategy and not the *first* priority for an immediate and critical security issue that requires immediate resource reallocation.
An assessment of current resource capacity is a good analytical step, but the *first* priority when critical security tasks are failing due to competing demands is to re-allocate existing resources to address the immediate threat, before a full assessment is completed.
Concept tested: IT steering committee crisis management
Topics
Community Discussion
No community discussion yet for this question.