CRISC · Question #174
An organization has experienced a cyber-attack that exposed customer personally identifiable information (Pll) and caused extended outages of network services. Which of the following stakeholders are
The correct answer is C. Risk owners based on risk impact. The most important stakeholders to include in a cyber response team for a significant attack are risk owners based on the risk impact.
Question
An organization has experienced a cyber-attack that exposed customer personally identifiable information (Pll) and caused extended outages of network services. Which of the following stakeholders are MOST important to include in the cyber response team to determine response actions?
Options
- ASecurity control owners based on control failures
- BCyber risk remediation plan owners
- CRisk owners based on risk impact
- DEnterprise risk management (ERM) team
How the community answered
(67 responses)- A7% (5)
- B4% (3)
- C73% (49)
- D15% (10)
Why each option
The most important stakeholders to include in a cyber response team for a significant attack are risk owners based on the risk impact.
Security control owners focus on specific controls, which may be a part of the incident, but risk owners have a broader view of the business impact.
Cyber risk remediation plan owners are responsible for long-term fixes, but the immediate response requires decision-making from those accountable for the actual risks.
Risk owners are accountable for the specific risks that materialized and their associated impacts, making them crucial for determining appropriate response actions and understanding the full scope of the incident. This ensures that the individuals ultimately responsible for the business functions and assets affected are directly involved in resolution.
The ERM team provides oversight and framework but may not have the granular operational accountability needed for immediate response actions.
Concept tested: Incident response team composition (risk ownership)
Source: https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/secure/security-governance-risk-compliance-strategies#risk-management-framework
Topics
Community Discussion
No community discussion yet for this question.