nerdexam
Isaca

CRISC · Question #174

An organization has experienced a cyber-attack that exposed customer personally identifiable information (Pll) and caused extended outages of network services. Which of the following stakeholders are

The correct answer is C. Risk owners based on risk impact. The most important stakeholders to include in a cyber response team for a significant attack are risk owners based on the risk impact.

Submitted by akirajp· Apr 18, 2026Risk Response and Reporting

Question

An organization has experienced a cyber-attack that exposed customer personally identifiable information (Pll) and caused extended outages of network services. Which of the following stakeholders are MOST important to include in the cyber response team to determine response actions?

Options

  • ASecurity control owners based on control failures
  • BCyber risk remediation plan owners
  • CRisk owners based on risk impact
  • DEnterprise risk management (ERM) team

How the community answered

(67 responses)
  • A
    7% (5)
  • B
    4% (3)
  • C
    73% (49)
  • D
    15% (10)

Why each option

The most important stakeholders to include in a cyber response team for a significant attack are risk owners based on the risk impact.

ASecurity control owners based on control failures

Security control owners focus on specific controls, which may be a part of the incident, but risk owners have a broader view of the business impact.

BCyber risk remediation plan owners

Cyber risk remediation plan owners are responsible for long-term fixes, but the immediate response requires decision-making from those accountable for the actual risks.

CRisk owners based on risk impactCorrect

Risk owners are accountable for the specific risks that materialized and their associated impacts, making them crucial for determining appropriate response actions and understanding the full scope of the incident. This ensures that the individuals ultimately responsible for the business functions and assets affected are directly involved in resolution.

DEnterprise risk management (ERM) team

The ERM team provides oversight and framework but may not have the granular operational accountability needed for immediate response actions.

Concept tested: Incident response team composition (risk ownership)

Source: https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/secure/security-governance-risk-compliance-strategies#risk-management-framework

Topics

#Incident Response#Risk Ownership#Stakeholder Management#Cyber Crisis Management

Community Discussion

No community discussion yet for this question.

Full CRISC Practice