CS0-003 · Question #94
An incident response team detected malicious software that could have gained access to credit card data. The incident response team was able to mitigate significant damage and implement corrective act
The correct answer is C. Company leadership. Following an incident where malicious software accessed credit card data, the incident response team should notify company leadership for lessons learned after mitigating damage and implementing corrective actions.
Question
An incident response team detected malicious software that could have gained access to credit card data. The incident response team was able to mitigate significant damage and implement corrective actions. By having incident response mechanisms in place. Which of the following should be notified for lessons learned?
Options
- AThe human resources department
- BCustomers
- CCompany leadership
- DThe legal team
How the community answered
(20 responses)- A5% (1)
- C90% (18)
- D5% (1)
Why each option
Following an incident where malicious software accessed credit card data, the incident response team should notify company leadership for lessons learned after mitigating damage and implementing corrective actions.
The human resources department is typically involved in personnel-related matters, not directly in reviewing technical lessons learned from an incident response.
Customers might require notification about a data breach, but they are not involved in internal 'lessons learned' discussions about incident response processes.
Company leadership is the primary audience for lessons learned from significant security incidents, as they need to understand the impact, evaluate incident response effectiveness, and make strategic decisions for future security improvements and resource allocation.
The legal team addresses compliance and potential legal ramifications, but they are not the central body for reviewing operational 'lessons learned' regarding security posture improvement.
Concept tested: Post-incident review and communication
Source: https://csrc.nist.gov/publications/detail/sp/800-61/rev-2/final
Topics
Community Discussion
No community discussion yet for this question.