nerdexam
GIAC

GCIH · Question #366

If an accounting department's computer system was compromised, who should make the decision about when that system is put back into production?

The correct answer is C. System owner for that system. The system owner is the person accountable for a system's business function and holds the authority to decide when a compromised system is returned to production.

Incident Response & Cyber Kill Chain

Question

If an accounting department's computer system was compromised, who should make the decision about when that system is put back into production?

Options

  • ALead incident handler, after recovery is complete
  • BHead of Information Systems or CIO
  • CSystem owner for that system
  • DSystem administrator for that system

How the community answered

(19 responses)
  • A
    5% (1)
  • C
    89% (17)
  • D
    5% (1)

Why each option

The system owner is the person accountable for a system's business function and holds the authority to decide when a compromised system is returned to production.

ALead incident handler, after recovery is complete

The lead incident handler manages the technical response process but does not hold business authority over system availability decisions.

BHead of Information Systems or CIO

The CIO or Head of IS has broad governance authority but the designated system owner is the appropriate decision maker for their specific system.

CSystem owner for that systemCorrect

The system owner is the individual responsible for the business function the system supports and bears accountability for its risk posture. They are positioned to weigh business impact against recovery completeness and make the final authorization decision. This is a foundational principle in NIST incident response and IT governance frameworks.

DSystem administrator for that system

The system administrator performs technical operations but lacks the business accountability and authority to authorize a system's return to production.

Concept tested: Incident response roles and system owner authority

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf

Topics

#incident response roles#system owner#recovery decision#IR governance

Community Discussion

No community discussion yet for this question.

Full GCIH Practice