QuestionQ114

Incident Detection and Response

Which of these roles is accountable for continuously approving exceptions to, and departures from, the incident management team charter?

  • A Chief information security officer (CISO)
  • B Incident response manager
  • C Cybersecurity analyst
  • D Security steering group
Explanation

The security steering group owns overarching incident-management governance, including approval of the incident management team charter and continuing authorization of exceptions or deviations. Operational responders and managers execute or supervise incident-response activities rather than approve governance-level departures.

Community Discussion

No comments yet. Be the first to start the discussion!