Certified Chief Information Security Officer (CCISO) — Question 109

A Security Operations Centre (SOC) manager is informed that a database containing highly sensitive corporate strategy information is under attack. Information has been stolen, and the database server was disconnected.
Who must be informed of this incident?

Answer options

Correct answer: B

Explanation

The data owner is the individual or group responsible for the management of the data, making them the most critical person to inform about the incident to assess the impact and take necessary actions. While internal audit, executive staff, and government regulators may also need to be involved later, the immediate priority is to notify the data owner for a focused response.