Certified in the Governance of Enterprise IT (CGEIT) — Question 124
Senior management is reviewing the results of a recent security incident with significant business impact. Which of the following findings should be of GREATEST concern?
Answer options
- A. Response efforts had to be outsourced due to insufficient internal resources.
- B. Significant gaps are present in the incident documentation.
- C. Response decisions were made without consulting the appropriate authority.
- D. The incident was not logged in the ticketing system.
Correct answer: C
Explanation
The most concerning finding is that response decisions were made without consulting the appropriate authority, as this can lead to mismanagement and further complications during the incident response. While outsourcing, documentation gaps, and logging issues are important, they are secondary to the potential chaos caused by not involving the right decision-makers.