200-201 Question 344
Single answerA cybersecurity analyst is tasked with aligning organizational stakeholders with the NIST Incident Response (IR) Lifecycle as part of a compliance effort. Which of the following stakeholders is MOST responsible for overseeing the 'Detection and Analysis' category under the NIST IR framework?
- A
IT Operations Team
- B
Incident Response Team (IRT)
- C
Executive Leadership
- D
Legal and Compliance Team
Show answer and explanation
Correct answer: B
Explanation
The 'Detection and Analysis' category of the NIST Incident Response Lifecycle is centered around identifying potential security events, analyzing them for legitimacy, and determining their impact. The Incident Response Team (IRT) is specifically trained and equipped for this role, whereas other stakeholders like IT Operations or Legal teams have supporting or peripheral responsibilities. Therefore, the IRT is the most appropriate choice for handling this category.
- A. Incorrect.
The IT Operations Team generally supports the implementation and maintenance of systems but is not primarily responsible for detecting and analyzing incidents. Their role is more reactive when systems go down or need updates.
- B. Correct.
The Incident Response Team (IRT) is directly tasked with identifying, analyzing, and confirming security events as incidents. They are the primary actors in the 'Detection and Analysis' phase of the NIST IR framework, making them the correct choice.
- C. Incorrect.
Executive Leadership focuses on approving budgets, strategies, and making high-level decisions. They are not directly involved in the 'Detection and Analysis' process.
- D. Incorrect.
The Legal and Compliance Team ensures compliance with legal and regulatory requirements but does not have direct involvement in the technical detection and analysis of security incidents.