CompTIA CySA+ (CS0-003)Reporting and CommunicationMedium
A security analyst discovers a critical vulnerability in a production web application that has a CVSSv3 base score of 9.8. The vulnerability allows unauthenticated remote code execution. The development team is currently focused on a major feature release. Which stakeholder group should be immediately informed, emphasizing the potential for data breach and service unavailability, to ensure prompt prioritization and resource allocation for remediation?
- AHuman Resources department
- BLegal department
- CExecutive leadership and application owners
- DEnd-users of the web application
Show answer & explanationAnswer & explanation
Correct answer: C. Executive leadership and application owners
Executive leadership and application owners have the authority to re-prioritize development efforts and allocate resources. They need to understand the critical business impact (data breach, service unavailability) to make informed decisions.
Why the other options are wrong
- A. Human Resources is not directly involved in the technical remediation or business prioritization of cybersecurity vulnerabilities.
- B. The legal department handles compliance and potential litigation, but they don't directly facilitate remediation prioritization or resource allocation.
- D. End-users are not the primary group for immediate vulnerability remediation prioritization; they would be informed after a fix or if service is impacted.
Executive Stakeholder Communication
The process of informing and engaging senior management and business owners about cybersecurity risks, incidents, and remediation efforts, focusing on business impact and strategic decisions.
- Prioritizes business context over technical jargon.
- Aims to secure resources and approval for security initiatives.
- Essential for managing high-impact risks effectively.
Memory trick: Critical issues need C-level attention for 'Cash and Control'.