The accountability and authority asymmetry
In most enterprises, the executive responsible for the availability of a business service — the head of payments, the head of trading, the plant manager, the head of clinical systems — does not have the authority to prevent that service from being taken offline during an incident. The SOC has the authority. The business owner has the accountability. These are different people, often in different reporting lines, and the asymmetry only becomes visible when something is actually shut down. NIST’s SP 800-61 Revision 3, finalized in April 2025 by Amy Nelson, Shanée Rekhi, Murugiah Souppaya and Karen Scarfone, restructures the entire incident response model around the NIST Cybersecurity Framework 2.0 — moving the framing explicitly from “tactical execution” to “strategic alignment with broader risk management.” That shift is exactly the gap I am describing. The new doctrine treats incident response not as a SOC function but as an organizational risk-management activity in which the business owner is a named participant.
This is not a problem that goes away with better SOC training. It is a governance problem. The asymmetry exists because the IR playbook was written by the security function, for the security function and never went through the legal and operational review that would have surfaced it. A SOC analyst at 4 a.m. on Saturday is not the right person to decide whether the company should lose fourteen hours of payments to prevent four hours of attacker dwell time. That decision belongs to a named operational owner — and if that owner cannot be reached in time, the playbook should specify a pre-agreed safe-state action, not let the analyst improvise.
The no-touch register: A second reading of your crown jewels list
Most security programs already maintain a crown jewels register — the inventory of systems whose loss would be existential. In its standard reading, the register drives investment, patch cadence, backup frequency and monitoring depth. That reading is right but incomplete. The same list has a second function that is at least as important: It is the inventory of systems your SOC must not touch without confirmation from a named business owner.
Click Here For The Original Source.
