A key component to being able to respond to security incidents promptly and effectively is the establishment of a computer emergency response team (CERT) responsible for dealing with major incidents. The CERT should include not only technical specialists but also senior operations management, because some potential responses to security incidents have significant economic consequences. For example, it may be necessary to temporarily shut down an e-commerce server. The decision to do so is too important to leave to the discretion of IT security staff; only operations management possesses the breadth of knowledge to properly evaluate the costs and benefits of such an action, and only it should have the authority to make that decision.