ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 564 - CGEIT discussion

Report
Export

An interna! health organization has been notified that a data breach has resulted in patient records being published online. Which of the following is MOST important consideration when determining the process for meeting the organization's legal and regulatory obligations?

A.

Organizational structure, including accountable partes

Answers
A.

Organizational structure, including accountable partes

B.

Data classification and related security policy

Answers
B.

Data classification and related security policy

C.

Context of the breach, including data ownership and location

Answers
C.

Context of the breach, including data ownership and location

D.

Details of how the breach occurred and related incident response efforts

Answers
D.

Details of how the breach occurred and related incident response efforts

Suggested answer: C

Explanation:

When determining the process for meeting an internal health organization's legal and regulatory obligations following a data breach, the most important consideration is the context of the breach, including data ownership and location. Understanding who owns the breached data and where it was stored or processed is crucial for determining jurisdictional and regulatory requirements. This context informs the organization's legal obligations, such as notification requirements and potential liabilities. While organizational structure, data classification, security policy, and details of the breach and incident response efforts are relevant, the context of the breach is paramount in guiding the legal and regulatory response.

asked 18/11/2024
THARINDU AMARASINGHE
30 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first