ExamGecko
Question list
Search
Search

Related questions











Question 570 - CISA discussion

Report
Export

Following a breach, what is the BEST source to determine the maximum amount of time before customers must be notified that their personal information may have been compromised?

A.
Industry regulations
Answers
A.
Industry regulations
B.
Industry standards
Answers
B.
Industry standards
C.
Incident response plan
Answers
C.
Incident response plan
D.
Information security policy
Answers
D.
Information security policy
Suggested answer: A

Explanation:

Following a breach, the maximum amount of time before customers must be notified that their personal information may have been compromised depends on the industry regulations that apply to the organization. Different industries and jurisdictions may have different legal and regulatory requirements for breach notification, such as the General Data Protection Regulation (GDPR) in the European Union, the Health Insurance Portability and Accountability Act (HIPAA) in the United States, or the Personal Information Protection and Electronic Documents Act (PIPEDA) in Canada. Industry standards, incident response plans, and information security policies are not as authoritative as industry regulations in determining the breach notification time frame.Reference:CISA Review Manual (Digital Version), [ISACA Privacy Principles and Program Management Guide]

asked 18/09/2024
Junwei Li
41 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first