ExamGecko
Question list
Search
Search

Question 19 - CISM discussion

Report
Export

ACISO learns that a third-party service provider did not notify the organization of a data breach that affected the service provider's data center. Which of the following should the CISO do FIRST?

A.
Recommend canceling the outsourcing contract.
Answers
A.
Recommend canceling the outsourcing contract.
B.
Request an independent review of the provider's data center.
Answers
B.
Request an independent review of the provider's data center.
C.
Notify affected customers of the data breach.
Answers
C.
Notify affected customers of the data breach.
D.
Determine the extent of the impact to the organization.
Answers
D.
Determine the extent of the impact to the organization.
Suggested answer: D

Explanation:

The CISO should first determine the extent of the impact to the organization by assessing the nature and scope of the data breach, the type and sensitivity of the data involved, the potential harm to the organization and its customers, and the legal and contractual obligations of the organization and the service provider. This will help the CISO to prioritize the appropriate actions and resources to respond to the incident and mitigate the risks.The other options are possible actions that the CISO may take after determining the impact, depending on the circumstances and the outcomes of the investigation.Reference= CISM Review Manual 15th Edition, page 2231; CISM Review Questions, Answers & Explanations Database - 12 Month Subscription, Question ID: 1030

asked 01/10/2024
wietse Bonnes
37 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first