ExamGecko
Question list
Search
Search

Question 411 - CISM discussion

Report
Export

Which of the following should an information security manager do FIRST after learning through mass media of a data breach at the organization's hosted payroll service provider?

A.
Suspend the data exchange with the provider
Answers
A.
Suspend the data exchange with the provider
B.
Notify appropriate regulatory authorities of the breach.
Answers
B.
Notify appropriate regulatory authorities of the breach.
C.
Initiate the business continuity plan (BCP)
Answers
C.
Initiate the business continuity plan (BCP)
D.
Validate the breach with the provider
Answers
D.
Validate the breach with the provider
Suggested answer: D

Explanation:

The first thing an information security manager should do after learning through mass media of a data breach at the organization's hosted payroll service provider is to validate the breach with the provider, which means contacting the provider directly and confirming the details and scope of the breach, such as when it occurred, what data was compromised, and what actions the provider is taking to mitigate the impact. Validating the breach with the provider can help the information security manager assess the situation accurately and plan the next steps accordingly. The other options, such as suspending the data exchange, notifying regulatory authorities, or initiating the business continuity plan, may be premature or unnecessary before validating the breach with the provider.

Reference:

https://www.wired.com/story/sequoia-hr-data-breach/

https://cybernews.com/news/kronos-major-hr-and-payroll-service-provider-hit-with-ransomware-warns-of-a-long-outage/

https://www.afr.com/work-and-careers/workplace/pay-in-crisis-as-major-payroll-company-hacked-20211117-p599mr

asked 01/10/2024
Alexandru adrian Blaga
22 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first