ExamGecko
Question list
Search
Search

Question 508 - CISM discussion

Report
Export

Which of the following is the MOST important reason for an organization to communicate to affected parties that a security incident has occurred?

A.
To improve awareness of information security
Answers
A.
To improve awareness of information security
B.
To disclose the root cause of the incident
Answers
B.
To disclose the root cause of the incident
C.
To increase goodwill toward the organization
Answers
C.
To increase goodwill toward the organization
D.
To comply with regulations regarding notification
Answers
D.
To comply with regulations regarding notification
Suggested answer: D

Explanation:

Complying with regulations regarding notification is the most important reason for an organization to communicate to affected parties that a security incident has occurred, as it helps to avoid legal penalties, fines, or sanctions that may result from failing to notify the relevant authorities, customers, or other stakeholders in a timely and appropriate manner. Additionally, complying with regulations regarding notification may also help to preserve the trust and reputation of the organization, as well as to facilitate the investigation and resolution of the incident.

Reference= CISM Review Manual 2022, page 3151; CISM Exam Content Outline, Domain 4, Task 4.5

asked 01/10/2024
cesar ganguie
42 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first