ExamGecko
Question list
Search
Search

Question 560 - CISM discussion

Report
Export

Which of the following should be an information security manager's FIRST course of action when one of the organization's critical third-party providers experiences a data breach?

A.
Inform the public relations officer.
Answers
A.
Inform the public relations officer.
B.
Inform customers of the breach.
Answers
B.
Inform customers of the breach.
C.
Invoke the incident response plan.
Answers
C.
Invoke the incident response plan.
D.
Monitor the third party's response.
Answers
D.
Monitor the third party's response.
Suggested answer: C

Explanation:

The information security manager's first course of action when one of the organization's critical third-party providers experiences a data breach should be to invoke the incident response plan that has been established for such scenarios. The incident response plan should define the roles and responsibilities, communication channels, escalation procedures, and recovery actions for dealing with a third-party data breach. Invoking the incident response plan will help to contain the impact, assess the damage, coordinate the response, and restore the normal operations as soon as possible.

Reference= CISM Review Manual, 16th Edition, page 290

asked 01/10/2024
Dylan Ogle
45 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first