ExamGecko
Question list
Search
Search

Question 636 - CISM discussion

Report
Export

Which of the following should be an information security manager's FIRST course of action when one of the organization's critical third-party providers experiences a data breach?

A.
Inform the public relations officer.
Answers
A.
Inform the public relations officer.
B.
Monitor the third party's response.
Answers
B.
Monitor the third party's response.
C.
Invoke the incident response plan.
Answers
C.
Invoke the incident response plan.
D.
Inform customers of the breach.
Answers
D.
Inform customers of the breach.
Suggested answer: C

Explanation:

The first course of action when one of the organization's critical third-party providers experiences a data breach is to invoke the incident response plan, which means activating the incident response team and following the predefined procedures and protocols to respond to the breach. Invoking the incident response plan helps to coordinate the communication and collaboration with the third-party provider, assess the scope and impact of the breach, contain and eradicate the threat, recover the affected systems and data, and report and disclose the incident to the relevant stakeholders and authorities.

Reference=Cybersecurity Incident Response Exercise Guidance - ISACA,Plan for third-party cybersecurity incident management

asked 01/10/2024
Daniel Vong
42 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first