ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 242 - CS0-003 discussion

Report
Export

An organization discovered a data breach that resulted in Pll being released to the public. During the lessons learned review, the panel identified discrepancies regarding who was responsible for external reporting, as well as the timing requirements. Which of the following actions would best address the reporting issue?

A.
Creating a playbook denoting specific SLAs and containment actions per incident type
Answers
A.
Creating a playbook denoting specific SLAs and containment actions per incident type
B.
Researching federal laws, regulatory compliance requirements, and organizational policies to document specific reporting SLAs
Answers
B.
Researching federal laws, regulatory compliance requirements, and organizational policies to document specific reporting SLAs
C.
Defining which security incidents require external notifications and incident reporting in addition to internal stakeholders
Answers
C.
Defining which security incidents require external notifications and incident reporting in addition to internal stakeholders
D.
Designating specific roles and responsibilities within the security team and stakeholders to streamline tasks
Answers
D.
Designating specific roles and responsibilities within the security team and stakeholders to streamline tasks
Suggested answer: B

Explanation:

Researching federal laws, regulatory compliance requirements, and organizational policies to document specific reporting SLAs is the best action to address the reporting issue. Reporting SLAs are service level agreements that specify the time frame and the format for notifying the relevant authorities and the affected individuals of a data breach. Reporting SLAs may vary depending on the type and severity of the breach, the type and location of the data, the industry and jurisdiction of the organization, and the internal policies of the organization. By researching and documenting the reporting SLAs for different scenarios, the organization can ensure that it complies with the legal and ethical obligations of data breach notification, and avoid any penalties, fines, or lawsuits that may result from failing to report a breach in a timely and appropriate manner12.

Reference: When and how to report a breach: Data breach reporting best practices, Incident and Breach Management

asked 02/10/2024
Cheikh Ndiaye
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first