CAS-003 · Question #581
During a recent incident, sensitive data was disclosed and subsequently destroyed through a properly secured, cloud-based storage platform. An incident response technician is working with management…
The correct answer is B. The legal or regulatory exposure that exists due to the breach. Legal and regulatory exposure is the most critical metric for senior leadership because it defines the organization's binding liability and potential financial penalties resulting from the breach.
Question
During a recent incident, sensitive data was disclosed and subsequently destroyed through a properly secured, cloud-based storage platform. An incident response technician is working with management to develop an after action report that conveys critical metrics regarding the incident. Which of the following would be MOST important to senior leadership to determine the impact of the breach?
Options
- AThe likely per-record cost of the breach to the organization
- BThe legal or regulatory exposure that exists due to the breach
- CThe amount of downtime required to restore the data
- DThe number of records compromised
How the community answered
(27 responses)- A19% (5)
- B70% (19)
- C4% (1)
- D7% (2)
Why each option
Legal and regulatory exposure is the most critical metric for senior leadership because it defines the organization's binding liability and potential financial penalties resulting from the breach.
Per-record cost is a useful financial modeling metric but is secondary to legal exposure, as regulatory fines and litigation costs often dwarf per-record estimates and require different executive escalation paths.
Senior leadership is accountable for organizational risk at the strategic level, and legal or regulatory exposure quantifies the most consequential obligations the organization faces after a breach, including fines under regulations such as GDPR or HIPAA, mandatory breach notifications, and potential civil litigation. These outcomes directly affect organizational viability, reputation, and financial standing in ways that require executive decision-making and legal counsel engagement. Understanding this exposure is the starting point for determining response priority, resource allocation, and external communication strategy.
Downtime required to restore data is an operational metric relevant to IT recovery teams; because the data was already described as destroyed on a secured cloud platform, restoration time is a lower-priority concern for senior leadership.
The number of records compromised is an important quantitative input but is not independently actionable for senior leadership without the legal and regulatory context that determines what obligations and penalties flow from that number.
Concept tested: Breach impact metrics and executive reporting priorities
Source: https://csrc.nist.gov/publications/detail/sp/800-61/rev-2/final
Topics
Community Discussion
No community discussion yet for this question.