nerdexam
Isaca

CGEIT · Question #384

An enterprise has lost an unencrypted backup tape of archived customer data. A data breach report is not mandatory in the relevant jurisdiction. From an ethical standpoint, what should the…

The correct answer is C. Communicate the breach to customers. From an ethical standpoint, even if not legally mandated, the enterprise should immediately communicate the data breach to its customers, as they have a right to know their personal information may have been compromised. This demonstrates transparency and ethical responsibility…

Submitted by joshua94· Apr 18, 2026Governance of Enterprise IT

Question

An enterprise has lost an unencrypted backup tape of archived customer data. A data breach report is not mandatory in the relevant jurisdiction. From an ethical standpoint, what should the enterprise do NEXT?

Options

  • AInitiate disciplinary proceedings against relevant employees.
  • BMandate a review of backup tape inventory procedures.
  • CCommunicate the breach to customers.
  • DRequire an evaluation of storage facility vendors.

How the community answered

(47 responses)
  • A
    4% (2)
  • B
    15% (7)
  • C
    72% (34)
  • D
    9% (4)

Why each option

From an ethical standpoint, even if not legally mandated, the enterprise should immediately communicate the data breach to its customers, as they have a right to know their personal information may have been compromised. This demonstrates transparency and ethical responsibility towards affected individuals.

AInitiate disciplinary proceedings against relevant employees.

Initiating disciplinary proceedings is an internal HR matter and doesn't address the ethical obligation to the affected customers.

BMandate a review of backup tape inventory procedures.

Mandating a review of inventory procedures is an important corrective action for future prevention but does not address the immediate ethical duty to inform those affected by the current breach.

CCommunicate the breach to customers.Correct

From an ethical standpoint, transparency and responsibility towards customers dictate that they should be informed when their personal data may have been compromised, even if there's no legal mandate. This allows customers to take their own protective measures and upholds the enterprise's commitment to ethical conduct and trust.

DRequire an evaluation of storage facility vendors.

Requiring an evaluation of storage vendors is another important internal corrective and preventative action, but it doesn't fulfill the immediate ethical obligation to customers affected by the breach.

Concept tested: Ethical Data Breach Response

Topics

#Ethical Responsibility#Data Breach Response#Customer Communication#Information Security Governance

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice