CGEIT · Question #384
An enterprise has lost an unencrypted backup tape of archived customer data. A data breach report is not mandatory in the relevant jurisdiction. From an ethical standpoint, what should the…
The correct answer is C. Communicate the breach to customers. From an ethical standpoint, even if not legally mandated, the enterprise should immediately communicate the data breach to its customers, as they have a right to know their personal information may have been compromised. This demonstrates transparency and ethical responsibility…
Question
An enterprise has lost an unencrypted backup tape of archived customer data. A data breach report is not mandatory in the relevant jurisdiction. From an ethical standpoint, what should the enterprise do NEXT?
Options
- AInitiate disciplinary proceedings against relevant employees.
- BMandate a review of backup tape inventory procedures.
- CCommunicate the breach to customers.
- DRequire an evaluation of storage facility vendors.
How the community answered
(47 responses)- A4% (2)
- B15% (7)
- C72% (34)
- D9% (4)
Why each option
From an ethical standpoint, even if not legally mandated, the enterprise should immediately communicate the data breach to its customers, as they have a right to know their personal information may have been compromised. This demonstrates transparency and ethical responsibility towards affected individuals.
Initiating disciplinary proceedings is an internal HR matter and doesn't address the ethical obligation to the affected customers.
Mandating a review of inventory procedures is an important corrective action for future prevention but does not address the immediate ethical duty to inform those affected by the current breach.
From an ethical standpoint, transparency and responsibility towards customers dictate that they should be informed when their personal data may have been compromised, even if there's no legal mandate. This allows customers to take their own protective measures and upholds the enterprise's commitment to ethical conduct and trust.
Requiring an evaluation of storage vendors is another important internal corrective and preventative action, but it doesn't fulfill the immediate ethical obligation to customers affected by the breach.
Concept tested: Ethical Data Breach Response
Topics
Community Discussion
No community discussion yet for this question.