nerdexam
Isaca

CGEIT · Question #576

An interna! health organization has been notified that a data breach has resulted in patient records being published online. Which of the following is MOST important consideration when determining the

The correct answer is C. Context of the breach, including data ownership and location. When a data breach occurs, understanding the context of the breach, specifically data ownership and location, is the most crucial factor for determining how to meet legal and regulatory obligations.

Submitted by mateo_ar· Apr 18, 2026Governance of Enterprise IT

Question

An interna! health organization has been notified that a data breach has resulted in patient records being published online. Which of the following is MOST important consideration when determining the process for meeting the organization's legal and regulatory obligations?

Options

  • AOrganizational structure, including accountable partes
  • BData classification and related security policy
  • CContext of the breach, including data ownership and location
  • DDetails of how the breach occurred and related incident response efforts

How the community answered

(33 responses)
  • A
    6% (2)
  • B
    18% (6)
  • C
    48% (16)
  • D
    27% (9)

Why each option

When a data breach occurs, understanding the context of the breach, specifically data ownership and location, is the most crucial factor for determining how to meet legal and regulatory obligations.

AOrganizational structure, including accountable partes

Organizational structure and accountable parties are important for internal incident response and assigning responsibilities but do not directly dictate the *process* for meeting external legal/regulatory obligations, which are external mandates.

BData classification and related security policy

Data classification and security policy are internal frameworks for protecting data, but the breach context (ownership, location) dictates which *external* legal/regulatory frameworks are triggered, rather than just internal policies.

CContext of the breach, including data ownership and locationCorrect

Legal and regulatory obligations for data breaches are often dictated by the type of data (ownership) and where it was stored or processed (location), as these factors determine which specific data protection laws (e.g., HIPAA, GDPR, state-specific laws) apply and what reporting requirements must be followed. Different jurisdictions and data types have varying compliance mandates.

DDetails of how the breach occurred and related incident response efforts

While details of how the breach occurred are vital for incident response and prevention, they are secondary to understanding the *context* (what data, where) that defines the initial legal and regulatory scope and reporting requirements.

Concept tested: Data breach legal/regulatory compliance factors

Topics

#Data Breach Response#Legal Compliance#Regulatory Obligations#Data Jurisdiction

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice