nerdexam
Isaca

CGEIT · Question #662

New legislation requires an enterprise to report cybersecurity incidents to a government agency within a defined timeline. Which of the following should be the FIRST course of action?

The correct answer is D. Understand requirements and definitions for reportable incidents.. The absolute first step when new legislation mandates incident reporting is to thoroughly understand the specific requirements and definitions of what constitutes a reportable incident.

Submitted by diego_uy· Apr 18, 2026Governance of Enterprise IT

Question

New legislation requires an enterprise to report cybersecurity incidents to a government agency within a defined timeline. Which of the following should be the FIRST course of action?

Options

  • AEstablish an incident reporting system and hotline.
  • BRequire automation of incident reporting to agencies.
  • CEstablish a cybersecurity incident manager role.
  • DUnderstand requirements and definitions for reportable incidents.

How the community answered

(56 responses)
  • A
    4% (2)
  • B
    7% (4)
  • C
    13% (7)
  • D
    77% (43)

Why each option

The absolute first step when new legislation mandates incident reporting is to thoroughly understand the specific requirements and definitions of what constitutes a reportable incident.

AEstablish an incident reporting system and hotline.

Establishing reporting systems and hotlines is a technical and procedural step that must be guided by a clear understanding of the reporting requirements.

BRequire automation of incident reporting to agencies.

Automating incident reporting is an advanced implementation step that can only be pursued effectively once the reporting criteria and processes are fully understood.

CEstablish a cybersecurity incident manager role.

Establishing an incident manager role is a necessary organizational step, but the manager needs a clear understanding of the legal requirements to effectively manage reportable incidents.

DUnderstand requirements and definitions for reportable incidents.Correct

Before implementing any solutions or roles, the enterprise must thoroughly understand the specific requirements, definitions, and timelines stipulated by the new legislation for reportable incidents. This foundational understanding ensures that all subsequent actions, such as system development or role establishment, are accurately aligned with legal obligations and prevents misinterpretations or non-compliance.

Concept tested: Legal compliance and requirement analysis

Source: https://learn.microsoft.com/en-us/compliance/regulatory/gdpr-incident-response

Topics

#Regulatory compliance#Legal requirements#Incident reporting#Governance framework

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice