CISA · Question #22
Following a breach, what is the BEST source to determine the maximum amount of time before customers must be notified that their personal information may have been compromised?
The correct answer is D. Industry regulations. The maximum time for customer notification after a data breach is primarily dictated by legal and compliance obligations, which are found in industry regulations.
Question
Following a breach, what is the BEST source to determine the maximum amount of time before customers must be notified that their personal information may have been compromised?
Options
- AIndustry standards
- BInformation security policy
- CIncident response plan
- DIndustry regulations
How the community answered
(65 responses)- A2% (1)
- B8% (5)
- C3% (2)
- D88% (57)
Why each option
The maximum time for customer notification after a data breach is primarily dictated by legal and compliance obligations, which are found in industry regulations.
Industry standards provide best practices and guidelines but typically do not mandate legally binding notification timelines.
An organization's information security policy should reflect regulatory requirements, but the policy itself is not the primary source of the legal mandate or specific timelines.
An incident response plan outlines the procedures for notification, but the actual legally required timelines are derived from external regulations.
Industry regulations, such as GDPR, CCPA, or HIPAA, explicitly define the legal requirements and mandatory timelines for notifying affected individuals and supervisory authorities after a personal data breach. Non-compliance can lead to significant legal penalties and reputational damage, making them the definitive source for such requirements.
Concept tested: Data breach notification requirements
Source: https://gdpr-info.eu/art-34-gdpr/
Topics
Community Discussion
No community discussion yet for this question.