nerdexam
Isaca

CISA · Question #22

Following a breach, what is the BEST source to determine the maximum amount of time before customers must be notified that their personal information may have been compromised?

The correct answer is D. Industry regulations. The maximum time for customer notification after a data breach is primarily dictated by legal and compliance obligations, which are found in industry regulations.

Submitted by carter_n· Apr 18, 2026Protection of Information Assets

Question

Following a breach, what is the BEST source to determine the maximum amount of time before customers must be notified that their personal information may have been compromised?

Options

  • AIndustry standards
  • BInformation security policy
  • CIncident response plan
  • DIndustry regulations

How the community answered

(65 responses)
  • A
    2% (1)
  • B
    8% (5)
  • C
    3% (2)
  • D
    88% (57)

Why each option

The maximum time for customer notification after a data breach is primarily dictated by legal and compliance obligations, which are found in industry regulations.

AIndustry standards

Industry standards provide best practices and guidelines but typically do not mandate legally binding notification timelines.

BInformation security policy

An organization's information security policy should reflect regulatory requirements, but the policy itself is not the primary source of the legal mandate or specific timelines.

CIncident response plan

An incident response plan outlines the procedures for notification, but the actual legally required timelines are derived from external regulations.

DIndustry regulationsCorrect

Industry regulations, such as GDPR, CCPA, or HIPAA, explicitly define the legal requirements and mandatory timelines for notifying affected individuals and supervisory authorities after a personal data breach. Non-compliance can lead to significant legal penalties and reputational damage, making them the definitive source for such requirements.

Concept tested: Data breach notification requirements

Source: https://gdpr-info.eu/art-34-gdpr/

Topics

#Data Breach Notification#Regulatory Compliance#Incident Response#Data Privacy

Community Discussion

No community discussion yet for this question.

Full CISA Practice