nerdexam
Isaca

CISM · Question #151

An organization experienced a breach which was successfully contained and remediated. Based on industry regulations, the breach needs to be communicated externally. What should the information securit

The correct answer is B. Refer to the incident response plan.. After a breach is contained and remediated, and external communication is required, the information security manager should first refer to the incident response plan to guide the notification process. This ensures compliance with established procedures and regulatory requirements

Submitted by fatema_kw· Apr 18, 2026Information Security Incident Management

Question

An organization experienced a breach which was successfully contained and remediated. Based on industry regulations, the breach needs to be communicated externally. What should the information security manager do NEXT?

Options

  • ARefer to the privacy policy.
  • BRefer to the incident response plan.
  • CSend out a breach notification to all parties involved.
  • DContact the board of directors.

How the community answered

(46 responses)
  • A
    11% (5)
  • B
    83% (38)
  • C
    4% (2)
  • D
    2% (1)

Why each option

After a breach is contained and remediated, and external communication is required, the information security manager should first refer to the incident response plan to guide the notification process. This ensures compliance with established procedures and regulatory requirements.

ARefer to the privacy policy.

While a privacy policy might mention breach notification requirements, the incident response plan provides the actionable steps and procedures for carrying out those notifications.

BRefer to the incident response plan.Correct

The incident response plan should contain detailed procedures for communication, especially external notifications, including who to notify, when, and what information to convey, in accordance with relevant industry regulations and legal obligations. Referring to the plan ensures that all necessary steps are followed methodically and legally.

CSend out a breach notification to all parties involved.

Sending out a notification immediately without consulting the incident response plan could lead to non-compliance with notification timing, content, or recipient requirements specified in the plan or regulations.

DContact the board of directors.

Contacting the board of directors is an important step for governance and significant incidents, but the specific next action for external communication procedures will be outlined in the incident response plan.

Concept tested: Post-incident breach notification procedures

Source: https://learn.microsoft.com/en-us/compliance/assurance/assurance-incident-response-plan

Topics

#Incident response#Breach notification#Regulatory compliance#Post-incident activities

Community Discussion

No community discussion yet for this question.

Full CISM Practice