nerdexam
Isaca

CISM · Question #198

An information security manager is notified that a third-party data processor has incurred a breach for which it is believed customer data has been lost. The information security manager should FIRST:

The correct answer is D. request details of the incident.. The information security manager's first step should be to request details of the incident. This helps to understand the scope, cause, and impact of the breach before taking further actions. It is essential to gather accurate information before proceeding with customer notificati

Submitted by katya_ua· Apr 18, 2026Information Security Incident Management

Question

An information security manager is notified that a third-party data processor has incurred a breach for which it is believed customer data has been lost. The information security manager should FIRST:

Options

  • Aalert affected customers.
  • Bprevent further transfers to the third party.
  • Cnotify law enforcement.
  • Drequest details of the incident.

How the community answered

(45 responses)
  • A
    4% (2)
  • B
    7% (3)
  • C
    13% (6)
  • D
    76% (34)

Explanation

The information security manager's first step should be to request details of the incident. This helps to understand the scope, cause, and impact of the breach before taking further actions. It is essential to gather accurate information before proceeding with customer notifications, stopping data transfers, or involving law enforcement.

Topics

#Incident response#Data breach#Third-party risk#Information gathering

Community Discussion

No community discussion yet for this question.

Full CISM Practice