nerdexam
Isaca

CISM · Question #246

An organization has been penalized by regulatory authorities for failing to notify them of a major security breach that may have compromised customer data. Which of the following is MOST likely in…

The correct answer is C. Incident communication plan. The penalty was specifically for failing to notify regulatory authorities - a communication failure, not a detection or response failure. The Incident Communication Plan governs who must be notified, by whom, by when, and through what channels when a breach occurs. The BCP (B)…

Submitted by yaw92· Apr 18, 2026Information Security Incident Management

Question

An organization has been penalized by regulatory authorities for failing to notify them of a major security breach that may have compromised customer data. Which of the following is MOST likely in need of review and updating to prevent similar penalties in the future?

Options

  • AInformation security policies and procedures
  • BBusiness continuity plan (BCP)
  • CIncident communication plan
  • DIncident response training program

How the community answered

(22 responses)
  • A
    14% (3)
  • B
    5% (1)
  • C
    77% (17)
  • D
    5% (1)

Explanation

The penalty was specifically for failing to notify regulatory authorities - a communication failure, not a detection or response failure. The Incident Communication Plan governs who must be notified, by whom, by when, and through what channels when a breach occurs. The BCP (B) focuses on operational continuity, not notifications. Security policies (A) are too broad to directly cause a notification failure. Training (D) may have contributed but is secondary - if the communication plan itself does not mandate regulatory notification with defined timelines, no amount of training will fix that gap.

Topics

#Incident communication#Regulatory compliance#Breach notification#Incident response planning

Community Discussion

No community discussion yet for this question.

Full CISM Practice