CISM · Question #328
An information security manager has confirmed the organization's cloud provider has unintentionally published some of the organization's business data. Which of the following should be done NEXT?
The correct answer is B. Invoke the incident response plan. When a data exposure incident is confirmed, the immediate priority is to invoke the incident response plan (B) - this is the structured, pre-approved process for containing, assessing, and remediating a breach, and it coordinates all subsequent actions under a defined…
Question
An information security manager has confirmed the organization's cloud provider has unintentionally published some of the organization's business data. Which of the following should be done NEXT?
Options
- AReview the cloud provider's service level agreement (SLA).
- BInvoke the incident response plan.
- CInitiate the organization's data loss prevention (DLP) processes.
- DIdentify users associated with the exposed data.
How the community answered
(61 responses)- A7% (4)
- B72% (44)
- C18% (11)
- D3% (2)
Explanation
When a data exposure incident is confirmed, the immediate priority is to invoke the incident response plan (B) - this is the structured, pre-approved process for containing, assessing, and remediating a breach, and it coordinates all subsequent actions under a defined framework.
Why the distractors are wrong:
- A (Review the SLA): Reviewing the SLA is a contractual/legal step relevant to accountability and remediation costs, but it's not an immediate response action - it can happen within the incident response process, not before it.
- C (Initiate DLP processes): DLP is a preventative control designed to stop data from leaving - it's too late to prevent the exposure that already occurred, and DLP actions would fall under the incident response plan anyway.
- D (Identify affected users): This is a valid step, but it's part of executing the incident response plan, not something you do before invoking it.
Memory tip: Think of the incident response plan as the "master switch" - when a confirmed incident occurs, you pull it first, and everything else (legal review, user notification, DLP assessment) flows from it. On exams, if an incident is confirmed, the answer is almost always "invoke the IR plan" before any specific tactical action.
Topics
Community Discussion
No community discussion yet for this question.