nerdexam
Isaca

CISM · Question #474

Which of the following should an information security manager do FIRST when informed that customer data has been breached within a third-party vendor's environment?

The correct answer is A. Request evidence of the breach.. The first step when informed of a customer data breach at a third-party vendor is to verify the breach by requesting evidence from the vendor. This helps confirm the nature, scope, and impact of the incident before taking further action. Once verified, the incident response team,

Submitted by krish.m· Apr 18, 2026Information Security Incident Management

Question

Which of the following should an information security manager do FIRST when informed that customer data has been breached within a third-party vendor's environment?

Options

  • ARequest evidence of the breach.
  • BNotify the incident response team.
  • CInform legal counsel.
  • DReview vendor obligations in the contract.

How the community answered

(29 responses)
  • A
    83% (24)
  • B
    3% (1)
  • C
    10% (3)
  • D
    3% (1)

Explanation

The first step when informed of a customer data breach at a third-party vendor is to verify the breach by requesting evidence from the vendor. This helps confirm the nature, scope, and impact of the incident before taking further action. Once verified, the incident response team, legal counsel, and contract obligations can be reviewed to determine the appropriate response. Acting without verification could lead to unnecessary escalation or misinformed decisions.

Topics

#Incident response#Third-party breach#Breach verification#Initial incident action

Community Discussion

No community discussion yet for this question.

Full CISM Practice