CISM · Question #474
Which of the following should an information security manager do FIRST when informed that customer data has been breached within a third-party vendor's environment?
The correct answer is A. Request evidence of the breach.. The first step when informed of a customer data breach at a third-party vendor is to verify the breach by requesting evidence from the vendor. This helps confirm the nature, scope, and impact of the incident before taking further action. Once verified, the incident response team,
Question
Which of the following should an information security manager do FIRST when informed that customer data has been breached within a third-party vendor's environment?
Options
- ARequest evidence of the breach.
- BNotify the incident response team.
- CInform legal counsel.
- DReview vendor obligations in the contract.
How the community answered
(29 responses)- A83% (24)
- B3% (1)
- C10% (3)
- D3% (1)
Explanation
The first step when informed of a customer data breach at a third-party vendor is to verify the breach by requesting evidence from the vendor. This helps confirm the nature, scope, and impact of the incident before taking further action. Once verified, the incident response team, legal counsel, and contract obligations can be reviewed to determine the appropriate response. Acting without verification could lead to unnecessary escalation or misinformed decisions.
Topics
Community Discussion
No community discussion yet for this question.