nerdexam
Isaca

CISM · Question #941

Which of the following is an information security manager's BEST course of action when a breach has been confirmed at the organization's third-party provider?

The correct answer is C. Inform the incident response team of the breach. When a breach is confirmed, the immediate priority is activating the incident response process - notifying the incident response team (C) ensures the organization can assess impact, contain damage, and begin recovery without delay. Why the distractors fall short: A (on-site…

Submitted by noor.lb· Apr 18, 2026Information Security Incident Management

Question

Which of the following is an information security manager's BEST course of action when a breach has been confirmed at the organization's third-party provider?

Options

  • ASuggest an on-site review at the third party.
  • BReport the vendor to the authorities.
  • CInform the incident response team of the breach.
  • DReview service level agreements (SLAs) within the contract.

How the community answered

(17 responses)
  • A
    18% (3)
  • B
    6% (1)
  • C
    71% (12)
  • D
    6% (1)

Explanation

When a breach is confirmed, the immediate priority is activating the incident response process - notifying the incident response team (C) ensures the organization can assess impact, contain damage, and begin recovery without delay.

Why the distractors fall short:

  • A (on-site review): Useful for post-incident audits or due diligence, but reviewing the vendor in person doesn't address the active breach happening right now.
  • B (report to authorities): May be required eventually (especially for regulated data), but this decision typically comes after internal assessment and involves legal/compliance teams - not the first move.
  • D (review SLAs): SLAs define obligations and may inform next steps, but reading contracts while a breach is in progress delays the critical containment work.

Memory tip: Think of it as a fire - you call the fire department (incident response team) first, then investigate how the fire started (on-site review), check the building code violations (SLAs), and file an insurance report (authorities). Response before review, always.

Topics

#Incident response#Third-party breach#Security incident management#Managerial action

Community Discussion

No community discussion yet for this question.

Full CISM Practice