Exam CISA All QuestionsBrowse all questions from this exam
Question 344

Following a breach, what is the BEST source to determine the maximum amount of time before customers must be notified that their personal information may have been compromised?

    Correct Answer: D

    The best source to determine the maximum amount of time before customers must be notified that their personal information may have been compromised is industry regulations. Industry regulations are legally binding rules set by governmental or regulatory bodies that dictate specific requirements and standards for various aspects of operations, including data breach notifications. These regulations are designed to provide clear and enforceable guidelines on how organizations should manage and respond to data breaches, including timelines for notifying affected customers.

Discussion
starzuuOption: D

i think D makes more sense. Regulations would matter more when it comes to deciding the maximum.

46080f2Option: C

C. is correct: “Following a breach ,..” is the key phrase here. It is about the best source for an urgent operational action and not about which is the best source to create the incident response plan. A Google search with operator 'site:isaca.org' and search term 'incident response plan' gives us an ISACA QAE compliant answer. An incident response plan has to be created according to different ‘incident response models’ depending on the industry. In other words, by the time the operational issue arises, the industry-related regulations have long been integrated into the incident response plan and the only thing left to do is to act accordingly. And the best source for this at the time of "following a breach..." is the incident response plan.

MunaMOption: D

answer should be D

analuisamoreiraOption: C

This is not subject of industry regulations.

kGiGa

Who should know the maximum time? The regulator, the auditor or the person who responsible for handling the incident?

AliHamzaOption: C

C is correct. When you create incident response plan you add this detail

3008Option: D

the best source to determine the maximum amount of time before customers must be notified after a data breach is industry regulations.

ItsBananass

Following a breach, what is the BEST SOURCE to determine the maximum amount ...

ItsBananass

I think the source is the incident response plan. While dealing with an incident do you want to look up breach notification research, best practices, industry standards and my not be right for your company.

testhongbrianOption: D

D for sure

Eric0223Option: D

regulartion should be top priority than others, otherwise, what s the point of this notifcation sooner or later?

JulianleehkOption: C

The question talking about breach, C could be correct.