An organization learns that a service provider experienced a breach last month and did not notify the organization. Which of the following should be the information security manager's FIRST course of action?
C - Prompt communication with senior management ensures they are aware of the situation, allowing for timely decisions and appropriate actions. It is essential to keep organizational leadership informed about security incidents.
I would check the contract first to understand whether there was something about communicating the breaches with the business, before I do anything else.
D. Review the provider contract.Terminating the provider contract (Option A) might be premature without understanding the contractual obligations and the specific details of the breach. Conducting a BIA (Option B) is important but secondary to understanding the legal and contractual aspects. Informing senior management (Option C) is a crucial step but should typically follow an initial assessment and understanding of the situation based on the contract review.
upvoted 1 times
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Booict
4 months agoAlexJacobson
9 months, 3 weeks agojcisco123
9 months, 4 weeks ago