BCS Foundation Certificate in Information Security Management Principles V9.0 CISMP-V9 Question # 9 Topic 1 Discussion
CISMP-V9 Exam Topic 1 Question 9 Discussion:
Question #: 9
Topic #: 1
Why might the reporting of security incidents that involve personal data differ from other types of security incident?
A.
Personal data is not highly transient so its 1 investigation rarely involves the preservation of volatile memory and full forensic digital investigation.
B.
Personal data is normally handled on both IT and non-IT systems so such incidents need to be managed in two streams.
C.
Data Protection legislation normally requires the reporting of incidents involving personal data to a Supervisory Authority.
D.
Data Protection legislation is process-oriented and focuses on quality assurance of procedures and governance rather than data-focused event investigation
The reporting of security incidents involving personal data is distinct from other types of incidents primarily due to the legal obligations imposed by data protection legislation. Such laws typically mandate that organizations report certain types of breaches involving personal data to a Supervisory Authority within a specified timeframe. This requirement is in place to ensure prompt and appropriate response to potential privacy risks affecting individuals’ rights and freedoms. Failure to comply can result in significant penalties for the organization. The reporting process also often includes notifying affected individuals, especially if there is a high risk of adverse effects on their rights and freedoms12.
References :=
The UK GDPR and the Data Protection Act 2018 outline the duty of organizations to report certain personal data breaches to the relevant supervisory authority, such as the ICO, within 72 hours of becoming aware of the breach1.
The ICO’s guide on personal data breaches provides detailed instructions on how to recognize a breach, the reporting process, and the importance of having robust breach detection, investigation, and internal reporting procedures12.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit