Isaca Certified in the Governance of Enterprise IT Exam CGEIT Question # 157 Topic 16 Discussion
CGEIT Exam Topic 16 Question 157 Discussion:
Question #: 157
Topic #: 16
An enterprise has lost an unencrypted backup tape of archived customer data. A data breach report is not mandatory in the relevant jurisdiction. From an ethical standpoint, what should the enterprise do NEXT?
A.
Initiate disciplinary proceedings against relevant employees.
B.
Mandate a review of backup tape inventory procedures.
C.
Communicate the breach to customers.
D.
Require an evaluation of storage facility vendors.
From an ethical standpoint, the enterprise should communicate the breach to customers, because they have a right to know that their personal data has been compromised and may be at risk of identity theft, fraud, or other malicious activity. Even if the data breach report is not mandatory in the relevant jurisdiction, the enterprise has a moral duty to respect the privacy and dignity of its customers, and to be transparent and accountable for its actions. Communicating the breach to customers can also help to preserve the trust and reputation of the enterprise, and to mitigate the potential legal and financial consequences of the breach. According to some data ethics experts, data breaches should be treated as public health issues, and organizations should adopt a proactive and responsible approach to inform and protect their customers12. Some examples of data breach communication best practices are: notifying customers as soon as possible, providing clear and accurate information about the nature and extent of the breach, explaining what actions the enterprise is taking to remedy the situation and prevent future incidents, offering assistanceand support to affected customers, such as identity protection services or credit monitoring, and apologizing sincerely and expressing commitment to data ethics34.
References :=
Data ethics: What it means and what it takes | McKinsey
The Skeleton of a Data Breach: The Ethical and Legal Concerns
Data breaches: A public health issue? | TheHill
How to Communicate a Data Breach Effectively - IT Governance Blog
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit