Isaca Certified in Risk and Information Systems Control CRISC Question # 498 Topic 50 Discussion
CRISC Exam Topic 50 Question 498 Discussion:
Question #: 498
Topic #: 50
A risk practitioner has recently become aware of unauthorized use of confidential personal information within the organization. Which of the following should the risk practitioner do FIRST?
A.
Establish database activity monitoring
B.
Report the incident to the chief privacy officer (CPO)
In the event of a data breach or misuse of confidential information, the first step is to activate the incident response plan. This ensures immediate containment, impact analysis, and communication protocols are followed.
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit