CompTIA CySA+ (CS0-003)Reporting and CommunicationMedium
A security analyst is tasked with generating a compliance report for the General Data Protection Regulation (GDPR). The organization recently experienced an incident involving unauthorized access to customer data. The report needs to include a metric that demonstrates the organization's commitment to data protection post-incident. Which of the following would be the MOST relevant metric to include for GDPR compliance reporting?
- ATotal volume of encrypted data at rest.
- BNumber of successful phishing emails blocked.
- CMean Time To Patch (MTTP) critical vulnerabilities.
- DPercentage of data subjects notified within 72 hours of breach discovery.
Show answer & explanationAnswer & explanation
Correct answer: D. Percentage of data subjects notified within 72 hours of breach discovery.
GDPR Article 33 and 34 explicitly mandate data breach notification to supervisory authorities within 72 hours and to affected data subjects without undue delay, respectively. Therefore, the 'percentage of data subjects notified within 72 hours of breach discovery' directly demonstrates compliance with these critical GDPR requirements post-incident.
Why the other options are wrong
- A. Encrypting data at rest is a protective measure, but this metric doesn't directly address the post-incident reporting or commitment required by GDPR for a breach.
- B. While important for security, this metric does not directly address GDPR's specific breach notification requirements.
- C. MTTP is a vulnerability management metric and does not directly relate to GDPR's breach notification or post-incident data protection commitment.
GDPR Breach Notification Compliance
GDPR mandates strict timelines for notifying supervisory authorities (72 hours) and affected data subjects (without undue delay) about personal data breaches, demonstrating an organization's commitment to data protection and transparency.
- Article 33: Notification to supervisory authority.
- Article 34: Communication to data subject.
- Timeliness is critical for compliance.
Memory trick: GDPR: Get Data Protected, Report Breaches Promptly.