ISC2 Certified in Cybersecurity (CC)Security PrinciplesHard
A retail company experiences a data breach where customer credit card information is stolen. Under specific regulations like PCI DSS, they are mandated to notify affected customers, regulatory bodies, and payment card brands within a defined timeframe. This obligation falls under which aspect of security management?
- AIncident Response
- BBusiness Continuity Planning
- CSecurity Awareness Training
- DDisaster Recovery Planning
Show answer & explanationAnswer & explanation
Correct answer: A. Incident Response
Incident response is a structured approach to managing the aftermath of a security breach or cyberattack. It includes detection, analysis, containment, eradication, recovery, and post-incident activities such as mandatory notifications and reporting.
Why the other options are wrong
- B. Business Continuity Planning focuses on maintaining business operations during disruptions.
- C. Security Awareness Training educates employees to prevent incidents, not respond to them.
- D. Disaster Recovery Planning focuses on restoring IT systems after a disaster.
Incident Response
A structured approach to managing the aftermath of a security breach or cyberattack, including detection, analysis, containment, and recovery.
- Aims to minimize damage and recovery time.
- Involves predefined steps and roles.
- Includes communication and reporting obligations.
Memory trick: Respond to incidents, recover from disasters, continue the business.