ISC2 Certified in Cybersecurity (CC)Security PrinciplesHard

A retail company experiences a data breach where customer credit card information is stolen. Under specific regulations like PCI DSS, they are mandated to notify affected customers, regulatory bodies, and payment card brands within a defined timeframe. This obligation falls under which aspect of security management?

  1. AIncident Response
  2. BBusiness Continuity Planning
  3. CSecurity Awareness Training
  4. DDisaster Recovery Planning
Show answer & explanation

Correct answer: A. Incident Response

Incident response is a structured approach to managing the aftermath of a security breach or cyberattack. It includes detection, analysis, containment, eradication, recovery, and post-incident activities such as mandatory notifications and reporting.

Why the other options are wrong

  • B. Business Continuity Planning focuses on maintaining business operations during disruptions.
  • C. Security Awareness Training educates employees to prevent incidents, not respond to them.
  • D. Disaster Recovery Planning focuses on restoring IT systems after a disaster.

Incident Response

A structured approach to managing the aftermath of a security breach or cyberattack, including detection, analysis, containment, and recovery.

  • Aims to minimize damage and recovery time.
  • Involves predefined steps and roles.
  • Includes communication and reporting obligations.

Memory trick: Respond to incidents, recover from disasters, continue the business.

More Security Principles questions