ISACA Certified Information Systems Auditor (CISA) ExamDomain 5: Protection of Information AssetsMedium

A CISA is evaluating an organization's incident response plan (IRP). The IRP outlines steps for detection, analysis, containment, eradication, recovery, and post-incident review. However, the CISA finds that the plan lacks specific procedures for handling incidents involving personally identifiable information (PII) that crosses national borders, which is a common occurrence for the organization. What is the MOST significant implication of this omission?

  1. AThe incident response team may not be adequately trained for PII breaches.
  2. BContainment and eradication efforts for PII might be delayed or ineffective.
  3. CThe organization may face increased fines and legal liabilities due to non-compliance.
  4. DPost-incident reviews will not accurately reflect the PII breach impact.
Show answer & explanation

Correct answer: C. The organization may face increased fines and legal liabilities due to non-compliance.

Incidents involving cross-border PII carry significant regulatory implications (e.g., GDPR, CCPA). A lack of specific procedures means the organization is likely to fail in meeting notification deadlines, reporting requirements, and other legal obligations, leading to substantial fines and legal liabilities.

Why the other options are wrong

  • A. Training is a separate issue; the IRP itself is lacking the foundational procedures for PII.
  • B. While possible, the immediate and most severe impact of lacking specific *procedures* for cross-border PII is regulatory non-compliance, not necessarily delayed technical steps.
  • D. Impact assessment is part of the review, but the primary risk of missing procedures is failing to meet legal obligations, which directly leads to fines.

Cross-Border PII Incident Response

Specific procedures within an incident response plan to address security incidents involving personally identifiable information that is processed or transferred across national boundaries.

  • Mandated by international data protection laws (e.g., GDPR).
  • Involves specific notification, reporting, and remediation requirements.
  • Non-compliance can lead to severe fines and legal consequences.

Memory trick: When PII crosses borders, the legal eagles are watching, and an incomplete plan means fines.

More Domain 5: Protection of Information Assets questions