QuestionQ223

Federal Privacy Laws

Which of the following measures would NOT have helped Crashpuppy reduce the financial impact of the security incidents?

  • A An indemnification provision in its Werkforce contract
  • B Comprehensive cybersecurity insurance
  • C A privacy policy on its website
  • D Multifactor authentication
Explanation

A website privacy policy generally discloses an organization’s data practices; it does not prevent phishing-based disclosure or unauthorized account access, nor does it fund incident response, ransom-related losses, or liability. By contrast, contractual indemnification can shift covered losses, cybersecurity insurance can cover cyberattack and breach-related costs, and multifactor authentication helps reduce unauthorized account compromise. The FTC identifies cyber insurance as protection against cyberattack losses, including breach response, extortion, and third-party claims, while CISA identifies MFA as an additional control that helps ensure only authorized users access business accounts.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!