QuestionQ276

Privacy Risk Assessment and Risk Management

The privacy team has learned of a potential breach of customer data resulting from a hack of a vendor’s network. What is the best next step for managing this incident?

  • A Identify the territories where the customers reside and report to the appropriate authorities.
  • B Meet with the Legal and Security teams to determine whether an actual breach occurred.
  • C Inform all impacted customers and explain that further information gathering is in process.
  • D Take no action since the hack was on the vendor's network and there are no reporting requirements for the company.
Explanation

A suspected vendor security incident should be promptly escalated for legal and security investigation to establish whether a personal-data breach actually occurred and to assess its impact and reporting threshold. Notification to authorities or affected individuals depends on that determination and the resulting risk assessment; use of a vendor does not remove the organization’s responsibilities.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!