CISM Incident Management Practice Question
An organization experiences a data breach involving customer personally identifiable information (PII). The incident response team has contained the breach. Which of the following should be the PRIMARY consideration when deciding whether to notify affected customers?
⚠ Common exam trap
The trap here is focusing on business or PR considerations instead of the mandatory legal and regulatory requirements that govern breach notification.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Legal and regulatory requirements for breach notification.
The primary consideration for notifying affected customers after a data breach is compliance with legal and regulatory requirements. These laws dictate the circumstances, timing, and method of notification. Failure to comply can result in significant penalties and legal liability. While cost, PR, and stock price are important, they are secondary to legal obligations and the ethical duty to protect customers.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The cost of providing credit monitoring services.
Why it's wrong here
While cost is a factor, it is not the primary consideration. Legal and regulatory requirements, as well as ethical obligations, take precedence. The decision to notify should be based on the potential harm to individuals and legal mandates, not solely on financial impact. Cost may influence how notification is done, but it should not drive the decision itself.
- ✗
The potential impact on the organization's stock price.
Why it's wrong here
Stock price impact is a business concern but not the primary consideration for notification. Legal and ethical obligations to protect customers' data and inform them of a breach take precedence. While investor relations may be a factor, it should not dictate whether notification occurs. Prioritizing stock price could lead to legal violations and long-term reputational harm.
- ✓
Legal and regulatory requirements for breach notification.
Why this is correct
Legal and regulatory requirements, such as GDPR, HIPAA, or state breach notification laws, mandate when and how affected individuals must be notified. These requirements are the primary consideration because failure to comply can result in fines, legal action, and reputational damage. The organization must assess the breach against these laws to determine its obligations.
- ✗
The organization's public relations strategy.
Why it's wrong here
Public relations is important for managing reputation, but it is not the primary driver for notification. The decision should be based on legal requirements and the risk to affected individuals. PR considerations may shape the messaging, but they should not override legal or ethical obligations. Prioritizing PR over legal duties could lead to further legal repercussions.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.