Courseiva
Incident Management →easyMultiple Choice

CISM Incident Management Practice Question

An organization has just experienced a data breach involving customer personal information. The incident manager is determining the appropriate communication strategy. Which action BEST aligns with CISM incident management practices?

⚠ Common exam trap

The trap here is equating transparency with immediate full technical disclosure, when CISM expects coordinated, legally reviewed communication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Coordinate with legal counsel and communications to notify affected parties and regulators as required.

Breach communication should be coordinated with legal counsel and communications to ensure regulatory notifications and customer messaging are timely, accurate, and compliant. Premature public disclosure, indefinite delay, and selective notification all fail to meet CISM expectations for structured, legally sound, and ethical incident communication.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Coordinate with legal counsel and communications to notify affected parties and regulators as required.

    Why this is correct

    CISM emphasizes that breach communication must be coordinated with legal counsel and communications teams to ensure regulatory notifications and customer messaging are accurate, timely, and compliant. This approach balances transparency with legal obligations and reputational management. It is the best action because it follows a structured, stakeholder-informed process rather than unilateral or premature disclosure.

  • ✗

    Notify only the customers who are likely to complain, to minimize business disruption.

    Why it's wrong here

    Selective notification based on likelihood of complaint is unethical and likely illegal. CISM requires notifying all affected parties as required by law and policy, not just those expected to complain. This approach would violate regulatory obligations, damage trust, and potentially lead to penalties. It is clearly wrong because it prioritizes business convenience over legal and ethical responsibilities.

  • ✗

    Publicly disclose all technical details of the breach immediately to demonstrate transparency.

    Why it's wrong here

    Immediate public disclosure of all technical details can expose vulnerabilities, hinder investigation, and create legal and reputational risks. CISM recommends coordinated communication with legal, communications, and executive stakeholders to determine what to disclose and when. Releasing raw technical details without review may also violate regulatory requirements or tip off attackers, so it is not the best practice.

  • ✗

    Delay all notifications until the forensic investigation is completely finished, regardless of regulatory deadlines.

    Why it's wrong here

    Delaying notifications until the investigation is fully complete can violate regulatory deadlines and erode customer trust. CISM expects organizations to meet legal notification timelines while continuing investigation. Waiting indefinitely is not acceptable because many jurisdictions require prompt disclosure. The correct approach is coordinated notification based on known facts and legal guidance, not indefinite delay.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.