Courseiva
Incident Management →hardMultiple Choice

CISM Incident Management Practice Question

An organization operates in multiple jurisdictions and suffers a breach involving personal data of customers in several countries. The incident response manager must coordinate communication with regulators, customers, and internal stakeholders while the technical investigation continues. Which of the following is the MOST important consideration when developing the incident communication strategy?

⚠ Common exam trap

The trap here is choosing between speed and completeness of disclosure, when the governing consideration is legal review and alignment with jurisdiction-specific notification requirements and deadlines.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ensure all external communications are approved through legal counsel and aligned with applicable regulatory notification requirements and deadlines.

Multi-jurisdiction breaches trigger overlapping notification laws with different deadlines and content rules, so external communications must be reviewed by legal counsel and mapped to each applicable requirement. This ensures deadlines are met, statements are consistent, and privileges or ongoing investigations are not compromised. Timely, accurate, and compliant communication protects the organization legally and preserves stakeholder trust while the technical investigation proceeds in parallel.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Ensure all external communications are approved through legal counsel and aligned with applicable regulatory notification requirements and deadlines.

    Why this is correct

    Breach notification obligations vary by jurisdiction and often carry strict deadlines, content requirements, and prescribed recipients. Legal counsel must review external communications to avoid conflicting statements, waiving privileges, or missing mandatory timelines. Aligning messages with regulatory requirements protects the organization from penalties and ensures affected parties receive accurate, timely information while the investigation continues.

  • ✗

    Release detailed technical findings immediately to all customers so they can assess their own risk without delay.

    Why it's wrong here

    Releasing detailed technical findings prematurely can expose unpatched vulnerabilities, aid attackers, and conflict with legal or regulatory guidance. Customers need accurate information, but timing and content must be coordinated with counsel and investigators. Immediate disclosure of raw technical detail can also create confusion and liability without providing actionable protection, especially before the scope of the breach is confirmed.

  • ✗

    Delay all notifications until the forensic investigation is fully complete to ensure accuracy in every statement.

    Why it's wrong here

    Waiting for a complete forensic picture can cause the organization to miss mandatory notification deadlines, which may trigger penalties and erode trust. Regulations often require notification within fixed periods after discovery, even if investigation is ongoing. Communications can be staged, providing confirmed information first and updates later, rather than delaying everything until the investigation concludes.

  • ✗

    Allow each regional business unit to communicate independently using its own messaging and timing without central coordination.

    Why it's wrong here

    Independent regional messaging risks inconsistent statements, missed regulatory deadlines, and contradictory information reaching the same stakeholders. A multi-jurisdiction breach requires centralized coordination to align messages, track obligations, and maintain a consistent narrative. Regional teams should contribute local requirements, but the overall strategy must be centrally managed to avoid legal and reputational harm.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.