CISSP Security and Risk Management Practice Question
An organization is required to report a personal data breach to the supervisory authority within 72 hours. Which regulation imposes this requirement?
⚠ Common exam trap
CISSP often tests the confusion between GDPR's 72-hour supervisory authority notification and HIPAA's 60-day HHS notification, or PCI DSS's contractual breach reporting — candidates must anchor on the exact 72-hour figure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
GDPR
The GDPR (General Data Protection Regulation) Article 33 mandates that controllers notify the supervisory authority of a personal data breach within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to rights and freedoms. This 72-hour window is a signature GDPR requirement. No other listed regulation imposes this specific timeline for personal data breaches.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
GDPR
Why this is correct
The General Data Protection Regulation (GDPR) explicitly mandates that organizations report personal data breaches to the relevant supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware of it. This strict timeline applies unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. It also requires notification to affected data subjects if the breach poses a high risk.
- ✗
PCI DSS
Why it's wrong here
The Payment Card Industry Data Security Standard (PCI DSS) is a set of security standards focused on protecting cardholder data, not a general data privacy regulation. While it requires organizations to have an incident response plan and notify payment brands and acquiring banks in the event of a breach involving cardholder data, it does not specify a universal 72-hour notification requirement to regulatory authorities or data subjects for all breaches.
- ✗
SOX
Why it's wrong here
The Sarbanes-Oxley Act (SOX) of 2002 was enacted primarily to protect investors by improving the accuracy and reliability of corporate financial reporting. Its scope encompasses corporate governance, internal controls over financial reporting, and accountability for financial accuracy. SOX does not contain specific provisions or timelines for reporting personal data breaches to authorities, as its focus is entirely distinct from data privacy regulations.
- ✗
HIPAA
Why it's wrong here
The Health Insurance Portability and Accountability Act (HIPAA) governs the privacy and security of protected health information (PHI) and includes breach notification requirements. While HIPAA's Breach Notification Rule mandates notifying affected individuals, the Secretary of HHS, and sometimes the media, the timeline for notification to the Secretary is generally within 60 days of discovery for breaches affecting 500 or more individuals, not the 72 hours specified in the question.
Go deeper
Related to this question
Learn chapter
Asset Security: Privacy and Data Retention
Key term
Data protection
Data protection refers to the practices and technologies used to safeguard personal and sensitive information from unauthorized access, loss, or corruption.
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
About these practice questions
One of 816 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.