What Is the First Step After an Undisclosed Vendor Breach?
An organization learns that a service provider experienced a breach last month and did not notify the organization. Which of the following should be the information security manager's FIRST course of action?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests prioritization in vendor incident response: understanding contractual obligations via contract review precedes escalation, impact assessment, or termination.
When a third-party vendor suffers a breach without notifying your organization, the information security manager must first review the contract to understand notification clauses and liabilities. Community consensus strongly supports this as the critical initial step before escalation or termination.
Many candidates choose 'Inform senior management' because transparency feels urgent, but leadership cannot make informed decisions until the ISM understands the actual contractual breaches and required response steps.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Reviewing the provider contract establishes the legal and operational baseline for incident response. It reveals mandatory notification timelines, liability clauses, and required remediation steps that dictate how the organization must react. Without this foundational knowledge, any subsequent action lacks strategic alignment and may violate existing agreements.Why the Other Options Are Wrong
Terminating the contract immediately (Option A) creates unnecessary operational disruption and ignores potential cure periods outlined in the agreement. Conducting a business impact analysis (Option B) is valuable but secondary, as the contract review defines the scope and severity needed to properly scope the BIA. Informing senior management (Option C) is essential but premature; leaders require the contractual facts gathered first to authorize appropriate escalation or financial recourse.Community Comment Notes
Top-voted community feedback strongly emphasizes checking contractual communication clauses before taking action. Contributors note that understanding legal obligations prevents rushed decisions like immediate termination or unstructured executive briefings. While one dissenting comment advocates for immediate leadership notification, the broader consensus aligns with ISACA’s risk-based methodology that prioritizes document assessment over reactive measures.Official Reference
Exam Strategy
Always prioritize assessment over action in CISM questions. When faced with external incidents, review governing documents (contracts, SLAs, policies) first to establish legal and operational baselines before escalating or changing relationships.
Frequently Asked Questions
Why shouldn't I inform senior management immediately?
Leadership needs factual data on contractual breaches and SLA violations before making strategic decisions. Reviewing the contract first provides the necessary context for an effective briefing.
Is terminating the contract ever the right first step?
No. Immediate termination risks operational disruption and may violate force majeure or cure period clauses. Always assess contractual obligations and mitigation options first.
Related Analysis
Practice All CISM Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISM Practice Test →