What Is the First Step After an Undisclosed Vendor Breach?

Vendor Risk Management
Answer Correct answer: D — Review the provider contract to determine notification obligations, liability terms, and required remediation steps before taking any further action.

An organization learns that a service provider experienced a breach last month and did not notify the organization. Which of the following should be the information security manager's FIRST course of action?

  1. Terminate the provider contract.
  2. Conduct a business impact analysis (BIA).
  3. Inform senior management.
  4. Review the provider contract. Correct Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests prioritization in vendor incident response: understanding contractual obligations via contract review precedes escalation, impact assessment, or termination.

When a third-party vendor suffers a breach without notifying your organization, the information security manager must first review the contract to understand notification clauses and liabilities. Community consensus strongly supports this as the critical initial step before escalation or termination.

Many candidates choose 'Inform senior management' because transparency feels urgent, but leadership cannot make informed decisions until the ISM understands the actual contractual breaches and required response steps.

Community Discussion (3 comments)

Booict 👍 1
C - Prompt communication with senior management ensures they are aware of the situation, allowing for timely decisions and appropriate actions. It is essential to keep organizational leadership informed about security incidents.
AlexJacobson 👍 2 Selected: D
I would check the contract first to understand whether there was something about communicating the breaches with the business, before I do anything else.
jcisco123 👍 2 Selected: D
D. Review the provider contract.Terminating the provider contract (Option A) might be premature without understanding the contractual obligations and the specific details of the breach. Conducting a BIA (Option B) is important but secondary to understanding the legal and contractual aspects. Informing senior management (Option C) is a crucial step but should typically follow an initial assessment and understanding of the situation based on the contract review.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Reviewing the provider contract establishes the legal and operational baseline for incident response. It reveals mandatory notification timelines, liability clauses, and required remediation steps that dictate how the organization must react. Without this foundational knowledge, any subsequent action lacks strategic alignment and may violate existing agreements.

Why the Other Options Are Wrong

Terminating the contract immediately (Option A) creates unnecessary operational disruption and ignores potential cure periods outlined in the agreement. Conducting a business impact analysis (Option B) is valuable but secondary, as the contract review defines the scope and severity needed to properly scope the BIA. Informing senior management (Option C) is essential but premature; leaders require the contractual facts gathered first to authorize appropriate escalation or financial recourse.

Community Comment Notes

Top-voted community feedback strongly emphasizes checking contractual communication clauses before taking action. Contributors note that understanding legal obligations prevents rushed decisions like immediate termination or unstructured executive briefings. While one dissenting comment advocates for immediate leadership notification, the broader consensus aligns with ISACA’s risk-based methodology that prioritizes document assessment over reactive measures.

Official Reference

Exam Strategy

Always prioritize assessment over action in CISM questions. When faced with external incidents, review governing documents (contracts, SLAs, policies) first to establish legal and operational baselines before escalating or changing relationships.

Frequently Asked Questions

Why shouldn't I inform senior management immediately?

Leadership needs factual data on contractual breaches and SLA violations before making strategic decisions. Reviewing the contract first provides the necessary context for an effective briefing.

Is terminating the contract ever the right first step?

No. Immediate termination risks operational disruption and may violate force majeure or cure period clauses. Always assess contractual obligations and mitigation options first.

Related Analysis

Practice All CISM Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISM Practice Test →

← Back to CISM Study Guide