ISC2 Governance, Risk and Compliance (CGRC) Practice Question
While reviewing your multinational organization's incident-response plan, you must map legal breach-notification timelines. Which regulation specifically requires a data controller to notify the competent supervisory authority of a personal data breach no later than 72 hours after becoming aware of it, unless the breach is unlikely to risk individuals' rights and freedoms?
Health Insurance Portability and Accountability Act (HIPAA)
Payment Card Industry Data Security Standard (PCI-DSS)
Federal Information Security Modernization Act (FISMA)
The General Data Protection Regulation (GDPR) sets a strict 72-hour deadline for data controllers to report personal data breaches to the relevant supervisory authority (Art. 33 (1)), unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. HIPAA allows up to 60 days to notify affected individuals, FISMA/OMB guidance generally requires federal agencies to report certain incidents to US-CERT within one hour, and PCI-DSS does not define a universal regulatory timeline-making GDPR the only framework in the list that mandates a 72-hour authority notification.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a data controller in GDPR?
Open an interactive chat with Bash
What happens if the data breach notification is delayed beyond 72 hours under GDPR?
Open an interactive chat with Bash
What risks to individuals' rights and freedoms does GDPR include in its breach evaluation criteria?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Security and Privacy Governance, Risk Management, and Compliance Program
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .