712-50 Question 265
Single answerDesign a response plan to identity theft incidencesA retail organization discovers that attackers used stolen customer information from a third-party loyalty portal to open fraudulent store-credit accounts in customers' names. The CEO asks the CISO to design the organization's response plan for identity theft incidents affecting customers. Which action should be the HIGHEST priority to include in the plan to reduce harm to affected individuals and support compliant incident handling?
- A
Establish a documented identity-theft response workflow that includes rapid verification of affected records, coordination with legal/privacy teams, timely customer notification with clear remediation steps, and a process to work with credit bureaus, fraud teams, and law enforcement where appropriate
- B
Wait until the forensic investigation is fully completed before notifying any potentially affected customers, to avoid sending incomplete information that could create confusion
- C
Focus the plan primarily on recovering the compromised portal and defer customer assistance activities until after systems are restored and business operations return to normal
- D
Require all affected customers to submit notarized affidavits before the organization will investigate or assist with potentially fraudulent accounts
Show answer and explanation
Correct answer: A
Explanation
The best answer is Option 1 because a response plan for identity theft incidents must be designed to reduce harm to affected individuals, not just restore systems. In executive security leadership terms, this means building a cross-functional process involving information security, privacy, legal, customer service, fraud operations, communications, and third-party management. Practical elements include: confirming what identity elements were exposed; assessing whether misuse is likely or already occurring; preserving evidence; coordinating with the breached third party; determining notification obligations; notifying affected individuals without undue delay where required; and providing concrete remediation guidance such as fraud alerts, credit monitoring where appropriate, account review, password resets, and support channels. Relevant best-practice sources include NIST incident response guidance such as SP 800-61, which emphasizes coordinated handling, communication, and containment, and broader privacy/security expectations reflected in breach notification laws and consumer protection practices. For identity theft specifically, response plans should also account for engagement with financial fraud teams, credit bureaus, and law enforcement as appropriate, because the incident's impact extends beyond the initial compromise into fraudulent use of personal data.
- A. Correct.
Correct. For identity theft incidents, the response plan must go beyond technical containment and include victim-centered actions. A strong plan should define how the organization confirms affected individuals, triggers legal/privacy review, communicates promptly and accurately, and helps victims mitigate harm through fraud monitoring, account remediation, and engagement with credit bureaus, payment/fraud teams, and law enforcement when warranted. This reflects established incident response and privacy breach practices: contain and investigate the incident while also reducing downstream harm to data subjects.
- B. Incorrect.
Incorrect. Although accuracy matters, delaying notification until every forensic detail is known is a common mistake. In identity theft scenarios, delay can increase consumer harm by allowing fraudulent accounts or transactions to continue. Most mature breach-response programs use phased communications: notify when there is sufficient confidence of material impact, explain what is known, and update as the investigation progresses. Legal notification timing varies by jurisdiction, but unnecessary delay is generally poor practice.
- C. Incorrect.
Incorrect. This option reflects an overly technical view of incident response. System recovery is important, but for identity theft incidents the organization must also address the immediate risk to affected individuals. A CISO-level response plan should balance containment, eradication, recovery, communications, compliance, and victim assistance. Deferring customer support until after restoration ignores the core business and legal consequences of identity misuse.
- D. Incorrect.
Incorrect. Requiring notarized affidavits before assistance creates friction and delays mitigation. While some formal documentation may eventually be needed for disputes or reimbursement, the incident response plan should prioritize fast triage, reasonable identity verification, fraud suppression, and customer guidance. Excessive administrative barriers increase harm and can undermine trust, especially when the organization already has evidence of exposure.