โ† All PLC Flashcard Decks

Data Breach Response & Incident Management Flashcards

6 cards from real PLC practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Data Breach Response & Incident Management flashcards as text
  1. Which US state was the FIRST to enact a data breach notification law, creating a model that most other states subsequently followed?

    Answer: California

    California enacted the first US state data breach notification law (SB 1386) in 2002, which became the template for nearly all subsequent state laws.

  2. A breach notification to a state Attorney General is typically triggered when the number of affected state residents exceeds what threshold under most state laws?

    Answer: Threshold varies; some states require notification regardless of number

    Most state breach notification laws require AG notification when the breach exceeds 500 or 1,000 residents, but thresholds vary widely by state and some states have no minimum.

  3. An organization's breach response team should include representatives from which departments to be most effective?

    Answer: Legal, IT Security, Communications, and Executive Leadership

    Effective breach response requires coordination among Legal (liability/notification), IT Security (containment/forensics), Communications (PR/messaging), and Executive Leadership (decisions/resources).

  4. What does the term 'safe harbor' mean in the context of US data breach notification laws?

    Answer: An exemption from notification if the breached data was encrypted

    Most US state breach notification laws provide a safe harbor exempting organizations from notification obligations when the exposed data was encrypted and the encryption key was not also compromised.

  5. Which of the following best describes 'notification fatigue' and its relevance to breach response?

    Answer: Consumers becoming desensitized to breach notices, reducing protective action

    Notification fatigue refers to consumers becoming so accustomed to breach notices that they fail to take protective actions, undermining the consumer-protection purpose of notification laws.

  6. Under HIPAA, when a breach affects 500 or more individuals in a single state or jurisdiction, covered entities must also notify:

    Answer: The HHS Office for Civil Rights within 60 days and prominent local media outlets

    HIPAA requires that breaches affecting 500+ individuals in a jurisdiction be reported to HHS-OCR within 60 days and to prominent media outlets in that jurisdiction.

Data Breach Response & Incident Management Flashcards โ€” PLC Study Cards with Answers