CCSP - Cloud Security Operations - Section 5.5

Manage communication with relevant parties.

Communication with vendors, customers, partners, regulators and other stakeholders, including what must be disclosed and when.

stakeholder communicationregulator notificationvendor and partner communicationbreach disclosure

Practice question for this objective

Free sampleCloud Security Operationseasy

A cloud security team confirms a breach that exposed regulated personal data. What is the primary factor that determines when the relevant data protection regulator must be notified?

  • AThe moment the incident response team has fully eradicated the threat and closed the incident
  • BThe notification timeframe defined by the applicable law or regulation, measured from awareness of the breach Correct
  • CThe next scheduled quarterly compliance review with the internal audit function
  • DThe cloud provider's preference for when its customers should contact outside authorities
Understand that regulator breach notification is triggered by the legal timeframe running from the organisation's awareness of the breach. Breach notification laws impose a defined deadline that starts when the organisation becomes aware of a qualifying breach, so the applicable legal timeframe, not incident closure or internal cadences, governs when the regulator must be told.

Why A is wrong: Waiting for full closure is tempting but wrong; many regimes require notification while response is still underway, well before eradication.

Why B is correct: Regulatory notification duties are set by law and run from the point the organisation becomes aware, so the legal timeframe is the controlling factor.

Why C is wrong: Aligning to an internal review cadence sounds orderly but ignores statutory clocks that demand notification within days, not at the next review.

Why D is wrong: A provider may offer support, but a customer's legal notification duty is set by regulation, not by the provider's scheduling preference.

See more CCSP practice questions, answers explained.

More in this domain

Back to all Cloud Security Operations objectives, or the CCSP cert hub.

Examworthy is not affiliated with or endorsed by ISC2. Original, blueprint-aligned practice material only.