IIC C11 Question Answer
[Regulatory Framework / Privacy]
What is generally thethirdstep in responding to a privacy breach?
Evaluate the risks associated with the breach
Contain the breach and assess ways to reduce harm
Determine who needs to be notified and send notices
Investigate how the breach happened and prevent recurrence
The typical privacy-breach response sequence used in Canadian insurance organizations follows four steps:
Contain the breachand secure the data (stop further exposure).
Evaluate the risks— determine sensitivity of data, potential harm, affected individuals, and severity.
Notifythose who must be informed (affected clients, regulators, privacy commissioners, insurers, or law enforcement).
Prevent recurrence— investigate causes and implement corrective measures.
Since Step 1 is containment and Step 2 is risk evaluation, thethirdstep isnotification.
Therefore, the correct answer isC.
TESTED 19 Dec 2025
Copyright © 2014-2025 ACE4Sure. All Rights Reserved