金融機関のコンピュータフォレンジック調査において、GLBA(グラム・リーチ・ブライリー法)で保護されている顧客データへの不正アクセスが疑わしい活動として発見され、顧客の安全に対する懸念が高まっています。しかし、侵害の発生源と範囲を特定することは非常に困難であり、GLBAガイドラインの遵守を困難にしています。
機密性の高い顧客データへの不正アクセスが発見された場合、GLBA の対象となるコンピューターフォレンジック調査ではどのような手順を踏む必要がありますか?
正解:D
According to CHFI v11 objectives under Computer Forensics Fundamentals and Regulations, Policies, and Ethics , a forensic investigator must ensure that technical investigation activities align with applicable legal and regulatory requirements. The Gramm-Leach-Bliley Act (GLBA) mandates that financial institutions protect customers' nonpublic personal information (NPI) and respond appropriately to any unauthorized access or disclosure.
When a breach involving GLBA-protected data is identified, the organization must follow a structured incident response and forensic investigation process while maintaining compliance with privacy laws. CHFI v11 emphasizes forensic readiness, legal compliance, and ethical handling of digital evidence. Notifying affected customers of their opt-out rights and implementing safeguards to protect compromised data are core requirements of GLBA's Privacy Rule and Safeguards Rule.
Ignoring the incident violates forensic and legal responsibilities, while sharing sensitive data with third parties risks further disclosure. Informing law enforcement alone is insufficient if customer notification obligations are not met. Proper customer notification demonstrates due diligence, supports transparency, and reduces legal risk. From a CHFI perspective, this approach ensures lawful evidence handling, regulatory compliance, and preservation of organizational credibility during forensic investigations.