A company has decided to implement a new archiving system A data breach occurred during the implementation of the project What should the project manager do first?
Correct Answer: A
According to the Project Management Professional (PMP) certification exam content outline, one of the tasks under the domain of executing the project is to "Implement approved changes, actions, and workarounds, including escalating decisions to the appropriate stakeholders, as necessary, to meet project objectives" 1. This implies that the project manager should have a risk management plan that includes predefined risk responses for potential threats and opportunities. A data breach is a serious threat that could compromise the confidentiality, integrity, and availability of the project data and deliverables. Therefore, the project manager should follow the planned risk response to handle the issue as the first step. The planned risk response could involve mitigating the impact of the breach, transferring the risk to a third party, avoiding further exposure, or accepting the consequences. The project manager should also communicate the issue to the relevant stakeholders and seek their support and guidance.
The other options are not the first steps that the project manager should take. Reviewing possible alternative documentation methods with the team (B) is not relevant to the data breach issue and could delay the resolution. Updating the risk register with the risk and proposed impact is important, but it should be done after implementing the risk response, not before. Asking the team to fix the system to resolve the issue (D) is not sufficient, as the project manager should also coordinate with other parties, such as the security team, the legal team, the customer, and the senior management, to address the breach and its implications. References: 1 Project Management Professional (PMP) Examination Content Outline, June 2019, p. 112 How to Effectively Manage a Data Breach 3 6 Steps to Developing a Data Breach Response Plan How to handle data breaches according to the GDPR