graphgrc

Data Breach Response Process

Process for responding to confirmed or suspected unauthorized access to customer or employee data.

Roles and Responsibilities

Prerequisites

Process Steps

Step 1: Breach Confirmation

Security team determines if incident qualifies as a data breach.

Data breach definition:

Initial assessment:

Owner: Security Team Duration: Hours (during incident response investigation phase)

Step 2: Immediate Notification to Leadership

Security team immediately notifies executive team and legal counsel.

Initial notification includes:

Notification method: Emergency meeting (in-person or video), followed by written summary

Owner: Security Team Duration: Within 2 hours of breach confirmation

Step 3: Regulatory Notification Timeline Assessment

Legal determines notification obligations and deadlines.

Regulations considered:

Deliverable: Regulatory notification plan with deadlines

Owner: Legal Duration: Within 6 hours of breach confirmation

Step 4: Data Breach Assessment

Security team completes detailed assessment of breach scope.

Assessment includes:

Deliverable: Data breach report (internal document)

Owner: Security Team Duration: 24-48 hours

Step 5: Regulatory Authority Notification (if required)

Legal submits breach notification to regulatory authorities within deadlines.

GDPR supervisory authority notification (if applicable):

State attorney general notifications (if applicable):

Owner: Legal Duration: Within regulatory deadlines (72 hours for GDPR)

Step 6: Individual Notification Planning

Exec team and legal decide on customer/employee notification approach.

Decision factors:

Notification content:

Owner: Legal, Executive Team, Customer Success Duration: 24-48 hours after breach confirmation

Step 7: Individual Notification Execution

Send breach notification to affected individuals.

Notification methods:

Timing:

Owner: Customer Success (customers), HR (employees) Duration: 1-2 days for sending (after approval)

Step 8: External Notifications (if needed)

Notify other parties as required.

Parties to notify:

Owner: Legal, Executive Team Duration: Days to weeks

Step 9: Customer Support and Monitoring

Provide resources and support to affected individuals.

Support includes:

Monitoring:

Owner: Customer Success Duration: Ongoing (weeks to months)

Step 10: Post-Breach Review and Remediation

Conduct thorough review and implement preventive controls.

Review:

Deliverable: Post-breach report with lessons learned and action items

Owner: Security Team Duration: 2-4 weeks after incident closure

Documentation Requirements

Required documentation (retain for 7 years):

Testing

References

Control Mapping


Referenced By

This section is automatically generated by make generate-backlinks. Do not edit manually.