There should be a comprehensive Data Breach Policy in place that outlines how the organization must respond to incidents involving the unauthorized disclosure of sensitive data in accordance with applicable standards, laws, and regulations.

Control Type: Administrative

Control Function: Corrective/Directive

Description: A Data Breach is a type of cyber incident that continues to affect organizations of all sizes and industries and remains one of the most significant cybersecurity risks. "Specifically, a data breach is defined as "an incident resulting in unauthorized access, disclosure, alteration, loss, destruction, or theft of sensitive information". Data breaches are among the most devastating incidents. Not only do they damage an organization’s reputation, but they can expose sensitive data to the public that may hamper the organization's bottom line. Organizations can also be hit with regulatory/legal consequences if they do not handle the incident properly, or if unaddressed vulnerabilities were found to have enabled the breach. Organizations that handle large amounts of data, including personally identifiable information from customers, should have a Data Breach Policy in place that outlines what needs to be done if a breach takes place.

The Data Breach Policy should contain:

  • Roles & Responsibilities Relating to Breach Response: this usually outlines the roles and responsibilities specified in the general incident response policy. There should be a clear triage and escalation hierarchy. There also needs to be roles for communicating the breach to relevant stakeholders, law enforcement, regulatory authorities, and the public.
  • Criteria for confirming the breach: incident response teams need to understand the steps to take to confirm that the breach is not a false positive. This needs to be done quickly and be clearly communicated
  • Immediate Breach Response Steps: these steps should be tested and practiced so that the breach is contained upon immediate confirmation. Response teams should evaluate appropriate containment measures based on the nature, scope, and severity of the breach. Potential actions may include network isolation, account suspension, segmentation, or temporary suspension of affected services.
  • Protecting the integrity of evidence: affected systems should not be immediately powered down or reset. They will need to be studied for criminal investigations into the breach. Thus, it is important to ensure their integrity. Workstations/servers that originated the breached data should be kept running, and no further modifications should be made to their state. Mobile devices that may be involved can be placed in Faraday Cages to preserve their state while preventing any further modifications. Chain of custody forms should be implemented for all affected assets and components.
  • Contacting Law Enforcement: The policy should establish criteria for determining when law enforcement involvement is appropriate and identify points of contact for relevant agencies. The policy should specify procedures for informing law enforcement about the breach and initiating their involvement in the investigation if needed. The policy should specify the contact information for specific law enforcement agencies that are relevant to the organization.
  • Contacting Stakeholders: there should be a procedure for informing key stakeholders at all levels of the breach. Organizations should practice and prepare for this by having prewritten data breach notification emails for stakeholders that only reveal the minimum of information about the breach and response measures in place.
  • Determine Notification Clauses: different laws and regulations have requirements for data breach notifications. Organizations need to know the specific notification timelines and reporting requirements of the legislative and regulatory bodies they fall under. Failure to understand these requirements can result in the organization missing the notification period and being subject to fines.
  • Notify Affected Customers: anytime customer data is involved in a data breach, they need to be notified in accordance with applicable notification rules. Channels for notification may include email, SMS, or phone calls. Notifications should be simple to understand, specific, and clearly specify what the customers can do to lower their chances of being compromised because of the breach.
  • Public Report: Where required by law, regulation, contractual obligation, or business need, the organization should prepare public communications regarding the breach. This will help preserve some of the trust that the organization may have lost because of the breach taking place. Such reports should contain:
    • How and when the data breach occurred
    • Types of personal data involved in the breach
    • What has been done or is being done by the organization in response to the breach.
    • What customers of the organization can do to mitigate potential harm because of the breach
    • Contact details for affected individuals to reach the organization for further information or assistance
Data Breach Notification Timelines/Requirements of Major Standards/Law/Regulations: