10. Respond: Data Breach Incident Plans Flashcards

1
Q

“All breaches are incidents, but not all incidents are breaches”

Incidents vs Breaches

A

Incident - compromises the confidentiality, integrity or availability of data and may not require notification.

Breach - results in the confirmed disclosure of data to an unauthorized party and requires external notification.

only the Privacy Office or Legal Office should declare a breach

Data breaches can involve risks to both organizations and individuals

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Examples of how incidents can occur

A

Malicious actors
Human error
Systems and glitches

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Creating an Incident Response Plan

A
  • How to protect privilege
  • Roles and responsibilities of team members
  • How to escalate possible issues and report suspicious activities
  • Severity rankings
  • Interactions with external parties
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Breach Causes and Responsibilities (LN)

A

Top Causes of Data Breaches:
- Malicious Attacks
- Criminal Attacks

Organizations are required to determine:
- Who is Liable for harm
- Who should notify affected individuals

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Examples of Breach Preparedness - “No definitive way to detect a breach”

A

Preparedness - focuses on measures for optimally responding to breach.

Training and Awareness - are vital in preparing for an incident.

Tabletop Exercise - a common incident preparedness training activity.

Incident Response Planning - creating one is key to organizational preparedness.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Response Tasks may happen in parallel to one another:

A

Response Tasks may happen in parallel to one another:
- Securing your operations
- Notifying appropriate parties
- Fixing vulnerabilities

Securing Operations Involves:
- Mobilizing the breach response team
- Analyzing vulnerabilities & addressing 3rd parties
- Managing expectations around communication

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Breach Communication

A

News of a Breach: coordinate efforts across the predefined steps and keep messaging consistent.

Internal and External Communication should be delivered around the same time.

Internal Communication (to employee only) - no need to legally notify…might be best option dependent on factors.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Breach Involvement

A

Breach Investigation - occurs once breach investigators conclude that sensitive information has been compromised.

Breach Reporting Obligations - vary by jurisdiction but tend to adhere to certain principles:
- preventing harm
- collection limitation
- accountability
- monitoring and enforcement
- mandatory reporting

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Breach Categories of Cost

A
  • Legal
  • First Party
  • Remediation
  • Intangible Costs

Several factors can impact the per record cost of a data breach

Data breaches provide opportunity for organizational change and growth.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Reporting Obligations to Know

A

Internal announcements:
- align with external
- FAQs
- Response training
- Explanatory info

External announcements:
- Regulator notification
- Letter Drops
- Call center launch
- Remediation offers
- Progress reporting

How well did you know this?
1
Not at all
2
3
4
5
Perfectly