Privacy Operational Life Cycle: Chapter 10 Respond: Data Breach Incident Flashcards

1
Q

Factors of Legal Exposure and Liability

A

Purported obligation to prevent unauthorized access or use of data

If the company satisfied an applicable industry standard of care

Whether there were damages or injury, and if org was cause of this

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

How incidents occur

A

Malicious actors
Human error
Systems and glitches

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Incident

A

situation when the confidentiality, integrity, or availability of personal info may potentially be compromised

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Breach

A

Legal term, requiring unauthorized access or acquisition of personal info

Determined by lawyers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Steps to prepare for an incident

A
  1. Training: expose gaps
  2. Creating incident response plan
  3. Know your stakeholders
  4. Insurance coverage
  5. Management of vendors
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Creating an incident response plan

A
  1. how to protect privilege
  2. Roles and responsibilities of team members
  3. How to escalate possible issues and report suspicious activities
  4. Severity rankings
  5. Interactions with external parties
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Roles in Incident Response Planning

A

InfoSec: detection, containment
Legal: limiting legal liability
Compliance/Privacy: advice and direction
HR: employee perspective
Marketing: advises on CRM
BusDev: handling and keeping customers
PR: Strategic and tactical comms
Union leadership: relationship with employees
Finance: cost of incident
CEO: demo value of preventing breaches
Customer care: offers customer insight

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Response in Bus Continuity Plan

A

Tabletop exercise: reinforce training
Updating the plan: lessons learned
Budgeting the response, training

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Incident Investigation

A
  1. Containment
  2. Legal privilege
  3. Notification with Insurer
  4. Credit Card companies
  5. Third-party forensics
  6. Involve key stakeholders
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Reporting obligations to know

A

Notification requirements
Internal announcements:
- align with external
- FAQs
- Response training
- Explanatory info
External announcements
Regulator notification
Letter Drops
Call center launch
Remediation offers
Progress reporting

How well did you know this?
1
Not at all
2
3
4
5
Perfectly