Answer yes if your organisation's Incident Response Plan contains an assessment of impact to legal and regulatory compliance. Please reference the section of any previously provided plan in the notes.
An incident response plan is a crucial document that outlines the operational steps that must be taken when an unexpected or disruptive event occurs. The plan can be invoked for both security and non-security incidents and should be an organic and operational document used to restore service and coordinate a response.
Categorisation and severity assessment of the incident should consider legal and regulatory commitments. For example:
These are just example legal and regulatory considerations. The specific considerations required will depend on the nature of the incident and the legal and regulatory commitments relevant to your organisation, which will vary by organisation type, size and jurisdiction.
Ensure your plan has a method for considering the legal and regulatory aspects of any incidents that cause the plan to be invoked. It can help to have legal counsel and data protection advisors review your company's plan.
If you would like to contribute to this article or provide feedback, please email knowledge@riskledger.com. Contributors will be recognised on our contributors page.