Answer yes if your organisation has a documented process for reporting information security breaches to all affected clients within 72 hours of the breach being discovered. Please describe the process in the notes, or provide a process document (as a PDF file) as evidence.
If your organisation holds data on behalf of your clients then you must have a documented process that can be used to notify them in a timely manner of any security breaches that may affect them. You should ensure that any process that you have implemented reports the incidents quick enough to be compliant with any client contract, legal or regulatory requirements your company may be subject to. For example:
It is important to have a breach notification process in place so that if your company were to suffer a security incident you can report this incident to your clients in a timely manner. This is important to ensure compliance with your client contractual requirements and a variety of regulatory requirements.
Consult with your regulator’s published guidance and your Legal Counsel to ensure that requirements are clearly defined and supported by your process. Your breach notification process should be linked to your incident response plan and should be linked to any regulatory notification processes implemented within your company.
If you would like to contribute to this article or provide feedback, please email knowledge@riskledger.com. Contributors will be recognised on our contributors page.