Data Breach Response Plan 0
Data Breach Response Plan 0
Data Breach Response Plan 0
RESPONSE PLAN
February 2018
Assess
6. The staff member/response team will complete a data breach assessment in accordance with the
Data Breach Assessment Report template at Attachment B.
Notification and Review
7. The staff member/response team will submit the completed Data Breach Assessment Report to the
Chief Executive who will coordinate notification (if required) of affected individuals and/or the
Australian Information Commissioner and the NBA’s internal review of the data breach.
Description Details
Description of the breach [Provide a short description of the breach, including the date and
time the breach was discovered and the duration and location of the
breach.]
How the breach was [Insert details about how the breach was discovered, and by whom.]
discovered
Cause and extent of breach [Insert details about the cause and the extent of the breach.]
List of affected individuals [List the affected individuals, or describe the class of individuals who
are or may be affected by the data breach.]
Is the breach likely to result [Evaluate whether the breach is likely to result in serious harm to
in serious harm to any of the any of the individuals to whom the information relates, having
individuals to whom the regard to:
harm relates? the kind of information involved;
the sensitivity of the information;
whether the information is protected by one or more security
measures, and the likelihood of those measures being
overcome;
the persons, or the kinds of persons, who have obtained, or
who could obtain, the information; and
if a security technology or methodology was used in relation
to the information and designed to make the information
unintelligible or meaningless to persons who are not
authorised to obtain the information, the likelihood that
Remedial action [Insert details of the steps the NBA has taken to reduce any potential
harm to individuals, e.g. by recovering lost information before it is
accessed or changing access controls on compromised systems.]
Is or will the remedial action [State whether the remedial action will result in making serious
result in making serious harm harm no longer likely. If serious harm is no longer likely, the NBA is
no longer likely? not required to prepare a statement to the Information
Commissioner or to notify affected individuals.]
Names of response team [Insert the names and roles of response team members. The make-
members up of the response team will be determined by the Chief Executive,
having regard to the skills required to respond to the breach.]