The organisation develops an incident response plan that gives a roadmap for its capability, describes its structure and fit within the organisation, meets its specific mission, size and structure, defines reportable incidents, sets metrics, defines the resources and management support needed, addresses incident information sharing, is reviewed and approved by defined roles at a set frequency, and explicitly assigns incident response responsibility; distributes it to incident response personnel, updates it for organisational and system changes and problems found, communicates changes, and protects it from unauthorized disclosure and modification. The GC discussion requires departments to meet the TBS mandatory procedures for privacy breaches, notify affected individuals and keep breach records. 1 enhancement.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.