FCC Customer Proprietary Network Information (CPNI) and Data Breach Rules (47 CFR 64.2001-2011)
FCC CPNI: Data Breach Notification (64.2011)

FCC Customer Proprietary Network Information (CPNI) and Data Breach Rules (47 CFR 64.2001-2011) CPNI-64.2011: Notification of CPNI security breaches (47 CFR 64.2011)

Section 64.2011 establishes the data breach notification regime: (a) DEFINITION OF BREACH - 'a person, without authorisation or exceeding authorisation, has intentionally gained access to + use + disclose CPNI' (the FCC 2024 amendment expanded this to include 'inadvertent + accidental' breaches in certain circumstances). (b) LAW ENFORCEMENT NOTIFICATION - within 7 BUSINESS DAYS of REASONABLE DETERMINATION OF A BREACH the carrier must electronically notify the United States Secret Service (USSS) + the Federal Bureau of Investigation (FBI) through the CENTRAL REPORTING FACILITY at https://www.cpnireporting.gov + the FCC. (c) CUSTOMER NOTIFICATION TIMING - the carrier MUST NOT notify customers OR disclose the breach publicly until 7 business days have passed AFTER the law enforcement notification UNLESS law enforcement requests an extension. (d) NOTIFICATION CONTENT - notifications must include the date of the breach + a description of CPNI affected + the carrier's contact information + steps that customers may take to protect their personal information. (e) RECORDKEEPING - carriers must maintain a record of any breaches discovered + notifications made for a minimum of 2 YEARS including all reports for that breach + the date of discovery + the steps taken to remedy the breach.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 45 controls across 23 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO/IEC 27004:2016 · 3 controls

  • 27004-3 Terms and definitions
  • 27004-A.2 Patching and Vulnerability Measures
  • 27004-B.1 Example measurement definitions

ISO/IEC 27011:2024 · 3 controls

  • 27011-1 Scope
  • 27011-3 Terms and definitions
  • 27011-8.1 User Endpoint Devices
  • 27557-1 Scope
  • 27557-3 Terms and definitions
  • 27557-6.2 Scope, context, and criteria for privacy

ISO/IEC 29100:2024 · 3 controls

  • 29100-1 Scope
  • 29100-3 Terms and definitions
  • 29100-4.1 Actors and roles
  • 58.1 Scope
  • 58.3 Definitions
  • 60601-1.3 Terminology and definitions
  • 60601-1.4.1 General requirements
  • 62351-2 Glossary of terms
  • 62351-8 Role-based access control (RBAC)

ISO/IEC 27014:2020 · 2 controls

  • 27014-1 Scope
  • 27014-3 Terms and definitions

ISO/IEC 27400:2022 · 2 controls

  • 27400-3 Terms and definitions
  • 27400-6.1 Secure Device Design

ISO/IEC 29147:2018 · 2 controls

  • 29147-3 Terms and definitions
  • 29147-9.2 Contact mechanisms and scope

ISO/IEC 30111:2019 · 2 controls

  • 30111-3 Terms and definitions
  • 30111-5.1 Organizational policy
  • 4.4.1 Resources, Roles, Responsibility, and Authority
  • R.16-VATR.Unhosted Unhosted (self-hosted / non-custodial) wallet transfers - 2024 Targeted Update

GDPR · 1 control

ISO/IEC 23837:2023 · 1 control

  • 23837-1.1 Scope

ISO/IEC 27007:2020 · 1 control

  • 27007-5.2 Audit Programme Objectives

ISO/IEC 27031:2011 · 1 control

  • 27031-5.1 IRBC Policy
  • 27050-1.4 Terms and definitions
  • 29115-3 Terms and definitions

ISO/IEC 29134:2023 · 1 control

  • 29134-3 Terms and definitions

PCI DSS 4.0 · 1 control

  • 2.2.2 2.2.2 Vendor default accounts managed

SWIFT CSCF · 1 control

  • SWIFTCSCF-1 Restrict Internet Access and Protect Critical Systems (Objective 1)
  • 15 U.S.C. § 78dd-2(h) Definition of Domestic Concern

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 45 it maps to, and the evidence behind each claim, over MCP and REST.