FCC Customer Proprietary Network Information (CPNI) and Data Breach Rules (47 CFR 64.2001-2011)
FCC CPNI: Data Breach Notification (64.2011)

FCC Customer Proprietary Network Information (CPNI) and Data Breach Rules (47 CFR 64.2001-2011) CPNI-64.2011: Notification of CPNI security breaches (47 CFR 64.2011)

Section 64.2011 establishes the data breach notification regime: (a) DEFINITION OF BREACH - 'a person, without authorisation or exceeding authorisation, has intentionally gained access to + use + disclose CPNI' (the FCC 2024 amendment expanded this to include 'inadvertent + accidental' breaches in certain circumstances). (b) LAW ENFORCEMENT NOTIFICATION - within 7 BUSINESS DAYS of REASONABLE DETERMINATION OF A BREACH the carrier must electronically notify the United States Secret Service (USSS) + the Federal Bureau of Investigation (FBI) through the CENTRAL REPORTING FACILITY at https://www.cpnireporting.gov + the FCC. (c) CUSTOMER NOTIFICATION TIMING - the carrier MUST NOT notify customers OR disclose the breach publicly until 7 business days have passed AFTER the law enforcement notification UNLESS law enforcement requests an extension. (d) NOTIFICATION CONTENT - notifications must include the date of the breach + a description of CPNI affected + the carrier's contact information + steps that customers may take to protect their personal information. (e) RECORDKEEPING - carriers must maintain a record of any breaches discovered + notifications made for a minimum of 2 YEARS including all reports for that breach + the date of discovery + the steps taken to remedy the breach.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 65 controls across 29 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO/IEC 27011:2024 · 4 controls

ISO/IEC 27400:2022 · 4 controls

  • 1.2 Operating System Privileged Account Control
  • 1.3 Virtualisation Platform Protection
  • 3.3 Configure Data Access Control Lists

ISO/IEC 27004:2016 · 3 controls

ISO/IEC 27014:2020 · 3 controls

ISO/IEC 29100:2024 · 3 controls

ISO/IEC 29134:2023 · 3 controls

ISO/IEC 29147:2018 · 3 controls

ISO/IEC 30111:2019 · 3 controls

  • 6.5 Preparing and Distributing Audit Report
  • 6.7 Conducting Audit Follow-up

ISO 19011 · 2 controls

  • 6.5 Preparing and Distributing Audit Report
  • 6.7 Conducting Audit Follow-up
  • 3.3 Configure Data Access Control Lists
  • 3.7.1 Key-management policies and procedures are implemented to include generation of strong cryptographic keys used to protect stored account data
  • 4.4.1 Resources, Roles, Responsibility, and Authority
  • R.16-VATR.Unhosted Unhosted (self-hosted / non-custodial) wallet transfers - 2024 Targeted Update

GDPR · 1 control

ISO 31000:2018 · 1 control

  • 6.7 Conducting Audit Follow-up

ISO/IEC 27007:2020 · 1 control

ISO/IEC 27031:2011 · 1 control

PCI DSS 4.0 · 1 control

  • 2.2.2 Vendor default accounts are managed as follows: • If the vendor default account(s) will be used, the default password is changed per Requirement 8.3.6. • If the vendor default account(s) will not be used,

SWIFT CSCF · 1 control

  • SWIFTCSCF-1 Restrict Internet Access and Protect Critical Systems (Objective 1)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 65 it maps to, and the evidence behind each claim, over MCP and REST.