Section 64.2011 establishes the data breach notification regime: (a) DEFINITION OF BREACH - 'a person, without authorisation or exceeding authorisation, has intentionally gained access to + use + disclose CPNI' (the FCC 2024 amendment expanded this to include 'inadvertent + accidental' breaches in certain circumstances). (b) LAW ENFORCEMENT NOTIFICATION - within 7 BUSINESS DAYS of REASONABLE DETERMINATION OF A BREACH the carrier must electronically notify the United States Secret Service (USSS) + the Federal Bureau of Investigation (FBI) through the CENTRAL REPORTING FACILITY at https://www.cpnireporting.gov + the FCC. (c) CUSTOMER NOTIFICATION TIMING - the carrier MUST NOT notify customers OR disclose the breach publicly until 7 business days have passed AFTER the law enforcement notification UNLESS law enforcement requests an extension. (d) NOTIFICATION CONTENT - notifications must include the date of the breach + a description of CPNI affected + the carrier's contact information + steps that customers may take to protect their personal information. (e) RECORDKEEPING - carriers must maintain a record of any breaches discovered + notifications made for a minimum of 2 YEARS including all reports for that breach + the date of discovery + the steps taken to remedy the breach.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.