Section 64.2011 establishes the data breach notification regime: (a) DEFINITION OF BREACH - 'a person, without authorisation or exceeding authorisation, has intentionally gained access to + use + disclose CPNI' (the FCC 2024 amendment expanded this to include 'inadvertent + accidental' breaches in certain circumstances). (b) LAW ENFORCEMENT NOTIFICATION - within 7 BUSINESS DAYS of REASONABLE DETERMINATION OF A BREACH the carrier must electronically notify the United States Secret Service (USSS) + the Federal Bureau of Investigation (FBI) through the CENTRAL REPORTING FACILITY at https://www.cpnireporting.gov + the FCC. (c) CUSTOMER NOTIFICATION TIMING - the carrier MUST NOT notify customers OR disclose the breach publicly until 7 business days have passed AFTER the law enforcement notification UNLESS law enforcement requests an extension. (d) NOTIFICATION CONTENT - notifications must include the date of the breach + a description of CPNI affected + the carrier's contact information + steps that customers may take to protect their personal information. (e) RECORDKEEPING - carriers must maintain a record of any breaches discovered + notifications made for a minimum of 2 YEARS including all reports for that breach + the date of discovery + the steps taken to remedy the breach.
This control maps to 65 controls across 29 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 65 it maps to, and the evidence behind each claim, over MCP and REST.