Notifiable Data Breaches Scheme (Australia)
Containment and Assessment

Notifiable Data Breaches Scheme (Australia) AUNDB-A2: Containment and 30-Day Assessment of Suspected Eligible Data Breaches

Contain suspected breaches and complete the section 26WH assessment within 30 days per Privacy Act sections 26WH + 26WF. Containment must (a) commence immediately on becoming aware of suspected breach including isolation of affected systems + revocation of compromised credentials + preservation of forensic evidence, (b) integrate with broader incident response runbooks. Assessment per section 26WH must (a) be reasonable and expeditious commencing as soon as practicable after the entity becomes aware that there are reasonable grounds to suspect there may have been an eligible data breach, (b) be completed within 30 days from the day on which the entity becomes aware unless circumstances render that impracticable (rare), (c) determine whether there is unauthorised access or unauthorised disclosure of personal information OR loss of personal information in circumstances where unauthorised access or unauthorised disclosure is likely to occur, AND a reasonable person would conclude the access or disclosure would be likely to result in serious harm to any of the individuals to whom the information relates, (d) consider the section 26WG factors for serious harm: kind or kinds of information + sensitivity + protections + persons or kinds of persons who have obtained or could obtain the information + nature of the harm + any other relevant matters. Document the assessment + decision + rationale + evidence in support.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.