Notifiable Data Breaches Scheme (Australia)
Recordkeeping and Governance

Notifiable Data Breaches Scheme (Australia) AUNDB-A7: Recordkeeping, Communications Strategy, Post-Incident Review, Board Reporting

Maintain recordkeeping + communications strategy + post-incident review + board reporting per OAIC guidance and Privacy Act section 26WL recordkeeping expectations. Recordkeeping must capture every suspected breach + assessment + decision + notification + remedial action + outcome with chain of custody appropriate to potential regulatory + civil litigation + criminal investigation use. Communications strategy for high impact breaches must coordinate (a) OAIC engagement, (b) individuals communication, (c) sector regulator engagement (APRA + ASIC + ACMA + state regulators), (d) law enforcement engagement (Australian Federal Police + state police + ACSC), (e) media engagement managed by communications professionals, (f) consumer support (call centre + portal + credit monitoring + identity remediation services), (g) employee communication, (h) shareholder and partner communication, (i) insurance notification. Post-incident review per OAIC expectation must (a) examine root cause + control gaps + response performance + obligation compliance, (b) produce documented findings + recommendations + closure tracking. Board and executive reporting must (a) report breaches above defined threshold to board or audit committee, (b) annual programme reporting covering breach metrics + control changes + investment + benchmarking. Train workforce + conduct tabletop exercises annually.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.