Per Privacy Act Part IIIC Notifiable Data Breaches scheme: breach notification. Requirements include (a) implement Notifiable Data Breaches (NDB) Scheme - if an eligible data breach occurs (unauthorised access or disclosure of personal information + likely to result in serious harm) notify OAIC + affected individuals as soon as practicable + (b) conduct breach assessment within 30 days of becoming aware of suspected breach + (c) operate Security Incident Response Procedures including detection + triage + containment + recovery + lessons learned + (d) maintain breach log + assessment process + tabletop exercises + (e) integrate with broader incident management + (f) maintain documentation supporting OAIC reporting.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.