Existing incident response plan specifically consider data breach scenarios involving personal information
Context and Guidance: Does your organisation have an incident response management plan for personal information data breach events? Does the incident response plan include the processes to notify individuals and/or regulatory bodies?