DATA BREACH RESPONSE POLICY

Last Update Status: 18/03/2022

1. Purpose

The purpose of the policy is to establish the goals and the vision for the breach response process. This policy will clearly define to whom it applies and under what circumstances, and it will include the definition of a breach, staff roles and responsibilities, standards and metrics (e.g., to enable prioritization of the incidents), as well as reporting, remediation, and feedback mechanisms. The policy shall be well published and made easily available to all personnel whose duties involve data privacy and security protection.

2. Scope

This policy applies to all whom collect, access, maintain, distribute, process, protect, store, use, transmit, dispose of, or otherwise handle personally identifiable information or sensitive personal information of POS Works.

3. Policy Compliance

Management will verify compliance to this policy through various methods, including but not limited to, periodic walk-thrus, business tool reports, internal and external audits, and feedback to the policy owner. 

Non-Compliance

Violations of this policy may be subject to disciplinary action. 

4. Policy

As soon as a theft, data breach or exposure containing POS Works protected data or sensitive data is identified, the process of investigating all access to that resource will begin.

 Management will chair an incident response team to handle the breach or exposure. 

The team will include relevant members from:

  • IT
  • Finance (if applicable)
  • Legal
  • Communications
  • Customer Services
  • Human Resources
  • The affected unit or department that uses the involved system or output or whose data may have been breached or exposed
  • Additional departments based on the data type involved, Additional individuals as deemed necessary by Management

Management will be notified of any theft, breach or exposure. IT, along with the designated forensic team, will analyze the breach or exposure to determine the root cause. 

Where appropriate for cyber insurance, the insurer will need to be provided access to forensic investigators and experts that will determine how the breach or exposure occurred; the types of data involved; the number of internal/external individuals and/or organizations impacted; and analyze the breach or exposure to determine the root cause.  

Work will commence with communications, legal and human resource departments to decide how to communicate the breach to: a) internal employees, b) the public, c) those directly affected and d) Government data breach reporting bodies.

All reasonable efforts will be made to limit or reduce any damage or impact of any breach as soon as practical on impacted persons. 

All investigations will be completed in no longer than 30 days.