Data Breach Response Plan
ReadyRoster's documented response plan for personal data breaches, aligned to the Notifiable Data Breaches scheme under the Australian Privacy Act 1988.
Response steps
- Step 1: Containment (0–4 hours): Isolate affected systems immediately. Revoke compromised credentials. Preserve logs and evidence for investigation.
- Step 2: Assessment (4–24 hours): Determine what personal information was accessed, how many individuals are affected, and the likely risk of serious harm.
- Step 3: Notification (within 72 hours): If the breach is likely to result in serious harm, notify the Office of the Australian Information Commissioner (OAIC), notify all affected individuals directly, and describe the breach, the information involved, and recommended steps.
- Step 4: Remediation: Implement measures to prevent recurrence. Update security controls. Document lessons learned.
- Step 5 — Review: Review this response plan after every incident and at minimum annually.
Features · Pricing · Compliance · Security · Roadmap · Contact