§1798.150 Private Right of Action for Data Breaches
A consumer whose nonencrypted and nonredacted PI (or email address with password/security question allowing account access) is subject to unauthorized access and exfiltration, theft, or disclosure as a result of the busi
4
artefacts
1
held by a system
0
at each review
moderate
to go live
Identity provider / directory
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Reasonable security program documentation (encryption, access control, monitoring) · Identity provider / directory
periodic reviewEvidence produced at each review
none for this control
governing documentDocuments that govern the control
- Incident response plan including 30-day cure handling · Policy repository / GRC workspace
- Breach notification procedure · Policy repository / GRC workspace
- Evidence of encryption/redaction of in-scope data fields · Policy repository / GRC workspace
First move
Start with the 1 of 4 artefacts that already live in a system (Identity provider / directory); keep the periodic reviews but log each one as a dated record with a named reviewer.
Common gaps auditors find
- Encryption not applied to sensitive elements
- No cure-letter handling workflow
- Reasonable security not benchmarked
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheet§1798.135(c) Authorized Agent Requests · §1798.155 Administrative Enforcement and Civil Penalties