SOC2-P6.3 P6.3 Record of unauthorised disclosures and breaches
SOC2-P6.3 in SOC 2 (the AICPA 2017 Trust Services Criteria with the revised points of focus). All SOC 2 controls held. Open SOC 2 on the standards site.
The control as we hold it
P6.3 Record of unauthorised disclosures and breaches. A full, correct and up-to-date log of detected or reported unauthorised disclosures, including breaches, of personal information is created and kept. Point of focus: the record of detected or reported unauthorised disclosures is maintained completely, accurately and promptly.
Reviewed and closest counterparts in the other frameworks
Reviewed rows come from a released pair; a closest match is the nearest held text and is not a reviewed row.
HIPAA Security Rule
- 164.306 Security Standards: General Rules (closest match)
- 164.308(a)(6)(i) Security Incident Procedures (Standard) (closest match)
- 164.308(a)(6)(ii) Response and Reporting (Required) (closest match)
- 164.310(d)(2)(iii) Accountability (Addressable) (closest match)
- 164.316(b)(1) Documentation (Standard) (closest match)
NIST SP 800-53 Rev 5
- NIST800-AU-3 AU-3 Content of Audit Records (closest match)
- NIST800-AU-10 AU-10 Non-repudiation (closest match)
- NIST800-AU-11 AU-11 Audit Record Retention (closest match)
- NIST800-AU-12 AU-12 Audit Record Generation (closest match)
- NIST800-AU-13 AU-13 Monitoring for Information Disclosure (closest match)
- NIST800-IR-4 IR-4 Incident Handling (closest match)
- NIST800-IR-5 IR-5 Incident Monitoring (closest match)
- NIST800-IR-6 IR-6 Incident Reporting (closest match)
What an auditor commonly asks for
General guidance for this control area (domain: P - Privacy), in our words, not a statement of the standard and not binding on an assessor.
- the privacy notice and its change log
- the consent and preference records
- the data-subject request log with resolution
- the retention and disposal records