Incident Response and Notification to the Cyber Center and Attorney General

Maturity Level

Privacy Logo
  1. Level 0: Non-Existent

    The practice is not implemented or acknowledged.
    No incident response plan exists, or responses are purely reactive and chaotic.

    Example Strategies

    • Identify individuals who can perform such functions in an ad hoc or as needed basis until permanent individuals are appointed.
  2. Level 1: Ad Hoc

    Practice may occur but is undocumented (no policies or procedures), application is reactive and not standardized.
    An informal understanding of incident response exists, but there's no documented plan or clear roles/responsibilities for privacy incidents.

    Example Strategies

    • Document a basic incident response plan specifically for privacy incidents.
    • Draft a written privacy incident response plan outlining initial steps, who to notify internally, and basic procedures for containment and assessment.
  3. Level 2: Defined

    Practice is implemented and documented, but documentation may not cover all relevant aspects, and application may be informal and inconsistent.
    A general incident response plan exists, but it may not specifically address privacy incidents or meet all Utah Code 63A-19-405 requirements. Testing is infrequent.

    Example Strategies

    • Regularly test the incident response plan and clearly define roles and responsibilities.
    • Conduct annual tabletop exercises or simulations of a data breach, involving relevant departments, to test the plan's effectiveness and clarify roles, responsibilities, and communication protocols (e.g., reporting to the Utah Cyber Center).
  4. Level 3: Consistently Implemented

    Practice is documented to cover all relevant aspects, application is formal and consistent.
    A formal, documented, and regularly tested incident response plan specifically for privacy incidents and data breaches is in place, with clear roles, responsibilities, and escalation procedures aligned with Utah Code.

    Example Strategies

    • Track and analyze privacy incidents to identify root causes and implement corrective actions.
    • Establish a system for logging all privacy incidents (even minor ones), conducting post-incident reviews to identify systemic issues, and implementing preventive measures based on findings.
  5. Level 4: Managed

    Practice is actively managed with metrics that are regularly reviewed to assess efficacy and facilitate improvement.
    The entity conducts regular tabletop exercises and simulations of privacy incidents, tracks the effectiveness of the response, and uses lessons learned to improve the plan.

    Example Strategies

    • Incident response plans are fully fleshed out with clear communication channels with requisite parties and determined processes and points of contact.
  6. Level 5: Optimized

    Practice is fully embedded in the entity with recognition and understanding across the workforce through active training and awareness campaigns, and inclusion in operations and strategy.
    The incident response plan is fully integrated with the entity's broader security operations, leveraging advanced threat detection and automated response capabilities, with a strong emphasis on proactive risk reduction.