What the Australian Notifiable Data Breaches Scheme Actually Requires of Your Organisation
The Notifiable Data Breaches scheme has been in operation since 2018, and the OAIC’s quarterly statistics make uncomfortable reading. Breach notifications have increased every year. The most common cause is not sophisticated cyberattack, it is human error and compromised credentials. And the sectors most frequently appearing in the data include healthcare, finance, legal, and education. The organisations that handle exactly the personal information the scheme is designed to protect.
What Triggers a Notification Obligation
A notifiable data breach occurs when there is unauthorised access to, disclosure of, or loss of personal information that is likely to result in serious harm to the individuals concerned. The threshold is “likely serious harm” not actual harm, and not certain harm. The assessment must be made promptly, and if the threshold is met, notification to the OAIC and affected individuals must follow.
This assessment requirement is where most organisations struggle. Identifying that a breach has occurred is one challenge. Assessing the likely harm consequences quickly enough to meet the notification timeline, without the processes and playbooks to do it, is another.
What ISO 27001 Adds
An ISO 27001 certified information security management system provides the incident detection, assessment, and response capabilities that the NDB scheme presupposes. The standard requires documented incident management procedures, defined roles and responsibilities, and regular testing of response capabilities.
Organisations with a functioning ISMS are materially better positioned to identify breaches promptly, assess their harm potential accurately, and execute the notification process correctly under time pressure.
AuditCo’s ISO 27001 services include assessment of incident management capabilities against both the standard’s requirements and the NDB scheme’s practical obligations. Talk to us about whether your incident response capability is genuinely fit for purpose.
Explore AuditCo’s ISO 27001 audit services
