{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"privacy","domain":["Incident Management & Response","Data Protection & Privacy","Compliance, Audit & Assurance"],"inherent_rating":"high","taxonomy":["nist-privacy-risk","enterprise-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Air-breach-notification-failure","description":"Failure to detect, assess, and notify affected individuals and regulators of personal-data breaches within required timeframes and content (GDPR Art.33/34, HIPAA breach rule), resulting in sanctions and compounded individual harm.","details":{"category":"privacy","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"ir-breach-notification-failure","taxonomies":["nist-privacy-risk","enterprise-risk"],"treatment":"mitigate"},"id":"risk:ir-breach-notification-failure","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Air-breach-notification-failure","sourceIds":["gdpr","hipaa","iso-27001","nist-800-53","nist-csf-2","soc2"],"sourceUrl":null,"title":"Failure to detect, assess, and notify breaches on time","type":"risk"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:04b40b037e51c3fd146d1a2c69b51720dad73989915420d0806b29a0ab3f3a1f","properties":{"rationale":"Prompt all-personnel event reporting enables timely detection, a prerequisite for meeting statutory breach-notification deadlines.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-ir-03-477c1ef0.json","sourceId":"uc:UC-IR-03","targetDetailPath":"/data/v1/records/risk-ir-breach-notification-failure-1f01c218.json","targetId":"risk:ir-breach-notification-failure","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:19966fd02f54cce81f20dee195b7fb916d132d716903829889db0ae1e56feef4","properties":{"rationale":"Assessing records affected and magnitude sizes notification obligations, but the operative notification defense is UC-IR-08; assessment is an upstream input that contributes, not the notification act itself.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-ir-05-0e11ebf5.json","sourceId":"uc:UC-IR-05","targetDetailPath":"/data/v1/records/risk-ir-breach-notification-failure-1f01c218.json","targetId":"risk:ir-breach-notification-failure","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1b38252b326129e0fbbe6888bb11bf3889a21a32ec21fc24a2336469973d6cb7","properties":{"rationale":"Plan defines communication paths and third-party/BC coordination that the downstream breach-notification chain depends on.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-ir-01-e7711d29.json","sourceId":"uc:UC-IR-01","targetDetailPath":"/data/v1/records/risk-ir-breach-notification-failure-1f01c218.json","targetId":"risk:ir-breach-notification-failure","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1fa3413a85c8476db33505a72b6bc4e3e0bc810f8052cce0cc2dd32ea89d6e6f","properties":{"rationale":"Validating and classifying events and declaring incidents is the assessment step that breach-notification-threshold decisions rest on.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-ir-04-6067c069.json","sourceId":"uc:UC-IR-04","targetDetailPath":"/data/v1/records/risk-ir-breach-notification-failure-1f01c218.json","targetId":"risk:ir-breach-notification-failure","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:463c2c0034411e95da828e0cd200cc1c3bf15c1d2d2c8b4d54c69b3c52e59697","properties":{"rationale":"The notification matrix, statutory-window notifications to regulators/individuals, and retained evidence directly defend against late or incomplete breach notification (GDPR/HIPAA).","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-ir-08-01afe3d1.json","sourceId":"uc:UC-IR-08","targetDetailPath":"/data/v1/records/risk-ir-breach-notification-failure-1f01c218.json","targetId":"risk:ir-breach-notification-failure","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5835f536ceae6e7d465086aea1d7e72874b25d0ef88b17f8b482cde65d17e64b","properties":{"rationale":"Assessing obligations triggered by the spill determines regulatory notification duties for the exposed regulated data.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-ir-11-6234912d.json","sourceId":"uc:UC-IR-11","targetDetailPath":"/data/v1/records/risk-ir-breach-notification-failure-1f01c218.json","targetId":"risk:ir-breach-notification-failure","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ecf69519de6862ac4c016524174b7effb622285c9a16bc07e923e9f747242f34","properties":{"rationale":"Notifying affected subjects, regulators, and other parties within statutory windows directly counters failure to notify breaches on time.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-data-15-efb7b99a.json","sourceId":"uc:UC-DATA-15","targetDetailPath":"/data/v1/records/risk-ir-breach-notification-failure-1f01c218.json","targetId":"risk:ir-breach-notification-failure","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:edf4d97d894de8125bfdae26b6463316b7b9f6bfee002bc741291f2fe9d15c0b","properties":{"rationale":"Routing vendors' breach notifications into incident response ensures timely detection/notification of third-party breaches.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-data-16-57ae2c9a.json","sourceId":"uc:UC-DATA-16","targetDetailPath":"/data/v1/records/risk-ir-breach-notification-failure-1f01c218.json","targetId":"risk:ir-breach-notification-failure","type":"mitigates"}],"schemaVersion":1}
