See purpose.
The purpose of the policy is to establish the goal and the vision for the breach response process. This policy will clearly define to whom it applies and under what circumstances, and it will include the definition of a breach, staff roles and responsibilities, standards and metrics (e.g., to enable prioritization of the incidents), as well as reporting, remediation, and feedback mechanisms. The policy shall be well publicized and made easily available to all personnel whose duties involve data privacy and security protection.
The Diocese of Paterson Information Security’s intentions for publishing a Data Breach Response Policy is to focus significant attention on data security. The Diocese of Paterson’s Information Technology team is committed to protecting The Diocese of Paterson’s employees, partners and the organization from illegal or damaging actions by individuals, either knowingly or unknowingly.
This policy applies to all whom collect, access, maintain, distribute, process, protects, stores, uses, transmits, disposes of, or otherwise handles personally identifiable information (PII), payment card information (PCI) or Protected Health Information (PHI) of The Diocese of Paterson’s members. Any agreements with vendors will contain language similar that protects the organization.