Client Data Breach Incident Response Worksheet
Client Data Breach Incident Response Worksheet
Section titled “Client Data Breach Incident Response Worksheet”Name:
Role:
Organizational Unit (e.g., agency, department, division, team) and Affiliation:
E-mail Address:
Phone Number:
Contact Information for alternate Law Enforcement Officer/Regulator (if appropriate)
Section titled “Contact Information for alternate Law Enforcement Officer/Regulator (if appropriate)”Name:
Role:
Organizational Unit (e.g., agency, department, division, team) and Affiliation:
E-mail Address:
Phone Number:
Contact Information for the Incident Reporter
Section titled “Contact Information for the Incident Reporter”Name:
Role:
Organizational Unit (e.g., agency, department, division, team) and Affiliation:
E-mail Address:
Phone Number:
Contact Information for the Incident Response Coordinator
Section titled “Contact Information for the Incident Response Coordinator”Name: Name:
Role:
Organizational Unit (e.g., agency, department, division, team) and Affiliation:
E-mail Address:
Phone Number:
Contact Information for the Incident Response Lead
Section titled “Contact Information for the Incident Response Lead”Name:
Role:
Organizational Unit (e.g., agency, department, division, team) and Affiliation:
E-mail Address:
Phone Number:
Other Team Members Involved
Section titled “Other Team Members Involved”Name:
Role:
Organizational Unit (e.g., agency, department, division, team) and Affiliation:
E-mail Address:
Phone Number:
Name:
Role:
Organizational Unit (e.g., agency, department, division, team) and Affiliation:
E-mail Address:
Phone Number:
(add other team member contact information on additional pages as necessary)
Incident Details
Section titled “Incident Details”Current status of the Incident (updated as appropriate, choose all that apply):
| Ongoing Attack | Contained | Eradicated | Recovery |
|---|---|---|---|
| Investigating | Impact Evaluated | Formal Incident Declared | Incident Closed |
| US Department of Defense Notified | Other Federal Regulators Notified | State/Local Regulators Notified | International Regulators Notified |
Status change date/timestamps (including time zone) when:
Incident Started:
Incident First Discovered:
Incident Reported:
Incident Declared:
Incident Resolved/Ended:
Physical location at which the:
Incident Started:
Incident First Discovered:
Incident Reported:
Information Types Impacted (check all that apply)
Section titled “Information Types Impacted (check all that apply)”| Government Information | Customer/Partner Information | Customer/Partner Information | Internal Information | Internal Information |
|---|---|---|---|---|
| Controlled Technical Information | Personal Health Information (“PHI”) | Employee Financial/Personal Health Info. | ||
| Covered Defense Information | Personally Identifiable Information (“PII”) | Employee Personally Identifiable Information | ||
| Controlled Unclassified Information | Customer Privileged Information (Case Histories/Legal Documents) | Legal (privileged) Information |
| Federal Contract Information | Customer Confidential Information | Organization Financial Information |
|---|---|---|
| Other Government Information | Partner Confidential Information | Organization Confidential Information |
From what jurisdiction(s) is/are the information (e.g., PII from Guam, California, and New York; Financial Information from Florida and Alabama; CUI from DoD and DHS):
Source/cause of the incident (if known):
| IP/Physical Address(es) | Individual/Equipment Name(s) | Notes |
|---|
Incident Description (how was the incident detected, what occurred, etc.):
(Continue the description on one or more separate pages as necessary)
Affected Resources (e.g., networks, subnets, hosts, applications, data), including hostnames, IP addresses, and function:
(Continue the description on one or more separate pages as necessary)
Vectors of Attack and Indicators of Compromise (e.g., equipment not showing up in inventory, traffic patterns, registry keys, MD5/SHA256 hashes, etc.):
(Continue the description on one or more separate pages as necessary)
Information Attributes (e.g., what kind of information (including healthcare information, banking information, PII, client information, and partner information) and from what jurisdiction(s)):
(Continue the description on one or more separate pages as necessary)
Impact Quantification Factors (functional impact, information impact, recoverability, etc.)
Section titled “Impact Quantification Factors (functional impact, information impact, recoverability, etc.)”| Factor Description | Individual Factor Severity Score | Individual Factor Severity Score | Individual Factor Severity Score | Individual Factor Severity Score | Individual Factor Severity Score | Total |
|---|---|---|---|---|---|---|
| Business Impact (check the appropraite box and enter corresponding score in the Total column) | None (0) | Few/ Limited (2) | Many/ Moderate (5) | Most/ Severe (8) | All/ Critical (10) | |
| To what extent will the Incident or the response to the Incident impact the organization’s ability to continue day- to-day operations? | ||||||
| To what extent will the Incident impact one or more Clients’ ability to continue day-to-day operations? | ||||||
| To what extent is the Incident spreading to other equipment/information? | ||||||
| Government Information (check the appropriate box and enter corresponding score in the Total column) | FCI (10) | CUI (55) | CDI (55) | CTI (55) | Total | |
| Is any government information (FCI, CUI, CDI, CTI, etc.) potentially involved in the incident? | ||||||
| Non-Government Information (check the appropraite box and enter corresponding score in the Total column) | None (0) | Few/ Limited (5) | Many/ Moderate (8) | Most/ Severe (10) | All/ Critical (15) | Total |
| How many client-related health records may have been exposed in the Incident? |
| How many client-related financial records may have been exposed in the Incident? | ||||||
|---|---|---|---|---|---|---|
| How many client-related records containing Personally Identifiable Information (PII) may have been exposed in the Incident? | ||||||
| How many employee financial or personal records, including PII, may have been exposed in the Incident? | ||||||
| To what extent is/are the organization’s bank account(s) impacted by the Incident? | ||||||
| To what extent is the organization’s confidential information impacted by the Incident? | ||||||
| How much of the information impacted by the Incident is likely to be subject to additional legal or regulatory restrictions (e.g., GDPR, CCPA, 23 NYCRR 500, etc.)? | ||||||
| Recoverability Effort (check the appropriate box and enter corresponding score in the Total column) | None (0) | Few/ Limited (5) | Many/ Moderate (8) | Most/ Severe (10) | All/ Critical (15) | Total |
| What is the expected level of effort needed to recover from the Incident? | ||||||
| Potentially Mitigating Factors (check the appropriate box and enter corresponding score in the Total column) | None (0) | Few/ Limited (-5) | Many/ Moderate (-8) | Most/ Severe (-10) | All/ Critical (-15) | Total |
| To what extent is the information impacted by the Incident encrypted where the encryption key was not also exposed? | ||||||
| Other Severity Factors (assign a score to each factor) | None | Few/ Limited | Many/ Moderate | Severe/ Most | All/ Critical | Total |
| Total Score |
|---|
Assign an overall Severity Score to the Incident based on the Total Score from the table above:
| Low | Moderate | High | Critical |
|---|---|---|---|
| 0- 10 | 11-25 | 26- 50 | 51+ |
Response Actions Performed (e.g., disconnected device from the network, shut down host/device, etc.)
Section titled “Response Actions Performed (e.g., disconnected device from the network, shut down host/device, etc.)”a. Log of Actions Taken by Incident Responders
Section titled “a. Log of Actions Taken by Incident Responders”| Date | Time | Incident Responder | Action Taken |
|---|
(Copy sheet or add notes on back/separate page(s) as necessary)
Post Incident Analysis
Section titled “Post Incident Analysis”- a. List of Evidence Gathered:
- b. Incident Handler/Involved Party Comments and Notes:
- c. Incident Cause (e.g., unpatched equipment, misconfigured application, zeroday, SQL injection, etc.):
- d. Incident Business Impact:
-
- Lessons Learned
- a. What went well?
Document the actions taken or other attributes of the response that went well. This is important because any issues/improvements that may be listed below can be modeled after the successful attributes of the response.
b. What could use improvement?
Section titled “b. What could use improvement?”What attributes of the organization’s response could use additional attention?
c. How can we improve the Incident Response Plan for next time?
Section titled “c. How can we improve the Incident Response Plan for next time?”Related Standards, Policies, Plans, and Procedures
Section titled “Related Standards, Policies, Plans, and Procedures”Incident Response Policy
Client Data Breach Incident Response Plan
Referenced Terms
- CUI
- Information that requires safeguarding or dissemination controls pursuant to and consistent with applicable law, regulations, and government-wide policies.
Revision History
- 2026-08-20 — Darren Rush
- Merge pull request #2 from safire-dev/dev (
16cb681)