Data Breach Policy
How CMIS responds when sensitive information may be at risk.
Last modified: 10/19/2022
CMIS treats potential incidents as a response process, not a guessing exercise: investigate, contain, assess, notify where required, and reduce future risk.
Purpose
This policy establishes how Construction Management Enterprises responds in the event of a data breach or suspected data breach. It outlines the process to investigate potential breaches, mitigate damage, and provide appropriate notice to affected parties when required.
Scope
This policy applies to incidents where Construction Management Enterprises could reasonably suspect or confirm a breach of customer, employee, contractor, or other personal identifying information handled by CMIS.
Definitions
Personal Identifying Information (PII) means information that could be used to distinguish or trace an individual's identity. Examples may include Social Security numbers, tax identification numbers, payment card information, payroll information, medical information, biometric records, dates of birth, addresses, phone numbers, maiden names, customer numbers, or similar personal information.
A breach means a situation where PII is accessed by someone other than an authorized user, or for a purpose that is not authorized.
Upon Learning of a Breach
Construction Management Enterprises will promptly investigate a breach or suspected breach of PII. Because PII is confidential, information about the investigation will be shared only with personnel who need it to perform the investigation and response.
The investigation will document available facts, including when the incident happened, how it happened, what types of information may have been involved, how many individuals may be affected, who was involved in the response, and what discoveries were made during the review.
Risk Assessment
If Construction Management Enterprises verifies and contains a breach, the response team will perform a risk assessment based on the sensitivity of the information, the volume of information involved, the number of individuals affected, whether the information is likely usable, whether the information appears to have been intentionally targeted, the strength of protections in place, and the ability to mitigate harm.
The response team will compile the findings, summarize the risk assessment, and provide the information to management and other appropriate advisors for review.
Notifying Affected Parties
Notification decisions are based on applicable legal requirements, the nature of the information involved, the number of individuals affected, and the facts developed through the investigation and risk assessment. Construction Management Enterprises may consult legal counsel to determine whether notice is required and what form the notice should take.
When notice is required, Construction Management Enterprises will notify affected parties in a timely and appropriate manner. Notice may be delayed if needed to avoid incomplete or misleading information, to support an active investigation, or to comply with applicable law enforcement or legal requirements.
Notification Content
A notification may include a brief description of the incident, the general types of information involved, what Construction Management Enterprises is doing to investigate and mitigate the incident, steps affected individuals can take to reduce potential harm, and contact information for follow-up questions.
Mitigating Risk
Based on the risk assessment, Construction Management Enterprises will develop and carry out an incident-specific mitigation plan. The plan may include containment actions, access review, credential changes, monitoring, communication with affected parties, additional safeguards, or other steps intended to reduce the impact of the incident and prevent similar incidents from recurring.
When appropriate, Construction Management Enterprises may provide affected individuals with practical steps they can take, such as monitoring accounts, reporting suspicious activity, contacting credit bureaus, watching for phishing attempts, filing a report with local law enforcement, or using identity-theft resources provided by government agencies.
Contact CMIS
Questions about this policy can be sent to contact@c-mis.com.