It contains 7 chapters and 10 appendices that include:
· Definitions of information security incidents and data breaches;
· Summaries of the 2 major privacy regulations (GDPR and LGPD);
· An Information Security Incident and Breach Management Approach of 4 phases:
· Phase 1. Security and Breach Obligations and Requirements Comprehension;
· Phase 2. Security & Privacy Framework Assurance;
· Phase 3. Security Incident and Data Breach Response Management; and
· Phase 4. Security and Breach Response Process Evaluation),
· 7 milestones and 37 steps to manage information security incident responses, investigate cybercrimes and handle data breaches; and
· Several policies, plans and forms (e.g., Threat Intelligence Policy, IT Logging Policy, Staff Education and Training Policy, Privacy Awareness, Communication and Training Plan, etc.).