Purpose and Relationship to Governing Documents
The purpose of this Data Breach Incident Response Policy ("Policy") is to establish a clear, structured framework for identifying, responding to, mitigating, and documenting data breaches that may impact VA WORKS, LLC ("Consultant") or its stakeholders.
This Policy forms part of the Governing Policies referenced in the Master Service Agreement (MSA), the MSA Terms and Conditions (https://vaworks.com/MasterServiceAgreement), and any applicable Scope of Work (SOW) Terms and Conditions (https://vaworks.com/SOWSelection). In the event of conflict, priority shall be determined in accordance with the MSA.
The goal of this Policy is to ensure timely, coordinated, and compliant responses to data incidents while maintaining transparency with affected Companies and protecting the integrity of Consultant's operations.
Scope and Responsibility Disclaimer
Consultant provides workforce management and virtual staffing services. Its personnel access Company systems exclusively through secure virtual desktop environments, software, or platforms that are owned, managed, and controlled by the Company.
Consultant does not store, process, or host Company data directly, nor does it control the systems or infrastructure in which such data resides.
Accordingly, any data breach, vulnerability, or system compromise originating within a Company's virtual desktop, software, or cloud environment shall be the sole responsibility of the Company as data owner.
Consultant's responsibility is limited to:
- Promptly reporting known or suspected incidents;
- Cooperating in investigations; and
- Assisting with mitigation when the incident involves Consultant-managed devices, accounts, or personnel.
This Policy applies only to systems and data under Consultant's control — including company-managed devices, communication platforms, subcontractor systems, and any proprietary or administrative data directly maintained by Consultant.
Definitions
- Data Breach: Any confirmed or suspected event resulting in unauthorized access, disclosure, alteration, loss, or destruction of data.
- Incident: A security event that may compromise the confidentiality, integrity, or availability of systems or data.
- Incident Response Team (IRT): The designated internal group responsible for managing Consultant's incident response process.
Roles and Responsibilities
- Incident Response Lead (IRL): Oversees breach management, coordinates communication, and ensures timely resolution.
- IT & Security Team: Detects, investigates, contains, and remediates incidents within Consultant-managed systems.
- HR & Legal: Ensures compliance with applicable laws, drafts notifications, and manages coordination with regulators or external stakeholders.
- Executive Management: Approves formal communications and oversees decision-making for significant or high-risk incidents.
- All Personnel: Must immediately report any suspected or actual data breach to admin@mxworks.com.
Incident Response Lifecycle and Responsibilities
Step 1 – Identification
- Consultant detects or is informed of potential unauthorized access, activity, or compromise within its environment.
- The Company monitors and identifies incidents within its own systems.
- Consultant will notify the Company within twenty-four (24) hours of confirming any data breach that could reasonably affect Company systems or information.
Step 2 – Containment
- Consultant isolates impacted devices or accounts, revokes compromised credentials, and secures communication channels.
- The Company executes containment measures within its own networks and hosted systems.
- Timing: 24–48 hours following incident identification.
Step 3 – Eradication and Investigation
- Consultant conducts forensic review, removes malicious components, and remediates vulnerabilities.
- The Company performs parallel eradication activities in its infrastructure as required.
- Timing: Within five (5) business days of containment or sooner if regulatory deadlines apply.
Step 4 – Recovery
- Consultant restores secure systems, re-enables validated accounts, and confirms security posture before returning to normal operations.
- The Company restores production systems under its control.
- Timing: After successful eradication and verification of system integrity.
Step 5 – Notification
- Consultant promptly notifies the Company of confirmed breaches or material risks.
- The Company is responsible for external notifications to regulators, customers, and other third parties as required under applicable law.
- Timing: Without undue delay and within any legally mandated reporting windows.
Step 6 – Post-Incident Review
- Consultant conducts a documented review of the incident, including root cause, corrective actions, and lessons learned.
- The Company may request a joint review meeting following any major incident.
- Timing: Within fourteen (14) business days of incident closure.
Data Breach Classification
- Low Severity: Minimal exposure; no sensitive data compromised. Notification: Internal only.
- Medium Severity: Limited non-public or business data accessed. Notification: Company required.
- High Severity: Involves large-scale exposure, legal obligations, or regulatory notification thresholds. Notification: Company, regulators, and affected individuals as applicable.
Recordkeeping and Documentation
Consultant maintains secure, detailed records of all incidents, including event timelines, communications, and mitigation steps.
All records shall be retained for a minimum of five (5) years and made available to the Company or relevant authorities upon written request.
Training and Awareness
All Consultant employees and independent contractors receive annual data protection and security training, which includes:
- Breach identification and reporting protocols;
- Secure handling of Company data; and
- Phishing and social engineering prevention.
At least one annual incident response simulation (tabletop exercise) will be conducted to evaluate and improve readiness.
Policy Review and Amendments
This Policy is reviewed annually or earlier if:
- Regulatory, contractual, or legal changes require updates; or
- A significant incident exposes the need for revision.
All amendments are governed by the Policy Maintenance and Amendment Control Policy, which mandates thirty (30) days' advance notice to Companies for standard updates.
