In 2.04.10, which is the appropriate answer if no breach has occurred since September 1, 2009?
If your agency has had no system security breach to report since this requirement came into effect on September 1, 2009, but you do have a procedure in place to carry out the referenced notification requirements, then the appropriate answer would be “In compliance”. If there has been no breach, and you do not have such a procedure defined, then the appropriate answer would be the “No breach…” answer. When DIR reviews agency compliance based on IRDR Part 2 responses, the “No breach…:” answer will be considered equivalent to “In compliance”.