You have been asked to help develop a company policy on what should be done in the event of a data breach, such as unauthorized access to your firm's customer database containing some 1.5 million records. What sort of process would you use to develop such a policy? What resources would you call on?