PM-15 Security and Privacy Groups and Associations. Establish and institutionalize contact with selected groups and associations within the security and privacy communities: To facilitate ongoing security and privacy education and training for organizational personnel; To
Security and Privacy Groups and Associations. Establish and institutionalize contact with selected groups and associations within the security and privacy communities: To facilitate ongoing security and privacy education.
system holds itEvidence a system already holds
none for this control
periodic reviewEvidence produced at each review
- Records of contact or membership, such as membership confirmations and meeting attendance · HR system / LMS
- Evidence the contact produced ongoing education for personnel, for example briefings circulated internally · Document repository
- Evidence of currency maintained on recommended practices, techniques and technologies through those contacts · Document repository
- Records of security and privacy information shared with the groups where appropriate · Data governance / DLP tooling
governing documentDocuments that govern the control
- The selected security and privacy groups and associations, and the rationale for selecting them · Policy repository / GRC workspace
First move
Common gaps auditors find
- Membership held by one individual with nothing flowing back to the wider organisation
- Contacts named in the plan with no evidence of any interaction during the period
- Information sharing one way only, receiving without any review of what may be shared out
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetPM-14 Testing, Training, and Monitoring. Implement a process for ensuring that organizational plans for conducting security and privacy testing, training, and monitoring activities associated with organizational systems: Are developed and maintained; and Continue to be · PM-16 Threat Awareness Program. Implement a threat awareness program that includes a cross-organization information-sharing capability for threat intelligence