EvidenceSheet

PM-18 Privacy Program Plan. Develop and disseminate an organization-wide privacy program plan that provides an overview of the agency's privacy program, and: Includes a description of the structure of the privacy program and the resources

Privacy Program Plan. Develop and disseminate an organization-wide privacy program plan that provides an overview of the agency's privacy program, and: Includes a description of the structure of the privacy program and t.

5
artefacts
0
held by a system
2
at each review
hard
to go live
Policy repository / GRC workspace
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

none for this control

periodic reviewEvidence produced at each review

  • Approval by a senior official with authority and resources, and evidence of dissemination · Document repository
  • Review and update records against the defined frequency and following privacy incidents or legal change · Data governance / DLP tooling

governing documentDocuments that govern the control

  • The organisation-wide privacy program plan, with the programme structure and the resources dedicated to it · Policy repository / GRC workspace
  • The strategic goals and objectives of the privacy programme and how they will be met · Policy repository / GRC workspace
  • Identification of the privacy controls in place or planned, and the roles and responsibilities behind them · Policy repository / GRC workspace

First move

This control is evidenced by people and documents, not systems. Put the document under version control with an owner and review date, and log each review as a record with reviewer and date. Do not try to automate it.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

PM-17 Protecting Controlled Unclassified Information on External Systems. Establish policy and procedures to ensure that requirements for the protection of controlled unclassified information that is processed, stored or transmitted on external systems, are implemented in · PM-19 Privacy Program Leadership Role. Appoint a senior agency official for privacy with the authority, mission, accountability, and resources to coordinate, develop, and implement, applicable privacy requirements and manage privacy risks through the organization-wide privacy