PM-18 Privacy Program Plan. Develop and disseminate an organization-wide privacy program plan that provides an overview of the agency's privacy program, and: Includes a description of the structure of the privacy program and the resources
Privacy Program Plan. Develop and disseminate an organization-wide privacy program plan that provides an overview of the agency's privacy program, and: Includes a description of the structure of the privacy program and t.
system holds itEvidence a system already holds
none for this control
periodic reviewEvidence produced at each review
- Approval by a senior official with authority and resources, and evidence of dissemination · Document repository
- Review and update records against the defined frequency and following privacy incidents or legal change · Data governance / DLP tooling
governing documentDocuments that govern the control
- The organisation-wide privacy program plan, with the programme structure and the resources dedicated to it · Policy repository / GRC workspace
- The strategic goals and objectives of the privacy programme and how they will be met · Policy repository / GRC workspace
- Identification of the privacy controls in place or planned, and the roles and responsibilities behind them · Policy repository / GRC workspace
First move
Common gaps auditors find
- Plan lists privacy obligations without naming the resources committed, which is the specific content the control requires
- Privacy folded into the security program plan rather than maintained as its own plan
- Not updated after a change in privacy law that altered the obligations it describes
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetPM-17 Protecting Controlled Unclassified Information on External Systems. Establish policy and procedures to ensure that requirements for the protection of controlled unclassified information that is processed, stored or transmitted on external systems, are implemented in · PM-19 Privacy Program Leadership Role. Appoint a senior agency official for privacy with the authority, mission, accountability, and resources to coordinate, develop, and implement, applicable privacy requirements and manage privacy risks through the organization-wide privacy