PM-23 Data Governance Body. Establish a Data Governance Body consisting of [organization-defined] with [organization-defined]
Data Governance Body. Establish a Data Governance Body consisting of [organization-defined] with [organization-defined].
system holds itEvidence a system already holds
none for this control
periodic reviewEvidence produced at each review
- Minutes and decision records from body meetings during the period · Policy repository / GRC workspace
- Records of requests to review data and the outcomes decided · Document repository
governing documentDocuments that govern the control
- The document establishing the Data Governance Body and its charter of operations · Policy repository / GRC workspace
- Membership showing the defined roles are filled, with their authority · Policy repository / GRC workspace
- The policies, procedures and standards the body issued or approved · Policy repository / GRC workspace
First move
Common gaps auditors find
- Body chartered but not convened, so no decisions exist to evidence it
- Membership lacks the legal and privacy roles required to decide the questions put to it
- Decisions taken with no record, leaving governance unauditable
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetPM-22 Personally Identifiable Information Quality Management. Develop and document organization-wide policies and procedures for: Reviewing for the accuracy, relevance, timeliness, and completeness of personally identifiable information across the information life cycle; Correcting or deleting inaccurate · PM-24 Data Integrity Board. Establish a Data Integrity Board to: Review proposals to conduct or participate in a matching program; and Conduct an annual review of all matching programs in which the agency has participated