EvidenceSheet

PM-25 Minimization of Personally Identifiable Information Used in Testing, Training, and Research. Develop, document, and implement policies and procedures that address the use of personally identifiable information for internal testing, training, and research; Limit or

Minimization of Personally Identifiable Information Used in Testing, Training, and Research. Develop, document, and implement policies and procedures that address the use of personally identifiable information for intern.

5
artefacts
1
held by a system
3
at each review
hard
to go live
HR system / LMS
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

  • Records showing test, training and research data is removed or destroyed when no longer needed · HR system / LMS

periodic reviewEvidence produced at each review

  • Evidence of the limitation or minimisation applied, such as synthetic data, subsetting or de-identification · Document repository
  • Authorisation records where real personally identifiable information was used, with the justification · Document repository
  • Privacy risk assessment covering the testing, training and research use · HR system / LMS

governing documentDocuments that govern the control

  • Policies and procedures addressing use of personally identifiable information for internal testing, training and research · HR system / LMS

First move

Mostly documents and reviews. Pull the 1 system-held artefact from your HR system / LMS on a schedule; put the documents under version control with an owner and review date, and log each review as a dated record with a named reviewer.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

PM-24 Data Integrity Board. Establish a Data Integrity Board to: Review proposals to conduct or participate in a matching program; and Conduct an annual review of all matching programs in which the agency has participated · PM-26 Complaint Management. Implement a process for receiving and responding to complaints, concerns, or questions from individuals about the organizational security and privacy practices that includes: Mechanisms that are easy to use and readily accessible