PT-1 Policy and Procedures. Develop, document, and disseminate to [organization-defined]: [organization-defined] personally identifiable information processing and transparency policy that: Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and Is consistent
Policy and Procedures. Develop, document, and disseminate to [organization-defined]: [organization-defined] personally identifiable information processing and transparency policy that: Addresses purpose, scope, roles, re.
system holds itEvidence a system already holds
none for this control
periodic reviewEvidence produced at each review
- Dissemination evidence to the defined personnel or roles · Identity provider / directory
governing documentDocuments that govern the control
- The personally identifiable information processing and transparency policy, covering purpose, scope, roles, responsibilities and management commitment · Policy repository / GRC workspace
- Evidence the policy addresses coordination among organisational entities and compliance · Policy repository / GRC workspace
- Procedures implementing the policy and its associated controls · Policy repository / GRC workspace
- Designation of the official to manage the policy and procedures, and review records against the defined frequency and triggering events · Policy repository / GRC workspace
First move
Common gaps auditors find
- Privacy obligations covered inside the security policy, with no distinct processing and transparency policy
- Coordination among entities unaddressed, so legal, marketing and product each interpret processing rules differently
- Review triggers not defined, so a change in privacy law does not prompt a policy update
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetPS-9 Position descriptions · PT-2 Authority to Process Personally Identifiable Information. Determine and document the [organization-defined] that permits the [organization-defined] of personally identifiable information; and Restrict the [organization-defined] of personally identifiable information to only that which is authorized