PT-2 Authority to Process Personally Identifiable Information. Determine and document the [organization-defined] that permits the [organization-defined] of personally identifiable information; and Restrict the [organization-defined] of personally identifiable information to only that which is authorized
Authority to Process Personally Identifiable Information. Determine and document the [organization-defined] that permits the [organization-defined] of personally identifiable information; and Restrict the [organization-d.
system holds itEvidence a system already holds
- Evidence processing is restricted to what the authority permits, such as configuration or procedural limits · Cloud console / configuration management
periodic reviewEvidence produced at each review
- Records of review where a new processing activity was assessed against existing authority · Data governance / DLP tooling
- Escalation records where processing was stopped or changed because authority was absent · Data governance / DLP tooling
governing documentDocuments that govern the control
- The documented authority that permits each processing of personally identifiable information, naming the statute, regulation or other basis · Policy repository / GRC workspace
- Mapping from each processing activity to its authority · Policy repository / GRC workspace
First move
Common gaps auditors find
- Authority recorded at system level while individual processing activities within it have no separate basis
- Secondary uses such as analytics and model training added with no reassessment of authority
- Authority documented but nothing restricts processing to it, so the record and the practice diverge
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetPT-1 Policy and Procedures. Develop, document, and disseminate to [organization-defined]: [organization-defined] personally identifiable information processing and transparency policy that: Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and Is consistent · PT-3 Personally Identifiable Information Processing Purposes. Identify and document the [organization-defined] for processing personally identifiable information; Describe the purpose(s) in the public privacy notices and policies of the organization; Restrict the [organization-defined] of personally identifiable