EvidenceSheet

PT-2 Authority to Process Personally Identifiable Information. Determine and document the [organization-defined] that permits the [organization-defined] of personally identifiable information; and Restrict the [organization-defined] of personally identifiable information to only that which is authorized

Authority to Process Personally Identifiable Information. Determine and document the [organization-defined] that permits the [organization-defined] of personally identifiable information; and Restrict the [organization-d.

5
artefacts
1
held by a system
2
at each review
hard
to go live
Policy repository / GRC workspace
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

  • Evidence processing is restricted to what the authority permits, such as configuration or procedural limits · Cloud console / configuration management

periodic reviewEvidence produced at each review

  • Records of review where a new processing activity was assessed against existing authority · Data governance / DLP tooling
  • Escalation records where processing was stopped or changed because authority was absent · Data governance / DLP tooling

governing documentDocuments that govern the control

  • The documented authority that permits each processing of personally identifiable information, naming the statute, regulation or other basis · Policy repository / GRC workspace
  • Mapping from each processing activity to its authority · Policy repository / GRC workspace

First move

Mostly documents and reviews. Pull the 1 system-held artefact from your Cloud console / configuration management on a schedule; put the documents under version control with an owner and review date, and log each review as a dated record with a named reviewer.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

PT-1 Policy and Procedures. Develop, document, and disseminate to [organization-defined]: [organization-defined] personally identifiable information processing and transparency policy that: Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and Is consistent · PT-3 Personally Identifiable Information Processing Purposes. Identify and document the [organization-defined] for processing personally identifiable information; Describe the purpose(s) in the public privacy notices and policies of the organization; Restrict the [organization-defined] of personally identifiable