PT-6 System of Records Notice. For systems that process information that will be maintained in a Privacy Act system of records: Draft system of records notices in accordance with OMB guidance and submit new and
System of Records Notice. For systems that process information that will be maintained in a Privacy Act system of records: Draft system of records notices in accordance with OMB guidance and submit new and.
system holds itEvidence a system already holds
none for this control
periodic reviewEvidence produced at each review
- Identification of systems that maintain information in a Privacy Act system of records · Data governance / DLP tooling
- Drafted system of records notices and evidence of submission to the required oversight for review · Data governance / DLP tooling
- Review records for the notices at the defined frequency · Data governance / DLP tooling
governing documentDocuments that govern the control
- The published Federal Register notices for new, modified and rescinded systems of records · Policy repository / GRC workspace
- Evidence the notice content matches how the system actually operates · Policy repository / GRC workspace
First move
Common gaps auditors find
- System of records identified but the notice never published, so the collection has no public basis
- Notice published at inception and not revised when the routine uses or categories of records changed
- Notices reviewed for existence rather than accuracy, so drift between notice and practice persists
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetPT-5 Privacy Notice. Provide notice to individuals about the processing of personally identifiable information that: Is available to individuals upon first interacting with an organization, and subsequently at [organization-defined]; Is clear and easy-to-understand, expressing information · PT-7 Specific Categories of Personally Identifiable Information. Apply [organization-defined] for specific categories of personally identifiable information