Control(s)
Category
Data Processing Policies, Processes, and Procedures (CT.PO-P): Policies, processes, and procedures are maintained and used to manage data processing (e.g., purpose, scope, roles and responsibilities in the data processing ecosystem, and management commitment) consistent with the organization’s risk strategy to protect individuals’ privacy.
Subcategory
- CT.PO-P1: Policies, processes, and procedures for authorizing data processing (e.g., organizational decisions, individual consent), revoking authorizations, and maintaining authorizations are established and in place.
CT.PO-P2: Policies, processes, and procedures for enabling data review, transfer, sharing or disclosure, alteration, and deletion are established and in place (e.g., to maintain data quality, manage data retention).
CT.PO-P3: Policies, processes, and procedures for enabling individuals’ data processing preferences and requests are established and in place.
CT.PO-P4: A data life cycle to manage data is aligned and implemented with the system development life cycle to manage systems.
Function
- CONTROL-P (CT-P)
What is the NIST Privacy Framework
The NIST Privacy Framework is a voluntary tool for improving privacy through Enterprise Risk Management, to enable better privacy engineering practices that support privacy by design concepts and
help organizations protect individuals’ privacy. The Privacy Framework can support organizations in:
- Building customers’ trust by supporting ethical decision-making in product and service design or
deployment that optimizes beneficial uses of data while minimizing adverse consequences for
individuals’ privacy and society as a whole;1 - Fulfilling current compliance obligations, as well as future-proofing products and services to
meet these obligations in a changing technological and policy environment; and - Facilitating communication about privacy practices with individuals, business partners,
assessors, and regulators.
Source: https://www.nist.gov/privacy-framework/privacy-framework
Note: NIST and related copyright and trademarks belong to their respective owner(s). This guide is for educational purposes only.