STIGhub
STIGs
RMF Controls
Compare
← All Controls
PT-1
PII Processing and Transparency
Rev 5
Policy and Procedures
CCI Identifiers (14)
CCI-004525
Develop and document organization-level; mission/business process-level; and/or system level personally identifiable information processing and transparency policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance.
CCI-004526
Disseminate organization-level; mission/business process-level; and/or system level personally identifiable information processing and transparency policy to organization-defined personnel or roles.
CCI-004527
Defines the personnel or roles to whom the organization-level; mission/business process-level; and/or system level personally identifiable information processing and transparency policy is to be disseminated.
CCI-004528
Develop and document organization-level; mission/business process-level; and/or system level personally identifiable information processing and transparency policy that is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines.
CCI-004529
Develop and document procedures to facilitate the implementation of the personally identifiable information processing and transparency policy and the associated personally identifiable information processing and transparency controls.
CCI-004530
Designate an organization-defined official to manage the development and documentation of the personally identifiable information processing and transparency policy.
CCI-004531
Designate an organization-defined official to manage the development and documentation of the personally identifiable information processing and transparency procedures.
CCI-004532
Defines the official designated to manage the development, documentation, and dissemination of the personally identifiable information processing and transparency policy and procedures.
CCI-004533
Review and update the current personally identifiable information processing and transparency policy on an organization-defined frequency.
CCI-004534
Review and update the current personally identifiable information processing and transparency policy following organization-defined events.
CCI-004535
Defines the events following reviewing and updating the current personally identifiable processing and transparency policy.
CCI-004536
Review and update the current personally identifiable information processing and transparency procedures on an organization-defined frequency.
CCI-004537
Review and update the current personally identifiable information processing and transparency procedures following organization-defined events.
CCI-004538
Defines the events following reviewing and updating the current personally identifiable processing and transparency procedures.
Linked STIG Checks (0)
No STIG checks reference this control.