STIGhub
STIGs
RMF Controls
Compare
← All Controls
TR-1
Transparency
Rev 4
Privacy Notice
CCI Identifiers (25)
CCI-003556
The organization provides effective notice to the public regarding its activities that impact privacy, including its collection, use, sharing, safeguarding, maintenance, and disposal of personally identifiable information (PII).
CCI-003557
The organization provides effective notice to individuals regarding its activities that impact privacy, including its collection, use, sharing, safeguarding, maintenance, and disposal of personally identifiable information (PII).
CCI-003558
The organization provides effective notice to the public regarding its authority for collecting personally identifiable information (PII).
CCI-003559
The organization provides effective notice to individuals regarding its authority for collecting personally identifiable information (PII).
CCI-003560
The organization provides effective notice to the public regarding the choices, if any, individuals may have regarding how the organization uses personally identifiable information (PII).
CCI-003561
The organization provides effective notice to individuals regarding the choices, if any, individuals may have regarding how the organization uses personally identifiable information (PII).
CCI-003562
The organization provides effective notice to the public regarding the consequences of exercising or not exercising the choices regarding how the organization uses personally identifiable information (PII).
CCI-003563
The organization provides effective notice to individuals regarding the consequences of exercising or not exercising the choices regarding how the organization uses personally identifiable information (PII).
CCI-003564
The organization provides effective notice to the public regarding the ability of individuals to access personally identifiable information (PII).
CCI-003565
The organization provides effective notice to individuals regarding the ability to access personally identifiable information (PII).
CCI-003566
The organization provides effective notice to the public regarding the ability to have personally identifiable information (PII) amended or corrected if necessary.
CCI-003567
The organization provides effective notice to individuals regarding the ability to have personally identifiable information (PII) amended or corrected if necessary.
CCI-003568
The organization describes the personally identifiable information (PII) the organization collects.
CCI-003569
The organization describes the purpose(s) for which it collects the personally identifiable information (PII).
CCI-003570
The organization describes how the organization uses personally identifiable information (PII) internally.
CCI-003571
The organization describes whether the organization shares personally identifiable information (PII) with external entities.
CCI-003572
The organization describes the categories of those external entities with whom personally identifiable information (PII) is shared.
CCI-003573
The organization describes the purposes for sharing personally identifiable information (PII) with external entities.
CCI-003574
The organization describes whether individuals have the ability to consent to specific uses or sharing of personally identifiable information (PII).
CCI-003575
The organization describes how individuals may exercise their consent regarding specific uses or sharing of personally identifiable information (PII).
CCI-003576
The organization describes how individuals may obtain access to personally identifiable information (PII).
CCI-003577
The organization describes how the personally identifiable information (PII) will be protected.
CCI-003578
The organization revises its public notices to reflect changes in practice or policy that affect personally identifiable information (PII), before or as soon as practicable after the change.
CCI-003579
The organization revises its public notices to reflect changes in practice or policy that impact privacy, before or as soon as practicable after the change.
CCI-003598
The organization defines the individuals or information systems to be the only recipients of organization-defined information, information system components, or devices, by employing organization-defined security safeguards.
deprecated
Linked STIG Checks (0)
No STIG checks reference this control.