Citations: NIST PF 1.0
No citations match the current filters.
ID-P
SNow
Reference: PF.001
IDENTIFY-P (ID-P): Develop the organizational understanding to manage privacy risk for individuals arising from data processing.
Authority Document
ID.IM-P
SNow
Reference: PF.002
Inventory and Mapping (ID.IM-P): Data processing by systems, products, or services is understood and informs the management of privacy risk.
Authority Document
ID.IM-P1
SNow
Reference: PF.003
ID.IM-P1: Systems/products/services that process data are inventoried.
Authority Document
Mapped Processes (1)
ID.IM-P2
SNow
Reference: PF.004
ID.IM-P2: Owners or operators (e.g., the organization or third parties such as service providers, partners, customers, and developers) and their roles with respect to the systems/products/services and components (e.g., internal or external) that process data are inventoried.
Authority Document
Mapped Processes (1)
ID.IM-P3
SNow
Reference: PF.005
ID.IM-P3: Categories of individuals (e.g., customers, employees or prospective employees, consumers) whose data are being processed are inventoried.
Authority Document
ID.IM-P4
SNow
Reference: PF.006
ID.IM-P4: Data actions of the systems/products/services are inventoried.
Authority Document
ID.IM-P5
SNow
Reference: PF.007
ID.IM-P5: The purposes for the data actions are inventoried.
Authority Document
ID.IM-P6
SNow
Reference: PF.008
ID.IM-P6: Data elements within the data actions are inventoried.
Authority Document
ID.IM-P7
SNow
Reference: PF.009
ID.IM-P7: The data processing environment is identified (e.g., geographic location, internal, cloud, third parties).
Authority Document
Mapped Processes (1)
ID.IM-P8
SNow
Reference: PF.010
ID.IM-P8: Data processing is mapped, illustrating the data actions and associated data elements for systems/products/services, including components; roles of the component owners/operators; and interactions of individuals or third parties with the systems/products/services.
Authority Document
Mapped Processes (1)
ID.BE-P
SNow
Reference: PF.011
Business Environment (ID.BE-P): The organizations mission, objectives, stakeholders, and activities are understood and prioritized; this information is used to inform privacy roles, responsibilities, and risk management decisions.
Authority Document
ID.BE-P1
SNow
Reference: PF.012
ID.BE-P1: The organizations role(s) in the data processing ecosystem are identified and communicated.
Authority Document
ID.BE-P2
SNow
Reference: PF.013
ID.BE-P2: Priorities for organizational mission, objectives, and activities are established and communicated.
Authority Document
ID.BE-P3
SNow
Reference: PF.014
ID.BE-P3: Systems/products/services that support organizational priorities are identified and key requirements communicated.
Authority Document
Mapped Processes (1)
ID.RA-P
SNow
Reference: PF.015
Risk Assessment (ID.RA-P): The organization understands the privacy risks to individuals and how such privacy risks may create follow-on impacts on organizational operations, including mission, functions, other risk management priorities (e.g., compliance, financial), reputation, workforce, and cult
Authority Document
ID.RA-P1
SNow
Reference: PF.016
ID.RA-P1: Contextual factors related to the systems/products/services and the data actions are identified (e.g., individuals demographics and privacy interests or perceptions, data sensitivity and/or types, visibility of data processing to individuals and third parties).
Authority Document
Mapped Processes (1)
ID.RA-P2
SNow
Reference: PF.017
ID.RA-P2: Data analytic inputs and outputs are identified and evaluated for bias.
Authority Document
Mapped Processes (2)
ID.RA-P3
SNow
Reference: PF.018
ID.RA-P3: Potential problematic data actions and associated problems are identified.
Authority Document
ID.RA-P4
SNow
Reference: PF.019
ID.RA-P4: Problematic data actions, likelihoods, and impacts are used to determine and prioritize risk.
Authority Document
ID.RA-P5
SNow
Reference: PF.020
ID.RA-P5: Risk responses are identified, prioritized, and implemented.
Authority Document
Mapped Processes (2)
ID.DE-P
SNow
Reference: PF.021
Data Processing Ecosystem Risk Management (ID.DE-P): The organizations priorities, constraints, risk tolerance, and assumptions are established and used to support risk decisions associated with managing privacy risk and third parties within the data processing ecosystem. The organization has estab
Authority Document
ID.DE-P1
SNow
Reference: PF.022
ID.DE-P1: Data processing ecosystem risk management policies, processes, and procedures are identified, established, assessed, managed, and agreed to by organizational stakeholders.
Authority Document
Mapped Processes (1)
ID.DE-P2
SNow
Reference: PF.023
ID.DE-P2: Data processing ecosystem parties (e.g., service providers, customers, partners, product manufacturers, application developers) are identified, prioritized, and assessed using a privacy risk assessment process.
Authority Document
Mapped Processes (1)
ID.DE-P3
SNow
Reference: PF.024
ID.DE-P3: Contracts with data processing ecosystem parties are used to implement appropriate measures designed to meet the objectives of an organizations privacy program.
Authority Document
Mapped Processes (1)
ID.DE-P4
SNow
Reference: PF.025
ID.DE-P4: Interoperability frameworks or similar multi-party approaches are used to manage data processing ecosystem privacy risks.
Authority Document
ID.DE-P5
SNow
Reference: PF.026
ID.DE-P5: Data processing ecosystem parties are routinely assessed using audits, test results, or other forms of evaluations to confirm they are meeting their contractual, interoperability framework, or other obligations.
Authority Document
Mapped Processes (1)
GV-P
SNow
Reference: PF.027
GOVERN-P (GV-P): Develop and implement the organizational governance structure to enable an ongoing understanding of the organizations risk management priorities that are informed by privacy risk.
Authority Document
GV.PO-P
SNow
Reference: PF.028
Governance Policies, Processes, and Procedures (GV.PO-P): The policies, processes, and procedures to manage and monitor the organizations regulatory, legal, risk, environmental, and operational requirements are understood and inform the management of privacy risk.
Authority Document
GV.PO-P1
SNow
Reference: PF.029
GV.PO-P1: Organizational privacy values and policies (e.g., conditions on data processing such as data uses or retention periods, individuals prerogatives with respect to data processing) are established and communicated.
Authority Document
SNow Control Objectives (1)
Mapped Processes (1)
GV.PO-P2
SNow
Reference: PF.030
GV.PO-P2: Processes to instill organizational privacy values within system/product/service development and operations are established and in place.
Authority Document
Mapped Processes (1)
GV.PO-P3
SNow
Reference: PF.031
GV.PO-P3: Roles and responsibilities for the workforce are established with respect to privacy.
Authority Document
Mapped Processes (1)
GV.PO-P4
SNow
Reference: PF.032
GV.PO-P4: Privacy roles and responsibilities are coordinated and aligned with third-party stakeholders (e.g., service providers, customers, partners).
Authority Document
Mapped Processes (1)
GV.PO-P5
SNow
Reference: PF.033
GV.PO-P5: Legal, regulatory, and contractual requirements regarding privacy are understood and managed.
Authority Document
Mapped Processes (2)
GV.PO-P6
SNow
Reference: PF.034
GV.PO-P6: Governance and risk management policies, processes, and procedures address privacy risks.
Authority Document
Mapped Processes (1)
GV.RM-P
SNow
Reference: PF.035
Risk Management Strategy (GV.RM-P): The organizations priorities, constraints, risk tolerances, and assumptions are established and used to support operational risk decisions.
Authority Document
GV.RM-P1
SNow
Reference: PF.036
GV.RM-P1: Risk management processes are established, managed, and agreed to by organizational stakeholders.
Authority Document
GV.RM-P2
SNow
Reference: PF.037
GV.RM-P2: Organizational risk tolerance is determined and clearly expressed.
Authority Document
Mapped Processes (1)
GV.RM-P3
SNow
Reference: PF.038
GV.RM-P3: The organizations determination of risk tolerance is informed by its role(s) in the data processing ecosystem.
Authority Document
GV.AT-P
SNow
Reference: PF.039
Awareness and Training (GV.AT-P): The organizations workforce and third parties engaged in data processing are provided privacy awareness education and are trained to perform their privacy-related duties and responsibilities consistent with related policies, processes, procedures, and agreements an
Authority Document
GV.AT-P1
SNow
Reference: PF.040
GV.AT-P1: The workforce is informed and trained on its roles and responsibilities.
Authority Document
Mapped Processes (2)
GV.AT-P2
SNow
Reference: PF.041
GV.AT-P2: Senior executives understand their roles and responsibilities.
Authority Document
Mapped Processes (1)
GV.AT-P3
SNow
Reference: PF.042
GV.AT-P3: Privacy personnel understand their roles and responsibilities.
Authority Document
Mapped Processes (1)
GV.AT-P4
SNow
Reference: PF.043
GV.AT-P4: Third parties (e.g., service providers, customers, partners) understand their roles and responsibilities.
Authority Document
Mapped Processes (2)
GV.MT-P
SNow
Reference: PF.044
Monitoring and Review (GV.MT-P): The policies, processes, and procedures for ongoing review of the organizations privacy posture are understood and inform the management of privacy risk.
Authority Document
GV.MT-P1
SNow
Reference: PF.045
GV.MT-P1: Privacy risk is re-evaluated on an ongoing basis and as key factors, including the organizations business environment (e.g., introduction of new technologies), governance (e.g., legal obligations, risk tolerance), data processing, and systems/products/services change.
Authority Document
Mapped Processes (2)
GV.MT-P2
SNow
Reference: PF.046
GV.MT-P2: Privacy values, policies, and training are reviewed and any updates are communicated.
Authority Document
GV.MT-P3
SNow
Reference: PF.047
GV.MT-P3: Policies, processes, and procedures for assessing compliance with legal requirements and privacy policies are established and in place.
Authority Document
Mapped Processes (2)
GV.MT-P4
SNow
Reference: PF.048
GV.MT-P4: Policies, processes, and procedures for communicating progress on managing privacy risks are established and in place.
Authority Document
Mapped Processes (1)
GV.MT-P5
SNow
Reference: PF.049
GV.MT-P5: Policies, processes, and procedures are established and in place to receive, analyze, and respond to problematic data actions disclosed to the organization from internal and external sources (e.g., internal discovery, privacy researchers, professional events).
Authority Document
Mapped Processes (2)
GV.MT-P6
SNow
Reference: PF.050
GV.MT-P6: Policies, processes, and procedures incorporate lessons learned from problematic data actions.
Authority Document
Mapped Processes (2)
GV.MT-P7
SNow
Reference: PF.051
GV.MT-P7: Policies, processes, and procedures for receiving, tracking, and responding to complaints, concerns, and questions from individuals about organizational privacy practices are established and in place.
Authority Document
Mapped Processes (1)
CT-P
SNow
Reference: PF.052
CONTROL-P (CT-P): Develop and implement appropriate activities to enable organizations or individuals to manage data with sufficient granularity to manage privacy risks.
Authority Document
CT.PO-P
SNow
Reference: PF.053
Data Processing Policies, Processes, and Procedures (CT.PO-P): Policies, processes, and procedures are maintained and used to manage data processing (e.g., purpose, scope, roles and responsibilities in the data processing ecosystem, and management commitment) consistent with the organizations risk
Authority Document
CT.PO-P1
SNow
Reference: PF.054
CT.PO-P1: Policies, processes, and procedures for authorizing data processing (e.g., organizational decisions, individual consent), revoking authorizations, and maintaining authorizations are established and in place.
Authority Document
CT.PO-P2
SNow
Reference: PF.055
CT.PO-P2: Policies, processes, and procedures for enabling data review, transfer, sharing or disclosure, alteration, and deletion are established and in place (e.g., to maintain data quality, manage data retention).
Authority Document
Mapped Processes (1)
CT.PO-P3
SNow
Reference: PF.056
CT.PO-P3: Policies, processes, and procedures for enabling individuals data processing preferences and requests are established and in place.
Authority Document
CT.PO-P4
SNow
Reference: PF.057
CT.PO-P4: A data life cycle to manage data is aligned and implemented with the system development life cycle to manage systems.
Authority Document
Mapped Processes (2)
CT.DM-P
SNow
Reference: PF.058
Data Processing Management (CT.DM-P): Data are managed consistent with the organizations risk strategy to protect individuals privacy, increase manageability, and enable the implementation of privacy principles (e.g., individual participation, data quality, data minimization).
Authority Document
CT.DM-P1
SNow
Reference: PF.059
CT.DM-P1: Data elements can be accessed for review.
Authority Document
CT.DM-P2
SNow
Reference: PF.060
CT.DM-P2: Data elements can be accessed for transmission or disclosure.
Authority Document
CT.DM-P3
SNow
Reference: PF.061
CT.DM-P3: Data elements can be accessed for alteration.
Authority Document
CT.DM-P4
SNow
Reference: PF.062
CT.DM-P4: Data elements can be accessed for deletion.
Authority Document
CT.DM-P5
SNow
Reference: PF.063
CT.DM-P5: Data are destroyed according to policy.
Authority Document
Mapped Processes (2)
CT.DM-P6
SNow
Reference: PF.064
CT.DM-P6: Data are transmitted using standardized formats.
Authority Document
CT.DM-P7
SNow
Reference: PF.065
CT.DM-P7: Mechanisms for transmitting processing permissions and related data values with data elements are established and in place.
Authority Document
CT.DM-P8
SNow
Reference: PF.066
CT.DM-P8: Audit/log records are determined, documented, implemented, and reviewed in accordance with policy and incorporating the principle of data minimization.
Authority Document
Mapped Processes (2)
CT.DM-P9
SNow
Reference: PF.067
CT.DM-P9: Technical measures implemented to manage data processing are tested and assessed.
Authority Document
Mapped Processes (1)
CT.DP-P
SNow
Reference: PF.069
Disassociated Processing (CT.DP-P): Data processing solutions increase disassociability consistent with the organizations risk strategy to protect individuals privacy and enable implementation of privacy principles (e.g., data minimization).
Authority Document
CT.DP-P1
SNow
Reference: PF.070
CT.DP-P1: Data are processed to limit observability and linkability (e.g., data actions take place on local devices, privacy-preserving cryptography).
Authority Document
CT.DP-P2
SNow
Reference: PF.071
CT.DP-P2: Data are processed to limit the identification of individuals (e.g., de-identification privacy techniques, tokenization).
Authority Document
CT.DP-P3
SNow
Reference: PF.072
CT.DP-P3: Data are processed to limit the formulation of inferences about individuals behavior or activities (e.g., data processing is decentralized, distributed architectures).
Authority Document
CT.DP-P4
SNow
Reference: PF.073
CT.DP-P4: System or device configurations permit selective collection or disclosure of data elements.
Authority Document
CT.DP-P5
SNow
Reference: PF.074
CT.DP-P5: Attribute references are substituted for attribute values.
Authority Document
CM-P
SNow
Reference: PF.075
COMMUNICATE-P (CM-P): Develop and implement appropriate activities to enable organizations and individuals to have a reliable understanding and engage in a dialogue about how data are processed and associated privacy risks.
Authority Document
CM.PO-P
SNow
Reference: PF.076
Communication Policies, Processes, and Procedures (CM.PO-P): Policies, processes, and procedures are maintained and used to increase transparency of the organizations data processing practices (e.g., purpose, scope, roles and responsibilities in the data processing ecosystem, and management commitm
Authority Document
CM.PO-P1
SNow
Reference: PF.077
CM.PO-P1: Transparency policies, processes, and procedures for communicating data processing purposes, practices, and associated privacy risks are established and in place.
Authority Document
CM.PO-P2
SNow
Reference: PF.078
CM.PO-P2: Roles and responsibilities (e.g., public relations) for communicating data processing purposes, practices, and associated privacy risks are established.
Authority Document
CM.AW-P
SNow
Reference: PF.079
Data Processing Awareness (CM.AW-P): Individuals and organizations have reliable knowledge about data processing practices and associated privacy risks, and effective mechanisms are used and maintained to increase predictability consistent with the organizations risk strategy to protect individuals
Authority Document
CM.AW-P1
SNow
Reference: PF.080
CM.AW-P1: Mechanisms (e.g., notices, internal or public reports) for communicating data processing purposes, practices, associated privacy risks, and options for enabling individuals data processing preferences and requests are established and in place.
Authority Document
CM.AW-P2
SNow
Reference: PF.081
CM.AW-P2: Mechanisms for obtaining feedback from individuals (e.g., surveys or focus groups) about data processing and associated privacy risks are established and in place.
Authority Document
Mapped Processes (1)
CM.AW-P3
SNow
Reference: PF.082
CM.AW-P3: System/product/service design enables data processing visibility.
Authority Document
CM.AW-P4
SNow
Reference: PF.083
CM.AW-P4: Records of data disclosures and sharing are maintained and can be accessed for review or transmission/disclosure.
Authority Document
CM.AW-P5
SNow
Reference: PF.084
CM.AW-P5: Data corrections or deletions can be communicated to individuals or organizations (e.g., data sources) in the data processing ecosystem.
Authority Document
CM.AW-P6
SNow
Reference: PF.085
CM.AW-P6: Data provenance and lineage are maintained and can be accessed for review or transmission/disclosure.
Authority Document
Mapped Processes (1)
CM.AW-P7
SNow
Reference: PF.086
CM.AW-P7: Impacted individuals and organizations are notified about a privacy breach or event.
Authority Document
Mapped Processes (1)
CM.AW-P8
SNow
Reference: PF.087
CM.AW-P8: Individuals are provided with mitigation mechanisms (e.g., credit monitoring, consent withdrawal, data alteration or deletion) to address impacts of problematic data actions.
Authority Document
Mapped Processes (2)
PR-P
SNow
Reference: PF.088
PROTECT-P (PR-P): Develop and implement appropriate data processing safeguards.
Authority Document
PR.PO-P
SNow
Reference: PF.089
Data Protection Policies, Processes, and Procedures (PR.PO-P): Security and privacy policies (e.g., purpose, scope, roles and responsibilities in the data processing ecosystem, and management commitment), processes, and procedures are maintained and used to manage the protection of data.
Authority Document
PR.PO-P1
SNow
Reference: PF.090
PR.PO-P1: A baseline configuration of information technology is created and maintained incorporating security principles (e.g., concept of least functionality).
Authority Document
PR.PO-P2
SNow
Reference: PF.091
PR.PO-P2: Configuration change control processes are established and in place.
Authority Document
PR.PO-P3
SNow
Reference: PF.092
PR.PO-P3: Backups of information are conducted, maintained, and tested.
Authority Document
Mapped Processes (1)
PR.PO-P4
SNow
Reference: PF.093
PR.PO-P4: Policy and regulations regarding the physical operating environment for organizational assets are met.
Authority Document
PR.PO-P5
SNow
Reference: PF.094
PR.PO-P5: Protection processes are improved.
Authority Document
PR.PO-P6
SNow
Reference: PF.095
PR.PO-P6: Effectiveness of protection technologies is shared.
Authority Document
Mapped Processes (2)
PR.PO-P7
SNow
Reference: PF.096
PR.PO-P7: Response plans (Incident Response and Business Continuity) and recovery plans (Incident Recovery and Disaster Recovery) are established, in place, and managed.
Authority Document
PR.PO-P8
SNow
Reference: PF.097
PR.PO-P8: Response and recovery plans are tested.
Authority Document
Mapped Processes (2)
PR.PO-P9
SNow
Reference: PF.098
PR.PO-P9: Privacy procedures are included in human resources practices (e.g., deprovisioning, personnel screening).
Authority Document
PR.AC-P
SNow
Reference: PF.100
Identity Management, Authentication, and Access Control (PR.AC-P): Access to data and devices is limited to authorized individuals, processes, and devices, and is managed consistent with the assessed risk of unauthorized access.
Authority Document
PR.AC-P1
SNow
Reference: PF.101
PR.AC-P1: Identities and credentials are issued, managed, verified, revoked, and audited for authorized individuals, processes, and devices.
Authority Document
PR.AC-P2
SNow
Reference: PF.102
PR.AC-P2: Physical access to data and devices is managed.
Authority Document
PR.AC-P3
SNow
Reference: PF.103
PR.AC-P3: Remote access is managed.
Authority Document
PR.AC-P4
SNow
Reference: PF.104
PR.AC-P4: Access permissions and authorizations are managed, incorporating the principles of least privilege and separation of duties.
Authority Document
PR.AC-P5
SNow
Reference: PF.105
PR.AC-P5: Network integrity is protected (e.g., network segregation, network segmentation).
Authority Document
Mapped Processes (1)
PR.AC-P6
SNow
Reference: PF.106
PR.AC-P6: Individuals and devices are proofed and bound to credentials, and authenticated commensurate with the risk of the transaction (e.g., individuals security and privacy risks and other organizational risks).
Authority Document
Mapped Processes (2)
PR.DS-P
SNow
Reference: PF.107
Data Security (PR.DS-P): Data are managed consistent with the organizations risk strategy to protect individuals privacy and maintain data confidentiality, integrity, and availability.
Authority Document
PR.DS-P1
SNow
Reference: PF.108
PR.DS-P1: Data-at-rest are protected.
Authority Document
Mapped Processes (3)
PR.DS-P2
SNow
Reference: PF.109
PR.DS-P2: Data-in-transit are protected.
Authority Document
PR.DS-P3
SNow
Reference: PF.110
PR.DS-P3: Systems/products/services and associated data are formally managed throughout removal, transfers, and disposition.
Authority Document
PR.DS-P4
SNow
Reference: PF.111
PR.DS-P4: Adequate capacity to ensure availability is maintained.
Authority Document
Mapped Processes (2)
PR.DS-P5
SNow
Reference: PF.112
PR.DS-P5: Protections against data leaks are implemented.
Authority Document
PR.DS-P6
SNow
Reference: PF.113
PR.DS-P6: Integrity checking mechanisms are used to verify software, firmware, and information integrity.
Authority Document
PR.DS-P7
SNow
Reference: PF.114
PR.DS-P7: The development and testing environment(s) are separate from the production environment.
Authority Document
PR.DS-P8
SNow
Reference: PF.115
PR.DS-P8: Integrity checking mechanisms are used to verify hardware integrity.
Authority Document
PR.MA-P
SNow
Reference: PF.116
Maintenance (PR.MA-P): System maintenance and repairs are performed consistent with policies, processes, and procedures.
Authority Document
PR.MA-P1
SNow
Reference: PF.117
PR.MA-P1: Maintenance and repair of organizational assets are performed and logged, with approved and controlled tools.
Authority Document
Mapped Processes (2)
PR.MA-P2
SNow
Reference: PF.118
PR.MA-P2: Remote maintenance of organizational assets is approved, logged, and performed in a manner that prevents unauthorized access.
Authority Document
Mapped Processes (2)
PR.PT-P
SNow
Reference: PF.119
Protective Technology (PR.PT-P): Technical security solutions are managed to ensure the security and resilience of systems/products/services and associated data, consistent with related policies, processes, procedures, and agreements.
Authority Document
PR.PT-P1
SNow
Reference: PF.120
PR.PT-P1: Removable media is protected and its use restricted according to policy.
Authority Document
PR.PT-P2
SNow
Reference: PF.121
PR.PT-P2: The principle of least functionality is incorporated by configuring systems to provide only essential capabilities.
Authority Document
PR.PT-P3
SNow
Reference: PF.122
PR.PT-P3: Communications and control networks are protected.
Authority Document
Mapped Processes (1)
PR.PT-P4
SNow
Reference: PF.123
PR.PT-P4: Mechanisms (e.g., failsafe, load balancing, hot swap) are implemented to achieve resilience requirements in normal and adverse situations.
Authority Document