ID.IM-P5: The purposes for the data actions are inventoried
Description
[csf.tools Note: Subcategories do not have detailed descriptions.]
Related Controls
NIST Special Publication 800-53 Revision 5.2.0
CM-13: Data Action Mapping
Develop and document a map of system data actions.
PT-1: Policy and Procedures
Develop, document, and disseminate to [Assignment: organization-defined personnel or roles]: [Assignment (one or more): organization-level, mission/business process-level, system-level] personally identifiable information processing and transparency policy that: Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and Is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines; and Procedures…
PT-2: Authority to Process Personally Identifiable Information
Determine and document the [Assignment: organization-defined authority] that permits the [Assignment: organization-defined processing] of personally identifiable information; and Restrict the [Assignment: organization-defined processing] of personally identifiable information to only that which is authorized.
PT-3: Personally Identifiable Information Processing Purposes
Identify and document the [Assignment: organization-defined purpose(s)] for processing personally identifiable information; Describe the purpose(s) in the public privacy notices and policies of the organization; Restrict the [Assignment: organization-defined processing] of personally identifiable information to only that which is compatible with the identified purpose(s); and Monitor changes in processing personally identifiable information and implement [Assignment:…
Cloud Controls Matrix v4.0
DSP-04: Data Classification
Classify data according to its type and sensitivity level.
DSP-12: Limitation of Purpose in Personal Data Processing
Define, implement and evaluate processes, procedures and technical measures to ensure that personal data is processed according to any applicable laws and regulations and for the purposes declared to the data subject.
IPY-01: Interoperability and Portability Policy and Procedures
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for interoperability and portability including requirements for: Communications between application interfaces Information processing interoperability Application development portability Information/Data exchange, usage, portability, integrity, and persistence Review and update the policies and procedures at least annually.
STA-02: SSRM Supply Chain
Apply, document, implement and manage the SSRM throughout the supply chain for the cloud service offering.