ID.IM-P6: Data elements within the data actions are inventoried
Description
[csf.tools Note: Subcategories do not have detailed descriptions.]
Related Controls
NIST Special Publication 800-53 Revision 5.2.0
CM-13: Data Action Mapping
Develop and document a map of system data actions.
PT-7: Specific Categories of Personally Identifiable Information
Apply [Assignment: organization-defined processing conditions] for specific categories of personally identifiable information.
Cloud Controls Matrix v4.0
CCC-04: Unauthorized Change Protection
Restrict the unauthorized addition, removal, update, and management of organization assets.
DSP-03: Data Inventory
Create and maintain a data inventory, at least for any sensitive data and personal data.
DSP-04: Data Classification
Classify data according to its type and sensitivity level.
DSP-11: Personal Data Access, Reversal, Rectification and Deletion
Define and implement, processes, procedures and technical measures to enable data subjects to request access to, modification, or deletion of their personal data, according to any applicable laws and regulations.
IPY-01: Interoperability and Portability Policy and Procedures
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for interoperability and portability including requirements for: Communications between application interfaces Information processing interoperability Application development portability Information/Data exchange, usage, portability, integrity, and persistence Review and update the policies and procedures at least annually.