Sensitive Information Metadata Use By Cloud Providers Restricted, v1.0

Defines conformance and assessment criteria for verifying that an organization prohibits cloud providers from using metadata derived from senitive information for advertising or any commercial purpose.
If an assessment step references organization-defined elements (E.g. <organization-defined personnel or roles>, <organization-defined frequency>, etc.), corresponding citations/excerpts must be provided to confirm that the organization has established and documented these values and that they apply as referenced in the conformance criteria.

Similarly, if a "Selection" among multiple options (e.g. [Selection (one or more): as needed; ]) is specified, evidence must be provided to establish that the option(s) implemented by the organization have been defined and documented.

The assessment step shall not be marked as satisfied without this evidence.

Assessment Steps (2)

1
Metadata Use By Cloud Providers Prohibited For Advertising and Commercial Purposes (MetadataUseByCloudProvidersProhibitedForAdvertisingandCommercialPurposes)
Does the organization prohibit cloud providers from using metadata derived from senitive information for advertising or any commercial purpose?
Artifacts
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
A2
Provide the type(s) of sensitive information processed by the organization.
2
Metadata Use Enumerated in Service Agreement (MetadataUseEnumeratedinServiceAgreement)
Does the organization require that all acceptable metadata uses (such as transaction logs, spam filtering, etc. be approved by the agency and enumerated within the service agreement with the cloud provider?
Artifacts
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
A2
Provide the type(s) of sensitive information processed by the organization.
If conformance criteria reference organization-defined elements (e.g. <organization-defined personnel or roles>, <organization-defined frequency>, etc.), these values must be defined and documented by the organization.

Similarly, if the criteria specify a "Selection" among multiple options (e.g. [Selection (one or more): as needed; ]), the option(s) implemented by the organization must also be defined and documented.

Conformance Criteria (2)

C1
Metadata derived from unencrypted CJI shall be protected in the same manner as CJI and shall not be used for any advertising or other commercial purposes by any cloud service provider or other associated entity.
Citation
CJIS-SP-V5.7
Section 5.10.1.5.
C2
The agency may permit limited use of metadata derived from unencrypted CJI when specifically approved by the agency and its "intended use" is detailed within the service agreement. Such authorized uses of metadata may include, but are not limited to the following: spam and spyware filtering, data loss prevention, spillage reporting, transaction logs (events and content - similar to Section 5.4), data usage/indexing metrics, and diagnostic/syslog data.