Privacy - Access Control - External Access, v1.0

Defines privacy requirements for organizations to document the conditions and credentials by which access to and disclosure of records they retain will be provided within the center or in other organizations, and document the level of audit trail kept of access to and disclosure of information they retain.

Assessment Step

1
Privacy - Access Control - External Access (Privacy-AccessControl-ExternalAccess)
Has the organization documented the conditions and credentials by which access to and disclosure of records it retains will be provided within the center or in other organizations, and documented the level of audit trail kept of access to and disclosure of information it retains(e.g. dissemination logs, algorithms)?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
Parameter
Satisfied By Privacy Policyrequired
BOOLEAN : Is the organization's privacy policy the source for all supporting information for satisfying the issuance criteria of this Trustmark Definition? (TRUE=yes)

Conformance Criteria (1)

C-1
Describe the conditions and credentials by which access to and disclosure of records retained by the center will be provided within the center or in other governmental agencies. Is an audit trail kept of access to and disclosure of information retained by the center (e.g., dissemination logs, algorithms)? Refer to N.2, Accountability, for more information on audit logs.
Citation
FCPP
Section J.3, Sharing and Disclosure