Privacy - Access Control - Internal Access, v1.0

Defines privacy requirements for organizations to document the conditions and credentials by which access to and disclosure of records they retain will be provided within the organization.

Assessment Step

1
Privacy - Access Control - Internal Access (Privacy-AccessControl-InternalAccess)
Has the organization documented the conditions and credentials by which access to and disclosure of records it retains will be provided within the organization?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
Parameter
Satisfied By Privacy Policyrequired
BOOLEAN : Is the organization's privacy policy the source for all supporting information for satisfying the issuance criteria of this Trustmark Definition? (TRUE=yes)

Conformance Criteria (1)

C-1
Describe the conditions and credentials by which access to and disclosure of records retained by the center will be provided within the center?
Citation
FCPP
Section J.3, Sharing and Disclosure