Privacy - Enforcement - Enforcement Procedures For Authorized Users, v1.0

Defines privacy requirements for organizations to have documented procedures for addressing authorized users' noncompliance with its privacy policy.

Assessment Step

1
Privacy - Enforcement - Enforcement Procedures For Authorized Users (Privacy-Enforcement-EnforcementProceduresForAuthorizedUsers)
Does the organization have documented procedures for enforcement if an authorized user is suspected of being or has been found to be in noncompliance with the provisions of the organization's privacy policy?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
Parameter
Satisfied By Privacy Policyrequired
BOOLEAN : Is the organization's privacy policy the source for all supporting information for satisfying the issuance criteria of this Trustmark Definition? (TRUE=yes)

Conformance Criteria (1)

C-1
What are your procedures for enforcement if an authorized user is suspected of being or has been found to be in noncompliance with the provisions of the center's privacy policy?
Citation
FCPP
Section N.3.1, Accountability and Enforcement