Privacy - Labeled Information - Access Limitations, v1.0

Defines privacy requirements for organizations to assign limitations to identify who is allowed to see and use information based on its label.

Assessment Step

1
Privacy - Labeled Information - Access Limitations (Privacy-LabeledInformation-AccessLimitations)
Has the organization assigned limitations to identify who is allowed to see (access) and use information based on its label (for example, credentialed, role-based levels of access)?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
Parameter
Satisfied By Privacy Policyrequired
BOOLEAN : Is the organization's privacy policy the source for all supporting information for satisfying the issuance criteria of this Trustmark Definition? (TRUE=yes)

Conformance Criteria (1)

C-1
Are limitations assigned to identify who is allowed to see (access) and use information based on its label (for example, credentialed, role-based levels of access)?
Citation
FCPP
Section E.5, Information