Privacy - Metadata Use for Protected Information, v1.0

Defines privacy requirements for organizations to require that basic descriptive information is entered and associated with each record, data set, or system of records containing sensitive information that will be accessed, used, and disclosed, including terrorism-related information shared through the ISE.

Assessment Step

1
Privacy - Metadata Use For Protected Information (Privacy-MetadataUseForProtectedInformation)
Does the organization require that certain basic descriptive information (metadata tags or labels) is entered and associated with each record, data set, or system of records containing sensitive information that will be accessed, used, and disclosed, including terrorism-related information shared through the ISE. Basic information may include, where relevant and appropriate: The name of the originating organization or party, department, component, subcomponent (where applicable). If applicable, the name of the organization's justice information system from which the information is disseminated. The date the information was collected (submitted) and, where feasible, the date its accuracy was last verified. The title and contact information for the person to whom questions regarding the information, including its accuracy, to be directed?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
Parameters
Information Typesrequired
ENUM_MULTI : Select the type(s) of sensitive information that apply.
  • PII
  • PHI
  • III
  • IIHI
  • Other
Satisfied By Privacy Policyrequired
BOOLEAN : Is the organization's privacy policy the source for all supporting information for satisfying the issuance criteria of this Trustmark Definition? (TRUE=yes)

Conformance Criteria (1)

C-1
Does your center require certain basic descriptive information (metadata tags or labels) to be entered and associated with each record, data set, or system of records containing personally identifiable information that will be accessed, used, and disclosed, including terrorism-related information shared through the ISE? Basic information may include, where relevant and appropriate: The name of the originating center or agency, department, component, subcomponent (where applicable). If applicable, the name of the center's justice information system from which the information is disseminated. The date the information was collected (submitted) and, where feasible, the date its accuracy was last verified. The title and contact information for the person to whom questions regarding the information, including its accuracy, should be directed.
Citation
FCPP
Section E.10, Information