Privacy - Onward Transfer - Access Limitations Identified In Privacy Policy, v1.0

Defines privacy requirements for organizations to document the types of user actions and permissions controlled by the organization's access limitations identified in the organization's privacy policy.

Assessment Step

1
Privacy - Onward Transfer - Access Limitations Identified In Privacy Policy (Privacy-OnwardTransfer-AccessLimitationsIdentifiedInPrivacyPolicy)
Are the organization documented types of user actions and permissions controlled by the organization's access limitations identified in the organization's privacy policy? Note: User actions and permissions are often used to identify agencies and individuals with a need and right to know particular information or intelligence, access case management information, access non-personally identifiable information (PII) only, or to identify who is authorized to submit or modify particular records or record sets, to have read only access or to be authorized to add/modify/delete records, or to be authorized to grant privileges.
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
Parameter
Satisfied By Privacy Policyrequired
BOOLEAN : Is the organization's privacy policy the source for all supporting information for satisfying the issuance criteria of this Trustmark Definition? (TRUE=yes)

Conformance Criteria (1)

C-1
Are the types of user actions and permissions controlled by the center's access limitations identified in the center's privacy policy? Note: User actions and permissions are often used to identify agencies and individuals with a need and right to know particular information or intelligence, access case management information, access non-personally identifiable information (PII) only, or to identify who is authorized to submit or modify particular records or record sets, to have read only access or to be authorized to add/modify/delete records, or to be authorized to grant privileges.
Citation
FCPP
Section J.1, Sharing and Disclosure