Privacy - Protected Information Identified, v1.0

Defines privacy requirements for organizations to identify their data holdings that contain protected information to be shared through the ISE, and put in place notice mechanisms to enable authorized ISE users to determine the nature of the protected information that the organization is making available in the ISE.

Assessment Step

1
Privacy - Protected Information Identified (Privacy-ProtectedInformationIdentified)
Does the organization require that for purposes of sharing terrorism-related information through the ISE, has your organization identified its data holdings that contain protected information (information about U.S. citizens or lawful permanent residents [constitutional minimum] or all individuals) to be shared through the ISE. [ISE information refers to terrorism related information, which includes terrorism information, homeland security information, and law enforcement information related to terrorism]. Further, has your organization put in place notice mechanisms, such as metadata or data field labels, for enabling ISE authorized users to determine the nature of the protected information that the organization is making available in the ISE, such that participants can handle the information in accordance with applicable legal requirements?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
Parameter
Satisfied By Privacy Policyrequired
BOOLEAN : Is the organization's privacy policy the source for all supporting information for satisfying the issuance criteria of this Trustmark Definition? (TRUE=yes)

Conformance Criteria (1)

C-1
For purposes of sharing terrorism-related information through the ISE, has your center identified its data holdings that contain protected information (information about U.S. citizens or lawful permanent residents [constitutional minimum] or all individuals) to be shared through the ISE? [ISE information refers to terrorism related information, which includes terrorism information, homeland security information, and law enforcement information related to terrorism.] Further, has your center put in place notice mechanisms, such as metadata or data field labels, for enabling ISE authorized users to determine the nature of the protected information that the center is making available in the ISE, such that participants can handle the information in accordance with applicable legal requirements?
Citation
FCPP
Section E.9, Information