Privacy - Security - Identification, v1.0

Defines privacy requirements for organizations to retain the identity of the user in an audit log upon electronic access to the organization's data.

Assessment Step

1
Privacy - Security - Identification (Privacy-Security-Identification)
Is the identity of the user retained in an audit log upon electronic access (portal) to the organization's data?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
Parameter
Satisfied By Privacy Policyrequired
BOOLEAN : Is the organization's privacy policy the source for all supporting information for satisfying the issuance criteria of this Trustmark Definition? (TRUE=yes)

Conformance Criteria (1)

C-1
Does electronic access (portal) to the center's data identify the user? Is the identity of the user retained in the audit log?
Citation
FCPP
Section N.2.1, Accountability and Enforcement