Security - Safeguards - Periodic Review, v1.0

Defines privacy requirements for sensitive information controllers to periodically review the safeguards used to protect sensitive information.

Assessment Step

1
Security - Safeguards - Periodic Review (Security-Safeguards-PeriodicReview)
Does the organization require that sensitive information controllers should periodically review the safeguards used to protect sensitive information that they hold?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
Parameter
Information Typesrequired
ENUM_MULTI : Select the type(s) of sensitive information that apply.
  • PII
  • PHI
  • III
  • IIHI
  • Other

Conformance Criteria (1)

C-1
Personal information controllers should periodically review the safeguards used to protect personal information that they hold.
Citation
APEC
Section 22, Security Safeguards