Security - Safeguards Proportional to Sensitivity, v1.0

Defines privacy requirements for sensitive information controllers to protect sensitive information that they hold with appropriate safeguards proportional to the sensitivity of the information.

Assessment Step

1
Security - Safeguards Proportional To Sensitivity (Security-SafeguardsProportionalToSensitivity)
Does the organization require that sensitive information controllers protect sensitive information that they hold with appropriate safeguards proportional to the sensitivity of the information?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
Parameter
Information Typesrequired
ENUM_MULTI : Select the type(s) of sensitive information that apply.
  • PII
  • PHI
  • III
  • IIHI
  • Other

Conformance Criteria (1)

C-1
Personal information controllers should protect personal information that they hold with appropriate safeguards proportional to the sensitivity of the information.
Citation
APEC
Section 22, Security Safeguards