PM-18
Program Management
Privacy Program Plan
Description
a. Develop and disseminate an organization-wide privacy program plan that provides an overview of the agency’s privacy program, and: b. Update the plan [organization-defined parameter] and to address changes in federal privacy laws and policy and organizational changes and problems identified during plan implementation or privacy control assessments.
Mapped SPARTA techniques
No techniques mapped to this control.
Cross-framework references
Relationships published by the source frameworks themselves, reproduced here with attribution. They are not SafeMode Space mappings and carry no confidence rating of ours.
Referenced by 7 in NIST Cybersecurity Framework 2.0
- DE.AE-04The estimated impact and scope of adverse events are understood
- GV.OC-02Internal and external stakeholders are understood, and their needs and expectations regarding cybersecurity risk management are understood and considered
- GV.OV-01Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction
- GV.RM-06A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated
- GV.RM-07Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions
- GV.SC-03Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes
- ID.RA-06Risk responses are chosen, prioritized, planned, tracked, and communicated
Cite as SafeMode Space, nist-80053-rev5 PM-18.