PM-27 Privacy Reporting

Program Management

Privacy New in Rev 5

Description

a. Develop [Assignment: organization-defined privacy reports] and disseminate to: 1. [Assignment: organization-defined oversight bodies] to demonstrate accountability with statutory, regulatory, and policy privacy mandates; and 2. [Assignment: organization-defined officials] and other personnel with responsibility for monitoring privacy program compliance; and b. Review and update privacy reports [Assignment: organization-defined frequency].

Supplemental Guidance

Through internal and external privacy reporting, organizations promote accountability and transparency in organizational privacy operations. Privacy reporting helps organizations to determine progress in meeting privacy compliance and risk mitigation requirements, to compare performance across the federal government, to identify vulnerabilities, and to identify the resources needed to implement privacy programs.

Changes from Rev 4

New control in Rev 5. Privacy program reporting requirements.

Compliance Mappings

ISO 27001:2022

A.5.34

ISO 27002:2022

5.34

PRA Operational Resilience

SS2/21-15.1

BSI IT-Grundschutz

CON.2

BIO2

5.34

RBI CSF

Annex1.24

SEBI CSCRF

CAPACITYRC.CO

ISO 27799

18.2