PM-05(01) Inventory of Personally Identifiable Information
Establish, maintain, and update pm-05.01_odp an inventory of all systems, applications, and projects that process personally identifiable information.
Parameter ID | Definition |
---|---|
pm-05.01_odp | frequency |
Baselines
- L
- M
- H
- P
Guidance
An inventory of systems, applications, and projects that process personally identifiable information supports the mapping of data actions, providing individuals with privacy notices, maintaining accurate personally identifiable information, and limiting the processing of personally identifiable information when such information is not needed for operational purposes. Organizations may use this inventory to ensure that systems only process the personally identifiable information for authorized purposes and that this processing is still relevant and necessary for the purpose specified therein.
Related controls 10
- AC-03 Access Enforcement L M H P
- CM-08 System Component Inventory L M H P
- CM-12 Information Location L M H P
- CM-13 Data Action Mapping L M H P
- PL-08 Security and Privacy Architectures L M H P
- PM-22 Personally Identifiable Information Quality Management L M H P
- PT-03 Personally Identifiable Information Processing Purposes L M H P
- PT-05 Privacy Notice L M H P
- SI-12 Information Management and Retention L M H P
- SI-18 Personally Identifiable Information Quality Operations L M H P