CCI-003445
CCI-003445 Definition
Status | |
Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
If the organization being inspected/assessed identifies IAW AR-5, CCI 3440 that IASE provided PII training meets the needs of the organization then the organization is automatically compliant. Otherwise, the organization being inspected/assessed documents and implements a process to update the comprehensive training and awareness strategy.
Validation Procedures
The organization conducting the inspection/assessment obtains and examines the documented results of the review conducted IAW AR-5, CCI 3440. If the review indicates that IASE provided PII training meets the needs of the organization then the organization is automatically compliant. Otherwise, the organization conducting the inspection/assessment obtains and examines the documented update process for the training and awareness strategy to ensure that the organization being inspected/assessed updates the strategy.
Compelling Evidence
Reference section of documentation that pertains to IASE PII training. Observe that If extra training is required the organization needs to define and document the unique privacy needs which must be addressed by training.