CCI-003475
CCI-003475 Definition
Status | |
Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
The organization being inspected/assessed defines and issues PII utility guidelines IAW DoD 5400.11-R. Utility guidelines are tailored as necessary for specific programs or systems. Utility of information covered under the Privacy Act is strictly limited to an authorized purpose and need-to-know. When evaluating options for greater PII utility, consult with the DoD Component's privacy office.
Validation Procedures
The organization conducting the inspection/assessment reviews the PII utility guidelines for the organization being inspected/assessed against documentation for the program or system to ensure utility thresholds are being met and that PII is not shared other than as allowed by policy or notice.
Compelling Evidence
Supply documentation referencing PII utility guidelines, and IAW PII utility guidelines set forth in DoD5400.11-R. Ensure documentation states utility thresholds and outlines procedure(s) to authorize the sharing of PII. If PII collected are specific and held in separate systems or programs, ensure documentation/policy addresses and is specific to each system/program. Supply PII Training certificate