CCI-003522
CCI-003522 Definition
Status | |
Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
The organization being inspected/assessed documents and implements a procedure for individuals to authorize the sharing of personally identifiable information (PII) prior to its collection. Minimally, where individual authorization is not feasible or appropriate, the organization will notify users that PII is being shared.
Validation Procedures
The organization conducting the inspection/assessment obtains and examines the documented procedure as well as a sampling of artifacts related to the authorization of the sharing of PII to ensure the organization being inspected/assessed provides means, where feasible and appropriate, for individuals to authorize the sharing of PII prior to its collection. Where authorization is not feasible or appropriate, the organization conducting the inspection/assessment ensures that the organization notifies users that PII is being shared.
Compelling Evidence
Supply documentation and reference the procedure for individuals to authorize the sharing of PII prior to its collection.