Privacy Program Plan
LOW MODERATE HIGHRequirements NIST SOURCE
- 1.Includes a description of the structure of the privacy program and the resources dedicated to the privacy program;
- 2.Provides an overview of the requirements for the privacy program and a description of the privacy program management controls and common controls in place or planned for meeting those requirements;
- 3.Includes the role of the senior agency official for privacy and the identification and assignment of roles of other privacy officials and staff and their responsibilities;
- 4.Describes management commitment, compliance, and the strategic goals and objectives of the privacy program;
- 5.Reflects coordination among organizational entities responsible for the different aspects of privacy; and
- 6.Is approved by a senior official with responsibility and accountability for the privacy risk being incurred to organizational operations (including mission, functions, image, and reputation), organizational assets, individuals, other organizations, and the Nation; and
Requirement Context
This element is part of PM-18 — Privacy Program Plan. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Requirement Context
This element is part of PM-18 — Privacy Program Plan. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Discussion (NIST Supplemental Guidance)
A privacy program plan is a formal document that provides an overview of an organization’s privacy program, including a description of the structure of the privacy program, the resources dedicated to the privacy program, the role of the senior agency official for privacy and other privacy officials and staff, the strategic goals and objectives of the privacy program, and the program management controls and common controls in place or planned for meeting applicable privacy requirements and managing privacy risks. Privacy program plans can be represented in single documents or compilations of documents. The senior agency official for privacy is responsible for designating which privacy controls the organization will treat as program management, common, system-specific, and hybrid controls. Privacy program plans provide sufficient information about the privacy program management and common controls (including the specification of parameters and assignment and selection operations explicitly or by reference) to enable control implementations that are unambiguously compliant with the intent of the plans and a determination of the risk incurred if the plans are implemented as intended. Program management controls are generally implemented at the organization level and are essential for managing the organization’s privacy program. Program management controls are distinct from common, system-specific, and hybrid controls because program management controls are independent of any particular information system. Together, the privacy plans for individual systems and the organization-wide privacy program plan provide complete coverage for the privacy controls employed within the organization. Common controls are documented in an appendix to the organization’s privacy program plan unless the controls are included in a separate privacy plan for a system. The organization-wide privacy program plan indicates which separate privacy plans contain descriptions of privacy controls.
Implementation Guidance
Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.
No engineering interpretation has been authored for PM-18 yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.
Assessment
Assessment Objectives
- the frequency of updates to the privacy program plan is defined;
- an organization-wide privacy program plan that provides an overview of the agency�s privacy program is developed;
- the privacy program plan includes a description of the structure of the privacy program;
- the privacy program plan includes a description of the resources dedicated to the privacy program;
- the privacy program plan provides an overview of the requirements for the privacy program;
- the privacy program plan provides a description of the privacy program management controls in place or planned for meeting the requirements of the privacy program;
- the privacy program plan provides a description of common controls in place or planned for meeting the requirements of the privacy program;
- the privacy program plan includes the role of the senior agency official for privacy;
- the privacy program plan includes the identification and assignment of the roles of other privacy officials and staff and their responsibilities;
- the privacy program plan describes management commitment;
- the privacy program plan describes compliance;
- the privacy program plan describes the strategic goals and objectives of the privacy program;
- the privacy program plan reflects coordination among organizational entities responsible for the different aspects of privacy;
- the privacy program plan is approved by a senior official with responsibility and accountability for the privacy risk being incurred by organizational operations (including, mission, functions, image, and reputation), organizational assets, individuals, other organizations, and the Nation;
- the privacy program plan is disseminated;
- the privacy program plan is updated <PM-18_ODP frequency>;
- the privacy program plan is updated to address changes in federal privacy laws and policies;
- the privacy program plan is updated to address organizational changes;
- the privacy program plan is updated to address problems identified during plan implementation or privacy control assessments.
Examine
[SELECT FROM: Privacy program plan; procedures addressing program plan development and implementation; procedures addressing program plan reviews, updates, and approvals; procedures addressing coordination of the program plan with relevant entities; records of program plan reviews, updates, and approvals; other relevant documents or records].
Interview
[SELECT FROM: Organizational personnel with privacy program planning and plan implementation responsibilities; organizational personnel with privacy responsibilities].
Overlays
STIGs & CCIs
No STIG checks or CCI mappings are currently loaded for PM-18. This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.
Learn more about STIG/CCI integration →Evidence
Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.
Policy
- Privacy program plan
- procedures addressing program plan development and implementation
- procedures addressing program plan reviews, updates, and approvals
- procedures addressing coordination of the program plan with relevant entities
- records of program plan reviews, updates, and approvals
Other Records
- other relevant documents or records