NIST800-PM-21 PM-21 Accounting of Disclosures
NIST800-PM-21 in NIST SP 800-53 Rev 5 (NIST SP 800-53 Rev 5, Release 5.2.0). All NIST SP 800-53 Rev 5 controls held. Open NIST SP 800-53 Rev 5 on the standards site.
The control as we hold it
PM-21 Accounting of Disclosures. a. Develop and maintain an accurate accounting of disclosures of personally identifiable information, including: 1. Date, nature, and purpose of each disclosure; and 2. Name and address, or other contact information of the individual or organization to which the disclosure was made; b. Retain the accounting of disclosures for the length of the time the personally identifiable information is maintained or five years after the disclosure is made, whichever is longer; and c. Make the accounting of disclosures available to the individual to whom the personally identifiable information relates upon request.
Reviewed and closest counterparts in the other frameworks
Reviewed rows come from a released pair; a closest match is the nearest held text and is not a reviewed row.
SOC 2
- SOC2-P2.1 P2.1 Choice and consent (closest match)
- SOC2-P6.1 P6.1 Disclosure to third parties with consent (closest match)
- SOC2-P6.2 P6.2 Record of authorised disclosures (closest match)
- SOC2-P6.3 P6.3 Record of unauthorised disclosures and breaches (closest match)
- SOC2-P6.7 P6.7 Accounting of personal information held and disclosed (closest match)
HIPAA Security Rule
- 164.308(a)(1)(ii)(D) Information System Activity Review (Required) (closest match)
- 164.312(b) Audit Controls (Standard) (closest match)
- 164.316(b)(1) Documentation (Standard) (closest match)
What an auditor commonly asks for
General guidance for this control area (domain: PM - Program Management), in our words, not a statement of the standard and not binding on an assessor.
- the information-security program plan
- the program oversight records