Canada ITSP.10.033 Security and Privacy Controls and Assurance Activities Catalogue
CA: Assessment, authorization, and monitoring – Canada ITSP.10.033 Security and Privacy Controls and Assurance Activities Catalogue

Canada ITSP.10.033 Security and Privacy Controls and Assurance Activities Catalogue CA-01: CA-01 Assessment, authorization and monitoring policy and procedures

The organisation develops, documents and disseminates to defined personnel or roles a assessment, authorization, and monitoring policy at the selected organisation, business process and, or, system level that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organisational entities and compliance and is consistent with applicable laws, Orders in Council, jurisprudence, directives, regulations, policies, standards and guidelines, together with procedures to implement the policy and the associated assessment, authorization, and monitoring controls; designates an official to manage the policy and procedures; and reviews and updates the policy and the procedures at a set frequency and after defined events. The GC discussion allows reliance on the TBS Standard on Privacy Impact Assessment as the minimum organisational assessment policy, with assessments triggered by decision-making uses, substantial modifications and contracting out. No enhancements.

Maintained by Gerard Blokdyk

Other controls in CA: Assessment, authorization, and monitoring – Canada ITSP.10.033 Security and Privacy Controls and Assurance Activities Catalogue

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.