Canada ITSP.10.033 Security and Privacy Controls and Assurance Activities Catalogue
PM: Program management – Canada ITSP.10.033 Security and Privacy Controls and Assurance Activities Catalogue

Canada ITSP.10.033 Security and Privacy Controls and Assurance Activities Catalogue PM-25: PM-25 Minimization of personal information used in testing, training, and research

The organisation develops, documents and implements policies and procedures on using personal information for internal testing, training and research, limits the amount used, authorizes its use only when the result cannot be achieved without it, and reviews the policies at a set frequency. Canada-specific addition: disclosure of datasets containing personal information to external contractors is restricted wherever possible. The GC discussion ties such uses to the original purpose or Privacy Act subsection 8(2). No enhancements. Deployed organisation-wide in the medium profile.

Maintained by Gerard Blokdyk

Other controls in PM: Program management – Canada ITSP.10.033 Security and Privacy Controls and Assurance Activities Catalogue

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.