Canada ITSP.10.033 Security and Privacy Controls and Assurance Activities Catalogue
RA: Risk assessment – Canada ITSP.10.033 Security and Privacy Controls and Assurance Activities Catalogue

Canada ITSP.10.033 Security and Privacy Controls and Assurance Activities Catalogue RA-08: RA-08 Privacy impact assessments

The organisation conducts privacy impact assessments when designing, developing or procuring means of handling personal information and when starting a new collection. Canada-specific addition: also when substantially modifying existing systems, programs or activities that handle personal information. The GC discussion requires following the TBS Directive on Privacy Practices, a privacy checklist first, approval by the program executive and the section 10 official, transmission to TBS and the Privacy Commissioner, a mitigation plan for gaps, and sharing with partners for multi-institution assessments. No enhancements.

Maintained by Gerard Blokdyk

Other controls in RA: Risk assessment – Canada ITSP.10.033 Security and Privacy Controls and Assurance Activities Catalogue

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.