The organisation acquires, develops and manages the system under a defined system development lifecycle that incorporates security and privacy, defines and documents security and privacy roles throughout it, identifies the people in those roles, and integrates the organisational security and privacy risk management process into lifecycle activities. The GC discussion allows testing as a consistent use of personal information under Privacy Act paragraph 8(2)(a) only if individuals were notified at collection and the personal information bank reflects it; otherwise privacy officials must be consulted. 3 enhancements.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.