From 336487f3329c16a3acf5c5ef0d10ac7e88e81740 Mon Sep 17 00:00:00 2001 From: gearnode Date: Wed, 9 Apr 2025 21:19:53 -0700 Subject: [PATCH] Update frameworks Signed-off-by: gearnode --- .../public/data/frameworks/ISO27001-2022.json | 69 +-- apps/console/public/data/frameworks/SOC2.json | 2 +- data/frameworks/ISO27001-2022.json | 494 ------------------ data/frameworks/SOC2.json | 249 --------- 4 files changed, 37 insertions(+), 777 deletions(-) delete mode 100644 data/frameworks/ISO27001-2022.json delete mode 100644 data/frameworks/SOC2.json diff --git a/apps/console/public/data/frameworks/ISO27001-2022.json b/apps/console/public/data/frameworks/ISO27001-2022.json index b81d1159f..03eb3da2b 100644 --- a/apps/console/public/data/frameworks/ISO27001-2022.json +++ b/apps/console/public/data/frameworks/ISO27001-2022.json @@ -1,123 +1,125 @@ { - "name": "ISO 27001 (2022)", "id": "ISO/IEC 27001:2022", + "name": "ISO 27001 (2022)", "controls": [ { - "id": "C.4.1", + "id": "4.1", "name": "Context of the organization - Understanding the organization and its context" }, { - "id": "C.4.2", + "id": "4.2", "name": "Context of the organization - Understanding the needs of interested parties" }, { - "id": "C.4.3", + "id": "4.3", "name": "Context of the organization - Determining the scope of the information security management system" }, { - "id": "C.4.4", + "id": "4.4", "name": "Context of the organization - Information security management system" }, { - "id": "C.5.1", + "id": "5.1", "name": "Leadership - Leadership and commitment" }, { - "id": "C.5.2", + "id": "5.2", "name": "Leadership - Policy" }, { - "id": "C.5.3", + "id": "5.3", "name": "Leadership - Organizational roles, responsibilities and authorities" }, { - "id": "C.6.1.1", + "id": "6.1.1", "name": "Planning - General actions to address risks and opportunities" }, { - "id": "C.6.1.2", + "id": "6.1.2", "name": "Planning - Information security risk assessment" }, { - "id": "C.6.1.3", + "id": "6.1.3", "name": "Planning - Information security risk treatment" }, { - "id": "C.6.2", + "id": "6.2", "name": "Planning - Information security objective and planning to achieve them" }, { - "id": "C.6.3", + "id": "6.3", "name": "Planning - Planning of Changes" }, { - "id": "C.7.1", + "id": "7.1", "name": "Support - Resources" }, { - "id": "C.7.2", + "id": "7.2", "name": "Support - Competence" }, { - "id": "C.7.3", + "id": "7.3", "name": "Support - Awareness" }, { - "id": "C.7.4", + "id": "7.4", "name": "Support - Communication" }, { - "id": "C.7.5.1", + "id": "7.5.1", "name": "Support - Documented information" }, { - "id": "C.7.5.2", - "name": "Support - Creating and Updating", - "id": "C.7.5.3", + "id": "7.5.2", + "name": "Support - Creating and Updating" + }, + { + "id": "7.5.3", "name": "Support - Control of documented information" }, { - "id": "C.8.1", + "id": "8.1", "name": "Operation - Operation planning and control" }, { - "id": "C.8.2", + "id": "8.2", "name": "Operation - Information security risk assessment" }, { - "id": "C.8.3", + "id": "8.3", "name": "Operation - Information security risk treatment" }, { - "id": "C.9.1", + "id": "9.1", "name": "Performance evaluation - Monitoring, measurement, analysis, and evaluation" }, { - "id": "C.9.2.1", + "id": "9.2.1", "name": "Performance evaluation - Internal Audit - General" }, { - "id": "C.9.2.2", + "id": "9.2.2", "name": "Performance evaluation - Internal Audit Program" }, { - "id": "C.9.3.1", + "id": "9.3.1", "name": "Performance evaluation - Management review - General" }, { - "id": "C.9.3.2", + "id": "9.3.2", "name": "Performance evaluation - Management review inputs" }, { - "id": "C.9.3.3", + "id": "9.3.3", "name": "Performance evaluation - Management review results" }, { - "id": "C.10.1", + "id": "10.1", "name": "Improvement - Continual Improvement" }, { - "id": "C.10.2", + "id": "10.2", "name": "Improvement - Nonconformity and corrective action" }, { @@ -457,7 +459,8 @@ "name": "Technological - Secure development life cycle" }, { - "id": "A.8.26" + "id": "A.8.26", + "name": "Technological - Application security requirements" }, { "id": "A.8.27", diff --git a/apps/console/public/data/frameworks/SOC2.json b/apps/console/public/data/frameworks/SOC2.json index b990897bc..f2ce9ff6c 100644 --- a/apps/console/public/data/frameworks/SOC2.json +++ b/apps/console/public/data/frameworks/SOC2.json @@ -1,5 +1,5 @@ { - "name": "SOC2", + "name": "SOC 2", "id": "SOC2", "controls": [ { diff --git a/data/frameworks/ISO27001-2022.json b/data/frameworks/ISO27001-2022.json deleted file mode 100644 index 8abde2875..000000000 --- a/data/frameworks/ISO27001-2022.json +++ /dev/null @@ -1,494 +0,0 @@ -{ - "name": "ISO/IEC 27001:2022", - "controls": [ - { - "id": "C.4.1", - "name": "Context of the organization - Understanding the organization and its context" - }, - { - "id": "C.4.2", - "name": "Context of the organization - Understanding the needs of interested parties" - }, - { - "id": "C.4.3", - "name": "Context of the organization - Determining the scope of the information security management system" - }, - { - "id": "C.4.4", - "name": "Context of the organization - Information security management system" - }, - { - "id": "C.5.1", - "name": "Leadership - Leadership and commitment" - }, - { - "id": "C.5.2", - "name": "Leadership - Policy" - }, - { - "id": "C.5.3", - "name": "Leadership - Organizational roles, responsibilities and authorities" - }, - { - "id": "C.6.1.1", - "name": "Planning - General actions to address risks and opportunities" - }, - { - "id": "C.6.1.2", - "name": "Planning - Information security risk assessment" - }, - { - "id": "C.6.1.3", - "name": "Planning - Information security risk treatment" - }, - { - "id": "C.6.2", - "name": "Planning - Information security objective and planning to achieve them" - }, - { - "id": "C.6.3", - "name": "Planning - Planning of Changes" - }, - { - "id": "C.7.1", - "name": "Support - Resources" - }, - { - "id": "C.7.2", - "name": "Support - Competence" - }, - { - "id": "C.7.3", - "name": "Support - Awareness" - }, - { - "id": "C.7.4", - "name": "Support - Communication" - }, - { - "id": "C.7.5.1", - "name": "Support - Documented information" - }, - { - "id": "C.7.5.2", - "name": "Support - Creating and Updating", - "id": "C.7.5.3", - "name": "Support - Control of documented information" - }, - { - "id": "C.8.1", - "name": "Operation - Operation planning and control" - }, - { - "id": "C.8.2", - "name": "Operation - Information security risk assessment" - }, - { - "id": "C.8.3", - "name": "Operation - Information security risk treatment" - }, - { - "id": "C.9.1", - "name": "Performance evaluation - Monitoring, measurement, analysis, and evaluation" - }, - { - "id": "C.9.2.1", - "name": "Performance evaluation - Internal Audit - General" - }, - { - "id": "C.9.2.2", - "name": "Performance evaluation - Internal Audit Program" - }, - { - "id": "C.9.3.1", - "name": "Performance evaluation - Management review - General" - }, - { - "id": "C.9.3.2", - "name": "Performance evaluation - Management review inputs" - }, - { - "id": "C.9.3.3", - "name": "Performance evaluation - Management review results" - }, - { - "id": "C.10.1", - "name": "Improvement - Continual Improvement" - }, - { - "id": "C.10.2", - "name": "Improvement - Nonconformity and corrective action" - }, - { - "id": "A.5.1", - "name": "Organizational - Policies for information security" - }, - { - "id": "A.5.2", - "name": "Organizational - Information security roles and responsibilities" - }, - { - "id": "A.5.3", - "name": "Organizational - Segregation of duties" - }, - { - "id": "A.5.4", - "name": "Organizational - Management responsibilities" - }, - { - "id": "A.5.5", - "name": "Organizational - Contact with authorities" - }, - { - "id": "A.5.6", - "name": "Organizational - Contact with special interest groups" - }, - { - "id": "A.5.7", - "name": "Organizational - Threat Intelligence" - }, - { - "id": "A.5.8", - "name": "Organizational - Information security in project management" - }, - { - "id": "A.5.9", - "name": "Organizational - Inventory of information and other associated assets" - }, - { - "id": "A.5.10", - "name": "Organizational - Acceptable use of information and other associated assets" - }, - { - "id": "A.5.11", - "name": "Organizational - Return of assets" - }, - { - "id": "A.5.12", - "name": "Organizational - Classification of information" - }, - { - "id": "A.5.13", - "name": "Organizational - Labelling of information" - }, - { - "id": "A.5.14", - "name": "Organizational - Information transfer" - }, - { - "id": "A.5.15", - "name": "Organizational - Access control" - }, - { - "id": "A.5.16", - "name": "Organizational - Identity management" - }, - { - "id": "A.5.17", - "name": "Organizational - Authentication information" - }, - { - "id": "A.5.18", - "name": "Organizational - Access rights" - }, - { - "id": "A.5.19", - "name": "Organizational - Information security in supplier relationships" - }, - { - "id": "A.5.20", - "name": "Organizational - Addressing information security within supplier agreements" - }, - { - "id": "A.5.21", - "name": "Organizational - Managing information security in the ICT supply chain" - }, - { - "id": "A.5.22", - "name": "Organizational - Monitoring, review and change management of supplier services" - }, - { - "id": "A.5.23", - "name": "Organizational - Information security for use of cloud services" - }, - { - "id": "A.5.24", - "name": "Organizational - Information security incident management planning and preparation" - }, - { - "id": "A.5.25", - "name": "Organizational - Assessment and decision on information security events" - }, - { - "id": "A.5.26", - "name": "Organizational - Response to information security incidents" - }, - { - "id": "A.5.27", - "name": "Organizational - Learning from information security incidents" - }, - { - "id": "A.5.28", - "name": "Organizational - Collection of evidence" - }, - { - "id": "A.5.29", - "name": "Organizational - Information security during disruption" - }, - { - "id": "A.5.30", - "name": "Organizational - ICT readiness for business continuity" - }, - { - "id": "A.5.31", - "name": "Organizational - Legal, statutory, regulatory and contractual requirements" - }, - { - "id": "A.5.32", - "name": "Organizational - Intellectual property rights" - }, - { - "id": "A.5.33", - "name": "Organizational - Protection of records" - }, - { - "id": "A.5.34", - "name": "Organizational - Privacy and protection of PII" - }, - { - "id": "A.5.35", - "name": "Organizational - Independent review of information security" - }, - { - "id": "A.5.36", - "name": "Organizational - Compliance with policies, rules and standards for information security" - }, - { - "id": "A.5.37", - "name": "Organizational - Documented operating procedures" - }, - { - "id": "A.6.1", - "name": "People - Screening" - }, - { - "id": "A.6.2", - "name": "People - Terms and conditions of employment" - }, - { - "id": "A.6.3", - "name": "People - Information security awareness, education and training" - }, - { - "id": "A.6.4", - "name": "People - Disciplinary process" - }, - { - "id": "A.6.5", - "name": "People - Responsibilities after termination or change of employment" - }, - { - "id": "A.6.6", - "name": "People - Confidentiality or non-disclosure agreements" - }, - { - "id": "A.6.7", - "name": "People - Remote working" - }, - { - "id": "A.6.8", - "name": "People - Information security event reporting" - }, - { - "id": "A.7.1", - "name": "Physical - Physical security perimeters" - }, - { - "id": "A.7.2", - "name": "Physical - Physical entry" - }, - { - "id": "A.7.3", - "name": "Physical - Securing offices, rooms and facilities" - }, - { - "id": "A.7.4", - "name": "Physical - Physical security monitoring" - }, - { - "id": "A.7.5", - "name": "Physical - Protecting against physical and environmental threats" - }, - { - "id": "A.7.6", - "name": "Physical - Working in secure areas" - }, - { - "id": "A.7.7", - "name": "Physical - Clear desk and clear screen" - }, - { - "id": "A.7.8", - "name": "Physical - Equipment siting and protection" - }, - { - "id": "A.7.9", - "name": "Physical - Security of assets off-premises" - }, - { - "id": "A.7.10", - "name": "Physical - Storage media" - }, - { - "id": "A.7.11", - "name": "Physical - Supporting utilities" - }, - { - "id": "A.7.12", - "name": "Physical - Cabling security" - }, - { - "id": "A.7.13", - "name": "Physical - Equipment maintenance" - }, - { - "id": "A.7.14", - "name": "Physical - Secure disposal or re-use of equipment" - }, - { - "id": "A.8.1", - "name": "Technological - User endpoint devices" - }, - { - "id": "A.8.2", - "name": "Technological - Privileged access rights" - }, - { - "id": "A.8.3", - "name": "Technological - Information access restriction" - }, - { - "id": "A.8.4", - "name": "Technological - Access to source code" - }, - { - "id": "A.8.5", - "name": "Technological - Secure authentication" - }, - { - "id": "A.8.6", - "name": "Technological - Capacity management" - }, - { - "id": "A.8.7", - "name": "Technological - Protection against malware" - }, - { - "id": "A.8.8", - "name": "Technological - Management of technical vulnerabilities" - }, - { - "id": "A.8.9", - "name": "Technological - Configuration management" - }, - { - "id": "A.8.10", - "name": "Technological - Information deletion" - }, - { - "id": "A.8.11", - "name": "Technological - Data masking" - }, - { - "id": "A.8.12", - "name": "Technological - Data leakage prevention" - }, - { - "id": "A.8.13", - "name": "Technological - Information backup" - }, - { - "id": "A.8.14", - "name": "Technological - Redundancy of information processing facilities" - }, - { - "id": "A.8.15", - "name": "Technological - Logging" - }, - { - "id": "A.8.16", - "name": "Technological - Monitoring activities" - }, - { - "id": "A.8.17", - "name": "Technological - Clock synchronization" - }, - { - "id": "A.8.18", - "name": "Technological - Use of privileged utility programs" - }, - { - "id": "A.8.19", - "name": "Technological - Installation of software on operational systems" - }, - { - "id": "A.8.20", - "name": "Technological - Networks security" - }, - { - "id": "A.8.21", - "name": "Technological - Security of network services" - }, - { - "id": "A.8.22", - "name": "Technological - Segregation of networks" - }, - { - "id": "A.8.23", - "name": "Technological - Web filtering" - }, - { - "id": "A.8.24", - "name": "Technological - Use of cryptography" - }, - { - "id": "A.8.25", - "name": "Technological - Secure development life cycle" - }, - { - "id": "A.8.26" - }, - { - "id": "A.8.27", - "name": "Technological - Secure system architecture and engineering principles" - }, - { - "id": "A.8.28", - "name": "Technological - Secure coding" - }, - { - "id": "A.8.29", - "name": "Technological - Security testing in development and acceptance" - }, - { - "id": "A.8.30", - "name": "Technological - Outsourced development" - }, - { - "id": "A.8.31", - "name": "Technological - Separation of development, test and production environments" - }, - { - "id": "A.8.32", - "name": "Technological - Change management" - }, - { - "id": "A.8.33", - "name": "Technological - Test information" - }, - { - "id": "A.8.34", - "name": "Technological - Protection of information systems during audit testing" - } - ] -} diff --git a/data/frameworks/SOC2.json b/data/frameworks/SOC2.json deleted file mode 100644 index ac44485ac..000000000 --- a/data/frameworks/SOC2.json +++ /dev/null @@ -1,249 +0,0 @@ -{ - "name": "SOC2", - "controls": [ - { - "id": "CC1.1", - "name": "COSO Principle 1: The entity demonstrates a commitment to integrity and ethical values." - }, - { - "id": "CC1.2", - "name": "COSO Principle 2: The board of directors demonstrates independence from management and exercises oversight of the development and performance of internal control." - }, - { - "id": "CC1.3", - "name": "COSO Principle 3: Management establishes, with board oversight, structures, reporting lines, and appropriate authorities and responsibilities in the pursuit of objectives." - }, - { - "id": "CC1.4", - "name": "COSO Principle 4: The entity demonstrates a individuals in alignment with objectives." - }, - { - "id": "CC1.5", - "name": "COSO Principle 5: The entity holds individuals in the pursuit of objectives." - }, - { - "id": "CC2.1", - "name": "COSO Principle 13: The entity obtains or generates functioning of internal control." - }, - { - "id": "CC2.2", - "name": "COSO Principle 14: The entity internally communicates information, including objectives and responsibilities for internal control, necessary to support the functioning of internal control." - }, - { - "id": "CC2.3", - "name": "COSO Principle 15: The entity communicates with functioning of internal control." - }, - { - "id": "CC3.1", - "name": "COSO Principle 6: The entity specifies objectives with assessment of risks relating to objectives." - }, - { - "id": "CC3.2", - "name": "COSO Principle 7: The entity identifies risks to the achievement of its objectives across the entity and analyzes risks as a basis for determining how the risks should be managed." - }, - { - "id": "CC3.3", - "name": "COSO Principle 8: The entity considers the potential objectives." - }, - { - "id": "CC3.4", - "name": "COSO Principle 9: The entity identifies and assesses internal control." - }, - { - "id": "CC4.1", - "name": "COSO Principle 16: The entity selects, develops, and performs ongoing and/or separate evaluations to ascertain whether the components of internal control are present and functioning." - }, - { - "id": "CC4.2", - "name": "COSO Principle 17: The entity evaluates and communicates internal control deficiencies in a timely corrective action, including senior management and the board of directors, as appropriate." - }, - { - "id": "CC5.1", - "name": "COSO Principle 10: The entity selects and develops control activities that contribute to the mitigation of risks to the achievement of objectives to acceptable levels." - }, - { - "id": "CC5.2", - "name": "COSO Principle 11: The entity also selects and support the achievement of objectives." - }, - { - "id": "CC5.3", - "name": "COSO Principle 12: The entity deploys control activities through policies that establish what is expected and in procedures that put policies into action." - }, - { - "id": "CC6.1", - "name": "The entity implements logical access security software, infrastructure, and architectures over protected information assets to protect them from security events to meet the entity’s objectives." - }, - { - "id": "CC6.2", - "name": "Prior to issuing system credentials and granting system access, the entity registers and authorizes new internal and external users whose access is administered by the entity. For those users whose access is administered by the entity, user system credentials are removed when user access is no longer authorized." - }, - { - "id": "CC6.3", - "name": "The entity authorizes, modifies, or removes access to data, software, functions, and other protected information assets based on roles, responsibilities, or the system design and changes, giving consideration to the concepts of least privilege and segregation of duties, to meet the entity’s objectives." - }, - { - "id": "CC6.4", - "name": "The entity restricts physical access to facilities and protected information assets (for example, data center locations) to authorized personnel to meet the entity’s objectives." - }, - { - "id": "CC6.5", - "name": "The entity discontinues logical and physical protections over physical assets only after the ability to read or diminished and is no longer required to meet the entity’s objectives." - }, - { - "id": "CC6.6", - "name": "The entity implements logical access security measures system boundaries." - }, - { - "id": "CC6.7", - "name": "The entity restricts the transmission, movement, and removal of information to authorized internal and transmission, movement, or removal to meet the entity’s objectives." - }, - { - "id": "CC6.8", - "name": "The entity implements controls to prevent or detect and software to meet the entity’s objectives." - }, - { - "id": "CC7.1", - "name": "To meet its objectives, the entity uses detection and monitoring procedures to identify (1) changes to vulnerabilities, and (2) susceptibilities to newly discovered vulnerabilities." - }, - { - "id": "CC7.2", - "name": "The entity monitors system components and the operation of those components for anomalies that are indicative of malicious acts, natural disasters, and errors affecting the entity’s ability to meet its objectives; anomalies are analyzed to determine whether they represent security events." - }, - { - "id": "CC7.3", - "name": "The entity evaluates security events to determine whether they could or have resulted in a failure of the entity to meet its objectives (security incidents) and, if so, takes actions to prevent or address such failures." - }, - { - "id": "CC7.4", - "name": "The entity responds to identified security incidents by executing a defined incident response program to understand, contain, remediate, and communicate security incidents, as appropriate." - }, - { - "id": "CC7.5", - "name": "The entity identifies, develops, and implements activities to recover from identified security incidents." - }, - { - "id": "CC8.1", - "name": "The entity authorizes, designs, develops or acquires, configures, documents, tests, approves, and implements changes to infrastructure, data, software, and procedures to meet its objectives." - }, - { - "id": "CC9.1", - "name": "The entity identifies, selects, and develops risk business disruptions." - }, - { - "id": "CC9.2", - "name": "The entity assesses and manages risks associated with vendors and business partners." - }, - { - "id": "A1.1", - "name": "The entity maintains, monitors, and evaluates current processing capacity and use of system components capacity demand and to enable the implementation of additional capacity to help meet its objectives." - }, - { - "id": "A1.2", - "name": "The entity authorizes, designs, develops or acquires, implements, operates, approves, maintains, and back-up processes, and recovery infrastructure to meet its objectives." - }, - { - "id": "A1.3", - "name": "The entity tests recovery plan procedures supporting system recovery to meet its objectives." - }, - { - "id": "C1.1", - "name": "The entity identifies and maintains confidential confidentiality." - }, - { - "id": "C1.2", - "name": "The entity disposes of confidential information to meet the entity’s objectives related to confidentiality." - }, - { - "id": "PI1.1", - "name": "The entity obtains or generates, uses, and communicates relevant, quality information regarding the objectives processed and product and service specifications, to support the use of products and services." - }, - { - "id": "PI1.2", - "name": "The entity implements policies and procedures over system inputs, including controls over completeness and accuracy, to result in products, services, and reporting to meet the entity’s objectives." - }, - { - "id": "PI1.3", - "name": "The entity implements policies and procedures over reporting to meet the entity’s objectives." - }, - { - "id": "PI1.4", - "name": "The entity implements policies and procedures to make available or deliver output completely, accurately, and timely in accordance with specifications to meet the entity’s objectives." - }, - { - "id": "PI1.5", - "name": "The entity implements policies and procedures to store inputs, items in processing, and outputs completely, accurately, and timely in accordance with system specifications to meet the entity’s objectives." - }, - { - "id": "P1.1", - "name": "The entity provides notice to data subjects about its privacy practices to meet the entity’s objectives related to privacy. The notice is updated and communicated to entity’s privacy practices, including changes in the use of personal information, to meet the entity’s objectives related to privacy." - }, - { - "id": "P2.1", - "name": "The entity communicates choices available regarding the collection, use, retention, disclosure, and disposal of personal information to the data subjects and the consequences, if any, of each choice. Explicit consent for the collection, use, retention, disclosure, and disposal of personal information is obtained from data subjects or other authorized persons, if required. Such consent is obtained only for the intended purpose of the information to meet the entity’s objectives related to privacy. The entity’s basis for determining implicit consent for the collection, use, retention, disclosure, and disposal of personal information is documented." - }, - { - "id": "P3.1", - "name": "Personal information is collected consistent with the entity’s objectives related to privacy." - }, - { - "id": "P3.2", - "name": "For information requiring explicit consent, the entity communicates the need for such consent, as well as the consequences of a failure to provide consent for the request for personal information, and obtains the consent prior to the collection of the information to meet the entity’s objectives related to privacy." - }, - { - "id": "P4.1", - "name": "The entity limits the use of personal information to the privacy." - }, - { - "id": "P4.2", - "name": "The entity retains personal information consistent with the entity’s objectives related to privacy." - }, - { - "id": "P4.3", - "name": "The entity securely disposes of personal information to meet the entity’s objectives related to privacy." - }, - { - "id": "P5.1", - "name": "The entity grants identified and authenticated data subjects the ability to access their stored personal information for review and, upon request, provides physical or electronic copies of that information to data subjects to meet the entity’s objectives related to privacy. If access is denied, data subjects are informed of the denial and reason for such denial, as required, to meet the entity’s objectives related to privacy." - }, - { - "id": "P5.2", - "name": "The entity corrects, amends, or appends personal information based on information provided by data subjects and communicates such information to third parties, as committed or required, to meet the entity’s objectives related to privacy. If a request for correction is denied, data subjects are informed of the denial and reason for such denial to meet the entity’s objectives related to privacy." - }, - { - "id": "P6.1", - "name": "The entity discloses personal information to third parties with the explicit consent of data subjects, and such consent is obtained prior to disclosure to meet the entity’s objectives related to privacy." - }, - { - "id": "P6.2", - "name": "The entity creates and retains a complete, accurate, and timely record of authorized disclosures of personal information to meet the entity’s objectives related to privacy." - }, - { - "id": "P6.3", - "name": "The entity creates and retains a complete, accurate, and timely record of detected or reported unauthorized information to meet the entity’s objectives related to privacy." - }, - { - "id": "P6.4", - "name": "The entity obtains privacy commitments from vendors and other third parties who have access to personal information to meet the entity’s objectives related to privacy. The entity assesses those parties’ compliance on a periodic and as-needed basis and takes corrective action, if necessary." - }, - { - "id": "P6.5", - "name": "The entity obtains commitments from vendors and other third parties with access to personal information to notify the entity in the event of actual or suspected unauthorized disclosures of personal information. Such notifications are reported to appropriate personnel and acted on in accordance with established incident response procedures to meet the entity’s objectives related to privacy." - }, - { - "id": "P6.6", - "name": "The entity provides notification of breaches and others to meet the entity’s objectives related to privacy." - }, - { - "id": "P6.7", - "name": "The entity provides data subjects with an accounting of the personal information held and disclosure of the subjects’ request, to meet the entity’s objectives related to privacy." - }, - { - "id": "P7.1", - "name": "The entity collects and maintains accurate, up-to-date, the entity’s objectives related to privacy." - }, - { - "id": "P8.1", - "name": "The entity implements a process for receiving, addressing, resolving, and communicating the resolution of inquiries, complaints, and disputes from data subjects and others and periodically monitors compliance to meet the entity’s objectives related to privacy. Corrections and other necessary actions related to identified deficiencies are made or taken in a timely manner." - } - ] -}