PRI-05.5 ยท Inventory of Personal Data (PD)

Control Description

Mechanisms exist to establish and maintain a current inventory of all Technology Assets, Applications and/or Services (TAAS) that collect, receive, process, store, transmit, update and/or share Personal Data (PD).

Control Question
Assessment question for control validation

Does the organization establish and maintain a current inventory of all Technology Assets, Applications and/or Services (TAAS) that collect, receive, process, store, transmit, update and/or share Personal Data (PD)?

Control Weighting
8
Validation Cadence
Annual
NIST CSF Function
Identify
Supply Chain Risk Management (SCRM) Tiers
Applicable SCRM tier levels for this control
Tier 2 - Operational
Core Control Designations
Special designations and baseline inclusions
MAD: PRI-05.5
ESP Level 1: PRI-05.5
ESP Level 2: PRI-05.5
ESP Level 3: PRI-05.5
Errata & Additional Notes

- wordsmithed control