PIA
Term · Cybersecurity · MLC-T-CYB-003131
1. An analysis of how information is handled to ensure handling conforms to applicable legal, regulatory, and policy requirements regarding privacy; to determine the risks and effects of creating, collecting, using, processing, storing, maintaining, disseminating, disclosing, and disposing of information in identifiable form in an electronic information system; and to examine and evaluate protections and alternate processes for handling information to mitigate potential privacy concerns. A privacy impact assessment is both an analysis and a formal document detailing the process and the outcome of the analysis.
2. An analysis of how information is handled: (i) to ensure handling conforms to applicable legal, regulatory, and policy requirements regarding privacy; (ii) to determine the risks and effects of collecting, maintaining, and disseminating information in identifiable form in an electronic information system; and (iii) to examine and evaluate protections and alternative processes for handling information to mitigate potential privacy risks.
| Identifier | MLC-T-CYB-003131 |
|---|---|
| Field | Cybersecurity |
| Expansions | privacy impact assessment; Privacy Impact Assessments |
| References | NIST SP 800-37 Rev. 2 from OMB Circular A-130 (2016); NIST SP 800-53 Rev. 5 from OMB Circular A-130 (2016); NIST SP 800-53B from OMB Circular A-130 (2016); NIST SP 800-53A Rev. 5 from OMB Circular A-130 (2016); NIST SP 800-18 Rev. 1 [Superseded] from OMB Memorandum 03-22; NIST SP 800-53 Rev. 4 [Superseded] from OMB Memorandum 03-22; NIST CSRC Glossary |
Record as JSON
{
"id": "MLC-T-CYB-003131",
"term": "PIA",
"field": "Cybersecurity",
"definition": "1. An analysis of how information is handled to ensure handling conforms to applicable legal, regulatory, and policy requirements regarding privacy; to determine the risks and effects of creating, collecting, using, processing, storing, maintaining, disseminating, disclosing, and disposing of information in identifiable form in an electronic information system; and to examine and evaluate protections and alternate processes for handling information to mitigate potential privacy concerns. A privacy impact assessment is both an analysis and a formal document detailing the process and the outcome of the analysis.\n\n2. An analysis of how information is handled: (i) to ensure handling conforms to applicable legal, regulatory, and policy requirements regarding privacy; (ii) to determine the risks and effects of collecting, maintaining, and disseminating information in identifiable form in an electronic information system; and (iii) to examine and evaluate protections and alternative processes for handling information to mitigate potential privacy risks.",
"expansions": [
"privacy impact assessment",
"Privacy Impact Assessments"
],
"references": [
"NIST SP 800-37 Rev. 2 from OMB Circular A-130 (2016); NIST SP 800-53 Rev. 5 from OMB Circular A-130 (2016); NIST SP 800-53B from OMB Circular A-130 (2016); NIST SP 800-53A Rev. 5 from OMB Circular A-130 (2016)",
"NIST SP 800-18 Rev. 1 [Superseded] from OMB Memorandum 03-22; NIST SP 800-53 Rev. 4 [Superseded] from OMB Memorandum 03-22",
"NIST CSRC Glossary"
],
"url": "https://mlchart.com/terminology/cybersecurity/pia/"
}
Record 3,131 of 4,693 in Cybersecurity terminology (MLC-0102). Request the full dataset.