Privacy impact assessment (PIA)
Term · Cybersecurity · MLC-T-CYB-003254
1. An analysis of how information is handled to ensure handling conforms to applicable legal, regulatory, and policy requirements regarding privacy; to determine the risks and effects of creating, collecting, using, processing, storing, maintaining, disseminating, disclosing, and disposing of information in identifiable form in an electronic information system; and to examine and evaluate protections and alternate processes for handling information to mitigate potential privacy concerns. Note: A privacy impact assessment is both an analysis and a formal document detailing the process and the outcome of the analysis.
2. An analysis of how information is handled to ensure handling conforms to applicable legal, regulatory, and policy requirements regarding privacy; to determine the risks and effects of creating, collecting, using, processing, storing, maintaining, disseminating, disclosing, and disposing of information in identifiable form in an electronic information system; and to examine and evaluate protections and alternate processes for handling information to mitigate potential privacy concerns. A privacy impact assessment is both an analysis and a formal document detailing the process and the outcome of the analysis.
3. “An analysis of how information is handled that ensures handling conforms to applicable legal, regulatory, and policy requirements regarding privacy; determines the risks and effects of collecting, maintaining and disseminating information in identifiable form in an electronicinformation system; and examines and evaluates protections and alternative processes for handling information to mitigate potential privacy risks.”
4. An analysis of how information is handled:
(i) to ensure handling conforms to applicable legal, regulatory,
and policy requirements regarding privacy;
(ii) to determine the risks and effects of collecting, maintaining,
and disseminating information in identifiable form in an
electronic information system; and
(iii) to examine and evaluate protections and alternative processes
for handling information to mitigate potential privacy risks.
5. A method of analyzing how personal information is collected, used, shared, and maintained. PIAs are used to identify and mitigate privacy risks throughout the development life cycle of a program or system. They also help ensure that handling information conforms to legal, regulatory, and policy requirements regarding privacy.
| Identifier | MLC-T-CYB-003254 |
|---|---|
| Field | Cybersecurity |
| Abbreviation | PIA |
| References | CNSSI 4009-2022 from OMB Circular A-130 (2016); NIST SP 800-37 Rev. 2 from OMB Circular A-130 (2016); NIST SP 800-53 Rev. 5 from OMB Circular A-130 (2016); NIST SP 800-53A Rev. 5 from OMB Circular A-130 (2016); NIST SP 800-53B from OMB Circular A-130 (2016); NIST SP 800-122 from OMB M-03-22; NIST SP 800-60 Vol. 1 Rev. 1 from OMB Memorandum 03-22; NIST SP 800-60 Vol. 2 Rev. 1 from OMB Memorandum 03-22; NIST SP 800-63-4; NIST SP 800-63A-4; NIST CSRC Glossary |
Record as JSON
{
"id": "MLC-T-CYB-003254",
"term": "Privacy impact assessment (PIA)",
"field": "Cybersecurity",
"definition": "1. An analysis of how information is handled to ensure handling conforms to applicable legal, regulatory, and policy requirements regarding privacy; to determine the risks and effects of creating, collecting, using, processing, storing, maintaining, disseminating, disclosing, and disposing of information in identifiable form in an electronic information system; and to examine and evaluate protections and alternate processes for handling information to mitigate potential privacy concerns. Note: A privacy impact assessment is both an analysis and a formal document detailing the process and the outcome of the analysis.\n\n2. An analysis of how information is handled to ensure handling conforms to applicable legal, regulatory, and policy requirements regarding privacy; to determine the risks and effects of creating, collecting, using, processing, storing, maintaining, disseminating, disclosing, and disposing of information in identifiable form in an electronic information system; and to examine and evaluate protections and alternate processes for handling information to mitigate potential privacy concerns. A privacy impact assessment is both an analysis and a formal document detailing the process and the outcome of the analysis.\n\n3. “An analysis of how information is handled that ensures handling conforms to applicable legal, regulatory, and policy requirements regarding privacy; determines the risks and effects of collecting, maintaining and disseminating information in identifiable form in an electronicinformation system; and examines and evaluates protections and alternative processes for handling information to mitigate potential privacy risks.”\n\n4. An analysis of how information is handled:\n(i) to ensure handling conforms to applicable legal, regulatory,\nand policy requirements regarding privacy;\n(ii) to determine the risks and effects of collecting, maintaining,\nand disseminating information in identifiable form in an\nelectronic information system; and\n(iii) to examine and evaluate protections and alternative processes\nfor handling information to mitigate potential privacy risks.\n\n5. A method of analyzing how personal information is collected, used, shared, and maintained. PIAs are used to identify and mitigate privacy risks throughout the development life cycle of a program or system. They also help ensure that handling information conforms to legal, regulatory, and policy requirements regarding privacy.",
"abbreviation": "PIA",
"references": [
"CNSSI 4009-2022 from OMB Circular A-130 (2016)",
"NIST SP 800-37 Rev. 2 from OMB Circular A-130 (2016); NIST SP 800-53 Rev. 5 from OMB Circular A-130 (2016); NIST SP 800-53A Rev. 5 from OMB Circular A-130 (2016); NIST SP 800-53B from OMB Circular A-130 (2016)",
"NIST SP 800-122 from OMB M-03-22",
"NIST SP 800-60 Vol. 1 Rev. 1 from OMB Memorandum 03-22; NIST SP 800-60 Vol. 2 Rev. 1 from OMB Memorandum 03-22",
"NIST SP 800-63-4; NIST SP 800-63A-4",
"NIST CSRC Glossary"
],
"url": "https://mlchart.com/terminology/cybersecurity/privacy-impact-assessment-pia/"
}
Record 3,238 of 4,669 in Cybersecurity terminology (MLC-0102). Request the full dataset.