April 16, 2018 Cybersecurity Framework Version 1.1 To address privacy implications, organizations may consider how their cybersecurity program might incorporate privacy principles such as: data minimization in the collection, disclosure, and retention of personal information material related to the cybersecurity incident; use limitations outside of cybersecurity activities on any information collected specifically for cybersecurity activities; transparency for certain cybersecurity activities; individual consent and redress for adverse impacts arising from use of personal information in cybersecurity activities; data quality, integrity, and security; and accountability and auditing. As organizations assess the Framework Core in Appendix A, the following processes and activities may be considered as a means to address the above-referenced privacy and civil liberties implications: Governance of cybersecurity risk     An organization’s assessment of cybersecurity risk and potential risk responses considers the privacy implications of its cybersecurity program. Individuals with cybersecurity-related privacy responsibilities report to appropriate management and are appropriately trained. Process is in place to support compliance of cybersecurity activities with applicable privacy laws, regulations, and Constitutional requirements. Process is in place to assess implementation of the above organizational measures and controls. Approaches to identifying, authenticating, and authorizing individuals to access organizational assets and systems  Steps are taken to identify and address the privacy implications of identity management and access control measures to the extent that they involve collection, disclosure, or use of personal information. Awareness and training measures   Applicable information from organizational privacy policies is included in cybersecurity workforce training and awareness activities. Service providers that provide cybersecurity-related services for the organization are informed about the organization’s applicable privacy policies. Anomalous activity detection and system and assets monitoring  Process is in place to conduct a privacy review of an organization’s anomalous activity detection and cybersecurity monitoring. Response activities, including information sharing or other mitigation efforts   Process is in place to assess and address whether, when, how, and the extent to which personal information is shared outside the organization as part of cybersecurity information sharing activities. Process is in place to conduct a privacy review of an organization’s cybersecurity mitigation efforts. This publication is available free of charge from: https://doi.org/10.6028/NIST.CSWP.04162018 19

Select target paragraph3