April 16, 2018
Cybersecurity Framework
Version 1.1
To address privacy implications, organizations may consider how their cybersecurity program
might incorporate privacy principles such as: data minimization in the collection, disclosure, and
retention of personal information material related to the cybersecurity incident; use limitations
outside of cybersecurity activities on any information collected specifically for cybersecurity
activities; transparency for certain cybersecurity activities; individual consent and redress for
adverse impacts arising from use of personal information in cybersecurity activities; data quality,
integrity, and security; and accountability and auditing.
As organizations assess the Framework Core in Appendix A, the following processes and
activities may be considered as a means to address the above-referenced privacy and civil
liberties implications:
Governance of cybersecurity risk
An organization’s assessment of cybersecurity risk and potential risk responses considers
the privacy implications of its cybersecurity program.
Individuals with cybersecurity-related privacy responsibilities report to appropriate
management and are appropriately trained.
Process is in place to support compliance of cybersecurity activities with applicable
privacy laws, regulations, and Constitutional requirements.
Process is in place to assess implementation of the above organizational measures and
controls.
Approaches to identifying, authenticating, and authorizing individuals to access
organizational assets and systems
Steps are taken to identify and address the privacy implications of identity management
and access control measures to the extent that they involve collection, disclosure, or use
of personal information.
Awareness and training measures
Applicable information from organizational privacy policies is included in cybersecurity
workforce training and awareness activities.
Service providers that provide cybersecurity-related services for the organization are
informed about the organization’s applicable privacy policies.
Anomalous activity detection and system and assets monitoring
Process is in place to conduct a privacy review of an organization’s anomalous activity
detection and cybersecurity monitoring.
Response activities, including information sharing or other mitigation efforts
Process is in place to assess and address whether, when, how, and the extent to which
personal information is shared outside the organization as part of cybersecurity
information sharing activities.
Process is in place to conduct a privacy review of an organization’s cybersecurity
mitigation efforts.
This publication is available free of charge from: https://doi.org/10.6028/NIST.CSWP.04162018
19