# PL-05 Privacy Impact Assessment

NIST SP 800-53 control. Family: PL Planning. Function: preventative. In no baseline. Mapping licence: CC BY-SA 4.0.
Withdrawn from SP 800-53 by NIST. Its content moved into RA-08.

Statement: The organization conducts a privacy impact assessment on the information system in accordance with OMB policy.
Guidance: OMB Memorandum 03-22 provides guidance for implementing the privacy provisions of the E-Government Act of 2002.

## Patterns that use it (1)
- Important (1): SP-013 Data Security Pattern

## Clauses by framework (7 frameworks)
- iso_42001_2023: A.5.2, A.5.3, A.5.4, A.5.5
- anssi: Hygiene.41
- osfi_b13: B-13.1.3
- finma_circular: IV.D(78), IV.D(79)
- gdpr: Art.35(1), Art.35(7), Art.36(1)
- dora: Art.6(2), Art.6(5)
- lgpd_bcb: LGPD.Art.37-38

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/PL-05
- Clauses only: /api/v1/controls/PL-05?fields=mappings
- Page for people: /controls/pl-05/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
