Final Draft of NIST Privacy Framework Released

Sheppard Mullin Richter & Hampton LLP
Contact

Sheppard Mullin Richter & Hampton LLP

NIST recently released a final version of its Privacy Framework to incorporate public feedback in response to the draft it issued late last year. For organizations familiar with the NIST Cybersecurity Framework first released in 2014, the privacy framework follows a similar structure and it is intended to be used together.

The document details a voluntary approach to assist organizations managing privacy risks. Like the NIST Cybersecurity Framework, the Privacy Framework calls for a risk-based approach to protecting privacy information. The Privacy Framework includes three sections – the Core, Profiles, and Implementation Tiers. The Core is a set of privacy protection activities and outcomes divided into key categories and subcategories with discrete outcomes. A Profile represents an organization’s current privacy activities or desired outcomes. Implementation Tiers provide a point of reference on how an organization views privacy risk and whether it has sufficient processes and resources in place to manage that risk. Tiers reflect a progression from informal, reactive responses to approaches that are agile and risk informed.

Putting it into practice: The NIST framework may help companies as they benchmark and work to identify potential gaps in compliance with privacy laws. It should not be viewed as a one-size fits all approach – particularly for companies in regulated industries or subject to numerous privacy laws. Although the framework doesn’t necessarily introduce significantly new concepts, we anticipate that companies could begin to see some business partners asking whether they adhere to or are familiar with this framework.

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Sheppard Mullin Richter & Hampton LLP | Attorney Advertising

Written by:

Sheppard Mullin Richter & Hampton LLP
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Sheppard Mullin Richter & Hampton LLP on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide