Skip to content

Evidence request lists

NIST Privacy Framework

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Communicate-P

NISTPF-4
Communicate-P - Privacy Notice, Transparency, and Individual Awareness

Apply Communicate-P function including: Communication Policies (CM.PO-P) covering policies for privacy communications + records of disclosures + privacy notice strategy; and Data Processing Awareness (CM.AW-P) covering individual privacy notice + mechanisms for individual access + correction + deletion + portability + opt-out + complaint + appeals + redress + data subject rights aligned with GDPR + CCPA + 24 US state privacy laws + ongoing communications during incidents and breaches. Apply transparency principles per OECD + FIPPs + APEC CBPR.

Artefacts an auditor will ask for
  • Privacy notice
  • Records of disclosures
  • DSAR/individual rights workflow
  • Complaint procedures
  • Annual notice review
Where this commonly fails
  • No privacy notice
  • No DSAR workflow
  • No complaint process
  • Stale notice

Control-P

NISTPF-3
Control-P - Privacy Controls, Data Management, and Disassociated Processing

Apply Control-P function including: Control Policies (CT.PO-P) covering policies + plans + processes for privacy risk control; Data Management (CT.DM-P) covering data quality + retention + destruction + access + transmission + alteration + deletion + correction + portability + opt-out + redress; and Disassociated Processing (CT.DP-P) covering data minimisation + anonymisation + de-identification + pseudonymisation + differential privacy + privacy-enhancing technologies (PETs) including homomorphic encryption + multi-party computation + zero-knowledge proofs.

Artefacts an auditor will ask for
  • Control policy statement
  • Data retention schedule
  • Data minimisation evidence
  • De-identification techniques
  • PETs deployment
  • Differential privacy parameters
Where this commonly fails
  • No control policy
  • Excessive retention
  • No minimisation
  • No PETs

Govern-P

NISTPF-2
Govern-P - Governance Policies, Risk Management Strategy, Awareness Training, and Monitoring

Apply Govern-P function including: Governance Policies (GV.PO-P) covering policies + responsibilities + roles + legal/regulatory requirements + privacy risk in governance; Risk Management Strategy (GV.RM-P) covering risk tolerance + ecosystem-informed risk; Awareness and Training (GV.AT-P) covering workforce training + role-based + privileged user + third-party awareness; and Monitoring and Review (GV.MT-P) covering programme monitoring + effectiveness review + privacy values incorporated + workforce informed + processes improvements. Integrate with NIST CSF 2.0 GOVERN function.

Artefacts an auditor will ask for
  • Privacy policies
  • Risk management strategy
  • Risk tolerance statement
  • Annual training records
  • Monitoring dashboards
  • Programme review
Where this commonly fails
  • Outdated policies
  • No risk tolerance
  • Missing training
  • No monitoring

Identify-P

NISTPF-1
Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment

Apply NIST Privacy Framework v1.0 (January 2020) Identify-P function categories: Business Environment (ID.BE-P) covering organizational mission + roles + responsibilities + stakeholders; Data Processing Ecosystem (ID.DE-P) covering ecosystem parties + interoperability + privacy measures in contracts; Inventory and Mapping (ID.IM-P) covering data actions inventory + purposes + data elements + processing environments + data flow mapping; and Risk Assessment (ID.RA-P) covering problematic data actions + likelihood and impact + risk responses. Cross-walk with NIST CSF 2.0 GOVERN and IDENTIFY functions. Version 1.1 in development 2024-2025.

Artefacts an auditor will ask for
  • Organizational mission statement
  • Data processing ecosystem map
  • Data action inventory
  • Data flow mapping
  • Risk assessment register
  • Problematic data action analysis
  • Annual review
Where this commonly fails
  • No business context
  • Missing ecosystem mapping
  • Stale inventory
  • No risk assessment

Protect-P Access

NISTPF-5
Protect-P Access Control (PR.AC-P)

Apply Protect-P Identity Management Authentication and Access Control (PR.AC-P) including: identity proofing + lifecycle management + credentials issued + revoked + physical access managed + remote access managed + access permissions managed (least privilege + separation of duties) + network integrity protected + individuals and devices proofed and authenticated to manage privacy risks. Implement MFA + zero trust architecture + RBAC + ABAC + PAM + JIT access aligned with NIST SP 800-63 + 800-207.

Artefacts an auditor will ask for
  • Identity proofing procedures
  • MFA deployment
  • RBAC matrices
  • Zero trust architecture
  • Access reviews
  • Annual evaluation
Where this commonly fails
  • No identity proofing
  • Weak MFA
  • Stale RBAC
  • No zero trust

Protect-P Data Security

NISTPF-6
Protect-P Data Security (PR.DS-P)

Apply Protect-P Data Security (PR.DS-P) including: data-at-rest protected + data-in-transit protected + systems managed during removal/transfer/disposition + adequate capacity to ensure availability + data leak protections + integrity verification for software/firmware/information + development/test separated from production + hardware integrity verified. Implement encryption (AES-256 + TLS 1.3 + PQC migration per FIPS 203/204/205) + DLP + secure software/hardware supply chain.

Artefacts an auditor will ask for
  • Encryption inventory
  • DLP deployment
  • Integrity verification
  • Dev/test segregation
  • Capacity planning
  • Annual evaluation
Where this commonly fails
  • Weak encryption
  • No DLP
  • No integrity verification
  • Mixed dev/prod

Protect-P Maintenance and Technology

NISTPF-7
Protect-P Maintenance and Protective Technology (PR.MA-P, PR.PT-P)

Apply Maintenance (PR.MA-P) including system maintenance + repair with approved tools + remote maintenance with prevention of unauthorised access. Apply Protective Technology (PR.PT-P) including: audit/log records determined + maintained + reviewed + removable media protected + use restricted per policy + least functionality incorporated + communications and control networks protected + resilience mechanisms implemented (high availability + DR + business continuity).

Artefacts an auditor will ask for
  • Maintenance procedures
  • Approved tool inventory
  • SIEM with retention
  • Removable media policy
  • Least functionality baselines
  • DR/BCP test reports
Where this commonly fails
  • Unauthorised maintenance
  • No SIEM
  • No removable media policy
  • No DR testing

Protect-P Processes

NISTPF-8
Protect-P Information Protection Processes (PR.PO-P)

Apply Protect-P Information Protection Processes and Procedures (PR.PO-P) including: baseline configuration management + configuration change control + backups conducted and tested + physical operating environment policy + protection processes improved + effectiveness of protection technologies shared + response and recovery plans established + response and recovery plans tested + privacy in HR practices + vulnerability management plan. Integrate with NIST CSF Protective Processes + RESPOND function.

Artefacts an auditor will ask for
  • Configuration baselines
  • Backup test records
  • Response/recovery plans
  • Annual tabletop exercise
  • Vulnerability management programme
  • HR privacy practices
Where this commonly fails
  • No baselines
  • No backup testing
  • No response plan
  • No vulnerability management
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the NIST Privacy Framework framework page.