An analysis of how information is handled to ensure handling conforms to applicable legal, regulatory, and policy requirements regarding privacy; to determine the risks and effects of creating, collecting, using, processing, storing, maintaining, disseminating, disclosing, and disposing of information in identifiable form in an electronic information system; and to examine and evaluate protections and alternate processes for handling information to mitigate potential privacy concerns. A privacy impact assessment is both an analysis and a formal document detailing the process and the outcome of the analysis.
Sources:
NIST SP 800-37 Rev. 2
under privacy impact assessment
from
OMB Circular A-130 (2016)
NIST SP 800-53 Rev. 5
under privacy impact assessment
from
OMB Circular A-130 (2016)
NIST SP 800-53A Rev. 5
under privacy impact assessment
from
OMB Circular A-130 (2016)
NIST SP 800-53B
under privacy impact assessment
from
OMB Circular A-130 (2016)