1.7 Privacy Governance, Organizational Roles & ISC2 Code of Ethics

Key Takeaways

  • The Fair Information Practice Principles (FIPPs) and Privacy by Design (PbD) form the foundational standards for privacy governance across technical architectures and data lifecycles.
  • A Privacy Threshold Analysis (PTA) determines whether a system processes PII, triggering the legal requirement for a comprehensive Privacy Impact Assessment (PIA) and System of Records Notice (SORN).
  • The Authorizing Official (AO) holds sole budgetary and operational authority to accept residual risk and grant an ATO; this risk acceptance authority cannot be delegated to an AODR.
  • The Security Control Assessor (SCA) must maintain strict independence and impartiality from system development, operation, and ownership.
  • The ISC2 Code of Ethics mandates strict adherence to four Canons in unalterable priority order, placing the protection of society and infrastructure above all other duties.
Last updated: August 2026

1.7 Privacy Governance, Organizational Roles & ISC2 Code of Ethics

Modern GRC governance is built upon the convergence of information security, data privacy engineering, institutional accountability, and professional ethics. The ISC2 CGRC exam tests candidates extensively on the formal definitions of organizational roles, strict separation of duties, federal privacy mandates, and the mandatory ISC2 Code of Ethics.


Privacy Governance Principles

Privacy governance ensures that organizations respect individual privacy rights throughout the data lifecycle: Collection, Creation, Use, Processing, Storage, Maintenance, Dissemination, and Disposal.

1. Fair Information Practice Principles (FIPPs)

Codified in OMB Circular A-130 and international privacy frameworks (e.g., OECD Guidelines), the FIPPs serve as the bedrock of global privacy policy:

┌─────────────────────────────────────────────────────────────────────────┐
│               FAIR INFORMATION PRACTICE PRINCIPLES (FIPPs)              │
├──────────────────────────┬──────────────────────────────────────────────┤
│ 1. Transparency          │ Provide clear notice regarding PII practices.│
│ 2. Individual Choice     │ Enable meaningful consent and participation. │
│ 3. Purpose Specification │ Explicitly state why PII is collected.       │
│ 4. Data Minimization     │ Collect only the minimum PII necessary.      │
│ 5. Use Limitation        │ Restrict PII use strictly to stated purpose. │
│ 6. Data Quality          │ Ensure PII is accurate, complete, & current. │
│ 7. Security Safeguards   │ Protect PII against unauthorized access/loss.│
│ 8. Accountability        │ Audit compliance and provide redress remedies│
└──────────────────────────┴──────────────────────────────────────────────┘

2. Privacy by Design (PbD)

Developed by Dr. Ann Cavoukian, Privacy by Design asserts that privacy cannot be bolted on after software deployment; it must be embedded natively into system architectures. PbD defines 7 Foundational Principles:

  1. Proactive not Reactive; Preventative not Remedial: Anticipates and prevents privacy-invasive events before they occur.
  2. Privacy as the Default Setting: Individuals do not have to take action to protect their privacy; privacy is built into the default configuration (opt-in rather than opt-out).
  3. Privacy Embedded into Design: Privacy is an essential core component of IT architecture and business practices, not an afterthought.
  4. Full Functionality (Positive-Sum, not Zero-Sum): Rejects false dichotomies (e.g., Security vs. Privacy or Privacy vs. Innovation); achieves all functional goals simultaneously.
  5. End-to-End Security (Full Lifecycle Protection): Protects data from initial collection through secure destruction.
  6. Visibility and Transparency (Keep it Open): Assures stakeholders that business practices and technologies operate according to stated promises.
  7. Respect for User Privacy (Keep it User-Centric): Prioritizes user interests through strong privacy defaults, comprehensive notices, and accessible redress options.

3. Federal Privacy Instruments: PTA, PIA, and SORN

Federal agencies execute privacy governance through three interrelated compliance artifacts:

  • Privacy Threshold Analysis (PTA): A preliminary diagnostic questionnaire used to determine whether an IT system, program, or procurement collects, maintains, or transmits PII. The PTA identifies whether a full Privacy Impact Assessment (PIA) and System of Records Notice (SORN) are required.
  • Privacy Impact Assessment (PIA): A comprehensive public document mandated by Section 208 of the E-Government Act of 2002. It analyzes what PII is collected, why it is collected, how it will be secured, with whom it will be shared, and how individuals can access their information.
  • System of Records Notice (SORN): A legal notice published in the Federal Register mandated by the Privacy Act of 1974 whenever an agency maintains records retrieved by a unique personal identifier (e.g., name, Social Security Number). SORNs must undergo a 30-day public comment period before becoming operational.

Key RMF & Organizational Roles (NIST SP 800-37 Rev. 2)

Strict governance requires defined roles, clear accountability, and separation of duties.

┌─────────────────────────────────────────────────────────────────────────┐
│                     AUTHORIZING OFFICIAL (AO)                           │
│    • Highest operational/budgetary authority                            │
│    • Formally accepts residual risk and signs the ATO                   │
└────────────────────┬───────────────────────────────┬────────────────────┘
                     │                               │
                     ▼                               ▼
┌─────────────────────────────────┐   ┌───────────────────────────────────┐
│   SENIOR AGENCY PRIVACY (SAOP)  │   │     CHIEF INFORMATION OFFICER     │
│  • Oversees privacy governance  │   │  • Leads enterprise IT & FISMA    │
│  • Co-authorizes PII systems    │   │  • Oversees CISO / SAISO          │
└─────────────────────────────────┘   └─────────────────┬─────────────────┘
                                                        │
                                                        ▼
                                      ┌───────────────────────────────────┐
                                      │        CISO / SAISO / ISSM        │
                                      │  • Directs security program       │
                                      │  • Manages ISSOs enterprise-wide  │
                                      └─────────────────┬─────────────────┘
                                                        │
                     ┌──────────────────────────────────┴─────────────────┐
                     ▼                                                    ▼
┌─────────────────────────────────┐                       ┌───────────────────────────────────┐
│   SYSTEM OWNER (ISO) & ISSO     │                       │  SECURITY CONTROL ASSESSOR (SCA)  │
│  • ISO: Procures & runs system  │                       │  • Independent assessment         │
│  • ISSO: Daily security posture │                       │  • Develops SAR (Impartial)       │
└─────────────────────────────────┘                       └───────────────────────────────────┘

Detailed Role Definitions

RoleAcronymKey Mandate & Core ResponsibilitiesSeparation of Duties Rules
Authorizing OfficialAOSenior executive with budgetary and operational authority to accept residual risk and grant formal authorization (ATO, DATO, IATT, ATU).Cannot be assigned to technical assessors; holds sole authority to accept residual risk.
AO Designated RepresentativeAODRActs on behalf of the AO to coordinate daily RMF workflows and review artifacts.CANNOT sign formal authorization decisions or accept residual risk on behalf of the AO.
Chief Information OfficerCIODirects agency-wide IT planning, budgeting, capital investment (FITARA), and cybersecurity program execution.Oversees agency IT strategy; reports to Agency Head.
Senior Agency Official for PrivacySAOP / CPOSenior executive with agency-wide responsibility for privacy governance, FIPPs enforcement, SORN/PIA review, and co-authorizing systems processing PII.Maintains independent privacy oversight across all agency systems.
Chief Information Security OfficerCISO / SAISOEstablishes information security policies, manages cybersecurity operations, and coordinates ISSMs/ISSOs.Primary operational security executive; typically reports to CIO or Agency Head.
Information System OwnerISOOfficial responsible for the overall procurement, development, integration, modification, and operation of a system.Responsible for system security plan (SSP) and funding control implementation.
Information Owner / Data StewardIOAuthority responsible for establishing data classification, handling rules, and access policies for specific data assets.Establishes rules for data access; coordinates with ISOs.
Information System Security OfficerISSOOperational security officer ensuring day-to-day security posture, baseline compliance, and POA&M tracking for assigned systems.Works closely with ISO; cannot serve as the independent SCA for the same system.
Information System Security EngineerISSEEngineering specialist who designs and implements security and privacy capabilities into enterprise architectures (NIST SP 800-160).Embeds controls into the engineering and development lifecycle.
Security Control AssessorSCAIndependent official who conducts impartial control testing (NIST SP 800-53A) and authors the Security Assessment Report (SAR).Must maintain strict independence; cannot have participated in system design, implementation, or daily operation.
Common Control ProviderCCPOrganizational entity responsible for implementing, documenting, and assessing common controls inherited by multiple systems.Documents controls once for enterprise-wide inheritance.

The ISC2 Code of Ethics

All ISC2 credential holders and candidates must adhere strictly to the ISC2 Code of Ethics. The Code consists of a Preamble and Four Mandatory Canons.

The Preamble

The safety and welfare of society and the common good, duty to our principals, and to each other, requires that we adhere, and be seen to adhere, to the highest ethical standards of behavior. Therefore, strict adherence to this Code is a condition of certification.

The Four Mandatory Canons (In Strict Order of Precedence)

When ethical duties conflict, the Canons must be resolved in exact hierarchical order:

┌─────────────────────────────────────────────────────────────────────────┐
│                     THE 4 MANDATORY CANONS OF ETHICS                    │
├─────────────────────────────────────────────────────────────────────────┤
│  1. Protect society, the common good, necessary public trust, and the   │
│     infrastructure.  (HIGHEST PRECEDENCE • SUPREME CANON)               │
├─────────────────────────────────────────────────────────────────────────┤
│  2. Act honorably, honestly, justly, responsibly, and legally.          │
├─────────────────────────────────────────────────────────────────────────┤
│  3. Provide diligent and competent service to principals.               │
├─────────────────────────────────────────────────────────────────────────┤
│  4. Advance and protect the profession.                                 │
└─────────────────────────────────────────────────────────────────────────┘

[!CAUTION] Exam Rule on Ethics Resolution: If an employer or client (Principal under Canon 3) asks a certified professional to conceal a critical security vulnerability affecting public critical infrastructure, the professional MUST prioritize Canon 1 (Protect society and infrastructure) over Canon 3 (Duty to principal).


Real-World RMF Scenario: Assessor Independence

Scenario: An agency IT department is rushing to launch a new citizen benefits portal before the fiscal year-end. To save time and budget, the System Owner (ISO) assigns the system's lead ISSO to perform the formal security control assessment and draft the Security Assessment Report (SAR).

GRC Action: The CISO and Authorizing Official immediately reject this arrangement. Under NIST SP 800-37 Rev. 2 and ISC2 governance standards, the Security Control Assessor (SCA) must be completely independent of the system's operational and development chain of command. Allowing the ISSO to assess their own system constitutes an unacceptable conflict of interest, invalidating the objectivity of the authorization package.


Common Exam Traps

  • ⚠️ Trap: Believing the Authorizing Official Designated Representative (AODR) can sign an ATO. The AODR can coordinate, review packages, and brief leadership, but only the Authorizing Official (AO) holds the legal authority to sign an authorization decision and accept risk.
  • ⚠️ Trap: Misordering the ISC2 Canons of Ethics. Canon 1 (Protect society and infrastructure) always takes precedence over Canon 3 (Service to principals) and Canon 4 (Advancing the profession).
  • ⚠️ Trap: Confusing a PTA with a PIA. A PTA is the initial screening questionnaire that determines if PII is present; the PIA is the comprehensive published analysis of privacy risks and controls.
Loading diagram...
RMF Organizational Governance & Separation of Duties Architecture
Test Your Knowledge

A certified CGRC professional discovers that their enterprise employer is intentionally suppressing an active critical vulnerability in medical device software distributed to public hospitals. Company executives order the professional to keep the vulnerability confidential. According to the ISC2 Code of Ethics, what is the professional's primary duty?

A
B
C
D
Test Your Knowledge

Which organizational role holds the sole authority to formally accept residual risk on behalf of an enterprise and issue an official Authority to Operate (ATO)?

A
B
C
D
Test Your Knowledge

What is the primary operational distinction between a Privacy Threshold Analysis (PTA) and a Privacy Impact Assessment (PIA)?

A
B
C
D