STIGhubSTIGhub
STIGsRMF ControlsCompare
STIGhub— A free STIG search and compliance tool·STIGs updated 3 days ago
Powered by Pylon·Privacy·Terms·© 2026 Beacon Cloud Solutions, Inc.
← All Controls

PM-26

Program ManagementRev 5organization

Complaint Management

Baselines:Privacy

Control Statement

Implement a process for receiving and responding to complaints, concerns, or questions from individuals about the organizational security and privacy practices that includes:

Supplemental Guidance

Complaints, concerns, and questions from individuals can serve as valuable sources of input to organizations and ultimately improve operational models, uses of technology, data collection practices, and controls. Mechanisms that can be used by the public include telephone hotline, email, or web-based forms. The information necessary for successfully filing complaints includes contact information for the senior agency official for privacy or other official designated to receive complaints. Privacy complaints may also include personally identifiable information which is handled in accordance with relevant policies and processes.

Related Controls (4)

IR-7IR-9PM-22SI-18

CCI Identifiers (11)

CCI-004435Implement a process for receiving and responding to complaints, concerns or questions from individuals about the organizational security practices.CCI-004436Implement a process for receiving and responding to complaints, concerns or questions from individuals about the organizational privacy practices.CCI-004437Implement mechanisms that are easy to use.CCI-004440Implement tracking mechanisms to ensure all complaints received are reviewed and appropriately addressed within an organization-defined time period.CCI-004441Defines the time period of which the tracking mechanisms to ensure all complaints received are reviewed and addressed.CCI-004442Implement acknowledgement of receipt of complaints, concerns, or questions from individuals within an organization-defined time period.CCI-004443Defines the time period for acknowledging the receipt of complaints, concerns, or questions from individuals.CCI-004444Implement response to complaints, concerns, or questions from individuals within an organization-defined time period.

Linked STIG Checks (0)

No STIG checks reference this control.

CCI-004445Defines the time period for response to complaints, concerns, or questions from individuals.
CCI-004438Implement mechanisms that are readily available by the public.
CCI-004439Implement all information necessary for successfully filing complaints.