---
title: CIPM mind map
source: https://credentialpress.com/guides/cipm-mind-map
tags: [cipm, mindmap]
---

# CIPM Body of Knowledge 4.2.0

## I Developing a framework (14 to 18)
- Program scope and strategy
- Vision and mission
- In-scope laws and standards

## II Program governance (12 to 16)
- Policies and processes
- Roles and responsibilities
- Privacy metrics
- Training and awareness

## III Assessing data (12 to 16)
- Data governance systems
- Processors and vendors
- Physical and technical controls
- Shared data in mergers

## IV Protecting personal data (9 to 13)
- Information security practices
- Privacy by Design
- Data use guidelines

## V Sustaining performance (7 to 9)
- Performance metrics
- Auditing the program
- Continuous assessment

## VI Requests and incidents (10 to 14)
- Access requests and rights
- Incident handling
- Improving the response plan

## Mnemonic: Frame Govern Assess Protect Sustain Respond
- **F** Developing a framework
- **G** Program governance
- **A** Assessing data
- **P** Protecting personal data
- **S** Sustaining performance
- **R** Requests and incidents
