Data Action Mapping

LOW MODERATE HIGH
0 Overlays 9 Related Controls
Graph
Export ▾

Requirements NIST SOURCE

Develop and document a map of system data actions.

Discussion (NIST Supplemental Guidance)

Data actions are system operations that process personally identifiable information. The processing of such information encompasses the full information life cycle, which includes collection, generation, transformation, use, disclosure, retention, and disposal. A map of system data actions includes discrete data actions, elements of personally identifiable information being processed in the data actions, system components involved in the data actions, and the owners or operators of the system components. Understanding what personally identifiable information is being processed (e.g., the sensitivity of the personally identifiable information), how personally identifiable information is being processed (e.g., if the data action is visible to the individual or is processed in another part of the system), and by whom (e.g., individuals may have different privacy perceptions based on the entity that is processing the personally identifiable information) provides a number of contextual factors that are important to assessing the degree of privacy risk created by the system. Data maps can be illustrated in different ways, and the level of detail may vary based on the mission and business needs of the organization. The data map may be an overlay of any system design artifact that the organization is using. The development of this map may necessitate coordination between the privacy and security programs regarding the covered data actions and the components that are identified as part of the system.

Implementation Guidance

Engineering Interpretation

Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.

No engineering interpretation has been authored for CM-13 yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.

Assessment

NIST SP 800-53A REV 5.2.0

Assessment Objectives

  1. a map of system data actions is developed and documented.

Examine

[SELECT FROM: Configuration management policy; procedures for identification and documentation of information location; procedures for mapping data actions; configuration management plan; system security plan; privacy plan; system design documentation; PII inventory documentation; data mapping documentation; change control records; system component inventory; other relevant documents or records].

Interview

[SELECT FROM: Organizational personnel with responsibilities for managing information location; organizational personnel responsible for data action mapping; organizational personnel with information security and privacy responsibilities; system/network administrators; system developers].

Test

[SELECT FROM: Organizational processes governing information location; mechanisms supporting or implementing data action mapping].

STIGs & CCIs

No STIG checks or CCI mappings are currently loaded for CM-13. This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.

Learn more about STIG/CCI integration →

Evidence

Potential Evidence — Derived

Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.

Policy

  • system security plan
  • privacy plan

Configuration

  • Configuration management policy
  • configuration management plan
  • system design documentation
  • PII inventory documentation
  • system component inventory

Testing

  • Organizational processes governing information location
  • mechanisms supporting or implementing data action mapping

Other Records

  • procedures for identification and documentation of information location
  • procedures for mapping data actions
  • data mapping documentation
  • change control records
  • other relevant documents or records