Data Governance Body
LOW MODERATE HIGHRequirements NIST SOURCE
Establish a Data Governance Body consisting of [roles] with [responsibilities].
Discussion (NIST Supplemental Guidance)
A Data Governance Body can help ensure that the organization has coherent policies and the ability to balance the utility of data with security and privacy requirements. The Data Governance Body establishes policies, procedures, and standards that facilitate data governance so that data, including personally identifiable information, is effectively managed and maintained in accordance with applicable laws, executive orders, directives, regulations, policies, standards, and guidance. Responsibilities can include developing and implementing guidelines that support data modeling, quality, integrity, and the de-identification needs of personally identifiable information across the information life cycle as well as reviewing and approving applications to release data outside of the organization, archiving the applications and the released data, and performing post-release monitoring to ensure that the assumptions made as part of the data release continue to be valid. Members include the chief information officer, senior agency information security officer, and senior agency official for privacy. Federal agencies are required to establish a Data Governance Body with specific roles and responsibilities in accordance with the EVIDACT and policies set forth under OMB M-19-23.
Implementation Guidance
Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.
No engineering interpretation has been authored for PM-23 yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.
Assessment
Assessment Objectives
- the roles of a Data Governance Body are defined;
- the responsibilities of a Data Governance Body are defined;
- a Data Governance Body consisting of <PM-23_ODP[01] roles> with <PM-23_ODP[02] responsibilities> is established.
Examine
[SELECT FROM: Privacy program plan; documentation relating to the Data Governance Body, including documents establishing such a body, its charter of operations, and any plans and reports; records of board meetings and decisions; records of requests to review data; policies, procedures, and standards that facilitate data governance].
Interview
[SELECT FROM: Officials serving on the Data Governance Body (e.g., chief information officer, senior agency information security officer, and senior agency official for privacy)].
Overlays
STIGs & CCIs
No STIG checks or CCI mappings are currently loaded for PM-23. This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.
Learn more about STIG/CCI integration →Evidence
Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.
Policy
- Privacy program plan
- policies, procedures, and standards that facilitate data governance
Other Records
- documentation relating to the Data Governance Body, including documents establishing such a body, its charter of operations, and any plans and reports
- records of board meetings and decisions
- records of requests to review data