Data Integrity Board
LOW MODERATE HIGHRequirements NIST SOURCE
Establish a Data Integrity Board to:
Requirement Context
This element is part of PM-24 — Data Integrity Board. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Requirement Context
This element is part of PM-24 — Data Integrity Board. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Discussion (NIST Supplemental Guidance)
A Data Integrity Board is the board of senior officials designated by the head of a federal agency and is responsible for, among other things, reviewing the agency’s proposals to conduct or participate in a matching program and conducting an annual review of all matching programs in which the agency has participated. As a general matter, a matching program is a computerized comparison of records from two or more automated PRIVACT systems of records or an automated system of records and automated records maintained by a non-federal agency (or agent thereof). A matching program either pertains to Federal benefit programs or Federal personnel or payroll records. At a minimum, the Data Integrity Board includes the Inspector General of the agency, if any, and the senior agency official for privacy.
Implementation Guidance
Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.
No engineering interpretation has been authored for PM-24 yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.
Assessment
Assessment Objectives
- a Data Integrity Board is established;
- the Data Integrity Board reviews proposals to conduct or participate in a matching program;
- the Data Integrity Board conducts an annual review of all matching programs in which the agency has participated.
Examine
[SELECT FROM: Privacy program plan; privacy program documents relating to the Data Integrity Board, including documents establishing the board, its charter of operations, and any plans and reports; computer matching agreements and notices; information sharing agreements; memoranda of understanding; records documenting annual reviews; governing requirements, including laws, executive orders, regulations, standards, and guidance].
Interview
[SELECT FROM: members of the Data Integrity Board (e.g., the chief information officer, senior information security officer, senior agency official for privacy, and agency Inspector General)].
Overlays
STIGs & CCIs
No STIG checks or CCI mappings are currently loaded for PM-24. This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.
Learn more about STIG/CCI integration →Evidence
Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.
Policy
- Privacy program plan
- privacy program documents relating to the Data Integrity Board, including documents establishing the board, its charter of operations, and any plans and reports
Other Records
- computer matching agreements and notices
- information sharing agreements
- memoranda of understanding
- records documenting annual reviews
- governing requirements, including laws, executive orders, regulations, standards, and guidance