Minimization of Personally Identifiable Information Used in Testing, Training, and Research

LOW MODERATE HIGH
1 Overlay 5 Related Controls
Graph
Export ▾

Requirements NIST SOURCE

Discussion (NIST Supplemental Guidance)

The use of personally identifiable information in testing, research, and training increases the risk of unauthorized disclosure or misuse of such information. Organizations consult with the senior agency official for privacy and/or legal counsel to ensure that the use of personally identifiable information in testing, training, and research is compatible with the original purpose for which it was collected. When possible, organizations use placeholder data to avoid exposure of personally identifiable information when conducting testing, training, and research.

Implementation Guidance

Engineering Interpretation

Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.

No engineering interpretation has been authored for PM-25 yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.

Assessment

NIST SP 800-53A REV 5.2.0

Assessment Objectives

  1. the frequency for reviewing policies that address the use of personally identifiable information for internal testing, training, and research is defined;
  2. the frequency for updating policies that address the use of personally identifiable information for internal testing, training, and research is defined;
  3. the frequency for reviewing procedures that address the use of personally identifiable information for internal testing, training, and research is defined;
  4. the frequency for updating procedures that address the use of personally identifiable information for internal testing, training, and research is defined;
  5. policies that address the use of personally identifiable information for internal testing are developed and documented;
  6. policies that address the use of personally identifiable information for internal training are developed and documented;
  7. policies that address the use of personally identifiable information for internal research are developed and documented;
  8. procedures that address the use of personally identifiable information for internal testing are developed and documented;
  9. procedures that address the use of personally identifiable information for internal training are developed and documented;
  10. procedures that address the use of personally identifiable information for internal research are developed and documented;
  11. policies that address the use of personally identifiable information for internal testing, are implemented;
  12. policies that address the use of personally identifiable information for training are implemented;
  13. policies that address the use of personally identifiable information for research are implemented;
  14. procedures that address the use of personally identifiable information for internal testing are implemented;
  15. procedures that address the use of personally identifiable information for training are implemented;
  16. procedures that address the use of personally identifiable information for research are implemented;
  17. the amount of personally identifiable information used for internal testing purposes is limited or minimized;
  18. the amount of personally identifiable information used for internal training purposes is limited or minimized;
  19. the amount of personally identifiable information used for internal research purposes is limited or minimized;
  20. the required use of personally identifiable information for internal testing is authorized;
  21. the required use of personally identifiable information for internal training is authorized;
  22. the required use of personally identifiable information for internal research is authorized;
  23. policies are reviewed <PM-25_ODP[01] frequency>;
  24. policies are updated <PM-25_ODP[02] frequency>;
  25. procedures are reviewed <PM-25_ODP[03] frequency>;
  26. procedures are updated <PM-25_ODP[04] frequency>.

Examine

[SELECT FROM: Privacy program plan; policies and procedures for the minimization of personally identifiable information used in testing, training, and research; documentation supporting policy implementation (e.g., templates for testing, training, and research; privacy threshold analysis; privacy risk assessment); data sets used for testing, training, and research].

Interview

[SELECT FROM: Organizational personnel with privacy program responsibilities; organizational personnel with privacy responsibilities; system developers; personnel with IRB responsibilities].

Test

[SELECT FROM: Organizational processes for data quality and personally identifiable information management; mechanisms supporting data quality management and personally identifiable information management to minimize the use of personally identifiable information].

Overlays

OT/ICS Overlay SP 800-82r3

NIST SP 800-82r3 Appendix F, Table 22. Blank baseline means the control/control enhancement is not selected in that initial OT baseline.

LOW

Not applicable at this tier.

MODERATE

Not applicable at this tier.

HIGH

  • Base control: Added (beyond standard baseline)

STIGs & CCIs

No STIG checks or CCI mappings are currently loaded for PM-25. This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.

Learn more about STIG/CCI integration →

Evidence

Potential Evidence — Derived

Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.

Policy

  • Privacy program plan
  • policies and procedures for the minimization of personally identifiable information used in testing, training, and research
  • documentation supporting policy implementation (e.g., templates for testing, training, and research

Testing

  • Organizational processes for data quality and personally identifiable information management
  • mechanisms supporting data quality management and personally identifiable information management to minimize the use of personally identifiable information

Other Records

  • privacy threshold analysis
  • privacy risk assessment)
  • data sets used for testing, training, and research