Minimization of Personally Identifiable Information Used in Testing, Training, and Research
LOW MODERATE HIGHRequirements NIST SOURCE
Requirement Context
This element is part of PM-25 — Minimization of Personally Identifiable Information Used in Testing, Training, and Research. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Requirement Context
This element is part of PM-25 — Minimization of Personally Identifiable Information Used in Testing, Training, and Research. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Requirement Context
This element is part of PM-25 — Minimization of Personally Identifiable Information Used in Testing, Training, and Research. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Requirement Context
This element is part of PM-25 — Minimization of Personally Identifiable Information Used in Testing, Training, and Research. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Discussion (NIST Supplemental Guidance)
The use of personally identifiable information in testing, research, and training increases the risk of unauthorized disclosure or misuse of such information. Organizations consult with the senior agency official for privacy and/or legal counsel to ensure that the use of personally identifiable information in testing, training, and research is compatible with the original purpose for which it was collected. When possible, organizations use placeholder data to avoid exposure of personally identifiable information when conducting testing, training, and research.
Implementation Guidance
Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.
No engineering interpretation has been authored for PM-25 yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.
Assessment
Assessment Objectives
- the frequency for reviewing policies that address the use of personally identifiable information for internal testing, training, and research is defined;
- the frequency for updating policies that address the use of personally identifiable information for internal testing, training, and research is defined;
- the frequency for reviewing procedures that address the use of personally identifiable information for internal testing, training, and research is defined;
- the frequency for updating procedures that address the use of personally identifiable information for internal testing, training, and research is defined;
- policies that address the use of personally identifiable information for internal testing are developed and documented;
- policies that address the use of personally identifiable information for internal training are developed and documented;
- policies that address the use of personally identifiable information for internal research are developed and documented;
- procedures that address the use of personally identifiable information for internal testing are developed and documented;
- procedures that address the use of personally identifiable information for internal training are developed and documented;
- procedures that address the use of personally identifiable information for internal research are developed and documented;
- policies that address the use of personally identifiable information for internal testing, are implemented;
- policies that address the use of personally identifiable information for training are implemented;
- policies that address the use of personally identifiable information for research are implemented;
- procedures that address the use of personally identifiable information for internal testing are implemented;
- procedures that address the use of personally identifiable information for training are implemented;
- procedures that address the use of personally identifiable information for research are implemented;
- the amount of personally identifiable information used for internal testing purposes is limited or minimized;
- the amount of personally identifiable information used for internal training purposes is limited or minimized;
- the amount of personally identifiable information used for internal research purposes is limited or minimized;
- the required use of personally identifiable information for internal testing is authorized;
- the required use of personally identifiable information for internal training is authorized;
- the required use of personally identifiable information for internal research is authorized;
- policies are reviewed <PM-25_ODP[01] frequency>;
- policies are updated <PM-25_ODP[02] frequency>;
- procedures are reviewed <PM-25_ODP[03] frequency>;
- procedures are updated <PM-25_ODP[04] frequency>.
Examine
[SELECT FROM: Privacy program plan; policies and procedures for the minimization of personally identifiable information used in testing, training, and research; documentation supporting policy implementation (e.g., templates for testing, training, and research; privacy threshold analysis; privacy risk assessment); data sets used for testing, training, and research].
Interview
[SELECT FROM: Organizational personnel with privacy program responsibilities; organizational personnel with privacy responsibilities; system developers; personnel with IRB responsibilities].
Test
[SELECT FROM: Organizational processes for data quality and personally identifiable information management; mechanisms supporting data quality management and personally identifiable information management to minimize the use of personally identifiable information].
Overlays
STIGs & CCIs
No STIG checks or CCI mappings are currently loaded for PM-25. This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.
Learn more about STIG/CCI integration →Evidence
Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.
Policy
- Privacy program plan
- policies and procedures for the minimization of personally identifiable information used in testing, training, and research
- documentation supporting policy implementation (e.g., templates for testing, training, and research
Testing
- Organizational processes for data quality and personally identifiable information management
- mechanisms supporting data quality management and personally identifiable information management to minimize the use of personally identifiable information
Other Records
- privacy threshold analysis
- privacy risk assessment)
- data sets used for testing, training, and research