← PT-6

Routine Uses

LOW MODERATE HIGH
0 Overlays 0 Related Controls
Graph
Export ▾

Requirements NIST SOURCE

Review all routine uses published in the system of records notice at [frequency] to ensure continued accuracy, and to ensure that routine uses continue to be compatible with the purpose for which the information was collected.

Discussion (NIST Supplemental Guidance)

A PRIVACT routine use is a particular kind of disclosure of a record outside of the federal agency maintaining the system of records. A routine use is an exception to the PRIVACT prohibition on the disclosure of a record in a system of records without the prior written consent of the individual to whom the record pertains. To qualify as a routine use, the disclosure must be for a purpose that is compatible with the purpose for which the information was originally collected. The PRIVACT requires agencies to describe each routine use of the records maintained in the system of records, including the categories of users of the records and the purpose of the use. Agencies may only establish routine uses by explicitly publishing them in the relevant system of records notice.

Implementation Guidance

Engineering Interpretation

Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.

No engineering interpretation has been authored for PT-6(1) yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.

Assessment

NIST SP 800-53A REV 5.2.0

Assessment Objectives

  1. the frequency at which to review all routine uses published in the system of records notice is defined;
  2. all routine uses published in the system of records notice are reviewed <PT-06(01)_ODP frequency> to ensure continued accuracy, and to ensure that routine uses continue to be compatible with the purpose for which the information was collected.

Examine

[SELECT FROM: Personally identifiable information processing and transparency policy and procedures; privacy notice; Privacy Act system of records; privacy plan; other relevant documents or records].

Interview

[SELECT FROM: Organizational personnel with personally identifiable information processing and transparency responsibilities; organizational personnel with information security and privacy responsibilities].

Test

[SELECT FROM: Organizational processes for reviewing system of records notices].

STIGs & CCIs

No STIG checks or CCI mappings are currently loaded for PT-6(1). This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.

Learn more about STIG/CCI integration →

Evidence

Potential Evidence — Derived

Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.

Policy

  • Personally identifiable information processing and transparency policy and procedures
  • privacy plan

Testing

  • Organizational processes for reviewing system of records notices

Other Records

  • privacy notice
  • Privacy Act system of records
  • other relevant documents or records