← PT-6

Exemption Rules

LOW MODERATE HIGH
0 Overlays 0 Related Controls
Graph
Export ▾

Requirements NIST SOURCE

Review all Privacy Act exemptions claimed for the system of records at [frequency] to ensure they remain appropriate and necessary in accordance with law, that they have been promulgated as regulations, and that they are accurately described in the system of records notice.

Discussion (NIST Supplemental Guidance)

The PRIVACT includes two sets of provisions that allow federal agencies to claim exemptions from certain requirements in the statute. In certain circumstances, these provisions allow agencies to promulgate regulations to exempt a system of records from select provisions of the PRIVACT . At a minimum, organizations’ PRIVACT exemption regulations include the specific name(s) of any system(s) of records that will be exempt, the specific provisions of the PRIVACT from which the system(s) of records is to be exempted, the reasons for the exemption, and an explanation for why the exemption is both necessary and appropriate.

Implementation Guidance

Engineering Interpretation

Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.

No engineering interpretation has been authored for PT-6(2) yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.

Assessment

NIST SP 800-53A REV 5.2.0

Assessment Objectives

  1. the frequency at which to review all Privacy Act exemptions claimed for the system of records is defined;
  2. all Privacy Act exemptions claimed for the system of records are reviewed <PT-06(02)_ODP frequency> to ensure that they remain appropriate and necessary in accordance with law;
  3. all Privacy Act exemptions claimed for the system of records are reviewed <PT-06(02)_ODP frequency> to ensure that they have been promulgated as regulations;
  4. all Privacy Act exemptions claimed for the system of records are reviewed <PT-06(02)_ODP frequency> to ensure that they are accurately described in the system of records notice.

Examine

[SELECT FROM: Personally identifiable information processing and transparency policy and procedures; privacy notice; Privacy Act system of records; Privacy Act exemptions; privacy plan; other relevant documents or records].

Interview

[SELECT FROM: Organizational personnel with personally identifiable information processing and transparency responsibilities; organizational personnel with information security and privacy responsibilities].

Test

[SELECT FROM: Organizational processes for Privacy Act system of records maintenance].

STIGs & CCIs

No STIG checks or CCI mappings are currently loaded for PT-6(2). This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.

Learn more about STIG/CCI integration →

Evidence

Potential Evidence — Derived

Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.

Policy

  • Personally identifiable information processing and transparency policy and procedures
  • privacy plan

Testing

  • Organizational processes for Privacy Act system of records maintenance

Other Records

  • privacy notice
  • Privacy Act system of records
  • Privacy Act exemptions
  • other relevant documents or records