Computer Matching Requirements

LOW MODERATE HIGH
0 Overlays 1 Related Control
Graph
Export ▾

Requirements NIST SOURCE

When a system or organization processes information for the purpose of conducting a matching program:

Discussion (NIST Supplemental Guidance)

The PRIVACT establishes requirements for federal and non-federal agencies if they engage in a matching program. In general, a matching program is a computerized comparison of records from two or more automated PRIVACT systems of records or an automated system of records and automated records maintained by a non-federal agency (or agent thereof). A matching program either pertains to federal benefit programs or federal personnel or payroll records. A federal benefit match is performed to determine or verify eligibility for payments under federal benefit programs or to recoup payments or delinquent debts under federal benefit programs. A matching program involves not just the matching activity itself but also the investigative follow-up and ultimate action, if any.

Implementation Guidance

Engineering Interpretation

Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.

No engineering interpretation has been authored for PT-8 yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.

Assessment

NIST SP 800-53A REV 5.2.0

Assessment Objectives

  1. approval to conduct the matching program is obtained from the Data Integrity Board when a system or organization processes information for the purpose of conducting a matching program;
  2. a computer matching agreement is developed when a system or organization processes information for the purpose of conducting a matching program;
  3. a computer matching agreement is entered into when a system or organization processes information for the purpose of conducting a matching program;
  4. a matching notice is published in the Federal Register when a system or organization processes information for the purpose of conducting a matching program;
  5. the information produced by the matching program is independently verified before taking adverse action against an individual, if required, when a system or organization processes information for the purpose of conducting a matching program;
  6. individuals are provided with notice when a system or organization processes information for the purpose of conducting a matching program;
  7. individuals are provided with an opportunity to contest the findings before adverse action is taken against them when a system or organization processes information for the purpose of conducting a matching program.

Examine

[SELECT FROM: Personally identifiable information processing and transparency policy and procedures; privacy notice; Privacy Act system of records; Federal Register notices; Data Integrity Board determinations; contracts; information sharing agreements; memoranda of understanding; governing requirements; privacy plan; other relevant documents or records].

Interview

[SELECT FROM: Organizational personnel with personally identifiable information processing and transparency responsibilities; organizational personnel with information security and privacy responsibilities].

Test

[SELECT FROM: Organizational processes for supporting and/or implementing personally identifiable information processing; matching program].

STIGs & CCIs

No STIG checks or CCI mappings are currently loaded for PT-8. This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.

Learn more about STIG/CCI integration →

Evidence

Potential Evidence — Derived

Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.

Policy

  • Personally identifiable information processing and transparency policy and procedures
  • privacy plan

Testing

  • Organizational processes for supporting and/or implementing personally identifiable information processing
  • matching program

Other Records

  • privacy notice
  • Privacy Act system of records
  • Federal Register notices
  • Data Integrity Board determinations
  • contracts
  • information sharing agreements
  • memoranda of understanding
  • governing requirements
  • other relevant documents or records