System of Records
LOW MODERATE HIGHRequirements NIST SOURCE
Include [Privacy Act requirements] in the acquisition contract for the operation of a system of records on behalf of an organization to accomplish an organizational mission or function.
Discussion (NIST Supplemental Guidance)
When, by contract, an organization provides for the operation of a system of records to accomplish an organizational mission or function, the organization, consistent with its authority, causes the requirements of the PRIVACT to be applied to the system of records.
Implementation Guidance
Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.
No engineering interpretation has been authored for SA-4(11) yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.
Assessment
Assessment Objectives
- Privacy Act requirements for the operation of a system of records are defined;
- <SA-04(11)_ODP Privacy Act requirements> are defined in the acquisition contract for the operation of a system of records on behalf of an organization to accomplish an organizational mission or function.
Examine
[SELECT FROM: System and services acquisition policy; system and services acquisition procedures; procedures addressing the integration of Privacy Act requirements into systems of records operated by external organizations; solicitation documentation; acquisition documentation; acquisition contracts for the system, system component, or system service; service level agreements; system security plan; privacy plan; personally identifiable information processing policy; privacy program plan; privacy impact assessment; privacy risk assessment documentation; other relevant documents or records].
Interview
[SELECT FROM: Organizational personnel with acquisition responsibilities; organizational personnel with information security and privacy responsibilities].
Test
[SELECT FROM: Contract management processes to verify Privacy Act requirements are defined for the operation of a system of records; vendor processes for demonstrating incorporation of Privacy Act requirements in its operation of a system of records].
Overlays
STIGs & CCIs
No STIG checks or CCI mappings are currently loaded for SA-4(11). This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.
Learn more about STIG/CCI integration →Evidence
Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.
Policy
- System and services acquisition policy
- system security plan
- privacy plan
- personally identifiable information processing policy
- privacy program plan
Testing
- Contract management processes to verify Privacy Act requirements are defined for the operation of a system of records
- vendor processes for demonstrating incorporation of Privacy Act requirements in its operation of a system of records
Other Records
- system and services acquisition procedures
- procedures addressing the integration of Privacy Act requirements into systems of records operated by external organizations
- solicitation documentation
- acquisition documentation
- acquisition contracts for the system, system component, or system service
- service level agreements
- privacy impact assessment
- privacy risk assessment documentation
- other relevant documents or records