Personally Identifiable Information Quality Operations

LOW MODERATE HIGH
5 Enhancements 0 Overlays 4 Related Controls
Graph
Export ▾

Requirements NIST SOURCE

Discussion (NIST Supplemental Guidance)

Personally identifiable information quality operations include the steps that organizations take to confirm the accuracy and relevance of personally identifiable information throughout the information life cycle. The information life cycle includes the creation, collection, use, processing, storage, maintenance, dissemination, disclosure, and disposal of personally identifiable information. Personally identifiable information quality operations include editing and validating addresses as they are collected or entered into systems using automated address verification look-up application programming interfaces. Checking personally identifiable information quality includes the tracking of updates or changes to data over time, which enables organizations to know how and what personally identifiable information was changed should erroneous information be identified. The measures taken to protect personally identifiable information quality are based on the nature and context of the personally identifiable information, how it is to be used, how it was obtained, and the potential de-identification methods employed. The measures taken to validate the accuracy of personally identifiable information used to make determinations about the rights, benefits, or privileges of individuals covered under federal programs may be more comprehensive than the measures used to validate personally identifiable information used for less sensitive purposes.

Enhancements NIST SOURCE

SI-18(1) Automation Support LOW MODERATE HIGH

Correct or delete personally identifiable information that is inaccurate or outdated, incorrectly determined regarding impact, or incorrectly de-identified using [automated mechanisms].

Discussion

The use of automated mechanisms to improve data quality may inadvertently create privacy risks. Automated tools may connect to external or otherwise unrelated systems, and the matching of records between these systems may create linkages with unintended consequences. Organizations assess and document these risks in their privacy impact assessments and make determinations that are in alignment with their privacy program plans. As data is obtained and used across the information life cycle, it is important to confirm the accuracy and relevance of personally identifiable information. Automated mechanisms can augment existing data quality processes and procedures and enable an organization to better identify and manage personally identifiable information in large-scale systems. For example, automated tools can greatly improve efforts to consistently normalize data or identify malformed data. Automated tools can also be used to improve the auditing of data and detect errors that may incorrectly alter personally identifiable information or incorrectly associate such information with the wrong individual. Automated capabilities backstop processes and procedures at-scale and enable more fine-grained detection and correction of data quality errors.

Open full page for SI-18(1) →
SI-18(2) Data Tags LOW MODERATE HIGH

Employ data tags to automate the correction or deletion of personally identifiable information across the information life cycle within organizational systems.

Discussion

Data tagging personally identifiable information includes tags that note processing permissions, authority to process, de-identification, impact level, information life cycle stage, and retention or last updated dates. Employing data tags for personally identifiable information can support the use of automation tools to correct or delete relevant personally identifiable information.

Open full page for SI-18(2) →
SI-18(3) Collection LOW MODERATE HIGH

Collect personally identifiable information directly from the individual.

Discussion

Individuals or their designated representatives can be sources of correct personally identifiable information. Organizations consider contextual factors that may incentivize individuals to provide correct data versus false data. Additional steps may be necessary to validate collected information based on the nature and context of the personally identifiable information, how it is to be used, and how it was obtained. The measures taken to validate the accuracy of personally identifiable information used to make determinations about the rights, benefits, or privileges of individuals under federal programs may be more comprehensive than the measures taken to validate less sensitive personally identifiable information.

Open full page for SI-18(3) →
SI-18(4) Individual Requests LOW MODERATE HIGH

Correct or delete personally identifiable information upon request by individuals or their designated representatives.

Discussion

Inaccurate personally identifiable information maintained by organizations may cause problems for individuals, especially in those business functions where inaccurate information may result in inappropriate decisions or the denial of benefits and services to individuals. Even correct information, in certain circumstances, can cause problems for individuals that outweigh the benefits of an organization maintaining the information. Organizations use discretion when determining if personally identifiable information is to be corrected or deleted based on the scope of requests, the changes sought, the impact of the changes, and laws, regulations, and policies. Organizational personnel consult with the senior agency official for privacy and legal counsel regarding appropriate instances of correction or deletion.

Open full page for SI-18(4) →
SI-18(5) Notice of Correction or Deletion LOW MODERATE HIGH

Notify [recipients] and individuals that the personally identifiable information has been corrected or deleted.

Discussion

When personally identifiable information is corrected or deleted, organizations take steps to ensure that all authorized recipients of such information, and the individual with whom the information is associated or their designated representatives, are informed of the corrected or deleted information.

Open full page for SI-18(5) →

Implementation Guidance

Engineering Interpretation

Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.

No engineering interpretation has been authored for SI-18 yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.

Assessment

NIST SP 800-53A REV 5.2.0

Assessment Objectives

  1. the frequency at which to check the accuracy of personally identifiable information across the information life cycle is defined;
  2. the frequency at which to check the relevance of personally identifiable information across the information life cycle is defined;
  3. the frequency at which to check the timeliness of personally identifiable information across the information life cycle is defined;
  4. the frequency at which to check the completeness of personally identifiable information across the information life cycle is defined;
  5. the accuracy of personally identifiable information across the information life cycle is checked <SI-18_ODP[01] frequency>;
  6. the relevance of personally identifiable information across the information life cycle is checked <SI-18_ODP[02] frequency>;
  7. the timeliness of personally identifiable information across the information life cycle is checked <SI-18_ODP[03] frequency>;
  8. the completeness of personally identifiable information across the information life cycle is checked <SI-18_ODP[04] frequency>;
  9. inaccurate or outdated personally identifiable information is corrected or deleted.

Examine

[SELECT FROM: System and information integrity policy; system and information integrity procedures; personally identifiable information processing policy; documentation addressing personally identifiable information quality operations; quality reports; maintenance logs; system audit records; audit findings; system security plan; privacy plan; privacy impact assessment; privacy risk assessment documentation; other relevant documents or records].

Interview

[SELECT FROM: Organizational personnel responsible for performing personally identifiable information quality inspections; organizational personnel with information security responsibilities; organizational personnel with privacy responsibilities].

Test

[SELECT FROM: Organizational processes for personally identifiable information quality inspection; automated mechanisms supporting and/or implementing personally identifiable information quality operations].

STIGs & CCIs

No STIG checks or CCI mappings are currently loaded for SI-18. This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.

Learn more about STIG/CCI integration →

Evidence

Potential Evidence — Derived

Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.

Policy

  • System and information integrity policy
  • personally identifiable information processing policy
  • system security plan
  • privacy plan

Testing

  • Organizational processes for personally identifiable information quality inspection
  • automated mechanisms supporting and/or implementing personally identifiable information quality operations

Other Records

  • system and information integrity procedures
  • documentation addressing personally identifiable information quality operations
  • quality reports
  • maintenance logs
  • system audit records
  • audit findings
  • privacy impact assessment
  • privacy risk assessment documentation
  • other relevant documents or records