Validated Algorithms and Software
LOW MODERATE HIGHRequirements NIST SOURCE
Perform de-identification using validated algorithms and software that is validated to implement the algorithms.
Discussion (NIST Supplemental Guidance)
Algorithms that appear to remove personally identifiable information from a dataset may in fact leave information that is personally identifiable or data that is re-identifiable. Software that is claimed to implement a validated algorithm may contain bugs or implement a different algorithm. Software may de-identify one type of data, such as integers, but not de-identify another type of data, such as floating point numbers. For these reasons, de-identification is performed using algorithms and software that are validated.
Implementation Guidance
Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.
No engineering interpretation has been authored for SI-19(7) yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.
Assessment
Assessment Objectives
- de-identification is performed using validated algorithms;
- de-identification is performed using software that is validated to implement the algorithms.
Examine
[SELECT FROM: System and information integrity policy; system and information integrity procedures; personally identifiable information processing policy; de-identification procedures; system configuration; de-identified datasets; algorithm and software validation tools; system security plan; privacy plan; privacy impact assessment; privacy risk assessment documentation; other relevant documents or records].
Interview
[SELECT FROM: Organizational personnel responsible for de-identifying the dataset; organizational personnel with information security and privacy responsibilities].
Test
[SELECT FROM: Validated algorithms and software].
STIGs & CCIs
No STIG checks or CCI mappings are currently loaded for SI-19(7). This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.
Learn more about STIG/CCI integration →Evidence
Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.
Policy
- System and information integrity policy
- personally identifiable information processing policy
- system security plan
- privacy plan
Configuration
- system configuration
Testing
- Validated algorithms and software
Other Records
- system and information integrity procedures
- de-identification procedures
- de-identified datasets
- algorithm and software validation tools
- privacy impact assessment
- privacy risk assessment documentation
- other relevant documents or records