← SI-19

Validated Algorithms and Software

LOW MODERATE HIGH
0 Overlays 0 Related Controls
Graph
Export ▾

Requirements NIST SOURCE

Perform de-identification using validated algorithms and software that is validated to implement the algorithms.

Discussion (NIST Supplemental Guidance)

Algorithms that appear to remove personally identifiable information from a dataset may in fact leave information that is personally identifiable or data that is re-identifiable. Software that is claimed to implement a validated algorithm may contain bugs or implement a different algorithm. Software may de-identify one type of data, such as integers, but not de-identify another type of data, such as floating point numbers. For these reasons, de-identification is performed using algorithms and software that are validated.

Implementation Guidance

Engineering Interpretation

Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.

No engineering interpretation has been authored for SI-19(7) yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.

Assessment

NIST SP 800-53A REV 5.2.0

Assessment Objectives

  1. de-identification is performed using validated algorithms;
  2. de-identification is performed using software that is validated to implement the algorithms.

Examine

[SELECT FROM: System and information integrity policy; system and information integrity procedures; personally identifiable information processing policy; de-identification procedures; system configuration; de-identified datasets; algorithm and software validation tools; system security plan; privacy plan; privacy impact assessment; privacy risk assessment documentation; other relevant documents or records].

Interview

[SELECT FROM: Organizational personnel responsible for de-identifying the dataset; organizational personnel with information security and privacy responsibilities].

Test

[SELECT FROM: Validated algorithms and software].

STIGs & CCIs

No STIG checks or CCI mappings are currently loaded for SI-19(7). This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.

Learn more about STIG/CCI integration →

Evidence

Potential Evidence — Derived

Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.

Policy

  • System and information integrity policy
  • personally identifiable information processing policy
  • system security plan
  • privacy plan

Configuration

  • system configuration

Testing

  • Validated algorithms and software

Other Records

  • system and information integrity procedures
  • de-identification procedures
  • de-identified datasets
  • algorithm and software validation tools
  • privacy impact assessment
  • privacy risk assessment documentation
  • other relevant documents or records