Skip to content

Nist 800 53 Pt

FieldValue
TypeSkill Resource
Source~/.copilot/skills/security/references/ato/nist-800-53-pt.json
DescriptionNot specified

Source Content

{
"catalog_uuid": "ea7c7688-79c5-463b-a91b-0650f2d98623",
"catalog_title": "Electronic (OSCAL) Version of NIST SP 800-53 Rev 5.2.0 Controls and SP 800-53A Rev 5.2.0 Assessment Procedures",
"catalog_version": "5.2.0",
"group": {
"id": "pt",
"class": "family",
"title": "Personally Identifiable Information Processing and Transparency",
"props": [
{
"name": "label",
"value": "PT"
}
],
"controls": [
{
"id": "pt-1",
"class": "SP800-53",
"title": "Policy and Procedures",
"params": [
{
"id": "pt-1_prm_1",
"props": [
{
"name": "aggregates",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "pt-01_odp.01"
},
{
"name": "aggregates",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "pt-01_odp.02"
}
],
"label": "organization-defined personnel or roles"
},
{
"id": "pt-01_odp.01",
"props": [
{
"name": "label",
"value": "PT-01_ODP[01]",
"class": "sp800-53a"
}
],
"label": "personnel or roles",
"guidelines": [
{
"prose": "personnel or roles to whom the personally identifiable information processing and transparency policy is to be disseminated is/are defined;"
}
]
},
{
"id": "pt-01_odp.02",
"props": [
{
"name": "label",
"value": "PT-01_ODP[02]",
"class": "sp800-53a"
}
],
"label": "personnel or roles",
"guidelines": [
{
"prose": "personnel or roles to whom the personally identifiable information processing and transparency procedures are to be disseminated is/are defined;"
}
]
},
{
"id": "pt-01_odp.03",
"props": [
{
"name": "alt-identifier",
"value": "pt-1_prm_2"
},
{
"name": "label",
"value": "PT-01_ODP[03]",
"class": "sp800-53a"
}
],
"select": {
"how-many": "one-or-more",
"choice": [
"organization-level",
"mission/business process-level",
"system-level"
]
}
},
{
"id": "pt-01_odp.04",
"props": [
{
"name": "alt-identifier",
"value": "pt-1_prm_3"
},
{
"name": "label",
"value": "PT-01_ODP[04]",
"class": "sp800-53a"
}
],
"label": "official",
"guidelines": [
{
"prose": "an official to manage the personally identifiable information processing and transparency policy and procedures is defined;"
}
]
},
{
"id": "pt-01_odp.05",
"props": [
{
"name": "alt-identifier",
"value": "pt-1_prm_4"
},
{
"name": "label",
"value": "PT-01_ODP[05]",
"class": "sp800-53a"
}
],
"label": "frequency",
"guidelines": [
{
"prose": "the frequency at which the current personally identifiable information processing and transparency policy is reviewed and updated is defined;"
}
]
},
{
"id": "pt-01_odp.06",
"props": [
{
"name": "alt-identifier",
"value": "pt-1_prm_5"
},
{
"name": "label",
"value": "PT-01_ODP[06]",
"class": "sp800-53a"
}
],
"label": "events",
"guidelines": [
{
"prose": "events that would require the current personally identifiable information processing and transparency policy to be reviewed and updated are defined;"
}
]
},
{
"id": "pt-01_odp.07",
"props": [
{
"name": "alt-identifier",
"value": "pt-1_prm_6"
},
{
"name": "label",
"value": "PT-01_ODP[07]",
"class": "sp800-53a"
}
],
"label": "frequency",
"guidelines": [
{
"prose": "the frequency at which the current personally identifiable information processing and transparency procedures are reviewed and updated is defined;"
}
]
},
{
"id": "pt-01_odp.08",
"props": [
{
"name": "alt-identifier",
"value": "pt-1_prm_7"
},
{
"name": "label",
"value": "PT-01_ODP[08]",
"class": "sp800-53a"
}
],
"label": "events",
"guidelines": [
{
"prose": "events that would require the personally identifiable information processing and transparency procedures to be reviewed and updated are defined;"
}
]
}
],
"props": [
{
"name": "label",
"value": "PT-01",
"class": "zero-padded"
},
{
"name": "label",
"value": "PT-1"
},
{
"name": "label",
"value": "PT-01",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "pt-01"
},
{
"name": "implementation-level",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "organization"
},
{
"name": "contributes-to-assurance",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "true"
}
],
"links": [
{
"href": "#27847491-5ce1-4f6a-a1e4-9e483782f0ef",
"rel": "reference"
}
],
"parts": [
{
"id": "pt-1_smt",
"name": "statement",
"parts": [
{
"id": "pt-1_smt.a",
"name": "item",
"props": [
{
"name": "label",
"value": "a."
}
],
"prose": "Develop, document, and disseminate to {{ insert: param, pt-1_prm_1 }}:",
"parts": [
{
"id": "pt-1_smt.a.1",
"name": "item",
"props": [
{
"name": "label",
"value": "1."
}
],
"prose": "{{ insert: param, pt-01_odp.03 }} personally identifiable information processing and transparency policy that:",
"parts": [
{
"id": "pt-1_smt.a.1.a",
"name": "item",
"props": [
{
"name": "label",
"value": "(a)"
}
],
"prose": "Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and"
},
{
"id": "pt-1_smt.a.1.b",
"name": "item",
"props": [
{
"name": "label",
"value": "(b)"
}
],
"prose": "Is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines; and"
}
]
},
{
"id": "pt-1_smt.a.2",
"name": "item",
"props": [
{
"name": "label",
"value": "2."
}
],
"prose": "Procedures to facilitate the implementation of the personally identifiable information processing and transparency policy and the associated personally identifiable information processing and transparency controls;"
}
]
},
{
"id": "pt-1_smt.b",
"name": "item",
"props": [
{
"name": "label",
"value": "b."
}
],
"prose": "Designate an {{ insert: param, pt-01_odp.04 }} to manage the development, documentation, and dissemination of the personally identifiable information processing and transparency policy and procedures; and"
},
{
"id": "pt-1_smt.c",
"name": "item",
"props": [
{
"name": "label",
"value": "c."
}
],
"prose": "Review and update the current personally identifiable information processing and transparency:",
"parts": [
{
"id": "pt-1_smt.c.1",
"name": "item",
"props": [
{
"name": "label",
"value": "1."
}
],
"prose": "Policy {{ insert: param, pt-01_odp.05 }} and following {{ insert: param, pt-01_odp.06 }} ; and"
},
{
"id": "pt-1_smt.c.2",
"name": "item",
"props": [
{
"name": "label",
"value": "2."
}
],
"prose": "Procedures {{ insert: param, pt-01_odp.07 }} and following {{ insert: param, pt-01_odp.08 }}."
}
]
}
]
},
{
"id": "pt-1_gdn",
"name": "guidance",
"prose": "Personally identifiable information processing and transparency policy and procedures address the controls in the PT family that are implemented within systems and organizations. The risk management strategy is an important factor in establishing such policies and procedures. Policies and procedures contribute to security and privacy assurance. Therefore, it is important that security and privacy programs collaborate on the development of personally identifiable information processing and transparency policy and procedures. Security and privacy program policies and procedures at the organization level are preferable, in general, and may obviate the need for mission- or system-specific policies and procedures. The policy can be included as part of the general security and privacy policy or be represented by multiple policies that reflect the complex nature of organizations. Procedures can be established for security and privacy programs, for mission or business processes, and for systems, if needed. Procedures describe how the policies or controls are implemented and can be directed at the individual or role that is the object of the procedure. Procedures can be documented in system security and privacy plans or in one or more separate documents. Events that may precipitate an update to personally identifiable information processing and transparency policy and procedures include assessment or audit findings, breaches, or changes in applicable laws, executive orders, directives, regulations, policies, standards, and guidelines. Simply restating controls does not constitute an organizational policy or procedure."
},
{
"id": "pt-1_obj",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-01",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "pt-1_obj.a",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-01a.",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "pt-1_obj.a-1",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-01a.[01]",
"class": "sp800-53a"
}
],
"prose": "a personally identifiable information processing and transparency policy is developed and documented;",
"links": [
{
"href": "#pt-1_smt.a",
"rel": "assessment-for"
}
]
},
{
"id": "pt-1_obj.a-2",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-01a.[02]",
"class": "sp800-53a"
}
],
"prose": "the personally identifiable information processing and transparency policy is disseminated to {{ insert: param, pt-01_odp.01 }};",
"links": [
{
"href": "#pt-1_smt.a",
"rel": "assessment-for"
}
]
},
{
"id": "pt-1_obj.a-3",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-01a.[03]",
"class": "sp800-53a"
}
],
"prose": "personally identifiable information processing and transparency procedures to facilitate the implementation of the personally identifiable information processing and transparency policy and associated personally identifiable information processing and transparency controls are developed and documented;",
"links": [
{
"href": "#pt-1_smt.a",
"rel": "assessment-for"
}
]
},
{
"id": "pt-1_obj.a-4",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-01a.[04]",
"class": "sp800-53a"
}
],
"prose": "the personally identifiable information processing and transparency procedures are disseminated to {{ insert: param, pt-01_odp.02 }};",
"links": [
{
"href": "#pt-1_smt.a",
"rel": "assessment-for"
}
]
},
{
"id": "pt-1_obj.a.1",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-01a.01",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "pt-1_obj.a.1.a",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-01a.01(a)",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "pt-1_obj.a.1.a-1",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-01a.01(a)[01]",
"class": "sp800-53a"
}
],
"prose": "the {{ insert: param, pt-01_odp.03 }} personally identifiable information processing and transparency policy addresses purpose;",
"links": [
{
"href": "#pt-1_smt.a.1.a",
"rel": "assessment-for"
}
]
},
{
"id": "pt-1_obj.a.1.a-2",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-01a.01(a)[02]",
"class": "sp800-53a"
}
],
"prose": "the {{ insert: param, pt-01_odp.03 }} personally identifiable information processing and transparency policy addresses scope;",
"links": [
{
"href": "#pt-1_smt.a.1.a",
"rel": "assessment-for"
}
]
},
{
"id": "pt-1_obj.a.1.a-3",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-01a.01(a)[03]",
"class": "sp800-53a"
}
],
"prose": "the {{ insert: param, pt-01_odp.03 }} personally identifiable information processing and transparency policy addresses roles;",
"links": [
{
"href": "#pt-1_smt.a.1.a",
"rel": "assessment-for"
}
]
},
{
"id": "pt-1_obj.a.1.a-4",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-01a.01(a)[04]",
"class": "sp800-53a"
}
],
"prose": "the {{ insert: param, pt-01_odp.03 }} personally identifiable information processing and transparency policy addresses responsibilities;",
"links": [
{
"href": "#pt-1_smt.a.1.a",
"rel": "assessment-for"
}
]
},
{
"id": "pt-1_obj.a.1.a-5",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-01a.01(a)[05]",
"class": "sp800-53a"
}
],
"prose": "the {{ insert: param, pt-01_odp.03 }} personally identifiable information processing and transparency policy addresses management commitment;",
"links": [
{
"href": "#pt-1_smt.a.1.a",
"rel": "assessment-for"
}
]
},
{
"id": "pt-1_obj.a.1.a-6",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-01a.01(a)[06]",
"class": "sp800-53a"
}
],
"prose": "the {{ insert: param, pt-01_odp.03 }} personally identifiable information processing and transparency policy addresses coordination among organizational entities;",
"links": [
{
"href": "#pt-1_smt.a.1.a",
"rel": "assessment-for"
}
]
},
{
"id": "pt-1_obj.a.1.a-7",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-01a.01(a)[07]",
"class": "sp800-53a"
}
],
"prose": "the {{ insert: param, pt-01_odp.03 }} personally identifiable information processing and transparency policy addresses compliance;",
"links": [
{
"href": "#pt-1_smt.a.1.a",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#pt-1_smt.a.1.a",
"rel": "assessment-for"
}
]
},
{
"id": "pt-1_obj.a.1.b",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-01a.01(b)",
"class": "sp800-53a"
}
],
"prose": "the {{ insert: param, pt-01_odp.03 }} personally identifiable information processing and transparency policy is consistent with applicable laws, Executive Orders, directives, regulations, policies, standards, and guidelines;",
"links": [
{
"href": "#pt-1_smt.a.1.b",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#pt-1_smt.a.1",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#pt-1_smt.a",
"rel": "assessment-for"
}
]
},
{
"id": "pt-1_obj.b",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-01b.",
"class": "sp800-53a"
}
],
"prose": "the {{ insert: param, pt-01_odp.04 }} is designated to manage the development, documentation, and dissemination of the personally identifiable information processing and transparency policy and procedures;",
"links": [
{
"href": "#pt-1_smt.b",
"rel": "assessment-for"
}
]
},
{
"id": "pt-1_obj.c",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-01c.",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "pt-1_obj.c.1",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-01c.01",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "pt-1_obj.c.1-1",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-01c.01[01]",
"class": "sp800-53a"
}
],
"prose": "the current personally identifiable information processing and transparency policy is reviewed and updated {{ insert: param, pt-01_odp.05 }};",
"links": [
{
"href": "#pt-1_smt.c.1",
"rel": "assessment-for"
}
]
},
{
"id": "pt-1_obj.c.1-2",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-01c.01[02]",
"class": "sp800-53a"
}
],
"prose": "the current personally identifiable information processing and transparency policy is reviewed and updated following {{ insert: param, pt-01_odp.06 }};",
"links": [
{
"href": "#pt-1_smt.c.1",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#pt-1_smt.c.1",
"rel": "assessment-for"
}
]
},
{
"id": "pt-1_obj.c.2",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-01c.02",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "pt-1_obj.c.2-1",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-01c.02[01]",
"class": "sp800-53a"
}
],
"prose": "the current personally identifiable information processing and transparency procedures are reviewed and updated {{ insert: param, pt-01_odp.07 }};",
"links": [
{
"href": "#pt-1_smt.c.2",
"rel": "assessment-for"
}
]
},
{
"id": "pt-1_obj.c.2-2",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-01c.02[02]",
"class": "sp800-53a"
}
],
"prose": "the current personally identifiable information processing and transparency procedures are reviewed and updated following {{ insert: param, pt-01_odp.08 }}.",
"links": [
{
"href": "#pt-1_smt.c.2",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#pt-1_smt.c.2",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#pt-1_smt.c",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#pt-1_smt",
"rel": "assessment-for"
}
]
},
{
"id": "pt-1_asm-examine",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "EXAMINE"
},
{
"name": "label",
"value": "PT-01-Examine",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Personally identifiable information processing and transparency policy and procedures\n\nprivacy plan\n\nprivacy program plan\n\nother relevant documents or records"
}
]
},
{
"id": "pt-1_asm-interview",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "INTERVIEW"
},
{
"name": "label",
"value": "PT-01-Interview",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational personnel with personally identifiable information processing and transparency responsibilities\n\norganizational personnel with information security and privacy responsibilities"
}
]
}
]
},
{
"id": "pt-2",
"class": "SP800-53",
"title": "Authority to Process Personally Identifiable Information",
"params": [
{
"id": "pt-02_odp.01",
"props": [
{
"name": "alt-identifier",
"value": "pt-2_prm_1"
},
{
"name": "label",
"value": "PT-02_ODP[01]",
"class": "sp800-53a"
}
],
"label": "authority",
"guidelines": [
{
"prose": "the authority to permit the processing (defined in PT-02_ODP[02]) of personally identifiable information is defined;"
}
]
},
{
"id": "pt-02_odp.02",
"props": [
{
"name": "alt-identifier",
"value": "pt-2_prm_2"
},
{
"name": "label",
"value": "PT-02_ODP[02]",
"class": "sp800-53a"
}
],
"label": "processing",
"guidelines": [
{
"prose": "the type of processing of personally identifiable information is defined;"
}
]
},
{
"id": "pt-02_odp.03",
"props": [
{
"name": "alt-identifier",
"value": "pt-2_prm_3"
},
{
"name": "label",
"value": "PT-02_ODP[03]",
"class": "sp800-53a"
}
],
"label": "processing",
"guidelines": [
{
"prose": "the type of processing of personally identifiable information to be restricted is defined;"
}
]
}
],
"props": [
{
"name": "label",
"value": "PT-02",
"class": "zero-padded"
},
{
"name": "label",
"value": "PT-2"
},
{
"name": "label",
"value": "PT-02",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "pt-02"
},
{
"name": "implementation-level",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "organization"
},
{
"name": "contributes-to-assurance",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "true"
}
],
"links": [
{
"href": "#18e71fec-c6fd-475a-925a-5d8495cf8455",
"rel": "reference"
},
{
"href": "#27847491-5ce1-4f6a-a1e4-9e483782f0ef",
"rel": "reference"
},
{
"href": "#a2590922-82f3-4277-83c0-ca5bee06dba4",
"rel": "reference"
},
{
"href": "#ac-2",
"rel": "related"
},
{
"href": "#ac-3",
"rel": "related"
},
{
"href": "#cm-13",
"rel": "related"
},
{
"href": "#ir-9",
"rel": "related"
},
{
"href": "#pm-9",
"rel": "related"
},
{
"href": "#pm-24",
"rel": "related"
},
{
"href": "#pt-1",
"rel": "related"
},
{
"href": "#pt-3",
"rel": "related"
},
{
"href": "#pt-5",
"rel": "related"
},
{
"href": "#pt-6",
"rel": "related"
},
{
"href": "#ra-3",
"rel": "related"
},
{
"href": "#ra-8",
"rel": "related"
},
{
"href": "#si-12",
"rel": "related"
},
{
"href": "#si-18",
"rel": "related"
}
],
"parts": [
{
"id": "pt-2_smt",
"name": "statement",
"parts": [
{
"id": "pt-2_smt.a",
"name": "item",
"props": [
{
"name": "label",
"value": "a."
}
],
"prose": "Determine and document the {{ insert: param, pt-02_odp.01 }} that permits the {{ insert: param, pt-02_odp.02 }} of personally identifiable information; and"
},
{
"id": "pt-2_smt.b",
"name": "item",
"props": [
{
"name": "label",
"value": "b."
}
],
"prose": "Restrict the {{ insert: param, pt-02_odp.03 }} of personally identifiable information to only that which is authorized."
}
]
},
{
"id": "pt-2_gdn",
"name": "guidance",
"prose": "The processing of personally identifiable information is an operation or set of operations that the information system or organization performs with respect to personally identifiable information across the information life cycle. Processing includes but is not limited to creation, collection, use, processing, storage, maintenance, dissemination, disclosure, and disposal. Processing operations also include logging, generation, and transformation, as well as analysis techniques, such as data mining.\n\nOrganizations may be subject to laws, executive orders, directives, regulations, or policies that establish the organization\u2019s authority and thereby limit certain types of processing of personally identifiable information or establish other requirements related to the processing. Organizational personnel consult with the senior agency official for privacy and legal counsel regarding such authority, particularly if the organization is subject to multiple jurisdictions or sources of authority. For organizations whose processing is not determined according to legal authorities, the organization\u2019s policies and determinations govern how they process personally identifiable information. While processing of personally identifiable information may be legally permissible, privacy risks may still arise. Privacy risk assessments can identify the privacy risks associated with the authorized processing of personally identifiable information and support solutions to manage such risks.\n\nOrganizations consider applicable requirements and organizational policies to determine how to document this authority. For federal agencies, the authority to process personally identifiable information is documented in privacy policies and notices, system of records notices, privacy impact assessments, [PRIVACT](#18e71fec-c6fd-475a-925a-5d8495cf8455) statements, computer matching agreements and notices, contracts, information sharing agreements, memoranda of understanding, and other documentation.\n\nOrganizations take steps to ensure that personally identifiable information is only processed for authorized purposes, including training organizational personnel on the authorized processing of personally identifiable information and monitoring and auditing organizational use of personally identifiable information."
},
{
"id": "pt-2_obj",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-02",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "pt-2_obj.a",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-02a.",
"class": "sp800-53a"
}
],
"prose": "the {{ insert: param, pt-02_odp.01 }} that permits the {{ insert: param, pt-02_odp.02 }} of personally identifiable information is determined and documented;",
"links": [
{
"href": "#pt-2_smt.a",
"rel": "assessment-for"
}
]
},
{
"id": "pt-2_obj.b",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-02b.",
"class": "sp800-53a"
}
],
"prose": "the {{ insert: param, pt-02_odp.03 }} of personally identifiable information is restricted to only that which is authorized.",
"links": [
{
"href": "#pt-2_smt.b",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#pt-2_smt",
"rel": "assessment-for"
}
]
},
{
"id": "pt-2_asm-examine",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "EXAMINE"
},
{
"name": "label",
"value": "PT-02-Examine",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Personally identifiable information processing and transparency policy and procedures\n\nprivacy plan\n\nother relevant documents or records"
}
]
},
{
"id": "pt-2_asm-interview",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "INTERVIEW"
},
{
"name": "label",
"value": "PT-02-Interview",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational personnel with personally identifiable information processing and transparency responsibilities\n\norganizational personnel with information security and privacy responsibilities"
}
]
},
{
"id": "pt-2_asm-test",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "TEST"
},
{
"name": "label",
"value": "PT-02-Test",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational processes for authorizing the processing of personally identifiable information\n\nmechanisms supporting and/or implementing the restriction of personally identifiable information processing"
}
]
}
],
"controls": [
{
"id": "pt-2.1",
"class": "SP800-53-enhancement",
"title": "Data Tagging",
"params": [
{
"id": "pt-02.01_odp.01",
"props": [
{
"name": "alt-identifier",
"value": "pt-2.1_prm_1"
},
{
"name": "label",
"value": "PT-02(01)_ODP[01]",
"class": "sp800-53a"
}
],
"label": "authorized processing",
"guidelines": [
{
"prose": "the authorized processing of personally identifiable information is defined;"
}
]
},
{
"id": "pt-02.01_odp.02",
"props": [
{
"name": "alt-identifier",
"value": "pt-2.1_prm_2"
},
{
"name": "label",
"value": "PT-02(01)_ODP[02]",
"class": "sp800-53a"
}
],
"label": "elements of personally identifiable information",
"guidelines": [
{
"prose": "elements of personally identifiable information to be tagged are defined;"
}
]
}
],
"props": [
{
"name": "label",
"value": "PT-02(01)",
"class": "zero-padded"
},
{
"name": "label",
"value": "PT-2(1)"
},
{
"name": "label",
"value": "PT-02(01)",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "pt-02.01"
},
{
"name": "implementation-level",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "system"
},
{
"name": "contributes-to-assurance",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "true"
}
],
"links": [
{
"href": "#pt-2",
"rel": "required"
},
{
"href": "#ac-16",
"rel": "related"
},
{
"href": "#ca-6",
"rel": "related"
},
{
"href": "#cm-12",
"rel": "related"
},
{
"href": "#pm-5",
"rel": "related"
},
{
"href": "#pm-22",
"rel": "related"
},
{
"href": "#pt-4",
"rel": "related"
},
{
"href": "#sc-16",
"rel": "related"
},
{
"href": "#sc-43",
"rel": "related"
},
{
"href": "#si-10",
"rel": "related"
},
{
"href": "#si-15",
"rel": "related"
},
{
"href": "#si-19",
"rel": "related"
}
],
"parts": [
{
"id": "pt-2.1_smt",
"name": "statement",
"prose": "Attach data tags containing {{ insert: param, pt-02.01_odp.01 }} to {{ insert: param, pt-02.01_odp.02 }}."
},
{
"id": "pt-2.1_gdn",
"name": "guidance",
"prose": "Data tags support the tracking and enforcement of authorized processing by conveying the types of processing that are authorized along with the relevant elements of personally identifiable information throughout the system. Data tags may also support the use of automated tools."
},
{
"id": "pt-2.1_obj",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-02(01)",
"class": "sp800-53a"
}
],
"prose": "data tags containing {{ insert: param, pt-02.01_odp.01 }} are attached to {{ insert: param, pt-02.01_odp.02 }}.",
"links": [
{
"href": "#pt-2.1_smt",
"rel": "assessment-for"
}
]
},
{
"id": "pt-2.1_asm-examine",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "EXAMINE"
},
{
"name": "label",
"value": "PT-02(01)-Examine",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Personally identifiable information processing and transparency policy and procedures including procedures addressing data tagging\n\ndata tag definitions\n\ndocumented requirements for use and monitoring of data tagging\n\ndata extracts with corresponding data tags\n\nprivacy plan\n\nother relevant documents or records"
}
]
},
{
"id": "pt-2.1_asm-interview",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "INTERVIEW"
},
{
"name": "label",
"value": "PT-02(01)-Interview",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational personnel with personally identifiable information processing and transparency responsibilities\n\norganizational personnel with information security and privacy responsibilities"
}
]
},
{
"id": "pt-2.1_asm-test",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "TEST"
},
{
"name": "label",
"value": "PT-02(01)-Test",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational processes for authorizing the processing of personally identifiable information\n\norganizational processes for data tagging\n\nmechanisms for applying and monitoring data tagging\n\nmechanisms supporting and/or implementing the restriction of personally identifiable information processing"
}
]
}
]
},
{
"id": "pt-2.2",
"class": "SP800-53-enhancement",
"title": "Automation",
"params": [
{
"id": "pt-02.02_odp",
"props": [
{
"name": "alt-identifier",
"value": "pt-2.2_prm_1"
},
{
"name": "label",
"value": "PT-02(02)_ODP",
"class": "sp800-53a"
}
],
"label": "automated mechanisms",
"guidelines": [
{
"prose": "automated mechanisms used to manage enforcement of the authorized processing of personally identifiable information are defined;"
}
]
}
],
"props": [
{
"name": "label",
"value": "PT-02(02)",
"class": "zero-padded"
},
{
"name": "label",
"value": "PT-2(2)"
},
{
"name": "label",
"value": "PT-02(02)",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "pt-02.02"
},
{
"name": "implementation-level",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "organization"
},
{
"name": "contributes-to-assurance",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "true"
}
],
"links": [
{
"href": "#pt-2",
"rel": "required"
},
{
"href": "#ca-6",
"rel": "related"
},
{
"href": "#cm-12",
"rel": "related"
},
{
"href": "#pm-5",
"rel": "related"
},
{
"href": "#pm-22",
"rel": "related"
},
{
"href": "#pt-4",
"rel": "related"
},
{
"href": "#sc-16",
"rel": "related"
},
{
"href": "#sc-43",
"rel": "related"
},
{
"href": "#si-10",
"rel": "related"
},
{
"href": "#si-15",
"rel": "related"
},
{
"href": "#si-19",
"rel": "related"
}
],
"parts": [
{
"id": "pt-2.2_smt",
"name": "statement",
"prose": "Manage enforcement of the authorized processing of personally identifiable information using {{ insert: param, pt-02.02_odp }}."
},
{
"id": "pt-2.2_gdn",
"name": "guidance",
"prose": "Automated mechanisms augment verification that only authorized processing is occurring."
},
{
"id": "pt-2.2_obj",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-02(02)",
"class": "sp800-53a"
}
],
"prose": "enforcement of the authorized processing of personally identifiable information is managed using {{ insert: param, pt-02.02_odp }}.",
"links": [
{
"href": "#pt-2.2_smt",
"rel": "assessment-for"
}
]
},
{
"id": "pt-2.2_asm-examine",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "EXAMINE"
},
{
"name": "label",
"value": "PT-02(02)-Examine",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Personally identifiable information processing and transparency policy and procedures\n\nprivacy plan\n\nother relevant documents or records"
}
]
},
{
"id": "pt-2.2_asm-interview",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "INTERVIEW"
},
{
"name": "label",
"value": "PT-02(02)-Interview",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational personnel with personally identifiable information processing and transparency responsibilities\n\norganizational personnel with information security and privacy responsibilities"
}
]
},
{
"id": "pt-2.2_asm-test",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "TEST"
},
{
"name": "label",
"value": "PT-02(02)-Test",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational processes for authorizing the processing of personally identifiable information\n\nautomated mechanisms supporting and/or implementing the management of authorized personally identifiable information processing"
}
]
}
]
}
]
},
{
"id": "pt-3",
"class": "SP800-53",
"title": "Personally Identifiable Information Processing Purposes",
"params": [
{
"id": "pt-03_odp.01",
"props": [
{
"name": "alt-identifier",
"value": "pt-3_prm_1"
},
{
"name": "label",
"value": "PT-03_ODP[01]",
"class": "sp800-53a"
}
],
"label": "purpose(s)",
"guidelines": [
{
"prose": "the purpose(s) for processing personally identifiable information is/are defined;"
}
]
},
{
"id": "pt-03_odp.02",
"props": [
{
"name": "alt-identifier",
"value": "pt-3_prm_2"
},
{
"name": "label",
"value": "PT-03_ODP[02]",
"class": "sp800-53a"
}
],
"label": "processing",
"guidelines": [
{
"prose": "the processing of personally identifiable information to be restricted is defined;"
}
]
},
{
"id": "pt-03_odp.03",
"props": [
{
"name": "alt-identifier",
"value": "pt-3_prm_3"
},
{
"name": "label",
"value": "PT-03_ODP[03]",
"class": "sp800-53a"
}
],
"label": "mechanisms",
"guidelines": [
{
"prose": "mechanisms to be implemented for ensuring any changes in the processing of personally identifiable information are made in accordance with requirements are defined;"
}
]
},
{
"id": "pt-03_odp.04",
"props": [
{
"name": "alt-identifier",
"value": "pt-3_prm_4"
},
{
"name": "label",
"value": "PT-03_ODP[04]",
"class": "sp800-53a"
}
],
"label": "requirements",
"guidelines": [
{
"prose": "requirements for changing the processing of personally identifiable information are defined;"
}
]
}
],
"props": [
{
"name": "label",
"value": "PT-03",
"class": "zero-padded"
},
{
"name": "label",
"value": "PT-3"
},
{
"name": "label",
"value": "PT-03",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "pt-03"
},
{
"name": "implementation-level",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "organization"
}
],
"links": [
{
"href": "#18e71fec-c6fd-475a-925a-5d8495cf8455",
"rel": "reference"
},
{
"href": "#27847491-5ce1-4f6a-a1e4-9e483782f0ef",
"rel": "reference"
},
{
"href": "#a2590922-82f3-4277-83c0-ca5bee06dba4",
"rel": "reference"
},
{
"href": "#ac-2",
"rel": "related"
},
{
"href": "#ac-3",
"rel": "related"
},
{
"href": "#at-3",
"rel": "related"
},
{
"href": "#cm-13",
"rel": "related"
},
{
"href": "#ir-9",
"rel": "related"
},
{
"href": "#pm-9",
"rel": "related"
},
{
"href": "#pm-25",
"rel": "related"
},
{
"href": "#pt-2",
"rel": "related"
},
{
"href": "#pt-5",
"rel": "related"
},
{
"href": "#pt-6",
"rel": "related"
},
{
"href": "#pt-7",
"rel": "related"
},
{
"href": "#ra-8",
"rel": "related"
},
{
"href": "#sc-43",
"rel": "related"
},
{
"href": "#si-12",
"rel": "related"
},
{
"href": "#si-18",
"rel": "related"
}
],
"parts": [
{
"id": "pt-3_smt",
"name": "statement",
"parts": [
{
"id": "pt-3_smt.a",
"name": "item",
"props": [
{
"name": "label",
"value": "a."
}
],
"prose": "Identify and document the {{ insert: param, pt-03_odp.01 }} for processing personally identifiable information;"
},
{
"id": "pt-3_smt.b",
"name": "item",
"props": [
{
"name": "label",
"value": "b."
}
],
"prose": "Describe the purpose(s) in the public privacy notices and policies of the organization;"
},
{
"id": "pt-3_smt.c",
"name": "item",
"props": [
{
"name": "label",
"value": "c."
}
],
"prose": "Restrict the {{ insert: param, pt-03_odp.02 }} of personally identifiable information to only that which is compatible with the identified purpose(s); and"
},
{
"id": "pt-3_smt.d",
"name": "item",
"props": [
{
"name": "label",
"value": "d."
}
],
"prose": "Monitor changes in processing personally identifiable information and implement {{ insert: param, pt-03_odp.03 }} to ensure that any changes are made in accordance with {{ insert: param, pt-03_odp.04 }}."
}
]
},
{
"id": "pt-3_gdn",
"name": "guidance",
"prose": "Identifying and documenting the purpose for processing provides organizations with a basis for understanding why personally identifiable information may be processed. The term \"process\" includes every step of the information life cycle, including creation, collection, use, processing, storage, maintenance, dissemination, disclosure, and disposal. Identifying and documenting the purpose of processing is a prerequisite to enabling owners and operators of the system and individuals whose information is processed by the system to understand how the information will be processed. This enables individuals to make informed decisions about their engagement with information systems and organizations and to manage their privacy interests. Once the specific processing purpose has been identified, the purpose is described in the organization\u2019s privacy notices, policies, and any related privacy compliance documentation, including privacy impact assessments, system of records notices, [PRIVACT](#18e71fec-c6fd-475a-925a-5d8495cf8455) statements, computer matching notices, and other applicable Federal Register notices.\n\nOrganizations take steps to help ensure that personally identifiable information is processed only for identified purposes, including training organizational personnel and monitoring and auditing organizational processing of personally identifiable information.\n\nOrganizations monitor for changes in personally identifiable information processing. Organizational personnel consult with the senior agency official for privacy and legal counsel to ensure that any new purposes that arise from changes in processing are compatible with the purpose for which the information was collected, or if the new purpose is not compatible, implement mechanisms in accordance with defined requirements to allow for the new processing, if appropriate. Mechanisms may include obtaining consent from individuals, revising privacy policies, or other measures to manage privacy risks that arise from changes in personally identifiable information processing purposes."
},
{
"id": "pt-3_obj",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-03",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "pt-3_obj.a",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-03a.",
"class": "sp800-53a"
}
],
"prose": "the {{ insert: param, pt-03_odp.01 }} for processing personally identifiable information is/are identified and documented;",
"links": [
{
"href": "#pt-3_smt.a",
"rel": "assessment-for"
}
]
},
{
"id": "pt-3_obj.b",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-03b.",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "pt-3_obj.b-1",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-03b.[01]",
"class": "sp800-53a"
}
],
"prose": "the purpose(s) is/are described in the public privacy notices of the organization;",
"links": [
{
"href": "#pt-3_smt.b",
"rel": "assessment-for"
}
]
},
{
"id": "pt-3_obj.b-2",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-03b.[02]",
"class": "sp800-53a"
}
],
"prose": "the purpose(s) is/are described in the policies of the organization;",
"links": [
{
"href": "#pt-3_smt.b",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#pt-3_smt.b",
"rel": "assessment-for"
}
]
},
{
"id": "pt-3_obj.c",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-03c.",
"class": "sp800-53a"
}
],
"prose": "the {{ insert: param, pt-03_odp.02 }} of personally identifiable information are restricted to only that which is compatible with the identified purpose(s);",
"links": [
{
"href": "#pt-3_smt.c",
"rel": "assessment-for"
}
]
},
{
"id": "pt-3_obj.d",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-03d.",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "pt-3_obj.d-1",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-03d.[01]",
"class": "sp800-53a"
}
],
"prose": "changes in the processing of personally identifiable information are monitored;",
"links": [
{
"href": "#pt-3_smt.d",
"rel": "assessment-for"
}
]
},
{
"id": "pt-3_obj.d-2",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-03d.[02]",
"class": "sp800-53a"
}
],
"prose": "{{ insert: param, pt-03_odp.03 }} are implemented to ensure that any changes are made in accordance with {{ insert: param, pt-03_odp.04 }}.",
"links": [
{
"href": "#pt-3_smt.d",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#pt-3_smt.d",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#pt-3_smt",
"rel": "assessment-for"
}
]
},
{
"id": "pt-3_asm-examine",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "EXAMINE"
},
{
"name": "label",
"value": "PT-03-Examine",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Personally identifiable information processing and transparency policy and procedures\n\nconfiguration management plan\n\norganizational privacy notices\n\norganizational policies\n\nPrivacy Act statements\n\ncomputer matching notices\n\napplicable Federal Register notices\n\ndocumented requirements for enforcing and monitoring the processing of personally identifiable information\n\nprivacy plan\n\nother relevant documents or records"
}
]
},
{
"id": "pt-3_asm-interview",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "INTERVIEW"
},
{
"name": "label",
"value": "PT-03-Interview",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational personnel with personally identifiable information processing and transparency responsibilities\n\norganizational personnel with information security and privacy responsibilities"
}
]
},
{
"id": "pt-3_asm-test",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "TEST"
},
{
"name": "label",
"value": "PT-03-Test",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational processes for authorizing the processing of personally identifiable information\n\nmechanisms supporting and/or implementing the management of authorized personally identifiable information processing\n\norganizational processes for monitoring changes in processing personally identifiable information"
}
]
}
],
"controls": [
{
"id": "pt-3.1",
"class": "SP800-53-enhancement",
"title": "Data Tagging",
"params": [
{
"id": "pt-03.01_odp.01",
"props": [
{
"name": "alt-identifier",
"value": "pt-3.1_prm_2"
},
{
"name": "label",
"value": "PT-03(01)_ODP[01]",
"class": "sp800-53a"
}
],
"label": "processing purposes",
"guidelines": [
{
"prose": "processing purposes to be contained in data tags are defined;"
}
]
},
{
"id": "pt-03.01_odp.02",
"props": [
{
"name": "alt-identifier",
"value": "pt-3.1_prm_1"
},
{
"name": "label",
"value": "PT-03(01)_ODP[02]",
"class": "sp800-53a"
}
],
"label": "elements of personally identifiable information",
"guidelines": [
{
"prose": "elements of personally identifiable information to be tagged are defined;"
}
]
}
],
"props": [
{
"name": "label",
"value": "PT-03(01)",
"class": "zero-padded"
},
{
"name": "label",
"value": "PT-3(1)"
},
{
"name": "label",
"value": "PT-03(01)",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "pt-03.01"
},
{
"name": "implementation-level",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "system"
},
{
"name": "contributes-to-assurance",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "true"
}
],
"links": [
{
"href": "#pt-3",
"rel": "required"
},
{
"href": "#ca-6",
"rel": "related"
},
{
"href": "#cm-12",
"rel": "related"
},
{
"href": "#pm-5",
"rel": "related"
},
{
"href": "#pm-22",
"rel": "related"
},
{
"href": "#sc-16",
"rel": "related"
},
{
"href": "#sc-43",
"rel": "related"
},
{
"href": "#si-10",
"rel": "related"
},
{
"href": "#si-15",
"rel": "related"
},
{
"href": "#si-19",
"rel": "related"
}
],
"parts": [
{
"id": "pt-3.1_smt",
"name": "statement",
"prose": "Attach data tags containing the following purposes to {{ insert: param, pt-03.01_odp.02 }}: {{ insert: param, pt-03.01_odp.01 }}."
},
{
"id": "pt-3.1_gdn",
"name": "guidance",
"prose": "Data tags support the tracking of processing purposes by conveying the purposes along with the relevant elements of personally identifiable information throughout the system. By conveying the processing purposes in a data tag along with the personally identifiable information as the information transits a system, a system owner or operator can identify whether a change in processing would be compatible with the identified and documented purposes. Data tags may also support the use of automated tools."
},
{
"id": "pt-3.1_obj",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-03(01)",
"class": "sp800-53a"
}
],
"prose": "data tags containing {{ insert: param, pt-03.01_odp.01 }} are attached to {{ insert: param, pt-03.01_odp.02 }}.",
"links": [
{
"href": "#pt-3.1_smt",
"rel": "assessment-for"
}
]
},
{
"id": "pt-3.1_asm-examine",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "EXAMINE"
},
{
"name": "label",
"value": "PT-03(01)-Examine",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Personally identifiable information processing and transparency policy and procedures\n\ndocumented description of how data tags are used to identify personally identifiable information data elements and their authorized uses\n\ndata tag schema\n\ndata extracts with corresponding data tags\n\nprivacy plan\n\nother relevant documents or records"
}
]
},
{
"id": "pt-3.1_asm-interview",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "INTERVIEW"
},
{
"name": "label",
"value": "PT-03(01)-Interview",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational personnel with personally identifiable information processing and transparency responsibilities\n\norganizational personnel with data tagging responsibilities\n\norganizational personnel with information security and privacy responsibilities"
}
]
},
{
"id": "pt-3.1_asm-test",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "TEST"
},
{
"name": "label",
"value": "PT-03(01)-Test",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational processes for authorizing the processing of personally identifiable information\n\nmechanisms supporting and/or implementing data tagging"
}
]
}
]
},
{
"id": "pt-3.2",
"class": "SP800-53-enhancement",
"title": "Automation",
"params": [
{
"id": "pt-03.02_odp",
"props": [
{
"name": "alt-identifier",
"value": "pt-3.2_prm_1"
},
{
"name": "label",
"value": "PT-03(02)_ODP",
"class": "sp800-53a"
}
],
"label": "automated mechanisms",
"guidelines": [
{
"prose": "automated mechanisms for tracking the processing purposes of personally identifiable information are defined;"
}
]
}
],
"props": [
{
"name": "label",
"value": "PT-03(02)",
"class": "zero-padded"
},
{
"name": "label",
"value": "PT-3(2)"
},
{
"name": "label",
"value": "PT-03(02)",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "pt-03.02"
},
{
"name": "implementation-level",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "organization"
},
{
"name": "contributes-to-assurance",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "true"
}
],
"links": [
{
"href": "#pt-3",
"rel": "required"
},
{
"href": "#ca-6",
"rel": "related"
},
{
"href": "#cm-12",
"rel": "related"
},
{
"href": "#pm-5",
"rel": "related"
},
{
"href": "#pm-22",
"rel": "related"
},
{
"href": "#sc-16",
"rel": "related"
},
{
"href": "#sc-43",
"rel": "related"
},
{
"href": "#si-10",
"rel": "related"
},
{
"href": "#si-15",
"rel": "related"
},
{
"href": "#si-19",
"rel": "related"
}
],
"parts": [
{
"id": "pt-3.2_smt",
"name": "statement",
"prose": "Track processing purposes of personally identifiable information using {{ insert: param, pt-03.02_odp }}."
},
{
"id": "pt-3.2_gdn",
"name": "guidance",
"prose": "Automated mechanisms augment tracking of the processing purposes."
},
{
"id": "pt-3.2_obj",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-03(02)",
"class": "sp800-53a"
}
],
"prose": "the processing purposes of personally identifiable information are tracked using {{ insert: param, pt-03.02_odp }}.",
"links": [
{
"href": "#pt-3.2_smt",
"rel": "assessment-for"
}
]
},
{
"id": "pt-3.2_asm-examine",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "EXAMINE"
},
{
"name": "label",
"value": "PT-03(02)-Examine",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Personally identifiable information processing and transparency policy and procedures\n\ndata extracts with corresponding data tags\n\nprivacy plan\n\nother relevant documents or records"
}
]
},
{
"id": "pt-3.2_asm-interview",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "INTERVIEW"
},
{
"name": "label",
"value": "PT-03(02)-Interview",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational personnel with personally identifiable information processing and transparency responsibilities\n\norganizational personnel with information security and privacy responsibilities"
}
]
},
{
"id": "pt-3.2_asm-test",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "TEST"
},
{
"name": "label",
"value": "PT-03(02)-Test",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational processes for managing the enforcement of authorized processing of personally identifiable information\n\nautomated tracking mechanisms"
}
]
}
]
}
]
},
{
"id": "pt-4",
"class": "SP800-53",
"title": "Consent",
"params": [
{
"id": "pt-04_odp",
"props": [
{
"name": "alt-identifier",
"value": "pt-4_prm_1"
},
{
"name": "label",
"value": "PT-04_ODP",
"class": "sp800-53a"
}
],
"label": "tools or mechanisms",
"guidelines": [
{
"prose": "the tools or mechanisms to be implemented for individuals to consent to the processing of their personally identifiable information are defined;"
}
]
}
],
"props": [
{
"name": "label",
"value": "PT-04",
"class": "zero-padded"
},
{
"name": "label",
"value": "PT-4"
},
{
"name": "label",
"value": "PT-04",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "pt-04"
},
{
"name": "implementation-level",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "organization"
}
],
"links": [
{
"href": "#18e71fec-c6fd-475a-925a-5d8495cf8455",
"rel": "reference"
},
{
"href": "#27847491-5ce1-4f6a-a1e4-9e483782f0ef",
"rel": "reference"
},
{
"href": "#737513fa-6758-403f-831d-5ddab5e23cb3",
"rel": "reference"
},
{
"href": "#ac-16",
"rel": "related"
},
{
"href": "#pt-2",
"rel": "related"
},
{
"href": "#pt-5",
"rel": "related"
}
],
"parts": [
{
"id": "pt-4_smt",
"name": "statement",
"prose": "Implement {{ insert: param, pt-04_odp }} for individuals to consent to the processing of their personally identifiable information prior to its collection that facilitate individuals\u2019 informed decision-making."
},
{
"id": "pt-4_gdn",
"name": "guidance",
"prose": "Consent allows individuals to participate in making decisions about the processing of their information and transfers some of the risk that arises from the processing of personally identifiable information from the organization to an individual. Consent may be required by applicable laws, executive orders, directives, regulations, policies, standards, or guidelines. Otherwise, when selecting consent as a control, organizations consider whether individuals can be reasonably expected to understand and accept the privacy risks that arise from their authorization. Organizations consider whether other controls may more effectively mitigate privacy risk either alone or in conjunction with consent. Organizations also consider any demographic or contextual factors that may influence the understanding or behavior of individuals with respect to the processing carried out by the system or organization. When soliciting consent from individuals, organizations consider the appropriate mechanism for obtaining consent, including the type of consent (e.g., opt-in, opt-out), how to properly authenticate and identity proof individuals and how to obtain consent through electronic means. In addition, organizations consider providing a mechanism for individuals to revoke consent once it has been provided, as appropriate. Finally, organizations consider usability factors to help individuals understand the risks being accepted when providing consent, including the use of plain language and avoiding technical jargon."
},
{
"id": "pt-4_obj",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-04",
"class": "sp800-53a"
}
],
"prose": "the {{ insert: param, pt-04_odp }} are implemented for individuals to consent to the processing of their personally identifiable information prior to its collection that facilitate individuals\u2019 informed decision-making.",
"links": [
{
"href": "#pt-4_smt",
"rel": "assessment-for"
}
]
},
{
"id": "pt-4_asm-examine",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "EXAMINE"
},
{
"name": "label",
"value": "PT-04-Examine",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Personally identifiable information processing and transparency policy and procedures\n\nconsent policies and procedures\n\nconsent tools and mechanisms\n\nconsent presentation or display (user interface)\n\nevidence of individuals\u2019 consent\n\nprivacy plan\n\nother relevant documents or records"
}
]
},
{
"id": "pt-4_asm-interview",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "INTERVIEW"
},
{
"name": "label",
"value": "PT-04-Interview",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational personnel with personally identifiable information processing and transparency responsibilities\n\norganizational personnel with information security and privacy responsibilities"
}
]
},
{
"id": "pt-4_asm-test",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "TEST"
},
{
"name": "label",
"value": "PT-04-Test",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational processes for the collection of personally identifiable information\n\nconsent tools or mechanisms for users to authorize the processing of their personally identifiable information\n\nmechanisms implementing consent"
}
]
}
],
"controls": [
{
"id": "pt-4.1",
"class": "SP800-53-enhancement",
"title": "Tailored Consent",
"params": [
{
"id": "pt-04.01_odp",
"props": [
{
"name": "alt-identifier",
"value": "pt-4.1_prm_1"
},
{
"name": "label",
"value": "PT-04(01)_ODP",
"class": "sp800-53a"
}
],
"label": "mechanisms",
"guidelines": [
{
"prose": "tailoring mechanisms for processing selected elements of personally identifiable information permissions are defined;"
}
]
}
],
"props": [
{
"name": "label",
"value": "PT-04(01)",
"class": "zero-padded"
},
{
"name": "label",
"value": "PT-4(1)"
},
{
"name": "label",
"value": "PT-04(01)",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "pt-04.01"
},
{
"name": "implementation-level",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "organization"
}
],
"links": [
{
"href": "#pt-4",
"rel": "required"
},
{
"href": "#pt-2",
"rel": "related"
}
],
"parts": [
{
"id": "pt-4.1_smt",
"name": "statement",
"prose": "Provide {{ insert: param, pt-04.01_odp }} to allow individuals to tailor processing permissions to selected elements of personally identifiable information."
},
{
"id": "pt-4.1_gdn",
"name": "guidance",
"prose": "While some processing may be necessary for the basic functionality of the product or service, other processing may not. In these circumstances, organizations allow individuals to select how specific personally identifiable information elements may be processed. More tailored consent may help reduce privacy risk, increase individual satisfaction, and avoid adverse behaviors, such as abandonment of the product or service."
},
{
"id": "pt-4.1_obj",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-04(01)",
"class": "sp800-53a"
}
],
"prose": "{{ insert: param, pt-04.01_odp }} are provided to allow individuals to tailor processing permissions to selected elements of personally identifiable information.",
"links": [
{
"href": "#pt-4.1_smt",
"rel": "assessment-for"
}
]
},
{
"id": "pt-4.1_asm-examine",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "EXAMINE"
},
{
"name": "label",
"value": "PT-04(01)-Examine",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Personally identifiable information processing and transparency policy and procedures\n\nconsent policies and procedures\n\nconsent tools and mechanisms\n\nconsent presentation or display (user interface)\n\nprivacy plan\n\nother relevant documents or records"
}
]
},
{
"id": "pt-4.1_asm-interview",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "INTERVIEW"
},
{
"name": "label",
"value": "PT-04(01)-Interview",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational personnel with personally identifiable information processing and transparency responsibilities\n\norganizational personnel with user interface or user experience responsibilities\n\norganizational personnel with information security and privacy responsibilities"
}
]
},
{
"id": "pt-4.1_asm-test",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "TEST"
},
{
"name": "label",
"value": "PT-04(01)-Test",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational processes for consenting to the processing of personally identifiable information\n\nconsent tools or mechanisms\n\nmechanisms implementing consent"
}
]
}
]
},
{
"id": "pt-4.2",
"class": "SP800-53-enhancement",
"title": "Just-in-time Consent",
"params": [
{
"id": "pt-04.02_odp.01",
"props": [
{
"name": "alt-identifier",
"value": "pt-4.2_prm_1"
},
{
"name": "label",
"value": "PT-04(02)_ODP[01]",
"class": "sp800-53a"
}
],
"label": "consent mechanisms",
"guidelines": [
{
"prose": "consent mechanisms to be presented to individuals are defined;"
}
]
},
{
"id": "pt-04.02_odp.02",
"props": [
{
"name": "alt-identifier",
"value": "pt-4.2_prm_2"
},
{
"name": "label",
"value": "PT-04(02)_ODP[02]",
"class": "sp800-53a"
}
],
"label": "frequency",
"guidelines": [
{
"prose": "the frequency at which to present consent mechanisms to individuals is defined;"
}
]
},
{
"id": "pt-04.02_odp.03",
"props": [
{
"name": "alt-identifier",
"value": "pt-4.2_prm_3"
},
{
"name": "label",
"value": "PT-04(02)_ODP[03]",
"class": "sp800-53a"
}
],
"label": "personally identifiable information processing",
"guidelines": [
{
"prose": "personally identifiable information processing to be presented in conjunction with organization-defined consent mechanisms is defined;"
}
]
}
],
"props": [
{
"name": "label",
"value": "PT-04(02)",
"class": "zero-padded"
},
{
"name": "label",
"value": "PT-4(2)"
},
{
"name": "label",
"value": "PT-04(02)",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "pt-04.02"
},
{
"name": "implementation-level",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "organization"
}
],
"links": [
{
"href": "#pt-4",
"rel": "required"
},
{
"href": "#pt-2",
"rel": "related"
}
],
"parts": [
{
"id": "pt-4.2_smt",
"name": "statement",
"prose": "Present {{ insert: param, pt-04.02_odp.01 }} to individuals at {{ insert: param, pt-04.02_odp.02 }} and in conjunction with {{ insert: param, pt-04.02_odp.03 }}."
},
{
"id": "pt-4.2_gdn",
"name": "guidance",
"prose": "Just-in-time consent enables individuals to participate in how their personally identifiable information is being processed at the time or in conjunction with specific types of data processing when such participation may be most useful to the individual. Individual assumptions about how personally identifiable information is being processed might not be accurate or reliable if time has passed since the individual last gave consent or the type of processing creates significant privacy risk. Organizations use discretion to determine when to use just-in-time consent and may use supporting information on demographics, focus groups, or surveys to learn more about individuals\u2019 privacy interests and concerns."
},
{
"id": "pt-4.2_obj",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-04(02)",
"class": "sp800-53a"
}
],
"prose": "{{ insert: param, pt-04.02_odp.01 }} are presented to individuals {{ insert: param, pt-04.02_odp.02 }} and in conjunction with {{ insert: param, pt-04.02_odp.03 }}.",
"links": [
{
"href": "#pt-4.2_smt",
"rel": "assessment-for"
}
]
},
{
"id": "pt-4.2_asm-examine",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "EXAMINE"
},
{
"name": "label",
"value": "PT-04(02)-Examine",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Personally identifiable information processing and transparency policy and procedures\n\nconsent policies and procedures\n\nprivacy plan\n\nother relevant documents or records"
}
]
},
{
"id": "pt-4.2_asm-interview",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "INTERVIEW"
},
{
"name": "label",
"value": "PT-04(02)-Interview",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational personnel with personally identifiable information processing and transparency responsibilities\n\norganizational personnel with user interface or user experience responsibilities\n\norganizational personnel with information security and privacy responsibilities"
}
]
},
{
"id": "pt-4.2_asm-test",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "TEST"
},
{
"name": "label",
"value": "PT-04(02)-Test",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational processes for the collection of personally identifiable information\n\nmechanisms for obtaining just-in-time consent from users for the processing of their personally identifiable information\n\nmechanisms implementing just-in-time consent"
}
]
}
]
},
{
"id": "pt-4.3",
"class": "SP800-53-enhancement",
"title": "Revocation",
"params": [
{
"id": "pt-04.03_odp",
"props": [
{
"name": "alt-identifier",
"value": "pt-4.3_prm_1"
},
{
"name": "label",
"value": "PT-04(03)_ODP",
"class": "sp800-53a"
}
],
"label": "tools or mechanisms",
"guidelines": [
{
"prose": "the tools or mechanisms to be implemented for revoking consent to the processing of personally identifiable information are defined;"
}
]
}
],
"props": [
{
"name": "label",
"value": "PT-04(03)",
"class": "zero-padded"
},
{
"name": "label",
"value": "PT-4(3)"
},
{
"name": "label",
"value": "PT-04(03)",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "pt-04.03"
},
{
"name": "implementation-level",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "organization"
}
],
"links": [
{
"href": "#pt-4",
"rel": "required"
},
{
"href": "#pt-2",
"rel": "related"
}
],
"parts": [
{
"id": "pt-4.3_smt",
"name": "statement",
"prose": "Implement {{ insert: param, pt-04.03_odp }} for individuals to revoke consent to the processing of their personally identifiable information."
},
{
"id": "pt-4.3_gdn",
"name": "guidance",
"prose": "Revocation of consent enables individuals to exercise control over their initial consent decision when circumstances change. Organizations consider usability factors in enabling easy-to-use revocation capabilities."
},
{
"id": "pt-4.3_obj",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-04(03)",
"class": "sp800-53a"
}
],
"prose": "the {{ insert: param, pt-04.03_odp }} are implemented for individuals to revoke consent to the processing of their personally identifiable information.",
"links": [
{
"href": "#pt-4.3_smt",
"rel": "assessment-for"
}
]
},
{
"id": "pt-4.3_asm-examine",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "EXAMINE"
},
{
"name": "label",
"value": "PT-04(03)-Examine",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Personally identifiable information processing and transparency policy and procedures\n\nconsent revocation policies and procedures\n\nconsent revocation user interface or user experience\n\nprivacy plan\n\nother relevant documents or records"
}
]
},
{
"id": "pt-4.3_asm-interview",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "INTERVIEW"
},
{
"name": "label",
"value": "PT-04(03)-Interview",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational personnel with personally identifiable information processing and transparency responsibilities\n\norganizational personnel with user interface or user experience responsibilities\n\norganizational personnel with information security and privacy responsibilities"
}
]
},
{
"id": "pt-4.3_asm-test",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "TEST"
},
{
"name": "label",
"value": "PT-04(03)-Test",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational processes for consenting to the processing of personally identifiable information\n\ntools or mechanisms for implementing consent revocation"
}
]
}
]
}
]
},
{
"id": "pt-5",
"class": "SP800-53",
"title": "Privacy Notice",
"params": [
{
"id": "pt-05_odp.01",
"props": [
{
"name": "alt-identifier",
"value": "pt-5_prm_1"
},
{
"name": "label",
"value": "PT-05_ODP[01]",
"class": "sp800-53a"
}
],
"label": "frequency",
"guidelines": [
{
"prose": "the frequency at which a notice is provided to individuals after initial interaction with an organization is defined;"
}
]
},
{
"id": "pt-05_odp.02",
"props": [
{
"name": "alt-identifier",
"value": "pt-5_prm_2"
},
{
"name": "label",
"value": "PT-05_ODP[02]",
"class": "sp800-53a"
}
],
"label": "information",
"guidelines": [
{
"prose": "information to be included with the notice about the processing of personally identifiable information is defined;"
}
]
}
],
"props": [
{
"name": "label",
"value": "PT-05",
"class": "zero-padded"
},
{
"name": "label",
"value": "PT-5"
},
{
"name": "label",
"value": "PT-05",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "pt-05"
},
{
"name": "implementation-level",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "organization"
}
],
"links": [
{
"href": "#18e71fec-c6fd-475a-925a-5d8495cf8455",
"rel": "reference"
},
{
"href": "#27847491-5ce1-4f6a-a1e4-9e483782f0ef",
"rel": "reference"
},
{
"href": "#3671ff20-c17c-44d6-8a88-7de203fa74aa",
"rel": "reference"
},
{
"href": "#pm-20",
"rel": "related"
},
{
"href": "#pm-22",
"rel": "related"
},
{
"href": "#pt-2",
"rel": "related"
},
{
"href": "#pt-3",
"rel": "related"
},
{
"href": "#pt-4",
"rel": "related"
},
{
"href": "#pt-7",
"rel": "related"
},
{
"href": "#ra-3",
"rel": "related"
},
{
"href": "#sc-42",
"rel": "related"
},
{
"href": "#si-18",
"rel": "related"
}
],
"parts": [
{
"id": "pt-5_smt",
"name": "statement",
"prose": "Provide notice to individuals about the processing of personally identifiable information that:",
"parts": [
{
"id": "pt-5_smt.a",
"name": "item",
"props": [
{
"name": "label",
"value": "a."
}
],
"prose": "Is available to individuals upon first interacting with an organization, and subsequently at {{ insert: param, pt-05_odp.01 }};"
},
{
"id": "pt-5_smt.b",
"name": "item",
"props": [
{
"name": "label",
"value": "b."
}
],
"prose": "Is clear and easy-to-understand, expressing information about personally identifiable information processing in plain language;"
},
{
"id": "pt-5_smt.c",
"name": "item",
"props": [
{
"name": "label",
"value": "c."
}
],
"prose": "Identifies the authority that authorizes the processing of personally identifiable information;"
},
{
"id": "pt-5_smt.d",
"name": "item",
"props": [
{
"name": "label",
"value": "d."
}
],
"prose": "Identifies the purposes for which personally identifiable information is to be processed; and"
},
{
"id": "pt-5_smt.e",
"name": "item",
"props": [
{
"name": "label",
"value": "e."
}
],
"prose": "Includes {{ insert: param, pt-05_odp.02 }}."
}
]
},
{
"id": "pt-5_gdn",
"name": "guidance",
"prose": "Privacy notices help inform individuals about how their personally identifiable information is being processed by the system or organization. Organizations use privacy notices to inform individuals about how, under what authority, and for what purpose their personally identifiable information is processed, as well as other information such as choices individuals might have with respect to that processing and other parties with whom information is shared. Laws, executive orders, directives, regulations, or policies may require that privacy notices include specific elements or be provided in specific formats. Federal agency personnel consult with the senior agency official for privacy and legal counsel regarding when and where to provide privacy notices, as well as elements to include in privacy notices and required formats. In circumstances where laws or government-wide policies do not require privacy notices, organizational policies and determinations may require privacy notices and may serve as a source of the elements to include in privacy notices.\n\nPrivacy risk assessments identify the privacy risks associated with the processing of personally identifiable information and may help organizations determine appropriate elements to include in a privacy notice to manage such risks. To help individuals understand how their information is being processed, organizations write materials in plain language and avoid technical jargon."
},
{
"id": "pt-5_obj",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-05",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "pt-5_obj.a",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-05a.",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "pt-5_obj.a-1",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-05a.[01]",
"class": "sp800-53a"
}
],
"prose": "a notice to individuals about the processing of personally identifiable information is provided such that the notice is available to individuals upon first interacting with an organization;",
"links": [
{
"href": "#pt-5_smt.a",
"rel": "assessment-for"
}
]
},
{
"id": "pt-5_obj.a-2",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-05a.[02]",
"class": "sp800-53a"
}
],
"prose": "a notice to individuals about the processing of personally identifiable information is provided such that the notice is subsequently available to individuals {{ insert: param, pt-05_odp.01 }};",
"links": [
{
"href": "#pt-5_smt.a",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#pt-5_smt.a",
"rel": "assessment-for"
}
]
},
{
"id": "pt-5_obj.b",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-05b.",
"class": "sp800-53a"
}
],
"prose": "a notice to individuals about the processing of personally identifiable information is provided that is clear, easy-to-understand, and expresses information about personally identifiable information processing in plain language;",
"links": [
{
"href": "#pt-5_smt.b",
"rel": "assessment-for"
}
]
},
{
"id": "pt-5_obj.c",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-05c.",
"class": "sp800-53a"
}
],
"prose": "a notice to individuals about the processing of personally identifiable information that identifies the authority that authorizes the processing of personally identifiable information is provided;",
"links": [
{
"href": "#pt-5_smt.c",
"rel": "assessment-for"
}
]
},
{
"id": "pt-5_obj.d",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-05d.",
"class": "sp800-53a"
}
],
"prose": "a notice to individuals about the processing of personally identifiable information that identifies the purpose for which personally identifiable information is to be processed is provided;",
"links": [
{
"href": "#pt-5_smt.d",
"rel": "assessment-for"
}
]
},
{
"id": "pt-5_obj.e",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-05e.",
"class": "sp800-53a"
}
],
"prose": "a notice to individuals about the processing of personally identifiable information which includes {{ insert: param, pt-05_odp.02 }} is provided.",
"links": [
{
"href": "#pt-5_smt.e",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#pt-5_smt",
"rel": "assessment-for"
}
]
},
{
"id": "pt-5_asm-examine",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "EXAMINE"
},
{
"name": "label",
"value": "PT-05-Examine",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Personally identifiable information processing and transparency policy and procedures\n\nprivacy notice\n\nPrivacy Act statements\n\nprivacy plan\n\nother relevant documents or records"
}
]
},
{
"id": "pt-5_asm-interview",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "INTERVIEW"
},
{
"name": "label",
"value": "PT-05-Interview",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational personnel with personally identifiable information processing and transparency responsibilities\n\norganizational personnel with user interface or user experience responsibilities\n\norganizational personnel with information security and privacy responsibilities"
}
]
},
{
"id": "pt-5_asm-test",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "TEST"
},
{
"name": "label",
"value": "PT-05-Test",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational processes and implementation support or mechanisms for providing notice to individuals regarding the processing of their personally identifiable information"
}
]
}
],
"controls": [
{
"id": "pt-5.1",
"class": "SP800-53-enhancement",
"title": "Just-in-time Notice",
"params": [
{
"id": "pt-05.01_odp",
"props": [
{
"name": "alt-identifier",
"value": "pt-5.1_prm_1"
},
{
"name": "label",
"value": "PT-05(01)_ODP",
"class": "sp800-53a"
}
],
"label": "frequency",
"guidelines": [
{
"prose": "the frequency at which to present a notice of personally identifiable information processing is defined;"
}
]
}
],
"props": [
{
"name": "label",
"value": "PT-05(01)",
"class": "zero-padded"
},
{
"name": "label",
"value": "PT-5(1)"
},
{
"name": "label",
"value": "PT-05(01)",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "pt-05.01"
},
{
"name": "implementation-level",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "organization"
}
],
"links": [
{
"href": "#pt-5",
"rel": "required"
},
{
"href": "#pm-21",
"rel": "related"
}
],
"parts": [
{
"id": "pt-5.1_smt",
"name": "statement",
"prose": "Present notice of personally identifiable information processing to individuals at a time and location where the individual provides personally identifiable information or in conjunction with a data action, or {{ insert: param, pt-05.01_odp }}."
},
{
"id": "pt-5.1_gdn",
"name": "guidance",
"prose": "Just-in-time notices inform individuals of how organizations process their personally identifiable information at a time when such notices may be most useful to the individuals. Individual assumptions about how personally identifiable information will be processed might not be accurate or reliable if time has passed since the organization last presented notice or the circumstances under which the individual was last provided notice have changed. A just-in-time notice can explain data actions that organizations have identified as potentially giving rise to greater privacy risk for individuals. Organizations can use a just-in-time notice to update or remind individuals about specific data actions as they occur or highlight specific changes that occurred since last presenting notice. A just-in-time notice can be used in conjunction with just-in-time consent to explain what will occur if consent is declined. Organizations use discretion to determine when to use a just-in-time notice and may use supporting information on user demographics, focus groups, or surveys to learn about users\u2019 privacy interests and concerns."
},
{
"id": "pt-5.1_obj",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-05(01)",
"class": "sp800-53a"
}
],
"prose": "a notice of personally identifiable information processing is presented to individuals at a time and location where the individual provides personally identifiable information, in conjunction with a data action, or {{ insert: param, pt-05.01_odp }}.",
"links": [
{
"href": "#pt-5.1_smt",
"rel": "assessment-for"
}
]
},
{
"id": "pt-5.1_asm-examine",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "EXAMINE"
},
{
"name": "label",
"value": "PT-05(01)-Examine",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Personally identifiable information processing and transparency policy and procedures\n\nprivacy notice\n\nprivacy plan\n\nother relevant documents or records"
}
]
},
{
"id": "pt-5.1_asm-interview",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "INTERVIEW"
},
{
"name": "label",
"value": "PT-05(01)-Interview",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational personnel with personally identifiable information processing and transparency responsibilities\n\norganizational personnel with user interface or user experience responsibilities\n\norganizational personnel with information security and privacy responsibilities"
}
]
},
{
"id": "pt-5.1_asm-test",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "TEST"
},
{
"name": "label",
"value": "PT-05(01)-Test",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational processes and implementation support or mechanisms for providing notice to individuals regarding the processing of their personally identifiable information"
}
]
}
]
},
{
"id": "pt-5.2",
"class": "SP800-53-enhancement",
"title": "Privacy Act Statements",
"props": [
{
"name": "label",
"value": "PT-05(02)",
"class": "zero-padded"
},
{
"name": "label",
"value": "PT-5(2)"
},
{
"name": "label",
"value": "PT-05(02)",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "pt-05.02"
},
{
"name": "implementation-level",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "organization"
}
],
"links": [
{
"href": "#pt-5",
"rel": "required"
},
{
"href": "#pt-6",
"rel": "related"
}
],
"parts": [
{
"id": "pt-5.2_smt",
"name": "statement",
"prose": "Include Privacy Act statements on forms that collect information that will be maintained in a Privacy Act system of records, or provide Privacy Act statements on separate forms that can be retained by individuals."
},
{
"id": "pt-5.2_gdn",
"name": "guidance",
"prose": "If a federal agency asks individuals to supply information that will become part of a system of records, the agency is required to provide a [PRIVACT](#18e71fec-c6fd-475a-925a-5d8495cf8455) statement on the form used to collect the information or on a separate form that can be retained by the individual. The agency provides a [PRIVACT](#18e71fec-c6fd-475a-925a-5d8495cf8455) statement in such circumstances regardless of whether the information will be collected on a paper or electronic form, on a website, on a mobile application, over the telephone, or through some other medium. This requirement ensures that the individual is provided with sufficient information about the request for information to make an informed decision on whether or not to respond.\n\n[PRIVACT](#18e71fec-c6fd-475a-925a-5d8495cf8455) statements provide formal notice to individuals of the authority that authorizes the solicitation of the information; whether providing the information is mandatory or voluntary; the principal purpose(s) for which the information is to be used; the published routine uses to which the information is subject; the effects on the individual, if any, of not providing all or any part of the information requested; and an appropriate citation and link to the relevant system of records notice. Federal agency personnel consult with the senior agency official for privacy and legal counsel regarding the notice provisions of the [PRIVACT](#18e71fec-c6fd-475a-925a-5d8495cf8455)."
},
{
"id": "pt-5.2_obj",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-05(02)",
"class": "sp800-53a"
}
],
"prose": "Privacy Act statements are included on forms that collect information that will be maintained in a Privacy Act system of records, or Privacy Act statements are provided on separate forms that can be retained by individuals.",
"links": [
{
"href": "#pt-5.2_smt",
"rel": "assessment-for"
}
]
},
{
"id": "pt-5.2_asm-examine",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "EXAMINE"
},
{
"name": "label",
"value": "PT-05(02)-Examine",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Personally identifiable information processing and transparency policy and procedures\n\nprivacy notice\n\nPrivacy Act system of records\n\nforms that include Privacy Act statements\n\nprivacy plan\n\nother relevant documents or records"
}
]
},
{
"id": "pt-5.2_asm-interview",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "INTERVIEW"
},
{
"name": "label",
"value": "PT-05(02)-Interview",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational personnel with personally identifiable information processing and transparency responsibilities\n\norganizational personnel with information security and privacy responsibilities"
}
]
},
{
"id": "pt-5.2_asm-test",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "TEST"
},
{
"name": "label",
"value": "PT-05(02)-Test",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational processes for including Privacy Act statements on forms that collect information or on separate forms that can be retained by individuals"
}
]
}
]
}
]
},
{
"id": "pt-6",
"class": "SP800-53",
"title": "System of Records Notice",
"props": [
{
"name": "label",
"value": "PT-06",
"class": "zero-padded"
},
{
"name": "label",
"value": "PT-6"
},
{
"name": "label",
"value": "PT-06",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "pt-06"
},
{
"name": "implementation-level",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "organization"
}
],
"links": [
{
"href": "#18e71fec-c6fd-475a-925a-5d8495cf8455",
"rel": "reference"
},
{
"href": "#3671ff20-c17c-44d6-8a88-7de203fa74aa",
"rel": "reference"
},
{
"href": "#ac-3",
"rel": "related"
},
{
"href": "#pm-20",
"rel": "related"
},
{
"href": "#pt-2",
"rel": "related"
},
{
"href": "#pt-3",
"rel": "related"
},
{
"href": "#pt-5",
"rel": "related"
}
],
"parts": [
{
"id": "pt-6_smt",
"name": "statement",
"prose": "For systems that process information that will be maintained in a Privacy Act system of records:",
"parts": [
{
"id": "pt-6_smt.a",
"name": "item",
"props": [
{
"name": "label",
"value": "a."
}
],
"prose": "Draft system of records notices in accordance with OMB guidance and submit new and significantly modified system of records notices to the OMB and appropriate congressional committees for advance review;"
},
{
"id": "pt-6_smt.b",
"name": "item",
"props": [
{
"name": "label",
"value": "b."
}
],
"prose": "Publish system of records notices in the Federal Register; and"
},
{
"id": "pt-6_smt.c",
"name": "item",
"props": [
{
"name": "label",
"value": "c."
}
],
"prose": "Keep system of records notices accurate, up-to-date, and scoped in accordance with policy."
}
]
},
{
"id": "pt-6_gdn",
"name": "guidance",
"prose": "The [PRIVACT](#18e71fec-c6fd-475a-925a-5d8495cf8455) requires that federal agencies publish a system of records notice in the Federal Register upon the establishment and/or modification of a [PRIVACT](#18e71fec-c6fd-475a-925a-5d8495cf8455) system of records. As a general matter, a system of records notice is required when an agency maintains a group of any records under the control of the agency from which information is retrieved by the name of an individual or by some identifying number, symbol, or other identifier. The notice describes the existence and character of the system and identifies the system of records, the purpose(s) of the system, the authority for maintenance of the records, the categories of records maintained in the system, the categories of individuals about whom records are maintained, the routine uses to which the records are subject, and additional details about the system as described in [OMB A-108](#3671ff20-c17c-44d6-8a88-7de203fa74aa)."
},
{
"id": "pt-6_obj",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-06",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "pt-6_obj.a",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-06a.",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "pt-6_obj.a-1",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-06a.[01]",
"class": "sp800-53a"
}
],
"prose": "system of records notices are drafted in accordance with OMB guidance for systems that process information that will be maintained in a Privacy Act system of records;",
"links": [
{
"href": "#pt-6_smt.a",
"rel": "assessment-for"
}
]
},
{
"id": "pt-6_obj.a-2",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-06a.[02]",
"class": "sp800-53a"
}
],
"prose": "new and significantly modified system of records notices are submitted to the OMB and appropriate congressional committees for advance review for systems that process information that will be maintained in a Privacy Act system of records;",
"links": [
{
"href": "#pt-6_smt.a",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#pt-6_smt.a",
"rel": "assessment-for"
}
]
},
{
"id": "pt-6_obj.b",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-06b.",
"class": "sp800-53a"
}
],
"prose": "system of records notices are published in the Federal Register for systems that process information that will be maintained in a Privacy Act system of records;",
"links": [
{
"href": "#pt-6_smt.b",
"rel": "assessment-for"
}
]
},
{
"id": "pt-6_obj.c",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-06c.",
"class": "sp800-53a"
}
],
"prose": "system of records notices are kept accurate, up-to-date, and scoped in accordance with policy for systems that process information that will be maintained in a Privacy Act system of records.",
"links": [
{
"href": "#pt-6_smt.c",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#pt-6_smt",
"rel": "assessment-for"
}
]
},
{
"id": "pt-6_asm-examine",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "EXAMINE"
},
{
"name": "label",
"value": "PT-06-Examine",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Personally identifiable information processing and transparency policy and procedures\n\nprivacy notice\n\nPrivacy Act system of records\n\nFederal Register notices\n\nprivacy plan\n\nother relevant documents or records"
}
]
},
{
"id": "pt-6_asm-interview",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "INTERVIEW"
},
{
"name": "label",
"value": "PT-06-Interview",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational personnel with personally identifiable information processing and transparency responsibilities\n\norganizational personnel with information security and privacy responsibilities"
}
]
},
{
"id": "pt-6_asm-test",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "TEST"
},
{
"name": "label",
"value": "PT-06-Test",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational processes for Privacy Act system of records maintenance"
}
]
}
],
"controls": [
{
"id": "pt-6.1",
"class": "SP800-53-enhancement",
"title": "Routine Uses",
"params": [
{
"id": "pt-06.01_odp",
"props": [
{
"name": "alt-identifier",
"value": "pt-6.1_prm_1"
},
{
"name": "label",
"value": "PT-06(01)_ODP",
"class": "sp800-53a"
}
],
"label": "frequency",
"guidelines": [
{
"prose": "the frequency at which to review all routine uses published in the system of records notice is defined;"
}
]
}
],
"props": [
{
"name": "label",
"value": "PT-06(01)",
"class": "zero-padded"
},
{
"name": "label",
"value": "PT-6(1)"
},
{
"name": "label",
"value": "PT-06(01)",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "pt-06.01"
},
{
"name": "implementation-level",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "organization"
}
],
"links": [
{
"href": "#pt-6",
"rel": "required"
}
],
"parts": [
{
"id": "pt-6.1_smt",
"name": "statement",
"prose": "Review all routine uses published in the system of records notice at {{ insert: param, pt-06.01_odp }} to ensure continued accuracy, and to ensure that routine uses continue to be compatible with the purpose for which the information was collected."
},
{
"id": "pt-6.1_gdn",
"name": "guidance",
"prose": "A [PRIVACT](#18e71fec-c6fd-475a-925a-5d8495cf8455) routine use is a particular kind of disclosure of a record outside of the federal agency maintaining the system of records. A routine use is an exception to the [PRIVACT](#18e71fec-c6fd-475a-925a-5d8495cf8455) prohibition on the disclosure of a record in a system of records without the prior written consent of the individual to whom the record pertains. To qualify as a routine use, the disclosure must be for a purpose that is compatible with the purpose for which the information was originally collected. The [PRIVACT](#18e71fec-c6fd-475a-925a-5d8495cf8455) requires agencies to describe each routine use of the records maintained in the system of records, including the categories of users of the records and the purpose of the use. Agencies may only establish routine uses by explicitly publishing them in the relevant system of records notice."
},
{
"id": "pt-6.1_obj",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-06(01)",
"class": "sp800-53a"
}
],
"prose": "all routine uses published in the system of records notice are reviewed {{ insert: param, pt-06.01_odp }} to ensure continued accuracy, and to ensure that routine uses continue to be compatible with the purpose for which the information was collected.",
"links": [
{
"href": "#pt-6.1_smt",
"rel": "assessment-for"
}
]
},
{
"id": "pt-6.1_asm-examine",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "EXAMINE"
},
{
"name": "label",
"value": "PT-06(01)-Examine",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Personally identifiable information processing and transparency policy and procedures\n\nprivacy notice\n\nPrivacy Act system of records\n\nprivacy plan\n\nother relevant documents or records"
}
]
},
{
"id": "pt-6.1_asm-interview",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "INTERVIEW"
},
{
"name": "label",
"value": "PT-06(01)-Interview",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational personnel with personally identifiable information processing and transparency responsibilities\n\norganizational personnel with information security and privacy responsibilities"
}
]
},
{
"id": "pt-6.1_asm-test",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "TEST"
},
{
"name": "label",
"value": "PT-06(01)-Test",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational processes for reviewing system of records notices"
}
]
}
]
},
{
"id": "pt-6.2",
"class": "SP800-53-enhancement",
"title": "Exemption Rules",
"params": [
{
"id": "pt-06.02_odp",
"props": [
{
"name": "alt-identifier",
"value": "pt-6.2_prm_1"
},
{
"name": "label",
"value": "PT-06(02)_ODP",
"class": "sp800-53a"
}
],
"label": "frequency",
"guidelines": [
{
"prose": "the frequency at which to review all Privacy Act exemptions claimed for the system of records is defined;"
}
]
}
],
"props": [
{
"name": "label",
"value": "PT-06(02)",
"class": "zero-padded"
},
{
"name": "label",
"value": "PT-6(2)"
},
{
"name": "label",
"value": "PT-06(02)",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "pt-06.02"
},
{
"name": "implementation-level",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "organization"
}
],
"links": [
{
"href": "#pt-6",
"rel": "required"
}
],
"parts": [
{
"id": "pt-6.2_smt",
"name": "statement",
"prose": "Review all Privacy Act exemptions claimed for the system of records at {{ insert: param, pt-06.02_odp }} to ensure they remain appropriate and necessary in accordance with law, that they have been promulgated as regulations, and that they are accurately described in the system of records notice."
},
{
"id": "pt-6.2_gdn",
"name": "guidance",
"prose": "The [PRIVACT](#18e71fec-c6fd-475a-925a-5d8495cf8455) includes two sets of provisions that allow federal agencies to claim exemptions from certain requirements in the statute. In certain circumstances, these provisions allow agencies to promulgate regulations to exempt a system of records from select provisions of the [PRIVACT](#18e71fec-c6fd-475a-925a-5d8495cf8455) . At a minimum, organizations\u2019 [PRIVACT](#18e71fec-c6fd-475a-925a-5d8495cf8455) exemption regulations include the specific name(s) of any system(s) of records that will be exempt, the specific provisions of the [PRIVACT](#18e71fec-c6fd-475a-925a-5d8495cf8455) from which the system(s) of records is to be exempted, the reasons for the exemption, and an explanation for why the exemption is both necessary and appropriate."
},
{
"id": "pt-6.2_obj",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-06(02)",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "pt-6.2_obj-1",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-06(02)[01]",
"class": "sp800-53a"
}
],
"prose": "all Privacy Act exemptions claimed for the system of records are reviewed {{ insert: param, pt-06.02_odp }} to ensure that they remain appropriate and necessary in accordance with law;",
"links": [
{
"href": "#pt-6.2_smt",
"rel": "assessment-for"
}
]
},
{
"id": "pt-6.2_obj-2",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-06(02)[02]",
"class": "sp800-53a"
}
],
"prose": "all Privacy Act exemptions claimed for the system of records are reviewed {{ insert: param, pt-06.02_odp }} to ensure that they have been promulgated as regulations;",
"links": [
{
"href": "#pt-6.2_smt",
"rel": "assessment-for"
}
]
},
{
"id": "pt-6.2_obj-3",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-06(02)[03]",
"class": "sp800-53a"
}
],
"prose": "all Privacy Act exemptions claimed for the system of records are reviewed {{ insert: param, pt-06.02_odp }} to ensure that they are accurately described in the system of records notice.",
"links": [
{
"href": "#pt-6.2_smt",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#pt-6.2_smt",
"rel": "assessment-for"
}
]
},
{
"id": "pt-6.2_asm-examine",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "EXAMINE"
},
{
"name": "label",
"value": "PT-06(02)-Examine",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Personally identifiable information processing and transparency policy and procedures\n\nprivacy notice\n\nPrivacy Act system of records\n\nPrivacy Act exemptions\n\nprivacy plan\n\nother relevant documents or records"
}
]
},
{
"id": "pt-6.2_asm-interview",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "INTERVIEW"
},
{
"name": "label",
"value": "PT-06(02)-Interview",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational personnel with personally identifiable information processing and transparency responsibilities\n\norganizational personnel with information security and privacy responsibilities"
}
]
},
{
"id": "pt-6.2_asm-test",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "TEST"
},
{
"name": "label",
"value": "PT-06(02)-Test",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational processes for Privacy Act system of records maintenance"
}
]
}
]
}
]
},
{
"id": "pt-7",
"class": "SP800-53",
"title": "Specific Categories of Personally Identifiable Information",
"params": [
{
"id": "pt-07_odp",
"props": [
{
"name": "alt-identifier",
"value": "pt-7_prm_1"
},
{
"name": "label",
"value": "PT-07_ODP",
"class": "sp800-53a"
}
],
"label": "processing conditions",
"guidelines": [
{
"prose": "processing conditions to be applied for specific categories of personally identifiable information are defined;"
}
]
}
],
"props": [
{
"name": "label",
"value": "PT-07",
"class": "zero-padded"
},
{
"name": "label",
"value": "PT-7"
},
{
"name": "label",
"value": "PT-07",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "pt-07"
},
{
"name": "implementation-level",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "organization"
}
],
"links": [
{
"href": "#18e71fec-c6fd-475a-925a-5d8495cf8455",
"rel": "reference"
},
{
"href": "#27847491-5ce1-4f6a-a1e4-9e483782f0ef",
"rel": "reference"
},
{
"href": "#3671ff20-c17c-44d6-8a88-7de203fa74aa",
"rel": "reference"
},
{
"href": "#c28ae9a8-1121-42a9-a85e-00cfcc9b9a94",
"rel": "reference"
},
{
"href": "#ir-9",
"rel": "related"
},
{
"href": "#pt-2",
"rel": "related"
},
{
"href": "#pt-3",
"rel": "related"
},
{
"href": "#ra-3",
"rel": "related"
}
],
"parts": [
{
"id": "pt-7_smt",
"name": "statement",
"prose": "Apply {{ insert: param, pt-07_odp }} for specific categories of personally identifiable information."
},
{
"id": "pt-7_gdn",
"name": "guidance",
"prose": "Organizations apply any conditions or protections that may be necessary for specific categories of personally identifiable information. These conditions may be required by laws, executive orders, directives, regulations, policies, standards, or guidelines. The requirements may also come from the results of privacy risk assessments that factor in contextual changes that may result in an organizational determination that a particular category of personally identifiable information is particularly sensitive or raises particular privacy risks. Organizations consult with the senior agency official for privacy and legal counsel regarding any protections that may be necessary."
},
{
"id": "pt-7_obj",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-07",
"class": "sp800-53a"
}
],
"prose": "{{ insert: param, pt-07_odp }} are applied for specific categories of personally identifiable information.",
"links": [
{
"href": "#pt-7_smt",
"rel": "assessment-for"
}
]
},
{
"id": "pt-7_asm-examine",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "EXAMINE"
},
{
"name": "label",
"value": "PT-07-Examine",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Personally identifiable information processing and transparency policy and procedures\n\nprivacy notice\n\nPrivacy Act system of records\n\ncomputer matching agreements and notices\n\ncontracts\n\nprivacy information sharing agreements\n\nmemoranda of understanding\n\ngoverning requirements\n\nprivacy plan\n\nother relevant documents or records"
}
]
},
{
"id": "pt-7_asm-interview",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "INTERVIEW"
},
{
"name": "label",
"value": "PT-07-Interview",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational personnel with personally identifiable information processing and transparency responsibilities\n\norganizational personnel with information security and privacy responsibilities"
}
]
},
{
"id": "pt-7_asm-test",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "TEST"
},
{
"name": "label",
"value": "PT-07-Test",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational processes for supporting and/or implementing personally identifiable information processing"
}
]
}
],
"controls": [
{
"id": "pt-7.1",
"class": "SP800-53-enhancement",
"title": "Social Security Numbers",
"props": [
{
"name": "label",
"value": "PT-07(01)",
"class": "zero-padded"
},
{
"name": "label",
"value": "PT-7(1)"
},
{
"name": "label",
"value": "PT-07(01)",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "pt-07.01"
},
{
"name": "implementation-level",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "organization"
}
],
"links": [
{
"href": "#pt-7",
"rel": "required"
},
{
"href": "#ia-4",
"rel": "related"
}
],
"parts": [
{
"id": "pt-7.1_smt",
"name": "statement",
"prose": "When a system processes Social Security numbers:",
"parts": [
{
"id": "pt-7.1_smt.a",
"name": "item",
"props": [
{
"name": "label",
"value": "(a)"
}
],
"prose": "Eliminate unnecessary collection, maintenance, and use of Social Security numbers, and explore alternatives to their use as a personal identifier;"
},
{
"id": "pt-7.1_smt.b",
"name": "item",
"props": [
{
"name": "label",
"value": "(b)"
}
],
"prose": "Do not deny any individual any right, benefit, or privilege provided by law because of such individual\u2019s refusal to disclose his or her Social Security number; and"
},
{
"id": "pt-7.1_smt.c",
"name": "item",
"props": [
{
"name": "label",
"value": "(c)"
}
],
"prose": "Inform any individual who is asked to disclose his or her Social Security number whether that disclosure is mandatory or voluntary, by what statutory or other authority such number is solicited, and what uses will be made of it."
}
]
},
{
"id": "pt-7.1_gdn",
"name": "guidance",
"prose": "Federal law and policy establish specific requirements for organizations\u2019 processing of Social Security numbers. Organizations take steps to eliminate unnecessary uses of Social Security numbers and other sensitive information and observe any particular requirements that apply."
},
{
"id": "pt-7.1_obj",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-07(01)",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "pt-7.1_obj.a",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-07(01)(a)",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "pt-7.1_obj.a-1",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-07(01)(a)[01]",
"class": "sp800-53a"
}
],
"prose": "when a system processes Social Security numbers, the unnecessary collection, maintenance, and use of Social Security numbers are eliminated;",
"links": [
{
"href": "#pt-7.1_smt.a",
"rel": "assessment-for"
}
]
},
{
"id": "pt-7.1_obj.a-2",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-07(01)(a)[02]",
"class": "sp800-53a"
}
],
"prose": "when a system processes Social Security numbers, alternatives to the use of Social Security Numbers as a personal identifier are explored;",
"links": [
{
"href": "#pt-7.1_smt.a",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#pt-7.1_smt.a",
"rel": "assessment-for"
}
]
},
{
"id": "pt-7.1_obj.b",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-07(01)(b)",
"class": "sp800-53a"
}
],
"prose": "when a system processes Social Security numbers, individual rights, benefits, or privileges provided by law are not denied because of an individual\u2019s refusal to disclose their Social Security number;",
"links": [
{
"href": "#pt-7.1_smt.b",
"rel": "assessment-for"
}
]
},
{
"id": "pt-7.1_obj.c",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-07(01)(c)",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "pt-7.1_obj.c-1",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-07(01)(c)[01]",
"class": "sp800-53a"
}
],
"prose": "when a system processes Social Security numbers, any individual who is asked to disclose their Social Security number is informed whether that disclosure is mandatory or voluntary, by what statutory or other authority such number is solicited, and what uses will be made of it;",
"links": [
{
"href": "#pt-7.1_smt.c",
"rel": "assessment-for"
}
]
},
{
"id": "pt-7.1_obj.c-2",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-07(01)(c)[02]",
"class": "sp800-53a"
}
],
"prose": "when a system processes Social Security numbers, any individual who is asked to disclose their Social Security number is informed by what statutory or other authority the number is solicited;",
"links": [
{
"href": "#pt-7.1_smt.c",
"rel": "assessment-for"
}
]
},
{
"id": "pt-7.1_obj.c-3",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-07(01)(c)[03]",
"class": "sp800-53a"
}
],
"prose": "when a system processes Social Security numbers, any individual who is asked to disclose their Social Security number is informed what uses will be made of it.",
"links": [
{
"href": "#pt-7.1_smt.c",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#pt-7.1_smt.c",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#pt-7.1_smt",
"rel": "assessment-for"
}
]
},
{
"id": "pt-7.1_asm-examine",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "EXAMINE"
},
{
"name": "label",
"value": "PT-07(01)-Examine",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Personally identifiable information processing and transparency policy and procedures\n\nprivacy notice\n\nPrivacy Act system of records\n\nprivacy notice\n\nseparate notice regarding the use of Social Security numbers\n\nprivacy plan\n\nother relevant documents or records"
}
]
},
{
"id": "pt-7.1_asm-interview",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "INTERVIEW"
},
{
"name": "label",
"value": "PT-07(01)-Interview",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational personnel with personally identifiable information processing and transparency responsibilities\n\norganizational personnel with information security and privacy responsibilities"
}
]
},
{
"id": "pt-7.1_asm-test",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "TEST"
},
{
"name": "label",
"value": "PT-07(01)-Test",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational processes for identifying, reviewing, and taking action to control the unnecessary use of Social Security numbers\n\nimplementation of an alternative to Social Security numbers as identifiers"
}
]
}
]
},
{
"id": "pt-7.2",
"class": "SP800-53-enhancement",
"title": "First Amendment Information",
"props": [
{
"name": "label",
"value": "PT-07(02)",
"class": "zero-padded"
},
{
"name": "label",
"value": "PT-7(2)"
},
{
"name": "label",
"value": "PT-07(02)",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "pt-07.02"
},
{
"name": "implementation-level",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "organization"
}
],
"links": [
{
"href": "#pt-7",
"rel": "required"
}
],
"parts": [
{
"id": "pt-7.2_smt",
"name": "statement",
"prose": "Prohibit the processing of information describing how any individual exercises rights guaranteed by the First Amendment unless expressly authorized by statute or by the individual or unless pertinent to and within the scope of an authorized law enforcement activity."
},
{
"id": "pt-7.2_gdn",
"name": "guidance",
"prose": "The [PRIVACT](#18e71fec-c6fd-475a-925a-5d8495cf8455) limits agencies\u2019 ability to process information that describes how individuals exercise rights guaranteed by the First Amendment. Organizations consult with the senior agency official for privacy and legal counsel regarding these requirements."
},
{
"id": "pt-7.2_obj",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-07(02)",
"class": "sp800-53a"
}
],
"prose": "the processing of information describing how any individual exercises rights guaranteed by the First Amendment is prohibited unless expressly authorized by statute or by the individual or unless pertinent to and within the scope of an authorized law enforcement activity.",
"links": [
{
"href": "#pt-7.2_smt",
"rel": "assessment-for"
}
]
},
{
"id": "pt-7.2_asm-examine",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "EXAMINE"
},
{
"name": "label",
"value": "PT-07(02)-Examine",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Personally identifiable information processing and transparency policy and procedures\n\nprivacy notice\n\nPrivacy Act system of records\n\nprivacy plan\n\nother relevant documents or records"
}
]
},
{
"id": "pt-7.2_asm-interview",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "INTERVIEW"
},
{
"name": "label",
"value": "PT-07(02)-Interview",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational personnel with personally identifiable information processing and transparency responsibilities\n\norganizational personnel with information security and privacy responsibilities"
}
]
},
{
"id": "pt-7.2_asm-test",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "TEST"
},
{
"name": "label",
"value": "PT-07(02)-Test",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational processes for supporting and/or implementing personally identifiable information processing"
}
]
}
]
}
]
},
{
"id": "pt-8",
"class": "SP800-53",
"title": "Computer Matching Requirements",
"props": [
{
"name": "label",
"value": "PT-08",
"class": "zero-padded"
},
{
"name": "label",
"value": "PT-8"
},
{
"name": "label",
"value": "PT-08",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "pt-08"
},
{
"name": "implementation-level",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "organization"
}
],
"links": [
{
"href": "#18e71fec-c6fd-475a-925a-5d8495cf8455",
"rel": "reference"
},
{
"href": "#94c64e1a-456c-457f-86da-83ac0dfc85ac",
"rel": "reference"
},
{
"href": "#27847491-5ce1-4f6a-a1e4-9e483782f0ef",
"rel": "reference"
},
{
"href": "#3671ff20-c17c-44d6-8a88-7de203fa74aa",
"rel": "reference"
},
{
"href": "#pm-24",
"rel": "related"
}
],
"parts": [
{
"id": "pt-8_smt",
"name": "statement",
"prose": "When a system or organization processes information for the purpose of conducting a matching program:",
"parts": [
{
"id": "pt-8_smt.a",
"name": "item",
"props": [
{
"name": "label",
"value": "a."
}
],
"prose": "Obtain approval from the Data Integrity Board to conduct the matching program;"
},
{
"id": "pt-8_smt.b",
"name": "item",
"props": [
{
"name": "label",
"value": "b."
}
],
"prose": "Develop and enter into a computer matching agreement;"
},
{
"id": "pt-8_smt.c",
"name": "item",
"props": [
{
"name": "label",
"value": "c."
}
],
"prose": "Publish a matching notice in the Federal Register;"
},
{
"id": "pt-8_smt.d",
"name": "item",
"props": [
{
"name": "label",
"value": "d."
}
],
"prose": "Independently verify the information produced by the matching program before taking adverse action against an individual, if required; and"
},
{
"id": "pt-8_smt.e",
"name": "item",
"props": [
{
"name": "label",
"value": "e."
}
],
"prose": "Provide individuals with notice and an opportunity to contest the findings before taking adverse action against an individual."
}
]
},
{
"id": "pt-8_gdn",
"name": "guidance",
"prose": "The [PRIVACT](#18e71fec-c6fd-475a-925a-5d8495cf8455) establishes requirements for federal and non-federal agencies if they engage in a matching program. In general, a matching program is a computerized comparison of records from two or more automated [PRIVACT](#18e71fec-c6fd-475a-925a-5d8495cf8455) systems of records or an automated system of records and automated records maintained by a non-federal agency (or agent thereof). A matching program either pertains to federal benefit programs or federal personnel or payroll records. A federal benefit match is performed to determine or verify eligibility for payments under federal benefit programs or to recoup payments or delinquent debts under federal benefit programs. A matching program involves not just the matching activity itself but also the investigative follow-up and ultimate action, if any."
},
{
"id": "pt-8_obj",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-08",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "pt-8_obj.a",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-08a.",
"class": "sp800-53a"
}
],
"prose": "approval to conduct the matching program is obtained from the Data Integrity Board when a system or organization processes information for the purpose of conducting a matching program;",
"links": [
{
"href": "#pt-8_smt.a",
"rel": "assessment-for"
}
]
},
{
"id": "pt-8_obj.b",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-08b.",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "pt-8_obj.b-1",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-08b.[01]",
"class": "sp800-53a"
}
],
"prose": "a computer matching agreement is developed when a system or organization processes information for the purpose of conducting a matching program;",
"links": [
{
"href": "#pt-8_smt.b",
"rel": "assessment-for"
}
]
},
{
"id": "pt-8_obj.b-2",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-08b.[02]",
"class": "sp800-53a"
}
],
"prose": "a computer matching agreement is entered into when a system or organization processes information for the purpose of conducting a matching program;",
"links": [
{
"href": "#pt-8_smt.b",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#pt-8_smt.b",
"rel": "assessment-for"
}
]
},
{
"id": "pt-8_obj.c",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-08c.",
"class": "sp800-53a"
}
],
"prose": "a matching notice is published in the Federal Register when a system or organization processes information for the purpose of conducting a matching program;",
"links": [
{
"href": "#pt-8_smt.c",
"rel": "assessment-for"
}
]
},
{
"id": "pt-8_obj.d",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-08d.",
"class": "sp800-53a"
}
],
"prose": "the information produced by the matching program is independently verified before taking adverse action against an individual, if required, when a system or organization processes information for the purpose of conducting a matching program;",
"links": [
{
"href": "#pt-8_smt.d",
"rel": "assessment-for"
}
]
},
{
"id": "pt-8_obj.e",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-08e.",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "pt-8_obj.e-1",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-08e.[01]",
"class": "sp800-53a"
}
],
"prose": "individuals are provided with notice when a system or organization processes information for the purpose of conducting a matching program;",
"links": [
{
"href": "#pt-8_smt.e",
"rel": "assessment-for"
}
]
},
{
"id": "pt-8_obj.e-2",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PT-08e.[02]",
"class": "sp800-53a"
}
],
"prose": "individuals are provided with an opportunity to contest the findings before adverse action is taken against them when a system or organization processes information for the purpose of conducting a matching program.",
"links": [
{
"href": "#pt-8_smt.e",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#pt-8_smt.e",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#pt-8_smt",
"rel": "assessment-for"
}
]
},
{
"id": "pt-8_asm-examine",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "EXAMINE"
},
{
"name": "label",
"value": "PT-08-Examine",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Personally identifiable information processing and transparency policy and procedures\n\nprivacy notice\n\nPrivacy Act system of records\n\nFederal Register notices\n\nData Integrity Board determinations\n\ncontracts\n\ninformation sharing agreements\n\nmemoranda of understanding\n\ngoverning requirements\n\nprivacy plan\n\nother relevant documents or records"
}
]
},
{
"id": "pt-8_asm-interview",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "INTERVIEW"
},
{
"name": "label",
"value": "PT-08-Interview",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational personnel with personally identifiable information processing and transparency responsibilities\n\norganizational personnel with information security and privacy responsibilities"
}
]
},
{
"id": "pt-8_asm-test",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "TEST"
},
{
"name": "label",
"value": "PT-08-Test",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational processes for supporting and/or implementing personally identifiable information processing\n\nmatching program"
}
]
}
]
}
]
}
}