NIST800-PM-25 PM-25 Minimization of Personally Identifiable Information Used in Testing, Training, and Research
NIST800-PM-25 in NIST SP 800-53 Rev 5 (NIST SP 800-53 Rev 5, Release 5.2.0). All NIST SP 800-53 Rev 5 controls held. Open NIST SP 800-53 Rev 5 on the standards site.
The control as we hold it
PM-25 Minimization of Personally Identifiable Information Used in Testing, Training, and Research. a. Develop, document, and implement policies and procedures that address the use of personally identifiable information for internal testing, training, and research; b. Limit or minimize the amount of personally identifiable information used for internal testing, training, and research purposes; c. Authorize the use of personally identifiable information when such information is required for internal testing, training, and research; and d. Review and update policies and procedures [Assignment: organization-defined frequency].
Reviewed and closest counterparts in the other frameworks
Reviewed rows come from a released pair; a closest match is the nearest held text and is not a reviewed row.
SOC 2
- SOC2-CC5.3 CC5.3 Deploying controls through policies and procedures (COSO principle 12) (closest match)
- SOC2-P3.1 P3.1 Collecting personal information consistent with objectives (closest match)
- SOC2-P4.2 P4.2 Retaining personal information (closest match)
- SOC2-P7.1 P7.1 Quality of personal information (closest match)
What an auditor commonly asks for
General guidance for this control area (domain: PM - Program Management), in our words, not a statement of the standard and not binding on an assessor.
- the information-security program plan
- the program oversight records