Skip to content

Evidence request lists

NIST SP 800-122

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Data Subject Rights

NISTSP122-3
PII Data Subject Rights and Automated Decision-Making

Honour PII data subject rights including: right of access + rectification + erasure/correction + portability + restriction of processing + objection + automated decision-making protections per Privacy Act 1974 access and amendment + state privacy laws + GDPR equivalence where applicable. Apply Section 4 rights with response timelines (30 days under Privacy Act + 45 days under most state privacy laws). Document Automated Decision-Making (ADM) involving PII with human review + safeguards + right to object.

Artefacts an auditor will ask for
  • Rights request portal
  • Response time tracking
  • ADM register
  • Human review process
  • Privacy Act compliance
Where this commonly fails
  • No rights process
  • Late responses
  • No ADM register
  • Missing human review

Governance and Continuous Monitoring

NISTSP122-8
Continuous Monitoring, Training, and Privacy Programme Governance

Apply Section 8 continuous monitoring of PII controls per NIST SP 800-137 + Information Security Continuous Monitoring (ISCM) + privacy continuous monitoring (PCM) integration. Conduct training and awareness programmes including role-based privacy training + annual refreshers + management body training. Designate Privacy Officer (Federal Chief Privacy Officer or Senior Agency Official for Privacy SAOP) per OMB M-22-09. Maintain Records of Processing Activities + Data Protection Impact Assessments + regulatory reporting + compliance monitoring + privacy budget + accountability per OMB Circular A-130.

Artefacts an auditor will ask for
  • ISCM/PCM strategy
  • Annual training
  • SAOP appointment
  • Privacy budget
  • OMB A-130 compliance
Where this commonly fails
  • No continuous monitoring
  • Missing training
  • No SAOP
  • Weak governance

Incident Response

NISTSP122-6
PII Breach Response and Incident Handling

Implement Section 6 PII breach response including: incident response for PII breaches + breach notification process per OMB Circular A-130 + OMB M-17-12 (federal civilian) + state breach notification laws + GDPR Article 33-34 + post-incident analysis and lessons learned. Notify US-CERT and CISA within 1 hour for federal civilian agencies. Notify affected individuals within 60 days for federal civilian (varies by state and statute). Coordinate with Privacy Officer + Office of General Counsel + Office of Public Affairs + Office of Inspector General.

Artefacts an auditor will ask for
  • IR plan for PII
  • US-CERT notification capability
  • Affected individual notification template
  • Post-incident reports
  • OMB M-17-12 compliance
Where this commonly fails
  • No IR plan
  • Late notification
  • No post-incident analysis
  • No OMB compliance

Minimisation and De-Identification

NISTSP122-4
PII Minimisation, Purpose Limitation, and Pseudonymisation

Apply Section 4.2-4.5 PII minimisation principles: collect only PII necessary + purpose limitation + storage limitation + accuracy + record retention per NARA schedule + secure disposal. Implement Section 5 de-identification techniques: pseudonymisation + anonymisation + aggregation + suppression + masking + differential privacy + k-anonymity + l-diversity + t-closeness + synthetic data generation. Reference NIST IR 8053 De-Identification of Personal Information + NIST SP 800-188 De-Identifying Government Datasets + NIST IR 8214A Threshold Schemes.

Artefacts an auditor will ask for
  • Minimisation justification
  • NARA retention schedule
  • De-identification techniques
  • Pseudonymisation deployment
  • NIST IR 8053 alignment
Where this commonly fails
  • No minimisation
  • Excessive retention
  • No de-identification
  • Weak pseudonymisation

Notice and Consent

NISTSP122-2
PII Privacy Notice, Consent, and Lawful Processing

Provide PII privacy notice per Section 4.1 + Privacy Act 1974 + e-Government Act 2002 + OMB Circular A-130 + agency System of Records Notice (SORN) covering: authority + purpose + routine uses + disclosure + retention + Privacy Act statement on collection forms. Obtain consent where required. Establish lawful basis for processing (statutory + regulatory + contractual + consent). Apply Fair Information Practice Principles (FIPPs) including transparency + individual participation + purpose specification + data minimisation + use limitation + data quality and integrity + security + accountability.

Artefacts an auditor will ask for
  • Privacy notice
  • System of Records Notice (SORN)
  • Consent records
  • FIPPs implementation matrix
  • Annual review
Where this commonly fails
  • No notice
  • Missing SORN
  • No consent records
  • Weak FIPPs

Scope and PIA

NISTSP122-1
Scope, PII Definition, and PII Confidentiality Impact Analysis

Comply with NIST Special Publication 800-122 Guide to Protecting the Confidentiality of Personally Identifiable Information (PII) published April 2010 + revision under development 2024-2025. Establish PII definition per OMB M-07-16 + GAO 08-536 (information about an individual that can identify or be linked to a specific individual including name + SSN + driver license + biometric data + financial accounts + email + phone). Conduct PII Confidentiality Impact Analysis (PCIA) per Section 3 to categorise PII impact (Low + Moderate + High) based on identifiability + quantity + data field sensitivity + context of use + obligation to protect + access to + location.

Artefacts an auditor will ask for
  • PII inventory
  • PCIA per PII system
  • Impact categorisation matrix
  • OMB M-07-16 compliance
  • Annual review
Where this commonly fails
  • No PII inventory
  • Missing PCIA
  • Wrong impact categorisation
  • No annual review

Security Controls

NISTSP122-5
PII Security Controls - Encryption, Access Control, Storage, Audit

Apply Section 5 PII security controls aligned with NIST SP 800-53 PII-related controls: access control (AC family) including least privilege + role-based access + separation of duties; encryption of PII at rest (FIPS 140-3 + AES-256 + PQC migration per FIPS 203/204/205) and in transit (TLS 1.3); storage confidentiality including secure cloud + encrypted databases + tokenisation; auditing and accountability (AU family) including logging + monitoring + log retention; media protection (MP family) including secure handling + disposal + sanitisation per NIST SP 800-88.

Artefacts an auditor will ask for
  • Access control matrix
  • Encryption inventory
  • Audit log policy
  • Media disposal records
  • NIST SP 800-88 compliance
Where this commonly fails
  • Weak access controls
  • No encryption
  • Missing audit logs
  • No sanitisation

Sharing and Transfers

NISTSP122-7
PII Sharing, Cross-Border Transfers, and Third-Party Agreements

Apply Section 7 PII sharing controls including: information sharing agreements (ISA) + memoranda of understanding (MOU) + computer matching agreements per Computer Matching and Privacy Protection Act of 1988; cross-border transfer safeguards per FTC Section 5 + APEC CBPR + EU-US Data Privacy Framework + Standard Contractual Clauses + Binding Corporate Rules where applicable; data processing agreements (DPA) with vendors + processors + third parties + cloud providers per FedRAMP + StateRAMP + DoD Impact Levels. Conduct Privacy Impact Assessment (PIA) prior to sharing per E-Government Act 2002.

Artefacts an auditor will ask for
  • ISA/MOU register
  • Computer matching agreements
  • Cross-border transfer mechanisms
  • DPA template
  • PIA per system
Where this commonly fails
  • No ISA
  • Missing PIAs
  • Weak DPAs
  • No cross-border controls
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the NIST SP 800-122 framework page.