NIST SP 800-122
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Data Subject Rights
Honour PII data subject rights including: right of access + rectification + erasure/correction + portability + restriction of processing + objection + automated decision-making protections per Privacy Act 1974 access and amendment + state privacy laws + GDPR equivalence where applicable. Apply Section 4 rights with response timelines (30 days under Privacy Act + 45 days under most state privacy laws). Document Automated Decision-Making (ADM) involving PII with human review + safeguards + right to object.
- Rights request portal
- Response time tracking
- ADM register
- Human review process
- Privacy Act compliance
- No rights process
- Late responses
- No ADM register
- Missing human review
Governance and Continuous Monitoring
Apply Section 8 continuous monitoring of PII controls per NIST SP 800-137 + Information Security Continuous Monitoring (ISCM) + privacy continuous monitoring (PCM) integration. Conduct training and awareness programmes including role-based privacy training + annual refreshers + management body training. Designate Privacy Officer (Federal Chief Privacy Officer or Senior Agency Official for Privacy SAOP) per OMB M-22-09. Maintain Records of Processing Activities + Data Protection Impact Assessments + regulatory reporting + compliance monitoring + privacy budget + accountability per OMB Circular A-130.
- ISCM/PCM strategy
- Annual training
- SAOP appointment
- Privacy budget
- OMB A-130 compliance
- No continuous monitoring
- Missing training
- No SAOP
- Weak governance
Incident Response
Implement Section 6 PII breach response including: incident response for PII breaches + breach notification process per OMB Circular A-130 + OMB M-17-12 (federal civilian) + state breach notification laws + GDPR Article 33-34 + post-incident analysis and lessons learned. Notify US-CERT and CISA within 1 hour for federal civilian agencies. Notify affected individuals within 60 days for federal civilian (varies by state and statute). Coordinate with Privacy Officer + Office of General Counsel + Office of Public Affairs + Office of Inspector General.
- IR plan for PII
- US-CERT notification capability
- Affected individual notification template
- Post-incident reports
- OMB M-17-12 compliance
- No IR plan
- Late notification
- No post-incident analysis
- No OMB compliance
Minimisation and De-Identification
Apply Section 4.2-4.5 PII minimisation principles: collect only PII necessary + purpose limitation + storage limitation + accuracy + record retention per NARA schedule + secure disposal. Implement Section 5 de-identification techniques: pseudonymisation + anonymisation + aggregation + suppression + masking + differential privacy + k-anonymity + l-diversity + t-closeness + synthetic data generation. Reference NIST IR 8053 De-Identification of Personal Information + NIST SP 800-188 De-Identifying Government Datasets + NIST IR 8214A Threshold Schemes.
- Minimisation justification
- NARA retention schedule
- De-identification techniques
- Pseudonymisation deployment
- NIST IR 8053 alignment
- No minimisation
- Excessive retention
- No de-identification
- Weak pseudonymisation
Notice and Consent
Provide PII privacy notice per Section 4.1 + Privacy Act 1974 + e-Government Act 2002 + OMB Circular A-130 + agency System of Records Notice (SORN) covering: authority + purpose + routine uses + disclosure + retention + Privacy Act statement on collection forms. Obtain consent where required. Establish lawful basis for processing (statutory + regulatory + contractual + consent). Apply Fair Information Practice Principles (FIPPs) including transparency + individual participation + purpose specification + data minimisation + use limitation + data quality and integrity + security + accountability.
- Privacy notice
- System of Records Notice (SORN)
- Consent records
- FIPPs implementation matrix
- Annual review
- No notice
- Missing SORN
- No consent records
- Weak FIPPs
Scope and PIA
Comply with NIST Special Publication 800-122 Guide to Protecting the Confidentiality of Personally Identifiable Information (PII) published April 2010 + revision under development 2024-2025. Establish PII definition per OMB M-07-16 + GAO 08-536 (information about an individual that can identify or be linked to a specific individual including name + SSN + driver license + biometric data + financial accounts + email + phone). Conduct PII Confidentiality Impact Analysis (PCIA) per Section 3 to categorise PII impact (Low + Moderate + High) based on identifiability + quantity + data field sensitivity + context of use + obligation to protect + access to + location.
- PII inventory
- PCIA per PII system
- Impact categorisation matrix
- OMB M-07-16 compliance
- Annual review
- No PII inventory
- Missing PCIA
- Wrong impact categorisation
- No annual review
Security Controls
Apply Section 5 PII security controls aligned with NIST SP 800-53 PII-related controls: access control (AC family) including least privilege + role-based access + separation of duties; encryption of PII at rest (FIPS 140-3 + AES-256 + PQC migration per FIPS 203/204/205) and in transit (TLS 1.3); storage confidentiality including secure cloud + encrypted databases + tokenisation; auditing and accountability (AU family) including logging + monitoring + log retention; media protection (MP family) including secure handling + disposal + sanitisation per NIST SP 800-88.
- Access control matrix
- Encryption inventory
- Audit log policy
- Media disposal records
- NIST SP 800-88 compliance
- Weak access controls
- No encryption
- Missing audit logs
- No sanitisation
Sharing and Transfers
Apply Section 7 PII sharing controls including: information sharing agreements (ISA) + memoranda of understanding (MOU) + computer matching agreements per Computer Matching and Privacy Protection Act of 1988; cross-border transfer safeguards per FTC Section 5 + APEC CBPR + EU-US Data Privacy Framework + Standard Contractual Clauses + Binding Corporate Rules where applicable; data processing agreements (DPA) with vendors + processors + third parties + cloud providers per FedRAMP + StateRAMP + DoD Impact Levels. Conduct Privacy Impact Assessment (PIA) prior to sharing per E-Government Act 2002.
- ISA/MOU register
- Computer matching agreements
- Cross-border transfer mechanisms
- DPA template
- PIA per system
- No ISA
- Missing PIAs
- Weak DPAs
- No cross-border controls
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the NIST SP 800-122 framework page.