id: "SA-08(33)" title: "Minimization" family: "SA" family_name: "System and Services Acquisition" sort_id: "sa-08.33" priority: "P1" implementation_level: "system" parent: "SA-08" enhancement: True


Statement

Implement the privacy principle of minimization using {{ insert: param, sa-08.33_odp }}.

Guidance

The principle of minimization states that organizations should only process personally identifiable information that is directly relevant and necessary to accomplish an authorized purpose and should only maintain personally identifiable information for as long as is necessary to accomplish the purpose. Organizations have processes in place, consistent with applicable laws and policies, to implement the principle of minimization.

Assessment Objective

the privacy principle of minimization is implemented using {{ insert: param, sa-08.33_odp }}.

System and services acquisition policy

system and services acquisition procedures

personally identifiable information processing policy

procedures addressing the minimization of personally identifiable information in system design

system design documentation

system configuration settings and associated documentation

change control records

information security and privacy requirements and specifications for the system

system security and privacy architecture

system security plan

privacy plan

privacy impact assessment

privacy risk assessment documentation

other relevant documents or records

Organizational personnel with information security and privacy responsibilities

organizational personnel with system specification, design, development, implementation, and modification responsibilities

system developers

Organizational processes for applying the privacy design principle of minimization in system specification, design, development, implementation, and modification

mechanisms supporting the application of the security design principle of sufficient documentation in system specification, design, development, implementation, and modification

mechanisms that enforce security and privacy policy

organizational processes for managing change configuration

mechanisms supporting configuration control