id: "SI-12(01)" title: "Limit Personally Identifiable Information Elements" family: "SI" family_name: "System and Information Integrity" sort_id: "si-12.01" priority: "P1" implementation_level: "organization" parent: "SI-12" enhancement: True


Statement

Limit personally identifiable information being processed in the information life cycle to the following elements of personally identifiable information: {{ insert: param, si-12.01_odp }}.

Guidance

Limiting the use of personally identifiable information throughout the information life cycle when the information is not needed for operational purposes helps to reduce the level of privacy risk created by a system. The information life cycle includes information creation, collection, use, processing, storage, maintenance, dissemination, disclosure, and disposition. Risk assessments as well as applicable laws, regulations, and policies can provide useful inputs to determining which elements of personally identifiable information may create risk.

Assessment Objective

personally identifiable information being processed in the information life cycle is limited to {{ insert: param, si-12.01_odp }}.

System and information integrity policy

system and information integrity procedures

personally identifiable information processing policy

personally identifiable information processing procedures

records retention and disposition policy

records retention and disposition procedures

federal laws, Executive Orders, directives, policies, regulations, standards, and operational requirements applicable to limiting personally identifiable information elements

personally identifiable information inventory

system audit records

audit findings

system security plan

privacy plan

privacy program plan

privacy impact assessment

privacy risk assessment documentation

data mapping documentation

other relevant documents or records

Organizational personnel with information and records management, retention, and disposition responsibilities

organizational personnel with security and privacy responsibilities

network administrators

Organizational processes for information management and retention (including limiting personally identifiable information processing)

automated mechanisms supporting and/or implementing limits to personally identifiable information processing