id: "SI-12(01)" title: "Limit Personally Identifiable Information Elements" family: "SI" family_name: "System and Information Integrity" sort_id: "si-12.01" priority: "P1" implementation_level: "organization" parent: "SI-12" enhancement: True
Statement
Limit personally identifiable information being processed in the information life cycle to the following elements of personally identifiable information: {{ insert: param, si-12.01_odp }}.
Guidance
Limiting the use of personally identifiable information throughout the information life cycle when the information is not needed for operational purposes helps to reduce the level of privacy risk created by a system. The information life cycle includes information creation, collection, use, processing, storage, maintenance, dissemination, disclosure, and disposition. Risk assessments as well as applicable laws, regulations, and policies can provide useful inputs to determining which elements of personally identifiable information may create risk.
Assessment Objective
personally identifiable information being processed in the information life cycle is limited to {{ insert: param, si-12.01_odp }}.
System and information integrity policy
system and information integrity procedures
personally identifiable information processing policy
personally identifiable information processing procedures
records retention and disposition policy
records retention and disposition procedures
federal laws, Executive Orders, directives, policies, regulations, standards, and operational requirements applicable to limiting personally identifiable information elements
personally identifiable information inventory
system audit records
audit findings
system security plan
privacy plan
privacy program plan
privacy impact assessment
privacy risk assessment documentation
data mapping documentation
other relevant documents or records
Organizational personnel with information and records management, retention, and disposition responsibilities
organizational personnel with security and privacy responsibilities
network administrators
Organizational processes for information management and retention (including limiting personally identifiable information processing)
automated mechanisms supporting and/or implementing limits to personally identifiable information processing