id: "SI-12(02)" title: "Minimize Personally Identifiable Information in Testing, Training, and Research" family: "SI" family_name: "System and Information Integrity" sort_id: "si-12.02" priority: "P1" implementation_level: "organization" parent: "SI-12" enhancement: True
Statement
Use the following techniques to minimize the use of personally identifiable information for research, testing, or training: {{ insert: param, si-12.2_prm_1 }}.
Guidance
Organizations can minimize the risk to an individual’s privacy by employing techniques such as de-identification or synthetic data. Limiting the use of personally identifiable information throughout the information life cycle when the information is not needed for research, testing, or training helps reduce the level of privacy risk created by a system. Risk assessments as well as applicable laws, regulations, and policies can provide useful inputs to determining the techniques to use and when to use them.
Assessment Objective: {{ insert: param, si-12.02_odp.01 }} are used to minimize the use of personally identifiable information for research;
Assessment Objective: {{ insert: param, si-12.02_odp.02 }} are used to minimize the use of personally identifiable information for testing;
Assessment Objective: {{ insert: param, si-12.02_odp.03 }} are used to minimize the use of personally identifiable information for training.
System and information integrity policy
system and information integrity procedures
personally identifiable information processing policy
personally identifiable information processing procedures
federal laws, Executive Orders, directives, policies, regulations, standards, and operational requirements applicable to minimizing the use of personally identifiable information in testing, training, and research
policy for the minimization of personally identifiable information used in testing, training, and research
procedures for the minimization of personally identifiable information used in testing, training, and research
documentation supporting minimization policy implementation (e.g., templates for testing, training, and research)
data sets used for testing, training, and research
system security plan
privacy plan
privacy impact assessment
privacy risk assessment documentation
other relevant documents or records
Organizational personnel with information and records management, retention, and disposition responsibilities
organizational personnel with information security and privacy responsibilities
network administrators
system developers
personnel with IRB responsibilities
Organizational processes for the minimization of personally identifiable information used in testing, training, and research
automated mechanisms supporting and/or implementing the minimization of personally identifiable information used in testing, training, and research