NIST 800-53 Rev 5

424 controls available

AT-3(5)privacy

Processing Personally Identifiable Information

Awareness and Training

Control Statement

Provide {{ insert: param, at-03.05_odp.01 }} with initial and {{ insert: param, at-03.05_odp.02 }} training in the employment and operation of personally identifiable information processing and transparency controls.

Discussion

Personally identifiable information processing and transparency controls include the organization’s authority to process personally identifiable information and personally identifiable information processing purposes. Role-based training for federal agencies addresses the types of information that may constitute personally identifiable information and the risks, considerations, and obligations associated with its processing. Such training also considers the authority to process personally identifiable information documented in privacy policies and notices, system of records notices, computer matching agreements and notices, privacy impact assessments, [PRIVACT](#18e71fec-c6fd-475a-925a-5d8495cf8455) statements, contracts, information sharing agreements, memoranda of understanding, and/or other documentation.

Framework
NIST SP 800-53 Rev 5
Family
Awareness and Training
Baselines
privacy

Related Frameworks

4 paths across 2 frameworks
SCF1 mapping
SAT-03.3Sensitive / Regulated Data Storage, Handling & Processing
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
CCI3 mappings
CCI-003791
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003792
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003793
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent

Related STIGs

2 STIGs reach this control through 27 CCIs. Expand a row to see the responsible NICE and O*NET roles.

Web / Application Server

2 STIGs