NIST 800-53 Rev 5

424 controls available

SA-8(33)privacy

Minimization

System and Services Acquisition

Control Statement

Implement the privacy principle of minimization using {{ insert: param, sa-08.33_odp }}.

Discussion

The principle of minimization states that organizations should only process personally identifiable information that is directly relevant and necessary to accomplish an authorized purpose and should only maintain personally identifiable information for as long as is necessary to accomplish the purpose. Organizations have processes in place, consistent with applicable laws and policies, to implement the principle of minimization.

Framework
NIST SP 800-53 Rev 5
Family
System and Services Acquisition
Baselines
privacy

Related Frameworks

42 paths across 2 frameworks
SCF3 mappings
DCH-18.2Limit Sensitive / Regulated Data In Testing, Training & Research
0.50
  • Secure Controls Framework · 2026.2 · scf_strm · related
END-13.3Collection Minimization
0.50
  • Secure Controls Framework · 2026.2 · scf_strm · related
PES-06.5Minimize Visitor Personal Data (PD)
0.50
  • Secure Controls Framework · 2026.2 · scf_strm · related
CCI19 mappings
CCI-004780
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-004781
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-004254
0.50
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-004255
0.50
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-004834
0.50
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-004920
0.50
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-004921
0.50
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-004425
0.25
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-004426
0.25
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-004427
0.25
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent

+9 more (top 10 by confidence shown)

Related STIGs

3 STIGs reach this control through 75 CCIs. Expand a row to see the responsible NICE and O*NET roles.

Endpoint Security Management

2 STIGs

Uncategorized

1 STIG