NIST 800-53 Rev 5

424 controls available

SI-12(1)privacy

Limit Personally Identifiable Information Elements

System and Information Integrity

Control Statement

Limit personally identifiable information being processed in the information life cycle to the following elements of personally identifiable information: {{ insert: param, si-12.01_odp }}.

Discussion

Limiting the use of personally identifiable information throughout the information life cycle when the information is not needed for operational purposes helps to reduce the level of privacy risk created by a system. The information life cycle includes information creation, collection, use, processing, storage, maintenance, dissemination, disclosure, and disposition. Risk assessments as well as applicable laws, regulations, and policies can provide useful inputs to determining which elements of personally identifiable information may create risk.

Framework
NIST SP 800-53 Rev 5
Family
System and Information Integrity
Baselines
privacy

Related Frameworks

30 paths across 2 frameworks
SCF2 mappings
DCH-18.1Minimize Sensitive / Regulated Data
0.50
  • Secure Controls Framework · 2026.2 · scf_strm · related
PRI-05.1Internal Use of Personal Data (PD) For Testing, Training and Research
0.50
  • Secure Controls Framework · 2026.2 · scf_strm · related
CCI28 mappings
CCI-005004
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-005005
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-004425
0.25
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-004426
0.25
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-004427
0.25
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-004428
0.25
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-004429
0.25
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-004430
0.25
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-004431
0.25
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-004432
0.25
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent

+18 more (top 10 by confidence shown)

Related STIGs

1 STIG reach this control through 7 CCIs. Expand a row to see the responsible NICE and O*NET roles.

Network Device

1 STIG