Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

NIST SP 800-53 Learning Center

PM-20 — Dissemination of Privacy Program Information

Read the official control and assessment content, then use the separately labeled Bare Metal Cyber perspective to connect the requirement to implementation, evidence, and sustained operation.

1Enhancements
0Parameters
1Baseline memberships
3Assessment methods

PM — Program Management · NIST SP 800-53 Release 5.2.0

Privacy
Official NIST control content

Control statement

Maintain a central resource webpage on the organization’s principal public website that serves as a central source of information about the organization’s privacy program and that:

  1. a.Ensures that the public has access to information about organizational privacy activities and can communicate with its senior agency official for privacy;
  2. b.Ensures that organizational privacy practices and reports are publicly available; and
  3. c.Employs publicly facing email addresses and/or phone lines to enable the public to provide feedback and/or direct questions to privacy offices regarding privacy practices.
Official NIST discussion

Discussion

For federal agencies, the webpage is located at www.[agency].gov/privacy. Federal agencies include public privacy impact assessments, system of records notices, computer matching notices and agreements, [PRIVACT](#18e71fec-c6fd-475a-925a-5d8495cf8455) exemption and implementation rules, privacy reports, privacy policies, instructions for individuals making an access or amendment request, email addresses for questions/complaints, blogs, and periodic publications.

Original Bare Metal Cyber perspective

From control text to operational evidence

Use Dissemination of Privacy Program Information as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to enterprise program governance, accountability, resources, metrics, and organization-wide risk decisions.

Implementation workflow

  • Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
  • Resolve each organization-defined parameter before declaring the control implemented.
  • Document how the implementation satisfies every clause of the official control statement.
  • Collect evidence as a normal byproduct of operation rather than only before an assessment.
  • Review exceptions, changes, and monitoring results on a risk-based cadence.

Evidence examples

  • program charters and policies
  • governance meeting records
  • risk and performance metrics
  • resource and responsibility assignments

Common failure patterns

  • program metrics count activity instead of outcomes
  • system-level risks never reach enterprise governance
  • responsibilities assigned without authority or resources
  • privacy and security managed in separate silos

Questions practitioners should ask

  • What risk decision is this control intended to support in this system?
  • Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
  • Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
  • What event or threshold requires the implementation to be reviewed or changed?
Official NIST SP 800-53A content

Assessment objectives and methods

Show the assessment objective
  1. PM-20[01]a central resource webpage is maintained on the organization’s principal public website;
  2. PM-20[02]the webpage serves as a central source of information about the organization’s privacy program;
  3. PM-20a.
    1. PM-20a.[01]the webpage ensures that the public has access to information about organizational privacy activities;
    2. PM-20a.[02]the webpage ensures that the public can communicate with its senior agency official for privacy;
  4. PM-20b.
    1. PM-20b.[01]the webpage ensures that organizational privacy practices are publicly available;
    2. PM-20b.[02]the webpage ensures that organizational privacy reports are publicly available;
  5. PM-20c.the webpage employs publicly facing email addresses and/or phone numbers to enable the public to provide feedback and/or direct questions to privacy offices regarding privacy practices.

Examine

  • Public website
  • publicly posted privacy program documents, including policies, procedures, plans, and reports
  • position description of the senior agency official for privacy
  • public privacy notices, including Federal Register notices
  • privacy impact assessments
  • privacy risk assessments
  • Privacy Act statements and system of records notices
  • computer matching agreements and notices
  • other relevant documents or records

Interview

  • Organizational personnel with privacy program information dissemination responsibilities
  • organizational personnel with privacy responsibilities

Test

  • Location, access, availability, and functionality of privacy resource webpage
Official relationships

Related controls

These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.

Official NIST enhancements

Control enhancements

Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.

Official NIST control enhancement

PM-20(1) — Privacy Policies on Websites, Applications, and Digital Services

Privacy

Develop and post privacy policies on all external-facing websites, mobile applications, and other digital services, that:

  1. (a)Are written in plain language and organized in a way that is easy to understand and navigate;
  2. (b)Provide information needed by the public to make an informed decision about whether and how to interact with the organization; and
  3. (c)Are updated whenever the organization makes a substantive change to the practices it describes and includes a time/date stamp to inform the public of the date of the most recent changes.
Official discussion

Organizations post privacy policies on all external-facing websites, mobile applications, and other digital services. Organizations post a link to the relevant privacy policy on any known, major entry points to the website, application, or digital service. In addition, organizations provide a link to the privacy policy on any webpage that collects personally identifiable information. Organizations may be subject to applicable laws, executive orders, directives, regulations, or policies that require the provision of specific information to the public. Organizational personnel consult with the senior agency official for privacy and legal counsel regarding such requirements.

Assessment objectives and methods
  1. PM-20(01)[01]privacy policies are developed and posted on all external-facing websites;
  2. PM-20(01)[02]privacy policies are developed and posted on all mobile applications;
  3. PM-20(01)[03]privacy policies are developed and posted on all other digital services;
  4. PM-20(01)(a)
    1. PM-20(01)(a)[01]the privacy policies are written in plain language;
    2. PM-20(01)(a)[02]the privacy policies are organized in a way that is easy to understand and navigate;
  5. PM-20(01)(b)
    1. PM-20(01)(b)[01]the privacy policies provide the information needed by the public to make an informed decision about whether to interact with the organization;
    2. PM-20(01)(b)[02]the privacy policies provide the information needed by the public to make an informed decision about how to interact with the organization;
  6. PM-20(01)(c)
    1. PM-20(01)(c)[01]the privacy policies are updated whenever the organization makes a substantive change to the practices it describes;
    2. PM-20(01)(c)[02]the privacy policies include a time/date stamp to inform the public of the date of the most recent changes.

Examine

  • Privacy program plan
  • privacy policies on the agency website, mobile applications, and/or other digital services

Interview

  • Organizational personnel with privacy program information dissemination responsibilities
  • organizational personnel with privacy responsibilities

Test

  • Organizational procedures and practices for authorizing, conducting, managing, and reviewing personally identifiable information processing
  • organizational procedures and practices for disseminating privacy program information
  • mechanisms supporting the dissemination of privacy program information
Source record

Authoritative sources