Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

NIST SP 800-53 Learning Center

PM-22 — Personally Identifiable Information Quality Management

Read the official control and assessment content, then use the separately labeled Bare Metal Cyber perspective to connect the requirement to implementation, evidence, and sustained operation.

0Enhancements
0Parameters
1Baseline memberships
3Assessment methods

PM — Program Management · NIST SP 800-53 Release 5.2.0

Privacy
Official NIST control content

Control statement

Develop and document organization-wide policies and procedures for:

  1. a.Reviewing for the accuracy, relevance, timeliness, and completeness of personally identifiable information across the information life cycle;
  2. b.Correcting or deleting inaccurate or outdated personally identifiable information;
  3. c.Disseminating notice of corrected or deleted personally identifiable information to individuals or other appropriate entities; and
  4. d.Appeals of adverse decisions on correction or deletion requests.
Official NIST discussion

Discussion

Personally identifiable information quality management includes steps that organizations take to confirm the accuracy and relevance of personally identifiable information throughout the information life cycle. The information life cycle includes the creation, collection, use, processing, storage, maintenance, dissemination, disclosure, and disposition of personally identifiable information. Organizational policies and procedures for personally identifiable information quality management are important because inaccurate or outdated personally identifiable information maintained by organizations may cause problems for individuals. Organizations consider the quality of personally identifiable information involved in business functions where inaccurate information may result in adverse decisions or the denial of benefits and services, or the disclosure of the information may cause stigmatization. Correct information, in certain circumstances, can cause problems for individuals that outweigh the benefits of organizations maintaining the information. Organizations consider creating policies and procedures for the removal of such information. The senior agency official for privacy ensures that practical means and mechanisms exist and are accessible for individuals or their authorized representatives to seek the correction or deletion of personally identifiable information. Processes for correcting or deleting data are clearly defined and publicly available. Organizations use discretion in determining whether data is to be deleted or corrected based on the scope of requests, the changes sought, and the impact of the changes. Additionally, processes include the provision of responses to individuals of decisions to deny requests for correction or deletion. The responses include the reasons for the decisions, a means to record individual objections to the decisions, and a means of requesting reviews of the initial determinations. Organizations notify individuals or their designated representatives when their personally identifiable information is corrected or deleted to provide transparency and confirm the completed action. Due to the complexity of data flows and storage, other entities may need to be informed of the correction or deletion. Notice supports the consistent correction and deletion of personally identifiable information across the data ecosystem.

Original Bare Metal Cyber perspective

From control text to operational evidence

Use Personally Identifiable Information Quality Management as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to enterprise program governance, accountability, resources, metrics, and organization-wide risk decisions.

Implementation workflow

  • Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
  • Resolve each organization-defined parameter before declaring the control implemented.
  • Document how the implementation satisfies every clause of the official control statement.
  • Collect evidence as a normal byproduct of operation rather than only before an assessment.
  • Review exceptions, changes, and monitoring results on a risk-based cadence.

Evidence examples

  • program charters and policies
  • governance meeting records
  • risk and performance metrics
  • resource and responsibility assignments

Common failure patterns

  • program metrics count activity instead of outcomes
  • system-level risks never reach enterprise governance
  • responsibilities assigned without authority or resources
  • privacy and security managed in separate silos

Questions practitioners should ask

  • What risk decision is this control intended to support in this system?
  • Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
  • Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
  • What event or threshold requires the implementation to be reviewed or changed?
Official NIST SP 800-53A content

Assessment objectives and methods

Show the assessment objective
  1. PM-22[01]organization-wide policies for personally identifiable information quality management are developed and documented;
  2. PM-22[02]organization-wide procedures for personally identifiable information quality management are developed and documented;
  3. PM-22a.
    1. PM-22a.[01]the policies address reviewing the accuracy of personally identifiable information across the information life cycle;
    2. PM-22a.[02]the policies address reviewing the relevance of personally identifiable information across the information life cycle;
    3. PM-22a.[03]the policies address reviewing the timeliness of personally identifiable information across the information life cycle;
    4. PM-22a.[04]the policies address reviewing the completeness of personally identifiable information across the information life cycle;
    5. PM-22a.[05]the procedures address reviewing the accuracy of personally identifiable information across the information life cycle;
    6. PM-22a.[06]the procedures address reviewing the relevance of personally identifiable information across the information life cycle;
    7. PM-22a.[07]the procedures address reviewing the timeliness of personally identifiable information across the information life cycle;
    8. PM-22a.[08]the procedures address reviewing the completeness of personally identifiable information across the information life cycle;
  4. PM-22b.
    1. PM-22b.[01]the policies address correcting or deleting inaccurate or outdated personally identifiable information;
    2. PM-22b.[02]the procedures address correcting or deleting inaccurate or outdated personally identifiable information;
  5. PM-22c.
    1. PM-22c.[01]the policies address disseminating notice of corrected or deleted personally identifiable information to individuals or other appropriate entities;
    2. PM-22c.[02]the procedures address disseminating notice of corrected or deleted personally identifiable information to individuals or other appropriate entities;
  6. PM-22d.
    1. PM-22d.[01]the policies address appeals of adverse decisions on correction or deletion requests;
    2. PM-22d.[02]the procedures address appeals of adverse decisions on correction or deletion requests.

Examine

  • Privacy program plan
  • policies and procedures addressing personally identifiable information quality management, information life cycle documentation, and sample notices of correction or deletion
  • records of monitoring PII quality management practices
  • documentation of reviews and updates of policies and procedures

Interview

  • Organizational personnel with privacy program information dissemination responsibilities
  • organizational personnel with privacy responsibilities

Test

  • [Organizational processes for data quality and personally identifiable information quality management procedures
  • mechanisms supporting and/or implementing quality management requirements
Official relationships

Related controls

These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.

Source record

Authoritative sources