Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

NIST SP 800-53 Learning Center

PT-2 — Authority to Process Personally Identifiable Information

Read the official control and assessment content, then use the separately labeled Bare Metal Cyber perspective to connect the requirement to implementation, evidence, and sustained operation.

2Enhancements
3Parameters
1Baseline memberships
3Assessment methods

PT — Personally Identifiable Information Processing and Transparency · NIST SP 800-53 Release 5.2.0

Privacy
Official NIST control content

Control statement

  1. a.Determine and document the [Organization-defined: authority] that permits the [Organization-defined: processing] of personally identifiable information; and
  2. b.Restrict the [Organization-defined: processing] of personally identifiable information to only that which is authorized.
Official NIST discussion

Discussion

The processing of personally identifiable information is an operation or set of operations that the information system or organization performs with respect to personally identifiable information across the information life cycle. Processing includes but is not limited to creation, collection, use, processing, storage, maintenance, dissemination, disclosure, and disposal. Processing operations also include logging, generation, and transformation, as well as analysis techniques, such as data mining. Organizations may be subject to laws, executive orders, directives, regulations, or policies that establish the organization’s authority and thereby limit certain types of processing of personally identifiable information or establish other requirements related to the processing. Organizational personnel consult with the senior agency official for privacy and legal counsel regarding such authority, particularly if the organization is subject to multiple jurisdictions or sources of authority. For organizations whose processing is not determined according to legal authorities, the organization’s policies and determinations govern how they process personally identifiable information. While processing of personally identifiable information may be legally permissible, privacy risks may still arise. Privacy risk assessments can identify the privacy risks associated with the authorized processing of personally identifiable information and support solutions to manage such risks. Organizations consider applicable requirements and organizational policies to determine how to document this authority. For federal agencies, the authority to process personally identifiable information is documented in privacy policies and notices, system of records notices, privacy impact assessments, [PRIVACT](#18e71fec-c6fd-475a-925a-5d8495cf8455) statements, computer matching agreements and notices, contracts, information sharing agreements, memoranda of understanding, and other documentation. Organizations take steps to ensure that personally identifiable information is only processed for authorized purposes, including training organizational personnel on the authorized processing of personally identifiable information and monitoring and auditing organizational use of personally identifiable information.

Official OSCAL parameters

Organization-defined parameters

These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.

authoritythe authority to permit the processing (defined in PT-02_ODP[02]) of personally identifiable information is defined;
processingthe type of processing of personally identifiable information is defined;
processingthe type of processing of personally identifiable information to be restricted is defined;
Original Bare Metal Cyber perspective

From control text to operational evidence

Use Authority to Process Personally Identifiable Information as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to privacy authority, purpose, transparency, consent, individual rights, and data-processing governance.

Implementation workflow

  • Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
  • Resolve each organization-defined parameter before declaring the control implemented.
  • Document how the implementation satisfies every clause of the official control statement.
  • Collect evidence as a normal byproduct of operation rather than only before an assessment.
  • Review exceptions, changes, and monitoring results on a risk-based cadence.

Evidence examples

  • privacy notices and consent records
  • authority and purpose documentation
  • data-processing inventories
  • individual request and redress records

Common failure patterns

  • collection justified by convenience rather than authority
  • notices do not reflect actual processing
  • secondary use expands without review
  • retention and deletion commitments not enforced

Questions practitioners should ask

  • What risk decision is this control intended to support in this system?
  • Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
  • Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
  • What event or threshold requires the implementation to be reviewed or changed?
Official NIST SP 800-53A content

Assessment objectives and methods

Show the assessment objective
  1. PT-02a.the [Organization-defined: authority] that permits the [Organization-defined: processing] of personally identifiable information is determined and documented;
  2. PT-02b.the [Organization-defined: processing] of personally identifiable information is restricted to only that which is authorized.

Examine

  • Personally identifiable information processing and transparency policy and procedures
  • privacy plan
  • other relevant documents or records

Interview

  • Organizational personnel with personally identifiable information processing and transparency responsibilities
  • organizational personnel with information security and privacy responsibilities

Test

  • Organizational processes for authorizing the processing of personally identifiable information
  • mechanisms supporting and/or implementing the restriction of personally identifiable information processing
Official relationships

Related controls

These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.

Official NIST enhancements

Control enhancements

Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.

Official NIST control enhancement

PT-2(1) — Data Tagging

Attach data tags containing [Organization-defined: authorized processing] to [Organization-defined: elements of personally identifiable information].

Official discussion

Data tags support the tracking and enforcement of authorized processing by conveying the types of processing that are authorized along with the relevant elements of personally identifiable information throughout the system. Data tags may also support the use of automated tools.

Organization-defined parameters (2)
authorized processingthe authorized processing of personally identifiable information is defined;
elements of personally identifiable informationelements of personally identifiable information to be tagged are defined;
Assessment objectives and methods

data tags containing [Organization-defined: authorized processing] are attached to [Organization-defined: elements of personally identifiable information].

Examine

  • Personally identifiable information processing and transparency policy and procedures including procedures addressing data tagging
  • data tag definitions
  • documented requirements for use and monitoring of data tagging
  • data extracts with corresponding data tags
  • privacy plan
  • other relevant documents or records

Interview

  • Organizational personnel with personally identifiable information processing and transparency responsibilities
  • organizational personnel with information security and privacy responsibilities

Test

  • Organizational processes for authorizing the processing of personally identifiable information
  • organizational processes for data tagging
  • mechanisms for applying and monitoring data tagging
  • mechanisms supporting and/or implementing the restriction of personally identifiable information processing
Related controls
Official NIST control enhancement

PT-2(2) — Automation

Manage enforcement of the authorized processing of personally identifiable information using [Organization-defined: automated mechanisms].

Official discussion

Automated mechanisms augment verification that only authorized processing is occurring.

Organization-defined parameters (1)
automated mechanismsautomated mechanisms used to manage enforcement of the authorized processing of personally identifiable information are defined;
Assessment objectives and methods

enforcement of the authorized processing of personally identifiable information is managed using [Organization-defined: automated mechanisms].

Examine

  • Personally identifiable information processing and transparency policy and procedures
  • privacy plan
  • other relevant documents or records

Interview

  • Organizational personnel with personally identifiable information processing and transparency responsibilities
  • organizational personnel with information security and privacy responsibilities

Test

  • Organizational processes for authorizing the processing of personally identifiable information
  • automated mechanisms supporting and/or implementing the management of authorized personally identifiable information processing
Related controls
Source record

Authoritative sources