Control statement
- a.Determine and document the [Organization-defined: authority] that permits the [Organization-defined: processing] of personally identifiable information; and
- b.Restrict the [Organization-defined: processing] of personally identifiable information to only that which is authorized.
Discussion
The processing of personally identifiable information is an operation or set of operations that the information system or organization performs with respect to personally identifiable information across the information life cycle. Processing includes but is not limited to creation, collection, use, processing, storage, maintenance, dissemination, disclosure, and disposal. Processing operations also include logging, generation, and transformation, as well as analysis techniques, such as data mining. Organizations may be subject to laws, executive orders, directives, regulations, or policies that establish the organization’s authority and thereby limit certain types of processing of personally identifiable information or establish other requirements related to the processing. Organizational personnel consult with the senior agency official for privacy and legal counsel regarding such authority, particularly if the organization is subject to multiple jurisdictions or sources of authority. For organizations whose processing is not determined according to legal authorities, the organization’s policies and determinations govern how they process personally identifiable information. While processing of personally identifiable information may be legally permissible, privacy risks may still arise. Privacy risk assessments can identify the privacy risks associated with the authorized processing of personally identifiable information and support solutions to manage such risks. Organizations consider applicable requirements and organizational policies to determine how to document this authority. For federal agencies, the authority to process personally identifiable information is documented in privacy policies and notices, system of records notices, privacy impact assessments, [PRIVACT](#18e71fec-c6fd-475a-925a-5d8495cf8455) statements, computer matching agreements and notices, contracts, information sharing agreements, memoranda of understanding, and other documentation. Organizations take steps to ensure that personally identifiable information is only processed for authorized purposes, including training organizational personnel on the authorized processing of personally identifiable information and monitoring and auditing organizational use of personally identifiable information.
Organization-defined parameters
These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.
From control text to operational evidence
Use Authority to Process Personally Identifiable Information as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to privacy authority, purpose, transparency, consent, individual rights, and data-processing governance.
Implementation workflow
- Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
- Resolve each organization-defined parameter before declaring the control implemented.
- Document how the implementation satisfies every clause of the official control statement.
- Collect evidence as a normal byproduct of operation rather than only before an assessment.
- Review exceptions, changes, and monitoring results on a risk-based cadence.
Evidence examples
- privacy notices and consent records
- authority and purpose documentation
- data-processing inventories
- individual request and redress records
Common failure patterns
- collection justified by convenience rather than authority
- notices do not reflect actual processing
- secondary use expands without review
- retention and deletion commitments not enforced
Questions practitioners should ask
- What risk decision is this control intended to support in this system?
- Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
- Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
- What event or threshold requires the implementation to be reviewed or changed?
Assessment objectives and methods
Show the assessment objective
- PT-02a.the [Organization-defined: authority] that permits the [Organization-defined: processing] of personally identifiable information is determined and documented;
- PT-02b.the [Organization-defined: processing] of personally identifiable information is restricted to only that which is authorized.
Examine
- Personally identifiable information processing and transparency policy and procedures
- privacy plan
- other relevant documents or records
Interview
- Organizational personnel with personally identifiable information processing and transparency responsibilities
- organizational personnel with information security and privacy responsibilities
Test
- Organizational processes for authorizing the processing of personally identifiable information
- mechanisms supporting and/or implementing the restriction of personally identifiable information processing
Related controls
These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.
Control enhancements
Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.
PT-2(1) — Data Tagging
Attach data tags containing [Organization-defined: authorized processing] to [Organization-defined: elements of personally identifiable information].
Official discussion
Data tags support the tracking and enforcement of authorized processing by conveying the types of processing that are authorized along with the relevant elements of personally identifiable information throughout the system. Data tags may also support the use of automated tools.
Organization-defined parameters (2)
Assessment objectives and methods
data tags containing [Organization-defined: authorized processing] are attached to [Organization-defined: elements of personally identifiable information].
Examine
- Personally identifiable information processing and transparency policy and procedures including procedures addressing data tagging
- data tag definitions
- documented requirements for use and monitoring of data tagging
- data extracts with corresponding data tags
- privacy plan
- other relevant documents or records
Interview
- Organizational personnel with personally identifiable information processing and transparency responsibilities
- organizational personnel with information security and privacy responsibilities
Test
- Organizational processes for authorizing the processing of personally identifiable information
- organizational processes for data tagging
- mechanisms for applying and monitoring data tagging
- mechanisms supporting and/or implementing the restriction of personally identifiable information processing
Related controls
PT-2(2) — Automation
Manage enforcement of the authorized processing of personally identifiable information using [Organization-defined: automated mechanisms].
Official discussion
Automated mechanisms augment verification that only authorized processing is occurring.
Organization-defined parameters (1)
Assessment objectives and methods
enforcement of the authorized processing of personally identifiable information is managed using [Organization-defined: automated mechanisms].
Examine
- Personally identifiable information processing and transparency policy and procedures
- privacy plan
- other relevant documents or records
Interview
- Organizational personnel with personally identifiable information processing and transparency responsibilities
- organizational personnel with information security and privacy responsibilities
Test
- Organizational processes for authorizing the processing of personally identifiable information
- automated mechanisms supporting and/or implementing the management of authorized personally identifiable information processing
Related controls
Authoritative sources
Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST. Official control requirements and interpretations remain with NIST and the responsible authorizing organization.