Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search exact control and technique identifiers, Cyber Wiki articles, framework records, playbooks, books, podcasts, Academy courses, and individual lessons.

NIST SP 800-53 Learning Center

SI-18 — Personally Identifiable Information Quality Operations

Read the official control and assessment content, then use the separately labeled Bare Metal Cyber perspective to connect the requirement to implementation, evidence, and sustained operation.

5Enhancements
5Parameters
1Baseline memberships
3Assessment methods

SI — System and Information Integrity · NIST SP 800-53 Release 5.2.0

Privacy
Official NIST control content

Control statement

  1. a.Check the accuracy, relevance, timeliness, and completeness of personally identifiable information across the information life cycle [Organization-defined: organization-defined frequency] ; and
  2. b.Correct or delete inaccurate or outdated personally identifiable information.
Official NIST discussion

Discussion

Personally identifiable information quality operations include the steps that organizations take to confirm the accuracy and relevance of personally identifiable information throughout the information life cycle. The information life cycle includes the creation, collection, use, processing, storage, maintenance, dissemination, disclosure, and disposal of personally identifiable information. Personally identifiable information quality operations include editing and validating addresses as they are collected or entered into systems using automated address verification look-up application programming interfaces. Checking personally identifiable information quality includes the tracking of updates or changes to data over time, which enables organizations to know how and what personally identifiable information was changed should erroneous information be identified. The measures taken to protect personally identifiable information quality are based on the nature and context of the personally identifiable information, how it is to be used, how it was obtained, and the potential de-identification methods employed. The measures taken to validate the accuracy of personally identifiable information used to make determinations about the rights, benefits, or privileges of individuals covered under federal programs may be more comprehensive than the measures used to validate personally identifiable information used for less sensitive purposes.

Official OSCAL parameters

Organization-defined parameters

These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.

organization-defined frequency
frequencythe frequency at which to check the accuracy of personally identifiable information across the information life cycle is defined;
frequencythe frequency at which to check the relevance of personally identifiable information across the information life cycle is defined;
frequencythe frequency at which to check the timeliness of personally identifiable information across the information life cycle is defined;
frequencythe frequency at which to check the completeness of personally identifiable information across the information life cycle is defined;
Original Bare Metal Cyber perspective

From control text to operational evidence

Use Personally Identifiable Information Quality Operations as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to flaw remediation, malicious-code protection, monitoring, integrity, and trustworthy information handling.

Implementation workflow

  • Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
  • Resolve each organization-defined parameter before declaring the control implemented.
  • Document how the implementation satisfies every clause of the official control statement.
  • Collect evidence as a normal byproduct of operation rather than only before an assessment.
  • Review exceptions, changes, and monitoring results on a risk-based cadence.

Evidence examples

  • patch and remediation records
  • malware protection configuration
  • monitoring alerts and response records
  • integrity validation and exception reports

Common failure patterns

  • patch compliance hides unsupported assets
  • alerts generated without response ownership
  • exceptions never expire
  • integrity monitoring excludes critical configurations

Questions practitioners should ask

  • What risk decision is this control intended to support in this system?
  • Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
  • Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
  • What event or threshold requires the implementation to be reviewed or changed?
Official NIST SP 800-53A content

Assessment objectives and methods

Show the assessment objective
  1. SI-18a.
    1. SI-18a.[01]the accuracy of personally identifiable information across the information life cycle is checked [Organization-defined: frequency];
    2. SI-18a.[02]the relevance of personally identifiable information across the information life cycle is checked [Organization-defined: frequency];
    3. SI-18a.[03]the timeliness of personally identifiable information across the information life cycle is checked [Organization-defined: frequency];
    4. SI-18a.[04]the completeness of personally identifiable information across the information life cycle is checked [Organization-defined: frequency];
  2. SI-18b.inaccurate or outdated personally identifiable information is corrected or deleted.

Examine

  • System and information integrity policy
  • system and information integrity procedures
  • personally identifiable information processing policy
  • documentation addressing personally identifiable information quality operations
  • quality reports
  • maintenance logs
  • system audit records
  • audit findings
  • system security plan
  • privacy plan
  • privacy impact assessment
  • privacy risk assessment documentation
  • other relevant documents or records

Interview

  • Organizational personnel responsible for performing personally identifiable information quality inspections
  • organizational personnel with information security responsibilities
  • organizational personnel with privacy responsibilities

Test

  • Organizational processes for personally identifiable information quality inspection
  • automated mechanisms supporting and/or implementing personally identifiable information quality operations
Official relationships

Related controls

These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.

Official NIST enhancements

Control enhancements

Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.

Official NIST control enhancement

SI-18(1) — Automation Support

Correct or delete personally identifiable information that is inaccurate or outdated, incorrectly determined regarding impact, or incorrectly de-identified using [Organization-defined: automated mechanisms].

Official discussion

The use of automated mechanisms to improve data quality may inadvertently create privacy risks. Automated tools may connect to external or otherwise unrelated systems, and the matching of records between these systems may create linkages with unintended consequences. Organizations assess and document these risks in their privacy impact assessments and make determinations that are in alignment with their privacy program plans. As data is obtained and used across the information life cycle, it is important to confirm the accuracy and relevance of personally identifiable information. Automated mechanisms can augment existing data quality processes and procedures and enable an organization to better identify and manage personally identifiable information in large-scale systems. For example, automated tools can greatly improve efforts to consistently normalize data or identify malformed data. Automated tools can also be used to improve the auditing of data and detect errors that may incorrectly alter personally identifiable information or incorrectly associate such information with the wrong individual. Automated capabilities backstop processes and procedures at-scale and enable more fine-grained detection and correction of data quality errors.

Organization-defined parameters (1)
automated mechanismsautomated mechanisms used to correct or delete personally identifiable information that is inaccurate, outdated, incorrectly determined regarding impact, or incorrectly de-identified are defined;
Assessment objectives and methods

[Organization-defined: automated mechanisms] are used to correct or delete personally identifiable information that is inaccurate, outdated, incorrectly determined regarding impact, or incorrectly de-identified.

Examine

  • System and information integrity policy
  • system and information integrity procedures
  • personally identifiable information processing policy
  • documentation addressing personally identifiable information quality operations
  • quality reports
  • maintenance logs
  • system audit records
  • audit findings
  • system security plan
  • privacy plan
  • privacy impact assessment
  • privacy risk assessment documentation
  • other relevant documents or records

Interview

  • Organizational personnel responsible for performing personally identifiable information quality inspections
  • organizational personnel with information security and privacy responsibilities

Test

  • Organizational processes for personally identifiable information quality inspection
  • automated mechanisms supporting and/or implementing personally identifiable information quality operations
Related controls
Official NIST control enhancement

SI-18(2) — Data Tags

Employ data tags to automate the correction or deletion of personally identifiable information across the information life cycle within organizational systems.

Official discussion

Data tagging personally identifiable information includes tags that note processing permissions, authority to process, de-identification, impact level, information life cycle stage, and retention or last updated dates. Employing data tags for personally identifiable information can support the use of automation tools to correct or delete relevant personally identifiable information.

Assessment objectives and methods

data tags are employed to automate the correction or deletion of personally identifiable information across the information life cycle within organizational systems.

Examine

  • System and information integrity policy
  • system and information integrity procedures
  • personally identifiable information processing policy
  • procedures addressing data tagging
  • personally identifiable information inventory
  • system audit records
  • audit findings
  • system security plan
  • privacy plan
  • privacy impact assessment
  • privacy risk assessment documentation
  • other relevant documents or records

Interview

  • Organizational personnel responsible for tagging data
  • organizational personnel with information security and privacy responsibilities

Test

  • Data tagging mechanisms
  • automated mechanisms supporting and/or implementing data tagging
Related controls
Official NIST control enhancement

SI-18(3) — Collection

Collect personally identifiable information directly from the individual.

Official discussion

Individuals or their designated representatives can be sources of correct personally identifiable information. Organizations consider contextual factors that may incentivize individuals to provide correct data versus false data. Additional steps may be necessary to validate collected information based on the nature and context of the personally identifiable information, how it is to be used, and how it was obtained. The measures taken to validate the accuracy of personally identifiable information used to make determinations about the rights, benefits, or privileges of individuals under federal programs may be more comprehensive than the measures taken to validate less sensitive personally identifiable information.

Assessment objectives and methods

personally identifiable information is collected directly from the individual.

Examine

  • System and information integrity policy
  • system and information integrity procedures
  • personally identifiable information processing policy
  • system configuration documentation
  • system audit records
  • user interface where personally identifiable information is collected
  • system security plan
  • privacy plan
  • privacy impact assessment
  • privacy risk assessment documentation
  • other relevant documents or records

Interview

  • Organizational personnel responsible for data collection
  • organizational personnel with information security and privacy responsibilities

Test

  • Data collection mechanisms
  • automated mechanisms supporting and/or validating collection directly from the individual
Official NIST control enhancement

SI-18(4) — Individual Requests

Privacy

Correct or delete personally identifiable information upon request by individuals or their designated representatives.

Official discussion

Inaccurate personally identifiable information maintained by organizations may cause problems for individuals, especially in those business functions where inaccurate information may result in inappropriate decisions or the denial of benefits and services to individuals. Even correct information, in certain circumstances, can cause problems for individuals that outweigh the benefits of an organization maintaining the information. Organizations use discretion when determining if personally identifiable information is to be corrected or deleted based on the scope of requests, the changes sought, the impact of the changes, and laws, regulations, and policies. Organizational personnel consult with the senior agency official for privacy and legal counsel regarding appropriate instances of correction or deletion.

Assessment objectives and methods

personally identifiable information is corrected or deleted upon request by individuals or their designated representatives.

Examine

  • System and information integrity policy
  • system and information integrity procedures
  • personally identifiable information processing policy
  • system configuration
  • individual requests
  • records of correction or deletion actions performed
  • system audit records
  • system security plan
  • privacy plan
  • privacy impact assessment
  • privacy risk assessment documentation
  • other relevant documents or records

Interview

  • Organizational personnel responsible for responding to individual requests for personally identifiable information correction or deletion
  • organizational personnel with information security and privacy responsibilities

Test

  • Request mechanisms
  • automated mechanisms supporting and/or implementing individual requests for correction or deletion
Official NIST control enhancement

SI-18(5) — Notice of Correction or Deletion

Notify [Organization-defined: recipients] and individuals that the personally identifiable information has been corrected or deleted.

Official discussion

When personally identifiable information is corrected or deleted, organizations take steps to ensure that all authorized recipients of such information, and the individual with whom the information is associated or their designated representatives, are informed of the corrected or deleted information.

Organization-defined parameters (1)
recipientsrecipients of personally identifiable information to be notified when the personally identifiable information has been corrected or deleted are defined;
Assessment objectives and methods

[Organization-defined: recipients] and individuals are notified when the personally identifiable information has been corrected or deleted.

Examine

  • System and information integrity policy
  • system and information integrity procedures
  • personally identifiable information processing policy
  • system configuration
  • individual requests for corrections or deletions
  • notifications of correction or deletion action
  • system audit records
  • system security plan
  • privacy plan
  • privacy impact assessment
  • privacy risk assessment documentation
  • other relevant documents or records

Interview

  • Organizational personnel responsible for sending correction or deletion notices
  • organizational personnel with information security and privacy responsibilities

Test

  • Organizational processes for notifications of correction or deletion
  • automated mechanisms supporting and/or implementing notifications of correction or deletion
Source record

Authoritative sources