# PM-25 Minimization of Personally Identifiable Information Used in Testing, Training, and Research

NIST SP 800-53 control. Family: PM Program Management. Function: preventative. Baselines: privacy. Mapping licence: CC BY-SA 4.0.

Statement: a. Develop, document, and implement policies and procedures that address the use of personally identifiable information for internal testing, training, and research; b. Limit or minimize the amount of personally identifiable information used for internal testing, training, and research purposes; c. Authorize the use of personally identifiable information when such information is required for internal testing, training, and research; and d. Review and update policies and procedures [Assignment: organization-defined frequency].
Guidance: The use of personally identifiable information in testing, research, and training increases the risk of unauthorized disclosure or misuse of such information. Organizations consult with the senior agency official for privacy and/or legal counsel to ensure that the use of personally identifiable information in testing, training, and research is compatible with the original purpose for which it was collected. When possible, organizations use placeholder data to avoid exposure of personally identifiable information when conducting testing, training, and research.

## Patterns that use it (4)
- Important (3): SP-039 Client-Side Encryption and Data Privacy; SP-045 AI Governance and Responsible AI; SP-050 Mobile Security Architecture (draft)
- Standard (1): SP-051 Tokenised Asset Security Architecture (draft)

## Clauses by framework (15 frameworks)
- iso_27001_2022: A.5.34. OSA's own, not in NIST's crosswalk: A.5.34
- iso_27002_2022: 5.34
- pci_dss_v4: 3.2
- bsi_grundschutz: CON.2
- bio2: 5.34
- rbi_csf: Annex1.15
- cra: CRA.I.2g
- bot_cyber: Ch9.2
- iosco_cyber: REG-1
- hitrust_csf: 06.b, 13.c, 13.e
- iso_27799: 18.2
- lloyds_ms: MS7.1
- nhs_dspt: NDG-5.2, NDG-5.4
- owasp_masvs_v2: MASVS-PRIVACY-1, MASVS-PRIVACY-2
- dpdpa: Rules.Sch2
OSA's mapping for iso_27001_2022 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/PM-25
- Clauses only: /api/v1/controls/PM-25?fields=mappings
- Page for people: /controls/pm-25/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
