← Controls / PM

PM-25 Minimization of Personally Identifiable Information Used in Testing, Training, and Research

Program Management

Privacy New in Rev 5

Description

a. Develop, document, and implement policies and procedures that address the use of personally identifiable information for internal testing, training, and research; b. Limit or minimize the amount of personally identifiable information used for internal testing, training, and research purposes; c. Authorize the use of personally identifiable information when such information is required for internal testing, training, and research; and d. Review and update policies and procedures [Assignment: organization-defined frequency].

Supplemental Guidance

The use of personally identifiable information in testing, research, and training increases the risk of unauthorized disclosure or misuse of such information. Organizations consult with the senior agency official for privacy and/or legal counsel to ensure that the use of personally identifiable information in testing, training, and research is compatible with the original purpose for which it was collected. When possible, organizations use placeholder data to avoid exposure of personally identifiable information when conducting testing, training, and research.

Changes from Rev 4

New control in Rev 5. PII minimization in testing/training.

Compliance Mappings

ISO 27001:2022

A.5.34

ISO 27002:2022

5.34

PCI DSS v4.0.1

3.2

BSI IT-Grundschutz

CON.2

BIO2

5.34

RBI CSF

Annex1.15

EU CRA

CRA.I.2g

IOSCO Cyber Resilience

REG-1

BOT Cyber Resilience

Ch9.2

Lloyd's Minimum Standards

MS7.1

HITRUST CSF v11

06.b13.c13.e

ISO 27799

18.2

NHS DSPT

NDG-5.2NDG-5.4

OWASP MASVS v2.1

MASVS-PRIVACY-1MASVS-PRIVACY-2

India DPDPA

Rules.Sch2