PM-25 Minimization of Personally Identifiable Information Used in Testing, Training, and Research. Develop, document, and implement policies and procedures that address the use of personally identifiable information for internal testing, training, and research; Limit or
Minimization of Personally Identifiable Information Used in Testing, Training, and Research. Develop, document, and implement policies and procedures that address the use of personally identifiable information for intern.
system holds itEvidence a system already holds
- Records showing test, training and research data is removed or destroyed when no longer needed · HR system / LMS
periodic reviewEvidence produced at each review
- Evidence of the limitation or minimisation applied, such as synthetic data, subsetting or de-identification · Document repository
- Authorisation records where real personally identifiable information was used, with the justification · Document repository
- Privacy risk assessment covering the testing, training and research use · HR system / LMS
governing documentDocuments that govern the control
- Policies and procedures addressing use of personally identifiable information for internal testing, training and research · HR system / LMS
First move
Common gaps auditors find
- Production data copied into lower environments as the default with minimisation applied only on request
- De-identification applied to obvious identifiers while the combination of remaining fields still identifies people
- Test data sets never destroyed, so copies persist long after the project ended
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetPM-24 Data Integrity Board. Establish a Data Integrity Board to: Review proposals to conduct or participate in a matching program; and Conduct an annual review of all matching programs in which the agency has participated · PM-26 Complaint Management. Implement a process for receiving and responding to complaints, concerns, or questions from individuals about the organizational security and privacy practices that includes: Mechanisms that are easy to use and readily accessible