CCI-005006
CCI-005006 Definition
| Status | |
| Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
Determine if: - [SI-12(02)_ODP[01]; techniques used to minimize the use of personally identifiable information for research are defined] are used to minimize the use of personally identifiable information for research. - [SI-12(02)_ODP[02]; techniques used to minimize the use of personally identifiable information for testing are defined] are used to minimize the use of personally identifiable information for testing. - [SI-12(02)_ODP[03]; techniques used to minimize the use of personally identifiable information for training are defined] are used to minimize the use of personally identifiable information for training.
Validation Procedures
Examine: [SELECT FROM: System and information integrity policy; system and information integrity procedures; personally identifiable information processing policy; personally identifiable information processing procedures; federal laws, Executive Orders, directives, policies, regulations, standards, and operational requirements applicable to minimizing the use of personally identifiable information in testing, training, and research; policy for the minimization of personally identifiable information used in testing, training, and research; procedures for the minimization of personally identifiable information used in testing, training, and research; documentation supporting minimization policy implementation (e.g., templates for testing, training, and research); data sets used for testing, training, and research; system security plan; privacy plan; privacy impact assessment; privacy risk assessment documentation; other relevant documents or records]. Interview: [SELECT FROM: Organizational personnel with information and records management, retention, and disposition responsibilities; organizational personnel with information security and privacy responsibilities; network administrators; system developers; personnel with IRB responsibilities]. Test: [SELECT FROM: Organizational processes for the minimization of personally identifiable information used in testing, training, and research; automated mechanisms supporting and/or implementing the minimization of personally identifiable information used in testing, training, and research].