PM-25 Minimization of Personally Identifiable Information Used in Testing, Training, and Research

Program Management

Privacy New in Rev 5

Description

a. Develop, implement, and update policies and procedures that address the use of personally identifiable information for internal testing, training, and research; b. Take measures to minimize the use of personally identifiable information for internal testing, training, and research purposes; and c. Where possible, use techniques to minimize the risk to privacy of using personally identifiable information for internal testing, training, and research, including de-identification and synthetic data generation.

Supplemental Guidance

Organizations can minimize the risk to privacy of using personally identifiable information for internal testing, training, and research by implementing privacy-protective techniques such as de-identification, anonymization, synthetic data generation, and other methods that reduce the risk of exposing PII during such activities. The use of production data containing PII for testing purposes introduces risk that the PII could be misused, improperly accessed, or disclosed.

Changes from Rev 4

New control in Rev 5. PII minimization in testing/training.

Compliance Mappings

ISO 27001:2022

A.5.34

ISO 27002:2022

5.34

PCI DSS v4.0.1

3.2

BSI IT-Grundschutz

CON.2

BIO2

5.34

RBI CSF

Annex1.15

EU CRA

CRA.I.2g

IOSCO Cyber Resilience

REG-1

BOT Cyber Resilience

Ch9.2

Lloyd's Minimum Standards

MS7.1

HITRUST CSF v11

06.b13.c13.e

ISO 27799

18.2

NHS DSPT

NDG-5.2NDG-5.4

OWASP MASVS v2.1

MASVS-PRIVACY-1MASVS-PRIVACY-2