SI-19 De-identification

System and Information Integrity

Privacy New in Rev 5

Description

a. Remove the following elements of personally identifiable information from datasets: [Assignment: organization-defined elements of personally identifiable information]; and b. Evaluate [Assignment: organization-defined frequency] for effectiveness of de-identification.

Supplemental Guidance

De-identification is the general term for the process of removing the association between a set of identifying data and the data subject. Many de-identification techniques are available, including but not limited to: removing identifiers, reducing the amount of detail included in data, grouping values into ranges, and adding random statistical noise. The appropriateness of the de-identification technique depends upon the context of the data and the purpose for which the data will be used.

Changes from Rev 4

New control in Rev 5.

Compliance Mappings

ISO 27001:2022

A.8.11

ISO 27002:2022

8.11

PCI DSS v4.0.1

3.4

BSI IT-Grundschutz

CON.2

ANSSI

SecNumCloud.19.3

BIO2

8.11

RBI CSF

Annex1.15

EU CRA

CRA.I.2gCRA.I.2m

NCA ECC

2-7

CBB TM

TM-9

IOSCO Cyber Resilience

PROT-3

SEBI CSCRF

PR.DS

BOT Cyber Resilience

Ch2.3Ch9.2

Common Criteria

CC Part 2 — FPR

ISO 27799

14.3H.4