NIST SP 800-53 Rev. 5
SC-7(24)
System and Communications Protection
enhancement

Personally Identifiable Information

Parent: SC-7

Description

For systems that process personally identifiable information: a. Apply the following processing rules to data elements of personally identifiable information: [organization-defined parameter]; b. Monitor for permitted processing at the external interfaces to the system and at key internal boundaries within the system; c. Document each processing exception; and d. Review and remove exceptions that are no longer supported.

Mapped SPARTA techniques

No techniques mapped to this control.

Cite as SafeMode Space, nist-80053-rev5 SC-7(24).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.