NIST Proposes New Privacy Controls for Federal Information Systems and Organizations
From NIST Tech Beat: July 19, 2011
Contact: Evelyn Brown
With increasing dependency on information systems and advances in cloud computing, the smart grid and mobile computing, maintaining the confidentiality and integrity of citizens' personally identifiable information is a growing challenge. A new draft document from the National Institute of Standards and Technology (NIST) addresses that challenge by adding privacy controls to the catalog of security controls used to protect federal information and information systems.
Personally identifiable information (PII) is information that is unique to an individual, such as a social security number, birth information, fingerprints and other biometrics. In the wrong hands, PII can be used in identity theft, fraud or other criminal activities. Today, more than ever, citizens are concerned that their personal information is protected as it is processed, stored and transmitted across computing clouds or mobile devices in the federal government and in other areas such as health care and banking. Protecting PII is a key goal of the federal government.
"Strong normalized privacy controls are an essential component in the ongoing effort to build measurable privacy compliance," said NIST Senior Internet Policy Advisor Ari Schwartz. "Certainty in controls and measures can help promote privacy, trust and greater confidence in new standards."
The new document, Privacy Control Catalog, will become Appendix J of Security Controls for Federal Information Systems and Organizations (NIST Special Publication 800-53, Revision 4). One of the foundational Federal Information Security Management Act (FISMA) documents, SP 800-53 is being updated to Revision 4 in December, 2011. SP 800-53 is also one of the Joint Task Force Transformation Initiative documents that NIST produces with the Department of Defense and the Intelligence Community.
"Privacy and security controls in federal information systems are complementary and mutually reinforcing in trying to achieve the privacy and security objectives of organizations," said NIST Fellow Ron Ross, project leader of the FISMA Implementation Project and Joint Task Force.
Incorporating privacy controls into SP 800-53 and taking advantage of established security controls to provide a solid foundation for information security helps to ensure that privacy requirements will be satisfied in a comprehensive, cost-effective, and risk-based manner.
The new privacy appendix:
Due to the special nature of the material in Appendix J, it is being vetted separately from other changes to the main document. The public comment period for this appendix runs through September 2, 2011. Comments should be sent to email@example.com. The publication may be found at http://csrc.nist.gov/publications/PubsDrafts.html#SP-800-53-Appendix%20J