Author(s)
Shirley M. Radack
Abstract
This bulletin summarizes the information presented in NIST Special Publication (SP) 800-122, Guide to Protecting the Confidentiality of Personally Identifiable Information (PII). Written by Erika McCallister, Tim Grance, and Karen Scarfone of NIST, the publication assists Federal agencies in carrying out their responsibilities to protect PII in information systems. SP 800-122 discusses how to identify and protect the confidentiality of PII as part of the organization s information security procedures, and explains the importance of protecting the privacy of the individuals whose personal information is kept by an organization. The bulletin summarizes background information on the characteristics of PII, and briefly discusses NIST s recommendations to agencies for protecting personal information, ensuring its security, and developing, documenting, and implementing information security programs under the Federal Information Security Management Act of 2002 (FISMA). References are provided to additional sources of information on protecting personally identifiable information.
Keywords
confidentiality, confidentiality safeguards, FISMA, incident response, information security, information systems security, personally identifiable information (PII), privacy, security breaches, security controls, security impact assessments, security plans, security risks
Citation
Radack, S.
(2010),
Guide to Protecting Personally Identifiable Information, ITL Bulletin, National Institute of Standards and Technology, Gaithersburg, MD, [online], https://tsapps.nist.gov/publication/get_pdf.cfm?pub_id=905656 (Accessed May 3, 2026)
Additional citation formats
Issues
If you have any questions about this publication or are having problems accessing it, please contact [email protected].