Questions from the NIST 800-53 r5 updates
Several Control Families are substantially enhanced in SP 800-53 r5. Two families that require particular note and planning are what used to be managed as PMO packages and Appendixes during the ATO FedRAMP process. These are Program Management (PM) and the PERSONALLY IDENTIFIABLE INFORMATION PROCESSING AND TRANSPARENCY Families.
The takeaway we'd like to reinforce is that the steps for preparing and "packaging" the overall programs within FedRAMP and other NIST-related compliance assessments are now prescriptive with distinct outcomes and assessment steps. What was once a set of prepared packages provided during the triennial assessment are now continuous and distributed controls within the catalog (800-53r5). Here's what NIST writes about the Program Management control domain.
PROGRAM MANAGEMENT CONTROLS [FISMA], [PRIVACT], and [OMB A-130] require federal agencies to develop, implement, and provide oversight for organization-wide information security and privacy programs to help ensure the confidentiality, integrity, and availability of federal information processed, stored, and transmitted by federal information systems and to protect individual privacy. The program management (PM) controls described in this section are implemented at the organization level and not directed at individual information systems. The PM controls have been designed to facilitate organizational compliance with applicable federal laws, executive orders, directives, policies, regulations, and standards. The controls are independent of [FIPS 200] impact levels and, therefore, are not associated with the control baselines described in [SP 800-53B]. Organizations document program management controls in the information security and privacy program plans. The organization-wide information security program plan (see PM-1) and privacy program plan (see PM-18) supplement system security and privacy plans (see PL-2) developed for organizational information systems. Together, the system security and privacy plans for the individual information systems and the information security and privacy program plans cover the totality of security and privacy controls employed by the organization.
| 800-53 Rev. 4 (Appendix J) Control | 800-53 Rev. 5 Controls |
| AP-1: Authority to Collect | PT-2: Authority to Process Personally Identifiable Information |
| AP-2: Purpose Specification | PT-3: Personally Identifiable Information Processing Purposes |
| AR-1: Governance and Privacy Program | PM-3: Information Security and Privacy Resources PM-18: Privacy Program Plan PM-19: Privacy Program Leadership Role |
| AR-2: Privacy Impact and Risk Assessment | RA-3: Risk Assessment RA-8: Privacy Impact Assessment |
| AR-3: Privacy Requirements for Contractors and Service Providers | SA-1: Policies and Procedures SA-4: Acquisition Process SA-9: External System Services |
| AR-4: Privacy Monitoring and Auditing | CA-2: Control Assessments |
| AR-5: Privacy Awareness and Training | AT-1: Policies and Procedures AT-2: Literacy Training and Awareness AT-3: Role-based Training PL-4: Rules of Behavior |
| AR-6: Privacy Reporting | PM-27: Privacy Reporting |
| AR-7: Privacy-Enhanced System Design and Development | No specific control reflects AR-7, but there are discretionary control enhancements that relate to automation. |
| AR-8: Accounting of Disclosures | PM-21: Accounting of Disclosures |
| DI-1: Data Quality | PM-22: Personally Identifiable Information Quality Management SI-18: Personally Identifiable Information Quality Operations |
| DI-2: Data Integrity and Data Integrity Board | PM-24: Data Integrity Board SI-1: Policies and Procedures |
| DM-1: Minimization of Personally Identifiable Information | SA-8(33): Security and Privacy Engineering Principles | Minimization PM-5(1): System Inventory | Inventory of Personally Identifiable Information SI-12(1): Information Management and Retention | Limit Personally Identifiable Information Elements |
| DM-2: Data Retention and Disposal | MP-6: Media Sanitization SI-12: Information Management and Retention SI-12(3): Information Management and Retention |Information Disposal |
| DM-3: Minimization of PII used in Testing, Training, and Research | PM-25: Minimization of Personally Identifiable Information used in Testing, Training, and Research SI-12(2): Information Management and Retention | Minimize Personally Identifiable Information in Testing, Training and Research |
| IP-1: Consent | PT-4: Consent |
| IP-2: Individual Access | AC-1: Policies and Procedures AC-3(14): Access Enforcement | Individual Access PM-20: Dissemination of Privacy Program Information PT-5: Privacy Notice PT-6: System of Records Notice |
| IP-3: Redress | PM-22: Personally Identifiable Information Quality Management SI-18: Personally Identifiable Information Quality Operations SI-18(4): Personally Identifiable Information Quality Operations | Individual Requests SI-18(5): Personally Identifiable Information Quality Operations | Notice of Correction or Deletion |
| IP-4: Complaint Management | PM-26: Complaint Management |
| SE-1: Inventory of Personally Identifiable Information | PM-5(1): System Inventory | Inventory of Personally Identifiable Information |
| SE-2: Privacy Incident Response | IR-8: Incident Response Plan IR-8(1): Incident Response Plan | Breaches |
| TR-1: Privacy Notice | PT-5: Privacy Notice PT-5(1): Privacy Notice | Just-In-Time Notice |
| TR-2: System of Records Notices and Privacy Act Statements | PT-5(2): Privacy Notice | Privacy Act Statements PT-6: System of Records Notice |
| TR-3: Dissemination of Privacy Program Information | PM-20: Dissemination of Privacy Program Information |
| UL-1: Internal Use | PT-3: Personally Identifiable Information Processing Purposes |
| UL-2: Information Sharing with Third Parties | AC-21: Information Sharing AT-3(5): Role-based Training | Processing Personally Identifiable Information AU-2: Event Logging PT-2: Authority to Process Personally Identifiable Information PT-3: Personally Identifiable Information Processing Purposes |

Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics