Questions from the NIST 800-53 r5 updates

Several Control Families are substantially enhanced in SP 800-53 r5. Two families that require particular note and planning are what used to be managed as PMO packages and Appendixes during the ATO FedRAMP process. These are Program Management (PM) and the PERSONALLY IDENTIFIABLE INFORMATION PROCESSING AND TRANSPARENCY Families.

The takeaway we'd like to reinforce is that the steps for preparing and "packaging" the overall programs within FedRAMP and other NIST-related compliance assessments are now prescriptive with distinct outcomes and assessment steps. What was once a set of prepared packages provided during the triennial assessment are now continuous and distributed controls within the catalog (800-53r5). Here's what NIST writes about the Program Management control domain. 

PROGRAM MANAGEMENT CONTROLS [FISMA], [PRIVACT], and [OMB A-130] require federal agencies to develop, implement, and provide oversight for organization-wide information security and privacy programs to help ensure the confidentiality, integrity, and availability of federal information processed, stored, and transmitted by federal information systems and to protect individual privacy. The program management (PM) controls described in this section are implemented at the organization level and not directed at individual information systems. The PM controls have been designed to facilitate organizational compliance with applicable federal laws, executive orders, directives, policies, regulations, and standards. The controls are independent of [FIPS 200] impact levels and, therefore, are not associated with the control baselines described in [SP 800-53B]. Organizations document program management controls in the information security and privacy program plans. The organization-wide information security program plan (see PM-1) and privacy program plan (see PM-18) supplement system security and privacy plans (see PL-2) developed for organizational information systems. Together, the system security and privacy plans for the individual information systems and the information security and privacy program plans cover the totality of security and privacy controls employed by the organization.

800-53 Rev. 4 (Appendix J) Control 800-53 Rev. 5 Controls
AP-1: Authority to Collect PT-2: Authority to Process Personally Identifiable Information
AP-2: Purpose Specification PT-3: Personally Identifiable Information Processing Purposes
AR-1: Governance and Privacy Program PM-3: Information Security and Privacy Resources
PM-18: Privacy Program Plan
PM-19: Privacy Program Leadership Role
AR-2: Privacy Impact and Risk Assessment RA-3: Risk Assessment
RA-8: Privacy Impact Assessment
AR-3: Privacy Requirements for Contractors and Service Providers SA-1: Policies and Procedures
SA-4: Acquisition Process
SA-9: External System Services
AR-4: Privacy Monitoring and Auditing CA-2: Control Assessments
AR-5: Privacy Awareness and Training AT-1: Policies and Procedures
AT-2: Literacy Training and Awareness
AT-3: Role-based Training
PL-4: Rules of Behavior
AR-6: Privacy Reporting PM-27: Privacy Reporting
AR-7: Privacy-Enhanced System Design and Development No specific control reflects AR-7, but there are discretionary control enhancements that relate to automation.
AR-8: Accounting of Disclosures PM-21: Accounting of Disclosures
DI-1: Data Quality   PM-22: Personally Identifiable Information Quality Management
SI-18: Personally Identifiable Information Quality Operations
DI-2: Data Integrity and Data Integrity Board PM-24: Data Integrity Board
SI-1: Policies and Procedures
DM-1: Minimization of Personally Identifiable Information SA-8(33): Security and Privacy Engineering Principles | Minimization
PM-5(1): System Inventory | Inventory of Personally Identifiable Information
SI-12(1): Information Management and Retention | Limit Personally Identifiable Information Elements
DM-2: Data Retention and Disposal MP-6: Media Sanitization
SI-12: Information Management and Retention
SI-12(3): Information Management and Retention |Information Disposal
DM-3: Minimization of PII used in Testing, Training, and Research PM-25: Minimization of Personally Identifiable Information used in Testing, Training, and Research
SI-12(2): Information Management and Retention | Minimize Personally Identifiable Information in Testing, Training and Research
IP-1: Consent PT-4: Consent
IP-2: Individual Access AC-1: Policies and Procedures
AC-3(14): Access Enforcement | Individual Access
PM-20: Dissemination of Privacy Program Information
PT-5: Privacy Notice
PT-6: System of Records Notice
IP-3: Redress PM-22: Personally Identifiable Information Quality Management
SI-18: Personally Identifiable Information Quality Operations
SI-18(4): Personally Identifiable Information Quality Operations | Individual Requests
SI-18(5): Personally Identifiable Information Quality Operations | Notice of Correction or Deletion
IP-4: Complaint Management PM-26: Complaint Management
SE-1: Inventory of Personally Identifiable Information PM-5(1): System Inventory | Inventory of Personally Identifiable Information
SE-2: Privacy Incident Response IR-8: Incident Response Plan
IR-8(1): Incident Response Plan | Breaches 
TR-1: Privacy Notice PT-5: Privacy Notice
PT-5(1): Privacy Notice | Just-In-Time Notice
TR-2: System of Records Notices and Privacy Act Statements PT-5(2): Privacy Notice | Privacy Act Statements
PT-6: System of Records Notice
TR-3: Dissemination of Privacy Program Information PM-20: Dissemination of Privacy Program Information
UL-1: Internal Use PT-3: Personally Identifiable Information Processing Purposes
UL-2: Information Sharing with Third Parties AC-21: Information Sharing
AT-3(5): Role-based Training | Processing Personally Identifiable Information
AU-2: Event Logging
PT-2: Authority to Process Personally Identifiable Information
PT-3: Personally Identifiable Information Processing Purposes
Main Menu