Questions from the NIST 800-53 r5 updates

Several Control Families are substantially enhanced in SP 800-53 r5. Two families that require particular note and planning are what used to be managed as PMO packages and Appendixes during the ATO FedRAMP process. These are Program Management (PM) and the PERSONALLY IDENTIFIABLE INFORMATION PROCESSING AND TRANSPARENCY Families.

The takeaway we'd like to reinforce is that the steps for preparing and "packaging" the overall programs within FedRAMP and other NIST-related compliance assessments are now prescriptive with distinct outcomes and assessment steps. What was once a set of prepared packages provided during the triennial assessment are now continuous and distributed controls within the catalog (800-53r5). Here's what NIST writes about the Program Management control domain. 

PROGRAM MANAGEMENT CONTROLS [FISMA], [PRIVACT], and [OMB A-130] require federal agencies to develop, implement, and provide oversight for organization-wide information security and privacy programs to help ensure the confidentiality, integrity, and availability of federal information processed, stored, and transmitted by federal information systems and to protect individual privacy. The program management (PM) controls described in this section are implemented at the organization level and not directed at individual information systems. The PM controls have been designed to facilitate organizational compliance with applicable federal laws, executive orders, directives, policies, regulations, and standards. The controls are independent of [FIPS 200] impact levels and, therefore, are not associated with the control baselines described in [SP 800-53B]. Organizations document program management controls in the information security and privacy program plans. The organization-wide information security program plan (see PM-1) and privacy program plan (see PM-18) supplement system security and privacy plans (see PL-2) developed for organizational information systems. Together, the system security and privacy plans for the individual information systems and the information security and privacy program plans cover the totality of security and privacy controls employed by the organization.

800-53 Rev. 4 (Appendix J) Control 800-53 Rev. 5 Controls
AP-1: Authority to Collect PT-2: Authority to Process Personally Identifiable Information
AP-2: Purpose Specification PT-3: Personally Identifiable Information Processing Purposes
AR-1: Governance and Privacy Program PM-3: Information Security and Privacy Resources
PM-18: Privacy Program Plan
PM-19: Privacy Program Leadership Role
AR-2: Privacy Impact and Risk Assessment RA-3: Risk Assessment
RA-8: Privacy Impact Assessment
AR-3: Privacy Requirements for Contractors and Service Providers SA-1: Policies and Procedures
SA-4: Acquisition Process
SA-9: External System Services
AR-4: Privacy Monitoring and Auditing CA-2: Control Assessments
AR-5: Privacy Awareness and Training AT-1: Policies and Procedures
AT-2: Literacy Training and Awareness
AT-3: Role-based Training
PL-4: Rules of Behavior
AR-6: Privacy Reporting PM-27: Privacy Reporting
AR-7: Privacy-Enhanced System Design and Development No specific control reflects AR-7, but there are discretionary control enhancements that relate to automation.
AR-8: Accounting of Disclosures PM-21: Accounting of Disclosures
DI-1: Data Quality   PM-22: Personally Identifiable Information Quality Management
SI-18: Personally Identifiable Information Quality Operations
DI-2: Data Integrity and Data Integrity Board PM-24: Data Integrity Board
SI-1: Policies and Procedures
DM-1: Minimization of Personally Identifiable Information SA-8(33): Security and Privacy Engineering Principles | Minimization
PM-5(1): System Inventory | Inventory of Personally Identifiable Information
SI-12(1): Information Management and Retention | Limit Personally Identifiable Information Elements
DM-2: Data Retention and Disposal MP-6: Media Sanitization
SI-12: Information Management and Retention
SI-12(3): Information Management and Retention |Information Disposal
DM-3: Minimization of PII used in Testing, Training, and Research PM-25: Minimization of Personally Identifiable Information used in Testing, Training, and Research
SI-12(2): Information Management and Retention | Minimize Personally Identifiable Information in Testing, Training and Research
IP-1: Consent PT-4: Consent
IP-2: Individual Access AC-1: Policies and Procedures
AC-3(14): Access Enforcement | Individual Access
PM-20: Dissemination of Privacy Program Information
PT-5: Privacy Notice
PT-6: System of Records Notice
IP-3: Redress PM-22: Personally Identifiable Information Quality Management
SI-18: Personally Identifiable Information Quality Operations
SI-18(4): Personally Identifiable Information Quality Operations | Individual Requests
SI-18(5): Personally Identifiable Information Quality Operations | Notice of Correction or Deletion
IP-4: Complaint Management PM-26: Complaint Management
SE-1: Inventory of Personally Identifiable Information PM-5(1): System Inventory | Inventory of Personally Identifiable Information
SE-2: Privacy Incident Response IR-8: Incident Response Plan
IR-8(1): Incident Response Plan | Breaches 
TR-1: Privacy Notice PT-5: Privacy Notice
PT-5(1): Privacy Notice | Just-In-Time Notice
TR-2: System of Records Notices and Privacy Act Statements PT-5(2): Privacy Notice | Privacy Act Statements
PT-6: System of Records Notice
TR-3: Dissemination of Privacy Program Information PM-20: Dissemination of Privacy Program Information
UL-1: Internal Use PT-3: Personally Identifiable Information Processing Purposes
UL-2: Information Sharing with Third Parties AC-21: Information Sharing
AT-3(5): Role-based Training | Processing Personally Identifiable Information
AU-2: Event Logging
PT-2: Authority to Process Personally Identifiable Information
PT-3: Personally Identifiable Information Processing Purposes

Which controls are associated with the Privacy Baseline? It's a lot. In fact, there are 97 controls designated as part of Privacy in the entirety of the SP 800-53 r5 catalog.

Control ID Control and Enhancement Name
AC-1 Policy and Procedures
AC-3(14) Access Enforcement | Individual Access
AT-1 Policy and Procedures
AT-2 Literacy Training and Awareness
AT-3 Role-based Training
AT-3(5) Role-based Training | Processing Personally Identifiable Information
AT-4 Training Records
AU-1 Policy and Procedures
AU-2 Event Logging
AU-3(3) Content of Audit Records | Limit Personally Identifiable Information Elements
AU-11 Audit Record Retention
CA-1 Policy and Procedures
CA-2 Control Assessments
CA-5 Plan of Action and Milestones
CA-6 Authorization
CA-7 Continuous Monitoring
CA-7(4) Continuous Monitoring | Risk Monitoring
CM-1 Policy and Procedures
CM-4 Impact Analyses
IR-1 Policy and Procedures
IR-2 Incident Response Training
IR-2(3) Incident Response Training | Breach
IR-3 Incident Response Testing
IR-4 Incident Handling
IR-5 Incident Monitoring
IR-6 Incident Reporting
IR-7 Incident Response Assistance
IR-8 Incident Response Plan
IR-8(1) Incident Response Plan | Breaches
MP-1 Policy and Procedures
MP-6 Media Sanitization
PE-8(3) Visitor Access Records | Limit Personally Identifiable Information Elements
PL-1 Policy and Procedures
PL-2 System Security and Privacy Plans
PL-4 Rules of Behavior
PL-4(1) Rules of Behavior | Social Media and External Site/application Usage Restrictions
PL-8 Security and Privacy Architectures
PL-9 Central Management
PM-3 Information Security and Privacy Resources
PM-4 Plan of Action and Milestones Process
PM-5(1) System Inventory | Inventory of Personally Identifiable Information
PM-6 Measures of Performance
PM-7 Enterprise Architecture
PM-8 Critical Infrastructure Plan
PM-9 Risk Management Strategy
PM-10 Authorization Process
PM-11 Mission and Business Process Definition
PM-13 Security and Privacy Workforce
PM-14 Testing, Training, and Monitoring
PM-17 Protecting Controlled Unclassified Information on External Systems
PM-18 Privacy Program Plan
PM-19 Privacy Program Leadership Role
PM-20 Dissemination of Privacy Program Information
PM-20(1) Dissemination of Privacy Program Information | Privacy Policies on Websites, Applications, and Digital Services
PM-21 Accounting of Disclosures
PM-22 Personally Identifiable Information Quality Management
PM-24 Data Integrity Board
PM-25 Minimization of Personally Identifiable Information Used in Testing, Training, and Research
PM-26 Complaint Management
PM-27 Privacy Reporting
PM-28 Risk Framing
PM-31 Continuous Monitoring Strategy
PS-6 Access Agreements
PT-1 Policy and Procedures
PT-2 Authority to Process Personally Identifiable Information
PT-3 Personally Identifiable Information Processing Purposes
PT-4 Consent
PT-5 Privacy Notice
PT-5(2) Privacy Notice | Privacy Act Statements
PT-6 System of Records Notice
PT-6(1) System of Records Notice | Routine Uses
PT-6(2) System of Records Notice | Exemption Rules
PT-7 Specific Categories of Personally Identifiable Information
PT-7(1) Specific Categories of Personally Identifiable Information | Social Security Numbers
PT-7(2) Specific Categories of Personally Identifiable Information | First Amendment Information
PT-8 Computer Matching Requirements
RA-1 Policy and Procedures
RA-3 Risk Assessment
RA-7 Risk Response
RA-8 Privacy Impact Assessments
SA-1 Policy and Procedures
SA-2 Allocation of Resources
SA-3 System Development Life Cycle
SA-4 Acquisition Process
SA-8(33) Security and Privacy Engineering Principles | Minimization
SA-9 External System Services
SA-11 Developer Testing and Evaluation
SC-7(24) Boundary Protection | Personally Identifiable Information
SI-1 Policy and Procedures
SI-12 Information Management and Retention
SI-12(1) Information Management and Retention | Limit Personally Identifiable Information Elements
SI-12(2) Information Management and Retention | Minimize Personally Identifiable Information in Testing, Training, and Research
SI-12(3) Information Management and Retention | Information Disposal
SI-18 Personally Identifiable Information Quality Operations
SI-18(4) Personally Identifiable Information Quality Operations | Individual Requests
SI-19 De-identification
Main Menu