ASOM-Fedv6.1Open the explorer
FO-1 · Federal Obligations

Privacy Terrain Identification

Control Statement

Elements holding personally identifiable information shall be identified on the terrain overlay, with the authority under which the information is held recorded against each.

Purpose. To make privacy exposure positional, so that the elements holding personal information can be defended, minimized and accounted for as terrain.

Discussion

Privacy terrain is the only ground in the framework where holding *more* of it is itself the risk. Everywhere else, an element on the overlay is an asset to be defended; here, an element holding personal information without a recorded authority is an exposure that should be removed rather than protected. The authority requirement is therefore doing double duty — it satisfies the federal obligation, and it surfaces holdings that no authority covers, which are the ones a defense should not be built around in the first place.

Goals and Metrics

A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.

Personal-information holdings are identified with their authority.
  • Percentage of elements holding personal information identified on the overlay
  • Number of such elements with no recorded authority for holding it

Accountability

Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.

AOCTISOCHUNTPLATISSO
Authorizing Official / CISO: AccountableCyber Threat Intelligence cell: ConsultedSOC / Defensive Operations: InformedHunt team: InformedPlatform and product owners: ConsultedGovernance / RMF / ISSO: Responsible

AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO

  • AccountableAuthorizing Official / CISO
  • ConsultedCyber Threat Intelligence cell
  • InformedSOC / Defensive Operations
  • InformedHunt team
  • ConsultedPlatform and product owners
  • ResponsibleGovernance / RMF / ISSO

Inputs and Outputs

Consumes

Produces

Activities

  1. L2Mark elements holding personally identifiable information on the terrain overlay.
  2. L2Record against each the authority under which the information is held.
  3. L2Flag marked elements carrying no recorded authority.
  4. L3Reconcile the marked set against the agency's privacy impact assessments and systems of records notices, in both directions — unmarked elements that appear in a notice, and marked elements that appear in none.
  5. L3Record the categories held, so that exposure can be assessed by sensitivity rather than by presence alone.
  6. L3Raise a finding for any holding with no covering authority, dispositioned as removal rather than as protection wherever the mission permits.
  7. L3Include derived and incidental holdings — logs, caches, analytics stores, backups — which are the holdings least likely to appear in a notice.
  8. L4Trend the count and weight of privacy terrain, since a defensible program should see it fall rather than grow.
  9. L4Measure the interval between a new holding appearing and its authority being recorded.
  10. L5Feed recurring unauthorized holdings back into system design and data retention practice, rather than remediating the same class each cycle.

Measurement

Outcome

Percentage of privacy terrain elements with a recorded covering authority.

Performance

Trend in the count and weight of privacy terrain across cycles.

Evidence and Assessment

Evidence expected

Terrain overlay with privacy elements marked; authority recorded per element; reconciliation record against assessments and notices.

Assessment procedure

Examine the overlay against the privacy impact assessments and systems of records notices; test for elements holding such information that are unmarked, including logs, caches and backups.

Related Guidance

Inherits
  • PT-2
  • PT-3
  • RA-8
Satisfies
  • GV.OC-03
  • ID.AM-07

Where This Control Is Used

Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.

Forms of Maneuver It Assesses

  • M5AmbushTrade space for information and time, and impose cost.1 of 13 techniques — M5.03

Terrain It Is Named On

  • T5DataPrivacy terrain identification names the PII holdings as terrain rather than as a compliance register.

Artifacts It Stands On

  • producesPrivacy and controlled-information terrain registerWhere privacy holdings and controlled unclassified information sit, the authorities under which they are held, and the boundaries their handling requires — expressed as denied paths, not as policy statements.
  • consumesCyber Terrain OverlayThe positional map of the estate: every element with a defensive layer, a defensive weight, a named accountable owner and its adjacencies. Not an asset inventory — an inventory enumerates, an overlay positions.

Roles It Puts to Work