NIST 800-53 r5 · Controls catalogue · Family PM
PM-26Complaint Management
Implement a process for receiving and responding to complaints, concerns, or questions from individuals about the organizational security and privacy practices that includes: Mechanisms that are easy to use and readily accessible by the public; All information necessary for successfully filing complaints; Tracking mechanisms to ensure all complaints received are reviewed and addressed within {{ insert: param, pm-26_prm_1 }}; Acknowledgement of receipt of complaints, concerns, or questions from individuals within {{ insert: param, pm-26_odp.03 }} ; and Response to complaints, concerns, or questions from individuals within {{ insert: param, pm-26_odp.04 }}.
Last updated: 22 August 2026 07:11 UTC
Implementations targeting this control (0)
- No implementations targeting this control yet.
ATT&CK techniques this control mitigates (0)
- No ATT&CK techniques mapped to this control yet.
Weaknesses this control addresses (5)AI-assisted
CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.
| CWE | Name | CVEs | Why this control addresses it |
|---|---|---|---|
CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | 11,000+ | Provides individuals an accessible, tracked channel to report exposures of sensitive information, prompting timely organizational review and remediation that shortens the window for exploitation. |
CWE-284 | Improper Access Control | 6,900+ | Enables users to surface and force remediation of improper access-control decisions in security practices, directly reducing the persistence of exploitable authorization gaps. |
CWE-285 | Improper Authorization | 1,500+ | Complaints about authorization failures are logged, acknowledged, and resolved within defined time bounds, making it harder for attackers to rely on long-lived authorization weaknesses. |
CWE-693 | Protection Mechanism Failure | 700+ | A formal redress process detects when protection mechanisms fail in practice and compels their repair, lowering the likelihood that known protection failures remain exploitable. |
CWE-359 | Exposure of Private Personal Information to an Unauthorized Actor | 200+ | Gives data subjects a reliable mechanism to report exposure of private personal information, driving corrective action that mitigates privacy-related information-leakage weaknesses. |
Top CVEs where this control is the strongest mitigation
| CVE | Risk | CVSS | EPSS | Match |
|---|---|---|---|---|
| No CVEs annotated to this control yet — the per-CVE backfill is in progress. | ||||