NIST 800-53 r5 · Controls catalogue · Family PT
PT-2Authority to Process Personally Identifiable Information
Determine and document the {{ insert: param, pt-02_odp.01 }} that permits the {{ insert: param, pt-02_odp.02 }} of personally identifiable information; and Restrict the {{ insert: param, pt-02_odp.03 }} of personally identifiable information to only that which is authorized.
Last updated: 22 August 2026 14:14 UTC
Implementations targeting this control (0)
- No implementations targeting this control yet.
ATT&CK techniques this control mitigates (0)
- No ATT&CK techniques mapped to this control yet.
Weaknesses this control addresses (7)AI-assisted
CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.
| CWE | Name | CVEs | Why this control addresses it |
|---|---|---|---|
CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | 11,000+ | Limits PII handling to authorized authority, making unauthorized exposure of sensitive information less likely. |
CWE-862 | Missing Authorization | 10,200+ | Requires explicit determination and documentation of authority before any PII processing occurs, addressing missing authorization. |
CWE-284 | Improper Access Control | 6,900+ | Requires documented authority and explicit restriction of PII processing to only authorized actions, directly mitigating improper access control. |
CWE-863 | Incorrect Authorization | 3,900+ | Restricts processing strictly to documented authorized uses, mitigating incorrect authorization decisions for sensitive data. |
CWE-285 | Improper Authorization | 1,500+ | Mandates determining authority and limiting processing to what is authorized, preventing improper authorization over personal data. |
CWE-359 | Exposure of Private Personal Information to an Unauthorized Actor | 200+ | Enforces restriction of PII processing to authorized purposes, reducing exposure of private personal information to unauthorized actors. |
CWE-213 | Exposure of Sensitive Information Due to Incompatible Policies | 32 | Demands documented authority and policy alignment for PII processing, reducing exposure due to incompatible or absent policies. |
Top CVEs where this control is the strongest mitigation
| CVE | Risk | CVSS | EPSS | Match |
|---|---|---|---|---|
CVE-2026-74969 | 6.5 | 8.8 | 0.0032 | good |
CVE-2024-26192 UPD | 6.2 | 8.2 | 0.0151 | good |
CVE-2025-43227 UPD | 6.1 | 7.5 | 0.0117 | good |
CVE-2025-66172 UPD | 6.1 | 8.1 | 0.0051 | good |
CVE-2025-11959 UPD | 6.0 | 8.1 | 0.0028 | good |
CVE-2025-34441 | 6.0 | 7.5 | 0.0083 | good |
CVE-2024-33271 UPD | 5.9 | 7.5 | 0.0048 | good |
CVE-2024-10267 UPD | 5.9 | 7.5 | 0.0060 | good |
CVE-2025-49715 UPD | 5.9 | 7.5 | 0.0069 | good |
CVE-2025-43399 UPD | 5.9 | 7.5 | 0.0055 | good |
CVE-2025-43405 UPD | 5.9 | 7.5 | 0.0055 | good |
CVE-2025-43496 UPD | 5.9 | 7.5 | 0.0049 | good |
CVE-2025-43500 UPD | 5.9 | 7.5 | 0.0049 | good |
CVE-2026-24735 | 5.9 | 7.5 | 0.0062 | good |
CVE-2020-37173 | 5.9 | 7.5 | 0.0056 | good |
CVE-2019-25762 UPD | 5.9 | 7.5 | 0.0063 | good |
CVE-2023-50053 UPD | 5.8 | 7.6 | 0.0053 | good |
CVE-2024-30056 UPD | 5.8 | 7.1 | 0.0155 | good |
CVE-2024-36677 UPD | 5.8 | 7.5 | 0.0038 | good |
CVE-2024-36682 UPD | 5.8 | 7.5 | 0.0038 | good |
CVE-2024-11206 UPD | 5.8 | 7.5 | 0.0038 | good |
CVE-2025-20060 UPD | 5.8 | 7.5 | 0.0038 | good |
CVE-2025-65857 UPD | 5.8 | 7.5 | 0.0042 | good |
CVE-2026-28906 UPD | 5.8 | 7.5 | 0.0043 | good |
CVE-2026-48615 | 5.8 | 7.5 | 0.0042 | good |