Cyber Resilience

NIST 800-53 r5 · Controls catalogue · Family PT

PT-2Authority to Process Personally Identifiable Information

Determine and document the {{ insert: param, pt-02_odp.01 }} that permits the {{ insert: param, pt-02_odp.02 }} of personally identifiable information; and Restrict the {{ insert: param, pt-02_odp.03 }} of personally identifiable information to only that which is authorized.

Last updated: 22 August 2026 14:14 UTC

Implementations targeting this control (0)

ATT&CK techniques this control mitigates (0)

Weaknesses this control addresses (7)AI-assisted

CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.

CWE Name CVEs Why this control addresses it
CWE-200Exposure of Sensitive Information to an Unauthorized Actor11,000+Limits PII handling to authorized authority, making unauthorized exposure of sensitive information less likely.
CWE-862Missing Authorization10,200+Requires explicit determination and documentation of authority before any PII processing occurs, addressing missing authorization.
CWE-284Improper Access Control6,900+Requires documented authority and explicit restriction of PII processing to only authorized actions, directly mitigating improper access control.
CWE-863Incorrect Authorization3,900+Restricts processing strictly to documented authorized uses, mitigating incorrect authorization decisions for sensitive data.
CWE-285Improper Authorization1,500+Mandates determining authority and limiting processing to what is authorized, preventing improper authorization over personal data.
CWE-359Exposure of Private Personal Information to an Unauthorized Actor200+Enforces restriction of PII processing to authorized purposes, reducing exposure of private personal information to unauthorized actors.
CWE-213Exposure of Sensitive Information Due to Incompatible Policies32Demands documented authority and policy alignment for PII processing, reducing exposure due to incompatible or absent policies.

Top CVEs where this control is the strongest mitigation

CVE Risk CVSS EPSS Match
CVE-2026-749696.58.80.0032good
CVE-2024-26192 6.28.20.0151good
CVE-2025-43227 6.17.50.0117good
CVE-2025-66172 6.18.10.0051good
CVE-2025-11959 6.08.10.0028good
CVE-2025-344416.07.50.0083good
CVE-2024-33271 5.97.50.0048good
CVE-2024-10267 5.97.50.0060good
CVE-2025-49715 5.97.50.0069good
CVE-2025-43399 5.97.50.0055good
CVE-2025-43405 5.97.50.0055good
CVE-2025-43496 5.97.50.0049good
CVE-2025-43500 5.97.50.0049good
CVE-2026-247355.97.50.0062good
CVE-2020-371735.97.50.0056good
CVE-2019-25762 5.97.50.0063good
CVE-2023-50053 5.87.60.0053good
CVE-2024-30056 5.87.10.0155good
CVE-2024-36677 5.87.50.0038good
CVE-2024-36682 5.87.50.0038good
CVE-2024-11206 5.87.50.0038good
CVE-2025-20060 5.87.50.0038good
CVE-2025-65857 5.87.50.0042good
CVE-2026-28906 5.87.50.0043good
CVE-2026-486155.87.50.0042good

Other controls in family PT

PT-1 PT-3 PT-4 PT-5 PT-6 PT-7 PT-8