NIST 800-53 r5 · Controls catalogue · Family PT
PT-3Personally Identifiable Information Processing Purposes
Identify and document the {{ insert: param, pt-03_odp.01 }} for processing personally identifiable information; Describe the purpose(s) in the public privacy notices and policies of the organization; Restrict the {{ insert: param, pt-03_odp.02 }} of personally identifiable information to only that which is compatible with the identified purpose(s); and Monitor changes in processing personally identifiable information and implement {{ insert: param, pt-03_odp.03 }} to ensure that any changes are made in accordance with {{ insert: param, pt-03_odp.04 }}.
Last updated: 22 August 2026 07:11 UTC
Implementations targeting this control (0)
- No implementations targeting this control yet.
ATT&CK techniques this control mitigates (0)
- No ATT&CK techniques mapped to this control yet.
Weaknesses this control addresses (5)AI-assisted
CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.
| CWE | Name | CVEs | Why this control addresses it |
|---|---|---|---|
CWE-284 | Improper Access Control | 6,900+ | Implements purpose-based restrictions that serve as an access control mechanism on PII handling and disclosure. |
CWE-285 | Improper Authorization | 1,500+ | Requires authorization decisions for PII processing to be limited to explicitly documented compatible purposes. |
CWE-359 | Exposure of Private Personal Information to an Unauthorized Actor | 200+ | Restricts PII processing and disclosure to authorized purposes, reducing unauthorized exposure of private personal information. |
CWE-501 | Trust Boundary Violation | 33 | Defines explicit trust boundaries for PII use via documented purposes and prevents processing outside those boundaries. |
CWE-213 | Exposure of Sensitive Information Due to Incompatible Policies | 32 | Directly enforces purpose compatibility and policy alignment for PII processing, preventing exposure from incompatible policies. |
Top CVEs where this control is the strongest mitigation
| CVE | Risk | CVSS | EPSS | Match |
|---|---|---|---|---|
CVE-2023-6517 UPD | 5.9 | 7.5 | 0.0048 | partial |
CVE-2025-54831 UPD | 5.3 | 6.5 | 0.0091 | partial |
CVE-2024-7267 UPD | 5.2 | 6.5 | 0.0060 | partial |
CVE-2023-3441 UPD | 4.9 | 6.6 | 0.0055 | partial |
CVE-2026-6280 | 4.9 | 6.5 | 0.0023 | partial |
CVE-2024-49354 UPD | 4.4 | 5.3 | 0.0034 | partial |
CVE-2025-24316 UPD | 4.4 | 5.3 | 0.0030 | partial |
CVE-2025-4976 UPD | 3.7 | 4.3 | 0.0040 | partial |
CVE-2024-44121 UPD | 3.6 | 4.3 | 0.0029 | partial |
CVE-2025-32791 UPD | 3.6 | 4.3 | 0.0028 | partial |
CVE-2023-5117 UPD | 3.2 | 3.7 | 0.0031 | partial |
CVE-2024-49827 UPD | 3.2 | 3.7 | 0.0024 | partial |
CVE-2025-52603 | 3.1 | 3.5 | 0.0026 | partial |
CVE-2026-56538 UPD | 3.0 | 3.5 | 0.0016 | partial |
CVE-2026-33216 UPD | 6.2 | 8.6 | 0.0037 | partial |