Comply with NIST Special Publication 800-122 Guide to Protecting the Confidentiality of Personally Identifiable Information (PII) published April 2010 + revision under development 2024-2025. Establish PII definition per OMB M-07-16 + GAO 08-536 (information about an individual that can identify or be linked to a specific individual including name + SSN + driver license + biometric data + financial accounts + email + phone). Conduct PII Confidentiality Impact Analysis (PCIA) per Section 3 to categorise PII impact (Low + Moderate + High) based on identifiability + quantity + data field sensitivity + context of use + obligation to protect + access to + location.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.