{"data":{"id":"PT-08","name":"Computer Matching Requirements","family":"PT","family_name":"Personally Identifiable Information Processing and Transparency","withdrawn":false,"description":"When a system or organization processes information for the purpose of conducting a matching program:\na. Obtain approval from the Data Integrity Board to conduct the matching program;\nb. Develop and enter into a computer matching agreement;\nc. Publish a matching notice in the Federal Register;\nd. Independently verify the information produced by the matching program before taking adverse action against an individual, if required; and\ne. Provide individuals with notice and an opportunity to contest the findings before taking adverse action against an individual.","supplemental_guidance":"The [PRIVACT] establishes requirements for federal and non-federal agencies if they engage in a matching program. In general, a matching program is a computerized comparison of records from two or more automated [PRIVACT] systems of records or an automated system of records and automated records maintained by a non-federal agency (or agent thereof). A matching program either pertains to federal benefit programs or federal personnel or payroll records. A federal benefit match is performed to determine or verify eligibility for payments under federal benefit programs or to recoup payments or delinquent debts under federal benefit programs. A matching program involves not just the matching activity itself but also the investigative follow-up and ultimate action, if any.","enhancements":[],"baseline_low":false,"baseline_moderate":false,"baseline_high":false,"nist_800_53":{"rev5":{"id":"PT-08","name":"Computer Matching Requirements","description":"When a system or organization processes information for the purpose of conducting a matching program:\na. Obtain approval from the Data Integrity Board to conduct the matching program;\nb. Develop and enter into a computer matching agreement;\nc. Publish a matching notice in the Federal Register;\nd. Independently verify the information produced by the matching program before taking adverse action against an individual, if required; and\ne. Provide individuals with notice and an opportunity to contest the findings before taking adverse action against an individual.","discussion":"The [PRIVACT] establishes requirements for federal and non-federal agencies if they engage in a matching program. In general, a matching program is a computerized comparison of records from two or more automated [PRIVACT] systems of records or an automated system of records and automated records maintained by a non-federal agency (or agent thereof). A matching program either pertains to federal benefit programs or federal personnel or payroll records. A federal benefit match is performed to determine or verify eligibility for payments under federal benefit programs or to recoup payments or delinquent debts under federal benefit programs. A matching program involves not just the matching activity itself but also the investigative follow-up and ultimate action, if any.","related_controls":["PM-24"],"baseline_low":false,"baseline_moderate":false,"baseline_high":false,"baseline_privacy":true,"new_in_rev5":true,"changes_from_rev4":"New control family introduced in Rev 5"}},"compliance_mappings":{"iso_27001_2022":["A.5.34"],"iso_27002_2022":["5.34"],"cobit_2019":["APO14"],"pci_dss_v4":[],"nist_csf_2":[],"cis_controls_v8":["CIS 3"],"soc2_tsc":[],"finos_ccc":[],"iso_42001_2023":["A.5.4"],"iec_62443":[],"asd_e8":[],"nis2":[],"apra_cps_234":[],"mas_trm":[],"pra_op_resilience":[],"bsi_grundschutz":["CON.2"],"anssi":["SecNumCloud.19.3"],"osfi_b13":[],"finma_circular":[],"gdpr":["Art.22(1)","Art.22(2)","Art.22(3)","Art.22(4)"],"dora":[],"bio2":["5.34"],"rbi_csf":["Annex1.15"],"fisc":[],"lgpd_bcb":[],"hkma_tme1":[],"mlps_2":[],"dnb_good_practice":[],"cra":[],"swift_cscf":[],"cbuae":["CR-5"],"cbe_csf":["CTO-2"],"popia":["s71"],"bot_cyber":["Ch9.2"],"nerc_cip":[],"nrc_73_54":[],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":[],"pci_pts":[],"fips_140":[],"cbest":[],"tiber_eu":[],"pci_hsm":[],"common_criteria":["CC Part 2 — FPR"],"isae_3402":[],"fca_sysc_13":[],"fda_21_cfr_11":[],"fda_cyber":[],"hitrust_csf":[],"iso_27799":[],"lloyds_ms":["MS7.1"],"naic_ds":[],"nhs_dspt":["NDG-6.2"],"pra_ss1_23":[],"solvency_ii":[],"owasp_masvs_v2":[],"csa_ccm_v4":[],"csa_aicm":[],"ccss_v9":[],"mica":["Art.98(1)"],"basel_sco60":[],"bssc":[],"sec_custody_digital":[],"dpdpa":[]},"attack_techniques":[],"metadata":{"last_reviewed":"2026-10-03","review_notes":"2026-10-03: statement, discussion and related controls taken from NIST SP 800-53 Release 5.2.0, which this file lacked.","mapping_status":"complete"},"function":"preventative","used_by_patterns":[]}}