# PM-24 Data Integrity Board

NIST SP 800-53 control. Family: PM Program Management. Function: preventative. Baselines: privacy. Mapping licence: CC BY-SA 4.0.

Statement: Establish a Data Integrity Board to: a. Review proposals to conduct or participate in a matching program; and b. Conduct an annual review of all matching programs in which the agency has participated.
Guidance: A Data Integrity Board is the board of senior officials designated by the head of a federal agency and is responsible for, among other things, reviewing the agency’s proposals to conduct or participate in a matching program and conducting an annual review of all matching programs in which the agency has participated. As a general matter, a matching program is a computerized comparison of records from two or more automated [PRIVACT] systems of records or an automated system of records and automated records maintained by a non-federal agency (or agent thereof). A matching program either pertains to Federal benefit programs or Federal personnel or payroll records. At a minimum, the Data Integrity Board includes the Inspector General of the agency, if any, and the senior agency official for privacy.

## Clauses by framework (5 frameworks)
- nist_csf_2: GV.RR-01, GV.RR-02
- sama_csf: 1.2
- hipaa_sr: §164.308(a)(2)
- sebi_cscrf: GV.PO
- hitrust_csf: 05.a
OSA's mapping for nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/PM-24
- Clauses only: /api/v1/controls/PM-24?fields=mappings
- Page for people: /controls/pm-24/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
