# PT-08 Computer Matching Requirements

NIST SP 800-53 control. Family: PT Personally Identifiable Information Processing and Transparency. Function: preventative. Baselines: privacy. Mapping licence: CC BY-SA 4.0.

Statement: When a system or organization processes information for the purpose of conducting a matching program: a. Obtain approval from the Data Integrity Board to conduct the matching program; b. Develop and enter into a computer matching agreement; c. Publish a matching notice in the Federal Register; d. Independently verify the information produced by the matching program before taking adverse action against an individual, if required; and e. Provide individuals with notice and an opportunity to contest the findings before taking adverse action against an individual.
Guidance: The [PRIVACT] establishes requirements for federal and non-federal agencies if they engage in a matching program. In general, a matching program is a computerized comparison of records from two or more automated [PRIVACT] systems of records or an automated system of records and automated records maintained by a non-federal agency (or agent thereof). A matching program either pertains to federal benefit programs or federal personnel or payroll records. A federal benefit match is performed to determine or verify eligibility for payments under federal benefit programs or to recoup payments or delinquent debts under federal benefit programs. A matching program involves not just the matching activity itself but also the investigative follow-up and ultimate action, if any.

## Clauses by framework (18 frameworks)
- iso_27001_2022: A.5.34. OSA's own, not in NIST's crosswalk: A.5.34
- iso_27002_2022: 5.34
- cobit_2019: APO14
- cis_controls_v8: CIS 3
- iso_42001_2023: A.5.4
- bsi_grundschutz: CON.2
- anssi: SecNumCloud.19.3
- gdpr: Art.22(1), Art.22(2), Art.22(3), Art.22(4)
- bio2: 5.34
- rbi_csf: Annex1.15
- cbuae: CR-5
- cbe_csf: CTO-2
- popia: s71
- bot_cyber: Ch9.2
- common_criteria: CC Part 2 — FPR
- lloyds_ms: MS7.1
- nhs_dspt: NDG-6.2
- mica: Art.98(1)
OSA's mapping for iso_27001_2022 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/PT-08
- Clauses only: /api/v1/controls/PT-08?fields=mappings
- Page for people: /controls/pt-08/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
