Guide to Protecting the Confidentiality of PII

Security breaches that lead to exposure of personally identifiable information (PII) are embarrassing and costly to your enterprise. This guide will help establish a risk-based approach to protecting private information.


Partner logo

NIST is a non-regulatory federal agency within the U.S. Department of Commerce. NIST's mission is to promote U.S. innovation and industrial competitiveness by advancing measurement science, standards and technology in ways that enhance economic security and improve our quality of life.

All IT Downloads from National Institute of Standards and Technology » | Visit National Institute of Standards and Technology »

From National Institute of Standards and Technology | May 19, 2009

Breaches of personally identifiable information (PII) have increased dramatically over the past few years and have resulted in the loss of millions of records. Breaches of PII are hazardous to both individuals and organizations. Individual harms may include identity theft, embarrassment, or blackmail. Organizational harms may include a loss of public trust, legal liability, or high costs to handle the breach. To appropriately protect the confidentiality of PII, organizations should use a risk-based approach. This document provides guidelines for a risk-based approach to protecting the confidentiality of PII.

The attached Zip file includes:

  • Intro Page.doc
  • Cover Sheet and Terms.pdf
  • Guide to Protecting the Confidentiality of PII.pdf
IT Downloads help you save time and money while executing essential IT management tasks. Download this useful resource now and put it to work for your business.

Understanding and Selecting a Data Loss Prevention Solution

This report provides the necessary background in DLP to help you understand the technology, know what to look for in a product (or service), and find the best match for your organization.

Connected Backup

Read this product brief to learn about an automated and easy-to-access backup and recovery solution that eliminates the risk of data loss from an organization's desktops and laptops, whether local or remote.