Cyber Posture

NIST 800-53 r5 · Controls catalogue · Family PT

PT-4Consent

Implement {{ insert: param, pt-04_odp }} for individuals to consent to the processing of their personally identifiable information prior to its collection that facilitate individuals’ informed decision-making.

Last updated: 09 May 2026 03:25 UTC

Implementations targeting this control (0)

ATT&CK techniques this control mitigates (0)

Weaknesses this control addresses (5)AI

CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.

CWE Name CVEs Why this control addresses it
CWE-862Missing Authorization8,680The control supplies the missing authorization check that would otherwise allow processing without user approval.
CWE-284Improper Access Control4,832Consent enforcement adds an explicit access-control gate before any PII processing can occur.
CWE-863Incorrect Authorization3,234Consent logic ensures authorization decisions governing PII are both present and correctly applied.
CWE-285Improper Authorization1,230Requiring affirmative consent implements an authorization decision for each instance of PII collection or use.
CWE-359Exposure of Private Personal Information to an Unauthorized Actor174Mandating consent prior to collection directly prevents unauthorized exposure of private personal information.

Top CVEs where this control is the strongest mitigation

CVE Risk CVSS EPSS Match
No CVEs annotated to this control yet — the per-CVE backfill is in progress.

Other controls in family PT

PT-1 PT-2 PT-3 PT-5 PT-6 PT-7 PT-8